-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 20 Mar 2025 13:56:44 +0100 Source: mercurial Binary: mercurial mercurial-dbgsym Architecture: armel Version: 6.3.2-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-02) <buildd_arm64-arm-conova-02@buildd.debian.org> Changed-By: Julien Cristau <jcristau@debian.org> Description: mercurial - easy-to-use, scalable distributed version control system Closes: 1100899 Changes: mercurial (6.3.2-1+deb12u1) bookworm-security; urgency=high . * CVE-2025-2361: reflected XSS in hgweb (closes: #1100899) * patchbomb: don't test ambiguous address (fixes FTBFS after python's fix for CVE-2023-27043). Checksums-Sha1: 38f1785c3499b3750adb00b29c9764631585e999 1573820 mercurial-dbgsym_6.3.2-1+deb12u1_armel.deb 9dff7cefeaa816f9b6d2f3b7776a62025d9c162a 7320 mercurial_6.3.2-1+deb12u1_armel-buildd.buildinfo 01481bb8c3026ed4f3943c9ec2463ab9f4203b9d 290692 mercurial_6.3.2-1+deb12u1_armel.deb Checksums-Sha256: fe4841ff0ea1ec4f768c1014b1420c43cd10412474a79bb30ad9cddf19591d46 1573820 mercurial-dbgsym_6.3.2-1+deb12u1_armel.deb 14267f4730617137bac073f2c046ece586e4799b89a155a9ce7e4116d5059575 7320 mercurial_6.3.2-1+deb12u1_armel-buildd.buildinfo fad61538bd4ff44cc8326616dd47f53a94acb40fcb4a0c8538f1de882edca2f4 290692 mercurial_6.3.2-1+deb12u1_armel.deb Files: 58c0b8e3d7c105de01f4de7b5e7e87d2 1573820 debug optional mercurial-dbgsym_6.3.2-1+deb12u1_armel.deb 593a6013b7595bcee2ef66d84a5b7200 7320 vcs optional mercurial_6.3.2-1+deb12u1_armel-buildd.buildinfo 67f64abb242f5f13369361b3ed4c0c19 290692 vcs optional mercurial_6.3.2-1+deb12u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKAzExpjGvTI78ZO8LARVyvnD3xkFAmfcSqYACgkQLARVyvnD 3xkwehAA5cIzADdt9hFcCJeFflV5Q2nKxTx5Zmsehj3QuQSVzvF1rp1/gqvW0xv5 86Gfz5aAQnoHQFy5cAVdqDLiEmjJJ5xcQ5Jg5n+XudA3sZdtWwrC5+hK1QWIvoJM PSZc0FhMLRYTCyU7TNY7NwDiGkUgs7ASfbSsNYNRGmT6zGHHMVEN+lfT5ZzTlZWi qy21AvTFR+xQj9w2TM8XC9w3JDydLZ3pZ19ligLrePiVuYn2a9tLqeWXV6cdkPQT 416QtbMwDayxSX2cU2Fpzlx6wC49D2gi0/qx8z14CMVVJVNX2etCpfY7AaNYu31D rxTJRLiOTHlFuiPWoeDsSE07J253Wy+OUDZYfTBmblBKU6R0Op87RSt2xgLLzG0f BBYog/qU553lGdZvgzYWeBSJUqu574VocxbDJK9Wwp1nOlpQnr8+60xRpotU5P7v /mpvgyUvyQ8mLqzERLh+3XbhDvryaDr1nmTu3/ASVWXfhVWw2S86W5AT9kdtR4yZ UYik7r9aD0ZK65OS8ppOI0Dw4g7WgrH5WAbFa0qXp74lVfAH4IJBtBGmsh7jAQX2 HIiWh8JBCu9r8Ou5SkT0/MXf4ezr50ipQbApXOM2vZdW23fMZNqkr+zQXUlalwZM yocZ/tXUd58vkKbKnYZdOC1Bn6SRWwJQ+IVmV+8aEjQuSfYF8QY= =oaGe -----END PGP SIGNATURE-----