-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 14 Apr 2020 22:52:16 -0400 Source: inetutils Binary: inetutils-ftp inetutils-ftpd inetutils-inetd inetutils-ping inetutils-traceroute inetutils-syslogd inetutils-talk inetutils-talkd inetutils-telnet inetutils-telnetd inetutils-tools Architecture: source amd64 Version: 2:1.9.2.39.3a460-3+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Guillem Jover <guillem@debian.org> Changed-By: Roberto C. Sanchez <roberto@debian.org> Description: inetutils-ftp - File Transfer Protocol client inetutils-ftpd - File Transfer Protocol server inetutils-inetd - internet super server inetutils-ping - ICMP echo tool inetutils-syslogd - system logging daemon inetutils-talk - talk to another user inetutils-talkd - remote user communication server inetutils-telnet - telnet client inetutils-telnetd - telnet server inetutils-tools - base networking utilities (experimental package) inetutils-traceroute - trace the IPv4 route to another host Closes: 956084 Changes: inetutils (2:1.9.2.39.3a460-3+deb8u1) jessie-security; urgency=high . * Non-maintainer upload by the LTS Team. * Add patch from Red Hat / Fedora: - Fix arbitrary remote code execution in telnetd via short writes or urgent data. Fixes CVE-2020-10188. Closes: #956084 Thanks to Michal Ruprich <michalruprich@gmail.com>. Note: While the PoC exploit does not work on inetutils due to the different codebases, the adapted patch was close enough to apply almost directly, even though the information leak might appear to still remain. Checksums-Sha1: 8dc613df95cea9d7092de1eaac2ea93548b53d9f 2742 inetutils_1.9.2.39.3a460-3+deb8u1.dsc 6de89cfd9070bf987ce0e22aca22d72151264b39 1337612 inetutils_1.9.2.39.3a460.orig.tar.xz 015a6394e603100d20ce33c76c9f83b4be9d518a 76720 inetutils_1.9.2.39.3a460-3+deb8u1.debian.tar.xz e85f2c8636a2e77941b4297e35cfd2538e932c35 215228 inetutils-syslogd_1.9.2.39.3a460-3+deb8u1_amd64.deb b16744456fb99efecbb4d82b9e0798f152f0a05b 237566 inetutils-ftp_1.9.2.39.3a460-3+deb8u1_amd64.deb afc8cafc2494e29a139c13993a6a90f13d85288c 236154 inetutils-ftpd_1.9.2.39.3a460-3+deb8u1_amd64.deb c3c453805b3bd2486629a1ce6ab9e3ba93295288 212696 inetutils-inetd_1.9.2.39.3a460-3+deb8u1_amd64.deb 5f1f6a73919bb67be6cb297a3ba13538f4cb52ec 215784 inetutils-ping_1.9.2.39.3a460-3+deb8u1_amd64.deb b83c79c9e8ba8262258cab694e0d8f83c7c937d0 198850 inetutils-traceroute_1.9.2.39.3a460-3+deb8u1_amd64.deb f97bc7e7f58664eaa208c29dda5b8cbb564eca21 201632 inetutils-talk_1.9.2.39.3a460-3+deb8u1_amd64.deb c6479108113ed6e5d5cd22dfbe1a0fd768b56a28 203632 inetutils-talkd_1.9.2.39.3a460-3+deb8u1_amd64.deb f64b5f3a17165ec1eeb4355f9a44805cd62e11d7 248886 inetutils-telnet_1.9.2.39.3a460-3+deb8u1_amd64.deb 777c099d91a91babb76a39bb8835549d9a967e71 232878 inetutils-telnetd_1.9.2.39.3a460-3+deb8u1_amd64.deb 7e7612b106f9cf4939a315efd3ba514e50ef268d 210194 inetutils-tools_1.9.2.39.3a460-3+deb8u1_amd64.deb Checksums-Sha256: 37796bb8a25d1ac49a3788c8c3f256224151aaea99de88eee6832515d7afcbfc 2742 inetutils_1.9.2.39.3a460-3+deb8u1.dsc b24c6ebe9c4a3ae10d421c4b59cc173fc72ea9cddf03386553c3740d247d0865 1337612 inetutils_1.9.2.39.3a460.orig.tar.xz af76b284f78fc035888d716155c3ff52bfa0e48e21e799f67a7c0f4ff886b0f8 76720 inetutils_1.9.2.39.3a460-3+deb8u1.debian.tar.xz 290a3abd8ab1e9065e618a288e434ea7dd92d3597c514ce13e5c9974359d7141 215228 inetutils-syslogd_1.9.2.39.3a460-3+deb8u1_amd64.deb fc6cffb90727b47fc1b9a754c75b5c758aa8f4201f8766e29bba9beb2042659c 237566 inetutils-ftp_1.9.2.39.3a460-3+deb8u1_amd64.deb 485dfd687098b10e72defea0d281c8ed463769d164db0a33dcc45952e95557e7 236154 inetutils-ftpd_1.9.2.39.3a460-3+deb8u1_amd64.deb 43417feeb0148d57bf901cb18cd9c71b33c2d66dc9b21f65b69eb6ef736d3b04 212696 inetutils-inetd_1.9.2.39.3a460-3+deb8u1_amd64.deb 9bd777b5f820de1f3a953c20938b72cc263b0b4a84c26fd1b89a5265390de27a 215784 inetutils-ping_1.9.2.39.3a460-3+deb8u1_amd64.deb f2f364ef08e4fd69da1294e69158636c28ac543150e6d1d4cd101d6e3fa98ee6 198850 inetutils-traceroute_1.9.2.39.3a460-3+deb8u1_amd64.deb 4989c155909a121608a3202491f2c6b94551984815a77bedd163d3d0dca96ba6 201632 inetutils-talk_1.9.2.39.3a460-3+deb8u1_amd64.deb 796196f1c8553fa5dfeb3a35fff1a3a75d8df453c6a0cde0a2631c16029082ef 203632 inetutils-talkd_1.9.2.39.3a460-3+deb8u1_amd64.deb f167e0e6687d0ef890556c961abdaf77d5896b0a0879b6cf83ec16531fabfd4b 248886 inetutils-telnet_1.9.2.39.3a460-3+deb8u1_amd64.deb e6aecbf65e8e3ba1d5d4437db8a3031ac7d38b732683a880949e689bff8d8210 232878 inetutils-telnetd_1.9.2.39.3a460-3+deb8u1_amd64.deb 5fb27b901abbe15a4126bed9030d1c0ef78168bb313e0ac49accdd81583e7c03 210194 inetutils-tools_1.9.2.39.3a460-3+deb8u1_amd64.deb Files: 0ca008f460907da1bffd4fb69dbe72aa 2742 net extra inetutils_1.9.2.39.3a460-3+deb8u1.dsc 6bed654771881213f6266c9ab08723b2 1337612 net extra inetutils_1.9.2.39.3a460.orig.tar.xz ca1a348fa31e1c7400903170d422769e 76720 net extra inetutils_1.9.2.39.3a460-3+deb8u1.debian.tar.xz c8c67e29e4c73ce4d32fd8f34dfe880f 215228 net extra inetutils-syslogd_1.9.2.39.3a460-3+deb8u1_amd64.deb 3c4c2db059a93dfb007d8234c9c1d0cc 237566 net extra inetutils-ftp_1.9.2.39.3a460-3+deb8u1_amd64.deb c27d276c8579a049d15703b7fb2ef95d 236154 net extra inetutils-ftpd_1.9.2.39.3a460-3+deb8u1_amd64.deb 7c0b0cf54b8c89bc2a6c9b7eb7e6020c 212696 net extra inetutils-inetd_1.9.2.39.3a460-3+deb8u1_amd64.deb 955b93f578959f8ea98f110eaf08dca8 215784 net extra inetutils-ping_1.9.2.39.3a460-3+deb8u1_amd64.deb 81a051fd15b9ccd711ccc14f9f2f53b6 198850 net extra inetutils-traceroute_1.9.2.39.3a460-3+deb8u1_amd64.deb 29eee1942dbc067369622767ade2d974 201632 net extra inetutils-talk_1.9.2.39.3a460-3+deb8u1_amd64.deb 761363698d3b7a470104af3464317f86 203632 net extra inetutils-talkd_1.9.2.39.3a460-3+deb8u1_amd64.deb 72bebba098ad8d7291cf96940bf5a490 248886 net extra inetutils-telnet_1.9.2.39.3a460-3+deb8u1_amd64.deb 2c74eaa50c60214de4d4d436654bd1fe 232878 net extra inetutils-telnetd_1.9.2.39.3a460-3+deb8u1_amd64.deb fe5016830565db8f00f16bf382054a0e 210194 net extra inetutils-tools_1.9.2.39.3a460-3+deb8u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEIYZ1DR4ae5UL01q7ldFmTdL1kUIFAl6We/0ACgkQldFmTdL1 kULYVxAAkQ/pMzF/Ut1fNduV8Amt1TLrlribw69rCVPwLPBszMgVmnwf4G+svRFi MmgWCrxQNRdcItUQgfn+qfyVEqUaygI6r2wYa4D4wn7dsWElhhqHyOXRM5XXZJcg kzQFbkDV6tfxqAdZnBALNhDMh+LR7OKs2XsngbtlGNn8tmyHuUgjRhYRg2kOOPuy aT53Xs8j7xTVZgUtomRQQjPQEykMiOs78SfYq19V/UPELnF28/6BhSsQo2WixGQ5 94YyyqJvBfozeAufzEEkBVH+Xa0x3u6SsAOduTUo563cKWYWMB74D+gJ2lIa+czt XvuE6foyv4/lil1DoIQ9+HskMBUfJNq+HIPCoqCtzGzgjtGcsHEddIuTXC+zYd1W Akn2Dfm44ZNreZu8pd7UCPHGcBAivmVhAitGLUeYGO+t84GTvNLVPMT2SR6lDff9 jxEAV76AChj2UTDjNEMQsbYs66qTLawCMTodABBMmgnznImPLybuhY7se9qRlLZU s20DXMautprGRwsVqtBgdy/35n+n3frT1BD+oOwl1zGgABG6TL6RuC7LEuZTK2dB +X2oIdlvdaq5o7khiB5R7VHI9JBZOgZlyfMhgSStjgKFLVQgFMc/xJ1HoLhyupCZ y/q0RJfoZ1pZrUaxcYL8xKVYFfOsVkQDnnK328XwNvVYKJuTS1g= =Uvpi -----END PGP SIGNATURE-----