-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 Oct 2017 17:20:45 +0200 Source: dnsmasq Binary: dnsmasq dnsmasq-base dnsmasq-utils Architecture: source Version: 2.76-5+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Simon Kelley <simon@thekelleys.org.uk> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: dnsmasq - Small caching DNS proxy and DHCP/TFTP server dnsmasq-base - Small caching DNS proxy and DHCP/TFTP server dnsmasq-utils - Utilities for manipulating DHCP leases Changes: dnsmasq (2.76-5+deb9u1) stretch-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2017-14491: DNS heap buffer overflow * CVE-2017-14492: DHCPv6 RA heap overflow * CVE-2017-14493: DHCPv6 - Stack buffer overflow * CVE-2017-14494: Infoleak handling DHCPv6 forwarded requests * CVE-2017-14496: Integer underflow in DNS response creation * CVE-2017-14495: OOM in DNS response creation * Misc code cleanups arising from Google analysis * CVE-2017-14491: DNS heap buffer overflow (further fix) Checksums-Sha1: bf88fdfe5d54b88a5fa6ff7ba7305db7df96e54a 2059 dnsmasq_2.76-5+deb9u1.dsc 5c01ce7d21ef9fd7f4598633960d1cb9473a7105 697687 dnsmasq_2.76.orig.tar.gz 89cd8528cbe921f7deedeb7edc362f324f0bc59a 27093 dnsmasq_2.76-5+deb9u1.diff.gz Checksums-Sha256: 3bd12aefea3b091f3b5c7c39cd8ff7f04192c2736f1951b206c62872468e309e 2059 dnsmasq_2.76-5+deb9u1.dsc 61a6e9cdc236dde71f4e7d117cd56404a6d878e45556799c497a057b21108208 697687 dnsmasq_2.76.orig.tar.gz 9419570a43eb9a041e4617c8f9c4985eca54f2db160611c9a5fe168b14ffb822 27093 dnsmasq_2.76-5+deb9u1.diff.gz Files: 58bdf87d900ace7b8023c34bad637129 2059 net optional dnsmasq_2.76-5+deb9u1.dsc 29744393167540affaef0539f30fb0e4 697687 net optional dnsmasq_2.76.orig.tar.gz dd5bcd6ccfe11316f9067c3410ea7f0e 27093 net optional dnsmasq_2.76-5+deb9u1.diff.gz -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlnRUfhfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89ELioP/jalnloghIQ3c0MqjXMhTQYKaVxcx/Ag ZwXamcxbpdRYm2bRUiX/qdwZAPAAHRSJcFeq1FYBSs7m4ZzIW3v7bUDx3Ym+wYp4 HDTIyy+wcnO1F+tW4ylPk3SFd0hQkG1o6Cjw4iGzyothFcjk8U5sIJ+6Y8ri/Hqt RKKaySRzfg4J/rdei4OW8YiHGcWgkwuLEfOkS8lPdDqjcG7stVaIp+G6APwL40cM 17/hIyGZUkChj83pX2DM+zAFST6Vvv/fpfhx3tEO9bt7mNUjXFnQyh5byOub8od9 g1kcxt3dQ7KnjXt0R1wM8XEDpU5oTgtASDFIW+4USdKdkeETzvEgoIxenkNg5L3i EUFaVKuuFp6qWYShD7gUthBpFRal9whnB4LuF45LDD4dZPpLg/nsr4VkHG2U684E 8oWTE93hnia0NYlGivWgqzNSqnrDsI/SkR9Rk1CBWZHWDsA1OxTYoi4n3Zsxsguo uRIUjlCYFfJo2BSNtHnZm0wqt0Rcz3SHAwaiR3/8E0kERnj/wS1+yr+vVWlOC0gM Rc6R6fkw0k/L52debD0fuFqaSqkHMazS3zbH36HwA9/k+bGwXfAKSb/9AUEPfoOz 1InqnxcF8b1RZYtFz1prAEngBe9qgctOjCvj/Cf3QeNjMYk1Y6AhyrzeAXR8Jp3p q3MSOeIYx6gT =OOuu -----END PGP SIGNATURE-----