Version in base suite: 1.0.8+2sarge1 Version in overlay suite: 1.0.8+2sarge1.1 Base version: alsa-modules-i386_1.0.8+2sarge1 Target version: alsa-modules-i386_1.0.8+2sarge1.1 Base file: /org/ftp.debian.org/ftp/pool/main/a/alsa-modules-i386/alsa-modules-i386_1.0.8+2sarge1.dsc Target file: /org/ftp.debian.org/ftp/pool/main/a/alsa-modules-i386/alsa-modules-i386_1.0.8+2sarge1.1.dsc diff -Nru /tmp/y4x19xnFjL/alsa-modules-i386-1.0.8+2sarge1/debian/changelog /tmp/H7vObpHyWs/alsa-modules-i386-1.0.8+2sarge1.1/debian/changelog --- /tmp/y4x19xnFjL/alsa-modules-i386-1.0.8+2sarge1/debian/changelog 2006-03-27 02:26:26.000000000 +0000 +++ /tmp/H7vObpHyWs/alsa-modules-i386-1.0.8+2sarge1.1/debian/changelog 2008-03-22 01:01:56.000000000 +0000 @@ -1,3 +1,14 @@ +alsa-modules-i386 (1.0.8+2sarge1.1) oldstable; urgency=high + + * Rebuild against alsa-driver_1.0.8-7sarge1: + * NMU by the Security Team + * 20_snd-page-alloc-leak.dpatch: + Fix an issue in the alsa subsystem that allows a local user to read + potentially sensitive kernel memory from the proc filesystem. + See CVE-2007-4571 + + -- dann frazier Fri, 21 Mar 2008 19:00:23 -0600 + alsa-modules-i386 (1.0.8+2sarge1) stable-security; urgency=high * Rebuild against kernel-build-2.4.27-3