-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 19 Dec 2019 23:13:43 +0100 Source: cyrus-sasl2 Architecture: source Version: 2.1.27~101-g0780600+dfsg-3+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Debian Cyrus SASL Team <pkg-cyrus-sasl2-debian-de...@lists.alioth.debian.org> Changed-By: Salvatore Bonaccorso <car...@debian.org> Closes: 947043 Changes: cyrus-sasl2 (2.1.27~101-g0780600+dfsg-3+deb9u1) stretch-security; urgency=high . * Non-maintainer upload by the Security Team. * Off-by-one in _sasl_add_string function (CVE-2019-19906) (Closes: #947043) Checksums-Sha1: dc9b60273777b625263abd376136cf5c2b19cc84 3381 cyrus-sasl2_2.1.27~101-g0780600+dfsg-3+deb9u1.dsc 627ff1c0d62984d60f7f98d6b14f6c36d6a9b0d9 1143888 cyrus-sasl2_2.1.27~101-g0780600+dfsg.orig.tar.xz d48a36988dc3604eeb198ea7b554e342cb9bfde6 94992 cyrus-sasl2_2.1.27~101-g0780600+dfsg-3+deb9u1.debian.tar.xz Checksums-Sha256: a331441098ece65be5bf13d871b486115af68daf06a0145adf6cda8ef71d73e4 3381 cyrus-sasl2_2.1.27~101-g0780600+dfsg-3+deb9u1.dsc 69f34971f768e7ee6a6b647ec2d16a5a72a854ecd4602b019d5f79ba61063fdc 1143888 cyrus-sasl2_2.1.27~101-g0780600+dfsg.orig.tar.xz be1ba4b3bfcc4740354342686deac73ca2e46c4871219599229efe8cfe98df6f 94992 cyrus-sasl2_2.1.27~101-g0780600+dfsg-3+deb9u1.debian.tar.xz Files: 71db97fd10e2727beddc112439fbe256 3381 libs standard cyrus-sasl2_2.1.27~101-g0780600+dfsg-3+deb9u1.dsc 4ca5bf3e08c62df06c3a5ffadcd9ab13 1143888 libs standard cyrus-sasl2_2.1.27~101-g0780600+dfsg.orig.tar.xz e88a9640371f49af4f8e95a42ba9ed21 94992 libs standard cyrus-sasl2_2.1.27~101-g0780600+dfsg-3+deb9u1.debian.tar.xz
-----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl3792RfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89E7BsP/08u143qVzZdjR/Gs9AjgRd5W2CAWMyL WMvJb9ITtiHtDHXEgJ6N0XdjqRhGCUHWWVrJ+c5pTl1Y5HukXeEVZgGB3zO8MwMz xW5UNL09mZcQ6fhXgHB7DSarrG9mupgHDBnmojzIz84VQDyECS9CGy3g8KPraqpv /o70Xm2opBpt/2v6jJy+cGe5HMw2dVuSGiwKOrhQ7qSkfYLjON7CwDVNXTcqD3JS xg6fkmGsxktdPV88at1INOF9Xb+kOklrRj1HqVEo+NmvwqR/wg64xj4StHGchNjX C+vDDgbJhQ0M2YImFMsicbCKV7wxt2CY0gF/ruyc0mPR5EnUsAyuEICzIRNVePwb 616HIjnxQ3IBvrMhdZTwLP3X6yvxsgVKacXwROpgEuo3MuyolTWXT1Ds9b9o5oCA mJOoghSkpQd+zUwLWqp37pKtIG5hVK2XfwDCN8Tw3OlZAKZRRErslp8mCgLdUS0P wEFc+rwH3+NzKk67Q5HgymzmlACR//RM3cOu6wZQt6IyA86rn6WRatA8CJbQWl2H Ljjz+borrD/hPFDdBRijq0k5q9RrQ2yrhi4z8iH99qGbNK7dMb5wXqoSwTvAD2iM RrWamA4tHAZ+S+AfDN7jkdMYzKMgyPgFbST0vov8gRgrswHRTqIcOOyb5Q0xjJIc Ao/Sm2HTJVdq =pspV -----END PGP SIGNATURE-----