-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 04 Apr 2017 16:45:15 +0200 Source: collectd Binary: collectd-core collectd collectd-utils collectd-dbg collectd-dev libcollectdclient-dev libcollectdclient0 Architecture: source amd64 all Version: 5.1.0-3+deb7u3 Distribution: wheezy-security Urgency: high Maintainer: Sebastian Harl <tokkee@debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: collectd - statistics collection and monitoring daemon collectd-core - statistics collection and monitoring daemon (core system) collectd-dbg - statistics collection and monitoring daemon (debugging symbols) collectd-dev - statistics collection and monitoring daemon (development files) collectd-utils - statistics collection and monitoring daemon (utilities) libcollectdclient-dev - client library for collectd's control interface (development file libcollectdclient0 - client library for collectd's control interface Closes: 859494 Changes: collectd (5.1.0-3+deb7u3) wheezy-security; urgency=high . * CVE-2017-7401: Fix an endless loop DoS vulnerability in parse_packet(). When a correct "Signature part" is received by a Collectd instance configured without the AuthFile option, an endless loop occurs due to a missing pointer increment to the next unprocessed part. (Closes: #859494) Checksums-Sha1: f27d4481563a30cf163362eecd9a8f40c7bf1456 3319 collectd_5.1.0-3+deb7u3.dsc 55f17b17a10710641a9bf4e8c5332cef661cafcd 1630323 collectd_5.1.0.orig.tar.gz b0205b4279c19a58a32033c3d9909fd4128f1c16 72374 collectd_5.1.0-3+deb7u3.diff.gz 10f2f26ffa00879810cae42317e7a4596ca50745 915750 collectd-core_5.1.0-3+deb7u3_amd64.deb e1cc552d65182fb90276f12fbe28b366fac7f080 76876 collectd_5.1.0-3+deb7u3_amd64.deb 9a208840ff9deb42a5fb5b48dc37555cd5fc7a28 88538 collectd-utils_5.1.0-3+deb7u3_amd64.deb 3ef0a40fef1f20cdc7a1c3f2916999b9bd200471 1349364 collectd-dbg_5.1.0-3+deb7u3_amd64.deb e6ba37d0d0e26b5e9e8c656c8ef1fb769c3161d1 71432 libcollectdclient-dev_5.1.0-3+deb7u3_amd64.deb 37734e82799af7e48c83dcc1f2e8836893f887de 77940 libcollectdclient0_5.1.0-3+deb7u3_amd64.deb 91659bef3dabdfcf311206e55e17ba493bf16bed 112812 collectd-dev_5.1.0-3+deb7u3_all.deb Checksums-Sha256: 00d8f21dae7b850d52da9dd7937e0703f68621ee076318913ffc9674fd332372 3319 collectd_5.1.0-3+deb7u3.dsc 8e06c03c5467f3021565570fc86c931a43579aa6dad25ca5999d66850cd19927 1630323 collectd_5.1.0.orig.tar.gz 38795ffb3a6edffdab01516825d62e98ca9681036d98b717b9a6c4c18cfbd525 72374 collectd_5.1.0-3+deb7u3.diff.gz 29f7fc252ae0d404004244c25fdb975ac788fa2b8bb33bbd4cac34f7d05cc66e 915750 collectd-core_5.1.0-3+deb7u3_amd64.deb 825af876d583e2a4f661664b7d0c455bf155bc24f0c6c0b4d6d8428ae9f0dbf7 76876 collectd_5.1.0-3+deb7u3_amd64.deb c60dcc3bcbfa5f282f571b0962843a8d2a669ef47009b2934e00e99b37408e23 88538 collectd-utils_5.1.0-3+deb7u3_amd64.deb ac3612105deff578143929305ae4411cc6fe1eda7db12ec119904e48d91f0621 1349364 collectd-dbg_5.1.0-3+deb7u3_amd64.deb 7d80b72b54b633ddd21fc44a60c691c9719f879efded200354836036220612a5 71432 libcollectdclient-dev_5.1.0-3+deb7u3_amd64.deb 9ce535a8711a7ae0134286fe205ebc7cf1d0880aced50affb7696c6840b21a11 77940 libcollectdclient0_5.1.0-3+deb7u3_amd64.deb f9a9270679539eea70382d0711bb50e991ec271acdb003716b4cd9c479462897 112812 collectd-dev_5.1.0-3+deb7u3_all.deb Files: 6681a424bb517875fb00323fbaaa4ef8 3319 utils optional collectd_5.1.0-3+deb7u3.dsc adc58a0d448a359ecf737da9398898c6 1630323 utils optional collectd_5.1.0.orig.tar.gz 9e39e11dd4081f180fc575ef2dfaa494 72374 utils optional collectd_5.1.0-3+deb7u3.diff.gz 7cff8fbe01d5248814ed222eb42d6cc7 915750 utils optional collectd-core_5.1.0-3+deb7u3_amd64.deb 79a06641bd4de0508b7a16f78bf43690 76876 utils optional collectd_5.1.0-3+deb7u3_amd64.deb b6d639bcf8cd458f7a0a05ec04fecf08 88538 utils optional collectd-utils_5.1.0-3+deb7u3_amd64.deb 9a90a5bc99aa04915a21615cd442675c 1349364 debug extra collectd-dbg_5.1.0-3+deb7u3_amd64.deb 9e0393ff998b58b4ebc6411ba0d0b7a0 71432 libdevel optional libcollectdclient-dev_5.1.0-3+deb7u3_amd64.deb de52e47f3ee7caf212d5fc1dfa8546cc 77940 libs optional libcollectdclient0_5.1.0-3+deb7u3_amd64.deb 4c0e955cef13fb3e0b71a7e77c9c2cef 112812 utils optional collectd-dev_5.1.0-3+deb7u3_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAljjue8ACgkQHpU+J9Qx HljxWQ/9FwHOuXEHC46zt6Xk1DO8SNyFLr0k6vi5lTLBT89dKrwpt4Z7mUGnW4ZB CnBbnvpQR+sjNZUlYektAhkvfi6pffyYjQ6RceuVd5MU8JQdfcC2oTJ6OPZ213t/ ziDC+gAv8Sgcgmk8KDKB8rRZUIiF8zwbroOSHsuGahkQcBD6uCnpkzAE1JvMIhdW z+2UeiBjj/MYmCR4wJB11fO2c19fk3LHtOtsgd3n/OiXAYUKF/+ZioBy56zUmmsP 59pQdYNjZhWf+YjcWNj9w4/nJfjRUOrwqLBBKMp4d5PB3zSz8LbVAr26mB3eO0MT znbmORQJCgn0DYEsabdYE2YSWj7mQ0VSM7+DZoLjbbHuolg3v6oZBRNptkCd3p6t 5yQzHuls64fP8HjxjqAng4logIlgUeOs333rMhtK3LwsTn2ZYnvsfOy3YLQJZto4 +rPgVjMi3ByMrHh+yiJW4RpMuBcj9UDg3hI2Ov9JvQreLRqzqDyvkfudEQx5TJbr EufZkzRp2QiNEtFnT4TJLsD+uxB2eHWpKvrvyOnO72Iv5ikpXZPp6Cu+CGmwm0H3 HbY3zI6qXhmH5Jve8dHB0eHrtjLY7ViAtj7mz+UkWhxhO3y0AT/tfifE9ORuwEkb j2qfj41nhVRfGZMqBrP4Y4JrvdbtwjyzCKSU38WlMfVXH/9Vits= =lFnB -----END PGP SIGNATURE-----