-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 05 Nov 2019 17:11:32 +0100 Source: openafs Binary: openafs-client openafs-fuse openafs-kpasswd openafs-fileserver openafs-dbserver openafs-doc openafs-krb5 libkopenafs1 libafsauthent1 libafsrpc1 libopenafs-dev openafs-modules-source openafs-modules-dkms libpam-openafs-kaserver openafs-dbg Architecture: source amd64 all Version: 1.6.9-2+deb8u9 Distribution: jessie-security Urgency: high Maintainer: Benjamin Kaduk <kaduk@mit.edu> Changed-By: Markus Koschany <apo@debian.org> Description: libafsauthent1 - AFS distributed file system runtime library (authentication) libafsrpc1 - AFS distributed file system runtime library (RPC layer) libkopenafs1 - AFS distributed file system runtime library (PAGs) libopenafs-dev - AFS distributed filesystem development libraries libpam-openafs-kaserver - AFS distributed filesystem kaserver PAM module openafs-client - AFS distributed filesystem client support openafs-dbg - AFS distributed filesystem debugging information openafs-dbserver - AFS distributed filesystem database server openafs-doc - AFS distributed filesystem documentation openafs-fileserver - AFS distributed filesystem file server openafs-fuse - AFS distributed file system experimental FUSE client openafs-kpasswd - AFS distributed filesystem old password changing openafs-krb5 - AFS distributed filesystem Kerberos 5 integration openafs-modules-dkms - AFS distributed filesystem kernel module DKMS source openafs-modules-source - AFS distributed filesystem kernel module source Changes: openafs (1.6.9-2+deb8u9) jessie-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2019-18601: OpenAFS is prone to denial of service from unserialized data access because remote attackers can make a series of VOTE_Debug RPC calls to crash a database server within the SVOTE_Debug RPC handler. * Fix CVE-2019-18602: OpenAFS is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer. * Fix CVE-2019-18603: OpenAFS is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer. Checksums-Sha1: 98d7800b6252422a89cfb36354fc4c836f77c54c 4139 openafs_1.6.9-2+deb8u9.dsc ecff87c05d695ed27766b5e3df8b7b5c266f4af9 163708 openafs_1.6.9-2+deb8u9.debian.tar.xz 245798f2bf32e08c03d9afe48c656279fc40f6cf 1974614 openafs-client_1.6.9-2+deb8u9_amd64.deb d605f42061618928e6fc1090049548b6e6b4bca2 286130 openafs-fuse_1.6.9-2+deb8u9_amd64.deb ba5e20e39bf9a056bce7f43eab03f3369fb8cee6 200260 openafs-kpasswd_1.6.9-2+deb8u9_amd64.deb 0b9edc118155f5a9e7c82913e43d63480eabffc6 1310510 openafs-fileserver_1.6.9-2+deb8u9_amd64.deb 74462b97965e606bdd751b1782b75faac62d7bca 454012 