-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 19 Feb 2021 11:30:06 +0100 Source: ipmitool Architecture: source Version: 1.8.18-6+deb10u1 Distribution: buster Urgency: medium Maintainer: Jörg Frings-Fürst <debian@jff.email> Changed-By: Thomas Goirand <zigo@debian.org> Closes: 950761 Changes: ipmitool (1.8.18-6+deb10u1) buster; urgency=medium . * Non-maintainer upload. * CVE-2020-5208: buffer overflows and potentially to remote code execution. Applied upstream patches: - CVE-2020-5208_1_Fix_buffer_overflow_vulnerabilities.patch - CVE-2020-5208_2-fru-Fix-buffer-overflow-in-ipmi_spd_print_fru.patch - CVE-2020-5208_3-session-Fix-buffer-overflow-in-ipmi_get_session_info.patch - CVE-2020-5208_4-channel-Fix-buffer-overflow.patch - CVE-2020-5208_5_lanp-Fix-buffer-overflows-in-get_lan_param_select.patch - CVE-2020-5208_6-fru-sdr-Fix-id_string-buffer-overflows.patch (Closes: #950761). Checksums-Sha1: 1e03a023cd27c1c0ae3d7e9538a1c2ca03d0a769 1930 ipmitool_1.8.18-6+deb10u1.dsc 4268254534c9cb0abfa5a25164931b74ff989eb7 25288 ipmitool_1.8.18-6+deb10u1.debian.tar.xz be8c255c850a896e7ad366393dbd9a19529e7761 6085 ipmitool_1.8.18-6+deb10u1_amd64.buildinfo Checksums-Sha256: b068185100ced6e7e06c2fdb674edbdbf71eec64367d9c9fb84798b45dcfc58b 1930 ipmitool_1.8.18-6+deb10u1.dsc ce84ca43243974f8a98127f3ba094989e8a945ba3b00ae815b8433c55848b92b 25288 ipmitool_1.8.18-6+deb10u1.debian.tar.xz 9fc8577b40ce23ef4e1c8d96ae461664f71b1a85bc21fcf1007353f9d53c12f7 6085 ipmitool_1.8.18-6+deb10u1_amd64.buildinfo Files: fa99fdd82a1d37d1c65cc6b7fb1db9b7 1930 utils optional ipmitool_1.8.18-6+deb10u1.dsc 44b889cde529d8550e2d0642cf2529a9 25288 utils optional ipmitool_1.8.18-6+deb10u1.debian.tar.xz fc636d477e8d16be2243e817b8800e29 6085 utils optional ipmitool_1.8.18-6+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmBfzqcACgkQ1BatFaxr Q/69pw/8D26WGi/NM3QORYlO9OUZfm+gUHSDVV+eh8/HtrAz/JHcEP/onJhzZmBr D15TvY+FUM4VXm3VQ58UIkKl0Ktsg6IlQJ7Q21dxkpThdX+PVJoqmShAcr4PoE2n FMaw+3DYB+QPFCzfOFHKmvj1P+2h3DiIXeLcZ+ieaVjrp3z9FzNHKvPoHw3c3l3e EPMjOxFfmFgG6WV40/uhp0EmrVi8VvcI0wUR/p4mbEDztZgttShOW9/S+04Zzu9O 3pfBH6NgOlsrOjslo+PlvcLFeoyLes4arRcmqew82uwo0ZdRLXXZ/Lgs1yAI3hb1 z40vRZoJJJ8ZfUC7+2DS8h5XyLJtmTpclERp1a3Zr6jK/4+y09dYY/3zoQnWWkr3 pd8FgiEZWIo2JUormju/kg/hF/bWgW+s2tvjylJttODp71KzatwDip/cYvcTYUcw UIFxt+XqI0JA/DT20EHQsffaeE9pV2/ckVYWMtKIEnyYBybWLC5WVntIdHdV4nSN cKBtXzpwwdKUkOUk8V+dtvo+QoYd2XfdN1CiEjTGiGV4TViWZ7Ha9YsSt64/f6fX BryvXTh8NcLVIr4poUHTDWR/Ixg4sRRmcGZjN2OmQySlcq4uT197FVWviW0rZGva ahds59nzGD7Eo3HcblA0FjiuORrWO3XbXc74Ppws8Pjc2gqrNmw= =QxmZ -----END PGP SIGNATURE-----