-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 22 May 2022 15:57:10 +0200 Source: condor Binary: htcondor htcondor-dbg htcondor-dev libclassad-dev libclassad8 Architecture: s390x Version: 8.6.8~dfsg.1-2+deb10u1 Distribution: buster-security Urgency: high Maintainer: s390x Build Daemon (zandonai) Changed-By: Markus Koschany Description: htcondor - distributed workload management system htcondor-dbg - distributed workload management system - debugging symbols htcondor-dev - distributed workload management system - development files libclassad-dev - HTCondor classads expression language - development library libclassad8 - HTCondor classads expression language - runtime library Changes: condor (8.6.8~dfsg.1-2+deb10u1) buster-security; urgency=high . * Non-maintainer upload. * Fix CVE-2019-18823: HTCondor has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user to the condor_schedd. (For example to submit or remove jobs) * Fix CVE-2022-26110: When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon. Checksums-Sha1: ee5016f93665b98402bc4db275171bfde52dd5b7 17796 condor_8.6.8~dfsg.1-2+deb10u1_s390x-buildd.buildinfo fc165b5757a5729f2f792ae0d994da6ae8a36808 49645184 htcondor-dbg_8.6.8~dfsg.1-2+deb10u1_s390x.deb c0aed5de0a464fd94d36b8059cfaed189c49ee55 302056 htcondor-dev_8.6.8~dfsg.1-2+deb10u1_s390x.deb 4223c413144d16a5cddb73bfaec56f04cc68dd83 3515324 htcondor_8.6.8~dfsg.1-2+deb10u1_s390x.deb 6853fc71d34fe572ded13c07500be755bafe8667 237552 libclassad-dev_8.6.8~dfsg.1-2+deb10u1_s390x.deb 481d15b629457f078b29577e57a4d138fdf4b552 181480 libclassad8_8.6.8~dfsg.1-2+deb10u1_s390x.deb Checksums-Sha256: aed3d01822739540cdc0ed9ca3303f1313763f9474163649f78bb689074f6716 17796 condor_8.6.8~dfsg.1-2+deb10u1_s390x-buildd.buildinfo d68328f6888f44b67ac684535cf32f21ded65ff725e0bf5aeae02765f3d9df4f 49645184 htcondor-dbg_8.6.8~dfsg.1-2+deb10u1_s390x.deb f4d2dd70ad06824ff1b6e216e8579943cfe4ee6d1828f1992d760f5969f2d1e8 302056 htcondor-dev_8.6.8~dfsg.1-2+deb10u1_s390x.deb d13176b407951776757724f1254556f193360db1e06f76240ba20ce534f60be2 3515324 htcondor_8.6.8~dfsg.1-2+deb10u1_s390x.deb 190ee8b220e8abb2ecb108936763bff8596bace79ad2d90bebeb052b6abeee2b 237552 libclassad-dev_8.6.8~dfsg.1-2+deb10u1_s390x.deb c8cb42fea9abb33f6c3c3d90c7b7fcab0ae0d466da1bd64d62d76330b07736e7 181480 libclassad8_8.6.8~dfsg.1-2+deb10u1_s390x.deb Files: 1a7aae189bdba68d0adeecc5f42292eb 17796 science extra condor_8.6.8~dfsg.1-2+deb10u1_s390x-buildd.buildinfo 9e3dfab9cb223738228ee1c320a36c30 49645184 debug extra htcondor-dbg_8.6.8~dfsg.1-2+deb10u1_s390x.deb 0cfc318442c5b91c0f24901a51782b72 302056 libdevel extra htcondor-dev_8.6.8~dfsg.1-2+deb10u1_s390x.deb 024930a66efc6be7243a1050499a6045 3515324 science extra htcondor_8.6.8~dfsg.1-2+deb10u1_s390x.deb 106e852edf6c3c4b4cfa043c7434d190 237552 libdevel extra libclassad-dev_8.6.8~dfsg.1-2+deb10u1_s390x.deb 469a4f2e10cf5a995f5ca351a35856bd 181480 libs extra libclassad8_8.6.8~dfsg.1-2+deb10u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEEwflLi3dfm21PN8mA0zNy/MAOYMFAmKKXQAACgkQA0zNy/MA OYMfBQ//ZYw5DQX5d1JVSGwvecGWmvoBmPimTpO5H4A5KLi1xVKmBwxdswY6/Kep zwFaVvufyOGvbe2XLPOznnvlHh2xCL4oq1ru1enlULyJsEWM34aHDjrnPfwaAuJ9 3TSdQJbVYHfsUKiTR1amufsnpzsmVB39zz8DFfVLumbmiBf3NZ9LIPO3vm2um1Y7 dDD1C0IdCEdJ7iD9Kr32ZCGwDcAKT7vOeacSgq93C0bi/g9UgzffbRU2aF6QYUCz 6RlL/8xEbDxwwlss1NdWHKPMLvdx+AeCOL7rdGyam2KUbbJHvUcpLNbuxmz+WwBL 1YptManx6GTd+0x55EhWFQcI5/s90P1I2MQqKxJf8J0Gslht1YvfFov1gMrFLCxK 4Pnck+PGaKC9qzc0I3NjiR9ksc4TI6ptv013+LNU23i+PQW5gNjETW4Faoan0/oe AANxZXQ/qq2uaFGIOoN8M1GYg8MNlVd6QhHrm0JUTN1L4QBih7wAgWhDePRx4GsQ snMB23buwDKBz9gsxkIbHWooIiybqODIeJFhHv7HOZUyqiZzCXDJyMFTrOVcfUUb M8EoiUK2zhVbO9gc4yRZsVt0Vv7NtgKON4+VA/KK9RzYzA0p34+HCeg1YdGsuKs7 /kLg1EY/BXSTikzrMUFHtx0PFtsGSqfkBUNw9exLIzknWGdX+lM= =VLNe -----END PGP SIGNATURE-----