-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 25 Jul 2020 11:03:10 +0200 Source: salt Binary: salt-common salt-master salt-minion salt-syndic salt-ssh salt-doc salt-cloud salt-api salt-proxy Architecture: source all Version: 2016.11.2+ds-1+deb9u5 Distribution: stretch-security Urgency: high Maintainer: Debian Salt Team <pkg-salt-team@lists.alioth.debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: salt-api - Generic, modular network access system salt-cloud - public cloud VM management system salt-common - shared libraries that salt requires for all packages salt-doc - additional documentation for salt, the distributed remote executi salt-master - remote manager to administer servers via salt salt-minion - client package for salt, the distributed remote execution system salt-proxy - Proxy client package for salt stack salt-ssh - remote manager to administer servers via Salt SSH salt-syndic - master-of-masters for salt, the distributed remote execution syst Changes: salt (2016.11.2+ds-1+deb9u5) stretch-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2018-15751 remote attackers are able to bypass authentication and execute arbitrary commands via salt-api(netapi) * CVE-2018-15750 remote attackers are able to determine which files exist on the server Checksums-Sha1: 978a31f9523d26f98f6ab580b19dbe01768ad16b 2911 salt_2016.11.2+ds-1+deb9u5.dsc 22ceeb790c472b20a520fc584f08b15431ffda8e 6096896 salt_2016.11.2+ds.orig.tar.xz fc9b0910c005107892b01c696278a37dfcba238f 38956 salt_2016.11.2+ds-1+deb9u5.debian.tar.xz 124de757133d9e187f2082bbe4b6d915b93f4909 24076 salt-api_2016.11.2+ds-1+deb9u5_all.deb 74029869cb1235af0fe018afdbc1fa3a05bfe96e 25588 salt-cloud_2016.11.2+ds-1+deb9u5_all.deb 518117ce9cda9584b48adfbb10efa18b38158e8e 4154308 salt-common_2016.11.2+ds-1+deb9u5_all.deb 164d3b85d29ceace2eb9ebbd53e955fd7711b9c2 4287580 salt-doc_2016.11.2+ds-1+deb9u5_all.deb 4a129e7f2e47791248636b51b81c9f8f5951d9f9 48258 salt-master_2016.11.2+ds-1+deb9u5_all.deb a83b77666faca5b67859af2186dd30d9cb7a3ab1 35576 salt-minion_2016.11.2+ds-1+deb9u5_all.deb 2b2b4d342920ffd7935f4ed710f91f4bfb87d10a 22888 salt-proxy_2016.11.2+ds-1+deb9u5_all.deb 16cf393f36982192d4611f5f9a2d58e23926902e 24126 salt-ssh_2016.11.2+ds-1+deb9u5_all.deb 8d1ab003371391ebed1f78377f40c86fbc6b3ae1 24402 salt-syndic_2016.11.2+ds-1+deb9u5_all.deb 27a33b021a12b72a16a43ede2c676df505ed7891 9943 salt_2016.11.2+ds-1+deb9u5_amd64.buildinfo Checksums-Sha256: b1f524f2f2aa37d9260d8b8a686bd4c8f3a6de318a8af7eb7006b307ee9b7c79 2911 salt_2016.11.2+ds-1+deb9u5.dsc d986b715e0bef20e797fe9fbe7b5d3d52e9528b941689a9c9487c6de0e7a0c28 6096896 salt_2016.11.2+ds.orig.tar.xz de4ba4b3fd6441018bbde9fa689ab57a52032f4aa5800fcccdd96daab2dbe5ef 38956 salt_2016.11.2+ds-1+deb9u5.debian.tar.xz caa00e1ba9382d86755858b1ff8ed567a0cac13b964e664db04d041f30f6793f 24076 salt-api_2016.11.2+ds-1+deb9u5_all.deb 1342bf66569edab06fa431c393db05f9866b3de133f79fa0b93a1665ba1063e5 25588 salt-cloud_2016.11.2+ds-1+deb9u5_all.deb 3720613717a4e50d58530f8c12fbd347c0ebb32675efa6e750a4c620ef9f0430 4154308 salt-common_2016.11.2+ds-1+deb9u5_all.deb bb1d7f7f7ce7c880bb3ab3c8081434cf6eda298aba00f8c6d66ef08c04b5d507 4287580 salt-doc_2016.11.2+ds-1+deb9u5_all.deb f73ccffb766a7d2a3a767fd4cc6ff98d78f1ce8761ffe42b37fec04eb7c9e2af 48258 salt-master_2016.11.2+ds-1+deb9u5_all.deb ef6d302041b83c4326eee5ad85a17e92b148aa2d50b2d31f2655f222e6a03798 35576 salt-minion_2016.11.2+ds-1+deb9u5_all.deb 55c71b76fe46ea6e19e501a6516cdfd891ffcc4ba3d5729bf544da70e0b46f50 22888 salt-proxy_2016.11.2+ds-1+deb9u5_all.deb 6155e2b24aaac26d4e36e0235a0294784d9d7ac279a4af836da6dd5ce720f8bc 24126 salt-ssh_2016.11.2+ds-1+deb9u5_all.deb 8fdc19fada3f8bd56eefa6739c9cc244bf288250c8073a3632a95b86942bf5b4 24402 salt-syndic_2016.11.2+ds-1+deb9u5_all.deb 96eb0ee8ed75915ffb10bcc1f03269fce335cc26943035057d679a126d4b0171 9943 salt_2016.11.2+ds-1+deb9u5_amd64.buildinfo Files: dbbf0392effee196490c3f481ae9cc6f 2911 admin extra salt_2016.11.2+ds-1+deb9u5.dsc ec60b35a21f25eed73e057b92cbef710 6096896 admin extra salt_2016.11.2+ds.orig.tar.xz c783440d8626d1da34046a963495fd21 38956 admin extra salt_2016.11.2+ds-1+deb9u5.debian.tar.xz 595fa45d9df34fd130dd5a7c24ae61ab 24076 admin extra salt-api_2016.11.2+ds-1+deb9u5_all.deb 2434167537edc49b7f9b16c88c1b4103 25588 admin extra salt-cloud_2016.11.2+ds-1+deb9u5_all.deb a487df008fee4ac77a087e8374d8d005 4154308 admin extra salt-common_2016.11.2+ds-1+deb9u5_all.deb e0bbe47fc6ea45cfabf895aae2dd4539 4287580 doc extra salt-doc_2016.11.2+ds-1+deb9u5_all.deb 589f151632082a8d9b56e1a9ec1d82bf 48258 admin extra salt-master_2016.11.2+ds-1+deb9u5_all.deb 6b6e5988aaaf87beb0d1c0f43ea7ec47 35576 admin extra salt-minion_2016.11.2+ds-1+deb9u5_all.deb 5faa8dd1b5606cdbd060e9cf49646ed4 22888 admin extra salt-proxy_2016.11.2+ds-1+deb9u5_all.deb 8d0779b397405c3f6c4844e53730ef26 24126 admin extra salt-ssh_2016.11.2+ds-1+deb9u5_all.deb 23716c2e920c560f6261857a197de43c 24402 admin extra salt-syndic_2016.11.2+ds-1+deb9u5_all.deb e4faa27401f21091e2c61c8c17c26074 9943 admin extra salt_2016.11.2+ds-1+deb9u5_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl8gMYRfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR7k6D/9Kw35216WGzh15alSR5OUataC6zyQP z84GAW6/2+l1bfoLzyn6WMtuy2XtpmrC5te8MuYcEMmzuyoFLuTAsJBud8qsK3NJ mZwNl5PtBNwJNNF1r97tXolvKnO5hanW1qXdhE35y0oK1SXpEH3nge+vrEugeLeU Zv1J2roXzuK0E+HFAnArdwv0W7FRgPHQs2acDkBGhITxNbCykaHjpO3WIfSMzfc3 BQ2pFu/sdsMB6ZciDQUvLBCUz5GUMZct6HAzwb7whzZ6HK8AZBxdao3iqZvnLC0r eCvEJKMqr0fHxRPNVNGm7lyx8iOi0SqT3xzNfLeKpEYvDj167wIHgRCgDFZo3Rnx 9OJ0trMXKRrx9NbmeE/VX2eicveybAmwuxGJCwP4Z7Q2UwmCG+wnSZbaGdUFSx1l qMSoYl+92L5U1TSjvoZoTf59C7QfreD2HlI3Q/TuKM1I9Ri8y7k4ikUTBHV4gLEc DMHF0fQo9LG0x2GpmKXj9znR1EkHNQZHKcOL1V6gAAuV51x6rJUtYO4sNoTrgkUh l0UcLgalCTqW/8DJenoexTICkbDNUM53CDVDr1QsX4mYDlZA3IYmgDmEPf14fi7V l1SRNLBeYVw1RFtqn5JiyltiE8KGCnpAVyj8nXnN3uRwDrT1TcL1U9VaTII09opH k4EK3ab9VBDDYA== =jxu3 -----END PGP SIGNATURE-----