• [RFR] wml://lts/security/2022/dla-303{2,3}.wml

    From Jean-Pierre Giraud@21:1/5 to All on Mon May 30 10:40:01 2022
    This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------X4hSXmNdkYBjmJnumXahzlPI
    Content-Type: multipart/mixed; boundary="------------FLmXePYdOJDkzGtV2l7Xetpz"

    --------------FLmXePYdOJDkzGtV2l7Xetpz
    Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64

    Qm9uam91ciwNCmRldXggbm91dmVsbGVzIGFubm9uY2VzIGRlIHPDqWN1cml0w6kgb250IMOp dMOpIHB1Ymxpw6llcy4gRW4gdm9pY2kgdW5lIA0KdHJhZHVjdGlvbi4gTWVyY2kgZCdhdmFu Y2UgcG91ciB2b3MgcmVsZWN0dXJlcy4NCkFtaWNhbGVtZW50LA0KamlwZWdlDQo= --------------FLmXePYdOJDkzGtV2l7Xetpz
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dla-3033.wml" Content-Disposition: attachment; filename="dla-3033.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249IjZkNjBl MmU5YzFkZTdmM2ZhMDhiOWM0MGRiZThlOTNlMDIwM2U4N2IiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6kgcG91ciBMVFM8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZv Pgo8cD5TbWFydHkzIGVzdCB1biBtb3RldXIgZGUgbW9kw6hsZXMgcG91ciBQSFAuIElsIGEg w6l0w6kgZMOpY291dmVydCBxdWUgbGVzCmF1dGV1cnMgZGUgbW9kw6hsZXMgcG91dmFpZW50 IGluamVjdGVyIGR1IGNvZGUgUEhQIGVuIGNob2lzaXNzYW50IGRlcyBub21zCmRlIDxxPnti bG9ja308L3E+IG91IGRlIGZpY2hpZXIgPHE+e2luY2x1ZGV9PC9xPiBtYWx2ZWlsbGFudHMu PC9wPgoKPHA+UG91ciBEZWJpYW7CoDkgPHE+U3RyZXRjaDwvcT4sIGNlIHByb2Jsw6htZSBh IMOpdMOpIGNvcnJpZ8OpIGRhbnMgbGEgdmVyc2lvbgozLjEuMzErMjAxNjEyMTQuMS5jN2Q0 MmU0K3NlbGZwYWNrMS0yK2RlYjl1Ni48L3A+Cgo8cD5Ob3VzIHZvdXMgcmVjb21tYW5kb25z IGRlIG1ldHRyZSDDoCBqb3VyIHZvcyBwYXF1ZXRzIHNtYXJ0eTMuPC9wPgoKPHA+UG91ciBk aXNwb3NlciBkJ3VuIMOpdGF0IGTDqXRhaWxsw6kgc3VyIGxhIHPDqWN1cml0w6kgZGUgc21h cnR5MywgdmV1aWxsZXoKY29uc3VsdGVyIHNhIHBhZ2UgZGUgc3VpdmkgZGUgc8OpY3VyaXTD qSDDoCBsJ2FkcmVzc2XCoDoKPGEgcmVsPSJub2ZvbGxvdyIgaHJlZj0iaHR0cHM6Ly9zZWN1 cml0eS10cmFja2VyLmRlYmlhbi5vcmcvdHJhY2tlci9zbWFydHkzIj5cCmh0dHBzOi8vc2Vj dXJpdHktdHJhY2tlci5kZWJpYW4ub3JnL3RyYWNrZXIvc21hcnR5MzwvYT4uPC9wPgoKPHA+ UGx1cyBk4oCZaW5mb3JtYXRpb25zIMOgIHByb3BvcyBkZXMgYW5ub25jZXMgZGUgc8OpY3Vy aXTDqSBkZSBEZWJpYW4gTFRTLApjb21tZW50IGFwcGxpcXVlciBjZXMgbWlzZXMgw6Agam91 ciBkYW5zIHZvdHJlIHN5c3TDqG1lIGV0IGxlcyBxdWVzdGlvbnMKZnLDqXF1ZW1tZW50IHBv c8OpZXMgcGV1dmVudCDDqnRyZSB0cm91dsOpZXMgc3VywqA6CjxhIHJlbD0ibm9mb2xsb3ci IGhyZWY9Imh0dHBzOi8vd2lraS5kZWJpYW4ub3JnL0xUUyI+aHR0cHM6Ly93aWtpLmRlYmlh bi5vcmcvTFRTPC9hPi48L3A+CjwvZGVmaW5lLXRhZz4KCiMgZG8gbm90IG1vZGlmeSB0aGUg Zm9sbG93aW5nIGxpbmUKI2luY2x1ZGUgIiQoRU5HTElTSERJUikvbHRzL3NlY3VyaXR5LzIw MjIvZGxhLTMwMzMuZGF0YSIKIyAkSWQ6ICQK
