-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 28 Dec 2020 21:06:07 +0100 Source: salt Architecture: source Version: 2018.3.4+dfsg1-6+deb10u2 Distribution: buster-security Urgency: high Maintainer: Debian Salt Team <pkg-salt-team@lists.alioth.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Changes: salt (2018.3.4+dfsg1-6+deb10u2) buster-security; urgency=high . * Non-maintainer upload by the Security Team. * Prevent shell injections in netapi SSH client (CVE-2020-16846) * Prevent creating world readable private keys with the TLS execution module (CVE-2020-17490) * Properly validate eauth credentials and tokens along with their ACLs (CVE-2020-25592) Checksums-Sha1: bce21a13d1079a06cde2ab2dfbbdff9c6d915527 4195 salt_2018.3.4+dfsg1-6+deb10u2.dsc fb1bd6fd294e2c148c735427b9d38cba5f2cd2fa 72328 salt_2018.3.4+dfsg1-6+deb10u2.debian.tar.xz ac4c1db1a254131cd164261579323d61838855b6 8237 salt_2018.3.4+dfsg1-6+deb10u2_source.buildinfo Checksums-Sha256: ca8cf14d8c14ced261b02a39974bb77fbacf3b0b113468d5658ffa3f8a249ad4 4195 salt_2018.3.4+dfsg1-6+deb10u2.dsc 7746be172978312417a19cc18d3ec3a7d35cee9e24fe3596835a12c1f6d9c719 72328 salt_2018.3.4+dfsg1-6+deb10u2.debian.tar.xz b368b4d0aca7b911ac55c8cbfae719bb632fd32c926cc61a4865bb4043c8dd1c 8237 salt_2018.3.4+dfsg1-6+deb10u2_source.buildinfo Files: 707a8c4a88b9469b38d9c1156b2e710d 4195 admin optional salt_2018.3.4+dfsg1-6+deb10u2.dsc a29a0c1c97dbe4c4abb5646046a2894b 72328 admin optional salt_2018.3.4+dfsg1-6+deb10u2.debian.tar.xz a1f92b93fa9f649fdd844025e667d7c5 8237 admin optional salt_2018.3.4+dfsg1-6+deb10u2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl/qO45fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89Ei3AP/jGqsMebNOVMlB4XrbeUKQ/d5NUkx4bc QcZMs/Pn3iSpa99229s06cYRxFbI75EPj03STgLfxBNzCg2JEDeOp03K7T43gDqA rwBDxWAzgzb6lxD9c1nLL8wm+e6SiaCZiTc99hLOLRIkuW0kLDa3iySKNWrrEu6Z aivdX+JoHqXX0MOV+Ckmrrd2Z+oEVFhjr4NHg2CRQGuEQw4SlTJhDO874eUMZFem axBxrpNVJ+FXK2Hc4aE0AAmiAsj3nlhu66bqQ46ZlH/t1lzqr2DrLDV5cRjQ0udY GyTfifUMF3LnS88iwbfk2onPeu0Uv5qdMJ72eTGNaRGIvmNXbCjyx+kj6KcaX3aF /uIm6fBNIrzyG8hI4j3JzQUxuSJXz/SzPcbLfSzOINDMhN57Rx9bQUfu1PWZ/sHT XpZI3hY+6+rfs6i62kYtZSroaXkHS1cNUzOWoyjNEp5Qv35OMqyC3n2N1UPOf4TG BCb02ocuuUbPWzaC1+C3T4m+g/SYMl/s7d1sC6GDmDtpAaA0NJoqDLWRJeB+n/bY SJosbXbJZqLHusRc3k4fSZeSQABWFdHrVNwHYGfHEaFRD16JLekNrucBLRdOyUes 7BclcC2Y/Ef8cBdm+tyqoibV+WpwHVZ7qvdksJ8fRROYwwt+B5benHjPt1w3tgtI OHFnRNXtELnh =PiDr -----END PGP SIGNATURE-----