-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 16 Jun 2024 10:40:07 +0000 Source: zookeeper Binary: libzookeeper-mt-dev libzookeeper-mt2 libzookeeper-mt2-dbgsym libzookeeper-st-dev libzookeeper-st2 libzookeeper-st2-dbgsym python3-zookeeper python3-zookeeper-dbgsym zookeeper-bin zookeeper-bin-dbgsym Architecture: mipsel Version: 3.8.0-11+deb12u2 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-03) Changed-By: Bastien Roucariès Description: libzookeeper-mt-dev - Development files for multi threaded zookeeper C bindings libzookeeper-mt2 - Multi threaded C bindings for zookeeper libzookeeper-st-dev - Development files for single threaded zookeeper C bindings libzookeeper-st2 - Single threaded C bindings for zookeeper python3-zookeeper - Python bindings for zookeeper zookeeper-bin - Command line utilities for zookeeper Closes: 1066947 Changes: zookeeper (3.8.0-11+deb12u2) bookworm; urgency=medium . * Team upload * Bug fix: CVE-2024-23944 (Closes: #1066947): An information disclosure in persistent watchers handling was found in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by attaching a persistent watcher (addWatch command) to a parent which the attacker has already access to. ZooKeeper server doesn't do ACL check when the persistent watcher is triggered and as a consequence, the full path of znodes that a watch event gets triggered upon is exposed to the owner of the watcher. It's important to note that only the path is exposed by this vulnerability, not the data of znode, but since znode path can contain sensitive information like user name or login ID, this issue is potentially critical. * Add salsa CI Checksums-Sha1: c4f8a547c5e545d9ebcf4118aa5868fb1815f9b7 82000 libzookeeper-mt-dev_3.8.0-11+deb12u2_mipsel.deb 044d8919eac93158d60de561425f9fe65714c79e 171500 libzookeeper-mt2-dbgsym_3.8.0-11+deb12u2_mipsel.deb a5fc277634b0dc6ccb9aebb15f7be50046aa0174 45848 libzookeeper-mt2_3.8.0-11+deb12u2_mipsel.deb 7bc70f8da6670ae4612163af0559a462eaaede97 76760 libzookeeper-st-dev_3.8.0-11+deb12u2_mipsel.deb b6e6a1d7f752831e64f38f9b8eec84159ca06398 155264 libzookeeper-st2-dbgsym_3.8.0-11+deb12u2_mipsel.deb 630b2ef72501ce806428738a44831eb63f8719d2 41800 libzookeeper-st2_3.8.0-11+deb12u2_mipsel.deb 52a59e01cdef24ef2599e5b95e323314ca254942 39848 python3-zookeeper-dbgsym_3.8.0-11+deb12u2_mipsel.deb 375c39b10acfa01b8e3ca5cd65d2c12ba2969916 22252 python3-zookeeper_3.8.0-11+deb12u2_mipsel.deb d4c86526f521196dbbc8ded70c7def87bc3ecc05 36100 zookeeper-bin-dbgsym_3.8.0-11+deb12u2_mipsel.deb 0c5d31cabf89e0ff89616c1c1cc033ad9013466c 21200 zookeeper-bin_3.8.0-11+deb12u2_mipsel.deb 4828aba7c2ad3a19847596872da6cb39cd2d07a2 23144 zookeeper_3.8.0-11+deb12u2_mipsel-buildd.buildinfo Checksums-Sha256: 6f86a72e5208692ce6e8cf398bb6f5a83c54a5233fb61c9d08edcaa33556c7a6 82000 libzookeeper-mt-dev_3.8.0-11+deb12u2_mipsel.deb d36378103ab46636d918c85321217bea1ba68e431b34cc54c3b200d84308c528 171500 libzookeeper-mt2-dbgsym_3.8.0-11+deb12u2_mipsel.deb