    --------------FLmXePYdOJDkzGtV2l7Xetpz
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dla-3032.wml" Content-Disposition: attachment; filename="dla-3032.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249IjcwN2Zk Zjc5ZDAwYTA4ZmM4YjgyNTZiMDZhYmMxOTdiMTc1MDZjNTAiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6kgcG91ciBMVFM8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZv Pgo8cD5VbiBkw6lmYXV0IGEgw6l0w6kgZMOpY291dmVydCBkYW5zIGxhIGZvbmN0aW9uIGNo ZWNrX2NodW5rX25hbWUoKSBkZQpwbmdjaGVjaywgdW4gb3V0aWwgcG91ciB2w6lyaWZpZXIg bCdpbnTDqWdyaXTDqSBkZXMgZmljaGllcnMgUE5HLCBKTkcgZXQgTU5HLgpDZSBkw6lmYXV0 IHBlcm1ldCDDoCB1biBhdHRhcXVhbnQgcXVpIHBldXQgdHJhbnNtZXR0cmUgdW4gZmljaGll ciBtYWx2ZWlsbGFudApwb3VyIHRyYWl0ZW1lbnQgw6AgcG5nY2hlY2sgZGUgcHJvdm9xdWVy IHVuIGTDqW5pIGRlIHNlcnZpY2UgdGVtcG9yYWlyZS48L3A+Cgo8cD5Qb3VyIERlYmlhbsKg OSA8cT5TdHJldGNoPC9xPiwgY2UgcHJvYmzDqG1lIGEgw6l0w6kgY29ycmlnw6kgZGFucyBs YSB2ZXJzaW9uCjIuMy4wLTcrZGViOXUxLjwvcD4KCjxwPk5vdXMgdm91cyByZWNvbW1hbmRv bnMgZGUgbWV0dHJlIMOgIGpvdXIgdm9zIHBhcXVldHMgcG5nY2hlY2suPC9wPgoKPHA+UG91 ciBkaXNwb3NlciBkJ3VuIMOpdGF0IGTDqXRhaWxsw6kgc3VyIGxhIHPDqWN1cml0w6kgZGUg cG5nY2hlY2ssIHZldWlsbGV6CmNvbnN1bHRlciBzYSBwYWdlIGRlIHN1aXZpIGRlIHPDqWN1 cml0w6kgw6AgbCdhZHJlc3NlwqA6CjxhIHJlbD0ibm9mb2xsb3ciIGhyZWY9Imh0dHBzOi8v c2VjdXJpdHktdHJhY2tlci5kZWJpYW4ub3JnL3RyYWNrZXIvcG5nY2hlY2siPlwKaHR0cHM6 Ly9zZWN1cml0eS10cmFja2VyLmRlYmlhbi5vcmcvdHJhY2tlci9wbmdjaGVjazwvYT4uPC9w PgoKPHA+UGx1cyBk4oCZaW5mb3JtYXRpb25zIMOgIHByb3BvcyBkZXMgYW5ub25jZXMgZGUg c8OpY3VyaXTDqSBkZSBEZWJpYW4gTFRTLApjb21tZW50IGFwcGxpcXVlciBjZXMgbWlzZXMg w6Agam91ciBkYW5zIHZvdHJlIHN5c3TDqG1lIGV0IGxlcyBxdWVzdGlvbnMKZnLDqXF1ZW1t ZW50IHBvc8OpZXMgcGV1dmVudCDDqnRyZSB0cm91dsOpZXMgc3VywqA6CjxhIHJlbD0ibm9m b2xsb3ciIGhyZWY9Imh0dHBzOi8vd2lraS5kZWJpYW4ub3JnL0xUUyI+aHR0cHM6Ly93aWtp LmRlYmlhbi5vcmcvTFRTPC9hPi48L3A+CjwvZGVmaW5lLXRhZz4KCiMgZG8gbm90IG1vZGlm eSB0aGUgZm9sbG93aW5nIGxpbmUKI2luY2x1ZGUgIiQoRU5HTElTSERJUikvbHRzL3NlY3Vy aXR5LzIwMjIvZGxhLTMwMzIuZGF0YSIKIyAkSWQ6ICQK

