-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 22 May 2022 15:57:10 +0200 Source: condor Binary: htcondor htcondor-dbg htcondor-dev libclassad-dev libclassad8 Architecture: ppc64el Version: 8.6.8~dfsg.1-2+deb10u1 Distribution: buster-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-unicamp-01) Changed-By: Markus Koschany Description: htcondor - distributed workload management system htcondor-dbg - distributed workload management system - debugging symbols htcondor-dev - distributed workload management system - development files libclassad-dev - HTCondor classads expression language - development library libclassad8 - HTCondor classads expression language - runtime library Changes: condor (8.6.8~dfsg.1-2+deb10u1) buster-security; urgency=high . * Non-maintainer upload. * Fix CVE-2019-18823: HTCondor has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user to the condor_schedd. (For example to submit or remove jobs) * Fix CVE-2022-26110: When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon. Checksums-Sha1: 31c198a8c2eba8ebd3ac561b3789ff10dda727cb 17933 condor_8.6.8~dfsg.1-2+deb10u1_ppc64el-buildd.buildinfo 700cbb3100f36f621c1f463cea7885282d86ac0c 49157524 htcondor-dbg_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb 4c45e23c43b026e1cc756db314ddb863e89dce58 357408 htcondor-dev_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb b9d17a339c96faeee739797b085fe5dab1016a07 4009068 htcondor_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb ec240e081bb3a5d21b66af33a5af694e32558c4b 268016 libclassad-dev_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb dc46e168bfa84b233b4aed83a68234a62e4b5d1b 204568 libclassad8_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb Checksums-Sha256: 6bea1c3d1ec98b6e5488a4ced835593da7aae1794101f7404005888375422329 17933 condor_8.6.8~dfsg.1-2+deb10u1_ppc64el-buildd.buildinfo 21e808ef515c312076964f4128af55df492b654bc7ed3d6ef8aef494197dd6dd 49157524 htcondor-dbg_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb 7a0648322537118bb119b362bac9f5c06648c8c8d24cd35e194251c27912aad5 357408 htcondor-dev_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb fed55ddf6f48cf6bb326d869c2c8994552e4b199d1f411edaddc331603707293 4009068 htcondor_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb cabfaf140ec4a9744984d38d7e81653aaee4cf0b52f406a4e5e27e3fd31e440d 268016 libclassad-dev_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb 4307d0b9a73b121e124709d0b26756f5fb6c76dbe3b087c506a466fe524929cf 204568 libclassad8_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb Files: efdb5e5b9a95a1d686dcae119ccf6df3 17933 science extra condor_8.6.8~dfsg.1-2+deb10u1_ppc64el-buildd.buildinfo 3535087e439469493396bf1d9eeb6598 49157524 debug extra htcondor-dbg_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb daa53d13c2cff1e5e5f576c7e05ccd79 357408 libdevel extra htcondor-dev_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb 38cea6778d9f6511f1f4d8c8a4d1f5f7 4009068 science extra htcondor_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb 25e92e0758d12be5f92b6abc4c0954ba 268016 libdevel extra libclassad-dev_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb 2529523249c8a3463c8940f2d5d94e24 204568 libs extra libclassad8_8.6.8~dfsg.1-2+deb10u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEM6ceAMELlsCX7atTQTdFj1F/eVQFAmKKYHMACgkQQTdFj1F/ eVTp7g/8D67s//gAuAtrg7hk+2kBKyG8cK7T4aLcl0me49W3xwHQxHC8Q1BjJHcU dfteqfq401yvc36GfQhxCGYRj4BVUEkFKMopw71IJugetnuWWUcdquzC2CpxsK7D iwKHR5pLbuPTNTokrElMPNJX6b7OlnCA9OEG36JPeWwxf8NqVP783FOX+wAW4cD2 7tetjSaxXFC8GV30518al/F6Z1zQsaLydyUSNvkSGyPE/DfwYNWSPb6s+sZeYc0Q DuoDJaLWe03pyrTnNncHkUbQhY+sdLifc1JrURgvd1SN+kkd7diMDmZ6whrX+/+y qjil47mKlJbKR3AKi6c9q6/p5mn1MUot6sqGkpGHjBmXJ4aaS03raZF2i4a+8adZ ZPDRdyWYK0e20ygxpT+KPqsdUInjoKw1Yv2GwZ/whjxK0Xm91uqcN5wxg/xkqaBy emzGy2gaeGjNdbXpm8PKs4TojkOUuoDzyeG54xUwVwPVHGdxTNFBf+nrThWQBbgn 2N53LPjY4y/2YgiIHMJYtdsqy627mmRBe0l2njKRQoQMOZk356+CpoXFcZC22Cm2 6x0wUFbNAmBmx522Fe+mq1MFuO8PW7y+FicKmrc9agbMoQ7yEWf0MsSebI9tK+wB zqmzI+un+hYGxcL3OLx7Ek6PxXkksj4ECSNLnXh7hV/ZAhEnX8E= =hkEC -----END PGP SIGNATURE-----