Format: 1.8 Date: Thu, 30 Jul 2015 17:42:43 -0400 Source: openafs Binary: openafs-client openafs-fuse openafs-kpasswd openafs-fileserver openafs-dbserver openafs-doc openafs-krb5 libkopenafs1 libafsauthent1 libafsrpc1 libopenafs-dev openafs-modules-source openafs-modules-dkms libpam-openafs-kaserver openafs-dbg Architecture: source amd64 all Version: 1.6.13-1 Distribution: unstable Urgency: high Maintainer: Benjamin Kaduk <kaduk@mit.edu> Changed-By: Benjamin Kaduk <kaduk@mit.edu> Description: libafsauthent1 - AFS distributed file system runtime library (authentication) libafsrpc1 - AFS distributed file system runtime library (RPC layer) libkopenafs1 - AFS distributed file system runtime library (PAGs) libopenafs-dev - AFS distributed filesystem development libraries libpam-openafs-kaserver - AFS distributed filesystem kaserver PAM module openafs-client - AFS distributed filesystem client support openafs-dbg - AFS distributed filesystem debugging information openafs-dbserver - AFS distributed filesystem database server openafs-doc - AFS distributed filesystem documentation openafs-fileserver - AFS distributed filesystem file server openafs-fuse - AFS distributed file system experimental FUSE client openafs-kpasswd - AFS distributed filesystem old password changing openafs-krb5 - AFS distributed filesystem Kerberos 5 integration openafs-modules-dkms - AFS distributed filesystem kernel module DKMS source openafs-modules-source - AFS distributed filesystem kernel module source Changes: openafs (1.6.13-1) unstable; urgency=high . * New upstream security release. - OPENAFS-SA-2015-001 CVE-2015-3282: vos leaks stack data onto the wire in the clear when creating vldb entries - OPENAFS-SA-2015-002 CVE-2015-3283: bos commands can be spoofed, including some which alter server state - OPENAFS-SA-2015-003 CVE-2015-3284: pioctls leak kernel memory contents - OPENAFS-SA-2015-004 CVE-2015-3285: kernel pioctl support for OSD command passing can trigger a panic - OPENAFS-SA02015-005 CVE 2015-3286 is Solaris-specific and did not affect Debian - OPENAFS-SA-2015-006: buffer overflow in vlserver * Also includes changes from the upstream 1.6.12 release: - Avoid database corruption if a database server is shut down and brought up again quickly with an altered database - Fix a potential buffer overflow in aklog - Support for Linux kernels up to 4.1 - Avoid spurious EIO errors when writing large chunks of data to mmapped files Checksums-Sha1: 20c7101c6a87d66d59a098c7c03845ea76513509 3798 openafs_1.6.13-1.dsc 1bf5b2ef81c2920863bd2c6d875224bf7927c9b2 6650360 openafs_1.6.13.orig.tar.xz 8672845bed14c9b53ac5b786751eed431a55a1b1 135644 openafs_1.6.13-1.debian.tar.xz d4112222ab4f91d7c51f030d78268c767718aae5 217234 libafsauthent1_1.6.13-1_amd64.deb af854f651c858bd096d32de0852f73ea5112485f 202048 libafsrpc1_1.6.13-1_amd64.deb 7088058250007cc744603342caec99e82749d782 94196 libkopenafs1_1.6.13-1_amd64.deb 9495a3a289f0ed1fafa1799265fc4fcd40d8b7af 1331478 libopenafs-dev_1.6.13-1_amd64.deb d4b50cbdd46e83fc9bafec800966f1da2cd3eae6 190626 libpam-openafs-kaserver_1.6.13-1_amd64.deb 083a708e3b3f7e383bf2f763610d3c15d967a5f5 1966196 openafs-client_1.6.13-1_amd64.deb 3dcd77f9cec68c05760e4d4d4392a3f0c09916cc 22503442 openafs-dbg_1.6.13-1_amd64.deb 827a0dad1c6c070b1266cf346fddb3381d3cd438 456032 openafs-dbserver_1.6.13-1_amd64.deb fe6c2fc5bf6072e597b0b489a7f22ce11b98a716 4003664 openafs-doc_1.6.13-1_all.deb 5a9a0b1e20da76f54285d9745daba20844c4422a 1342606 openafs-fileserver_1.6.13-1_amd64.deb 8c5ce5272c0f05ce90bd7d0ce17ed5adf6bab866 288970 openafs-fuse_1.6.13-1_amd64.deb 834b92516d4cb46d2955bcf9c1caec58042e6db9 203058 openafs-kpasswd_1.6.13-1_amd64.deb ab9fef802b36b68e13efdaea24cc108eccd975fa 262818 openafs-krb5_1.6.13-1_amd64.deb 0653677261293871fbfad02507df4b2712ee395b 943938 openafs-modules-dkms_1.6.13-1_all.deb 1e093724836a2853cf11a1fdf1d7ec612e4b8972 1158772 openafs-modules-source_1.6.13-1_all.deb Checksums-Sha256: 485898955478793c89aa78f3882ecebaf7ab4dda1d2a96372ff5fcef756e932b 3798 openafs_1.6.13-1.dsc 293e02b85f5ec4007b2317777a9eea02033a12f3eb2790cd7137c7f119927049 6650360 openafs_1.6.13.orig.tar.xz 66551e62ab38fd2fac1edd3c806d35e22e0963fc7e61c9ec3258ee75ec35959d 135644 openafs_1.6.13-1.debian.tar.xz 449e18eabf60e678e95f926ea61d30a22d336dc0aeb704e10ea9999160fd463c 217234 libafsauthent1_1.6.13-1_amd64.deb 217c49f45d2e896067598438f2d3a26738bb3690fe69ea90a37933c4f667e128 202048 libafsrpc1_1.6.13-1_amd64.deb 338a9dd12ac8bcade71b25efd7a223bd619aa9ee6a3b176b3e4833a1d2d62b9b 94196 libkopenafs1_1.6.13-1_amd64.deb c27e71714e7e752baf644d880d3810c770b7fc6301dc5e9868269af423d3bdc4 1331478 libopenafs-dev_1.6.13-1_amd64.deb a398990d6cedd737158d1f732e8d055d542fc9d3f26d7699ec36c6819d4ba2a4 190626 libpam-openafs-kaserver_1.6.13-1_amd64.deb 2fef3a11498f248141863d8cfc90e5668d7fea44671c894b9409f5606f663d9d 1966196 openafs-client_1.6.13-1_amd64.deb d6df03940ae8e5569403626e8b17a2c0df3a13c4c76dbd2c2f95b1b3289a6038 22503442 openafs-dbg_1.6.13-1_amd64.deb d12496c9fbd054ac010a521935ebd098e3c407f9f47cdedd302b3a7d80ec6147 456032 openafs-dbserver_1.6.13-1_amd64.deb 423e91f68c754c4c8f2ab52c6a49f2cff6b04d123bdd81a971a66a28b9d8d722 4003664 openafs-doc_1.6.13-1_all.deb 6ee43356670452a4e73b670635e164674a34866a0568ce6eb556fc345a1c0445 1342606 openafs-fileserver_1.6.13-1_amd64.deb f13135783971c60f9b5b3a722bc3cd1e9b4642e6785d649bfb110a3d16f2f36d 288970 openafs-fuse_1.6.13-1_amd64.deb 2db10585f2d31d5a9953f35d7ef318a42ef0e0fa6bef94e95accd0c81d964ca0 203058 openafs-kpasswd_1.6.13-1_amd64.deb 3340cefab5aaa8bba23c498786210b2b58fdb25586ff0c257e415886371e3fd1 262818 openafs-krb5_1.6.13-1_amd64.deb c4f3bc9f43af42643eb4ddf649d0687c2d805fa65c6c5f083ac5cc17b55ff494 943938 openafs-modules-dkms_1.6.13-1_all.deb b984bffe2b8270147f0f9e0193f809c4fbb40c32f0506cd7c1592e7805c49064 1158772 openafs-modules-source_1.6.13-1_all.deb Files: ce38687aa2b7b6330d11db380c2e0396 3798 net optional openafs_1.6.13-1.dsc 990658db81a68a8ec1093f418c1600c9 6650360 net optional openafs_1.6.13.orig.tar.xz d3dff20db8dad025c7091085f226d2c1 135644 net optional openafs_1.6.13-1.debian.tar.xz 17b331678037f243d76c1f66c80523b0 217234 libs optional libafsauthent1_1.6.13-1_amd64.deb cffbf389956f8da498d77f3bbe1e88f6 202048 libs optional libafsrpc1_1.6.13-1_amd64.deb eb9c81171ea2fa5b8acbf70d6f569a87 94196 libs optional libkopenafs1_1.6.13-1_amd64.deb c799b1419741ddb1efd91823a4715a3a 1331478 libdevel extra libopenafs-dev_1.6.13-1_amd64.deb 297da8643ef2452bf59e00f21288a4fb 190626 admin extra libpam-openafs-kaserver_1.6.13-1_amd64.deb e6eac9b3bbd454b2702c52e95906cd95 1966196 net optional openafs-client_1.6.13-1_amd64.deb 34ed3726b2f5bfd483065700ed9b5da8 22503442 debug extra openafs-dbg_1.6.13-1_amd64.deb c2acece2a10ec7c992c1182a481bb13a 456032 net optional openafs-dbserver_1.6.13-1_amd64.deb ede5efa05476b5a7e5d90caf2df1fe82 4003664 doc optional openafs-doc_1.6.13-1_all.deb f23b6141de3a2b8721510f754f774c23 1342606 net optional openafs-fileserver_1.6.13-1_amd64.deb 561f8a18b23232dc8e11009355a9ff7d 288970 net extra openafs-fuse_1.6.13-1_amd64.deb 6c210615d9f6d110fea444eb3159815f 203058 net extra openafs-kpasswd_1.6.13-1_amd64.deb 5e11727bbe11a7cd78cbbc5accde1bad 262818 net optional openafs-krb5_1.6.13-1_amd64.deb ddf23cfef9b7f6d062661411fc8efad1 943938 kernel extra openafs-modules-dkms_1.6.13-1_all.deb 158a54fadb67b57a0058bf3f037c9d7a 1158772 kernel extra openafs-modules-source_1.6.13-1_all.deb