-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 23:07:28 +0200 Source: glibc Binary: libc-bin libc-bin-dbgsym libc-dev-bin libc-dev-bin-dbgsym libc-devtools libc-devtools-dbgsym libc6 libc6-amd64 libc6-amd64-dbgsym libc6-dbg libc6-dev libc6-dev-amd64 libc6-dev-dbgsym libc6-dev-x32 libc6-udeb libc6-x32 libc6-x32-dbgsym locales-all nscd nscd-dbgsym Architecture: i386 Version: 2.36-9+deb12u7 Distribution: bookworm-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) Changed-By: Aurelien Jarno Description: libc-bin - GNU C Library: Binaries libc-dev-bin - GNU C Library: Development binaries libc-devtools - GNU C Library: Development tools libc6 - GNU C Library: Shared libraries libc6-amd64 - GNU C Library: 64bit Shared libraries for AMD64 libc6-dbg - GNU C Library: detached debugging symbols libc6-dev - GNU C Library: Development Libraries and Header Files libc6-dev-amd64 - GNU C Library: 64bit Development Libraries for AMD64 libc6-dev-x32 - GNU C Library: X32 ABI Development Libraries for AMD64 libc6-udeb - GNU C Library: Shared libraries - udeb (udeb) libc6-x32 - GNU C Library: X32 ABI Shared libraries for AMD64 locales-all - GNU C Library: Precompiled locale data nscd - GNU C Library: Name Service Cache Daemon Changes: glibc (2.36-9+deb12u7) bookworm-security; urgency=medium . * debian/patches/local-CVE-2024-33599-nscd.diff: Fix a stack-based buffer overflow in nscd netgroup cache (CVE-2024-33599). * debian/patches/local-CVE-2024-33600-nscd.diff: Fix a null pointer dereferences in nscd after failed netgroup cache insertion (CVE-2024-33600). * debian/patches/any/local-CVE-2024-33601-33602-nscd.diff: Fix a DoS in nscd in case of memory allocation failure (CVE-2024-33601) and a memory corruption in nscd when the underlying NSS callback function does not use the buffer space to store all strings (CVE-2024-33602). Checksums-Sha1: d2d3e2984ba41c71a73ced2a1ed25fb680785d2e 15186 glibc_2.36-9+deb12u7_i386-buildd.buildinfo 85d0feaeca602761adfa92cb468274e537a1dc7b 2247004 libc-bin-dbgsym_2.36-9+deb12u7_i386.deb f8df7fefe2341f5a3e15ae6481bd2d4197dc6bc0 632900 libc-bin_2.36-9+deb12u7_i386.deb 09e61381f9b84d934659f1bc9969463f86567401 28688 libc-dev-bin-dbgsym_2.36-9+deb12u7_i386.deb 341507015be137967562748501a41caf8238f3be 45940 libc-dev-bin_2.36-9+deb12u7_i386.deb b06fa5df45b454b0396f1b5ab597751b33520416 42860 libc-devtools-dbgsym_2.36-9+deb12u7_i386.deb ab2de71cd85e72e22d2943376fb64358b01c2483 55160 libc-devtools_2.36-9+deb12u7_i386.deb 5bcb8ee09ae4bb195593bf05aa6a3cfbdbf40b34 7393676 libc6-amd64-dbgsym_2.36-9+deb12u7_i386.deb 2ed9073cdfdb1d97decd56f09524b5aa26068d66 2585820 libc6-amd64_2.36-9+deb12u7_i386.deb 1be278a9f0c85fcb6940056077dfb438480e8683 7073880 libc6-dbg_2.36-9+deb12u7_i386.deb abc01033166202fb5407e0f299ce6a9c3912dab9 1528252 libc6-dev-amd64_2.36-9+deb12u7_i386.deb 5fb4c6c1ac4a76749fdb5d02b6a6f55d5f077e8b 14868 libc6-dev-dbgsym_2.36-9+deb12u7_i386.deb a98e8483f4ef73a20c647b46a4a7a48cb6841bc4 