-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 16 Jun 2024 10:40:07 +0000 Source: zookeeper Binary: libzookeeper-mt-dev libzookeeper-mt2 libzookeeper-mt2-dbgsym libzookeeper-st-dev libzookeeper-st2 libzookeeper-st2-dbgsym python3-zookeeper python3-zookeeper-dbgsym zookeeper-bin zookeeper-bin-dbgsym Architecture: arm64 Version: 3.8.0-11+deb12u2 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-conova-04) Changed-By: Bastien Roucariès Description: libzookeeper-mt-dev - Development files for multi threaded zookeeper C bindings libzookeeper-mt2 - Multi threaded C bindings for zookeeper libzookeeper-st-dev - Development files for single threaded zookeeper C bindings libzookeeper-st2 - Single threaded C bindings for zookeeper python3-zookeeper - Python bindings for zookeeper zookeeper-bin - Command line utilities for zookeeper Closes: 1066947 Changes: zookeeper (3.8.0-11+deb12u2) bookworm; urgency=medium . * Team upload * Bug fix: CVE-2024-23944 (Closes: #1066947): An information disclosure in persistent watchers handling was found in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by attaching a persistent watcher (addWatch command) to a parent which the attacker has already access to. ZooKeeper server doesn't do ACL check when the persistent watcher is triggered and as a consequence, the full path of znodes that a watch event gets triggered upon is exposed to the owner of the watcher. It's important to note that only the path is exposed by this vulnerability, not the data of znode, but since znode path can contain sensitive information like user name or login ID, this issue is potentially critical. * Add salsa CI Checksums-Sha1: f2c67760826534699946b527f1f41c616fe0f896 76588 libzookeeper-mt-dev_3.8.0-11+deb12u2_arm64.deb e1419992eeecc732cfc2bac890b252764eafb4c5 165764 libzookeeper-mt2-dbgsym_3.8.0-11+deb12u2_arm64.deb 36c3494e471b954d60b0aecf2d1d7b9049e3fe8d 48540 libzookeeper-mt2_3.8.0-11+deb12u2_arm64.deb 6f4552235e531be348f1851ea3d91eec244e88b1 72164 libzookeeper-st-dev_3.8.0-11+deb12u2_arm64.deb b824b1c08bb93ac7151eeba5aeaf1c84b05dba3e 150352 libzookeeper-st2-dbgsym_3.8.0-11+deb12u2_arm64.deb 861ab2273dd37888e85053d988bb94b61f6d44b4 43848 libzookeeper-st2_3.8.0-11+deb12u2_arm64.deb ebc005d40acbce401699bbdd29aa7d15b29cea8e 38860 python3-zookeeper-dbgsym_3.8.0-11+deb12u2_arm64.deb 73e3e4b88da1f463840243a3625eb118929d3adc 24120 python3-zookeeper_3.8.0-11+deb12u2_arm64.deb 1be37cd2acddbe0a326635cab65f03af1b6e159c 37444 zookeeper-bin-dbgsym_3.8.0-11+deb12u2_arm64.deb cf503733be9c78491dd3d0732224f3cd1e5f6646 20744 zookeeper-bin_3.8.0-11+deb12u2_arm64.deb f894a8ede54f210d48cd27f24f9986a9a5b55270 23290 zookeeper_3.8.0-11+deb12u2_arm64-buildd.buildinfo Checksums-Sha256: 1edd0f9e2de549597ae2543271bd83bb1579db60e7dce5137d12ed50103cf182 76588 libzookeeper-mt-dev_3.8.0-11+deb12u2_arm64.deb cc7c216b33e2d4d71b3b419fdee7a5b5fe623fe02744f67a217f4b67905fff23 165764 libzookeeper-mt2-dbgsym_3.8.0-11+deb12u2_arm64.deb