-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 09 Nov 2021 15:49:53 +0100 Source: salt Architecture: source Version: 2016.11.2+ds-1+deb9u7 Distribution: stretch-security Urgency: high Maintainer: Debian Salt Team <pkg-salt-team@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Changes: salt (2016.11.2+ds-1+deb9u7) stretch-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2020-28243 CVE-2020-28972 CVE-2020-35662 CVE-2021-3148 CVE-2021-3144 CVE-2021-25281 CVE-2021-25282 CVE-2021-25283 CVE-2021-25284 CVE-2021-3197 and CVE-2021-31607. Multiple security vulnerabilites have been discovered in Salt, a powerful remote execution manager, that allow for local privilege escalation on a minion, server side template injection attacks, insufficient checks for eauth credentials, shell and command injections or incorrect validation of SSL certificates. Checksums-Sha1: 14879f1f7d3062b2e493469e89f37ff57b02ad25 2903 salt_2016.11.2+ds-1+deb9u7.dsc 1df11eb76bc91cd74a6535138b1f6328212476f6 54228 salt_2016.11.2+ds-1+deb9u7.debian.tar.xz 23b6cbde45219983c13591ac2858e3445e756af6 5803 salt_2016.11.2+ds-1+deb9u7_source.buildinfo Checksums-Sha256: 17c80c638b09924079bf329b00d179f261a86726b28cc843c7a8a0c659e4d0b5 2903 salt_2016.11.2+ds-1+deb9u7.dsc 1d2ba65f74c74df976d966c3f814872f0def0477221962a02609453e706a47b6 54228 salt_2016.11.2+ds-1+deb9u7.debian.tar.xz 996514919e08dcc136339850f902d6f54da6a338deb2ed63fedbd68c5b8b082e 5803 salt_2016.11.2+ds-1+deb9u7_source.buildinfo Files: b7bc3733f6d593a8261fc6c3bc317449 2903 admin extra salt_2016.11.2+ds-1+deb9u7.dsc 51a4ed060bf5c1a41b3ea0930ca83fbe 54228 admin extra salt_2016.11.2+ds-1+deb9u7.debian.tar.xz b65c95b4d2931b632b27304df3fdbf2b 5803 admin extra salt_2016.11.2+ds-1+deb9u7_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmGL/v1fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1Hk7fUQAI2kO0kRzwxDhLjGXT1l6THI/ybUbNs8vdcg il6ESK8E+upllsdVdp2gPHrW35YHs4pcmOi1BDIivnKzs2YZbn6UFQoBjlCWDfga Eur8E74Xe24giRbAwUZwdSCyrxu+XVdpN/JrMP0o8pPiVAQ7xLDWGLlIKVNyaF4h qoJqOwbJod0gNcKRr4kL+N5LgkL9PWET5yWM20BtUIi7hd4nv1s/fm66fQRutq4g GmtolgQkppkyPzh/JQa+Nl1sffI1xo0LboeJvZ+Bzdlzn0z7B3Ew3kDQQ+OHcots TreVps/j4cNN7sSUZ6RiNHHX0yfn38qAbmn/h82L4c6HhwgLCJ14vgzfwxgf+xFl 4agQWeGR1nbJd35BE9lIR45qhx84epN2cZnNMGmRXMZyWiyHtAvY6kmhGECV3JVW aAn6W9/dnFhjYp30N3ZQa+nqFrMIky5KrqWPryOJ8ZkOUdKTsKi24FsyAwhp0SuC HIXtv8HOI9rYKO5O6P/m5VBWx8hD3uWxNrv5xnGcGXb0wnR9hs7N6Rvrn8Y3i2Ac GV4p10NUeA31+aa58G4dqpo7LvCYGGP2ja1VXgL/YzZPQPlp8TvZDhtGcrgYRVwH 6rHCvSBjEfvBODUKjBRGNztM1v6YOq9OJ6VMBAR1dBjpKtSH291skt7j8M0zfcb8 PrKlOhLg =8JKP -----END PGP SIGNATURE-----