Linux Today: Linux News On Internet Time.
Search Linux Today
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Server Daily
IT Management Daily
Subscribe News
Subscribe PR
Subscribe Security

internet.com
Internet News
Small Business

Advertise
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

Malware devs embrace open-source

A tale of two distros: Ubuntu and Linux Mint

Raspberry Pi benchmarked against Beagleboard, low price is long term

20 popular Ubuntu Linux apps you may want to try

A Selection of the Very Best Open Source Tutorials and Tools

Android Ice Cream Sandwich ported to x86 tablets, netbooks and notebooks

SECURITY: Google Chrome 17 Improves Security

How to read a CSV file in Perl?

Red Hat Brings Gluster to Amazon Cloud

New Linux kernel fixes power-saving issues



Applications Management Engineer Sr (NYC)
Next Step Systems
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume
:Advisories: October 3, 2005
Advisories: October 3, 2005
Oct 4, 2005, 04 :45 UTC (0 Talkback[s]) (2530 reads)

Debian GNU/Linux


Debian Security Advisory DSA 833-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
October 1st, 2005 http://www.debian.org/security/faq


Package : mysql-dfsg-4.1
Vulnerability : buffer overflow
Problem type : remote
Debian-specific: no
CVE ID : CAN-2005-2558
BugTraq ID : 14509

A stack-based buffer overflow in the init_syms function of MySQL, a popular database, has been discovered that allows remote authenticated users who can create user-defined functions to execute arbitrary code via a long function_name field. The ability to create user-defined functions is not typically granted to untrusted users.

The following vulnerability matrix explains which version of MySQL in which distribution has this problem fixed:
 woodysargesid
mysql3.23.49-8.14n/an/a
mysql-dfsgn/a4.0.24-10sarge14.0.24-10sarge1
mysql-dfsg-4.1n/a4.1.11a-4sarge24.1.14-2
mysql-dfsg-5.0n/an/a5.0.11beta-3

We recommend that you upgrade your mysql-dfsg-4.1 packages.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-dfsg-4.1_4.1.11a-4sarge2.dsc
      Size/MD5 checksum: 1021 ef5b7f754fd69c6ddf96185a9ea99d8c
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-dfsg-4.1_4.1.11a-4sarge2.diff.gz
      Size/MD5 checksum: 163217 c22faa82cad1a38568146d03a316b4c3
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-dfsg-4.1_4.1.11a.orig.tar.gz
      Size/MD5 checksum: 15771855 3c0582606a8903e758c2014c2481c7c3

Architecture independent components:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-common-4.1_4.1.11a-4sarge2_all.deb
      Size/MD5 checksum: 35758 f4c17c57aaed4aba0d06b22391a443ff

Alpha architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge2_alpha.deb
      Size/MD5 checksum: 1589626 326e06854e8cc7b4df3ca853a8776e6f
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge2_alpha.deb
      Size/MD5 checksum: 7963496 4da7672c7e6ce497cc6c2b72c2438c5f
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge2_alpha.deb
      Size/MD5 checksum: 1000022 a8edacbc3c87b781c4aae6772c42f2c9
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge2_alpha.deb
      Size/MD5 checksum: 17484824 d0e8f9bfebd9c492d0ed336c236050ad

AMD64 architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge2_amd64.deb
      Size/MD5 checksum: 1450438 8e3eca09ae3044bc15d7332a97eaadb3
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge2_amd64.deb
      Size/MD5 checksum: 5549144 3b9308fd3c89158b20ae75ab4835d333
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge2_amd64.deb
      Size/MD5 checksum: 848676 0cdc8e7e48e1821fcbab39aee1c6b22b
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge2_amd64.deb
      Size/MD5 checksum: 14709814 b602e0bff5fda27efbc2bf52c0b46e32

ARM architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge2_arm.deb
      Size/MD5 checksum: 1388184 ba83a61338a7b6198754c22e134bdabd
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge2_arm.deb
      Size/MD5 checksum: 5557760 54ac64644fe2897b5c2554f5332bf402
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge2_arm.deb
      Size/MD5 checksum: 835900 a29f9b8bfe41d70e24cb6eef94b43bc9
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge2_arm.deb
      Size/MD5 checksum: 14555832 a482f115a2f27abee4ad2a79dfbd6cd1

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge2_i386.deb
      Size/MD5 checksum: 1416570 e49242dae5f45b947a47ea1fe728d128
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge2_i386.deb
      Size/MD5 checksum: 5641688 b3eb7e254df56c09ada9c1fa61fab946
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge2_i386.deb
      Size/MD5 checksum: 829688 f3cdde3f2a6698f394ba0edfdbd29446
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge2_i386.deb
      Size/MD5 checksum: 14556498 45421b845326a2e40a720dc44b64985d

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge2_ia64.deb
      Size/MD5 checksum: 1711912 475cfa72891c402d1c948be09e6a98f7
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge2_ia64.deb
      Size/MD5 checksum: 7780996 03bd4ba1db9460ef9d9be5b01d880453
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge2_ia64.deb
      Size/MD5 checksum: 1049796 b8253e96506666bc4a3b659994bdd48a
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge2_ia64.deb
      Size/MD5 checksum: 18474740 4a483fc2350bda7a6eb2599c7fbf9e0d

HP Precision architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge2_hppa.deb
      Size/MD5 checksum: 1550304 aadb8f7fbda0ef84b8afcf7baf76dffb
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge2_hppa.deb
      Size/MD5 checksum: 6249354 21f0e228f658552c1ecb4d05975e3921
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge2_hppa.deb
      Size/MD5 checksum: 909194 235968a78d019efc6be2e1df68fb4cb3
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge2_hppa.deb
      Size/MD5 checksum: 15786932 aee2e68c3f7938d0ba7292289f032bda

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge2_m68k.deb
      Size/MD5 checksum: 1396882 3ef005165d935a0089c42b9dca782125
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge2_m68k.deb
      Size/MD5 checksum: 5282906 9becdb0b18c3c42b5211739e9f5f5f46
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge2_m68k.deb
      Size/MD5 checksum: 803022 43eb1fdfe29144e10d1730f1dcc45507
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge2_m68k.deb
      Size/MD5 checksum: 14070110 51c9d88be73414000742c7c2961307a1

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge1_mips.deb
      Size/MD5 checksum: 1477766 fb7a8d1fb9d4607d7172c36032ebcbbb
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge1_mips.deb
      Size/MD5 checksum: 6051760 6e97430bc9b02e866e04414e627f9f4c
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge1_mips.deb
      Size/MD5 checksum: 903542 f99636d7c17d9b9647c34d3dd3379c2d
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge1_mips.deb
      Size/MD5 checksum: 15407442 36eaf9d65e7c4dcaeff920389c6bd890

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge2_mipsel.deb
      Size/MD5 checksum: 1445350 539eadf9ac7e9b384825c944759ec6b4
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge2_mipsel.deb
      Size/MD5 checksum: 5969562 bdf9697878b6a439d079528660a67fbc
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge2_mipsel.deb
      Size/MD5 checksum: 889260 07d1f0071ce62ce433c9c924544fe5fc
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge2_mipsel.deb
      Size/MD5 checksum: 15103284 5be83f139ae6ac41ffad5a2a7a52ce49

PowerPC architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge2_powerpc.deb
      Size/MD5 checksum: 1475432 2fc2f711fd16172952db58a59c17f9cb
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge2_powerpc.deb
      Size/MD5 checksum: 6025146 f230533abfce5f92e7ee95d0966ea984
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge2_powerpc.deb
      Size/MD5 checksum: 906432 d566b964257453976d7c36e309b705de
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge2_powerpc.deb
      Size/MD5 checksum: 15402508 dc78398b45128bc2d2f6881427ff044d

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge2_s390.deb
      Size/MD5 checksum: 1537572 fc84f1f6e3f72bf3e62ae6d09fd29ed5
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge2_s390.deb
      Size/MD5 checksum: 5460800 94db267d9e373a8490a0067257ae14a4
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge2_s390.deb
      Size/MD5 checksum: 883408 9f613cb6264d5fd7da0c216301e34af1
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge2_s390.deb
      Size/MD5 checksum: 15053922 3d90c52ba65c7550da1558bb7d5ab346

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge2_sparc.deb
      Size/MD5 checksum: 1459496 478640727168f01c3832f53ada90b8d9
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge2_sparc.deb
      Size/MD5 checksum: 6205444 427316f73787f388a361c76124e59cb5
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge2_sparc.deb
      Size/MD5 checksum: 867394 9e2217f00d72fa652b5e45fae5829eb8
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge2_sparc.deb
      Size/MD5 checksum: 15390434 e79df4002a1dfb61f2253030e8cb1033

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 834-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
October 1st, 2005 http://www.debian.org/security/faq


Package : prozilla
Vulnerability : buffer overflow
Problem type : remote
Debian-specific: no
CVE ID : CAN-2005-2961

Tavis Ormandy discovered a buffer overflow in prozilla, a multi-threaded download accelerator, which may be exploited to execute arbitrary code.

For the old stable distribution (woody) this problem has been fixed in version 1.3.6-3woody3.

The stable distribution (sarge) does not contain prozilla packages.

The unstable distribution (sid) does not contain prozilla packages.

We recommend that you upgrade your prozilla package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody


Source archives:

    http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6-3woody3.dsc
      Size/MD5 checksum: 612 66c3a184d2185a18a2e20b173c6835c7
    http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6-3woody3.diff.gz
      Size/MD5 checksum: 9891 32d706f874d8c4fba1c1eed7111cd292
    http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6.orig.tar.gz
      Size/MD5 checksum: 152755 65864dfe72f5cb7d7e595ca6f34fc7d7

Alpha architecture:

    http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6-3woody3_alpha.deb
      Size/MD5 checksum: 78514 6183e73c5841beee0d8e9cc450a6c702

ARM architecture:

    http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6-3woody3_arm.deb
      Size/MD5 checksum: 65506 595b0c25a968731fc39dd9644cccf9ba

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6-3woody3_i386.deb
      Size/MD5 checksum: 64514 8c4c382318cb97f659736dc1ea017335

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6-3woody3_ia64.deb
      Size/MD5 checksum: 93574 ab60cc2fc3cac11774217fec4fe9da56

HP Precision architecture:

    http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6-3woody3_hppa.deb
      Size/MD5 checksum: 74560 a3443807a553e685573f9f34aa2cbe71

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6-3woody3_m68k.deb
      Size/MD5 checksum: 61492 e295c8293423298836b5ea829ccd2f18

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6-3woody3_mips.deb
      Size/MD5 checksum: 73168 16ebff4a693d9fb1b96c1814045edd22

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6-3woody3_mipsel.deb
      Size/MD5 checksum: 73234 85e2da96f32feb26af7600faeac69820

PowerPC architecture:

    http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6-3woody3_powerpc.deb
      Size/MD5 checksum: 68628 b95100d9ef36bd36649118b2dee08a0c

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6-3woody3_s390.deb
      Size/MD5 checksum: 65556 bf4165b94d5a28e591d5fdc10b46d94d

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6-3woody3_sparc.deb
      Size/MD5 checksum: 68174 3ff8ca31ef5d0e124a1e8714506a861f

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 835-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
October 1st, 2005 http://www.debian.org/security/faq


Package : cfengine
Vulnerability : insecure temporary files
Problem type : local
Debian-specific: no
CVE ID : CAN-2005-2960

Javier Fernández-Sanguino Peña discovered several insecure temporary file uses in cfengine, a tool for configuring and maintaining networked machines, that can be exploited by a symlink attack to overwrite arbitrary files owned by the user executing cfengine, which is probably root.

For the old stable distribution (woody) these problems have been fixed in version 1.6.3-9woody1.

For the stable distribution (sarge) these problems have been fixed in version 1.6.5-1sarge1.

For the unstable distribution (sid) these problems have will be fixed soon.

We recommend that you upgrade your cfengine package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody


Source archives:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.3-9woody1.dsc
      Size/MD5 checksum: 697 bb2e5be7b89c57f6c4cf1e3738ecd922
    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.3-9woody1.diff.gz
      Size/MD5 checksum: 38077 1ae76d1eb77ebd60a3333c062a1a7c31
    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.3.orig.tar.gz
      Size/MD5 checksum: 867415 19079eafbee44e3d39308c086d4b539b

Architecture independent components:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine-doc_1.6.3-9woody1_all.deb
      Size/MD5 checksum: 355562 ca9a13fab7548459c6084dc69d426aec

Alpha architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.3-9woody1_alpha.deb
      Size/MD5 checksum: 405720 7b6364578e2eba666365e77e32507c4b

ARM architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.3-9woody1_arm.deb
      Size/MD5 checksum: 339210 aa977174967f661d2f212f3433bf6788

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.3-9woody1_i386.deb
      Size/MD5 checksum: 303270 a64338d36f68b7935cfc5989c850cd5e

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.3-9woody1_ia64.deb
      Size/MD5 checksum: 493172 41bcf6762cf4837c8709be21cff9eb7f

HP Precision architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.3-9woody1_hppa.deb
      Size/MD5 checksum: 386724 e9442e863083edcb1e487a6c5fe93352

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.3-9woody1_m68k.deb
      Size/MD5 checksum: 281060 d948916061d5e8efb533e3b77b77a0ab

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.3-9woody1_mips.deb
      Size/MD5 checksum: 363318 0bc37a72bb1f08f35a2b579484ffb573

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.3-9woody1_mipsel.deb
      Size/MD5 checksum: 361536 c2b6aa55d276d9b6ac74e78b8117f58c

PowerPC architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.3-9woody1_powerpc.deb
      Size/MD5 checksum: 340640 d54511ed3ad4994ae81fa8f5d94bddd2

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.3-9woody1_s390.deb
      Size/MD5 checksum: 320202 4bfb085818e449b6a6a294d842fd93ce

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.3-9woody1_sparc.deb
      Size/MD5 checksum: 348898 1a5bee66a3136dd0c7c81e389ea6d02c

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5-1sarge1.dsc
      Size/MD5 checksum: 688 0c5710c1edf3c6fdd6823d6db891d299
    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5-1sarge1.diff.gz
      Size/MD5 checksum: 102832 8a282e6d4dde8c710e02a544967c5fe6
    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5.orig.tar.gz
      Size/MD5 checksum: 880066 fc02d8d56433f32020c3030192cad66e

Architecture independent components:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine-doc_1.6.5-1sarge1_all.deb
      Size/MD5 checksum: 385994 1081dd615fdd1cd5682599b5253936ba

Alpha architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5-1sarge1_alpha.deb
      Size/MD5 checksum: 420810 2402bacaa76d7763c27589c85a399605

AMD64 architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5-1sarge1_amd64.deb
      Size/MD5 checksum: 353842 953d1eb46f2cce0aedfb78e5f988cc53

ARM architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5-1sarge1_arm.deb
      Size/MD5 checksum: 340160 83ed417663d90df0727a6a8c2606d11b

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5-1sarge1_i386.deb
      Size/MD5 checksum: 323384 18459b30d0c2c5044e6922abde4425ea

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5-1sarge1_ia64.deb
      Size/MD5 checksum: 488116 f7a1c07bf59ba6163a82fed6a27666c1

HP Precision architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5-1sarge1_hppa.deb
      Size/MD5 checksum: 373982 778d47c9a7bba6a52c34580e2885a4f0

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5-1sarge1_m68k.deb
      Size/MD5 checksum: 289354 a8c67ffa26a9453959be270dd6109a36

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5-1sarge1_mips.deb
      Size/MD5 checksum: 366596 5978436e06a6fb7ad82d7f9860d02614

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5-1sarge1_mipsel.deb
      Size/MD5 checksum: 365032 4914663ccd6d58abfac5ae149c2b75cb

PowerPC architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5-1sarge1_powerpc.deb
      Size/MD5 checksum: 356614 a98b9bb1a97577472f350ae0f22bf37f

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5-1sarge1_s390.deb
      Size/MD5 checksum: 346324 33ac8dfdaa2fcb7ddccf258f901b8531

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/c/cfengine/cfengine_1.6.5-1sarge1_sparc.deb
      Size/MD5 checksum: 338540 21169b41e6976910873d642a7acef495

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 836-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
October 1st, 2005 http://www.debian.org/security/faq


Package : cfengine2
Vulnerability : insecure temporary files
Problem type : local
Debian-specific: no
CVE ID : CAN-2005-2960

Javier Fernández-Sanguino Peña discovered insecure temporary file use in cfengine2, a tool for configuring and maintaining networked machines, that can be exploited by a symlink attack to overwrite arbitrary files owned by the user executing cfengine, which is probably root.

The old stable distribution (woody) is not affected by this problem.

For the stable distribution (sarge) these problems have been fixed in version 2.1.14-1sarge1.

For the unstable distribution (sid) these problems will be fixed soon.

We recommend that you upgrade your cfengine2 package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14-1sarge1.dsc
      Size/MD5 checksum: 825 c3ee62f9ce0b5432069c59049bc0c652
    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14-1sarge1.diff.gz
      Size/MD5 checksum: 32635 ab7a8c127448eca0dce586c9ba672a85
    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14.orig.tar.gz
      Size/MD5 checksum: 3513765 bc60a13b6890275ba6b17a07c257cac5

Architecture independent components:

    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2-doc_2.1.14-1sarge1_all.deb
      Size/MD5 checksum: 510730 0f6ff1887770d9fe9070dddebdcc5edf

Alpha architecture:

    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14-1sarge1_alpha.deb
      Size/MD5 checksum: 827762 5c9ced60f5d41e785a55ba7b4582a796

AMD64 architecture:

    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14-1sarge1_amd64.deb
      Size/MD5 checksum: 701256 b4888a6dc496aaa48b2a0fdc3715a67f

ARM architecture:

    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14-1sarge1_arm.deb
      Size/MD5 checksum: 685630 a48e6708452f90c1e8d4fe993e3f4771

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14-1sarge1_i386.deb
      Size/MD5 checksum: 649868 b77b9785ac4b67f0701039b436a3244c

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14-1sarge1_ia64.deb
      Size/MD5 checksum: 984586 3defd29cd3a9d4eea73ee5b4711bd944

HP Precision architecture:

    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14-1sarge1_hppa.deb
      Size/MD5 checksum: 752410 a53dea0a28cb6e55bb9c707dafe2def7

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14-1sarge1_m68k.deb
      Size/MD5 checksum: 566602 b803dacc74b7a3a8fe0d871a994e96d8

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14-1sarge1_mips.deb
      Size/MD5 checksum: 721626 f85c4d747912fe55625d993479f45167

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14-1sarge1_mipsel.deb
      Size/MD5 checksum: 718708 b667ffc1a228ca13f1fd65642d5504c9

PowerPC architecture:

    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14-1sarge1_powerpc.deb
      Size/MD5 checksum: 702944 63b9669606bbfc5bb97eaca5bd1f5f55

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14-1sarge1_s390.deb
      Size/MD5 checksum: 683930 822f52d113e7d4798be7e5fb9e542f25

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/c/cfengine2/cfengine2_2.1.14-1sarge1_sparc.deb
      Size/MD5 checksum: 673916 e1cc606ccd6fb6345140839a340e4640

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 837-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
October 2nd, 2005 http://www.debian.org/security/faq


Package : mozilla-firefox
Vulnerability : buffer overflow
Problem type : remote
Debian-specific: no
CVE ID : CAN-2005-2871
Debian Bug : 327452

Tom Ferris discovered a bug in the IDN hostname handling of Mozilla Firefox, which is also present in the other browsers from the same family that allows remote attackers to cause a denial of service and possibly execute arbitrary code via a hostname with dashes.

For the stable distribution (sarge) this problem has been fixed in version 1.0.4-2sarge4.

For the unstable distribution (sid) this problem has been fixed in version 1.0.6-5.

We recommend that you upgrade your mozilla-firefox package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge4.dsc
      Size/MD5 checksum: 1001 8da49448d0292379ed213ed55b50f636
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge4.diff.gz
      Size/MD5 checksum: 323756 9badf2bda14c11b86ab011d90ec281f6
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4.orig.tar.gz
      Size/MD5 checksum: 40212297 8e4ba81ad02c7986446d4e54e978409d

Alpha architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge4_alpha.deb
      Size/MD5 checksum: 11163256 741a6fe56dbd1c917f70ea4a83f5d4f5
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge4_alpha.deb
      Size/MD5 checksum: 166972 e694067de0f9e51eba3b71fed7192fad
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge4_alpha.deb
      Size/MD5 checksum: 58796 066536b71dd6ed961be9a17aa79f9ca1

AMD64 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge4_amd64.deb
      Size/MD5 checksum: 9398022 6bc930760808bc9d9b61fb1f01bd860d
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge4_amd64.deb
      Size/MD5 checksum: 161704 b602c78f8f7ff6071d85639ead31b0d1
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge4_amd64.deb
      Size/MD5 checksum: 57272 d9f98cb3de4145f0866772bc599f5573

ARM architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge4_arm.deb
      Size/MD5 checksum: 8216838 391be886f3e02b83cbdf198fc9e64f43
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge4_arm.deb
      Size/MD5 checksum: 153148 e320c57a33a8d2f90db51e8ccd1fdcbf
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge4_arm.deb
      Size/MD5 checksum: 52626 f011883c695c1f62417810a7046bfb18

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge4_i386.deb
      Size/MD5 checksum: 8889628 c2dae022a03416af59f47a124ac04771
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge4_i386.deb
      Size/MD5 checksum: 156932 f3c968bdc962762016ab5ce7de6c3d49
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge4_i386.deb
      Size/MD5 checksum: 54188 9c2479ab8ebd935c40f52dc516d1ef9b

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge4_ia64.deb
      Size/MD5 checksum: 11617372 9e64ba01ab67c89e3496f658495e2d6b
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge4_ia64.deb
      Size/MD5 checksum: 167278 6c518d35da2f88bc1387391bc413af6e
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge4_ia64.deb
      Size/MD5 checksum: 61972 b413956fa64c1339729ca8c5fb069d0c

HP Precision architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge4_hppa.deb
      Size/MD5 checksum: 10266508 9985b2364613b496578d5aa58335f193
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge4_hppa.deb
      Size/MD5 checksum: 164684 8d34b3fb5b1d4085eb1905cf8f4b4169
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge4_hppa.deb
      Size/MD5 checksum: 57774 3c1f6134aa0bedd285693c272156dadf

