[ubuntu/hirsute-proposed] ceph 16.2.4-0ubuntu0.21.04.1 (Accepted)

James Page james.page at ubuntu.com
Tue Jun 1 22:11:01 UTC 2021


ceph (16.2.4-0ubuntu0.21.04.1) hirsute; urgency=medium

  [ Chris MacNaughton ]
  * d/ceph-base.install: Remove ceph-deploy man page installation
    (LP: #1892448).

  [ James Page ]
  * SECURITY UPDATE: New upstream release (LP: #1928645):
    - CVE-2021-3509: Dashboard XSS via token cookie.
    - CVE-2021-3531: Swift API denial of service.
    - CVE-2021-3531: HTTP header injects via CORS in RGW.
    - d/p/bug1925347.patch: Drop, included in release.

Date: Thu, 27 May 2021 06:18:16 +0100
Changed-By: James Page <james.page at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/ceph/16.2.4-0ubuntu0.21.04.1
-------------- next part --------------
Format: 1.8
Date: Thu, 27 May 2021 06:18:16 +0100
Source: ceph
Built-For-Profiles: noudeb
Architecture: source
Version: 16.2.4-0ubuntu0.21.04.1
Distribution: hirsute
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: James Page <james.page at ubuntu.com>
Launchpad-Bugs-Fixed: 1892448 1928645
Changes:
 ceph (16.2.4-0ubuntu0.21.04.1) hirsute; urgency=medium
 .
   [ Chris MacNaughton ]
   * d/ceph-base.install: Remove ceph-deploy man page installation
     (LP: #1892448).
 .
   [ James Page ]
   * SECURITY UPDATE: New upstream release (LP: #1928645):
     - CVE-2021-3509: Dashboard XSS via token cookie.
     - CVE-2021-3531: Swift API denial of service.
     - CVE-2021-3531: HTTP header injects via CORS in RGW.
     - d/p/bug1925347.patch: Drop, included in release.
Checksums-Sha1:
 141f627206e9a6ed60bc092d20e74779a9f95edc 9529 ceph_16.2.4-0ubuntu0.21.04.1.dsc
 2d95d45df20c963c77f2c71bde43ebd891a9b5ee 104037804 ceph_16.2.4.orig.tar.xz
 031b6669c2714c4252e1d00bf80af3fb021369b9 117852 ceph_16.2.4-0ubuntu0.21.04.1.debian.tar.xz
 1014e337ada882915d106a5988288de348e05621 17155 ceph_16.2.4-0ubuntu0.21.04.1_source.buildinfo
Checksums-Sha256:
 f2169589b70f672c463dc60adeb2f50e260a1bfd165f72dd67558cc1f0b03ed8 9529 ceph_16.2.4-0ubuntu0.21.04.1.dsc
 52cba46896d57febb1697297a573e9e1f79bdb6d07c78ac04ee77e164410fd59 104037804 ceph_16.2.4.orig.tar.xz
 3b7cbd2fb4cc4a70d286bec7232343d891a63bc563380ffdaead047273661d7f 117852 ceph_16.2.4-0ubuntu0.21.04.1.debian.tar.xz
 c92353fee99657c93876785c30861ca11e17aa625d9d30b81ca62b85b05d89d9 17155 ceph_16.2.4-0ubuntu0.21.04.1_source.buildinfo
Files:
 b01160f5f68f1bfc690f82543890da6b 9529 admin optional ceph_16.2.4-0ubuntu0.21.04.1.dsc
 b1428106c5391c7c1ffa5db5bc3c71da 104037804 admin optional ceph_16.2.4.orig.tar.xz
 f9afaaf0a52464700e998990ce1ca525 117852 admin optional ceph_16.2.4-0ubuntu0.21.04.1.debian.tar.xz
 b96f5bae244ff5656842cd5643cb4dbf 17155 admin optional ceph_16.2.4-0ubuntu0.21.04.1_source.buildinfo
Original-Maintainer: Ceph Packaging Team <team+ceph at tracker.debian.org>


More information about the Hirsute-changes mailing list