-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 Oct 2017 19:14:59 +0200 Source: dnsmasq Binary: dnsmasq dnsmasq-base dnsmasq-utils Architecture: all source Version: 2.72-3+deb8u2 Distribution: jessie-security Urgency: high Maintainer: Simon Kelley <simon@thekelleys.org.uk> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: dnsmasq - Small caching DNS proxy and DHCP/TFTP server dnsmasq-base - Small caching DNS proxy and DHCP/TFTP server dnsmasq-utils - Utilities for manipulating DHCP leases Changes: dnsmasq (2.72-3+deb8u2) jessie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2017-14491: DNS heap buffer overflow * CVE-2017-14492: DHCPv6 RA heap overflow * CVE-2017-14493: DHCPv6 - Stack buffer overflow * CVE-2017-14494: Infoleak handling DHCPv6 forwarded requests * CVE-2017-14491: DNS heap buffer overflow (further fix) Checksums-Sha1: 022e6e3fa9bff68c3d5b9331ebbc96dad75a23d6 2059 dnsmasq_2.72-3+deb8u2.dsc a36b56f54911e4f1ec3b511eb800611da4c591e9 24651 dnsmasq_2.72-3+deb8u2.diff.gz 33d77f9be8115b435502469b5cb927b02945c5e8 15826 dnsmasq_2.72-3+deb8u2_all.deb Checksums-Sha256: 961bb5a12eae727be9a49b1447336914325787c4d13a52934aaa0c3b0108e671 2059 dnsmasq_2.72-3+deb8u2.dsc 8eac72c6de2ea5e094fd201684f0a0311bebabc4a743b314efe1b4b092b2b053 24651 dnsmasq_2.72-3+deb8u2.diff.gz fe35e04c65015833d143fa6a83a353b1eef679be27129a184efbed2dbe2dc6b3 15826 dnsmasq_2.72-3+deb8u2_all.deb Files: a6378a9775f4f2b1cae88029a3c79b53 2059 net optional dnsmasq_2.72-3+deb8u2.dsc 5737011efa9ca2ac6aaf52c6106f429c 24651 net optional dnsmasq_2.72-3+deb8u2.diff.gz 931849870505fac0045954bb89db655c 15826 net optional dnsmasq_2.72-3+deb8u2_all.deb -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlnRUlRfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89ElzYP/AgPiniJv0mp3KiB7nEEnpO6AoeikhtX UGh4v6vx7HIxApv8lPPFR1SUZGciTaGejEKSsHXvwlsRV/RQLhL15ZqP3ehJ1b4J 2SU+o1YaYAYkWKQ8wY4I8LDFcD1qQ3mEYVoNogCOQENz5OfvR7EizJYJ0OjEZoCh A3e5CPM1lQo5ft+PXxLRwxaacVKr5jLO0gTIN5vw/owcjwwacn9IyezsTIY0P9rT LgunX9h0B7DT82mLh4zwYwE94FmsdkcPTNXfsiHQGhEuTGWH0mkjmlRtwccR3NHW a4lzaxDxwbXbdKumkH9pTgySiH5cpu82SKqUjKG27gA9IKD2E/tnXkkTKvcILsv8 B94NbQQSjV2KvtxtxreGdolSdb0ModEtaMVzB1+hfObf4aiE4uHwiGOGWRVU0zJf PkJznzNDKbt2pHiH5ZM7eCkMgDAB2z7kKOtmSwY1PvZdvB4S1jYmBDHyO758OcsV eq28gpOff/OVRgKPQKR359D1zI31tOtU97jZXn0sSV9kkGHj7fkLJ/CoG3KaX/4E 8hu+IxazUqOp5XBc026Amq/2zKhL2VOoqXm9AtIBmOiJqIkuD1LYRhehuWi9DHcA 710gLzANHFfKlWZWeOnSh43u1OdVYxIUlTqT+6Kqz94tUrxwNRGs/9HDI+flnpdJ kj4uazG9HcZz =UkuK -----END PGP SIGNATURE-----