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge4_m68k.deb
      Size/MD5 checksum: 8167076 9fbcdcc9c20c9c53bfe0c2e8867505ee
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge4_m68k.deb
      Size/MD5 checksum: 155844 5e17dab94ba264505d9e976b6cada360
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge4_m68k.deb
      Size/MD5 checksum: 53438 d65525a81b47a3ffb818044ff0f6c082

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge4_mips.deb
      Size/MD5 checksum: 9919764 dad3b9c7736be1a76182805decbe4226
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge4_mips.deb
      Size/MD5 checksum: 154698 ddcb26a6501acc4bfb01f84679c71df1
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge4_mips.deb
      Size/MD5 checksum: 54444 b05103132d75b1398fd4ac93210f8fa0

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge4_mipsel.deb
      Size/MD5 checksum: 9803612 9277b9d3635327414a54a0fa5bc43fab
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge4_mipsel.deb
      Size/MD5 checksum: 154254 9aae814cc1d5dc31ac24a4c573a3d54d
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge4_mipsel.deb
      Size/MD5 checksum: 54270 df2809a9996ea6eaf4d940420f22e654

PowerPC architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge4_powerpc.deb
      Size/MD5 checksum: 8561724 53cb5d60984f432cfb7ae7c1ee917a60
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge4_powerpc.deb
      Size/MD5 checksum: 155320 09439c02519d6082619a356c2e568649
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge4_powerpc.deb
      Size/MD5 checksum: 56564 71de49e9fe39bc3e0873d9ea09627edb

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge4_s390.deb
      Size/MD5 checksum: 9635928 4288345b4f7a1f65483220fe9e26615e
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge4_s390.deb
      Size/MD5 checksum: 162324 f7a9b952749be394d1743c0cc0442d78
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge4_s390.deb
      Size/MD5 checksum: 56758 eea32af660a5d5a5b63214c476fa8a29

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge4_sparc.deb
      Size/MD5 checksum: 8651566 2255aa4861022395d74e7ba0e7eeef0f
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge4_sparc.deb
      Size/MD5 checksum: 155558 b9110a9180419dc9437e5ab610176139
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge4_sparc.deb
      Size/MD5 checksum: 52998 658a72bc8e0a9d496ef9553da5676acb

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 838-1 security@debian.org
http://www.debian.org/security/ Michael Stone
October 2nd, 2005 http://www.debian.org/security/faq


Package : mozilla-firefox
Vulnerability : multiple
Problem type : remote
Debian-specific: no
CVE Id(s) : CAN-2005-2701 CAN-2005-2702 CAN-2005-2703 CAN-2005-2704 CAN-2005-2705 CAN-2005-2706 CAN-2005-2707

Multiple security vulnerabilities have been identified in the mozilla-firefox web browser. These vulnerabilities could allow an attacker to execute code on the victim's machine via specially crafted network resources.

CAN-2005-2701

Heap overrun in XBM image processing

CAN-2005-2702

Denial of service (crash) and possible execution of arbitrary code via Unicode sequences with "zero-width non-joiner" characters.

CAN-2005-2703

XMLHttpRequest header spoofing

CAN-2005-2704

Object spoofing using XBL <implements>

CAN-2005-2705

JavaScript integer overflow

CAN-2005-2706

Privilege escalation using about: scheme

CAN-2005-2707

Chrome window spoofing allowing windows to be created without UI components such as a URL bar or status bar that could be used to carry out phishing attacks

For the stable distribution (sarge), these problems have been fixed in version 1.0.4-2sarge5

For the unstable distribution (sid), these problems have been fixed in version 1.0.7-1

We recommend that you upgrade your mozilla-firefox package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge5.dsc
      Size/MD5 checksum: 1001 bf9cf2b7106335cccc2afb10f6386c57
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge5.diff.gz
      Size/MD5 checksum: 332598 d3f81e09a762be3c51aa20655ada5d32
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4.orig.tar.gz
      Size/MD5 checksum: 40212297 8e4ba81ad02c7986446d4e54e978409d

Alpha architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge5_alpha.deb
      Size/MD5 checksum: 11167102 e970a996296228bd2af2cb8006a86398
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge5_alpha.deb
      Size/MD5 checksum: 167592 d446479007005f2d27d079ccedf51d7d
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge5_alpha.deb
      Size/MD5 checksum: 59416 7bf500b4f181df6ab4aa6dc831a23338

AMD64 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge5_amd64.deb
      Size/MD5 checksum: 9399402 d94263433669cae93749d3f0d378839c
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge5_amd64.deb
      Size/MD5 checksum: 162334 4ffdc291bacf5b604deeaf8d6efd96eb
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge5_amd64.deb
      Size/MD5 checksum: 57946 7d7472b0fb90ed789c4f84dbcdd14687

ARM architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge5_arm.deb
      Size/MD5 checksum: 8217720 3e0ce81e8d78fbca6d38d6a7e90791f3
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge5_arm.deb
      Size/MD5 checksum: 153792 662f8f96e75cc109541bf141e79a2714
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge5_arm.deb
      Size/MD5 checksum: 53280 b3517ce11632b3adbf5970d8f4c35b8c

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge5_i386.deb
      Size/MD5 checksum: 8891730 795a6aa3ca33a5e328e863612ceb0ac3
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge5_i386.deb
      Size/MD5 checksum: 157566 5e5d92e6c30a1d677edcc2fd9beb1861
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge5_i386.deb
      Size/MD5 checksum: 54820 885991c2f4580f06f12ba1cc6ff456ac

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge5_ia64.deb
      Size/MD5 checksum: 11618922 f02ebe51045adc2008ebba0a7355f58c
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge5_ia64.deb
      Size/MD5 checksum: 167924 863962943669b737773e716bb45560b7
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge5_ia64.deb
      Size/MD5 checksum: 62602 01f5675efee57e112e1734306580e43b

HP Precision architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge5_hppa.deb
      Size/MD5 checksum: 10267086 7fb5e359ae146c7306def5b0a7ba48b4
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge5_hppa.deb
      Size/MD5 checksum: 165300 cf86dfe338ca9bfde77a402690db15ae
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge5_hppa.deb
      Size/MD5 checksum: 58402 f98081adb227cf6a12dc267bbf9c7689

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge5_m68k.deb
      Size/MD5 checksum: 8167708 d5d4eadda39add959235921126b5db4b
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge5_m68k.deb
      Size/MD5 checksum: 156434 01a518572787d1e5505eb393c4670cd9
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge5_m68k.deb
      Size/MD5 checksum: 54070 b50c79ee5b2b3fd61ccb3848ad201f29

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge5_mips.deb
      Size/MD5 checksum: 9922382 384196380da339cc6c381afd18c8d0e8
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge5_mips.deb
      Size/MD5 checksum: 155362 38e914d95e0b2d38b2d34f09988218c9
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge5_mips.deb
      Size/MD5 checksum: 55078 343647c905cf9792d53eb67b4e11df02

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge5_mipsel.deb
      Size/MD5 checksum: 9804868 cfe93fb808ecfc8e9a2bf359af772069
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge5_mipsel.deb
      Size/MD5 checksum: 154892 9321e20f831ad309fc214c8130223103
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge5_mipsel.deb
      Size/MD5 checksum: 54904 74a6c0efaa41729a646d5f5762ab637d

PowerPC architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge5_powerpc.deb
      Size/MD5 checksum: 8563444 7c373a381a8ba34307e59f2cd47fcc43
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge5_powerpc.deb
      Size/MD5 checksum: 155948 a764030b0841e225c5a89e6366bb88e5
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge5_powerpc.deb
      Size/MD5 checksum: 57186 39cb6349c6ef1bc0e9e62365e7beeebf

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge5_sparc.deb
      Size/MD5 checksum: 8652776 fa0fdecf5fb5ed186ade4d987b8920cb
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge5_sparc.deb
      Size/MD5 checksum: 156204 84483f5fa63c2da5f6e8de90f462edbe
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge5_sparc.deb
      Size/MD5 checksum: 53640 d43b2dbd4fd362e7fd01b4985c0ff3d0

These files will probably be moved into the stable distribution on its next update.


For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>


Mandriva Linux

Mandriva Linux Security Update Advisory


Package name: kernel
Advisory ID: MDKSA-2005:171
Date: October 3rd, 2005
Affected versions: Corporate 3.0, Multi Network Firewall 2.0


Problem Description:

A number of vulnerabilities in the 2.6 Linux kernel have been corrected with these updated packages:

An array index overflow in the xfrm_sk_policy_insert function could allow a local user to cause a Denial of Service (oops or deadlock) and possibly execute arbitrary code (CAN-2005-2456).

The zlib routines in the Linux 2.6 kernel before 2.6.12.5 allowed a remote attacker to cause a DoS (crash) via a compressed file with "improper tables" (CAN-2005-2458).

The huft_build function in the zlib routines in Linux 2.6 kernels prior to 2.6.12.5 returned the wrong value, allowing remote attackers to cause a DoS (crash) via a certain compressed file (CAN-2005-2459).

A stack-based buffer overflow in the sendmsg function call in Linux 2.6 kernels prior to 2.6.13.1 allow local users to execute arbitrary code by calling sendmsg and modifying the message contents in another thread (CAN-2005-2490).

xattr.c in the ext2 and ext3 file system code in the 2.6 Linux kernel did not properly compare the name_index fields when sharing xattr blocks which would prevent default ACLs from being applied (CAN-2005-2801).

The ipt_recent kernel module in 2.6 Linux kernels prior to 2.6.12 when running on 64-bit processors allowed remote attackers to cause a DoS (kernel panic) via certain attacks such as SSH brute force (CAN-2005-2872).

The ipt_recent kernel module in 2.6 Linux kernels prior to 2.6.12 did not properly perform certain time tests when the jiffies value is greater than LONG_MAX which could cause ipt_recent netfilter rules to block too early (CAN-2005-2873).

The updated packages have been patched to address these issues and all users are urged to upgrade immediately.

Updated kernels for Mandrivalinux 10.1 and later will be made available soon.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2456
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2458
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2459
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2490
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2801
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2872
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2873


Updated Packages:

Multi Network Firewall 2.0:
f7468b4d253251b7c7a5ee84571193c5 mnf/2.0/RPMS/kernel-2.6.3.28mdk-1-1mdk.i586.rpm
a9d37454e919b348a708922d2aece2ca mnf/2.0/RPMS/kernel-i686-up-4GB-2.6.3.28mdk-1-1mdk.i586.rpm
790766354d63b081ce608ee769b73574 mnf/2.0/RPMS/kernel-p3-smp-64GB-2.6.3.28mdk-1-1mdk.i586.rpm
c5a5e24e5cc9b8c9cc17867966a3d70b mnf/2.0/RPMS/kernel-secure-2.6.3.28mdk-1-1mdk.i586.rpm
7cdb6d2c133e02457229ef6eb2a7b405 mnf/2.0/RPMS/kernel-smp-2.6.3.28mdk-1-1mdk.i586.rpm
9c8a3b678f7a51be86a3555542a59188 mnf/2.0/SRPMS/kernel-2.6.3.28mdk-1-1mdk.src.rpm

Corporate 3.0:
0f6c6ac828beca090b72d4f25b34ded2 corporate/3.0/RPMS/kernel-2.6.3.28mdk-1-1mdk.i586.rpm
8b228ab0567e6f8cae1e15fe44261f97 corporate/3.0/RPMS/kernel-enterprise-2.6.3.28mdk-1-1mdk.i586.rpm
4177dbd5341d41d1605b83546b1b419b corporate/3.0/RPMS/kernel-i686-up-4GB-2.6.3.28mdk-1-1mdk.i586.rpm
543e310e249819d29d19354cac294376 corporate/3.0/RPMS/kernel-p3-smp-64GB-2.6.3.28mdk-1-1mdk.i586.rpm
0a6fd8b7c3434a6e903fa2183e5ef23c corporate/3.0/RPMS/kernel-secure-2.6.3.28mdk-1-1mdk.i586.rpm
fccb12c9f27dc1b72e4d1ff212ae29d0 corporate/3.0/RPMS/kernel-smp-2.6.3.28mdk-1-1mdk.i586.rpm
15a9d0b1914ca4b47dc49d694ede1c33 corporate/3.0/RPMS/kernel-source-2.6.3-28mdk.i586.rpm
a62fc25d549523e00efa006644543dda corporate/3.0/RPMS/kernel-source-stripped-2.6.3-28mdk.i586.rpm
9c8a3b678f7a51be86a3555542a59188 corporate/3.0/SRPMS/kernel-2.6.3.28mdk-1-1mdk.src.rpm

Corporate 3.0/X86_64:
8ad1a6656bc68149b775b6012b4b3d10 x86_64/corporate/3.0/RPMS/kernel-2.6.3.28mdk-1-1mdk.x86_64.rpm
aced128f099513e241f79bceaff13733 x86_64/corporate/3.0/RPMS/kernel-secure-2.6.3.28mdk-1-1mdk.x86_64.rpm
c67c7c76be4a011de9a6e2c26bd22af6 x86_64/corporate/3.0/RPMS/kernel-smp-2.6.3.28mdk-1-1mdk.x86_64.rpm
aef5ccc688591da64d004c4eb50a8ad4 x86_64/corporate/3.0/RPMS/kernel-source-2.6.3-28mdk.x86_64.rpm
2436bca0b07afefecdba53f24a9c8f73 x86_64/corporate/3.0/RPMS/kernel-source-stripped-2.6.3-28mdk.x86_64.rpm
9c8a3b678f7a51be86a3555542a59188 x86_64/corporate/3.0/SRPMS/kernel-2.6.3.28mdk-1-1mdk.src.rpm


To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>



No talkbacks posted.
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!

..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP