[SECURITY] [DLA 3643-1] pmix security update

2023-10-31 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA256

- -
Debian LTS Advisory DLA-3643-1debian-...@lists.debian.org
https://www.debian.org/lts/security/   Chris Lamb
October 31, 2023  https://wiki.debian.org/LTS
- -

Package: pmix
Version: 3.1.2-3+deb10u1
CVE ID : CVE-2023-41915
Debian Bug : 1051729

It was discovered that there was an arbitrary file overwrite
vulnerability in pmix, a library used in parallel/cluster computing.

Attackers could have obtained ownership of arbitrary files via a
symlink-related race condition during execution of library code with
UID 0. 

For Debian 10 buster, this problem has been fixed in version
3.1.2-3+deb10u1.

We recommend that you upgrade your pmix packages.

For the detailed security status of pmix please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/pmix

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-BEGIN PGP SIGNATURE-

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmVBKFYACgkQHpU+J9Qx
HlhwaQ//Wvxx47p4W+/8bvD1TpnEUdq3sLkAzzXL8S4w1BMhQfTqqAi7Nnuh0cez
1AGQN3msm+aowkQGyVzkrKGDmOJ/DTcNZxvEOl9R2HoAK/FmLW7FQ2f68g1Zc/lu
RKS1jFSU53b9InbDBucRDAdPgqOsEnKJ3SEfVR34Gn9yEZ3l4VzF7Wy97rjaDAOC
2vNFmZI2hE6D3wvRu4KvwjJGBAeaPX+LQ/XhAp8veoMDjhG89YgVMZyCjKmJ/zDf
OgqejwToGoYiuDgU9+yTY5Bf+qL2inXZeWX6VYZHYPNfwaHy7zUa1uKVZc7WnqmN
KA2uYoF8iguQEond/o4GN3oqLLPdNv7Svsu61ak9joir2dbI4AQDOdcivwB5S6C0
GPZ5fn+GO1uN4fQIApelnb4cnhGL+ElW4kqfLogPjWt2eCQnDU1cUztOyQRuZ/sL
D2ZOpUBvQVuwhmB0jOm4XHUr9oJf8g5VZvFYQtIxYcENLQs2kBKRjAq0Yx1Bjno7
H9JPHgAOhMaRCMJDGoh58LHu/kXegn4Kn3i74hbrJ7XSXVaM99iuPwlQvhrlmVZJ
fAgFugQFGGYq46UtojG4UYaN4YEADUKdNWd8Bb9ZU3zs9oiqtMwrN8r65a74shGa
iBaR1lG9HLj7BcoklN/wOeukqRz24lIElH6/zmFWKS6PdHXW2y8=
=wZoD
-END PGP SIGNATURE-



[SECURITY] [DLA 3638-1] h2o security update

2023-10-31 Thread Anton Gladky
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

- -
Debian LTS Advisory DLA-3638-1debian-...@lists.debian.org
https://www.debian.org/lts/security/ Anton Gladky
October 29, 2023  https://wiki.debian.org/LTS
- -

Package: h2o
Version: 2.2.5+dfsg2-2+deb10u2
CVE ID : CVE-2023-44487
Debian Bug : 1054232

A vulnerability has been identified in h2o, a high-performance web server
with support for HTTP/2.

A security vulnerability CVE-2023-44487 was discovered that could potentially
be exploited to disrupt server operation.

The vulnerability in the h2o HTTP/2 server was related to the handling of
certain types of HTTP/2 requests. In certain scenarios, an attacker could
send a series of malicious requests, causing the server to process them
rapidly and exhaust system resources.

The applied upstream patch changes the ABI. Therefore, if your application
is built against any shared libraries of h2o, you need to rebuild it.
No Debian package is affected.

For Debian 10 buster, this problem has been fixed in version
2.2.5+dfsg2-2+deb10u2.

We recommend that you upgrade your h2o packages.

For the detailed security status of h2o please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/h2o

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-BEGIN PGP SIGNATURE-

iQIzBAEBCgAdFiEEu71F6oGKuG/2fnKF0+Fzg8+n/wYFAmVBCo8ACgkQ0+Fzg8+n
/wbanQ//Yo0J2I6ph/5a2hZfQ+kgbsMBXCy7hZh6CenGPgHTjCWPp48ss7Pje0ZB
j6w6EdMMpqgGHkS3ODMoavcK1Kvh+9ARtpS8yHvLuQo60IF8juaeJXQvSYZm9Lvk
4E7EiMOZ3MU+zPht9DgDi6CdeT9TS0aMRqWT89ClRJ63PUFJvIojby6wSKZ5jXg5
REoD1tAwNw+TMpQuH5NFCkn/SwhzPxwV/gzLSgwqynkXOBoVk1oLQ0e0utyla3tg
RUl1x3b6LGm3mzpsufCSJ6e4nLoj7VWz0w1/U+RPYB+Sp4ORailC1LwF9GwjEuhq
o+CETCwUsO4WtyR5QtSFTWYDBF65j9X+OfOSsuC5POykBM/KmXyRsZHzeETp30/c
vbciK9xFP5b5iNk1aEfLxL2QJVcENFAfBzfIizggKWSFVVoJiSDQVbN3dY4QoQ8P
yXX2CFgQmmv0TtSp7j7Lq1/oAxIiIp4RQWjqA18T3w1muuQ20fNJnEgNAs0Lh69v
eiM6qbP5w9WMC0BUjPSqmg693A+SPk5nxcq1BX1uvQmF1UGlKCGX8E7iX8YAthjg
KfWHS9KEUuW4AyoHCnJFtRqSEumScOaPfzNcfYMn/aCPCZ/TL/Qa1Mft26hpBn66
j7C637FYQ4gLCQMRykeHo45ES4jaZZO6XuotgUgDybgdzsv0vjc=
=0auQ
-END PGP SIGNATURE-