-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 22 May 2022 15:57:10 +0200 Source: condor Binary: htcondor htcondor-dbg htcondor-dev libclassad-dev libclassad8 Architecture: mips64el Version: 8.6.8~dfsg.1-2+deb10u1 Distribution: buster-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-04) Changed-By: Markus Koschany Description: htcondor - distributed workload management system htcondor-dbg - distributed workload management system - debugging symbols htcondor-dev - distributed workload management system - development files libclassad-dev - HTCondor classads expression language - development library libclassad8 - HTCondor classads expression language - runtime library Changes: condor (8.6.8~dfsg.1-2+deb10u1) buster-security; urgency=high . * Non-maintainer upload. * Fix CVE-2019-18823: HTCondor has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user to the condor_schedd. (For example to submit or remove jobs) * Fix CVE-2022-26110: When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon. Checksums-Sha1: e4ae7643f0aad34d8a115801a67a8a39c21e6a17 17786 condor_8.6.8~dfsg.1-2+deb10u1_mips64el-buildd.buildinfo 483e38a352f868f602706d9931f9c1d34f28b9e2 49463916 htcondor-dbg_8.6.8~dfsg.1-2+deb10u1_mips64el.deb 53343612c68eaa68fdec968611488a225c7383af 363612 htcondor-dev_8.6.8~dfsg.1-2+deb10u1_mips64el.deb f04de253ceae6ecd681b2757fac4fac8aeafe513 3485368 htcondor_8.6.8~dfsg.1-2+deb10u1_mips64el.deb 1b0536f1025920555cf3faa68e0b1080eb050884 283744 libclassad-dev_8.6.8~dfsg.1-2+deb10u1_mips64el.deb 7dd4d4e2a00988c961d0913d4735e6ec25cf8355 176076 libclassad8_8.6.8~dfsg.1-2+deb10u1_mips64el.deb Checksums-Sha256: 8d07d3ec68a883fc2d5bf74c3e0c32b730ffc33044dc1d704067bd999681fa70 17786 condor_8.6.8~dfsg.1-2+deb10u1_mips64el-buildd.buildinfo bf6d2c5740d0ba0b695aed6a2f0d351e16d6f75a7a1cf3fa3b7b58af989850f9 49463916 htcondor-dbg_8.6.8~dfsg.1-2+deb10u1_mips64el.deb 9bebb4226a55d0955bfb7f49f94935e482b0f777513a023e522b96e1ba3e4d7c 363612 htcondor-dev_8.6.8~dfsg.1-2+deb10u1_mips64el.deb d06f44ceb2090aaf9158f895dae555af0b4686c0a314e32538766421a4c001ac 3485368 htcondor_8.6.8~dfsg.1-2+deb10u1_mips64el.deb 84e9532eb6e14951bca1f5851e45fa70bbed5318454ca84d73fbf2b75b0b7ef6 283744 libclassad-dev_8.6.8~dfsg.1-2+deb10u1_mips64el.deb e71cd45af562dd7019260f421c3a5049f225330f69a41c0702a368cd3eb5c0e5 176076 libclassad8_8.6.8~dfsg.1-2+deb10u1_mips64el.deb Files: 9c200738808d02f66ae78db8167e3c28 17786 science extra condor_8.6.8~dfsg.1-2+deb10u1_mips64el-buildd.buildinfo c1237f9f5a76fb576b1102a809b6a3ae 49463916 debug extra htcondor-dbg_8.6.8~dfsg.1-2+deb10u1_mips64el.deb 8faf1a309bc98dbfdff2386f8109c2d7 363612 libdevel extra htcondor-dev_8.6.8~dfsg.1-2+deb10u1_mips64el.deb 32b953636ba023360e9dca5d0bbe19b6 3485368 science extra htcondor_8.6.8~dfsg.1-2+deb10u1_mips64el.deb 0950ca04b2368ee202bb8610eb9d4f94 283744 libdevel extra libclassad-dev_8.6.8~dfsg.1-2+deb10u1_mips64el.deb b437ea3456f54d2a4b339ae4d77a9222 176076 libs extra libclassad8_8.6.8~dfsg.1-2+deb10u1_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEx6RZvlDb+lBUAQ0pbKFgWHp4vjEFAmKKcegACgkQbKFgWHp4 vjGwsg/9FOQFX/s9JHBGBm/NzZjTOkQp2jGJG3kGPdU6t0Kj4Fgcex82LZD5iWUb Y6An8GRwR7nXIuip2IYZxyddCGDNmxhzgDLaU5wCjDDZp3Cu+MdooxX/RaBVb5jF C7ittjGryPDMKLOlrLqJCvWdyjrEs19DwxnI34gLA3D2iYYYhb/HoRO4cQIoe8uW mbqhKsVq7/HfAJ32ju56EyHmbBl0HzLJlzF1eVgCYkU/LBVuvMHAxi07gG1ij4o6 T43qWkZOHZfo+X+ejSI41HO/A5cL38PQnjH6Cns6xFSSaLMgIoCTTwqDLeBy2oE+ QrxDis29fmvkO8qztLwDsRTlTKqT4KEUwD5kZ2kltrjF5FDQ4qcx1UThMC4Qb9h2 UB6m59HfN6J9XtXzxqbX2hh5qWaJNqJBVLZibPrX+NLXOOddOR2hQAt/jOTqJ9EU 5eMt4pPuJiUQTlMRYfvNBevo1DWPtLhGez7qUn4VFDvH9XyF5lVZtACZk8dz+PKZ BEbk5AagteQQ4defnYj0Zrb5ASnv8VK7NDsqsH8TyW4hfaQE5C7K/hnTX7cpXH8v Ca9Z//EYH473H4fTJ3LkYFyWtj6hnZ2hKQ6/yh+o7JvSjQHHEDMM2cpU2djjjxxI +g2YfsdEkZcmhESwhArwox63Y3JM8W+HA29L+FwQnKPHqBqaPyg= =Xu82 -----END PGP SIGNATURE-----