Linux Today: Linux News On Internet Time.
Search Linux Today
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Server Daily
IT Management Daily
Subscribe News
Subscribe PR
Subscribe Security

internet.com
Internet News
Small Business

Advertise
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

20 popular Ubuntu Linux apps you may want to try

A Selection of the Very Best Open Source Tutorials and Tools

Android Ice Cream Sandwich ported to x86 tablets, netbooks and notebooks

SECURITY: Google Chrome 17 Improves Security

How to read a CSV file in Perl?

Red Hat Brings Gluster to Amazon Cloud

New Linux kernel fixes power-saving issues

Using Wii remote with Android Device- Taking Gaming to the Next Level

Commercial Support now available for the open-source NGINX Web server

Linux Top 5: Linux's New Fellow



Applications Management Engineer Sr (NYC)
Next Step Systems
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume
:Advisories, August 1, 2006
Advisories, August 1, 2006
Aug 2, 2006, 03 :45 UTC (0 Talkback[s]) (2660 reads)

Debian GNU/Linux


Debian Security Advisory DSA 1130-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
July 30th, 2006 http://www.debian.org/security/faq


Package : sitebar
Vulnerability : missing input validation
Problem type : remote
Debian-specific: no
CVE ID : CVE-2006-3320
BugTraq ID : 18680
Debian Bug : 377299

A a cross-site scripting vulnerability has been discovered in sitebar, a web based bookmark manager written in PHP, which allows remote attackers to inject arbitrary web script or HTML.

For the stable distribution (sarge) this problem has been fixed in version 3.2.6-7.1.

For the unstable distribution (sid) this problem has been fixed in version 3.3.8-1.1.

We recommend that you upgrade your sitebar package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given at the end of this advisory:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7.1.dsc
      Size/MD5 checksum: 567 af6299567258255742c9289ead8618e4
    http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7.1.diff.gz
      Size/MD5 checksum: 9214 2309667ac14ea821c7a1ba14b8a59916
    http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6.orig.tar.gz
      Size/MD5 checksum: 333352 a86243f7a70a1a9ac80342fbcca14297

Architecture independent components:

    http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7.1_all.deb
      Size/MD5 checksum: 339760 98d388ce2b2c8d746d333f6286e22c0b

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 1131-1 security@debian.org
http://www.debian.org/security/ Steve Kemp
Aug 1st, 2006 http://www.debian.org/security/faq


Package : apache
Vulnerability : buffer overflow
Problem-Type : remote
Debian-specific: no
CVE ID : CVE-2006-3747
CERT advisory : VU#395412
Debian Bug : 380231

Mark Dowd discovered a buffer overflow in the mod_rewrite component of apache, a versatile high-performance HTTP server. In some situations a remote attacker could exploit this to execute arbitary code.

For the stable distribution (sarge) this problem has been fixed in version 1.3.33-6sarge2.

For the unstable distribution (sid) this problems will be fixed shortly.

We recommend that you upgrade your apache package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33-6sarge2.dsc
      Size/MD5 checksum: 1119 8188c2fe660d475970139af295b07b86
    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33-6sarge2.diff.gz
      Size/MD5 checksum: 372930 40c5ca3d91d1307a191915459bc94237
    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33.orig.tar.gz
      Size/MD5 checksum: 3105683 1a34f13302878a8713a2ac760d9b6da8

Architecture independent components:

    http://security.debian.org/pool/updates/main/a/apache/apache-dev_1.3.33-6sarge2_all.deb
      Size/MD5 checksum: 334562 a6a506713c09c27143feffe738aed3f9
    http://security.debian.org/pool/updates/main/a/apache/apache-doc_1.3.33-6sarge2_all.deb
      Size/MD5 checksum: 1332888 f24fa9421e8dc9acec2467b58468f2dd
    http://security.debian.org/pool/updates/main/a/apache/apache-utils_1.3.33-6sarge2_all.deb
      Size/MD5 checksum: 212626 b9a5198ee442212cdd248be8827400a1

Alpha architecture:

    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33-6sarge2_alpha.deb
      Size/MD5 checksum: 428152 a58caae837e1025d97cf44bf8fb23f0f
    http://security.debian.org/pool/updates/main/a/apache/apache-common_1.3.33-6sarge2_alpha.deb
      Size/MD5 checksum: 904242 ce2a0e4b97c1926dafdf31e589883995
    http://security.debian.org/pool/updates/main/a/apache/apache-dbg_1.3.33-6sarge2_alpha.deb
      Size/MD5 checksum: 9223072 182f1789104e294f72fede75dc13b875
    http://security.debian.org/pool/updates/main/a/apache/apache-perl_1.3.33-6sarge2_alpha.deb
      Size/MD5 checksum: 569406 185346b21b2adbc248a06f689f094b97
    http://security.debian.org/pool/updates/main/a/apache/apache-ssl_1.3.33-6sarge2_alpha.deb
      Size/MD5 checksum: 542576 dfe389cdb48d38ee2a27a3a622a6c6e0
    http://security.debian.org/pool/updates/main/a/apache/libapache-mod-perl_1.29.0.3-6sarge2_alpha.deb
      Size/MD5 checksum: 505050 36759af8debeceeebdd083a337e590cb

AMD64 architecture:

    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33-6sarge2_amd64.deb
      Size/MD5 checksum: 401466 6d45b8e9a23382f6b2eadc28af28e4a4
    http://security.debian.org/pool/updates/main/a/apache/apache-common_1.3.33-6sarge2_amd64.deb
      Size/MD5 checksum: 876652 7474a08ccd74235787761b8e1ffe8c0e
    http://security.debian.org/pool/updates/main/a/apache/apache-dbg_1.3.33-6sarge2_amd64.deb
      Size/MD5 checksum: 9162572 b55d8df232edbd900372fe339a065fd1
    http://security.debian.org/pool/updates/main/a/apache/apache-perl_1.3.33-6sarge2_amd64.deb
      Size/MD5 checksum: 524410 41142b30d22c99476977c339cf071504
    http://security.debian.org/pool/updates/main/a/apache/apache-ssl_1.3.33-6sarge2_amd64.deb
      Size/MD5 checksum: 513708 5377d3aa2ad92e07db2654d3fd3761d1
    http://security.debian.org/pool/updates/main/a/apache/libapache-mod-perl_1.29.0.3-6sarge2_amd64.deb
      Size/MD5 checksum: 492544 2d15619f2db2d39d6abdaf25574fbf4c

ARM architecture:

    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33-6sarge2_arm.deb
      Size/MD5 checksum: 384260 7785f5fa4d814bd1a1ec946fe007ec53
    http://security.debian.org/pool/updates/main/a/apache/apache-common_1.3.33-6sarge2_arm.deb
      Size/MD5 checksum: 841372 83ed59ba296d64b5b6731c3a57902810
    http://security.debian.org/pool/updates/main/a/apache/apache-dbg_1.3.33-6sarge2_arm.deb
      Size/MD5 checksum: 8985914 50fc722807a399105950b15e5eaba3b3
    http://security.debian.org/pool/updates/main/a/apache/apache-perl_1.3.33-6sarge2_arm.deb
      Size/MD5 checksum: 495910 f7d7a9218c3bdabbf0982b3ec563bca6
    http://security.debian.org/pool/updates/main/a/apache/apache-ssl_1.3.33-6sarge2_arm.deb
      Size/MD5 checksum: 489556 7645d9195f00f4bf0c655eefaf971dff
    http://security.debian.org/pool/updates/main/a/apache/libapache-mod-perl_1.29.0.3-6sarge2_arm.deb
      Size/MD5 checksum: 479280 e689e83904766cf209049c39fe3ee2d1

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33-6sarge2_i386.deb
      Size/MD5 checksum: 386664 0f0192626abd5a456bf7b6d43f9f1708
    http://security.debian.org/pool/updates/main/a/apache/apache-common_1.3.33-6sarge2_i386.deb
      Size/MD5 checksum: 860158 60891f21e526885833f7f7fcf43c92e4
    http://security.debian.org/pool/updates/main/a/apache/apache-dbg_1.3.33-6sarge2_i386.deb
      Size/MD5 checksum: 9124844 9d2e020813d5298c3f4d62dcd8ec6aaa
    http://security.debian.org/pool/updates/main/a/apache/apache-perl_1.3.33-6sarge2_i386.deb
      Size/MD5 checksum: 504860 a084ffd32a38948db9dd0692ead50eeb
    http://security.debian.org/pool/updates/main/a/apache/apache-ssl_1.3.33-6sarge2_i386.deb
      Size/MD5 checksum: 493690 c442e0c156f98044c20a665d989aeca0
    http://security.debian.org/pool/updates/main/a/apache/libapache-mod-perl_1.29.0.3-6sarge2_i386.deb
      Size/MD5 checksum: 486804 3862e6781f044fc2c4ae24170f47fe6f

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33-6sarge2_ia64.deb
      Size/MD5 checksum: 463372 13eb11e0de167d54b6606605ae1ff0f6
    http://security.debian.org/pool/updates/main/a/apache/apache-common_1.3.33-6sarge2_ia64.deb
      Size/MD5 checksum: 971834 2be725f2e6b84c10c512a0d804480e33
    http://security.debian.org/pool/updates/main/a/apache/apache-dbg_1.3.33-6sarge2_ia64.deb
      Size/MD5 checksum: 9355772 3b5d28d3d2531719d46c23920dd3e94c
    http://security.debian.org/pool/updates/main/a/apache/apache-perl_1.3.33-6sarge2_ia64.deb
      Size/MD5 checksum: 627356 247a7da511dae2d5e698f2b424fe24c5
    http://security.debian.org/pool/updates/main/a/apache/apache-ssl_1.3.33-6sarge2_ia64.deb
      Size/MD5 checksum: 585922 aa5d4b2f9bcefe026da9168170e0c819
    http://security.debian.org/pool/updates/main/a/apache/libapache-mod-perl_1.29.0.3-6sarge2_ia64.deb
      Size/MD5 checksum: 532826 9b9c3b43b6e85e92dd2c064871f7d9f3

HP Precision architecture:

    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33-6sarge2_hppa.deb
      Size/MD5 checksum: 406614 50c84b8682cd3b8af4e0eceaf7fd505a
    http://security.debian.org/pool/updates/main/a/apache/apache-common_1.3.33-6sarge2_hppa.deb
      Size/MD5 checksum: 905560 b02464bd2a9c5ca732e0c4f9208baee0
    http://security.debian.org/pool/updates/main/a/apache/apache-dbg_1.3.33-6sarge2_hppa.deb
      Size/MD5 checksum: 9100908 4516c9ad78527b3cb2be9daef76e9566
    http://security.debian.org/pool/updates/main/a/apache/apache-perl_1.3.33-6sarge2_hppa.deb
      Size/MD5 checksum: 536024 e8ab5a278d1424ef9d68c155ae3a7ab8
    http://security.debian.org/pool/updates/main/a/apache/apache-ssl_1.3.33-6sarge2_hppa.deb
      Size/MD5 checksum: 518824 c6befb0053d4ed7daa9e9f3d1538bbb6
    http://security.debian.org/pool/updates/main/a/apache/libapache-mod-perl_1.29.0.3-6sarge2_hppa.deb
      Size/MD5 checksum: 508750 6beec32a45b93df126f4973619c6076a

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33-6sarge2_m68k.deb
      Size/MD5 checksum: 371072 d4f978e09502b619b7933e23290eaf5e
    http://security.debian.org/pool/updates/main/a/apache/apache-common_1.3.33-6sarge2_m68k.deb
      Size/MD5 checksum: 847234 8ca3d2d72183081217ae742327dd49f7
    http://security.debian.org/pool/updates/main/a/apache/apache-dbg_1.3.33-6sarge2_m68k.deb
      Size/MD5 checksum: 8973668 e6614fd4445efa2a29002d5f02d0b7c5
    http://security.debian.org/pool/updates/main/a/apache/apache-perl_1.3.33-6sarge2_m68k.deb
      Size/MD5 checksum: 448692 e2024a331a75dabd3ff86927a1883cbc
    http://security.debian.org/pool/updates/main/a/apache/apache-ssl_1.3.33-6sarge2_m68k.deb
      Size/MD5 checksum: 477360 43f62ac274ccd93160d1db6d3110ebe6
    http://security.debian.org/pool/updates/main/a/apache/libapache-mod-perl_1.29.0.3-6sarge2_m68k.deb
      Size/MD5 checksum: 489432 df5d49e0e858809966e4395cdfcab073

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33-6sarge2_mips.deb
      Size/MD5 checksum: 403276 4ff63b289978627f3db22de263e158ef
    http://security.debian.org/pool/updates/main/a/apache/apache-common_1.3.33-6sarge2_mips.deb
      Size/MD5 checksum: 851592 3e0d11bf481c1378ff776062dc2eed70
    http://security.debian.org/pool/updates/main/a/apache/apache-dbg_1.3.33-6sarge2_mips.deb
      Size/MD5 checksum: 9048564 aa4a667fdc83d41e739b69c949967929
    http://security.debian.org/pool/updates/main/a/apache/apache-perl_1.3.33-6sarge2_mips.deb
      Size/MD5 checksum: 485152 0672cc250050d8e0e571ced7cb4420a0
    http://security.debian.org/pool/updates/main/a/apache/apache-ssl_1.3.33-6sarge2_mips.deb
      Size/MD5 checksum: 509872 09572aa1dd63bd7b1bff9b61d5752358
    http://security.debian.org/pool/updates/main/a/apache/libapache-mod-perl_1.29.0.3-6sarge2_mips.deb
      Size/MD5 checksum: 443532 6efd073b42b13599960f29ff9263892a

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33-6sarge2_mipsel.deb
      Size/MD5 checksum: 403652 6906feb21ddb7af2a5ec9d4c2ccd874c
    http://security.debian.org/pool/updates/main/a/apache/apache-common_1.3.33-6sarge2_mipsel.deb
      Size/MD5 checksum: 849942 5786e24b7849df4eea36f3d3da80a82a
    http://security.debian.org/pool/updates/main/a/apache/apache-dbg_1.3.33-6sarge2_mipsel.deb
      Size/MD5 checksum: 9054052 f0d853c8399534429fcd2a3463016ef1
    http://security.debian.org/pool/updates/main/a/apache/apache-perl_1.3.33-6sarge2_mipsel.deb
      Size/MD5 checksum: 485376 9001e3d37ac660635946eb066e50ec78
    http://security.debian.org/pool/updates/main/a/apache/apache-ssl_1.3.33-6sarge2_mipsel.deb
      Size/MD5 checksum: 510664 398e615c936d6e72bb443ce3550e57e2
    http://security.debian.org/pool/updates/main/a/apache/libapache-mod-perl_1.29.0.3-6sarge2_mipsel.deb
      Size/MD5 checksum: 443422 e3a6f0ca68df1d8e8f26eef8f23b2822

PowerPC architecture:

    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33-6sarge2_powerpc.deb
      Size/MD5 checksum: 398666 29de2415f45cd033d04c28be500664ee
    http://security.debian.org/pool/updates/main/a/apache/apache-common_1.3.33-6sarge2_powerpc.deb
      Size/MD5 checksum: 921400 c36acb601638cb0a9961a2f5d95fcb28
    http://security.debian.org/pool/updates/main/a/apache/apache-dbg_1.3.33-6sarge2_powerpc.deb
      Size/MD5 checksum: 9252458 aa5f5cdc62365a6951cb6a67e005dc34
    http://security.debian.org/pool/updates/main/a/apache/apache-perl_1.3.33-6sarge2_powerpc.deb
      Size/MD5 checksum: 515350 0d654fea1e92be4c2bb1375b6a51c060
    http://security.debian.org/pool/updates/main/a/apache/apache-ssl_1.3.33-6sarge2_powerpc.deb
      Size/MD5 checksum: 510372 15269ec946e59741172a69c8e7ea7557
    http://security.debian.org/pool/updates/main/a/apache/libapache-mod-perl_1.29.0.3-6sarge2_powerpc.deb
      Size/MD5 checksum: 490708 2b1e1ae12a9cb2e8f59b6b8b219d7f9e

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33-6sarge2_s390.deb
      Size/MD5 checksum: 403204 73201862887af010def1edf24d22594d
    http://security.debian.org/pool/updates/main/a/apache/apache-common_1.3.33-6sarge2_s390.deb
      Size/MD5 checksum: 868450 b84df926a3235d152d8f7f35aa3394ae
    http://security.debian.org/pool/updates/main/a/apache/apache-dbg_1.3.33-6sarge2_s390.deb
      Size/MD5 checksum: 9183050 1cf5c335b2cf863898c0c84e4e150776
    http://security.debian.org/pool/updates/main/a/apache/apache-perl_1.3.33-6sarge2_s390.deb
      Size/MD5 checksum: 490090 b361f3cf52b919b5e92d96f92a77270a
    http://security.debian.org/pool/updates/main/a/apache/apache-ssl_1.3.33-6sarge2_s390.deb
      Size/MD5 checksum: 514442 d3374e5f0d5cb468409795a1a7c9b8b3
    http://security.debian.org/pool/updates/main/a/apache/libapache-mod-perl_1.29.0.3-6sarge2_s390.deb
      Size/MD5 checksum: 460466 bf56d745cf3b78e3ade0204a718417c6

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/a/apache/apache_1.3.33-6sarge2_sparc.deb
      Size/MD5 checksum: 385534 020faf78c7c61702c94d10eb03a07e37
    http://security.debian.org/pool/updates/main/a/apache/apache-common_1.3.33-6sarge2_sparc.deb
      Size/MD5 checksum: 849304 2cffd052a21ba9306ebadf4af2f6b734
    http://security.debian.org/pool/updates/main/a/apache/apache-dbg_1.3.33-6sarge2_sparc.deb
      Size/MD5 checksum: 9046234 f32d81e7736df5b65bf9912506b03466
    http://security.debian.org/pool/updates/main/a/apache/apache-perl_1.3.33-6sarge2_sparc.deb
      Size/MD5 checksum: 504168 e3a5510199db8f05f5a6f3028b82ef11
    http://security.debian.org/pool/updates/main/a/apache/apache-ssl_1.3.33-6sarge2_sparc.deb
      Size/MD5 checksum: 491970 4f9732af9bcf8e6ecc54cb24f65b7d0b
    http://security.debian.org/pool/updates/main/a/apache/libapache-mod-perl_1.29.0.3-6sarge2_sparc.deb
      Size/MD5 checksum: 490256 9c6e61c66d2f8641680f6f7dfe7316fe

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 1132-1 security@debian.org
http://www.debian.org/security/ Steve Kemp
Aug 1st, 2005 http://www.debian.org/security/faq


Package : apache2
Vulnerability : buffer overflow
Problem-Type : remote
Debian-specific: no
CVE ID : CVE-2006-3747
CERT advisory : VU#395412
Debian Bug : 380182

Mark Dowd discovered a buffer overflow in the mod_rewrite component of apache, a versatile high-performance HTTP server. In some situations a remote attacker could exploit this to execute arbitary code.

For the stable distribution (sarge) this problem has been fixed in version 2.0.54-5sarge1.

For the unstable distribution (sid) this problem will be fixed shortly.

We recommend that you upgrade your apache2 package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54-5sarge1.dsc
      Size/MD5 checksum: 1153 4b2aeab1c5578a6879c1d036487c75a2
    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54-5sarge1.diff.gz
      Size/MD5 checksum: 110080 57c824fbbbae3fa68d504797fa8e6341
    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54.orig.tar.gz
      Size/MD5 checksum: 7493636 37d0d0a3e25ad93d37f0483021e70409

Architecture independent components:

    http://security.debian.org/pool/updates/main/a/apache2/apache2-doc_2.0.54-5sarge1_all.deb
      Size/MD5 checksum: 3891046 f860e8207364bbbf05cfd81fa281508e
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-threadpool_2.0.54-5sarge1_all.deb
      Size/MD5 checksum: 33564 7d974c7e0f38c6e31017e712f15214fd

Alpha architecture:

    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54-5sarge1_alpha.deb
      Size/MD5 checksum: 33488 f36f397f92e8946d342d8b939a8e1f41
    http://security.debian.org/pool/updates/main/a/apache2/apache2-common_2.0.54-5sarge1_alpha.deb
      Size/MD5 checksum: 865320 82e919111eccc60ed021aa196cc3cb00
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-perchild_2.0.54-5sarge1_alpha.deb
      Size/MD5 checksum: 246374 e6d9e455161bad25b178992b109c9375
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.0.54-5sarge1_alpha.deb
      Size/MD5 checksum: 241488 80524503bc76924132c26df38c61e5ad
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.0.54-5sarge1_alpha.deb
      Size/MD5 checksum: 245676 91eab40f8da34595f1a96c1b3c2254a3
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.0.54-5sarge1_alpha.deb
      Size/MD5 checksum: 167694 81b924d7aca297e86e600a3439d31d4a
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.0.54-5sarge1_alpha.deb
      Size/MD5 checksum: 168422 fa3bf3865b48d5a8324a6e6135ffaab1
    http://security.debian.org/pool/updates/main/a/apache2/apache2-utils_2.0.54-5sarge1_alpha.deb
      Size/MD5 checksum: 97552 67c989219009488916ba16f399fa33fb
    http://security.debian.org/pool/updates/main/a/apache2/libapr0_2.0.54-5sarge1_alpha.deb
      Size/MD5 checksum: 155792 ff3355874d8b7fa7c6ad1c55f8eabb8c
    http://security.debian.org/pool/updates/main/a/apache2/libapr0-dev_2.0.54-5sarge1_alpha.deb
      Size/MD5 checksum: 315260 ed3c2bc91b3be333c535aae01959f5f0

AMD64 architecture:

    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54-5sarge1_amd64.deb
      Size/MD5 checksum: 33482 431da06ae2973e4ab7e6195652b4f8b6
    http://security.debian.org/pool/updates/main/a/apache2/apache2-common_2.0.54-5sarge1_amd64.deb
      Size/MD5 checksum: 826686 3e2d13f95a82053ec6afa782ae62ffec
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-perchild_2.0.54-5sarge1_amd64.deb
      Size/MD5 checksum: 221350 7f3384834425befc9437ff16795fe827
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.0.54-5sarge1_amd64.deb
      Size/MD5 checksum: 216820 76034c08d148bf01b7eb72f5156fe2bc
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.0.54-5sarge1_amd64.deb
      Size/MD5 checksum: 220588 382bd5f3a47262c68c72566ae45aa005
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.0.54-5sarge1_amd64.deb
      Size/MD5 checksum: 167698 fb700ccba617ede30505a1a75f1528c1
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.0.54-5sarge1_amd64.deb
      Size/MD5 checksum: 168438 d0dd58b34bf5bb543f2bf9971bc30f17
    http://security.debian.org/pool/updates/main/a/apache2/apache2-utils_2.0.54-5sarge1_amd64.deb
      Size/MD5 checksum: 92732 db6b4a3d3d2fa90a193c5d799b27161c
    http://security.debian.org/pool/updates/main/a/apache2/libapr0_2.0.54-5sarge1_amd64.deb
      Size/MD5 checksum: 137334 5318191c95c001866e475a9f8218a0d0
    http://security.debian.org/pool/updates/main/a/apache2/libapr0-dev_2.0.54-5sarge1_amd64.deb
      Size/MD5 checksum: 278836 fd2955649002a6d3c4b6de7c9f18c794

ARM architecture:

    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54-5sarge1_arm.deb
      Size/MD5 checksum: 33490 1584e54d81dbfc1d45f6208ad268903d
    http://security.debian.org/pool/updates/main/a/apache2/apache2-common_2.0.54-5sarge1_arm.deb
      Size/MD5 checksum: 793694 233ea0fad9d5531cdc20182474c583fc
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-perchild_2.0.54-5sarge1_arm.deb
      Size/MD5 checksum: 202316 8916fa2da9d7740f4b1ac22f498bd47d
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.0.54-5sarge1_arm.deb
      Size/MD5 checksum: 197954 bbaefcea762f1600f0ba330d79d63b5e
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.0.54-5sarge1_arm.deb
      Size/MD5 checksum: 201344 c494ebb8a6662ebb777f9f615ea50579
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.0.54-5sarge1_arm.deb
      Size/MD5 checksum: 167706 ac66b709dbf32ea62406dd9131727f4b
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.0.54-5sarge1_arm.deb
      Size/MD5 checksum: 168440 bbb3c010fb98d9bc96da846cb57c1c80
    http://security.debian.org/pool/updates/main/a/apache2/apache2-utils_2.0.54-5sarge1_arm.deb
      Size/MD5 checksum: 92652 92ac8c180bd95c8fcb4fbcc173fd93f9
    http://security.debian.org/pool/updates/main/a/apache2/libapr0_2.0.54-5sarge1_arm.deb
      Size/MD5 checksum: 122384 4802054d8d5b2f25d5b4ed32f2bbcad2
    http://security.debian.org/pool/updates/main/a/apache2/libapr0-dev_2.0.54-5sarge1_arm.deb
      Size/MD5 checksum: 267920 02f1b191a308bdb9c4c9955a9a5170ea

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54-5sarge1_i386.deb
      Size/MD5 checksum: 33486 7234f5717dbcbb800e90949d63cc1ddc
    http://security.debian.org/pool/updates/main/a/apache2/apache2-common_2.0.54-5sarge1_i386.deb
      Size/MD5 checksum: 812294 87b7c53659af00252c76484d030b76dd
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-perchild_2.0.54-5sarge1_i386.deb
      Size/MD5 checksum: 206644 f27a272c1e7c8a64fe3099e81879afe5
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.0.54-5sarge1_i386.deb
      Size/MD5 checksum: 202834 e9c259b62700c20aa0a123aac7ef8468
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.0.54-5sarge1_i386.deb
      Size/MD5 checksum: 206402 0b12002711a684dee34a6f158c08b008
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.0.54-5sarge1_i386.deb
      Size/MD5 checksum: 168868 9905d2bd31aaf49cb4c522a7130fc53e
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.0.54-5sarge1_i386.deb
      Size/MD5 checksum: 169670 6bdf51222903fb1af0a1950e8f02e7e6
    http://security.debian.org/pool/updates/main/a/apache2/apache2-utils_2.0.54-5sarge1_i386.deb
      Size/MD5 checksum: 90916 15031d3164bf986a7d321d67f6f872f7
    http://security.debian.org/pool/updates/main/a/apache2/libapr0_2.0.54-5sarge1_i386.deb
      Size/MD5 checksum: 130372 f3aa36ce42aca7c552630338b70c4147
    http://security.debian.org/pool/updates/main/a/apache2/libapr0-dev_2.0.54-5sarge1_i386.deb
      Size/MD5 checksum: 260374 ffbe645e8c6762205148f7aa8656a3c7

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54-5sarge1_ia64.deb
      Size/MD5 checksum: 33486 0cd1947abffb3793f6c0dc7690632573
    http://security.debian.org/pool/updates/main/a/apache2/apache2-common_2.0.54-5sarge1_ia64.deb
      Size/MD5 checksum: 973648 7522385d947774e00a2b0f9c8586cc11
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-perchild_2.0.54-5sarge1_ia64.deb
      Size/MD5 checksum: 289276 bace1a0298d9336892bedbdc708f35ec
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.0.54-5sarge1_ia64.deb
      Size/MD5 checksum: 281296 6495947c25e20f5459d44980378420f7
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.0.54-5sarge1_ia64.deb
      Size/MD5 checksum: 287876 d63b895f7d31859642932ef11521120b
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.0.54-5sarge1_ia64.deb
      Size/MD5 checksum: 167676 ae253a0de588b5f3c75cd0139c23b94e
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.0.54-5sarge1_ia64.deb
      Size/MD5 checksum: 168418 b9a670874ff49ad8016ce34f65db75ca
    http://security.debian.org/pool/updates/main/a/apache2/apache2-utils_2.0.54-5sarge1_ia64.deb
      Size/MD5 checksum: 106404 02c8d485338f0f86e61769bedfd1195e
    http://security.debian.org/pool/updates/main/a/apache2/libapr0_2.0.54-5sarge1_ia64.deb
      Size/MD5 checksum: 177836 5f1d653818331006ad992b9f29fec1c3
    http://security.debian.org/pool/updates/main/a/apache2/libapr0-dev_2.0.54-5sarge1_ia64.deb
      Size/MD5 checksum: 328478 565500d14485fdfc229d31094477d79d

HP Precision architecture:

    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54-5sarge1_hppa.deb
      Size/MD5 checksum: 33488 c097912333905a2634218aca2f925af4
    http://security.debian.org/pool/updates/main/a/apache2/apache2-common_2.0.54-5sarge1_hppa.deb
      Size/MD5 checksum: 880192 bbf9181e42bf15946ea823bd4c60187a
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-perchild_2.0.54-5sarge1_hppa.deb
      Size/MD5 checksum: 228778 3f678491b1a4cdf7087ba3f7b579d2e4
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.0.54-5sarge1_hppa.deb
      Size/MD5 checksum: 222784 53c3247eb337389bf5610ffdc12101aa
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.0.54-5sarge1_hppa.deb
      Size/MD5 checksum: 227604 a55def8a3be473430a5add57f74a9e3e
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.0.54-5sarge1_hppa.deb
      Size/MD5 checksum: 167694 d986e8cc3ad0512e9e37d9d22209df6a
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.0.54-5sarge1_hppa.deb
      Size/MD5 checksum: 168436 77ed5eaaad9378052171f6317ba7f3b0
    http://security.debian.org/pool/updates/main/a/apache2/apache2-utils_2.0.54-5sarge1_hppa.deb
      Size/MD5 checksum: 98822 048922c9ca8664f57b80c2f45f401d7f
    http://security.debian.org/pool/updates/main/a/apache2/libapr0_2.0.54-5sarge1_hppa.deb
      Size/MD5 checksum: 144996 20192edf00b0449ef13a9c104750c1fb
    http://security.debian.org/pool/updates/main/a/apache2/libapr0-dev_2.0.54-5sarge1_hppa.deb
      Size/MD5 checksum: 285012 86cf97e94f01f18e3c2263d94eb3f4f2

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54-5sarge1_m68k.deb
      Size/MD5 checksum: 33496 7ed8701d7c988c636a45eb66ea558b11
    http://security.debian.org/pool/updates/main/a/apache2/apache2-common_2.0.54-5sarge1_m68k.deb
      Size/MD5 checksum: 783354 bbd0d75542a89db2b9af3fda0801251b
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-perchild_2.0.54-5sarge1_m68k.deb
      Size/MD5 checksum: 188908 1798d4afe93c070b947be8d80097a3a5
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.0.54-5sarge1_m68k.deb
      Size/MD5 checksum: 185514 1c0bf8a9a6f173753080c77af11fde0b
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.0.54-5sarge1_m68k.deb
      Size/MD5 checksum: 188314 c188c7e4ab5c0bd9af90e3cce04cb119
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.0.54-5sarge1_m68k.deb
      Size/MD5 checksum: 167770 7c804084f4c5104ea0e1759664bfc950
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.0.54-5sarge1_m68k.deb
      Size/MD5 checksum: 168494 46bb18ed1ad60faee0356fcf927a8d7e
    http://security.debian.org/pool/updates/main/a/apache2/apache2-utils_2.0.54-5sarge1_m68k.deb
      Size/MD5 checksum: 88058 4dd93405f96d8a1504403b5e807ed11d
    http://security.debian.org/pool/updates/main/a/apache2/libapr0_2.0.54-5sarge1_m68k.deb
      Size/MD5 checksum: 117584 c02517bf4a19a576ceb5eb53788b8ddb
    http://security.debian.org/pool/updates/main/a/apache2/libapr0-dev_2.0.54-5sarge1_m68k.deb
      Size/MD5 checksum: 250068 f9858a08d86d3c5da03ce9ab5742c807

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54-5sarge1_mips.deb
      Size/MD5 checksum: 33492 99198a05154084edcf0a023b4178c174
    http://security.debian.org/pool/updates/main/a/apache2/apache2-common_2.0.54-5sarge1_mips.deb
      Size/MD5 checksum: 807540 b5be0b94c36ef91ad37f8e97ee38da6b
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-perchild_2.0.54-5sarge1_mips.deb
      Size/MD5 checksum: 217966 40962c3bb0de39504e18a3e4d17960d4
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.0.54-5sarge1_mips.deb
      Size/MD5 checksum: 213184 17b42ce494efe8d695083b65c18bd04f
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.0.54-5sarge1_mips.deb
      Size/MD5 checksum: 217340 af8e8d55645e3f8515838cc6a4d0b96a
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.0.54-5sarge1_mips.deb
      Size/MD5 checksum: 167712 62bcc19fbe039422058de75fac9ef8a2
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.0.54-5sarge1_mips.deb
      Size/MD5 checksum: 168456 97347f55c5ca750159492a5e9fef0f05
    http://security.debian.org/pool/updates/main/a/apache2/apache2-utils_2.0.54-5sarge1_mips.deb
      Size/MD5 checksum: 103016 7dfdbeb967d4db76535e326fe3bbe831
    http://security.debian.org/pool/updates/main/a/apache2/libapr0_2.0.54-5sarge1_mips.deb
      Size/MD5 checksum: 134456 fefc232dee0333abe758f480922e485a
    http://security.debian.org/pool/updates/main/a/apache2/libapr0-dev_2.0.54-5sarge1_mips.deb
      Size/MD5 checksum: 286508 e450f3a5c862321728f126fd27e67da8

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54-5sarge1_mipsel.deb
      Size/MD5 checksum: 33492 a0beae9521a8681328ed01833936c7e6
    http://security.debian.org/pool/updates/main/a/apache2/apache2-common_2.0.54-5sarge1_mipsel.deb
      Size/MD5 checksum: 807356 efa828902d16f408dc2fb75344a02484
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-perchild_2.0.54-5sarge1_mipsel.deb
      Size/MD5 checksum: 217238 f61a494fe69366f8f0f319ec622c125d
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.0.54-5sarge1_mipsel.deb
      Size/MD5 checksum: 212602 1e168ac088ef73b5a9ae213eaed0e65b
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.0.54-5sarge1_mipsel.deb
      Size/MD5 checksum: 216474 4da5c94813eb4c75e4c39e464b459286
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.0.54-5sarge1_mipsel.deb
      Size/MD5 checksum: 167712 91d4f8ca1a018c1d772d2436a40c264a
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.0.54-5sarge1_mipsel.deb
      Size/MD5 checksum: 168454 810be6456b1b49e29c2ad063677df5d7
    http://security.debian.org/pool/updates/main/a/apache2/apache2-utils_2.0.54-5sarge1_mipsel.deb
      Size/MD5 checksum: 102908 4053b03ba06284397e0a2e049ac0b07e
    http://security.debian.org/pool/updates/main/a/apache2/libapr0_2.0.54-5sarge1_mipsel.deb
      Size/MD5 checksum: 134504 4cf1d17baaceacbd49aff1a5f0386eb9
    http://security.debian.org/pool/updates/main/a/apache2/libapr0-dev_2.0.54-5sarge1_mipsel.deb
      Size/MD5 checksum: 287146 327a38414b6477d2bfc899b6c36814a4

PowerPC architecture:

    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54-5sarge1_powerpc.deb
      Size/MD5 checksum: 33488 a02c59618834f05f05875bfb44db86a8
    http://security.debian.org/pool/updates/main/a/apache2/apache2-common_2.0.54-5sarge1_powerpc.deb
      Size/MD5 checksum: 856080 7f25f6e8e6e6861106e349f49de39f3f
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-perchild_2.0.54-5sarge1_powerpc.deb
      Size/MD5 checksum: 214658 4542ef6b2b9b2cad21c9b43cc090cc20
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.0.54-5sarge1_powerpc.deb
      Size/MD5 checksum: 209732 a77570da8616c950a61c3e1f1774d263
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.0.54-5sarge1_powerpc.deb
      Size/MD5 checksum: 213720 0187a654fc3972354c4b1ce9f25b298e
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.0.54-5sarge1_powerpc.deb
      Size/MD5 checksum: 167700 23b513fe1438e05bfb285c6b2ba5fa88
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.0.54-5sarge1_powerpc.deb
      Size/MD5 checksum: 168438 2fdbfc52471761f05ac81c88104df718
    http://security.debian.org/pool/updates/main/a/apache2/apache2-utils_2.0.54-5sarge1_powerpc.deb
      Size/MD5 checksum: 102074 e3e2f1cce29967a7f16d482c5a12f31e
    http://security.debian.org/pool/updates/main/a/apache2/libapr0_2.0.54-5sarge1_powerpc.deb
      Size/MD5 checksum: 134326 a065ca58466cb424e6fdecf4916a34ab
    http://security.debian.org/pool/updates/main/a/apache2/libapr0-dev_2.0.54-5sarge1_powerpc.deb
      Size/MD5 checksum: 272016 1036f4767ca54dcf7f9ea8a0ccd7219b

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54-5sarge1_s390.deb
      Size/MD5 checksum: 33484 be5320d7ff7f2535f2c2afcc1c1a0017
    http://security.debian.org/pool/updates/main/a/apache2/apache2-common_2.0.54-5sarge1_s390.deb
      Size/MD5 checksum: 836920 0217fc29e0cd0c73ffc16321ac76ee67
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-perchild_2.0.54-5sarge1_s390.deb
      Size/MD5 checksum: 223934 b8fe548deef75a8474c513ffeaef612b
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.0.54-5sarge1_s390.deb
      Size/MD5 checksum: 219814 03b24d5271b0d0392de3cae6a8b2cddc
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.0.54-5sarge1_s390.deb
      Size/MD5 checksum: 223316 b19825c6436769e45e9ff4b304893e0a
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.0.54-5sarge1_s390.deb
      Size/MD5 checksum: 167674 b927beaf64fcf061278749e9112f606b
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.0.54-5sarge1_s390.deb
      Size/MD5 checksum: 168406 2a691c0d5a113e67dbe4428f33850b55
    http://security.debian.org/pool/updates/main/a/apache2/apache2-utils_2.0.54-5sarge1_s390.deb
      Size/MD5 checksum: 95882 f4f2d57ef253b639334593daee4ea458
    http://security.debian.org/pool/updates/main/a/apache2/libapr0_2.0.54-5sarge1_s390.deb
      Size/MD5 checksum: 145992 524ec24014483b5380e1f498fc96eb71
    http://security.debian.org/pool/updates/main/a/apache2/libapr0-dev_2.0.54-5sarge1_s390.deb
      Size/MD5 checksum: 275226 812a50d7371049f438c8469dd72aaab7

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.0.54-5sarge1_sparc.deb
      Size/MD5 checksum: 33492 e1759ef13bc51722b31ac10f9469ab11
    http://security.debian.org/pool/updates/main/a/apache2/apache2-common_2.0.54-5sarge1_sparc.deb
      Size/MD5 checksum: 802626 7936568d0f0220d40a0c24c020188e92
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-perchild_2.0.54-5sarge1_sparc.deb
      Size/MD5 checksum: 205614 75b026656494f526a4c53c7202ef4a85
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.0.54-5sarge1_sparc.deb
      Size/MD5 checksum: 200878 a9195c31cdba9cd787cad14eba216719
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.0.54-5sarge1_sparc.deb
      Size/MD5 checksum: 204536 f0f6b6b0b5e4222e35deb55b955c1241
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.0.54-5sarge1_sparc.deb
      Size/MD5 checksum: 167688 1f9b82c2aa5ef014de1a00279fba8acc
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.0.54-5sarge1_sparc.deb
      Size/MD5 checksum: 168428 1055661a5018ca3698a508dac343a5ef
    http://security.debian.org/pool/updates/main/a/apache2/apache2-utils_2.0.54-5sarge1_sparc.deb
      Size/MD5 checksum: 91002 a2c433609f36de5d6d0e8ae5ad367fb2
    http://security.debian.org/pool/updates/main/a/apache2/libapr0_2.0.54-5sarge1_sparc.deb
      Size/MD5 checksum: 123598 5739e26b7619a2a36a0541288b45e91a
    http://security.debian.org/pool/updates/main/a/apache2/libapr0-dev_2.0.54-5sarge1_sparc.deb
      Size/MD5 checksum: 260480 d21565096a339f3e4cbff58cf5deb352

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 1133-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
August 1st, 2006 http://www.debian.org/security/faq


Package : mantis
Vulnerability : missing input sanitising
Problem-Type : remote
Debian-specific: no
CVE ID : CVE-2006-0664 CVE-2006-0665 CVE-2006-0841 CVE-2006-1577
Debian Bug : 361138 378353

Several remote vulnerabilities have been discovered in the Mantis bug tracking system, which may lead to the execution of arbitrary web script. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2006-0664

A cross-site scripting vulnerability was discovered in config_defaults_inc.php.

CVE-2006-0665

Cross-site scripting vulnerabilities were discovered in query_store.php and manage_proj_create.php.

CVE-2006-0841

Multiple cross-site scripting vulnerabilities were discovered in view_all_set.php, manage_user_page.php, view_filters_page.php and proj_doc_delete.php.

CVE-2006-1577

Multiple cross-site scripting vulnerabilities were discovered in view_all_set.php.

For the stable distribution (sarge) these problems have been fixed in version 0.19.2-5sarge4.1.

For the unstable distribution (sid) these problems have been fixed in version 0.19.4-3.1.

We recommend that you upgrade your mantis package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/m/mantis/mantis_0.19.2-5sarge4.1.dsc
      Size/MD5 checksum: 586 186850cfa7493513907212591d8c550b
    http://security.debian.org/pool/updates/main/m/mantis/mantis_0.19.2-5sarge4.1.diff.gz
      Size/MD5 checksum: 42068 74a6598eff0b5f741df8c768c060edc4
    http://security.debian.org/pool/updates/main/m/mantis/mantis_0.19.2.orig.tar.gz
      Size/MD5 checksum: 1298615 042c42c6de3bc536181391c1e9b25db3

Architecture independent components:

    http://security.debian.org/pool/updates/main/m/mantis/mantis_0.19.2-5sarge4.1_all.deb
      Size/MD5 checksum: 897142 6a94215892b6efedd61e042973060022

These files will probably be moved into the stable distribution on its next update.


For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

Gentoo Linux


Gentoo Linux Security Advisory GLSA 200608-01

http://security.gentoo.org/


Severity: High
Title: Apache: Off-by-one flaw in mod_rewrite
Date: August 01, 2006
Bugs: #141986
ID: 200608-01


Synopsis

A flaw in mod_rewrite could result in a Denial of Service or the execution of arbitrary code.

Background

The Apache HTTP server is one of the most popular web servers on the Internet. The Apache module mod_rewrite provides a rule-based engine to rewrite requested URLs on the fly.

Affected packages


Package / Vulnerable / Unaffected

1 net-www/apache < 2.0.58-r2 *>= 1.3.34-r14 *>= 1.3.37 >= 2.0.58-r2

Description

An off-by-one flaw has been found in Apache's mod_rewrite module by Mark Dowd of McAfee Avert Labs. This flaw is exploitable depending on the types of rewrite rules being used.

Impact

A remote attacker could exploit the flaw to cause a Denial of Service or execution of arbitrary code. Note that Gentoo Linux is not vulnerable in the default configuration.

Workaround

There is no known workaround at this time.

Resolution

All Apache users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose net-www/apache

References

[ 1 ] CVE-2006-3747

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3747

[ 2 ] Apache HTTP Server 2.0 Announcement

http://www.apache.org/dist/httpd/Announcement2.0.html

[ 3 ] Apache HTTP Server 1.3 Announcement

http://www.apache.org/dist/httpd/Announcement1.3.html

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200608-01.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5

Mandriva Linux


Mandriva Linux Security Advisory MDKSA-2006:135
http://www.mandriva.com/security/


Package : freeciv
Date : July 31, 2006
Affected: 2006.0


Problem Description:

Buffer overflow in Freeciv 2.1.0-beta1 and earlier, and SVN 15 Jul 2006 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) negative chunk_length or a (2) large chunk->offset value in a PACKET_PLAYER_ATTRIBUTE_CHUNK packet in the generic_handle_player_attribute_chunk function in common/packets.c, and (3) a large packet->length value in the handle_unit_orders function in server/unithand.c.

The updated packages have been patched to fix this issue.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3913


Updated Packages:

Mandriva Linux 2006.0:
5ddab58ab94283b8c4398875a2a845de 2006.0/RPMS/freeciv-client-2.0.4-2.2.20060mdk.i586.rpm
218f597230b3435da9a41a6cc1f27826 2006.0/RPMS/freeciv-data-2.0.4-2.2.20060mdk.i586.rpm
ee661fb04809a50f893342ac350dfc3f 2006.0/RPMS/freeciv-server-2.0.4-2.2.20060mdk.i586.rpm
73be75ec52570bc9a58eed1f94916135 2006.0/SRPMS/freeciv-2.0.4-2.2.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
5c0a814a9abb1d374837141815fccb7a x86_64/2006.0/RPMS/freeciv-client-2.0.4-2.2.20060mdk.x86_64.rpm
454360b2ce12207760c7e4325c8e5c3f x86_64/2006.0/RPMS/freeciv-data-2.0.4-2.2.20060mdk.x86_64.rpm
dea806eb51d3c13f893a3adcd9866f85 x86_64/2006.0/RPMS/freeciv-server-2.0.4-2.2.20060mdk.x86_64.rpm
73be75ec52570bc9a58eed1f94916135 x86_64/2006.0/SRPMS/freeciv-2.0.4-2.2.20060mdk.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>

Mandriva Linux Security Advisory MDKSA-2006:136
http://www.mandriva.com/security/


Package : kdegraphics
Date : August 1, 2006
Affected: Corporate 3.0


Problem Description:

Tavis Ormandy, Google Security Team, discovered several vulnerabilites the libtiff image processing library. Older versions of kdegraphics use an embedded copy of the libtiff code, with possibly the same vulnerabilities:

Several buffer overflows have been discovered, including a stack buffer overflow via TIFFFetchShortPair() in tif_dirread.c, which is used to read two unsigned shorts from the input file. While a bounds check is performed via CheckDirCount(), no action is taken on the result allowing a pathological tdir_count to read an arbitrary number of unsigned shorts onto a stack buffer. (CVE-2006-3459)

A heap overflow vulnerability was discovered in the jpeg decoder, where TIFFScanLineSize() is documented to return the size in bytes that a subsequent call to TIFFReadScanline() would write, however the encoded jpeg stream may disagree with these results and overrun the buffer with more data than expected. (CVE-2006-3460)

The NeXT RLE decoder was also vulnerable to a heap overflow vulnerability, where no bounds checking was performed on the result of certain RLE decoding operations. This was solved by ensuring the number of pixels written did not exceed the size of the scanline buffer already prepared. (CVE-2006-3462)

An infinite loop was discovered in EstimateStripByteCounts(), where a 16bit unsigned short was used to iterate over a 32bit unsigned value, should the unsigned int (td_nstrips) have exceeded USHORT_MAX, the loop would never terminate and continue forever. (CVE-2006-3463)

Multiple unchecked arithmetic operations were uncovered, including a number of the range checking operations deisgned to ensure the offsets specified in tiff directories are legitimate. These can be caused to wrap for extreme values, bypassing sanity checks. Additionally, a number of codepaths were uncovered where assertions did not hold true, resulting in the client application calling abort(). (CVE-2006-3464)

The updated packages have been patched to correct these issues.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3459
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3460
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3462
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3463
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3464


Updated Packages:

Corporate 3.0:
ffe82a8c94848359195a701299aa19b1 corporate/3.0/RPMS/kdegraphics-3.2-15.12.C30mdk.i586.rpm
4e8f11ba3a0c99c69c128e106e87054b corporate/3.0/RPMS/kdegraphics-common-3.2-15.12.C30mdk.i586.rpm
50eb22c5dd901bc8fa21b555ba95b50b corporate/3.0/RPMS/kdegraphics-kdvi-3.2-15.12.C30mdk.i586.rpm
49e8afb51a0bf84832efe7ad612e2f68 corporate/3.0/RPMS/kdegraphics-kfax-3.2-15.12.C30mdk.i586.rpm
7887720f05d3a9a45b849aa372aaf727 corporate/3.0/RPMS/kdegraphics-kghostview-3.2-15.12.C30mdk.i586.rpm
0f2eba3232a585463cb5adaba611e8d9 corporate/3.0/RPMS/kdegraphics-kiconedit-3.2-15.12.C30mdk.i586.rpm
0e590ee1edf76c6a8cec5e87f0d6d3ad corporate/3.0/RPMS/kdegraphics-kooka-3.2-15.12.C30mdk.i586.rpm
c3b8af17de250652eb59fe9824500847 corporate/3.0/RPMS/kdegraphics-kpaint-3.2-15.12.C30mdk.i586.rpm
a42c4b132192b823c8e0d516c2c59ea5 corporate/3.0/RPMS/kdegraphics-kpdf-3.2-15.12.C30mdk.i586.rpm
78d76cf40472248ae81e296bfb0688f7 corporate/3.0/RPMS/kdegraphics-kpovmodeler-3.2-15.12.C30mdk.i586.rpm
8775439408ddd984d92721cec5c450c0 corporate/3.0/RPMS/kdegraphics-kruler-3.2-15.12.C30mdk.i586.rpm
324e0c5054f677229884cd940193e8cb corporate/3.0/RPMS/kdegraphics-ksnapshot-3.2-15.12.C30mdk.i586.rpm
7d4c56e5f329fa4aaff59a68340ab1c4 corporate/3.0/RPMS/kdegraphics-ksvg-3.2-15.12.C30mdk.i586.rpm
7fd0b572f5f14217d6351a2541e00eba corporate/3.0/RPMS/kdegraphics-kuickshow-3.2-15.12.C30mdk.i586.rpm
539a8dbb1b3541eb91766ec6723eb5f5 corporate/3.0/RPMS/kdegraphics-kview-3.2-15.12.C30mdk.i586.rpm
35697d28e45aa111345ac4dcdf74cfb9 corporate/3.0/RPMS/kdegraphics-mrmlsearch-3.2-15.12.C30mdk.i586.rpm
3ffbe6daaf39f4cf7d82361ce5c98775 corporate/3.0/RPMS/libkdegraphics0-common-3.2-15.12.C30mdk.i586.rpm
8e1a27553501fa692fe636e4b47e6e4a corporate/3.0/RPMS/libkdegraphics0-common-devel-3.2-15.12.C30mdk.i586.rpm
07c85d488505f6a1d2b76ca471f44df2 corporate/3.0/RPMS/libkdegraphics0-kooka-3.2-15.12.C30mdk.i586.rpm
cb66d0274660cd8ae83011c81549817a corporate/3.0/RPMS/libkdegraphics0-kooka-devel-3.2-15.12.C30mdk.i586.rpm
e7ebdfdb1f7de60a67c12d12fb707391 corporate/3.0/RPMS/libkdegraphics0-kpovmodeler-3.2-15.12.C30mdk.i586.rpm
4097d61133e196d5befdb27416d2852b corporate/3.0/RPMS/libkdegraphics0-kpovmodeler-devel-3.2-15.12.C30mdk.i586.rpm
2bebf0ea38c518bdf949ce5ccb5f6fee corporate/3.0/RPMS/libkdegraphics0-ksvg-3.2-15.12.C30mdk.i586.rpm
055a6c51d85eaf06a41a1ff58b05d60f corporate/3.0/RPMS/libkdegraphics0-ksvg-devel-3.2-15.12.C30mdk.i586.rpm
57d301f6fd18ab065b8ff0ef03d1ce1a corporate/3.0/RPMS/libkdegraphics0-kuickshow-3.2-15.12.C30mdk.i586.rpm
d951ff658d420ba1d02903af2741ee1e corporate/3.0/RPMS/libkdegraphics0-kview-3.2-15.12.C30mdk.i586.rpm
9affc4cf4a576b53ce6115597b934b07 corporate/3.0/RPMS/libkdegraphics0-kview-devel-3.2-15.12.C30mdk.i586.rpm
3f82bebd036a81c07910a92a41cf67f2 corporate/3.0/RPMS/libkdegraphics0-mrmlsearch-3.2-15.12.C30mdk.i586.rpm
7da97a6a01cc1ee884b57a63f532ae6e corporate/3.0/SRPMS/kdegraphics-3.2-15.12.C30mdk.src.rpm

Corporate 3.0/X86_64:
9aea4a7d7363002d86d3e5bf4a3f989c x86_64/corporate/3.0/RPMS/kdegraphics-3.2-15.12.C30mdk.x86_64.rpm
2ae89f69ce9a016fb8c4d0e3e36d43be x86_64/corporate/3.0/RPMS/kdegraphics-common-3.2-15.12.C30mdk.x86_64.rpm
d8195cf7e7848a81f3de13385f98d12a x86_64/corporate/3.0/RPMS/kdegraphics-kdvi-3.2-15.12.C30mdk.x86_64.rpm
316c9ce7fcc39e4fddd1bbabd1f14caf x86_64/corporate/3.0/RPMS/kdegraphics-kfax-3.2-15.12.C30mdk.x86_64.rpm
c9d4aff70f034a34bc45f3e4898ce1c3 x86_64/corporate/3.0/RPMS/kdegraphics-kghostview-3.2-15.12.C30mdk.x86_64.rpm
8851cd0f9265ba9a74eeee6f9f260d08 x86_64/corporate/3.0/RPMS/kdegraphics-kiconedit-3.2-15.12.C30mdk.x86_64.rpm
482a85cdee1f349f37d5260ef61c4e45 x86_64/corporate/3.0/RPMS/kdegraphics-kooka-3.2-15.12.C30mdk.x86_64.rpm
6d877b1991d4b033fe65b1959f5cc83f x86_64/corporate/3.0/RPMS/kdegraphics-kpaint-3.2-15.12.C30mdk.x86_64.rpm
5695710f2da2f7e4932cec14affcd227 x86_64/corporate/3.0/RPMS/kdegraphics-kpdf-3.2-15.12.C30mdk.x86_64.rpm
abbf166e5edf694b11507c488fdd7bd9 x86_64/corporate/3.0/RPMS/kdegraphics-kpovmodeler-3.2-15.12.C30mdk.x86_64.rpm
9792b16c83ff79618a53ef75ce17ab2d x86_64/corporate/3.0/RPMS/kdegraphics-kruler-3.2-15.12.C30mdk.x86_64.rpm
7304c418876d04f729771c013356b29f x86_64/corporate/3.0/RPMS/kdegraphics-ksnapshot-3.2-15.12.C30mdk.x86_64.rpm
d71200dbae7ee507efe8b524d1d0ea90 x86_64/corporate/3.0/RPMS/kdegraphics-ksvg-3.2-15.12.C30mdk.x86_64.rpm
9ccf9a90d87a2deda26d624bc956219f x86_64/corporate/3.0/RPMS/kdegraphics-kuickshow-3.2-15.12.C30mdk.x86_64.rpm
6089e2fd15c38a71e49ad7a396cbb987 x86_64/corporate/3.0/RPMS/kdegraphics-kview-3.2-15.12.C30mdk.x86_64.rpm
797f03c1792a9a8d1ef1f19a69d3a344 x86_64/corporate/3.0/RPMS/kdegraphics-mrmlsearch-3.2-15.12.C30mdk.x86_64.rpm
6bee61c89fcd6e95f49db89f36eb1541 x86_64/corporate/3.0/RPMS/lib64kdegraphics0-common-3.2-15.12.C30mdk.x86_64.rpm
06f97ba7f3ab4a14f4dc6ee60113741e x86_64/corporate/3.0/RPMS/lib64kdegraphics0-common-devel-3.2-15.12.C30mdk.x86_64.rpm
7e6c67ba4e81a922e5201d8dcb2ef742 x86_64/corporate/3.0/RPMS/lib64kdegraphics0-kooka-3.2-15.12.C30mdk.x86_64.rpm
566c9e310a35f17f25ebe5939deb515b x86_64/corporate/3.0/RPMS/lib64kdegraphics0-kooka-devel-3.2-15.12.C30mdk.x86_64.rpm
b8a16808b64873d4cdbdba01632c358f x86_64/corporate/3.0/RPMS/lib64kdegraphics0-kpovmodeler-3.2-15.12.C30mdk.x86_64.rpm
a2dc96c8eeadbfc11619ee72e165c3a4 x86_64/corporate/3.0/RPMS/lib64kdegraphics0-kpovmodeler-devel-3.2-15.12.C30mdk.x86_64.rpm
dc55dbb5d5ded3918bd20f762d2c9bdc x86_64/corporate/3.0/RPMS/lib64kdegraphics0-ksvg-3.2-15.12.C30mdk.x86_64.rpm
5f1a91bfc2c835989bc2471d459ae534 x86_64/corporate/3.0/RPMS/lib64kdegraphics0-ksvg-devel-3.2-15.12.C30mdk.x86_64.rpm
03e89291ec1a8722fa4a48df390ccaa5 x86_64/corporate/3.0/RPMS/lib64kdegraphics0-kuickshow-3.2-15.12.C30mdk.x86_64.rpm
11a242471daafa5cd19d71360676cae6 x86_64/corporate/3.0/RPMS/lib64kdegraphics0-kview-3.2-15.12.C30mdk.x86_64.rpm
7d1945bbd292094bebdd66ba0eab18f7 x86_64/corporate/3.0/RPMS/lib64kdegraphics0-kview-devel-3.2-15.12.C30mdk.x86_64.rpm
804b8efff16a11377bb24bd4efd03d01 x86_64/corporate/3.0/RPMS/lib64kdegraphics0-mrmlsearch-3.2-15.12.C30mdk.x86_64.rpm
7da97a6a01cc1ee884b57a63f532ae6e x86_64/corporate/3.0/SRPMS/kdegraphics-3.2-15.12.C30mdk.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>


Mandriva Linux Security Advisory MDKSA-2006:137
http://www.mandriva.com/security/


Package : libtiff
Date : August 1, 2006
Affected: 2006.0, Corporate 3.0, Multi Network Firewall 2.0


Problem Description:

Tavis Ormandy, Google Security Team, discovered several vulnerabilites the libtiff image processing library:

Several buffer overflows have been discovered, including a stack buffer overflow via TIFFFetchShortPair() in tif_dirread.c, which is used to read two unsigned shorts from the input file. While a bounds check is performed via CheckDirCount(), no action is taken on the result allowing a pathological tdir_count to read an arbitrary number of unsigned shorts onto a stack buffer. (CVE-2006-3459)

A heap overflow vulnerability was discovered in the jpeg decoder, where TIFFScanLineSize() is documented to return the size in bytes that a subsequent call to TIFFReadScanline() would write, however the encoded jpeg stream may disagree with these results and overrun the buffer with more data than expected. (CVE-2006-3460)

Another heap overflow exists in the PixarLog decoder where a run length encoded data stream may specify a stride that is not an exact multiple of the number of samples. The result is that on the final decode operation the destination buffer is overrun, potentially allowing an attacker to execute arbitrary code. (CVE-2006-3461)

The NeXT RLE decoder was also vulnerable to a heap overflow vulnerability, where no bounds checking was performed on the result of certain RLE decoding operations. This was solved by ensuring the number of pixels written did not exceed the size of the scanline buffer already prepared. (CVE-2006-3462)

An infinite loop was discovered in EstimateStripByteCounts(), where a 16bit unsigned short was used to iterate over a 32bit unsigned value, should the unsigned int (td_nstrips) have exceeded USHORT_MAX, the loop would never terminate and continue forever. (CVE-2006-3463)

Multiple unchecked arithmetic operations were uncovered, including a number of the range checking operations deisgned to ensure the offsets specified in tiff directories are legitimate. These can be caused to wrap for extreme values, bypassing sanity checks. Additionally, a number of codepaths were uncovered where assertions did not hold true, resulting in the client application calling abort(). (CVE-2006-3464)

A flaw was also uncovered in libtiffs custom tag support, as documented here http://www.libtiff.org/v3.6.0.html. While well formed tiff files must have correctly ordered directories, libtiff attempts to support broken images that do not. However in certain circumstances, creating anonymous fields prior to merging field information from codec information can result in recognised fields with unexpected values. This state results in abnormal behaviour, crashes, or potentially arbitrary code execution. (CVE-2006-3465)

The updated packages have been patched to correct these issues.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3459
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3460
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3461
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3462
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3463
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3464
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3465


Updated Packages:

Mandriva Linux 2006.0:
c0173eb2f2d497fce68b863a6d01433e 2006.0/RPMS/libtiff3-3.6.1-12.6.20060mdk.i586.rpm
55369714ae92ea654507f33944285322 2006.0/RPMS/libtiff3-devel-3.6.1-12.6.20060mdk.i586.rpm
8303a2a5f5b98d0fe984c4f62a8849e7 2006.0/RPMS/libtiff3-static-devel-3.6.1-12.6.20060mdk.i586.rpm
898dbc11589b623cba53d4e0dea4ec6e 2006.0/RPMS/libtiff-progs-3.6.1-12.6.20060mdk.i586.rpm
1f77f216c421961825035b17e2fc3d0f 2006.0/SRPMS/libtiff-3.6.1-12.6.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
67217a6617c35cfa110b9199ce827c7f x86_64/2006.0/RPMS/lib64tiff3-3.6.1-12.6.20060mdk.x86_64.rpm
b5ea6efd7fcb1db40c69457de4d90980 x86_64/2006.0/RPMS/lib64tiff3-devel-3.6.1-12.6.20060mdk.x86_64.rpm
673437e87cd25febee28993cd3c9488d x86_64/2006.0/RPMS/lib64tiff3-static-devel-3.6.1-12.6.20060mdk.x86_64.rpm
c0173eb2f2d497fce68b863a6d01433e x86_64/2006.0/RPMS/libtiff3-3.6.1-12.6.20060mdk.i586.rpm
55369714ae92ea654507f33944285322 x86_64/2006.0/RPMS/libtiff3-devel-3.6.1-12.6.20060mdk.i586.rpm
8303a2a5f5b98d0fe984c4f62a8849e7 x86_64/2006.0/RPMS/libtiff3-static-devel-3.6.1-12.6.20060mdk.i586.rpm
c3a7a68b6fef5f74240a6f526412d216 x86_64/2006.0/RPMS/libtiff-progs-3.6.1-12.6.20060mdk.x86_64.rpm
1f77f216c421961825035b17e2fc3d0f x86_64/2006.0/SRPMS/libtiff-3.6.1-12.6.20060mdk.src.rpm

Corporate 3.0:
7ed65170763bdbb2db2c73a0e6d21dc5 corporate/3.0/RPMS/libtiff3-3.5.7-11.12.C30mdk.i586.rpm
c4fd193c4ac3c199f98751b615f7f5ad corporate/3.0/RPMS/libtiff3-devel-3.5.7-11.12.C30mdk.i586.rpm
2d4920c58d576d4174358a62eb533acd corporate/3.0/RPMS/libtiff3-static-devel-3.5.7-11.12.C30mdk.i586.rpm
aa07135a25873d7265dfb1a4ac1fd365 corporate/3.0/RPMS/libtiff-progs-3.5.7-11.12.C30mdk.i586.rpm
8c70315b6e8fcbfeb56abaf9df8fef52 corporate/3.0/SRPMS/libtiff-3.5.7-11.12.C30mdk.src.rpm

Corporate 3.0/X86_64:
c48326e5749da37145fe7744b2ec7da7 x86_64/corporate/3.0/RPMS/lib64tiff3-3.5.7-11.12.C30mdk.x86_64.rpm
d5a2fa2ad3de5d7a77332920eea6ccb2 x86_64/corporate/3.0/RPMS/lib64tiff3-devel-3.5.7-11.12.C30mdk.x86_64.rpm
3582b0f21935141f83bb83787ce6537a x86_64/corporate/3.0/RPMS/lib64tiff3-static-devel-3.5.7-11.12.C30mdk.x86_64.rpm
7ed65170763bdbb2db2c73a0e6d21dc5 x86_64/corporate/3.0/RPMS/libtiff3-3.5.7-11.12.C30mdk.i586.rpm
b8de80aaa29a62815ef364357c319d95 x86_64/corporate/3.0/RPMS/libtiff-progs-3.5.7-11.12.C30mdk.x86_64.rpm
8c70315b6e8fcbfeb56abaf9df8fef52 x86_64/corporate/3.0/SRPMS/libtiff-3.5.7-11.12.C30mdk.src.rpm

Multi Network Firewall 2.0:
8cc2951ca065dced86d900d2713f7755 mnf/2.0/RPMS/libtiff3-3.5.7-11.12.M20mdk.i586.rpm
20c7813342fc7964cfc3f35465232ade mnf/2.0/SRPMS/libtiff-3.5.7-11.12.M20mdk.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>

SUSE Linux


SUSE Security Announcement

Package: libtiff
Announcement ID: SUSE-SA:2006:044
Date: Tue, 01 Aug 2006 17:00:00 +0000
Affected Products: SLE SDK 10 SUSE LINUX 10.1 SUSE LINUX 10.0 SUSE LINUX 9.3 SUSE LINUX 9.2 SuSE Linux Desktop 1.0 SuSE Linux Enterprise Server 8 SUSE SLES 10 SUSE SLES 9 UnitedLinux 1.0
Vulnerability Type: possible remote code execution
Severity (1-10): 8
SUSE Default Package: yes
Cross-References: CVE-2006-3459, CVE-2006-3460, CVE-2006-3461, CVE-2006-3462, CVE-2006-3463, CVE-2006-3464, CVE-2006-3465

Content of This Advisory:

  1. Security Vulnerability Resolved: fixed heap- and integer-overflows Problem Description
  2. Solution or Work-Around
  3. Special Instructions and Notes
  4. Package Location and Checksums
  5. Pending Vulnerabilities, Solutions, and Work-Arounds:
  6. Authenticity Verification and Additional Information

1) Problem Description and Brief Discussion

This update of libtiff is the result of a source-code audit done by Tavis Ormandy, Google Security Team. It fixes various bugs that can lead to denial-of-service conditions as well as to remote code execution while parsing a tiff image provided by an attacker.

2) Solution or Work-Around

No work-around known.

3) Special Instructions and Notes

Please restart all applications using libtiff. Desktop users should logout and re-login.
On server systems you have to restart all server applications manually.

4) Package Location and Checksums

The preferred method for installing security updates is to use the YaST Online Update (YOU) tool. YOU detects which updates are required and automatically performs the necessary steps to verify and install them. Alternatively, download the update packages for your distribution manually and verify their integrity by the methods listed in Section 6 of this announcement. Then install the packages using the command

rpm -Fhv <file.rpm>

to apply the update, replacing <file.rpm> with the filename of the downloaded RPM package.

x86 Platform:

SUSE LINUX 10.1:
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/libtiff-3.8.2-5.9.i586.rpm cee78f3b8393e87212f6c7eee1f1352f
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/libtiff-devel-3.8.2-5.9.i586.rpm 29374ea1d07be6b3c19828622fc8d85d

SUSE LINUX 10.0:
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/libtiff-3.7.3-2.6.i586.rpm c48675b2ee56aedbe4d14ae756343883
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/libtiff-devel-3.7.3-2.6.i586.rpm a19043509104bbdf56e208c44533fd17

SUSE LINUX 9.3:
   ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/libtiff-3.7.1-7.8.i586.rpm a9302f4fcd3b68edcbf6fa65ee8442c3
   ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/libtiff-devel-3.7.1-7.8.i586.rpm 12d72bbfb69a3fdb99007570d1e085ad

SUSE LINUX 9.2:
   ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/libtiff-3.6.1-47.12.i586.rpm 7f20ea84b8c0f57b61d885c45111d6b5
   ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/libtiff-devel-3.6.1-47.12.i586.rpm f36060a6d1979685ee7ca48e7b752a13

Power PC Platform:

SUSE LINUX 10.1:
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/libtiff-3.8.2-5.9.ppc.rpm 854544b32d5b37295c74ccb50117696f
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/libtiff-devel-3.8.2-5.9.ppc.rpm 133cb5b0ca0d416e9680f887c97ad755

SUSE LINUX 10.0:
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/libtiff-3.7.3-2.6.ppc.rpm 99f01efad45f24e8d6d71d267cb8268c
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/libtiff-devel-3.7.3-2.6.ppc.rpm d7e48acc3fcb3c1ba3f4eb1f10ea1bee

x86-64 Platform:

SUSE LINUX 10.1:
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/libtiff-3.8.2-5.9.x86_64.rpm 1925947454d5a294eea0ae33f84e7a18
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/libtiff-32bit-3.8.2-5.9.x86_64.rpm d5815aa12ff3a020e9db8217a968d413
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/libtiff-devel-3.8.2-5.9.x86_64.rpm aef78c4623c541daffd9d7264481028d
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/libtiff-devel-32bit-3.8.2-5.9.x86_64.rpm 2310393005c3a73e8a07149febf55d0c

SUSE LINUX 10.0:
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/libtiff-3.7.3-2.6.x86_64.rpm 58b69feace7592ebe3d2cfb89145e23f
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/libtiff-32bit-3.7.3-2.6.x86_64.rpm 3eb152a3d6896290bb14ce2e282f7fa4
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/libtiff-devel-3.7.3-2.6.x86_64.rpm 01395b47c733b9e8624b1c16fb7d3da0
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/libtiff-devel-32bit-3.7.3-2.6.x86_64.rpm 06071d61873c07b51feec446cd708bb8

SUSE LINUX 9.3:
   ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/libtiff-3.7.1-7.8.x86_64.rpm 1c210504374ad6344a8a6e4f4d248707
   ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/libtiff-32bit-9.3-7.3.x86_64.rpm 86b90ea77293182e332ace686ae7d08e
   ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/libtiff-devel-3.7.1-7.8.x86_64.rpm 9f87e7aed1c3847bb74795e3f9180354

SUSE LINUX 9.2:
   ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/libtiff-3.6.1-47.12.x86_64.rpm 17a80e08f430667462d8c8dbda680671
   ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/libtiff-32bit-9.2-200607271428.x86_64.rpm f11b621445853ca5e01a85dba0e86709
   ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/libtiff-devel-3.6.1-47.12.x86_64.rpm 63006aa37717b2e4151847e71e94b9ad

Our maintenance customers are notified individually. The packages are offered for installation from the maintenance web:

   http://support.novell.com/cgi-bin/search/searchtid.cgi?psdb/e25437fbc064183ed90d520bb8ab53f2.html
   http://support.novell.com/cgi-bin/search/searchtid.cgi?psdb/af67a688fbb2e507784c8a1e9db46ab3.html


5) Pending Vulnerabilities, Solutions, and Work-Arounds:

Please read the weekly summary report.


6) Authenticity Verification and Additional Information

  • Announcement authenticity verification:

    SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature.

    To verify the signature of the announcement, save it as text into a file and run the command

    gpg --verify <file>

    replacing <file> with the name of the file where you saved the announcement. The output for a valid signature looks like:

    gpg: Signature made <DATE> using RSA key ID 3D25D3D9
    gpg: Good signature from "SuSE Security Team <security@suse.de>"

    where <DATE> is replaced by the date the document was signed.

    If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command

    gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc

  • Package authenticity verification:

    SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and the integrity of a package needs to be verified to ensure that it has not been tampered with.

    There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or RPM package:

    1. Using the internal gpg signatures of the rpm package
    2. MD5 checksums as provided in this announcement
    1. The internal rpm package signatures provide an easy way to verify the authenticity of an RPM package. Use the command

      rpm -v --checksig <file.rpm>

      to verify the signature of the package, replacing <file.rpm> with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from build@suse.de with the key ID 9C800ACA. This key is automatically imported into the RPM database (on RPMv4-based distributions) and the gpg key ring of 'root' during installation. You can also find it on the first installation CD and at the end of this announcement.

    2. If you need an alternative means of verification, use the md5sum

      command to verify the authenticity of the packages. Execute the command

      md5sum <filename.rpm>

      after you downloaded the file from a SUSE FTP server or its mirrors. Then compare the resulting md5sum with the one that is listed in the SUSE security announcement. Because the announcement containing the checksums is cryptographically signed (by security@suse.de), the checksums show proof of the authenticity of the package if the signature of the announcement is valid. Note that the md5 sums published in the SUSE Security Announcements are valid for the respective packages only. Newer versions of these packages cannot be verified.

  • SUSE runs two security mailing lists to which any interested party may subscribe:

        suse-security@suse.com

    • General Linux and SUSE security discussion.
      All SUSE security announcements are sent to this list. To subscribe, send an e-mail to

      <suse-security-subscribe@suse.com>.

        suse-security-announce@suse.com

For general information or the frequently asked questions (FAQ), send mail to <suse-security-info@suse.com> or
<suse-security-faq@suse.com>.


SUSE's security contact is <security@suse.com> or <security@suse.de>.
The <security@suse.de> public key is listed below.

The information in this advisory may be distributed or reproduced, provided that the advisory is not modified in any way. In particular, the clear text signature should show proof of the authenticity of the text.

SUSE Linux Products GmbH provides no warranties of any kind whatsoever with respect to the information contained in this security advisory.

Type Bits/KeyID Date User ID
pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security@suse.de>
pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build@suse.de>


SUSE Security Announcement

Package: freetype2
Announcement ID: SUSE-SA:2006:045
Date: Tue, 01 Aug 2006 18:00:00 +0000
Affected Products: SLE SDK 10 SUSE LINUX 10.1 SUSE LINUX 10.0 SUSE LINUX 9.3 SUSE LINUX 9.2 SuSE Linux Desktop 1.0 SuSE Linux Enterprise Server 8 SUSE SLES 10 SUSE SLES 9 UnitedLinux 1.0
Vulnerability Type: possible code execution
Severity (1-10): 8
SUSE Default Package: yes
Cross-References: CVE-2006-3467

Content of This Advisory:

  1. Security Vulnerability Resolved: integer overflow Problem Description
  2. Solution or Work-Around
  3. Special Instructions and Notes
  4. Package Location and Checksums
  5. Pending Vulnerabilities, Solutions, and Work-Arounds:
  6. Authenticity Verification and Additional Information

1) Problem Description and Brief Discussion

This security update fixes crashes in the PCF handling of freetype2 which might be used to crash freetype2 using applications or even to execude code in them.

2) Solution or Work-Around

No work-around known.

3) Special Instructions and Notes

Please restart all applications using libtiff. Desktop users should logout and re-login.
On server systems you have to restart all server applications manually.

4) Package Location and Checksums

The preferred method for installing security updates is to use the YaST Online Update (YOU) tool. YOU detects which updates are required and automatically performs the necessary steps to verify and install them. Alternatively, download the update packages for your distribution manually and verify their integrity by the methods listed in Section 6 of this announcement. Then install the packages using the command

rpm -Fhv <file.rpm>

to apply the update, replacing <file.rpm> with the filename of the downloaded RPM package.

x86 Platform:

SUSE LINUX 10.1:
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/freetype2-2.1.10-18.8.i586.rpm 5b3f167cce62870117a4e2fa009bae4f
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/freetype2-devel-2.1.10-18.8.i586.rpm e927b989339e9f9bec00d1b9dcaf9a19

SUSE LINUX 10.0:
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/freetype2-2.1.10-4.4.i586.rpm 531f4629f8dc5a2875f9e1c9aec0b1b5
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/freetype2-devel-2.1.10-4.4.i586.rpm 42dd4c6ca44ba52786519f59c83624b9

SUSE LINUX 9.3:
   ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/freetype2-2.1.9-4.4.i586.rpm c4c0764be947a478d0b5583e50510903
   ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/freetype2-devel-2.1.9-4.4.i586.rpm 3519d6e62b3d582bc47e5af1a2c774c6

SUSE LINUX 9.2:
   ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/freetype2-2.1.9-3.4.i586.rpm 146856628a74cb15457e11aa7337c31f
   ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/freetype2-devel-2.1.9-3.4.i586.rpm c416e6195fb1aa805e288526d54381af

Power PC Platform:

SUSE LINUX 10.1:
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/freetype2-2.1.10-18.8.ppc.rpm 2fb95c4f2d717cf3813db084be206a9f
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/freetype2-devel-2.1.10-18.8.ppc.rpm e42b9fb058f7fc177a5923b76d43aa1d

SUSE LINUX 10.0:
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/freetype2-2.1.10-4.4.ppc.rpm 57edbb76b03b7ea2c4a0649549f2556f
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/freetype2-devel-2.1.10-4.4.ppc.rpm 3e84a91d83f2723e4f1e9174bc744976

x86-64 Platform:

SUSE LINUX 10.1:
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/freetype2-2.1.10-18.8.x86_64.rpm b6e4eb912ae20cc5e2108918aa4223ce
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/freetype2-32bit-2.1.10-18.8.x86_64.rpm 200e0497a3aba6400b95def9fd370743
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/freetype2-devel-2.1.10-18.8.x86_64.rpm 0069a1143bda97ed5c65e37561b634a6
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/freetype2-devel-32bit-2.1.10-18.8.x86_64.rpm eadbd8ec95d26e0b377c41b0a4b81ce7

SUSE LINUX 10.0:
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/freetype2-2.1.10-4.4.x86_64.rpm 502ee9101176c8cabe74ffa96b9c86bf
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/freetype2-32bit-2.1.10-4.4.x86_64.rpm b3839f54586cb9250067b43e9c37ff4f
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/freetype2-devel-2.1.10-4.4.x86_64.rpm db9965909415db561e09bee9f6fbb445
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/freetype2-devel-32bit-2.1.10-4.4.x86_64.rpm e84c092650ccd5dee76edaa90cbb26b0

SUSE LINUX 9.3:
   ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/freetype2-2.1.9-4.4.x86_64.rpm eef00de5d1a91266ed07285f4da34af2
   ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/freetype2-32bit-9.3-7.2.x86_64.rpm c906a892e78ffd90fcd96aba1d20f0f2
   ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/freetype2-devel-2.1.9-4.4.x86_64.rpm 62c7a3e6baab5ea1276f4e1b6bc2ca69
   ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/freetype2-devel-32bit-9.3-7.2.x86_64.rpm e5d5670a23d190565c0c3691bcf6dba7

SUSE LINUX 9.2:
   ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/freetype2-2.1.9-3.4.x86_64.rpm de7b9ea0e3aeae01c5fac30cc34a4e55
   ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/freetype2-32bit-9.2-200607282225.x86_64.rpm d2abe911c1b5147c1ac917c3f2704397
   ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/freetype2-devel-2.1.9-3.4.x86_64.rpm b5b7030ca22d70fad00bd1ed437906bb
   ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/freetype2-devel-32bit-9.2-200607282225.x86_64.rpm 8d1c484d443d317fc05ee83f426c83fa

Sources:

SUSE LINUX 10.1:
   ftp://ftp.suse.com/pub/suse/update/10.1/rpm/src/freetype2-2.1.10-18.8.src.rpm 0b6ab9aba01fb96057457dfa029075c6

SUSE LINUX 10.0:
   ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/src/freetype2-2.1.10-4.4.src.rpm 22d3bccb56fade850da7f816f1b482f2

SUSE LINUX 9.3:
   ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/src/freetype2-2.1.9-4.4.src.rpm 1535c2f49679dac17b60199e3f447121

SUSE LINUX 9.2:
   ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/src/freetype2-2.1.9-3.4.src.rpm 0a33023485fbdd877595ad66e541d06c

Our maintenance customers are notified individually. The packages are offered for installation from the maintenance web:

   http://support.novell.com/cgi-bin/search/searchtid.cgi?psdb/f534b9ffd4b983d69bc74733530440a8.html
   http://support.novell.com/cgi-bin/search/searchtid.cgi?psdb/c5665912fca64d68365399f85b8dad06.html


5) Pending Vulnerabilities, Solutions, and Work-Arounds:

Please restart all applications using libtiff. Desktop users should logout and re-login.
On server systems you have to restart all server applications manually.


6) Authenticity Verification and Additional Information

  • Announcement authenticity verification:

    SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature.

    To verify the signature of the announcement, save it as text into a file and run the command

    gpg --verify <file>

    replacing <file> with the name of the file where you saved the announcement. The output for a valid signature looks like:

    gpg: Signature made <DATE> using RSA key ID 3D25D3D9
    gpg: Good signature from "SuSE Security Team <security@suse.de>"

    where <DATE> is replaced by the date the document was signed.

    If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command

    gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc

  • Package authenticity verification:

    SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and the integrity of a package needs to be verified to ensure that it has not been tampered with.

    There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or RPM package:

    1. Using the internal gpg signatures of the rpm package
    2. MD5 checksums as provided in this announcement
    1. The internal rpm package signatures provide an easy way to verify the authenticity of an RPM package. Use the command

      rpm -v --checksig <file.rpm>

      to verify the signature of the package, replacing <file.rpm> with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from build@suse.de with the key ID 9C800ACA. This key is automatically imported into the RPM database (on RPMv4-based distributions) and the gpg key ring of 'root' during installation. You can also find it on the first installation CD and at the end of this announcement.

    2. If you need an alternative means of verification, use the md5sum

      command to verify the authenticity of the packages. Execute the command

      md5sum <filename.rpm>

      after you downloaded the file from a SUSE FTP server or its mirrors. Then compare the resulting md5sum with the one that is listed in the SUSE security announcement. Because the announcement containing the checksums is cryptographically signed (by security@suse.de), the checksums show proof of the authenticity of the package if the signature of the announcement is valid. Note that the md5 sums published in the SUSE Security Announcements are valid for the respective packages only. Newer versions of these packages cannot be verified.

  • SUSE runs two security mailing lists to which any interested party may subscribe:

        suse-security@suse.com

    • General Linux and SUSE security discussion.
      All SUSE security announcements are sent to this list. To subscribe, send an e-mail to

      <suse-security-subscribe@suse.com>.

        suse-security-announce@suse.com

For general information or the frequently asked questions (FAQ), send mail to <suse-security-info@suse.com> or
<suse-security-faq@suse.com>.


SUSE's security contact is <security@suse.com> or <security@suse.de>.
The <security@suse.de> public key is listed below.

The information in this advisory may be distributed or reproduced, provided that the advisory is not modified in any way. In particular, the clear text signature should show proof of the authenticity of the text.

SUSE Linux Products GmbH provides no warranties of any kind whatsoever with respect to the information contained in this security advisory.

Type Bits/KeyID Date User ID
pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security@suse.de>
pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build@suse.de>

Ubuntu Linux


Ubuntu Security Notice USN-327-2 August 01, 2006
firefox regression
https://bugzilla.mozilla.org/show_bug.cgi?id=346167

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

Ubuntu 6.06 LTS:
firefox 1.5.dfsg+1.5.0.5-0ubuntu6.06.1

After a standard system upgrade you need to restart Firefox to effect the necessary changes.

Details follow:

USN-327-1 fixed several vulnerabilities in Firefox. Unfortunately the new version introduced a regression in the handling of streamed media. Embedded media which were linked with a scheme other than http:// did not work any more. This update fixes this regression.

Updated packages for Ubuntu 6.06 LTS:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_1.5.dfsg+1.5.0.5-0ubuntu6.06.1.diff.gz
      Size/MD5: 175666 687919fcd46adfbb0d7178b5475305c1
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_1.5.dfsg+1.5.0.5-0ubuntu6.06.1.dsc
      Size/MD5: 1113 e442234ffa0a54f87807c1288e47fa5d
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_1.5.dfsg+1.5.0.5.orig.tar.gz
      Size/MD5: 44067762 749933c002e158576ec15782fc451e43

Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/universe/f/firefox/mozilla-firefox-dev_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_all.deb
      Size/MD5: 49298 f514abb6f942165f1fc3d5374bbae15a
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/mozilla-firefox_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_all.deb
      Size/MD5: 50184 a7b0bf4028ede77740dc0662a827dcf0

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-dbg_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_amd64.deb
      Size/MD5: 47269380 3ad3fdf041a077e1fd691138bb9bfeb6
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-dev_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_amd64.deb
      Size/MD5: 2796780 4d08389abd46a4cfb1ea417a8ad5fa3b
    http://security.ubuntu.com/ubuntu/pool/universe/f/firefox/firefox-dom-inspector_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_amd64.deb
      Size/MD5: 216230 e1d98cf540498d5fc02661a5486db16d
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-gnome-support_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_amd64.deb
      Size/MD5: 82448 5a283f508971dc233a454789387b4132
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_amd64.deb
      Size/MD5: 9400588 cf74b732b4ba49854c319c00d3d82a4b
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnspr-dev_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_amd64.deb
      Size/MD5: 218920 9c0d2ee7cf67eeb17e850fd730f3b8fb
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnspr4_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_amd64.deb
      Size/MD5: 161968 57e24fd2d917b17029289f334c04b17c
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnss-dev_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_amd64.deb
      Size/MD5: 235846 b3a13148395af99060cd418e9a23705d
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnss3_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_amd64.deb
      Size/MD5: 757540 3c825373eeda432f0fe8fa4e97d00fec

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-dbg_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_i386.deb
      Size/MD5: 43837564 d1bb1e8b82e23a0fbf07e57c56eed7af
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-dev_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_i386.deb
      Size/MD5: 2796780 49e77e98de42a21d531468df796e2296
    http://security.ubuntu.com/ubuntu/pool/universe/f/firefox/firefox-dom-inspector_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_i386.deb
      Size/MD5: 209648 500f92b789dc30a7cce74e58c339bbdd
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-gnome-support_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_i386.deb
      Size/MD5: 74834 ec2db908691d504cf714a4c4ea5b411e
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_i386.deb
      Size/MD5: 7916466 272500e32887186917f370dcc09661ee
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnspr-dev_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_i386.deb
      Size/MD5: 218924 a80027c5868b295ee9e81d1244ec568e
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnspr4_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_i386.deb
      Size/MD5: 146678 18754a6f6caa2d3e83114d6971f7ff3a
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnss-dev_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_i386.deb
      Size/MD5: 235800 0ebc9b9ddd1624df7351c888a9ad597f
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnss3_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_i386.deb
      Size/MD5: 669656 1e4bf8aa2fef808a6eaa00248dd1c602

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-dbg_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_powerpc.deb
      Size/MD5: 48648198 9f923bf4ed6ea38bf1a050596fac80ba
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-dev_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_powerpc.deb
      Size/MD5: 2796794 60ac8a2a5612636dcb18eca87627da5b
    http://security.ubuntu.com/ubuntu/pool/universe/f/firefox/firefox-dom-inspector_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_powerpc.deb
      Size/MD5: 213088 136b6615471b6534cc67bf9434ee81cd
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-gnome-support_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_powerpc.deb
      Size/MD5: 77990 814f8da56cb35a11334b9b47ec576ced
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_powerpc.deb
      Size/MD5: 9019140 3c7e22b56427131aebc6ff373e49b5a5
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnspr-dev_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_powerpc.deb
      Size/MD5: 218924 5b01bb06b02263e9375821a87b1b1d77
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnspr4_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_powerpc.deb
      Size/MD5: 159206 a7751fe73e867e8186f7a061742382e2
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnss-dev_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_powerpc.deb
      Size/MD5: 235840 7688b5a53549f0af5eecb275fdd710c5
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnss3_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_powerpc.deb
      Size/MD5: 768422 3a735934106b31a280790b31a8c588b2

sparc architecture (Sun SPARC/UltraSPARC)

    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-dbg_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_sparc.deb
      Size/MD5: 45235548 0c65d01cfaf7ddcc68f1c3253e8dc6e4
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-dev_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_sparc.deb
      Size/MD5: 2796822 dc63fcecff2886edacdc0ec13ce63f5c
    http://security.ubuntu.com/ubuntu/pool/universe/f/firefox/firefox-dom-inspector_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_sparc.deb
      Size/MD5: 210578 c364e5a088dec391b520667db74583fa
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-gnome-support_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_sparc.deb
      Size/MD5: 76444 ebc3ec5b4fbe2384925d9665b37ecb44
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_1.5.dfsg+1.5.0.5-0ubuntu6.06.1_sparc.deb
      Size/MD5: 8411422 17c6cf3dcba9e75b75da8dbb4f41f944
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnspr-dev_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_sparc.deb
      Size/MD5: 218928 f9c0866dcc283b35745c36f84db4d595
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnspr4_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_sparc.deb
      Size/MD5: 149152 7beacf9f311aba0c67084caf4dd69a57
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnss-dev_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_sparc.deb
      Size/MD5: 235844 365427c372b02847c7667f905aca1542
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnss3_1.firefox1.5.dfsg+1.5.0.5-0ubuntu6.06.1_sparc.deb
      Size/MD5: 681710 fbef3d2ba1b7d40ae3afebbe29d9191f



No talkbacks posted.
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!

..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP