-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 16 Jun 2024 10:40:07 +0000 Source: zookeeper Binary: libzookeeper-mt-dev libzookeeper-mt2 libzookeeper-mt2-dbgsym libzookeeper-st-dev libzookeeper-st2 libzookeeper-st2-dbgsym python3-zookeeper python3-zookeeper-dbgsym zookeeper-bin zookeeper-bin-dbgsym Architecture: armel Version: 3.8.0-11+deb12u2 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-ubc-04) Changed-By: Bastien Roucariès Description: libzookeeper-mt-dev - Development files for multi threaded zookeeper C bindings libzookeeper-mt2 - Multi threaded C bindings for zookeeper libzookeeper-st-dev - Development files for single threaded zookeeper C bindings libzookeeper-st2 - Single threaded C bindings for zookeeper python3-zookeeper - Python bindings for zookeeper zookeeper-bin - Command line utilities for zookeeper Closes: 1066947 Changes: zookeeper (3.8.0-11+deb12u2) bookworm; urgency=medium . * Team upload * Bug fix: CVE-2024-23944 (Closes: #1066947): An information disclosure in persistent watchers handling was found in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by attaching a persistent watcher (addWatch command) to a parent which the attacker has already access to. ZooKeeper server doesn't do ACL check when the persistent watcher is triggered and as a consequence, the full path of znodes that a watch event gets triggered upon is exposed to the owner of the watcher. It's important to note that only the path is exposed by this vulnerability, not the data of znode, but since znode path can contain sensitive information like user name or login ID, this issue is potentially critical. * Add salsa CI Checksums-Sha1: 0088db0c852cf5385c8ee1ed681cb29c6b9e5c62 71116 libzookeeper-mt-dev_3.8.0-11+deb12u2_armel.deb e1bc4fb47b0842177a968dad253ed5911c9b6284 160444 libzookeeper-mt2-dbgsym_3.8.0-11+deb12u2_armel.deb 3449b98a9ef6a8a04a12c43a52f330c1377838aa 44972 libzookeeper-mt2_3.8.0-11+deb12u2_armel.deb 8df54fe3eeb3fc9f1270327b1b46b1b262c353ec 67112 libzookeeper-st-dev_3.8.0-11+deb12u2_armel.deb 10f805de9cd306dfea6d5276d88b312082161ba7 144420 libzookeeper-st2-dbgsym_3.8.0-11+deb12u2_armel.deb abe7a845363fc82512afd4f96ab5e98764b55b3e 40896 libzookeeper-st2_3.8.0-11+deb12u2_armel.deb 6da1285fbca39dacbb9f0616d13c80289cbac3ef 37944 python3-zookeeper-dbgsym_3.8.0-11+deb12u2_armel.deb 472264f84ad12fb8e1232e02fb86c0b4be702921 22752 python3-zookeeper_3.8.0-11+deb12u2_armel.deb 7ab49d87435a3e5b4de9ca5f9be5e308f2fa6fb2 35580 zookeeper-bin-dbgsym_3.8.0-11+deb12u2_armel.deb 3536dacccaf9f28705c5aa6cdd7232b9dad277af 20120 zookeeper-bin_3.8.0-11+deb12u2_armel.deb 425cf7b606c1a48f8357691393fc43513f012b8c 23164 zookeeper_3.8.0-11+deb12u2_armel-buildd.buildinfo Checksums-Sha256: 387144c35fa9a2b9f7807c478fa96ac8764547a1e0d2392a52428d988af1fb6c 71116 libzookeeper-mt-dev_3.8.0-11+deb12u2_armel.deb 20ffbf033e519dcc846422c4d2bd4bfbb1745272ac710b4b8917b3cd1d86e81b 160444 libzookeeper-mt2-dbgsym_3.8.0-11+deb12u2_armel.deb