• Re: [RFR] wml://lts/security/2022/dla-31{76,88,89,96,99}.wml

    From JP Guillonneau@21:1/5 to All on Sat Nov 19 09:50:02 2022
    Bonjour,

    Le 19/11/22 00:20 Jean-Pierre a écrit :
    cinq nouvelles annonces de sécurité ont été publiées.

    un doublon.


    Amicalement.

    --
    Jean-Paul

    --- dla-3176.wml.orig 2022-11-19 09:24:52.799612843 +0100
    +++ dla-3176.wml 2022-11-19 09:31:58.054179500 +0100
    @@ -10,7 +10,7 @@
    que l'attaquant peut réaliser une reconnaissance sur la cible particulière
    du serveur ClickHouse pour obtenir des identifiants valables. Tout jeu
    d'identifiants devrait fonctionner, dans la mesure où même un utilisateur -avec les privilèges les privilèges les plus bas peut déclencher toutes les +avec les privilèges les plus bas peut déclencher toutes les
    vulnérabilités. En déclenchant les vulnérabilités, un attaquant peut
    planter le serveur ClickHouse, divulguer des contenus de mémoire ou même
    provoquer l'exécution de code distant.</p>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Jean-Pierre Giraud@21:1/5 to All on Fri Nov 25 19:50:01 2022
    --=-+3h/vvj4lDrof9bGHPxu
    Content-Type: text/plain; charset="UTF-8"
    Content-Transfer-Encoding: quoted-printable

    Bonjour,
    Le samedi 19 novembre 2022 à 09:42 +0100, JP Guillonneau a écrit :
    Bonjour,

    Le 19/11/22 00:20 Jean-Pierre a écrit :
    cinq nouvelles annonces de sécurité ont été publiées.
    un doublon.
    Amicalement.
    Passage en LCFC. Je ne renvoie que le fichier corrigé suivant la
    suggestion de Jean-Paul.
    Merci d'avance pour vos ultimes relectures.
    Amicalement,
    jipege

    --=-+3h/vvj4lDrof9bGHPxu
    Content-Disposition: attachment; filename="dla-3176.wml" Content-Transfer-Encoding: base64
    Content-Type: text/vnd.wap.wml; name="dla-3176.wml"; charset="UTF-8"

