-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 11 Dec 2025 22:25:07 +0100 Source: paramiko Architecture: source Version: 2.7.2-1+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: Debian Python Modules Team <python-modules-team@lists.alioth.debian.org> Changed-By: Bastien Roucariès <rouca@debian.org> Closes: 1008012 Changes: paramiko (2.7.2-1+deb11u1) bullseye-security; urgency=medium . * LTS team upload * Fix CVE-2022-24302 (Closes: #1008012) A race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure. Checksums-Sha1: 069f6d8f5d67f009f13ee2400e791f68762a4330 2672 paramiko_2.7.2-1+deb11u1.dsc d09ec309dc298ac52af1fd99c560ce68a0402903 1069537 paramiko_2.7.2.orig.tar.gz 417df57e99aa63a43b538fde2877ad311a7bb2d5 455 paramiko_2.7.2.orig.tar.gz.asc a58f8d18f086c760c9b03d46ec60064504c06841 10356 paramiko_2.7.2-1+deb11u1.debian.tar.xz 804aa035405e41168738e97bd01e175adc7b23f0 6190 paramiko_2.7.2-1+deb11u1_source.buildinfo Checksums-Sha256: c3f40cecf8ed8dae41bd8925eab74618f48c9f6b779efbae14aa7437cf1e3b72 2672 paramiko_2.7.2-1+deb11u1.dsc 7f36f4ba2c0d81d219f4595e35f70d56cc94f9ac40a6acdf51d6ca210ce65035 1069537 paramiko_2.7.2.orig.tar.gz 7e08a54b6fa93ad84fdce56cb4822a91ac08164f64fde6e64793c1e636fe93b1 455 paramiko_2.7.2.orig.tar.gz.asc 4051211b2bca790784b67aaca2edc2d6c98ff97f700b9bd8bdecc3312bf2eb9d 10356 paramiko_2.7.2-1+deb11u1.debian.tar.xz 6daa50f7e799e232b4247b6b397239f0d35e1c2fb825d7d3e38bfcdbe750f606 6190 paramiko_2.7.2-1+deb11u1_source.buildinfo Files: 22ec44f16ec820bd2942a03836d518a6 2672 python optional paramiko_2.7.2-1+deb11u1.dsc 44136d79da4cd7619e368018ad022619 1069537 python optional paramiko_2.7.2.orig.tar.gz 7d6806113fc07a14197859cf1a45b935 455 python optional paramiko_2.7.2.orig.tar.gz.asc b1dfa99ac26d8a71bedb8289a333fdaa 10356 python optional paramiko_2.7.2-1+deb11u1.debian.tar.xz d5d93de3411c691deec9bbcefe579b2e 6190 python optional paramiko_2.7.2-1+deb11u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmk+/fIACgkQADoaLapB CF+PFA//WLcwv3jE/7lGmryG+zRlW1tz+RFNyFd0d6xJY4g4KgSGJTx10MImwoYJ mjisDLnIn9q70xwH5zX6dcPN49REH9Zx7QTmik/IWt2hAvFFJUwIL1MvqSdExlde hEMKFXmVwnyja2Is/npSKE968PUFtxdMk7MpV/17yKvpOVnDTDiKj7N0eWVJrCas 8rMDAcKPCC79AZOZBe610LtTO9v2ITiro2Y4NxlR6Y9yG3IQLKzLsQ2390vlUAHg Hm78vJKNt47ROQcVC+tIxgDo49UXDBWTOGjzewLYWkLr5VNXKk5dX0PZp4cijePW UIJ0KsaBx2jkX04UgLvY3hhw/e8J9WQlk+Lkktmmp4ycAwzzVcu1zhaOQRcsR6Ls RDfxtiLkHRi+VMS6wl+vcpaSL3gui2f8OYEp9WPEVl7PaQPw+IsDLqye4NEvLxfx VjC1iFH9o2gRSFLpM06R9JD3UJd0G10/X/IEeIw7Y7OywE5/1rgOtXGfZ5eUYdb/ rEbWGmo7klEUQ1WH5Dr7ezp0ckVCUBtMhWvTlwShGUMgL0hTQdKEBMzUXE8ABO1w dX/SqYfR/SGibrplYqX3Ja7QJSw6+ZGOlno29nvFqUvux7vaKve9u9d/PQR3ii/5 OPnzn9cMXeZ7xeLZ8ydd9p5jWaDOfCnlQ84D+fCWlnUJ3tOU9pU= =f5Me -----END PGP SIGNATURE-----