-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 19 Nov 2017 00:50:34 +0100 Source: procmail Binary: procmail Architecture: source Version: 3.22-25+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Santiago Vila <sanvila@debian.org> Changed-By: Santiago Vila <sanvila@debian.org> Description: procmail - Versatile e-mail processor Closes: 876511 Changes: procmail (3.22-25+deb9u1) stretch-security; urgency=high . * Fix buffer overflow in loadbuf(). Closes: #876511. Reported by Jakub Wilk using American Fuzzy Lop. For reference, this is CVE-2017-16844. Checksums-Sha1: 0173d72fcd61cda46ca66363939704e40b4b6195 1348 procmail_3.22-25+deb9u1.dsc cd4e44c15559816453fd60349e5a32289f6f2965 226817 procmail_3.22.orig.tar.gz e4d6f9cb38c29d11521fd081fca75adeeb2486d5 20148 procmail_3.22-25+deb9u1.debian.tar.xz 548c5a66172301a584512f2efd1973b95cbaf81f 3983 procmail_3.22-25+deb9u1_source.buildinfo Checksums-Sha256: 82a68568288e4a90915f03061475c3f7751bec8e3e4958f07820804d7076607b 1348 procmail_3.22-25+deb9u1.dsc 087c75b34dd33d8b9df5afe9e42801c9395f4bf373a784d9bc97153b0062e117 226817 procmail_3.22.orig.tar.gz f5b5b88ad0227fe17550112cc6904a0f7cb4c518dd7e880d77ed262e8e0d512c 20148 procmail_3.22-25+deb9u1.debian.tar.xz 6f5593d3e204161253b0ba2bbb49501896fe6fba23d97ef071509c8264370692 3983 procmail_3.22-25+deb9u1_source.buildinfo Files: e590abc5c0af8037cc94bb9505ad1e43 1348 mail standard procmail_3.22-25+deb9u1.dsc 1678ea99b973eb77eda4ecf6acae53f1 226817 mail standard procmail_3.22.orig.tar.gz 7b2168bea67bf9d4cbb1278fa630d1d6 20148 mail standard procmail_3.22-25+deb9u1.debian.tar.xz c3d8efc6dc9eac9c3ca0b3a48c44e73c 3983 mail standard procmail_3.22-25+deb9u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEE1Uw7+v+wQt44LaXXQc5/C58bizIFAloQylQACgkQQc5/C58b izIhQwf+PoCH4TP8TA/Okagbl+R2xRzJt9jPioTkZ5HoNTHXaznWNx6OIkikheFV dr0up/szJuGh7yazL7nyepylWEgs5AgBvmHCt+LJv+EfRrrwG+dOlqBj6bsOkl+r MOIdiOWNH6VI25dsyLoPEGjlSFDjFuqbWmTeyfyqatIaJEwWTtqvjr9Oy9CJzh8G OQfEQIW8IagM7T7qik/34dMFGktQdFpDboBZUb2Ztk6EALcUKtPOMHxRfFQZcIgw NZLic2y84aQfZYwW9Ids6yX6tps36XQnZcLETd3hzCoS55uiOP4DtP4N1WP7hr3/ ejg4+JKEz0F3XIk4LIvtXv9DuwMQjA== =7OCt -----END PGP SIGNATURE-----