-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 25 Jan 2021 12:48:26 +0000 Source: crmsh Binary: crmsh crmsh-doc Architecture: source all Version: 2.3.2-4+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Debian HA Maintainers <debian-ha-maintainers@lists.alioth.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: crmsh - CRM shell for the pacemaker cluster manager crmsh-doc - crmsh HTML Documentation Changes: crmsh (2.3.2-4+deb9u1) stretch-security; urgency=high . * CVE-2020-35459: Fix an issue where local attackers were able to execute commands via shell code injection to the "crm history" command-line, potentially allowing escalation of privileges. Checksums-Sha1: 23f24bd78c7a818f30fcc00784dbb0c6162d0cb8 2311 crmsh_2.3.2-4+deb9u1.dsc 549d7fccfa4b5747d03c66b7eba4e3a653423f0a 879736 crmsh_2.3.2.orig.tar.gz 22284f4fff249d128e8295ec2c4aeb77f4bd1001 25856 crmsh_2.3.2-4+deb9u1.debian.tar.xz 5f39417eb1cbae08ac46463a566a4584439b603c 401790 crmsh-doc_2.3.2-4+deb9u1_all.deb aec49cd3bd623f2b3827d35952ea4c972524e1a2 449194 crmsh_2.3.2-4+deb9u1_all.deb 7ccde888bb8026506762b423ca28097a910df6cd 7316 crmsh_2.3.2-4+deb9u1_amd64.buildinfo Checksums-Sha256: edd61db29abeaca529151c87221faffd32ad0d1b27a0e21b302bf65966f19d61 2311 crmsh_2.3.2-4+deb9u1.dsc ac78b7786f6a52cc3d86b3d80b2d8627e84873330cd4846d5ea48869189ad864 879736 crmsh_2.3.2.orig.tar.gz 5cf4f957d44e0cca36f7e30667ebbd41c1e7e50756f34830c49881b322ff356e 25856 crmsh_2.3.2-4+deb9u1.debian.tar.xz 9da5d23715c5c3ac3e5bf11dfae4ec712ff244e508e5a90fb7a9cdaebf1e2c5e 401790 crmsh-doc_2.3.2-4+deb9u1_all.deb 16e3d4ca2957d08b25c167f3fd851b31f80a4795f3d51df9bdf35ba264a9315a 449194 crmsh_2.3.2-4+deb9u1_all.deb 14302cccb3ad4fb062a5862927c068716966e298f189fef37adebe332c07bfe5 7316 crmsh_2.3.2-4+deb9u1_amd64.buildinfo Files: 989244229f1792fefc2ad66c521e1613 2311 admin extra crmsh_2.3.2-4+deb9u1.dsc 0a475d3c56a158dc991de61a26450eb5 879736 admin extra crmsh_2.3.2.orig.tar.gz 028bbd17b9de46746aeaee7d16976b42 25856 admin extra crmsh_2.3.2-4+deb9u1.debian.tar.xz 9c41b0d4b7ecb16a56f258ebea3bb7e4 401790 doc extra crmsh-doc_2.3.2-4+deb9u1_all.deb 6142d02e627c31e5a2ea426fbd4eb4ea 449194 admin extra crmsh_2.3.2-4+deb9u1_all.deb 5195a4e8fef63accc14354ef29908055 7316 admin extra crmsh_2.3.2-4+deb9u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmAO3o4ACgkQHpU+J9Qx HljrhA//T55I2Ld58xtZ3vY5HHebpKmsTBAQYwb882l3XVh7bUNbAxdLZ+KGCgc5 QfRLfOUCgYY8AIkblxdTY0D5U/bPH8z7RtEQ0TlczwWm0NLFrYzIQgn9rbt+ezwQ lvOFp1zJoBgGjoUcoJNM2h8x7RbfBb4yx7IRGDnS2mVqkf4n3BLgKfk2dFbFH4DR cBvU7/JhTGbvQ/F3+JN/3fD0YhGya1F8WAHtTTlQpsEsSPMukslMfLoLUTN1Y/1U kB2MpqXInyaVYR0rOuQitBFQDxPmM5mglyNToIuhqd5cRX5bgKiWRgazJBnXL6vr Rzke3bnnmCd+OERbTRC51l3abpGGfSV+yLyiQNUe2KRgqy4AR5mXMZmlueNiI2O1 7GrS8Xtqv3g91Rm+PGj5dN4L0lP4YZU3whqkzkaIBm2EyxpIJ7HmrMhUjckzUB+4 LtxZ+CLn8ZN8U51j4gk5gNAMnSulo4O8KUdqzdsL6syi1Oxt2yNgzI/+AtnFqvAZ KuqHiGDhccJeGqRQwznOceDQrEU8REbjqUelUA4WHj69uTp5IIsyaWiGbem/4Wgf zh9DgP9LPRvsxPOOl4ZZ15G1SZ8ii7tLWdlBMFTHaGoKGl35Uk7kgcOwl9j2Iery hxp5S/kGxgAAQTI3pBbuz0BLyqCBxE2bCLlmVAsH/B7P7qLGaKo= =MzVQ -----END PGP SIGNATURE-----