Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5194-1] booth security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5194-1] booth security update


Chronologisch Thread  
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5194-1] booth security update
  • Date: Fri, 29 Jul 2022 14:43:46 +0000
  • Authentication-results: mail.piratenpartei.de; dkim=none; dmarc=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 2001:41b8:202:deb:216:36ff:fe40:4002) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"
  • List-archive: https://lists.debian.org/msgid-search/20220729144346.GA9830 AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From: Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=HpzYCXf01itRdMd8UIiiyfHhXwcQd2HxwxxG91tPSLE=; b=PU BrNGM7whz2EWUkDUSqsJ1F4/WjEjsBYZ37iQMDe2nQ0izNEo+XAH0YBPRvPLFNvIcDRKWeV7rzBel nL6LkHviFo5GDygfKs3WShgx75zF5KCnAkoSvbv40ihv+15knXTzoi98eqs0FY7hPAV9LpGsbJucc GZO/5sWd3yEXGn8tl8zQIWOqnSkMqvwRPmTZFVBVmeFQjYqc+OjlFX6GnrmZWE+DNDTE5qZ7SyE5G c4soizKu3xvotpq8TyAo6BiZlFpVnyPe+CebwDuookLCLTrfvvMZ2lVN2GIh61p1AEY7gzcVDdiY/ plJBgZOAV2CmarUMDCTr+p0fnsNYW+0w==;
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Fri, 29 Jul 2022 14:44:07 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <mzqwohRq9DH.A.niE.2I_4iB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5194-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
July 29, 2022 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : booth
CVE ID : CVE-2022-2553

It was discovered that Booth, a cluster ticket manager, didn't correctly
restrict intra-node communication when configuring the "authfile"
configuration directive.

For the oldstable distribution (buster), this problem has been fixed
in version 1.0-162-g27f917f-2+deb10u1.

For the stable distribution (bullseye), this problem has been fixed in
version 1.0-237-gdd88847-2+deb11u1.

We recommend that you upgrade your booth packages.

For the detailed security status of booth please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/booth

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmLj8gwACgkQEMKTtsN8
TjalHxAAoPI+F3FRUFhoVklMv81foVZFasj1zBF6uAYS+i0JQ2ew/QNWSNhoCaYH
pX3jKXdvV8P70o/C2m7W7hUHy5htVzjhYVBmypAO5mX6lkZAFmcHC6BORRU52kBy
RPthRslI6La5P96YmS4JtTKspMgAWU3kzmeyPD+KzIrRR1HGRxcAZYJaP+uDR4JZ
2tU48H4wMIZFPQryiF6sUaaOXdXpv5rAeMJad7EodFbfLEQDLoJF3kWeUa2ejDxF
SrtZ7sD+awOtJ+6Ys+6MY3gnzwSGha4dHWLnWDL8UrfTgidy6hOXa59uXnhwub8l
aXlFl+SPIE3ChF/lVpS+UgPYNh61m1rVOU9kpjwUPeJ56F3doYSUtyiXJEGRXaVU
xQhQu06JRR5qbMxkM9YondyagEs7WZDRvpz+gFf1H0Y9ES55GOBxGWYwp3nFqRM2
qUgdhjnUakSNR+lrMLtg9huXYIW5zRVYCXzasCGHNMoUDp/Ke78ielMb8YGPj9tu
Xxnj14CHTo2mnt7PNsF1WAXvSOX//wJGmM2t9PmqnROIy2VhqPbmjvfP2+evpmPZ
gtk9h+ji3RI8EjksdhSdH/M8ULbPrTbe7A0oW37i/p/pNBqNWElrSkmnOKO7BKYi
o6Nou0+eoTRsvi3EZDz6t4ijKnBGY4yn+6SZwZfY3hhh1Wm0CzI=
=j4L8
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5194-1] booth security update, Moritz Muehlenhoff, 29.07.2022

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang