-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 22 May 2022 15:57:10 +0200 Source: condor Binary: htcondor-doc Architecture: all Version: 8.6.8~dfsg.1-2+deb10u1 Distribution: buster-security Urgency: high Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Markus Koschany Description: htcondor-doc - distributed workload management system - documentation Changes: condor (8.6.8~dfsg.1-2+deb10u1) buster-security; urgency=high . * Non-maintainer upload. * Fix CVE-2019-18823: HTCondor has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user to the condor_schedd. (For example to submit or remove jobs) * Fix CVE-2022-26110: When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon. Checksums-Sha1: bc9cb74ba08442fd36745a5b3f0eb11ee6a4cdea 17317 condor_8.6.8~dfsg.1-2+deb10u1_all-buildd.buildinfo 48ff5a8148ee9ecf0d6a59901e5e8045011e7c1c 1325520 htcondor-doc_8.6.8~dfsg.1-2+deb10u1_all.deb Checksums-Sha256: 048f01de3074d8e6a7ce1016e0001b84b7f06b60e6a7d93c643a203e1b059c28 17317 condor_8.6.8~dfsg.1-2+deb10u1_all-buildd.buildinfo 380a3a50baa8f1766bc0ab785a49650f12d387a0266a0b8caad6de8fdb3ba8fd 1325520 htcondor-doc_8.6.8~dfsg.1-2+deb10u1_all.deb Files: f2eab00b9640e17a2aa267decaff6cee 17317 science extra condor_8.6.8~dfsg.1-2+deb10u1_all-buildd.buildinfo 34058007baa107a23ad67cb64e5b55c5 1325520 doc extra htcondor-doc_8.6.8~dfsg.1-2+deb10u1_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfA7dsu0ZDzzHaw+5NX/smi6DkKgFAmKKYK8ACgkQNX/smi6D kKiFAxAAjiAEC7WhEgyw4PDMomKx+W3/pt3UlMQZQdgtnzJft8P0/w0p/rS5A0Tu 9Tp3bYhe3OjprDcD2zhYPOkGV2aphVZASHZPGrRJvukJyL5G87vBl1rgvmJvMGsV Ru/uthOpeTT+yPojk9Tp+RTJcFTQhTn0j92lTnjWiWhVZ5QCfwrClq/iWoasBvB9 3w2Fwx+O6327OuVZ5TxUzOcl0HeW70YMCsEa1NUbjGi+UPy+0DwprUTx2bN953Bu l6RhZ+P8sD43l1iCc2FMXfs7iWIPUm0wU6BKnQcyL/+1DP3V9zp5L72Tc2M984Fy PuTTlmB1EcBI+TP3Mc6EBMcSHwQBf3IR9LMYymombfufa4zjaHYfNGzsxivcAvsK x06ZFjEzlUBtvCZd6uiZA7sfxxDWjpErRRMtBnucK1oI68unBkR832CvzMtCL1GA J9A7E750V0um8/DIxdENLlSauQhIj6f1z6JrOKCCvObA8THvEBZA3aBwD2bllmH5 WFvIBBAzCXW04WVu3UVxr2IcFD7v6YmuZCyF9CVlxUTCrcL2IFE69EDyh6OTWfY5 WjhpqTBpCsW8QP3qvlfjT2QfNM48t49ek+SCBjDtUZZhKn8MZwpA7K8jAlTXeUa2 BTmY2Db+c/gjVjM+2AZ40f4xnW7Szk5dOFfV5RoeEYGnTeqtNXw= =He+/ -----END PGP SIGNATURE-----