-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 21 Jan 2018 16:03:02 +0100 Source: couchdb Binary: couchdb Architecture: source amd64 Version: 1.2.0-5+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.hu> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: couchdb - RESTful document oriented database Changes: couchdb (1.2.0-5+deb7u1) wheezy-security; urgency=high . * Non-maintainer upload by the Wheezy LTS Team. * CVE-2017-12635 Prevent non-admin users to give themselves admin privileges. * CVE-2017-12636 Blacklist some configuration options to prevent execution of arbitrary shell commands as the CouchDB user Checksums-Sha1: bd23c02fc72bc9bfc8c89e0f5117497abc1fa2ac 2070 couchdb_1.2.0-5+deb7u1.dsc da17af99cf3b1f9a89f0051b7d9de0cbd6fe81b6 1326925 couchdb_1.2.0.orig.tar.gz 1605940a1798a8c4422394c43bc0e9149eb8e083 15221 couchdb_1.2.0-5+deb7u1.debian.tar.gz 8590582730219c17b97bfa8463f07fa20d58451c 1037808 couchdb_1.2.0-5+deb7u1_amd64.deb Checksums-Sha256: cae203928fe52fb82e9d71d8a2f1a5182ff0af10757e00848c49a29a5892ebc9 2070 couchdb_1.2.0-5+deb7u1.dsc 0f254ddea2471dbc4d3c6cd1fa61e4782c75475fb325024e10f68bf1aa8d5c37 1326925 couchdb_1.2.0.orig.tar.gz 2d7b4252e09c0b24830b1f4645ab59396e9cbf2ab7a887a92251253a6ecb844d 15221 couchdb_1.2.0-5+deb7u1.debian.tar.gz dcf13c5f46924fa85223367771b201b74c961a974787d054f63c1154cf29b919 1037808 couchdb_1.2.0-5+deb7u1_amd64.deb Files: 35173c3d6c81fb68b0e45640cc61c338 2070 misc optional couchdb_1.2.0-5+deb7u1.dsc a5cbbcaac288831b3d8a08b725657f10 1326925 misc optional couchdb_1.2.0.orig.tar.gz 6b273056d51183ac24a51f25d0f4506c 15221 misc optional couchdb_1.2.0-5+deb7u1.debian.tar.gz 71d26edf77f084d0909e5c2546c8229f 1037808 misc optional couchdb_1.2.0-5+deb7u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAlpkt+hfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR7PjEACiE8s0Ey/BVeH3werMqoZyjV0lIsuz XIIE5hBSE2vfkofoK6yYlvfcDN2bOIvXhdgu8apUbkIMBLcO7Rh1RrET6qvTCKo6 0uX53NH8XzVfOrrUXes5xA7Ks0jjo3WRkXGxLGwXw6x51a8pg13XaNFEVDOjKI+O SB27bJ2XaqK5JaQ4eR8aburIcgdv/EYPhvOsNyBYOf+VLxhXYCiPi6iz1VaWBPl1 Mcw9ZB5Iucce+yx+OkG1O/ODGJmBEzlfp65uBBQiLt6jCAG1i0QkG76X3zcGkctY xQnk+MO/GNwUIeaeONU4/RMUZB0DYGSOyoBrYvxlV0u1VEwUAd1aTBHEu8jgXkPp KgJgGDUECC7wCp91Mnumq6VnZFnQDzdW4ZDtibyiZceCUmrAB4peGe+j8VnJQ6qD JTJPAfY37r7zrTf2TGRPGFxIQS36DRYe+xXO/5NPN8y+KeqLZpmaceZoUgW1YNCu lp8wrFz2DZzjunYaHGtMqsSApCPMOT0h7uJ48dTVpV7mVmtDNnYxjR+u/Cl1dkK2 pB+5aydKRiEH3+4kW1yScNgiYyw8GJRVMMko9wnTV/Dc0Q9+vTlijm40Rqvj6pCW 4xiFlaXquXWQyqjWUlDYVIc9SUOQmLVfRqF+8pAcPOTDI8HOPJldyU3bcet/mHuJ CFjTL+zsMEFLPQ== =O39z -----END PGP SIGNATURE-----