-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 04 May 2020 13:32:51 +0200 Source: otrs2 Architecture: source Version: 6.0.28-1 Distribution: unstable Urgency: high Maintainer: Patrick Matthäi <pmatth...@debian.org> Changed-By: Patrick Matthäi <pmatth...@debian.org> Closes: 959448 Changes: otrs2 (6.0.28-1) unstable; urgency=high . * New upstream release. - Fixes CVE-2020-1774, also known as OSA-2020-11: When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it’s possible to mix them and to send private key to the third-party instead of public key. Closes: #959448 * Add new dependency libmath-random-secure-perl. * Upgrade to debhelper-compat 13. Checksums-Sha1: 3db7fc57b3da0779cd004769b9d0b8a652fac96a 1817 otrs2_6.0.28-1.dsc 7168f7094cb11fb9f475b473577aadaaac9e8350 25785989 otrs2_6.0.28.orig.tar.bz2 086cf44e4740f7fc6607545dce414307fda120f5 30832 otrs2_6.0.28-1.debian.tar.xz 20cddec92faf688c831e987cfb800b984e5c2d74 5917 otrs2_6.0.28-1_source.buildinfo Checksums-Sha256: f46f317ac8f36b4c24190ebd951b03e4520e89e8d7d97a8c555d351128cb652d 1817 otrs2_6.0.28-1.dsc 7c04d581689423863037dc12a37ad5cf48815522c23a19defe46a68d617319b8 25785989 otrs2_6.0.28.orig.tar.bz2 1ffa3e67591e87147d2e808fb613cf3f293eb928ee8ba371bc71241a4ea33293 30832 otrs2_6.0.28-1.debian.tar.xz 23f31eb2985263bd8d3ccb85a45ae31bf6f5ba311eaf80cc5aef51516beedccc 5917 otrs2_6.0.28-1_source.buildinfo Files: b3feb520b4157f3ad38b69888b99228a 1817 non-free/web optional otrs2_6.0.28-1.dsc 70fde076204f5c79234aa3d61b59e74f 25785989 non-free/web optional otrs2_6.0.28.orig.tar.bz2 fbf2a83a3176de606f7d91d4b2640d38 30832 non-free/web optional otrs2_6.0.28-1.debian.tar.xz 04bf8ec672cad344f004c777efa51ec0 5917 non-free/web optional otrs2_6.0.28-1_source.buildinfo
-----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEWKA9xYJCWk3IuQ4TEtmwSpDL2OQFAl6wDjoACgkQEtmwSpDL 2OTyaA//XMQ4Mjvfr10Q1RioZiFE+cT/dlCxgtSjiCil3LvX1D+W6tAaCTg0Y8FR /kPmxa9N++4Kgy6vnBN/7rBdOvfPod9BdBdtpVhBlpVSUvC5TiXa27KB5YOhxY9j uQIkZzimoe2o8MNQ9ClLwWCgQowniSBeAow+lUknVsehcM+qzh7uH6jDGfNB76eR wbTarLx5UaMI3INhmXgAjCFZuYxlpmw//hAC2lyn05m9miIjez5f8NBwu+jJSoOR IT7Zb0DYEJUeIPEJieO2MZMnrZOaZv7IpzMkevUA7QLkmioK2QLrtgCG4uRWEPKX rpRH4t7FwaCNN7iWOUd4k7rwCwc52LVJpai3a8jXM1YAOdpK/6e+XM4GHl/vxXov c0pV3MrQYIc6AYnYBlxOSgV+o2v8EMItEYtWhfSD65lKq+UCfE5ZPzhf3uMuR+ey 5phV+ldRl7rDgLcMKds5JbsIrR6oergvyjY3SOPSkosmrTiAmPDWMcPvKUBWs4MI yOUrhWBS2kjJ1BMn9C4Ia9RKX4/7Gm0zySdr1YsGNLSMy6XF6E4FyqVyGkcLcv1S QsEb/F0um3Xv6BHzk8d+g7pWW1j5R/EOEG6HvROEE+HXuA3IbZZdDogWFRAGze6d /a5itBvv2RHfK0x0le6l4bLvca75KjIQbePc8GH6jERr65hNtqI= =I9aQ -----END PGP SIGNATURE-----