Linux Today: Linux News On Internet Time.
Search Linux Today
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Server Daily
IT Management Daily
Subscribe News
Subscribe PR
Subscribe Security

internet.com
Internet News
Small Business

Advertise
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

20 popular Ubuntu Linux apps you may want to try

A Selection of the Very Best Open Source Tutorials and Tools

Android Ice Cream Sandwich ported to x86 tablets, netbooks and notebooks

SECURITY: Google Chrome 17 Improves Security

How to read a CSV file in Perl?

Red Hat Brings Gluster to Amazon Cloud

New Linux kernel fixes power-saving issues

Using Wii remote with Android Device- Taking Gaming to the Next Level

Commercial Support now available for the open-source NGINX Web server

Linux Top 5: Linux's New Fellow



Applications Management Engineer Sr (NYC)
Next Step Systems
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume
:Advisories, October 2, 2006
Advisories, October 2, 2006
Oct 3, 2006, 03 :45 UTC (0 Talkback[s]) (2601 reads)

Debian GNU/Linux


Debian Security Advisory DSA 1185-2 security@debian.org
http://www.debian.org/security/ Noah Meyerhans
October 2nd, 2006 http://www.debian.org/security/faq


Package : openssl
Vulnerability : denial of service
Problem-Type : remote
Debian-specific: no
CVE ID : CVE-2006-2940

The fix used to correct CVE-2006-2940 introduced code that could lead to the use of uninitialized memory. Such use is likely to cause the application using the openssl library to crash, and has the potential to allow an attacker to cause the execution of arbitrary code.

For the stable distribution (sarge) these problems have been fixed in version 0.9.7e-3sarge4.

For the unstable and testing distributions (sid and etch, respectively), these problems will be fixed in version 0.9.7k-3 of the openssl097 compatibility libraries, and version 0.9.8c-3 of the openssl package.

We recommend that you upgrade your openssl package. Note that services linking against the openssl shared libraries will need to be restarted. Common examples of such services include most Mail Transport Agents, SSH servers, and web servers.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e-3sarge4.dsc
      Size/MD5 checksum: 639 179f34093d860afff66964b5f1c99ee3
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e-3sarge4.diff.gz
      Size/MD5 checksum: 29707 0b4d462730327aba5a751bd4bec71c10
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e.orig.tar.gz
      Size/MD5 checksum: 3043231 a8777164bca38d84e5eb2b1535223474

Alpha architecture:

    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.7e-3sarge4_alpha.deb
      Size/MD5 checksum: 3341886 f0d0ef51fac89227b0d0705116439f5c
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.7_0.9.7e-3sarge4_alpha.deb
      Size/MD5 checksum: 2448092 8065c52c7649f36221f8a48adfb4cb29
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e-3sarge4_alpha.deb
      Size/MD5 checksum: 930234 5953c4c4a45352d41c3c414eda63ff00

AMD64 architecture:

    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.7e-3sarge4_amd64.deb
      Size/MD5 checksum: 2693980 cbd25bbed17ec73561337bfc3d8ed2ed
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.7_0.9.7e-3sarge4_amd64.deb
      Size/MD5 checksum: 769904 2671cdf2f48013617ea509daac2bb4dc
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e-3sarge4_amd64.deb
      Size/MD5 checksum: 903782 e370684d7c84d1eebcb69cdda35c6c6c

ARM architecture:

    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.7e-3sarge4_arm.deb
      Size/MD5 checksum: 2556330 75c1a253ddad0b7ad87053552770e5c4
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.7_0.9.7e-3sarge4_arm.deb
      Size/MD5 checksum: 690202 ccd435ca2c183940152f3bd70d84ee0b
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e-3sarge4_arm.deb
      Size/MD5 checksum: 894144 2e5caaa90184d9ee9e607d18728e6f93

HP Precision architecture:

    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.7e-3sarge4_hppa.deb
      Size/MD5 checksum: 2695990 58fe1a247ef47faa559eef610b437db6
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.7_0.9.7e-3sarge4_hppa.deb
      Size/MD5 checksum: 791382 f0c64d06307af937218944d6d8db6e2f
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e-3sarge4_hppa.deb
      Size/MD5 checksum: 914576 631c681a3c4ce355962a7c684767a155

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.7e-3sarge4_i386.deb
      Size/MD5 checksum: 2554956 c4c9aa14e74dbd6dac2cadd7cf48b522
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.7_0.9.7e-3sarge4_i386.deb
      Size/MD5 checksum: 2265180 9047b6c6036c048ad75fa397f220ae39
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e-3sarge4_i386.deb
      Size/MD5 checksum: 906268 070d1d1680f90da5509121c44de7a254

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.7e-3sarge4_ia64.deb
      Size/MD5 checksum: 3396206 3a3d88238a48d33b39e7575a97c6cfdf
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.7_0.9.7e-3sarge4_ia64.deb
      Size/MD5 checksum: 1038432 e2e4e1d388c5d45c8d30e16d661ad24c
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e-3sarge4_ia64.deb
      Size/MD5 checksum: 975152 1783b49f3b7a12bd18dff0fcc37f5d68

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.7e-3sarge4_m68k.deb
      Size/MD5 checksum: 2317348 b4930b1cf5e642bf509d44dd83de193f
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.7_0.9.7e-3sarge4_m68k.deb
      Size/MD5 checksum: 661716 d5fb4eb5947c8765e268696e94a46a8b
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e-3sarge4_m68k.deb
      Size/MD5 checksum: 889932 e1ecef3780edd38743246dfda1424e8c

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.7e-3sarge4_mips.deb
      Size/MD5 checksum: 2779464 591dbe4f6d73d56c9e9ff72f2d0a5385
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.7_0.9.7e-3sarge4_mips.deb
      Size/MD5 checksum: 706682 0b3de7eef13969d065ed057fda34afc2
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e-3sarge4_mips.deb
      Size/MD5 checksum: 896834 e2b8f38056a06f63c3ce6c10d9d95dba

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.7e-3sarge4_mipsel.deb
      Size/MD5 checksum: 2767364 883d0167f6642e90e8a183b4f87a78ba
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.7_0.9.7e-3sarge4_mipsel.deb
      Size/MD5 checksum: 694532 f4961231ef2c2b8ff46f173338a7fa36
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e-3sarge4_mipsel.deb
      Size/MD5 checksum: 895922 2ad35f3927ba71d8054fe8cd4316f5b0

PowerPC architecture:

    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.7e-3sarge4_powerpc.deb
      Size/MD5 checksum: 2775608 0dca0ec9cf2d230ce68394849be748b1
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.7_0.9.7e-3sarge4_powerpc.deb
      Size/MD5 checksum: 779456 6736cdc1dfe5f19013f4dee0a2b3b1cf
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e-3sarge4_powerpc.deb
      Size/MD5 checksum: 908418 8759696eff63836597e4247c06ba7b22

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.7e-3sarge4_s390.deb
      Size/MD5 checksum: 2717788 12fb63ace68a2698c19c725530ab18d9
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.7_0.9.7e-3sarge4_s390.deb
      Size/MD5 checksum: 814012 adcee88124369de1daeae0545e0517a0
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e-3sarge4_s390.deb
      Size/MD5 checksum: 918524 b93704f4ce84489d4ee163098a783962

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.7e-3sarge4_sparc.deb
      Size/MD5 checksum: 2630606 a20a47b2f291810a09fd04a4c130ddb0
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.7_0.9.7e-3sarge4_sparc.deb
      Size/MD5 checksum: 1886152 8521da994bf2a6df3bdc457fb3e0683b
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.7e-3sarge4_sparc.deb
      Size/MD5 checksum: 924556 ff8cee5f5a9653a9dd917b4ec51166ee

These files will probably be moved into the stable distribution on its next update.


