-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 15 Sep 2018 10:11:57 -0400 Source: 389-ds-base Binary: 389-ds 389-ds-base-libs 389-ds-base-libs-dbg 389-ds-base-dev 389-ds-base 389-ds-base-dbg Architecture: source all amd64 Version: 1.3.3.5-4+deb8u3 Distribution: jessie-security Urgency: high Maintainer: Debian 389ds Team <pkg-fedora-ds-maintainers@lists.alioth.debian.org> Changed-By: Hugo Lefeuvre <hle@debian.org> Description: 389-ds - 389 Directory Server suite - metapackage 389-ds-base - 389 Directory Server suite - server 389-ds-base-dbg - 389 Directory Server suite - server debugging symbols 389-ds-base-dev - 389 Directory Server suite - development files 389-ds-base-libs - 389 Directory Server suite - libraries 389-ds-base-libs-dbg - 389 Directory Server suite - library debugging symbols Changes: 389-ds-base (1.3.3.5-4+deb8u3) jessie-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2018-14624: The emergency logging system is affected by a race condition caused by the invalidation of the concurrently used log file FD without proper locking. This issue might be triggered by remote attackers to cause DoS (crash) and cause any other undefined behavior. Checksums-Sha1: d0d04c889de9e620e668b0f55fe986fe1877ca0c 2277 389-ds-base_1.3.3.5-4+deb8u3.dsc 4ac8b76b32af33427f280dee4b66854a383685b4 35344 389-ds-base_1.3.3.5-4+deb8u3.debian.tar.xz a72f9c0e0b4e0fc582a4ef6a8d73db421e6222c0 16370 389-ds_1.3.3.5-4+deb8u3_all.deb efaac19ba70fc5fcf16e454abe1aa117b8c0ee7f 387042 389-ds-base-libs_1.3.3.5-4+deb8u3_amd64.deb 850ce398a40eba3d96fe5341bed4239a0acd612b 1282998 389-ds-base-libs-dbg_1.3.3.5-4+deb8u3_amd64.deb f23ad2000270cd1c74f128d03c15dfc5edd12ef5 69618 389-ds-base-dev_1.3.3.5-4+deb8u3_amd64.deb 6f3c3b6f7bfb2a404e425983456ba8559ec0c671 1455770 389-ds-base_1.3.3.5-4+deb8u3_amd64.deb 94bb10fc45cb073a0e15622593a29577f916e2a2 4182226 389-ds-base-dbg_1.3.3.5-4+deb8u3_amd64.deb Checksums-Sha256: 33ceb53fb411a7da1c459276242f0282078bd3c2fbbaffe4709c08264f9c4345 2277 389-ds-base_1.3.3.5-4+deb8u3.dsc 7e8677b8fc7904bbfadafc795af74ac2b8d222480c433258c322d02b8db12402 35344 389-ds-base_1.3.3.5-4+deb8u3.debian.tar.xz e1e0f99cd07f86a2cfaa6046afbc1d5f4ee3e80e3622a10dfe4a15815da96740 16370 389-ds_1.3.3.5-4+deb8u3_all.deb 8062acef542eeaf48b0534c84ff86f2de5dc0716bd70991807a83ebeaac9ba5f 387042 389-ds-base-libs_1.3.3.5-4+deb8u3_amd64.deb ec254e7c37775356291ee58a1924f3cf285a87088d3a62aa55b6c4ee712063e5 1282998 389-ds-base-libs-dbg_1.3.3.5-4+deb8u3_amd64.deb 46b01dcd1bb720a7c4c56c1346ea22c1425df7a16868f8cb612c4ee9a19c3960 69618 389-ds-base-dev_1.3.3.5-4+deb8u3_amd64.deb 75fc0730231ceba38aae6f47aa096f1eae998db1629acbd317c56d9d4264f5d0 1455770 389-ds-base_1.3.3.5-4+deb8u3_amd64.deb 5677ab460fc8350ead39e1442624a87392cb554be2b9fc67e000968d3bc7f5a5 4182226 389-ds-base-dbg_1.3.3.5-4+deb8u3_amd64.deb Files: 852e17adc1e63c09b3240518015ea845 2277 net optional 389-ds-base_1.3.3.5-4+deb8u3.dsc 5383e81e65350cfd7769e8595327b5d1 35344 net optional 389-ds-base_1.3.3.5-4+deb8u3.debian.tar.xz 1cab636825d8892bd5cb8b54cd585ac8 16370 net optional 389-ds_1.3.3.5-4+deb8u3_all.deb 65bcabea694bbee5f66f3cb3160e856e 387042 libs optional 389-ds-base-libs_1.3.3.5-4+deb8u3_amd64.deb fc69ac7134914caea665c8c5178e7f7f 1282998 debug extra 389-ds-base-libs-dbg_1.3.3.5-4+deb8u3_amd64.deb 06b4746c54e718f7cd424d18b7ec0187 69618 libdevel optional 389-ds-base-dev_1.3.3.5-4+deb8u3_amd64.deb 797d0fd2c09e77feab87128cd6db1f6a 1455770 net optional 389-ds-base_1.3.3.5-4+deb8u3_amd64.deb ca7c75f7fd6720f4c4e1677ef4c4a17d 4182226 debug extra 389-ds-base-dbg_1.3.3.5-4+deb8u3_amd64.deb -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEUFZhdgIWqBhwqCvuZYVUZx9w0DQFAluvv4cACgkQZYVUZx9w 0DSR/wf/Zo5mGQesSuXwVGngC/VRIXizojv0xex3LdxQTpGjmDThFvp7Wpy4DGcE XwBN1o6S8/iz6euIu0gyvY0SjXQcoSOq2CZQfqk3zmD2yVVBC/xT15zQcKr+jhRQ zmhmIL0wBhQpHhByt0lNfOOHFjl2+1KyG/BVLiDCEKCv30GIn7LFFP4f6DEL/+cv /v6DMZRtfKS5HindDo9wFYr8KmEGdvdMv1JJC9SRWoL36YEbG70mxZJOAl5A2VF5 AQYRt8SnJzF9CBYOL0Nos/5L5NYOxIof+Zm94KI0l91A0DOri/7wOFs2tE0eewMC ScoS7Dg231u3MMpi5QylQklCxb2Mpw== =Hvgf -----END PGP SIGNATURE-----