-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 05 Jul 2024 06:15:50 +0200 Source: cockpit Binary: cockpit-bridge cockpit-bridge-dbgsym cockpit-pcp cockpit-pcp-dbgsym cockpit-tests cockpit-tests-dbgsym cockpit-ws cockpit-ws-dbgsym Architecture: ppc64el Version: 287.1-0+deb12u3 Distribution: bookworm Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Martin Pitt Description: cockpit-bridge - Cockpit bridge server-side component cockpit-pcp - Cockpit PCP integration cockpit-tests - Tests for Cockpit cockpit-ws - Cockpit Web Service Changes: cockpit (287.1-0+deb12u3) bookworm; urgency=medium . * Add 0002-pam-ssh-add-Fix-insecure-killing-of-session-ssh-agen.patch: Cockpit’s pam_ssh_add module had a vulnerability when user_readenv is enabled in /etc/pam.d/cockpit (which is the default on Debian). This could cause a Denial of Service if a locally-authenticated user crafted a ~/.pam_environment file: it would kill an arbitrary process on the system with root privileges when logging out of a Cockpit session. Patch cherry-picked from upstream (08965365ac311f906a5). [CVE-2024-6126] Checksums-Sha1: 8383881356fa5f940bb8e57315a80b97b220d6b0 733220 cockpit-bridge-dbgsym_287.1-0+deb12u3_ppc64el.deb 2a223a65ed5bc557e87a7427bb33481637098294 261428 cockpit-bridge_287.1-0+deb12u3_ppc64el.deb 0a76782a43a83f4efa8408a15038b8fd029198ba 224016 cockpit-pcp-dbgsym_287.1-0+deb12u3_ppc64el.deb a45d2cce328cd8bafe48c9843da7998870b1ae42 83764 cockpit-pcp_287.1-0+deb12u3_ppc64el.deb 18ce17f13731d6e628517517c21feab74a9c7e84 4664 cockpit-tests-dbgsym_287.1-0+deb12u3_ppc64el.deb a1801e528f37c9603501b8f8d6f102689eb69ad2 475340 cockpit-tests_287.1-0+deb12u3_ppc64el.deb b7e79f5e8ad67a16ac6cfbbdfe2184057630b966 466912 cockpit-ws-dbgsym_287.1-0+deb12u3_ppc64el.deb 65f0ea06776baefee2ca26e22ab11dd778a961d5 821092 cockpit-ws_287.1-0+deb12u3_ppc64el.deb 606bddc972bc7aaf817d4d8041c50fa56cf4d74a 12452 cockpit_287.1-0+deb12u3_ppc64el-buildd.buildinfo Checksums-Sha256: 7fe56cda5433cf231826fa1426e93cf8088b9a1d3ce5f892cf41bfebffa89739 733220 cockpit-bridge-dbgsym_287.1-0+deb12u3_ppc64el.deb c212fb237c8a7449b51fa811191aa9efb992128c81a50a5a06c928648b4a724f 261428 cockpit-bridge_287.1-0+deb12u3_ppc64el.deb 1923b29dac74c5b187a87c09d834e9fbb107bdca26c04095ea58cb48f84b17bb 224016 cockpit-pcp-dbgsym_287.1-0+deb12u3_ppc64el.deb 96c38a7f8cfd5a10e8b8df4f139bbbab4691fb988321c31f68da2fead61002d5 83764 cockpit-pcp_287.1-0+deb12u3_ppc64el.deb 07e233b2b54f90eb4cf625dc332e324794ea19c6f03e69e52e3c2451517ce4da 4664 cockpit-tests-dbgsym_287.1-0+deb12u3_ppc64el.deb 2c7f4f4978d2d3d7c621556714d355df10a2e8f71297b92a7b6c9765a3afe767 475340 cockpit-tests_287.1-0+deb12u3_ppc64el.deb 458096f6af8d31c758b02adb1af590b1a22caffb7d0c59a7c2fcd0658386bc11 466912 cockpit-ws-dbgsym_287.1-0+deb12u3_ppc64el.deb 7b838d81243fd853b04afaee139bacb240687a03215b79a6123b7f8d9d5df5b1 821092 cockpit-ws_287.1-0+deb12u3_ppc64el.deb 0e29e67fa4828de448548494c6b447120e95797e06723f812340e7b5b41643e9 12452 cockpit_287.1-0+deb12u3_ppc64el-buildd.buildinfo Files: 7907c399359c0927eee29721ca7d43fd 733220 debug optional cockpit-bridge-dbgsym_287.1-0+deb12u3_ppc64el.deb 078cb7bbcfb0fe1d58adddf0a90931f5 261428 admin optional cockpit-bridge_287.1-0+deb12u3_ppc64el.deb b4b46404a203ed621778176118d17cad 224016 debug optional cockpit-pcp-dbgsym_287.1-0+deb12u3_ppc64el.deb 7194443e5a9e4e87f81b045ff5b0d951 83764 admin optional cockpit-pcp_287.1-0+deb12u3_ppc64el.deb bde74cf3948e63bffded388057d5dba1 4664 debug optional cockpit-tests-dbgsym_287.1-0+deb12u3_ppc64el.deb 6566e81ffc20d0793c345da3db9e52e3 475340 admin optional cockpit-tests_287.1-0+deb12u3_ppc64el.deb 7ca0e07595f97e6efbaee5a7ad63a3be 466912 debug optional cockpit-ws-dbgsym_287.1-0+deb12u3_ppc64el.deb 2a8736afaf484cb545c5ee6ff352a18c 821092 admin optional cockpit-ws_287.1-0+deb12u3_ppc64el.deb f8638705357a0e62e9bd9b2e6243122a 12452 admin optional cockpit_287.1-0+deb12u3_ppc64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmyxOicioak1AZZAyyPVDLEOGa2QFAmazDsoACgkQyPVDLEOG a2RA5xAApon1NYPHwPOGulpLGnduAp2JS2163Ekc1xWind4rxT7sv0XboED0yDcN IpFokxGj2kj/7zfodURq25EY/0HkFHBQTpoGCfBj7DijEt0wcR3CXTtVuXW5iwSM CJTmu7PTHSjuoQrYR8xEo3ZwlpJ8qfYC4vevLJ6/abwQ53W/fEGi8zcEj8yKMbAP iot68z+GXenGbO5TeKt7Xl/vsqWyDrBrESH+7lHaBS+qy05a4Qk7baUPPPdVD/y2 ivkxk4jERCBcqIcBk1NnX1ieCUQNK8QcrirrcUpHgTusdGJiLQsQSK33rl2KTR7V PlQKM7PN3WGNGg9yNuISu4d8XICzgUUlQwTgmiBNYNCLC61J4dx553Ht1BjjmPzo 0wgzwptpsQ/ECDD35X+1rrB+UDt/IuKPYFqP1zAgLSkVI2yb+WdC8+/WybwjLtGD Oshl5ZHzPJSjUFN5V2bjY6WREUWoQKOoWtcs4jkgMDJ9HclKR5nQfKKtKJ3t2KJy 4zF94F6TRX3zDItLelz1mXN0drKAbYosN7L6CKTx1KDf8b6Ydwb1bLIokmRzC4+j E4EfOCxDpYqSfrEmz/ur4TBRAc01d2YcjynViS1zD7+0abCGynr8mAJushmww2X0 UMGVmV3/YsJQzlPoS4LSC9lkV49j/wIBAXIN/4Q0SG02T/e+GWs= =Kz+F -----END PGP SIGNATURE-----