For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

Mandriva Linux


Mandriva Linux Security Advisory MDKSA-2006:172-1
http://www.mandriva.com/security/


Package : openssl
Date : October 2, 2006
Affected: 2006.0, 2007.0, Corporate 3.0, Corporate 4.0, Multi Network Firewall 2.0


Problem Description:

Dr S N Henson of the OpenSSL core team and Open Network Security recently developed an ASN1 test suite for NISCC (www.niscc.gov.uk). When the test suite was run against OpenSSL two denial of service vulnerabilities were discovered.

During the parsing of certain invalid ASN1 structures an error condition is mishandled. This can result in an infinite loop which consumes system memory. (CVE-2006-2937)

Certain types of public key can take disproportionate amounts of time to process. This could be used by an attacker in a denial of service attack. (CVE-2006-2940)

Tavis Ormandy and Will Drewry of the Google Security Team discovered a buffer overflow in the SSL_get_shared_ciphers utility function, used by some applications such as exim and mysql. An attacker could send a list of ciphers that would overrun a buffer. (CVE-2006-3738)

Tavis Ormandy and Will Drewry of the Google Security Team discovered a possible DoS in the sslv2 client code. Where a client application uses OpenSSL to make a SSLv2 connection to a malicious server that server could cause the client to crash. (CVE-2006-4343)

Updated packages are patched to address these issues.

Update:

There was an error in the original published patches for CVE-2006-2940. New packages have corrected this issue.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2937
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2940
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4343


Updated Packages:

Mandriva Linux 2006.0:
5e48a8d9a6a03a045b6d0d2b6903dc5b 2006.0/i586/libopenssl0.9.7-0.9.7g-2.5.20060mdk.i586.rpm
f86f3a2efd19ff5fb1600212cbd8e463 2006.0/i586/libopenssl0.9.7-devel-0.9.7g-2.5.20060mdk.i586.rpm
73b99c1a8a34fe3c2279c09c4f385804 2006.0/i586/libopenssl0.9.7-static-devel-0.9.7g-2.5.20060mdk.i586.rpm
526fcd69e1a1768c82afd573dc16982f 2006.0/i586/openssl-0.9.7g-2.5.20060mdk.i586.rpm
441a806fc8a50f74f5b4bcfce1fc8f66 2006.0/SRPMS/openssl-0.9.7g-2.5.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
54ed69fc4976d3c0953eeebd3c10471a 2006.0/x86_64/lib64openssl0.9.7-0.9.7g-2.5.20060mdk.x86_64.rpm
632fbe5eaff684ec2f27da4bbe93c4f6 2006.0/x86_64/lib64openssl0.9.7-devel-0.9.7g-2.5.20060mdk.x86_64.rpm
04dbe52bda3051101db73fabe687bd7e 2006.0/x86_64/lib64openssl0.9.7-static-devel-0.9.7g-2.5.20060mdk.x86_64.rpm
5e48a8d9a6a03a045b6d0d2b6903dc5b 2006.0/x86_64/libopenssl0.9.7-0.9.7g-2.5.20060mdk.i586.rpm
f86f3a2efd19ff5fb1600212cbd8e463 2006.0/x86_64/libopenssl0.9.7-devel-0.9.7g-2.5.20060mdk.i586.rpm
73b99c1a8a34fe3c2279c09c4f385804 2006.0/x86_64/libopenssl0.9.7-static-devel-0.9.7g-2.5.20060mdk.i586.rpm
ca169246cc85db55839b265b90e8c842 2006.0/x86_64/openssl-0.9.7g-2.5.20060mdk.x86_64.rpm
441a806fc8a50f74f5b4bcfce1fc8f66 2006.0/SRPMS/openssl-0.9.7g-2.5.20060mdk.src.rpm

Mandriva Linux 2007.0:
db68f8f239604fb76a0a10c70104ef61 2007.0/i586/libopenssl0.9.8-0.9.8b-2.2mdv2007.0.i586.rpm
26a4de823aee08e40d28ed7e6ff5b2ff 2007.0/i586/libopenssl0.9.8-devel-0.9.8b-2.2mdv2007.0.i586.rpm
ab949cf85296ceae864f83fbbac2b55a 2007.0/i586/libopenssl0.9.8-static-devel-0.9.8b-2.2mdv2007.0.i586.rpm
a97c6033a33fabcd5509568304b7a988 2007.0/i586/openssl-0.9.8b-2.2mdv2007.0.i586.rpm
78964615b7bd71028671257640be3bc5 2007.0/SRPMS/openssl-0.9.8b-2.2mdv2007.0.src.rpm

Mandriva Linux 2007.0/X86_64:
1895971ef1221056075c4ee3d4aaac72 2007.0/x86_64/lib64openssl0.9.8-0.9.8b-2.2mdv2007.0.x86_64.rpm
cfd59201e5e9c436f42b969b4aa567f1 2007.0/x86_64/lib64openssl0.9.8-devel-0.9.8b-2.2mdv2007.0.x86_64.rpm
36da85c76eddf95feeb3f4b792528483 2007.0/x86_64/lib64openssl0.9.8-static-devel-0.9.8b-2.2mdv2007.0.x86_64.rpm
db68f8f239604fb76a0a10c70104ef61 2007.0/x86_64/libopenssl0.9.8-0.9.8b-2.2mdv2007.0.i586.rpm
26a4de823aee08e40d28ed7e6ff5b2ff 2007.0/x86_64/libopenssl0.9.8-devel-0.9.8b-2.2mdv2007.0.i586.rpm
ab949cf85296ceae864f83fbbac2b55a 2007.0/x86_64/libopenssl0.9.8-static-devel-0.9.8b-2.2mdv2007.0.i586.rpm
e3aebeae455a0820c5f28483bd6d3fa5 2007.0/x86_64/openssl-0.9.8b-2.2mdv2007.0.x86_64.rpm
78964615b7bd71028671257640be3bc5 2007.0/SRPMS/openssl-0.9.8b-2.2mdv2007.0.src.rpm

Corporate 3.0:
7f60837e42b45ce50f365ec1372d6aeb corporate/3.0/i586/libopenssl0.9.7-0.9.7c-3.7.C30mdk.i586.rpm
1e7834f6f0fe000f8f00ff49ee6f7ea0 corporate/3.0/i586/libopenssl0.9.7-devel-0.9.7c-3.7.C30mdk.i586.rpm
6c86220445ef34c2dadadc3e00701885 corporate/3.0/i586/libopenssl0.9.7-static-devel-0.9.7c-3.7.C30mdk.i586.rpm
c25c4042a91b6e7bf9aae1aa2fea32a5 corporate/3.0/i586/openssl-0.9.7c-3.7.C30mdk.i586.rpm
2c47b1604aa89033799b1ead4bcebe01 corporate/3.0/SRPMS/openssl-0.9.7c-3.7.C30mdk.src.rpm

Corporate 3.0/X86_64:
52dfd4d10e00c9bd0944e4486190de93 corporate/3.0/x86_64/lib64openssl0.9.7-0.9.7c-3.7.C30mdk.x86_64.rpm
258a19afc44dadfaa00d0ebd8b3c0df4 corporate/3.0/x86_64/lib64openssl0.9.7-devel-0.9.7c-3.7.C30mdk.x86_64.rpm
cd5cc151e476552be549c6a37b8a71ea corporate/3.0/x86_64/lib64openssl0.9.7-static-devel-0.9.7c-3.7.C30mdk.x86_64.rpm
7f60837e42b45ce50f365ec1372d6aeb corporate/3.0/x86_64/libopenssl0.9.7-0.9.7c-3.7.C30mdk.i586.rpm
492fcc0df9172557a3297d0082321d4d corporate/3.0/x86_64/openssl-0.9.7c-3.7.C30mdk.x86_64.rpm
2c47b1604aa89033799b1ead4bcebe01 corporate/3.0/SRPMS/openssl-0.9.7c-3.7.C30mdk.src.rpm

