-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 Aug 2021 16:16:07 +0200 Source: libspf2 Binary: libspf2-2 libspf2-dev libspf2-2-dbg spfquery libmail-spf-xs-perl Architecture: source Version: 1.2.10-7+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Magnus Holmgren <holmgren@debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: libmail-spf-xs-perl - library for validating mail senders with SPF - Perl bindings libspf2-2 - library for validating mail senders with SPF libspf2-2-dbg - library for validating mail senders with SPF (debugging symbols) libspf2-dev - Header and development libraries for libspf2 spfquery - query SPF (Sender Policy Framework) to validate mail senders Changes: libspf2 (1.2.10-7+deb9u1) stretch-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2021-20314: Stack buffer overflow in libspf2 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages. Checksums-Sha1: dbc44fbfd75fe927b9f4e327bb4d603a6d8b3693 2263 libspf2_1.2.10-7+deb9u1.dsc 3c31b20c737d9a8044440e5bf25697016b9cb582 508842 libspf2_1.2.10.orig.tar.gz 280bc82f916e7f134b8a0d4c021cc3ec0e0c5ee9 14876 libspf2_1.2.10-7+deb9u1.debian.tar.xz 80ea8ac45978cec0eda1e3b07d7c4b29b62979ac 7223 libspf2_1.2.10-7+deb9u1_amd64.buildinfo Checksums-Sha256: d573204ea3e293634378ec0d8f7ee9e204ec29294e9f49388fef66996f5b3035 2263 libspf2_1.2.10-7+deb9u1.dsc d91e3de81ae287a2976c44f60283bd3000d720e6a112dc7142eedf1831b821c9 508842 libspf2_1.2.10.orig.tar.gz b2263594298dc793f741d4b292a657b28db6012cab2e4506842642f7119d41f2 14876 libspf2_1.2.10-7+deb9u1.debian.tar.xz d98503bf015993c607b684fc572d6cd9cd2ae93ede7ba909485582a8de904c6f 7223 libspf2_1.2.10-7+deb9u1_amd64.buildinfo Files: 70bb2c4cdacafced9628d69cd622368d 2263 libs optional libspf2_1.2.10-7+deb9u1.dsc 7bb9937d0705649eaa8646de66dc3562 508842 libs optional libspf2_1.2.10.orig.tar.gz c5950a4dc0841c477eef3d165db74eac 14876 libs optional libspf2_1.2.10-7+deb9u1.debian.tar.xz 640a5667373f514691baf40381fd79f9 7223 libs optional libspf2_1.2.10-7+deb9u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmET6xdfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkJR0QAKuSDw4JqTLsHilHFDtRkFnV3F2vC71pU8I0 H1JGeV3Y6SROWFOL8hdxrWBwtNVRLXd2O84dTeiWo1QpEvesh67ou9BB5GScJcpn 08Vu/Z1T7Z29UGktnOUlXIVozIszAysGWi/28MfK2gYXNc8vHr5GB9KIMOua98WF VY3myv38NXctfe48bSkci49ypNTFovN9kku+nOMhdtwCuBE4FXTBQMvLnn+6PE8E glI+FnbJokSzefuUEDov8adXqj+zD2yk5ZXXiCqgFsrS2Aax2qVrbd5sUHRQhPPd JsPjAyYwE5KkA3Tu8fgow8X4d8OFGd+PE7uSe1wkDp2RobwI2e71rvUrrn5Voq79 qJYQXRR7e6AXcsWPR+huBlEO66qHDcCfC2P88UQMZLXGpGyQNzrOCoHVo2ON5Or5 ZEY5ZkhcZfyzs3yB6BLWnOXyPk6gxJf5HesV/S4Tz2TnULQ3KeW5UAGPJ59z+u1O iPQbQzSxjSdeq/kSZgSfmG6LSUW3DBmQcbcIy+tMhXSUy4/jh+62jX6+Ajw0L6Pl 4tG5hP2vV1LU00puiqUMIQcj4d/VosAkUHLyxRLDOYSOEy2jkhSOlguZtKppS2b4 9HXjpyr26cgjjJf65WINx7O1M7FH6lhlaLZnmuebPCwofTFSXEd2ntvokLOxVU3H +argWrq/ =1dzl -----END PGP SIGNATURE-----