• [RFR] wml://lts/security/2022/dla-304{5,7}.wml

    From Jean-Pierre Giraud@21:1/5 to All on Wed Jun 8 10:00:02 2022
    This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------VGI13uzXPUA7cd2IMzpXzzBz
    Content-Type: multipart/mixed; boundary="------------S7mpuBTa5x8jiKRBP1toPuJQ"

    --------------S7mpuBTa5x8jiKRBP1toPuJQ
    Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64

    Qm9uam91ciwNCmRldXggbm91dmVsbGVzIGFubm9uY2VzIGRlIHPDqWN1cml0w6kgb250IMOp dMOpIHB1Ymxpw6llcy4gRW4gdm9pY2kgdW5lIA0KdHJhZHVjdGlvbi4gTWVyY2kgZCdhdmFu Y2UgcG91ciB2b3MgcmVsZWN0dXJlcy4NCkFtaWNhbGVtZW50LA0KamlwZWdlDQo= --------------S7mpuBTa5x8jiKRBP1toPuJQ
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dla-3047.wml" Content-Disposition: attachment; filename="dla-3047.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249IjY0NzQ0 OTIxOWZiNDY3MTk1NDNkMWY3MWFhNjBlNzgyZTQyZDExZWIiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6kgcG91ciBMVFM8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZv Pgo8cD5MZSBwYXF1ZXQgRGViaWFuIGQnQXZhaGksIHVuIGNhZHJpY2llbCBwb3VyIGxlIDxx Pk11bHRpY2FzdCBETlMgU2VydmljZQpEaXNjb3Zlcnk8L3E+LCBleMOpY3V0YWl0IGxlIHNj cmlwdCBhdmFoaS1kYWVtb24tY2hlY2stZG5zLnNoIGF2ZWMgbGVzCnByaXZpbMOoZ2VzIGR1 IHN1cGVydXRpbGlzYXRldXIgY2UgcXVpIHBvdXZhaXQgcGVybWV0dHJlIMOgIHVuIGF0dGFx dWFudApsb2NhbCBkZSBwcm92b3F1ZXIgdW4gZMOpbmkgZGUgc2VydmljZSBvdSBkZSBjcsOp ZXIgZGVzIGZpY2hpZXJzIHZpZGVzCmFyYml0cmFpcmVzIMOgIGwnYWlkZSBkJ3VuZSBwYXIg bGllbiBzeW1ib2xpcXVlIHN1ciBkZXMgZmljaGllcnMgc291cwovdmFyL3J1bi9hdmFoaS1k YWVtb24uIExlIHNjcmlwdCBlc3QgbWFpbnRlbmFudCBleMOpY3V0w6kgYXZlYyBsZXMgcHJp dmlsw6hnZXMKZGUgbCd1dGlsaXNhdGV1ciBldCBkdSBncm91cGUgYXZhaGkgZXQgcmVxdWll cnQgc3VkbyBhZmluIGRlIHLDqWFsaXNlciBjZWxhLjwvcD4KCjxwPkxlIHNjcmlwdCBzdXNt ZW50aW9ubsOpIGEgw6l0w6kgcmV0aXLDqSDDoCBwYXJ0aXIgZGUgRGViaWFuwqAxMCA8cT5C dXN0ZXI8L3E+LgpMZSBwYWxsaWF0aWYgbmUgcG91cnJhaXQgcGFzIMOqdHJlIGltcGzDqW1l bnTDqSBwb3VyIERlYmlhbsKgOSA8cT5TdHJldGNoPC9xPgpwYXJjZSBxdWUgbGlibnNzLW1k bnPCoDAuMTAgbmUgZm91cm5pdCBwYXMgbGEgZm9uY3Rpb24gcmVxdWlzZSBwb3VyIGxlCnJl bXBsYWNlci48L3A+Cgo8cD5FbiBvdXRyZSwgaWwgYSDDqXTDqSBkw6ljb3V2ZXJ0Cig8YSBo cmVmPSJodHRwczovL3NlY3VyaXR5LXRyYWNrZXIuZGViaWFuLm9yZy90cmFja2VyL0NWRS0y MDIxLTM0NjgiPkNWRS0yMDIxLTM0Njg8L2E+KQpxdWUgbCfDqXbDqW5lbWVudCB1dGlsaXPD qSBwb3VyIHNpZ25hbGVyIGwnaW50ZXJydXB0aW9uIGRlIGxhIGNvbm5leGlvbiBkdQpjbGll bnQgc3VyIGxlIHNvY2tldCBVbml4IGQnYXZhaGkgbidlc3QgcGFzIGNvcnJlY3RlbWVudCBn w6lyw6kgY29ycmVjdGVtZW50CmRhbnMgbGEgZm9uY3Rpb24gY2xpZW50X3dvcmssIHBlcm1l dHRhbnQgw6AgdW4gYXR0YXF1YW50IGxvY2FsIGRlIGTDqWNsZW5jaGVyCnVuZSBib3VjbGUg aW5maW5pZS48L3A+Cgo8cD5Qb3VyIERlYmlhbsKgOSA8cT5TdHJldGNoPC9xPiwgY2VzIHBy b2Jsw6htZXMgb250IMOpdMOpIGNvcnJpZ8OpcyBkYW5zIGxhCnZlcnNpb24gMC42LjMyLTIr ZGViOXUxLjwvcD4KCjxwPk5vdXMgdm91cyByZWNvbW1hbmRvbnMgZGUgbWV0dHJlIMOgIGpv dXIgdm9zIHBhcXVldHMgYXZhaGkuPC9wPgoKPHA+UG91ciBkaXNwb3NlciBkJ3VuIMOpdGF0 IGTDqXRhaWxsw6kgc3VyIGxhIHPDqWN1cml0w6kgZGUgYXZhaGksIHZldWlsbGV6CmNvbnN1 bHRlciBzYSBwYWdlIGRlIHN1aXZpIGRlIHPDqWN1cml0w6kgw6AgbCdhZHJlc3NlwqA6Cjxh IHJlbD0ibm9mb2xsb3ciIGhyZWY9Imh0dHBzOi8vc2VjdXJpdHktdHJhY2tlci5kZWJpYW4u b3JnL3RyYWNrZXIvYXZhaGkiPlwKaHR0cHM6Ly9zZWN1cml0eS10cmFja2VyLmRlYmlhbi5v cmcvdHJhY2tlci9hdmFoaTwvYT4uPC9wPgoKPHA+UGx1cyBk4oCZaW5mb3JtYXRpb25zIMOg IHByb3BvcyBkZXMgYW5ub25jZXMgZGUgc8OpY3VyaXTDqSBkZSBEZWJpYW4gTFRTLApjb21t ZW50IGFwcGxpcXVlciBjZXMgbWlzZXMgw6Agam91ciBkYW5zIHZvdHJlIHN5c3TDqG1lIGV0 IGxlcyBxdWVzdGlvbnMKZnLDqXF1ZW1tZW50IHBvc8OpZXMgcGV1dmVudCDDqnRyZSB0cm91 dsOpZXMgc3VywqA6CjxhIHJlbD0ibm9mb2xsb3ciIGhyZWY9Imh0dHBzOi8vd2lraS5kZWJp YW4ub3JnL0xUUyI+aHR0cHM6Ly93aWtpLmRlYmlhbi5vcmcvTFRTPC9hPi48L3A+CjwvZGVm aW5lLXRhZz4KCiMgZG8gbm90IG1vZGlmeSB0aGUgZm9sbG93aW5nIGxpbmUKI2luY2x1ZGUg IiQoRU5HTElTSERJUikvbHRzL3NlY3VyaXR5LzIwMjIvZGxhLTMwNDcuZGF0YSIKIyAkSWQ6
    ICQK
    --------------S7mpuBTa5x8jiKRBP1toPuJQ
