• Re: [RFR] wml://security/2022/dsa-513{2,3,4,5,6}.wml

    From [email protected]@21:1/5 to All on Fri May 13 10:10:01 2022
    Bonjour,

    cinq nouvelles annonces de s�curit� ont �t� publi�es.

    un bac trop bas, ds la version 11 et 13, et une suggestion,
    amicalement, bubu
    --- dsa-5132.wml 2022-05-13 10:00:21.409508658 +0200
    +++ dsa-5132.relu.wml 2022-05-13 10:01:30.010403254 +0200
    @@ -3,7 +3,7 @@
    <define-tag moreinfo>
    <p>ecdsautils, une collection d'outils de chiffrement sur courbes
    elliptiques ECDSA en ligne de commande, vérifiait incorrectement certaines -signatures de chiffrement : une signature consistant en zéros uniquement +signatures de chiffrement : une signature consistant en des zéros uniquement
    était toujours considérée comme valable, simplifiant la contrefaçon de
    signatures.</p>

    --- dsa-5136.wml 2022-05-13 09:56:56.626500886 +0200
    +++ dsa-5136.relu.wml 2022-05-13 09:58:20.039794827 +0200
    @@ -2,7 +2,7 @@
    <define-tag description>Mise à jour de sécurité</define-tag>
    <define-tag moreinfo>
    <p>Alexander Lakhin a découvert que la fonctionnalité autovacuum et de -multiples commandes pouvaient s'échapper du bas à sable
    +multiples commandes pouvaient s'échapper du bac à sable
    <q>security-restricted operation</q>.</p>

    <p>Pour
  • From Jean-Pierre Giraud@21:1/5 to All on Fri May 13 09:50:01 2022
    This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------2TxNqnXsDtk65Ls00YIexEqu
    Content-Type: multipart/mixed; boundary="------------KVwG0zgNTHIFx3iNIkBaVJX1"

    --------------KVwG0zgNTHIFx3iNIkBaVJX1
    Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64