openafs-dbserver_1.6.9-2+deb8u9_amd64.deb 98609b5c02e5dffbf6e381d9794ca4e6dfb1fad7 4001394 openafs-doc_1.6.9-2+deb8u9_all.deb f155102b926042bddd7ce3fe6ee8d5bae84c5113 259080 openafs-krb5_1.6.9-2+deb8u9_amd64.deb 3ae9b6a9de0cbc67a82403df650787ca6d0c66b1 91490 libkopenafs1_1.6.9-2+deb8u9_amd64.deb 8a5a8f86debf57517409b97ae44ef2317de6a4d8 214738 libafsauthent1_1.6.9-2+deb8u9_amd64.deb 738077472d2ffa9f5da8d44fbf6e5a0f473d24d9 199824 libafsrpc1_1.6.9-2+deb8u9_amd64.deb 9b7c34b03fe07b89bcc9062f9b840cd96e1bb667 1289796 libopenafs-dev_1.6.9-2+deb8u9_amd64.deb 46d7c350baf0ec4ea3e1c6be4c269246393643da 1159602 openafs-modules-source_1.6.9-2+deb8u9_all.deb aadcf39f2fcb3a64902bac5fe7dfbb3503cf8311 940888 openafs-modules-dkms_1.6.9-2+deb8u9_all.deb d260a52df95aea5b8a4fc22b6bb7b609ee69efdf 188110 libpam-openafs-kaserver_1.6.9-2+deb8u9_amd64.deb 353680d5378004a119b68f73783b3f90d2c2c177 21964230 openafs-dbg_1.6.9-2+deb8u9_amd64.deb Checksums-Sha256: 200158c9496b24ba56076371b28d29c3a3b17d5330517c25c6039963a956afaa 4139 openafs_1.6.9-2+deb8u9.dsc 5e1921526d7087304f5b252600fea522b3e8733c1028d8fa3cc1c29230fc770b 163708 openafs_1.6.9-2+deb8u9.debian.tar.xz 1521131efceb8c4082389023fa4e47b669b75319a968996d30814d7b24c368e4 1974614 openafs-client_1.6.9-2+deb8u9_amd64.deb 72f884f8878e845a8e735cf3291842df67008ab29237cec8ea9ed330ee319330 286130 openafs-fuse_1.6.9-2+deb8u9_amd64.deb 8ef47c259db0a331c7bc295cfc05ca23945e974f7483a4c79b91e18e5b2e9b22 200260 openafs-kpasswd_1.6.9-2+deb8u9_amd64.deb 6d33f17481a395ae76d9a599136902faecc9aa89e78889c9bde223fc51c60b10 1310510 openafs-fileserver_1.6.9-2+deb8u9_amd64.deb 72e57379de2c5b27a42111585fbd5b3a5dfb9bea4362d4ade548799687c6c0cb 454012 openafs-dbserver_1.6.9-2+deb8u9_amd64.deb 04d6437844fe370b4b7b9d340f357f3465ecb85bfda58dae10502c2f1ff3b447 4001394 openafs-doc_1.6.9-2+deb8u9_all.deb c06df4e719b3c41e2c6240ba582cd9b382febc490c2fde2ea15cf356fe63f286 259080 openafs-krb5_1.6.9-2+deb8u9_amd64.deb d7789cd56a5e96a0917b6fb2cdeb62f4748ca9ffaeb2d3213a7616fff76217f6 91490 libkopenafs1_1.6.9-2+deb8u9_amd64.deb b6515d657a50f6d92a16fce92b9aed57694f611856a514fdeae1d5ed22337c54 214738 libafsauthent1_1.6.9-2+deb8u9_amd64.deb 6aab6ce6362e3e047decd54d3c6cdf1af07531e5c91fcbe74bbe44ae3924d2d0 199824 libafsrpc1_1.6.9-2+deb8u9_amd64.deb d429cb7074ae0133b712e056a90179629c1042363f34e5111118f6e471c7f5e9 1289796 libopenafs-dev_1.6.9-2+deb8u9_amd64.deb 39a871cfee2997cfd9d51af38c8634382b7d1c26eaa03c8e08ea15a52c4a71f6 1159602 openafs-modules-source_1.6.9-2+deb8u9_all.deb 56f8b4ffa4239341728c4060667c8e52c2235daf22e712e1d40ccaa7816fa1a9 940888 openafs-modules-dkms_1.6.9-2+deb8u9_all.deb