• [RFR] wml://lts/security/2022/dla-317{7,9}.wml

    From Jean-Pierre Giraud@21:1/5 to All on Sat Nov 12 17:50:01 2022
    This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------cMibeeekZThUzEJ6ltbsNI06
    Content-Type: multipart/mixed; boundary="------------q9D5xlfUSAme9mAO0aHA06my"

    --------------q9D5xlfUSAme9mAO0aHA06my
    Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64

    Qm9uam91ciwNCmRldXggbm91dmVsbGVzIGFubm9uY2VzIGRlIHPDqWN1cml0w6kgb250IMOp dMOpIHB1Ymxpw6llcy4gRW4gdm9pY2kgdW5lIA0KdHJhZHVjdGlvbi4gTWVyY2kgZCdhdmFu Y2UgcG91ciB2b3MgcmVsZWN0dXJlcy4NCkFtaWNhbGVtZW50LA0KamlwZWdlDQo= --------------q9D5xlfUSAme9mAO0aHA06my
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dla-3179.wml" Content-Disposition: attachment; filename="dla-3179.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249ImJmZmZm ZmVjMzFlODViNWM3NjhiNjA5MGUzZDM4M2ZmOTBjNzgwNzUiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6kgcG91ciBMVFM8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZv PgoKPHA+SWwgZXhpc3RhaXQgdW5lIHZ1bG7DqXJhYmlsaXTDqSBwb3RlbnRpZWxsZSBkJ8Op Y3JpdHVyZSBob3JzIGxpbWl0ZXMgZGFucwpwaXhtYW4sIHVuZSBiaWJsaW90aMOocXVlIGRl IG1hbmlwdWxhdGlvbiBkZSBwaXhlbHMgcG91ciBkZSBub21icmV1c2VzCmFwcGxpY2F0aW9u cyBncmFwaGlxdWVzIHBvdXIgTGludXguPC9wPgoKPHVsPgoKPGxpPjxhIGhyZWY9Imh0dHBz Oi8vc2VjdXJpdHktdHJhY2tlci5kZWJpYW4ub3JnL3RyYWNrZXIvQ1ZFLTIwMjItNDQ2Mzgi PkNWRS0yMDIyLTQ0NjM4PC9hPgoKPHA+RGFucyBsaWJwaXhtYW4gZGFucyBsZXMgdmVyc2lv bnMgZGUgUGl4bWFuIGFudMOpcmlldXJlcyDDoMKgMC40Mi4yLCBpbApleGlzdGFpdCB1bmUg w6ljcml0dXJlIGhvcnMgbGltaXRlcyAob3UgZMOpcGFzc2VtZW50IGRlIHRhcykgZGFucwpy YXN0ZXJpemVfZWRnZXNfOCwgZHVlIMOgIHVuIGTDqXBhc3NlbWVudCBkJ2VudGllciBkYW5z CnBpeG1hbl9zYW1wbGVfZmxvb3JfeS48L3A+PC9saT4KCjwvdWw+Cgo8cD5Qb3VyIERlYmlh biAxMCA8cT5CdXN0ZXI8L3E+LCBjZSBwcm9ibMOobWUgYSDDqXTDqSBjb3JyaWfDqSBkYW5z IGxhIHZlcnNpb24KMC4zNi4wLTErZGViMTB1MS48L3A+Cgo8cD5Ob3VzIHZvdXMgcmVjb21t YW5kb25zIGRlIG1ldHRyZSDDoCBqb3VyIHZvcyBwYXF1ZXRzIHBpeG1hbi48L3A+Cgo8cD5Q bHVzIGTigJlpbmZvcm1hdGlvbnMgw6AgcHJvcG9zIGRlcyBhbm5vbmNlcyBkZSBzw6ljdXJp dMOpIGRlIERlYmlhbiBMVFMsCmNvbW1lbnQgYXBwbGlxdWVyIGNlcyBtaXNlcyDDoCBqb3Vy IGRhbnMgdm90cmUgc3lzdMOobWUgZXQgbGVzIHF1ZXN0aW9ucwpmcsOpcXVlbW1lbnQgcG9z w6llcyBwZXV2ZW50IMOqdHJlIHRyb3V2w6llcyBzdXLCoDoKPGEgaHJlZj0iaHR0cHM6Ly93 aWtpLmRlYmlhbi5vcmcvTFRTIj5odHRwczovL3dpa2kuZGViaWFuLm9yZy9MVFM8L2E+Ljwv cD4KPC9kZWZpbmUtdGFnPgoKIyBkbyBub3QgbW9kaWZ5IHRoZSBmb2xsb3dpbmcgbGluZQoj aW5jbHVkZSAiJChFTkdMSVNIRElSKS9sdHMvc2VjdXJpdHkvMjAyMi9kbGEtMzE3OS5kYXRh IgojICRJZDogJAo=
    --------------q9D5xlfUSAme9mAO0aHA06my
    Content-Type: text/vnd.wap.wml; charset=UTF-8; name="dla-3177.wml" Content-Disposition: attachment; filename="dla-3177.wml" Content-Transfer-Encoding: base64

    I3VzZSB3bWw6OmRlYmlhbjo6dHJhbnNsYXRpb24tY2hlY2sgdHJhbnNsYXRpb249IjY0NWFm NmY2NTU3MmExZjU1N2U2NDdmYTU5ZWNhYzZmYmIxZDNhNWUiIG1haW50YWluZXI9IkplYW4t UGllcnJlIEdpcmF1ZCIKPGRlZmluZS10YWcgZGVzY3JpcHRpb24+TWlzZSDDoCBqb3VyIGRl IHPDqWN1cml0w6kgcG91ciBMVFM8L2RlZmluZS10YWc+CjxkZWZpbmUtdGFnIG1vcmVpbmZv PgoKPHA+SWwgZXhpc3RhaXQgcGx1c2lldXJzIHZ1bG7DqXJhYmlsaXTDqXMgZGFucyBEamFu Z28sIHVuIGNhZHJpY2llbCBwb3B1bGFpcmUKZGUgZMOpdmVsb3BwZW1lbnQgd2ViIGJhc8Op IHN1ciBQeXRob27CoDo8L3A+Cgo8dWw+Cgo8bGk+PGEgaHJlZj0iaHR0cHM6Ly9zZWN1cml0 eS10cmFja2VyLmRlYmlhbi5vcmcvdHJhY2tlci9DVkUtMjAyMi0yODM0NiI+Q1ZFLTIwMjIt MjgzNDY8L2E+wqA6ClVuIHByb2Jsw6htZSBhIMOpdMOpIGTDqWNvdXZlcnQgZGFucyBsZXMg dmVyc2lvbnMgZGUgRGphbmdvwqAyLjIgYW50w6lyaWV1cmVzCsOgwqAyLjIuMjgsIDMuMsKg YW50w6lyaWV1cmVzIMOgwqAzLjIuMTMgZXQgNC4wwqBhbnTDqXJpZXVyZXMgw6DCoDQuMC40 LiBMZXMgbcOpdGhvZGVzClF1ZXJ5U2V0LmFubm90YXRlKCksIGFnZ3JlZ2F0ZSgpIGV0IGV4 dHJhKCkgc29udCBzdWpldHRlcyDDoCB1bmUgaW5qZWN0aW9uCmRlIGNvZGUgU1FMIGRhbnMg bGVzIGFsaWFzIGRlIGNvbG9ubmVzIMOgIGwnYWlkZSBkJ3VuIGRpY3Rpb25uYWlyZQpjb250 cmVmYWl0IChhdmVjIHVuZSBleHBhbnNpb24gZGljdGlvbm5haXJlKSBlbiB0YW50IHF1J2Fy Z3VtZW50ICoqa3dhcmdzCnBhc3PDqXMgw6AgY2VzIG3DqXRob2Rlcy48L2xpPgoKPGxpPjxh IGhyZWY9Imh0dHBzOi8vc2VjdXJpdHktdHJhY2tlci5kZWJpYW4ub3JnL3RyYWNrZXIvQ1ZF LTIwMjEtNDUxMTUiPkNWRS0yMDIxLTQ1MTE1PC9hPsKgOgpVbiBwcm9ibMOobWUgYSDDqXTD qSBkw6ljb3V2ZXJ0IGRhbnMgbGVzIHZlcnNpb25zIGRlIERqYW5nb8KgMi4yIGFudMOpcmll dXJlcwrDoMKgMi4yLjI2LCAzLjLCoGFudMOpcmlldXJlcyDDoMKgMy4yLjExIGV0IDQuMMKg YW50w6lyaWV1cmVzIMOgwqA0LjAuMS4KVXNlckF0dHJpYnV0ZVNpbWlsYXJpdHlWYWxpZGF0 b3Igw6l0YWl0IGV4cG9zw6kgdW5lIHN1cmNoYXJnZSBpbXBvcnRhbnRlIGxvcnMKZGUgbCfD qXZhbHVhdGlvbiBkJ3VuIG1vdCBkZSBwYXNzZSByZcOndSBncm9zc2kgZGUgZmHDp29uIGFy dGlmaWNpZWxsZSBwYXIKcmFwcG9ydCBhdXggdmFsZXVycyBkZSByw6lmw6lyZW5jZS4gRGFu cyBsZXMgY2FzIG/DuSBsJ2FjY8OocyDDoApsJ2VucmVnaXN0cmVtZW50IGRlcyB1dGlsaXNh dGV1cnMgbifDqXRhaXQgcGFzIHJlc3RyZWludCwgY2VsYSBvZmZyYWl0IHVuCnZlY3RldXIg cG90ZW50aWVsIHBvdXIgdW5lIGF0dGFxdWUgcGFyIGTDqW5pIGRlIHNlcnZpY2UuPC9saT4K CjxsaT48YSBocmVmPSJodHRwczovL3NlY3VyaXR5LXRyYWNrZXIuZGViaWFuLm9yZy90cmFj a2VyL0NWRS0yMDIxLTQ1MTE2Ij5DVkUtMjAyMS00NTExNjwvYT7CoDoKVW4gcHJvYmzDqG1l IGEgw6l0w6kgZMOpY291dmVydCBkYW5zIGxlcyB2ZXJzaW9ucyBkZSBEamFuZ2/CoDIuMiBh bnTDqXJpZXVyZXMKw6DCoDIuMi4yNiwgMy4ywqBhbnTDqXJpZXVyZXMgw6DCoDMuMi4xMSBl dCA0LjDCoGFudMOpcmlldXJlcyDDoMKgNC4wLjEuIER1IGZhaXQgZGUKbCdleHBsb2l0YXRp b24gZGUgbGEgbG9naXF1ZSBkZSByw6lzb2x1dGlvbiBkZSB2YXJpYWJsZSBkdSBsYW5nYWdl IGRlCmdhYmFyaXRzIGRlIERqYW5nbywgbGUgZmlsdHJlIGRlIGdhYmFyaXQgZGljdHNvcnQg w6l0YWl0IMOpdmVudHVlbGxlbWVudAp2dWxuw6lyYWJsZSDDoCB1bmUgZGl2dWxnYXRpb24g ZCdpbmZvcm1hdGlvbnMgb3Ugw6AgbCdhcHBlbCBkJ3VuZSBtw6l0aG9kZQppbXByw6l2dWUs IHNpIHVuZSBjbMOpIGNvbnRyZWZhaXRlIGRlIGZhw6dvbiBhcHByb3ByacOpZSDDqXRhaXQg cGFzc8OpZS48L2xpPgoKPC91bD4KCjxwPlBvdXIgRGViaWFuIDEwIDxxPkJ1c3RlcjwvcT4s IGNlcyBwcm9ibMOobWVzIG9udCDDqXTDqSBjb3JyaWfDqXMgZGFucyBsYQp2ZXJzaW9uIDE6 MS4xMS4yOS0xK2RlYjEwdTMuPC9wPgoKPHA+Tm91cyB2b3VzIHJlY29tbWFuZG9ucyBkZSBt ZXR0cmUgw6Agam91ciB2b3MgcGFxdWV0cyBweXRob24tZGphbmdvLjwvcD4KCjxwPlBsdXMg ZOKAmWluZm9ybWF0aW9ucyDDoCBwcm9wb3MgZGVzIGFubm9uY2VzIGRlIHPDqWN1cml0w6kg ZGUgRGViaWFuIExUUywKY29tbWVudCBhcHBsaXF1ZXIgY2VzIG1pc2VzIMOgIGpvdXIgZGFu cyB2b3RyZSBzeXN0w6htZSBldCBsZXMgcXVlc3Rpb25zCmZyw6lxdWVtbWVudCBwb3PDqWVz IHBldXZlbnQgw6p0cmUgdHJvdXbDqWVzIHN1csKgOgo8YSBocmVmPSJodHRwczovL3dpa2ku ZGViaWFuLm9yZy9MVFMiPmh0dHBzOi8vd2lraS5kZWJpYW4ub3JnL0xUUzwvYT4uPC9wPgo8 L2RlZmluZS10YWc+CgojIGRvIG5vdCBtb2RpZnkgdGhlIGZvbGxvd2luZyBsaW5lCiNpbmNs dWRlICIkKEVOR0xJU0hESVIpL2x0cy9zZWN1cml0eS8yMDIyL2RsYS0zMTc3LmRhdGEiCiMg JElkOiAkCg==

