Linux Today: Linux News On Internet Time.
Search Linux Today
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Server Daily
IT Management Daily
Subscribe News
Subscribe PR
Subscribe Security

internet.com
Internet News
Small Business

Advertise
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

Malware devs embrace open-source

A tale of two distros: Ubuntu and Linux Mint

Raspberry Pi benchmarked against Beagleboard, low price is long term

20 popular Ubuntu Linux apps you may want to try

A Selection of the Very Best Open Source Tutorials and Tools

Android Ice Cream Sandwich ported to x86 tablets, netbooks and notebooks

SECURITY: Google Chrome 17 Improves Security

How to read a CSV file in Perl?

Red Hat Brings Gluster to Amazon Cloud

New Linux kernel fixes power-saving issues



Applications Management Engineer Sr (NYC)
Next Step Systems
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume
:Advisories, January 10, 2006
Advisories, January 10, 2006
Jan 11, 2006, 04 :45 UTC (0 Talkback[s]) (2361 reads)

Debian GNU/Linux


Debian Security Advisory DSA 929-1 security@debian.org
http://www.debian.org/security/ Steve Kemp
Jan 9, 2006 http://www.debian.org/security/faq


Vulnerability : buffer overflow
Problem-Type : local
Debian-specific: no
CVE ID : CVE-2005-3540

Steve Kemp from the Debian Security Audit project discovered a buffer overflow in petris, a clone of the Tetris game, which may be exploited to execute arbitary code with group games privileges.

The old stable distribution (woody) does not contain the petris package.

For the stable distribution (sarge) this problem has been fixed in version 1.0.1-4sarge0.

For the unstable distribution the package will be updated shortly.

We recommend that you upgrade your petris package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    petris_1.0.1-4sarge0.diff.gz
      Size/MD5 checksum: 4255 f043952580a76a670090f5e10456cac0
    petris_1.0.1-4sarge0.dsc
      Size/MD5 checksum: 597 a8f7e7dc2da54370faf95307432ea057
    petris_1.0.1.orig.tar.gz
      Size/MD5 checksum: 11400 36ce4098c5305606ebbb66641eb9cea3

Alpha architecture:

    petris_1.0.1-4sarge0_alpha.deb
      Size/MD5 checksum: 17164 14925ee0cd40732d78d4d3267e304a6d

AMD64 architecture:

    petris_1.0.1-4sarge0_amd64.deb
      Size/MD5 checksum: 16118 ae80ded8db7237ac7ffbd235e94583bc

ARM architecture:

    petris_1.0.1-4sarge0_arm.deb
      Size/MD5 checksum: 14808 710db3e851a54a5c385a691de161ec35

HP Precision architecture:

    petris_1.0.1-4sarge0_hppa.deb
      Size/MD5 checksum: 16402 a7f392bda8179958a5cd95299865c1a5

Intel IA-32 architecture:

    petris_1.0.1-4sarge0_i386.deb
      Size/MD5 checksum: 15040 2efc32faf40e7402e818a088ab2ba6e2

Intel IA-64 architecture:

    petris_1.0.1-4sarge0_ia64.deb
      Size/MD5 checksum: 19610 bea0e1a48f9159ea1ef1c291af8f7974

Motorola 680x0 architecture:

    petris_1.0.1-4sarge0_m68k.deb
      Size/MD5 checksum: 14342 84fd7e89e8034c491df081bf562047f5

Big endian MIPS architecture:

    petris_1.0.1-4sarge0_mips.deb
      Size/MD5 checksum: 16488 4828a8700d380fe7fee578c4982cadc1

Little endian MIPS architecture:

    petris_1.0.1-4sarge0_mipsel.deb
      Size/MD5 checksum: 16434 3da9a116a510b2d095076015494fc72c

PowerPC architecture:

    petris_1.0.1-4sarge0_powerpc.deb
      Size/MD5 checksum: 17154 246d78ced212deb20bafdffc25b34503

IBM S/390 architecture:

    petris_1.0.1-4sarge0_s390.deb
      Size/MD5 checksum: 15928 bafe7066921152a84e610268031b1c3b

Sun Sparc architecture:

    petris_1.0.1-4sarge0_sparc.deb
      Size/MD5 checksum: 14866 e7a0d84f92bbf1e57d4aef61e257fc48

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 930-1 security@debian.org
http://www.debian.org/security/ Steve Kemp
Jan 9, 2006 http://www.debian.org/security/faq


Vulnerability : format string attack
Problem-Type : local
Debian-specific: no
CVE ID : CVE-2006-0083

Ulf Harnhammar from the Debian Security Audit project discovered a format string attack in the logging code of smstools, which may be exploited to execute arbitary code with root privileges.

The old stable distribution (woody) does not contain smstools package.

For the stable distribution (sarge) this problem has been fixed in version 1.14.8-1sarge0.

For the unstable distribution the package will be updated shortly.

We recommend that you upgrade your smstools package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    smstools_1.14.8-1sarge0.diff.gz
      Size/MD5 checksum: 5106 ef55852ce6da003ef5f45df6eed1a8c5
    smstools_1.14.8-1sarge0.dsc
      Size/MD5 checksum: 624 1e69b0c4a20ce7f08bce8a8b51b8504d
    smstools_1.14.8.orig.tar.gz
      Size/MD5 checksum: 158423 85b342e53d7fdde89ef25ad21e1c5fe0

Alpha architecture:

    smstools_1.14.8-1sarge0_alpha.deb
      Size/MD5 checksum: 184268 59ca41ecd61cc94de2b63c8698464732

AMD64 architecture:

    smstools_1.14.8-1sarge0_amd64.deb
      Size/MD5 checksum: 178130 f957b798e9de3075e013521bbf6241d6

ARM architecture:

    smstools_1.14.8-1sarge0_arm.deb
      Size/MD5 checksum: 173506 aa2b0df1d47ad50070aebacc266f729d

HP Precision architecture:

    smstools_1.14.8-1sarge0_hppa.deb
      Size/MD5 checksum: 180032 168dba93586bc10214fbb6a5914f962e

Intel IA-32 architecture:

    smstools_1.14.8-1sarge0_i386.deb
      Size/MD5 checksum: 166816 aee3afc84707f7190c255ed3739c2958

Intel IA-64 architecture:

    smstools_1.14.8-1sarge0_ia64.deb
      Size/MD5 checksum: 201440 9868ead0f8885bc3851137b23d76877d

Motorola 680x0 architecture:

    smstools_1.14.8-1sarge0_m68k.deb
      Size/MD5 checksum: 166452 d713ee667bee3c3186ba477f9d0f91a8

Big endian MIPS architecture:

    smstools_1.14.8-1sarge0_mips.deb
      Size/MD5 checksum: 182332 846d0a829680db2b3662982c9fe49d4f

Little endian MIPS architecture:

    smstools_1.14.8-1sarge0_mipsel.deb
      Size/MD5 checksum: 182004 db7200f1504ea22681e23e749435c22a

PowerPC architecture:

    smstools_1.14.8-1sarge0_powerpc.deb/ Size/MD5 checksum: 172100 183e00f44548fce56df228441593bb90

IBM S/390 architecture:

    smstools_1.14.8-1sarge0_s390.deb
      Size/MD5 checksum: 179978 ab77f608c71a908bc51e7781b51c416d

Sun Sparc architecture:

    smstools_1.14.8-1sarge0_sparc.deb
      Size/MD5 checksum: 175994 a03ff752a8910e397e73f53649c5a931

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 930-2 security@debian.org
http://www.debian.org/security/ Steve Kemp

January 10, 2006 http://www.debian.org/security/faq


Package : smstools
Vulnerability : format string attack
Problem-Type : local
Debian-specific: no
CVE ID : CVE-2006-0083

Ulf Harnhammar from the Debian Security Audit project discovered a format string attack in the logging code of smstools, which may be exploited to execute arbitary code with root privileges.

The original advisory for this issue said that the old stable distribution (woody) was not affected because it did not contain smstools. This was incorrect, and the only change in this updated advisory is the inclusion of corrected packages for woody.

For the old stable distribution (woody) this problem has been fixed in version 1.5.0-2woody0.

For the stable distribution (sarge) this problem has been fixed in version 1.14.8-1sarge0.

For the unstable distribution the package will be updated shortly.

We recommend that you upgrade your smstools package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody


Source archives:

    http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0-2woody0.dsc
      Size/MD5 checksum: 595 3b125f8d494769561c579a2afb8eedf3
    http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0-2woody0.diff.gz
      Size/MD5 checksum: 7441 8fd87155404a99eb88ff06e5e7bccd4b
    http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0.orig.tar.gz
      Size/MD5 checksum: 42987 0286109d2011a5b8ab2fbd2cda6085be

Alpha architecture:

    http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0-2woody0_alpha.deb
      Size/MD5 checksum: 56840 8d84dd61b7002fbb5f5ff1411345cdf6

ARM architecture:

    http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0-2woody0_arm.deb
      Size/MD5 checksum: 44604 af22b10857060a0fe0f1db651ea54689

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0-2woody0_i386.deb
      Size/MD5 checksum: 43106 af2b3c3a8a18d71481fbadeef60846f8

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0-2woody0_ia64.deb
      Size/MD5 checksum: 74424 96904451a1a06e22d4fcee797dc68450

HP Precision architecture:

    http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0-2woody0_hppa.deb
      Size/MD5 checksum: 44432 70d55071bbdf08f2d3265da85cb43458

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0-2woody0_m68k.deb
      Size/MD5 checksum: 41598 d25cce8dcfed54f7f9b62e7764775907

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0-2woody0_mips.deb
      Size/MD5 checksum: 52646 2edd9efcca5f608c09d6903335d7dc14

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0-2woody0_mipsel.deb
      Size/MD5 checksum: 52290 5f019a902c94b8d4c0a6b9781afa2664

PowerPC architecture:

    http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0-2woody0_powerpc.deb
      Size/MD5 checksum: 43316 df4f00d5ccc813274a3936455ff39b70

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0-2woody0_s390.deb
      Size/MD5 checksum: 43812 9e6f27fb09a8e1152db4238eb851b659

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0-2woody0_sparc.deb
      Size/MD5 checksum: 51388 d98ca0bc6bbeecb8d19e630528c6fd9f



Debian Security Advisory DSA 931-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
January 9th, 2006 http://www.debian.org/security/faq


Package : xpdf
Vulnerability : buffer overflows
Problem type : remote
Debian-specific: no
CVE IDs : CAN-2005-3191 CAN-2005-3192 CAN-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628 Debian Bug : 342281

"infamous41md" and Chris Evans discovered several heap based buffer overflows in xpdf, the Portable Document Format (PDF) suite, that can lead to a denial of service by crashing the application or possibly to the execution of arbitrary code.

For the old stable distribution (woody) these problems have been fixed in version 1.00-3.8.

For the stable distribution (sarge) these problems have been fixed in version 3.00-13.4.

For the unstable distribution (sid) these problems have been fixed in version 3.01-4.

We recommend that you upgrade your xpdf package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody


Source archives:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf_1.00-3.8.dsc
      Size/MD5 checksum: 706 f8091cb4e0b0c7baa8ccc4ee75a50699
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf_1.00-3.8.diff.gz
      Size/MD5 checksum: 11832 ab0665a0fa767785037ceff313cbc1b3
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf_1.00.orig.tar.gz
      Size/MD5 checksum: 397750 81f3c381cef729e4b6f4ce21cf5bbf3c

Architecture independent components:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-common_1.00-3.8_all.deb
      Size/MD5 checksum: 38826 43072ed4680dab2c7d68eec7b3f7c45a
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf_1.00-3.8_all.deb
      Size/MD5 checksum: 1286 7bd55048fc7aab6c9c35f65d472932da

Alpha architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.8_alpha.deb
      Size/MD5 checksum: 571434 7be66f32548c87a66c2353d976a99c36
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.8_alpha.deb
      Size/MD5 checksum: 1046964 c83387b2ce2c92faa2cbbc86f2d9a9a8

ARM architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.8_arm.deb
      Size/MD5 checksum: 487502 655007df84b968ec59de01638b77f0b8
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.8_arm.deb
      Size/MD5 checksum: 887368 a2d7e4052bf2a5c4a495c4e45dedf89b

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.8_i386.deb
      Size/MD5 checksum: 449748 0ae0c17cc4624b254b2aeac09c995d6f
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.8_i386.deb
      Size/MD5 checksum: 828498 530637087a864c6def87e31283bdeceb

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.8_ia64.deb
      Size/MD5 checksum: 683068 19ecb0905f8636e67bf7238c10f59ad5
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.8_ia64.deb
      Size/MD5 checksum: 1230046 ed52eb1ba803c65bed5b9b82ec551eef

HP Precision architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.8_hppa.deb
      Size/MD5 checksum: 564570 e375463f1a090ee04616a2a28d074792
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.8_hppa.deb
      Size/MD5 checksum: 1034076 c7baa8decb624ae001b8325c426c3e83

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.8_m68k.deb
      Size/MD5 checksum: 427756 e516e992cf634de082e9261fec596417
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.8_m68k.deb
      Size/MD5 checksum: 795168 5315ec1734af63b31df537992fd575d7

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.8_mips.deb
      Size/MD5 checksum: 555626 38b3797dc8685b374bfa4d5b8310e002
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.8_mips.deb
      Size/MD5 checksum: 1017302 f1420c53961b3574c404e3dcee80e633

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.8_mipsel.deb
      Size/MD5 checksum: 546712 be27f108ed722e04bee9473fb463a749
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.8_mipsel.deb
      Size/MD5 checksum: 999554 d8983b16cb67d5b5da734e8a166079b1

PowerPC architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.8_powerpc.deb
      Size/MD5 checksum: 470466 c90999ac3ffef0f1ca9907ec0c52e8ca
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.8_powerpc.deb
      Size/MD5 checksum: 860678 1b79e9b04f6b86cee3365c27c99b8c8a

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.8_s390.deb
      Size/MD5 checksum: 430408 09493b1bae3177137a922adbaee7af25
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.8_s390.deb
      Size/MD5 checksum: 786644 98062cef2cfd5f78eba94f92f7ffc7ec

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.8_sparc.deb
      Size/MD5 checksum: 444146 9bb3e73108672a45c87eb172b30b645e
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.8_sparc.deb
      Size/MD5 checksum: 810204 53735cf450d1ff09449dd4e744e31f4a

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf_3.00-13.4.dsc
      Size/MD5 checksum: 781 df2be00a261c47ed25cbf00bdcefcc32
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf_3.00-13.4.diff.gz
      Size/MD5 checksum: 50734 3018a9155bbcf704f47132bbefddd5b5
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf_3.00.orig.tar.gz
      Size/MD5 checksum: 534697 95294cef3031dd68e65f331e8750b2c2

Architecture independent components:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-common_3.00-13.4_all.deb
      Size/MD5 checksum: 56504 333976022e4bd6b1a241844231f2db30
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf_3.00-13.4_all.deb
      Size/MD5 checksum: 1284 1b077a992654b8df5727d844deb84e0c

Alpha architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_3.00-13.4_alpha.deb
      Size/MD5 checksum: 802112 93e96a4213f4966d8c0bb2c1e34b572d
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_3.00-13.4_alpha.deb
      Size/MD5 checksum: 1528190 5db2e3cd7ab5f2865d5303163c3d08a7

AMD64 architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_3.00-13.4_amd64.deb
      Size/MD5 checksum: 667754 df5e85b58bcb2f7b86837e7a79b745f9
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_3.00-13.4_amd64.deb
      Size/MD5 checksum: 1273734 5554c8f473a892cc8478f50bc1dd96dd

ARM architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_3.00-13.4_arm.deb
      Size/MD5 checksum: 674458 b419a39cb5b1bbaefe52c51f163913d5
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_3.00-13.4_arm.deb
      Size/MD5 checksum: 1279040 fe5af7d7209bb14e865404ea695a6df3

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_3.00-13.4_i386.deb
      Size/MD5 checksum: 656804 e319b835c10f76ad7946b74da24ba1bf
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_3.00-13.4_i386.deb
      Size/MD5 checksum: 1242164 731e556748f3f84465bd6537462fde03

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_3.00-13.4_ia64.deb
      Size/MD5 checksum: 950974 fe4f3be5aa05772806309faaa3847db3
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_3.00-13.4_ia64.deb
      Size/MD5 checksum: 1801950 27c19b5813e7d2aa34aca9847c277b40

HP Precision architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_3.00-13.4_hppa.deb
      Size/MD5 checksum: 832646 a2504b353573d384d443e923782775f1
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_3.00-13.4_hppa.deb
      Size/MD5 checksum: 1580478 72266677b36f9ec9ab2c2bcac1dfe7ac

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_3.00-13.4_m68k.deb
      Size/MD5 checksum: 585736 e1331547251b0d5eba96c68e6665abf2
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_3.00-13.4_m68k.deb
      Size/MD5 checksum: 1116746 46d969a98302c1b49b5e9a355047adfc

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_3.00-13.4_mips.deb
      Size/MD5 checksum: 807800 d1acd349bc0a932ea3467db9796919f5
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_3.00-13.4_mips.deb
      Size/MD5 checksum: 1524848 685d65d2a07676b55fa3abd8505018a9

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_3.00-13.4_mipsel.deb
      Size/MD5 checksum: 798090 18503fbab79be783005bed35d4cdb02d
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_3.00-13.4_mipsel.deb
      Size/MD5 checksum: 1503796 aaa4b1de4370d52cc2b3e595542f82c3

PowerPC architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_3.00-13.4_powerpc.deb
      Size/MD5 checksum: 694126 08e64354f30b1bd573092925b894c77f
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_3.00-13.4_powerpc.deb
      Size/MD5 checksum: 1313048 5f39d0ffe44186db884a7c1115704666

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_3.00-13.4_s390.deb
      Size/MD5 checksum: 630774 8b48412164ae96066c61399a5c7b3cd7
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_3.00-13.4_s390.deb
      Size/MD5 checksum: 1198670 6b837427a05f0b19630197183c9c50f1

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_3.00-13.4_sparc.deb
      Size/MD5 checksum: 626394 0bbb59b11b9d11f9129fbd475e3ab186
    http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_3.00-13.4_sparc.deb
      Size/MD5 checksum: 1181726 a523c04a7ae1c3b8fc24c29f46d3c589

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 932-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
January 9th, 2006 http://www.debian.org/security/faq


Package : xpdf
Vulnerability : buffer overflows
Problem type : remote
Debian-specific: no

CVE IDs : CVE-2005-3191 CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628 Debian Bug : 342281

"infamous41md" and Chris Evans discovered several heap based buffer overflows in xpdf, the Portable Document Format (PDF) suite, that can lead to a denial of service by crashing the application or possibly to the execution of arbitrary code. The same code is present in kpdf which is part of the kdegraphics package.

The old stable distribution (woody) does not contain kpdf packages.

For the stable distribution (sarge) these problems have been fixed in version 3.3.2-2sarge3.

For the unstable distribution (sid) these problems have been fixed in version 3.5.0-3.

We recommend that you upgrade your kpdf package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics_3.3.2-2sarge3.dsc
      Size/MD5 checksum: 1317 883261a391a85afb038bb7ea2150ecd7
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics_3.3.2-2sarge3.diff.gz
      Size/MD5 checksum: 159106 1169ddf001b77319f2859c87ce482bc4
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics_3.3.2.orig.tar.gz
      Size/MD5 checksum: 7661488 6d0bb2c6e2e2f666d123778fbc520317

Architecture independent components:

    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics_3.3.2-2sarge3_all.deb
      Size/MD5 checksum: 17620 9c3f491df5dcb49a81b26062df50ea98

Alpha architecture:

    http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 92500 5a48e6e37e72346756b6153dea64cb03
    http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 109094 2c0eef65ec4eeb3ed658efdbfb8783e8
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-dev_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 64974 7eb446cb432616cc6caa48b3eef3e6b1
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-kfile-plugins_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 276194 7f1b3ceabb2e6bfbd3bf6286833e69a8
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdvi_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 497566 9a2bb4bb6e4bc14a4e37d38791d7eb21
    http://security.debian.org/pool/updates/main/k/kdegraphics/kfax_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 149330 5ee25f6cbc684023ed30bf965d86ada8
    http://security.debian.org/pool/updates/main/k/kdegraphics/kgamma_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 92958 4170a1ba0e59a2af45780bb4f45b5763
    http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 245964 8377a72e9f7739c74cdcb22326d48e0f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 159532 0edc3bcc04d6f54be88002bbb713931a
    http://security.debian.org/pool/updates/main/k/kdegraphics/kmrml_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 244546 c2095b637627385e2630892c60b0fbb9
    http://security.debian.org/pool/updates/main/k/kdegraphics/kolourpaint_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 831188 c9c211bd627e7466a9ac9601b3adbfa6
    http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 774074 77de1419dadbe632654580ba685bf0f8
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpdf_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 534432 f5986e5949252346fcc57e5f0732b3c5
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpovmodeler_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 2317542 fb2095e8e363d4d79953a899fafa6296
    http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 63414 0a3e195e572178fc40f0d1fd0e54077d
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 103090 acfc3b3d030f748a5b7e1e8247d90938
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksvg_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 1357640 bba569d594464e09d8389f53580a562c
    http://security.debian.org/pool/updates/main/k/kdegraphics/kuickshow_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 483788 bf0e57bf80bafa78ece4734d16e5c720
    http://security.debian.org/pool/updates/main/k/kdegraphics/kview_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 695424 47141779a11b3ed4d52373d21f3d0199
    http://security.debian.org/pool/updates/main/k/kdegraphics/kviewshell_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 183880 85eaebeedbb011b5ba8d237c9a773363
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 33092 294ab0b1581c856d3a05dfb4d771772d
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_3.3.2-2sarge3_alpha.deb
      Size/MD5 checksum: 148226 51ca1b3297696bbe103b34c1e692f10e

AMD64 architecture:

    http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 87972 60ca2731887c79514aad0535af7ce5a6
    http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 100302 afa754568e0f5e3b1b08208c070ea80b
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-dev_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 64970 13ead70c497d1abe4d8e0b64054673e0
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-kfile-plugins_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 252140 4d3a0b70d7a21e29b598a8fdfa078e1f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdvi_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 485710 ec9300643ce00f9c6194f35d5935b7d0
    http://security.debian.org/pool/updates/main/k/kdegraphics/kfax_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 144900 a98182043ec1e0ddf008a94f8e9f6b39
    http://security.debian.org/pool/updates/main/k/kdegraphics/kgamma_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 87874 459b38e1e638dcd1a402f677b0d72ddb
    http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 234010 d591becbe09936e1d6ca04c2afc91fce
    http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 143496 ffd0abcf446a1a5df52ff1d3034525a0
    http://security.debian.org/pool/updates/main/k/kdegraphics/kmrml_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 233908 374d3456398f6c282c2e1f038d180872
    http://security.debian.org/pool/updates/main/k/kdegraphics/kolourpaint_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 767986 448ef8aa521118792792f0f7c9743497
    http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 759638 ba8104609502f55782e5b1e88a177c93
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpdf_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 485858 7cebf4d6a0c863aee628c0a13ca57435
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpovmodeler_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 2233414 a4d0efeb95af95c396eecf9d34645c42
    http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 63094 c14bc4abc51418dd6a43c4925b7ab8ff
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 99826 e6b6c796dc699297438449788f1385bd
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksvg_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 1223444 7b995aadba63947f3c16c26d60af7c04
    http://security.debian.org/pool/updates/main/k/kdegraphics/kuickshow_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 477640 99e831229b3434c714bfbfe3b06d67c6
    http://security.debian.org/pool/updates/main/k/kdegraphics/kview_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 678640 ed56083f0c5d480e6b030bbe46cf39c5
    http://security.debian.org/pool/updates/main/k/kdegraphics/kviewshell_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 173234 ea854daab244c805f22fab1ef00c4501
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 33092 8a0f5e5ccdec0da1715a228d6e918be7
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_3.3.2-2sarge3_amd64.deb
      Size/MD5 checksum: 140160 943f60daa34a3022cdf1e61a74be6727

ARM architecture:

    http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 82404 7cde7db938cb953a501d3042a1533859
    http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 88398 02d60aceb08f53faf77f10ae59aa170f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-dev_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 64994 8039a436f88742aaef37358b86a2522b
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-kfile-plugins_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 222994 b8e5d381f364876dd65d7f90eeb432f6
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdvi_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 471280 676d721e8731aa075dcb33411fe39e15
    http://security.debian.org/pool/updates/main/k/kdegraphics/kfax_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 137266 c27349004cbc42a68a0e62f622ee6f75
    http://security.debian.org/pool/updates/main/k/kdegraphics/kgamma_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 84972 260016c06dde14b7e4e6c4dc9da6b1c7
    http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 217514 91a5acde5bb21adc9e197f78f30c1bbd
    http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 127548 ee8f84522aa0ea8fe92653901d40f3ab
    http://security.debian.org/pool/updates/main/k/kdegraphics/kmrml_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 210264 4f63ea87da3f3a63d6fed1935593348f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kolourpaint_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 712230 d58a0fcd3ea98346d14bc9845f3ad9bd
    http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 739682 97d75f7b75ff91a8332d59045de83dc1
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpdf_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 424114 1152a75238667a9593905bbd40038be1
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpovmodeler_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 2095184 7ac33f99bea7667b03ab3c1c86870c67
    http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 59256 deed7c4085f53831f63191526d5390e6
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 93348 40f906de514a2593d7dad7ba7f13210a
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksvg_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 1310486 d97b0bb5e736350a506f0a64dd57e75d
    http://security.debian.org/pool/updates/main/k/kdegraphics/kuickshow_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 465466 3f9d7de13c7aeeb827aef0c7bfb994cc
    http://security.debian.org/pool/updates/main/k/kdegraphics/kview_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 641312 480c12a4a3d0ca2195bb9ae374d3e582
    http://security.debian.org/pool/updates/main/k/kdegraphics/kviewshell_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 155152 8798f061114f9a6fb019d20fcdcae533
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 33094 b2469fd24237631256b1d5e5efe8f733
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_3.3.2-2sarge3_arm.deb
      Size/MD5 checksum: 124204 0073a82d7a0ada3716163d082a99a18a

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 85920 1f8dccfa7b64c34f08cfab3d6c88a2d5
    http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 95446 fc147588e733eb66d6a2614b3da77560
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-dev_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 64968 95f5c54d6b0d7205ee7580abd066f37d
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-kfile-plugins_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 222032 d91de9dd780ff410d01627b8062fd23f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdvi_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 483864 df6ef6393a0aa1694e0767a425da1c57
    http://security.debian.org/pool/updates/main/k/kdegraphics/kfax_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 140482 0ee2d3187a06af8e7e1f43ea90886c01
    http://security.debian.org/pool/updates/main/k/kdegraphics/kgamma_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 85876 6deee36ae927df2b9c43075946d0c363
    http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 227452 7a03c8c5ae46d8776538555b67ebddd8
    http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 135884 52eb8e5cbccf5952cacffab1ab8bb6ee
    http://security.debian.org/pool/updates/main/k/kdegraphics/kmrml_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 221742 f994714fee52570758cca71a04099870
    http://security.debian.org/pool/updates/main/k/kdegraphics/kolourpaint_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 748352 aff6500c8e7b6347cb2cfce12e761318
    http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 750644 8c662c18ac1d5234e99b7ac304570fa6
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpdf_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 452124 ea5f910e36dd17810d01e0ede44187f1
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpovmodeler_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 2205646 62e1fd98168e576ae78986e7cf88fadf
    http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 62548 0866b72eb70749a328304996b5da6245
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 97222 f4e1290335928e9b76b2715135a23516
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksvg_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 1220820 c86f6657d183e99e8a69a11c741543c7
    http://security.debian.org/pool/updates/main/k/kdegraphics/kuickshow_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 472032 7558051b7f3432ae2b5088c79afbc906
    http://security.debian.org/pool/updates/main/k/kdegraphics/kview_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 643484 3d7111575de51a703afefc6de1b64d59
    http://security.debian.org/pool/updates/main/k/kdegraphics/kviewshell_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 166918 bf6a7f7b5018c5e9d3fbf8c0804bc4a0
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 33098 693fd2750e0678a95ab13df3d443c320
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_3.3.2-2sarge3_i386.deb
      Size/MD5 checksum: 134532 09327e3fa166ffd9e4606338b936ee86

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 102406 51fdcb159c85449f909f7d74c20f0aa1
    http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 117808 017a9c64eaff071bbe3e91d0c8bdc91f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-dev_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 64968 2bfd3bf06bf9a4ef822a7289fbd7cc43
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-kfile-plugins_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 322930 3997e095f2530c1bbcd229ecb9836f24
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdvi_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 540612 5258387412c170df5f9fa19fcd8dfaaf
    http://security.debian.org/pool/updates/main/k/kdegraphics/kfax_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 160086 d15976032f48a9e120c6b56776f8342f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kgamma_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 103936 21d42fecd9a1fceac1cbef91cbb68c96
    http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 280826 d8242161f03e63ba52162775e62ad101
    http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 176204 21237877e70bc93a8371ab0aa5faf220
    http://security.debian.org/pool/updates/main/k/kdegraphics/kmrml_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 277288 8ca48ad52ffae22c953b88d44abfdd1f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kolourpaint_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 888426 edce61c7a9a65ef65c9dd08d2ea83fd7
    http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 799002 9abe5f38e0781adbf404ec1105c0e9df
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpdf_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 629398 801d1509b6dccd250d5dc3757ecadee8
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpovmodeler_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 2537880 4e7c3dba6e19729547b22a8c7dcfa0b7
    http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 67780 686786077def8ae34c3132188521993e
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 108160 2a09dbbe80ea1624d9a1a2b1b261ab7a
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksvg_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 1417144 cc3cfe3e709d5862283e580a0820f283
    http://security.debian.org/pool/updates/main/k/kdegraphics/kuickshow_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 501596 2a80a9c5248498a866672d85eca0a0f5
    http://security.debian.org/pool/updates/main/k/kdegraphics/kview_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 730722 1b0750ba641b4ccbb1926e1446bbc9eb
    http://security.debian.org/pool/updates/main/k/kdegraphics/kviewshell_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 205764 56d117733da1be89fd8525d491c95a16
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 33084 d31c892ef95d30f0f8359df61b0481f4
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_3.3.2-2sarge3_ia64.deb
      Size/MD5 checksum: 170504 4a0acca19f8752621874046503a3f9df

HP Precision architecture:

    http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 93242 1679b3c9cf120b5b56d883cead2f544f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 101232 7e5c1f2c3885fea8f87f9fec1028b888
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-dev_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 64986 55bd18e636b2485314120388d3ed4a73
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-kfile-plugins_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 270922 e7f5050518729caa3ae6925227f023ab
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdvi_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 505386 84e47f0d34928923f2c2e0ae1ccf5487
    http://security.debian.org/pool/updates/main/k/kdegraphics/kfax_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 146200 ebb3cd2ddf9afcfa113d1b0d60dd256e
    http://security.debian.org/pool/updates/main/k/kdegraphics/kgamma_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 93228 6a20a730277fa505d4e27495fd4b3424
    http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 250216 f42a8d0d6d594a601a362ea0f738b185
    http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 146362 b3529d2098e96ed4f19d31d17865c2e2
    http://security.debian.org/pool/updates/main/k/kdegraphics/kmrml_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 246034 32b469be4a18a7cfe1c9a65aead8a533
    http://security.debian.org/pool/updates/main/k/kdegraphics/kolourpaint_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 796926 8c3f9a89fc543ec69a12a659c7dcfbe3
    http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 757492 478d712e3bade83d527140c8fa2821e8
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpdf_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 535250 f726eb1a2a2705c84c48bbf1abd268ab
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpovmodeler_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 2371576 8ac6f9581c28c9252eac55ed6c09385a
    http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 61422 8d6b0374dea1c1efb042fc5e5edcf0c7
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 99192 2aad4f1b8942ade1bb889a2ee10746b0
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksvg_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 1563008 a8203d54a3f59af2739fb75d6cd90049
    http://security.debian.org/pool/updates/main/k/kdegraphics/kuickshow_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 485056 918c0d745609e787bc58de530c6abaff
    http://security.debian.org/pool/updates/main/k/kdegraphics/kview_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 700886 4c84103b7cea6763a57fa608e094c69e
    http://security.debian.org/pool/updates/main/k/kdegraphics/kviewshell_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 183850 a03abfea16b0a0946221d473ddd796ae
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 33092 7ba9eb3e7b707decced38a098b067e26
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_3.3.2-2sarge3_hppa.deb
      Size/MD5 checksum: 148004 90d49f8cef0520eb1c022918dd429a99

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 85370 03208de88212ee8e3c433c6c69673877
    http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 91096 b75db8b3d6a30dd952ae78758510b296
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-dev_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 65010 82d5536cd79f3bac8a4b483e5571eb23
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-kfile-plugins_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 229546 7b682eb8db73e63407bff2b29f6ffb4c
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdvi_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 476952 fe27e5395f5ea231f77dd1abbb74c7e5
    http://security.debian.org/pool/updates/main/k/kdegraphics/kfax_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 138540 acfa677ff78e256cd8e085cf75d16d97
    http://security.debian.org/pool/updates/main/k/kdegraphics/kgamma_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 85196 988a2fdd5de86648a524b8dec7173ea9
    http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 229420 9c328ece393d69c84db7304c8260fdb5
    http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 128626 7e1f68605fc327a146fc851894004ead
    http://security.debian.org/pool/updates/main/k/kdegraphics/kmrml_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 223556 941a4f007761da9124029e68431fff9f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kolourpaint_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 705084 2439ec0bc20dd2c60022ead6b118ab5e
    http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 743170 832c8961b239bcf874a90c5ac3fd14f1
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpdf_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 447448 c38dcc1879650cd3bcdae5484631c281
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpovmodeler_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 2148768 0148565136745e0309b056cfdc77874e
    http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 61280 cd7c09ba73c52e33d77a277833c28c24
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 96636 a1d244a87142ca153826f09623196b4b
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksvg_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 1315968 b3dbc843325ecc8b4f23dfbdbd04da35
    http://security.debian.org/pool/updates/main/k/kdegraphics/kuickshow_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 475814 5adbdb5ea44cc6e774d06269f0123014
    http://security.debian.org/pool/updates/main/k/kdegraphics/kview_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 682572 22deaf8ff281062b43f45a50e8e52c53
    http://security.debian.org/pool/updates/main/k/kdegraphics/kviewshell_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 166284 c772a82c000c4faed889bc1572907198
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 33100 117362ae11ee0926fe62d4251e45b9c8
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_3.3.2-2sarge3_m68k.deb
      Size/MD5 checksum: 133970 cc9320ce6077055fbef7f357baccb36b

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 79726 8ef8a7f51e426bab0c79c893b17b44e8
    http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 102528 96063761ffb299e8663aabdc1dc830dc
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-dev_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 64974 8632642c61fd3e514d79c53c440b0157
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-kfile-plugins_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 217900 9f068d5736f65a59d58843ef3719914a
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdvi_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 461010 44d402c815ef59102a9d1f6a1922e5c7
    http://security.debian.org/pool/updates/main/k/kdegraphics/kfax_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 140512 5dede51b9875eb9627fe84508f3ff4cc
    http://security.debian.org/pool/updates/main/k/kdegraphics/kgamma_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 81838 109efab6c00ef662a00ea4f41e7a0069
    http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 215748 ad22b37ce1d1ffef16c7cefde0ffd7d5
    http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 146198 b9c2cba23d25f1bf3bdbbdbeaffeadbd
    http://security.debian.org/pool/updates/main/k/kdegraphics/kmrml_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 204014 83a4764d81ef5ee7fd7fe890e23c9939
    http://security.debian.org/pool/updates/main/k/kdegraphics/kolourpaint_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 787984 c020ab67521dcaca8e49c0bae8216b28
    http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 756170 a1d1e3e06e5eed39f29d03ce572d5771
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpdf_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 455814 8b5479eb17b3ea84f56d35f3d1992b43
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpovmodeler_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 2057362 71d2689d1981f83a6f8ff468d69cc0ce
    http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 59274 1cf3d865852bbb4965229a95c78a52b1
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 97718 1e697e2bf6d19eb71efe3350e63a8ddc
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksvg_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 1127026 0bc2eab83b2cc242ecaebba694289235
    http://security.debian.org/pool/updates/main/k/kdegraphics/kuickshow_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 463634 9bee129653701a27a392f118c2e2fc28
    http://security.debian.org/pool/updates/main/k/kdegraphics/kview_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 649718 dfa1146d95d54eab9f51301b5f4a28eb
    http://security.debian.org/pool/updates/main/k/kdegraphics/kviewshell_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 156802 9126d5152c28c24889e5269a9adde39f
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 33094 9875a23d1590f9016f8a8bb450bf3a6d
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_3.3.2-2sarge3_mips.deb
      Size/MD5 checksum: 124558 eb55d58484f5ecdc59b2c6eb3c47a805

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 79070 ea21445ae1aef174831e9534db959308
    http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 101596 ed6adfa04d7c4c2c4d002cb5a278583f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-dev_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 64972 434438d23e8b0ccc9c38dcc699164e53
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-kfile-plugins_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 215850 82f87ff8b5520823f839092cef2356b0
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdvi_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 459624 e577a100b76fe42784b6dcc35f5046b6
    http://security.debian.org/pool/updates/main/k/kdegraphics/kfax_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 139548 4e829465b219a4d56b86b687b33d5df0
    http://security.debian.org/pool/updates/main/k/kdegraphics/kgamma_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 81370 937ce8392adf141a1f79af0dfc80e499
    http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 213272 bf8c38a0afb9c9f966cd00bc42a4d4c0
    http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 144554 ca97a5ce320d502c908580bf0bcc4033
    http://security.debian.org/pool/updates/main/k/kdegraphics/kmrml_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 201638 45e29afdb0ab123d149a739520f1c32c
    http://security.debian.org/pool/updates/main/k/kdegraphics/kolourpaint_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 785228 9902604485b4e9633f3e36f01fc8f920
    http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 754276 b1be56ab0f23c02f6aa29b1276a3d917
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpdf_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 446852 99ac862679028515f5f715c047719e2f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpovmodeler_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 2046016 8c9919a529a79538629221bf98e37b61
    http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 59068 5c2aad04a5f5265034faca5d8fd82c64
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 97168 498f72e93b50faefb22a9ca9335193a1
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksvg_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 1101768 8cb8b46c5207d06911d77d3178f9a4f8
    http://security.debian.org/pool/updates/main/k/kdegraphics/kuickshow_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 461868 4792dcccbb8fcda14f2eb601692e2c01
    http://security.debian.org/pool/updates/main/k/kdegraphics/kview_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 647264 9a340b39b3b2ce04d2ed0cfe240bca8b
    http://security.debian.org/pool/updates/main/k/kdegraphics/kviewshell_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 154678 79ac08fbe101be7efe6e3471d5fb787d
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 33100 3c5ab7cfcd4fce969cd6066c9a9b31d9
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_3.3.2-2sarge3_mipsel.deb
      Size/MD5 checksum: 122404 3d2878bbacb4862c25b73d6c71a6f649

PowerPC architecture:

    http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 84678 c40175b83c13941983dd07e2ec17bdda
    http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 94604 720a71fb1d61f0f16a919926a996ebb8
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-dev_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 64990 6b4a44cd20244525cf7ed61ef63da641
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-kfile-plugins_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 249552 78b554c699af127b69b39b49ac4c180b
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdvi_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 474624 b38b81bf2974e7d72095eb84b00de64d
    http://security.debian.org/pool/updates/main/k/kdegraphics/kfax_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 140692 cfb9009df7900bfbfdbc39f7523fc587
    http://security.debian.org/pool/updates/main/k/kdegraphics/kgamma_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 85162 130665aee67bc16e9be3ca54a3762862
    http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 224802 60d742b0d2303bc63b1849dae1397581
    http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 132544 6f6bd6ab29fcbf3311f1015a35aec78f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kmrml_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 222198 993f41bfbccf6481ca327f2e8dc3c20d
    http://security.debian.org/pool/updates/main/k/kdegraphics/kolourpaint_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 725370 0f9836476933dbe813ea538c5d052cd8
    http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 744166 608091d9c9b27dde512ac47b6947d626
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpdf_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 467524 46073d588f362de378386698c39c95c7
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpovmodeler_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 2142348 9e3bfa19052e85058e4fa31a6298f0a0
    http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 61046 b4d834e88473d8776d305e0448ebe476
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 95544 977ad02f98bcf9731dc2fca1ad1eebc5
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksvg_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 1191074 8fb34b60f7d2fb4484da19634fb83ca2
    http://security.debian.org/pool/updates/main/k/kdegraphics/kuickshow_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 470198 4b8539d72cc39d7e1939f526c765c8b7
    http://security.debian.org/pool/updates/main/k/kdegraphics/kview_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 676288 94b7d619e9eb8ecd0cfb0bb3be8ae4ba
    http://security.debian.org/pool/updates/main/k/kdegraphics/kviewshell_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 161756 d59119ba3140c9e41aaafc0c16af7c63
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 33098 980dc1cabb51360efe73cb00e37b3ae1
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_3.3.2-2sarge3_powerpc.deb
      Size/MD5 checksum: 132262 66496d5de6353b80c647b32f4c18ef8b

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 89880 99dff2d06524836ab720abd471999d66
    http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 98316 893cdc7754cae8a00ee116fcdbf9fb73
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-dev_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 64972 bd908c097ca775f368b3b87db83ada06
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-kfile-plugins_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 236504 603bbb604f6cf907a31b29e8c0438351
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdvi_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 484950 957eae05f1920388664d5db6b42ae80f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kfax_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 145404 061c37b7acbe75a09bc6a983e24eca22
    http://security.debian.org/pool/updates/main/k/kdegraphics/kgamma_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 87136 4c9745eccb44c21a609b5ffaf768a26a
    http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 244122 9b7d68631bccc0af9b79214ec7d3e8d5
    http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 140834 3230bfe76d926783b336e0b424685896
    http://security.debian.org/pool/updates/main/k/kdegraphics/kmrml_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 239688 42a8e7956bfd756ffba9e7bcd5314e8c
    http://security.debian.org/pool/updates/main/k/kdegraphics/kolourpaint_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 765928 3a38ceb3563211404e5534bc691b887c
    http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 755596 40d810e17c05d8ff21d76550c0e5cc3a
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpdf_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 496480 0a48f1beb7a4e03425783a909bc88ef0
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpovmodeler_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 2195656 c26f4c732fe8393766eccff6a845e938
    http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 63070 ea7b94304194ffa4d0bbd708f84737db
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 100742 b5f3558b9d1e30038dabbf0f4b0ba36f
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksvg_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 1192548 db812a33636b9a681083895da654d9ac
    http://security.debian.org/pool/updates/main/k/kdegraphics/kuickshow_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 481678 93c6f759b0cc1965dbb93536dc255dac
    http://security.debian.org/pool/updates/main/k/kdegraphics/kview_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 682752 519c3b25389f72155e005e12a6989972
    http://security.debian.org/pool/updates/main/k/kdegraphics/kviewshell_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 176666 194c2424523d195373e0d4177b2c1ded
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 33090 8882749212a6e977b9eec3e9fb595f50
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_3.3.2-2sarge3_s390.deb
      Size/MD5 checksum: 142212 c95e8e7fe4365be445daead6d366c5ac

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 82296 25f2b504c0cc096508d2565f38db6f28
    http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 90720 d8a9ee57d67676bdd2637a40b941b8cb
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-dev_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 64980 967f32d4dc6fc6f5d9ff4ef838bae770
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics-kfile-plugins_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 219164 141a05361d233b94f81be5a802de14d9
    http://security.debian.org/pool/updates/main/k/kdegraphics/kdvi_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 477510 e71886db4ca53b2c23f421857844dc35
    http://security.debian.org/pool/updates/main/k/kdegraphics/kfax_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 137938 22442ddae2f20c3663c270541e9ba9c1
    http://security.debian.org/pool/updates/main/k/kdegraphics/kgamma_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 83210 abfc0612516de6079f6552f0dae1743f
    http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 223774 3b242e3415e216278bd5922d09cafa73
    http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 130520 171569986b9d5f75037fac7216f51014
    http://security.debian.org/pool/updates/main/k/kdegraphics/kmrml_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 213588 25bdfc45123cbcac842c5c01882c9551
    http://security.debian.org/pool/updates/main/k/kdegraphics/kolourpaint_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 714158 a4ba5b48aec9eaf736315dee410a53bc
    http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 744042 5894e3e97fc45d024219a9ff7e115854
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpdf_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 451392 de85d22d0d458866bdffba846d4accc2
    http://security.debian.org/pool/updates/main/k/kdegraphics/kpovmodeler_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 2142550 732f1d703ab5d8bba7345e50db66283c
    http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 60184 012973b512f9bdfbf15830812fc2b863
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 95092 766c1952f778a25f2aab9bd20964a676
    http://security.debian.org/pool/updates/main/k/kdegraphics/ksvg_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 1175232 7398855b8444740ce27001c427544406
    http://security.debian.org/pool/updates/main/k/kdegraphics/kuickshow_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 469204 b2e9d809bfc831938f3d080990b7efae
    http://security.debian.org/pool/updates/main/k/kdegraphics/kview_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 639718 6054b8e3f4c9142551a7fd114cb71bb6
    http://security.debian.org/pool/updates/main/k/kdegraphics/kviewshell_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 160294 c47394d5c4923c4a921fd400a8f107a0
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 33090 84d007d379333f73de214d1af530ea8d
    http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_3.3.2-2sarge3_sparc.deb
      Size/MD5 checksum: 128730 ef6ffca3dd504cd20953e7b5c0775014

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 933-1 security@debian.org
http://www.debian.org/security/ Michael Stone
January 9, 2006 http://www.debian.org/security/faq


Package : hylafax
Vulnerability : arbitrary command execution Problem-Type : local
Debian-specific: no
CVE ID : CVE-2005-3539

Patrice Fournier found that hylafax passes unsanitized user data in the notify script, allowing users with the ability to submit jobs to run arbitrary commands with the privileges of the hylafax server.

For the old stable distribution (woody) this problem has been fixed in version 4.1.1-4woody1.

For the stable distribution (sarge) this problem has been fixed in version 4.2.1-5sarge3.

For the unstable distribution the problem has been fixed in version 4.2.4-2.

We recommend that you upgrade your hylafax package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody


Source archives:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax_4.1.1-4woody1.dsc
      Size/MD5 checksum: 800 c9fd457c2782971a41c8328435b00ece
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax_4.1.1-4woody1.diff.gz
      Size/MD5 checksum: 116777 a2c212abd4a22134b673b3df345cb779
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax_4.1.1.orig.tar.gz
      Size/MD5 checksum: 1287689 1ed081750be70a800708699b7568e17e

Architecture independent components:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-doc_4.1.1-4woody1_all.deb
      Size/MD5 checksum: 318384 bf2352b27b55b6a6b66acd8184864ed5

Alpha architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.1.1-4woody1_alpha.deb
      Size/MD5 checksum: 556394 4acfe414a92ca39dd08d945927134fde
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.1.1-4woody1_alpha.deb
      Size/MD5 checksum: 1362704 7c5d2805a86e35f77fbdc320608eae21

ARM architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.1.1-4woody1_arm.deb
      Size/MD5 checksum: 445742 bd7631c263e79ba1fa222616fab0814c
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.1.1-4woody1_arm.deb
      Size/MD5 checksum: 1096024 a5bccc072005832e21a63af6cd355d80

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.1.1-4woody1_i386.deb
      Size/MD5 checksum: 462478 a1b1d1ffb63fa002602fa817985c10d4
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.1.1-4woody1_i386.deb
      Size/MD5 checksum: 1132898 f7f7933a5c26c69048628d20c6d8c6e2

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.1.1-4woody1_ia64.deb
      Size/MD5 checksum: 615750 9dd3e91618a0b7ff630fc8e73472be90
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.1.1-4woody1_ia64.deb
      Size/MD5 checksum: 1491998 fcfa52b30bf30151ce3d9c9c283738b2

HP Precision architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.1.1-4woody1_hppa.deb
      Size/MD5 checksum: 501764 532a01a8b1c509fff8640a63743f27b0
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.1.1-4woody1_hppa.deb
      Size/MD5 checksum: 1231584 2d3a3a7072c00e4fc71bb48045aac459

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.1.1-4woody1_m68k.deb
      Size/MD5 checksum: 451356 52f1e0515d0dc3f88b25de500aa8916c
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.1.1-4woody1_m68k.deb
      Size/MD5 checksum: 1100320 294aa660f86c7090eb0092755a788009

PowerPC architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.1.1-4woody1_powerpc.deb
      Size/MD5 checksum: 450900 349b2498e9ca56c63e219911b79e2953
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.1.1-4woody1_powerpc.deb
      Size/MD5 checksum: 1104560 48b998cf768a2ff858c948e5892b32c4

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.1.1-4woody1_s390.deb
      Size/MD5 checksum: 441344 51762120b318ed4c800a12e28242b5fa
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.1.1-4woody1_s390.deb
      Size/MD5 checksum: 1087136 ba81545268b85fa2783814ca8322d3b3

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.1.1-4woody1_sparc.deb
      Size/MD5 checksum: 433674 4786a267f600ba71c8f9c80a1f371439
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.1.1-4woody1_sparc.deb
      Size/MD5 checksum: 1082890 6bdc5a6359c4b953f5127031af69cbe2

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax_4.2.1-5sarge3.dsc
      Size/MD5 checksum: 746 1202e740bcb10a01977c98f6967d2da4
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax_4.2.1-5sarge3.diff.gz
      Size/MD5 checksum: 51922 e7d0531c64d48a9907e1a9c73b882bff
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax_4.2.1.orig.tar.gz
      Size/MD5 checksum: 1412035 05430e41a279d0fff6d6e4b444440829

Architecture independent components:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-doc_4.2.1-5sarge3_all.deb
      Size/MD5 checksum: 372578 70db2ce1b777e475cbe3335abc31a5a6

Alpha architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.2.1-5sarge3_alpha.deb
      Size/MD5 checksum: 373996 440dedf0a21a7ea99573ff9a0c8eb675
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.2.1-5sarge3_alpha.deb
      Size/MD5 checksum: 863606 cff4540597762579538d71e447b09f01

AMD64 architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.2.1-5sarge3_amd64.deb
      Size/MD5 checksum: 350894 a8040ccfde418e5cdf9f353f8b7471d9
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.2.1-5sarge3_amd64.deb
      Size/MD5 checksum: 801152 977bdc76fc44339599770227ba93befc

ARM architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.2.1-5sarge3_arm.deb
      Size/MD5 checksum: 342534 a79825720236fdafac2c6a7841b1fdec
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.2.1-5sarge3_arm.deb
      Size/MD5 checksum: 808884 10810889ed1c044fb1fec91af88184b2

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.2.1-5sarge3_i386.deb
      Size/MD5 checksum: 348172 0b3837a725542ab94fe7525beb54926d
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.2.1-5sarge3_i386.deb
      Size/MD5 checksum: 805786 05e61ba137faedbaf4a6d4b3faf0cce6

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.2.1-5sarge3_ia64.deb
      Size/MD5 checksum: 402530 a592a7397d1b75dc541584e3e10cbd23
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.2.1-5sarge3_ia64.deb
      Size/MD5 checksum: 924558 eb3701170b63c4ca617c93c74aa59f76

HP Precision architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.2.1-5sarge3_hppa.deb
      Size/MD5 checksum: 402386 7ec015549d9aa57e5a8e037deb6edb32
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.2.1-5sarge3_hppa.deb
      Size/MD5 checksum: 911520 948195eaaf686a5cffa3237df90d8504

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.2.1-5sarge3_m68k.deb
      Size/MD5 checksum: 345380 635f021fb40dbdd09c138608e64c309c
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.2.1-5sarge3_m68k.deb
      Size/MD5 checksum: 784438 3bc0f358363b448d3f8e72f95743a9fe

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.2.1-5sarge3_mips.deb
      Size/MD5 checksum: 352748 a65a3fcfffc4ec111fe4237a92734254
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.2.1-5sarge3_mips.deb
      Size/MD5 checksum: 836146 17146c51624cfc1f7c7eaac74c483f21

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.2.1-5sarge3_mipsel.deb
      Size/MD5 checksum: 350272 d5d512363681880db5e3d587021cab19
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.2.1-5sarge3_mipsel.deb
      Size/MD5 checksum: 831156 b06e0395c7b347093f2f9e1fe9673b91

PowerPC architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.2.1-5sarge3_powerpc.deb
      Size/MD5 checksum: 356672 778a434ea9e2e73d85ee8b7eaec4062c
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.2.1-5sarge3_powerpc.deb
      Size/MD5 checksum: 819686 4e82d570b0ffe822945814f90a5c175c

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_4.2.1-5sarge3_s390.deb
      Size/MD5 checksum: 339480 5afce0e8172e75b1b39d0086f69c5e0a
    http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_4.2.1-5sarge3_s390.deb
      Size/MD5 checksum: 767944 bc881199411dce80be644491b031af07

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 934-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
January 9, 2006 http://www.debian.org/security/faq


Package : pound
Vulnerability : several
Problem-Type : remote
Debian-specific: no

CVE ID : CVE-2005-1391 CVE-2005-3751 Debian Bug : 307852

Two vulnerabilities have been discovered in Pound, a reverse proxy and load balancer for HTTP. The Common Vulnerabilities and Exposures project identifies the following problems:

  • CVE-2005-1391: Overly long HTTP Host: headers may trigger a buffer overflow in the add_port() function, which may lead to the execution of arbitrary code.
  • CVE-2005-3751: HTTP requests with conflicting Content-Length and Transfer-Encoding headers could lead to HTTP Request Smuggling Attack, which can be exploited to bypass packet filters or poison web caches.

The old stable distribution (woody) does not contain pound packages.

For the stable distribution (sarge) these problems have been fixed in version 1.8.2-1sarge1

For the unstable distribution (sid) these problems have been fixed in version 1.9.4-1

We recommend that you upgrade your pound package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/p/pound/pound_1.8.2-1sarge1.dsc
      Size/MD5 checksum: 643 334d91f8800581281ab9c8bad5bbdbf4
    http://security.debian.org/pool/updates/main/p/pound/pound_1.8.2-1sarge1.diff.gz
      Size/MD5 checksum: 13242 9e404c899bfd5409610ed5f14345d341
    http://security.debian.org/pool/updates/main/p/pound/pound_1.8.2.orig.tar.gz
      Size/MD5 checksum: 140455 c9b0793bb4d57be2270093d79b13c019

Alpha architecture:

    http://security.debian.org/pool/updates/main/p/pound/pound_1.8.2-1sarge1_alpha.deb
      Size/MD5 checksum: 73284 0458e20d63c3f5f5788afe7564a385da

AMD64 architecture:

    http://security.debian.org/pool/updates/main/p/pound/pound_1.8.2-1sarge1_amd64.deb
      Size/MD5 checksum: 68652 01ae48ac313a8e533f32eec2f6f7a62f

ARM architecture:

    http://security.debian.org/pool/updates/main/p/pound/pound_1.8.2-1sarge1_arm.deb
      Size/MD5 checksum: 69072 73b7eb49a74c8a5ff6a8015cf9a0e45d

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/p/pound/pound_1.8.2-1sarge1_i386.deb
      Size/MD5 checksum: 68684 da43b8adaf115680c72d8f5dce9bc99f

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/p/pound/pound_1.8.2-1sarge1_ia64.deb
      Size/MD5 checksum: 80756 ec6d043c70e50e8ba492ef6a73a4cc18

HP Precision architecture:

    http://security.debian.org/pool/updates/main/p/pound/pound_1.8.2-1sarge1_hppa.deb
      Size/MD5 checksum: 70288 22fa75150b2253640667714cf6197567

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/p/pound/pound_1.8.2-1sarge1_m68k.deb
      Size/MD5 checksum: 65138 1de5e7b4492a51900e13f9a0f5decd18

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/p/pound/pound_1.8.2-1sarge1_mips.deb
      Size/MD5 checksum: 68586 3eb28320dc9229ee8cc08d2967e8ee9b

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/p/pound/pound_1.8.2-1sarge1_mipsel.deb
      Size/MD5 checksum: 68654 510807d792c96e8cc43edf72fcdcc243

PowerPC architecture:

    http://security.debian.org/pool/updates/main/p/pound/pound_1.8.2-1sarge1_powerpc.deb
      Size/MD5 checksum: 69218 d03e4cc71f99c2017a417cf8f073438c

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/p/pound/pound_1.8.2-1sarge1_s390.deb
      Size/MD5 checksum: 69268 dac44abdc98358ccc66c2c3f41bd0965

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 935-1 security@debian.org
http://www.debian.org/security/ Michael Stone
January 10, 2006 http://www.debian.org/security/faq


Package : libapache2-mod-auth-pgsql Vulnerability : format string vulnerability Problem-Type : remote
Debian-specific: no

CVE ID : CVE-2005-3656 Debian Bug : 307852

iDEFENSE reports that a format string vulnerability in mod_auth_pgsql, a library used to authenticate web users against a PostgreSQL database, could be used to execute arbitrary code with the privileges of the httpd user.

The old stable distribution (woody) does not contain libapache2-mod-auth-pgsql.

For the stable distribution (sarge) this problem has been fixed in version 2.0.2b1-5sarge0.

For the unstable distribution (sid) this problem will be fixed shortly.

We recommend that you upgrade your libapache2-mod-auth-pgsql package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5sarge0.dsc
      Size/MD5 checksum: 718 64320b302321622c1007810e18f6559a
    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5sarge0.diff.gz
      Size/MD5 checksum: 5031 400a8ca9689409375c56eafe38a957a7
    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1.orig.tar.gz
      Size/MD5 checksum: 15928 e2c032df0cd7e4a46381dcf6e488efe9

Alpha architecture:

    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5sarge0_alpha.deb
      Size/MD5 checksum: 20410 4e2c27c73a6ca3ca70713e31842c01ca

AMD64 architecture:

    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5sarge0_amd64.deb
      Size/MD5 checksum: 20040 9b542446b7336c88c2ffabdad730b74f

ARM architecture:

    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5sarge0_arm.deb
      Size/MD5 checksum: 18806 fcf3a9529b0b2af5a67237360c60f554

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5sarge0_i386.deb
      Size/MD5 checksum: 19406 f869e108de0839dcdcc2ee9459a8848d

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5sarge0_ia64.deb
      Size/MD5 checksum: 22282 018e612149c4d4a2cb139ee91b972cae

HP Precision architecture:

    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5sarge0_hppa.deb
      Size/MD5 checksum: 20686 dc84765b12cb57c7c2b68d9f875d8f07

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5sarge0_m68k.deb
      Size/MD5 checksum: 18944 ab3c2f517273d868d8dd3fcf9b78ea0a

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5sarge0_mips.deb
      Size/MD5 checksum: 18884 cfed58fc3dd4bc0e7b635f048b9ef317

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5sarge0_mipsel.deb
      Size/MD5 checksum: 18860 dc5b1b912b0fcf62d2a8edc7a5a9fa52

PowerPC architecture:

    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5sarge0_powerpc.deb
      Size/MD5 checksum: 20710 bdc297d45748433b2adcd3ac962612a3

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5sarge0_s390.deb
      Size/MD5 checksum: 19840 798db337084461ee60239274cf89f4e0

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5sarge0_sparc.deb
      Size/MD5 checksum: 19006 6cd6c8809599feec59df63281adcfd7b

These files will probably be moved into the stable distribution on its next update.


For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

Fedora Core


Fedora Update Notification
FEDORA-2005-000
2006-01-05

Product : Fedora Core 4

Name : ethereal

Version : 0.10.14
Release : 1.FC4.1
Summary : Network traffic analyzer

Description :
Ethereal is a network traffic analyzer for Unix-ish operating systems.

This package lays base for libpcap, a packet capture and filtering library, contains command-line utilities, contains plugins and documentation for ethereal. A graphical user interface is packaged separately to GTK+ package.


  • Thu Dec 29 2005 Radek Vokal <rvokal@redhat.com> 0.10.14-1.FC4.1
    • upgrade to 0.10.14

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

affe1eb1afcd43ff516e84d2d72ffc05 SRPMS/ethereal-0.10.14-1.FC4.1.src.rpm
0bad077e8bb64b17b8d46ff7b850981b ppc/ethereal-0.10.14-1.FC4.1.ppc.rpm
7c3487788fd67fcff93a8ab84b8a02d6 ppc/ethereal-gnome-0.10.14-1.FC4.1.ppc.rpm
269573f80ae4c2e6ed293679017e3c52 ppc/debug/ethereal-debuginfo-0.10.14-1.FC4.1.ppc.rpm
1f2d0fc4c51781edf58492848d275a30 x86_64/ethereal-0.10.14-1.FC4.1.x86_64.rpm
0596c4ecffad375876556769cba26662 x86_64/ethereal-gnome-0.10.14-1.FC4.1.x86_64.rpm
933603daec37ab30725cf822c015e911 x86_64/debug/ethereal-debuginfo-0.10.14-1.FC4.1.x86_64.rpm
b108f4faf613e9ec7ac1c872f6f6b9e6 i386/ethereal-0.10.14-1.FC4.1.i386.rpm
ceaa262d2bbd36d7e598f306d2ae85d8 i386/ethereal-gnome-0.10.14-1.FC4.1.i386.rpm
2889e71042aca4212a9f373e66f6a8e1 i386/debug/ethereal-debuginfo-0.10.14-1.FC4.1.i386.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.



Fedora Update Notification
FEDORA-2005-000
2006-01-05

Product : Fedora Core 4
Name : cups
Version : 1.1.23
Release : 15.3
Summary : Common Unix Printing System

Description :
The Common UNIX Printing System provides a portable printing layer for UNIX™ operating systems. It has been developed by Easy Software Products to promote a standard printing solution for all UNIX vendors and users. CUPS provides the System V and Berkeley command-line interfaces.


Update Information:

This update fixes the pdftops filter's handling of some incorrectly-formed PDF files. Issues fixed are CVE-2005-3625, CVE-2005-3626, and CVE-2005-3627.


  • Wed Jan 4 2006 Tim Waugh <twaugh@redhat.com> 1:1.1.23-15.3
    • Apply patch to fix CVE-2005-3625, CVE-2005-3626, CVE-2005-3627 (bug #176868).

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

b65393b6e832e37cd45944fa1fcb2f9f SRPMS/cups-1.1.23-15.3.src.rpm
02eadf80e0cfb528185e0b9274077006 ppc/cups-1.1.23-15.3.ppc.rpm
e2cb40aef49d878dd26d5f03cb1fd01e ppc/cups-devel-1.1.23-15.3.ppc.rpm
a5435a5bcfffa902385e459d87a497c6 ppc/cups-libs-1.1.23-15.3.ppc.rpm
2de63386f71fc3c04f698b7c72c1dba8 ppc/cups-lpd-1.1.23-15.3.ppc.rpm
43eb8850d0fafe3de68878b6f8daf77a ppc/debug/cups-debuginfo-1.1.23-15.3.ppc.rpm
a6ad7b471609dc51991518fff8d3cf60 ppc/cups-libs-1.1.23-15.3.ppc64.rpm
8742299c1f7299076bb2b3981fff4c98 x86_64/cups-1.1.23-15.3.x86_64.rpm
bd297bc78d37c1b460d1c9e43230ca69 x86_64/cups-devel-1.1.23-15.3.x86_64.rpm
6ac6c13e86d1305d9bcf9a319e78e4c2 x86_64/cups-libs-1.1.23-15.3.x86_64.rpm
40c906f6e51a7e80053d20ed3cd46db0 x86_64/cups-lpd-1.1.23-15.3.x86_64.rpm
ba48481077a96a3e2ba2aa8a45b3af62 x86_64/debug/cups-debuginfo-1.1.23-15.3.x86_64.rpm
dd421fc881b169edd6eeb4dd066c86b2 x86_64/cups-libs-1.1.23-15.3.i386.rpm
e4de7feac1df02a425ab3efa6144f4ff i386/cups-1.1.23-15.3.i386.rpm
3e11e02156acc1ab98c39e81eaa94845 i386/cups-devel-1.1.23-15.3.i386.rpm
dd421fc881b169edd6eeb4dd066c86b2 i386/cups-libs-1.1.23-15.3.i386.rpm
2b0df8e6199debab3a3715b643b4b504 i386/cups-lpd-1.1.23-15.3.i386.rpm
4f1b9c6b9a2455ed4e4f0a6531a5a006 i386/debug/cups-debuginfo-1.1.23-15.3.i386.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.



Fedora Update Notification
FEDORA-2005-000
2006-01-05

Product : Fedora Core 3
Name : cups
Version : 1.1.22
Release : 0.rc1.8.9
Summary : Common Unix Printing System

Description :
The Common UNIX Printing System provides a portable printing layer for UNIX™ operating systems. It has been developed by Easy Software Products to promote a standard printing solution for all UNIX vendors and users. CUPS provides the System V and Berkeley command-line interfaces.


Update Information:

This update fixes the pdftops filter's handling of some incorrectly-formed PDF files. Issues fixed are CVE-2005-3625, CVE-2005-3626, and CVE-2005-3627.


  • Wed Jan 4 2006 Tim Waugh <twaugh@redhat.com> 1:1.1.22-0.rc1.8.9
    • Apply patch to fix CVE-2005-3625, CVE-2005-3626, CVE-2005-3627 (bug #176870).

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

e4863c8e84bd2e0be139cf9c9b981c7d SRPMS/cups-1.1.22-0.rc1.8.9.src.rpm
61f09f282d5d6d06c313d7b2a6d4a01d x86_64/cups-1.1.22-0.rc1.8.9.x86_64.rpm
0a1c9a3519066b1722f2f68f441ce135 x86_64/cups-devel-1.1.22-0.rc1.8.9.x86_64.rpm
5b704b556030ef26c76d866812161aa8 x86_64/cups-libs-1.1.22-0.rc1.8.9.x86_64.rpm
2451f45b1e738ece7af8d7dd9caf6b47 x86_64/debug/cups-debuginfo-1.1.22-0.rc1.8.9.x86_64.rpm
bb9815d2bc773c35dc61c429b77454c8 x86_64/cups-libs-1.1.22-0.rc1.8.9.i386.rpm
7a71e7c01a6ef6d50dc39e78b50496de i386/cups-1.1.22-0.rc1.8.9.i386.rpm
c8f38a36664e624ae521e76867ac1467 i386/cups-devel-1.1.22-0.rc1.8.9.i386.rpm
bb9815d2bc773c35dc61c429b77454c8 i386/cups-libs-1.1.22-0.rc1.8.9.i386.rpm
3f5ca45efebf5218f43faaaebb42f39e i386/debug/cups-debuginfo-1.1.22-0.rc1.8.9.i386.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.



Fedora Update Notification
FEDORA-2005-013
2006-01-06

Product : Fedora Core 4
Name : kernel
Version : 2.6.14
Release : 1.1656_FC4
Summary : The Linux kernel (the core of the Linux operating system)

Description :
The kernel package contains the Linux kernel (vmlinuz), the core of any Linux operating system. The kernel handles the basic functions of the operating system: memory allocation, process allocation, device input and output, etc.


Update Information:

This update fixes several low-priority security problems that were discovered during the development of 2.6.15, and backported.

Notably, CVE-2005-4605.


  • Thu Jan 5 2006 Dave Jones <davej@redhat.com> [2.6.14-1.1656_FC4]
    • Rebuild.
  • Tue Jan 3 2006 Dave Jones <davej@redhat.com> [2.6.14-1.1655_FC4]
    • Small fixes from 2.6.15
    • sysctl: don't overflow the user-supplied buffer with '0'
    • sysctl: make sure to terminate strings with a NUL
    • Insanity avoidance in /proc
  • Sun Jan 1 2006 Dave Jones <davej@redhat.com>
    • Fix the ACPI whitelist date again.
  • Wed Dec 28 2005 Dave Jones <davej@redhat.com>
    • Tighten permissions on /proc/pid/smaps. (#176687)
  • Wed Dec 28 2005 Dave Jones <davej@redhat.com> [2.6.14-1.1654_FC4]
    • Fix usb storage oops. (#176576)
    • Fix ACPI owner_id limit.
    • Decrease stack usage in block layer.
  • Tue Dec 27 2005 Dave Jones <davej@redhat.com>
    • 2.6.14.5
    • usbhid incorrectly claimed wacom penpartner tablet. (#161241)
    • Reinstate the y2k ACPI blacklist cutoff. It broke working suspend for apm users.
  • Fri Dec 16 2005 Dave Jones <davej@redhat.com>
    • Rebase to final 2.6.14.4

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

0986f8f9b53aff89e38c3ac432455d13 SRPMS/kernel-2.6.14-1.1656_FC4.src.rpm
2713f20165811439c3230da4211b23f4 ppc/kernel-2.6.14-1.1656_FC4.ppc.rpm
86884ffa980bb5b799f5b7ee905f5b4d ppc/kernel-devel-2.6.14-1.1656_FC4.ppc.rpm
4c795cdd720d46f9d31abc606c51299a ppc/kernel-smp-2.6.14-1.1656_FC4.ppc.rpm
065ac33d47bc2a11160bee854e8fec43 ppc/kernel-smp-devel-2.6.14-1.1656_FC4.ppc.rpm
bf84da79ec3d9d43e2c75eae522969dc ppc/debug/kernel-debuginfo-2.6.14-1.1656_FC4.ppc.rpm
cc10f57c8999e3e276ac719007824087 ppc/kernel-2.6.14-1.1656_FC4.ppc64.rpm
a68170aaef2c4192295d6855624b9925 ppc/kernel-devel-2.6.14-1.1656_FC4.ppc64.rpm
260132f52671b5141bac5fcb05dcc57e x86_64/kernel-2.6.14-1.1656_FC4.x86_64.rpm
a643d88decc67e58dee08d6b4dc18464 x86_64/kernel-devel-2.6.14-1.1656_FC4.x86_64.rpm
86363061f3f32695afa7d649f53cfe83 x86_64/kernel-smp-2.6.14-1.1656_FC4.x86_64.rpm
aa6ec4216105399c8728227b1ee0af06 x86_64/kernel-smp-devel-2.6.14-1.1656_FC4.x86_64.rpm
48c87979a0e88a03c0434c84ed8d805a x86_64/debug/kernel-debuginfo-2.6.14-1.1656_FC4.x86_64.rpm
ddedbf5bbad3cf9c1372aeb443a3af79 x86_64/kernel-doc-2.6.14-1.1656_FC4.noarch.rpm
8429eea3c447c93407d7ace4226edec5 i386/kernel-2.6.14-1.1656_FC4.i586.rpm
13bc09d73c8c64c20b0e6a8074a022b0 i386/kernel-devel-2.6.14-1.1656_FC4.i586.rpm
4ae77938bec18857eec961af30a8cfc1 i386/debug/kernel-debuginfo-2.6.14-1.1656_FC4.i586.rpm
58281f46cef7bc8617e7c10236429ea5 i386/kernel-2.6.14-1.1656_FC4.i686.rpm
f03110252518776bc6baf106f7381292 i386/kernel-devel-2.6.14-1.1656_FC4.i686.rpm
c008e26f80b86bff71cd0bd396a537e1 i386/kernel-smp-2.6.14-1.1656_FC4.i686.rpm
7ad41e47ad57b279619dedd308f1eeef i386/kernel-smp-devel-2.6.14-1.1656_FC4.i686.rpm
0cac7a02ccb6648427f80392c25ef552 i386/debug/kernel-debuginfo-2.6.14-1.1656_FC4.i686.rpm
ddedbf5bbad3cf9c1372aeb443a3af79 i386/kernel-doc-2.6.14-1.1656_FC4.noarch.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.



Fedora Update Notification
FEDORA-2005-014
2006-01-06

Product : Fedora Core 3
Name : mod_auth_pgsql
Version : 2.0.1
Release : 6.2
Summary : Basic authentication for the Apache web server using a PostgreSQL database.

Description :
mod_auth_pgsql can be used to limit access to documents served by a web server by checking fields in a table in a PostgresQL database.


Update Information:

Several format string flaws were found in the way mod_auth_pgsql logs information. It may be possible for a remote attacker to execute arbitrary code as the 'apache' user if mod_auth_pgsql is used for user authentication. The Common Vulnerabilities and Exposures project assigned the name CVE-2005-3656 to this issue.

Please note that this issue only affects servers which have mod_auth_pgsql installed and configured to perform user authentication against a PostgreSQL database.

Red Hat would like to thank iDefense for reporting this issue.


  • Fri Jan 6 2006 Joe Orton <jorton@redhat.com> 2.0.1-6.2
    • add security fix for CVE-2005-3656
    • don't strip .so file so debuginfo works
    • fix r->user handling (Mirko Streckenbach, #150087)

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

f4de3874523d13558b62a7b616a9924b SRPMS/mod_auth_pgsql-2.0.1-6.2.src.rpm
710fe9e31a155fca650aa2e948caf3e0 x86_64/mod_auth_pgsql-2.0.1-6.2.x86_64.rpm
a98acc532d16f6824643f84681a925ba x86_64/debug/mod_auth_pgsql-debuginfo-2.0.1-6.2.x86_64.rpm
2b1130b5b5be47de09f927b2dd87bd94 i386/mod_auth_pgsql-2.0.1-6.2.i386.rpm
2d348cb3ca7f7525dce925a20fed88da i386/debug/mod_auth_pgsql-debuginfo-2.0.1-6.2.i386.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.



Fedora Update Notification
FEDORA-2005-015
2006-01-06

Product : Fedora Core 4
Name : mod_auth_pgsql
Version : 2.0.1
Release : 8.1
Summary : Basic authentication for the Apache web server using a PostgreSQL database.

Description :
mod_auth_pgsql can be used to limit access to documents served by a web server by checking fields in a table in a PostgresQL database.


Update Information:

Several format string flaws were found in the way mod_auth_pgsql logs information. It may be possible for a remote attacker to execute arbitrary code as the 'apache' user if mod_auth_pgsql is used for user authentication. The Common Vulnerabilities and Exposures project assigned the name CVE-2005-3656 to this issue.

Please note that this issue only affects servers which have mod_auth_pgsql installed and configured to perform user authentication against a PostgreSQL database.

Red Hat would like to thank iDefense for reporting this issue.


  • Fri Jan 6 2006 Joe Orton <jorton@redhat.com> 2.0.1-8.1
    • add security fix for CVE-2005-3656
    • don't strip .so file so debuginfo works

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

d92214578ca55f9fe41d1ae02bf6d43e SRPMS/mod_auth_pgsql-2.0.1-8.1.src.rpm
747cb8b5486624f9df1057fca3ee7e86 ppc/mod_auth_pgsql-2.0.1-8.1.ppc.rpm
7039f4f23f6a28fc27faa06ef83ea3a0 ppc/debug/mod_auth_pgsql-debuginfo-2.0.1-8.1.ppc.rpm
d5815a490b1ec2c2f59f9715253d5665 x86_64/mod_auth_pgsql-2.0.1-8.1.x86_64.rpm
4a1db6971295f3cc99b8641485577123 x86_64/debug/mod_auth_pgsql-debuginfo-2.0.1-8.1.x86_64.rpm
6ce00956921bda6ae3f5f6ed19bdde75 i386/mod_auth_pgsql-2.0.1-8.1.i386.rpm
4b265b8401bc3c5b56140b0bb65ce159 i386/debug/mod_auth_pgsql-debuginfo-2.0.1-8.1.i386.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.



Fedora Update Notification
FEDORA-2005-025
2006-01-10

Product : Fedora Core 3
Name : gpdf
Version : 2.8.2
Release : 7.2
Summary : viewer for Portable Document Format (PDF) files for GNOME

Description :
This is GPdf, a viewer for Portable Document Format (PDF) files for GNOME. GPdf is based on the Xpdf program and uses additional GNOME libraries for better desktop integration.

GPdf includes the gpdf application, a Bonobo control for PDF display which can be embedded in Nautilus, and a Nautilus property page for PDF files.


Update Information:

Chris Evans discovered several flaws in the way CUPS processes PDF files. An attacker could construct a carefully crafted PDF file that could cause CUPS to crash or possibly execute arbitrary code when opened. The Common Vulnerabilities and Exposures project assigned the names CVE-2005-3624, CVE-2005-3625, CVE-2005-3626, and CVE-2005-3627 to these issues.


  • Tue Jan 10 2006 Ray Strode <rstrode@redhat.com> 2.8.2-7.2
    • Apply fix for CVE-2005-3624 (also covers CVE-2005-3193) (bug 176866)

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

3f7a8f70d4f2a8f18d823c572ad99755361adf23 SRPMS/gpdf-2.8.2-7.2.src.rpm
e0b1860bc92e3b69c60dbe53548ca709223d1822 x86_64/gpdf-2.8.2-7.2.x86_64.rpm
42a7a344a3d3e040bf37e002c788f8ca5fde8dba x86_64/debug/gpdf-debuginfo-2.8.2-7.2.x86_64.rpm
cada2bbc6925dbb27ea17317f9f8c31488d33cd0 i386/gpdf-2.8.2-7.2.i386.rpm
9280b56de65f4acedd3c13b5ff455fdc610463ae i386/debug/gpdf-debuginfo-2.8.2-7.2.i386.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.


Fedora Legacy


Fedora Legacy Update Advisory

Synopsis: Updated gettext package fixes security issues
Advisory ID: FLSA:136323
Issue date: 2006-01-09
Product: Red Hat Linux, Fedora Core
Keywords: Bugfix
CVE Names: CVE-2004-0966



1. Topic:

An updated gettext package that fixes security bugs is now available.

The GNU gettext package provides a set of tools and documentation for producing multi-lingual messages in programs.

2. Relevant releases/architectures:

Red Hat Linux 9 - i386
Fedora Core 1 - i386
Fedora Core 2 - i386

3. Problem description:

Temporary file vulnerabilities were discovered in the gettext package. A malicious user could use the "autopoint" and "gettextize" scripts to create or overwrite another user's files. The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the name CVE-2004-0966 to this issue.

All users of gettext should upgrade to this updated package, which includes a patch to correct these issues.

4. Solution:

Before applying this update, make sure all previously released errata relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory only contains the desired RPMs.

Please note that this update is also available via yum and apt. Many people find this an easier way to apply updates. To use yum issue:

yum update

or to use apt:

apt-get update; apt-get upgrade

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. This assumes that you have yum or apt-get configured for obtaining Fedora Legacy content. Please visit http://www.fedoralegacy.org/docs for directions on how to configure yum and apt-get.

5. Bug IDs fixed:

https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136323

6. RPMs required:

Red Hat Linux 9:

SRPM:
http://download.fedoralegacy.org/redhat/9/updates/SRPMS/gettext-0.11.4-7.2.legacy.src.rpm

i386:
http://download.fedoralegacy.org/redhat/9/updates/i386/gettext-0.11.4-7.2.legacy.i386.rpm

Fedora Core 1:

SRPM:
http://download.fedoralegacy.org/fedora/1/updates/SRPMS/gettext-0.12.1-1.2.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/1/updates/i386/gettext-0.12.1-1.2.legacy.i386.rpm

Fedora Core 2:

SRPM:
http://download.fedoralegacy.org/fedora/2/updates/SRPMS/gettext-0.14.1-2.1.2.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/2/updates/i386/gettext-0.14.1-2.1.2.legacy.i386.rpm

7. Verification:

SHA1 sum Package Name


7b6dee52052cf366ae9d78f42d2266045992e8b2 redhat/9/updates/i386/gettext-0.11.4-7.2.legacy.i386.rpm
ccb4260c2f1d4778bf1190bd6d96950c361b8131 redhat/9/updates/SRPMS/gettext-0.11.4-7.2.legacy.src.rpm

7b29432779dcbbb183b98fb5c60208366346ea93 fedora/1/updates/i386/gettext-0.12.1-1.2.legacy.i386.rpm
22bc34eef7d35bad85cf013381187660a4a68c8d fedora/1/updates/SRPMS/gettext-0.12.1-1.2.legacy.src.rpm

7851e6bb612ae72e3fae9870ca160d2a96e7123b fedora/2/updates/i386/gettext-0.14.1-2.1.2.legacy.i386.rpm
6c972dcef9866f7e53ba6855478078f8f24684d0 fedora/2/updates/SRPMS/gettext-0.14.1-2.1.2.legacy.src.rpm

These packages are GPG signed by Fedora Legacy for security. Our key is available from http://www.fedoralegacy.org/about/security.php

You can verify each package with the following command:

rpm --checksig -v <filename>

If you only wish to verify that each package has not been corrupted or tampered with, examine only the sha1sum with the following command:

sha1sum <filename>

8. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0966

9. Contact:

The Fedora Legacy security contact is <secnotice@fedoralegacy.org>. More project details at http://www.fedoralegacy.org



Fedora Legacy Update Advisory

Synopsis: Updated htdig packages fix security issues
Advisory ID: FLSA:152907
Issue date: 2006-01-09
Product: Red Hat Linux, Fedora Core
Keywords: Bugfix
CVE Names: CVE-2005-0085



1. Topic:

Updated htdig packages that fix a security bug are now available.

The ht://Dig system is a Web search and indexing system for a small domain or intranet.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - i386
Red Hat Linux 9 - i386
Fedora Core 1 - i386
Fedora Core 2 - i386

3. Problem description:

A cross-site scripting bug has been found in htdig. This issue could allow an attacker to send a carefully crafted message, which could result in causing the victim's machine to execute a malicious script. The Common Vulnerabilities and Exposures project has assigned the name CVE-2005-0085 to this issue.

All users of htdig should upgrade to these updated packages, which include a backported patch to correct this issue.

4. Solution:

Before applying this update, make sure all previously released errata relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory only contains the desired RPMs.

Please note that this update is also available via yum and apt. Many people find this an easier way to apply updates. To use yum issue:

yum update

or to use apt:

apt-get update; apt-get upgrade

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. This assumes that you have yum or apt-get configured for obtaining Fedora Legacy content. Please visit http://www.fedoralegacy.org/docs for directions on how to configure yum and apt-get.

5. Bug IDs fixed:

https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152907

6. RPMs required:

Red Hat Linux 7.3:
SRPM:
http://download.fedoralegacy.org/redhat/7.3/updates/SRPMS/htdig-3.2.0-2.011302.3.legacy.src.rpm

i386:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/htdig-3.2.0-2.011302.3.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/htdig-web-3.2.0-2.011302.3.legacy.i386.rpm

Red Hat Linux 9:

SRPM:
http://download.fedoralegacy.org/redhat/9/updates/SRPMS/htdig-3.2.0-16.20021103.3.legacy.src.rpm

i386:
http://download.fedoralegacy.org/redhat/9/updates/i386/htdig-3.2.0-16.20021103.3.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/htdig-web-3.2.0-16.20021103.3.legacy.i386.rpm

Fedora Core 1:

SRPM:
http://download.fedoralegacy.org/fedora/1/updates/SRPMS/htdig-3.2.0-19.20030601.2.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/1/updates/i386/htdig-3.2.0-19.20030601.2.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/htdig-web-3.2.0-19.20030601.2.legacy.i386.rpm

Fedora Core 2:

SRPM:
http://download.fedoralegacy.org/fedora/2/updates/SRPMS/htdig-3.2.0b5-7.2.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/2/updates/i386/htdig-3.2.0b5-7.2.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/2/updates/i386/htdig-web-3.2.0b5-7.2.legacy.i386.rpm

7. Verification:

SHA1 sum Package Name


9f2c2108c62a38698946a3d054a02318115575db redhat/7.3/updates/i386/htdig-3.2.0-2.011302.3.legacy.i386.rpm
2f7355e1dac9e1f0af4de0ba4c57707afe253ef0 redhat/7.3/updates/i386/htdig-web-3.2.0-2.011302.3.legacy.i386.rpm
e76b1a954834c707a05d323e1910165c204edc21 redhat/7.3/updates/SRPMS/htdig-3.2.0-2.011302.3.legacy.src.rpm

a660dbbc2839b32b186bb121e972a553586286fa redhat/9/updates/i386/htdig-3.2.0-16.20021103.3.legacy.i386.rpm
f6904537f1da733bf209d20d28b295dcc7d69b99 redhat/9/updates/i386/htdig-web-3.2.0-16.20021103.3.legacy.i386.rpm
37c36aefd9331dc327e24e2fa040399be0b80601 redhat/9/updates/SRPMS/htdig-3.2.0-16.20021103.3.legacy.src.rpm

7478d40f0bae9370d5ab262fe916c41944776adf fedora/1/updates/i386/htdig-3.2.0-19.20030601.2.legacy.i386.rpm
8df233b896f4a139ad123a5465c3d3816da27623 fedora/1/updates/i386/htdig-web-3.2.0-19.20030601.2.legacy.i386.rpm
908e27f80a740632f88bfba330c356b68c76c429 fedora/1/updates/SRPMS/htdig-3.2.0-19.20030601.2.legacy.src.rpm

7b03742a875fb2964b294a1e35d690539a097204 fedora/2/updates/i386/htdig-3.2.0b5-7.2.legacy.i386.rpm
5f590cad676cc7dae81a24d5b02c55cae3ebe603 fedora/2/updates/i386/htdig-web-3.2.0b5-7.2.legacy.i386.rpm
31ab214325ff0fadfa3a2f0d385e16b8de24aed9 fedora/2/updates/SRPMS/htdig-3.2.0b5-7.2.legacy.src.rpm

These packages are GPG signed by Fedora Legacy for security. Our key is available from http://www.fedoralegacy.org/about/security.php

You can verify each package with the following command:

rpm --checksig -v <filename>

If you only wish to verify that each package has not been corrupted or tampered with, examine only the sha1sum with the following command:

sha1sum <filename>

8. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0085

9. Contact:

The Fedora Legacy security contact is <secnotice@fedoralegacy.org>. More project details at http://www.fedoralegacy.org


Gentoo Linux


Gentoo Linux Security Advisory GLSA 200601-02

http://security.gentoo.org/


Severity: Normal
Title: KPdf, KWord: Multiple overflows in included Xpdf code
Date: January 04, 2006
Bugs: #114429, #115851
ID: 200601-02


Synopsis

KPdf and KWord both include vulnerable Xpdf code to handle PDF files, making them vulnerable to the execution of arbitrary code.

Background

KPdf is a KDE-based PDF viewer included in the kdegraphics package. KWord is a KDE-based word processor also included in the koffice package.

Affected packages


Package / Vulnerable / Unaffected

1 kde-base/kdegraphics < 3.4.3-r3 >= 3.4.3-r3 2 kde-base/kpdf < 3.4.3-r3 >= 3.4.3-r3 3 app-office/koffice < 1.4.2-r6 >= 1.4.2-r6 4 app-office/kword < 1.4.2-r6 >= 1.4.2-r6 ------------------------------------------------------------------- 4 affected packages on all of their supported architectures.


Description

KPdf and KWord both include Xpdf code to handle PDF files. This Xpdf code is vulnerable to several heap overflows (GLSA 200512-08) as well as several buffer and integer overflows discovered by Chris Evans.

Impact

An attacker could entice a user to open a specially crafted PDF file with Kpdf or KWord, potentially resulting in the execution of arbitrary code with the rights of the user running the affected application.

Workaround

There is no known workaround at this time.

Resolution

All kdegraphics users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=kde-base/kdegraphics-3.4.3-r3"

All Kpdf users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=kde-base/kpdf-3.4.3-r3"

All KOffice users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=app-office/koffice-1.4.2-r6"

All KWord users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=app-office/kword-1.4.2-r6"

References

[ 1 ] CAN-2005-3191

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3191

[ 2 ] CAN-2005-3192

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3192

[ 3 ] CAN-2005-3193

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3193

[ 4 ] CVE-2005-3624

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3624

[ 5 ] CVE-2005-3625

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3625

[ 6 ] CVE-2005-3626

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3626

[ 7 ] CVE-2005-3627

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3627

[ 8 ] GLSA 200512-08

http://www.gentoo.org/security/en/glsa/glsa-200512-08.xml

[ 9 ] KDE Security Advisory: kpdf/xpdf multiple integer overflows

http://www.kde.org/info/security/advisory-20051207-2.txt

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200601-02.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0


Gentoo Linux Security Advisory GLSA 200601-03

http://security.gentoo.org/


Severity: High
Title: HylaFAX: Multiple vulnerabilities
Date: January 06, 2006
Bugs: #116389
ID: 200601-03


Synopsis

HylaFAX is vulnerable to arbitrary code execution and unauthorized access vulnerabilities.

Background

HylaFAX is an enterprise-class system for sending and receiving facsimile messages and for sending alpha-numeric pages.

Affected packages


Package / Vulnerable / Unaffected
1 net-misc/hylafax < 4.2.3-r1 >= 4.2.3-r1

Description

Patrice Fournier discovered that HylaFAX runs the notify script on untrusted user input. Furthermore, users can log in without a password when HylaFAX is installed with the pam USE-flag disabled.

Impact

An attacker could exploit the input validation vulnerability to run arbitrary code as the user running HylaFAX, which is usually uucp. The password vulnerability could be exploited to log in without proper user credentials.

Workaround

There is no known workaround at this time.

Resolution

All HylaFAX users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=net-misc/hylafax-4.2.3-r1"

References

[ 1 ] CVE-2005-3538

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3538

[ 2 ] CVE-2005-3539

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3539

[ 3 ] HylaFAX release announcement

http://www.hylafax.org/content/HylaFAX_4.2.4_release

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200601-03.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0


Gentoo Linux Security Advisory GLSA 200601-04

http://security.gentoo.org/


Severity: High
Title: VMware Workstation: Vulnerability in NAT networking
Date: January 07, 2006
Bugs: #116238
ID: 200601-04


Synopsis

VMware guest operating systems can execute arbitrary code with elevated privileges on the host operating system through a flaw in NAT networking.

Background

VMware Workstation is a powerful virtual machine for developers and system administrators.

Affected packages


Package / Vulnerable / Unaffected

1 vmware-workstation < 5.5.1.19175 >= 5.5.1.19175 *>= 4.5.3.19414

Description

Tim Shelton discovered that vmnet-natd, the host module providing NAT-style networking for VMware guest operating systems, is unable to process incorrect 'EPRT' and 'PORT' FTP requests.

Impact

Malicious guest operating systems using the NAT networking feature or local VMware Workstation users could exploit this vulnerability to execute arbitrary code on the host system with elevated privileges.

Workaround

Disable the NAT service by following the instructions at http://www.vmware.com/support/kb, Answer ID 2002.

Resolution

All VMware Workstation users should upgrade to a fixed version:

    # emerge --sync
    # emerge --ask --oneshot --verbose app-emulation/vmware-workstation

References

[ 1 ] CVE-2005-4459

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4459

[ 2 ] VMware Security Response

http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=2000

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200601-04.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0

Mandriva Linux


Mandriva Linux Security Advisory MDKSA-2006:003
http://www.mandriva.com/security/


Package : poppler
Date : January 5, 2006
Affected: 2006.0


Problem Description:

Multiple heap-based buffer overflows in the DCTStream::readProgressiveSOF and DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, allow user-complicit attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index. (CVE-2005-3191)

Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01 allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field. (CVE-2005-3192)

Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier allows user-complicit attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with large size values that cause insufficient memory to be allocated. (CVE-2005-3193)

An additional patch re-addresses memory allocation routines in goo/gmem.c (Martin Pitt/Canonical, Dirk Mueller/KDE).

In addition, Chris Evans discovered several other vulnerbilities in the xpdf code base:

Out-of-bounds heap accesses with large or negative parameters to "FlateDecode" stream. (CVE-2005-3192)

Out-of-bounds heap accesses with large or negative parameters to "CCITTFaxDecode" stream. (CVE-2005-3624)

Infinite CPU spins in various places when stream ends unexpectedly. (CVE-2005-3625)

NULL pointer crash in the "FlateDecode" stream. (CVE-2005-3626)

Overflows of compInfo array in "DCTDecode" stream. (CVE-2005-3627)

Possible to use index past end of array in "DCTDecode" stream. (CVE-2005-3627)

Possible out-of-bounds indexing trouble in "DCTDecode" stream. (CVE-2005-3627)

Poppler uses an embedded copy of the xpdf code, with the same vulnerabilities.

The updated packages have been patched to correct these problems.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3191
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3192
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3193
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3624
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3625
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3626
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3627


Updated Packages:

Mandriva Linux 2006.0:
eed45eed8ae99ca240c873c03a5cbf40 2006.0/RPMS/libpoppler0-0.4.1-3.1.20060mdk.i586.rpm
8af1cf9763672dd33d2211958a8171ba 2006.0/RPMS/libpoppler0-devel-0.4.1-3.1.20060mdk.i586.rpm
867596ef4e09751ed3d4e1e7a4e640da 2006.0/RPMS/libpoppler-qt0-0.4.1-3.1.20060mdk.i586.rpm
fd4736b863ce01d20bd6d2ae1228417a 2006.0/RPMS/libpoppler-qt0-devel-0.4.1-3.1.20060mdk.i586.rpm
c40f77c8b63d7af311801ab97ef8f72e 2006.0/SRPMS/poppler-0.4.1-3.1.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
d4dc20ee3d3cc10d39c3b9a05214ca7c x86_64/2006.0/RPMS/lib64poppler0-0.4.1-3.1.20060mdk.x86_64.rpm
0e577cbd784f733c54369cc153777978 x86_64/2006.0/RPMS/lib64poppler0-devel-0.4.1-3.1.20060mdk.x86_64.rpm
7145106c6988a8b99a0622265cc5b24a x86_64/2006.0/RPMS/lib64poppler-qt0-0.4.1-3.1.20060mdk.x86_64.rpm
913bb80df9cc19fe5948b23633915529 x86_64/2006.0/RPMS/lib64poppler-qt0-devel-0.4.1-3.1.20060mdk.x86_64.rpm
c40f77c8b63d7af311801ab97ef8f72e x86_64/2006.0/SRPMS/poppler-0.4.1-3.1.20060mdk.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>


Mandriva Linux Security Advisory MDKSA-2006:004
http://www.mandriva.com/security/


Package : pdftohtml
Date : January 5, 2006
Affected: 2006.0


Problem Description:

Multiple heap-based buffer overflows in the DCTStream::readProgressiveSOF and DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, allow user-complicit attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index. (CVE-2005-3191)

Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01 allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field. (CVE-2005-3192)

Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier allows user-complicit attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with large size values that cause insufficient memory to be allocated. (CVE-2005-3193)

An additional patch re-addresses memory allocation routines in goo/gmem.c (Martin Pitt/Canonical, Dirk Mueller/KDE).

In addition, Chris Evans discovered several other vulnerbilities in the xpdf code base:

Out-of-bounds heap accesses with large or negative parameters to "FlateDecode" stream. (CVE-2005-3192)

Out-of-bounds heap accesses with large or negative parameters to "CCITTFaxDecode" stream. (CVE-2005-3624)

Infinite CPU spins in various places when stream ends unexpectedly. (CVE-2005-3625)

NULL pointer crash in the "FlateDecode" stream. (CVE-2005-3626)

Overflows of compInfo array in "DCTDecode" stream. (CVE-2005-3627)

Possible to use index past end of array in "DCTDecode" stream. (CVE-2005-3627)

Possible out-of-bounds indexing trouble in "DCTDecode" stream. (CVE-2005-3627)

Pdftohtml uses an embedded copy of the xpdf code, with the same vulnerabilities.

The updated packages have been patched to correct these problems.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3191
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3192
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3193
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3624
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3625
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3626
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3627


Updated Packages:

Mandriva Linux 2006.0:
1f14f1f733a877f14e5470107ce6eea0 2006.0/RPMS/pdftohtml-0.36-2.1.20060mdk.i586.rpm
535348b440e6a16b800b1fb00b4b8d3e 2006.0/SRPMS/pdftohtml-0.36-2.1.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
88b1b1351cda8999e1ae2b0b813798be x86_64/2006.0/RPMS/pdftohtml-0.36-2.1.20060mdk.x86_64.rpm
535348b440e6a16b800b1fb00b4b8d3e x86_64/2006.0/SRPMS/pdftohtml-0.36-2.1.20060mdk.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>


Mandriva Linux Security Advisory MDKSA-2006:005
http://www.mandriva.com/security/


Package : xpdf
Date : January 5, 2006
Affected: 2006.0, Corporate 2.1, Corporate 3.0


Problem Description:

Multiple heap-based buffer overflows in the DCTStream::readProgressiveSOF and DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, allow user-complicit attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index. (CVE-2005-3191)

Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01 allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field. (CVE-2005-3192)

Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier allows user-complicit attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with large size values that cause insufficient memory to be allocated. (CVE-2005-3193)

An additional patch re-addresses memory allocation routines in goo/gmem.c (Martin Pitt/Canonical, Dirk Mueller/KDE).

In addition, Chris Evans discovered several other vulnerbilities in the xpdf code base:

Out-of-bounds heap accesses with large or negative parameters to "FlateDecode" stream. (CVE-2005-3192)

Out-of-bounds heap accesses with large or negative parameters to "CCITTFaxDecode" stream. (CVE-2005-3624)

Infinite CPU spins in various places when stream ends unexpectedly. (CVE-2005-3625)

NULL pointer crash in the "FlateDecode" stream. (CVE-2005-3626)

Overflows of compInfo array in "DCTDecode" stream. (CVE-2005-3627)

Possible to use index past end of array in "DCTDecode" stream. (CVE-2005-3627)

Possible out-of-bounds indexing trouble in "DCTDecode" stream. (CVE-2005-3627)

The updated packages have been patched to correct these problems.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3191
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3192
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3193
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3624
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3625
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3626
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3627


Updated Packages:

Mandriva Linux 2006.0:
9f0d2d83c61f4cab871138ac2866dd30 2006.0/RPMS/xpdf-3.01-1.1.20060mdk.i586.rpm
51daa161fb5581aba221d4be39c5acbc 2006.0/SRPMS/xpdf-3.01-1.1.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
c0eb562149fe7025798ce38ef361d9c7 x86_64/2006.0/RPMS/xpdf-3.01-1.1.20060mdk.x86_64.rpm
51daa161fb5581aba221d4be39c5acbc x86_64/2006.0/SRPMS/xpdf-3.01-1.1.20060mdk.src.rpm

Corporate Server 2.1:
d35b8a8e201185bff3b6acfa9c3b9186 corporate/2.1/RPMS/xpdf-1.01-4.10.C21mdk.i586.rpm
1f5f85d3bc3577b1141d3ea54015b63a corporate/2.1/SRPMS/xpdf-1.01-4.10.C21mdk.src.rpm

Corporate Server 2.1/X86_64:
f1a715d6a7fe797d09cde9dff6db4800 x86_64/corporate/2.1/RPMS/xpdf-1.01-4.10.C21mdk.x86_64.rpm
1f5f85d3bc3577b1141d3ea54015b63a x86_64/corporate/2.1/SRPMS/xpdf-1.01-4.10.C21mdk.src.rpm

Corporate 3.0:
bfb96e34ea12293b22cd766b61da64fe corporate/3.0/RPMS/xpdf-3.00-5.7.C30mdk.i586.rpm
1e4153bea0ed2092819aa88dbc67ade4 corporate/3.0/SRPMS/xpdf-3.00-5.7.C30mdk.src.rpm

Corporate 3.0/X86_64:
0eb5eba5d264041cd67931add3d6e841 x86_64/corporate/3.0/RPMS/xpdf-3.00-5.7.C30mdk.x86_64.rpm
1e4153bea0ed2092819aa88dbc67ade4 x86_64/corporate/3.0/SRPMS/xpdf-3.00-5.7.C30mdk.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>


Mandriva Linux Security Advisory MDKSA-2006:006
http://www.mandriva.com/security/


Package : gpdf
Date : January 5, 2006
Affected: Corporate 3.0


Problem Description:

Multiple heap-based buffer overflows in the DCTStream::readProgressiveSOF and DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, allow user-complicit attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index. (CVE-2005-3191)

Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01 allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field. (CVE-2005-3192)

Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier allows user-complicit attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with large size values that cause insufficient memory to be allocated. (CVE-2005-3193)

An additional patch re-addresses memory allocation routines in goo/gmem.c (Martin Pitt/Canonical, Dirk Mueller/KDE).

In addition, Chris Evans discovered several other vulnerbilities in the xpdf code base:

Out-of-bounds heap accesses with large or negative parameters to "FlateDecode" stream. (CVE-2005-3192)

Out-of-bounds heap accesses with large or negative parameters to "CCITTFaxDecode" stream. (CVE-2005-3624)

Infinite CPU spins in various places when stream ends unexpectedly. (CVE-2005-3625)

NULL pointer crash in the "FlateDecode" stream. (CVE-2005-3626)

Overflows of compInfo array in "DCTDecode" stream. (CVE-2005-3627)

Possible to use index past end of array in "DCTDecode" stream. (CVE-2005-3627)

Possible out-of-bounds indexing trouble in "DCTDecode" stream. (CVE-2005-3627)

Gpdf uses an embedded copy of the xpdf code, with the same vulnerabilities.

The updated packages have been patched to correct these problems.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3191
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3192
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3193
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3624
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3625
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3626
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3627


Updated Packages:

Corporate 3.0:
c632c70e9cb361a9cd5f15044e81fc2d corporate/3.0/RPMS/gpdf-0.112-2.7.C30mdk.i586.rpm
b1f95183009314b1b90f09e8856eb590 corporate/3.0/SRPMS/gpdf-0.112-2.7.C30mdk.src.rpm

Corporate 3.0/X86_64:
7b23a4672b186d5bbc25c0873e75eda3 x86_64/corporate/3.0/RPMS/gpdf-0.112-2.7.C30mdk.x86_64.rpm
b1f95183009314b1b90f09e8856eb590 x86_64/corporate/3.0/SRPMS/gpdf-0.112-2.7.C30mdk.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>


Mandriva Linux Security Advisory MDKSA-2006:007
http://www.mandriva.com/security/


Package : apache2
Date : January 5, 2006
Affected: 10.1, 10.2, 2006.0


Problem Description:

A flaw was discovered in mod_imap when using the Referer directive with image maps that could be used by a remote attacker to perform a crosssite scripting attack, in certain site configurations, if a victim could be forced to visit a malicious URL using certain web browsers (CVE-2005-3352).

Also, a NULL pointer dereference flaw was found in mod_ssl that affects server configurations where an SSL virtual host was configured with access controls and a custom 400 error document. This could allow a remote attacker to send a carefully crafted request to trigger the issue and cause a crash, but only with the non-default worker MPM (CVE-2005-3357).

The provided packages have been patched to prevent these problems.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3352
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3357


Updated Packages:

Mandriva Linux 10.1:
99d7e03e08f46bb8d2c6246cccc7f03a 10.1/RPMS/apache2-2.0.50-7.6.101mdk.i586.rpm
7338a879c51aad4c89484443c2b806ce 10.1/RPMS/apache2-common-2.0.50-7.6.101mdk.i586.rpm
e016511ca52a8afe34438d8262207768 10.1/RPMS/apache2-devel-2.0.50-7.6.101mdk.i586.rpm
bdebdafd3768e26c0d58ad1fc6cae9ff 10.1/RPMS/apache2-manual-2.0.50-7.6.101mdk.i586.rpm
b9f4c1a36d9e89f41de503b0f8428719 10.1/RPMS/apache2-mod_cache-2.0.50-7.6.101mdk.i586.rpm
7b6411056d388050ef4c98d3c1de3e24 10.1/RPMS/apache2-mod_dav-2.0.50-7.6.101mdk.i586.rpm
fd87e01a054073ab1a1ef9de5bb3ac54 10.1/RPMS/apache2-mod_deflate-2.0.50-7.6.101mdk.i586.rpm
ecf73bf07822403bbae9c453adad28b3 10.1/RPMS/apache2-mod_disk_cache-2.0.50-7.6.101mdk.i586.rpm
7174d7461248d61ae8294406937482f3 10.1/RPMS/apache2-mod_file_cache-2.0.50-7.6.101mdk.i586.rpm
daa7a98f93d00a64bb0a7a52324471cd 10.1/RPMS/apache2-mod_ldap-2.0.50-7.6.101mdk.i586.rpm
68ee307aedbe6af498d87fe112f835dc 10.1/RPMS/apache2-mod_mem_cache-2.0.50-7.6.101mdk.i586.rpm
610525fcf03a696c50192991d0a28c9b 10.1/RPMS/apache2-mod_proxy-2.0.50-7.6.101mdk.i586.rpm
5a2d76582859bc52306c6f22725f2ab7 10.1/RPMS/apache2-mod_ssl-2.0.50-4.4.101mdk.i586.rpm
1749b95a9ad45825cb085f82144794df 10.1/RPMS/apache2-modules-2.0.50-7.6.101mdk.i586.rpm
55a3abf1039dfb0c4d547685b3605fd4 10.1/RPMS/apache2-source-2.0.50-7.6.101mdk.i586.rpm
e7e0c2080af16bc3215ff67a841f6323 10.1/RPMS/apache2-worker-2.0.50-7.6.101mdk.i586.rpm
50bb5f9723f0146fe82d312f7fbeb2cf 10.1/SRPMS/apache2-2.0.50-7.6.101mdk.src.rpm
21c1f068fe82b86e3396b37f7ec96782 10.1/SRPMS/apache2-mod_ssl-2.0.50-4.4.101mdk.src.rpm

Mandriva Linux 10.1/X86_64:
43085852f7b6e5a55e4220cbd6493b74 x86_64/10.1/RPMS/apache2-2.0.50-7.6.101mdk.x86_64.rpm
2715904b29d6433d25f6ea35715d5484 x86_64/10.1/RPMS/apache2-common-2.0.50-7.6.101mdk.x86_64.rpm
71828de67a3c26f4061eeebef8e6de2b x86_64/10.1/RPMS/apache2-devel-2.0.50-7.6.101mdk.x86_64.rpm
d37b18f9791c65466e5fafdf0287720e x86_64/10.1/RPMS/apache2-manual-2.0.50-7.6.101mdk.x86_64.rpm
088b8334c6efef6f17a1602be41b6045 x86_64/10.1/RPMS/apache2-mod_cache-2.0.50-7.6.101mdk.x86_64.rpm
9326eca120d7ac3e71337bad1f85fef0 x86_64/10.1/RPMS/apache2-mod_dav-2.0.50-7.6.101mdk.x86_64.rpm
36818cef250fc94d074f0fc0f2c6d8c7 x86_64/10.1/RPMS/apache2-mod_deflate-2.0.50-7.6.101mdk.x86_64.rpm
63d37c81fe0b48ccd91d79e4c90dd5ec x86_64/10.1/RPMS/apache2-mod_disk_cache-2.0.50-7.6.101mdk.x86_64.rpm
f7daa039d6878f063ca97468d9328fa8 x86_64/10.1/RPMS/apache2-mod_file_cache-2.0.50-7.6.101mdk.x86_64.rpm
13e394bc675d106270fe8fca27f7acbd x86_64/10.1/RPMS/apache2-mod_ldap-2.0.50-7.6.101mdk.x86_64.rpm
8b1fd1bd22e33a25be158b7e152aba60 x86_64/10.1/RPMS/apache2-mod_mem_cache-2.0.50-7.6.101mdk.x86_64.rpm
f88328582773c7129bf2a341d9cb88db x86_64/10.1/RPMS/apache2-mod_proxy-2.0.50-7.6.101mdk.x86_64.rpm
62170db76a317250d37884dfd07e3f1c x86_64/10.1/RPMS/apache2-mod_ssl-2.0.50-4.4.101mdk.x86_64.rpm
eeedff56c6e4f15df683f9c98f0c7e8c x86_64/10.1/RPMS/apache2-modules-2.0.50-7.6.101mdk.x86_64.rpm
aedf2f9b3ab9b65889546ce8dddb7930 x86_64/10.1/RPMS/apache2-source-2.0.50-7.6.101mdk.x86_64.rpm
99a1557b76f495547ada02c17044b472 x86_64/10.1/RPMS/apache2-worker-2.0.50-7.6.101mdk.x86_64.rpm
50bb5f9723f0146fe82d312f7fbeb2cf x86_64/10.1/SRPMS/apache2-2.0.50-7.6.101mdk.src.rpm
21c1f068fe82b86e3396b37f7ec96782 x86_64/10.1/SRPMS/apache2-mod_ssl-2.0.50-4.4.101mdk.src.rpm

Mandriva Linux 10.2:
a333c0076408d381172729a3931b17a3 10.2/RPMS/apache2-2.0.53-9.4.102mdk.i586.rpm
7e566b7644bfe3bbb1303f0e37cb628f 10.2/RPMS/apache2-common-2.0.53-9.4.102mdk.i586.rpm
ccd22632bbf16a56a84da384b5305129 10.2/RPMS/apache2-devel-2.0.53-9.4.102mdk.i586.rpm
70a1d15adde5528d7b0f665a3ff417fa 10.2/RPMS/apache2-manual-2.0.53-9.4.102mdk.i586.rpm
493f14509e35e304ddac110c3cddf35e 10.2/RPMS/apache2-mod_cache-2.0.53-9.4.102mdk.i586.rpm
794dddbfe413f7164404a2796c563af6 10.2/RPMS/apache2-mod_dav-2.0.53-9.4.102mdk.i586.rpm
9e99b957feb9c25266783d73a6cead4e 10.2/RPMS/apache2-mod_deflate-2.0.53-9.4.102mdk.i586.rpm
bbea1ff737de001b9e8824ade6464c66 10.2/RPMS/apache2-mod_disk_cache-2.0.53-9.4.102mdk.i586.rpm
df8f7bc21c3c093004af7d6e64d83353 10.2/RPMS/apache2-mod_file_cache-2.0.53-9.4.102mdk.i586.rpm
e206646de8e097a4ddc077592eec6ac2 10.2/RPMS/apache2-mod_ldap-2.0.53-9.4.102mdk.i586.rpm
264d47c6eaae58b7b919926571f0813b 10.2/RPMS/apache2-mod_mem_cache-2.0.53-9.4.102mdk.i586.rpm
5bbdc04926add1d2e0ee25cd84b08416 10.2/RPMS/apache2-mod_proxy-2.0.53-9.4.102mdk.i586.rpm
9812f26d7fc8a7f78fadb5d8d2e4dc76 10.2/RPMS/apache2-mod_ssl-2.0.53-8.3.102mdk.i586.rpm
c944feb9397c469b029a047aca7fe907 10.2/RPMS/apache2-modules-2.0.53-9.4.102mdk.i586.rpm
dc00d356dad2e8859e526b10435376e8 10.2/RPMS/apache2-peruser-2.0.53-9.4.102mdk.i586.rpm
364990940ed6e5c3db23fc8fc1cb88e1 10.2/RPMS/apache2-source-2.0.53-9.4.102mdk.i586.rpm
ed7da603004ed00a9c31c7b2e5740de8 10.2/RPMS/apache2-worker-2.0.53-9.4.102mdk.i586.rpm
c27d53f234ab8c96a69c9c275c6f1f0a 10.2/SRPMS/apache2-2.0.53-9.4.102mdk.src.rpm
2c26a3a648da8cfd2e4bde1c9bc750f0 10.2/SRPMS/apache2-mod_ssl-2.0.53-8.3.102mdk.src.rpm

Mandriva Linux 10.2/X86_64:
0fcbb0c7eb9cef2036620ed5c11fbf6f x86_64/10.2/RPMS/apache2-2.0.53-9.4.102mdk.x86_64.rpm
3d102f0fa1141027d29630ea6411ce5a x86_64/10.2/RPMS/apache2-common-2.0.53-9.4.102mdk.x86_64.rpm
ccaa8d4880ea65e7719eee95aa7b90c9 x86_64/10.2/RPMS/apache2-devel-2.0.53-9.4.102mdk.x86_64.rpm
fafc80a0e194e93bd953dcdee0720818 x86_64/10.2/RPMS/apache2-manual-2.0.53-9.4.102mdk.x86_64.rpm
26687c7bfe86b91b42dc07613df73fee x86_64/10.2/RPMS/apache2-mod_cache-2.0.53-9.4.102mdk.x86_64.rpm
077b06db86a6ab2196438b15aaa31759 x86_64/10.2/RPMS/apache2-mod_dav-2.0.53-9.4.102mdk.x86_64.rpm
ae41f94f76bff884bd2486de55458baf x86_64/10.2/RPMS/apache2-mod_deflate-2.0.53-9.4.102mdk.x86_64.rpm
6a8189940aa47a10818d9bd719fcc692 x86_64/10.2/RPMS/apache2-mod_disk_cache-2.0.53-9.4.102mdk.x86_64.rpm
6621cd9d22659033024dcdb02c7e52ba x86_64/10.2/RPMS/apache2-mod_file_cache-2.0.53-9.4.102mdk.x86_64.rpm
1fb8e1694f110fd3d1c6dccf876bf41c x86_64/10.2/RPMS/apache2-mod_ldap-2.0.53-9.4.102mdk.x86_64.rpm
91d3a68b8b932631b29476a7a146abfe x86_64/10.2/RPMS/apache2-mod_mem_cache-2.0.53-9.4.102mdk.x86_64.rpm
adb92885445936c836bc7f13361a90a5 x86_64/10.2/RPMS/apache2-mod_proxy-2.0.53-9.4.102mdk.x86_64.rpm
15e330d09dacde2f4fe20416bc7ecff4 x86_64/10.2/RPMS/apache2-mod_ssl-2.0.53-8.3.102mdk.x86_64.rpm
ee60914821883fdbca75ec50b9536929 x86_64/10.2/RPMS/apache2-modules-2.0.53-9.4.102mdk.x86_64.rpm
67ef23ffa11a16c85677d00f92bfec5e x86_64/10.2/RPMS/apache2-peruser-2.0.53-9.4.102mdk.x86_64.rpm
b0a16af065114c3a0331c7e3e992153a x86_64/10.2/RPMS/apache2-source-2.0.53-9.4.102mdk.x86_64.rpm
aa7123321a5aef41c57d9669fa600909 x86_64/10.2/RPMS/apache2-worker-2.0.53-9.4.102mdk.x86_64.rpm
c27d53f234ab8c96a69c9c275c6f1f0a x86_64/10.2/SRPMS/apache2-2.0.53-9.4.102mdk.src.rpm
2c26a3a648da8cfd2e4bde1c9bc750f0 x86_64/10.2/SRPMS/apache2-mod_ssl-2.0.53-8.3.102mdk.src.rpm

Mandriva Linux 2006.0:
698cc58241479ed3420b7ea05e004caf 2006.0/RPMS/apache-base-2.0.54-13.2.20060mdk.i586.rpm
50b24b5c0b57d8855b12b1df63907a55 2006.0/RPMS/apache-devel-2.0.54-13.2.20060mdk.i586.rpm
d45773a5afbd7e95b8fbf4a5742d7421 2006.0/RPMS/apache-mod_cache-2.0.54-13.2.20060mdk.i586.rpm
1ed0c6065f7ff959fff70886994db98c 2006.0/RPMS/apache-mod_dav-2.0.54-13.2.20060mdk.i586.rpm
11cdcc4a223fdd3d451c17394a4ab19f 2006.0/RPMS/apache-mod_deflate-2.0.54-13.2.20060mdk.i586.rpm
77554cf3457a32465a9977b51f0f8089 2006.0/RPMS/apache-mod_disk_cache-2.0.54-13.2.20060mdk.i586.rpm
d39cefb6075e3de9c459aa97774cd1c0 2006.0/RPMS/apache-mod_file_cache-2.0.54-13.2.20060mdk.i586.rpm
46246bc1f89e93a8cd317079052cad8b 2006.0/RPMS/apache-mod_ldap-2.0.54-13.2.20060mdk.i586.rpm
6059a50db5752ade252619303d179ac9 2006.0/RPMS/apache-mod_mem_cache-2.0.54-13.2.20060mdk.i586.rpm
52eb38740e1753591a2efe1f165c9a52 2006.0/RPMS/apache-mod_proxy-2.0.54-13.2.20060mdk.i586.rpm
c58f95e19b34e5fffaacec10e999c614 2006.0/RPMS/apache-mod_ssl-2.0.54-6.1.20060mdk.i586.rpm
08d836daa888cd101f00c562931d1d96 2006.0/RPMS/apache-modules-2.0.54-13.2.20060mdk.i586.rpm
fcbf7783e8a0959b78308bc0fcb28c66 2006.0/RPMS/apache-mod_userdir-2.0.54-13.2.20060mdk.i586.rpm
44577d0be1ea6dd781310dc6d82b8357 2006.0/RPMS/apache-mpm-peruser-2.0.54-13.2.20060mdk.i586.rpm
2c7c4b9e077fa21d3be5379feb4a1bf5 2006.0/RPMS/apache-mpm-prefork-2.0.54-13.2.20060mdk.i586.rpm
b5194b3fdc57e710f671695a003d7a86 2006.0/RPMS/apache-mpm-worker-2.0.54-13.2.20060mdk.i586.rpm
c15e6970096ec90359fb5f950838c361 2006.0/RPMS/apache-source-2.0.54-13.2.20060mdk.i586.rpm
f55dcf60da3a4e0bc6a9c7c22f153e32 2006.0/SRPMS/apache-2.0.54-13.2.20060mdk.src.rpm
377a0a4c5813cca0cfd1ec6c1be57964 2006.0/SRPMS/apache-mod_ssl-2.0.54-6.1.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
19f2682c0c8ea82d5d053057ebbea331 x86_64/2006.0/RPMS/apache-base-2.0.54-13.2.20060mdk.x86_64.rpm
3b74fc5aef89568e65f512a52056d98c x86_64/2006.0/RPMS/apache-devel-2.0.54-13.2.20060mdk.x86_64.rpm
0573fef90fc16c5507371b57b78b8163 x86_64/2006.0/RPMS/apache-mod_cache-2.0.54-13.2.20060mdk.x86_64.rpm
2322bbe1b74c5ff49d54cc68839e86ce x86_64/2006.0/RPMS/apache-mod_dav-2.0.54-13.2.20060mdk.x86_64.rpm
e318276c19d2d08fafe6f838b459f214 x86_64/2006.0/RPMS/apache-mod_deflate-2.0.54-13.2.20060mdk.x86_64.rpm
109e024c0fc738fd04336f9fe640a704 x86_64/2006.0/RPMS/apache-mod_disk_cache-2.0.54-13.2.20060mdk.x86_64.rpm
bec4ad366bf9a556387f36bd4586ee1f x86_64/2006.0/RPMS/apache-mod_file_cache-2.0.54-13.2.20060mdk.x86_64.rpm
aa3de6fb4e051150b8c7afee465ac079 x86_64/2006.0/RPMS/apache-mod_ldap-2.0.54-13.2.20060mdk.x86_64.rpm
7ee80c338ffee9b2e4bcf942a5b4684a x86_64/2006.0/RPMS/apache-mod_mem_cache-2.0.54-13.2.20060mdk.x86_64.rpm
65da37880faf3811a35ba596fab84245 x86_64/2006.0/RPMS/apache-mod_proxy-2.0.54-13.2.20060mdk.x86_64.rpm
17be071c0d39a17f0f6d4c9ddf051c42 x86_64/2006.0/RPMS/apache-mod_ssl-2.0.54-6.1.20060mdk.x86_64.rpm
b913963f3ffafce4ddf9d87187f5ccf8 x86_64/2006.0/RPMS/apache-modules-2.0.54-13.2.20060mdk.x86_64.rpm
faf591ab4124eedd3b7121595035087a x86_64/2006.0/RPMS/apache-mod_userdir-2.0.54-13.2.20060mdk.x86_64.rpm
533dff0067505fc71673a112719a3891 x86_64/2006.0/RPMS/apache-mpm-peruser-2.0.54-13.2.20060mdk.x86_64.rpm
3ea58408fb222e88d7b819967ec5ecf7 x86_64/2006.0/RPMS/apache-mpm-prefork-2.0.54-13.2.20060mdk.x86_64.rpm
e2dbb1c9a18e5766a08adc3ddb4f1fb6 x86_64/2006.0/RPMS/apache-mpm-worker-2.0.54-13.2.20060mdk.x86_64.rpm
aa027a7ca0870145495edc79c9e3f7cb x86_64/2006.0/RPMS/apache-source-2.0.54-13.2.20060mdk.x86_64.rpm
f55dcf60da3a4e0bc6a9c7c22f153e32 x86_64/2006.0/SRPMS/apache-2.0.54-13.2.20060mdk.src.rpm
377a0a4c5813cca0cfd1ec6c1be57964 x86_64/2006.0/SRPMS/apache-mod_ssl-2.0.54-6.1.20060mdk.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>


Mandriva Linux Security Advisory MDKSA-2006:008
http://www.mandriva.com/security/


Package : koffice
Date : January 6, 2006
Affected: .


Problem Description:

Multiple heap-based buffer overflows in the DCTStream::readProgressiveSOF and DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, allow user-complicit attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index. (CVE-2005-3191)

Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01 allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field. (CVE-2005-3192)

Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier allows user-complicit attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with large size values that cause insufficient memory to be allocated. (CVE-2005-3193)

An additional patch re-addresses memory allocation routines in goo/gmem.c (Martin Pitt/Canonical, Dirk Mueller/KDE).

In addition, Chris Evans discovered several other vulnerabilities in the xpdf code base:

Out-of-bounds heap accesses with large or negative parameters to "FlateDecode" stream. (CVE-2005-3192)

Out-of-bounds heap accesses with large or negative parameters to "CCITTFaxDecode" stream. (CVE-2005-3624)

Infinite CPU spins in various places when stream ends unexpectedly. (CVE-2005-3625)

NULL pointer crash in the "FlateDecode" stream. (CVE-2005-3626)

Overflows of compInfo array in "DCTDecode" stream. (CVE-2005-3627)

Possible to use index past end of array in "DCTDecode" stream. (CVE-2005-3627)

Possible out-of-bounds indexing trouble in "DCTDecode" stream. (CVE-2005-3627)

Koffice uses an embedded copy of the xpdf code, with the same vulnerabilities.

The updated packages have been patched to correct these problems.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3191
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3192
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3193
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3624
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3625
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3626
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3627
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3628


Updated Packages:


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>


Mandriva Linux Security Advisory MDKSA-2006:009
http://www.mandriva.com/security/


Package : apache2-mod_auth_pgsql
Date : January 6, 2006
Affected: 10.1, 10.2, 2006.0


Problem Description:

iDefense discovered several format string vulnerabilities in the way that mod_auth_pgsql logs information which could potentially be used by a remote attacker to execute arbitrary code as the apache user if mod_auth_pgsql is used for user authentication.

The provided packages have been patched to prevent this problem.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3656


Updated Packages:

Mandriva Linux 10.1:
5fd1e2329146f2c03845fe516acaa123 10.1/RPMS/apache2-mod_auth_pgsql-2.0.50_2.0.2b1-3.1.101mdk.i586.rpm
c7cfefd7de46d13ee74f25e35f2fd76a 10.1/SRPMS/apache2-mod_auth_pgsql-2.0.50_2.0.2b1-3.1.101mdk.src.rpm

Mandriva Linux 10.1/X86_64:
631ed3b26fddd6f5198d4a33aa31326c x86_64/10.1/RPMS/apache2-mod_auth_pgsql-2.0.50_2.0.2b1-3.1.101mdk.x86_64.rpm
c7cfefd7de46d13ee74f25e35f2fd76a x86_64/10.1/SRPMS/apache2-mod_auth_pgsql-2.0.50_2.0.2b1-3.1.101mdk.src.rpm

Mandriva Linux 10.2:
477fd516e48926f13a66cc0a92366598 10.2/RPMS/apache2-mod_auth_pgsql-2.0.53_2.0.2b1-6.1.102mdk.i586.rpm
12baf2fcd6739141f29c4f6000f83e28 10.2/SRPMS/apache2-mod_auth_pgsql-2.0.53_2.0.2b1-6.1.102mdk.src.rpm

Mandriva Linux 10.2/X86_64:
7d5ba837da8f1681587c431fe219f9fa x86_64/10.2/RPMS/apache2-mod_auth_pgsql-2.0.53_2.0.2b1-6.1.102mdk.x86_64.rpm
12baf2fcd6739141f29c4f6000f83e28 x86_64/10.2/SRPMS/apache2-mod_auth_pgsql-2.0.53_2.0.2b1-6.1.102mdk.src.rpm

Mandriva Linux 2006.0:
abe116d3afce2e1dd6c29a4a922ecf0a 2006.0/RPMS/apache-mod_auth_pgsql-2.0.54_2.0.2b1-3.1.20060mdk.i586.rpm
c6755d865f6de4cf51a9f6918798aafc 2006.0/SRPMS/apache-mod_auth_pgsql-2.0.54_2.0.2b1-3.1.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
a8e95a35a1eda50cc392193496c15721 x86_64/2006.0/RPMS/apache-mod_auth_pgsql-2.0.54_2.0.2b1-3.1.20060mdk.x86_64.rpm
c6755d865f6de4cf51a9f6918798aafc x86_64/2006.0/SRPMS/apache-mod_auth_pgsql-2.0.54_2.0.2b1-3.1.20060mdk.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>

Red Hat Linux


Red Hat Security Advisory

Synopsis: Critical: mod_auth_pgsql security update
Advisory ID: RHSA-2006:0164-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2006-0164.html
Issue date: 2006-01-05
Updated on: 2006-01-05
Product: Red Hat Enterprise Linux
CVE Names: CVE-2005-3656


1. Summary:

Updated mod_auth_pgsql packages that fix format string security issues are now available for Red Hat Enterprise Linux 3 and 4.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Problem description:

The mod_auth_pgsql package is an httpd module that allows user authentication against information stored in a PostgreSQL database.

Several format string flaws were found in the way mod_auth_pgsql logs information. It may be possible for a remote attacker to execute arbitrary code as the 'apache' user if mod_auth_pgsql is used for user authentication. The Common Vulnerabilities and Exposures project assigned the name CVE-2005-3656 to this issue.

Please note that this issue only affects servers which have mod_auth_pgsql installed and configured to perform user authentication against a PostgreSQL database.

All users of mod_auth_pgsql should upgrade to these updated packages, which contain a backported patch to resolve this issue.

This issue does not affect the mod_auth_pgsql package supplied with Red Hat Enterprise Linux 2.1.

Red Hat would like to thank iDefense for reporting this issue.

4. Solution:

Before applying this update, make sure all previously released errata relevant to your system have been applied.

This update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system.

5. Bug IDs fixed (http://bugzilla.redhat.com/):

177042 - CVE-2005-3656 mod_auth_pgsql format string issue

6. RPMs required:

Red Hat Enterprise Linux AS version 3:

SRPMS:
ftp://updates.redhat.com/enterprise/3AS/en/os/SRPMS/mod_auth_pgsql-2.0.1-4.ent.1.src.rpm
78d123ce4dd88d2b473f3def9d1f78d8 mod_auth_pgsql-2.0.1-4.ent.1.src.rpm

i386:
416d662759b7e9a6cac6db24813cadf9
mod_auth_pgsql-2.0.1-4.ent.1.i386.rpm

ia64:
4a72fdbf3b94d7d1891e66d8465a5798
mod_auth_pgsql-2.0.1-4.ent.1.ia64.rpm

ppc:
7b319bd7a03d74b6337b259f96950e8c
mod_auth_pgsql-2.0.1-4.ent.1.ppc.rpm

s390:
c989ef09e9c107cd05e9ca4e75bbc789
mod_auth_pgsql-2.0.1-4.ent.1.s390.rpm

s390x:
476139795bf63306aaf2d478fb471982
mod_auth_pgsql-2.0.1-4.ent.1.s390x.rpm

x86_64:
cb2bd4600e4fab1ffc7e2b1fbb2a6dfb
mod_auth_pgsql-2.0.1-4.ent.1.x86_64.rpm

Red Hat Desktop version 3:

SRPMS:
ftp://updates.redhat.com/enterprise/3desktop/en/os/SRPMS/mod_auth_pgsql-2.0.1-4.ent.1.src.rpm
78d123ce4dd88d2b473f3def9d1f78d8 mod_auth_pgsql-2.0.1-4.ent.1.src.rpm

i386:
416d662759b7e9a6cac6db24813cadf9
mod_auth_pgsql-2.0.1-4.ent.1.i386.rpm

x86_64:
cb2bd4600e4fab1ffc7e2b1fbb2a6dfb
mod_auth_pgsql-2.0.1-4.ent.1.x86_64.rpm

Red Hat Enterprise Linux ES version 3:

SRPMS:
ftp://updates.redhat.com/enterprise/3ES/en/os/SRPMS/mod_auth_pgsql-2.0.1-4.ent.1.src.rpm
78d123ce4dd88d2b473f3def9d1f78d8 mod_auth_pgsql-2.0.1-4.ent.1.src.rpm

i386:
416d662759b7e9a6cac6db24813cadf9
mod_auth_pgsql-2.0.1-4.ent.1.i386.rpm

ia64:
4a72fdbf3b94d7d1891e66d8465a5798
mod_auth_pgsql-2.0.1-4.ent.1.ia64.rpm

x86_64:
cb2bd4600e4fab1ffc7e2b1fbb2a6dfb
mod_auth_pgsql-2.0.1-4.ent.1.x86_64.rpm

Red Hat Enterprise Linux WS version 3:

SRPMS:
ftp://updates.redhat.com/enterprise/3WS/en/os/SRPMS/mod_auth_pgsql-2.0.1-4.ent.1.src.rpm
78d123ce4dd88d2b473f3def9d1f78d8 mod_auth_pgsql-2.0.1-4.ent.1.src.rpm

i386:
416d662759b7e9a6cac6db24813cadf9
mod_auth_pgsql-2.0.1-4.ent.1.i386.rpm

ia64:
4a72fdbf3b94d7d1891e66d8465a5798
mod_auth_pgsql-2.0.1-4.ent.1.ia64.rpm

x86_64:
cb2bd4600e4fab1ffc7e2b1fbb2a6dfb
mod_auth_pgsql-2.0.1-4.ent.1.x86_64.rpm

Red Hat Enterprise Linux AS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/mod_auth_pgsql-2.0.1-7.1.src.rpm
2a46d8268d1d434ed8ec089bf83e62bd mod_auth_pgsql-2.0.1-7.1.src.rpm

i386:
19b586cf092086566de31c883b116f8f
mod_auth_pgsql-2.0.1-7.1.i386.rpm

ia64:
90ca4b0d4160b78edda12d3d300bc2bb
mod_auth_pgsql-2.0.1-7.1.ia64.rpm

ppc:
514eea209095325a9d0c4acb6c1a181f
mod_auth_pgsql-2.0.1-7.1.ppc.rpm

s390:
9c32645c2f524537233212c532e6d0a7
mod_auth_pgsql-2.0.1-7.1.s390.rpm

s390x:
7eef05e02885fad7fb86485fe2b46630
mod_auth_pgsql-2.0.1-7.1.s390x.rpm

x86_64:
542f993464e75b8e6370c453e1dc8c7d
mod_auth_pgsql-2.0.1-7.1.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/mod_auth_pgsql-2.0.1-7.1.src.rpm
2a46d8268d1d434ed8ec089bf83e62bd mod_auth_pgsql-2.0.1-7.1.src.rpm

i386:
19b586cf092086566de31c883b116f8f
mod_auth_pgsql-2.0.1-7.1.i386.rpm

x86_64:
542f993464e75b8e6370c453e1dc8c7d
mod_auth_pgsql-2.0.1-7.1.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/mod_auth_pgsql-2.0.1-7.1.src.rpm
2a46d8268d1d434ed8ec089bf83e62bd mod_auth_pgsql-2.0.1-7.1.src.rpm

i386:
19b586cf092086566de31c883b116f8f
mod_auth_pgsql-2.0.1-7.1.i386.rpm

ia64:
90ca4b0d4160b78edda12d3d300bc2bb
mod_auth_pgsql-2.0.1-7.1.ia64.rpm

x86_64:
542f993464e75b8e6370c453e1dc8c7d
mod_auth_pgsql-2.0.1-7.1.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/mod_auth_pgsql-2.0.1-7.1.src.rpm
2a46d8268d1d434ed8ec089bf83e62bd mod_auth_pgsql-2.0.1-7.1.src.rpm

i386:
19b586cf092086566de31c883b116f8f
mod_auth_pgsql-2.0.1-7.1.i386.rpm

ia64:
90ca4b0d4160b78edda12d3d300bc2bb
mod_auth_pgsql-2.0.1-7.1.ia64.rpm

x86_64:
542f993464e75b8e6370c453e1dc8c7d
mod_auth_pgsql-2.0.1-7.1.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3656

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact details at https://www.redhat.com/security/team/contact/

Copyright 2006 Red Hat, Inc.


Red Hat Security Advisory

Synopsis: Critical: auth_ldap security update
Advisory ID: RHSA-2006:0179-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2006-0179.html
Issue date: 2006-01-10
Updated on: 2006-01-10
Product: Red Hat Enterprise Linux
CVE Names: CVE-2006-0150


1. Summary:

An updated auth_ldap packages that fixes a format string security issue is now available for Red Hat Enterprise Linux 2.1.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386

3. Problem description:

The auth_ldap package is an httpd module that allows user authentication against information stored in an LDAP database.

A format string flaw was found in the way auth_ldap logs information. It may be possible for a remote attacker to execute arbitrary code as the 'apache' user if auth_ldap is used for user authentication. The Common Vulnerabilities and Exposures project assigned the name CVE-2006-0150 to this issue.

Note that this issue only affects servers that have auth_ldap installed and configured to perform user authentication against an LDAP database.

All users of auth_ldap should upgrade to this updated package, which contains a backported patch to resolve this issue.

This issue does not affect the Red Hat Enterprise Linux 3 or 4 distributions as they do not include the auth_ldap package.

4. Solution:

Before applying this update, make sure all previously released errata relevant to your system have been applied.

This update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system.

5. Bug IDs fixed (http://bugzilla.redhat.com/):

177421 - CVE-2006-0150 auth_ldap format string issue

6. RPMs required:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1:

SRPMS:
ftp://updates.redhat.com/enterprise/2.1AS/en/os/SRPMS/auth_ldap-1.4.8-3.1.src.rpm
b386cc76da4f4dbbcafc5e0200567b76 auth_ldap-1.4.8-3.1.src.rpm

i386:
569bce40fcb6cc7cefa9179d949fb192
auth_ldap-1.4.8-3.1.i386.rpm

ia64:
56aea79641ddb17dc98d26b6f20dd439
auth_ldap-1.4.8-3.1.ia64.rpm

Red Hat Linux Advanced Workstation 2.1:

SRPMS:
ftp://updates.redhat.com/enterprise/2.1AW/en/os/SRPMS/auth_ldap-1.4.8-3.1.src.rpm
b386cc76da4f4dbbcafc5e0200567b76 auth_ldap-1.4.8-3.1.src.rpm

ia64:
56aea79641ddb17dc98d26b6f20dd439
auth_ldap-1.4.8-3.1.ia64.rpm

Red Hat Enterprise Linux ES version 2.1:

SRPMS:
ftp://updates.redhat.com/enterprise/2.1ES/en/os/SRPMS/auth_ldap-1.4.8-3.1.src.rpm
b386cc76da4f4dbbcafc5e0200567b76 auth_ldap-1.4.8-3.1.src.rpm

i386:
569bce40fcb6cc7cefa9179d949fb192
auth_ldap-1.4.8-3.1.i386.rpm

Red Hat Enterprise Linux WS version 2.1:

SRPMS:
ftp://updates.redhat.com/enterprise/2.1WS/en/os/SRPMS/auth_ldap-1.4.8-3.1.src.rpm
b386cc76da4f4dbbcafc5e0200567b76 auth_ldap-1.4.8-3.1.src.rpm

i386:
569bce40fcb6cc7cefa9179d949fb192
auth_ldap-1.4.8-3.1.i386.rpm

These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0150

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact details at https://www.redhat.com/security/team/contact/

Copyright 2006 Red Hat, Inc.

Ubuntu Linux


Ubuntu Security Notice USN-235-1 January 05, 2006
sudo vulnerability
CVE-2005-4158

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)
Ubuntu 5.04 (Hoary Hedgehog)
Ubuntu 5.10 (Breezy Badger)

The following packages are affected:

sudo

The problem can be corrected by upgrading the affected package to version 1.6.7p5-1ubuntu4.4 (for Ubuntu 4.10), 1.6.8p5-1ubuntu2.3 (for Ubuntu 5.04), or 1.6.8p9-2ubuntu2.2 (for Ubuntu 5.10). In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

Charles Morris discovered a privilege escalation vulnerability in sudo. On executing Perl scripts with sudo, various environment variables that affect Perl's library search path were not cleaned properly. If sudo is set up to grant limited sudo execution of Perl scripts to normal users, this could be exploited to run arbitrary commands as the target user.

This security update also filters out environment variables that can be exploited similarly with Python, Ruby, and zsh scripts.

Please note that this does not affect the default Ubuntu installation, or any setup that just grants full root privileges to certain users.

Updated packages for Ubuntu 4.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.7p5-1ubuntu4.4.diff.gz
      Size/MD5: 28048 5218c513df9c959dd313c4be22aaa25b
    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.7p5-1ubuntu4.4.dsc
      Size/MD5: 585 3f914d6d796048d161dda14c8de1e09f
    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.7p5.orig.tar.gz
      Size/MD5: 349785 55d503e5c35bf1ea83d38244e0242aaf

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.7p5-1ubuntu4.4_amd64.deb
      Size/MD5: 156626 e425b3d24d561805a976fbd860addf90

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.7p5-1ubuntu4.4_i386.deb
      Size/MD5: 146046 740822460f6711c889f331e6f63b3c3b

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.7p5-1ubuntu4.4_powerpc.deb
      Size/MD5: 153604 995c81080a1eb4b5266bae6fa3bad812

Updated packages for Ubuntu 5.04:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.8p5-1ubuntu2.3.diff.gz
      Size/MD5: 24291 cfa4cda75436030ce5c8b2a5778f3736
    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.8p5-1ubuntu2.3.dsc
      Size/MD5: 585 8a8e0849da19d006b46655bbfa57b593
    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.8p5.orig.tar.gz
      Size/MD5: 584832 03538d938b8593d6f1d66ec6c067b5b5

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.8p5-1ubuntu2.3_amd64.deb
      Size/MD5: 170784 1da10690d4d5a3c3623e0b20282de467

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.8p5-1ubuntu2.3_i386.deb
      Size/MD5: 159012 be5ccb2125b6046ddc7b7b850d32812e

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.8p5-1ubuntu2.3_powerpc.deb
      Size/MD5: 165848 9a2e4fbd41fc1cc8280c3a013ef3d3fb

Updated packages for Ubuntu 5.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.8p9-2ubuntu2.2.diff.gz
      Size/MD5: 22481 3b49d421cf10302c44e601946c029f06
    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.8p9-2ubuntu2.2.dsc
      Size/MD5: 585 10738797809673ab80a30ce1a2401ffd
    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.8p9.orig.tar.gz
      Size/MD5: 585509 6d0346abd16914956bc7ea4f17fc85fb

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.8p9-2ubuntu2.2_amd64.deb
      Size/MD5: 172686 466d5461ec58d669f5978ffe47e2ff1d

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.8p9-2ubuntu2.2_i386.deb
      Size/MD5: 159106 5a4898a7ea752ae91b9113d5d8d5751c

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.8p9-2ubuntu2.2_powerpc.deb
      Size/MD5: 167236 43125eeceec512ca67b03d30fc4d2484


Ubuntu Security Notice USN-236-1 January 05, 2006
xpdf, poppler, cupsys, tetex-bin vulnerabilities
CVE-2005-3624, CVE-2005-3625, CVE-2005-3626, CVE-2005-3627

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)
Ubuntu 5.04 (Hoary Hedgehog)
Ubuntu 5.10 (Breezy Badger)

The following packages are affected:

cupsys
libpoppler0c2
tetex-bin
xpdf-reader
xpdf-utils

The problem can be corrected by upgrading the affected package to the following versions:

Ubuntu 4.10:

xpdf: 3.00-8ubuntu1.10 cupsys: 1.1.20final+cvs20040330-4ubuntu16.10 tetex-bin: 2.0.2-21ubuntu0.7

Ubuntu 5.04:

xpdf: 3.00-11ubuntu3.6 tetex-bin: 2.0.2-25ubuntu0.4

Ubuntu 5.10:
libpoppler0c2: 0.4.2-0ubuntu6.5
tetex-bin: 2.0.2-30ubuntu3.4

In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

Chris Evans discovered several integer overflows in the XPDF code, which is present in xpdf, the Poppler library, and tetex-bin. By tricking an user into opening a specially crafted PDF file, an attacker could exploit this to execute arbitrary code with the privileges of the application that processes the document.

The CUPS printing system also uses XPDF code to convert PDF files to PostScript. By attempting to print such a crafted PDF file, a remote attacker could execute arbitrary code with the privileges of the printer server (user 'cupsys').

Updated packages for Ubuntu 4.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys_1.1.20final+cvs20040330-4ubuntu16.10.diff.gz
      Size/MD5: 1356783 70cf50cb2698eda0f1fdf4ba80bba9c0
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys_1.1.20final+cvs20040330-4ubuntu16.10.dsc
      Size/MD5: 869 6419d00d007c25bbb3dfde3a211da8a2
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys_1.1.20final+cvs20040330.orig.tar.gz
      Size/MD5: 5645146 5eb5983a71b26e4af841c26703fc2f79
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-21ubuntu0.8.diff.gz
      Size/MD5: 115044 1e418efc75c217322017a65531aa7577
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-21ubuntu0.8.dsc
      Size/MD5: 1062 08d1cae5f243f41c22849af971df51a2
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2.orig.tar.gz
      Size/MD5: 11677169 8f02d5940bf02072ce5fe05429c90e63
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf_3.00-8ubuntu1.10.diff.gz
      Size/MD5: 50967 df04827d6c4e0444319c9ceae6f64e7c
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf_3.00-8ubuntu1.10.dsc
      Size/MD5: 790 67411f3b9b4bab265bc6d99b2c5cdb3d
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf_3.00.orig.tar.gz
      Size/MD5: 534697 95294cef3031dd68e65f331e8750b2c2

Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-common_3.00-8ubuntu1.10_all.deb
      Size/MD5: 56950 6ee4e6d4442efd717e1a9a2ae080986c
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf_3.00-8ubuntu1.10_all.deb
      Size/MD5: 1282 b2695f5415cf3541bdaf5fe4d7115d3e

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys-bsd_1.1.20final+cvs20040330-4ubuntu16.10_amd64.deb
      Size/MD5: 59524 a85a0138ae4d9d5467703136e9ac6e97
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys-client_1.1.20final+cvs20040330-4ubuntu16.10_amd64.deb
      Size/MD5: 107866 5764836e8deebbfab06b4e3519eed2c1
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys_1.1.20final+cvs20040330-4ubuntu16.10_amd64.deb
      Size/MD5: 3615784 fa3748932d7e2d007012ca15882d3e35
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsimage2-dev_1.1.20final+cvs20040330-4ubuntu16.10_amd64.deb
      Size/MD5: 63178 17dd4cd8ebbb35628a87add73feaa88a
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsimage2_1.1.20final+cvs20040330-4ubuntu16.10_amd64.deb
      Size/MD5: 53828 18778f1d6d2534e32304a97004a82e28
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsys2-dev_1.1.20final+cvs20040330-4ubuntu16.10_amd64.deb
      Size/MD5: 102316 fadb908483701999d4a5e3b45a0c5e3f
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsys2-gnutls10_1.1.20final+cvs20040330-4ubuntu16.10_amd64.deb
      Size/MD5: 75364 cea8e759b61180e3b3caf0077163e130
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea-dev_2.0.2-21ubuntu0.8_amd64.deb
      Size/MD5: 72750 0286333baff0270901cad8a7ba39bd43
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea3_2.0.2-21ubuntu0.8_amd64.deb
      Size/MD5: 60678 050ccb51b249f8251b353d3f790c37a0
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-21ubuntu0.8_amd64.deb
      Size/MD5: 4329890 1a89d71600ca13bdc909937e161028e6
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-reader_3.00-8ubuntu1.10_amd64.deb
      Size/MD5: 668002 dc13243a970e6e7613e6f40a80f35d4a
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-utils_3.00-8ubuntu1.10_amd64.deb
      Size/MD5: 1274366 9139208cdc21eea9a918e03c261483b2

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys-bsd_1.1.20final+cvs20040330-4ubuntu16.10_i386.deb
      Size/MD5: 58868 c10b30a78ba36ed779a4559e21e4f750
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys-client_1.1.20final+cvs20040330-4ubuntu16.10_i386.deb
      Size/MD5: 105608 6cc7a55b7b329ebc1b276b393ababdfe
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys_1.1.20final+cvs20040330-4ubuntu16.10_i386.deb
      Size/MD5: 3604646 ad79b6c0aa5d22e9d895edb0a2e2bfbc
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsimage2-dev_1.1.20final+cvs20040330-4ubuntu16.10_i386.deb
      Size/MD5: 62736 a147e720d247c711937b506392f00939
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsimage2_1.1.20final+cvs20040330-4ubuntu16.10_i386.deb
      Size/MD5: 53392 87a5119820ce75167ab660e02f6e9b1d
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsys2-dev_1.1.20final+cvs20040330-4ubuntu16.10_i386.deb
      Size/MD5: 98952 adf242c814d93aa8f69e8555499969c5
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsys2-gnutls10_1.1.20final+cvs20040330-4ubuntu16.10_i386.deb
      Size/MD5: 72636 d7dd933126043bd716596f5388c593ae
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea-dev_2.0.2-21ubuntu0.8_i386.deb
      Size/MD5: 64816 b612d75ce93f9d0a8c719d3a561c1665
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea3_2.0.2-21ubuntu0.8_i386.deb
      Size/MD5: 57108 0f6214c10ad0f219da4f68e27140c30d
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-21ubuntu0.8_i386.deb
      Size/MD5: 3814532 610ab1d57e85c9c54097664df9b44a2c
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-reader_3.00-8ubuntu1.10_i386.deb
      Size/MD5: 633054 39428df85e30742c005ccb5e6cb85ad9
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-utils_3.00-8ubuntu1.10_i386.deb
      Size/MD5: 1196622 7796d8702bc51268325abeef2a3e8705

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys-bsd_1.1.20final+cvs20040330-4ubuntu16.10_powerpc.deb
      Size/MD5: 63444 e5f1b9c38f9301dfa3dda5a5abf5132d
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys-client_1.1.20final+cvs20040330-4ubuntu16.10_powerpc.deb
      Size/MD5: 115430 b4b4a1c965cb5c6cfbbfed0f6350cf75
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys_1.1.20final+cvs20040330-4ubuntu16.10_powerpc.deb
      Size/MD5: 3635092 6e90b4c97a89abc955bd0a27cfbf081d
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsimage2-dev_1.1.20final+cvs20040330-4ubuntu16.10_powerpc.deb
      Size/MD5: 62364 ba9781a3f6ac12995e468178f9579ab7
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsimage2_1.1.20final+cvs20040330-4ubuntu16.10_powerpc.deb
      Size/MD5: 56028 ecd23c117a5d9baedae11666f59de4d6
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsys2-dev_1.1.20final+cvs20040330-4ubuntu16.10_powerpc.deb
      Size/MD5: 101692 338f9c14d0cc16f13a4e8ef205fce357
    http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsys2-gnutls10_1.1.20final+cvs20040330-4ubuntu16.10_powerpc.deb
      Size/MD5: 75462 a8f11ea69bb384a28419826c135bc675
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea-dev_2.0.2-21ubuntu0.8_powerpc.deb
      Size/MD5: 74894 75c33bc046c97e754f646f3f0e12411f
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea3_2.0.2-21ubuntu0.8_powerpc.deb
      Size/MD5: 62056 da8d8549d1d038ddc79b2e9a64887d50
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-21ubuntu0.8_powerpc.deb
      Size/MD5: 4352698 b86700e68e8dcd7688751edcbf519d27
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-reader_3.00-8ubuntu1.10_powerpc.deb
      Size/MD5: 694178 3d58566f6d96c4cab62317b49aa6ae87
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-utils_3.00-8ubuntu1.10_powerpc.deb
      Size/MD5: 1314108 4f2b9f97072c67b168d38caf822c552c

Updated packages for Ubuntu 5.04:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-25ubuntu0.4.diff.gz
      Size/MD5: 128664 45240e7994c9367f938f584098fbb09c
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-25ubuntu0.4.dsc
      Size/MD5: 1062 a07000b306e0920065c77cd2f9b384cc
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2.orig.tar.gz
      Size/MD5: 11677169 8f02d5940bf02072ce5fe05429c90e63
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf_3.00-11ubuntu3.6.diff.gz
      Size/MD5: 51784 b15793093c9c2711075888c63af9ab39
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf_3.00-11ubuntu3.6.dsc
      Size/MD5: 798 906bd260f2b44a8a5ac9d01dd4993995
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf_3.00.orig.tar.gz
      Size/MD5: 534697 95294cef3031dd68e65f331e8750b2c2

Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-common_3.00-11ubuntu3.6_all.deb
      Size/MD5: 57200 4400774e9933c5349b9789c52a44b095
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf_3.00-11ubuntu3.6_all.deb
      Size/MD5: 1284 c625f5692f602d4ebcf2c47258fdece3

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea-dev_2.0.2-25ubuntu0.4_amd64.deb
      Size/MD5: 72754 f363a4a3d8722e498f0f18bf73ce497f
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea3_2.0.2-25ubuntu0.4_amd64.deb
      Size/MD5: 61370 eb13736eb2b41093d1bf90773c2910f5
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-25ubuntu0.4_amd64.deb
      Size/MD5: 4355314 a681cbd47377db085c2a42019d0a053f
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-reader_3.00-11ubuntu3.6_amd64.deb
      Size/MD5: 668054 1eab64286fbeaef4657cb49511973707
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-utils_3.00-11ubuntu3.6_amd64.deb
      Size/MD5: 1274368 4de5460d641a76aad11e151c3b026dd6

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea-dev_2.0.2-25ubuntu0.4_i386.deb
      Size/MD5: 64806 31942578e6865ed72e00f14dbe3a9343
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea3_2.0.2-25ubuntu0.4_i386.deb
      Size/MD5: 57828 42bd4718aea17e67f3e29871d05cfc95
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-25ubuntu0.4_i386.deb
      Size/MD5: 3835352 023cbca029204dc69d56711fbc659f81
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-reader_3.00-11ubuntu3.6_i386.deb
      Size/MD5: 632918 b920732995531e02d8890c3215de6ea2
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-utils_3.00-11ubuntu3.6_i386.deb
      Size/MD5: 1196030 4613c0b5ef2c9c7be45d1c3b6869c80b

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea-dev_2.0.2-25ubuntu0.4_powerpc.deb
      Size/MD5: 74898 a1554733d124cb750632520bd899754d
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea3_2.0.2-25ubuntu0.4_powerpc.deb
      Size/MD5: 62822 ac4f66789f6decf07d4e80e52ff9e0d5
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-25ubuntu0.4_powerpc.deb
      Size/MD5: 4380704 32db3c3f89c30f7dd5ca3c358e49cd34
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-reader_3.00-11ubuntu3.6_powerpc.deb
      Size/MD5: 694340 0faabc75501ead26b97d7517d233627a
    http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-utils_3.00-11ubuntu3.6_powerpc.deb
      Size/MD5: 1314038 d26cb93199833036603de84a618ae958

Updated packages for Ubuntu 5.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/poppler_0.4.2-0ubuntu6.5.diff.gz
      Size/MD5: 108158 3b0400388e9fe6848d52f944950fbc2a
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/poppler_0.4.2-0ubuntu6.5.dsc
      Size/MD5: 1655 ee433ee2475783eb5e3170931773ed0e
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/poppler_0.4.2.orig.tar.gz
      Size/MD5: 777935 beb1eea135a3c5b679a7a22d01a500c0
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-30ubuntu3.4.diff.gz
      Size/MD5: 156562 bb792572fbde8b63615165e3740186f9
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-30ubuntu3.4.dsc
      Size/MD5: 1026 23cac8967296e48d4da27de0837c2a0f
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2.orig.tar.gz
      Size/MD5: 11677169 8f02d5940bf02072ce5fe05429c90e63

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea-dev_2.0.2-30ubuntu3.4_amd64.deb
      Size/MD5: 73848 900cf4e89cf55f4680a5944817840b6c
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea3_2.0.2-30ubuntu3.4_amd64.deb
      Size/MD5: 63076 5009e9b32adaa3ac8bbe635b599909e0
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/libpoppler-dev_0.4.2-0ubuntu6.5_amd64.deb
      Size/MD5: 611756 95c5c5c54b57e6e70593be4f99568f53
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/libpoppler-glib-dev_0.4.2-0ubuntu6.5_amd64.deb
      Size/MD5: 44156 06abe0627ce47641f5f21411e7573024
    http://security.ubuntu.com/ubuntu/pool/universe/p/poppler/libpoppler-qt-dev_0.4.2-0ubuntu6.5_amd64.deb
      Size/MD5: 29460 e4ab72981af906ee9f502d868f2ecb92
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/libpoppler0c2-glib_0.4.2-0ubuntu6.5_amd64.deb
      Size/MD5: 39820 b04fed79f5981be18da3c147c7f2d468
    http://security.ubuntu.com/ubuntu/pool/universe/p/poppler/libpoppler0c2-qt_0.4.2-0ubuntu6.5_amd64.deb
      Size/MD5: 28164 236bf5b8c7db1e4eca25993af9b73308
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/libpoppler0c2_0.4.2-0ubuntu6.5_amd64.deb
      Size/MD5: 455384 7a943e97109c49e9e0451681f6b3dc4b
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/poppler-utils_0.4.2-0ubuntu6.5_amd64.deb
      Size/MD5: 82644 59448a2dd769a55417a282c678c727cf
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-30ubuntu3.4_amd64.deb
      Size/MD5: 4482546 13854c81a43ff61f83f5acb62073457b

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea-dev_2.0.2-30ubuntu3.4_i386.deb
      Size/MD5: 65990 be626bfe51eb356c164680fc3473e88f
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea3_2.0.2-30ubuntu3.4_i386.deb
      Size/MD5: 59122 56367f7df74b07d5920c6eec00e415c2
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/libpoppler-dev_0.4.2-0ubuntu6.5_i386.deb
      Size/MD5: 549104 c3e85404bed40383f2a50e321e77e2eb
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/libpoppler-glib-dev_0.4.2-0ubuntu6.5_i386.deb
      Size/MD5: 41376 9a949716495531222246fe1bf26b5fbf
    http://security.ubuntu.com/ubuntu/pool/universe/p/poppler/libpoppler-qt-dev_0.4.2-0ubuntu6.5_i386.deb
      Size/MD5: 28392 e4af4ab179e8aa794a44b87edb61bc6b
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/libpoppler0c2-glib_0.4.2-0ubuntu6.5_i386.deb
      Size/MD5: 38286 c43802ca8e232aa7ac8b8c64e826c4be
    http://security.ubuntu.com/ubuntu/pool/universe/p/poppler/libpoppler0c2-qt_0.4.2-0ubuntu6.5_i386.deb
      Size/MD5: 27502 b1dc43c7cf9b1df947ff3c0512c4f5ee
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/libpoppler0c2_0.4.2-0ubuntu6.5_i386.deb
      Size/MD5: 416006 bb98e269ec369ac2142cef3b4e183a7f
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/poppler-utils_0.4.2-0ubuntu6.5_i386.deb
      Size/MD5: 76994 b4752646cdcd2f2a662008b6a2955833
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-30ubuntu3.4_i386.deb
      Size/MD5: 3883882 1e314747d160ea172c78f15e6924ad80

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea-dev_2.0.2-30ubuntu3.4_powerpc.deb
      Size/MD5: 75808 d6fd625468a9b7ef81a6c2fb3bf49e9c
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea3_2.0.2-30ubuntu3.4_powerpc.deb
      Size/MD5: 64304 faf97ea53dcdbff89049204171a0e69f
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/libpoppler-dev_0.4.2-0ubuntu6.5_powerpc.deb
      Size/MD5: 643884 8a478eb72ab0c39fec824f42f787ecf4
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/libpoppler-glib-dev_0.4.2-0ubuntu6.5_powerpc.deb
      Size/MD5: 46320 cbdf9ca4730b2a9cc44f1787d993cae6
    http://security.ubuntu.com/ubuntu/pool/universe/p/poppler/libpoppler-qt-dev_0.4.2-0ubuntu6.5_powerpc.deb
      Size/MD5: 29786 ba6e5d1dd6a10b99e94f00651e27f420
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/libpoppler0c2-glib_0.4.2-0ubuntu6.5_powerpc.deb
      Size/MD5: 41310 d461300dd976d041d514f07761026647
    http://security.ubuntu.com/ubuntu/pool/universe/p/poppler/libpoppler0c2-qt_0.4.2-0ubuntu6.5_powerpc.deb
      Size/MD5: 29652 a7d323e54fa19dfb1b287a3dbb33a399
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/libpoppler0c2_0.4.2-0ubuntu6.5_powerpc.deb
      Size/MD5: 457778 48200cc18151a2c6d1c24d5fa91b4529
    http://security.ubuntu.com/ubuntu/pool/main/p/poppler/poppler-utils_0.4.2-0ubuntu6.5_powerpc.deb
      Size/MD5: 87660 f0efcd8ce009edf98a43e0a2f0a28d5a
    http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-30ubuntu3.4_powerpc.deb
      Size/MD5: 4471706 c982b93f69b93ffbb4ef021b523165f5


Ubuntu Security Notice USN-236-2 January 09, 2006
kdegraphics, koffice vulnerabilities
CVE-2005-3624, CVE-2005-3625, CVE-2005-3626, CVE-2005-3627

A security issue affects the following Ubuntu releases:

Ubuntu 5.04 (Hoary Hedgehog)
Ubuntu 5.10 (Breezy Badger)

The following packages are affected:

kpdf
kword

The problem can be corrected by upgrading the affected package to the following versions:

Ubuntu 5.04:

kpdf: 1:1.3.5-2ubuntu1.3
kword: 4:3.4.0-0ubuntu3.3

Ubuntu 5.10:

libpoppler0c2: 1:1.4.1-0ubuntu7.2
kword: 4:3.4.3-0ubuntu2.2

After a standard system upgrade you need to restart kpdf and kword to effect the necessary changes.

Details follow:

USN-236-1 fixed several vulnerabilities in xpdf. kpdf and kword contain copies of xpdf code and are thus vulnerable to the same issues.

For reference, this is the original advisory:

Chris Evans discovered several integer overflows in the XPDF code, which is present in xpdf, the Poppler library, and tetex-bin. By tricking an user into opening a specially crafted PDF file, an attacker could exploit this to execute arbitrary code with the privileges of the application that processes the document.

Updated packages for Ubuntu 5.04:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kdegraphics_3.4.0-0ubuntu3.3.diff.gz
      Size/MD5: 158398 9db30424b899f3fb56b0590748be696c
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kdegraphics_3.4.0-0ubuntu3.3.dsc
      Size/MD5: 1373 adee4c9bcb48e9697d743123dd904797
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kdegraphics_3.4.0.orig.tar.gz
      Size/MD5: 8099991 c60ab0a0d727701144b5342dcbee201a
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koffice_1.3.5-2ubuntu1.3.diff.gz
      Size/MD5: 11243 2a5cacc1efbd52cf9173ac6c81b369e0
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koffice_1.3.5-2ubuntu1.3.dsc
      Size/MD5: 1000 5f6c95f21c07fb52ac3c94a8df659ead
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koffice_1.3.5.orig.tar.gz
      Size/MD5: 13154501 2c9b45ecbf16a8c5d16ce9d2f51c2571

Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kdegraphics_3.4.0-0ubuntu3.3_all.deb
      Size/MD5: 10902 9f696262640aba230190f6c39f8240fb
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kivio-data_1.3.5-2ubuntu1.3_all.deb
      Size/MD5: 615888 53f2fc7051115f4c3eb7173b3b345108
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koffice-data_1.3.5-2ubuntu1.3_all.deb
      Size/MD5: 685370 e79fa0d6c393788141567269701b621d
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koffice-doc-html_1.3.5-2ubuntu1.3_all.deb
      Size/MD5: 305970 2d048f1183cc1f12d7e4ddb79367ecb2
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koffice_1.3.5-2ubuntu1.3_all.deb
      Size/MD5: 14106 d99a235f6eb7247cd2845898c2218564

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kamera_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 82562 11dd07b3282e958df0cafdab5edf8a26
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/karbon_1.3.5-2ubuntu1.3_amd64.deb
      Size/MD5: 855260 fc7b950da1cf313361b526f0c8994b0c
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kchart_1.3.5-2ubuntu1.3_amd64.deb
      Size/MD5: 674352 ef41ae2ca4155f07e37094fc48b569c3
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kcoloredit_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 94122 146bc3adba2280df9f07ff24164872c4
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kdegraphics-dev_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 59420 c3b54746c8d5d5adedb1e161ae8b1884
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kdegraphics-kfile-plugins_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 265096 ad50f86a5d457a544fe7256e126a0b08
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kdvi_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 505336 08eae2b16adf6b177a5edcde634ee2de
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kfax_3.4.0-0ubuntu3.3_amd64.deb Size/MD5: 143708 1d0791d16859ca91cb99f791c62efaa7
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kformula_1.3.5-2ubuntu1.3_amd64.deb
      Size/MD5: 693932 edf6d48f64812c273bb758a12c9804fa
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kgamma_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 76724 7c9aa5c65b1d3c8deb84e972c9c8324a
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kghostview_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 231466 8a6f94297dee00ec6f151cccf7861157
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kiconedit_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 137922 33eb0e8eda50190404d3dd04bdb2dc23
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kivio_1.3.5-2ubuntu1.3_amd64.deb
      Size/MD5: 583846 0b459d969cbb1dcb1c767ef9ef866546
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kmrml_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 228170 ec7ef99cd588650b99980ce3d49d0ee4
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koffice-dev_1.3.5-2ubuntu1.3_amd64.deb
      Size/MD5: 148072 251796ad9ae8d66152cc12b7bd78b30f
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koffice-libs_1.3.5-2ubuntu1.3_amd64.deb
      Size/MD5: 2135582 9bb355a2259dbf8d5412f1afc6586e09
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kolourpaint_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 799340 9207d36406dc32993528851ff71a2d3d
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kooka_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 753634 d5e0d9315ae634066257ba09e0ac5192
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koshell_1.3.5-2ubuntu1.3_amd64.deb
      Size/MD5: 51788 5d0b0c96d70e2423a83f9be5a5979404
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kpdf_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 659664 f29539e7025aca999c0a612ba2cfaeba
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kpovmodeler_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 2240230 55c5ec54fa41f0f5e3a67f3e2ed7c187
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kpresenter_1.3.5-2ubuntu1.3_amd64.deb
      Size/MD5: 2537302 775eb355824d45ddb8dea9f721a671cb
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kruler_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 56854 05d9c4bdd3203fc1b98875d009bb736c
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/ksnapshot_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 132682 3bef71587887b4913e539a9b437382aa
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kspread_1.3.5-2ubuntu1.3_amd64.deb
      Size/MD5: 1755326 81ca9417afeb811fdcfddc87b6f46090
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/ksvg_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 1217054 cef54ba3b425fc0df32bdcb4571f370c
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kugar_1.3.5-2ubuntu1.3_amd64.deb
      Size/MD5: 552400 82711bf47cf55fd326ba453bb9f92cb6
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kuickshow_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 471912 ea4f7f5aab0db781ff7fb61f321ab0c9
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kview_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 686180 f8b481f6e0f055c03f8c827c6052b3bb
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kviewshell_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 256660 d80289045822a3d25e49a9ad625fd2e7
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kword_1.3.5-2ubuntu1.3_amd64.deb
      Size/MD5: 3591928 d77699c70fafcde1c3581f6365cc91b9
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/libkscan-dev_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 10296 695d8d2b85839a3fa9b01cfa0b4921b8
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/libkscan1_3.4.0-0ubuntu3.3_amd64.deb
      Size/MD5: 134366 597f3b881d0f483b4f2f2c0a8a82557b

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kamera_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 78998 5a06bd2f8b922f0e7283d7a4b7b53694
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/karbon_1.3.5-2ubuntu1.3_i386.deb
      Size/MD5: 779268 c5a3d6e40c8eeee84a5607a49fe8246f
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kchart_1.3.5-2ubuntu1.3_i386.deb
      Size/MD5: 660882 f10f68be7ee7e91346091fe936f429fc
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kcoloredit_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 86812 c76de85a25358c0eb8a22af1de37dbdb
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kdegraphics-dev_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 59430 c92307ea66d88a20967fcb074c8ce6f3
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kdegraphics-kfile-plugins_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 222464 675bef4e842d0d187db12fe085cdfaaf
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kdvi_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 496428 25f3feead7ad6bda6847b718cee14225
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kfax_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 136502 09bc386cd660c6dbd97f06e6231b1cec
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kformula_1.3.5-2ubuntu1.3_i386.deb
      Size/MD5: 689850 c65ccde4b76c8725b811e1db4f925b83
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kgamma_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 73858 c85afdaf39ed53dd0cee8e5846ad06d2
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kghostview_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 220680 364546b05f360adbfab78e9d0a334127
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kiconedit_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 126578 cc2aca9082d8a3adf7d6b49aa61a8249
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kivio_1.3.5-2ubuntu1.3_i386.deb
      Size/MD5: 541946 680e296e38c7325d2b80707b81847f3b
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kmrml_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 210752 0854ed60ccb2753d4864b9dba2008c7b
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koffice-dev_1.3.5-2ubuntu1.3_i386.deb
      Size/MD5: 148070 21986b1cc43d8e0832be28ccd3bd0796
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koffice-libs_1.3.5-2ubuntu1.3_i386.deb
      Size/MD5: 1995222 cc243289c79e303e9f2b3a627a6d3084
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kolourpaint_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 767594 dcdf65e9d8d97d00344cd043e60cb64c
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kooka_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 738762 81a4d73d762942210e9c3ebe20df5162
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koshell_1.3.5-2ubuntu1.3_i386.deb
      Size/MD5: 49578 30d95ee1fa69bc2685936be1fd7cf06a
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kpdf_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 612534 15632b40e795a84f6fc90b77c1bf6140
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kpovmodeler_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 2169210 de63173a6c015460ce56043c41741e99
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kpresenter_1.3.5-2ubuntu1.3_i386.deb
      Size/MD5: 2503824 a37276a6c3f79a1a0ee72ec4c43d7a91
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kruler_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 55388 3884e22484c9fb6683e66572ecf51ca1
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/ksnapshot_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 129340 e3ec0756347ac46bfbeb48da20d0c2f7
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kspread_1.3.5-2ubuntu1.3_i386.deb
      Size/MD5: 1669158 466096908fb3a50c65feba74b3599e63
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/ksvg_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 1195642 9c736e4291a2d729fdb325a1eae39175
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kugar_1.3.5-2ubuntu1.3_i386.deb
      Size/MD5: 533916 8c1890b28d6dda27876de50ceb44058c
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kuickshow_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 464002 02ef4bf8642eb4f8e925afba72019f5d
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kview_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 648844 1cf3025ef4d2b83f7914122aebe1fc7a
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kviewshell_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 238156 fa82037e65e43d58d4141074192ba755
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kword_1.3.5-2ubuntu1.3_i386.deb
      Size/MD5: 3453298 fe39708e776bf19b26620fba588426eb
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/libkscan-dev_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 10298 fe206552273a1d9c3ba4bb652147291f
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/libkscan1_3.4.0-0ubuntu3.3_i386.deb
      Size/MD5: 125668 efad3f6c426749d3164a4869def770ec

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kamera_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 79714 86ae34b12c6a169172ea3bc3a9a28290
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/karbon_1.3.5-2ubuntu1.3_powerpc.deb
      Size/MD5: 827488 c50f71f2bef52983b32e5034743ff311
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kchart_1.3.5-2ubuntu1.3_powerpc.deb
      Size/MD5: 651794 8462677f9e469f8830d33be14b2bd9ae
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kcoloredit_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 88710 9dbe72f46dcc39c414d4e694169be3af
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kdegraphics-dev_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 59428 155c85a2ac00d5de235c902abc6ae7fa
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kdegraphics-kfile-plugins_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 261052 b2f283b6f1beadf14b881f7d661cfbbe
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kdvi_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 493792 1741d5247c6730e280eec5b6e50389db
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kfax_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 139172 e6bb01690deb2ea26ab404bd4a940a81
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kformula_1.3.5-2ubuntu1.3_powerpc.deb
      Size/MD5: 691152 7f731040fc226aa16bc4ef8263bb51c9
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kgamma_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 74478 cb6908554792780f42209f5822584e25
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kghostview_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 222958 1b87974768e826e713b0677349b4a38c
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kiconedit_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 127644 063b9e7bc969bc24d74500098dd7f07c
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kivio_1.3.5-2ubuntu1.3_powerpc.deb
      Size/MD5: 555576 01e91674288a0d512ee5f1f02613b503
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kmrml_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 216288 51975d3716d28e79a7e49067d3ae4aee
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koffice-dev_1.3.5-2ubuntu1.3_powerpc.deb
      Size/MD5: 148074 c227d59a05dc0f20c6dc3f525213b604
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koffice-libs_1.3.5-2ubuntu1.3_powerpc.deb
      Size/MD5: 2023540 249cc57abf501dfa64b55f95826dd5b5
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kolourpaint_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 757358 250e848a70311e50052a1c94a19a9831
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kooka_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 738708 08b74eff1b85e4591aadc83df37346d3
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/koshell_1.3.5-2ubuntu1.3_powerpc.deb
      Size/MD5: 52054 a4d6047e11059be097c03cda6237a800
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kpdf_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 630262 eebf6bde76ecc2f471ae08736167882c
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kpovmodeler_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 2152862 8d36288a69f5885823b3bfeaa3fec3e9
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kpresenter_1.3.5-2ubuntu1.3_powerpc.deb
      Size/MD5: 2480088 e01719bbea1fc5ab3edcc5f7eaea91a9
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kruler_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 55000 96e0a13be7059afe6945e76dd647e30b
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/ksnapshot_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 129092 913a3fe9748ff392d936e6f5a8a7d62f
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kspread_1.3.5-2ubuntu1.3_powerpc.deb
      Size/MD5: 1664024 aa3e2ef658102430361c198d9b96955e
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/ksvg_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 1178978 e8532fd5e4e32959a63414bea4a4a5d2
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kugar_1.3.5-2ubuntu1.3_powerpc.deb
      Size/MD5: 534208 21003c4f0cc8e650ab8cd64ad2c28ea6
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kuickshow_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 465646 c565ca8ea2d1f3b33739addeec1aee80
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kview_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 682896 5b63cf5c1e00baeccaa52127bdf8dc9a
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kviewshell_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 239288 1d2ebd0b4479a96d859daa13187db0cc
    http://security.ubuntu.com/ubuntu/pool/universe/k/koffice/kword_1.3.5-2ubuntu1.3_powerpc.deb
      Size/MD5: 3493044 46a299a1774626393a0cd7636dc8efc5
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/libkscan-dev_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 10304 af4d01c5a5d43362a166843791d2d870
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/libkscan1_3.4.0-0ubuntu3.3_powerpc.deb
      Size/MD5: 127348 9e67dc1d5311d25f2aa099ec3ec36801

Updated packages for Ubuntu 5.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kdegraphics_3.4.3-0ubuntu2.2.diff.gz
      Size/MD5: 191701 66a4002c1918810d4332f5d03d3b89bb
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kdegraphics_3.4.3-0ubuntu2.2.dsc
      Size/MD5: 1450 2e9eb7ba513b708844f1159bb3ef50fe
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kdegraphics_3.4.3.orig.tar.gz
      Size/MD5: 8067314 778d7159d185220af63066bfcc768211
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koffice_1.4.1-0ubuntu7.2.diff.gz
      Size/MD5: 67251 2b5356ae3cfe7abe9ebddf3b521f7421
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koffice_1.4.1-0ubuntu7.2.dsc
      Size/MD5: 1048 1236357a8c649ac56b0d4c5e52e1ae0e
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koffice_1.4.1.orig.tar.gz
      Size/MD5: 21026614 9e214aef83d2a9a6485a831a67b7bcfa

Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kdegraphics-doc-html_3.4.3-0ubuntu2.2_all.deb
      Size/MD5: 144158 97f156793b2107659f744c68f025dd8e
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kdegraphics_3.4.3-0ubuntu2.2_all.deb
      Size/MD5: 19028 46cc5471e64a6d2fa1ee4f7ecd113c32
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kivio-data_1.4.1-0ubuntu7.2_all.deb
      Size/MD5: 634574 3dc62a012ee8b1f53469f4ab5639a11a
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koffice-data_1.4.1-0ubuntu7.2_all.deb
      Size/MD5: 688188 ffceb7fa106e10d8e265493909d7f88e
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koffice-doc-html_1.4.1-0ubuntu7.2_all.deb
      Size/MD5: 326138 3227536fb4d8b0b5eb3829e1d5671b08
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koffice_1.4.1-0ubuntu7.2_all.deb
      Size/MD5: 22722 f3a9cc9340915f5f1a775f9ed481ef03

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kamera_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 92084 228d75134d82b53f337792b399dc4538
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/karbon_1.4.1-0ubuntu7.2_amd64.deb
      Size/MD5: 432824 df43ef124267e64f76f878139ad853a2
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kchart_1.4.1-0ubuntu7.2_amd64.deb
      Size/MD5: 960726 09a9b774c0f0384bf2a8053ab6db34cc
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kcoloredit_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 108398 2129bc936a37df2d71e28359db52c2e4
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kdegraphics-dev_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 66998 68e0b61abd547b820207a6a1affbab4c
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kdegraphics-kfile-plugins_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 269708 64338cec2719781752ddaa1f899ac2a3
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kdvi_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 526324 8df5f9f79bf9f16eb3ad984117a3eed2
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kfax_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 156428 fe1da0664557a589a145bcb98fabeb6d
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kformula_1.4.1-0ubuntu7.2_amd64.deb
      Size/MD5: 707588 0542f378ee18f030cc582931c5143787
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kgamma_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 84534 220393fc40fa67d031f8863c72e8e88e
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kghostview_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 243988 c7daaf28e15e5f022f3e25904f11c642
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kiconedit_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 149562 7343f7a2d06bd5e8a0d8b365b690a551
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kivio_1.4.1-0ubuntu7.2_amd64.deb
      Size/MD5: 166864 8095bd562d334c5a5f98e74ee4fef883
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kmrml_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 238316 8d53ec406afa0f6d2663c77443db3212
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koffice-dev_1.4.1-0ubuntu7.2_amd64.deb
      Size/MD5: 178290 4c2e50e5b0a41b05030d875913246c17
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koffice-libs_1.4.1-0ubuntu7.2_amd64.deb
      Size/MD5: 5551784 87e576a6a18ff46aca59e709afb6f2d8
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kolourpaint_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 815948 71147dc10e398ba6b3a213c5aecd74fe
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kooka_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 767854 6322e6c5a6be8590facf4c98ab9fefe0
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koshell_1.4.1-0ubuntu7.2_amd64.deb
      Size/MD5: 106518 d223ef38ac02c665a78883ebe3f9fb67
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kpdf_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 689590 9a53b9000cac7758c5d0274dbec212fe
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kpovmodeler_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 2291172 b751f861be5f65d97b133d4b77462c67
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kpresenter_1.4.1-0ubuntu7.2_amd64.deb
      Size/MD5: 2895334 7a5c93a3873249da61a71a32c0fd1bd5
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/krita_1.4.1-0ubuntu7.2_amd64.deb
      Size/MD5: 2574672 9369b95d09103c1200aab406369a3135
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kruler_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 66468 548f682d003ca365f73faab9c7067b9f
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/ksnapshot_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 146096 b0a759cc4645bfa608a6532b1d6c97cd
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kspread_1.4.1-0ubuntu7.2_amd64.deb
      Size/MD5: 1034814 9172440725d0229142a4bab77bcf7430
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/ksvg_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 1250998 1b8b31a6f3119ae4058d46c3e2512c3a
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kthesaurus_1.4.1-0ubuntu7.2_amd64.deb
      Size/MD5: 327150 81df083183e9de3d9aac77f5db16be3e
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kugar_1.4.1-0ubuntu7.2_amd64.deb
      Size/MD5: 481210 039f99f1cbd1470792a383393b084a7b
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kuickshow_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 481402 a123f3928429ce1c86940de9a0f4cbb1
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kview_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 699032 59db3708f30879258f90753938648ddc
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kviewshell_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 269508 3af4f8333441a75764de649260405fdb
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kword_1.4.1-0ubuntu7.2_amd64.deb
      Size/MD5: 5736000 a07b92a5a0facf8bef37606d042b01d4
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/libkscan-dev_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 18880 389ab397f858deda7905d649c883aae1
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/libkscan1_3.4.3-0ubuntu2.2_amd64.deb
      Size/MD5: 143420 9a7a3260f749ce41f7d3eaeb87cef2ba

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kamera_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 85166 dad9efb1dc16bdea102f26ffa7767773
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/karbon_1.4.1-0ubuntu7.2_i386.deb
      Size/MD5: 377228 8565f56c8acca6c0e8a42cb2dc4bd717
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kchart_1.4.1-0ubuntu7.2_i386.deb
      Size/MD5: 954668 a7e2f87653f3fa6364f11f1455cf7cee
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kcoloredit_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 99180 0d75b211785523c07e505f192ed03d54
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kdegraphics-dev_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 67004 e7c7ec71d823d57952e4bef2f7596a95
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kdegraphics-kfile-plugins_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 224360 8be76eb464fcf29d9796501947c75098
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kdvi_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 509722 578ab8f61c000c3808c5c8637a4f2f7e
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kfax_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 147818 5849b5b036642f6eaa7590004a4a3cf9
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kformula_1.4.1-0ubuntu7.2_i386.deb
      Size/MD5: 701170 d2c39ace49b90ca97e823d79969f98be
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kgamma_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 78284 960dff28109a19d41ff9e1821f2d00cd
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kghostview_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 226120 0e74ae6edbfd5b73bc10def965300321
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kiconedit_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 136700 028d0ddb215cba70f096531e15f1d86c
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kivio_1.4.1-0ubuntu7.2_i386.deb
      Size/MD5: 153154 d831389b04fb0ded416c7d689abb920f
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kmrml_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 211932 17b2824c885dec58e95cb1343bd12225
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koffice-dev_1.4.1-0ubuntu7.2_i386.deb
      Size/MD5: 178292 71c02485c9bb5a8a14fdaa3ce2384075
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koffice-libs_1.4.1-0ubuntu7.2_i386.deb
      Size/MD5: 4949076 51cbc57113b02a031c4e1596a3a3c851
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kolourpaint_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 767750 dc2c1ea5dbb36ccca3cde057a7d877ed
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kooka_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 748572 a9bfbe4c9b81c591799a31fe21557f83
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koshell_1.4.1-0ubuntu7.2_i386.deb
      Size/MD5: 101030 70614a9db1410e16c919410a04af1b3c
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kpdf_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 615922 175fa198fee3753d32c795b5e6e28b2d
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kpovmodeler_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 2147284 9c2b715a772ec6b544fa00c517d3c130
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kpresenter_1.4.1-0ubuntu7.2_i386.deb
      Size/MD5: 2785880 855e0f026ff1e59d30067bd85ff3705f
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/krita_1.4.1-0ubuntu7.2_i386.deb
      Size/MD5: 2495252 a3cb97a4a2177c6e95ad0b89e9fd1175
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kruler_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 64780 6577abffc7edd767b23fcf27dcab1fbb
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/ksnapshot_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 141934 f57fea6adf30a82d6d9956c6366f785c
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kspread_1.4.1-0ubuntu7.2_i386.deb
      Size/MD5: 966878 82c82b6e30abfd7a58fa099f76b53273
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/ksvg_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 1198688 f0d42beb0ba46c5a9bbf041448ee5b6d
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kthesaurus_1.4.1-0ubuntu7.2_i386.deb
      Size/MD5: 322202 b536e392a9bedb12732b50bf0eb81504
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kugar_1.4.1-0ubuntu7.2_i386.deb
      Size/MD5: 449410 07aa1cfa31575ffa0e3907baeddffaf2
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kuickshow_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 469432 094b7bc7a2505cad4bf531fb243dd857
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kview_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 654646 b22e9e6e6030df9bd2ae61c6dab3b71b
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kviewshell_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 243112 f4ad9d9439e8332b2b5d3631a01c1d2f
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kword_1.4.1-0ubuntu7.2_i386.deb
      Size/MD5: 5462630 72e3c42204423f4d1629192d689fed5d
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/libkscan-dev_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 18882 9108fbcdd6832e121c23eecca34f8388
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/libkscan1_3.4.3-0ubuntu2.2_i386.deb
      Size/MD5: 128788 0d319e786c4eeab8eef22cac52c6b405

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kamera_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 87828 2e9a62e19bc87f613c5c697e097e8ea2
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/karbon_1.4.1-0ubuntu7.2_powerpc.deb
      Size/MD5: 430418 ec0e1e6ba2d38c2d928096f4ab868086
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kchart_1.4.1-0ubuntu7.2_powerpc.deb
      Size/MD5: 964898 7e909e5ae7add974a4c33c8049128c36
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kcoloredit_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 103350 72c98082f565971b1707968794874dd6
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kdegraphics-dev_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 67004 e65a7f70af9c10ea04887bea449f8b22
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kdegraphics-kfile-plugins_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 266894 a0db56a0a664a28f79128b24431c8946
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kdvi_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 515536 3c13e33902b121d7a1670546c6ca4a09
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kfax_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 152392 3fc1f5d16679db419d4b5301de2f74b6
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kformula_1.4.1-0ubuntu7.2_powerpc.deb
      Size/MD5: 706228 28aecf57ea9e1d291a08d412897a83fb
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kgamma_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 80616 4eeda4a5e607f16588ad594febe83823
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kghostview_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 230508 9b59c5a738a5fb6e2bfdc582af63d409
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kiconedit_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 140146 4bdb27086f12fcbd1818cecc0867980b
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kivio_1.4.1-0ubuntu7.2_powerpc.deb
      Size/MD5: 170328 3429a6bbcfa7a90d4415d54a0d13b821
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kmrml_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 225820 6c3a377116a560eb52c5689f26001eb8
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koffice-dev_1.4.1-0ubuntu7.2_powerpc.deb
      Size/MD5: 178292 62954a73274237509fc0af87f34cc821
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koffice-libs_1.4.1-0ubuntu7.2_powerpc.deb
      Size/MD5: 5217762 945914da7cd47f8dd4d993e6ddf14a53
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kolourpaint_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 777836 c7e60e9e034a313a1ed0780816bd45b3
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kooka_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 753362 fa19956c4369782f0a101d34df8a4a3e
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/koshell_1.4.1-0ubuntu7.2_powerpc.deb
      Size/MD5: 105030 687765c576482a279654420be2f9c619
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/kpdf_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 655588 667da67be64babc41a09396c6288e4df
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kpovmodeler_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 2201642 f4a82dbde2e79992b3396c7c004f8f55
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kpresenter_1.4.1-0ubuntu7.2_powerpc.deb
      Size/MD5: 2831066 013e2c67a340d7648c330b3d7d9edff3
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/krita_1.4.1-0ubuntu7.2_powerpc.deb
      Size/MD5: 2539698 d95a7cf266b1607dd5f25cc3df3738da
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kruler_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 64880 2b2371efb9601fcd8972b98dcdb37d39
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/ksnapshot_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 142424 9b7c88724799db2949018c04b4ee280c
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kspread_1.4.1-0ubuntu7.2_powerpc.deb
      Size/MD5: 996304 63dfd8b433b376b6c9b3a1a401646965
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/ksvg_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 1237382 c4239de4fcf1476231cd5681b2c49d7f
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kthesaurus_1.4.1-0ubuntu7.2_powerpc.deb
      Size/MD5: 329100 820ac197a4717f4e650c39e99fed79cd
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kugar_1.4.1-0ubuntu7.2_powerpc.deb
      Size/MD5: 466556 924a39e1fdc1b72bd69dd98ed55ddc7c
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kuickshow_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 475542 c3139760cb52d10e786953970a96cbb1
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kview_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 694186 dfcf3b7eba3899c08552559fbfc3ecbf
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/kviewshell_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 251648 1b3f13c2750cfae7bc8fd46e206fdaa3
    http://security.ubuntu.com/ubuntu/pool/main/k/koffice/kword_1.4.1-0ubuntu7.2_powerpc.deb
      Size/MD5: 5618072 5cd4d11ace8a776313305d114e123909
    http://security.ubuntu.com/ubuntu/pool/universe/k/kdegraphics/libkscan-dev_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 18886 49387bf57b066a69a5063ad04cf9b20b
    http://security.ubuntu.com/ubuntu/pool/main/k/kdegraphics/libkscan1_3.4.3-0ubuntu2.2_powerpc.deb
      Size/MD5: 132048 d4a685120ae8ad6569a8ea737a92cf0a


Ubuntu Security Notice USN-237-1 January 06, 2006
nbd vulnerability
CVE-2005-3354

A security issue affects the following Ubuntu releases:

Ubuntu 5.10 (Breezy Badger)

The following packages are affected:

nbd-server

The problem can be corrected by upgrading the affected package to version 1:2.7.4-1ubuntu0.1. In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

Kurt Fitzner discovered that the NBD (network block device) server did not correctly verify the maximum size of request packets. By sending specially crafted large request packets, a remote attacker who is allowed to access the server could exploit this to execute arbitrary code with root privileges.

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/n/nbd/nbd_2.7.4-1ubuntu0.1.diff.gz
      Size/MD5: 33658 9681548b7c1a6382eae974202817d7b9
    http://security.ubuntu.com/ubuntu/pool/main/n/nbd/nbd_2.7.4-1ubuntu0.1.dsc
      Size/MD5: 588 29acf0d03aae92f01ad55faf0bc315e4
    http://security.ubuntu.com/ubuntu/pool/main/n/nbd/nbd_2.7.4.orig.tar.gz
      Size/MD5: 131430 841999f8d7ae0d6a903a6285ff68a49e

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/n/nbd/nbd-client_2.7.4-1ubuntu0.1_amd64.deb
      Size/MD5: 22292 dd1283e9e72c3e468a8395ac4e4ee5f9
    http://security.ubuntu.com/ubuntu/pool/main/n/nbd/nbd-server_2.7.4-1ubuntu0.1_amd64.deb
      Size/MD5: 29780 3e33c37166bb012f07233bafbd8dcfc2

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/n/nbd/nbd-client_2.7.4-1ubuntu0.1_i386.deb
      Size/MD5: 22306 224ebd247235d85b13d127c4a14e1d8e
    http://security.ubuntu.com/ubuntu/pool/main/n/nbd/nbd-server_2.7.4-1ubuntu0.1_i386.deb
      Size/MD5: 30020 ec25105a117d294f401f751fccf31737

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/n/nbd/nbd-client_2.7.4-1ubuntu0.1_powerpc.deb
      Size/MD5: 22298 0efb5b981bbc2d62e67b8c8fef322e56
    http://security.ubuntu.com/ubuntu/pool/main/n/nbd/nbd-server_2.7.4-1ubuntu0.1_powerpc.deb
      Size/MD5: 31996 a4ace5d1280fab68a6fc0c93bc4fccc0


Ubuntu Security Notice USN-238-1 January 06, 2006
blender vulnerability
CVE-2005-3354

A security issue affects the following Ubuntu releases:

Ubuntu 5.10 (Breezy Badger)

The following packages are affected:

blender

The problem can be corrected by upgrading the affected package to version 2.37a-1ubuntu1.1. In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

Kurt Fitzner discovered that the NBD (network block device) server did not correctly verify the maximum size of request packets. By sending specially crafted large request packets, a remote attacker who is allowed to access the server could exploit this to execute arbitrary code with root privileges.

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/b/blender/blender_2.37a-1ubuntu1.1.diff.gz
      Size/MD5: 11607 282c2bc853abdd9fcadeb94fd42d293f
    http://security.ubuntu.com/ubuntu/pool/main/b/blender/blender_2.37a-1ubuntu1.1.dsc
      Size/MD5: 759 f6d6c5fe8bba50202cb60db85a1f3240
    http://security.ubuntu.com/ubuntu/pool/main/b/blender/blender_2.37a.orig.tar.gz
      Size/MD5: 7885589 2af6afdb01c1d297c43602982d9a919c

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/b/blender/blender_2.37a-1ubuntu1.1_amd64.deb
      Size/MD5: 4791610 926553266642bd9f625e1b27dccd23ff

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/b/blender/blender_2.37a-1ubuntu1.1_i386.deb
      Size/MD5: 4113452 ee9f2a301ed054d9c56dd2412757465b

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/b/blender/blender_2.37a-1ubuntu1.1_powerpc.deb
      Size/MD5: 4641056 8b75ee14b6ce089d7172c88343a1b821


Ubuntu Security Notice USN-238-2 January 06, 2006
blender vulnerability
CVE-2005-4470

A security issue affects the following Ubuntu releases:

Ubuntu 5.10 (Breezy Badger)

The following packages are affected:

blender

The problem can be corrected by upgrading the affected package to version 2.37a-1ubuntu1.1. In general, a standard system upgrade is sufficient to effect the necessary changes.

The original advisory in USN-238-1 accidentially contained a wrong CVE number and advisory text. We apologize for this error.

Details follow:

Damian Put discovered that Blender did not properly validate a 'length' value in .blend files. Negative values led to an insufficiently sized memory allocation. By tricking a user into opening a specially crafted .blend file, this could be exploited to execute arbitrary code with the privileges of the Blender user.

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/b/blender/blender_2.37a-1ubuntu1.1.diff.gz
      Size/MD5: 11607 282c2bc853abdd9fcadeb94fd42d293f
    http://security.ubuntu.com/ubuntu/pool/main/b/blender/blender_2.37a-1ubuntu1.1.dsc
      Size/MD5: 759 f6d6c5fe8bba50202cb60db85a1f3240
    http://security.ubuntu.com/ubuntu/pool/main/b/blender/blender_2.37a.orig.tar.gz
      Size/MD5: 7885589 2af6afdb01c1d297c43602982d9a919c

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/b/blender/blender_2.37a-1ubuntu1.1_amd64.deb
      Size/MD5: 4791610 926553266642bd9f625e1b27dccd23ff

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/b/blender/blender_2.37a-1ubuntu1.1_i386.deb
      Size/MD5: 4113452 ee9f2a301ed054d9c56dd2412757465b

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/b/blender/blender_2.37a-1ubuntu1.1_powerpc.deb
      Size/MD5: 4641056 8b75ee14b6ce089d7172c88343a1b821


Ubuntu Security Notice USN-239-1 January 09, 2006
libapache2-mod-auth-pgsql vulnerability
CVE-2005-3656

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)
Ubuntu 5.04 (Hoary Hedgehog)
Ubuntu 5.10 (Breezy Badger)

The following packages are affected:

libapache2-mod-auth-pgsql

The problem can be corrected by upgrading the affected package to version 2.0.2b1-2ubuntu0.1 (for Ubuntu 4.10), 2.0.2b1-5ubuntu0.1 (for Ubuntu 5.04), or 2.0.2b1-6ubuntu0.1 (for Ubuntu 5.10). After a standard system upgrade you need to restart the Apache 2 server to effect the necessary changes:

sudo /etc/init.d/apache2 restart

Details follow:

Several format string vulnerabilities were discovered in the error logging handling. By sending specially crafted user names, an unauthenticated remote attacker could exploit this to crash the Apache server or possibly even execute arbitrary code with the privileges of Apache (user 'www-data').

Updated packages for Ubuntu 4.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-2ubuntu0.1.diff.gz
      Size/MD5: 3333 92b6b02989c62a28214e6691ff09bb50
    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-2ubuntu0.1.dsc
      Size/MD5: 709 d4c469c2bc7fe0735ba9f59a504ff554
    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1.orig.tar.gz
      Size/MD5: 15928 e2c032df0cd7e4a46381dcf6e488efe9

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-2ubuntu0.1_amd64.deb
      Size/MD5: 19802 b1e6729a94175772ee2cac63ea2da13d

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-2ubuntu0.1_i386.deb
      Size/MD5: 18974 178de9440075d3694ed1f4af72773daa

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-2ubuntu0.1_powerpc.deb
      Size/MD5: 20368 e872d0f306e7906b9d4205b9e24eff8e

Updated packages for Ubuntu 5.04:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5ubuntu0.1.diff.gz
      Size/MD5: 5078 c95a57458bc15935390275860fc65894
    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5ubuntu0.1.dsc
      Size/MD5: 724 d32ade3227241ac2b26d70f755d0bdfe
    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1.orig.tar.gz
      Size/MD5: 15928 e2c032df0cd7e4a46381dcf6e488efe9

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5ubuntu0.1_amd64.deb
      Size/MD5: 20104 4c7840fa3e2c912f926e025be838b011

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5ubuntu0.1_i386.deb
      Size/MD5: 19270 e07b1d6409abe38dc4fa3f67701846e1

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-5ubuntu0.1_powerpc.deb
      Size/MD5: 20738 b6feefa3f30174ae9368af78eed30b6f

Updated packages for Ubuntu 5.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-6ubuntu0.1.diff.gz
      Size/MD5: 5173 33ce214fcaa05c8bde42809d9407368b
    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-6ubuntu0.1.dsc
      Size/MD5: 708 ded1588c8d8cf28128cde3d71f567201
    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1.orig.tar.gz
      Size/MD5: 15928 e2c032df0cd7e4a46381dcf6e488efe9

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-6ubuntu0.1_amd64.deb
      Size/MD5: 20348 68f6cfd60cbf7e6f2cad792bfaf5177a

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-6ubuntu0.1_i386.deb
      Size/MD5: 19092 52712f3b790ea61ef60aa8734d55baac

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-auth-pgsql/libapache2-mod-auth-pgsql_2.0.2b1-6ubuntu0.1_powerpc.deb
      Size/MD5: 21122 69d5ec8ec12d43c03dead9fee1135bab



No talkbacks posted.
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!

..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP