-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Feb 2025 08:46:50 +0100 Source: golang-glog Architecture: source Version: 0.0~git20160126.23def4e-3+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org> Changed-By: Andrej Shadura <andrewsh@debian.org> Changes: golang-glog (0.0~git20160126.23def4e-3+deb11u1) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Security Team. * Backport an upstream commit dependency for the CVE-2024-45339 fix. The fix for CVE-2024-45339 breaks log rotation mechanism. If log rotation happens twice in the same second, new log file cannot be created. * Apply upstream patch for CVE-2024-45339: - Fail when attempting to create a new log file if the file already exists. Checksums-Sha1: 4bf917a608624b655c246889acee2e4976377434 1650 golang-glog_0.0~git20160126.23def4e-3+deb11u1.dsc 4559f8e060026757296eb48759de8d7e9f9cc138 18072 golang-glog_0.0~git20160126.23def4e.orig.tar.xz 93bff4e6c93ce24da6b32b440392e42ed3064edd 5012 golang-glog_0.0~git20160126.23def4e-3+deb11u1.debian.tar.xz e7f56d42246c7edbb611cb4727da28ce75f64771 5922 golang-glog_0.0~git20160126.23def4e-3+deb11u1_source.buildinfo Checksums-Sha256: d0dcbf91cd494a71de51b58a057f92412fa36ce79b65c373040fcb3c2b356f50 1650 golang-glog_0.0~git20160126.23def4e-3+deb11u1.dsc a123f86df0d3c8c0547550096863551cf043321c67a5a6952d6c2f422fbfd282 18072 golang-glog_0.0~git20160126.23def4e.orig.tar.xz f7b92a2623ff7fa5299c7ed262a43fe6e99d87597a38f4e7e893967ab991848d 5012 golang-glog_0.0~git20160126.23def4e-3+deb11u1.debian.tar.xz 275fece8e165310566e955afd7bf4a9f74dc5f7d958e580f94ab5d1d4f675412 5922 golang-glog_0.0~git20160126.23def4e-3+deb11u1_source.buildinfo Files: 6fc5d21311094fb890cd9ed0d9a117f5 1650 devel optional golang-glog_0.0~git20160126.23def4e-3+deb11u1.dsc deb29d8c49756785b502ea309a054dd3 18072 devel optional golang-glog_0.0~git20160126.23def4e.orig.tar.xz 27c2ea93402e951a4713ccd825445127 5012 devel optional golang-glog_0.0~git20160126.23def4e-3+deb11u1.debian.tar.xz db8823803671e61fd73633977902e37d 5922 devel optional golang-glog_0.0~git20160126.23def4e-3+deb11u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQSD3NF/RLIsyDZW7aHoRGtKyMdyYQUCZ7He3QAKCRDoRGtKyMdy YWtuAQD6Wj6w3FZBRxldYiJRmPcHiTxXJ9koikst4y7eRoajmQEA6JHTdVTOHj5C eig8bLLXBH3QD64yzlPgiB3JK8A77gI= =tbIn -----END PGP SIGNATURE-----