[Pkg-matrix-maintainers] matrix-synapse_1.33.2-1_source.changes ACCEPTED into unstable
Debian FTP Masters
ftpmaster at ftp-master.debian.org
Tue May 11 16:03:40 BST 2021
Accepted:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Tue, 11 May 2021 16:47:19 +0200
Source: matrix-synapse
Architecture: source
Version: 1.33.2-1
Distribution: unstable
Urgency: high
Maintainer: Matrix Packaging Team <pkg-matrix-maintainers at lists.alioth.debian.org>
Changed-By: Andrej Shadura <andrewsh at debian.org>
Changes:
matrix-synapse (1.33.2-1) unstable; urgency=high
.
* New upstream release.
* Explicitly depend on python3-cryptography.
* Refresh patch.
* SECURITY UPDATE (CVE-2021-29471, GHSA-x345-32rc-8h85):
- Denial of service attack via push rule patterns:
"Push rules" can specify conditions under which they will match,
including event_match, which matches event content against a
pattern including wildcards. Certain patterns can cause very poor
performance in the matching engine, leading to a denial-of-service
when processing moderate-length events.
Checksums-Sha1:
16b63f3640af44217188c43fd679b924fdd32b1b 2414 matrix-synapse_1.33.2-1.dsc
465c51999a5633f5c0cd49e7fbc87e4c75ac77ab 7275914 matrix-synapse_1.33.2.orig.tar.gz
57e6f9db157425b78cf10cdcf916b5bb9774440c 108116 matrix-synapse_1.33.2-1.debian.tar.xz
Checksums-Sha256:
128519146dc00c9009cf4a6001b47c5ec578bda82d8703f7f94d7dcb08d0e505 2414 matrix-synapse_1.33.2-1.dsc
5e0a934dba5994ec102e94ba323e88746b9aec6ccaae03ba2c94780a6dbfeb97 7275914 matrix-synapse_1.33.2.orig.tar.gz
158cad759d75016f7b7014021dfdbc21d2c04554227668045a8ecd5387de1bb3 108116 matrix-synapse_1.33.2-1.debian.tar.xz
Files:
e2165fc7d64e0e40b039b989f2dcdd58 2414 net optional matrix-synapse_1.33.2-1.dsc
363595af742130c96209712b20125574 7275914 net optional matrix-synapse_1.33.2.orig.tar.gz
7411372ce4d8619a8ff5b02364c885fb 108116 net optional matrix-synapse_1.33.2-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iHUEARYIAB0WIQSD3NF/RLIsyDZW7aHoRGtKyMdyYQUCYJqZ5gAKCRDoRGtKyMdy
YRAqAP9a45cqeXtunVKOXISDW/yI4SiNUFAGGdG2BeFbZccjqwEAttj5nKEOAzfI
kNNm/s91tgMeY4paUMBmsnksgai43A8=
=2GSr
-----END PGP SIGNATURE-----
Thank you for your contribution to Debian.
More information about the Pkg-matrix-maintainers
mailing list