libzstd (1.4.8+dfsg-2) unstable; urgency=high
authorÉtienne Mollier <etienne.mollier@mailoo.org>
Thu, 18 Feb 2021 08:52:53 +0000 (08:52 +0000)
committerÉtienne Mollier <etienne.mollier@mailoo.org>
Thu, 18 Feb 2021 08:52:53 +0000 (08:52 +0000)
commit9a6cec64d45b19b552aaf7e56a6484ca156b2230
tree5033bbcc6d8644652b4e62fb4a51a5d6487c279e
parent06f0e0cad3b26ee3e23fe52db62ede0b055b934b
parent395339dc85b30fa777d0ef3afb9e62f416cb1937
libzstd (1.4.8+dfsg-2) unstable; urgency=high

  * Team upload.
  * When a file with restricted permissions is compressed, the resulting file
    inherits the umask of the user for the time of the compression.  This was
    partially mitigated previously by running a change of permissions after a
    `chmod`, but left a small but exploitable window just after the `fopen`.
    This update adds 0018-fix-file-permissions-on-compression.patch to make
    sure the compressed file is not group nor world readable for the _entire_
    duration of the compression.
Closes: #982519
[dgit import unpatched libzstd 1.4.8+dfsg-2]
24 files changed:
debian/README.Debian
debian/README.source
debian/changelog
debian/control
debian/copyright
debian/libzstd-dev.examples
debian/libzstd1.symbols
debian/patches/0006-Use-bash-for-test-script-portablitity.patch
debian/patches/0008-Address-embedded-zlib.patch
debian/patches/0013-skip-memory-greedy-tests.patch
debian/patches/0014-Reproducible-build.patch
debian/patches/0015-Skip-dev-random-tests-on-hurd.patch
debian/patches/0017-alpha-fbfs-st_mtime.patch
debian/patches/0018-fix-file-permissions-on-compression.patch
debian/patches/series
debian/rules
debian/salsa-ci.yml
debian/source/format
debian/source/lintian-overrides
debian/tests/control
debian/watch
debian/zstd.docs
debian/zstd.install
debian/zstd.manpages