-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 11 Aug 2025 17:13:52 +0200 Source: aide Binary: aide aide-dbgsym Architecture: amd64 Version: 0.18.3-1+deb12u4 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Hannes von Haugwitz Description: aide - Advanced Intrusion Detection Environment - dynamic binary Changes: aide (0.18.3-1+deb12u4) bookworm-security; urgency=high . * Apply upstream patch to escape control characters in report and log output (CVE-2025-54389) * also apply upstream patch to fix double free during report generation, which is required for the security patch * Apply upstream patch to fix null pointer dereference after reading incorrectly encoded xattr attributes from database (CVE-2025-54409) Checksums-Sha1: f2e683c4caecd2f740e36a84e3740fc0577b2214 192640 aide-dbgsym_0.18.3-1+deb12u4_amd64.deb 13a36d5f8440bf21afb734b1e8bf7683658c7ef3 7024 aide_0.18.3-1+deb12u4_amd64-buildd.buildinfo ad7b37803d804f3ce8b19d8f62d0cd326d62b137 134168 aide_0.18.3-1+deb12u4_amd64.deb Checksums-Sha256: 534972b783609373f66ff3c7a175d7a352a3409ea4ccb3ba812436716a9174bc 192640 aide-dbgsym_0.18.3-1+deb12u4_amd64.deb bd73fd8427a018feafd64aa65e38e23f54674a9d9e0cffbd0c9d6d04882b07d6 7024 aide_0.18.3-1+deb12u4_amd64-buildd.buildinfo 792ac1d050075b26e700c8d24c3ca665366b9e78cf89d547c37f5edbe7a711c2 134168 aide_0.18.3-1+deb12u4_amd64.deb Files: 22c493ceb86f987c53e5a816e7409325 192640 debug optional aide-dbgsym_0.18.3-1+deb12u4_amd64.deb 368ad219e3671a1d52fda604b2a35958 7024 admin optional aide_0.18.3-1+deb12u4_amd64-buildd.buildinfo b2d15075a61366921945968beb8b29d1 134168 admin optional aide_0.18.3-1+deb12u4_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXNeYFUF3FbHcrtSeIy3Pg040HrAFAmiaVfsACgkQIy3Pg040 HrDHPhAAmRqL8s2tN7ZeK6qH1yrKSAMVppl+NKaXi0FLZMJDjb0SUszKjrwWHVAK TxnNEt6PYTF731dNwmvxJgNCSTe4qO3kg9Pl7ysYt5406Veu7zNt5XwOIDFaNh2+ q5BRQUVxjQVpQuLYvBeqcXYtGh1VprXANraZnPcriE/jSgqysxGZhJx+QLBbCBb9 ws0Wzqld621s2DaPfATwVnMvA6xUXyuFA69Ew/08RVXA3qBMhfoB65+Kw979yUOr ff2pBsNmnUssyg7+Jq7xFNlLIYEtDvZPc1GY0yhkOR/kb6UBZ31GficDOKAUbv0X ymOyS+dmPM6PuapZAHNSR9ikCS7pTCcR+thjnTbuTuZorkYkO2vYhdPnx6V6aoQl q/zMUpytfEP9dDYJXnhB6UIOwe3FExztpy+1ddl3fb8J9dmRDOpbQ6q+umDIH/bD GpcaiYsIUeHghAZdGUoFL5vBqNXtBIx9jkACImwpZwjcENnmrHFFRQUe0mofPtKS ANKLt/nE7bCpmAmAGM+lOhia0obZfUHmdxvvYPbqntysl4oXunz041JarMtehnoO 964wMvxX2tBqxKtEm9ZGpe8/CWxx+1gOCaOUwk1ngn2zFYuwm6259/vsErmLGb0k NdJ2V2BobWJ/Apta6tWN6FAi/8xd14kVjdX6snN7Exoo0RnO+JM= =aLCD -----END PGP SIGNATURE-----