Corporate 4.0:
76b3078e53be2ddc019bee74ccb1f39e corporate/4.0/i586/libopenssl0.9.7-0.9.7g-2.5.20060mlcs4.i586.rpm
0aa4ca3b0d2925255650fb90132d7aad corporate/4.0/i586/libopenssl0.9.7-devel-0.9.7g-2.5.20060mlcs4.i586.rpm
86dc91f1701293f3319a833746bbe421 corporate/4.0/i586/libopenssl0.9.7-static-devel-0.9.7g-2.5.20060mlcs4.i586.rpm
daa6c3473f59405778dedd02de73fcc9 corporate/4.0/i586/openssl-0.9.7g-2.5.20060mlcs4.i586.rpm
a8d2a946d266a94c6d46537ad78b18fa corporate/4.0/SRPMS/openssl-0.9.7g-2.5.20060mlcs4.src.rpm

Corporate 4.0/X86_64:
b5ae71aacd5b99be9e9327d58da29230 corporate/4.0/x86_64/lib64openssl0.9.7-0.9.7g-2.5.20060mlcs4.x86_64.rpm
89296e03778a198940c1c413e44b9f45 corporate/4.0/x86_64/lib64openssl0.9.7-devel-0.9.7g-2.5.20060mlcs4.x86_64.rpm
cb17a0d801c1181ab380472b8ffb085e corporate/4.0/x86_64/lib64openssl0.9.7-static-devel-0.9.7g-2.5.20060mlcs4.x86_64.rpm
76b3078e53be2ddc019bee74ccb1f39e corporate/4.0/x86_64/libopenssl0.9.7-0.9.7g-2.5.20060mlcs4.i586.rpm
0aa4ca3b0d2925255650fb90132d7aad corporate/4.0/x86_64/libopenssl0.9.7-devel-0.9.7g-2.5.20060mlcs4.i586.rpm
86dc91f1701293f3319a833746bbe421 corporate/4.0/x86_64/libopenssl0.9.7-static-devel-0.9.7g-2.5.20060mlcs4.i586.rpm
8d9a55afdc6d930916bac00fd4c4739b corporate/4.0/x86_64/openssl-0.9.7g-2.5.20060mlcs4.x86_64.rpm
a8d2a946d266a94c6d46537ad78b18fa corporate/4.0/SRPMS/openssl-0.9.7g-2.5.20060mlcs4.src.rpm

Multi Network Firewall 2.0:
cd7ad7e95ce17995dfa8129ebe517049 mnf/2.0/i586/libopenssl0.9.7-0.9.7c-3.7.M20mdk.i586.rpm
11771240baebdc6687af70a8a0f2ffd2 mnf/2.0/i586/libopenssl0.9.7-devel-0.9.7c-3.7.M20mdk.i586.rpm
8f672bc81b9528598a8560d876612bfa mnf/2.0/i586/libopenssl0.9.7-static-devel-0.9.7c-3.7.M20mdk.i586.rpm
214f857a36e5c3e600671b7291cd08ae mnf/2.0/i586/openssl-0.9.7c-3.7.M20mdk.i586.rpm
bbb299fd643ccbfbdc1a48b12c7005ce mnf/2.0/SRPMS/openssl-0.9.7c-3.7.M20mdk.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>


Mandriva Linux Security Advisory MDKSA-2006:177
http://www.mandriva.com/security/


Package : MySQL
Date : October 2, 2006
Affected: 2006.0, Corporate 3.0, Multi Network Firewall 2.0


Problem Description:

Openssl recently had several vulnerabilities which were patched (CVE-2006-2937,2940,3738,4339, 4343). Some MySQL versions are built against a static copy of the SSL libraries. As a precaution an updated copy built against the new libraries in being made available.


Updated Packages:

Mandriva Linux 2006.0:
418e35dd59274a82fbbd30ad86ae4b52 2006.0/i586/libmysql14-4.1.12-4.10.20060mdk.i586.rpm
c5f9cb360efec94d2697ed851ee176a2 2006.0/i586/libmysql14-devel-4.1.12-4.10.20060mdk.i586.rpm
910de5c23772bb3f26cdcdce8003d114 2006.0/i586/MySQL-4.1.12-4.10.20060mdk.i586.rpm
abe1945164f6a636299eb1ae4bba1c78 2006.0/i586/MySQL-bench-4.1.12-4.10.20060mdk.i586.rpm
28b3e7d8c05df9b754f4cf945f30d428 2006.0/i586/MySQL-client-4.1.12-4.10.20060mdk.i586.rpm
675e9b54a946384c41f75fddbf1ae01f 2006.0/i586/MySQL-common-4.1.12-4.10.20060mdk.i586.rpm
1d4f0ae66414ce37aebfd3f4c1a83899 2006.0/i586/MySQL-Max-4.1.12-4.10.20060mdk.i586.rpm
22bda4fffb5fd0a4947e7b6504490221 2006.0/i586/MySQL-NDB-4.1.12-4.10.20060mdk.i586.rpm
65f2714658fbaa7194aa6a9e35bea114 2006.0/SRPMS/MySQL-4.1.12-4.10.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
6e7f0056a120f698eec53cb07638b4c7 2006.0/x86_64/lib64mysql14-4.1.12-4.10.20060mdk.x86_64.rpm
b1ea5845d8148276d1a5d3c86a7812c7 2006.0/x86_64/lib64mysql14-devel-4.1.12-4.10.20060mdk.x86_64.rpm
be05d787582cdffc9b501afec29d0d4a 2006.0/x86_64/MySQL-4.1.12-4.10.20060mdk.x86_64.rpm
afef58f5bdbbc31174b7e4a38e6d3bea 2006.0/x86_64/MySQL-bench-4.1.12-4.10.20060mdk.x86_64.rpm
7df7c9d58ca919d0c2bfd8ec54df9f64 2006.0/x86_64/MySQL-client-4.1.12-4.10.20060mdk.x86_64.rpm
6f2adf900838a2daffc58c367356b5b9 2006.0/x86_64/MySQL-common-4.1.12-4.10.20060mdk.x86_64.rpm
4ae3e7c5ee1d2e808685fcf5ea1abbf6 2006.0/x86_64/MySQL-Max-4.1.12-4.10.20060mdk.x86_64.rpm
adc04989620b1683064bceca1cc1f997 2006.0/x86_64/MySQL-NDB-4.1.12-4.10.20060mdk.x86_64.rpm
65f2714658fbaa7194aa6a9e35bea114 2006.0/SRPMS/MySQL-4.1.12-4.10.20060mdk.src.rpm

Corporate 3.0:
323307ba6f7102132a1cb8443a75e66c corporate/3.0/i586/libmysql12-4.0.18-1.11.C30mdk.i586.rpm
49c8f4902afaceb40a5d02484b8698b0 corporate/3.0/i586/libmysql12-devel-4.0.18-1.11.C30mdk.i586.rpm
b0610cd3eef31b8264c9d87f214ae974 corporate/3.0/i586/MySQL-4.0.18-1.11.C30mdk.i586.rpm
99122a2f538b7705392589376204ccb8 corporate/3.0/i586/MySQL-bench-4.0.18-1.11.C30mdk.i586.rpm
ebfc7f7d062943f19fdc21e7b4a7c2d6 corporate/3.0/i586/MySQL-client-4.0.18-1.11.C30mdk.i586.rpm
7a57faae42e4291c023440d71c334694 corporate/3.0/i586/MySQL-common-4.0.18-1.11.C30mdk.i586.rpm
5b72f88050ce6ff4baf59050d4f1e105 corporate/3.0/i586/MySQL-Max-4.0.18-1.11.C30mdk.i586.rpm
bace43f39e7de6cca61705269164ff26 corporate/3.0/SRPMS/MySQL-4.0.18-1.11.C30mdk.src.rpm