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dla-3045.wml" Content-Disposition: attachment; filename="dla-3045.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249ImQ0Zjk1 OWVjZDQ4ZTk1Y2ZjYTNjNWQzYWM4ODVhMTgwZWRiYTliYjIiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6kgcG91ciBMVFM8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZv PgoKPHA+SWwgeSBhdmFpdCB1bmUgcG90ZW50aWVsbGUgdnVsbsOpcmFiaWxpdMOpIGRlIHNj cmlwdCBpbnRlcnNpdGUgZGFucwpwaHAtaG9yZGUtbWltZS12aWV3ZXIsIHVuZSBiaWJsaW90 aMOocXVlIGRlIHZpc3VhbGlzZXVyIE1JTUUgcG91ciBsYQpwbGF0ZWZvcm1lIGQnb3V0aWwg ZGUgdHJhdmFpbCBlbiBncm91cGUgSG9yZGUuPC9wPgoKPHVsPgoKPGxpPjxhIGhyZWY9Imh0 dHBzOi8vc2VjdXJpdHktdHJhY2tlci5kZWJpYW4ub3JnL3RyYWNrZXIvQ1ZFLTIwMjItMjY4 NzQiPkNWRS0yMDIyLTI2ODc0PC9hPgoKPHA+bGliL0hvcmRlL01pbWUvVmlld2VyL09vby5w aHAgZGFucyBIb3JkZSBNaW1lX1ZpZXdlciBhdmFudCBsYQp2ZXJzaW9uwqAyLjIuNCBwZXJt ZXQgdW4gc2NyaXB0IGludGVyc2l0ZSDDoCBsJ2FpZGUgZCd1biBkb2N1bWVudCBPcGVuT2Zm aWNlLAptZW5hbnQgw6AgdW5lIHByaXNlIGRlIGNvbnRyw7RsZSBkZSBjb21wdGUgZGFucyA8 cT5Ib3JkZSBHcm91cHdhcmUgV2VibWFpbApFZGl0aW9uPC9xPi4gQ2VsYSBzdXJ2aWVudCBh cHLDqHMgbGUgcmVuZHUgWFNMVC48L3A+PC9saT4KCjwvdWw+Cgo8cD5Qb3VyIERlYmlhbsKg OSA8cT5TdHJldGNoPC9xPiwgY2VzIHByb2Jsw6htZXMgb250IMOpdMOpIGNvcnJpZ8OpcyBk YW5zIGxhCnZlcnNpb24gMi4yLjEtMStkZWI5dTEuPC9wPgoKPHA+Tm91cyB2b3VzIHJlY29t bWFuZG9ucyBkZSBtZXR0cmUgw6Agam91ciB2b3MgcGFxdWV0cwpwaHAtaG9yZGUtbWltZS12 aWV3ZXIuPC9wPgoKPHA+UGx1cyBk4oCZaW5mb3JtYXRpb25zIMOgIHByb3BvcyBkZXMgYW5u b25jZXMgZGUgc8OpY3VyaXTDqSBkZSBEZWJpYW4gTFRTLApjb21tZW50IGFwcGxpcXVlciBj ZXMgbWlzZXMgw6Agam91ciBkYW5zIHZvdHJlIHN5c3TDqG1lIGV0IGxlcyBxdWVzdGlvbnMK ZnLDqXF1ZW1tZW50IHBvc8OpZXMgcGV1dmVudCDDqnRyZSB0cm91dsOpZXMgc3VywqA6Cjxh IGhyZWY9Imh0dHBzOi8vd2lraS5kZWJpYW4ub3JnL0xUUyI+aHR0cHM6Ly93aWtpLmRlYmlh bi5vcmcvTFRTPC9hPi48L3A+CjwvZGVmaW5lLXRhZz4KCiMgZG8gbm90IG1vZGlmeSB0aGUg Zm9sbG93aW5nIGxpbmUKI2luY2x1ZGUgIiQoRU5HTElTSERJUikvbHRzL3NlY3VyaXR5LzIw MjIvZGxhLTMwNDUuZGF0YSIKIyAkSWQ6ICQK

    --------------S7mpuBTa5x8jiKRBP1toPuJQ--

    --------------VGI13uzXPUA7cd2IMzpXzzBz--

    -----BEGIN PGP SIGNATURE-----

    wsF5BAABCAAjFiEEcH/R3vmpi4JWBoDfeBP2a44wMXIFAmKgVqMFAwAAAAAACgkQeBP2a44wMXLp 4hAAq0WhmPvG6Hi5HSOp6lRRZQhUozD2QDYh6QjHSkovapPPYRm9tpA+PbUJKIHZXBVuLV+Ezos6 StoqVDeTwF5cGO543tGyKnjMJ80hF5xH//4KSFXjgmpsMPRe2muKtKYBVub+jUEZVC/tOW9iXBBV vLHNaXdHHpK+m0r90NRJPZjDOD5WWr/PDHGH/AzC6hL72aV3cceAYwgDqanwQNFyCxlEJSyVAYAt qeSfE6hyq4D99LY2mUady56pvhUQb6yRSKnq7hfORkYtSTQ7NZ/JOq7tnFutlQMPi+uQR6gHmrAe 7lxunkiT8754qhIw5FbW8KdV0/7OqKrGXX5bkrmtAcQgby+tElhkKR3PbEBpf7fSKcVuWv9OAB4/ uNK4a1V0FccX1BACq8iVBPWRkdy/bCjcVIJRsIgkatZbQ/slhOmbU/JFn88cuaAN69F1AlnZSyyr YfyFS90cz1+Yu8VmGHAt5cFli6WVIeSVAfrZFtwo+gmwGj2PtDfudsvRB7bwAPuy3y09jwj2Eivc 4vIdjCg1EbHxAOS5fzsXq1581BDjpGrjLhHULUJeKcaG/DkUmYsBtPSdlJIm6pJPktUje+KTyZ/0 AnFJ1cDDI8xYkXLXtmnO/jf2o6uzVbYkRxJdE9Ryc0bvqRquhklLQqlQACb4lpFoDxWh2qfnGso6 s6w=
    =XzN6
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From [email protected]@21:1/5 to All on Wed Jun 8 11:00:01 2022
    Bonjour,
    Bonjour,
    d�tail , suggestion (ou bien pourrait ne pas �tre)
    amicalement, bubu
    --- dla-3047.wml 2022-06-08 10:49:46.040975107 +0200
    +++ dla-3047.relu.wml 2022-06-08 10:52:14.634485818 +0200
    @@ -5,19 +5,19 @@
    Discovery</q>, exécutait le script avahi-daemon-check-dns.sh avec les
    privilèges du superutilisateur ce qui pouvait permettre à un attaquant
    local de provoquer un déni de service ou de créer des fichiers vides -arbitraires à l'aide d'une par lien symbolique sur des fichiers sous +arbitraires à l'aide d'un lien symbolique sur des fichiers sous
    /var/run/avahi-daemon. Le script est maintenant exécuté avec les privilèges
    de l'utilisateur et du groupe avahi et requiert sudo afin de réaliser cela.</p>

    <p>Le script susmentionné a été retiré à partir de Debian 10 <q>Buster</q>.
    -Le palliatif ne pourrait pas être implémenté pour Debian 9 <q>Stretch</q> +Le palliatif ne peut pas être implémenté pour Debian 9 <q>Stretch</q>
    parce que libnss-mdns 0.10 ne fournit pas la fonction requise pour le
    remplacer.</p>

    <p>En outre, il a été découver