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249IjQ5YzY4ZTQ1 YWVmYzAxNmMzNmExYTU0NDFiZTc2NGNmMGE0ZDg2YWEiIG1haW50YWluZXI9IkplYW4tUGllcnJl IEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRlIHPDqWN1cml0 w6kgcG91ciBMVFM8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZvPgo8cD5QbHVzaWV1 cnMgdnVsbsOpcmFiaWxpdMOpcyBkZSBzw6ljdXJpdMOpIG9udCDDqXTDqSBkw6ljb3V2ZXJ0ZXMg ZGFucwpjbGlja2hvdXNlLCB1biBzeXN0w6htZSBkZSBiYXNlIGRlIGRvbm7DqWVzIG9yaWVudMOp ZSBjb2xvbm5lLjwvcD4KCgo8cD5MZXMgdnVsbsOpcmFiaWxpdMOpcyByZXF1acOocmVudCB1bmUg YXV0aGVudGlmaWNhdGlvbiwgbWFpcyBwZXV2ZW50IMOqdHJlCmTDqWNsZW5jaMOpZXMgcGFyIHRv dXQgdXRpbGlzYXRldXIgZG90w6kgZGUgZHJvaXRzIGVuIGxlY3R1cmUuIENlbGEgc2lnbmlmaWUK cXVlIGwnYXR0YXF1YW50IHBldXQgcsOpYWxpc2VyIHVuZSByZWNvbm5haXNzYW5jZSBzdXIgbGEg Y2libGUgcGFydGljdWxpw6hyZQpkdSBzZXJ2ZXVyIENsaWNrSG91c2UgcG91ciBvYnRlbmlyIGRl cyBpZGVudGlmaWFudHMgdmFsYWJsZXMuIFRvdXQgamV1CmQnaWRlbnRpZmlhbnRzIGRldnJhaXQg Zm9uY3Rpb25uZXIsIGRhbnMgbGEgbWVzdXJlIG/DuSBtw6ptZSB1biB1dGlsaXNhdGV1cgphdmVj IGxlcyBwcml2aWzDqGdlcyBsZXMgcGx1cyBiYXMgcGV1dCBkw6ljbGVuY2hlciB0b3V0ZXMgbGVz IHZ1bG7DqXJhYmlsaXTDqXMuCkVuIGTDqWNsZW5jaGFudCBsZXMgdnVsbsOpcmFiaWxpdMOpcywg dW4gYXR0YXF1YW50IHBldXQgcGxhbnRlciBsZSBzZXJ2ZXVyCkNsaWNrSG91c2UsIGRpdnVsZ3Vl ciBkZXMgY29udGVudXMgZGUgbcOpbW9pcmUgb3UgbcOqbWUgcHJvdm9xdWVyIGwnZXjDqWN1dGlv bgpkZSBjb2RlIGRpc3RhbnQuPC9wPgoKPHVsPgoKPGxpPjxhIGhyZWY9Imh0dHBzOi8vc2VjdXJp dHktdHJhY2tlci5kZWJpYW4ub3JnL3RyYWNrZXIvQ1ZFLTIwMjEtNDIzODciPkNWRS0yMDIxLTQy Mzg3PC9hPjoKCjxwPlVuZSBsZWN0dXJlIGRlIHRhcyBob3JzIGxpbWl0ZXMgZGFucyBsZSBjb2Rl YyBkZSBjb21wcmVzc2lvbiBMWjQgZGUKQ2xpY2tob3VzZSBsb3JzIGRlIGwnYW5hbHlzZSBkJ3Vu ZSByZXF1w6p0ZSBtYWx2ZWlsbGFudGUuIERhbnMgbGUgY2FkcmUgZGUKbGEgYm91Y2xlIGRlIExa NDo6ZGVjb21wcmVzc0ltcGwoKSwgdW5lIHZhbGV1ciAxNsKgYml0cyBub24gc2lnbsOpZSBmb3Vy bmllCnBhciBsJ3V0aWxpc2F0ZXVyICg8cT5vZmZzZXQ8L3E+KSBlc3QgbHVlIMOgIHBhcnRpciBk ZXMgZG9ubsOpZXMgY29tcHJlc3PDqWVzLgpMJ29mZnNldCBlc3QgZW5zdWl0ZSB1dGlsaXPDqSBw b3VyIGxhIGxvbmd1ZXVyIGQndW5lIG9ww6lyYXRpb24gZGUgY29waWUsCnNhbnMgdsOpcmlmaWVy IGxlcyBsaW1pdGVzIHN1cMOpcmlldXJlcyBkZSBsYSBzb3VyY2UgZGUgbCdvcMOpcmF0aW9uIGRl IGNvcGllLjwvcD4KPC9saT4KCjxsaT48YSBocmVmPSJodHRwczovL3NlY3VyaXR5LXRyYWNrZXIu ZGViaWFuLm9yZy90cmFja2VyL0NWRS0yMDIxLTQyMzg4Ij5DVkUtMjAyMS00MjM4ODwvYT46Cgo8 cD5VbmUgbGVjdHVyZSBkZSB0YXMgaG9ycyBsaW1pdGVzIGRhbnMgbGUgY29kZWMgZGUgY29tcHJl c3Npb24gTFo0IGRlCkNsaWNraG91c2UgbG9ycyBkZSBsJ2FuYWx5c2UgZCd1bmUgcmVxdcOqdGUg bWFsdmVpbGxhbnRlLiBEYW5zIGxlIGNhZHJlIGRlCmxhIGJvdWNsZSBkZSBMWjQ6OmRlY29tcHJl c3NJbXBsKCksIHVuZSB2YWxldXIgMTbCoGJpdHMgbm9uIHNpZ27DqWUgZm91cm5pZQpwYXIgbCd1 dGlsaXNhdGV1ciAoPHE+b2Zmc2V0PC9xPikgZXN0IGx1ZSDDoCBwYXJ0aXIgZGVzIGRvbm7DqWVz IGNvbXByZXNzw6llcy4KTCdvZmZzZXQgZXN0IGVuc3VpdGUgdXRpbGlzw6kgcG91ciBsYSBsb25n dWV1ciBkJ3VuZSBvcMOpcmF0aW9uIGRlIGNvcGllLApzYW5zIHbDqXJpZmllciBsZXMgbGltaXRl cyBpbmbDqXJpZXVyZXMgZGUgbGEgc291cmNlIGRlIGwnb3DDqXJhdGlvbiBkZSBjb3BpZS48L3A+ CjwvbGk+Cgo8bGk+PGEgaHJlZj0iaHR0cHM6Ly9zZWN1cml0eS10cmFja2VyLmRlYmlhbi5vcmcv dHJhY2tlci9DVkUtMjAyMS00MzMwNCI+Q1ZFLTIwMjEtNDMzMDQ8L2E+OgoKPHA+VW4gZMOpcGFz c2VtZW50IGRlIHRhbXBvbiBkZSB0YXMgZGFucyBsZSBjb2RlYyBkZSBjb21wcmVzc2lvbiBMWjQg ZGUKQ2xpY2tob3VzZSBsb3JzIGRlIGwnYW5hbHlzZSBkJ3VuZSByZXF1w6p0ZSBtYWx2ZWlsbGFu dGUuIElsIG4neSBwYXMgZGUKdsOpcmlmaWNhdGlvbiBxdWUgbGVzIG9ww6lyYXRpb25zIGRlIGNv cGllIGRhbnMgbGEgYm91Y2xlIGRlCkxaNDo6ZGVjb21wcmVzc0ltcGwsIGV0IHBhcnRpY3VsacOo cmVtZW50IGwnb3DDqXJhdGlvbiBkZSBjb3BpZSBhcmJpdHJhaXJlCndpbGRDb3B5Jmx0O2NvcHlf YW1vdW50Jmd0OyhvcCwgaXAsY29weV9lbmQpLCBuZSBkw6lwYXNzZW50IHBhcyBsZXMgbGltaXRl cwpkdSB0YW1wb24gZGUgZGVzdGluYXRpb24uPC9wPjwvbGk+Cgo8bGk+PGEgaHJlZj0iaHR0cHM6 Ly9zZWN1cml0eS10cmFja2VyLmRlYmlhbi5vcmcvdHJhY2tlci9DVkUtMjAyMS00MzMwNSI+Q1ZF LTIwMjEtNDMzMDU8L2E+OgoKPHA+VW4gZMOpcGFzc2VtZW50IGRlIHRhbXBvbiBkZSB0YXMgZGFu cyBsZSBjb2RlYyBkZSBjb21wcmVzc2lvbiBMWjQgZGUKQ2xpY2tob3VzZSBsb3JzIGRlIGwnYW5h bHlzZSBkJ3VuZSByZXF1w6p0ZSBtYWx2ZWlsbGFudGUuIElsIG4neSBwYXMgZGUKdsOpcmlmaWNh dGlvbiBxdWUgZGFucyBsZXMgb3DDqXJhdGlvbnMgZGUgY29waWUgZGFucyBsYSBib3VjbGUgZGUK TFo0OjpkZWNvbXByZXNzSW1wbCwgZXQgcGFydGljdWxpw6hyZW1lbnQgbCdvcMOpcmF0aW9uIGRl IGNvcGllIGFyYml0cmFpcmUKd2lsZENvcHkmbHQ7Y29weV9hbW91bnQmZ3Q7KG9wLCBpcCxjb3B5 X2VuZCksIG5lIGTDqXBhc3NlbnQgcGFzIGxlcyBsaW1pdGVzCmR1IHRhbXBvbiBkZSBkZXN0aW5h dGlvbi4gQ2UgcHJvYmzDqG1lIGVzdCB0csOocyBzZW1ibGFibGUgYXUKPGEgaHJlZj0iaHR0cHM6 Ly9zZWN1cml0eS10cmFja2VyLmRlYmlhbi5vcmcvdHJhY2tlci9DVkUtMjAyMS00MzMwNCI+Q1ZF LTIwMjEtNDMzMDQ8L2E+LAptYWlzIGwnb3DDqXJhdGlvbiBkZSBjb3BpZSB2dWxuw6lyYWJsZSBz ZSB0cm91dmUgZGFucyB1biBhcHBlbCBkaWZmw6lyZW50IGRlCndpbGRDb3B5LjwvcD48L2xpPgoK PC91bD4KCjxwPlBvdXIgRGViaWFuIDEwIEJ1c3RlciwgY2VzIHByb2Jsw6htZXMgb250IMOpdMOp IGNvcnJpZ8OpcyBkYW5zIGxhIHZlcnNpb24KMTguMTYuMStkcy00K2RlYjEwdTEuPC9wPgoKPHA+ Tm91cyB2b3VzIHJlY29tbWFuZG9ucyBkZSBtZXR0cmUgw6Agam91ciB2b3MgcGFxdWV0cyBjbGlj a2hvdXNlLjwvcD4KCjxwPlBvdXIgZGlzcG9zZXIgZCd1biDDqXRhdCBkw6l0YWlsbMOpIHN1ciBs YSBzw6ljdXJpdMOpIGRlIGNsaWNraG91c2UsIHZldWlsbGV6CmNvbnN1bHRlciBzYSBwYWdlIGRl IHN1aXZpIGRlIHPDqWN1cml0w6kgw6AgbCdhZHJlc3NlwqA6CjxhIGhyZWY9Imh0dHBzOi8vc2Vj dXJpdHktdHJhY2tlci5kZWJpYW4ub3JnL3RyYWNrZXIvY2xpY2tob3VzZSI+XApodHRwczovL3Nl Y3VyaXR5LXRyYWNrZXIuZGViaWFuLm9yZy90cmFja2VyL2NsaWNraG91c2U8L2E+LjwvcD4KCjxw PlBsdXMgZOKAmWluZm9ybWF0aW9ucyDDoCBwcm9wb3MgZGVzIGFubm9uY2VzIGRlIHPDqWN1cml0 w6kgZGUgRGViaWFuIExUUywKY29tbWVudCBhcHBsaXF1ZXIgY2VzIG1pc2VzIMOgIGpvdXIgZGFu cyB2b3RyZSBzeXN0w6htZSBldCBsZXMgcXVlc3Rpb25zCmZyw6lxdWVtbWVudCBwb3PDqWVzIHBl dXZlbnQgw6p0cmUgdHJvdXbDqWVzIHN1csKgOgo8YSBocmVmPSJodHRwczovL3dpa2kuZGViaWFu Lm9yZy9MVFMiPmh0dHBzOi8vd2lraS5kZWJpYW4ub3JnL0xUUzwvYT4uPC9wPgo8L2RlZmluZS10 YWc+CgojIGRvIG5vdCBtb2RpZnkgdGhlIGZvbGxvd2luZyBsaW5lCiNpbmNsdWRlICIkKEVOR0xJ U0hESVIpL2x0cy9zZWN1cml0eS8yMDIyL2RsYS0zMTc2LmRhdGEiCiMgJElkOiAkCg==


    --=-+3h/vvj4lDrof9bGHPxu--

    -----BEGIN PGP SIGNATURE-----

    iQIzBAABCgAdFiEEcH/R3vmpi4JWBoDfeBP2a44wMXIFAmOBDHAACgkQeBP2a44w MXI8aw/+LEhda29nbT0yHna6WUeqagbkEApW6cuNX7IBdtq2JJr+Vn/Xe6yOREg0 KMb6r+iQCuzwz8Ot8TUBBm05/mfssdJyPGzEvqaLYmXzcqxA1K+1KF3i91I7Y9CZ LVtt+uvi35SSmfU7g0MyIw2BPQjGJlASVlmFjz8swk1D+C3Y029vA4k/GqVQDMRc y051nlIKQZu+wFqFMasNxpG4WKqICR6D9h0VsDZz8SVbcEtzf2+1wFEABPB8vQSq OixaGF18o8gGdJX07zWvR+MMFLOS5ijqjHM5Xfg/vpmvecx3kKFtCjXIfRp5r53L AIFdWBFHi3YRr6ZiSALp5SuqbIvfmsYOjzMP2NKkBSQFmVW4UD867zd7kqDKoTrA JsZuDj3mYZMHQUzp9/bKV58KAb13DVU0WQEHsH8HbKLFHu+9Lo1qRd4udMcfFhV7 1c2bJ/SStxfAkL7qUNd0HxYTlw1RViCN0GM41DNQbvyxIvqXJUxoK3cnaWqLBh1A wxYKEjgQiPG3OsaJHcq57v5IUxsncmTlvKTPJ/8CBrRF3/+DAHh9kGmvCruVHxMq mTnnr02aUXxFc0UHe36T88j/L8ux/DK7XcwE6snXwuOKmYhPd5mEYm1P98/hHg1D HCucndI1zf50eM2f5CHnqbsJjhKag/TbJc953I7kQ64m/daf1C8=
    =SaQT
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Jean-Pierre Giraud@21:1/5 to All on Wed Nov 30 10:50:01 2022
    Bonjour,

    Le vendredi 25 novembre 2022 à 19:41 +0100, Jean-Pierre Giraud a
    écrit :
    Le samedi 19 novembre 2022 à 09:42 +0100, JP Guillonneau a écrit :
    Le 19/11/22 00:20 Jean-Pierre a écrit :


    Terminé. Merci à Jean-Paul pour ses relectures.
    Amicalement,
    jipege

    -----BEGIN PGP SIGNATURE-----

    iQIzBAABCgAdFiEEcH/R3vmpi4JWBoDfeBP2a44wMXIFAmOHJgcACgkQeBP2a44w MXI1xw/8Co6KPszkuH4lFCHlfGDg/I75mwgigknVUCrBpuVwWzEjEd7ZR+kctERD 6CrO+hkkL6g8JlmEevzqGoVJiwsjpVkPWJJgXBh0FU/wwJFsrVi7Q9BTSaUfUEs+ YklSRYrcDx+kVpQMxaXw3DJ0gxbBxUQGXqafGvQ9uhNaC4QSeFT3IMErM/NV3yoP E1G/sAEIXPYLIZxHTR5AnJDHLJAwpi8ameJqRQTyULnVXRQPqObzVI5rpSKkcJ3N X6+GfVAtubOiE6aaVDAddoY+PltsJNWNNiGWH5jhx/+SeWro4pHpoQPNRKnT8ka5 UQjrJcwhtEW+EfPZDmKyh+R2fc6vy/rbqGe/LcZw7Uh6c+7YX9/nbA2jA6bsxrkE dG0GrEXyFQJPMVTDVN/jDJv9fz+Osgq+ozskqL6KJzxeImvm3VSh8AWZ6prdGtGZ yVkRdNYvfNyVuznVoUZcylwabpOKniKR31qR6Z1RxZWdy8pmTFVCo3FRBVsjmMiw JLLjbkfm6JB4+CuIK8prz154HHDTpc1UHzA2ye8HmdeJPFhf6zZLfmVYOfh/ZSRj H1Hj33GVHk/OBnG705TcNps7P8rR7MEeNLtBd2n4AqyqrbpvS5Z1m/RSy6JCLyAf Jv5mHEtJVBVtuv57UqnMPY6uNz8P1vpuFTZD8pLW2iyeFT/zJpU=
    =b/c1
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)