-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 18 Aug 2022 15:02:04 +0800 Source: freecad Binary: freecad freecad-common Architecture: all Version: 0.19.1+dfsg1-2+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: all Build Daemon (x86-csail-02) Changed-By: Aron Xu Description: freecad - Extensible Open Source CAx program freecad-common - Extensible Open Source CAx program - common files Changes: freecad (0.19.1+dfsg1-2+deb11u1) bullseye-security; urgency=medium . * Non-maintainer upload by the Security Team. * CVE-2021-45844 and CVE-2021-45845: - Fix two external command execution issues in Python scripts that are vunlnerbale to OS command injection when crafted input file is applied Checksums-Sha1: 2c9556046954e58061775962e6209cb96be203f9 17235896 freecad-common_0.19.1+dfsg1-2+deb11u1_all.deb 9f32c422478f43b22ac11fc416e38856deb1dfac 31398 freecad_0.19.1+dfsg1-2+deb11u1_all-buildd.buildinfo a3faac4e568e836ef58bb3935d8c505c4496cf52 35328 freecad_0.19.1+dfsg1-2+deb11u1_all.deb Checksums-Sha256: e9073a10eeded7573bbd016760a66d49411aedb845ee00b9a172f93e2280e5ee 17235896 freecad-common_0.19.1+dfsg1-2+deb11u1_all.deb de854f3990d79cf1e50a7d2aacb58bf9d764c46e143c8994a94996b4a9dc22c3 31398 freecad_0.19.1+dfsg1-2+deb11u1_all-buildd.buildinfo ab17ef28368d8233025912283a190a40b404a7c910775e67785e00123cb06fb2 35328 freecad_0.19.1+dfsg1-2+deb11u1_all.deb Files: 1ca24bd33ea2c9635376a2c6797dc5d5 17235896 science optional freecad-common_0.19.1+dfsg1-2+deb11u1_all.deb eb8af1bee9045a0778d63b6a84814dcd 31398 science optional freecad_0.19.1+dfsg1-2+deb11u1_all-buildd.buildinfo 2e4bd77422cf4cd05940563a9c2b781f 35328 science optional freecad_0.19.1+dfsg1-2+deb11u1_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEEfeZ4tM1TNG7DMXxJGSMJV360gIFAmMexVEACgkQJGSMJV36 0gLPqQ//ey8+v9IrbfHmAfYm3WJmp3rKj6I5kJOM/kvP0YyimQErSuCl2/+PUV2l khXSUiELpgUYWW2dxAcnszpHCsoJ+p3Vt5ZuhlRyKht9xNR65RfqJMvzKOPHgGsc jKTpGrW9iFnN2TnzkRq3yAJmtDyYUg0e89QE7I+uEPydZNZL4kAUy3hcpFNku8os 6uu93d6O3e5djjiwJI8jq1/geAUYEIPK5SVCidD0rvdtNz+FExOm0ZsMroEg09T+ CrMQIyybxRcUQ9w9FSzL35la8QZTdYyEDGhOPhwVCzh59Ag5yS9lSAGqZ7JUBuwh L7JIgorkdEyCxfDB/9FPyikmbdwJWZkZVISis9cxXkFOBbAdNUgHkrv2mgCKrRIx mGNIpelpy4iBshvQukYxr8yqgNf5aPQLukQ5jQ4yhFD9UAJxux8ff9yjnlArwZn7 LnJwUlomOCYuczE52JF7Pc54A0b5OiaHRUjnxnjPqusFZLwl1SSBCCuMwgaVSENu sydr9GBjPXNYfPKe6Fem8tpjq+214c+/BO3dETgG7Dw8sq3tQ8+pNXLWajI1LSaB rb0aQOOIdOM/tLUC+skZwhQzypjphqh6ofIoGRmA7uE5BmoJhjdMRDxKGXUm5QsN tUG0+fSmeAT5hErU5TXH40rLMgzNalfbffK8d8zSkoPAs0R4O/U= =DSgS -----END PGP SIGNATURE-----