-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 07 Aug 2021 13:02:07 +0200 Source: c-ares Architecture: source Version: 1.14.0-1+deb10u1 Distribution: buster-security Urgency: high Maintainer: Gregor Jasny Changed-By: Salvatore Bonaccorso Changes: c-ares (1.14.0-1+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the Security Team. * Missing input validation on hostnames returned by DNS servers (CVE-2021-3672) - ares_expand_name() should escape more characters - ares_expand_name(): fix formatting and handling of root name response Checksums-Sha1: 4f20b8ba380e65ad20882f0b0bf7e67b1efc72de 2327 c-ares_1.14.0-1+deb10u1.dsc 5b4989208c936d6445d4d73487634fe0b07e8ea7 1335940 c-ares_1.14.0.orig.tar.gz b7df69506ca5fc89ddcb100b7f6be50b1f9a7efa 488 c-ares_1.14.0.orig.tar.gz.asc bc91e04d67d9a870e6f2795aaf35210b16e7edbf 11384 c-ares_1.14.0-1+deb10u1.debian.tar.xz Checksums-Sha256: 3519511759e5769e674e759a215cfc1688f4e984776cfc3f2d52c3b697e918ec 2327 c-ares_1.14.0-1+deb10u1.dsc 45d3c1fd29263ceec2afc8ff9cd06d5f8f889636eb4e80ce3cc7f0eaf7aadc6e 1335940 c-ares_1.14.0.orig.tar.gz d84d42c725ef5a9d34835806200c04652b2139f9fb46828c92573a04a6c83288 488 c-ares_1.14.0.orig.tar.gz.asc e51baf79b1f48bfca1e5c82032a3de1a8b50140b56c8a86bbac81711c08acb1e 11384 c-ares_1.14.0-1+deb10u1.debian.tar.xz Files: c037b39e3e0a33d5d091fe4be58d8f89 2327 libs optional c-ares_1.14.0-1+deb10u1.dsc e57b37a7c46283e83c21cde234df10c7 1335940 libs optional c-ares_1.14.0.orig.tar.gz 610c31b99ec18b210c63e02e33b52a12 488 libs optional c-ares_1.14.0.orig.tar.gz.asc 98e94fd241216d2f7b6602b440164463 11384 libs optional c-ares_1.14.0-1+deb10u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmEOh0FfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EGssP/A/BTLN8Cl3d5kFpgkwnt7PPqpdEF0Ed ljDBXFskcjAL501mSjozihyH+OAwXyLcTsXyTAlKBaq2AeMoA4idrk3TLrn2svdp 6PaBoiBJDKtrhoq5uWsK6JxfxN2aUtR1HYoIQKXGQei6kL1N+caKD8JX4hin1rqt JmxucP8XFhsHyjTql2qkAaT2XAstP/TLE9mXnq4FWFBmH94c0rpugllfSKp7bj57 mSLg1saVvtYiRCfUbYelW53mMr6ejBXE/H+y/XNi2iaxh4jwQGY6v+8MPCiVfwc9 f7bk9PDOnjWOEEuRcEDtUcvWccsNrGlhT4hYvJw1xuwyiMZVpr25FqeEh1BeLH9h FXFSeRbMvM2xKf94Yx73t5qxuZp2YeP2GxycBzP+gt9mRGbrSwNRDNbKelpiGAnq +5ENSluTcv48F5+qIYZ5LYNrB9OAwrj0jBpze8ivsCWaddHCYQenhvSCy/pRIPfd mhKZwEcaMHDYTISjNdqwV/o31Dunuz7rMDDCL68MwNcvVN/umtmVSfyabxBoDm1J +pZNQuCWexqPyPfXdppezCM1iCQYlz5vJttE9Q5/JzSJQ2CfB3EZMfgsQTLhRf5E vryr/BvRz0qeJL/d6rLx0gGbQFsrSqtUY8FttT/6lO8FKFnSqH+S18Jq0GIxUcb2 uUmDr0NEMYkK =taiJ -----END PGP SIGNATURE-----