-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 09 Oct 2024 12:49:43 +0200 Source: python-sql Architecture: source Version: 1.4.0-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: Debian Tryton Maintainers Changed-By: Mathias Behrle Changes: python-sql (1.4.0-1+deb12u1) bookworm-security; urgency=high . * Add 01-escape_non_expressions.patch. Description: Escape non expressions for unary operators This patch fixes CVE-2024-9774 vulnerability for SQL injection attacks from https://discuss.tryton.org/t/security-release-for-issue-93 Checksums-Sha1: 6af308aa797880311f78924700ee544c28139dc8 2391 python-sql_1.4.0-1+deb12u1.dsc fa088ac08abded4e881eed038098840753f362a0 32599 python-sql_1.4.0.orig.tar.gz 945e16a20050fd8b0b07cbc9f9ca0227237b74c9 506 python-sql_1.4.0.orig.tar.gz.asc fc0e149c0cd5df39434a3e4806345e4ab0ad4fcc 25884 python-sql_1.4.0-1+deb12u1.debian.tar.xz e592171ee78aec03735c6e5f2204b8686f14a04b 7129 python-sql_1.4.0-1+deb12u1_amd64.buildinfo Checksums-Sha256: f7bd0e4932a8c8e7ac7d2aba533646152b0a4d88cbfa7f6a842158208a254890 2391 python-sql_1.4.0-1+deb12u1.dsc 6fe764082f48891d857ea7e6fa425fa54f13531ddf6b89f24c098e646ad1b4b6 32599 python-sql_1.4.0.orig.tar.gz 6403494824ea3925b1ccd50708780f16f8842187cdb6d54c77fb8b2564618331 506 python-sql_1.4.0.orig.tar.gz.asc ceb7d393bf263b54070356602bf776a2a5b6c4b0ba15ac3e673dc1cb4e28fb5e 25884 python-sql_1.4.0-1+deb12u1.debian.tar.xz b1d8788aacb69cc3837e8df48df6b083099dddffa148381f2d1b734675512af6 7129 python-sql_1.4.0-1+deb12u1_amd64.buildinfo Files: 5049404adb54373e7f07a526594af791 2391 python optional python-sql_1.4.0-1+deb12u1.dsc 2df8cfc796811700a7eb67d2207ca194 32599 python optional python-sql_1.4.0.orig.tar.gz 41c46b0e7ef62fe540b7fd8e012f1e20 506 python optional python-sql_1.4.0.orig.tar.gz.asc bb9b5f5a09d715a1ce7360978202454f 25884 python optional python-sql_1.4.0-1+deb12u1.debian.tar.xz 4164319914b2a5f4414c44c00951e46f 7129 python optional python-sql_1.4.0-1+deb12u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- Comment: Signed by Mathias Behrle iQJFBAEBCgAvFiEErCl+XEa50LYccXaB1tCb5IQFu/YFAmcSFUQRHG1hdGhpYXNi QG05cy5iaXoACgkQ1tCb5IQFu/aOTw//T8Ub79fBuo1G0p+NhFWFwCZ0FSAcvx1u /dAmyKjN0mXoopxgwqGbBM25uDnNHvUZ62T//3fbBqpHn4NqkrQ0Wbq2JsRskr/+ gidSnxd/KckZYqVfORA7zmsbNLdkmF3vhh1m/wJXhqdBhioW20fyk326vlUKslmv kiDmUQa5MZX4Yop1YOBECS4F+MLGXuNC8rOLb8bfPWE6WxcJU98uQwWQpXOEgG9b nY8+xOzTcb8QUC4Ozstap+RtP2PJgOZkIfmHLPQxq67WGQYRAPIv5gDLxHqCgyHo Yjo/EQ8ux2oA2C1CtxQav3hQ370f4YYe7xaWbOfmcO+hciNY+n0HxGO9+AuMSrOM TOuub0w9Jttoo1RyFDt1QbsiL1Yxs4npreaM74YI5pmD501gMe6Uo8VIMkji0tNl 6Kj5mLnI1rAh/jD56AnqC6f+nQWcDsRbvimgg9BHvY0RhWyDyMNg9tMU2WhLwktf fTd+CpLwXH+8keBRnBilW1sOvZNIbl5uUIIfOiQSx3FKgyMrlAf2dvdzTJiKJzAe 8HD61Q/espuYNVJO2aMR7tihbQpVeB97F6X6E3YQ4WSvhHlzXNnwCica2Py+ZUyS LdbvMfeys/vbQbVSmmFm2MTNhQstW2kKo6uH6TnHpE9jKXlhOROKypszp3wB5Ci2 /tTZg9a5M9s= =5FCg -----END PGP SIGNATURE-----