-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 02 Dec 2020 11:47:58 +0100 Source: slurm-llnl Architecture: source Version: 18.08.5.2-1+deb10u2 Distribution: buster-security Urgency: medium Maintainer: Debian HPC Team <debian-hpc@lists.debian.org> Changed-By: Gennaro Oliva <oliva.g@na.icar.cnr.it> Changes: slurm-llnl (18.08.5.2-1+deb10u2) buster-security; urgency=medium . * Fix potential buffer overflows from use of unpackmem() CVE-2020-27745 * Avoid unsafe use of magic cookie as arg to xauth command for X11 forwarding CVE-2020-27746 * Stop job launch if --uid fails CVE-2019-19728 * Fix Authentication bypass with message aggregation CVE-2020-12693 Checksums-Sha1: 9bbbc69627f1223a9ec00e655c3024f6abf5e073 3753 slurm-llnl_18.08.5.2-1+deb10u2.dsc 6f6304647ebf02cfe42c83b8faa29cbd9541e5a8 134872 slurm-llnl_18.08.5.2-1+deb10u2.debian.tar.xz a5c7ad6c80a59bfd7b4dd13b653a720500107a30 23541 slurm-llnl_18.08.5.2-1+deb10u2_amd64.buildinfo Checksums-Sha256: f32371faf34e5f4bc1f7df261dc71d5e0e9dd95270d8e7c53b6b39d88e0c3626 3753 slurm-llnl_18.08.5.2-1+deb10u2.dsc f68d714031e4a104dab3a1202dd3a71fbfcca9e326eb67c1aab23f7f58c2b50e 134872 slurm-llnl_18.08.5.2-1+deb10u2.debian.tar.xz 8948c449ca6890d69ad8a811ab242e002809d79e7c987f5153a4dbbeb21f941b 23541 slurm-llnl_18.08.5.2-1+deb10u2_amd64.buildinfo Files: ca9b321280c50bab90fedca91fbbf811 3753 admin optional slurm-llnl_18.08.5.2-1+deb10u2.dsc 416df082f4e46262d3afd956013dfa73 134872 admin optional slurm-llnl_18.08.5.2-1+deb10u2.debian.tar.xz cb61b92a492b902390924100e6f13343 23541 admin optional slurm-llnl_18.08.5.2-1+deb10u2_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJLBAEBCgA1FiEE6zNF9WRBuLgad5h2ffpBrZYZhdcFAmAPU5oXHG9saXZhLmdA bmEuaWNhci5jbnIuaXQACgkQffpBrZYZhdf7jA//Tz6QakS2V8TJFic7FbdvPmiU B6XgWrglpdBaPKuB8LbHkRtXagnK3xg2e/xGNgzUHP6L9HFUlG85mJwWqudeknoI YCyYNmLKBCF8kMGi7hW5rhzRYqpTqSX6EPPjLOM8LaFj9PuDz702OLwr8TzaXQdK qqxpck8fiZbgvTiPevEYMRYNvUN0YDLTkTK+9tAlAeIi5IRG4x5IkSqg1ZaYaC9t ZAmCbt5CGdJgKhFpymCoscEJo+5BimqFsP1yIzovoD7K3v5KjwW6COZ61kkideW3 fbc8tLoviZv4Hcr+tJxz8YTboor7MjEK9BlsBxFc5eLJUnIGRusFT3ngntehzKU9 3f6owsHcjrWyuzmYuenzFnxOhgtMWgjmekPI4kLYQxHgRFuNla86hMCTHWILum0b N3ctV99nEGoQ7rXoQ25tecUvVswQzNPTBmb6XmQLkhPx0XRgW41jkMFWqVRWcsh+ HxlydYYoxgtwJ9kyvVwGelDFbiin1+HgviCVm1zhvMd8YL2OCXrGm9fKaVo/8Xkc R9mKV3TN3j3u7xAT1wqaRX4w+eV6jrzdzfbVM8ublhd03FeE7ZzYFtnnm3Xasa5y wWVKdeOvvGkEXOXSZYp+yRQiLVaCEh77S42jvSTTVB27ahraM5lJZch5W2/rnUio VnjyIvj0y1eW9gggFVE= =gHLV -----END PGP SIGNATURE-----