Format: 1.8 Date: Tue, 09 Jun 2020 08:16:51 -0400 Source: nfs-utils Binary: nfs-kernel-server nfs-common Architecture: i386 Version: 1:1.2.8-9ubuntu12.3 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: nfs-common - NFS support files common to client and server nfs-kernel-server - support for NFS kernel server Changes: nfs-utils (1:1.2.8-9ubuntu12.3) xenial-security; urgency=medium . * SECURITY UPDATE: privilege escalation via directory permissions - debian/patches/CVE-2019-3689.patch: take user-id from /var/lib/nfs/sm in support/nsm/file.c, utils/statd/sm-notify.man, utils/statd/statd.man. - debian/nfs-common.postinst: don't make /var/lib/nfs owned by statd. - CVE-2019-3689 Checksums-Sha1: 845dd9e25a76811d5bf7324025bd3f5ae03962cf 296498 nfs-common-dbgsym_1.2.8-9ubuntu12.3_i386.ddeb 239e38e65d4dbaf09a826ad6e6c01e3278d42117 191322 nfs-common_1.2.8-9ubuntu12.3_i386.deb 6d40b1642b770bfe56f0cf7d13f031f21c0c9436 157278 nfs-kernel-server-dbgsym_1.2.8-9ubuntu12.3_i386.ddeb ef9d857ee7399f8d008da4a51eecc4340735c93d 90994 nfs-kernel-server_1.2.8-9ubuntu12.3_i386.deb Checksums-Sha256: 043dff91b1587ba3f66256eadeb2f070020899e4daf82848c3a699c8c75fef6b 296498 nfs-common-dbgsym_1.2.8-9ubuntu12.3_i386.ddeb dfd4d2c3cf03acb0a995fa5efcec9d58d47e8c281c9b0cd7ae649aaa3017e2c5 191322 nfs-common_1.2.8-9ubuntu12.3_i386.deb 33527c3a7422d4f64fa49a3b14fa0884b3dcfdd15abc64aa762933f2a57be32d 157278 nfs-kernel-server-dbgsym_1.2.8-9ubuntu12.3_i386.ddeb c2823aba7ee489251aa44c9a5220eae51cb3f292699ea65f9a8fb9edec448db8 90994 nfs-kernel-server_1.2.8-9ubuntu12.3_i386.deb Files: ddfa24be835e2c4fe809fced3ab9133d 296498 net extra nfs-common-dbgsym_1.2.8-9ubuntu12.3_i386.ddeb 9223777a36fd92bce09bfe5d7804783d 191322 net standard nfs-common_1.2.8-9ubuntu12.3_i386.deb cde0344ea5c505ae849c9c0419a69b01 157278 net extra nfs-kernel-server-dbgsym_1.2.8-9ubuntu12.3_i386.ddeb a2b5231d5a2d9afba156431b6d68902e 90994 net optional nfs-kernel-server_1.2.8-9ubuntu12.3_i386.deb Original-Maintainer: Debian kernel team