Format: 1.8 Date: Fri, 06 Aug 2021 12:08:41 +0930 Source: mongodb Binary: mongodb mongodb-server mongodb-server-core mongodb-clients Architecture: ppc64el Version: 1:3.6.3-0ubuntu1.3 Distribution: bionic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Alex Murray Description: mongodb - object/document-oriented database (metapackage) mongodb-clients - object/document-oriented database (client apps) mongodb-server - object/document-oriented database (managed server package) mongodb-server-core - object/document-oriented database (server binaries package) Launchpad-Bugs-Fixed: 1934518 Changes: mongodb (1:3.6.3-0ubuntu1.3) bionic-security; urgency=medium . [Heather Lemon] * SECURITY UPDATE: account session reuse leads to unauthorized access (LP: #1934518) - d/p/CVE-2019-2386-SERVER-38984-Validate-unique-User-ID-on-UserCache-hi.patch: Attach ID to users. After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts - CVE-2019-2386 . [Alex Murray] * Refresh d/p/CVE-2019-2386-SERVER-38984-Validate-unique-User-ID-on-UserCache-hi.patch with the version from the 3.4 upstream branch that is still licensed under the AGPL. Checksums-Sha1: a2c009a58f37fca95e5edf67665a0a60a2eefb4a 447013816 mongodb-clients-dbgsym_3.6.3-0ubuntu1.3_ppc64el.ddeb c3b7bbbbbb03401dd5d9fcb7ce56b791441cac9a 20438600 mongodb-clients_3.6.3-0ubuntu1.3_ppc64el.deb 5ec391c7f7ec5f83e2edf35c90dec05946eab722 500946852 mongodb-server-core-dbgsym_3.6.3-0ubuntu1.3_ppc64el.ddeb 60376a685c2884e23fe2827b093221c361148aac 20245756 mongodb-server-core_3.6.3-0ubuntu1.3_ppc64el.deb 5bab8023e1bf66e749f4c0843ebb0574d2fea6fa 10978 mongodb_3.6.3-0ubuntu1.3_ppc64el.buildinfo e1eb0035538d4e9aaf3a900a48b69fc00b5f1899 10256 mongodb_3.6.3-0ubuntu1.3_ppc64el.deb Checksums-Sha256: 048ec770feccc6aad19173a4d82c6db57f83d495142ced254c64ffd4c4a1b1f4 447013816 mongodb-clients-dbgsym_3.6.3-0ubuntu1.3_ppc64el.ddeb 4b742c7a765aa7d4d10fee1ca6f85e9bffd8301fb5154aada2d3d4f03eb609c6 20438600 mongodb-clients_3.6.3-0ubuntu1.3_ppc64el.deb d3adedc650ddf6c628eac34823d99a61955ee1dc9ad439bca5e9d9ab5ce6a918 500946852 mongodb-server-core-dbgsym_3.6.3-0ubuntu1.3_ppc64el.ddeb 09a7385dc7131b959e253c4c5fe72a5b607aabad9a6fedcf89d8bad5a7af5b73 20245756 mongodb-server-core_3.6.3-0ubuntu1.3_ppc64el.deb e409417041038e9fdb1cf2ebe0925e33be2c60562f50af8942538b04d468b349 10978 mongodb_3.6.3-0ubuntu1.3_ppc64el.buildinfo 5ec157bebdf19727a7a69449ebaf890aea62583e934712fcd4ee03b39038ff4e 10256 mongodb_3.6.3-0ubuntu1.3_ppc64el.deb Files: c97b28fa3d871e20bb182647cc77826c 447013816 debug optional mongodb-clients-dbgsym_3.6.3-0ubuntu1.3_ppc64el.ddeb 888e2a78a3d9a8d1a28c2d1f4e6054c6 20438600 database optional mongodb-clients_3.6.3-0ubuntu1.3_ppc64el.deb bf7fa778821ceb3e390773df8dce695f 500946852 debug optional mongodb-server-core-dbgsym_3.6.3-0ubuntu1.3_ppc64el.ddeb a0f70d3aadf58d611419d18322ebc2ce 20245756 database optional mongodb-server-core_3.6.3-0ubuntu1.3_ppc64el.deb 73e73cfa41b9bf30c4ffa8d04a4b8638 10978 database optional mongodb_3.6.3-0ubuntu1.3_ppc64el.buildinfo 89ef70df5560dcd610ae2cfc7d9723e8 10256 database optional mongodb_3.6.3-0ubuntu1.3_ppc64el.deb Original-Maintainer: Debian MongoDB Maintainers