-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 22 Mar 2020 21:17:19 -0700 Source: libpam-krb5 Binary: libpam-heimdal libpam-heimdal-dbgsym libpam-krb5 libpam-krb5-dbgsym Architecture: source amd64 Version: 4.8-2+deb10u1 Distribution: buster-security Urgency: high Maintainer: Russ Allbery <rra@debian.org> Changed-By: Russ Allbery <rra@debian.org> Description: libpam-heimdal - PAM module for Heimdal Kerberos libpam-krb5 - PAM module for MIT Kerberos Changes: libpam-krb5 (4.8-2+deb10u1) buster-security; urgency=high . * SECURITY: Fix potential one-byte buffer overflow when the underlying Kerberos library initiates prompting (such as for PKINIT or when the no_prompt PAM option is set). (CVE-2020-10595) Checksums-Sha1: 886f3b6e9331c2bd112d02037d6e24a1a7745a4d 1968 libpam-krb5_4.8-2+deb10u1.dsc 9462ed82c3e98f7aa6f275639636b1e20e3cf52a 411860 libpam-krb5_4.8.orig.tar.xz bca623889431d41e38185de633d67c5463cffbd3 488 libpam-krb5_4.8.orig.tar.xz.asc 30773d362563d6697b6dbd26b385a352636f0d13 26012 libpam-krb5_4.8-2+deb10u1.debian.tar.xz fcce01cb35482eb64d343fb57b6b58d0ad5711e6 101928 libpam-heimdal-dbgsym_4.8-2+deb10u1_amd64.deb f1874cee399190e74e9d6ee973f2a07556db6991 87604 libpam-heimdal_4.8-2+deb10u1_amd64.deb 9211bfcc1daa09d3d2fdaa8d47302f35b0ae38dd 77524 libpam-krb5-dbgsym_4.8-2+deb10u1_amd64.deb 6e8cdbf96aed58f2e8c4439a1519de7a7e3b1658 7902 libpam-krb5_4.8-2+deb10u1_amd64.buildinfo 571bd20edc78b3016ba517251f95eabad501fbb0 90472 libpam-krb5_4.8-2+deb10u1_amd64.deb Checksums-Sha256: e67c1c10f02587f441bb326c750fe586350e818c3212715a634456c4a0478265 1968 libpam-krb5_4.8-2+deb10u1.dsc cbb59f6f72ad6207c8376b14af89badadd62fbfc7f661ca779e7afa4434457e2 411860 libpam-krb5_4.8.orig.tar.xz 24c528863dd7d2b40a43e72529dc8fe5d9bb534c6c2a33c5f8a4a5cf0acffec3 488 libpam-krb5_4.8.orig.tar.xz.asc 5307cd888d7789ab528b8fbb9850f284d54d470a605bdc68625e0f37fd23d177 26012 libpam-krb5_4.8-2+deb10u1.debian.tar.xz f5f5eaecd7d22a9ac5ae5911755b96c91452acd2b8ae535a7c53c283a3c83d16 101928 libpam-heimdal-dbgsym_4.8-2+deb10u1_amd64.deb e7a55f706b93663db14a1ce010d5f926f81a8ca7ec4667fba90d1de2cae8059c 87604 libpam-heimdal_4.8-2+deb10u1_amd64.deb 9669dd87deb710226aa538753312d3411a196aff896ecd7bcd12bd00fe235169 77524 libpam-krb5-dbgsym_4.8-2+deb10u1_amd64.deb 636f26c61e3eccfd667f47121f9f2e12a6b63fc9ece99e585f6d1238d40e0790 7902 libpam-krb5_4.8-2+deb10u1_amd64.buildinfo ba6b0c774a0fa9111b05bf3907391b0fdf869b76cfe605b76ce59c9886dd6b5a 90472 libpam-krb5_4.8-2+deb10u1_amd64.deb Files: 2828f089eeec62182d863c28250524ed 1968 admin optional libpam-krb5_4.8-2+deb10u1.dsc a9d8d5a6ce3932701fed2aa446a49d34 411860 admin optional libpam-krb5_4.8.orig.tar.xz 472fc14d852bdcc999f8f5f2e25aba4a 488 admin optional libpam-krb5_4.8.orig.tar.xz.asc 851a85a5ccb5e41382357e43154661a3 26012 admin optional libpam-krb5_4.8-2+deb10u1.debian.tar.xz c796421c85eed15f768ce28fdb134925 101928 debug optional libpam-heimdal-dbgsym_4.8-2+deb10u1_amd64.deb 385866d1bfa9a52ba0def0dbd9ec128f 87604 admin optional libpam-heimdal_4.8-2+deb10u1_amd64.deb 8bb506fac994527afcc050617efb12ad 77524 debug optional libpam-krb5-dbgsym_4.8-2+deb10u1_amd64.deb 5ffa06af8097628b8d1e19f940931f86 7902 admin optional libpam-krb5_4.8-2+deb10u1_amd64.buildinfo 11b36d1814ff0ca40c4aff324439fe04 90472 admin optional libpam-krb5_4.8-2+deb10u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEE1zk0tJZ0z1zNmsJ4fYAxXFc23nUFAl6A83sACgkQfYAxXFc2 3nV2rQf8DjeBpZ/ajhyQJ22+NW4o8HLegO0OPf6/yke17cEduxGpga6GWK5aCejM 3VE2sXVThnK1RWDK4aLg6a+G4tmYTdWSn8jkJx+DI9uEbJXWAZsUJFWl8bMMbm2O Ios2VVzcKzaJZ3ZAQ4nkGR08fVe9dxjPYeHsq1TQlLL/x1CJgGfSarI8js85wdb7 EGVmP9H+p0Er/y1HWXNsSM3GuaD8OQFdDrlieilVuqiog3kl6k4uVz2Ycoj4Aj/n 3ksV6I7FF6ASf0nyRnh2Rx8VsVR7Ay+KoPuB1fdcQVG1p5fDXnbVkpd/HAniNoSP QQSVEj13Y1KzT02jTmYpyCXOVDko4Q== =8y7J -----END PGP SIGNATURE-----