-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Mon, 12 May 2025 09:03:43 +0200
Source: ironic
Architecture: source
Version: 1:29.0.0-6
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <
team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <
zigo@debian.org>
Closes: 1104964
Changes:
ironic (1:29.0.0-6) unstable; urgency=high
.
* CVE-2025-44021: Ironic fails to restrict paths used for file:// image URLs.
Add upstream patch: OSSA-2025-001_Disallow+unsafe_image_file_paths.patch.
(Closes: #1104964).
Checksums-Sha1:
b4a6cc3055f231ec9776bf3eff42928c5203668a 4064 ironic_29.0.0-6.dsc
15172b4f766d0fe8d915e4d26455aee962afee15 22412 ironic_29.0.0-6.debian.tar.xz
97cb81e5b74fdc120bbd1651387225e1027d0ce6 22303 ironic_29.0.0-6_amd64.buildinfo Checksums-Sha256:
717c17472686985536732c82c56a2847c98532187737904ba60254c84585ddc3 4064 ironic_29.0.0-6.dsc
331ee26a5ffc6fde97b2306688b77f00267e025081e9190ad389ce326db9f96e 22412 ironic_29.0.0-6.debian.tar.xz
270f3e0f286a0c1d4ab445e3ab0072d0779ee9031426321e6e354056a73476bf 22303 ironic_29.0.0-6_amd64.buildinfo
Files:
60765b2c869766bc5d73502a2db70716 4064 net optional ironic_29.0.0-6.dsc
2d9c97aba9f561bf643badd17154ccf5 22412 net optional ironic_29.0.0-6.debian.tar.xz
613b2119264266c0a33a9a86176a142d 22303 net optional ironic_29.0.0-6_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmghoeMACgkQ1BatFaxr Q/7yiw/+O54HxQlh2rZpaoVX0EQFGj6ZgVcADgnMC26pHP4rFGLt612dZVRXwJ6h OzeRi1XbJm0PwWNFxzyYbrwnDqZYv+JU4Xq/BL9wOy6RHcTuhdomjfbBcmBFUqSx rqc1zNtHpAJKkr00uI932VNt77Gda1pq9sVO2KsSqFxkBjglxTVEeE8UKzpGOGjs 04CBD15MQOQ914OuqW9etZqOpHFfqqhx26li6opszSsATAKIOIrjqV5rb70JPcxQ W9HLbm4Ho5APW0+XZBGKqFgIw1pp7nrQwrMLM3XmAfIFzdCRTiW/OlJnreZwongD 37BW3w3cILu7jI1ibzqDR4ZYIeyEIWmaimoo5NYKVm7mB5XzOoD6EKy24l5Dg8D6 N1u1QUsQQqhX1hYwNfxXuVTvXlMy/KzZDp+3erOltbJ0ftxZ5SLPcelysJOU5nWM os+x3O1Htf2dQyRM6lozTPPo31DbRlo+uALd1FJDk9MMLTTTw8Ex9eEdFtYexiQE MCxRFlkY4Ce4D1wl3TVnMyo+yCx7KAeqTlYHgW8/u+rLENq7q3tuBXRdUAR8XTvj KGySvmlq3SbEda7cF3rTQrSeGSANpyEwtgm3egF8lFnZfRyggoRAKKq7QlE5wNfg XX/CD6av7VKmUwRFq0tm8HlSN5N/n1xBAHzuoh3j9XCK3AyDdtI=
=KmKp
-----END PGP SIGNATURE-----
--==============W67662908092702683=Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCaCGn+gAKCRCb9qggYcy5 IYP7AQDeW01ao2Ya79lYoE9DIIbVqqHTb1Q9/r99ENb3KD2OAwEA4mfrQzBY14xr LS/VpY//4Ib6Te5JcRMOSwn5SxOxcA0=ttsb
-----END PGP SIGNATURE-----
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)