-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 22 Jun 2017 18:07:12 +0200 Source: c-ares Binary: libc-ares-dev libc-ares2 Architecture: source amd64 Version: 1.9.1-3+deb7u2 Distribution: wheezy-security Urgency: high Maintainer: Andreas Schuldei <andreas@debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: libc-ares-dev - library for asynchronous name resolves (development files) libc-ares2 - library for asynchronous name resolves Changes: c-ares (1.9.1-3+deb7u2) wheezy-security; urgency=high . * Non-maintainer upload by the LTS team. * CVE-2017-1000381 The c-ares function ares_parse_naptr_reply(), which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way. Checksums-Sha1: 358dc5495acdb57db56f617665f1e173c9cb7d68 2138 c-ares_1.9.1-3+deb7u2.dsc fe41e47f300bfd587b7f552a141ad3bf85437b0f 782945 c-ares_1.9.1.orig.tar.gz 74a6589b23fae8b6ef5123b9d34804f713774d99 7529 c-ares_1.9.1-3+deb7u2.debian.tar.gz d9b103443229f2db69f34195d65caaf70920c797 141020 libc-ares-dev_1.9.1-3+deb7u2_amd64.deb a6680030523e2c97b881ea97b581e8957e6e702a 74586 libc-ares2_1.9.1-3+deb7u2_amd64.deb Checksums-Sha256: cd606216c3e523e07152e0ba77b813c27e48afdb1212666e8d25e8c6557f299b 2138 c-ares_1.9.1-3+deb7u2.dsc 023f28001f2f839645c8700187391a011198950c73ddd91510c7549d87373936 782945 c-ares_1.9.1.orig.tar.gz 4a769e78ad9a71969759ebc314c9a64aa97e936f433888798b6839207dc37423 7529 c-ares_1.9.1-3+deb7u2.debian.tar.gz b38aeb781b6223a422113ae6c225e842cf1234c0900acbfcf765ea3b2e43c0a8 141020 libc-ares-dev_1.9.1-3+deb7u2_amd64.deb c5e4443f02a02bda4f1506e9faca6e405491463c7dc289a7a309bf5925da50b2 74586 libc-ares2_1.9.1-3+deb7u2_amd64.deb Files: a46db3233c5b9691f54e558c916658dc 2138 libs extra c-ares_1.9.1-3+deb7u2.dsc 389db4917a3b58c4ce4ebfe961fd84c4 782945 libs extra c-ares_1.9.1.orig.tar.gz 72f6b34ed112dd9ac4a39214da6066c7 7529 libs extra c-ares_1.9.1-3+deb7u2.debian.tar.gz 20934b4d0f716c7bd497def38e4c56b5 141020 libdevel extra libc-ares-dev_1.9.1-3+deb7u2_amd64.deb 731e20e5df22120303038062fa7e9205 74586 libs extra libc-ares2_1.9.1-3+deb7u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAllMAE9fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR4sYEACIkxzH7ZSrwJa4Z0gWhBqa7GIS+buZ WwtvqTAik9STHikF4zFeBCKbUj3Jah0NcnWB3JJy1SfSUIL9IAcTKTyiyLgb1P1O wjQLNXVoQ6iGK2qW1gRtPPQ44Dr8mS0bxB9OkqggRFNcQaGKy1hkvUmfgIKrhEbo DPqwIpdYHl9ejE1U6/DtBtCb0pWU1VRfH+qFGmPyFoEvrYB9yl201lgrUYq0RbKn S2d/L4jFGdB4NhREggesawjev8Fu/TOq6QElJCjLDyeshT1TlO5eobM+UrKKVeXB S74L9KxuRgBMDfxxuWBzVMs6Y+2HC5FL5Xo/gICew8yc0z3a87FQZIzkEklAjKXC p9UzNl/Abeslb3hxOfJTM/KEXsZKRFfZi8olTsUOQLcV7ebLiEAMgTI89Vrj5Gfg zClITTAb0wHHsSgq/gzeDrR7jjLLPMeth9S/nqtRPw598xbkCi6m3ec184tU6VU1 QqfR/pu8gtu1laFjvQaFCRMSCqlioSzpPbR2SIkhlNZXKdVjX2JqKIthLNEGA/iX w2d91LMB2EHyBKMvxO5nMf3EgOMDuu8Ci+Th+KCwrYuUOsRmOTabNDtF9Y+uJ9tH n9P2STag93PfO0/ZfAiZ8/57/d1JjhoCiLnUyyXAXv/UF0yC4S/aC940lX0lcjo0 GIhIvbgdItpI6w== =jE2t -----END PGP SIGNATURE-----