• [RFR] wml://security/2022/dsa-51{38,39,40,41}.wml

    From Jean-Pierre Giraud@21:1/5 to All on Fri May 20 09:00:01 2022
    This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------QnQ3JTTQir8D15gqsafwErsp
    Content-Type: multipart/mixed; boundary="------------HePbXcHWj7e7rqFvL0KBGJyP"

    --------------HePbXcHWj7e7rqFvL0KBGJyP
    Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64

    Qm9uam91ciwNCnF1YXRyZSBub3V2ZWxsZXMgYW5ub25jZXMgZGUgc8OpY3VyaXTDqSBvbnQg w6l0w6kgcHVibGnDqWVzLiBFbiB2b2ljaSB1bmUgDQp0cmFkdWN0aW9uLiBNZXJjaSBkJ2F2 YW5jZSBwb3VyIHZvcyByZWxlY3R1cmVzLg0KQW1pY2FsZW1lbnQsDQpqaXBlZ2UNCg== --------------HePbXcHWj7e7rqFvL0KBGJyP
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dsa-5141.wml" Content-Disposition: attachment; filename="dsa-5141.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249Ijg3NzY0 Y2Y3YzAyMGVjNWQ4Zjc1ZTc3MTYwNWU2MjA1MjVkNTE1ZmUiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6k8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZvPgo8cD5QbHVz aWV1cnMgcHJvYmzDqG1lcyBkZSBzw6ljdXJpdMOpIG9udCDDqXTDqSBkw6ljb3V2ZXJ0cyBk YW5zIFRodW5kZXJiaXJkLCBxdWkKcG91dmFpZW50IGF2b2lyIHBvdXIgY29uc8OpcXVlbmNl IHVuIGTDqW5pIGRlIHNlcnZpY2Ugb3UgbCdleMOpY3V0aW9uIGRlIGNvZGUKYXJiaXRyYWly ZS48L3A+Cgo8cD5Qb3VyIGxhIGRpc3RyaWJ1dGlvbiBvbGRzdGFibGUgKEJ1c3RlciksIGNl cyBwcm9ibMOobWVzIG9udCDDqXTDqSBjb3JyaWfDqXMKZGFucyBsYSB2ZXJzaW9uwqAxOjkx LjkuMC0xfmRlYjEwdTEuPC9wPgoKPHA+UG91ciBsYSBkaXN0cmlidXRpb24gc3RhYmxlIChC dWxsc2V5ZSksIGNlcyBwcm9ibMOobWVzIG9udCDDqXTDqSBjb3JyaWfDqXMKZGFucyBsYSB2 ZXJzaW9uwqAxOjkxLjkuMC0xfmRlYjExdTEuPC9wPgoKPHA+Tm91cyB2b3VzIHJlY29tbWFu ZG9ucyBkZSBtZXR0cmUgw6Agam91ciB2b3MgcGFxdWV0cyB0aHVuZGVyYmlyZC48L3A+Cgo8 cD5Qb3VyIGRpc3Bvc2VyIGQndW4gw6l0YXQgZMOpdGFpbGzDqSBzdXIgbGEgc8OpY3VyaXTD qSBkZSB0aHVuZGVyYmlyZCwKdmV1aWxsZXogY29uc3VsdGVyIHNhIHBhZ2UgZGUgc3Vpdmkg ZGUgc8OpY3VyaXTDqSDDoCBsJ2FkcmVzc2XCoDoKPGEgaHJlZj0iaHR0cHM6Ly9zZWN1cml0 eS10cmFja2VyLmRlYmlhbi5vcmcvdHJhY2tlci90aHVuZGVyYmlyZCI+XApodHRwczovL3Nl Y3VyaXR5LXRyYWNrZXIuZGViaWFuLm9yZy90cmFja2VyL3RodW5kZXJiaXJkPC9hPi48L3A+ CjwvZGVmaW5lLXRhZz4KCiMgZG8gbm90IG1vZGlmeSB0aGUgZm9sbG93aW5nIGxpbmUKI2lu Y2x1ZGUgIiQoRU5HTElTSERJUikvc2VjdXJpdHkvMjAyMi9kc2EtNTE0MS5kYXRhIgojICRJ ZDogJAo=
    --------------HePbXcHWj7e7rqFvL0KBGJyP
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dsa-5140.wml" Content-Disposition: attachment; filename="dsa-5140.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249IjUzYmRh OGFjN2JhNTZjNzVmMWE3ZmViNWNlNTU3Zjg5Yjg0ZjU3MWUiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6k8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZvPgo8cD5KYWNl ayBLb25pZWN6bnkgYSBkw6ljb3V2ZXJ0IHVuZSB2dWxuw6lyYWJpbGl0w6kgZCdpbmplY3Rp b24gU1FMIGRhbnMgbGUKZG9yc2FsIGJhY2stc3FsIGRlIHNsYXBkIGRhbnMgT3BlbkxEQVAs IHVuZSBpbXBsw6ltZW50YXRpb24gbGlicmUgZHUKcHJvdG9jb2xlIMKrwqBMaWdodHdlaWdo dCBEaXJlY3RvcnkgQWNjZXNzIFByb3RvY29swqDCuyAoTERBUCksIHBlcm1ldHRhbnQgw6Ag dW4KYXR0YXF1YW50IGRlIG1vZGlmaWVyIGxhIGJhc2UgZGUgZG9ubsOpZXMgcGVuZGFudCBk J3VuZSBvcMOpcmF0aW9uIGRlCnJlY2hlcmNoZSBkZSBMREFQIGxvcnMgZHUgdHJhaXRlbWVu dCBkJ3VuIGZpbHRyZSBkZSByZWNoZXJjaGUgY29udHJlZmFpdApwb3VyIGwnb2NjYXNpb24u PC9wPgoKPHA+UG91ciBsYSBkaXN0cmlidXRpb24gb2xkc3RhYmxlIChCdXN0ZXIpLCBjZSBw cm9ibMOobWUgYSDDqXTDqSBjb3JyaWfDqSBkYW5zCmxhIHZlcnNpb27CoDIuNC40NytkZnNn LTMrZGViMTB1Ny48L3A+Cgo8cD5Qb3VyIGxhIGRpc3RyaWJ1dGlvbiBzdGFibGUgKEJ1bGxz ZXllKSwgY2UgcHJvYmzDqG1lIGEgw6l0w6kgY29ycmlnw6kgZGFucwpsYSB2ZXJzaW9uwqAy LjQuNTcrZGZzZy0zK2RlYjExdTEuPC9wPgoKPHA+Tm91cyB2b3VzIHJlY29tbWFuZG9ucyBk ZSBtZXR0cmUgw6Agam91ciB2b3MgcGFxdWV0cyBvcGVubGRhcC48L3A+Cgo8cD5Qb3VyIGRp c3Bvc2VyIGQndW4gw6l0YXQgZMOpdGFpbGzDqSBzdXIgbGEgc8OpY3VyaXTDqSBkZSBvcGVu bGRhcCwgdmV1aWxsZXoKY29uc3VsdGVyIHNhIHBhZ2UgZGUgc3VpdmkgZGUgc8OpY3VyaXTD qSDDoCBsJ2FkcmVzc2XCoDoKPGEgaHJlZj0iaHR0cHM6Ly9zZWN1cml0eS10cmFja2VyLmRl Ymlhbi5vcmcvdHJhY2tlci9vcGVubGRhcCI+XApodHRwczovL3NlY3VyaXR5LXRyYWNrZXIu ZGViaWFuLm9yZy90cmFja2VyL29wZW5sZGFwPC9hPi48L3A+CjwvZGVmaW5lLXRhZz4KCiMg ZG8gbm90IG1vZGlmeSB0aGUgZm9sbG93aW5nIGxpbmUKI2luY2x1ZGUgIiQoRU5HTElTSERJ Uikvc2VjdXJpdHkvMjAyMi9kc2EtNTE0MC5kYXRhIgojICRJZDogJAo= --------------HePbXcHWj7e7rqFvL0KBGJyP
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dsa-5139.wml" Content-Disposition: attachment; filename="dsa-5139.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249IjIxOWVh MWI3YTI5NDM5ZmNmNzU0M2FhNzMxNDAwZmYzZWFhZTQwNjEiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6k8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZvPgo8cD5FbGlz b24gTml2ZW4gYSBkw6ljb3V2ZXJ0IHF1ZSBsZSBzY3JpcHQgY19yZWhhc2ggaW5jbHVzIGRh bnMgT3BlblNTTCBuZQpuZSBuZXR0b3lhaXQgcGFzIGNvcnJlY3RlbWVudCBsZXMgbcOpdGFj YXJhY3TDqHJlcyBkZSBsJ2ludGVycHLDqXRldXIgZGUKY29tbWFuZGUgY2UgcXVpIHBvdXZh aXQgYXZvaXIgcG91ciBjb25zw6lxdWVuY2UgbCdleMOpY3V0aW9uIGRlIGNvbW1hbmRlcwph cmJpdHJhaXJlcy48L3A+Cgo8cD5Qb3VyIGxhIGRpc3RyaWJ1dGlvbiBvbGRzdGFibGUgKEJ1 c3RlciksIGNlIHByb2Jsw6htZSBhIMOpdMOpIGNvcnJpZ8OpIGRhbnMKbGEgdmVyc2lvbsKg MS4xLjFuLTArZGViMTB1Mi48L3A+Cgo8cD5Qb3VyIGxhIGRpc3RyaWJ1dGlvbiBzdGFibGUg KEJ1bGxzZXllKSwgY2UgcHJvYmzDqG1lIGEgw6l0w6kgY29ycmlnw6kgZGFucwpsYSB2ZXJz aW9uwqAxLjEuMW4tMCtkZWIxMXUyLjwvcD4KCjxwPk5vdXMgdm91cyByZWNvbW1hbmRvbnMg ZGUgbWV0dHJlIMOgIGpvdXIgdm9zIHBhcXVldHMgb3BlbnNzbC48L3A+Cgo8cD5Qb3VyIGRp c3Bvc2VyIGQndW4gw6l0YXQgZMOpdGFpbGzDqSBzdXIgbGEgc8OpY3VyaXTDqSBkZSBvcGVu c3NsLCB2ZXVpbGxlegpjb25zdWx0ZXIgc2EgcGFnZSBkZSBzdWl2aSBkZSBzw6ljdXJpdMOp IMOgIGwnYWRyZXNzZcKgOgo8YSBocmVmPSJodHRwczovL3NlY3VyaXR5LXRyYWNrZXIuZGVi aWFuLm9yZy90cmFja2VyL29wZW5zc2wiPlwKaHR0cHM6Ly9zZWN1cml0eS10cmFja2VyLmRl Ymlhbi5vcmcvdHJhY2tlci9vcGVuc3NsPC9hPi48L3A+CjwvZGVmaW5lLXRhZz4KCiMgZG8g bm90IG1vZGlmeSB0aGUgZm9sbG93aW5nIGxpbmUKI2luY2x1ZGUgIiQoRU5HTElTSERJUikv c2VjdXJpdHkvMjAyMi9kc2EtNTEzOS5kYXRhIgojICRJZDogJAo= --------------HePbXcHWj7e7rqFvL0KBGJyP
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dsa-5138.wml" Content-Disposition: attachment; filename="dsa-5138.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249ImNjMGI2 YmJmYWJlYjBjODFhMjJjZWQxYTJiMTZmNTliY2FhZDkzODYiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6k8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZvPgo8cD5MZSBz ZXJ2ZXVyIFdTR0kgV2FpdHJlc3Mgw6l0YWl0IHZ1bG7DqXJhYmxlIMOgIHVuZSBkaXNzaW11 bGF0aW9uIGRlIHJlcXXDqnRlCkhUVFAgZGFucyBjZXJ0YWlucyBzY8OpbmFyaW9zIGxvcnMg ZGUgc29uIHV0aWxpc2F0aW9uIGRlcnJpw6hyZSB1bgptYW5kYXRhaXJlLjwvcD4KCjxwPlBv dXIgbGEgZGlzdHJpYnV0aW9uIG9sZHN0YWJsZSAoQnVzdGVyKSwgY2UgcHJvYmzDqG1lIGEg w6l0w6kgY29ycmlnw6kgZGFucwpsYSB2ZXJzaW9uwqAxLjIuMH5iMi0yK2RlYjEwdTEuPC9w PgoKPHA+UG91ciBsYSBkaXN0cmlidXRpb24gc3RhYmxlIChCdWxsc2V5ZSksIGNlIHByb2Js w6htZSBhIMOpdMOpIGNvcnJpZ8OpIGRhbnMKbGEgdmVyc2lvbsKgMS40LjQtMS4xK2RlYjEx dTEuPC9wPgoKPHA+Tm91cyB2b3VzIHJlY29tbWFuZG9ucyBkZSBtZXR0cmUgw6Agam91ciB2 b3MgcGFxdWV0cyB3YWl0cmVzcy48L3A+Cgo8cD5Qb3VyIGRpc3Bvc2VyIGQndW4gw6l0YXQg ZMOpdGFpbGzDqSBzdXIgbGEgc8OpY3VyaXTDqSBkZSB3YWl0cmVzcywgdmV1aWxsZXoKY29u c3VsdGVyIHNhIHBhZ2UgZGUgc3VpdmkgZGUgc8OpY3VyaXTDqSDDoCBsJ2FkcmVzc2XCoDoK PGEgaHJlZj0iaHR0cHM6Ly9zZWN1cml0eS10cmFja2VyLmRlYmlhbi5vcmcvdHJhY2tlci93 YWl0cmVzcyI+XApodHRwczovL3NlY3VyaXR5LXRyYWNrZXIuZGViaWFuLm9yZy90cmFja2Vy L3dhaXRyZXNzPC9hPi48L3A+CjwvZGVmaW5lLXRhZz4KCiMgZG8gbm90IG1vZGlmeSB0aGUg Zm9sbG93aW5nIGxpbmUKI2luY2x1ZGUgIiQoRU5HTElTSERJUikvc2VjdXJpdHkvMjAyMi9k c2EtNTEzOC5kYXRhIgojICRJZDogJAo=

    --------------HePbXcHWj7e7rqFvL0KBGJyP--

    --------------QnQ3JTTQir8D15gqsafwErsp--

    -----BEGIN PGP SIGNATURE-----

    wsF5BAABCAAjFiEEcH/R3vmpi4JWBoDfeBP2a44wMXIFAmKHO3MFAwAAAAAACgkQeBP2a44wMXKW ExAAmMY2nXbSZGLGWhY3PRQLj59Kf316KIXi8cH3EGx9wk+O+H3kwuOHnP3P30leby5nSNeFgF+R uRmwtaxbhLeVXKdMBG/mU8ufHDwQhy4bGrhGitCqpkesZTbxp3glRv1Hod+Z6ehVbm6Lc53nEE22 kpLlUIDyXCzUrJ8zmT8TowEHNExUUAdab/6elzFqWTFjz1uanKZ/2Z5GcHk+YqVtCS6cSZ6oS9oL bSDod9oMYo9NPWVplnkjqDtUJBjmsaAy9kc6AjfwNFDTqa1xBRcgzpEMa0amdzSncHSfSojY81vF MxL+mmF1uzxx9MitTS22COLBOQ4+uDMyaET8t0QjD2XeMRNlVFsZqx9Ck/XCHBYps2D4jkZXHRzH qjMDs8YX3wsbMDC/ehocEVXlPKuym8zrGchWfWdBmQA5EjQ3TWxIh3Mn+sQ5ppCwN9dVN+DPtR24 g0T+VVO6o1ZRKNWW6RzhwMAvIvdiZe0HdUaUogg4f3uNe4L0A4ueNiEMwyc7HC9XM3pn0FMLyoiZ dQp+XxM2AIWQswiKVsy+fdICTa8vxFuuMh90DCZbv5N+7RC5AiQ+dK1HJduCadm+88o5NCXgHwEL qGQfhwMZ9AQtNx1IM5oa3kVxHA3b1E4tjqcsU0Xf4vhw4ePF7k5N9hn+ZQq4GHpW9sEI/o+205y1 LZM=
    =eZ67
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From [email protected]@21:1/5 to All on Fri May 20 11:50:01 2022
    Bonjour,
    un d�tail,
    amicalement,
    bubu
    --- dsa-5140.wml 2022-05-20 11:42:05.886858828 +0200
    +++ dsa-5140.relu.wml 2022-05-20 11:43:16.087740953 +0200
    @@ -4,7 +4,7 @@
    <p>Jacek Konieczny a découvert une vulnérabilité d'injection SQL dans le
    dorsal back-sql de slapd dans OpenLDAP, une implémentation libre du
    protocole « Lightweight Directory Access Protocol » (LDAP), permettant à un
    -attaquant de modifier la base de données pendant d'une opération de +attaquant de modifier la base de données pendant une opération de
    recherche de LDAP lors du traitement d'un filtre de recherche contrefait
    pour l'occasion.</p>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)