Linux Today: Linux News On Internet Time.
Search Linux Today
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Server Daily
IT Management Daily
Subscribe News
Subscribe PR
Subscribe Security

internet.com
Internet News
Small Business

Advertise
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

Raspberry Pi benchmarked against Beagleboard, low price is long term

20 popular Ubuntu Linux apps you may want to try

A Selection of the Very Best Open Source Tutorials and Tools

Android Ice Cream Sandwich ported to x86 tablets, netbooks and notebooks

SECURITY: Google Chrome 17 Improves Security

How to read a CSV file in Perl?

Red Hat Brings Gluster to Amazon Cloud

New Linux kernel fixes power-saving issues

Using Wii remote with Android Device- Taking Gaming to the Next Level

Commercial Support now available for the open-source NGINX Web server



Applications Management Engineer Sr (NYC)
Next Step Systems
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume
:Advisories, April 30, 2006
Advisories, April 30, 2006
May 1, 2006, 04 :45 UTC (0 Talkback[s]) (2462 reads)

Debian GNU/Linux


Debian Security Advisory DSA 1045-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
April 27th, 2006 http://www.debian.org/security/faq


Package : openvpn
Vulnerability : design error
Problem type : remote
Debian-specific: no
CVE ID : CVE-2006-1629
BugTraq ID : 17392
Debian Bug : 360559

Hendrik Weimer discovered that OpenVPN, the Virtual Private Network daemon, allows to push environment variables to a client allowing a malicious VPN server to take over connected clients.

the old stable distribution (woody) does not contain openvpn packages.

For the stable distribution (sarge) this problem has been fixed in version 2.0-1sarge3.

For the unstable distribution (sid) this problem has been fixed in version 2.0.6-1.

We recommend that you upgrade your openvpn package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sarge3.dsc
      Size/MD5 checksum: 631 4b7b2a37e742638edc00b452b3e7dc29
    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sarge3.diff.gz
      Size/MD5 checksum: 53070 f8a032cd64a2d37f877e1b793997c606
    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0.orig.tar.gz
      Size/MD5 checksum: 639201 7401faebc6baee9add32608709c54eec

Alpha architecture:

    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sarge3_alpha.deb
      Size/MD5 checksum: 347494 059b75282cf82fd3054c434787b8df81

AMD64 architecture:

    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sarge3_amd64.deb
      Size/MD5 checksum: 316628 a2d46180b7f72438314ad38326a84af2

ARM architecture:

    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sarge3_arm.deb
      Size/MD5 checksum: 296770 f246ffba0c98997a90a54b20c504f8b9

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sarge3_i386.deb
      Size/MD5 checksum: 302698 8b40b4ffdce700b3733b87027c9d8ca0

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sarge3_ia64.deb
      Size/MD5 checksum: 395804 e7753416c88c3b8345e69ed857da7617

HP Precision architecture:

    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sarge3_hppa.deb
      Size/MD5 checksum: 316926 ce6991ede97b0d644eb159d29f0a9a2b

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sarge3_m68k.deb
      Size/MD5 checksum: 276714 6e2321f9bc66e808ce3463d9757ef2a5

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sarge3_mips.deb
      Size/MD5 checksum: 317870 3a05521f53d444a5fc1427f5e49909cb

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sarge3_mipsel.deb
      Size/MD5 checksum: 319716 829deeeaa2ffb3af25b4a4f2a40c835b

PowerPC architecture:

    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sarge3_powerpc.deb
      Size/MD5 checksum: 309084 93acf83128599cf529b3477ff0aa7b68

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sarge3_s390.deb
      Size/MD5 checksum: 307544 e53abb03c1d50b9835653d0afb020fcc

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sarge3_sparc.deb
      Size/MD5 checksum: 295114 63a22f249484eb71df4e205e211d2054

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 1046-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
April 27th, 2006 http://www.debian.org/security/faq


Package : mozilla
Vulnerability : several
Problem type : remote
Debian-specific: no
CVE IDs : CVE-2005-2353 CVE-2005-4134 CVE-2006-0292 CVE-2006-0293 CVE-2006-0296 CVE-2006-0748 CVE-2006-0749 CVE-2006-0884 CVE-2006-1045 CVE-2006-1529 CVE-2006-1530 CVE-2006-1531 CVE-2006-1723 CVE-2006-1724 CVE-2006-1727 CVE-2006-1728 CVE-2006-1729 CVE-2006-1730 CVE-2006-1731 CVE-2006-1733 CVE-2006-1734 CVE-2006-1735 CVE-2006-1736 CVE-2006-1737 CVE-2006-1738 CVE-2006-1739 CVE-2006-1740 CVE-2006-1741 CVE-2006-1742 CVE-2006-1790
CERT advisories: VU#179014 VU#252324 VU#329500 VU#350262 VU#488774 VU#492382 VU#592425 VU#736934 VU#813230 VU#842094 VU#932734 VU#935556
BugTraq IDs : 15773 16476 16476 16770 16881 17516

Several security related problems have been discovered in Mozilla. The Common Vulnerabilities and Exposures project identifies the following vulnerabilities:

CVE-2005-2353

The "run-mozilla.sh" script allows local users to create or overwrite arbitrary files when debugging is enabled via a symlink attack on temporary files.

CVE-2005-4134

Web pages with extremely long titles cause subsequent launches of the browser to appear to "hang" for up to a few minutes, or even crash if the computer has insufficient memory. [MFSA-2006-03]

CVE-2006-0292

The Javascript interpreter does not properly dereference objects, which allows remote attackers to cause a denial of service or execute arbitrary code. [MFSA-2006-01]

CVE-2006-0293

The function allocation code allows attackers to cause a denial of service and possibly execute arbitrary code. [MFSA-2006-01]

CVE-2006-0296

XULDocument.persist() did not validate the attribute name, allowing an attacker to inject arbitrary XML and JavaScript code into localstore.rdf that would be read and acted upon during startup. [MFSA-2006-05]

CVE-2006-0748

An anonymous researcher for TippingPoint and the Zero Day Initiative reported that an invalid and nonsensical ordering of table-related tags can be exploited to execute arbitrary code. [MFSA-2006-27]

CVE-2006-0749

A particular sequence of HTML tags can cause memory corruption that can be exploited to exectute arbitary code. [MFSA-2006-18]

CVE-2006-0884

Georgi Guninski reports that forwarding mail in-line while using the default HTML "rich mail" editor will execute JavaScript embedded in the e-mail message with full privileges of the client. [MFSA-2006-21]

CVE-2006-1045

The HTML rendering engine does not properly block external images from inline HTML attachments when "Block loading of remote images in mail messages" is enabled, which could allow remote attackers to obtain sensitive information. [MFSA-2006-26]

CVE-2006-1529

A vulnerability potentially allows remote attackers to cause a denial of service and possibly execute arbitrary. [MFSA-2006-20]

CVE-2006-1530

A vulnerability potentially allows remote attackers to cause a denial of service and possibly execute arbitrary. [MFSA-2006-20]

CVE-2006-1531

A vulnerability potentially allows remote attackers to cause a denial of service and possibly execute arbitrary. [MFSA-2006-20]

CVE-2006-1723

A vulnerability potentially allows remote attackers to cause a denial of service and possibly execute arbitrary. [MFSA-2006-20]

CVE-2006-1724

A vulnerability potentially allows remote attackers to cause a denial of service and possibly execute arbitrary. [MFSA-2006-20]

CVE-2006-1725

Due to an interaction between XUL content windows and the history mechanism, some windows may to become translucent, which might allow remote attackers to execute arbitrary code. [MFSA-2006-29]

CVE-2006-1726

"shutdown" discovered that the security check of the function js_ValueToFunctionObject() can be circumvented and exploited to allow the installation of malware. [MFSA-2006-28]

CVE-2006-1727

Georgi Guninski reported two variants of using scripts in an XBL control to gain chrome privileges when the page is viewed under "Print Preview".under "Print Preview". [MFSA-2006-25]

CVE-2006-1728

"shutdown" discovered that the crypto.generateCRMFRequest method can be used to run arbitrary code with the privilege of the user running the browser, which could enable an attacker to install malware. [MFSA-2006-24]

CVE-2006-1729

Claus Jørgensen reported that a text input box can be pre-filled with a filename and then turned into a file-upload control, allowing a malicious website to steal any local file whose name they can guess. [MFSA-2006-23]

CVE-2006-1730

An anonymous researcher for TippingPoint and the Zero Day Initiative discovered an integer overflow triggered by the CSS letter-spacing property, which could be exploited to execute arbitrary code. [MFSA-2006-22]

CVE-2006-1731

"moz_bug_r_a4" discovered that some internal functions return prototypes instead of objects, which allows remote attackers to conduct cross-site scripting attacks. [MFSA-2006-19]

CVE-2006-1732

"shutdown" discovered that it is possible to bypass same-origin protections, allowing a malicious site to inject script into content from another site, which could allow the malicious page to steal information such as cookies or passwords from the other site, or perform transactions on the user's behalf if the user were already logged in. [MFSA-2006-17]

CVE-2006-1733

"moz_bug_r_a4" discovered that the compilation scope of privileged built-in XBL bindings is not fully protected from web content and can still be executed which could be used to execute arbitrary JavaScript, which could allow an attacker to install malware such as viruses and password sniffers. [MFSA-2006-16]

CVE-2006-1734

"shutdown" discovered that it is possible to access an internal function object which could then be used to run arbitrary JavaScriptcode with full permissions of the user running the browser, which could be used to install spyware or viruses. [MFSA-2006-15]

CVE-2006-1735

It is possible to create JavaScript functions that would get compiled with the wrong privileges, allowing an attacker to run code of their choice with full permissions of the user running the browser, which could be used to install spyware or viruses. [MFSA-2006-14]

CVE-2006-1736

It is possible to trick users into downloading and saving an executable file via an image that is overlaid by a transparent image link that points to the executable. [MFSA-2006-13]

CVE-2006-1737

An integer overflow allows remote attackers to cause a denial of service and possibly execute arbitrary bytecode via JavaScript with a large regular expression. [MFSA-2006-11]

CVE-2006-1738

An unspecified vulnerability allows remote attackers to cause a denial of service. [MFSA-2006-11]

CVE-2006-1739

Certain Cascading Style Sheets (CSS) can cause an out-of-bounds array write and buffer overflow that could lead to a denial of service and the possible execution of arbitrary code. [MFSA-2006-11]

CVE-2006-1740

It is possible for remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the location to a malicious site. [MFSA-2006-12]

CVE-2006-1741

"shutdown" discovered that it is possible to inject arbitrary JavaScript code into a page on another site using a modal alert to suspend an event handler while a new page is being loaded. This could be used to steal confidential information. [MFSA-2006-09]

CVE-2006-1742

Igor Bukanov discovered that the JavaScript engine does not properly handle temporary variables, which might allow remote attackers to trigger operations on freed memory and cause memory corruption, causing memory corruption. [MFSA-2006-10]

CVE-2006-1790

A regression fix that could lead to memory corruption allows remote attackers to cause a denial of service and possibly execute arbitrary code. [MFSA-2006-11]

For the stable distribution (sarge) these problems have been fixed in version 1.7.8-1sarge5.

