-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 28 Mar 2017 10:29:15 +0000 Source: apparmor Binary: apparmor apparmor-utils apparmor-profiles libapparmor-dev libapparmor1 libapparmor-perl libapache2-mod-apparmor libpam-apparmor apparmor-notify python-libapparmor python3-libapparmor python-apparmor python3-apparmor dh-apparmor apparmor-easyprof Architecture: source Version: 2.11.0-3 Distribution: unstable Urgency: medium Maintainer: Debian AppArmor Team <pkg-apparmor-team@lists.alioth.debian.org> Changed-By: intrigeri <intrigeri@debian.org> Closes: 858768 Description: apparmor-easyprof - AppArmor easyprof profiling tool apparmor-notify - AppArmor notification system apparmor-profiles - profiles for AppArmor Security policies apparmor - user-space parser utility for AppArmor apparmor-utils - utilities for controlling AppArmor dh-apparmor - AppArmor debhelper routines libapache2-mod-apparmor - changehat AppArmor library as an Apache module libapparmor1 - changehat AppArmor library libapparmor-dev - AppArmor development libraries and header files libapparmor-perl - AppArmor library Perl bindings libpam-apparmor - changehat AppArmor library as a PAM module python3-apparmor - AppArmor Python3 utility library python3-libapparmor - AppArmor library Python3 bindings python-apparmor - AppArmor Python utility library python-libapparmor - AppArmor library Python bindings Changes: apparmor (2.11.0-3) unstable; urgency=medium . * Fix CVE-2017-6507: don't unload unknown profiles during package configuration or when restarting the apparmor init script, upstart job, or systemd unit as this could leave processes unconfined (Closes: #858768). Changes cherry-picked from Ubuntu's 2.11.0-2ubuntu3: - debian/apparmor.postinst, debian/apparmor.init, debian/apparmor.upstart: Remove calls to unload_obsolete_profiles() - debian/patches/utils-add-aa-remove-unknown.patch, debian/apparmor.install debian/apparmor.manpages: Include a new utility, aa-remove-unknown, which can be used to unload unknown profiles. Based on an upstream patch but adjusted to source the /lib/apparmor/functions shipped in Debian/Ubuntu. Checksums-Sha1: 2ef5a755def67ee644ba7d5440071951554b6277 3098 apparmor_2.11.0-3.dsc 5c427fb74c1f2ce3acb9f731e1265f44c43e491d 82112 apparmor_2.11.0-3.debian.tar.xz Checksums-Sha256: 9214a631718111bf2a15830bde3ce709ed0f2de4a0d8779a5be47f40bdaa6464 3098 apparmor_2.11.0-3.dsc 25857dcef3e0866de64545c12b4ed328ed75d7b98462603bcf766b13882a8c66 82112 apparmor_2.11.0-3.debian.tar.xz Files: 632d877fb58a4126c16a3a68fd83b145 3098 admin extra apparmor_2.11.0-3.dsc 56f5e337a2acb12f9d44529badcf346c 82112 admin extra apparmor_2.11.0-3.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEcMAxqZeuB0p8dimNy2kI2AAOzf4FAljaRa8ACgkQy2kI2AAO zf5IxQ//T2wmwtexipxEmwlyh/HKOPSRJyq3TmgXt4Or+5yzCVPruSQRkBR8PQp0 CIDascJB+Q7lC+WIlIX/oicUYRjHWkLGyfpNJ+cjbfK9BJtJnxoOyx0AcaHVyO+2 Aucea8R3wa2qZzzFQKlJPd/JLkSeA+DWNKdwFW38vhbKM7HCtGtIhv3YYtnqXwFt SiNuuE6MAsfy7UqxQrCBkR5rchEG3HfY6UBgo6EBxfcMtvIF1RaMVuNVsoU2FE+X o1QzxPdCt5PE7cmyLTT2NRyJZT0q4FNrrXBx932bAME+8ABvieKPoVSoXe0SwUDo hc6r4HYX4Qn1XNAAte0MQERP61TwnLjLAH5+JlJmdWzoIV2IJknd/aQmu43y8Vtd 0Yy6NybY+1I8Aa+O0hZWDrTBs7ABVP+6XjBWB9f0z0v+pRkETKO39UbKc/vZMQ5g z836V+3NYsQpTw93cgB9JPtAUr9OqRqo9XxrkBDX00oaE+IRnpCiwWRTJLloDvSj /e3q/4f69KR14ryrFqIrNmmYw22aCdkJTTOAy4+ouKTRvBQIS5ThY+BC8AsKeT7s ZvAajnmRt5WpPiVYs81wjL57jNGInTjtNm0WX4Ykwtef7O7xdq/HcyGpCmcwP4ip vwbz4+bYxJ7gCgLnhlvbau3U56Y55jm5qK+3z14DPzmGF0WaN20= =4taG -----END PGP SIGNATURE-----