-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4938-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 13, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : linuxptp CVE ID : CVE-2021-3570 Debian Bug : 990748 Miroslav Lichvar reported that the ptp4l program in linuxptp, an implementation of the Precision Time Protocol (PTP), does not validate the messageLength field of incoming messages, allowing a remote attacker to cause a denial of service, information leak, or potentially remote code execution. For the stable distribution (buster), this problem has been fixed in version 1.9.2-1+deb10u1. We recommend that you upgrade your linuxptp packages. For the detailed security status of linuxptp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/linuxptp Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmDt8ypfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0SGSg//ZAp+F3pt6rG0gSxl1xBJSQhsBoGfS0c+W6Fn6arlh0TvUDPh7JF8BHQ1 XpRgar3KduoOVsGsZWEN8vzEMBFhzpVmuvJzvD68vul8TMcS3L14kNHjaU54zHaV wHYr4UOXf7EuC/B43np3VGUbGxYYzI9ip+o3keolehoBZuN+oY3Hp+OmSUueX5lT vANPjQWNu8saJYVvAF7Nf3zjVkfpju0i8cI9SiuavWBwAwvdX16iSqcG3DVSWbSJ jAAWGBMi9aQt8JQUS/3kbsfHxKj3uZMQSNj7Ei/cMH8r3Qt/qJOIvDQtZ1cJwQ26 /xYcdEzq4ThHGOog+SGXWOzcfsURR+S9dIan9owQwf+9ikVbIi79t59jxsA76GHW BFUD/j/EI02JjmjXjbtj44wbSNkdzuiyJkWhTn154RJFa5OrJk3/7GVCMpzRDSZX 2TTEy5x8Uy55JOF9g0mjAezvohrDAz3VUNXWdErAeGHk61IwmGsa3jtpxhGLeGY0 73SB6NwcOccJ5OfAR/CxUn+TfaV+Gacq950tSVXfj5qlp8iY6ppHBAiRWgRQ+2i3 dLAt3kBdDxti7yydylS/SQTKrLfRnTbA6uPFkHhXPDPWmRVyl7HhoMoBkdQxTjBZ j43aERAw23XYTYuDdgUb3dAcrlnFOAGTC9H8SjljuHARAuG0GOA= =7/xl -----END PGP SIGNATURE-----