For the unstable distribution (sid) these problems will be fixed in version 1.7.13-1.

We recommend that you upgrade your Mozilla packages.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge5.dsc
      Size/MD5 checksum: 1123 b486e464eae65686c7b15f50f77cb767
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge5.diff.gz
      Size/MD5 checksum: 472258 0aa0d6b2edcd13fa83ce9ed271a0724f
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8.orig.tar.gz
      Size/MD5 checksum: 30589520 13c0f0331617748426679e8f2e9f537a

Alpha architecture:

    http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge5_alpha.deb
      Size/MD5 checksum: 168068 7ed348802218aae8f17044f1938ad609
    http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge5_alpha.deb
      Size/MD5 checksum: 146702 f3229e78b1ad87a9c8e2bad153faa5a3
    http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge5_alpha.deb
      Size/MD5 checksum: 184934 6f62bafa779c954315d04b385eeded59
    http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge5_alpha.deb
      Size/MD5 checksum: 856276 ab399c2ed74a5b13deb58aaad3d49087
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge5_alpha.deb
      Size/MD5 checksum: 1032 e4569c9693441a0edb94ee11912dad30
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge5_alpha.deb
      Size/MD5 checksum: 11477828 62b8bda344ef70da1c47de2adc23dd4a
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge5_alpha.deb
      Size/MD5 checksum: 403276 2978138077e4a2ecad90dd0e8c856709
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge5_alpha.deb
      Size/MD5 checksum: 158332 364e72f576f30e42fe8bfa8e1fba365c
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge5_alpha.deb
      Size/MD5 checksum: 3357226 6956cd03cbeda6aa147c984e5fd8317d
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge5_alpha.deb
      Size/MD5 checksum: 122282 ac007b2334d2c4f61585b9059e2c8ab3
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge5_alpha.deb
      Size/MD5 checksum: 204160 bb0fc8af6b06e34ac81a32d04c9c3cef
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge5_alpha.deb
      Size/MD5 checksum: 1937094 f7881427bd1afc9371f2a577a02080e9
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge5_alpha.deb
      Size/MD5 checksum: 212402 1df52addc8f7c47b6681abd51e331f41

AMD64 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge5_amd64.deb
      Size/MD5 checksum: 168066 bd11d5d2dcd7e78621de4ae0c03ed6b8
    http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge5_amd64.deb
      Size/MD5 checksum: 145798 518a796a9423412004eed5ac6c756d61
    http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge5_amd64.deb
      Size/MD5 checksum: 184930 b6d7c90efdfe1c52bfbb6c47cdcf1244
    http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge5_amd64.deb
      Size/MD5 checksum: 714636 086b722ae6d2aa33ebcaa4101fd0751b
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge5_amd64.deb
      Size/MD5 checksum: 1030 d62e40f94f76fe6780cd517eaceeec7d
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge5_amd64.deb
      Size/MD5 checksum: 10945270 2abf8d616e8b889e29f4afea01032679
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge5_amd64.deb
      Size/MD5 checksum: 403266 66e021c850ef757ce9a2a0ebf30e462a
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge5_amd64.deb
      Size/MD5 checksum: 158326 14b7ddf2988885d66b85bd7458fa98ad
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge5_amd64.deb
      Size/MD5 checksum: 3351216 9221380d16e886cae475efb410429c3f
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge5_amd64.deb
      Size/MD5 checksum: 121176 98f3f0e73d27e92d2f951c892b528bbe
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge5_amd64.deb
      Size/MD5 checksum: 204152 ef08d9bbbb26b9c6bdda0bbf8e698299
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge5_amd64.deb
      Size/MD5 checksum: 1936008 339c98bcc87876a27b0ca0dacb6ef0cc
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge5_amd64.deb
      Size/MD5 checksum: 204336 b25851b6c4ae6818918a0b80507eec2d

ARM architecture:

    http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge5_arm.deb
      Size/MD5 checksum: 168068 863d83042249fbb53cb5570a5fd03f12
    http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge5_arm.deb
      Size/MD5 checksum: 124162 eed0ab266786523a435d87925369370f
    http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge5_arm.deb
      Size/MD5 checksum: 184952 2d6919422ee7aa37b28d2bf6bc942f5f
    http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge5_arm.deb
      Size/MD5 checksum: 631844 c44b2cf0e0ae4ccc927a41ab6eb25380
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge5_arm.deb
      Size/MD5 checksum: 1030 4d0eb279d61409bb9bbcaa7e8f785471
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge5_arm.deb
      Size/MD5 checksum: 9207420 46aff4f2b0913d187048f19bc59f6e1e
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge5_arm.deb
      Size/MD5 checksum: 403314 17d6accdd639278bad64e9e4042013e2
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge5_arm.deb
      Size/MD5 checksum: 158382 5f900a4d4627d27289dc53aaa32e90da
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge5_arm.deb
      Size/MD5 checksum: 3340838 a4ce703b7b9f05440ba72b7dd177cdd9
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge5_arm.deb
      Size/MD5 checksum: 112674 8426b940dab4c2339a2894dc09584028
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge5_arm.deb
      Size/MD5 checksum: 204184 e0f3e9a65adb373574cafe68b75a7f57
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge5_arm.deb
      Size/MD5 checksum: 1604382 43b950f85fb316f1bc0d773ef25c6a85
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge5_arm.deb
      Size/MD5 checksum: 168862 6245436dde393fbb8526d622d6372b96

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge5_i386.deb
      Size/MD5 checksum: 170350 1890d8f6cf1f6d7d3f24862b8b236d5e
    http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge5_i386.deb
      Size/MD5 checksum: 136640 cb2ab0bf38cc5afff64327cbf4f79fbe
    http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge5_i386.deb
      Size/MD5 checksum: 187128 af578fd816c0534baa15529168dd1170
    http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge5_i386.deb
      Size/MD5 checksum: 661394 3a94641ec0f1b8bebbed0b428f40e3e8
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge5_i386.deb
      Size/MD5 checksum: 1030 42b5cb15c988c9d2328e6be2266dda42
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge5_i386.deb
      Size/MD5 checksum: 10332780 89748f75d483a5b4905e842cf85081a6
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge5_i386.deb
      Size/MD5 checksum: 403506 3b03c89eec36142148548f7cd64e5d12
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge5_i386.deb
      Size/MD5 checksum: 158344 d36c1032ddd6ba8051ad27786662525a
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge5_i386.deb
      Size/MD5 checksum: 3592688 f30a67ca521067cde834d346b4646c1b
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge5_i386.deb
      Size/MD5 checksum: 116678 dda364a06fa45c104c5222988b826a6b
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge5_i386.deb
      Size/MD5 checksum: 204156 2a7e71b2393ddee06457536053b6f426
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge5_i386.deb
      Size/MD5 checksum: 1816066 cdc0f8d06a00c14337ad20178284685c
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge5_i386.deb
      Size/MD5 checksum: 192632 26c12b2f1e572cc70ab80fae0a20d75f

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge5_ia64.deb
      Size/MD5 checksum: 168070 088af473a08b7478a172e483ffe0a3cb
    http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge5_ia64.deb
      Size/MD5 checksum: 174160 255499b7e29813343a088957bc4e450e
    http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge5_ia64.deb
      Size/MD5 checksum: 184942 6ebb70d67e23a8ff659ec788048c558d
    http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge5_ia64.deb
      Size/MD5 checksum: 966574 fa7081da19e2c59b89c5b47d70314a38
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge5_ia64.deb
      Size/MD5 checksum: 1032 dac2c365bc58d57275205fbecd04d2f2
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge5_ia64.deb
      Size/MD5 checksum: 12943234 f0e1ea934e597443636be3dc1f8323bc
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge5_ia64.deb
      Size/MD5 checksum: 403274 d519dfad807b19794742e6723f6872c8
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge5_ia64.deb
      Size/MD5 checksum: 158334 c729929af3c1879ab058541227487677
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge5_ia64.deb
      Size/MD5 checksum: 3377040 de356df345ed8ab5ce2a970827990b0d
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge5_ia64.deb
      Size/MD5 checksum: 125582 9975c43ca6954d98309ab11ac03aadd4
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge5_ia64.deb
      Size/MD5 checksum: 204158 fa835bffaf5008bccdcd62ff2114a481
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge5_ia64.deb
      Size/MD5 checksum: 2302210 db2d6cd804c0372eafba307436cd9296
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge5_ia64.deb
      Size/MD5 checksum: 242664 b8a9d7bba6700b6cb700187bbed51102

HP Precision architecture:

    http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge5_hppa.deb
      Size/MD5 checksum: 168076 e744a5d49021e510fa29396332c5490f
    http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge5_hppa.deb
      Size/MD5 checksum: 156738 c856122cc9fa2e985882f624ec57df99
    http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge5_hppa.deb
      Size/MD5 checksum: 184946 74cb243dddf99e01bc525efebc9fd96b
    http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge5_hppa.deb
      Size/MD5 checksum: 754578 b940f076bd46aff2f6418828503a2afc
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge5_hppa.deb
      Size/MD5 checksum: 1036 37b2840edf5a86c22ba5dab71452f300
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge5_hppa.deb
      Size/MD5 checksum: 12162800 74b60c8375cc5d2c379fc4e586526bc7
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge5_hppa.deb
      Size/MD5 checksum: 403282 c138582e5075ee91ffbdba982acce035
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge5_hppa.deb
      Size/MD5 checksum: 158338 4ad85659f4aae7580c71a8457128e3c4
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge5_hppa.deb
      Size/MD5 checksum: 3357886 b8891334da36453c8e5619fe0896f2af
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge5_hppa.deb
      Size/MD5 checksum: 123502 195bf5cd60cabb129d9ed04bf100241d
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge5_hppa.deb
      Size/MD5 checksum: 204160 c26281b91291c131ad3fb2f1565caa6d
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge5_hppa.deb
      Size/MD5 checksum: 2135138 b0883259ed740bcd41bf43ae4680e1b8
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge5_hppa.deb
      Size/MD5 checksum: 216144 d73d1e1d42427175d865021d69422f8b

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge5_m68k.deb
      Size/MD5 checksum: 168092 398298d8ffad737508ed118d4d69d112
    http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge5_m68k.deb
      Size/MD5 checksum: 125818 2099631f9bd235623d98a32fa45b34d6
    http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge5_m68k.deb
      Size/MD5 checksum: 184984 542adc7ea5dac9443e87d2b72023fc80
    http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge5_m68k.deb
      Size/MD5 checksum: 599936 fada9efe3f62935cbb4ea56cd889e73f
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge5_m68k.deb
      Size/MD5 checksum: 1046 2de17261893fc2e2697bbe35b59d768e
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge5_m68k.deb
      Size/MD5 checksum: 9703464 afcf7cec434793064c55e67cfea1f441
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge5_m68k.deb
      Size/MD5 checksum: 403358 3890cf07cef780ae34a7e294225db0db
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge5_m68k.deb
      Size/MD5 checksum: 158380 b213d524e1473ab78ee23a556afb48ac
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge5_m68k.deb
      Size/MD5 checksum: 3335462 13fc8f2927e661e55e6bd63490bbbab8
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge5_m68k.deb
      Size/MD5 checksum: 114470 14ec6e7861bf73f3b7f82b91b86cf567
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge5_m68k.deb
      Size/MD5 checksum: 204180 73817862c43af283a652039ba5b45cd1
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge5_m68k.deb
      Size/MD5 checksum: 1683074 ab15cea98788c380e269a94d2df5472a
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge5_m68k.deb
      Size/MD5 checksum: 174748 23a6847a17c4d7e3bf6ef072798e8239

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge5_mips.deb
      Size/MD5 checksum: 168074 958f2c3227b801f01d1166a54187ee41
    http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge5_mips.deb
      Size/MD5 checksum: 140686 2244af2acdc2844be99005e4e3f0d121
    http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge5_mips.deb
      Size/MD5 checksum: 184960 54829d9c8798df955039c7268b25392a
    http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge5_mips.deb
      Size/MD5 checksum: 725672 2310546bc1cbe2df5a6c1fef62ce1ccf
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge5_mips.deb
      Size/MD5 checksum: 1032 6a43b5ff3f81433a162dd200ea052fcb
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge5_mips.deb
      Size/MD5 checksum: 10728020 4caf72ce0e493eaf1b9a5fdf0ae57d6e
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge5_mips.deb
      Size/MD5 checksum: 403274 d4c7bd6d0638bffa0c5d2c23cf080611
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge5_mips.deb
      Size/MD5 checksum: 158336 d1d77d961279da110d01de630e53846b
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge5_mips.deb
      Size/MD5 checksum: 3357194 94993156be09ad11712075d917d21660
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge5_mips.deb
      Size/MD5 checksum: 117610 77ca046034494b735a10028e5af8eed5
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge5_mips.deb
      Size/MD5 checksum: 204150 f6b3f0d0bfc84aa27a24beee692c9932
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge5_mips.deb
      Size/MD5 checksum: 1795504 2d34d3ff2dd99a2d0089c1eca53b0579
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge5_mips.deb
      Size/MD5 checksum: 189880 2cb68bac9a41b14e627426ebb1405fd1

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge5_mipsel.deb
      Size/MD5 checksum: 168082 c1eba053c4a1c0421ea508b29fbaa683
    http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge5_mipsel.deb
      Size/MD5 checksum: 140636 a2474b059a8c1e4845922102cc1d58d8
    http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge5_mipsel.deb
      Size/MD5 checksum: 184940 4a7289c8753105101fe9b0862e3aad71
    http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge5_mipsel.deb
      Size/MD5 checksum: 715106 67e1dc2600da37597fb75e22b7875a6d
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge5_mipsel.deb
      Size/MD5 checksum: 1038 d0f622dcb3b5b41b62986c3c7c338370
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge5_mipsel.deb
      Size/MD5 checksum: 10603070 6a6966022c2f8a8ab2807e656043e39a
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge5_mipsel.deb
      Size/MD5 checksum: 403296 6b7722ec5a34cae5f221c3958dc65bc1
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge5_mipsel.deb
      Size/MD5 checksum: 158342 87c0d4a874ca1aa5e3be85e2249dbe6b
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge5_mipsel.deb
      Size/MD5 checksum: 3357982 a7258380f1f7fcc380d2a8161cc1b803
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge5_mipsel.deb
      Size/MD5 checksum: 117204 e77b1061daa3c8a762b9bd0a58f340ee
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge5_mipsel.deb
      Size/MD5 checksum: 204162 b2e72e6b19f1092e84f2977291e782bf
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge5_mipsel.deb
      Size/MD5 checksum: 1777610 f88abea35dc9ac1c7760d2ae8761303a
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge5_mipsel.deb
      Size/MD5 checksum: 187444 37c35256b507720467747edfd7ad6606

PowerPC architecture:

    http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge5_powerpc.deb
      Size/MD5 checksum: 168078 e8a320169dd21bd2653f2e1cceacaea8
    http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge5_powerpc.deb
      Size/MD5 checksum: 131146 01deac585f851b2b22d117db76271f69
    http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge5_powerpc.deb
      Size/MD5 checksum: 184928 69c925958815b6a0b66d67660e530d21
    http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge5_powerpc.deb
      Size/MD5 checksum: 718850 182c8077cedbd4b17e519bf9d4340ddf
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge5_powerpc.deb
      Size/MD5 checksum: 1038 8492a6da8120bcd6498c1cf5b5e7bb29
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge5_powerpc.deb
      Size/MD5 checksum: 9703116 df00589069a7994886b37154a83ba48a
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge5_powerpc.deb
      Size/MD5 checksum: 403294 3530285f43e66537f891885855b56a4a
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge5_powerpc.deb
      Size/MD5 checksum: 158344 f0158562b460aa36a08f24b3c6a828c5
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge5_powerpc.deb
      Size/MD5 checksum: 3339658 0d6d999cd0559fd93be3257664ad9165
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge5_powerpc.deb
      Size/MD5 checksum: 114598 bf235995c329c00a51416cb6d9996fad
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge5_powerpc.deb
      Size/MD5 checksum: 204166 2156c81a5e15e4444d2c5be22ee066a8
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge5_powerpc.deb
      Size/MD5 checksum: 1642978 409eb5485153365138f9d130db5a0bf5
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge5_powerpc.deb
      Size/MD5 checksum: 175672 d148c3a307177bd5a88d211c554c515f

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge5_s390.deb
      Size/MD5 checksum: 168062 f336a2de372d02f5dad5673afd3b6e19
    http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge5_s390.deb
      Size/MD5 checksum: 156458 71cc856f65e80354b508799a720d2223
    http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge5_s390.deb
      Size/MD5 checksum: 184956 46fe112fa61e011e2fb79cff847378cb
    http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge5_s390.deb
      Size/MD5 checksum: 798872 7d02d09328a985bed9aaa3f603c56b72
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge5_s390.deb
      Size/MD5 checksum: 1036 7d25a776a8f9e3467060085df346a772
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge5_s390.deb
      Size/MD5 checksum: 11325484 cad88ede93803739d98498f4b43c74c2
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge5_s390.deb
      Size/MD5 checksum: 403292 fc353648cb5e5fabf0b07211729fb8c7
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge5_s390.deb
      Size/MD5 checksum: 158346 e173c32ab6b9a1904f0236fb00ce836f
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge5_s390.deb
      Size/MD5 checksum: 3352214 ca96b4f7ee3c1498904a567a6462778d
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge5_s390.deb
      Size/MD5 checksum: 121378 c33f1b9d5907dd6422a0ecb38c6f714a
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge5_s390.deb
      Size/MD5 checksum: 204166 e4f8a67148cf7b703c280ec91f289298
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge5_s390.deb
      Size/MD5 checksum: 1944742 31da3121c50c27f4df3be7939cbe7324
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge5_s390.deb
      Size/MD5 checksum: 213446 4d431a25410f0e6039f4032c9acf3378

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/m/mozilla/libnspr-dev_1.7.8-1sarge5_sparc.deb
      Size/MD5 checksum: 168070 0005424068108c85553255259aea5f5b
    http://security.debian.org/pool/updates/main/m/mozilla/libnspr4_1.7.8-1sarge5_sparc.deb
      Size/MD5 checksum: 128364 0988e532f8ef63759610a007d07bf60b
    http://security.debian.org/pool/updates/main/m/mozilla/libnss-dev_1.7.8-1sarge5_sparc.deb
      Size/MD5 checksum: 184942 62e592a514e25e3c7c5420c5c53f3d8e
    http://security.debian.org/pool/updates/main/m/mozilla/libnss3_1.7.8-1sarge5_sparc.deb
      Size/MD5 checksum: 672638 f35942f6694b22af40973af8fb9058a5
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla_1.7.8-1sarge5_sparc.deb
      Size/MD5 checksum: 1030 771b441d8c662e3db4c45646f4e6a99b
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-browser_1.7.8-1sarge5_sparc.deb
      Size/MD5 checksum: 9373440 a4560f2a4bc80bbf93829f7bf0a1bc5d
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-calendar_1.7.8-1sarge5_sparc.deb
      Size/MD5 checksum: 403276 440bcce7ec880544cff5bba723239473
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-chatzilla_1.7.8-1sarge5_sparc.deb
      Size/MD5 checksum: 158336 d0ecad8b66d39437bec068ee8e182397
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dev_1.7.8-1sarge5_sparc.deb
      Size/MD5 checksum: 3340588 5f44ff3da184961882044aef4a46e696
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-dom-inspector_1.7.8-1sarge5_sparc.deb
      Size/MD5 checksum: 112516 83e39c205c5098b2e0b58c1301a39705
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-js-debugger_1.7.8-1sarge5_sparc.deb
      Size/MD5 checksum: 204156 ae1c34bb6889e7912fb210d120f5d7f8
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-mailnews_1.7.8-1sarge5_sparc.deb
      Size/MD5 checksum: 1583742 fa8be53ec188d2471269ea2b88142e51
    http://security.debian.org/pool/updates/main/m/mozilla/mozilla-psm_1.7.8-1sarge5_sparc.deb
      Size/MD5 checksum: 168022 e8bd471a692f313db05316ecf5e4c7b8

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 1047-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
April 30th, 2006 http://www.debian.org/security/faq


Package : resmgr
Vulnerability : programming error
Problem type : local
Debian-specific: no

A problem has been discovered in resmgr, a resource manager library daemon and PAM module, that allows local users to bypass access control rules and open any USB device when access to one device was granted.

the old stable distribution (woody) does not contain resmgr packages.

For the stable distribution (sarge) this problem has been fixed in version 1.0-2sarge2.

For the unstable distribution (sid) this problem has been fixed in version 1.0-4.

We recommend that you upgrade your resmgr package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0-2sarge2.dsc
      Size/MD5 checksum: 614 9b90463431b3893f727ff080df0a5239
    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0-2sarge2.diff.gz
      Size/MD5 checksum: 7976 52d70d8e9684ab80719d806d9088d067
    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0.orig.tar.gz
      Size/MD5 checksum: 40970 c5d77b35fc30a7bead00ea2951c19a2f

Alpha architecture:

    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr-dev_1.0-2sarge2_alpha.deb
      Size/MD5 checksum: 4428 f20cb82298535193b9629c4811251192
    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr1_1.0-2sarge2_alpha.deb
      Size/MD5 checksum: 8870 d0c6a5a4f04fa2258280cb4b6d60c0c9
    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0-2sarge2_alpha.deb
      Size/MD5 checksum: 36690 efb631c58b56a16c40d1a3152e9d4f8f

AMD64 architecture:

    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr-dev_1.0-2sarge2_amd64.deb
      Size/MD5 checksum: 4422 0ca68e35b937773dfa3b89dd8945281b
    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr1_1.0-2sarge2_amd64.deb
      Size/MD5 checksum: 8194 0317c1c3ed93bd13aebe521949d4fda5
    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0-2sarge2_amd64.deb
      Size/MD5 checksum: 33304 2275f781d337907b87ad31d0779d1a0c

ARM architecture:

    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr-dev_1.0-2sarge2_arm.deb
      Size/MD5 checksum: 4428 13adf84fa226c83cf36ddc7014a413b8
    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr1_1.0-2sarge2_arm.deb
      Size/MD5 checksum: 7058 8d0e935b6ca4425174490e7523bb86ab
    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0-2sarge2_arm.deb
      Size/MD5 checksum: 29328 21f2b68f8dc44be7b4304f66f3d080ae

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr-dev_1.0-2sarge2_i386.deb
      Size/MD5 checksum: 4422 852f6d951e3ed2fd4e8740e2bc8b1fa6
    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr1_1.0-2sarge2_i386.deb
      Size/MD5 checksum: 25906 0f7831ec7b0382a6962cbddecfa2ef5c
    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0-2sarge2_i386.deb
      Size/MD5 checksum: 41224 d6df916c394f4c826b4d9e75434a261a

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr-dev_1.0-2sarge2_ia64.deb
      Size/MD5 checksum: 4414 39ad0549329d2dd0810d580c65629012
    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr1_1.0-2sarge2_ia64.deb
      Size/MD5 checksum: 10196 031bad7b1ba99e6b7e337b7f506321c3
    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0-2sarge2_ia64.deb
      Size/MD5 checksum: 41210 47ba589e9bf7ee09769447dd759dbc0e

HP Precision architecture:

    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr-dev_1.0-2sarge2_hppa.deb
      Size/MD5 checksum: 4436 4f9e59f8941fd2160002dfaac94ae756
    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr1_1.0-2sarge2_hppa.deb
      Size/MD5 checksum: 8676 8a92ed14b17e608d4607b626af2948f4
    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0-2sarge2_hppa.deb
      Size/MD5 checksum: 33612 2dbb5089a1e6a6bcd8a202687ab2c826

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr-dev_1.0-2sarge2_m68k.deb
      Size/MD5 checksum: 4444 752f2adf6c0c977de1a346d8326ceea4
    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr1_1.0-2sarge2_m68k.deb
      Size/MD5 checksum: 7238 1674a58df5be5d7d7a46dd8eca880b0d
    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0-2sarge2_m68k.deb
      Size/MD5 checksum: 28882 5c65ca27ee2816344da1a0e9289a9414

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr-dev_1.0-2sarge2_mips.deb
      Size/MD5 checksum: 4434 49b9292653d918bf6f94809322d8fb48
    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr1_1.0-2sarge2_mips.deb
      Size/MD5 checksum: 7778 5246faae2986c92f6edf9b0cb518ed85
    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0-2sarge2_mips.deb
      Size/MD5 checksum: 34712 4817872f485e1b6c402caa019bf3fa62

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr-dev_1.0-2sarge2_mipsel.deb
      Size/MD5 checksum: 4432 c783ce5980d7d0b22aa1c69a66d89456
    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr1_1.0-2sarge2_mipsel.deb
      Size/MD5 checksum: 7814 a5226c77b764b2c79b32211a67a0580e
    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0-2sarge2_mipsel.deb
      Size/MD5 checksum: 34668 00efd90689cce6b0874622a32ad687cd

PowerPC architecture:

    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr-dev_1.0-2sarge2_powerpc.deb
      Size/MD5 checksum: 4442 2cb12a62b99ee151de15f62b01cd3cdb
    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr1_1.0-2sarge2_powerpc.deb
      Size/MD5 checksum: 9474 4d7589e21c6604b0915cdcb13f64d66b
    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0-2sarge2_powerpc.deb
      Size/MD5 checksum: 36228 c7bb76f8eb7e08c1db19eb2b061e9a01

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr-dev_1.0-2sarge2_s390.deb
      Size/MD5 checksum: 4428 1f49b31b45334df4f298c96ce35b9b7d
    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr1_1.0-2sarge2_s390.deb
      Size/MD5 checksum: 8302 6065fe66f9b5a41bbf6e7d23b4090d32
    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0-2sarge2_s390.deb
      Size/MD5 checksum: 33282 b3b1443b323c144c8f72e0b37f70546d

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr-dev_1.0-2sarge2_sparc.deb
      Size/MD5 checksum: 4434 27815a5a67681abf7ac81c6998de4c73
    http://security.debian.org/pool/updates/main/r/resmgr/libresmgr1_1.0-2sarge2_sparc.deb
      Size/MD5 checksum: 7296 9974ef49ba0e43ab99d4892876a66f0d
    http://security.debian.org/pool/updates/main/r/resmgr/resmgr_1.0-2sarge2_sparc.deb
      Size/MD5 checksum: 29564 b7255b27b8ea036030ffe9487b8da09d

These files will probably be moved into the stable distribution on its next update.


For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

Fedora Core


Fedora Update Notification
FEDORA-2006-473
2006-04-27

Product : Fedora Core 4
Name : libtiff
Version : 3.7.1
Release : 6.fc4.1
Summary : A library of functions for manipulating TIFF format image files.

Description :
The libtiff package contains a library of functions for manipulating TIFF (Tagged Image File Format) image format files. TIFF is a widely used file format for bitmapped images. TIFF files usually end in the .tif extension and they are often quite large.

The libtiff package should be installed if you need to manipulate TIFF format image files.


Update Information:

This updates fixes serveral vulnerabilities in libtiff.


* Wed Apr 26 2006 Matthias Clasen <mclasen@redhat.com> - 3.7.1-6.fc4.1 - Fix multiple vulnerabilities (#189933, #189974, CVE-2006-2024)
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

fc85fc083881e06fdeece647aeb98a2e9b2f7952 SRPMS/libtiff-3.7.1-6.fc4.1.src.rpm
e2db5abb2efd165434e20d29b99154c37566edf6 ppc/libtiff-3.7.1-6.fc4.1.ppc.rpm
74b40fd554620c1aa5d9b4920761fccbdc8f2bb6 ppc/libtiff-devel-3.7.1-6.fc4.1.ppc.rpm
0f1fcc2bb8973859cc8e00a4900ea82782f63c1c ppc/debug/libtiff-debuginfo-3.7.1-6.fc4.1.ppc.rpm
63321e57b0445da06864815c675eb6d2eef7c3bc x86_64/libtiff-3.7.1-6.fc4.1.x86_64.rpm
2c96cf3bfb814830e6f3fc8ac573a3b90732b653 x86_64/libtiff-devel-3.7.1-6.fc4.1.x86_64.rpm
94968b95b8798b173a23ba6b7b449b213195a20a x86_64/debug/libtiff-debuginfo-3.7.1-6.fc4.1.x86_64.rpm
6c362bcbc13becdd3cb7a91ecd272bd260564d04 i386/libtiff-3.7.1-6.fc4.1.i386.rpm
6a89ec5b0e4a6945ebef4f2a0c310f3f5104964b i386/libtiff-devel-3.7.1-6.fc4.1.i386.rpm
b2f21b90d05b9b508213e7461185098cb1adcba0 i386/debug/libtiff-debuginfo-3.7.1-6.fc4.1.i386.rpm

This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at http://fedora.redhat.com/docs/yum/.


Fedora Update Notification
FEDORA-2006-474
2006-04-27

Product : Fedora Core 5
Name : libtiff
Version : 3.7.4
Release : 4
Summary : Library of functions for manipulating TIFF format image files

Description :
The libtiff package contains a library of functions for manipulating TIFF (Tagged Image File Format) image format files. TIFF is a widely used file format for bitmapped images. TIFF files usually end in the .tif extension and they are often quite large.

The libtiff package should be installed if you need to manipulate TIFF format image files.


Update Information:

This update fixes several vulnerabilities in libtiff.


* Wed Apr 26 2006 Matthias Clasen <mclasen@redhat.com> - 3.7.4-4 - fix several vulnerabilities (#189933, #189974, CVE-2006-2024)
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

f10f9f02eeed876e595757f26b7001f89d429acd SRPMS/libtiff-3.7.4-4.src.rpm
63df5887d2e5eef6e5825c31becdd2a3fd4ac331 ppc/libtiff-3.7.4-4.ppc.rpm
1c918c481ba1424d23487481a1746ce2e2a351cc ppc/libtiff-devel-3.7.4-4.ppc.rpm
64536d586ab9b70544b3030e4ca7cd0cfbd92408 ppc/debug/libtiff-debuginfo-3.7.4-4.ppc.rpm
e67065b4eff65172ea28cb52fcb74dc8a51f9e9d x86_64/libtiff-3.7.4-4.x86_64.rpm
0a96584fb47408728abc6f0c4856f4eb22f90f96 x86_64/libtiff-devel-3.7.4-4.x86_64.rpm
c6816dcc190d212a929ca208e4dd09a9ae384062 x86_64/debug/libtiff-debuginfo-3.7.4-4.x86_64.rpm
10a8510cf5b10ca29df0d046bc41ca551b87828d i386/libtiff-3.7.4-4.i386.rpm
1e9d034a1331234afeed76134b9eef4bc4f00f8b i386/libtiff-devel-3.7.4-4.i386.rpm
c9d13d1a6523a044393f97daff65653888a0c046 i386/debug/libtiff-debuginfo-3.7.4-4.i386.rpm

This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at http://fedora.redhat.com/docs/yum/.

Gentoo Linux


Gentoo Linux Security Advisory GLSA 200604-17

http://security.gentoo.org/


Severity: High
Title: Ethereal: Multiple vulnerabilities in protocol dissectors
Date: April 27, 2006
Bugs: #130505
ID: 200604-17


Synopsis

Ethereal is vulnerable to numerous vulnerabilities, potentially resulting in the execution of arbitrary code.

Background

Ethereal is a feature-rich network protocol analyzer.

Affected packages


Package / Vulnerable / Unaffected
1 net-analyzer/ethereal < 0.99.0 >= 0.99.0

Description

Coverity discovered numerous vulnerabilities in versions of Ethereal prior to 0.99.0, including:

  • buffer overflows in the ALCAP (CVE-2006-1934), COPS (CVE-2006-1935) and telnet (CVE-2006-1936) dissectors.
  • buffer overflows in the NetXray/Windows Sniffer and Network Instruments file code (CVE-2006-1934).

For further details please consult the references below.

Impact

An attacker might be able to exploit these vulnerabilities to crash Ethereal or execute arbitrary code with the permissions of the user running Ethereal, which could be the root user.

Workaround

There is no known workaround at this time.

Resolution

All Ethereal users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=net-analyzer/ethereal-0.99.0"

References

[ 1 ] CVE-2006-1932

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1932

[ 2 ] CVE-2006-1933

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1933

[ 3 ] CVE-2006-1934

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1934

[ 4 ] CVE-2006-1935

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1935

[ 5 ] CVE-2006-1936

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1936

[ 6 ] CVE-2006-1937

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1937

[ 7 ] CVE-2006-1938

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1938

[ 8 ] CVE-2006-1939

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1939

[ 9 ] CVE-2006-1940

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1940

[ 10 ] Ethereal enpa-sa-00023

http://www.ethereal.com/appnotes/enpa-sa-00023.html

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200604-17.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0


Gentoo Linux Security Advisory GLSA 200604-18

http://security.gentoo.org/


Severity: Normal
Title: Mozilla Suite: Multiple vulnerabilities
Date: April 28, 2006
Bugs: #130887
ID: 200604-18


Synopsis

Several vulnerabilities in Mozilla Suite allow attacks ranging from script execution with elevated privileges to information leaks.

Background

The Mozilla Suite is a popular all-in-one web browser that includes a mail and news reader.

Affected packages


Package / Vulnerable / Unaffected

1 www-client/mozilla < 1.7.13 >= 1.7.13 2 www-client/mozilla-bin < 1.7.13 >= 1.7.13 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures.


Description

Several vulnerabilities were found in Mozilla Suite. Version 1.7.13 was released to fix them.

Impact

A remote attacker could craft malicious web pages or emails that would leverage these issues to inject and execute arbitrary script code with elevated privileges, steal local files, cookies or other information from web pages or emails, and spoof content. Some of these vulnerabilities might even be exploited to execute arbitrary code with the rights of the user running the client.

Workaround

There are no known workarounds for all the issues at this time.

Resolution

All Mozilla Suite users should upgrade to the latest version:

    # emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/mozilla-1.7.13"

All Mozilla Suite binary users should upgrade to the latest version:

    # emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/mozilla-bin-1.7.13"

References

[ 1 ] CVE-2005-4134

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4134

[ 2 ] CVE-2006-0292

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0292

[ 3 ] CVE-2006-0293

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0293

[ 4 ] CVE-2006-0296

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0296

[ 5 ] CVE-2006-0748

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0748

[ 6 ] CVE-2006-0749

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0749

[ 7 ] CVE-2006-0884

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0884

[ 8 ] CVE-2006-1045

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1045

[ 9 ] CVE-2006-1727

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1727

[ 10 ] CVE-2006-1728

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1728

[ 11 ] CVE-2006-1729

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1729

[ 12 ] CVE-2006-1730

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1730

[ 13 ] CVE-2006-1731

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1731

[ 14 ] CVE-2006-1732

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1732

[ 15 ] CVE-2006-1733

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1733

[ 16 ] CVE-2006-1734

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1734

[ 17 ] CVE-2006-1735

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1735

[ 18 ] CVE-2006-1736

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1736

[ 19 ] CVE-2006-1737

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1737

[ 20 ] CVE-2006-1738

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1738

[ 21 ] CVE-2006-1739

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1739

[ 22 ] CVE-2006-1740

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1740

[ 23 ] CVE-2006-1741

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1741

[ 24 ] CVE-2006-1742

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1742

[ 25 ] CVE-2006-1790

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1790

[ 26 ] Mozilla Foundation Security Advisories

http://www.mozilla.org/projects/security/known-vulnerabilities.html#Mozilla

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200604-18.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0

Slackware Linux

[slackware-security] thunderbird (SSA:2006-120-01)

New Thunderbird packages are available for Slackware 10.2 and -current to fix security issues.

More details about the issues may be found here:

http://www.mozilla.org/projects/security/known-vulnerabilities.html#thunderbird

Here are the details from the Slackware 10.2 ChangeLog:
+--------------------------+
patches/packages/mozilla-thunderbird-1.5.0.2-i686-1.tgz:
Upgraded to thunderbird-1.5.0.2.
This upgrade fixes several possible security bugs.
For more information, see:
    http://www.mozilla.org/projects/security/known-vulnerabilities.html#thunderbird
(* Security fix *)
+--------------------------+

Where to find the new packages:

Updated package for Slackware 10.2:
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/mozilla-thunderbird-1.5.0.2-i686-1.tgz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/mozilla-thunderbird-1.5.0.2-i686-1.tgz

MD5 signatures:

Slackware 10.2 package:
f8b0dae2ab456cb9570cd646c9cc2a18 mozilla-thunderbird-1.5.0.2-i686-1.tgz

Slackware -current package:
e153239b8e2d33454468bf0e4c24dd8d mozilla-thunderbird-1.5.0.2-i686-1.tgz

Installation instructions:

Upgrade the package as root:
# upgradepkg mozilla-thunderbird-1.5.0.2-i686-1.tgz

+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com


Ubuntu Linux


Ubuntu Security Notice USN-274-1 April 27, 2006
mysql-dfsg vulnerability
CVE-2006-0903

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)
Ubuntu 5.04 (Hoary Hedgehog)
Ubuntu 5.10 (Breezy Badger)

The following packages are affected:

mysql-server

The problem can be corrected by upgrading the affected package to version 4.0.20-2ubuntu1.7 (for Ubuntu 4.10), 4.0.23-3ubuntu2.2 (for Ubuntu 5.04), or 4.0.24-10ubuntu2.1 (for Ubuntu 5.10). In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

A logging bypass was discovered in the MySQL query parser. A local attacker could exploit this by inserting NUL characters into query strings (even into comments), which would cause the query to be logged incompletely.

This only affects you if you enabled the 'log' parameter in the MySQL configuration.

Updated packages for Ubuntu 4.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-dfsg_4.0.20-2ubuntu1.7.diff.gz
      Size/MD5: 176824 f214253e4c2a6ffcfd949bc19410ee6b
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-dfsg_4.0.20-2ubuntu1.7.dsc
      Size/MD5: 894 19ef051a7994a4faea9b248c12dc44b5
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-dfsg_4.0.20.orig.tar.gz
      Size/MD5: 9760117 f092867f6df2f50b34b8065312b9fb2b

Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-common_4.0.20-2ubuntu1.7_all.deb
      Size/MD5: 25144 b28d3fdc01b8d8194d0388d8d48a257d

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient-dev_4.0.20-2ubuntu1.7_amd64.deb
      Size/MD5: 2811182 c4111aec963f9a495b261b299e449c2e
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12_4.0.20-2ubuntu1.7_amd64.deb
      Size/MD5: 305220 8f6653a1152af3624e68a759a2893827
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-client_4.0.20-2ubuntu1.7_amd64.deb
      Size/MD5: 423266 f5702114938059a53d531535caaad7f5
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-server_4.0.20-2ubuntu1.7_amd64.deb
      Size/MD5: 3578122 92a1b9e4c8d874dffc09ebf5fb13e72b

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient-dev_4.0.20-2ubuntu1.7_i386.deb
      Size/MD5: 2774718 6b2c35f99be213bfc34133995e611f46
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12_4.0.20-2ubuntu1.7_i386.deb
      Size/MD5: 288162 61879cbc26a9b7dbb27c6c842546458d
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-client_4.0.20-2ubuntu1.7_i386.deb
      Size/MD5: 397264 612dc9f1b1149a2af49b0a2aa157e009
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-server_4.0.20-2ubuntu1.7_i386.deb
      Size/MD5: 3487310 47ecf2e29f3dbe465dfd990ba80c36eb

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient-dev_4.0.20-2ubuntu1.7_powerpc.deb
      Size/MD5: 3110894 81feb50003ee69b7e93b809b8c0bfc39
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12_4.0.20-2ubuntu1.7_powerpc.deb
      Size/MD5: 308852 a8fe34e726d5302deb751838ef8ccb06
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-client_4.0.20-2ubuntu1.7_powerpc.deb
      Size/MD5: 452684 52bfacf4b50418cc8d30fdde7679eab4
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-server_4.0.20-2ubuntu1.7_powerpc.deb
      Size/MD5: 3770820 3c992663d03b4b9f548207e7dddb2749

Updated packages for Ubuntu 5.04:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-dfsg_4.0.23-3ubuntu2.2.diff.gz
      Size/MD5: 343725 a2b298ae7189d19d610096bd509ce596
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-dfsg_4.0.23-3ubuntu2.2.dsc
      Size/MD5: 891 b92cb6c84451811ccf7bd7c2a56c50b4
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-dfsg_4.0.23.orig.tar.gz
      Size/MD5: 9814467 5eec8f66ed48c6ff92e73161651a492b

Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-common_4.0.23-3ubuntu2.2_all.deb
      Size/MD5: 31990 2d6d3941ca77a34d4fe04919aac8cbc7

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12-dev_4.0.23-3ubuntu2.2_amd64.deb
      Size/MD5: 2866184 3b5f0aa334fc9e1fa7056cf210f94fd2
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12_4.0.23-3ubuntu2.2_amd64.deb
      Size/MD5: 306820 e2917d28d803a34a4c72da0fbba151d3
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-client_4.0.23-3ubuntu2.2_amd64.deb
      Size/MD5: 431414 cc314f27a6afe67c821a7a51da383545
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-server_4.0.23-3ubuntu2.2_amd64.deb
      Size/MD5: 3628640 b296921ef40461d59e9bbba7b2e52357

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12-dev_4.0.23-3ubuntu2.2_i386.deb
      Size/MD5: 2825934 44b9304d6fa1fd3e3c2e3e9686024c10
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12_4.0.23-3ubuntu2.2_i386.deb
      Size/MD5: 289510 da17fd8185519af7a3df1a861ce33d07
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-client_4.0.23-3ubuntu2.2_i386.deb
      Size/MD5: 404598 158bbb7ad75e303bf5c13adb383b599a
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-server_4.0.23-3ubuntu2.2_i386.deb
      Size/MD5: 3537624 9482f91850da2bd3fdde233aa9e64052

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12-dev_4.0.23-3ubuntu2.2_powerpc.deb
      Size/MD5: 3179624 7466544fb8fc5a7209340039b65c63da
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12_4.0.23-3ubuntu2.2_powerpc.deb
      Size/MD5: 312406 8fb8562ffa55040773a02eeb64ba8272
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-client_4.0.23-3ubuntu2.2_powerpc.deb
      Size/MD5: 462192 265ff5c43fc9afefe1af28c3a4386e5e
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-server_4.0.23-3ubuntu2.2_powerpc.deb
      Size/MD5: 3839282 617a98d3bc28182b3ff37e0e3f130795

Updated packages for Ubuntu 5.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-dfsg_4.0.24-10ubuntu2.1.diff.gz
      Size/MD5: 97810 0dbdcd235f3f6a2f424de7113b74655d
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-dfsg_4.0.24-10ubuntu2.1.dsc
      Size/MD5: 964 f84c5803fc7d13589346e910387f30c6
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-dfsg_4.0.24.orig.tar.gz
      Size/MD5: 9923794 aed8f335795a359f32492159e3edfaa3

Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-common_4.0.24-10ubuntu2.1_all.deb
      Size/MD5: 34664 544a522c6d3206981da17184e978e617

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12-dev_4.0.24-10ubuntu2.1_amd64.deb
      Size/MD5: 3231158 c1d669e10ac67d1e9b0f121833683779
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12_4.0.24-10ubuntu2.1_amd64.deb
      Size/MD5: 307700 4bc18b69d4e43b694497b4076d79cd75
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-client_4.0.24-10ubuntu2.1_amd64.deb
      Size/MD5: 439484 a29c262a4aa8cdd57f8dfe8009cb8b7d
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-server_4.0.24-10ubuntu2.1_amd64.deb
      Size/MD5: 3922016 e92ecc0bd9a6fea65f42c7bead40b6db

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12-dev_4.0.24-10ubuntu2.1_i386.deb
      Size/MD5: 2868302 9dabada4f3d7a4a85df44299b94eae88
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12_4.0.24-10ubuntu2.1_i386.deb
      Size/MD5: 291550 efbfa0fc65a09ead055a27414e1be54a
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-client_4.0.24-10ubuntu2.1_i386.deb
      Size/MD5: 413452 596701868b19ae58687798f73327db4d
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-server_4.0.24-10ubuntu2.1_i386.deb
      Size/MD5: 3555444 32eed9d4f3f58a083c505555e249a0ac

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12-dev_4.0.24-10ubuntu2.1_powerpc.deb
      Size/MD5: 3089942 a58bb68ffed82acc2161d2bf49542da8
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12_4.0.24-10ubuntu2.1_powerpc.deb
      Size/MD5: 305526 f033567ad51627ff2137a3118deb668a
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-client_4.0.24-10ubuntu2.1_powerpc.deb
      Size/MD5: 453378 ab9be3cf1197c77c7992942c4c1cc9c0
    http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-server_4.0.24-10ubuntu2.1_powerpc.deb
      Size/MD5: 3664012 e9a402c36b385dcb83d2248ff4487a2c


Ubuntu Security Notice USN-275-1 April 27, 2006
mozilla vulnerabilities
CVE-2005-4134, CVE-2006-0292, CVE-2006-0296, CVE-2006-0748, CVE-2006-0749, CVE-2006-1727, CVE-2006-1728, CVE-2006-1729, CVE-2006-1730, CVE-2006-1731, CVE-2006-1732, CVE-2006-1733, CVE-2006-1734, CVE-2006-1735, CVE-2006-1736, CVE-2006-1737, CVE-2006-1738, CVE-2006-1739, CVE-2006-1740, CVE-2006-1741, CVE-2006-1742, CVE-2006-1790

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)
Ubuntu 5.04 (Hoary Hedgehog)
Ubuntu 5.10 (Breezy Badger)

The following packages are affected:

mozilla-browser
mozilla-mailnews
mozilla-psm

The problem can be corrected by upgrading the affected package to version 2:1.7.13-0ubuntu04.10 (for Ubuntu 4.10), 2:1.7.13-0ubuntu05.04 (for Ubuntu 5.04), and 2:1.7.13-0ubuntu5.10 (for Ubuntu 5.10). After a standard system upgrade you need to restart Mozilla to effect the necessary changes.

Details follow:

Web pages with extremely long titles caused subsequent launches of Mozilla browser to hang for up to a few minutes, or caused Mozilla to crash on computers with insufficient memory. (CVE-2005-4134)

Igor Bukanov discovered that the JavaScript engine did not properly declare some temporary variables. Under some rare circumstances, a malicious website could exploit this to execute arbitrary code with the privileges of the user. (CVE-2006-0292, CVE-2006-1742)

The function XULDocument.persist() did not sufficiently validate the names of attributes. An attacker could exploit this to inject arbitrary XML code into the file 'localstore.rdf', which is read and evaluated at startup. This could include JavaScript commands that would be run with the user's privileges. (CVE-2006-0296)

Due to a flaw in the HTML tag parser a specific sequence of HTML tags caused memory corruption. A malicious web site could exploit this to crash the browser or even execute arbitrary code with the user's privileges. (CVE-2006-0748)

An invalid ordering of table-related tags caused Mozilla to use a negative array index. A malicious website could exploit this to execute arbitrary code with the privileges of the user. (CVE-2006-0749)

Georgi Guninski discovered that embedded XBL scripts of web sites could escalate their (normally reduced) privileges to get full privileges of the user if that page is viewed with "Print Preview". (CVE-2006-1727)

The crypto.generateCRMFRequest() function had a flaw which could be exploited to run arbitrary code with the user's privileges. (CVE-2006-1728)

Claus Jørgensen and Jesse Ruderman discovered that a text input box could be pre-filled with a filename and then turned into a file-upload control with the contents intact. A malicious web site could exploit this to read any local file the user has read privileges for. (CVE-2006-1729)

An integer overflow was detected in the handling of the CSS property "letter-spacing". A malicious web site could exploit this to run arbitrary code with the user's privileges. (CVE-2006-1730)

The methods valueOf.call() and .valueOf.apply() returned an object whose privileges were not properly confined to those of the caller, which made them vulnerable to cross-site scripting attacks. A malicious web site could exploit this to modify the contents or steal confidential data (such as passwords) from other opened web pages. (CVE-2006-1731) The window.controllers array variable (CVE-2006-1732) and event handlers (CVE-2006-1741) were vulnerable to a similar attack.

The privileged built-in XBL bindings were not fully protected from web content and could be accessed by calling valueOf.call() and valueOf.apply() on a method of that binding. A malicious web site could exploit this to run arbitrary JavaScript code with the user's privileges. (CVE-2006-1733)

It was possible to use the Object.watch() method to access an internal function object (the "clone parent"). A malicious web site could exploit this to execute arbitrary JavaScript code with the user's privileges. (CVE-2006-1734)

By calling the XBL.method.eval() method in a special way it was possible to create JavaScript functions that would get compiled with the wrong privileges. A malicious web site could exploit this to execute arbitrary JavaScript code with the user's privileges. (CVE-2006-1735)

Michael Krax discovered that by layering a transparent image link to an executable on top of a visible (and presumably desirable) image a malicious site could fool the user to right-click and choose "Save image as..." from the context menu, which would download the executable instead of the image. (CVE-2006-1736)

Several crashes have been fixed which could be triggered by web sites and involve memory corruption. These could potentially be exploited to execute arbitrary code with the user's privileges. (CVE-2006-1737, CVE-2006-1738, CVE-2006-1739, CVE-2006-1790)

If the user has turned on the "Entering secure site" modal warning dialog, it was possible to spoof the browser's secure-site indicators (the lock icon and the gold URL field background) by first loading the target secure site in a pop-up window, then changing its location to a different site, which retained the displayed secure-browsing indicators from the original site. (CVE-2006-1740)

Updated packages for Ubuntu 4.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla_1.7.13-0ubuntu04.10.diff.gz
      Size/MD5: 789067 afbbc4f9ea7c9c1a48bd8704da61a004
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla_1.7.13-0ubuntu04.10.dsc
      Size/MD5: 1116 d3a18730ba0f1521d03fff0d56c34135
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla_1.7.13.orig.tar.gz
      Size/MD5: 38788839 db906560b5abe488286ad1edc21d52b6

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr-dev_1.7.13-0ubuntu04.10_amd64.deb
      Size/MD5: 168070 8454dfee4d5439ddd6fd4ddcd98c3070
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr4_1.7.13-0ubuntu04.10_amd64.deb
      Size/MD5: 140586 001454b7dd1cad8daf6db93ce6fba117
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss-dev_1.7.13-0ubuntu04.10_amd64.deb
      Size/MD5: 184956 d1da3bb4641e33ee472002526d87f4ef
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss3_1.7.13-0ubuntu04.10_amd64.deb
      Size/MD5: 709296 15284d31d8e1c024059294fb9a8408ce
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-browser_1.7.13-0ubuntu04.10_amd64.deb
      Size/MD5: 11420564 bea63a13a32b2769b43ee7c38e43af1c
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-calendar_1.7.13-0ubuntu04.10_amd64.deb
      Size/MD5: 403266 4edb2357797855099c7f79bafdc9ba30
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-chatzilla_1.7.13-0ubuntu04.10_amd64.deb
      Size/MD5: 158322 146d4b4f257eacc4c3e1db3467ea8d81
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-dev_1.7.13-0ubuntu04.10_amd64.deb
      Size/MD5: 3351116 607a5c4adf10e336de39d2b7770c981b
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-dom-inspector_1.7.13-0ubuntu04.10_amd64.deb
      Size/MD5: 121132 48043706c3c2583a98972a1646fc9d36
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-js-debugger_1.7.13-0ubuntu04.10_amd64.deb
      Size/MD5: 204152 9813c46799e587ac101d9428bc6ddb33
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-mailnews_1.7.13-0ubuntu04.10_amd64.deb
      Size/MD5: 1937716 36f516ea810b2adb6528521f014612a1
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-psm_1.7.13-0ubuntu04.10_amd64.deb
      Size/MD5: 204524 7a7b2b313f32e428bcd93be658e92972
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla_1.7.13-0ubuntu04.10_amd64.deb
      Size/MD5: 1040 3c9e48cf32c266f15f9771b0c376e4d3

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr-dev_1.7.13-0ubuntu04.10_i386.deb
      Size/MD5: 168072 04ee8d17cbcbbbce5b1e5681fef1924d
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr4_1.7.13-0ubuntu04.10_i386.deb
      Size/MD5: 127176 dc4d73a38bc22d39edd75992693793a0
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss-dev_1.7.13-0ubuntu04.10_i386.deb
      Size/MD5: 184942 3bed336965d075017074341c8aca7905
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss3_1.7.13-0ubuntu04.10_i386.deb
      Size/MD5: 639014 21565048c296e069d6a5525ba651ad9a
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-browser_1.7.13-0ubuntu04.10_i386.deb
      Size/MD5: 10605678 18cec92f27982424eee7a93343deda7b
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-calendar_1.7.13-0ubuntu04.10_i386.deb
      Size/MD5: 403276 475ba0bcfca9550ff12db6f9dd46abfe
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-chatzilla_1.7.13-0ubuntu04.10_i386.deb
      Size/MD5: 158316 2bf4a10a6a9c7afc7bd3d2ef3d9c0485
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-dev_1.7.13-0ubuntu04.10_i386.deb
      Size/MD5: 3344102 715c47b566ffb5e682ad26499da6f096
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-dom-inspector_1.7.13-0ubuntu04.10_i386.deb
      Size/MD5: 115820 3d9489d74afaf7cc3ad8f8aeb626eb3f
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-js-debugger_1.7.13-0ubuntu04.10_i386.deb
      Size/MD5: 204152 553e5ce695c8cc24936c82305531d9a4
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-mailnews_1.7.13-0ubuntu04.10_i386.deb
      Size/MD5: 1780866 df132aaa16c925466be55a119c288367
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-psm_1.7.13-0ubuntu04.10_i386.deb
      Size/MD5: 188476 3fe3e488b55b253b1982af3a80cf7a3b
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla_1.7.13-0ubuntu04.10_i386.deb
      Size/MD5: 1036 24bf669e5cc5cc3f903b6fdc126e6f6c

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr-dev_1.7.13-0ubuntu04.10_powerpc.deb
      Size/MD5: 168074 e2acc217b4ecf3dce72f6c34491bae14
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr4_1.7.13-0ubuntu04.10_powerpc.deb
      Size/MD5: 125830 b91d146c2307bd2478b3891f2d86ca85
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss-dev_1.7.13-0ubuntu04.10_powerpc.deb
      Size/MD5: 184954 07d2e55528a02b594d75d41d590e1ad9
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss3_1.7.13-0ubuntu04.10_powerpc.deb
      Size/MD5: 713720 fad07be7d0de7b698fdda3764f65e7b6
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-browser_1.7.13-0ubuntu04.10_powerpc.deb
      Size/MD5: 10170804 7bf67766d637fdf91db7f5e672c97c25
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-calendar_1.7.13-0ubuntu04.10_powerpc.deb
      Size/MD5: 403270 d25b902af5107d4bc7f359f904558a76
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-chatzilla_1.7.13-0ubuntu04.10_powerpc.deb
      Size/MD5: 158322 12d20f752f7fd731ab7a7b87bf485467
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-dev_1.7.13-0ubuntu04.10_powerpc.deb
      Size/MD5: 3339290 3773d4eee27eca29abd7b3b43f8ac125
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-dom-inspector_1.7.13-0ubuntu04.10_powerpc.deb
      Size/MD5: 114540 47e63b04a99892b8dc00743ed5253444
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-js-debugger_1.7.13-0ubuntu04.10_powerpc.deb
      Size/MD5: 204150 37605aa679b02c43906c1da7a929a557
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-mailnews_1.7.13-0ubuntu04.10_powerpc.deb
      Size/MD5: 1642526 1af9ee17bc9217b6e7279019e57bd597
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-psm_1.7.13-0ubuntu04.10_powerpc.deb
      Size/MD5: 175648 494c34353aa8af0003a3abdd9c8cb580
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla_1.7.13-0ubuntu04.10_powerpc.deb
      Size/MD5: 1036 bb2757d3fdd5d5c7799fa0b1c1a16108

Updated packages for Ubuntu 5.04:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla_1.7.13-0ubuntu05.04.diff.gz
      Size/MD5: 312149 9e2a7c854ac6a5f9ad25d07d85bb9051
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla_1.7.13-0ubuntu05.04.dsc
      Size/MD5: 1136 435e57e3bfb0406b5cb8f5751a42532a
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla_1.7.13.orig.tar.gz
      Size/MD5: 38788839 db906560b5abe488286ad1edc21d52b6

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr-dev_1.7.13-0ubuntu05.04_amd64.deb
      Size/MD5: 168078 90665311c622f04c54c6d94762f97b64
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr4_1.7.13-0ubuntu05.04_amd64.deb
      Size/MD5: 141110 1b818bb446e3e67b44f946f9424de237
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss-dev_1.7.13-0ubuntu05.04_amd64.deb
      Size/MD5: 184940 756d6dfd81aead732cb3969d5ca27da8
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss3_1.7.13-0ubuntu05.04_amd64.deb
      Size/MD5: 709922 608a8d12da3cd59ab625121c636d3cdc
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-browser_1.7.13-0ubuntu05.04_amd64.deb
      Size/MD5: 10607166 8554d260ce02455655d6edec14697562
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-calendar_1.7.13-0ubuntu05.04_amd64.deb
      Size/MD5: 403266 4835b8a0cc45043427b42c3ad92713bc
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-chatzilla_1.7.13-0ubuntu05.04_amd64.deb
      Size/MD5: 158318 22af79d42c1c6fdcb18146dad1085ffe
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-dev_1.7.13-0ubuntu05.04_amd64.deb
      Size/MD5: 3351248 79ea60ddc09b5cd1d716b1a27ca73be8
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-dom-inspector_1.7.13-0ubuntu05.04_amd64.deb
      Size/MD5: 121182 fb749f046fb40bfe999e817b0411e272
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-js-debugger_1.7.13-0ubuntu05.04_amd64.deb
      Size/MD5: 204156 23704d1a074dfbc7c24345aa47402622
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-mailnews_1.7.13-0ubuntu05.04_amd64.deb
      Size/MD5: 1935868 e64abd02523b56c48d82205130fc85cc
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-psm_1.7.13-0ubuntu05.04_amd64.deb
      Size/MD5: 204490 0480f560119cac1957ce20ebd3307103
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla_1.7.13-0ubuntu05.04_amd64.deb
      Size/MD5: 1040 152b421f0ceec65384b126f4feaad4b2

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr-dev_1.7.13-0ubuntu05.04_i386.deb
      Size/MD5: 168068 6ad586817f76898a96f680e7ab416d2e
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr4_1.7.13-0ubuntu05.04_i386.deb
      Size/MD5: 127750 98fe626168bfd7d27a2311f355794a90
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss-dev_1.7.13-0ubuntu05.04_i386.deb
      Size/MD5: 184938 6fea51308639ccc79da58ea3f558d159
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss3_1.7.13-0ubuntu05.04_i386.deb
      Size/MD5: 639796 d05ab209f85fe4923f682984ef6929d4
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-browser_1.7.13-0ubuntu05.04_i386.deb
      Size/MD5: 9622320 82e2e379706f4966765525cb8d1545bc
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-calendar_1.7.13-0ubuntu05.04_i386.deb
      Size/MD5: 403272 33320a452c1333e09b334526061b6df8
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-chatzilla_1.7.13-0ubuntu05.04_i386.deb
      Size/MD5: 158322 a503ea48989e41a3708939acf4e81fb1
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-dev_1.7.13-0ubuntu05.04_i386.deb
      Size/MD5: 3343798 2701682b9c9387877d66ff8125f2ccdd
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-dom-inspector_1.7.13-0ubuntu05.04_i386.deb
      Size/MD5: 115828 1c2689a2ff1415a714f0eb87064bfd95
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-js-debugger_1.7.13-0ubuntu05.04_i386.deb
      Size/MD5: 204156 a807983dc65a6b0172f3d74ec55847ed
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-mailnews_1.7.13-0ubuntu05.04_i386.deb
      Size/MD5: 1780802 b5efc4fbdd10a5144a288f691bac2a27
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-psm_1.7.13-0ubuntu05.04_i386.deb
      Size/MD5: 188476 fa2f19a5d6bee332d15ca568f7530ba0
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla_1.7.13-0ubuntu05.04_i386.deb
      Size/MD5: 1040 d1fae72f5fee7daaf9c7107bed452d76

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr-dev_1.7.13-0ubuntu05.04_powerpc.deb
      Size/MD5: 168070 a505b26a0909b9795716c1d290ecb17e
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr4_1.7.13-0ubuntu05.04_powerpc.deb
      Size/MD5: 126474 f6365509dabc4b03f5adc986c397296f
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss-dev_1.7.13-0ubuntu05.04_powerpc.deb
      Size/MD5: 184958 3e7b5fc3ec3c45bed6c67ec69476ac66
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss3_1.7.13-0ubuntu05.04_powerpc.deb
      Size/MD5: 714134 c011c69d35e1c5e489dcafb2575b001b
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-browser_1.7.13-0ubuntu05.04_powerpc.deb
      Size/MD5: 9172754 c902d3e4018478cc07a727d8245a33d4
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-calendar_1.7.13-0ubuntu05.04_powerpc.deb
      Size/MD5: 403270 f94141278087b1b0e62286e9f577b41a
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-chatzilla_1.7.13-0ubuntu05.04_powerpc.deb
      Size/MD5: 158326 5a09e8d5c572f3ee09a949c505297dae
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-dev_1.7.13-0ubuntu05.04_powerpc.deb
      Size/MD5: 3339462 3a1bd5c57c39864099432ebfe00ea9c8
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-dom-inspector_1.7.13-0ubuntu05.04_powerpc.deb
      Size/MD5: 114570 da9b57cd61dd9859736f0ddbe142db5a
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-js-debugger_1.7.13-0ubuntu05.04_powerpc.deb
      Size/MD5: 204152 d7be56b320bf028e6b4d8ab3a07d936c
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-mailnews_1.7.13-0ubuntu05.04_powerpc.deb
      Size/MD5: 1642912 f40ca57faf41f619e11ffd664953b25f
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-psm_1.7.13-0ubuntu05.04_powerpc.deb
      Size/MD5: 175692 aef5bc7564dbfd726e50a5f727c8888b
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla_1.7.13-0ubuntu05.04_powerpc.deb
      Size/MD5: 1042 28eaa6f51c0abb4539127ad6c5a71ed3

Updated packages for Ubuntu 5.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla_1.7.13-0ubuntu5.10.diff.gz
      Size/MD5: 314233 ae7d4f002c8932b4efe546974d90b8ec
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla_1.7.13-0ubuntu5.10.dsc
      Size/MD5: 1076 0d6918758733e99e2c834fb94914ddb5
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla_1.7.13.orig.tar.gz
      Size/MD5: 38788839 db906560b5abe488286ad1edc21d52b6

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr-dev_1.7.13-0ubuntu5.10_amd64.deb
      Size/MD5: 168046 0f5e810e26e89cc9e172560d64af62a7
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr4_1.7.13-0ubuntu5.10_amd64.deb
      Size/MD5: 143178 e1d7426427b855a752f87fa4697f40fa
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss-dev_1.7.13-0ubuntu5.10_amd64.deb
      Size/MD5: 184924 406280f39569c509c57830b8ace1f7cd
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss3_1.7.13-0ubuntu5.10_amd64.deb
      Size/MD5: 718706 deefb84d84680c6ad8b255361ed6c972
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-browser_1.7.13-0ubuntu5.10_amd64.deb
      Size/MD5: 10663004 3cdfe88e65604779a55dd1e7fc90de69
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-calendar_1.7.13-0ubuntu5.10_amd64.deb
      Size/MD5: 403266 d2ece836b553bf4f6828a2703de72b03
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-chatzilla_1.7.13-0ubuntu5.10_amd64.deb
      Size/MD5: 158316 88571d69efda699691adb2dc1b0059e0
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-dev_1.7.13-0ubuntu5.10_amd64.deb
      Size/MD5: 3346934 af363fbd775bc3d5661685644ac0eef3
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-dom-inspector_1.7.13-0ubuntu5.10_amd64.deb
      Size/MD5: 122354 fc8f4abe88cb4e66febfb22421663308
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-js-debugger_1.7.13-0ubuntu5.10_amd64.deb
      Size/MD5: 204144 1bf156b75456465427d5200a93854c17
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-mailnews_1.7.13-0ubuntu5.10_amd64.deb
      Size/MD5: 1962838 49e5173facb38c5213dfae77cdf8381e
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-psm_1.7.13-0ubuntu5.10_amd64.deb
      Size/MD5: 204124 a723d0a84ea1756d287cd8953960d7a1
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla_1.7.13-0ubuntu5.10_amd64.deb
      Size/MD5: 1028 0530d2f3d6bca9437d4dab099be12da7

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr-dev_1.7.13-0ubuntu5.10_i386.deb
      Size/MD5: 168044 c5cefa2cfe5fa950665cac06de6a4b8e
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr4_1.7.13-0ubuntu5.10_i386.deb
      Size/MD5: 128552 2ecf8696f15d571db1002a1a1af750c2
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss-dev_1.7.13-0ubuntu5.10_i386.deb
      Size/MD5: 184936 1765bf3ee5bbc6ab257b7600c412c80e
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss3_1.7.13-0ubuntu5.10_i386.deb
      Size/MD5: 634748 81fd332af8cde66b3816490204004beb
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-browser_1.7.13-0ubuntu5.10_i386.deb
      Size/MD5: 9185012 083b390cb1349877e843bacf15030687
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-calendar_1.7.13-0ubuntu5.10_i386.deb
      Size/MD5: 403272 7c9ede3c6f06e00f92d11a1e3b95f33a
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-chatzilla_1.7.13-0ubuntu5.10_i386.deb
      Size/MD5: 158316 be031f5cfc072e0d0a5049c38b5e5030
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-dev_1.7.13-0ubuntu5.10_i386.deb
      Size/MD5: 3336558 bb7d0449416fb72126f49e900be255be
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-dom-inspector_1.7.13-0ubuntu5.10_i386.deb
      Size/MD5: 115300 9cd869c247919112fcfd2b60449bde3d
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-js-debugger_1.7.13-0ubuntu5.10_i386.deb
      Size/MD5: 204148 39cf81a1da978a065ff7beaf407af81c
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-mailnews_1.7.13-0ubuntu5.10_i386.deb
      Size/MD5: 1691466 4ae8c0b396740a8536b82d42eb5833bf
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-psm_1.7.13-0ubuntu5.10_i386.deb
      Size/MD5: 178770 08799211aed5ddc959d0dd30452373c8
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla_1.7.13-0ubuntu5.10_i386.deb
      Size/MD5: 1030 b7f4ba3c0d614a0d07a9558fd918479e

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr-dev_1.7.13-0ubuntu5.10_powerpc.deb
      Size/MD5: 168044 0829cac0cfb96a68067c668c4c69a98e
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnspr4_1.7.13-0ubuntu5.10_powerpc.deb
      Size/MD5: 130246 6712bc7157ca31b6bcd26ab0c195d8bf
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss-dev_1.7.13-0ubuntu5.10_powerpc.deb
      Size/MD5: 184924 f437cd22c0f0cb4d76fdd4fddeb402b4
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/libnss3_1.7.13-0ubuntu5.10_powerpc.deb
      Size/MD5: 696236 4d178d94cedbd9ef45e551aa495dcc44
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-browser_1.7.13-0ubuntu5.10_powerpc.deb
      Size/MD5: 9260072 b8939063410b595ab64e8269ca389bbc
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-calendar_1.7.13-0ubuntu5.10_powerpc.deb
      Size/MD5: 403266 249e5ec3d811245a789582c2f098761b
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-chatzilla_1.7.13-0ubuntu5.10_powerpc.deb
      Size/MD5: 158312 20254d7bb5ae30e40b37682b2784a561
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-dev_1.7.13-0ubuntu5.10_powerpc.deb
      Size/MD5: 3335612 1cdaccd79f7c4872593470c0113f8bea
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-dom-inspector_1.7.13-0ubuntu5.10_powerpc.deb
      Size/MD5: 115342 82c75c3c26430fb3c52415d249780e3a
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-js-debugger_1.7.13-0ubuntu5.10_powerpc.deb
      Size/MD5: 204144 874bd210d77bd1bbeba95570f46ce17e
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla-mailnews_1.7.13-0ubuntu5.10_powerpc.deb
      Size/MD5: 1671412 e81d375eab70a1c4d80faed553ab325e
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla/mozilla-psm_1.7.13-0ubuntu5.10_powerpc.deb
      Size/MD5: 175906 bc22ce561713e114bc0d5923965390a1
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla/mozilla_1.7.13-0ubuntu5.10_powerpc.deb
      Size/MD5: 1036 0e244be210e40298f2bfe64e89f81887



No talkbacks posted.
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!

..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP