Linux Today: Linux News On Internet Time.
Search Linux Today
search.internet.com
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Become a Marketplace Partner

internet.commerce
Be a Commerce Partner














The Linux Channel at internet.com
Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Subscribe News
Subscribe PR
Subscribe Security

internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

 







Current Newswire:

Dell Ubuntu Order Experience

Power Up Linux GUI Apps

Ksplice debuts zero downtime service for Linux

BM Ups Its Processor Power to 7

KDE.org Relaunched for Software Compilation 4.4

The application is the new the operating system

Linux can compete with the iPad on price, but where’s the magic?

The Bruno Knaapen Technology Learning Center is Established

Anjal: GNOME's Evolution for Netbooks

Linux Mint 8 KDE Community Edition




UNIX Systems Administrator (IL)
Next Step Systems
US-IL-Chicago

Justtechjobs.com Post A Job | Post A Resume
:Advisories, June 4, 2006:
Advisories, June 4, 2006:
Jun 5, 2006, 05 :30 UTC (0 Talkback[s]) (2265 reads)


Debian Security Advisory DSA 1086-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
June 2nd, 2006 http://www.debian.org/security/faq


Package : xmcd
Vulnerability : design flaw
Problem type : local
Debian-specific: no
CVE ID : CVE-2006-2542
Debian Bug : 366816

The xmcdconfig creates directories world-writeable allowing local users to fill the /usr and /var partition and hence cause a denial of service. This problem has been half-fixed since version 2.3-1.

For the old stable distribution (woody) this problem has been fixed in version 2.6-14woody1.

For the stable distribution (sarge) this problem has been fixed in version 2.6-17sarge1.

For the unstable distribution (sid) this problem has been fixed in version 2.6-18.

We recommend that you upgrade your xmcd package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given at the end of this advisory:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody


Source archives:

    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-14woody1.dsc
      Size/MD5 checksum: 619 42038224877b80e57969e82e14a6ee5a
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-14woody1.diff.gz
      Size/MD5 checksum: 19169 3144b9f7dc78b1a0a668eff06ded3b08
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6.orig.tar.gz
      Size/MD5 checksum: 553934 ce3208e21d8e37059e44ce9310d08f5f

Alpha architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-14woody1_alpha.deb
      Size/MD5 checksum: 65648 d4beba33b15cdef57c315666e9dbeaf3
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-14woody1_alpha.deb
      Size/MD5 checksum: 458520 da2013cefff5009ed770397ea7cf23fe

ARM architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-14woody1_arm.deb
      Size/MD5 checksum: 60464 2a9f06c9a2f888ea56ac62bdfe2eb05e
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-14woody1_arm.deb
      Size/MD5 checksum: 378038 932f832766a947aac29d9b40f2f8a026

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-14woody1_i386.deb
      Size/MD5 checksum: 58970 506435aef6b9a12c0715e73dea67eefd
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-14woody1_i386.deb
      Size/MD5 checksum: 324960 2eba0f70812dada62ec2fb3f3b054318

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-14woody1_ia64.deb
      Size/MD5 checksum: 66140 6d3eff9fdf1d9c6052c9554bc4dd584a
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-14woody1_ia64.deb
      Size/MD5 checksum: 543700 dce5ff73c754b4425fe642117a52f5fa

HP Precision architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-14woody1_hppa.deb
      Size/MD5 checksum: 60954 f48d59a10a2891bdb1842da42fe0b0f4
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-14woody1_hppa.deb
      Size/MD5 checksum: 406294 2b12245768fce9c5f57cc4a8818ea1be

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-14woody1_m68k.deb
      Size/MD5 checksum: 58890 ce57236e978ed6310d23cf1cfede3224
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-14woody1_m68k.deb
      Size/MD5 checksum: 309832 0de1924af1c4981505849da8e6b8c7af

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-14woody1_mips.deb
      Size/MD5 checksum: 61476 8a4dcea7adbfb4a1c3294a2622e05d15
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-14woody1_mips.deb
      Size/MD5 checksum: 377170 91d622c19970fe0dcda24f63e85c7350

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-14woody1_mipsel.deb
      Size/MD5 checksum: 61436 27eaa3e4c2365f2e4b49c526acc3df00
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-14woody1_mipsel.deb
      Size/MD5 checksum: 378122 c9b63596911f83c72a4c9b7fbd01abf0

PowerPC architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-14woody1_powerpc.deb
      Size/MD5 checksum: 60998 74e9b62e02f69db4dfedab57100904dd
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-14woody1_powerpc.deb
      Size/MD5 checksum: 364402 28547836494d0142a84c2bf58888c6bf

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-14woody1_s390.deb
      Size/MD5 checksum: 59818 8d3d1ca6ff1fd1ceb32c42b73d4fe3bb
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-14woody1_s390.deb
      Size/MD5 checksum: 347966 dd3cc13ee026156516f315b77cb1f06b

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-14woody1_sparc.deb
      Size/MD5 checksum: 62724 597ddc3fe6e1c56a3ecb78e2b46c7fd4
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-14woody1_sparc.deb
      Size/MD5 checksum: 361214 e93e33fe714c4b5429eb7a2bce8ba0ea

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-17sarge1.dsc
      Size/MD5 checksum: 619 25a530a0383c4ab2cbc2d23a6c95d5f2
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-17sarge1.diff.gz
      Size/MD5 checksum: 20482 d9ce89eebe6f068df0c1d49eacc0bb4b
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6.orig.tar.gz
      Size/MD5 checksum: 553934 ce3208e21d8e37059e44ce9310d08f5f

Alpha architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-17sarge1_alpha.deb
      Size/MD5 checksum: 62480 d99e5ad3da64edbfbc6a9e5c610683e1
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-17sarge1_alpha.deb
      Size/MD5 checksum: 452252 19bf881ff9a11a1d398d97ef2158f07c

AMD64 architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-17sarge1_amd64.deb
      Size/MD5 checksum: 60974 d14a6718ad2f95983d0af699aa585df2
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-17sarge1_amd64.deb
      Size/MD5 checksum: 375978 1064343cbef2794c637ce6431935280b

ARM architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-17sarge1_arm.deb
      Size/MD5 checksum: 60052 870eb636eb62c6b3d5fc310d82e9ae2c
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-17sarge1_arm.deb
      Size/MD5 checksum: 363752 cf23e90fa86d845a66c297a12de2c887

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-17sarge1_i386.deb
      Size/MD5 checksum: 59976 95f0064a7b485df46d6275e3ba98b28e
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-17sarge1_i386.deb
      Size/MD5 checksum: 347032 2e5dfd037ca6a7d7e7ef77fa5b3cdd6a

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-17sarge1_ia64.deb
      Size/MD5 checksum: 64146 9cf8c9c4c9aa5a6bf8da06ff9079e4df
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-17sarge1_ia64.deb
      Size/MD5 checksum: 521072 6759905bab7f05d9cba71fa19b7b971d

HP Precision architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-17sarge1_hppa.deb
      Size/MD5 checksum: 61618 578d619050afd48ba63fbb103a443673
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-17sarge1_hppa.deb
      Size/MD5 checksum: 399428 b7c61aa93ff2efd42cb4375940b675df

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-17sarge1_m68k.deb
      Size/MD5 checksum: 59428 a95f8b6d48635de344faf79d8dce01f5
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-17sarge1_m68k.deb
      Size/MD5 checksum: 311534 313f9f8e4db059b0c58bc37ef61fe6cd

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-17sarge1_mips.deb
      Size/MD5 checksum: 61656 35c929f75f4ab0989ab7fe94afe08a3d
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-17sarge1_mips.deb
      Size/MD5 checksum: 379520 57b63417bfb1d07afb79767268e56022

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-17sarge1_mipsel.deb
      Size/MD5 checksum: 61688 63b48f033d11adeb78d933e36ad0a904
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-17sarge1_mipsel.deb
      Size/MD5 checksum: 381286 0e05464ae0243e4c6abfa50d21bf032c

PowerPC architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-17sarge1_powerpc.deb
      Size/MD5 checksum: 60740 5bfc0950afeb05321af3623f90b015e4
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-17sarge1_powerpc.deb
      Size/MD5 checksum: 372902 e1706bbfe5c2e920465f339824c3639a

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-17sarge1_s390.deb
      Size/MD5 checksum: 60742 95dcd70b6713309c6f0d57017b024ed7
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-17sarge1_s390.deb
      Size/MD5 checksum: 364676 0e28c9bf8c98276469af3b7a906f9c39

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/x/xmcd/cddb_2.6-17sarge1_sparc.deb
      Size/MD5 checksum: 59944 6057d32cd180068884fa63923163cc92
    http://security.debian.org/pool/updates/main/x/xmcd/xmcd_2.6-17sarge1_sparc.deb
      Size/MD5 checksum: 354052 51387f66a75f9ab56fa036b970ace931

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 1087-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
June 3rd, 2006 http://www.debian.org/security/faq


Package : postgresql
Vulnerability : programming error
Problem type : remote
Debian-specific: no
CVE IDs : CVE-2006-2313 CVE-2006-2314

Several encoding problems have been discovered in PostgreSQL, a popular SQL database. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2006-2313

Akio Ishida and Yasuo Ohgaki discovered a weakness in the handling of invalidly-encoded multibyte text data which could allow an attacker to inject arbitrary SQL commands.

CVE-2006-2314

A similar problem exists in client-side encodings (such as SJIS, BIG5, GBK, GB18030, and UHC) which contain valid multibyte characters that end with the backslash character. An attacker could supply a specially crafted byte sequence that is able to inject arbitrary SQL commands.

This issue does not affect you if you only use single-byte (like SQL_ASCII or the ISO-8859-X family) or unaffected multibyte (like UTF-8) encodings.

psycopg and python-pgsql use the old encoding for binary data and may have to be updated.

The old stable distribution (woody) is affected by these problems but we're unable to correct the package.

For the stable distribution (sarge) these problems have been fixed in version 7.4.7-6sarge2.

For the unstable distribution (sid) these problems have been fixed in version 7.4.13-1.

We recommend that you upgrade your postgresql packages.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given at the end of this advisory:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7-6sarge2.dsc
      Size/MD5 checksum: 985 78d63a976c27999c86bbd57f70eae80d
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7-6sarge2.diff.gz
      Size/MD5 checksum: 189611 577fb231aac4f86692e935b6a30eb1f4
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7.orig.tar.gz
      Size/MD5 checksum: 9952102 d193c58aef02a745e8657c48038587ac

Architecture independent components:

    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-doc_7.4.7-6sarge2_all.deb
      Size/MD5 checksum: 2266882 86068a0b0bd5f3353746555933d29317

Alpha architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg-dev_7.4.7-6sarge2_alpha.deb
      Size/MD5 checksum: 239980 bb173b640c9f206c320d20b554d724fa
    http://security.debian.org/pool/updates/main/p/postgresql/libecpg4_7.4.7-6sarge2_alpha.deb
      Size/MD5 checksum: 104826 0d4a8d8aea91799bc70617f9e47b5b29
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.4.7-6sarge2_alpha.deb
      Size/MD5 checksum: 82408 f4a3dad48412573e5b993c4d9e7400f1
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl-dev_7.4.7-6sarge2_alpha.deb
      Size/MD5 checksum: 61972 7cc403fea81613636d180358568638ca
    http://security.debian.org/pool/updates/main/p/postgresql/libpq3_7.4.7-6sarge2_alpha.deb
      Size/MD5 checksum: 139496 bede365b3e3505f79cb734747744fd5e
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7-6sarge2_alpha.deb
      Size/MD5 checksum: 4153162 86740fcfb886861702c8bccbcfb7a8be
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.4.7-6sarge2_alpha.deb
      Size/MD5 checksum: 614270 16108bc1a5cc9d7d51337597e2f5090c
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.4.7-6sarge2_alpha.deb
      Size/MD5 checksum: 701704 de550242e2d5cbbf0d9c24aad75a4977
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.4.7-6sarge2_alpha.deb
      Size/MD5 checksum: 546150 d9c95cc8ac6e21509b13640d0589c46c