    Qm9uam91ciwNCmNpbnEgbm91dmVsbGVzIGFubm9uY2VzIGRlIHPDqWN1cml0w6kgb250IMOp dMOpIHB1Ymxpw6llcy4gRW4gdm9pY2kgdW5lIA0KdHJhZHVjdGlvbi4gTWVyY2kgZCdhdmFu Y2UgcG91ciB2b3MgcmVsZWN0dXJlcy4NCkFtaWNhbGVtZW50LA0KamlwZWdlDQo= --------------KVwG0zgNTHIFx3iNIkBaVJX1
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dsa-5136.wml" Content-Disposition: attachment; filename="dsa-5136.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249IjhiYzY2 YjA2Y2E4YzI5NzQ2NWEzYzVkMDFjYmE5ZDQwNTMxODExZmUiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6k8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZvPgo8cD5BbGV4 YW5kZXIgTGFraGluIGEgZMOpY291dmVydCBxdWUgbGEgZm9uY3Rpb25uYWxpdMOpIGF1dG92 YWN1dW0gZXQgZGUKbXVsdGlwbGVzIGNvbW1hbmRlcyBwb3V2YWllbnQgcyfDqWNoYXBwZXIg ZHUgYmFzIMOgIHNhYmxlCjxxPnNlY3VyaXR5LXJlc3RyaWN0ZWQgb3BlcmF0aW9uPC9xPi48 L3A+Cgo8cD5Qb3VyIGRlcyBpbmZvcm1hdGlvbnMgY29tcGzDqW1lbnRhaXJlcywgdmV1aWxs ZXogdm91cyByw6lmw6lyZXIgw6AgbCdhbm5vbmNlCmFtb250IMOgIGwnYWRyZXNzZSA8YSBo cmVmPSJodHRwczovL3d3dy5wb3N0Z3Jlc3FsLm9yZy9zdXBwb3J0L3NlY3VyaXR5L0NWRS0y MDIyLTE1NTIvIj5cCmh0dHBzOi8vd3d3LnBvc3RncmVzcWwub3JnL3N1cHBvcnQvc2VjdXJp dHkvQ1ZFLTIwMjItMTU1Mi88L2E+LjwvcD4KCjxwPlBvdXIgbGEgZGlzdHJpYnV0aW9uIHN0 YWJsZSAoQnVsbHNleWUpLCBjZSBwcm9ibMOobWUgYSDDqXTDqSBjb3JyaWfDqSBkYW5zCmxh IHZlcnNpb27CoDEzLjctMCtkZWIxMXUxLjwvcD4KCjxwPk5vdXMgdm91cyByZWNvbW1hbmRv bnMgZGUgbWV0dHJlIMOgIGpvdXIgdm9zIHBhcXVldHMgcG9zdGdyZXNxbC0xMy48L3A+Cgo8 cD5Qb3VyIGRpc3Bvc2VyIGQndW4gw6l0YXQgZMOpdGFpbGzDqSBzdXIgbGEgc8OpY3VyaXTD qSBkZSBwb3N0Z3Jlc3FsLTEzLAp2ZXVpbGxleiBjb25zdWx0ZXIgc2EgcGFnZSBkZSBzdWl2 aSBkZSBzw6ljdXJpdMOpIMOgIGwnYWRyZXNzZcKgOgo8YSBocmVmPSJodHRwczovL3NlY3Vy aXR5LXRyYWNrZXIuZGViaWFuLm9yZy90cmFja2VyL3Bvc3RncmVzcWwtMTMiPlwKaHR0cHM6 Ly9zZWN1cml0eS10cmFja2VyLmRlYmlhbi5vcmcvdHJhY2tlci9wb3N0Z3Jlc3FsLTEzPC9h Pi48L3A+CjwvZGVmaW5lLXRhZz4KCiMgZG8gbm90IG1vZGlmeSB0aGUgZm9sbG93aW5nIGxp bmUKI2luY2x1ZGUgIiQoRU5HTElTSERJUikvc2VjdXJpdHkvMjAyMi9kc2EtNTEzNi5kYXRh IgojICRJZDogJAo=
    --------------KVwG0zgNTHIFx3iNIkBaVJX1
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dsa-5135.wml" Content-Disposition: attachment; filename="dsa-5135.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249IjAzN2Zh NDU2MTY3NmZmM2MyOGZjMTJiMTQ4Nzc2ZjliZmM4MWZmZWQiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6k8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZvPgo8cD5BbGV4 YW5kZXIgTGFraGluIGEgZMOpY291dmVydCBxdWUgbGEgZm9uY3Rpb25uYWxpdMOpIGF1dG92 YWN1dW0gZXQgZGUKbXVsdGlwbGVzIGNvbW1hbmRlcyBwb3V2YWllbnQgcyfDqWNoYXBwZXIg ZHUgYmFzIMOgIHNhYmxlCjxxPnNlY3VyaXR5LXJlc3RyaWN0ZWQgb3BlcmF0aW9uPC9xPi48 L3A+Cgo8cD5Qb3VyIGRlcyBpbmZvcm1hdGlvbnMgY29tcGzDqW1lbnRhaXJlcywgdmV1aWxs ZXogdm91cyByw6lmw6lyZXIgw6AgbCdhbm5vbmNlCmFtb250IMOgIGwnYWRyZXNzZSA8YSBo cmVmPSJodHRwczovL3d3dy5wb3N0Z3Jlc3FsLm9yZy9zdXBwb3J0L3NlY3VyaXR5L0NWRS0y MDIyLTE1NTIvIj5cCmh0dHBzOi8vd3d3LnBvc3RncmVzcWwub3JnL3N1cHBvcnQvc2VjdXJp dHkvQ1ZFLTIwMjItMTU1Mi88L2E+LjwvcD4KCjxwPlBvdXIgbGEgZGlzdHJpYnV0aW9uIG9s ZHN0YWJsZSAoQnVzdGVyKSwgY2UgcHJvYmzDqG1lIGEgw6l0w6kgY29ycmlnw6kgZGFucwps YSB2ZXJzaW9uwqAxMS4xNi0wK2RlYjEwdTEuPC9wPgoKPHA+Tm91cyB2b3VzIHJlY29tbWFu ZG9ucyBkZSBtZXR0cmUgw6Agam91ciB2b3MgcGFxdWV0cyBwb3N0Z3Jlc3FsLTExLjwvcD4K CjxwPlBvdXIgZGlzcG9zZXIgZCd1biDDqXRhdCBkw6l0YWlsbMOpIHN1ciBsYSBzw6ljdXJp dMOpIGRlIHBvc3RncmVzcWwtMTEsIHZldWlsbGV6CmNvbnN1bHRlciBzYSBwYWdlIGRlIHN1 aXZpIGRlIHPDqWN1cml0w6kgw6AgbCdhZHJlc3NlwqA6CjxhIGhyZWY9Imh0dHBzOi8vc2Vj dXJpdHktdHJhY2tlci5kZWJpYW4ub3JnL3RyYWNrZXIvcG9zdGdyZXNxbC0xMSI+XApodHRw czovL3NlY3VyaXR5LXRyYWNrZXIuZGViaWFuLm9yZy90cmFja2VyL3Bvc3RncmVzcWwtMTE8 L2E+LjwvcD4KPC9kZWZpbmUtdGFnPgoKIyBkbyBub3QgbW9kaWZ5IHRoZSBmb2xsb3dpbmcg bGluZQojaW5jbHVkZSAiJChFTkdMSVNIRElSKS9zZWN1cml0eS8yMDIyL2RzYS01MTM1LmRh dGEiCiMgJElkOiAkCg==
    --------------KVwG0zgNTHIFx3iNIkBaVJX1
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dsa-5134.wml" Content-Disposition: attachment; filename="dsa-5134.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249IjJiZmJm ZGJmZWE3N2ZiZDQzMmVhYjA1NzQ3MDM0OThmMWVmZjI5OGIiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6k8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZvPgo8cD5QbHVz aWV1cnMgcHJvYmzDqG1lcyBkZSBzw6ljdXJpdMOpIG9udCDDqXTDqSBkw6ljb3V2ZXJ0cyBk YW5zIENocm9taXVtLCBxdWkKcG91dmFpZW50IGF2b2lyIHBvdXIgY29uc8OpcXVlbmNlcyBs J2V4w6ljdXRpb24gZGUgY29kZSBhcmJpdHJhaXJlLCB1biBkw6luaQpkZSBzZXJ2aWNlIG91 IGxhIGRpdnVsZ2F0aW9uIGQnaW5mb3JtYXRpb25zLjwvcD4KCjxwPlBvdXIgbGEgZGlzdHJp YnV0aW9uIHN0YWJsZSAoQnVsbHNleWUpLCBjZXMgcHJvYmzDqG1lcyBvbnQgw6l0w6kgY29y cmlnw6lzCmRhbnMgbGEgdmVyc2lvbsKgMTAxLjAuNDk1MS42NC0xfmRlYjExdTEuPC9wPgoK PHA+Tm91cyB2b3VzIHJlY29tbWFuZG9ucyBkZSBtZXR0cmUgw6Agam91ciB2b3MgcGFxdWV0 cyBjaHJvbWl1bS48L3A+Cgo8cD5Qb3VyIGRpc3Bvc2VyIGQndW4gw6l0YXQgZMOpdGFpbGzD qSBzdXIgbGEgc8OpY3VyaXTDqSBkZSBjaHJvbWl1bSwgdmV1aWxsZXoKY29uc3VsdGVyIHNh IHBhZ2UgZGUgc3VpdmkgZGUgc8OpY3VyaXTDqSDDoCBsJ2FkcmVzc2XCoDoKPGEgaHJlZj0i aHR0cHM6Ly9zZWN1cml0eS10cmFja2VyLmRlYmlhbi5vcmcvdHJhY2tlci9jaHJvbWl1bSI+ XApodHRwczovL3NlY3VyaXR5LXRyYWNrZXIuZGViaWFuLm9yZy90cmFja2VyL2Nocm9taXVt PC9hPi48L3A+CjwvZGVmaW5lLXRhZz4KCiMgZG8gbm90IG1vZGlmeSB0aGUgZm9sbG93aW5n IGxpbmUKI2luY2x1ZGUgIiQoRU5HTElTSERJUikvc2VjdXJpdHkvMjAyMi9kc2EtNTEzNC5k YXRhIgojICRJZDogJAo=
    --------------KVwG0zgNTHIFx3iNIkBaVJX1
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dsa-5133.wml" Content-Disposition: attachment; filename="dsa-5133.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249IjFhODcz YTNiMzlhYWRmN2M3MDgyYjg1OTRlOGI2NTgyYjY3NGNmNDEiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6k8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZvPgo8cD5QbHVz aWV1cnMgcHJvYmzDqG1lcyBkZSBzw6ljdXJpdMOpIG9udCDDqXTDqSBkw6ljb3V2ZXJ0cyBk YW5zIFFFTVUsIHVuCsOpbXVsYXRldXIgZGUgcHJvY2Vzc2V1ciByYXBpZGUsIHF1aSBwb3V2 YWllbnQgYXZvaXIgcG91ciBjb25zw6lxdWVuY2UgdW4KZMOpbmkgZGUgc2VydmljZSBvdSBs J2V4w6ljdXRpb24gZGUgY29kZSBhcmJpdHJhaXJlLjwvcD4KCjxwPlBvdXIgbGEgZGlzdHJp YnV0aW9uIHN0YWJsZSAoQnVsbHNleWUpLCBjZSBwcm9ibMOobWUgYSDDqXTDqSBjb3JyaWfD qSBkYW5zCmxhIHZlcnNpb27CoDE6NS4yK2Rmc2ctMTErZGViMTF1Mi48L3A+Cgo8cD5Ob3Vz IHZvdXMgcmVjb21tYW5kb25zIGRlIG1ldHRyZSDDoCBqb3VyIHZvcyBwYXF1ZXRzIHFlbXUu PC9wPgoKPHA+UG91ciBkaXNwb3NlciBkJ3VuIMOpdGF0IGTDqXRhaWxsw6kgc3VyIGxhIHPD qWN1cml0w6kgZGUgcWVtdSwgdmV1aWxsZXoKY29uc3VsdGVyIHNhIHBhZ2UgZGUgc3Vpdmkg ZGUgc8OpY3VyaXTDqSDDoCBsJ2FkcmVzc2XCoDoKPGEgaHJlZj0iaHR0cHM6Ly9zZWN1cml0 eS10cmFja2VyLmRlYmlhbi5vcmcvdHJhY2tlci9xZW11Ij5cCmh0dHBzOi8vc2VjdXJpdHkt dHJhY2tlci5kZWJpYW4ub3JnL3RyYWNrZXIvcWVtdTwvYT4uPC9wPgo8L2RlZmluZS10YWc+ CgojIGRvIG5vdCBtb2RpZnkgdGhlIGZvbGxvd2luZyBsaW5lCiNpbmNsdWRlICIkKEVOR0xJ U0hESVIpL3NlY3VyaXR5LzIwMjIvZHNhLTUxMzMuZGF0YSIKIyAkSWQ6ICQK --------------KVwG0zgNTHIFx3iNIkBaVJX1
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dsa-5132.wml" Content-Disposition: attachment; filename="dsa-5132.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249Ijk5Yzkw NDEzNjExZDFhZjVlMmRhNWNjNDcxZjExOTRlMjBiNDc1ZGUiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6k8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZvPgo8cD5lY2Rz YXV0aWxzLCB1bmUgY29sbGVjdGlvbiBkJ291dGlscyBkZSBjaGlmZnJlbWVudCBzdXIgY291 cmJlcwplbGxpcHRpcXVlcyBFQ0RTQSBlbiBsaWduZSBkZSBjb21tYW5kZSwgdsOpcmlmaWFp dCBpbmNvcnJlY3RlbWVudCBjZXJ0YWluZXMKc2lnbmF0dXJlcyBkZSBjaGlmZnJlbWVudMKg OiB1bmUgc2lnbmF0dXJlIGNvbnNpc3RhbnQgZW4gesOpcm9zIHVuaXF1ZW1lbnQKw6l0YWl0 IHRvdWpvdXJzIGNvbnNpZMOpcsOpZSBjb21tZSB2YWxhYmxlLCBzaW1wbGlmaWFudCBsYSBj b250cmVmYcOnb24gZGUKc2lnbmF0dXJlcy48L3A+Cgo8cD5Qb3VyIGxhIGRpc3RyaWJ1dGlv biBvbGRzdGFibGUgKEJ1c3RlciksIGNlIHByb2Jsw6htZSBhIMOpdMOpIGNvcnJpZ8OpIGRh bnMKbGEgdmVyc2lvbsKgMC4zLjIrZ2l0MjAxNTEwMTgtMitkZWIxMHUxLjwvcD4KCjxwPlBv dXIgbGEgZGlzdHJpYnV0aW9uIHN0YWJsZSAoQnVsbHNleWUpLCBjZSBwcm9ibMOobWUgYSDD qXTDqSBjb3JyaWfDqSBkYW5zCmxhIHZlcnNpb27CoDAuMy4yK2dpdDIwMTUxMDE4LTIrZGVi MTF1MS48L3A+Cgo8cD5Ob3VzIHZvdXMgcmVjb21tYW5kb25zIGRlIG1ldHRyZSDDoCBqb3Vy IHZvcyBwYXF1ZXRzIGVjZHNhdXRpbHMuPC9wPgoKPHA+UG91ciBkaXNwb3NlciBkJ3VuIMOp dGF0IGTDqXRhaWxsw6kgc3VyIGxhIHPDqWN1cml0w6kgZGUgZWNkc2F1dGlscywgdmV1aWxs ZXoKY29uc3VsdGVyIHNhIHBhZ2UgZGUgc3VpdmkgZGUgc8OpY3VyaXTDqSDDoCBsJ2FkcmVz c2XCoDoKPGEgaHJlZj0iaHR0cHM6Ly9zZWN1cml0eS10cmFja2VyLmRlYmlhbi5vcmcvdHJh Y2tlci9lY2RzYXV0aWxzIj5cCmh0dHBzOi8vc2VjdXJpdHktdHJhY2tlci5kZWJpYW4ub3Jn L3RyYWNrZXIvZWNkc2F1dGlsczwvYT4uPC9wPgo8L2RlZmluZS10YWc+CgojIGRvIG5vdCBt b2RpZnkgdGhlIGZvbGxvd2luZyBsaW5lCiNpbmNsdWRlICIkKEVOR0xJU0hESVIpL3NlY3Vy aXR5LzIwMjIvZHNhLTUxMzIuZGF0YSIKIyAkSWQ6ICQK

    --------------KVwG0zgNTHIFx3iNIkBaVJX1--

    --------------2TxNqnXsDtk65Ls00YIexEqu--

    -----BEGIN PGP SIGNATURE-----

    wsF5BAABCAAjFiEEcH/R3vmpi4JWBoDfeBP2a44wMXIFAmJ+DHAFAwAAAAAACgkQeBP2a44wMXK1 8A/7BBa6lxQHbQ2N/+muZHLMnHnH4TlMfecDXZBgEoNJWUJFhfHV5SyXnN3zN1NAAIb+0lHhW2uT iaL6fnKQ2bjkNAGN0nDbszNBJ83k7SVxDfvdlehZqPlXic27WxJxodXaxS5JZyz4iOsOuWDA8NUH kiaoDrQYstTuJ4Lezmr6v5URDkGhA8g85VnaW+s7CU0KKFH9XGOXg+OOBvNXIPlGJMMGZY4grPfw RDXiDnTxoSYvjMKmqThpFtmXUZLXRp45zxNh/eMNLGkKLoTlDB8gxLfldXBCgZepgvytn99MVfcV JYL9EOYGSg1HZg707uNICGZB6lkhD12oaUNQOwwX977YcYXYuf4RvAZVdMS/jvUmcvnkAlLJEIEb PTKhgjt8CMn69YyJB5wz9iMEJRrQpOLWxB7OiXfvB5N3IKbe3kKUtv21ExGuvQzbamoooco33w+y gd4TCmEXLiydNVTB2kObhIaW3odw2+3IVoIiZck8qzoCiOmfD86M0wsSS1I4qA0WX1bcLXfNJExY cWYwd+1SrY33qboylaYD+bAJZDa8GbwmR52sKdKg/K2fsuPebzp8hJXmLAAQssLNklEjFT7hMVdC cTaoofhi0l4Jw7wb03YCSutxW6yJKhAU9JehqUOIgBBpp8Fb+rb8l8XlniUasgACFpJryTlHDNn4 ZrY=
    =MhCl
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)