Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5609-1] slurm-wlm security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5609-1] slurm-wlm security update


Chronologisch Thread  
  • From: Salvatore Bonaccorso <carnil AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5609-1] slurm-wlm security update
  • Date: Sun, 28 Jan 2024 12:38:35 +0000
  • List-archive: https://lists.debian.org/msgid-search/E1rU4Ql-008vP0-By AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version: Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=oqsMHJhTjnsnSQyGQvP869+t2+fgLsFjJV0Rei2JUiM=; b=We l+Vaq74QwDc4FJemcuDW14n26n7XQCvS/b5MhhQzGOeO1lvnCWRVW91eXy+DudVSTc9xedztClm1u wmJ6L0+ZMmxvY1T1lcjfxxGNjkMiOPXH+6IW8ryikoeis3jJ+uuQ3gmy6RaFYSkqrJ0ZzwOFPsqVz PbYl8MN98XOxU2e2z7beq6lbKEo72scx61f0WY8AbM2KdK5p6yh+DkwJLD9RUnJwNSe3r1fJu3i8E TFy3Ya6JRYACW1uQOC58EaN4R37gH2kloHnvTzxMc0r4v+fe0vd5qRz6Filk/7x0i/WEkgkECQBnE w92y0EXpfBrBsDOi8pLW2EC27B/5LOFA==;
  • Old-return-path: <carnil AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Sun, 28 Jan 2024 12:39:03 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <amXP20H-6xI.A.a_B.nrktlB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5609-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
January 28, 2024 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : slurm-wlm
CVE ID : CVE-2023-49933 CVE-2023-49936 CVE-2023-49937 CVE-2023-49938
Debian Bug : 1058720

Several vulnerabilities were discovered in the Slurm Workload Manager, a
cluster resource management and job scheduling system, which may result
in privilege escalation, denial of service, bypass of message hash
checks or opening files with an incorrect set of extended groups.

For the stable distribution (bookworm), these problems have been fixed
in version 22.05.8-4+deb12u2.

We recommend that you upgrade your slurm-wlm packages.

For the detailed security status of slurm-wlm please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/slurm-wlm

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmW2Sj9fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0Q/0xAAiIX2hFquenx281NrzLcnOeIiuvf/+2eXs4/yVQ2P91S7kTzdbRc9n1dV
AIwcvQHKHlQH7z/GHVLtjLDwjiAc34OcPzvLipiFgg6JRmKweOMWqyRns9DaIy4v
RZRg7RvS4ltDOuqP9UXScTom4GAM3GCF6wrvxsyNwSvwayaJtqQw09OjWHJsKOPe
aKJ6yIBfXUukreUQUctVH5P3HG58S1WD/8EqYrpgxC0mBYxs2Iv2FkEcyyiWY2mt
huOqkmzfxf25xzQqlDg7kPMikHkqsHmKiFViAWOe44o0C7jED1JOh72BZk93ktrB
WaA0lqj9w+CUhPoUinOL76qn+ija8URNIlnPExmY8/BlBDwEZ9pawTo/wv/IS34G
zPDrpQQsBTRPpfO9FrJYPf87Ryfp7OpkWfa6LLqTckDp0PQc05/ABdKVtBw/OtfH
Zud9/qO+M80045IP4QIzDOiYkAQPEbnS3qlT6Io8RYu4C1tNiALBksMnuim3E63d
KbRN4lBzCujKY0clKPLtafE6uNXv9gpQRdq2irDGo+IY8A2rfziWqrmdmiP5bxyQ
sZNpTuNSVGa5s+skId17xZDH/uQBi6UTT/0Qz8mceqa1Ufzu2bbpNHVdgGZ+YbAj
AT7bOr5AY1JHqdCDXx6Pl2vQhIss20R3bxi8O0oZODPquGWgkwA=
=fdxl
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5609-1] slurm-wlm security update, Salvatore Bonaccorso, 28.01.2024

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang