-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 21 Dec 2020 20:03:02 +0100 Source: slirp Binary: slirp slirp-dbgsym Architecture: source amd64 Version: 1:1.0.17-8+deb10u1 Distribution: buster Urgency: high Maintainer: Roberto Lumbreras <rover@debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: slirp - SLIP/PPP emulator using a dial up shell account Changes: slirp (1:1.0.17-8+deb10u1) buster; urgency=high . * CVE-2020-7039 Due to mismanagement of memory, a heap-based buffer overflow or other out-of-bounds access might happen, which can lead to a DoS or potential execute arbitrary code. * CVE-2020-8608 Prevent a buffer overflow vulnerability due to incorrect usage of return values from snprintf. Checksums-Sha1: d44c0f4029469f93720ccb6bec918c3e6e8d0a1d 1899 slirp_1.0.17-8+deb10u1.dsc 9b660f5365f1d9536d9171c1e0de490ab2232ec8 305754 slirp_1.0.17.orig.tar.gz 33f0cae0b168e61240db03a2816aa94faecd94c9 16388 slirp_1.0.17-8+deb10u1.debian.tar.xz 5ffd4d1a79d8f09b3cf788ee3299b175fa9d72ab 616084 slirp-dbgsym_1.0.17-8+deb10u1_amd64.deb 97530a31d286f8cff3fb0d02ac72a373618afb36 5893 slirp_1.0.17-8+deb10u1_amd64.buildinfo a97f4d233ff229349d554cf972879334329e7927 181856 slirp_1.0.17-8+deb10u1_amd64.deb Checksums-Sha256: 02dd7dcdd018c6702b8420543df9d63716f82766eed80288e46b9d9d760d0db6 1899 slirp_1.0.17-8+deb10u1.dsc afe59cd298075aa1b9eba5a5f7cf720597372b8b81657de529b2cd35a2a2bc2e 305754 slirp_1.0.17.orig.tar.gz dd2c87c985b01fc128ab7a8819ea9acf02d6ba09d4cb27cad43065f146f01b8c 16388 slirp_1.0.17-8+deb10u1.debian.tar.xz 5ae5760b35b3286e9fb6947f6ce579c9a8ed4212799584d9f47be32676236471 616084 slirp-dbgsym_1.0.17-8+deb10u1_amd64.deb 85380eafa342c1fd054aa3bffb8de042360d8724e58ac35d3e9800b62b0b6183 5893 slirp_1.0.17-8+deb10u1_amd64.buildinfo 9b3d7456b16d70daa25c245f1e8ae6005ce7f7ad1df842b1b0be221ef9c77899 181856 slirp_1.0.17-8+deb10u1_amd64.deb Files: 2b45ec3c2ce8278e26230daff6cae605 1899 net optional slirp_1.0.17-8+deb10u1.dsc e167ee2023fbec89468b93b6bff6960e 305754 net optional slirp_1.0.17.orig.tar.gz 2e1377837c460a6ab23e3bf5f56da09e 16388 net optional slirp_1.0.17-8+deb10u1.debian.tar.xz 4d985c0eea2302af59efc357f1031fd9 616084 debug optional slirp-dbgsym_1.0.17-8+deb10u1_amd64.deb fe4d0f3e500b002dd67c2a31e36fbafa 5893 net optional slirp_1.0.17-8+deb10u1_amd64.buildinfo b3038c6b9cc0b96e132c6f8a5c4556dc 181856 net optional slirp_1.0.17-8+deb10u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmAG5QBfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR1muEAChuRUSLy6ve+uTA4P85Y1RPcXNtcHF tXs/CQAxmEs/tcMESZzRduyrS2WN/7c+Rg88Fy+2ThJIEmWDjvnQK2BK4Wg0rxsG 3PkS8hvpBr/c/O5iB6tKPhH96EcbE+0RYeQR/pSp2adi7eAPnwGp3QRMjGNhIwCW Twph5/LE2w7TpNag7hHWeMNIfap+9lszPWAHEh7LwKI1N489gFnPFGvHSiYVlUUh 0E9U8y+4cH08lWPfcPdZjuEygLlyR0IIYllQ3sOqjn2YRyiQrp/jD3lrGTldbQAL 6wfcpTVwrejdWQvYGBN10vs2Z5nr/nFXs78RcoOLeVFXwssvaAP/rYMMPYiCC64s 9no+jU6ZSefuJhzAx+gAIZ1+k3gNsG88Op8M7cx+LsDBnFBCZDJLh60YKR83Lpvv s5BJjZd1roL1LrVHHSCgTRJfuxni6eRvSt47NOotIPz/KHwwXTeL+8Ry5NgmFc8b MRCsRM8/YavA6CWvhsDIXxTpoexlJzW2r8qk9OePI8tTBIlyRHsJ8r3gPDiAomBZ P4y8d/MkUj6lNAQHn5TeDqnqCrFa31YkwyftSVPE2RD/WE+6sR2PrTqcyKFyvnX+ 0h6GdHa3DykBF0SLm/E1TEi/wTgrXNGaoIHZd59WwuOQDEDsrxObWnpHuZ1BH3sy x7RNnwJnsVXXRg== =FJkk -----END PGP SIGNATURE-----