Accepted ipmitool 1.8.18-6+deb10u1 (source) into proposed-updates->stable-new, proposed-updates
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Fri, 19 Feb 2021 11:30:06 +0100
Source: ipmitool
Architecture: source
Version: 1.8.18-6+deb10u1
Distribution: buster
Urgency: medium
Maintainer: Jörg Frings-Fürst <debian@jff.email>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 950761
Changes:
ipmitool (1.8.18-6+deb10u1) buster; urgency=medium
.
* Non-maintainer upload.
* CVE-2020-5208: buffer overflows and potentially to remote code execution.
Applied upstream patches:
- CVE-2020-5208_1_Fix_buffer_overflow_vulnerabilities.patch
- CVE-2020-5208_2-fru-Fix-buffer-overflow-in-ipmi_spd_print_fru.patch
- CVE-2020-5208_3-session-Fix-buffer-overflow-in-ipmi_get_session_info.patch
- CVE-2020-5208_4-channel-Fix-buffer-overflow.patch
- CVE-2020-5208_5_lanp-Fix-buffer-overflows-in-get_lan_param_select.patch
- CVE-2020-5208_6-fru-sdr-Fix-id_string-buffer-overflows.patch
(Closes: #950761).
Checksums-Sha1:
1e03a023cd27c1c0ae3d7e9538a1c2ca03d0a769 1930 ipmitool_1.8.18-6+deb10u1.dsc
4268254534c9cb0abfa5a25164931b74ff989eb7 25288 ipmitool_1.8.18-6+deb10u1.debian.tar.xz
be8c255c850a896e7ad366393dbd9a19529e7761 6085 ipmitool_1.8.18-6+deb10u1_amd64.buildinfo
Checksums-Sha256:
b068185100ced6e7e06c2fdb674edbdbf71eec64367d9c9fb84798b45dcfc58b 1930 ipmitool_1.8.18-6+deb10u1.dsc
ce84ca43243974f8a98127f3ba094989e8a945ba3b00ae815b8433c55848b92b 25288 ipmitool_1.8.18-6+deb10u1.debian.tar.xz
9fc8577b40ce23ef4e1c8d96ae461664f71b1a85bc21fcf1007353f9d53c12f7 6085 ipmitool_1.8.18-6+deb10u1_amd64.buildinfo
Files:
fa99fdd82a1d37d1c65cc6b7fb1db9b7 1930 utils optional ipmitool_1.8.18-6+deb10u1.dsc
44b889cde529d8550e2d0642cf2529a9 25288 utils optional ipmitool_1.8.18-6+deb10u1.debian.tar.xz
fc636d477e8d16be2243e817b8800e29 6085 utils optional ipmitool_1.8.18-6+deb10u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmBfzqcACgkQ1BatFaxr
Q/69pw/8D26WGi/NM3QORYlO9OUZfm+gUHSDVV+eh8/HtrAz/JHcEP/onJhzZmBr
D15TvY+FUM4VXm3VQ58UIkKl0Ktsg6IlQJ7Q21dxkpThdX+PVJoqmShAcr4PoE2n
FMaw+3DYB+QPFCzfOFHKmvj1P+2h3DiIXeLcZ+ieaVjrp3z9FzNHKvPoHw3c3l3e
EPMjOxFfmFgG6WV40/uhp0EmrVi8VvcI0wUR/p4mbEDztZgttShOW9/S+04Zzu9O
3pfBH6NgOlsrOjslo+PlvcLFeoyLes4arRcmqew82uwo0ZdRLXXZ/Lgs1yAI3hb1
z40vRZoJJJ8ZfUC7+2DS8h5XyLJtmTpclERp1a3Zr6jK/4+y09dYY/3zoQnWWkr3
pd8FgiEZWIo2JUormju/kg/hF/bWgW+s2tvjylJttODp71KzatwDip/cYvcTYUcw
UIFxt+XqI0JA/DT20EHQsffaeE9pV2/ckVYWMtKIEnyYBybWLC5WVntIdHdV4nSN
cKBtXzpwwdKUkOUk8V+dtvo+QoYd2XfdN1CiEjTGiGV4TViWZ7Ha9YsSt64/f6fX
BryvXTh8NcLVIr4poUHTDWR/Ixg4sRRmcGZjN2OmQySlcq4uT197FVWviW0rZGva
ahds59nzGD7Eo3HcblA0FjiuORrWO3XbXc74Ppws8Pjc2gqrNmw=
=QxmZ
-----END PGP SIGNATURE-----