Format: 1.8 Date: Fri, 24 Nov 2017 12:55:21 -0500 Source: busybox Binary: busybox busybox-static busybox-initramfs busybox-udeb busybox-syslogd udhcpc udhcpd Architecture: s390x Version: 1:1.27.2-1ubuntu4 Distribution: bionic-proposed Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: busybox - Tiny utilities for small and embedded systems busybox-initramfs - Standalone shell setup for initramfs busybox-static - Standalone rescue shell with tons of builtin utilities busybox-syslogd - Provides syslogd and klogd using busybox busybox-udeb - Tiny utilities for the debian-installer (udeb) udhcpc - Provides the busybox DHCP client implementation udhcpd - Provides the busybox DHCP server implementation Changes: busybox (1:1.27.2-1ubuntu4) bionic; urgency=medium . * SECURITY UPDATE: directory traversal via tar symlink extraction - debian/patches/CVE-2011-5325-2.patch: do not extract unsafe symlinks unless env variable is set in archival/libarchive/Kbuild.src, archival/libarchive/data_extract_all.c, archival/libarchive/unsafe_symlink_target.c, archival/tar.c, coreutils/link.c, include/bb_archive.h, libbb/copy_file.c, testsuite/tar.tests. - CVE-2011-5325 * SECURITY UPDATE: integer overflow in get_next_block - debian/patches/CVE-2017-15873.patch: fix runCnt overflow in archival/libarchive/decompress_bunzip2.c. - CVE-2017-15873 * SECURITY UPDATE: integer underflow in unlzma - debian/patches/CVE-2017-15874.patch: add another check to archival/libarchive/decompress_unlzma.c. - CVE-2017-15874 * SECURITY UPDATE: code execution in tab autocomplete feature - debian/patches/CVE-2017-16544.patch: check for control characters in libbb/lineedit.c. - CVE-2017-16544 Checksums-Sha1: 4df4f645b132dac0272979ee8229e275e863473f 1462396 busybox-dbgsym_1.27.2-1ubuntu4_s390x.ddeb f49241ca44bcc4dded5bd20ea55f7ce02d0a7512 699700 busybox-initramfs-dbgsym_1.27.2-1ubuntu4_s390x.ddeb 1bee31256910162444e4ae744ba00479554777bb 167924 busybox-initramfs_1.27.2-1ubuntu4_s390x.deb dc7fc1e5892a5a066087ac089a7492ab9fc78c62 1638996 busybox-static-dbgsym_1.27.2-1ubuntu4_s390x.ddeb bcadb58ed1c5daf0543c1e35f7568428be16a89c 802940 busybox-static_1.27.2-1ubuntu4_s390x.deb 341a357ce0f5d4887f1be068caf2a3b463ae8be9 171244 busybox-udeb_1.27.2-1ubuntu4_s390x.udeb 22e44502e9edb9385523731ada1894ede6b75733 6895 busybox_1.27.2-1ubuntu4_s390x.buildinfo 2825480af80e6d4b4a01600e69f4003013869b4d 389580 busybox_1.27.2-1ubuntu4_s390x.deb dbaa3bf237103ba227d9d77460e6b250ac965c46 2944 udhcpc_1.27.2-1ubuntu4_s390x.deb 928b570500b8d223cbbfb7ee75a18a031781889d 5756 udhcpd_1.27.2-1ubuntu4_s390x.deb Checksums-Sha256: e499080b90e7a42e1a82ba00a4ddc0152965ba260c5a9dd869e25eb535743498 1462396 busybox-dbgsym_1.27.2-1ubuntu4_s390x.ddeb 26136d6599c742d623db3427af7c8d77885a97d31d7b4e8d3d872a4733c0bc61 699700 busybox-initramfs-dbgsym_1.27.2-1ubuntu4_s390x.ddeb b368470b2eea8c058b607a530290f45e71458e49c08fe34e52dcb97b30e529e6 167924 busybox-initramfs_1.27.2-1ubuntu4_s390x.deb 3fcd1b8a2866a29d904825e7c2847f43632e5aa4f5e6794462245f6d29b6ae4c 1638996 busybox-static-dbgsym_1.27.2-1ubuntu4_s390x.ddeb 62ed079b97c4f9ba80c550da32a8d6f59730dc2fdcad0a110c091b2fbf06e74e 802940 busybox-static_1.27.2-1ubuntu4_s390x.deb 433cf3eae868dae37e7dde728fda269e5910f1630c427017728f19c1462cf7a4 171244 busybox-udeb_1.27.2-1ubuntu4_s390x.udeb e9bb9e755fd00a0917c316b71ac5348fb8afe8594bb88907767b80d50a60ffc6 6895 busybox_1.27.2-1ubuntu4_s390x.buildinfo 461a0f2a7eb1a44f6e3ac943c088f62febef405a8990054ec049764b4fa4bb05 389580 busybox_1.27.2-1ubuntu4_s390x.deb ff5708302ad2ceb860f2f9b3829231d0e468d28eed397fca0db22d4744c0af1b 2944 udhcpc_1.27.2-1ubuntu4_s390x.deb 00d467f1c29217ecb4c169f6841e2f438cbe18383ac4baa5a036fe2ba6115d04 5756 udhcpd_1.27.2-1ubuntu4_s390x.deb Files: 7a2038bf83d3a1f2c88f5808aba8f4a4 1462396 debug optional busybox-dbgsym_1.27.2-1ubuntu4_s390x.ddeb 19f1e9d19df3012d29e7250f601607a7 699700 debug optional busybox-initramfs-dbgsym_1.27.2-1ubuntu4_s390x.ddeb 6973aca9c55ce7d26a68dd13ac6bbf30 167924 shells optional busybox-initramfs_1.27.2-1ubuntu4_s390x.deb f877adc8e92925752968a8f120428ce5 1638996 debug optional busybox-static-dbgsym_1.27.2-1ubuntu4_s390x.ddeb c3060e1b3f2b82ff96ccb03534974eb1 802940 shells extra busybox-static_1.27.2-1ubuntu4_s390x.deb 311dd6d9c5b309be5209c6300e1b5fab 171244 debian-installer extra busybox-udeb_1.27.2-1ubuntu4_s390x.udeb 869aaf7b06b850a93b6dbed1008a1b5a 6895 utils optional busybox_1.27.2-1ubuntu4_s390x.buildinfo e50574dcf1cb6a0d8e518e06b6f27b5d 389580 utils optional busybox_1.27.2-1ubuntu4_s390x.deb 74fb1bb197cea637044bebbe135b976b 2944 net optional udhcpc_1.27.2-1ubuntu4_s390x.deb f375b4f2d22ab3f671df7ad5deafa901 5756 net optional udhcpd_1.27.2-1ubuntu4_s390x.deb Original-Maintainer: Debian Install System Team