New Debian c-ares 1.12.0-1+deb9u2 fixes: This update addresses the following issue: * missing input validation of host names may lead to Domain Hijacking (CVE-2021-3672)
--- mirror/ftp/4.3/unmaintained/4.3-0/source/c-ares_1.12.0-1+deb9u1.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/c-ares_1.12.0-1+deb9u2.dsc @@ -1,3 +1,10 @@ +1.12.0-1+deb9u2 [Mon, 09 Aug 2021 22:03:02 +0200] Thorsten Alteholz <debian@alteholz.de>: + + * Non-maintainer upload by the LTS Team. + * CVE-2021-3672 + Missing input validation of host names returned by Domain Name + Servers can lead to output of wrong hostnames. + 1.12.0-1+deb9u1 [Mon, 26 Jun 2017 22:00:03 +0200] Gregor Jasny <gjasny@googlemail.com>: * Add patch for CVE-2017-1000381 (Closes: #865360) <http://piuparts.knut.univention.de/4.4-8/#3907691794637359261>
OK: yaml OK: announce_errata OK: patch OK: piuparts
<https://errata.software-univention.de/#/?erratum=4.4x1022>