-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 18 Nov 2021 21:52:04 +0100 Source: salt Architecture: source Version: 2018.3.4+dfsg1-6+deb10u3 Distribution: buster-security Urgency: high Maintainer: Debian Salt Team <pkg-salt-team@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Changes: salt (2018.3.4+dfsg1-6+deb10u3) buster-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix CVE-2020-28243 CVE-2020-28972 CVE-2020-35662 CVE-2021-3148 CVE-2021-3144 CVE-2021-25281 CVE-2021-25282 CVE-2021-25283 CVE-2021-25284 CVE-2021-3197, CVE-2021-31607 and CVE-2021-21996. Multiple security vulnerabilites have been discovered in Salt, a powerful remote execution manager, that allow for local privilege escalation on a minion, server side template injection attacks, insufficient checks for eauth credentials, shell and command injections or incorrect validation of SSL certificates. Checksums-Sha1: b6381d1b068b8a4426af1ab4bec0ae656f3128f2 4191 salt_2018.3.4+dfsg1-6+deb10u3.dsc 2b4516e5d1fa3d0a8bbd57813d4ca43476040e87 89784 salt_2018.3.4+dfsg1-6+deb10u3.debian.tar.xz 217108d5363b4b76bc8a1582b5aa1ffd2791ee54 6994 salt_2018.3.4+dfsg1-6+deb10u3_source.buildinfo Checksums-Sha256: d4119431b6a1a17b59daf4cde54229e2b3894fc19796267634a6df6e28809b95 4191 salt_2018.3.4+dfsg1-6+deb10u3.dsc 3cda812a1aa6112414980dd5260b6b3c51acc1c4fc1b782897cb61cd7ddb85c6 89784 salt_2018.3.4+dfsg1-6+deb10u3.debian.tar.xz 9de192cb0d3cd22d63a1940a2335f14e806f7480bb0824fbc920dbef84db5cfe 6994 salt_2018.3.4+dfsg1-6+deb10u3_source.buildinfo Files: dbebbee55d30c6e1a604fd40696f038b 4191 admin optional salt_2018.3.4+dfsg1-6+deb10u3.dsc 7bd7b73fe0cf03fea952c8f52488196a 89784 admin optional salt_2018.3.4+dfsg1-6+deb10u3.debian.tar.xz 3bacbd18303943d65fd0ce0a40679800 6994 admin optional salt_2018.3.4+dfsg1-6+deb10u3_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmGW069fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkBNUP/j8UGIwD6Sl8eRYMDSygMVJccc2YmUVdwCJ8 /QS6n4w2zvHHryXp4ETgf+KK7fGAGx+Ny2t2n1LLBrOYwOONTlCkZSPLDY6RMtM+ +oqt/LJ4dWbUB5yw+ULwQI98l6SofLePhfS3L4KZyHFizFkc6sawbPWba3AwPfIe FZiqgu/zmQsMlJDGwGnUd4MwyGPPqJa4wp7Un45S9f0hFM4Rq8l0VZsmkhxKyYym pzq11EkQ64PdUH5pXiQ/2aQ1IpMK3lYhoJSecT9gJ+aJst2JoFgGMNrM7uktfp7U WWHW6Gk2Tk/VXzQ2+eAVB/kc4b7q+ugRtkzSe5bNw8BfP/i9Vp7MgrqgF7+YTLIF NDKQbqgYJcoRwp1CIN3k6J5gdLDbaWWiCzmzNnTD3q1kltp4wpbID7d2pK24KysK zqXAFxJM9JcvG91GYty7UbQxUAi4QDMOr4QQeoGjlQ6ZDSakpDa/q6QW7fn68oTx UpF+IDdp/mBYbwlVq9tcolgsEHXOONIzjir6ee1vJKA92Jrb+QwYgf9kcu+syJdS Z52SdnjAUGgURX5hXcvZZ9i8gcqdS5Xj8B8Y2i/SIyJhouwOw4XGEMkncrxQYXZT SgwQYhQT33F7wcFuYBkYWuBgKaYExXNwL+IlUM8YaWAsHZBMNtWvZbUfazYu5+yU JJ1ONNwE =IT6f -----END PGP SIGNATURE-----