it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Sebastien Delafond <seb AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 4859-1] libzstd security update
- Date: Sat, 20 Feb 2021 08:21:27 +0000
- List-archive: https://lists.debian.org/msgid-search/E1lDNW3-0008Ul-H5 AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version :Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=5xg49si3LLMY/Gv1sylXtzy7QgAZKlmMvyPqQY0uIOA=; b=Hu U0jZrfbouVovW2tbe6TeTF7WyoF+WPw11fy083+C/x0yXB+3/dRTqmHQH4c/9falAzyR8u74v9l07 uOqS0Nu3yf6jdsMeegL2ZWNTimznPwUDCsQCdJVYGmUKj91t1v4FSpO0qQdayMB5LBPVETiLk631r l6jYtP+ECkizjVKy/H+UzgR/58qoj+heWYfiQF1gqVcHJ303H5eBKHCLJ6BCPTKu4/WAYsxGgGNWc pQLffCwopmdnQz5R8j7fKyh+fGbhWSId2azTJFFuJlaLRGFmhvE1gwKq8LVtAjD9wJ75dGEc3opQk 2S4S4oyIxUQ+SGfTggFFJGQ4fTRoTFHA==;
- Old-return-path: <seb AT seger.debian.org>
- Priority: urgent
- Resent-date: Sat, 20 Feb 2021 08:21:44 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <Y2kdjqNK2VG.A.EZF.YaMMgB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-4859-1 security AT debian.org
https://www.debian.org/security/ Sebastien Delafond
February 20, 2021 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : libzstd
Debian Bug : 982519
It was discovered that zstd, a compression utility, was vulnerable to
a race condition: it temporarily exposed, during a very short
timeframe, a world-readable version of its input even if the original
file had restrictive permissions.
For the stable distribution (buster), this problem has been fixed in
version 1.3.8+dfsg-3+deb10u2.
We recommend that you upgrade your libzstd packages.
For the detailed security status of libzstd please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libzstd
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAmAwxgIACgkQEL6Jg/PV
nWRqcgf+OvA7eeLqYuHuwtSD8e5xD5NIGGrOwcKkIRm/FtQx/ezBFwPwHzLT6MIx
snzDop6ANxRg5X6b1/6ARioYH6YdHQorcENZ7laO9wXujEThhPnkVNG8UK7HGK76
hWqgLbnr/LF3jc6aiFeX5zKMw8mbMzhCzouQnp5P4hVKchUuyuwyPx41XGFfUvXR
GeWKl9jlFuFdS8WDjhbGltheqjQUjQ25LnXkGOsc/XrjCvO+q3n7qP+0HLbkDnhe
Dqe9n7iQwvRLGNf6MXUL05zAzV8sAf5pbJGt00fS3O7zu9k/x5W5bJ8HsXMKUvVx
eRQUIpAJXVDe/1dmIZiUDccC6H1bhw==
=p1vr
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 4859-1] libzstd security update, Sebastien Delafond, 20.02.2021
Archiv bereitgestellt durch MHonArc 2.6.24.