1516480 libc6-dev-x32_2.36-9+deb12u7_i386.deb 17552699febec61151d1679c13bd8735b4defaea 1720584 libc6-dev_2.36-9+deb12u7_i386.deb fedbc434922927ef76d5dd910f60afdc055f441a 1223168 libc6-udeb_2.36-9+deb12u7_i386.udeb 39fae0d53c0b68817e564693b6f3fa736298af92 7279236 libc6-x32-dbgsym_2.36-9+deb12u7_i386.deb 8f2585c9d87332a23a3172f473ff3894a1f7dff0 2583580 libc6-x32_2.36-9+deb12u7_i386.deb 490d6cf90a2f2798147d3302901febcc63f61ce2 2626572 libc6_2.36-9+deb12u7_i386.deb 1b28f4dfdd1d261952c147df0bcf24e25b430024 10699520 locales-all_2.36-9+deb12u7_i386.deb a503397b3ee65e91c71dfa25cacc2e0373bd8f0a 256308 nscd-dbgsym_2.36-9+deb12u7_i386.deb 5f05d3bb95759de8dd5b7761910f1620f9c0a13c 106144 nscd_2.36-9+deb12u7_i386.deb Checksums-Sha256: c187e6f238cdd04d59c0f1c29cbb30bd949c757c263b42dc7c1f5f8f28a33261 15186 glibc_2.36-9+deb12u7_i386-buildd.buildinfo 5a2594ca349a09c92ae96fa0ec50178f1a23e060988dcd04ee95757c35c87dea 2247004 libc-bin-dbgsym_2.36-9+deb12u7_i386.deb b96dcf4e651a2faf6e79672107711a9a98dbb368d5d5809303f93e71db78d374 632900 libc-bin_2.36-9+deb12u7_i386.deb c76320492c26faf8ff6681b5531b0c770d14ffc350555d2b8f000d531c0d8b17 28688 libc-dev-bin-dbgsym_2.36-9+deb12u7_i386.deb edb9e8a59652d62a4e2486ae0c5d9e84d665608b4389e1b57ce9775cda787fe0 45940 libc-dev-bin_2.36-9+deb12u7_i386.deb 626539dec6b270049438d5d752b479dd88232491c362b1cca64dcbf50bbb42f1 42860 libc-devtools-dbgsym_2.36-9+deb12u7_i386.deb 6d8d720ff29533d004ee60aaa1e87008747b27786be6494424e680d4008fc8fb 55160 libc-devtools_2.36-9+deb12u7_i386.deb 2c0bf29fa2df4ed48681839fba2d8a71eb1da2a41791eec811de06e6642ac075 7393676 libc6-amd64-dbgsym_2.36-9+deb12u7_i386.deb 29ae8e058096044d4c909b0cefa48af81c0f7b06a054e83a3825bc13b176a2da 2585820 libc6-amd64_2.36-9+deb12u7_i386.deb 518e6886b68c6598df8226c78cd88d1ca5f357a6ada33cdf64ed630e05150ba6 7073880 libc6-dbg_2.36-9+deb12u7_i386.deb ed5fb56699038d09bac7f959ada43a21708df4f6b4c61bb62291c889e7db364b 1528252 libc6-dev-amd64_2.36-9+deb12u7_i386.deb cdf202da0b7ea2c4fcfb444687f2504bece80fe51840ac391b5a24de85ab2033 14868 libc6-dev-dbgsym_2.36-9+deb12u7_i386.deb 1d9e939833a0d250eff65b2ba0b035f5de61fbcf39206492865a7ac16e3fa970 1516480 libc6-dev-x32_2.36-9+deb12u7_i386.deb 8e8e95f51286907d40352732d598e5979fc8e0fe4a48f5d333d05b4c1b4004c9 1720584 libc6-dev_2.36-9+deb12u7_i386.deb 935ec107281473ddf8147e0fe25afda5edf334bfa8ba8064f94d156d642c6660 1223168 libc6-udeb_2.36-9+deb12u7_i386.udeb c60b4362967f58d39171019b7c8a3713e65d118d6c8ca6a5904e2e1bd48ad31d 7279236 libc6-x32-dbgsym_2.36-9+deb12u7_i386.deb 9eea298eab1c8f7fa4f75b513795a2f935e76fa098d65bcf6ce10d72318d58b8 2583580 libc6-x32_2.36-9+deb12u7_i386.deb c7bd9122134c9d5110920181e62bfd88aa0322e9c9c0dde4b7cc98d7275c107f 2626572 libc6_2.36-9+deb12u7_i386.deb a9a974e9e9c71b4c125b167f21c0692132e3a8994e6d844cb1751d31e8d5c0a6 10699520 locales-all_2.36-9+deb12u7_i386.deb 983a8968b80f6716d26dd09ee855774853328d261d231392a4136c5559541e18 256308 nscd-dbgsym_2.36-9+deb12u7_i386.deb e27fe56f4f86a53df7ccb73c8fbaa76a70414167c4fd043f8924a4b2df6e86f5 106144 nscd_2.36-9+deb12u7_i386.deb Files: 990cde99f221412ad1bfe649901fc245 15186 libs required glibc_2.36-9+deb12u7_i386-buildd.buildinfo 69380870c8a4641300ebf9d7c957ae7b 2247004 debug optional libc-bin-dbgsym_2.36-9+deb12u7_i386.deb 9827f8724cc36e76ddd8e2cd9aab26ed 632900 libs required libc-bin_2.36-9+deb12u7_i386.deb 7869feb07d32fb9f092c184f4164fd23 28688 debug optional libc-dev-bin-dbgsym_2.36-9+deb12u7_i386.deb 19cc22a7cd6d24eb398531c82a651c1b 45940 libdevel optional libc-dev-bin_2.36-9+deb12u7_i386.deb fb0fa7af831f9a048f946a8b8b450796 42860 debug optional libc-devtools-dbgsym_2.36-9+deb12u7_i386.deb 5c42a26c08082ca59ecd4636c54fc0ad 55160 devel optional libc-devtools_2.36-9+deb12u7_i386.deb 91111a8ff80e4b2a3a621b24b368bbaa 7393676 debug optional libc6-amd64-dbgsym_2.36-9+deb12u7_i386.deb d344e700788cd0bceb103d45746ecb7e 2585820 libs optional libc6-amd64_2.36-9+deb12u7_i386.deb 5d5c3ea2c28cfe8482c4e77cff85c6e1 7073880 debug optional libc6-dbg_2.36-9+deb12u7_i386.deb b5f2054fe215ec3dabc425ec0018e9dd 1528252 libdevel optional libc6-dev-amd64_2.36-9+deb12u7_i386.deb 8bfbf7275fc1acb22baf7d09e0d93c69 14868 debug optional libc6-dev-dbgsym_2.36-9+deb12u7_i386.deb 00f3b26c89cca1f19ffd5362d29edc2b 1516480 libdevel optional libc6-dev-x32_2.36-9+deb12u7_i386.deb 25f7033b09759c1dd34cce105f14dacb 1720584 libdevel optional libc6-dev_2.36-9+deb12u7_i386.deb 9cb85ffa21f6d78637fd4eebc28d6f81 1223168 debian-installer optional libc6-udeb_2.36-9+deb12u7_i386.udeb 956ad360eea7f47aafcdff564ce924e9 7279236 debug optional libc6-x32-dbgsym_2.36-9+deb12u7_i386.deb f048233020eb8afb0ec1e877c34fdbff 2583580 libs optional libc6-x32_2.36-9+deb12u7_i386.deb 6f16842927bcc19043ab825991081b1e 2626572 libs optional libc6_2.36-9+deb12u7_i386.deb 3b766a8e26816c8e5fa318c90bf67e9e 10699520 localization optional locales-all_2.36-9+deb12u7_i386.deb 52a6ee803258684a4f87f3982c0d2d5b 256308 debug optional nscd-dbgsym_2.36-9+deb12u7_i386.deb 7cdf16dd46ca7e7691db6523edbbd876 106144 admin optional nscd_2.36-9+deb12u7_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEGBeuno8wiDXCewDuqqLQG5ksqMMFAmYxc4IACgkQqqLQG5ks qMOYFA//UlrT02H7dlNcTWrbVBLk8UmmKOGD+Pj9gqm2DcMcW3KzTZRrpp3F1FIb UWzD1QVU6/f1UfRnDfnOnrk+hLdoKYPBEa48pm0yVEV+E7/Pr4osHccYozy7W8q5 vP0zul6BY00HfROgUDlT1zL1p1AcASQzc+UIdOI5ethOhBpGK6ZKHx0xAy0MvM4J Ng6Weeg7y99O5XUo0cpFFchlh8ua/LUOYE7HQDQOZTzD0JuJC4anzIXLhxtY8LxQ SsMdqnjo7TlcJ3nlKjzj92BO7MI4ET00+ONmioK1swRFpz8Yva4BuVRfG7fG8GN/ uKs1RUyS6QKLzxDpKgnbm/CQmn64EscNfqMWFt9DHUwje7UKgpkQCCD4AJrSfZgP HiXCIElFF3TpgTxVs+Z+ic4rZK7w6cPdSKFKhzLWEQyy8NtLZzKvUj82ILhW4Y9u O2AthXwqmBrpT2TVdXQCluheWKmLQ0WTjCXwVR34p3cLmL0jWCVLYJKfN7+wB7UM bDaL2/6LnbLSF4Tiw4KEwrGKR0z1umq/XfLbvLNrJEetw4uEZ49YvMpVCzl5ozCS UypyrislbhEWQxXzjZIfynEsltfFWoklMoIzaB5sMzh9Zaxc6tu22jBcAKukINuq D2BW1Do6B9MkR3mp9RhOXLNzf0sSU8cs68zEGri/IKHGUmhAZfo= =ac/c -----END PGP SIGNATURE-----