d6d61d3d9585312dd0b23cba139934e3c8d1ff58bbecadb133cdfda1c90f30fc 188110 libpam-openafs-kaserver_1.6.9-2+deb8u9_amd64.deb cbd86cf6640c57e4a98ca5ffb7ccb396132872700e913fd38e6839270f5fa2f6 21964230 openafs-dbg_1.6.9-2+deb8u9_amd64.deb Files: d3335e8d2c97c34c624913f9cc79f842 4139 net optional openafs_1.6.9-2+deb8u9.dsc bdeface352c18d27442fa8bf92018a65 163708 net optional openafs_1.6.9-2+deb8u9.debian.tar.xz 2c8a4265c9592325ef9c5b4892a7c6b1 1974614 net optional openafs-client_1.6.9-2+deb8u9_amd64.deb 313b7f4039ac7c6e7169cd5d04343285 286130 net extra openafs-fuse_1.6.9-2+deb8u9_amd64.deb e819f3f336b4b65720f941db27a1d209 200260 net extra openafs-kpasswd_1.6.9-2+deb8u9_amd64.deb 2ce52d5612d1c341c59be7cfcb6ce98a 1310510 net optional openafs-fileserver_1.6.9-2+deb8u9_amd64.deb 0b9f8a1a31a411cff33870b91efba27b 454012 net optional openafs-dbserver_1.6.9-2+deb8u9_amd64.deb 1427676d1663326ae515930e1ba64660 4001394 doc optional openafs-doc_1.6.9-2+deb8u9_all.deb a93a609f798b55de664c5b4f9cb9acd9 259080 net optional openafs-krb5_1.6.9-2+deb8u9_amd64.deb 1d0820ab5bc1994f0d726e3e067b9759 91490 libs optional libkopenafs1_1.6.9-2+deb8u9_amd64.deb 4eaf4326367aa1116462746c3f080dd0 214738 libs optional libafsauthent1_1.6.9-2+deb8u9_amd64.deb 113c0f04f403e3154ecd03b11861d1d6 199824 libs optional libafsrpc1_1.6.9-2+deb8u9_amd64.deb d63c9a68d5d9e3be02c33d321691da5e 1289796 libdevel extra libopenafs-dev_1.6.9-2+deb8u9_amd64.deb ee16f50df89b2d7b43166808b3e3de28 1159602 kernel extra openafs-modules-source_1.6.9-2+deb8u9_all.deb 613b0b12300554f55e4185e37390c50f 940888 kernel extra openafs-modules-dkms_1.6.9-2+deb8u9_all.deb fda5cee5f34e5ec17b50b9c9f8330fc4 188110 admin extra libpam-openafs-kaserver_1.6.9-2+deb8u9_amd64.deb 3c378d27ce7714be0bfcb555b38612a8 21964230 debug extra openafs-dbg_1.6.9-2+deb8u9_amd64.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl3B/cJfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkVz8P/1zs1qDdom+Q4WtsWEcOUg+eHgu/BuyOTNt2 srpytFTxNPMdZn4xDPNb9iKpQIxZBIz/Ks5/GCNWw1pFa3FEUhu7j0tZIwNl7LiV ZIHEQALWu/GT4zPCiYIegYrcsjG7/zLbjGFjNkThi5AuJvQpMf4gwGbWvNpUxLjA NEFSPzbOgJyqnA39mcTAwbiRfwHu4oKFQgl5Lwdqbopxut8TRoLeA6DAbgSUU+GB IH3JZfjIlv5l9Dws5N1Ei73lph4gkdH5dKjqoB9dSNM4sh+Fs84I70JkQT5pS7vJ l359PlZQFC3r4q9b9EtqZC2XiQ3GHXkvGirUpEl3ssdDmNV6b4ddG3DrckMyZxwA t8Be+WjnmDEzbZAGvG1oulQmSMdUVFKezx9W3TA7i4YCLfnWi4U0D+WQordq44Sv xnAjvzYgyFDqjYcAVjWVJXIbYsYxvJOLykUg75CKCsUlrOoepWsnslCAy/HUmBRa wIRAJDLH+sUZGtoTwjn0u9sDOz3ZqzOOBG3SfKLlpiTf+nNzmWfZ4kvKpZWghwcx qL1u/XvWVvSRWL0WjwAJfEx5mQI6R9ojsxy1NPsw67bk4YGyippoTPQJ7IvKmKGY lthzOnTwtri78UlFK9sYXMu8GOS634bCB/tMXTXWQghdD6+//j8w7ebrRXPETU8m dzuN64D0 =stgC -----END PGP SIGNATURE-----