[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 2882-1] sphinxsearch security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-2882-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                    Thorsten Alteholz
January 17, 2022                              https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : sphinxsearch
Version        : 2.2.11-1.1+deb9u1
CVE ID         : CVE-2020-29050


It was discovered that sphinxsearch, a fast standalone full-text SQL search engine, could allow arbitrary files to be read by abusing a configuration option.


For Debian 9 stretch, this problem has been fixed in version 2.2.11-1.1+deb9u1.

We recommend that you upgrade your sphinxsearch packages.

For the detailed security status of sphinxsearch please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/sphinxsearch

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmHkq/xfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7
WEfy0BAAiG06kpKtuwS3EcECZCmA2eLiE8d3cupKlbRL1Jvm/q0KV1t8sf2UhKBL
Y43/ciLzGignu8ozjhaDm0PsiTkocs/1JiTQeu1N6gY5WRiPMWZOW0naMTXLbTiT
MfZAo3Knm4pGPUDsUz6tOBf6EbXpBf6W0vYmF+CCc9BRsN3hZ+BYgdNyUkRGJYYV
/Wr6v3BgrdOmbz9bCNg7ONzNbG+7eRfy/L1e3Lqj05WJ8sV1CJ2ROAph/EteBGEd
4T7SJFQNJadpTyi3Gbb35JYOLAX0wKAJz7/tu3kggfIgV5BUzh91npS7oq8KrYep
VaEHfjGfFtUqpBALa9wv22r2SRnCTbJsPzCvHWOdjDHwcqqjqt3tcPHzoGkwXaaL
FR0JfRXeZLtjntHyDgbk8arIqIbQ5ZzFOqhW/gqh8KfErhg7zUqDUAU3FMH5BHkc
C1ELu1qjnCUAG8pPqDtAu8TxSqeYprzUOuV4hiAHOpV3IJA39kTlhlMnS2M5IgqY
Aq16m99sa47mbXe23y+S/vHiyZAL7CU9noafnPL91lU1bVj1BZeRLM7kNPGZLQgr
WLNCgEBmZKKvFe2MkMNKLShm36at5IymiYM/PQAfO3ToQy88DzVCt8nUw8PBAUlh
KQBEu9kkadAKf6AYZ9gVE/wav5nEyO6soOdXKuaSj/cIXWRdtJg=
=wWGl
-----END PGP SIGNATURE-----


Reply to: