-
debian/3.0.1-2
corosync Debian release 3.0.1-2 Format: 1.8 Date: Mon, 04 Feb 2019 00:31:24 +0100 Source: corosync Architecture: source Version: 3.0.1-2 Distribution: unstable Urgency: medium Maintainer: Debian HA Maintainers <debian-ha-maintainers@lists.alioth.debian.org> Changed-By: Ferenc Wágner <wferi@debian.org> Closes: 921265 Changes: corosync (3.0.1-2) unstable; urgency=medium . * [70f53cb] Switch to Debhelper level 12. On level 11 corosync.service is started by the dh_installinit snippet in the postinst script, before the dh_installsystemd snippet could enable it. This leads to an immediate stop since version 3.0.1, where corosync.service got the StopWhenUnneeded=true directive upstream. (Closes: #921265) * [5a00d0f] The package reorganization is already complete in stretch * [bf80b75] dwz chokes on our binaries currently * [c66c615] Minimize upstream signing key Checksums-Sha1: c7eacab935636ca2782a5840abbc2ed4a891ad3e 3381 corosync_3.0.1-2.dsc eaceb85cc65601cb92756b9af9578c1873eb54c7 26444 corosync_3.0.1-2.debian.tar.xz 2bee51a72d9722ec4872583d98ac39f2a6abd9d5 14966 corosync_3.0.1-2_amd64.buildinfo Checksums-Sha256: 1b639b3ae19956ffef4ff176f27a298ed1d786740d000f4f8c477b14af90c894 3381 corosync_3.0.1-2.dsc aa00c236121d3387f6c0842eaa989578ddd5865c74031febde1ff7808daf1b8b 26444 corosync_3.0.1-2.debian.tar.xz 16beb01a5eaa15d61d58ef3657fef1a1e9164ec32b062f60aa2c94df316889dd 14966 corosync_3.0.1-2_amd64.buildinfo Files: 50679f82556e490dc54876c8f6c5d877 3381 admin optional corosync_3.0.1-2.dsc 91ce067a21c30511ced6a8fa8fd9c9a9 26444 admin optional corosync_3.0.1-2.debian.tar.xz 02b00abd72df2fa2f3abb662b6143dd5 14966 admin optional corosync_3.0.1-2_amd64.buildinfo -
debian/3.0.1-1
corosync Debian release 3.0.1-1 Format: 1.8 Date: Fri, 01 Feb 2019 09:15:16 +0100 Source: corosync Architecture: source Version: 3.0.1-1 Distribution: unstable Urgency: medium Maintainer: Debian HA Maintainers <debian-ha-maintainers@lists.alioth.debian.org> Changed-By: Ferenc Wágner <wferi@debian.org> Changes: corosync (3.0.1-1) unstable; urgency=medium . * [426b1e4] New upstream release (3.0.1) * [c58aa08] Refresh our patches * [ca02815] Update Standards-Version to 4.3.0 (no changes required) * [a5dd92a] Don't use the orphaned dh-exec, Kronosnet is Linux only in Debian * [f5c0f29] Test-drive a bunch of small patches for upstream Checksums-Sha1: 65be981f2323a2dca73020153a10c2a8607763c9 3381 corosync_3.0.1-1.dsc 2c161a1d289847af088d2630d13f06b1491416ea 1054742 corosync_3.0.1.orig.tar.gz f636031a59481de0981ac0e8b0a5dc74c97732bb 801 corosync_3.0.1.orig.tar.gz.asc 87fa636e27aba6d01f9a4fa95f604ef8a3284a4c 28128 corosync_3.0.1-1.debian.tar.xz e2c0154cabb64c88d9dd7020415096345ad1408c 14970 corosync_3.0.1-1_amd64.buildinfo Checksums-Sha256: 49df70bf5644a44257acf115b2e2a7370776e7bb4ade90fd824db32e3c1f0652 3381 corosync_3.0.1-1.dsc 1e5bb77a68d1195932cb1518fedaf7b996d257809312097c4886c16da72f677e 1054742 corosync_3.0.1.orig.tar.gz 713b5e4d071206e22b012a3b263e45e1e261e5e4cfc8c4f6f26320e402a2a314 801 corosync_3.0.1.orig.tar.gz.asc 5373d436826548d1cc98b7691b213ae671fb6e4eb424bd1c29cfa750118a47a3 28128 corosync_3.0.1-1.debian.tar.xz ceed80f9c3373c08b3568c8d4622677dbcd7ff62500eb1f9847b9480473cbfba 14970 corosync_3.0.1-1_amd64.buildinfo Files: 27b0348de19b21d1c3f2859f7bda3c3f 3381 admin optional corosync_3.0.1-1.dsc fcd9759e77ce26bb656165c542c757c4 1054742 admin optional corosync_3.0.1.orig.tar.gz 31988a5a30f3a618f4abcd03a98e2ee1 801 admin optional corosync_3.0.1.orig.tar.gz.asc 27bd7a0aa5a568c59b042026bb88da1e 28128 admin optional corosync_3.0.1-1.debian.tar.xz 09d7f95131142c441158c6b28e26325b 14970 admin optional corosync_3.0.1-1_amd64.buildinfo
-
debian/3.0.0-1
corosync Debian release 3.0.0-1 Format: 1.8 Date: Sat, 22 Dec 2018 19:40:13 +0100 Source: corosync Binary: corosync corosync-notifyd corosync-doc libcfg7 libcmap4 libcorosync-common4 libcpg4 libquorum5 libsam4 libvotequorum8 libcfg-dev libcmap-dev libcorosync-common-dev libcpg-dev libquorum-dev libsam-dev libvotequorum-dev Architecture: source amd64 all Version: 3.0.0-1 Distribution: unstable Urgency: medium Maintainer: Debian HA Maintainers <debian-ha-maintainers@lists.alioth.debian.org> Changed-By: Ferenc Wágner <wferi@debian.org> Description: corosync - cluster engine daemon and utilities corosync-doc - cluster engine HTML documentation corosync-notifyd - cluster engine notification daemon libcfg-dev - cluster engine CFG library development libcfg7 - cluster engine CFG library libcmap-dev - cluster engine CMAP library development libcmap4 - cluster engine CMAP library libcorosync-common-dev - cluster engine common development libcorosync-common4 - cluster engine common library libcpg-dev - cluster engine CPG library development libcpg4 - cluster engine CPG library libquorum-dev - cluster engine Quorum library development libquorum5 - cluster engine Quorum library libsam-dev - cluster engine SAM library development libsam4 - cluster engine SAM library libvotequorum-dev - cluster engine Votequorum library development libvotequorum8 - cluster engine Votequorum library Closes: 576209 898266 915224 Changes: corosync (3.0.0-1) unstable; urgency=medium . [ Ferenc Wágner ] * [1f7a1e6] New upstream beta release (2.99.5) * [da76f82] Delete upstreamed patches, refresh the rest https://github.com/corosync/corosync/issues/81 was fixed in a different way. Qdevice and qnet were split out into a separate project. * [572d2a4] dh_installchangelogs finds ChangeLog by itself. I guess #711131 might have been the original reason for the override. * [db96368] Qdevice and qnet were split out into a separate project * [ca28efd] With the Kronosnet dependency Hurd compatibility is off the table * [a80ac6f] corosync-notifyd propagates the error since e313bbf * [91df99e] RDMA support was removed in 10075a0 * [cbd44d0] Looks like the upstream init scripts aren't misplaced anymore * [cff3ceb] Christoph got the overview man pages moved to the correct sections (Closes: #576209) * [065839c] The stale SECURITY file was removed by 6bdf096 * [1d8c4f0] Rename libcfg according to its new SO version * [580ad26] Add cmap_initialize_map to libcmap4.symbols * [03ddc00] Update Standards-Version to 4.2.1 (no changes required) * [71598bf] The debug symbol migration is complete * [83ff368] The Lintian tag about shipping INSTALL changed name * [2657a3b] Clean up trailing whitespace in debian/changelog * [fa7447b] The libtotem-pg library was discontinued (853e5b9) * [6bbab6f] New patch: Enable PrivateTmp in the systemd service files * [6ddd0bd] Remove corosync-dev, which was already transitional in stretch * [6b0129e] Corosync does not use environmental variables anymore * [8b272c3] Update source location * [be8a155] Update copyright years * [382f034] We got rid of the example conffiles during stretch * [50b2d8e] Upstream agreed to sign the tarballs, let's check the signature * [8057226] Require at least libqb 1.0.3 to avoid binutils issues (Closes: #898266) * [f69e2aa] Crypto is handled by Kronosnet * [2f8aa88] Use the upstream configuration example. Nodelist is required now, and it's better to let the token timeout scale with the cluster size. All in all, we might as well patch the upstream example into a working configuration. * [ff10f63] New upstream release (3.0.0) * [6b1357d] Refresh our patches * [74f03fc] Adjust autopkgtest to changed output . [ Andreas Henriksson ] * [1b43cee] Fix BASHPATH to make it reproducible. Otherwise it's detected differently on merged-usr vs non-merged. (Closes: #915224) Checksums-Sha1: a68ab6871a41b672c7d7eeb7fe4a596d998a7407 3390 corosync_3.0.0-1.dsc 306ad7c9418fa727e8ef33aecbb2edc07bf3be66 1053048 corosync_3.0.0.orig.tar.gz 8292098a3b339a4095c6fa105addd2e25025847d 801 corosync_3.0.0.orig.tar.gz.asc a90639c645f7774c715a9e235f9d2e9fa6a53834 25632 corosync_3.0.0-1.debian.tar.xz 900fa7444df2378367d4f9d9828f49984332d676 951136 corosync-dbgsym_3.0.0-1_amd64.deb ba9ca134672126f2bcc1bf2d2f9e22e938b5b670 10135160 corosync-doc_3.0.0-1_all.deb 724a56168940674f627e775d1d556faed8f3e5c5 103008 corosync-notifyd-dbgsym_3.0.0-1_amd64.deb 08a94524028b0d9d2de022d3fde852694c776825 254672 corosync-notifyd_3.0.0-1_amd64.deb d34c8f95c00c16cbb5d2a55b0afabc4884abdee7 14875 corosync_3.0.0-1_amd64.buildinfo 4f347bb48e222724b942ae3f4517282c10ebd93b 459868 corosync_3.0.0-1_amd64.deb f87a0276b1be9404cf69a7f1ca26976501a7b6e8 241032 libcfg-dev_3.0.0-1_amd64.deb b09689f04abf09ec58c7971860e7fa6a1d5c174d 56468 libcfg7-dbgsym_3.0.0-1_amd64.deb b8791e59d969abd71f97ec5699e285a893c4952d 244168 libcfg7_3.0.0-1_amd64.deb 4c2dff49ceed4b9ad2e9a8c91a1dc2fd5e301bfc 273600 libcmap-dev_3.0.0-1_amd64.deb 65f42532209842e68d2ec59a899071f21889dcb9 64964 libcmap4-dbgsym_3.0.0-1_amd64.deb 97a7020874ad1a613ed7457888cff8aae90fa699 246048 libcmap4_3.0.0-1_amd64.deb 6bd00ce3a174118da7076e39a4bcf76947973593 241948 libcorosync-common-dev_3.0.0-1_amd64.deb ccd4c9b4a25e9e160121e0691a29c06768dcc3f8 18108 libcorosync-common4-dbgsym_3.0.0-1_amd64.deb be7c36a25f65fa5934ed42af9a3df5525946814a 241416 libcorosync-common4_3.0.0-1_amd64.deb 347d9a90b76a5d51a6e7e617930f9742dc21fe9e 277748 libcpg-dev_3.0.0-1_amd64.deb 1c1e6ae001dfc4b893cfd07aadaede39b7900aa7 77936 libcpg4-dbgsym_3.0.0-1_amd64.deb 8140db5ed02217589b21b84dcd5352a1df352bf1 247300 libcpg4_3.0.0-1_amd64.deb 75873edc1c4de7d1950f4c9e2ae3dd84e0f31fb8 257276 libquorum-dev_3.0.0-1_amd64.deb fe4832d8a07f89409b3f0bb52b8e167e4892991b 48264 libquorum5-dbgsym_3.0.0-1_amd64.deb bd8560349485dbd073375cd1d30432e46484f781 242832 libquorum5_3.0.0-1_amd64.deb 1f60fe65c7c27b70b882ef521b41dff1872048eb 266588 libsam-dev_3.0.0-1_amd64.deb b962ea52008e8b6184a5589283173510ab9ad25a 65644 libsam4-dbgsym_3.0.0-1_amd64.deb b42aceeafcc4acab0b02e1877bc167d3cafb9890 247024 libsam4_3.0.0-1_amd64.deb c40ec373c88da24d788416eabe456c8d8a6d1b2e 272344 libvotequorum-dev_3.0.0-1_amd64.deb e39f86a0adaa1a5a4c852aa2c1659df09ee4c0a9 53500 libvotequorum8-dbgsym_3.0.0-1_amd64.deb 1958b4b5fcc846ac86d3769217e3de09c2eb5399 243960 libvotequorum8_3.0.0-1_amd64.deb Checksums-Sha256: a9b2939b8404f12aacfd90ea9a634c42de1c4d306c7a23742d8af9cdf65a6a64 3390 corosync_3.0.0-1.dsc 7c7991afe1414245f6570b4d371de3ab65342865a8b3f6539b31d0776fab769e 1053048 corosync_3.0.0.orig.tar.gz 32023f7dac4648457d6a55550a2f69806e5cfedbfe7ff1235258043f93391469 801 corosync_3.0.0.orig.tar.gz.asc d50e8bb8fd740471e728cd97ef1421ef9b44f828dd7a0df6cdee1bb58fad2aac 25632 corosync_3.0.0-1.debian.tar.xz