-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 06 Oct 2016 18:57:12 +0200 Source: c-ares Binary: libc-ares-dev libc-ares2 Architecture: source amd64 Version: 1.9.1-3+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: Andreas Schuldei <andreas@debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: libc-ares-dev - library for asynchronous name resolves (development files) libc-ares2 - library for asynchronous name resolves Changes: c-ares (1.9.1-3+deb7u1) wheezy-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2016-5180. Heap-based buffer overflow in the ares_mkquery function allowed remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot. Checksums-Sha1: dd8b450e5130a5aa2aed7319e7317b8b21cf60ff 2101 c-ares_1.9.1-3+deb7u1.dsc fe41e47f300bfd587b7f552a141ad3bf85437b0f 782945 c-ares_1.9.1.orig.tar.gz 2c004ce9d1bede185f34957c413e1bbfc9a9f143 6944 c-ares_1.9.1-3+deb7u1.debian.tar.gz ad6ab319bacc61ea0ff81bf065c4ee254003e036 140894 libc-ares-dev_1.9.1-3+deb7u1_amd64.deb 6ddadec70889f20b38b5aad4145eb30d7f46f77f 74662 libc-ares2_1.9.1-3+deb7u1_amd64.deb Checksums-Sha256: d92976753cc4e15ca86815a850b727fb8aee8f279b444723fe3609622526a057 2101 c-ares_1.9.1-3+deb7u1.dsc 023f28001f2f839645c8700187391a011198950c73ddd91510c7549d87373936 782945 c-ares_1.9.1.orig.tar.gz 18743f3fe1c6091a7e961c4304b6bd99b5e60038f2c9b0aa83d66e4a736e0fbb 6944 c-ares_1.9.1-3+deb7u1.debian.tar.gz 703508c00ed9c1eea1a925d03bf3629539e96345f3cf5e218da8f38e251abef2 140894 libc-ares-dev_1.9.1-3+deb7u1_amd64.deb 77bda7ea2575d8141e3f682d1e2f74703efe334180c6dbe85ef9cbd4374a4af5 74662 libc-ares2_1.9.1-3+deb7u1_amd64.deb Files: fcf6880a9b25e2fde113c692ac7319a7 2101 libs extra c-ares_1.9.1-3+deb7u1.dsc 389db4917a3b58c4ce4ebfe961fd84c4 782945 libs extra c-ares_1.9.1.orig.tar.gz e2a1f7b22cbf8119bdb0f8db57d2fece 6944 libs extra c-ares_1.9.1-3+deb7u1.debian.tar.gz 4602284b15f37302c2948eadf73dfbbb 140894 libdevel extra libc-ares-dev_1.9.1-3+deb7u1_amd64.deb 4867b298b98fe1ad3a11ed6d529f0597 74662 libs extra libc-ares2_1.9.1-3+deb7u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQKMBAEBCgB2BQJX9pVOXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRBQ0YzRDA4OEVGMzJFREVGNkExQTgzNUZE OUFEMTRCOTUxM0I1MUU0DxxhcG9AZGViaWFuLm9yZwAKCRDZrRS5UTtR5EyREADF CK9QANsbfAxTHE+CGzIDhIGWDshHF3Ty1vgIZSyxUWQG4eN+/LaO4Y8RqZKLg7uA WkLkEde4GNwUGvFvexLUEgxt3PpnmuIw0RdxjfHOeUDMiZfo9gEvz5+TvBNMAyXI y7DQrfe4toUdXRrNZUiJFYKzkCSv7iBBMPe/KBPsWJLZQRVR7NYprGELZYeHgMkV t9AN2Mdo7CjdGqT+RB9sfJ8l+5JNwLsz9N3fIUdVkeInwwolu6UgAAOX9LfXIRW2 NBazSg0XzM4tgWn7td7x+kCG5Rsnc6SpBuLWrqFb9OQz1FlDvoNEq6ORtySAjAYA VaZFDi7GwHEyoiCBtapdPxt5QgKwmQHH1xnhT6+ghfi6e4vxbO7KOdf22i3Wj7GS R4X2q6aXU607fTKuaOOd5UyONqMCVcZeOBlbHGEqoFjl8JoUpmih08ulxtc1pFcq M830PoPdh1qgM6MwHjv2oeriE49KpBwyc7vxY/UWQHfl3qYRsi0cgZ/M8MVwNJ3F WBdVweBGxmrIHJ+oBWVJefBFmz4Vl1yyajqubM9dKO6PIcIlw+vBWN656OgIFdYS 0ksjugrNiaxCtVMD7xZ38J/hXc0IFmWEKc7uzwPdaZ2UM2K8vhz7HNviwwp70cxO UXKE+kEdNEGUlG/vyVMdTRA1U4yF0TZnDluPO06piw== =apUF -----END PGP SIGNATURE-----