[continued from previous message]
Received: from mailly.debian.org ([2001:41b8:202:de
b:6564:a62:52c3:4b72]:51714)
by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RS
_PSS_RSAE_SHA256__AES_256_GCM:256)
(Exim 4.96)
(envelope-from )
id 1vEm0q-002a0G-2D
for 1119539-close@bugs.debian.org;
Fri, 31 Oct 2025 10:05:41 +0000
Received: from [192.91.235.231] (port=49914 helo=fasolo.debian.org)
from C=NA,ST=NA,L=Ankh Morpork,O=Debian SMTP,OU=Debian SMTP CA,
N=fasolo.debian.org,EMAIL=hostmaster@fasolo.debian.org (verified)
by mailly.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_P
S_RSAE_SHA256__AES_256_GCM:256)
(Exim 4.96)
(envelope-from )
id 1vEm0q-000eiH-0f
for 1119539-close@bugs.debian.org;
Fri, 31 Oct 2025 10:05:40 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-
ID
:Content-Description:In-Reply-To:References;
bh=oNuBsB01me9wLpwL2+alC7PxnbjPdA+sUAObHDg4Og0=; b
=j6iQSgpPdsyMOHEky58g5Hur7q
QDN20j/fN6JnJGrnjTC6tow+TBb2PnSyK2lO+RKuGWVaCw2dw8
t3pRBV8iKoxxplG1FdcIel6NrUe
3i6VZ5pyAUao35DBRCMjNkiM2ZJWwWyq/bVGk2IISqa1wHPKhF
9/IRnZkSlBPulGumUfjPm/9qzbB
7pR0Nxd9728r+tgjy00qY0ckYvTZgzAnJHUb3xdICM6gTnu+bH
+w2mawcitavdWZyHgvTj37WXy4J
twjzepsZGCDBof/P410bPwdbTEvM7Clko3hXpp2IFsnowTUTsv
jrfrxtclqt5s5iwUP7rdRx2cetL
ELBkSN2w==;
Received: from dak by fasolo.debian.org with local (Exim 4.96)
(envelope-from )
id 1vEm0p-00A4yr-2W;
Fri, 31 Oct 2025 10:05:39 +0000
From: Debian FTP Masters
Reply-To: Michael Tokarev
To: 1119539-close@bugs.debian.org
X-DAK: dak process-upload
X-Debian: DAK
X-Debian-Package: busybox
Debian: DAK
Debian-Changes: busybox_1.37.0-7_source.changes
Debian-Source: busybox
Debian-Version: 1:1.37.0-7
Debian-Architecture: source
Debian-Suite: unstable
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1119539: fixed in busybox 1:1.37.0-7
Content-Type: multipart/signed; micalg="pgp-sha256";
protocol="application/pgp-signature";
boundary="===============6596095547798193347=="
Message-Id:
Date: Fri, 31 Oct 2025 10:05:39 +0000
--===============6596095547798193347==
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Source: busybox
Source-Version: 1:1.37.0-7
Done: Michael Tokarev
We believe that the bug you reported is fixed in the latest version of
busybox, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1119539@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Michael Tokarev (supplier of updated busybox package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 31 Oct 2025 12:47:09 +0300
Source: busybox
Architecture: source
Version: 1:1.37.0-7
Distribution: unstable
Urgency: medium
Maintainer: Debian Install System Team
Changed-By: Michael Tokarev
Closes: 1055307 1119539
Changes:
busybox (1:1.37.0-7) unstable; urgency=medium
.
* patches/archival-disallow-path-traversals-CVE-2023-39810.patch
(Closes: #1055307, CVE-2023-39810)
* archival-disallow-path-traversals-CVE-2023-39810.patch:
use the correct "echo" when constructing the archive
* d/config/pkg/* CONFIG_FEATURE_PATH_TRAVERSAL_PROTECTION=y
* enable chattr and lsattr applets (Closes: #1119539)
* udeb: install all links in /usr/, do not touch /bin & /sbin
Checksums-Sha1:
9bcc3aa50d9ad73e611ec714f84d489b094a3f89 2377 busybox_1.37.0-7.dsc
9b6817999237674feee9aef35fff0dec261b2cb2 66864 busybox_1.37.0-7.debian.tar.
xz
4e4c91bb74b879c0645bb54df879bf9c7a989804 5613 busybox_1.37.0-7_
ource.buildinfo
Checksums-Sha256:
2f3944fccc4e1dae361bebb29631f703a29751d2bca4f50e3e582876b1af8c8e 2377
busybox_1.37.0-7.dsc
f92b18875c8411c4bb5d024899fc0592b799e500fb0e4792a764352d380d2255 66864
busybox_1.37.0-7.debian.tar.xz
d94ac1e65cd72b5d6c899eb55533fcde79177ef7de145de2e519cf4bada93b38 5613
busybox_1.37.0-7_source.buildinfo
Files:
267448354ab2a2ae41ee15c01672ee2a 2377 utils optional busybox_1.37.0-7.dsc
dd7c740817de9e86a3e1b83a1c8a9d4d 66864 utils optional busybox_1
37.0-7.debian.tar.xz
40f11fae73b08fc24bbd595d31aebd0b 5613 utils optional busybox_1.
7.0-7_source.buildinfo
-----BEGIN PGP SIGNATURE-----
wsG7BAEBCgBvBYJpBIWwCRCCqkokOx6UeEcUAAAAAAAeACBzYWx0QG5vdGF0aW9u
cy5zZXF1b2lhLXBncC5vcmfBT4SEoErUBHc/OzQpxFSlo+AeiNdNXg6NlcB67FHZ
fBYhBGSqKrUx1WkDNmv++YKqSiQ7HpR4AADY1A/7BbLbXTxWPSGrKh7PrJ8Esbv8
GXTmadalyjABzquzHN0FZwl7pBriapx7GXiH0FHN3ciixlmMHR7DBUgOcBnc/nvf
EOZeUqXRu6wauM1iyF9Rv/xD8pnPHluFAu2zM9Rz9MSLGLpK31WbXTfw/gSOPjMk
da2Pp7+/wfImlkfkaJTwy2exBzjW0MdwKV++LNOCygf161jfCkii4hw1YlKj7zH1
bJnVLDHImGC6QT2D2hKXwT9k+n7SzRzGTxaKKeLKi1FANguma3KIgl3stbrxeH1p
cOvaKqKUxS0Y8ehcoH9a+R5qCyBHc4f4+PEMVhufpAzJ8K+eHum2goi7rC49dt/p
mPE6j6CVHYsibytcmVTP7Q7h3M15Id2wMxQuo30rYZ12CSPz2mymqubxSWD4UvBx
v9Li4MFAFwWyvMVOk/160c3xqiN7c2fTVzHscCOcYmb8HyMijBs3nE04cFlQX0sk
LBYcF3vL7P05Biy7HiAt50d3UhSroDCWQhP9P9KpPF9cUng4/JwFfECRRJXH+nwl
j0h4vuhhtJimhom6teKydNxP3TTQrTLy8boY+nPwv6NrKHxmGizUwXRwXg1Gx9be
SHoP8xzhzl2oYTzYn4mUVmgAtWjOGnbugcTlZN5wGeAqOe5gp3SU1qq/xWMc+qPF
5baoA54DjoB84Ts2cVI=
=7xeF
-----END PGP SIGNATURE-----
--==============e96095547798193347=Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCaQSJ8wAKCRCb9qggYcy5
IYsdAP9EdcMWMS/ff4A3DcRa/Cfsz4c6nGbfxEoXRmqTYQRNlgD+I7tvgrwWrkBG
gz5XYTeSPrIZsmz8uSOlz+r1tUTGNAg=v/5w
-----END PGP SIGNATURE-----
--==============e96095547798193347==--
--- SoupGate-Win32 v1.05
* Origin: you cannot sedate... all the things you hate (1:229/2)
|