e7cf13791ea6c5f60f2e28017a2bfebbcfc6f8371f93ebf665fdcdb8cfaa46c5 48540 libzookeeper-mt2_3.8.0-11+deb12u2_arm64.deb aac67f5fe95ee841aaf772e99d251eb5b774eb5aff9e8c229862337c4cff8b85 72164 libzookeeper-st-dev_3.8.0-11+deb12u2_arm64.deb 65b220db894d522698b9ed65295ec9c0c023789f411e5a69b628a87889d2fe96 150352 libzookeeper-st2-dbgsym_3.8.0-11+deb12u2_arm64.deb 6a195f1391f98b302aa07b76148a86642809bb8549c1f341d27dd23f46d87460 43848 libzookeeper-st2_3.8.0-11+deb12u2_arm64.deb 13d08b74fce565ad1ad87a972ce3a360f902fb4763ee10a4700ee2b1bcfb6390 38860 python3-zookeeper-dbgsym_3.8.0-11+deb12u2_arm64.deb b655c64a271f96be5061b147669aa7dbf6af3739063a0f37e6ed8c0ff2aa85d0 24120 python3-zookeeper_3.8.0-11+deb12u2_arm64.deb ce960f74fbe3ab868b4e8331aa2da6025c23526d03058050677cd23d9434ae22 37444 zookeeper-bin-dbgsym_3.8.0-11+deb12u2_arm64.deb c636a33a712ae23862a30a6eda568cd70948eaa5a850b92d419e6b4da69e9614 20744 zookeeper-bin_3.8.0-11+deb12u2_arm64.deb ee9545ae0cfd805da59b2c6b2978fe936c3593201e33c65bf7220d5701f958d4 23290 zookeeper_3.8.0-11+deb12u2_arm64-buildd.buildinfo Files: bd97e2099dddb946426db5ff8578ea61 76588 libdevel optional libzookeeper-mt-dev_3.8.0-11+deb12u2_arm64.deb 643ab8d4946cbf308e29d1a7330023be 165764 debug optional libzookeeper-mt2-dbgsym_3.8.0-11+deb12u2_arm64.deb ff63e687e4d52e44d795c29c98dfeb29 48540 libs optional libzookeeper-mt2_3.8.0-11+deb12u2_arm64.deb 59d60b840e8029f199c78474cf09413a 72164 libdevel optional libzookeeper-st-dev_3.8.0-11+deb12u2_arm64.deb 7a91ec8593e8e14b49e111ba4c79aeb4 150352 debug optional libzookeeper-st2-dbgsym_3.8.0-11+deb12u2_arm64.deb f4e09ad269bb14759de4396756490535 43848 libs optional libzookeeper-st2_3.8.0-11+deb12u2_arm64.deb 3a70b2eaed1c364c17f54d62f58226ae 38860 debug optional python3-zookeeper-dbgsym_3.8.0-11+deb12u2_arm64.deb 04b955767f0b8a6c5ff9dd4ba4515a7a 24120 python optional python3-zookeeper_3.8.0-11+deb12u2_arm64.deb 354989a2a28ffe4d3818afcdd418523f 37444 debug optional zookeeper-bin-dbgsym_3.8.0-11+deb12u2_arm64.deb 37f36f4695bf35cb60d9f73c1f83dbff 20744 misc optional zookeeper-bin_3.8.0-11+deb12u2_arm64.deb 467dda90eb55c3a47a094e9ea907bf6e 23290 java optional zookeeper_3.8.0-11+deb12u2_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvEwFZ4bqkVI+Rh6t+N4VxR6LZYEFAmdxjeAACgkQ+N4VxR6L ZYHnXxAAiAbTSll30z3azsjmkf0GQdV/gaE7jVyaBL7VXyCVjDkHji3x+rI2unZ4 w3XXxSsjPAShJG5tbbsJ3lNzxo3e0x1XO7EBhR8kjLlBDOmTeseo4MaGYZfNcXY/ 3RQLFcQjFBfN3VveX0vhwRZe6TvbZ1aD8ZTMHEYIUN2LQNkt2mUSvJxrkqZKVFS/ qJpUxjLtLPD+zEd8Hwl400RRAUy2PFkDKtIXkbvbezhesiv6RgMoVC2tfCtHlqGX AzZgoVs9ACwzuuqORoKMgvVTyrED9GAWY4Oqzl31hiFyO/xlSwrxuuyAAIHpHIL9 jLN0RGiRW5bN0hb9IvueKl0A/zHloKCQcad/BE+xgkpVtFQYV5me5NMZf8X0hLr+ L9hFTMtXanoqUIiqiVus1D/b7A+R4VsDaXseffY4zHdX0l6ETM22pixa5WXJ1en3 LDVhsP/LkExoHvqR5p9RZqBvUWQ+/lxfEeaietVdxqzKrKo3EMVTLUK0HjRBmmM0 tAJdy/SxnKrLTTYKCf/dzg/Buye1GbwR6BpyG6uhLBLBuZQ/lWLLdy5Shmd66jLG /XVgdK9UxfpCueZozpTg6ejF0KWgwIuhuQhV0HEHs2SyuxS/u3zSeyy4lHBiuMv7 d8/RDk/dDCo3a2OV9rXb5i+yiyL68u3qvGLQT8cdvWVkWhUF6ZQ= =woof -----END PGP SIGNATURE-----