Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2020.4220 libproxy security update 30 November 2020 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: libproxy Publisher: Debian Operating System: Debian GNU/Linux Impact/Access: Execute Arbitrary Code/Commands -- Remote/Unauthenticated Denial of Service -- Remote/Unauthenticated Resolution: Patch/Upgrade CVE Names: CVE-2020-26154 CVE-2020-25219 Reference: ESB-2020.4054 ESB-2020.3524 ESB-2020.3196 Original Bulletin: http://www.debian.org/security/2020/dsa-4800 - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - - ------------------------------------------------------------------------- Debian Security Advisory DSA-4800-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso November 28, 2020 https://www.debian.org/security/faq - - ------------------------------------------------------------------------- Package : libproxy CVE ID : CVE-2020-25219 CVE-2020-26154 Debian Bug : 968366 971394 Two vulnerabilities were discovered in libproxy, an automatic proxy configuration management library, which could result in denial of service, or possibly, execution of arbitrary code. For the stable distribution (buster), these problems have been fixed in version 0.4.15-5+deb10u1. We recommend that you upgrade your libproxy packages. For the detailed security status of libproxy please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libproxy Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org - -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl/CsThfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0QHNQ/+KeeiXOgCF5TqJaI8wsFh6wIxZ7JaalX6Ps/N0IZTsbXF8b7SxIiPcEEO aw5MqYfmnhSlCN8f8HEpqIixdHDN4J+uLihus5yzsS/s8Th9/aXbOa2ZGc4ck8tw 7RIAfmBG6YSaNUuYInEvQrZaiLSPn/pF3PEMY9CtPrhctwK1+XMBc5Kmdu0o17fT pu2GuzUgprLRkS10la1GZIujq5NsWB8ywFolbSmXHIcLf0l6BnstLNLCpbNlcqsC mWbSMn0UZ+Eazc8OtfdXIP2eFbYfXENI+A+8RxuKELAtrT4wC94YZkES8gzqhb92 ndx/yCbyGR96BdKBEZ7lVXK25bmxKP7igG+30y/qZE8Oj4EUI1Dn+J/OZ9Nva0rT lxeqPxtgN7pj+sQD+5NmqHCRj/TmKQXJwZfWmgrvtTQ7l2qbI21CbvjeG2sZLiUa xADZ1rZu8stzvSJLljidi1cZsSwRoWJsZwNqfWWJYZUUaShLBI8ITHQZgX2X0bca 8HVW9CqxcM8AtemwjdXzTa9RVfE3cNq/PfNAVc/QOiN4p0zK3pykte4d3aRzb6Un wDwzm/HbIFmJoAsy6GHuXLZuQWcjuZVmGvMd1gmF9GrQHMX+hnsHdKAPsW+6SH6R denOzLMjuiG3BZ2qergUqV0S5DNigLBxZMB7scErENIssRu/5eQ= =xNP+ - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBX8RLKuNLKJtyKPYoAQhOeA//UDzO24BG+kAfILwAlaH8lddlaxE08Ouf 0T9N+IO+SLrsvn+TFf4o1MjbKSK6RiMOjES8gZobnKVHbMq8TGl9biS9tgdVDHiV o65ijosNCVikVVTfWDe5NGgoYA7uXRG8Uct9gGFmcz3cfiy+JOULUtBv0xoG7BjP cIhLcV/doramW/49EjogME58HN/FEujIx7RZHMONTksZG++RjVvXIHy+LsocBE39 oPkwXzV0lttp1UhQyZ2bp9RiAHDBWciEBaNHXEAVTi6bSj2hner4h5eI7QRSqwbw 8xeuUPVMvL2IVr+dHDG2AaQmHd7Jlh8UUA/4A/91ERK/eILvz3UG89n7uyzHcWCG 4oXRRY38WOidTDJsMujHfdbtnK5q+w4B/FrYYV/n6eOKU2/5PuiJHyIAmWJt6Uch e+6rSU0I21R+AQv2WGiXsq1QJRwZFOp33mYUMFeybUIKojlopowChCNKf2TGqGMw pDAGh2n1CuatPGMCkrLnSEr7i5FZafFZVNwzTZK573aYMjkRX3UuT+rbPbGpBBdA 9pjPj6nTOPZoXmN6wOFf1ph+L4o1awVxEt+pvvm/+8tQdeRXihrJT8c0NpAgFr4d FyclVOkSGTsxGLiCTqVUmCaB1ErVCq/5jMb34u+a0JyKMKKkYNEJn/bOTwBOrGP9 qJ/+7Rl8mDY= =blVT -----END PGP SIGNATURE-----