fe72827d0dff342b1eeb5558d47b35d1ea8bf2f51ed900bfaa27cce7634f739b 45848 libzookeeper-mt2_3.8.0-11+deb12u2_mipsel.deb d6fc565caedac4c293e9666cce580e4923abb7168dfef57ee3f529ca9fe82f6f 76760 libzookeeper-st-dev_3.8.0-11+deb12u2_mipsel.deb 4bd4e59cd883514bda1ace0021a9db94befd581faa9dbbbf458d068cfa26e6a7 155264 libzookeeper-st2-dbgsym_3.8.0-11+deb12u2_mipsel.deb 9f6d5b07a317f4916e25e250e5b66ec7b582dc86e4992ff43ce06fc5b05c9215 41800 libzookeeper-st2_3.8.0-11+deb12u2_mipsel.deb 765dbfd8a3e34329903dcba70654ac2cf3c16530b3c33548d3beaf357fc13384 39848 python3-zookeeper-dbgsym_3.8.0-11+deb12u2_mipsel.deb 60de5d4a34ab6ab4bbd95d86f9e391998d1020c6650812cb3bef4e2ab4898d12 22252 python3-zookeeper_3.8.0-11+deb12u2_mipsel.deb f23089abbff7c8f1b87174a83d27415ef7610b13c33b07f5f27f65b04b319d6e 36100 zookeeper-bin-dbgsym_3.8.0-11+deb12u2_mipsel.deb 9503c83b079cd4b2af5bde8740cec5a039832e8e174f04855b72162ce5a780b8 21200 zookeeper-bin_3.8.0-11+deb12u2_mipsel.deb 9a52834db7be56db02808e114ab085d1e7d769f858581c0d589b4b584d44b3ab 23144 zookeeper_3.8.0-11+deb12u2_mipsel-buildd.buildinfo Files: 81ca82fadf52375ca6a127b910991fb2 82000 libdevel optional libzookeeper-mt-dev_3.8.0-11+deb12u2_mipsel.deb 6a99f934c00569a5223dab23eb1fa387 171500 debug optional libzookeeper-mt2-dbgsym_3.8.0-11+deb12u2_mipsel.deb e237ea2c3887a16b536db92c5d3045eb 45848 libs optional libzookeeper-mt2_3.8.0-11+deb12u2_mipsel.deb 217428ce30f671cae50ac185bc2d9275 76760 libdevel optional libzookeeper-st-dev_3.8.0-11+deb12u2_mipsel.deb a932a4a3b1783406213067b832b46fe1 155264 debug optional libzookeeper-st2-dbgsym_3.8.0-11+deb12u2_mipsel.deb 0d76296adbbc932f0c810f232fae86fb 41800 libs optional libzookeeper-st2_3.8.0-11+deb12u2_mipsel.deb 58e31cc1cd9680cd3df40fc240562420 39848 debug optional python3-zookeeper-dbgsym_3.8.0-11+deb12u2_mipsel.deb c4ce83a98e40027b2b3259cdb8490d1d 22252 python optional python3-zookeeper_3.8.0-11+deb12u2_mipsel.deb 3cd2d4bf92e1a02dabf7c2ad15cc7e14 36100 debug optional zookeeper-bin-dbgsym_3.8.0-11+deb12u2_mipsel.deb f418a82295c91d1b0b9030fa7ead8422 21200 misc optional zookeeper-bin_3.8.0-11+deb12u2_mipsel.deb 024b9ffa138a54405aec2648a59e8ca9 23144 java optional zookeeper_3.8.0-11+deb12u2_mipsel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEunmvxaaGKuI+hxxClmZGXOM83t8FAmdx3IMACgkQlmZGXOM8 3t+S4g/8DCQ8EU0w1X/u5uylXfu1za7SyrKw9desqAKTaA2hpzUT7o2pIRTy/tmt N9GqbmK6mp+4P4Bk/wYVYRDqvLAVZcHcrZJpT2fh/T3jc2Qa7394l0zurxpbp3zz LHgqdhbJkXR1jR+XQC3zcB5TjKnbJyVEnwnQmbHROeVIKjn+zVkRZosVx4SSX1ro QYTsvoJ0K/5Y2hUhfvf4rEMsceB8ELBLme9e4NBKBXtW2RNMb9YYW8/Swqv6mrr6 AO680VmGFyu+4wZz/GqgAmeX7qjkDX7JoUSVyR9Oi6uiK9e/Gaof97JM8kQ9Olqh BbpVFMzhk8QTXfnOGoctqEJlI5qO7bi6sxR+VJS0Mm+cWIwJdQ4CkNlKaljp5SAe LmDSKkp1ED7EAEi46QLTmMfpHiKUxqWgFwe0Y6ZV2fTEhMPoBdN3RxNBxcARldms cZJoGCxLLMYsJLKYpO4F2Xbj6wcrl+EDE6Ojn1jQs5Qaq/m2a0ufomla3EDk634n e/IHrIq/j0Qpjwt3MBN8S4QlSanBMFg8refPlQXSCVA1056d6z27Hb8pMQq3wPd+ evXhZWo9y/mZj74mzNFx3+8qIa2BU4ywVGBnai9B4jqe0pcGxioLxkrUkFIhp6Bv as+NmNm6jhMzbsSK6hTyZSse0cwjQJYA9Sf3HGi6B3c6y3qqXXU= =OKCi -----END PGP SIGNATURE-----