-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 27 Jun 2021 17:02:18 +0200 Source: python-urllib3 Architecture: source Version: 1.26.5-1~exp1 Distribution: unstable Urgency: medium Maintainer: Debian Python Team <team+pyt...@tracker.debian.org> Changed-By: Daniele Tricoli <er...@debian.org> Closes: 989848 Changes: python-urllib3 (1.26.5-1~exp1) unstable; urgency=medium . * New upstream version 1.26.5 - CVE-2021-33503: Catastrophic backtracking in URL authority parser when passed URL containing many @ characters. (Closes: #989848) * Refresh patches. Checksums-Sha1: d78a6df6ec7cf78dda84f78dcee361ee25b5eadb 2243 python-urllib3_1.26.5-1~exp1.dsc 31d7e239a9dbaf0a9602d3f272d911d05f98d8a0 292865 python-urllib3_1.26.5.orig.tar.gz ec997abf6779a9f82124b704f6e555ab6c905c1f 12164 python-urllib3_1.26.5-1~exp1.debian.tar.xz 5804e0cd201a284285ab97346d8fa3b08afd6b5e 7037 python-urllib3_1.26.5-1~exp1_amd64.buildinfo Checksums-Sha256: 39abf0f987b0addc16146995dffde5073af9c878018f0cad23a43f0eb74a0671 2243 python-urllib3_1.26.5-1~exp1.dsc a7acd0977125325f516bda9735fa7142b909a8d01e8b2e4c8108d0984e6e0098 292865 python-urllib3_1.26.5.orig.tar.gz b986919e426bc0a2266345aecd30eb7eb209a709abaff0fc21b27a0338aaf360 12164 python-urllib3_1.26.5-1~exp1.debian.tar.xz f9616b2f4f6748477afaff6e7bf22973cdd837e312b40279676946d4b9596114 7037 python-urllib3_1.26.5-1~exp1_amd64.buildinfo Files: bb939c130944cb77324d9b7e093eb2b3 2243 python optional python-urllib3_1.26.5-1~exp1.dsc 33b8670413e684188b1340204bc8ad75 292865 python optional python-urllib3_1.26.5.orig.tar.gz 882c94c34455cc465a8b50260c7315d9 12164 python optional python-urllib3_1.26.5-1~exp1.debian.tar.xz d590951ccb1631674cc7b8d0bc5a916f 7037 python optional python-urllib3_1.26.5-1~exp1_amd64.buildinfo
-----BEGIN PGP SIGNATURE----- iQJFBAEBCgAvFiEExlrvn+W/jMvW7bAZi69SLA1szt0FAmDYlN8RHGVyaW9sQGRl Ymlhbi5vcmcACgkQi69SLA1szt2hQQ//adazCbRYGc0ZM1fFhrlmHfqLaI+Rvlku 6prwETppTwW5GMCALAAiql6XMG0oYS7FD2O0qpamaPdnxDXBN1WFv9tdZRrWbQNI NqaEwQrZuPYsG7zbXsjmWHQI0Flugw3m2ARBJ6VGXIDFExYdO6ujrZDso1pOT7Dk cMjX+XHHmmSumZ2xmhgrKHYKoflLleGymk/crTY9pg8GD115312tPOsSKyqtAdnb uoMNV9vAEsy58Klyhe2bOrgw3tkskKc3VuGqE2n5/YAnIsSL6TDc5094rMLQ4Mf2 vOJrtreBKdpyB5YnsQ2fxgmtBtsfjm/1tmR5fMNYibo1VHt+380cByN6E5wk8zXF zeuHmLjEK1F1hzb7ko3Wo4vZcbCn5b+aAfGEXLs0qyXDggXa2KYdM92S25t+avbN 0Q9ncMciUGIkVhsLFQO/XNe7lgh2IqdI6pecDThtT/Mtn4lhNEY4IuOajDBLAJsL wTARNhZ3Ycy9kQkicOPB2hNeIduBLQujJ6m9Vpw2vtzxFaCI/xSaih2oXNlAZr9+ jx5azuIieh9quJAOxPfk/2H2mAV5K3DfhribDhn77ylVukUI0WtVUY52qBgHsHOF 3YEhKsoaCVYDcKSl+V5ZinUBSBSwYd7K5spymJ8qoagQwVGgNQbiaFYTLH2lmjCK cVwhMqu5cZc= =sQ6r -----END PGP SIGNATURE-----