-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 07 Aug 2021 11:56:59 +0200 Source: c-ares Architecture: source Version: 1.17.1-1+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: Gregor Jasny <gjasny@googlemail.com> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Changes: c-ares (1.17.1-1+deb11u1) bullseye-security; urgency=high . * Non-maintainer upload by the Security Team. * Missing input validation on hostnames returned by DNS servers (CVE-2021-3672) - ares_expand_name() should escape more characters - ares_expand_name(): fix formatting and handling of root name response Checksums-Sha1: 85d0adb0ffb84e42184b399d044da23347e9a85b 2301 c-ares_1.17.1-1+deb11u1.dsc 431d5ff705db752f5d25e610827b7cb3653fc7ff 1518701 c-ares_1.17.1.orig.tar.gz 32c725307893cc9b23fba718b14856d2297d17f5 488 c-ares_1.17.1.orig.tar.gz.asc 5b54312fc4e08b80264d2fab236d64b78881ceb1 9960 c-ares_1.17.1-1+deb11u1.debian.tar.xz Checksums-Sha256: 067653ef0abc6767bea6ed02821536a1716d79a0f34aedb62a0b4cb389aa85a5 2301 c-ares_1.17.1-1+deb11u1.dsc d73dd0f6de824afd407ce10750ea081af47eba52b8a6cb307d220131ad93fc40 1518701 c-ares_1.17.1.orig.tar.gz 2dac298ea5c1add08bfcacc65bf879016c7f9e2ab54ca4f92f83c2b5681b4c60 488 c-ares_1.17.1.orig.tar.gz.asc 64a43590c385ecd2d6b4198978b8c4cf07de750319b015a44bcd7e090b8eeafe 9960 c-ares_1.17.1-1+deb11u1.debian.tar.xz Files: 5b8dece4f9c6e4b056b590cdc071d9bf 2301 libs optional c-ares_1.17.1-1+deb11u1.dsc 28f65c8ee6c097986bd902fd4f0804e2 1518701 libs optional c-ares_1.17.1.orig.tar.gz f3f45f08e421c698c8d9907042b6825a 488 libs optional c-ares_1.17.1.orig.tar.gz.asc 3e7763cee8683eae5c391ffb98e3931e 9960 libs optional c-ares_1.17.1-1+deb11u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmEOh/JfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EnPgQAJdqbPP88ENRcSYgPTgcwur1fk4Rxnvx daAhs9kP5WNEIHibDOIgfKoU+JD56CtREWAcUT/fMFAJc8AugWbsXxKDeupQ2HAh OBMoeop0/F312Nm8y0fdyPBnhdS8jHrs5/bvkN1vt3mC9u7/M3W8O/LkCnxfkn/5 mpimJ8fUPBrcsZZZY6WvMs4l4NAJx5HWlxBeDkpdprWIZk5nlhTKr+q+uR0rlR8p Tk4EGROUI0mlgv6O7guBRvnn6PNYvgD4n1jNpR2dtcwuwkdx1qk/YTDIlfAhSrC5 L4+EBlVRyIbzU84QFhVQTd6zCxY64wvMkMIaDz0hsgpMzftRKMiyuWnEzD7o0lSX uRP/xFZmeRSFWwKCPLxL63he2qa8bFeIkbEF/vdopAX3kt9lkYI+hyYz7gl2WCk3 iS0VtRrji0BTZ3eGyIw1I5eqP9ot92LaCLmMeUGU/9IC6vBQlem8+jnE9nRuyFMo 1xVgc36pyD2q+HRpbSy54uuFQh0sfRZTeOwfjgG037OkkJvKtNyaPqqISErnW0zy bjI8HrhkDGxVPH5TQc6YsTznaCvs3YQr7ltU0KT9Cd02e4kV00hxYYkU5VmDBduS 3v/OoKC3mc4KBr1nNF36YZmkjbfQlne73ORvpb3yc1fnLDaJGtzZrzxeDGrosC+q Imb8uW8/b1wu =Qg3G -----END PGP SIGNATURE-----