Format: 1.8 Date: Fri, 06 Aug 2021 12:08:41 +0930 Source: mongodb Binary: mongodb mongodb-server mongodb-server-core mongodb-clients Architecture: s390x Version: 1:3.6.3-0ubuntu1.3 Distribution: bionic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Alex Murray Description: mongodb - object/document-oriented database (metapackage) mongodb-clients - object/document-oriented database (client apps) mongodb-server - object/document-oriented database (managed server package) mongodb-server-core - object/document-oriented database (server binaries package) Launchpad-Bugs-Fixed: 1934518 Changes: mongodb (1:3.6.3-0ubuntu1.3) bionic-security; urgency=medium . [Heather Lemon] * SECURITY UPDATE: account session reuse leads to unauthorized access (LP: #1934518) - d/p/CVE-2019-2386-SERVER-38984-Validate-unique-User-ID-on-UserCache-hi.patch: Attach ID to users. After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts - CVE-2019-2386 . [Alex Murray] * Refresh d/p/CVE-2019-2386-SERVER-38984-Validate-unique-User-ID-on-UserCache-hi.patch with the version from the 3.4 upstream branch that is still licensed under the AGPL. Checksums-Sha1: d12a2a53697f43066e708ae74d9757827216c983 466969900 mongodb-clients-dbgsym_3.6.3-0ubuntu1.3_s390x.ddeb c3d58e1711d15d19191189e060b9443e7ccabaa4 18031640 mongodb-clients_3.6.3-0ubuntu1.3_s390x.deb b04d2d9ec77009c70267821e0aa5aa64b197bf7e 523807452 mongodb-server-core-dbgsym_3.6.3-0ubuntu1.3_s390x.ddeb 890e05476418cd31173a647abb5db5ef0489b981 18496224 mongodb-server-core_3.6.3-0ubuntu1.3_s390x.deb 9d4c3d75a0b30d3d0b8fd2f437552ae946486559 10737 mongodb_3.6.3-0ubuntu1.3_s390x.buildinfo a892da5ec978a1564a0d5b34e682d49648f50c35 10252 mongodb_3.6.3-0ubuntu1.3_s390x.deb Checksums-Sha256: e635ef67613fcd2e1f2bbfc3349d34b515d3662527a121ec9578369e50ad34b4 466969900 mongodb-clients-dbgsym_3.6.3-0ubuntu1.3_s390x.ddeb fb8996c7a3f58593028702132fb15eafe4ea826422f83c8259f218181ba463d6 18031640 mongodb-clients_3.6.3-0ubuntu1.3_s390x.deb 5c979fe67b6c55486cc40667795dd8cd504f31e9e59c5329805787111bba1cf4 523807452 mongodb-server-core-dbgsym_3.6.3-0ubuntu1.3_s390x.ddeb 3e163a1f668ccc79de369fc04d4d5d39b9e9ce778b63db4df2252801ac4382fc 18496224 mongodb-server-core_3.6.3-0ubuntu1.3_s390x.deb b3a5e0b9996986de676d4fc5d4432f386e41d9117defead3e03f68ab0add3018 10737 mongodb_3.6.3-0ubuntu1.3_s390x.buildinfo ee8b53a8a9d0d577422064a3a61790fc518093ac32dfc1c5ce55e0e5a0a3c1c7 10252 mongodb_3.6.3-0ubuntu1.3_s390x.deb Files: 1fcc97dd66d350db50c1592cc120aea3 466969900 debug optional mongodb-clients-dbgsym_3.6.3-0ubuntu1.3_s390x.ddeb 55a83d11bda8f3da10777491dc534e95 18031640 database optional mongodb-clients_3.6.3-0ubuntu1.3_s390x.deb e187b66bcb7a4d1f2ac2ea51e7ec74de 523807452 debug optional mongodb-server-core-dbgsym_3.6.3-0ubuntu1.3_s390x.ddeb 593dac3c21bd3f39246d3b8186526c8f 18496224 database optional mongodb-server-core_3.6.3-0ubuntu1.3_s390x.deb 8728ea0aa623ac1b07da2da20051e6fd 10737 database optional mongodb_3.6.3-0ubuntu1.3_s390x.buildinfo f248a6b09fad805239a02b186eb85d66 10252 database optional mongodb_3.6.3-0ubuntu1.3_s390x.deb Original-Maintainer: Debian MongoDB Maintainers