it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Salvatore Bonaccorso <carnil AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5055-1] util-linux security update
- Date: Mon, 24 Jan 2022 11:31:30 +0000
- List-archive: https://lists.debian.org/msgid-search/E1nBxZK-0003nK-AM AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version :Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=E77zIflHn6Jq5v49nmnme4DoXUFXydnqDTZ8M32+Y5o=; b=d6 L+woKFg3UZk5yXQprIgRUdRaho1/jU1DiuC4unz1tHAqpLUhb5OcwdfvDx83OZJb2FsEE2HrCjaXa E0AprvkGia7aPl/+eDMcTQJrjh6HSQRRd+U7tUavwFlyHD1oO80zoXKdSKJr7wfzGz1hXxRtsZBs2 FeJ6/YUulC1TG+6iA88x78djkGGLFTndsdAAvAnToatUxSHnyiBjKo7niTSyiRKbbLTM8eP/jALzk sLdx8vBw46OJWqJOZIO7agCHibBQDomsx1MgFouCKqysybnmNyYcyrimG3pVwrUIPrN5g0o2E6Cm8 1dSIEoxm3VyUcs3UkMZ4AuR1A33w6rPg==;
- Old-return-path: <carnil AT seger.debian.org>
- Priority: urgent
- Resent-date: Mon, 24 Jan 2022 11:31:47 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <HGiC5TKsfXD.A.Ix.j4o7hB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5055-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
January 24, 2022 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : util-linux
CVE ID : CVE-2021-3995 CVE-2021-3996
The Qualys Research Labs discovered two vulnerabilities in util-linux's
libmount. These flaws allow an unprivileged user to unmount other users'
filesystems that are either world-writable themselves or mounted in a
world-writable directory (CVE-2021-3996), or to unmount FUSE filesystems
that belong to certain other users (CVE-2021-3995).
For the stable distribution (bullseye), these problems have been fixed in
version 2.36.1-8+deb11u1.
We recommend that you upgrade your util-linux packages.
For the detailed security status of util-linux please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/util-linux
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmHujUNfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0TD/BAAmjdIgQgYI0Bc7fcp4tMNHOADXbn5cJysAee0P55kb863q5TM49DzbHuB
Xh5Fh7+f4O/rDUXZoW/2hm43pbwDs8EH8LGYjTkspHraRkFEq7mLR6753SIVXHTP
U/k9eShfgqRggCq7OTiALBXC00yMNn75PGsd5GPKEv2egSG34+bdp2RPnKc+R7cC
yLkwuN6oNq0+KW08HzQp6FSYX7V+a8gsO2QWdlgAuXQC4ICCtYV1jtYn/GJ2SB6E
E98nNIUBSR5sf8bXKDpPTrxvbAF1Y0719A7MwGnZS9bNVIBMlx0tNHSCddLrE6/F
BMHSyvTQo+xLs5t+Esxb2rfsjuOlrbwte++8GR/LnVr/Zi/vVrzkccwneQlhHPzp
Ok8fJ7ipEVbpBWyWdomsQXb8y7o8RFHr9P374JmCQE/urMaOHq1Lc7C9ctVJ5VHb
3+BV/FpMAvY6KekNqriSiX9aXXfWr4HQr7OO6rlz84/rC7wlVpYOx4TRaRGPQPyD
STfa8W1shaMlxgL9zgmAtgCu4nNOR4BqVi5ZbuxY8sdbBM7tFD4DuD6sIhNAFadL
pIpbvGte7FFHci4vQX/TEZVUGP0yqbNkvuScvT9k9ca/vytJ+9JZf4BUjGF/tO7C
HS76o443AhdoYbCm7xtQHf2sm3eqPY6ULXTBZmLgVN3q6jWiyhQ=
=lcvO
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5055-1] util-linux security update, Salvatore Bonaccorso, 24.01.2022
Archiv bereitgestellt durch MHonArc 2.6.24.