Corporate 3.0/X86_64:
9b4551d3c2cbbd83f2d648281e281fb7 corporate/3.0/x86_64/lib64mysql12-4.0.18-1.11.C30mdk.x86_64.rpm
4bb8482468f2c5d8f949d3b70c18bec5 corporate/3.0/x86_64/lib64mysql12-devel-4.0.18-1.11.C30mdk.x86_64.rpm
e840471dd81001b0bcf6eecb5fe15b7b corporate/3.0/x86_64/MySQL-4.0.18-1.11.C30mdk.x86_64.rpm
9de8c944a34e0a1245f076c59e8a116e corporate/3.0/x86_64/MySQL-bench-4.0.18-1.11.C30mdk.x86_64.rpm
2ad4b05e6082164ca3aaa0444b2a1560 corporate/3.0/x86_64/MySQL-client-4.0.18-1.11.C30mdk.x86_64.rpm
a9a07403bf8c415d72ab28fd224cec31 corporate/3.0/x86_64/MySQL-common-4.0.18-1.11.C30mdk.x86_64.rpm
bd267d5fe073af1ce9b36e18713f18db corporate/3.0/x86_64/MySQL-Max-4.0.18-1.11.C30mdk.x86_64.rpm
bace43f39e7de6cca61705269164ff26 corporate/3.0/SRPMS/MySQL-4.0.18-1.11.C30mdk.src.rpm

Multi Network Firewall 2.0:
6bfd646483d072e2b53f9eee29279f93 mnf/2.0/i586/libmysql12-4.0.18-1.11.M20mdk.i586.rpm
dfaed993c2887c8ff6bae73d28bd8448 mnf/2.0/SRPMS/MySQL-4.0.18-1.11.M20mdk.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>


Mandriva Linux Security Advisory MDKSA-2006:178
http://www.mandriva.com/security/


Package : ntp
Date : October 2, 2006
Affected: 2006.0, 2007.0, Corporate 4.0


Problem Description:

Openssl recently had several vulnerabilities which were patched (CVE-2006-2937,2940,3738,4339, 4343). Some versions of ntp are built against a static copy of the SSL libraries. As a precaution an updated copy built against the new libraries in being made available.


Updated Packages:

Mandriva Linux 2006.0:
98c8d5fa78f53e234fbe25720dd7c64e 2006.0/i586/ntp-4.2.0-21.2.20060mdk.i586.rpm
690334db340a7418fd42f31f3ef0092b 2006.0/i586/ntp-client-4.2.0-21.2.20060mdk.i586.rpm
615821f6def15f16d1add3ef4db74584 2006.0/SRPMS/ntp-4.2.0-21.2.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
69b70d3b9c86494a072c1897a41c62a4 2006.0/x86_64/ntp-4.2.0-21.2.20060mdk.x86_64.rpm
55e6f0121357ff75a3963f779b83621f 2006.0/x86_64/ntp-client-4.2.0-21.2.20060mdk.x86_64.rpm
615821f6def15f16d1add3ef4db74584 2006.0/SRPMS/ntp-4.2.0-21.2.20060mdk.src.rpm

Mandriva Linux 2007.0:
4b1e5dc60377ee51d9369269a82672b4 2007.0/i586/ntp-4.2.0-31.2mdv2007.0.i586.rpm
6a2eca6a384e49006d39a1d2af6eb4b4 2007.0/i586/ntp-client-4.2.0-31.2mdv2007.0.i586.rpm
b3c8e254ab51edad15cec56a931873f4 2007.0/SRPMS/ntp-4.2.0-31.2mdv2007.0.src.rpm

Mandriva Linux 2007.0/X86_64:
9a17e864f1d5d2b5b6990729ea94c371 2007.0/x86_64/ntp-4.2.0-31.2mdv2007.0.x86_64.rpm
d267c0c5bfec9691572555e5147e459d 2007.0/x86_64/ntp-client-4.2.0-31.2mdv2007.0.x86_64.rpm
b3c8e254ab51edad15cec56a931873f4 2007.0/SRPMS/ntp-4.2.0-31.2mdv2007.0.src.rpm

Corporate 4.0:
90da334ac6d246c3b62c5ed9734f7047 corporate/4.0/i586/ntp-4.2.0-21.2.20060mlcs4.i586.rpm
ba752440cb884a7451e1f3efc877c9d9 corporate/4.0/i586/ntp-client-4.2.0-21.2.20060mlcs4.i586.rpm
27f37e1e3d5ea1b4bd19cfb57a501659 corporate/4.0/SRPMS/ntp-4.2.0-21.2.20060mlcs4.src.rpm

Corporate 4.0/X86_64:
19aaa620b9533f90f145b77ca6bddf2b corporate/4.0/x86_64/ntp-4.2.0-21.2.20060mlcs4.x86_64.rpm
0aeb37acab5364abb19fd6af5cc33f87 corporate/4.0/x86_64/ntp-client-4.2.0-21.2.20060mlcs4.x86_64.rpm
27f37e1e3d5ea1b4bd19cfb57a501659 corporate/4.0/SRPMS/ntp-4.2.0-21.2.20060mlcs4.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>

Ubuntu


Ubuntu Security Notice USN-354-1 October 02, 2006
firefox vulnerabilities
CVE-2006-3113, CVE-2006-3677, CVE-2006-3801, CVE-2006-3802, CVE-2006-3803, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-3810, CVE-2006-3811, CVE-2006-3812, CVE-2006-4253, CVE-2006-4340, CVE-2006-4565, CVE-2006-4566, CVE-2006-4567, CVE-2006-4568, CVE-2006-4569, CVE-2006-4571

A security issue affects the following Ubuntu releases:

Ubuntu 5.10

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

Ubuntu 5.10:

firefox 1.5.dfsg+1.5.0.7-0ubuntu5.10.3
firefox-dom-inspector 1.5.dfsg+1.5.0.7-0ubuntu5.10.3
firefox-gnome-support 1.5.dfsg+1.5.0.7-0ubuntu5.10.3
devhelp 0.10-1ubuntu2.1
devhelp-common 0.10-1ubuntu2.1
epiphany-browser 1.8.2-0ubuntu1.1
epiphany-browser-dev 1.8.2-0ubuntu1.1
gnome-app-install 0+20051005.1
libdevhelp-1-0 0.10-1ubuntu2.1
libdevhelp-1-dev 0.10-1ubuntu2.1
mozilla-firefox-locale-af-za 1.5-ubuntu5.10-1
mozilla-firefox-locale-ast-es 1.5-ubuntu5.10-1
mozilla-firefox-locale-bg-bg 1.5-ubuntu5.10-1
mozilla-firefox-locale-cs-cz 1.5-ubuntu5.10-1
mozilla-firefox-locale-da-dk 1.5-ubuntu5.10-1
mozilla-firefox-locale-de 1.5-ubuntu5.10-1
mozilla-firefox-locale-de-de 1.5-ubuntu5.10-1
mozilla-firefox-locale-en-gb 1.5-ubuntu5.10-1
mozilla-firefox-locale-es 1.5-ubuntu5.10-1
mozilla-firefox-locale-es-ar 1.5-ubuntu5.10-1
mozilla-firefox-locale-es-es 1.5-ubuntu5.10-1
mozilla-firefox-locale-fi-fi 1.5-ubuntu5.10-1
mozilla-firefox-locale-fr 1.5-ubuntu5.10-1
mozilla-firefox-locale-fr-fr 1.5-ubuntu5.10-1
mozilla-firefox-locale-ga-ie 1.5-ubuntu5.10-1
mozilla-firefox-locale-gu-in 1.5-ubuntu5.10-1
mozilla-firefox-locale-he-il 1.5-ubuntu5.10-1
mozilla-firefox-locale-hu-hu 1.5-ubuntu5.10-1
mozilla-firefox-locale-mk-mk 1.5-ubuntu5.10-1
mozilla-firefox-locale-nl-nl 1.5-ubuntu5.10-1
mozilla-firefox-locale-pa-in 1.5-ubuntu5.10-1
mozilla-firefox-locale-pl 1.5-ubuntu5.10-1
mozilla-firefox-locale-pl-pl 1.5-ubuntu5.10-1
mozilla-firefox-locale-pt-br 1.5-ubuntu5.10-1
mozilla-firefox-locale-pt-pt 1.5-ubuntu5.10-1
mozilla-firefox-locale-ro-ro 1.5-ubuntu5.10-1
mozilla-firefox-locale-ru-ru 1.5-ubuntu5.10-1
mozilla-firefox-locale-sl-si 1.5-ubuntu5.10-1
mozilla-firefox-locale-sq-al 1.5-ubuntu5.10-1
mozilla-firefox-locale-sv 1.5-ubuntu5.10-1
mozilla-firefox-locale-sv-se 1.5-ubuntu5.10-1
mozilla-firefox-locale-tr-tr 1.5-ubuntu5.10-1
mozilla-firefox-locale-xh-za 1.5-ubuntu5.10-1
mozilla-firefox-locale-zh-cn 1.5-ubuntu5.10-1
mozilla-firefox-locale-zh-tw 1.5-ubuntu5.10-1
yelp 2.12.1-0ubuntu1.1

After a standard system upgrade you need to restart Firefox to effect the necessary changes. Since the 1.0.x series of Firefox is not supported any more, this update introduces the firefox 1.5 series into Ubuntu 5.10. Please check whether all your extensions still work as expected.

Details follow:

Various flaws have been reported that allow an attacker to execute arbitrary code with user privileges by tricking the user into opening a malicious URL. (CVE-2006-3113, CVE-2006-3677, CVE-2006-3801, CVE-2006-3803, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3809, CVE-2006-3811, CVE-2006-3812, CVE-2006-4253, CVE-2006-4565, CVE-2006-4566, CVE-2006-4568, CVE-2006-4569 CVE-2006-4571)

Cross-site scripting vulnerabilities were found in the XPCNativeWrapper() function and native DOM method handlers. A malicious web site could exploit these to modify the contents or steal confidential data (such as passwords) from other opened web pages. (CVE-2006-3802, CVE-2006-3810)

A bug was found in the script handler for automatic proxy configuration. A malicious proxy could send scripts which could execute arbitrary code with the user's privileges. (CVE-2006-3808)

The NSS library did not sufficiently check the padding of PKCS #1 v1.5 signatures if the exponent of the public key is 3 (which is widely used for CAs). This could be exploited to forge valid signatures without the need of the secret key. (CVE-2006-4340)

Jon Oberheide reported a way how a remote attacker could trick users into downloading arbitrary extensions with circumventing the normal SSL certificate check. The attacker would have to be in a position to spoof the victim's DNS, causing them to connect to sites of the attacker's choosing rather than the sites intended by the victim. If they gained that control and the victim accepted the attacker's cert for the Mozilla update site, then the next update check could be hijacked and redirected to the attacker's site without detection. (CVE-2006-4567)

Packages which embed or extend Firefox have been updated to work with the new version.

Updated packages for Ubuntu 5.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_1.5.dfsg+1.5.0.7-0ubuntu5.10.3.diff.gz
      Size/MD5: 175367 a26d52d72d57fa4447cdc6c4d8120d9e
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_1.5.dfsg+1.5.0.7-0ubuntu5.10.3.dsc
      Size/MD5: 1056 b9d557cd0d8d2105dde2c669d958ac18
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_1.5.dfsg+1.5.0.7.orig.tar.gz
      Size/MD5: 43116523 025ca9a48809d142dd4817e396157afa
    http://security.ubuntu.com/ubuntu/pool/main/d/devhelp/devhelp_0.10-1ubuntu2.1.diff.gz
      Size/MD5: 12508 2d1f8e2d37966901a16125834c48a5ae
    http://security.ubuntu.com/ubuntu/pool/main/d/devhelp/devhelp_0.10-1ubuntu2.1.dsc
      Size/MD5: 1674 50224ab103882c85e8584773f70d0b0b
    http://security.ubuntu.com/ubuntu/pool/main/d/devhelp/devhelp_0.10.orig.tar.gz
      Size/MD5: 532744 79e71acb839ca504f37cccf2e520abe1
    http://security.ubuntu.com/ubuntu/pool/main/e/epiphany-browser/epiphany-browser_1.8.2-0ubuntu1.1.diff.gz
      Size/MD5: 13906 7351cceba02fb251087d19c9fada3539
    http://security.ubuntu.com/ubuntu/pool/main/e/epiphany-browser/epiphany-browser_1.8.2-0ubuntu1.1.dsc
      Size/MD5: 2223 f1784da472d75a158d5008b72db78c29
    http://security.ubuntu.com/ubuntu/pool/main/e/epiphany-browser/epiphany-browser_1.8.2.orig.tar.gz
      Size/MD5: 4657374 2232bfd4090f9f9187c84bc46f785471
    http://security.ubuntu.com/ubuntu/pool/main/g/gnome-app-install/gnome-app-install_0+20051005.1.dsc
      Size/MD5: 616 5b63f100196cc122a0d14fb10128fe0a
    http://security.ubuntu.com/ubuntu/pool/main/g/gnome-app-install/gnome-app-install_0+20051005.1.tar.gz
      Size/MD5: 2722120 c1b93c90799172e7939737b685849028
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-all_1.5-ubuntu5.10-1.diff.gz
      Size/MD5: 17550 75aba6066f369b482725b6ecafe351b5
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-all_1.5-ubuntu5.10-1.dsc
      Size/MD5: 1711 8643261713bcaededc638c59ddb5a639
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-all_1.5-ubuntu5.10.orig.tar.gz
      Size/MD5: 3834374 cbb9bc1c91c73b100a134ffef3527575
    http://security.ubuntu.com/ubuntu/pool/main/y/yelp/yelp_2.12.1-0ubuntu1.1.diff.gz
      Size/MD5: 10203 52a694c6ae7dd1b2cf47d23fa405cb32
    http://security.ubuntu.com/ubuntu/pool/main/y/yelp/yelp_2.12.1-0ubuntu1.1.dsc
      Size/MD5: 1716 a81a9690f6ae9313f143764f1577353e
    http://security.ubuntu.com/ubuntu/pool/main/y/yelp/yelp_2.12.1.orig.tar.gz
      Size/MD5: 1126243 8e4a9cdacb146ee9094281a2a809de1b

Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/universe/f/firefox/mozilla-firefox-dev_1.5.dfsg+1.5.0.7-0ubuntu5.10.3_all.deb
      Size/MD5: 49450 a96a7f73505926f9670b5db1507d8a63
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/mozilla-firefox_1.5.dfsg+1.5.0.7-0ubuntu5.10.3_all.deb
      Size/MD5: 50340 822d93a2f02f32e0c4b05e6a0d18d251
    http://security.ubuntu.com/ubuntu/pool/main/d/devhelp/devhelp-common_0.10-1ubuntu2.1_all.deb
      Size/MD5: 42554 d3a1266307910c8d97cf0a61765f6be6
    http://security.ubuntu.com/ubuntu/pool/main/e/epiphany-browser/epiphany-browser-dev_1.8.2-0ubuntu1.1_all.deb
      Size/MD5: 155316 985cbd3ceba8913d1c6b658634f5515f
    http://security.ubuntu.com/ubuntu/pool/main/g/gnome-app-install/gnome-app-install_0+20051005.1_all.deb
      Size/MD5: 2363516 2951dc5a3fa5363484a2ded4e9d63525
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-af-za_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 14920 3d8b3b0207b6dbbd50a18f44124be44d
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-ast-es_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 14922 ce395b5cb94745bccc6d339aeaa47af6
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla-firefox-locale-all/mozilla-firefox-locale-bg-bg_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 177054 301d8b790f931e8fced7d729462b119f
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-cs-cz_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 167818 1130c3f572b0c3212e19db196869e6c1
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-da-dk_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 156822 16dd2084e870f2b103e31475bab8fbc2
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-de-de_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 156254 ec05416b5cf4a1404834a91aa7780636
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla-firefox-locale-all/mozilla-firefox-locale-de_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 14948 47a942dd614f3690468ace7dfce944a4
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-en-gb_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 153066 c6ef3d6a1796a7187064d8dd8efade2d
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-es-ar_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 160414 c2d04fa793a6c8537921825ad9d3fed3
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-es-es_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 146512 7c879206052a84628f2cb1dba61225a2
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla-firefox-locale-all/mozilla-firefox-locale-es_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 14962 45b0b022da96d82426e0379789e76115
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-fi-fi_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 157538 dc7d6ba83a34dc635d5ba13a6e00fb85
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-fr-fr_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 218898 08bac23bc1814781169971c79e340029
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla-firefox-locale-all/mozilla-firefox-locale-fr_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 14952 cc5d3ba9021d9c7935e88820c3b1cb22
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-ga-ie_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 159686 6e7cfaad656bd78d391e87d3efdaf15c
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla-firefox-locale-all/mozilla-firefox-locale-gu-in_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 176464 071b3ed411c73bd2e4b3de929c59e17a
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-he-il_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 159710 61f6d12b159c9769ec245cafd3a44416
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-hu-hu_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 168628 ff688d627228681bd3578e4193ec85bc
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla-firefox-locale-all/mozilla-firefox-locale-mk-mk_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 176372 b2d833c6ec5a6a7be6d65cbcd852d4d6
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-nl-nl_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 166614 2ad5e24d1ab820968e352198acafe73b
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla-firefox-locale-all/mozilla-firefox-locale-pa-in_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 166320 4a3310c669c84b411c556de9be00c9ae
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-pl-pl_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 256734 8fd75e6450ea6c262259d3f5c97ed0d6
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla-firefox-locale-all/mozilla-firefox-locale-pl_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 14950 d9e41ad5ebd9fa22e4e6368ccdb84e56
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-pt-br_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 158306 2ebf181536dfc4fabf7264459d8168d9
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-pt-pt_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 14918 cde145bb4308469314341fdce0df4150
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-ro-ro_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 157404 74e2fda0bbddc1ae9494d971b8b94000
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-ru-ru_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 184988 10a5c4a5bfbbb5564e512f307d3affd0
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-sl-si_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 159592 a12d61905553ac247cdd5cabfbea8266
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla-firefox-locale-all/mozilla-firefox-locale-sq-al_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 14920 3cf47efcf547af1eefcb9a37468d9264
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-sv-se_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 169870 60dd6cd5b9c870fc03bd89d8ad8ba68b
    http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla-firefox-locale-all/mozilla-firefox-locale-sv_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 14952 716f89f697d527336ddc754422b61f9e
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-tr-tr_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 150822 e655fabf918cde4d5dbec858198dfc2b
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-xh-za_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 14924 5d0a3d18420c2dceb9943098b1cc5edb
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-zh-cn_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 150806 2bf7032ceccd2f2691d4210711ce533b
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox-locale-all/mozilla-firefox-locale-zh-tw_1.5-ubuntu5.10-1_all.deb
      Size/MD5: 141592 c4ab2103bcd210600bf2180b57e4c0a4

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-dev_1.5.dfsg+1.5.0.7-0ubuntu5.10.3_amd64.deb
      Size/MD5: 3151994 d6fbafaa57ddf56a5d2c15d0d0b7a54a
    http://security.ubuntu.com/ubuntu/pool/universe/f/firefox/firefox-dom-inspector_1.5.dfsg+1.5.0.7-0ubuntu5.10.3_amd64.deb
      Size/MD5: 216360 ada223fd220cc75f1cf061cd44294a1c
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-gnome-support_1.5.dfsg+1.5.0.7-0ubuntu5.10.3_amd64.deb
      Size/MD5: 82664 be7890c0fa145f6a1e76e9abdbfd500f
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_1.5.dfsg+1.5.0.7-0ubuntu5.10.3_amd64.deb
      Size/MD5: 10222068 bccb7d71de1abbe3036fe130d5f5d1a0
    http://security.ubuntu.com/ubuntu/pool/main/d/devhelp/devhelp_0.10-1ubuntu2.1_amd64.deb
      Size/MD5: 48324 ad3fbfef83d3cf097e377be6dd9e0f75
    http://security.ubuntu.com/ubuntu/pool/main/e/epiphany-browser/epiphany-browser_1.8.2-0ubuntu1.1_amd64.deb
      Size/MD5: 2079044 4aee57db6320497c7739f70ef350f752
    http://security.ubuntu.com/ubuntu/pool/main/d/devhelp/libdevhelp-1-0_0.10-1ubuntu2.1_amd64.deb
      Size/MD5: 72862 1e41cee42bd67a3dbe0aaf4d9b1d8bae
    http://security.ubuntu.com/ubuntu/pool/main/d/devhelp/libdevhelp-1-dev_0.10-1ubuntu2.1_amd64.deb
      Size/MD5: 71654 6a79359848bfa3324b9619db75431060
    http://security.ubuntu.com/ubuntu/pool/main/y/yelp/yelp_2.12.1-0ubuntu1.1_amd64.deb
      Size/MD5: 229922 b1f9ca522767d93f64e59ada4fe01ec7

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-dev_1.5.dfsg+1.5.0.7-0ubuntu5.10.3_i386.deb
      Size/MD5: 3152010 59a8bc4edc49fcd2ec6a0b905ae3b4fe
    http://security.ubuntu.com/ubuntu/pool/universe/f/firefox/firefox-dom-inspector_1.5.dfsg+1.5.0.7-0ubuntu5.10.3_i386.deb
      Size/MD5: 209884 8ec25aa9f564f83747edc4998a54a7e1
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-gnome-support_1.5.dfsg+1.5.0.7-0ubuntu5.10.3_i386.deb
      Size/MD5: 75022 1e84dccc6587ae34f3f201c21d15e8b6
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_1.5.dfsg+1.5.0.7-0ubuntu5.10.3_i386.deb
      Size/MD5: 8644430 4c998b81cbdd13cff81cbf77c18edf9b
    http://security.ubuntu.com/ubuntu/pool/main/d/devhelp/devhelp_0.10-1ubuntu2.1_i386.deb
      Size/MD5: 48072 c032680500dc8c5d47ef50cf458c8bb0
    http://security.ubuntu.com/ubuntu/pool/main/e/epiphany-browser/epiphany-browser_1.8.2-0ubuntu1.1_i386.deb
      Size/MD5: 2036736 50122be5b65d5cbfe84a3f103be32100
    http://security.ubuntu.com/ubuntu/pool/main/d/devhelp/libdevhelp-1-0_0.10-1ubuntu2.1_i386.deb
      Size/MD5: 69370 1b0c3dbdf68c4026c39e4a20cd32f4f1
    http://security.ubuntu.com/ubuntu/pool/main/d/devhelp/libdevhelp-1-dev_0.10-1ubuntu2.1_i386.deb
      Size/MD5: 65234 838439c919084ee33c3f36a82d51d0a9
    http://security.ubuntu.com/ubuntu/pool/main/y/yelp/yelp_2.12.1-0ubuntu1.1_i386.deb
      Size/MD5: 220626 2b86b96b577e9c67b68aeb92a37e7ef1

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-dev_1.5.dfsg+1.5.0.7-0ubuntu5.10.3_powerpc.deb
      Size/MD5: 3152066 ecbc956d8fdd0b70cda57dad123005af
    http://security.ubuntu.com/ubuntu/pool/universe/f/firefox/firefox-dom-inspector_1.5.dfsg+1.5.0.7-0ubuntu5.10.3_powerpc.deb
      Size/MD5: 213294 e83df33479eb5a7c075394ad48c2686c
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-gnome-support_1.5.dfsg+1.5.0.7-0ubuntu5.10.3_powerpc.deb
      Size/MD5: 78272 3702fb290fc9a477f43b72372d9e9029
    http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_1.5.dfsg+1.5.0.7-0ubuntu5.10.3_powerpc.deb
      Size/MD5: 9826234 5bedd17d1e16eff3e1876798e675350f
    http://security.ubuntu.com/ubuntu/pool/main/d/devhelp/devhelp_0.10-1ubuntu2.1_powerpc.deb
      Size/MD5: 49832 84caef479729caf65c18e90bc3f023a1
    http://security.ubuntu.com/ubuntu/pool/main/e/epiphany-browser/epiphany-browser_1.8.2-0ubuntu1.1_powerpc.deb
      Size/MD5: 2056216 e384f64d7861c356659504e4c440be81
    http://security.ubuntu.com/ubuntu/pool/main/d/devhelp/libdevhelp-1-0_0.10-1ubuntu2.1_powerpc.deb
      Size/MD5: 70986 15343da493ea42d99fc5a9ac63e398f6
    http://security.ubuntu.com/ubuntu/pool/main/d/devhelp/libdevhelp-1-dev_0.10-1ubuntu2.1_powerpc.deb
      Size/MD5: 72078 e55e86a842651dddefef98ab21ddb106
    http://security.ubuntu.com/ubuntu/pool/main/y/yelp/yelp_2.12.1-0ubuntu1.1_powerpc.deb
      Size/MD5: 225382 7f30ecd915d851c66791fbfddebb5c49


Ubuntu Security Notice USN-355-1 October 02, 2006
openssh vulnerabilities
CVE-2006-4924, CVE-2006-5051

A security issue affects the following Ubuntu releases:

Ubuntu 5.04
Ubuntu 5.10
Ubuntu 6.06 LTS

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

Ubuntu 5.04:
openssh-server 1:3.9p1-1ubuntu2.3

Ubuntu 5.10:
openssh-server 1:4.1p1-7ubuntu4.2

Ubuntu 6.06 LTS:
openssh-server 1:4.2p1-7ubuntu3.1

In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

Tavis Ormandy discovered that the SSH daemon did not properly handle authentication packets with duplicated blocks. By sending specially crafted packets, a remote attacker could exploit this to cause the ssh daemon to drain all available CPU resources until the login grace time expired. (CVE-2006-4924)

Mark Dowd discovered a race condition in the server's signal handling. A remote attacker could exploit this to crash the server. (CVE-2006-5051)

Updated packages for Ubuntu 5.04:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh_3.9p1-1ubuntu2.3.diff.gz
      Size/MD5: 143243 ee5b491cf023e53b4991fe319da669aa
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh_3.9p1-1ubuntu2.3.dsc
      Size/MD5: 866 237dcc91dde3201ba0bc5b9372654708
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh_3.9p1.orig.tar.gz
      Size/MD5: 832804 530b1dcbfe7a4a4ce4959c0775b85a5a

Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh_3.9p1-1ubuntu2.3_all.deb
      Size/MD5: 31312 a25012353606283dbae09b56dc60f1bb

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-udeb_3.9p1-1ubuntu2.3_amd64.udeb
      Size/MD5: 166846 b0507203d786efa365cef305acc0b790
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_3.9p1-1ubuntu2.3_amd64.deb
      Size/MD5: 544562 4464ce148432194666a3fd7fae5b884f
    http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-server-udeb_3.9p1-1ubuntu2.3_amd64.udeb
      Size/MD5: 179290 2774b437173889390312fab14a0d9edf
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_3.9p1-1ubuntu2.3_amd64.deb
      Size/MD5: 279624 deb54b320447ab79b8d8fb351c04960d
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnome_3.9p1-1ubuntu2.3_amd64.deb
      Size/MD5: 62924 083fd0c899ed8c0c088f6f659d2fd017

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-udeb_3.9p1-1ubuntu2.3_i386.udeb
      Size/MD5: 139452 31deaca18b94b27d52c1870d86810db4
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_3.9p1-1ubuntu2.3_i386.deb
      Size/MD5: 492810 8df816ca89945adc93e80d49f53aebe6
    http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-server-udeb_3.9p1-1ubuntu2.3_i386.udeb
      Size/MD5: 149160 632d59e71b6a3f5aab50e4cfd3842442
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_3.9p1-1ubuntu2.3_i386.deb
      Size/MD5: 256218 5f9791afb335d57cd1a830c1e886ee08
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnome_3.9p1-1ubuntu2.3_i386.deb
      Size/MD5: 62512 9f21ce3a1134980ec47c1e99cf62ff61

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-udeb_3.9p1-1ubuntu2.3_powerpc.udeb
      Size/MD5: 159886 447da8535b3b4c0b85fefd44e01f4c4d
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_3.9p1-1ubuntu2.3_powerpc.deb
      Size/MD5: 541254 8d16c7e18fef84ab8f6a435c8c988b93
    http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-server-udeb_3.9p1-1ubuntu2.3_powerpc.udeb
      Size/MD5: 163428 e0ca6e79f907c35e2c32e515b8e808dd
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_3.9p1-1ubuntu2.3_powerpc.deb
      Size/MD5: 273640 c8e00fcbe413ac902ccc4dca508572f2
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnome_3.9p1-1ubuntu2.3_powerpc.deb
      Size/MD5: 64092 a88a46209fac664959c35b36fb93066e

Updated packages for Ubuntu 5.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh_4.1p1-7ubuntu4.2.diff.gz
      Size/MD5: 158624 fc0f2620cc3fc07ad4ea050b675e5f1b
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh_4.1p1-7ubuntu4.2.dsc
      Size/MD5: 971 cd61da4d0742c684aaf90b8390252818
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh_4.1p1.orig.tar.gz
      Size/MD5: 909689 3709109adf0b82176668b3d3478dd033

Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh_4.1p1-7ubuntu4.2_all.deb
      Size/MD5: 1050 d520acb54639c9b900b973c08e1a5fe8

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-udeb_4.1p1-7ubuntu4.2_amd64.udeb
      Size/MD5: 162614 0e4e07c663d0f33f3fd73a0b6c2e433a
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_4.1p1-7ubuntu4.2_amd64.deb
      Size/MD5: 584852 bb1ac6382aa349a7bea3cccf0948117e
    http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-server-udeb_4.1p1-7ubuntu4.2_amd64.udeb
      Size/MD5: 179490 a1bccf78a412d6799d25f0ca73ab4623
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_4.1p1-7ubuntu4.2_amd64.deb
      Size/MD5: 223914 ec3d782f9c3b88c97cea3b928e458fea
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnome_4.1p1-7ubuntu4.2_amd64.deb
      Size/MD5: 78228 02951ff37cc638222a067c77b808523d

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-udeb_4.1p1-7ubuntu4.2_i386.udeb
      Size/MD5: 138272 3a49a90c6f6f9f52c775aeecb05caf76
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_4.1p1-7ubuntu4.2_i386.deb
      Size/MD5: 515080 0100950f90ddd99704be28b2c9ff8478
    http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-server-udeb_4.1p1-7ubuntu4.2_i386.udeb
      Size/MD5: 149782 c89f7310123da769a7eec86d6ba72a6a
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_4.1p1-7ubuntu4.2_i386.deb
      Size/MD5: 195292 7cf57e81b03dce633eb56bdc44655c89
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnome_4.1p1-7ubuntu4.2_i386.deb
      Size/MD5: 77944 15d8e58dd24c85d380432bc3b7a633c7

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-udeb_4.1p1-7ubuntu4.2_powerpc.udeb
      Size/MD5: 155858 f4f64f9b3de12bfc043661e8e31d090c
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_4.1p1-7ubuntu4.2_powerpc.deb
      Size/MD5: 569144 baabd24742192f1df2ceb5220d540937
    http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-server-udeb_4.1p1-7ubuntu4.2_powerpc.udeb
      Size/MD5: 163322 42064b77c600c04ba5441876830a772d
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_4.1p1-7ubuntu4.2_powerpc.deb
      Size/MD5: 215386 c4360aa642d117f539ff2d1082ae705b
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnome_4.1p1-7ubuntu4.2_powerpc.deb
      Size/MD5: 79512 e25ff733bd60854f7a42cfa0c636eb7d

sparc architecture (Sun SPARC/UltraSPARC)

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-udeb_4.1p1-7ubuntu4.2_sparc.udeb
      Size/MD5: 147902 13d070c8101686ef53e062c136d609be
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_4.1p1-7ubuntu4.2_sparc.deb
      Size/MD5: 524974 c67b3c3cd75b37b9e10d03033e657c7c
    http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-server-udeb_4.1p1-7ubuntu4.2_sparc.udeb
      Size/MD5: 158836 a425ab0c6cbc9ae5dd09a4880a36e374
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_4.1p1-7ubuntu4.2_sparc.deb
      Size/MD5: 199192 85892b06e6780bba357d9c68ff36e0fd
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnome_4.1p1-7ubuntu4.2_sparc.deb
      Size/MD5: 77982 ab47361323b0a7686fe4fad3639df44d

Updated packages for Ubuntu 6.06 LTS:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh_4.2p1-7ubuntu3.1.diff.gz
      Size/MD5: 171326 3d966ce050b176961a34c8f14148ef18
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh_4.2p1-7ubuntu3.1.dsc
      Size/MD5: 1005 acf698bd9a5e848b80343a49b3ab5f5b
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh_4.2p1.orig.tar.gz
      Size/MD5: 928420 93295701e6bcd76fabd6a271654ed15c

Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh_4.2p1-7ubuntu3.1_all.deb
      Size/MD5: 1056 ff5c9e1bc32aac160738d603fb3c9015

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-udeb_4.2p1-7ubuntu3.1_amd64.udeb
      Size/MD5: 165846 e483c01679c325ac0edeb5981cdba060
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_4.2p1-7ubuntu3.1_amd64.deb
      Size/MD5: 610616 5a5b73f2d68a90385b2dd70c539cfb4a
    http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-server-udeb_4.2p1-7ubuntu3.1_amd64.udeb
      Size/MD5: 182038 bc2c80a21f2afde523a17e311233ebc5
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_4.2p1-7ubuntu3.1_amd64.deb
      Size/MD5: 236212 90663453b5c114622627469f4ffd822a
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnome_4.2p1-7ubuntu3.1_amd64.deb
      Size/MD5: 86868 12bbd3d97943ce3751a3186494c31798

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-udeb_4.2p1-7ubuntu3.1_i386.udeb
      Size/MD5: 140068 8873836c923eb3205df376916b0c3669
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_4.2p1-7ubuntu3.1_i386.deb
      Size/MD5: 536704 801dcb0f46badf9ff4376a4484663b00
    http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-server-udeb_4.2p1-7ubuntu3.1_i386.udeb
      Size/MD5: 151544 28e22a72700630c00231c843662ed755
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_4.2p1-7ubuntu3.1_i386.deb
      Size/MD5: 205490 7e5acb93eb0243e1272f1ffed0145112
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnome_4.2p1-7ubuntu3.1_i386.deb
      Size/MD5: 86476 091d1ca0ef964b1cbc714cb050ef558d

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-udeb_4.2p1-7ubuntu3.1_powerpc.udeb
      Size/MD5: 158524 ae42600aed557c45556394035eacd10a
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_4.2p1-7ubuntu3.1_powerpc.deb
      Size/MD5: 593628 29d5510f526ddfa16a138b1d61c1cc75
    http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-server-udeb_4.2p1-7ubuntu3.1_powerpc.udeb
      Size/MD5: 165942 d5d1c6333c9406b1bf623b4db1c8824a
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_4.2p1-7ubuntu3.1_powerpc.deb
      Size/MD5: 226264 166b3da3dd64758a38f7731dc0c16703
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnome_4.2p1-7ubuntu3.1_powerpc.deb
      Size/MD5: 88152 2860a81b3d8d554f5356bab74573504b

sparc architecture (Sun SPARC/UltraSPARC)

    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-udeb_4.2p1-7ubuntu3.1_sparc.udeb
      Size/MD5: 149224 5f60da6926ed8b994cdc8dcf42b65088
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_4.2p1-7ubuntu3.1_sparc.deb
      Size/MD5: 543560 c9003ef5e14236a26d3b3a7abb25db9f
    http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-server-udeb_4.2p1-7ubuntu3.1_sparc.udeb
      Size/MD5: 160664 51e52151d74fd317648700234478e638
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_4.2p1-7ubuntu3.1_sparc.deb
      Size/MD5: 208870 6833a77599010cfe464f54bf0290b516
    http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnome_4.2p1-7ubuntu3.1_sparc.deb
      Size/MD5: 86516 8dac0a82e5edaabfac6f8596a84ff884


Ubuntu Security Notice USN-356-1 October 02, 2006
gdb vulnerability
CVE-2006-4146

A security issue affects the following Ubuntu releases:

Ubuntu 5.04
Ubuntu 5.10
Ubuntu 6.06 LTS

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

Ubuntu 5.04:
gdb 6.3-5ubuntu1.2

Ubuntu 5.10:
gdb 6.3-6ubuntu2.1

Ubuntu 6.06 LTS:
gdb 6.4-1ubuntu5.1

In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

Will Drewry, of the Google Security Team, discovered buffer overflows in GDB's DWARF processing. This would allow an attacker to execute arbitrary code with user privileges by tricking the user into using GDB to load an executable that contained malicious debugging information.

Updated packages for Ubuntu 5.04:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-5ubuntu1.2.diff.gz
      Size/MD5: 153643 e778f57ab6b5e5cd8a25f341dea386d2
    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-5ubuntu1.2.dsc
      Size/MD5: 837 5d33b1de3070cc590724be1c5e4fbc6a
    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3.orig.tar.gz
      Size/MD5: 17374476 812de9e756d53c749ea5516d9ffa5905

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-5ubuntu1.2_amd64.deb
      Size/MD5: 2952220 1f8fa48cd5e17e4b453daa59e4b420a2

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-5ubuntu1.2_i386.deb
      Size/MD5: 2648450 b4c9fb6a83e310e881875395bf1aad2d

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-5ubuntu1.2_powerpc.deb
      Size/MD5: 4047224 8208cb25191742da0764d92b7a1f638a

Updated packages for Ubuntu 5.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-6ubuntu2.1.diff.gz
      Size/MD5: 155595 d6fffb81e21b1f3c9d94de74c99e391b
    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-6ubuntu2.1.dsc
      Size/MD5: 837 fad531a07b7820254e5f9a6e46299a30
    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3.orig.tar.gz
      Size/MD5: 17374476 812de9e756d53c749ea5516d9ffa5905

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-6ubuntu2.1_amd64.deb
      Size/MD5: 3013838 05ff0877c090fd168f390f8f56164aac

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-6ubuntu2.1_i386.deb
      Size/MD5: 2647276 5c3884902f84eae7c261b1bbb1806152

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-6ubuntu2.1_powerpc.deb
      Size/MD5: 4123126 af6da76ce945b6e2867f7834ba00a42e

sparc architecture (Sun SPARC/UltraSPARC)

    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-6ubuntu2.1_sparc.deb
      Size/MD5: 2802006 d8816a2ea175c3f3949716157bfa195d

Updated packages for Ubuntu 6.06 LTS:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.4-1ubuntu5.1.diff.gz
      Size/MD5: 49396 b7d66d72f16c73371c3fdd73d0bf8128
    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.4-1ubuntu5.1.dsc
      Size/MD5: 791 7daf4d5cd11ed554e6f675355fb29cdf
    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.4.orig.tar.gz
      Size/MD5: 18508095 7dc98022ee96bba5331f195dc8a5491a

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.4-1ubuntu5.1_amd64.deb
      Size/MD5: 3089952 2f9c6efaca60dd3c92246f515e50a6fe

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.4-1ubuntu5.1_i386.deb
      Size/MD5: 2700670 24c99faef3d69502f34212adc45aa0f5

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.4-1ubuntu5.1_powerpc.deb
      Size/MD5: 4208002 83aef6ee330108b55587c8cd048e13f7

sparc architecture (Sun SPARC/UltraSPARC)

    http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.4-1ubuntu5.1_sparc.deb
      Size/MD5: 2824562 c38ce8413d8a9a7e363d0ff15d89544f



No talkbacks posted.
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!

..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP