-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 09 Nov 2020 14:59:51 +0100 Source: salt Architecture: source Version: 3002.1+dfsg1-1 Distribution: unstable Urgency: medium Maintainer: Debian Salt Team <pkg-salt-team@alioth-lists.debian.net> Changed-By: Benjamin Drung <benjamin.drung@cloud.ionos.com> Changes: salt (3002.1+dfsg1-1) unstable; urgency=medium . * New upstream release: - Prevent shell injections in netapi SSH client (CVE-2020-16846) - Prevent creating world readable private keys with the TLS execution module. (CVE-2020-17490) - Properly validate eauth credentials and tokens along with their ACLs (CVE-2020-25592) Checksums-Sha1: e3846ef6d317443d3e2d8edc6a1cee4c391e44d4 4192 salt_3002.1+dfsg1-1.dsc 6a3076b88d3f2ed28dc95dad81c5cb7a06616a1e 10722576 salt_3002.1+dfsg1.orig.tar.xz 1d257d69f719d74083a205748321c08f9bed73d7 70376 salt_3002.1+dfsg1-1.debian.tar.xz 15e5d4231518fb13d187e809b1e0bb10f89b3cda 14111 salt_3002.1+dfsg1-1_source.buildinfo Checksums-Sha256: d514b6c20441867c9bb7c5033f26b3005924a71dfb2bc08714d24f2f62ce234b 4192 salt_3002.1+dfsg1-1.dsc 8a98e528f73c07bd1fe9a0e52bbcd569d98e09b4be40c883eaa1bd945947d75a 10722576 salt_3002.1+dfsg1.orig.tar.xz 6c133b9ebf8815b710f805c1fac4df472140242392547d79a38a6ae3ebe023fc 70376 salt_3002.1+dfsg1-1.debian.tar.xz ed9cfd7898125e77c30d2f9571959e955a03421cca40fe1476d48d64a3b01f2f 14111 salt_3002.1+dfsg1-1_source.buildinfo Files: f0e71c255c043bdb854e05a1b3eb637b 4192 admin optional salt_3002.1+dfsg1-1.dsc c0e0b5fd2caa12ab5e4f72f5e00e0097 10722576 admin optional salt_3002.1+dfsg1.orig.tar.xz b3b9cd060039f5a45492c2fd66d167a4 70376 admin optional salt_3002.1+dfsg1-1.debian.tar.xz aa564ff1f327ad01cd7a4873ad540537 14111 admin optional salt_3002.1+dfsg1-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5/q3CzlQJ15towl13YzVpd6MfnoFAl+pS3oACgkQ3YzVpd6M fnp5QA//UpDbr9rAN6iRs7uEO3H1FPlyMrcu9IeJ6mWes4aMoH7MwGu+UXYrLtN5 N+GuVwHOnYTG+dzjZNIIK6b18G9u7bbv1HXvR+eQAd9kjwepuMYAEqNxUSgUNaB0 wBqcxMhDdIl7xa1EgHE0lJbhNqI+YH11tYsXKFMG0CXYCJ4F8SnOk2UnVlrEHd0U 9fZ2HX0EqAYPKeuPYAQBJ3EaD8rDU39ESVPbPWbhWhfatcfux11BJKV/4jSD3Qjy Qas9mX5iichDWsIVJ3bXburSi867ISTJ0xOFNuDoZ4uAQvxcvnu5KbM4zes7/7n8 pYxXCmCVwQRXrZWaK7lVO4X/qVhFNNoH2b0NDF/VgIc+VHelIBCk8TR/foqeFvBw QFZ0KJqJ52MpbS5h7/hXgz3mdVcRDUEMHN+6teUpMWU6JElbt3QSQL5DL34SscP1 rmc733xcM6nyuXJetrSbbZI4+YKkDxzqPSuWR5vyB/8t3eSMn+ii0gWAxdFov4Wl zYAWda5CNNxbrP812Tv6+0dFBhX3Pg7/MnfV51f4ehs3/0Z8lbs99R6g7xue5iN3 TAkcyf0gE6DoMje6Z8zqmtqsH2HfW9Qw9dSVvWQQ5LQFX8IRS1OFSwvxvg46uco/ u5rOXzUjaMtQyIRqfSQ1rXz52eC01TrQhZHHSqCAXmyIdvnAZho= =LPSJ -----END PGP SIGNATURE-----