• [SECURITY] [DSA 4938-1] linuxptp security update

    From Salvatore Bonaccorso@21:1/5 to All on Tue Jul 13 22:20:03 2021
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4938-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso
    July 13, 2021 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : linuxptp
    CVE ID : CVE-2021-3570
    Debian Bug : 990748

    Miroslav Lichvar reported that the ptp4l program in linuxptp, an
    implementation of the Precision Time Protocol (PTP), does not validate
    the messageLength field of incoming messages, allowing a remote attacker
    to cause a denial of service, information leak, or potentially remote
    code execution.

    For the stable distribution (buster), this problem has been fixed in
    version 1.9.2-1+deb10u1.

    We recommend that you upgrade your linuxptp packages.

    For the detailed security status of linuxptp please refer to its
    security tracker page at:
    https://security-tracker.debian.org/tracker/linuxptp

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmDt8ypfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0SGSg//ZAp+F3pt6rG0gSxl1xBJSQhsBoGfS0c+W6Fn6arlh0TvUDPh7JF8BHQ1 XpRgar3KduoOVsGsZWEN8vzEMBFhzpVmuvJzvD68vul8TMcS3L14kNHjaU54zHaV wHYr4UOXf7EuC/B43np3VGUbGxYYzI9ip+o3keolehoBZuN+oY3Hp+OmSUueX5lT vANPjQWNu8saJYVvAF7Nf3zjVkfpju0i8cI9SiuavWBwAwvdX16iSqcG3DVSWbSJ jAAWGBMi9aQt8JQUS/3kbsfHxKj3uZMQSNj7Ei/cMH8r3Qt/qJOIvDQtZ1cJwQ26 /xYcdEzq4ThHGOog+SGXWOzcfsURR+S9dIan9owQwf+9ikVbIi79t59jxsA76GHW BFUD/j/EI02JjmjXjbtj44wbSNkdzuiyJkWhTn154RJFa5OrJk3/7GVCMpzRDSZX 2TTEy5x8Uy55JOF9g0mjAezvohrDAz3VUNXWdErAeGHk61IwmGsa3jtpxhGLeGY0 73SB6NwcOccJ5OfAR/CxUn+TfaV+Gacq950tSVXfj5qlp8iY6ppHBAiRWgRQ+2i3 dLAt3kBdDxti7yydylS/SQTKrLfRnTbA6uPFkHhXPDPWmRVyl7HhoMoBkdQxTjBZ j43aERAw23XYTYuDdgUb3dAcrlnFOAGTC9H8SjljuHARAuG0GOA=
    =7/xl
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)