    --------------FLmXePYdOJDkzGtV2l7Xetpz--

    --------------X4hSXmNdkYBjmJnumXahzlPI--

    -----BEGIN PGP SIGNATURE-----

    wsF5BAABCAAjFiEEcH/R3vmpi4JWBoDfeBP2a44wMXIFAmKUgUoFAwAAAAAACgkQeBP2a44wMXJJ cg//ZDiBbSa1jkk/l4VwtBXrSEQ7FVEsJxB172MIRxpHn3EbAEMkuNOLsYQgW+AcY5X9tGBUHVT1 UZPzd9FS+9PWo4iVVbyaPpuM9IBmMqjdUU7JLTuW2XSGsGyisp+os/DeyN6pOc34i8qsY2oS5ELK 4ZrJMwRbXCVhtJqV6RLY3t6+xzpfJxGn27RQaHQrrVK1WmbXpDqF8yBF6MeP4vFFAYtVsJFxXxND 8xrc4KUIJvowWLwRjCWtSSJwWK0RDi45UCSOGiYvaODLy1TMUu3O33OxmvhTNCo1PYOsWRMqu4S/ O6Wgh+4Szrc30WVqUbA2Qt+PqMgp6Yz0d30PO2dd10YdgO08Y3FLvmlVQ58CYStyMFhfZpX6VaRG yLNRwbwwlBzFuwhHEaNPqiU2YyxQdSfbil0CgQqPgIDDhSwZJv4GOGFblTV3Zr1FVGJKXMTs+crk 3wtAY+qk2prAlWhGRcuwu/CXqw+nr5SL9+fhIJw8cZ85rIn2oKJ57z8iME2UIIR7kmSjQAYEivNk RNL2G6QDrOw+w/JyEdU3dqYOr/GPB4Y7MNSYqPpA+xZGz/Ory/TykrHZuITrn2cPuTYToZ+nWgG/ L1edAGqpE4ujdnLDUUwso2fy+uu6yikIrgihy1dB9FTjXrSzUyoPqQjp2o/Def8M0cZG94qygKtr kRE=
    =p+az
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Jean-Pierre Giraud@21:1/5 to All on Mon May 30 11:50:01 2022
    This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------j76aO0ICF9PBY5Gv56iKCJGu
    Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64

    Qm9uam91ciwNCg0KTGUgMzAvMDUvMjAyMiDDoCAxMTozNiwgYnVidWJAbm8tbG9nLm9yZyBh IMOpY3JpdMKgOg0KPiBCb25qb3VyLA0KPiAgICB1bmUgc3VnZ2VzdGlvbiwNCj4+IGRldXgg bm91dmVsbGVzIGFubm9uY2VzIGRlIHPDqWN1cml0w6kgb250IMOpdMOpIHB1Ymxpw6llcy4g RW4gdm9pY2kgdW5lDQo+PiB0cmFkdWN0aW9uLiBNZXJjaSBkJ2F2YW5jZSBwb3VyIHZvcyBy ZWxlY3R1cmVzLg0KPj4gQW1pY2FsZW1lbnQsDQo+PiBqaXBlZ2UNCj4+DQo+IGFtaWNhbGVt ZW50LA0KPiAgICAgIGJ1YnUNCkplICBjb25zZXJ2ZSBtYSB0cmFkdWN0aW9uLCBjYXIgbCdv cmlnaW5hbCBkaXQgOg0KYSBtYWxpY2lvdXMge2Jsb2NrfSBuYW1lIG9yIHtpbmNsdWRlfSBm aWxlIG5hbWUNCkFtaWNhbGVtZW50LA0KamlwZWdlDQo=

    --------------j76aO0ICF9PBY5Gv56iKCJGu--

    -----BEGIN PGP SIGNATURE-----

    wsF5BAABCAAjFiEEcH/R3vmpi4JWBoDfeBP2a44wMXIFAmKUkTUFAwAAAAAACgkQeBP2a44wMXJu Gw/+ND+McdBRDBGbpQqWDn3R9l9x2z0FdqSvhFK9bdfRW5hG10aII8sjKYRi0AC1ojNjsQkWMH0Y zrPkjqUti/ytYqsT2jcaQcrb0ZaGVvJnJNTw9c2We6TuPtRpZUBckXdO9CoG4itXofH4qrsxJjz5 29qTzCMLKwBHLSCoGYCcjJzR5PB0AtyRXbmuWJ30FTpVTerJjkwf+UifTwawOFoxogJP7lSv8nql 9eQpxaN8ena9NxtrYPM8xccyKebZW2Am+F3R3Y8mfXrdq+qiO72D9h5VHhmgTvYg0NjehQr7kP38 imrZUfbYi95GDBykakHaWy3wMeugGD6MDJW8ksA0BTr8nnhuW8wWRYDYKbM4fp2WDycaKv8drNnT kypiPobekD4dW6XfXCeNjxkcWNm2EOhQjLSxH8sznYHReoX8oq+HNb3ZW8YyP+aNX/JdcGm8BPRz r17zAEICKOlrTnC/p1ni7kDMMMdcH3F/mC8ytLVY2oThfGH1Q8BE2XBhO3xhkBaYTkUQQJP8cIrD OJyvjEkUyPN7y/6+9xForEx5O83vKK/mVYac+AdpevLNTYWaRJUG+BKXeQl75t8fZEOACudoLtqx Ob2iyrAflZC2q/Z+nhNXsJIpvxeQDHboywxui8kevmZbalPc/UtPWAqbtNV9DHendTRyUebwa1Yc 47g=
    =8juy
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From [email protected]@21:1/5 to All on Mon May 30 11:40:01 2022
    Bonjour,
    une suggestion,
    deux nouvelles annonces de s�curit� ont �t� publi�es. En voici une traduction. Merci d'avance pour vos relectures.
    Amicalement,
    jipege

    amicalement,
    bubu
    --- dla-3033.wml 2022-05-30 11:31:20.912469018 +0200
    +++ dla-3033.relu.wml 2022-05-30 11:33:18.241948610 +0200
    @@ -3,7 +3,7 @@
    <define-tag moreinfo>
    <p>Smarty3 est un moteur de modèles pour PHP. Il a été découvert que les
    auteurs de modèles pouvaient injecter du code PHP en choisissant des noms
    -de <q>{block}</q> ou de fichier <q>{include}</q> malveillants.</p>
    +de fichiers <q>{block}</q> ou <q>{include}</q> malveillants.</p>

    <p>Pour Debian 9 <q>Stretch</q>, ce problème a été corrigé dans la version
    3.1.31+20161214.1.c7d42e4+selfpack1-2+deb9u6.</p>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From [email protected]@21:1/5 to All on Mon May 30 12:00:01 2022
    RE hello,
    Je conserve ma traduction, car l'original dit :
    a malicious {block} name or {include} file name
    Amicalement,
    jipege

    ok, j'ai pas lu la m�me,
    je me suis bas� sur https://www.debian.org/security/2022/dsa-5151
    bon je viens de voir que c'est pas le m�me num�ro de dsa/dla .. J'ai
    cherch� par titre...
    amicalement,
    bubu

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)