• [SECURITY] [DSA 5036-1] sphinxsearch security update

    From Salvatore Bonaccorso@21:1/5 to All on Thu Jan 6 19:40:01 2022
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-5036-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso January 06, 2022 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : sphinxsearch
    CVE ID : CVE-2020-29050

    It was discovered that sphinxsearch, a fast standalone full-text SQL
    search engine, could allow arbitrary files to be read by abusing a configuration option.

    For the oldstable distribution (buster), this problem has been fixed
    in version 2.2.11-2+deb10u1.

    We recommend that you upgrade your sphinxsearch packages.

    For the detailed security status of sphinxsearch please refer to its
    security tracker page at: https://security-tracker.debian.org/tracker/sphinxsearch

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmHXNlpfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0SXNg//e9BBJyizvCyPwCutL0A7pHVzu7jxZOo3wuUc+e3EHy2gvQgDpVIXTOfR tK7L898ydkqNy+Ds0mwHeArnOo+hhsR4/Xy+lkMSoslFpNcmWtxy7HHgluck2ppG 6fobzUx5xwjmBBYDSQMXr2GZnYWTY7rqIKMVB9bO+40mKiCC41+GzzAGZD0IDkzx clcrS3c3wDVbrUYQf6rFPgOTd0epvd4vCC/2Fh7OorZSWGInlmhwBXDdBKVJKcMa FxBhLHVN1lasY82YP3ZlNKhLOUW8ULhOtYcpQlI6Ggw6yXAkLh7kQGcLo41nNNd8 OeDaugNtR1CxpudbnKBdPUOf58Xv6YiwOnnF/fTYgWQbYNC8OWcXa/HFylgtiJSx +wVnIcHEF3n9Zd3YHXmbOO916KeZvetWrNqDuYA7YxRcrLbi07k2hW7UeF7+GOzD fuS6fhONWW/REpsoRb3KQq1QPdvU+iiDuasUMrL8myHfzPRUF/WUkSdNj/zW3w4U CUyenZzySZTzZGrsO4xFM6YKI/ZMA+T7ytMQCVA2UWuUEgdvQ3N1R6iLUkHohni7 heWiYX3CPaC6rikjDpVi3FH6R/9kecqPM/NsD+bxdvnQfxJ6ZCZdt22+59ckSYmg 60aJNgFJLvBm14gf9Wer2elUHElt4qbBV+gIGrGxPFTKpoONKi8=
    =eHD6
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)