    --------------q9D5xlfUSAme9mAO0aHA06my--

    --------------cMibeeekZThUzEJ6ltbsNI06--

    -----BEGIN PGP SIGNATURE-----

    wsF5BAABCAAjFiEEcH/R3vmpi4JWBoDfeBP2a44wMXIFAmNvzgcFAwAAAAAACgkQeBP2a44wMXLB 2xAAjd+5m3EfUWH1FaXbSgV9iREDfhtrUVzLzhHdxJfeJr5XQUcGGmO25uPf1JeeCMnPw94k1jni lEGOpzX7ZjGN/ibBP20ulv/9Lc/5+txX8MuZUiQcoHVQ8dw0j8ark35PhnTDcemv0TZOlqEjuCS/ 0oti+ZYAnCyp/8tLtfwKHaL1HLK/bCDVQWlchNJq7aIJ7jUKOUBGQgeVHc0mTkjoTottLx2wwSJt PyfECBILzWDwZSRHEwXiYXNf+YJtzbrJspxY71Z6UKGILsCLkHLJRpLfJgELQtdSdgjxs7M1ANh3 mgUtw758nhP1DmXY0xgbgKnk7so5M3CkvKUn/dsL2e5UTrqA7ku1d4ETjLUHkrY2Qoukq4OyagIQ xa5OpjuWf+YnE2R0zLrICn7+dEE+kw+BInzakoXoXhlrFC4BpEXhUzfdG3dhVsUkGs1FCslajiAU e2pcjl77qmSwVR2GEN4ECKuu53ZuK5H3FHQwCNhylpy6qBJ4LDYAzbvuIdQ/Inb+ZbtcRtGsMukM RCLQUwJWzjiqAoapS/zha5A10ufLF3uF1m21tKv/WZzSeuCfDyins38gci6W2cijFOho/5HKHutV Ty6csaPNJGE3vUQKr6Xvq18QUNfIzn7nTBBwKEzM0+3cGql+VFTO7hGFjVDXJR5VviYIfd9DWrcT 1AY=
    =07Tk
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From JP Guillonneau@21:1/5 to All on Sun Nov 13 08:50:01 2022
    Bonjour,

    Le 12/11/22 17:47 Jean-Pierre a écrit :
    deux nouvelles annonces de sécurité ont été publiées. En voici une traduction. Merci d'avance pour vos relectures.

    détail.

    Amicalement.

    --
    Jean-Paul

    --- dla-3177.wml.orig 2022-11-13 08:42:08.507801160 +0100
    +++ dla-3177.wml 2022-11-13 08:42:28.664024962 +0100
    @@ -18,7 +18,7 @@
    <li><a href="https://security-tracker.debian.org/tracker/CVE-2021-45115">CVE-2021-45115</a> :
    Un problème a été découvert dans les versions de Django 2.2 antérieures
    à 2.2.26, 3.2 antérieures à 3.2.11 et 4.0 antérieures à 4.0.1. -UserAttributeSimilarityValidator était exposé une surcharge importante lors +UserAttributeSimilarityValidator était exposé à une surcharge importante lors
    de l'évaluation d'un mot de passe reçu grossi de façon artificielle par
    rapport aux valeurs de référence. Dans les cas où l'accès à
    l'enregistrement des utilisateurs n'était pas restreint, cela offrait un

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)