Format: 1.8 Date: Mon, 02 Nov 2020 12:02:46 -0500 Source: accountsservice Architecture: source Version: 0.6.55-0ubuntu13.2 Distribution: groovy-security Urgency: medium Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Launchpad-Bugs-Fixed: 1900255 Changes: accountsservice (0.6.55-0ubuntu13.2) groovy-security; urgency=medium . * SECURITY UPDATE: accountsservice drop privileges SIGSTOP DoS (LP: #1900255) - debian/patches/0010-set-language.patch: updated to not drop real uid and real gid in user_drop_privileges_to_user. - debian/patches/0009-language-tools.patch: updated to not reset effective uid. - CVE-2020-16126 * SECURITY UPDATE: accountsservice .pam_environment infinite loop (LP: #1900255) - debian/patches/0010-set-language.patch: updated to use O_NOFOLLOW and limit the number of lines read from file. - CVE-2020-16127 Checksums-Sha1: 8ae7d402b3f30dc5f68fcdd28fb8b2401d4ddb87 2821 accountsservice_0.6.55-0ubuntu13.2.dsc 00b187f0747fa9815bf3869d01f4da669480de9f 29776 accountsservice_0.6.55-0ubuntu13.2.debian.tar.xz 4a8061451277dfc828aff651525b35a370d01418 10321 accountsservice_0.6.55-0ubuntu13.2_source.buildinfo Checksums-Sha256: 85f25b8c00c7a9acd73951df70d2a8aadb5c2dea46ed147160a1d214995299d6 2821 accountsservice_0.6.55-0ubuntu13.2.dsc 81000d1e4fb41e8d4bb3cd8c78f8ef852392df7817ad4e3ff3baa1095535c632 29776 accountsservice_0.6.55-0ubuntu13.2.debian.tar.xz 8b35a21a6f593d3af52af0301f73b3e6c9469f8ad122d057b8fdbc27d43a0f46 10321 accountsservice_0.6.55-0ubuntu13.2_source.buildinfo Files: 12c20ac9ad8edbb221e7d4a316cd12f1 2821 admin optional accountsservice_0.6.55-0ubuntu13.2.dsc 63a90d915e0e14e9c54272f0ad11279a 29776 admin optional accountsservice_0.6.55-0ubuntu13.2.debian.tar.xz 4ffdcd8c5276400b535b25014908fe8a 10321 admin optional accountsservice_0.6.55-0ubuntu13.2_source.buildinfo Original-Maintainer: Debian freedesktop.org maintainers