AMD64 architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg-dev_7.4.7-6sarge2_amd64.deb
      Size/MD5 checksum: 210208 602e081a5b8ef164d0d7114cfbb002e2
    http://security.debian.org/pool/updates/main/p/postgresql/libecpg4_7.4.7-6sarge2_amd64.deb
      Size/MD5 checksum: 96442 ecdcbc5b59750b9871d49e3319a18fb8
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.4.7-6sarge2_amd64.deb
      Size/MD5 checksum: 79380 ca54542f754ac5da8c992f5889c12cc9
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl-dev_7.4.7-6sarge2_amd64.deb
      Size/MD5 checksum: 56212 364aaa1ac5a22e12262b90314f060d33
    http://security.debian.org/pool/updates/main/p/postgresql/libpq3_7.4.7-6sarge2_amd64.deb
      Size/MD5 checksum: 131638 82fcd52b9cb9c93afb1e9545df89ee28
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7-6sarge2_amd64.deb
      Size/MD5 checksum: 3887452 f408a28bc585b4f98e72e343813316be
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.4.7-6sarge2_amd64.deb
      Size/MD5 checksum: 559516 2b31c9a4fc43ab7ca0d9dd2f55dd1bb9
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.4.7-6sarge2_amd64.deb
      Size/MD5 checksum: 654962 0b5970688a0f4ed4476ea80196b3e33d
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.4.7-6sarge2_amd64.deb
      Size/MD5 checksum: 519740 b291ff79aa9dcf4c94b4f544222b6e3c

ARM architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg-dev_7.4.7-6sarge2_arm.deb
      Size/MD5 checksum: 216872 60267ccd42ebc905fbed60faf15ce7c8
    http://security.debian.org/pool/updates/main/p/postgresql/libecpg4_7.4.7-6sarge2_arm.deb
      Size/MD5 checksum: 92170 6f866dbf0695c4857d73dbd9c538caa7
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.4.7-6sarge2_arm.deb
      Size/MD5 checksum: 76290 53279156767dd6b03ebde6a1a7a6e9d5
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl-dev_7.4.7-6sarge2_arm.deb
      Size/MD5 checksum: 56338 14809b9f1149cc9a09b2b7f65efffd07
    http://security.debian.org/pool/updates/main/p/postgresql/libpq3_7.4.7-6sarge2_arm.deb
      Size/MD5 checksum: 124098 72f5fa7ae580925a88a2d3dd8fc96c3d
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7-6sarge2_arm.deb
      Size/MD5 checksum: 3789942 b819ecda4f08a2f321942e6efd760e35
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.4.7-6sarge2_arm.deb
      Size/MD5 checksum: 534538 b1cd2927aaf7a59ebe9274e9d88beff9
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.4.7-6sarge2_arm.deb
      Size/MD5 checksum: 628216 a94c9d9207b560b6eed5fd823bdd5406
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.4.7-6sarge2_arm.deb
      Size/MD5 checksum: 518454 db9f0c0c6ab0c0c3a504c5a1faf93d54

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg-dev_7.4.7-6sarge2_i386.deb
      Size/MD5 checksum: 207204 aafafd90bea915cfce42e4cc8997a7ae
    http://security.debian.org/pool/updates/main/p/postgresql/libecpg4_7.4.7-6sarge2_i386.deb
      Size/MD5 checksum: 95146 fbccb71b54ddae5b4f0100262e546edd
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.4.7-6sarge2_i386.deb
      Size/MD5 checksum: 78032 c2199f8932f9af670103bae577da7928
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl-dev_7.4.7-6sarge2_i386.deb
      Size/MD5 checksum: 55678 ba9771127582d3c4d041d0ebd54714f8
    http://security.debian.org/pool/updates/main/p/postgresql/libpq3_7.4.7-6sarge2_i386.deb
      Size/MD5 checksum: 128310 fcdcfa9995f3929c4af97fa75540fdf8
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7-6sarge2_i386.deb
      Size/MD5 checksum: 3799030 0d851c1ad83ba723ca81009464c69f71
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.4.7-6sarge2_i386.deb
      Size/MD5 checksum: 539660 c3511e4e1935e5e741e630b33828492f
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.4.7-6sarge2_i386.deb
      Size/MD5 checksum: 625940 32bb7a6139270dd119f72a7b708a6c54
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.4.7-6sarge2_i386.deb
      Size/MD5 checksum: 516050 9aa8818dec80c8830fde3b0d6849d310

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg-dev_7.4.7-6sarge2_ia64.deb
      Size/MD5 checksum: 250406 02e0cd73738b871e12fe07d435f502e8
    http://security.debian.org/pool/updates/main/p/postgresql/libecpg4_7.4.7-6sarge2_ia64.deb
      Size/MD5 checksum: 117496 0b12feda47694da718abaa8b82e3a7df
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.4.7-6sarge2_ia64.deb
      Size/MD5 checksum: 91804 c75fd48f53fa84033593c5000c4e2ba1
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl-dev_7.4.7-6sarge2_ia64.deb
      Size/MD5 checksum: 60582 c81d60f2b9fcafc17bf2c890f62a67af
    http://security.debian.org/pool/updates/main/p/postgresql/libpq3_7.4.7-6sarge2_ia64.deb
      Size/MD5 checksum: 152570 657268cc59f43720a4fbcd7401f68a51
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7-6sarge2_ia64.deb
      Size/MD5 checksum: 4408476 6b9c54e4e402f7f2dd0bab017b53b066
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.4.7-6sarge2_ia64.deb
      Size/MD5 checksum: 682300 919925ab2e1e3f0214223ec4d557198f
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.4.7-6sarge2_ia64.deb
      Size/MD5 checksum: 776054 17a52e7ee887815ea0eca17db214e143
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.4.7-6sarge2_ia64.deb
      Size/MD5 checksum: 543558 304d71b16b2de34209431a6e4f5f47b4

HP Precision architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg-dev_7.4.7-6sarge2_hppa.deb
      Size/MD5 checksum: 217744 7ea61b426c2ead22a87d8e6b2b8cbc06
    http://security.debian.org/pool/updates/main/p/postgresql/libecpg4_7.4.7-6sarge2_hppa.deb
      Size/MD5 checksum: 104378 cb8adb9c1dd2bc415a6157fa12f928e5
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.4.7-6sarge2_hppa.deb
      Size/MD5 checksum: 83740 3799d1cfececc128d9a6a790c08a86c7
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl-dev_7.4.7-6sarge2_hppa.deb
      Size/MD5 checksum: 58682 3caab961a85db146b0d37f982af37622
    http://security.debian.org/pool/updates/main/p/postgresql/libpq3_7.4.7-6sarge2_hppa.deb
      Size/MD5 checksum: 134686 5a730cd2793948c69aacb82d00124259
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7-6sarge2_hppa.deb
      Size/MD5 checksum: 4263326 56aa2f4f1caab2fddf15b8c0c960c426
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.4.7-6sarge2_hppa.deb
      Size/MD5 checksum: 572462 2989c44d3ed16aff10af1bbdfee973f8
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.4.7-6sarge2_hppa.deb
      Size/MD5 checksum: 686150 ad186c53d5cf30ec79bd5f7a8de97a7c
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.4.7-6sarge2_hppa.deb
      Size/MD5 checksum: 523900 eb948f532e5cfdebe504925a73103c9d

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg-dev_7.4.7-6sarge2_m68k.deb
      Size/MD5 checksum: 194254 60cb0f51cdb1e8c270bf5092b8d8255c
    http://security.debian.org/pool/updates/main/p/postgresql/libecpg4_7.4.7-6sarge2_m68k.deb
      Size/MD5 checksum: 89926 557536dec7b52d56abd80da0e3395204
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.4.7-6sarge2_m68k.deb
      Size/MD5 checksum: 76946 8d5b8aaaad2faef72647dab6bf74a706
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl-dev_7.4.7-6sarge2_m68k.deb
      Size/MD5 checksum: 53920 d8a7c7dfde0b9848c9b820b1b021013b
    http://security.debian.org/pool/updates/main/p/postgresql/libpq3_7.4.7-6sarge2_m68k.deb
      Size/MD5 checksum: 125348 e2a9707ad1ac5f7fe1c1f2455242bc2c
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7-6sarge2_m68k.deb
      Size/MD5 checksum: 3974176 da72953d869784679784c9753972128f
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.4.7-6sarge2_m68k.deb
      Size/MD5 checksum: 510460 0c3be055f6a3e09377c5669e25ee6cc3
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.4.7-6sarge2_m68k.deb
      Size/MD5 checksum: 608894 52181b4b31ca796c2a67737706c2d732
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.4.7-6sarge2_m68k.deb
      Size/MD5 checksum: 507366 b47589dc8e2cba5f2484136ae1360bd8

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg-dev_7.4.7-6sarge2_mips.deb
      Size/MD5 checksum: 209612 24ecb0017cc2d0213c9ae14def963f7c
    http://security.debian.org/pool/updates/main/p/postgresql/libecpg4_7.4.7-6sarge2_mips.deb
      Size/MD5 checksum: 95740 7bc16022786a15ce296cc450bad14690
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.4.7-6sarge2_mips.deb
      Size/MD5 checksum: 80856 4ae6337bf3f0749e5646398025b4ca3a
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl-dev_7.4.7-6sarge2_mips.deb
      Size/MD5 checksum: 56260 32e7db2cc80977c8202f4dd11e4d37c0
    http://security.debian.org/pool/updates/main/p/postgresql/libpq3_7.4.7-6sarge2_mips.deb
      Size/MD5 checksum: 128346 19627a5e0dab29be81b092ef9a064f1c
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7-6sarge2_mips.deb
      Size/MD5 checksum: 4171356 e97e1b50aa6ce9f1b3963d9ab20eeacc
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.4.7-6sarge2_mips.deb
      Size/MD5 checksum: 582144 804d77b5e1089b5b39e57eb228836aca
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.4.7-6sarge2_mips.deb
      Size/MD5 checksum: 641800 4b006574dbeda3bcedc514ca12433b10
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.4.7-6sarge2_mips.deb
      Size/MD5 checksum: 521302 8d1b8b6bc9bc640761909527c425083a

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg-dev_7.4.7-6sarge2_mipsel.deb
      Size/MD5 checksum: 207620 1b974ad276e845a8b9da8afb88b20118
    http://security.debian.org/pool/updates/main/p/postgresql/libecpg4_7.4.7-6sarge2_mipsel.deb
      Size/MD5 checksum: 95932 06b9e5d8fd2e82c622febe7faf7b2be7
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.4.7-6sarge2_mipsel.deb
      Size/MD5 checksum: 80612 7a2d7bbd54b8f08aa09c2cd307d3d2be
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl-dev_7.4.7-6sarge2_mipsel.deb
      Size/MD5 checksum: 56322 22475b9bc5de36f15ad8560795455133
    http://security.debian.org/pool/updates/main/p/postgresql/libpq3_7.4.7-6sarge2_mipsel.deb
      Size/MD5 checksum: 128422 f6fbc5968a69601bcf94d71ad0f88532
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7-6sarge2_mipsel.deb
      Size/MD5 checksum: 3862226 e4424c77620f0c30beb7d8ac0e253d9f
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.4.7-6sarge2_mipsel.deb
      Size/MD5 checksum: 581426 ed5a9b2a615bdfcc7036287667502038
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.4.7-6sarge2_mipsel.deb
      Size/MD5 checksum: 641240 dc49d2bcf81a25280664c73b1af8797b
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.4.7-6sarge2_mipsel.deb
      Size/MD5 checksum: 521720 5ff500cb5542403582240c7e37bbcdda

PowerPC architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg-dev_7.4.7-6sarge2_powerpc.deb
      Size/MD5 checksum: 210904 48e1dd207b4b025e80b35406d75b43ee
    http://security.debian.org/pool/updates/main/p/postgresql/libecpg4_7.4.7-6sarge2_powerpc.deb
      Size/MD5 checksum: 100428 901be88d71fc0e06ccf3e50fb4151b93
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.4.7-6sarge2_powerpc.deb
      Size/MD5 checksum: 84596 72fbac10fd10eedcc4ef1673e5ad57b2
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl-dev_7.4.7-6sarge2_powerpc.deb
      Size/MD5 checksum: 55326 96fcce34e09b75e683c09e63d94b0ac2
    http://security.debian.org/pool/updates/main/p/postgresql/libpq3_7.4.7-6sarge2_powerpc.deb
      Size/MD5 checksum: 129898 6467b522f8bcf577a5a5eac47e695e5f
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7-6sarge2_powerpc.deb
      Size/MD5 checksum: 4203052 1f019762641079d46b162b4ad2837458
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.4.7-6sarge2_powerpc.deb
      Size/MD5 checksum: 565430 a305cd9acfcec0d648edb56eaae2f605
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.4.7-6sarge2_powerpc.deb
      Size/MD5 checksum: 686040 3d34c6d9faf50a6c88c736364895cbdf
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.4.7-6sarge2_powerpc.deb
      Size/MD5 checksum: 516676 c2e91f20faa7669ab94fae166f94cac5

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg-dev_7.4.7-6sarge2_s390.deb
      Size/MD5 checksum: 208296 1ceaec0962943f05b7cb930c5a8ec5f0
    http://security.debian.org/pool/updates/main/p/postgresql/libecpg4_7.4.7-6sarge2_s390.deb
      Size/MD5 checksum: 97814 73b521d57581888ffa97f4c519aa2b78
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.4.7-6sarge2_s390.deb
      Size/MD5 checksum: 80456 704e9ef41e3f89e610f7400c998ce88c
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl-dev_7.4.7-6sarge2_s390.deb
      Size/MD5 checksum: 56994 b135a1197a5b47a4070a07ffceb33348
    http://security.debian.org/pool/updates/main/p/postgresql/libpq3_7.4.7-6sarge2_s390.deb
      Size/MD5 checksum: 133966 f80f2bfb7a971fd9ff4f3266c9fdddcd
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7-6sarge2_s390.deb
      Size/MD5 checksum: 4161698 8dac213b26c2f64b394ead91cf796c8e
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.4.7-6sarge2_s390.deb
      Size/MD5 checksum: 549568 a82366bd7a49ca2e2c3f84a0f99b61b2
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.4.7-6sarge2_s390.deb
      Size/MD5 checksum: 665482 6d7faf109031c6f295966e65bd69ed79
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.4.7-6sarge2_s390.deb
      Size/MD5 checksum: 520664 3ebbbcd84b599632d3b74a6aa5cfbd9e

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg-dev_7.4.7-6sarge2_sparc.deb
      Size/MD5 checksum: 205870 9fe5eac55d9ecb77cde27081e43fa2e2
    http://security.debian.org/pool/updates/main/p/postgresql/libecpg4_7.4.7-6sarge2_sparc.deb
      Size/MD5 checksum: 93606 1ef27ddd79e25a9de9f65673076ccbed
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.4.7-6sarge2_sparc.deb
      Size/MD5 checksum: 77926 525d22dd799578af00d5ee3e09718dbd
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl-dev_7.4.7-6sarge2_sparc.deb
      Size/MD5 checksum: 56150 07daedfabe9931672c7fced5ef515708
    http://security.debian.org/pool/updates/main/p/postgresql/libpq3_7.4.7-6sarge2_sparc.deb
      Size/MD5 checksum: 127594 e488f86dcbce2df62c3dbfe56766d1c2
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.4.7-6sarge2_sparc.deb
      Size/MD5 checksum: 4091222 6c3cbbb9965d35a5813ea78abac52645
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.4.7-6sarge2_sparc.deb
      Size/MD5 checksum: 535876 f914be88ee8da6b67cc3af31db4ef42b
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.4.7-6sarge2_sparc.deb
      Size/MD5 checksum: 633208 f23620f4d6708b1946e85349372e3048
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.4.7-6sarge2_sparc.deb
      Size/MD5 checksum: 514344 6d8417121070e1faa09936e6ac9b943f

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 1088-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
June 3rd, 2006 http://www.debian.org/security/faq


Package : centericq
Vulnerability : buffer overflow
Problem type : remote
Debian-specific: no
CVE ID : CVE-2005-3863
BugTraq ID : 15600
Debian Bug : 340959

Mehdi Oudad and Kevin Fernandez discovered a buffer overflow in the ktools library which is used in centericq, a text-mode multi-protocol instant messenger client, which may lead local or remote attackers to execute arbitrary code.

For the old stable distribution (woody) this problem has been fixed in version 4.5.1-1.1woody2.

For the stable distribution (sarge) this problem has been fixed in version 4.20.0-1sarge4.

For the unstable distribution (sid) this problem has been fixed in version 4.21.0-6.

We recommend that you upgrade your centericq package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given at the end of this advisory:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody


Source archives:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody2.dsc
      Size/MD5 checksum: 603 792e9548d8f6d540c26fa0fdbdd1df57
    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody2.diff.gz
      Size/MD5 checksum: 3827 dc51504b36a05b003de1d22c2c879223
    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1.orig.tar.gz
      Size/MD5 checksum: 680625 e50121ea43a54140939b7bec8efdefe0

Alpha architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody2_alpha.deb
      Size/MD5 checksum: 868742 1e533bd67111dbaca069ec6a7e9122ec

ARM architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody2_arm.deb
      Size/MD5 checksum: 809068 400376da91c99a970032220e39de0c73

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody2_i386.deb
      Size/MD5 checksum: 648950 4b30966a06e54085bbb8db33f03beeca

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody2_ia64.deb
      Size/MD5 checksum: 930922 f8aaa7129fb4ffc5de2468662166db5f

HP Precision architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody2_hppa.deb
      Size/MD5 checksum: 821294 79ffab208975e12fb264cbb4ef36c6b3

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody2_m68k.deb
      Size/MD5 checksum: 612174 969fff39d5249b24d5c711cc312a92d4

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody2_mips.deb
      Size/MD5 checksum: 649086 11f73ccf6f59687b0e9f4eb2d939fc93

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody2_mipsel.deb
      Size/MD5 checksum: 634462 2a54c83a7a9f5a47495e7d608d2705bd

PowerPC architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody2_powerpc.deb
      Size/MD5 checksum: 633210 21767275a156aa5309d2febe03e395db

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody2_s390.deb
      Size/MD5 checksum: 534764 483dda7f47f832ef50ae50a721164e62

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody2_sparc.deb
      Size/MD5 checksum: 617338 1eeee2554ee66d37458909aea51e0b18

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge4.dsc
      Size/MD5 checksum: 851 347a8183b403014c403f1757f353e436
    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge4.diff.gz
      Size/MD5 checksum: 106308 ee5a0e2b155ab6ee35c7be04941cb574
    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0.orig.tar.gz
      Size/MD5 checksum: 1796894 874165f4fbd40e3be677bdd1696cee9d

Alpha architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge4_alpha.deb
      Size/MD5 checksum: 1650570 6addf20af3c5fce5003cfcd998c88dad
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge4_alpha.deb
      Size/MD5 checksum: 336024 cabf30b626c0b1ffc7adc474e650b0da
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge4_alpha.deb
      Size/MD5 checksum: 1651594 c9b361454f6ed7546d6b7fcfb417c420
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge4_alpha.deb
      Size/MD5 checksum: 1650632 414f32a3fee64fcfe7b98365d64486f1

AMD64 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge4_amd64.deb
      Size/MD5 checksum: 1355518 6bc3845c82740d0b089337dd3068078e
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge4_amd64.deb
      Size/MD5 checksum: 336006 6eee21ecd6ee4600813192d98ca172e7
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge4_amd64.deb
      Size/MD5 checksum: 1355798 226ae854f90219c9cc8c662b9be2e903
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge4_amd64.deb
      Size/MD5 checksum: 1355566 27d8db8b20503f0527e558846b20ebbb

ARM architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge4_arm.deb
      Size/MD5 checksum: 2185394 bf00243e825f49f26585f547cec1f404
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge4_arm.deb
      Size/MD5 checksum: 336028 ce7a340b924cb1ab7a571fdc0c301945
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge4_arm.deb
      Size/MD5 checksum: 2186140 adf229a4553875379348b1688f910678
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge4_arm.deb
      Size/MD5 checksum: 2185460 7375a4503258d1fcb9d4f03d34b54cf4

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge4_i386.deb
      Size/MD5 checksum: 1348826 1f8a99153aa93509805a95eedfb1e493
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge4_i386.deb
      Size/MD5 checksum: 335880 51caf40c0a4cb709ed257453e46fcc74
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge4_i386.deb
      Size/MD5 checksum: 1349608 2b46f86353b8b1323e6776c23c434750
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge4_i386.deb
      Size/MD5 checksum: 1348924 608dd61bfbb98d99867eefabcccbbbae

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge4_ia64.deb
      Size/MD5 checksum: 1881388 88f88e10e529a68cfb6ebd2d9ce76fb2
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge4_ia64.deb
      Size/MD5 checksum: 335984 577780bd2cf3fffd54f985dfe71c9b28
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge4_ia64.deb
      Size/MD5 checksum: 1882292 9d43ae3452ed00c896882a40f4e2b21f
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge4_ia64.deb
      Size/MD5 checksum: 1881456 a5350a5fe409bfc0545ce0d3b6201e99

HP Precision architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge4_hppa.deb
      Size/MD5 checksum: 1812604 ba840154c90fa7fd5c5d27f629a4e7d0
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge4_hppa.deb
      Size/MD5 checksum: 336684 49cbe7f7dacb8774e60cde1c436647eb
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge4_hppa.deb
      Size/MD5 checksum: 1813616 3a3358848c14c28e63a317a87111bcf5
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge4_hppa.deb
      Size/MD5 checksum: 1812646 d4d53c94a0670042863ba66bf822c8af

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge4_m68k.deb
      Size/MD5 checksum: 1399506 050350f784fa16edc990a0af9094d360
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge4_m68k.deb
      Size/MD5 checksum: 336772 ff95d538d955d3f3a29c2b1b76b1629b
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge4_m68k.deb
      Size/MD5 checksum: 1400204 6787c44b90c3e24a2e550661f2070024
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge4_m68k.deb
      Size/MD5 checksum: 1399546 960a182de7c92c96153f95f7858288b6

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge4_mips.deb
      Size/MD5 checksum: 1493242 45baa39468c703cebbb3e7135992fe08
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge4_mips.deb
      Size/MD5 checksum: 336704 aa4c66a0022918403b8b5725f888f1f9
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge4_mips.deb
      Size/MD5 checksum: 1493744 7758a3e4853e9735bddceecdde402a37
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge4_mips.deb
      Size/MD5 checksum: 1493310 3b92ec1941f96ba976c7c98824231566

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge4_mipsel.deb
      Size/MD5 checksum: 1483388 bf669f331a7becc56851b41c70f0dbcf
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge4_mipsel.deb
      Size/MD5 checksum: 336048 7a7ecf280bc1d03e79af0cfa794ddb9a
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge4_mipsel.deb
      Size/MD5 checksum: 1483970 c3cd579d088ad124053bd73a2633a470
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge4_mipsel.deb
      Size/MD5 checksum: 1483438 7d1493bfa167fd7f7644232e215fad7f

PowerPC architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge4_powerpc.deb
      Size/MD5 checksum: 1386192 92d2bce7027d47f82e68f50a2a54892f
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge4_powerpc.deb
      Size/MD5 checksum: 336702 8cab14ba1f096f2e2588120b5cf06e97
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge4_powerpc.deb
      Size/MD5 checksum: 1386680 58e198a5b828b1abb309630ecf966bf7
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge4_powerpc.deb
      Size/MD5 checksum: 1386242 8e54c9ce0432cebc1c9f95001d6edb15

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge4_s390.deb
      Size/MD5 checksum: 1194054 20c8220d71c45fc511d363fd434e88eb
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge4_s390.deb
      Size/MD5 checksum: 336668 078e0cf4a6ba1e74668f7f8cf04adb0d
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge4_s390.deb
      Size/MD5 checksum: 1194422 49ac26d59e6c572f38dfdd061945fa36
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge4_s390.deb
      Size/MD5 checksum: 1194088 5eb550e0f1d026c258ad84f7ef7f680e

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge4_sparc.deb
      Size/MD5 checksum: 1326004 a7db40a610eb3b6dcfe96a5909cc8313
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge4_sparc.deb
      Size/MD5 checksum: 336682 f28c264b6cedbf41aaf46e32f7bb7c12
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge4_sparc.deb
      Size/MD5 checksum: 1327028 044779001762380ee8a32bcc1193ea12
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge4_sparc.deb
      Size/MD5 checksum: 1326022 3084bf7ba7146a24608d84796a9c50eb

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 1089-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
June 3rd, 2006 http://www.debian.org/security/faq


Package : freeradius
Vulnerability : several
Problem type : remote
Debian-specific: no
CVE IDs : CVE-2005-4744 CVE-2006-1354
BugTraq IDs : 17171 17293
Debian Bug : 359042

Several problems have been discovered in freeradius, a high-performance and highly configurable RADIUS server. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2005-4744

SuSE researchers have discovered several off-by-one errors may allow remote attackers to cause a denial of service and possibly execute arbitrary code.

CVE-2006-1354

Due to insufficient input validation it is possible for a remote attacker to bypass authentication or cause a denial of service.

The old stable distribution (woody) does not contain this package.

For the stable distribution (sarge) this problem has been fixed in version 1.0.2-4sarge1.

For the unstable distribution (sid) this problem has been fixed in version 1.1.0-1.2.

We recommend that you upgrade your freeradius package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2-4sarge1.dsc
      Size/MD5 checksum: 897 56748d8bbc17aa4e7393b990eb74b3eb
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2-4sarge1.diff.gz
      Size/MD5 checksum: 15630 20c245bcb697ed963fa5599fd64412fd
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2.orig.tar.gz
      Size/MD5 checksum: 1931715 422a004f2354b2a7364f5b683891a26a

Architecture independent components:

    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-dialupadmin_1.0.2-4sarge1_all.deb
      Size/MD5 checksum: 111708 ad56d19ec032f33dc7c80816176fdb33

Alpha architecture:

    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2-4sarge1_alpha.deb
      Size/MD5 checksum: 2234836 a9bfbf394a28e96c3a548f4c9cc6daf1
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-iodbc_1.0.2-4sarge1_alpha.deb
      Size/MD5 checksum: 54158 01356bafaa902def24608e4ff0f5234f
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-krb5_1.0.2-4sarge1_alpha.deb
      Size/MD5 checksum: 54986 bee15f15d005285f827766f996c60ce4
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-ldap_1.0.2-4sarge1_alpha.deb
      Size/MD5 checksum: 107460 56d7d0ee92185d08baac041d5997849f
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-mysql_1.0.2-4sarge1_alpha.deb
      Size/MD5 checksum: 55930 f9b5543a03e90b5dff4657eb74c17e1d

AMD64 architecture:

    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2-4sarge1_amd64.deb
      Size/MD5 checksum: 1961200 87bf5381e4746425397e6315811aa202
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-iodbc_1.0.2-4sarge1_amd64.deb
      Size/MD5 checksum: 53024 c61df3f04a0f4022edf411bd98416ba6
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-krb5_1.0.2-4sarge1_amd64.deb
      Size/MD5 checksum: 53786 e21e4a4f2073dd8ed6eb123432b45360
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-ldap_1.0.2-4sarge1_amd64.deb
      Size/MD5 checksum: 99594 5090d67f5a4da97b097656608a570ba6
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-mysql_1.0.2-4sarge1_amd64.deb
      Size/MD5 checksum: 54750 0431a87e678e805a6ef551dd8e5307aa

ARM architecture:

    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2-4sarge1_arm.deb
      Size/MD5 checksum: 2034200 a78f3ddf85f1e71c32e9b86bbbbe8e85
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-iodbc_1.0.2-4sarge1_arm.deb
      Size/MD5 checksum: 51194 7238cf725afbcaf03efab289cc6bd11b
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-krb5_1.0.2-4sarge1_arm.deb
      Size/MD5 checksum: 52600 9f16d186efe2c9ee581516d9263acd33
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-ldap_1.0.2-4sarge1_arm.deb
      Size/MD5 checksum: 96374 0e057ed9a937bcf2e6a0604434510bb4
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-mysql_1.0.2-4sarge1_arm.deb
      Size/MD5 checksum: 53186 4c11d61d72cdfba0ba4282f49955d727

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2-4sarge1_i386.deb
      Size/MD5 checksum: 2028508 9be926753b1314b3e7453bcb36773c03
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-iodbc_1.0.2-4sarge1_i386.deb
      Size/MD5 checksum: 51446 953e5b759545a6238bdccb91260e6f25
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-krb5_1.0.2-4sarge1_i386.deb
      Size/MD5 checksum: 52560 79302631d1252b0c5916f2c3659f0eb9
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-ldap_1.0.2-4sarge1_i386.deb
      Size/MD5 checksum: 97512 4bbd2b53a66a237ce910fcf147302637
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-mysql_1.0.2-4sarge1_i386.deb
      Size/MD5 checksum: 53282 2e067204ac8293570a8a177763afdcc3

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2-4sarge1_ia64.deb
      Size/MD5 checksum: 2375466 943bd9e40c1ffab804b453d8d6acc7f4
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-iodbc_1.0.2-4sarge1_ia64.deb
      Size/MD5 checksum: 53962 0cb36b4572da7058d92fe910d492c95f
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-krb5_1.0.2-4sarge1_ia64.deb
      Size/MD5 checksum: 55154 f075e38a76ab13c658f7131721f4489b
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-ldap_1.0.2-4sarge1_ia64.deb
      Size/MD5 checksum: 112832 a64d3649091a27afe04ca6cb4136f668
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-mysql_1.0.2-4sarge1_ia64.deb
      Size/MD5 checksum: 56028 99aa443bc1fd14e50e50a507aeec0100

HP Precision architecture:

    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2-4sarge1_hppa.deb
      Size/MD5 checksum: 2039272 d016b1a80144623a6e6ee3adabad8ae8
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-iodbc_1.0.2-4sarge1_hppa.deb
      Size/MD5 checksum: 54602 ee33f588d756dd6196f79b1447f0aa8f
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-krb5_1.0.2-4sarge1_hppa.deb
      Size/MD5 checksum: 56014 bb6ab35f1ad31b57a7bd19d071812693
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-ldap_1.0.2-4sarge1_hppa.deb
      Size/MD5 checksum: 105438 7bd780bb55549c009ba25c59f07306a7
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-mysql_1.0.2-4sarge1_hppa.deb
      Size/MD5 checksum: 56354 1cdfaf9766a45583c41573f53dc1947e

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2-4sarge1_m68k.deb
      Size/MD5 checksum: 2017716 7e004414928552bd42e6824f45b09608
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-iodbc_1.0.2-4sarge1_m68k.deb
      Size/MD5 checksum: 52950 eb95df0d1973deff8557f8ef21af5789
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-krb5_1.0.2-4sarge1_m68k.deb
      Size/MD5 checksum: 53954 531a9c1328415fedd7d258af62c822e6
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-ldap_1.0.2-4sarge1_m68k.deb
      Size/MD5 checksum: 95190 adbb0a86dcfad99fb7d6ab2d327157cc
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-mysql_1.0.2-4sarge1_m68k.deb
      Size/MD5 checksum: 54802 7b908b24521cb21174a13617434b376c

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2-4sarge1_mips.deb
      Size/MD5 checksum: 2135574 4eb5a131e58807a2928130a1260a2dad
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-iodbc_1.0.2-4sarge1_mips.deb
      Size/MD5 checksum: 53200 b5dd30dd319f8154ef914f773a0c1448
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-krb5_1.0.2-4sarge1_mips.deb
      Size/MD5 checksum: 53668 d7e9aad513740e93a52db17e902e5747
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-ldap_1.0.2-4sarge1_mips.deb
      Size/MD5 checksum: 97996 8bb100ed36fc455f73b667ec4bb4da7e
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-mysql_1.0.2-4sarge1_mips.deb
      Size/MD5 checksum: 55140 f6cdf24be5e60b91e61dce6280a02192

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2-4sarge1_mipsel.deb
      Size/MD5 checksum: 2102240 86ab8809a4bef9538ea4c7693492ca3f
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-iodbc_1.0.2-4sarge1_mipsel.deb
      Size/MD5 checksum: 52062 281530578f22e92c57ff60374000b0f3
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-krb5_1.0.2-4sarge1_mipsel.deb
      Size/MD5 checksum: 52400 df97212268ea91baad3ca2dfdc4c7fce
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-ldap_1.0.2-4sarge1_mipsel.deb
      Size/MD5 checksum: 96492 3d63745a6aaf6bbf32a9cb48582acdd7
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-mysql_1.0.2-4sarge1_mipsel.deb
      Size/MD5 checksum: 53936 9ded19b30c574fa280e54f246cf80749

PowerPC architecture:

    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2-4sarge1_powerpc.deb
      Size/MD5 checksum: 2330602 3362429b3da2311b68d86ebfc07544ee
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-iodbc_1.0.2-4sarge1_powerpc.deb
      Size/MD5 checksum: 58844 69224d3064f8a9b2f632c3a0035d61ca
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-krb5_1.0.2-4sarge1_powerpc.deb
      Size/MD5 checksum: 60056 ba48d26580793fe3963306e9408982c7
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-ldap_1.0.2-4sarge1_powerpc.deb
      Size/MD5 checksum: 108876 9ee35d9bba2ed802d84274b458f861be
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-mysql_1.0.2-4sarge1_powerpc.deb
      Size/MD5 checksum: 61222 cf3addbb9c8ff12ea10eea6f6dc8ea7d

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2-4sarge1_s390.deb
      Size/MD5 checksum: 2581854 d4ec31ca6d5a56a0276321aa6cd666e1
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-iodbc_1.0.2-4sarge1_s390.deb
      Size/MD5 checksum: 65650 d568c8c65934c39f20a0a06424d06cb7
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-krb5_1.0.2-4sarge1_s390.deb
      Size/MD5 checksum: 66414 5c5883970226a543b1d4186676e56733
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-ldap_1.0.2-4sarge1_s390.deb
      Size/MD5 checksum: 122758 e5394b982f52d76fe7e06aa1b894724b
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-mysql_1.0.2-4sarge1_s390.deb
      Size/MD5 checksum: 68072 cdac845ff69647c86434cb0dca112b09

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/f/freeradius/freeradius_1.0.2-4sarge1_sparc.deb
      Size/MD5 checksum: 2080708 0ecadd00e7bd093d9c8a5684c066b62e
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-iodbc_1.0.2-4sarge1_sparc.deb
      Size/MD5 checksum: 52898 b0f8020da1f2ab6d29cbd587361f6831
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-krb5_1.0.2-4sarge1_sparc.deb
      Size/MD5 checksum: 54004 98076e96d39bf98c15a220f2f1e13317
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-ldap_1.0.2-4sarge1_sparc.deb
      Size/MD5 checksum: 98894 550cc64d2b5c0b6a4af33d669df6abc0
    http://security.debian.org/pool/updates/main/f/freeradius/freeradius-mysql_1.0.2-4sarge1_sparc.deb
      Size/MD5 checksum: 54868 b18f2bfe5e3bd063a243f94d4060ab52

These files will probably be moved into the stable distribution on its next update.


For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>


No talkbacks posted.
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!






..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP


The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers