-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 14 Jun 2023 15:06:21 +0200 Source: python-werkzeug Architecture: source Version: 1.0.1+dfsg1-2+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: Python Modules Packaging Team Changed-By: Salvatore Bonaccorso Closes: 1031370 Changes: python-werkzeug (1.0.1+dfsg1-2+deb11u1) bullseye-security; urgency=high . * Non-maintainer upload by the Security Team. * don't strip leading = when parsing cookie (CVE-2023-23934) (Closes: #1031370) * limit the maximum number of multipart form parts (CVE-2023-25577) (Closes: #1031370) Checksums-Sha1: fc90d53f87e4e19112ad3f0c9500f75ce12e13a6 2632 python-werkzeug_1.0.1+dfsg1-2+deb11u1.dsc 4b5aa9ff48e780268966cbfca8cafd82586ba8a9 730032 python-werkzeug_1.0.1+dfsg1.orig.tar.xz 62bd35696886de9ea2d0d9b001f31b1dc037be66 10296 python-werkzeug_1.0.1+dfsg1-2+deb11u1.debian.tar.xz 7a4867dee3964998b87e488b994555034e409a62 8047 python-werkzeug_1.0.1+dfsg1-2+deb11u1_source.buildinfo Checksums-Sha256: f37c7dceab0b6505e103cf57ce1b04539db4ede1f35484e0ad5d5bff7a699d09 2632 python-werkzeug_1.0.1+dfsg1-2+deb11u1.dsc 12432f3bd8abf78aa8d8f144d3088acdf6612c6984ad8ae812b34c2391f9bffa 730032 python-werkzeug_1.0.1+dfsg1.orig.tar.xz e3e7e4c1b8eccc1c0da5381f2f9eeb5d978478220ae68a640b99d39c11b5c4c9 10296 python-werkzeug_1.0.1+dfsg1-2+deb11u1.debian.tar.xz 849fd2104872dbe56ff5c1bfe4437e17afaa9fd3f46c213f29078a1eccfac5ca 8047 python-werkzeug_1.0.1+dfsg1-2+deb11u1_source.buildinfo Files: a9ba9bd763ad45be3331e131219d40d4 2632 python optional python-werkzeug_1.0.1+dfsg1-2+deb11u1.dsc e8c571418ddb9a5dddf85e74a7098121 730032 python optional python-werkzeug_1.0.1+dfsg1.orig.tar.xz f6c85804f50981e8348d5b19e6fcea48 10296 python optional python-werkzeug_1.0.1+dfsg1-2+deb11u1.debian.tar.xz b3cb64cee6dfddaa7c294f3424558a00 8047 python optional python-werkzeug_1.0.1+dfsg1-2+deb11u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmSJvpZfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89Ek84QAInOwS2DkY3CAlMafA/bEcERdwbM26p5 TAApxtFm2jQ9fKR3nKUilD8ZLZBGm3MQQMW5jvgn4hp26CEpWdCEiwFUV5sX5pmR UveCgpiEsj+SkStrkw+K4t/mllfPiEFecBgdFUAu05DsCIZATqjKY2vn6GWh8Efc hNI5yYOZFj8KFvhzDdYhE06YAHF+uCbUmkeCPxgT2orQhSS/g5gDbCPgI4s5bubo N9b/Ye8+vYPtZKgq/SiRb9cILS47rxmka84GLCnZLtg50fGGAYjgGPw7riUb+R2I utjjVDt5jwtxY4KyUQHnUVoqbQG+QmnpDIoYORo1SIs7ltTOYJr4WRrw9bUsf/Xl 0OitiahlycKlHdU+zsUZLC9PE/29jn22VC2/0tlCrflncKc9UAUgwm39fZid6rTi 8r6NR9x7IFTGYRIwVC/mxjcQg8G63rQB+AVSV0dKa9mLrqFR3DA9E5G5/YmkmnY5 9xiuxQ+cgMvi2cYFkJeAQtMk1i4p1uLDaSmWfDzlt6BuNYqku6UVj+/prxxvqMx6 snI9jSyHzBMw0S3+mOrOmeSwqJ/nUHpbYylEHB+IoLiPci1lXc1k7+gR1L/K50sY 4NHpDIolFY3ltm2yqn54vYzmdkV6Gp9+tigyQF5r+hb9VcxTw82vu+ApKwLTK+iM W5Cw5VSA2z06 =6+2O -----END PGP SIGNATURE-----