-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 05 Jul 2024 06:15:50 +0200 Source: cockpit Binary: cockpit-bridge cockpit-bridge-dbgsym cockpit-pcp cockpit-pcp-dbgsym cockpit-tests cockpit-tests-dbgsym cockpit-ws cockpit-ws-dbgsym Architecture: mips64el Version: 287.1-0+deb12u3 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-04) Changed-By: Martin Pitt Description: cockpit-bridge - Cockpit bridge server-side component cockpit-pcp - Cockpit PCP integration cockpit-tests - Tests for Cockpit cockpit-ws - Cockpit Web Service Changes: cockpit (287.1-0+deb12u3) bookworm; urgency=medium . * Add 0002-pam-ssh-add-Fix-insecure-killing-of-session-ssh-agen.patch: Cockpit’s pam_ssh_add module had a vulnerability when user_readenv is enabled in /etc/pam.d/cockpit (which is the default on Debian). This could cause a Denial of Service if a locally-authenticated user crafted a ~/.pam_environment file: it would kill an arbitrary process on the system with root privileges when logging out of a Cockpit session. Patch cherry-picked from upstream (08965365ac311f906a5). [CVE-2024-6126] Checksums-Sha1: 7caf955ac237596987381cd9725879d678de5da9 756048 cockpit-bridge-dbgsym_287.1-0+deb12u3_mips64el.deb 66b12c98126be95be40a92a752d8dacbab61d9d7 221940 cockpit-bridge_287.1-0+deb12u3_mips64el.deb b90593f5577749e151cf4a7e7ff7b539d3e4b9e5 229764 cockpit-pcp-dbgsym_287.1-0+deb12u3_mips64el.deb 0bc1aa0b21d355fd14a6eba26aa60e1ddc92c3df 68812 cockpit-pcp_287.1-0+deb12u3_mips64el.deb 1d9f49cd8af7d03f200040222e596656df06165e 4804 cockpit-tests-dbgsym_287.1-0+deb12u3_mips64el.deb 9e86455f46c5ad0a0de2973aad4480d7dac402d2 475216 cockpit-tests_287.1-0+deb12u3_mips64el.deb bdd10259fff28c4259f930a57a363f96fa584981 480592 cockpit-ws-dbgsym_287.1-0+deb12u3_mips64el.deb 1be7ebb4f3ba024c17b68f1cdf6b8d6c0d2ab97e 799792 cockpit-ws_287.1-0+deb12u3_mips64el.deb 70b8e97c3744003b6eec28806e1f084bc2854bf1 12326 cockpit_287.1-0+deb12u3_mips64el-buildd.buildinfo Checksums-Sha256: 7892f1650785b4e3a288a88c5592920852346864279a7be92688c39995b724bf 756048 cockpit-bridge-dbgsym_287.1-0+deb12u3_mips64el.deb e5e8b160c50b6c108b15a110e57e65c88d04aa59fc6dca8443987bfd4b755dd3 221940 cockpit-bridge_287.1-0+deb12u3_mips64el.deb e0a9ab951a6fea22fff79c5e401f997f1720368b388f3ae4499596a799eb8785 229764 cockpit-pcp-dbgsym_287.1-0+deb12u3_mips64el.deb 8ba3b73b69bacdeee62aa6d715c41ffa70857a3143e7fbc57e6f1ef2c6cee56a 68812 cockpit-pcp_287.1-0+deb12u3_mips64el.deb 82685ae2fd2115f6794c32f9fe871dee44172cc4ce75a5a763757f450fb76772 4804 cockpit-tests-dbgsym_287.1-0+deb12u3_mips64el.deb 6cbcaf1b8277c6ed939b080a1e5a2feb289cd58c54a9ee69015b6903dadc1503 475216 cockpit-tests_287.1-0+deb12u3_mips64el.deb 7aca883f15012b4e57f4df33fe0fef4c1370db35caf6495dfbdd92d464e87a37 480592 cockpit-ws-dbgsym_287.1-0+deb12u3_mips64el.deb a6772b088ea55003f1545f35b5999d482e67067d6c395b9cbac26aed764ee16a 799792 cockpit-ws_287.1-0+deb12u3_mips64el.deb 6f0ef01e0dd93a06fe6fefec5276e9b8b7f9c96bddbb5ec6d7586b5e0540304e 12326 cockpit_287.1-0+deb12u3_mips64el-buildd.buildinfo Files: e0c2d5c5e55ba7b89be7af5d2b7ec71f 756048 debug optional cockpit-bridge-dbgsym_287.1-0+deb12u3_mips64el.deb bc587299f9e308d9003577f8f8d53cb5 221940 admin optional cockpit-bridge_287.1-0+deb12u3_mips64el.deb ae03e71d14444785df1d118d7a37700a 229764 debug optional cockpit-pcp-dbgsym_287.1-0+deb12u3_mips64el.deb 2fdac3318365850d44137baa59a5b535 68812 admin optional cockpit-pcp_287.1-0+deb12u3_mips64el.deb 45aa47e0c94fa426f91270747bae5da2 4804 debug optional cockpit-tests-dbgsym_287.1-0+deb12u3_mips64el.deb 604e49988476841794bc5518b6d9aee4 475216 admin optional cockpit-tests_287.1-0+deb12u3_mips64el.deb 8b13ec711ba65bd9df0c14378813cd15 480592 debug optional cockpit-ws-dbgsym_287.1-0+deb12u3_mips64el.deb d604f6c0a46f667eafe04f0b49be3ec6 799792 admin optional cockpit-ws_287.1-0+deb12u3_mips64el.deb 68c8a9eef0a59f932cff92db345eca82 12326 admin optional cockpit_287.1-0+deb12u3_mips64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEEmZlxOBLdXDBxnwAL00bee7O74EFAmazM/4ACgkQL00bee7O 74GpvhAAvSGnUUXQ1+9ynr6HlY6b+WMhm444CLGcbLIIaFeuoO6rCb8NXPqrei76 FwI3El85oOZPsUmBBy23Ek02j4l/G3eGXXUcFjB24PgmmwosVNdaMoo7a0+gnQCo 4xiSbpRrx/lTFpcaVhOJaIiCHhP4xWZSbkIquKw9r8Iky4ja2mj114wCnfldhhHv m+B0/dynEeXLoCgaFZqA18wYXCKVv0fpwZhCaDmXSIdqLKhT7Wds8N7up8EvJwre I2BowsuRSL35guQqE3yD96TDLP3B2d55fw+tImfrbo1i5Kkf7A2VhN6MGXp8VoZJ 96N/gq9EZ2E7o/I6ySMCGc7LBMYKom77ZTLgPQDKTqRBndCQnefyFn0ggBQmiISI HAzgfvgTLF82evuQDitG8D2cBTKTHMvRMgsKYqax5boDRQVsGZSUA6dyLKRPZKel 29Dmz5egkPRu1yN8isVs9nIUJzIOmMl/X50UooGG/UATPrIZoXwinqFmWLVNn6Gu LPWSYa/kkvtA7GI4HSqNNZDZevgFAIONNkM5UnZdiyI641Yyh73/PfnNMPYMLpnP VGVdfiyzjfgBbuz9tLRLVlCQvNpL73qXw4BIkv8872hCaNRYiRjudIcWSKoHUwkq +VkYnaLJXcUcYSsLHDborvBMBrOWrWPyZ55WQvJ2xO1LKG6NPJ4= =f264 -----END PGP SIGNATURE-----