-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 30 Jan 2022 17:29:14 +0100 Source: logrotate Architecture: source Version: 3.18.0-2+deb11u1 Distribution: bullseye Urgency: medium Maintainer: Christian Göttsche <cgzones@googlemail.com> Changed-By: Christian Göttsche <cgzones@googlemail.com> Changes: logrotate (3.18.0-2+deb11u1) bullseye; urgency=medium . * d/patches: cherry-pick upstream fixes: - skip locking if state file is world-readable (CVE-2022-1348) . - more strict configuration parsing to avoid parsing parts of foreign files, e.g. core dumps, (see #1002022) . - do not use incorrect stat information when verifying an olddir configuration after creating the olddir . - advance pointer in full_write on incomplete write to avoid data corruption Checksums-Sha1: a045da2b87495a9dc0c938335bd2660403d0b479 2262 logrotate_3.18.0-2+deb11u1.dsc 95876c510cc57b7e7eb8c96caf70a52216474378 27356 logrotate_3.18.0-2+deb11u1.debian.tar.xz 1792c4b4b3e0a1e329e4b2a87b951bf81944399f 6002 logrotate_3.18.0-2+deb11u1_source.buildinfo Checksums-Sha256: a61c94eb0b67f261bf1bf17af0794b08ff8d17cfeffcc6091f803df1e77bec26 2262 logrotate_3.18.0-2+deb11u1.dsc 309f43a6ad7f7b50febe5f4c960a1c57af7eb78bd891a9c6d5b3e92fb1e97d98 27356 logrotate_3.18.0-2+deb11u1.debian.tar.xz 88a719fe4d248ce6aac473ceb7e5aacddb51417b8f059d812d6e529ac3e68956 6002 logrotate_3.18.0-2+deb11u1_source.buildinfo Files: a7c1559790468f87161bba2c583743d1 2262 admin important logrotate_3.18.0-2+deb11u1.dsc 7f54ffa47de43f18819e46a01dd62068 27356 admin important logrotate_3.18.0-2+deb11u1.debian.tar.xz b0222cf3d9308f9b33261bea164d806e 6002 admin important logrotate_3.18.0-2+deb11u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEkjZVexcMh/iCHArDweDZLphvfH4FAmKOv2IACgkQweDZLphv fH75vxAA7U6FQoj3QMwlK3oK44Fr4maFeDPStiSkMc/rtLgPhiM509c7BTkw02p5 GUsqunXVNuzOIsE0q/8/wW2vYvMSzhSj7ErrRwLZUwEGUKsYruReW9uIevrf86t+ VIaYWT64hgwQOE4oCqNiHrSUpNaVmIp24q8+ZSLKCqwY7KYE5H02z71AKj5jVNo9 AWCQ3obU+dxLcGOkN7ZtfOabcMLaezbh6IZyqCUtBrQsBKXD32EV+zzH+qwaMSud FWUd8H9X0PsvFL4+AviPv3NFt0MskgsANOF/22F5ACIjfma8MsqHM2jo+HoRMAr8 oTqNBH/0jJC3dfwzBd+avdjduW/+Hy6TooVN2PB566qr25ucDS5BPITA3Lm4l/Qn qzLLpg82Rm/QCkewvs34MI1sQY5A1tLeDw5fDpOiZ5dCq4G+/XQYR+zUtn5v5fYb S7h2AgtHcVpkRNGQlSIhQ2HVIlj9QH4ZZgoF/u1ZUVmULuRQ5DdSnikP9SyZmGuT Yl8bPeX1t12g39O4cPqD90H040MBuD/HXo9dV8WlQR9NaVAAShIPiww2cEFbj3aP +Af57xcEQo+tC72LkJMCzTcEaSqfvVza9i/TXvFMdOPoup8rid6lDuN5MKu52cig RKG5+jmcRqgfaKOZa8uSn9RSv3mXIozKpTK8Dq6JnF6d8K9jIcE= =z+a4 -----END PGP SIGNATURE-----