eede1c4f50e92664d15a93089a219de96fe524470c3b6461301257f1ac60a57a 951136 corosync-dbgsym_3.0.0-1_amd64.deb 1827e03ae55fdd74105dca0377faa6776954395a87b53e1efb3fe39301c70ef3 10135160 corosync-doc_3.0.0-1_all.deb 557b408138c5b267cb96d8703b6bd4688410eeb7fa6867e9c0a10d7ae2a848d3 103008 corosync-notifyd-dbgsym_3.0.0-1_amd64.deb 3164424138027898de0a5dc2b4a3248d9045414b9e4a91e36233dc9e69e589bc 254672 corosync-notifyd_3.0.0-1_amd64.deb a47faa1116a37d119e8321c7e4e9e8c5ec8efee605f6fcb8b634468b67471fac 14875 corosync_3.0.0-1_amd64.buildinfo 9e97662bc8364140db410af3f6e2580e7e2e007b2cb0db5524289d9d0d11dcdd 459868 corosync_3.0.0-1_amd64.deb 15c659bc2d58169a1d4f5de415df3ad126595e6e91e9738b5a85ecdc9e399cfe 241032 libcfg-dev_3.0.0-1_amd64.deb fbe06af0968e5c066ed07e724d6b42378363cd16584fb7bdd51d6f9694875735 56468 libcfg7-dbgsym_3.0.0-1_amd64.deb 787d03088759ba7a285be91f0cd8e2cdcac382eefc3200425bf109e0b335422a 244168 libcfg7_3.0.0-1_amd64.deb 194f1fd429aa1ea65ce45fc8cbc45c51fb461ff628100a8be4b409bce56b800d 273600 libcmap-dev_3.0.0-1_amd64.deb 65e2267f15a45288a6a079bae6026fe2e1dc1052f0379006d8dc2b79fda63911 64964 libcmap4-dbgsym_3.0.0-1_amd64.deb 5c64b22df65cac40c17bda89d93e575142f5d398d8192adc870b70c246933503 246048 libcmap4_3.0.0-1_amd64.deb 34f8931c32110eeceda68e7a982070626e8ca68e291c461b0355a6aea90dcdf2 241948 libcorosync-common-dev_3.0.0-1_amd64.deb ebb203c3d6947faf933fef2763b4dbd54fea7d7e8f1b37407a519e2e4971a151 18108 libcorosync-common4-dbgsym_3.0.0-1_amd64.deb e277ead8cf096e96b1e97284df9d08c44c640754eb703b1168c51ec5609f6336 241416 libcorosync-common4_3.0.0-1_amd64.deb 5ebc0c5a17496b269572fd5cfc18f41aae417743157625ac77f5d3cadd2957ca 277748 libcpg-dev_3.0.0-1_amd64.deb 2aef80dc0ba15ad11fe6d5cec58e836a225b9cc93de9ea5bb35db9a668e9e6f3 77936 libcpg4-dbgsym_3.0.0-1_amd64.deb 1e16aaac7dfe068dd4b4bf6b49692fdbcf386085cd47e569cb4c64a3e6e0d1be 247300 libcpg4_3.0.0-1_amd64.deb 96fddcecffa829049f2e0c1a89dedc4292ec5ea9612448f57d96d1ca241545dc 257276 libquorum-dev_3.0.0-1_amd64.deb a95a58bda878d943ea4a0a61a59bea76aa8f84641bc15e38b6180b90fe7e97d9 48264 libquorum5-dbgsym_3.0.0-1_amd64.deb d36be93735d58a0f4f9aee31b996c882842db20f6804c7f6adc2ae51e170e0f9 242832 libquorum5_3.0.0-1_amd64.deb 3edabcaf979f85f850d824c9bb4cfc1920bb164d7d6dc8337131f0c63e1660ec 266588 libsam-dev_3.0.0-1_amd64.deb 1575a222966c669075ea1c0ba29ca3cc92fe8198d4f8b682364b6fe09a0a9edc 65644 libsam4-dbgsym_3.0.0-1_amd64.deb 900ae21ab717a663881c66a6d820636ebe08b856e0d527635f90239f25ec12d5 247024 libsam4_3.0.0-1_amd64.deb 331edde0191c2e77a1bb1d8627176efabf7ab46f1f0d3bcfd0ea4fdcee5d1b93 272344 libvotequorum-dev_3.0.0-1_amd64.deb ea6c0231e4b1da3149e455dc5d027e2696db813e2ecb66fe326f8b9616fb4ba1 53500 libvotequorum8-dbgsym_3.0.0-1_amd64.deb a60182faf2f464431e97c65527bde5263c2809397823c2fabbe4fa234580fcb5 243960 libvotequorum8_3.0.0-1_amd64.deb Files: 8039719f59b391fd13a62b450957f4cf 3390 admin optional corosync_3.0.0-1.dsc d3ecf2b879ee5944fad22e01e9ccfaff 1053048 admin optional corosync_3.0.0.orig.tar.gz 96bbca0c3a4189000824c4ee76d86c77 801 admin optional corosync_3.0.0.orig.tar.gz.asc 31961ae4adf0f75091fdd4af1fb2ab2c 25632 admin optional corosync_3.0.0-1.debian.tar.xz 52d531e6ee1eda8311722654f2c71dad 951136 debug optional corosync-dbgsym_3.0.0-1_amd64.deb d8f5cbbab61ede40aa477cb106794cff 10135160 doc optional corosync-doc_3.0.0-1_all.deb 6381fb6e2454a4b596e97042e7dcd4c1 103008 debug optional corosync-notifyd-dbgsym_3.0.0-1_amd64.deb 60061d15e487ae09038973cb9ed13ab9 254672 admin optional corosync-notifyd_3.0.0-1_amd64.deb d368e4343f1bb0148d9153055d786530 14875 admin optional corosync_3.0.0-1_amd64.buildinfo 19b9739581f3ff145736eff7ee3bcf3f 459868 admin optional corosync_3.0.0-1_amd64.deb ab944617859186173399765f23592a15 241032 libdevel optional libcfg-dev_3.0.0-1_amd64.deb cbb3e7df96fad89568fcc103c6c90f86 56468 debug optional libcfg7-dbgsym_3.0.0-1_amd64.deb 0f8340b1e757a546a7ea6e35494bf6dc 244168 libs optional libcfg7_3.0.0-1_amd64.deb 753ede9386b6ae9872d2db6eb3dc6f7a 273600 libdevel optional libcmap-dev_3.0.0-1_amd64.deb 1a78e23bbac64fc6c2da83fe14cc1e0d 64964 debug optional libcmap4-dbgsym_3.0.0-1_amd64.deb 8a461331bc1a070f29b6707d4d48122c 246048 libs optional libcmap4_3.0.0-1_amd64.deb d044a5fb8204f1fc214c3aad16440928 241948 libdevel optional libcorosync-common-dev_3.0.0-1_amd64.deb aee3e683ca396a551fdd53a49976e982 18108 debug optional libcorosync-common4-dbgsym_3.0.0-1_amd64.deb ab2524d993c21420898f71e4d91db56e 241416 libs optional libcorosync-common4_3.0.0-1_amd64.deb a10eb1b9695f96089622e9fd3ebc11ad 277748 libdevel optional libcpg-dev_3.0.0-1_amd64.deb f475f075c75b1772727b0cf729522026 77936 debug optional libcpg4-dbgsym_3.0.0-1_amd64.deb 9a6f2493dd819b319116eed7998f62b7 247300 libs optional libcpg4_3.0.0-1_amd64.deb a04241b18776bb73691d00e3daacb9df 257276 libdevel optional libquorum-dev_3.0.0-1_amd64.deb 0efde2d1d74ef6e3ce50c549ffc79f7c 48264 debug optional libquorum5-dbgsym_3.0.0-1_amd64.deb 245e127de37c92474f656c09e58da4c8 242832 libs optional libquorum5_3.0.0-1_amd64.deb fc08d6c88a40eaae788cd9643f6a0b14 266588 libdevel optional libsam-dev_3.0.0-1_amd64.deb 6ef211434f3cc3a196b98cd4bdaff122 65644 debug optional libsam4-dbgsym_3.0.0-1_amd64.deb fcbadb9d817f6aa8cca86b30d420076e 247024 libs optional libsam4_3.0.0-1_amd64.deb eda8048c7dfc08ed26ce8e65780bbdab 272344 libdevel optional libvotequorum-dev_3.0.0-1_amd64.deb 5dca05beddec74b06c7b2055df7bdff1 53500 debug optional libvotequorum8-dbgsym_3.0.0-1_amd64.deb 1065d7688893b04bacdba4b718fb6ed9 243960 libs optional libvotequorum8_3.0.0-1_amd64.deb -
debian/2.4.2-3+deb9u1_bpo8+1
corosync Debian release 2.4.2-3+deb9u1~bpo8+1 Format: 1.8 Date: Tue, 24 Apr 2018 12:06:51 +0200 Source: corosync Binary: corosync corosync-notifyd corosync-dbg corosync-qdevice corosync-qnetd corosync-doc corosync-dev libcfg6 libcmap4 libcorosync-common4 libcpg4 libquorum5 libsam4 libtotem-pg5 libvotequorum8 libcfg-dev libcmap-dev libcorosync-common-dev libcpg-dev libquorum-dev libsam-dev libtotem-pg-dev libvotequorum-dev Architecture: source i386 all Version: 2.4.2-3+deb9u1~bpo8+1 Distribution: jessie-backports Urgency: high Maintainer: Debian HA Maintainers <debian-ha-maintainers@lists.alioth.debian.org> Changed-By: Ferenc Wágner <wferi@debian.org> Description: corosync - cluster engine daemon and utilities corosync-dbg - cluster engine debugging symbols corosync-dev - cluster engine generic development (transitional package) corosync-doc - cluster engine HTML documentation corosync-notifyd - cluster engine notification daemon corosync-qdevice - cluster engine quorum device daemon corosync-qnetd - cluster engine quorum device network daemon libcfg-dev - cluster engine CFG library development libcfg6 - cluster engine CFG library libcmap-dev - cluster engine CMAP library development libcmap4 - cluster engine CMAP library libcorosync-common-dev - cluster engine common development libcorosync-common4 - cluster engine common library libcpg-dev - cluster engine CPG library development libcpg4 - cluster engine CPG library libquorum-dev - cluster engine Quorum library development libquorum5 - cluster engine Quorum library libsam-dev - cluster engine SAM library development libsam4 - cluster engine SAM library libtotem-pg-dev - cluster engine Totem library development libtotem-pg5 - cluster engine Totem library libvotequorum-dev - cluster engine Votequorum library development libvotequorum8 - cluster engine Votequorum library Closes: 887563 Changes: corosync (2.4.2-3+deb9u1~bpo8+1) jessie-backports; urgency=high . * Rebuild for jessie-backports. * [e44e00f] --restart-after-upgrade instead of stop in prerm and start in postinst. The previous stable security upgrade resulted in user complaints about Pacemaker remaining stopped after the Corosync upgrade. This is what systemd does with dependent services on stop+start. We can afford doing a restart instead, which behaves more like users expect. WARNING: on this upgrade the old prerm will still stop Corosync (and consequently: its dependencies!) for one last time. Pure restart behavior becomes effective for the forthcoming upgrades only. (Closes: #887563) . corosync (2.4.2-3+deb9u1) stretch-security; urgency=high . * [c2ee7ce] New patch fixing CVE-2018-1084: integer overflow in exec/totemcrypto.c. An integer overflow leading to an out-of-bound read was found in authenticate_nss_2_3() in Corosync. An attacker could craft a malicious packet that would lead to a denial of service. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1084 Thanks to Jan Friesse * [cfd0189] New patches fixing other vulnerabilities similar to CVE-2018-1084. The msgio patch fixes a real problem when message length > 2^31, which can't be mitigated by enabling encryption of the Corosync traffic. The other patches fix buffer overflows resulting in stack corruption and uses of unallocated memory; these can be mitigated by encryption. * [2ce17dc] The security patches introduced a new symbol Checksums-Sha1: 5aa40c6a1054a0ead4355752c02bcc21cd53a8c5 2793 corosync_2.4.2-3+deb9u1~bpo8+1.dsc 659d7fe9a811e95ef971ce5be1a025b9c1fe2f40 43832 corosync_2.4.2-3+deb9u1~bpo8+1.debian.tar.xz 9c29bc912b13443acc065f61cf9140c58b00d96c 383468 corosync_2.4.2-3+deb9u1~bpo8+1_i386.deb b99698d0a0e5cb82b5c1c7f089ceb2fec94d7ceb 225778 corosync-notifyd_2.4.2-3+deb9u1~bpo8+1_i386.deb 87a11466f625aac08db81b46f860892e497ab4bf 2025530 corosync-dbg_2.4.2-3+deb9u1~bpo8+1_i386.deb 0096d2eab40401aed511d1aaabe23ea9883b579e 275474 corosync-qdevice_2.4.2-3+deb9u1~bpo8+1_i386.deb 89975ebaed635b0123bd2fc9afb415e1c93215a3 266090 corosync-qnetd_2.4.2-3+deb9u1~bpo8+1_i386.deb e68ff7c6f4977c353dd9f32c281e0da392186f41 10148694 corosync-doc_2.4.2-3+deb9u1~bpo8+1_all.deb 3cfb104fc9dd40b6a1d455bfbcc7fcacbe2584d4 210872 corosync-dev_2.4.2-3+deb9u1~bpo8+1_all.deb b0519cefc67ffcd372fe26f83e3d950e554fb83c 216192 libcfg6_2.4.2-3+deb9u1~bpo8+1_i386.deb 2691a0df689e963cd2046ac6e0362cbf36ca4a90 218690 libcmap4_2.4.2-3+deb9u1~bpo8+1_i386.deb 717b749d4f52e9afe48bb355ca8bf5653a5a57e6 213120 libcorosync-common4_2.4.2-3+deb9u1~bpo8+1_i386.deb ec60a43415bbd0a5ee69aa12499c23fad26423ae 219322 libcpg4_2.4.2-3+deb9u1~bpo8+1_i386.deb 3efe1ba4b644953e9eafd4d7d9455d352f6dc93e 214710 libquorum5_2.4.2-3+deb9u1~bpo8+1_i386.deb 29caffaae4cc921e9ec4c9e6a0ffd65c11fef43f 219724 libsam4_2.4.2-3+deb9u1~bpo8+1_i386.deb 49e80a3e6d32adbb5c36f07c058cde818e0ba28f 275546 libtotem-pg5_2.4.2-3+deb9u1~bpo8+1_i386.deb 3e09477bcf2858a95f15431f15e6896976027c41 216278 libvotequorum8_2.4.2-3+deb9u1~bpo8+1_i386.deb 1a6023bb26c1d475ad251a7b50d607f69b483017 212410 libcfg-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb b2e9b6ad690c60a607d568b8e23dece36ec41491 243414 libcmap-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb 52891bda11d2e03b9171f3a03dd9e1f0e2c18b09 213428 libcorosync-common-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb 0c3bc0fac76ecca2869930f59f8fc2cb68358207 248650 libcpg-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb 3ba10ad95735ea3aaf7eed220f05cd278326a0e4 228850 libquorum-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb dcde7aca1d45df8f29f49355b64fb2cbd062ac47 238178 libsam-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb 5cd53f60484e896970a1ba0bb2e5a07a3467bb43 215070 libtotem-pg-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb fcf189055771b19ffc47924015dca2d7487ebb36 243800 libvotequorum-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb Checksums-Sha256: 6eac71dad90a6b42be50f35bfb266eafb889dd4cab54962ae7b9e55ba838f81e 2793 corosync_2.4.2-3+deb9u1~bpo8+1.dsc e4a3c09c9520e15a117259843dea6fdfc26d1d5882289247c63b3a298c91c58e 43832 corosync_2.4.2-3+deb9u1~bpo8+1.debian.tar.xz f1aa331b7f42ca61d3154e3d434bdd1085c429847403d959ca37542d5587f8d3 383468 corosync_2.4.2-3+deb9u1~bpo8+1_i386.deb 2980ac61657a3341fcf7d7508c72c834622043c621bfdcc0cf2ab1e4503dd704 225778 corosync-notifyd_2.4.2-3+deb9u1~bpo8+1_i386.deb 2fe985851030b9f0ceb1e7d30629706ca76bb0cf6b372203fb9eb030c402457f 2025530 corosync-dbg_2.4.2-3+deb9u1~bpo8+1_i386.deb 151944f649f4a7bd4c3fc3ce99efd4be71187dfc7092dfae7e00d9ad651eb64e 275474 corosync-qdevice_2.4.2-3+deb9u1~bpo8+1_i386.deb c72ec424e769b93de55f52f71a8f2c148f10349081f1f470ec910cb313e17b9d 266090 corosync-qnetd_2.4.2-3+deb9u1~bpo8+1_i386.deb 2f97614e3fd2834f2e96b014c681f837ce59c73a8fffaaab5f4a7fe50e310b11 10148694 corosync-doc_2.4.2-3+deb9u1~bpo8+1_all.deb e94121e09c5661f2bc10212768ae8f25df75778db872261c90e90f1587d41a5a 210872 corosync-dev_2.4.2-3+deb9u1~bpo8+1_all.deb 8b0538fec62185e07daf24d2aa4c42b096bc9df1051ad535bcf4c2916220e14e 216192 libcfg6_2.4.2-3+deb9u1~bpo8+1_i386.deb b0e8a499a8543d45156c87b976d7c551171be3906bb9caa81ef6e70616d4f2d5 218690 libcmap4_2.4.2-3+deb9u1~bpo8+1_i386.deb fdb085f7ad30186f9dbd5364871f9b4ef789ae3a00b545fdcf408e83dd178e4b 213120 libcorosync-common4_2.4.2-3+deb9u1~bpo8+1_i386.deb 94a286d202bdedc60d190bd8c31b756254ecfc3ac0698a0859e05c51642db7b6 219322 libcpg4_2.4.2-3+deb9u1~bpo8+1_i386.deb 39e7409eaefe8a79b43be092189c4daadeb42701adb33dc69b455bdf76040e6a 214710 libquorum5_2.4.2-3+deb9u1~bpo8+1_i386.deb 96dad03c0f6fdc794a13991bb5903bc092625ec67538de94b0f354d51889da1e 219724 libsam4_2.4.2-3+deb9u1~bpo8+1_i386.deb 242747e217b5039475e1ef0d10d723472d9a6280e4024e707926070c9e939642 275546 libtotem-pg5_2.4.2-3+deb9u1~bpo8+1_i386.deb 5a39bbcacd6057d057559bd65220c5f7f81b68e30f237946a31c323845563e30 216278 libvotequorum8_2.4.2-3+deb9u1~bpo8+1_i386.deb 597b6e65a23fef514b09e329840135d2a1fc48bdaa1841edf5db731d37ee9499 212410 libcfg-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb 62903d4f64a65441181a4951d12fa2a001c0cdb5ded1f56dab12a4243614f23e 243414 libcmap-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb 67fc1a666e167476e993d9185aaac9842856619e9446af9392b63bfbf56a4a00 213428 libcorosync-common-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb 8434c0d738da881508004575f86d35cc2dad20a4f8a4a262ad34cfa9290c3a3e 248650 libcpg-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb c9bc78e38cc4f47d48f94742e6cc64ea219dacc6093ff033ade3241bbc64997d 228850 libquorum-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb 80879cef1a9c8c0381a629f93c0682985f666578bf411c0fd7fcf0e1ef6adcb9 238178 libsam-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb 4c5a72a294b6353103464390715fdb54bc4024d34c7163ee7f5441b175bc687d 215070 libtotem-pg-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb e86d8d0b2b265fd47c26bbd0383b3a19a0af56a5709489349f0d13c849545d21 243800 libvotequorum-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb Files: 34845f99f9a7c40149a1ef2d97248bd3 2793 admin optional corosync_2.4.2-3+deb9u1~bpo8+1.dsc 6fe4bed9d1e1b91efaa2805758434d69 43832 admin optional corosync_2.4.2-3+deb9u1~bpo8+1.debian.tar.xz bb276c3b2fe12dbd66f49c50db7d5df9 383468 admin optional corosync_2.4.2-3+deb9u1~bpo8+1_i386.deb d69f367c0d1776a8432acded1965dc96 225778 admin optional corosync-notifyd_2.4.2-3+deb9u1~bpo8+1_i386.deb a92c2fca89ec1da72397b1b56c368286 2025530 debug extra corosync-dbg_2.4.2-3+deb9u1~bpo8+1_i386.deb 6fd83da875ab0db96f1fbedfebf5f529 275474 admin optional corosync-qdevice_2.4.2-3+deb9u1~bpo8+1_i386.deb afe1b19db15a098b40ac9ed884616926 266090 admin optional corosync-qnetd_2.4.2-3+deb9u1~bpo8+1_i386.deb a949d48fa5edb5cb7c2f9f504da5479c 10148694 doc optional corosync-doc_2.4.2-3+deb9u1~bpo8+1_all.deb c0639fb4f2e225a678a6773d64e9117f 210872 oldlibs extra corosync-dev_2.4.2-3+deb9u1~bpo8+1_all.deb 4539f234c051a312fdbfb137cc546c8c 216192 libs optional libcfg6_2.4.2-3+deb9u1~bpo8+1_i386.deb 3e95eee0514228c79d171ccad7a1b54c 218690 libs optional libcmap4_2.4.2-3+deb9u1~bpo8+1_i386.deb 92cba185b38578f38ba368c9b4bcbacc 213120 libs optional libcorosync-common4_2.4.2-3+deb9u1~bpo8+1_i386.deb 0f749165dfce8d298b3601133b5cc501 219322 libs optional libcpg4_2.4.2-3+deb9u1~bpo8+1_i386.deb bb2dc5e6eb641eba4d4500a682c36fc8 214710 libs optional libquorum5_2.4.2-3+deb9u1~bpo8+1_i386.deb f10d818fa833f9fed1fe24e633b67e5f 219724 libs optional libsam4_2.4.2-3+deb9u1~bpo8+1_i386.deb b36232364064d7ed7ac0e583c1bc1d44 275546 libs optional libtotem-pg5_2.4.2-3+deb9u1~bpo8+1_i386.deb b4fc5b07021aa7e793ee0591c8529476 216278 libs optional libvotequorum8_2.4.2-3+deb9u1~bpo8+1_i386.deb 4b71a321f30f28a7e8936744031d30f3 212410 libdevel optional libcfg-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb fb932606d9854775ea051b57db3949e4 243414 libdevel optional libcmap-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb b543980b6fdc41e9ccf9251f714b05e8 213428 libdevel optional libcorosync-common-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb 7be6dbae5a53ae2ce319e379ae29f0fa 248650 libdevel optional libcpg-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb 63db254cca4a8817e57105ea00b8342e 228850 libdevel optional libquorum-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb e17d11d8084bc696c036c247c3cf1253 238178 libdevel optional libsam-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb dadfcb443d0b94e9ac343077b3299e1b 215070 libdevel optional libtotem-pg-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb 533a9dc5ab277beaa9f149e0c4affa6b 243800 libdevel optional libvotequorum-dev_2.4.2-3+deb9u1~bpo8+1_i386.deb -
debian/2.4.4-3
corosync Debian release 2.4.4-3 Format: 1.8 Date: Sun, 22 Apr 2018 16:47:13 +0200 Source: corosync Binary: corosync corosync-notifyd corosync-qdevice corosync-qnetd corosync-doc corosync-dev libcfg6 libcmap4 libcorosync-common4 libcpg4 libquorum5 libsam4 libtotem-pg5 libvotequorum8 libcfg-dev libcmap-dev libcorosync-common-dev libcpg-dev libquorum-dev libsam-dev libtotem-pg-dev libvotequorum-dev Architecture: source Version: 2.4.4-3 Distribution: unstable Urgency: high Maintainer: Debian HA Maintainers <debian-ha-maintainers@lists.alioth.debian.org> Changed-By: Ferenc Wágner <wferi@debian.org> Description: corosync - cluster engine daemon and utilities corosync-dev - cluster engine generic development (transitional package) corosync-doc - cluster engine HTML documentation corosync-notifyd - cluster engine notification daemon corosync-qdevice - cluster engine quorum device daemon corosync-qnetd - cluster engine quorum device network daemon libcfg-dev - cluster engine CFG library development libcfg6 - cluster engine CFG library libcmap-dev - cluster engine CMAP library development libcmap4 - cluster engine CMAP library libcorosync-common-dev - cluster engine common development libcorosync-common4 - cluster engine common library libcpg-dev - cluster engine CPG library development libcpg4 - cluster engine CPG library libquorum-dev - cluster engine Quorum library development libquorum5 - cluster engine Quorum library libsam-dev - cluster engine SAM library development libsam4 - cluster engine SAM library libtotem-pg-dev - cluster engine Totem library development libtotem-pg5 - cluster engine Totem library libvotequorum-dev - cluster engine Votequorum library development libvotequorum8 - cluster engine Votequorum library Closes: 896528 Changes: corosync (2.4.4-3) unstable; urgency=high . * High urgency because 2.4.4 still hasn't reached testing yet. * [901fc27] Adjust symbols files to libqb magic 2. The powerpcspe and ppc64 build failures were late. * [4767a4f] Header dependency generation was removed by mistake (Closes: #896528) Checksums-Sha1: 701724e94a4cb9829201ce78abf8114c5e8a09b7 2588 corosync_2.4.4-3.dsc d1699d984eac01735a20269044f9f2493d76c307 31284 corosync_2.4.4-3.debian.tar.xz 5f29c19c71bdb9c25bc119143d1f5dda55ee9ca9 16425 corosync_2.4.4-3_amd64.buildinfo Checksums-Sha256: 1951cc5123fe1b02df4784387be08a223dddd95bf63e534ac84f04c29ff94f59 2588 corosync_2.4.4-3.dsc f60a35c1ef4dba215a910b7a7c856ffd49dcc71005e67d34b32ce35f97a8ec49 31284 corosync_2.4.4-3.debian.tar.xz 5aa12325bcd9350723e7dab624531c28f996ddd9df82b9cb9367d07277d9db6f 16425 corosync_2.4.4-3_amd64.buildinfo Files: 5c2a3bbb63ff942ce3956670ea937802 2588 admin optional corosync_2.4.4-3.dsc 00ffcb559baedda02eb8e1682e9d07de 31284 admin optional corosync_2.4.4-3.debian.tar.xz 777f906eed45b592c1c2ce51b29af974 16425 admin optional corosync_2.4.4-3_amd64.buildinfo -
debian/2.4.4-2
corosync Debian release 2.4.4-2 Format: 1.8 Date: Sat, 21 Apr 2018 11:21:00 +0200 Source: corosync Binary: corosync corosync-notifyd corosync-qdevice corosync-qnetd corosync-doc corosync-dev libcfg6 libcmap4 libcorosync-common4 libcpg4 libquorum5 libsam4 libtotem-pg5 libvotequorum8 libcfg-dev libcmap-dev libcorosync-common-dev libcpg-dev libquorum-dev libsam-dev libtotem-pg-dev libvotequorum-dev Architecture: source Version: 2.4.4-2 Distribution: unstable Urgency: high Maintainer: Debian HA Maintainers <debian-ha-maintainers@lists.alioth.debian.org> Changed-By: Ferenc Wágner <wferi@debian.org> Description: corosync - cluster engine daemon and utilities corosync-dev - cluster engine generic development (transitional package) corosync-doc - cluster engine HTML documentation corosync-notifyd - cluster engine notification daemon corosync-qdevice - cluster engine quorum device daemon corosync-qnetd - cluster engine quorum device network daemon libcfg-dev - cluster engine CFG library development libcfg6 - cluster engine CFG library libcmap-dev - cluster engine CMAP library development libcmap4 - cluster engine CMAP library libcorosync-common-dev - cluster engine common development libcorosync-common4 - cluster engine common library libcpg-dev - cluster engine CPG library development libcpg4 - cluster engine CPG library libquorum-dev - cluster engine Quorum library development libquorum5 - cluster engine Quorum library libsam-dev - cluster engine SAM library development libsam4 - cluster engine SAM library libtotem-pg-dev - cluster engine Totem library development libtotem-pg5 - cluster engine Totem library libvotequorum-dev - cluster engine Votequorum library development libvotequorum8 - cluster engine Votequorum library Closes: 896441 Changes: corosync (2.4.4-2) unstable; urgency=high . * High urgency FTBFS fix on ppc64el to unblock migration of security fix * [63ab152] Adjust symbols files to libqb magic * [9d3c9d6] New patch: Please make the manpages reproducible. Thanks to Chris Lamb (Closes: #896441) Checksums-Sha1: 872423c72c4850c9a765f505f3579e3cddbeeed5 2588 corosync_2.4.4-2.dsc 0d68c1fabfa52da2b4b34a390e1a89234d25c0c4 31164 corosync_2.4.4-2.debian.tar.xz 5f5412b91f6d90cdcf95d7eb3ca0a754213768d6 16425 corosync_2.4.4-2_amd64.buildinfo Checksums-Sha256: 5f0a7b00a47b2e3df65773657dfe33d10a06de36d822b97bb415cca066a9a529 2588 corosync_2.4.4-2.dsc 7bd2577aa8dad2c07da361e248abd596a8628cc7beee59464154a81f6d702d76 31164 corosync_2.4.4-2.debian.tar.xz ccd0f61545544ef66b5d72d11643f0b27ff085eaf2502c4f38d5d67fe02b412b 16425 corosync_2.4.4-2_amd64.buildinfo Files: 2ff0b42edcb162f6451a7c6a25b58d1b 2588 admin optional corosync_2.4.4-2.dsc 68afe5e2e5daec8e585610875b2eebb7 31164 admin optional corosync_2.4.4-2.debian.tar.xz dac6a48a75d94f00d6af3d5f042f2dd5 16425 admin optional corosync_2.4.4-2_amd64.buildinfo -
debian/2.4.4-1
corosync Debian release 2.4.4-1 Format: 1.8 Date: Fri, 20 Apr 2018 10:20:20 +0200 Source: corosync Binary: corosync corosync-notifyd corosync-qdevice corosync-qnetd corosync-doc corosync-dev libcfg6 libcmap4 libcorosync-common4 libcpg4 libquorum5 libsam4 libtotem-pg5 libvotequorum8 libcfg-dev libcmap-dev libcorosync-common-dev libcpg-dev libquorum-dev libsam-dev libtotem-pg-dev libvotequorum-dev Architecture: source Version: 2.4.4-1 Distribution: unstable Urgency: high Maintainer: Debian HA Maintainers <debian-ha-maintainers@lists.alioth.debian.org> Changed-By: Ferenc Wágner <wferi@debian.org> Description: corosync - cluster engine daemon and utilities corosync-dev - cluster engine generic development (transitional package) corosync-doc - cluster engine HTML documentation corosync-notifyd - cluster engine notification daemon corosync-qdevice - cluster engine quorum device daemon corosync-qnetd - cluster engine quorum device network daemon libcfg-dev - cluster engine CFG library development libcfg6 - cluster engine CFG library libcmap-dev - cluster engine CMAP library development libcmap4 - cluster engine CMAP library libcorosync-common-dev - cluster engine common development libcorosync-common4 - cluster engine common library libcpg-dev - cluster engine CPG library development libcpg4 - cluster engine CPG library libquorum-dev - cluster engine Quorum library development libquorum5 - cluster engine Quorum library libsam-dev - cluster engine SAM library development libsam4 - cluster engine SAM library libtotem-pg-dev - cluster engine Totem library development libtotem-pg5 - cluster engine Totem library libvotequorum-dev - cluster engine Votequorum library development libvotequorum8 - cluster engine Votequorum library Changes: corosync (2.4.4-1) unstable; urgency=high . [ Valentin Vidic ] * [069e127] Replace deprecated Priority: extra. Priority optional should be used instead. . [ Christoph Berg ] * [67b0779] Remove Richard and myself from Uploaders . [ Ferenc Wágner ] * [8c93a47] Update old style gbp.conf section names * [0863b9c] Old patch gained symbolic renames * [aae3275] New patches with various watchdog changes * [42da333] Switch to using HTTPS in the homepage URLs * [8dfbe1d] New upstream release (2.4.4) SECURITY fix for CVE-2018-1084 and similar bugs * [e550fa0] Delete upstreamed or misguided patches, refresh the rest. SOURCE_DATE_EPOCH is exported by debhelper and used by the upstream build system. Fully expanded substitutions must be performed by sed rules, AC_CONFIG_FILES is not suitable for performing such expansions. * [ff3bbdd] Update Standards-Version to 4.1.4 (no changes required) * [8da0691] Clean up trailing whitespace under the debian directory * [e11ae7f] Switch to Debhelper compat level 11 * [2c3fa47] Replace hand-made control substitution with stock dpkg method * [2b66152] Lintian does not emit embedded-javascript-library for Doxygen anymore * [d09a1b0] Migrate to salsa.debian.org/ha-team * [3483060] Upstart is dead, disable support * [1a5e66e] New patch: Fix typo: sucesfully -> successfully * [16a5d77] New libqb introduced some helper symbols https://github.com/ClusterLabs/libqb/pull/266 * [5212e89] Make sure to fully expand LOGDIR in the config examples * [7d1d319] Make qnetd stay with the DBM NSS DB format for now. At least until certutil can handle the upgrade. The postinst will have to be adapted as well. * [61d6673] qnetd-certutil uses ps and w * [68c3813] New patch: Fix typo: defualt -> default * [ecfb1b7] The security patches introduced a new symbol * [afab077] The sid toolchain does not add any dependencies to libcorosync_common4 * [cabd81d] Avoid recursive chmod in qnetd postinst. Lintian warns about the recursive chmod, but chmod -R g-w isn't an escalation vector, because it only takes away permissions. Still, it's better to make the list of affected files explicit. * [563c7d8] Test the shipped Augeas lense Checksums-Sha1: ef9a92b9d9434df9256aa8a6a5de70eaa9f5e798 2588 corosync_2.4.4-1.dsc 91073468906f05090d9a825024e5871e15d84ba7 1204051 corosync_2.4.4.orig.tar.gz 290311415253e81b1145d2863a42ff7d7fa4961f 30488 corosync_2.4.4-1.debian.tar.xz c735fb6488c957be08b375d97a9f370cb1173bd0 16425 corosync_2.4.4-1_amd64.buildinfo Checksums-Sha256: 705c1640fe670f97e3a3737259014b2771721f86a2e380c13eca15dded0301c4 2588 corosync_2.4.4-1.dsc 9bd4707bb271df16f8d543ec782eb4c35ec0330b7be696b797da4bd8f058a25d 1204051 corosync_2.4.4.orig.tar.gz 89ed52c2af1e936f7dd8ce658390752be5c106d7915a3c2c2a05d2cdd642b3b0 30488 corosync_2.4.4-1.debian.tar.xz 88ad7eb7f930764ba8bc69bd7d81455199ddfaf4231f28160d797ea286cb05a3 16425 corosync_2.4.4-1_amd64.buildinfo Files: 468c619101d8a12c7c020ccadb835153 2588 admin optional corosync_2.4.4-1.dsc 69db29ff4bc035936946be44fc8be5cd 1204051 admin optional corosync_2.4.4.orig.tar.gz 3fe7c3bd06ba2efe442fc1450f4e4811 30488 admin optional corosync_2.4.4-1.debian.tar.xz 7dfb8186355ad7b7e741ddf212384f5b 16425 admin optional corosync_2.4.4-1_amd64.buildinfo -
debian/2.4.2-3+deb9u1
corosync Debian release 2.4.2-3+deb9u1 Format: 1.8 Date: Sat, 14 Apr 2018 09:05:14 CEST Source: corosync Binary: corosync corosync-notifyd corosync-qdevice corosync-qnetd corosync-doc corosync-dev libcfg6 libcmap4 libcorosync-common4 libcpg4 libquorum5 libsam4 libtotem-pg5 libvotequorum8 libcfg-dev libcmap-dev libcorosync-common-dev libcpg-dev libquorum-dev libsam-dev libtotem-pg-dev libvotequorum-dev Architecture: source Version: 2.4.2-3+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Debian HA Maintainers <debian-ha-maintainers@lists.alioth.debian.org> Changed-By: Ferenc Wágner <wferi@debian.org> Description: corosync - cluster engine daemon and utilities corosync-dev - cluster engine generic development (transitional package) corosync-doc - cluster engine HTML documentation corosync-notifyd - cluster engine notification daemon corosync-qdevice - cluster engine quorum device daemon corosync-qnetd - cluster engine quorum device network daemon libcfg-dev - cluster engine CFG library development libcfg6 - cluster engine CFG library libcmap-dev - cluster engine CMAP library development libcmap4 - cluster engine CMAP library libcorosync-common-dev - cluster engine common development libcorosync-common4 - cluster engine common library libcpg-dev - cluster engine CPG library development libcpg4 - cluster engine CPG library libquorum-dev - cluster engine Quorum library development libquorum5 - cluster engine Quorum library libsam-dev - cluster engine SAM library development libsam4 - cluster engine SAM library libtotem-pg-dev - cluster engine Totem library development libtotem-pg5 - cluster engine Totem library libvotequorum-dev - cluster engine Votequorum library development libvotequorum8 - cluster engine Votequorum library Changes: corosync (2.4.2-3+deb9u1) stretch-security; urgency=high . * [c2ee7ce] New patch fixing CVE-2018-1084: integer overflow in exec/totemcrypto.c. An integer overflow leading to an out-of-bound read was found in authenticate_nss_2_3() in Corosync. An attacker could craft a malicious packet that would lead to a denial of service. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1084 Thanks to Jan Friesse * [cfd0189] New patches fixing other vulnerabilities similar to CVE-2018-1084. The msgio patch fixes a real problem when message length > 2^31, which can't be mitigated by enabling encryption of the Corosync traffic. The other patches fix buffer overflows resulting in stack corruption and uses of unallocated memory; these can be mitigated by encryption. * [2ce17dc] The security patches introduced a new symbol Checksums-Sha256: 7c442d2f88a5b0d7441e6988d3a47b3e6a2351dff3801d6e74a27aa6b946fe0a 2712 corosync_2.4.2-3+deb9u1.dsc 63cf0c83a33962304f63af8e14054b624d3b6de52ed214f68002dc4e0397c558 43288 corosync_2.4.2-3+deb9u1.debian.tar.xz f26e3011309fe4bcce94b1dc20ea8c462f19483a73f3ca62f13b925d011a4ba9 1152240 corosync_2.4.2.orig.tar.gz Checksums-Sha1: 739ef7f76dd4f91c74f26f3e49417156f67a9f88 2712 corosync_2.4.2-3+deb9u1.dsc 5a4c66fdf10c0ee7ae4998316284d9300c3514ca 43288 corosync_2.4.2-3+deb9u1.debian.tar.xz fdb77f06158d0a5fae931ea99e5d146e96f14914 1152240 corosync_2.4.2.orig.tar.gz Files: 1b975a45194010ea4f3e9bc481ad4dab 2712 admin optional corosync_2.4.2-3+deb9u1.dsc 67f7242c56ece39e8d03231f11b7a829 43288 admin optional corosync_2.4.2-3+deb9u1.debian.tar.xz 547fa78704da53aa35912be58d31035f 1152240 admin optional corosync_2.4.2.orig.tar.gz