-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 03 Jul 2017 10:41:18 -0400 Source: puppet Binary: puppet-common puppet puppetmaster-common puppetmaster puppetmaster-passenger vim-puppet puppet-el puppet-testsuite Architecture: source all Version: 2.7.23-1~deb7u4 Distribution: wheezy-security Urgency: high Maintainer: Puppet Package Maintainers <pkg-puppet-devel@lists.alioth.debian.org> Changed-By: Antoine Beaupré <anarcat@debian.org> Description: puppet - Centralized configuration management - agent startup and compatib puppet-common - Centralized configuration management puppet-el - syntax highlighting for puppet manifests in emacs puppet-testsuite - Centralized configuration management - test suite puppetmaster - Centralized configuration management - master startup and compati puppetmaster-common - Puppet master common scripts puppetmaster-passenger - Centralised configuration management - master setup to run under vim-puppet - syntax highlighting for puppet manifests in vim Closes: 863212 Changes: puppet (2.7.23-1~deb7u4) wheezy-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2017-2295: Unsafe YAML deseralization (Closes: #863212). * This update rejects non-PSON client catalog requests, which will break clients running non-patched versions or older than 3.2.3. It is therefore necessary to update both clients and servers for this security upgrade. Checksums-Sha1: 36dee04966a9ea7fdebd418b90dbc481d8eff0ae 2482 puppet_2.7.23-1~deb7u4.dsc 9a1eef4a8756439fe179249c67955a4effad5c42 41570 puppet_2.7.23-1~deb7u4.debian.tar.gz 65d8e5dccef2e42b3f9bcba6b6360b577e8b4d7d 1066494 puppet-common_2.7.23-1~deb7u4_all.deb 66282a379f8b69c09eaf5a46a5686b46b67e828d 278058 puppet_2.7.23-1~deb7u4_all.deb 5cb6611b36a424e42c128d69039b4630769fce9e 274456 puppetmaster-common_2.7.23-1~deb7u4_all.deb 82fbf68e5754c7f1c32f7fbbc7f073f981831735 270816 puppetmaster_2.7.23-1~deb7u4_all.deb ed2c077fb877ae674d2e39e1cb6bf293680313b9 270052 puppetmaster-passenger_2.7.23-1~deb7u4_all.deb 76b08b130ef1e0c369a7f1406d425e93a21facf0 270134 vim-puppet_2.7.23-1~deb7u4_all.deb f43382526d68acaa480e29fdb846cf10e2439362 270778 puppet-el_2.7.23-1~deb7u4_all.deb 8bbdb3c8314adf2be04b5496b80cc649c48fab15 1183624 puppet-testsuite_2.7.23-1~deb7u4_all.deb Checksums-Sha256: d53b074b1a4bf1b8c71afe9894d9e4fe437b7cd30997cf70ba8df5b9800989b2 2482 puppet_2.7.23-1~deb7u4.dsc dec834ce552e9a5f7a12ac62fd51d7fd217ce2298eaaf1bf01041075dc52eee9 41570 puppet_2.7.23-1~deb7u4.debian.tar.gz f757c166c2799a0941d61f331ddbdc9da143dd36507578f178f61853b45b77b1 1066494 puppet-common_2.7.23-1~deb7u4_all.deb c2dfea745d1b364ebc0d06ecf8e09471ec3dea4d75bf57099215f5b968d85fd3 278058 puppet_2.7.23-1~deb7u4_all.deb 6ca882846e0853a868e582c29abc32144a39aafd8e17a1265315007c15e134a9 274456 puppetmaster-common_2.7.23-1~deb7u4_all.deb 58467799b462ffd8a8eecc2e45a178bc90afa7e82874f2fccf162a4d0ade64ea 270816 puppetmaster_2.7.23-1~deb7u4_all.deb 0434b6c566845effd25c5710ede1efad1542d28ddf4b5e7d4bee161dc3209c5e 270052 puppetmaster-passenger_2.7.23-1~deb7u4_all.deb dd5c798fdebdb7f249847c7aa87919a8be2bbc7ead19eb480091bcc638b27430 270134 vim-puppet_2.7.23-1~deb7u4_all.deb f412d46343338dfd476327b9a9d72ff47d2e0962abfb39ce9b7338064322e974 270778 puppet-el_2.7.23-1~deb7u4_all.deb 33da1788dd62f6a58015cc7e61df10a3362e5d5e49c6f1b460b4c362f118a71b 1183624 puppet-testsuite_2.7.23-1~deb7u4_all.deb Files: 65774a46c302656acfed959714a652ec 2482 admin optional puppet_2.7.23-1~deb7u4.dsc 4a74887316ca1a5fe77767dbfa61a4b9 41570 admin optional puppet_2.7.23-1~deb7u4.debian.tar.gz 17d54fcb19162adcac67e870ff6a75a3 1066494 admin optional puppet-common_2.7.23-1~deb7u4_all.deb ca5fcdfe0767c59a1957d11991243b29 278058 admin optional puppet_2.7.23-1~deb7u4_all.deb 6edf911b6776588a260ca47052822afd 274456 admin optional puppetmaster-common_2.7.23-1~deb7u4_all.deb ea29cd125b5e524bd24a084ecbfed169 270816 admin optional puppetmaster_2.7.23-1~deb7u4_all.deb 32930bd74e14f638f97c3ed06e0547a0 270052 admin optional puppetmaster-passenger_2.7.23-1~deb7u4_all.deb f43f55bf853613d60f1875268b60f41e 270134 admin optional vim-puppet_2.7.23-1~deb7u4_all.deb 9aec91200c0463c054d7e06ccf782a9a 270778 admin optional puppet-el_2.7.23-1~deb7u4_all.deb 59fcd53f6c070b6589b6bd0db51484aa 1183624 admin optional puppet-testsuite_2.7.23-1~deb7u4_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEjckBzmQUbASK1Q+7eSFSUnt1kh4FAllaWecACgkQeSFSUnt1 kh674BAAu2O6fxKbtqiTwFe5Xsxhr8VcVDLJG/DOeiw+fzv1/yaCmCORyJlm4ScG nbMxreH9rQ9tn7u+ZUUEXQUvQOnYZ/HpEqjgCWN9XI/6QSVxyWvPN/7J5AxvO+l4 fOMu7lJialKBXBX63teREtdkeJ8BmQF3+xAABg6IUJMrkuozb1QUhwO34Gk6Emfo hsjXl2IRTtNI6+sXMAqaKBFH805CXGiyW0kj8YKpEa2XRZpcOThEk985WKgKAADI SBMjRFl2fKGiwIvlerh5QhA4dQJllBEh3zB8p5prTXbCb01KNwMwCCF4el+hIl0G U4JXuRZ1t2mfHzXbA0mQ+h/Cn4iOJOwpIiAs9z80ZtUJGfVuCxQTmxp9Myo9a3aP pdZ3ZiG5E3orhaYL5YKH+gncrjKL3SFaESK1yE9rXbOCzvZrkH44Y1zSAaiL5LK6 01zasFf926uxWN7p+EKUY3CPL0sW3MS0IqOrZIsjNwiGVc++jyAIPwnzLjubsMUb D7a53UrhL59PeFOA857sGNEoqLm8I6mTEiwpOPhyJ0tFsiICE06SJ+Nv6e2kdnQ0 98y3sZU6k9Y/j56li5eU4cuk97OhSoV6lx6ww60XjoPmlw4b4yRxnG50FqiVSt/M bC/A7d3byluzIrzYLVvc4B/TgJa9B2rmUPWk7MTF4a3txmG1XDE= =o/s7 -----END PGP SIGNATURE-----