-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 05 Jul 2024 06:15:50 +0200 Source: cockpit Binary: cockpit-bridge cockpit-bridge-dbgsym cockpit-pcp cockpit-pcp-dbgsym cockpit-tests cockpit-tests-dbgsym cockpit-ws cockpit-ws-dbgsym Architecture: mipsel Version: 287.1-0+deb12u3 Distribution: bookworm Urgency: medium Maintainer: mips64el Build Daemon (mipsel-osuosl-02) Changed-By: Martin Pitt Description: cockpit-bridge - Cockpit bridge server-side component cockpit-pcp - Cockpit PCP integration cockpit-tests - Tests for Cockpit cockpit-ws - Cockpit Web Service Changes: cockpit (287.1-0+deb12u3) bookworm; urgency=medium . * Add 0002-pam-ssh-add-Fix-insecure-killing-of-session-ssh-agen.patch: Cockpit’s pam_ssh_add module had a vulnerability when user_readenv is enabled in /etc/pam.d/cockpit (which is the default on Debian). This could cause a Denial of Service if a locally-authenticated user crafted a ~/.pam_environment file: it would kill an arbitrary process on the system with root privileges when logging out of a Cockpit session. Patch cherry-picked from upstream (08965365ac311f906a5). [CVE-2024-6126] Checksums-Sha1: 1f94f6a05930c6b671fd7757baf98132252780ed 732532 cockpit-bridge-dbgsym_287.1-0+deb12u3_mipsel.deb a4e9bb40512a052d8fc6b6cfba6e443a3ca77182 228016 cockpit-bridge_287.1-0+deb12u3_mipsel.deb 7c8eeec4817683ae2a2452ec77455af0aa27560c 223532 cockpit-pcp-dbgsym_287.1-0+deb12u3_mipsel.deb df5aac152fdf8ea1f9082d57156840bb06fc7155 72372 cockpit-pcp_287.1-0+deb12u3_mipsel.deb d26f304d8c94be0751bdafb303f576a6f0736332 4716 cockpit-tests-dbgsym_287.1-0+deb12u3_mipsel.deb 8cbb8a1bc03fb3a8a4501700e45fe32865addd38 475164 cockpit-tests_287.1-0+deb12u3_mipsel.deb 02ffc67c353d1fb93b783f50956c391d09b55281 467252 cockpit-ws-dbgsym_287.1-0+deb12u3_mipsel.deb 09f676a99b0a861cdc39c8aea95fb6b01b23f109 802996 cockpit-ws_287.1-0+deb12u3_mipsel.deb aa8af199347307fc8c447d884a7a36edc5b36743 12267 cockpit_287.1-0+deb12u3_mipsel-buildd.buildinfo Checksums-Sha256: c6da784003be3bcf59982c98d1f2349a3eabd720633322f59b554e45d90be073 732532 cockpit-bridge-dbgsym_287.1-0+deb12u3_mipsel.deb 1d0d887a59107773a11fbbc34240db204de06c747372caf8bc4089ffa9e2d285 228016 cockpit-bridge_287.1-0+deb12u3_mipsel.deb e4f716f8e36c27d4d0b0fc308c5f9be43178cc55044c415e3fc36028e128b2ae 223532 cockpit-pcp-dbgsym_287.1-0+deb12u3_mipsel.deb 8ff612b81e5879e6bdcbbe5f546d14a41ddfc0b21863cccff1785f4cc303a5b1 72372 cockpit-pcp_287.1-0+deb12u3_mipsel.deb 592fe484d10e5b6d1b614f7da20e2f7af51bc4449462785af0fd5f104d714edf 4716 cockpit-tests-dbgsym_287.1-0+deb12u3_mipsel.deb a0ee340f6da5dc24757c0d5e3e885c9b1e36c5f72e668ab3d949d6db29bade4b 475164 cockpit-tests_287.1-0+deb12u3_mipsel.deb b35f8a616f7f7a85dfdd647934476590689ba4bc97ea5d3cbe57e7e5846c64bd 467252 cockpit-ws-dbgsym_287.1-0+deb12u3_mipsel.deb cc8ddaa45f94fa6fa67dd44e5a0e1b2eddc67b7e43d8c6247ccaf66a95bd0d77 802996 cockpit-ws_287.1-0+deb12u3_mipsel.deb 3af73dd6c13aeb7bb197605c420e6a0654333d20ca83abe5fa791cc2468efc88 12267 cockpit_287.1-0+deb12u3_mipsel-buildd.buildinfo Files: dde95d0381c75bb670af582dfbc18561 732532 debug optional cockpit-bridge-dbgsym_287.1-0+deb12u3_mipsel.deb fccbdcb7e0d9bc107e7e30543b321102 228016 admin optional cockpit-bridge_287.1-0+deb12u3_mipsel.deb 9ec956855154525d9f201177466e2c05 223532 debug optional cockpit-pcp-dbgsym_287.1-0+deb12u3_mipsel.deb 5ae8046cb75b6c412a53f95aa0282d36 72372 admin optional cockpit-pcp_287.1-0+deb12u3_mipsel.deb 7b0153b627d84b17bac27bc1168dfdb8 4716 debug optional cockpit-tests-dbgsym_287.1-0+deb12u3_mipsel.deb cfe570be4d16fc8320f10837cd4e6862 475164 admin optional cockpit-tests_287.1-0+deb12u3_mipsel.deb 1ff1a629e500a6cd318c6c0edd7783ac 467252 debug optional cockpit-ws-dbgsym_287.1-0+deb12u3_mipsel.deb 4d411a60c8f8432bf889585d5c8f5326 802996 admin optional cockpit-ws_287.1-0+deb12u3_mipsel.deb 51b0a37fa344321556f94815682ae591 12267 admin optional cockpit_287.1-0+deb12u3_mipsel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEDr2J+AJzKxM96x4w+k4sZ5IEFbUFAmazNSUACgkQ+k4sZ5IE FbXV1g//eTJV8nm4WOPtB3ofPr6QM8Xqs8ESOIpySSkfDkygTSD2LzQ+jU2GkApD ZBCHTgaq7HdG41ZOpgYOH6BJvZOo7M4pAZFAUsn5NgV2urBEX5zU3RIVK0dfyPOA ryXnbyDWaShjULk8wdXetKNkqHRdAvDWqa6C4EXRYxbv8PTa0kqti+c11ZlWYED+ p8UkLJjGsvgNqKsc1yXPzsD+eQb3HoW0vgnuknpymLNVTAYwLNrLiJtalM3dprP3 bmddwVd77a461K/mNEKqaEgA8Cxfp/Wr/8tX7/VDZ3qqut0N1LLEQofeK80f4lVh aWSv9hNHakHU8JyUNWDq1rOPbsV/44BeTthQzLA5haeQgmNbyCrbO6nT1UitTSus dkiiLDFEDbjI+Dk2iQAHK5MQ64HoPwbzK4mk7JqXuNHwITfWfPMKbKmqHBqYoYSu ZE2SiLrwQGt6GLy+MqyobuoAb3KfB7iuAxSEii4pv8uLhX5AoCPT1B3psW7nwiCF +kwPvynwkV6Y7IrgUXw8kj9hGbrEWsepBOjo31AAf48deuSs4+5xOv0xGK6DIPu6 oo2oyKGcBxMUxdsYFwehF8vP7OBf5nbcR0fwiklS+m6rSQ0STLIYh6NPD9+ZfB+B DomkeC3kW0I15xBgVVrP71rbI9sjjAzzB00H6rsWTCVNS3qEwpg= =SeSz -----END PGP SIGNATURE-----