c78e382c2e9ff757b442e71558a2f0f961f79191ae91507ea61066e577c1224a 44972 libzookeeper-mt2_3.8.0-11+deb12u2_armel.deb a1262db687097d2df1cd462f3e59fe97d8c18263b034c054545cf15d2a35117f 67112 libzookeeper-st-dev_3.8.0-11+deb12u2_armel.deb 38c3130325ea1aa98505f7e78229d9ec226528b1b5da78fb61a1f18c1f687058 144420 libzookeeper-st2-dbgsym_3.8.0-11+deb12u2_armel.deb b121898e80c5998df85783fe1a2543c092a978a459e474680caf0b357c078f8b 40896 libzookeeper-st2_3.8.0-11+deb12u2_armel.deb a3f71cdcbcab74a360a253214ca0daba1d54f8cfb72a90d213bb7d2bbf06ce4a 37944 python3-zookeeper-dbgsym_3.8.0-11+deb12u2_armel.deb 4ede3ce60d583a5e9f998716f1dfcb98774c94ce29a762f2834be97779c05f6b 22752 python3-zookeeper_3.8.0-11+deb12u2_armel.deb 695f2168f49d2ecc43efa1217992a2ee774821b56852a3e2a2e93acfca73b0c6 35580 zookeeper-bin-dbgsym_3.8.0-11+deb12u2_armel.deb 46e1320ec7f86e9159c0c26c9e3bc24949c3c96f69bcea6311c0faea41692e99 20120 zookeeper-bin_3.8.0-11+deb12u2_armel.deb 125bbd514008cc7695bba68b4a4af5a238fcce9417b3afbff7b8cc8260d50e18 23164 zookeeper_3.8.0-11+deb12u2_armel-buildd.buildinfo Files: ead60ea15624c88309cdeab7250b8c71 71116 libdevel optional libzookeeper-mt-dev_3.8.0-11+deb12u2_armel.deb b2afa9873d9f761976db6fba68421e44 160444 debug optional libzookeeper-mt2-dbgsym_3.8.0-11+deb12u2_armel.deb a4058be2a3c9e5f466193b28ea8870f5 44972 libs optional libzookeeper-mt2_3.8.0-11+deb12u2_armel.deb 32d75dac7c668d2d25617738cf8959a7 67112 libdevel optional libzookeeper-st-dev_3.8.0-11+deb12u2_armel.deb 64beb6e8b5e2645045275dd9c3cbfff9 144420 debug optional libzookeeper-st2-dbgsym_3.8.0-11+deb12u2_armel.deb 730ba9bbd4e780fb73f2c7a439c82a76 40896 libs optional libzookeeper-st2_3.8.0-11+deb12u2_armel.deb 02dff80b49a8ef43c04f72cc16157484 37944 debug optional python3-zookeeper-dbgsym_3.8.0-11+deb12u2_armel.deb 77ae1f231dce4051fb17a11a44ad1a17 22752 python optional python3-zookeeper_3.8.0-11+deb12u2_armel.deb 386febaddfcbae382446e13a70f0c0c2 35580 debug optional zookeeper-bin-dbgsym_3.8.0-11+deb12u2_armel.deb 6d737ae94f1f30592f8afe43fdf3a200 20120 misc optional zookeeper-bin_3.8.0-11+deb12u2_armel.deb 74501538326b8d3486a859c0eb21a53e 23164 java optional zookeeper_3.8.0-11+deb12u2_armel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE6s8UzO+WAx8RRAOV80lOEvgzuSsFAmdxllwACgkQ80lOEvgz uStuvg/9H6kQmxzF/astP0h4s7bRC+GmsB2SpdgU3pE1pzGrt+y5uHYFSrDTUt8A 68LbW4TuJaPj9GwSybQ7WDnmFJyL73E9FgcTeEHmK0n9Ax1StNljb1PzclAxLOU2 nvzi5YfNmYy3mwuJwZhW2LTrtTwqDtGdtT3vnGRgO6TyvRVL+IMKsGae1+Mus2so VDXcWtq5jHek/3OMPcI0wsU40am/kunR3CnO6Bo2qlaIm33TEo8JH2ZWIg3jETPf rMTPgZSkUiyRs2zZ/2TsOh0S84uVJmhI9CsjO/txmbTCPPDL+b2LHYWB9sM2b1Rk VMiylfbsUG0VSYIWPK6H24cnQUuLgAcywCTcHFysidIyjT8uh5lPyiN6e/eslwkG N/fDn9ocMWub3cBadHbGeZYaue75p+T8PcWbYmByPsyqFur1Pt7qTd0+mN2WWMWs FfjIcUbDNW9rVGNEAXUmhZX18zgvfbl8ylQ4skJl5kBMCHLG4JTHPMknL4zzJEJt FWBlDFUaaOsWaoGLVnbuXcmfD7PsaVbKRYWxqLfM0Jti/XPXza5wV7JVMXKYNcAQ zsljbAAIjkxz9zeGXd/FIQIjlF2NUeMMM3JJKa8uDfo3FsEEsAwMl2wraj/KN5Im w2potxGwCA9jh416PrsFT8IEClTPLThEMYXuu0NniPwLSWjlqiM= =tTub -----END PGP SIGNATURE-----