-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2019.1871
                  [DLA 1801-1] zookeeper security update
                                27 May 2019

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           zookeeper
Publisher:         Debian
Operating System:  Debian GNU/Linux 8
                   UNIX variants (UNIX, Linux, OSX)
Impact/Access:     Access Confidential Data -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2019-0201  

Original Bulletin: 
   https://lists.debian.org/debian-lts-announce/2019/05/msg00033.html

Comment: This advisory references vulnerabilities in products which run on 
         platforms other than Debian. It is recommended that administrators 
         running zookeeper check for an updated version of the software for 
         their operating system.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : zookeeper
Version        : 3.4.9-3+deb8u2
CVE ID         : CVE-2019-0201
Debian Bug     : #929283

It was discovered that there was an information disclosure
vulnerability in zookeeper, a distributed co-ordination server.
Users who were not authorised to read data were able to view the
access control list.

For Debian 8 "Jessie", this issue has been fixed in zookeeper version
3.4.9-3+deb8u2.

We recommend that you upgrade your zookeeper packages.


Regards,

- - -- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-

- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAlznpesACgkQHpU+J9Qx
HljDZBAAnkcvRRXeoKBIwobVEv75OPEb42ucpzi57nZiBMRvKlqgv35UBGYTusQ0
THTNVZnUICKBGqMi3NIVUzBHRU/zSS6pIJ+SKfHvdZR9bBoLownx6iVxUAuzL7lw
tKaJVW5S/1OzzWbRk6yH1jB2MXVyCR5srSANKMsmEpDH9tZMuDgmiHVIOo/pkto4
SvrTM/ekLXXYYqS/kKHgO55PYpg3LtUAJscXX3M26he9PnCDNpOJRR5GREvTz3cw
Ne5tWVAqkOCrZCRFZ+zoOHV89wI/CKissptNa276GWH0c+kLQxYqmJnxzSAlYhnS
v1sgc/4aDjv27h3NXzU+YMIDWmOWQzVtbjKw46HJbMpIacIHob6zWgBWLbBs4Ty/
uwLR7+MKY3NPODeWTasrbIaQsxVU9UhPnJ5K13+ldfUSqsooBK0gUYhs+zUXiWIk
8fQGQzJzHeVoXc6+MB89LfGjSMOArMnS+77DcVkI7tuPfmgXr7r9t8FFetjzHfkV
/P+PPW17auWKGzRF0viCEcI5AJMlPWviWdQl8vG1NBnvWFhO/fJ6dkG3xaC8XZ6z
e3TNMRlzqNlZvZpznu/FGbH95/wn7MEiDJvR0PsMTQFEK71EkwnmmupQNw1FutUF
WPtG/sNknIpSYBkdBmYLVtM5M4ciiqLRtWnDOzw4IfwD0dh3HeU=
=2iUZ
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXOspnWaOgq3Tt24GAQhjaA//YUhGWmlBRA59ZjVXlRfUlqQUN5t233fy
OTXFxH09yJtzkMX7Z9e+sW2JTpspjGKy3va6k11JsYHcbRUFUdIvqg4/Fgl8Q/IF
G+hEl5d4XlUrY6/btXVeqnTBadEHzA5OWZbw3xpLRGm9V2OyRnvkci5dML2x1tS1
PnkT48UIpMR0grEatVNOQFxL2vNXr2hdkITmAm8buW8rfMNFkFsJniEzqVLo4dFZ
TOhVw5L2u7yA370femA6TaliMvzNiBN8JfIUpDCLUjgBghDOryjLfRQs60MyMbpQ
x9j/kLNe/vd3y5bS+xFOjPlUR0IUfOnB5BghyrWB/kDyKm/ynLLElbyEGx+4RhZo
Buw5cYFh+u7vf1FIcWnSofkB1eII1tOONjdNsNuZckxjHfzxF/U8xMelSGtocDSk
MHkC+BuO0KUqsPHuTYMvhJtcYziUro5oTHLe0Uy2JD1ywIViv6BHuiK3fMwNMKaA
5ajNlT27ksrNsVIql24B1cGcG9LTMv8ZMRCECiIf22lv36ggARfWIbskvhD5nvaP
2b+wD1GKd1lbkOWjKthNgO598lG2sLyzw4hOafwfMU8fbEOBLcFZ6IMlHQWbkdnu
DiKdzHxoaCJUoC+8bhloRzK4BOnh1ABd0ZbZJm3crKqQs+VwiTpl1gccJMw69v1x
r56nJc2GdGg=
=jowY
-----END PGP SIGNATURE-----