Linux Today: Linux News On Internet Time.
Search Linux Today
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Server Daily
IT Management Daily
Subscribe News
Subscribe PR
Subscribe Security

internet.com
Internet News
Small Business

Advertise
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

20 popular Ubuntu Linux apps you may want to try

A Selection of the Very Best Open Source Tutorials and Tools

Android Ice Cream Sandwich ported to x86 tablets, netbooks and notebooks

SECURITY: Google Chrome 17 Improves Security

How to read a CSV file in Perl?

Red Hat Brings Gluster to Amazon Cloud

New Linux kernel fixes power-saving issues

Using Wii remote with Android Device- Taking Gaming to the Next Level

Commercial Support now available for the open-source NGINX Web server

Linux Top 5: Linux's New Fellow



Applications Management Engineer Sr (NYC)
Next Step Systems
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume
:Advisories, November 30, 2006
Advisories, November 30, 2006
Dec 1, 2006, 04 :45 UTC (0 Talkback[s]) (2759 reads)

Debian GNU/Linux


Debian Security Advisory DSA 1221-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
November 30th, 2006 http://www.debian.org/security/faq


Package : libgsf
Vulnerability : buffer overflow
Problem type : local (remote)
Debian-specific: no

"infamous41md" discovered a heap buffer overflow vulnerability in libgsf, a GNOME library for reading and writing structured file formats, which could lead to the execution of arbitrary code.

For the stable distribution (sarge) this problem has been fixed in version 1.11.1-1sarge1

For the unstable distribution (sid) this problem has been fixed in version 1.14.2-1

We recommend that you upgrade your libgsf packages.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given at the end of this advisory:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf_1.11.1-1sarge1.dsc
      Size/MD5 checksum: 837 bc96a9630b2605bdd8091a0f3f934f09
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf_1.11.1-1sarge1.diff.gz
      Size/MD5 checksum: 7678 23aa764ba57e0ec811916b78bf986917
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf_1.11.1.orig.tar.gz
      Size/MD5 checksum: 572284 d3260e0411c3a972c4f5bf3f2d1fbdf3

Alpha architecture:

    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_alpha.deb
      Size/MD5 checksum: 107854 37c60803868436da0effcaaac0eb3261
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_alpha.deb
      Size/MD5 checksum: 84542 869400c0b10cab3e7a1e353091c15138
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_alpha.deb
      Size/MD5 checksum: 211104 d80136fdc38edad9f97f2fc335a13c87
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_alpha.deb
      Size/MD5 checksum: 42524 3c201fc969af6fc144ddfa9d308ca7d9
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_alpha.deb
      Size/MD5 checksum: 10796 56f4a381eaadbc54ad5da1515fc02a28
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_alpha.deb
      Size/MD5 checksum: 50690 a134d813591188748c8237b76ca07eff

AMD64 architecture:

    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_amd64.deb
      Size/MD5 checksum: 95598 741f5e3cf1276c57a862c6c32989bf45
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_amd64.deb
      Size/MD5 checksum: 72884 f1440dcac0f635ef12ecaf9321e19741
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_amd64.deb
      Size/MD5 checksum: 172702 751adb98ffb3ae93b849c56bdfda3e35
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_amd64.deb
      Size/MD5 checksum: 41496 5d8b547d18ec67bc74e577341e9127fe
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_amd64.deb
      Size/MD5 checksum: 10274 c974e8cf41208991a4994274aed34cf4
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_amd64.deb
      Size/MD5 checksum: 47474 36ccd40752ff3e33d220494388e82ba3

ARM architecture:

    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_arm.deb
      Size/MD5 checksum: 92054 81c8e51b0f1a565c2c7975ca00c54aef
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_arm.deb
      Size/MD5 checksum: 71122 4983eeffaa1ef96a18eabbb6eff072d6
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_arm.deb
      Size/MD5 checksum: 171650 addecc2d0f2e2e9b9e0973af85e4d6d5
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_arm.deb
      Size/MD5 checksum: 41006 7631c2c831ccb352ee3eaafa1ae08501
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_arm.deb
      Size/MD5 checksum: 9650 0bef0c46800914370452657c52827a7b
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_arm.deb
      Size/MD5 checksum: 47752 6446fcefbd64ec916cac67dd7629746d

HP Precision architecture:

    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_hppa.deb
      Size/MD5 checksum: 109452 00cf9a2ea0ae3c7c77407ac31899f577
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_hppa.deb
      Size/MD5 checksum: 87188 90c3ca91f8fadd35a892f94b975b4303
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_hppa.deb
      Size/MD5 checksum: 184032 272c9099df0279b1da9eb533e64f4a8c
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_hppa.deb
      Size/MD5 checksum: 42832 a4270866dd0ee896a1754ec02fdea6a2
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_hppa.deb
      Size/MD5 checksum: 11366 6af045e1bd59419b2abbd1a065e83263
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_hppa.deb
      Size/MD5 checksum: 48450 cfb513337e4b16dca1ae5b939739b02b

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_i386.deb
      Size/MD5 checksum: 94438 b70e154e2bc349b763da552b36563c41
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_i386.deb
      Size/MD5 checksum: 71724 cc4fd9cd9e3150632fdb600f61926d16
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_i386.deb
      Size/MD5 checksum: 165774 75f1cda5fe58d7fa1e32e059ff56aa5c
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_i386.deb
      Size/MD5 checksum: 41418 0462a3a69e5f6391f2d84609803af28c
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_i386.deb
      Size/MD5 checksum: 10002 2296a2ef95208dd25b1245e5596fad8a
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_i386.deb
      Size/MD5 checksum: 47022 dad57213a389b1c396940c6420b2a6d3

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_ia64.deb
      Size/MD5 checksum: 120382 00ae4c44067d719530f10345b907b39d
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_ia64.deb
      Size/MD5 checksum: 96808 219ae265d340982c4fcc625f0f4aac2e
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_ia64.deb
      Size/MD5 checksum: 207722 321d9e0e5f245a1460934be4c53b3485
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_ia64.deb
      Size/MD5 checksum: 44498 73ce9eb8ceb61f3eb5bdebc2f7fbd97a
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_ia64.deb
      Size/MD5 checksum: 13112 7114570dd9b7d2ccae2482e8a9749836
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_ia64.deb
      Size/MD5 checksum: 50314 0e341aa4f2d297c21b50c07ea5b022e5

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_m68k.deb
      Size/MD5 checksum: 93418 3241ab0596f2a1be8758b0df6f0b1b91
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_m68k.deb
      Size/MD5 checksum: 70380 76e2fbd85c632cc917dbdd4631eaeab1
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_m68k.deb
      Size/MD5 checksum: 159350 ad3e05a11cfc6950f5366e586af28c44
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_m68k.deb
      Size/MD5 checksum: 41064 ccc2b9e4e7cd38f48d633c509b8359ba
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_m68k.deb
      Size/MD5 checksum: 9520 13f4d5efeeb5033221455c053b52ef8e
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_m68k.deb
      Size/MD5 checksum: 46432 ba90a1e901880066827139232f828e41

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_mips.deb
      Size/MD5 checksum: 95486 47af6ae61145d336e6d67cb66572fa2c
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_mips.deb
      Size/MD5 checksum: 71142 4d50bc59c572fb8de56626b17a96716c
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_mips.deb
      Size/MD5 checksum: 181358 4680c5668264c0660f5915f5490a9862
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_mips.deb
      Size/MD5 checksum: 41328 e14b22945be8551fe477286239829702
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_mips.deb
      Size/MD5 checksum: 9502 a65d4536f7d5a7e217930f665acd1ce4
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_mips.deb
      Size/MD5 checksum: 48412 062423f994430f2f458f72ff1c11aa60

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_mipsel.deb
      Size/MD5 checksum: 95064 12574be55cbd0f0d161d438eb3681132
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_mipsel.deb
      Size/MD5 checksum: 71040 2ef8b71ca0069594121861ea8f1cb138
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_mipsel.deb
      Size/MD5 checksum: 181248 5b1d0d0d255bd232630232b944c90de3
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_mipsel.deb
      Size/MD5 checksum: 41342 61d8b2256e13a2f42101eaaac777f147
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_mipsel.deb
      Size/MD5 checksum: 9534 090bc4a1110ad678cc31f878a7f625fe
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_mipsel.deb
      Size/MD5 checksum: 48484 8e6b7e08584b30d39676e324e8d2f160

PowerPC architecture:

    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_powerpc.deb
      Size/MD5 checksum: 97424 a5fe077b6c128e6d3707f54f25446793
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_powerpc.deb
      Size/MD5 checksum: 76080 80b8cfd0da0406e51e0650b31f6b855b
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_powerpc.deb
      Size/MD5 checksum: 175872 c8608277b96bc3b9fe1c9acab58df7f5
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_powerpc.deb
      Size/MD5 checksum: 42750 40d7d2fe820e4fe563ad45a52a993882
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_powerpc.deb
      Size/MD5 checksum: 12502 f67804ec2e5e233f6eba20a306c87d0f
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_powerpc.deb
      Size/MD5 checksum: 47456 67f2eab4c5e7626021e0203de6dd45b0

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_s390.deb
      Size/MD5 checksum: 104934 b4f495487d1d69c57bae68b1710c3c34
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_s390.deb
      Size/MD5 checksum: 82180 ce2e17b2cb7894fe75f70bf6c0e3e3c8
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_s390.deb
      Size/MD5 checksum: 179024 a117c2b0ff8c3ba57c950872d1dcbe63
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_s390.deb
      Size/MD5 checksum: 42410 1e4cd37bee40b3064120794ffa40ed61
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_s390.deb
      Size/MD5 checksum: 10518 6bf95840b71480e8a040bf7795af7bae
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_s390.deb
      Size/MD5 checksum: 47984 a8ffd9f03d9e884f1b919ef8e31a2ef0

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_sparc.deb
      Size/MD5 checksum: 95404 99a1f0843ed4865942a214b1f6cf5b2d
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_sparc.deb
      Size/MD5 checksum: 72240 af4c9ac2d4fb67f66f27cb7e2effd99f
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_sparc.deb
      Size/MD5 checksum: 168950 0848099749ef6395067268f3331b7da4
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_sparc.deb
      Size/MD5 checksum: 41156 ade5d9a99a9140a319fd885cb48d8161
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_sparc.deb
      Size/MD5 checksum: 9438 04f6af54df0a761be766ccab9deba73c
    http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_sparc.deb
      Size/MD5 checksum: 47262 97392dc7cab74baee5953c66d46fa894

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 1222-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
November 30th, 2006 http://www.debian.org/security/faq


Package : proftpd
Vulnerability : several
Problem-Type : remote
Debian-specific: no
CVE ID : CVE-2006-5815 CVE-2006-6170 CVE-2006-6171
Debian Bug : 399070

Several remote vulnerabilities have been discovered in the proftpd FTP daemon, which may lead to the execution of arbitrary code or denial of service. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2006-5815

It was discovered that a buffer overflow in the sreplace() function may lead to denial of service and possibly the execution of arbitrary code.

CVE-2006-6170

It was discovered that a buffer overflow in the mod_tls addon module may lead to the execution of arbitrary code.

CVE-2006-6171

It was discovered that insufficient validation of FTP command buffer size limits may lead to denial of service. Due to unclear information this issue was already fixed in DSA-1218 as CVE-2006-5815.

For the stable distribution (sarge) these problem has been fixed in version 1.2.10-15sarge3.

For the unstable distribution (sid) this problem has been fixed in version 1.3.0-16 of the proftpd-dfsg package.

We recommend that you upgrade your proftpd package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3.dsc
      Size/MD5 checksum: 897 d4dea6caa9438bea9d260f20761393ec
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3.diff.gz
      Size/MD5 checksum: 128340 4f14cee4723b725983eed3d7d9e7fe39
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10.orig.tar.gz
      Size/MD5 checksum: 920495 7d2bc5b4b1eef459a78e55c027a4f3c4

Architecture independent components:

    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-doc_1.2.10-15sarge3_all.deb
      Size/MD5 checksum: 422614 c673d2a4e9db616bca66e8c2f992a95d

Alpha architecture:

    http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_alpha.deb
      Size/MD5 checksum: 444532 d4950ecc709597f04a379e4a3f5644f9
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_alpha.deb
      Size/MD5 checksum: 200874 92481cca4bbbce0f0db4fb16ac0c53af
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_alpha.deb
      Size/MD5 checksum: 457334 b730aa7d3ff1c08d08bca66168686626
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_alpha.deb
      Size/MD5 checksum: 476906 15a84985231a886c2d9cfaa108edad31
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_alpha.deb
      Size/MD5 checksum: 476588 3ae27f992a26986872cfc4e26af3add5

ARM architecture:

    http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_arm.deb
      Size/MD5 checksum: 373966 1c371d644b23ffa23ae4cdb847237048
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_arm.deb
      Size/MD5 checksum: 188856 094b34ff2e629e4a2e34a40632130782
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_arm.deb
      Size/MD5 checksum: 384130 3a073b4e2ce0a4c006b021bc2a70713c
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_arm.deb
      Size/MD5 checksum: 399002 52a258d6db3529dc42f93b3377166f48
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_arm.deb
      Size/MD5 checksum: 398846 010ff68a50710591d79e6791a36ebe4e

HP Precision architecture:

    http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_hppa.deb
      Size/MD5 checksum: 403768 625a4174453f9aae518fecf9e4f6cffd
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_hppa.deb
      Size/MD5 checksum: 194534 d69950a0728249287a953efd0e256d95
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_hppa.deb
      Size/MD5 checksum: 414946 26cd4464a72e49bf3dd7bae1e6bcb4c5
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_hppa.deb
      Size/MD5 checksum: 431866 880875bdcf2aa45c40af333a205a9386
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_hppa.deb
      Size/MD5 checksum: 431612 82c75ec629e6408d19f8b7f4e1704e0b

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_i386.deb
      Size/MD5 checksum: 371322 3fa4ccac9c73bc8c19e075ed49f01a42
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_i386.deb
      Size/MD5 checksum: 188924 2bdb4609055c6a77ef45e376f43bb6b8
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_i386.deb
      Size/MD5 checksum: 381022 5cc5974e4124b09a5c3a7a04fc4c0dfb
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_i386.deb
      Size/MD5 checksum: 396780 1e05de59c612c3b59a0384c6b728909c
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_i386.deb
      Size/MD5 checksum: 396546 e7e49a7c96f3c5f1a335bdce31b4a41d

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_ia64.deb
      Size/MD5 checksum: 519752 379b681d8139096f30c07adaf360a258
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_ia64.deb
      Size/MD5 checksum: 207072 6a7a86411c903cfe92848369d8939dc9
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_ia64.deb
      Size/MD5 checksum: 535426 f6e1da6b7febf2b374ce3d9cf844596e
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_ia64.deb
      Size/MD5 checksum: 562386 6b9476b33d3eb98e87cda796ef3e1cba
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_ia64.deb
      Size/MD5 checksum: 562222 ddaf242f3d24e951b9578f2bf37ae4c7

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_m68k.deb
      Size/MD5 checksum: 332616 7f28eb7a6612422159554511d20c565c
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_m68k.deb
      Size/MD5 checksum: 187212 97853824e6e354d30d08e5d4f92f866a
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_m68k.deb
      Size/MD5 checksum: 340948 7cb0f9de38603efd2becbaf8a767860d
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_m68k.deb
      Size/MD5 checksum: 353236 b8afaa29deb9a2aaa5826fefd92ee051
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_m68k.deb
      Size/MD5 checksum: 352866 dddab5e89fc109de3892f100d5ea702d

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_mips.deb
      Size/MD5 checksum: 382502 88e5ef3fca660e28577a39db65f0743b
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_mips.deb
      Size/MD5 checksum: 201698 9a79029722afde2e9f9881323f09f523
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_mips.deb
      Size/MD5 checksum: 391960 847c19048ee9c921abbcedb0742be96d
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_mips.deb
      Size/MD5 checksum: 406524 d89d533478c0e5f9997869122173e627
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_mips.deb
      Size/MD5 checksum: 406246 f12661492861e6c6f94f5f2ae57318d4

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_mipsel.deb
      Size/MD5 checksum: 384380 83f0858fa68da448e561f9cfd48fedab
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_mipsel.deb
      Size/MD5 checksum: 201916 8a197d293f4c7d735bd0584ec6ec74ee
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_mipsel.deb
      Size/MD5 checksum: 393456 45fb0f0a6f79be0ebab17ebf7305340f
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_mipsel.deb
      Size/MD5 checksum: 409566 4d33f9e7c059949a27704379228b7119
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_mipsel.deb
      Size/MD5 checksum: 409366 5ee8e0e4dc1c831a2f56ff92404ea1c8

PowerPC architecture:

    http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_powerpc.deb
      Size/MD5 checksum: 384536 67c443041e0f5fdc280952fe849f6905
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_powerpc.deb
      Size/MD5 checksum: 195440 cf7b974f9f75e96ff9eb60afd64ceac0
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_powerpc.deb
      Size/MD5 checksum: 395224 3ef2ae27f6234f181b2934f8656d47a0
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_powerpc.deb
      Size/MD5 checksum: 412098 160500875d6d666fe89ff3590767f205
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_powerpc.deb
      Size/MD5 checksum: 411734 baf2f4a518503428bd46c7528adf3ed0

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_s390.deb
      Size/MD5 checksum: 379718 c33ac1f5e3afa17837d6b8a6b46173bc
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_s390.deb
      Size/MD5 checksum: 193048 f1533436a3741501e67ca8a10781b274
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_s390.deb
      Size/MD5 checksum: 390196 865bc00469365ae23db91d9a86ef201f
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_s390.deb
      Size/MD5 checksum: 404046 022be9231922608c55613044285a367e
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_s390.deb
      Size/MD5 checksum: 403780 a182f9bada4a850d9103f76a6024521a

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_sparc.deb
      Size/MD5 checksum: 369766 1ebaaa6c12ee1db33142347ad7bd2256
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_sparc.deb
      Size/MD5 checksum: 189086 370817d19ca97068c40263ebc64a4345
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_sparc.deb
      Size/MD5 checksum: 379560 5d3c311d57939b9d6ccc262ad9226845
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_sparc.deb
      Size/MD5 checksum: 394922 119cdba979f469fce53f1311d15b9ab1
    http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_sparc.deb
      Size/MD5 checksum: 394722 ebb293c93ebceaa14edd1ceacc64a3d8

These files will probably be moved into the stable distribution on its next update.


For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

Gentoo Linux


Gentoo Linux Security Advisory GLSA 200611-26

http://security.gentoo.org/


Severity: High
Title: ProFTPD: Remote execution of arbitrary code
Date: November 30, 2006
Bugs: #154650
ID: 200611-26


Synopsis

ProFTPD is affected by mutiple vulnerabilities allowing for the remote execution of arbitrary code.

Background

ProFTPD is a highly-configurable FTP server.

Affected packages


Package / Vulnerable / Unaffected
1 net-ftp/proftpd < 1.3.0a >= 1.3.0a

Description

Evgeny Legerov discovered a stack-based buffer overflow in the s_replace() function in support.c, as well as a buffer overflow in in the mod_tls module. Additionally, an off-by-two error related to the CommandBufferSize configuration directive was reported.

Impact

An authenticated attacker could exploit the s_replace() vulnerability by uploading a crafted .message file or sending specially crafted commands to the server, possibly resulting in the execution of arbitrary code with the rights of the user running ProFTPD. An unauthenticated attacker could send specially crafted data to the server with mod_tls enabled which could result in the execution of arbitrary code with the rights of the user running ProFTPD. Finally, the off-by-two error related to the CommandBufferSize configuration directive was fixed - exploitability of this error is disputed. Note that the default configuration on Gentoo is to run ProFTPD as an unprivileged user, and has mod_tls disabled.

Workaround

There is no known workaround at this time.

Resolution

All ProFTPD users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=net-ftp/proftpd-1.3.0a"

References

[ 1 ] CVE-2006-5815

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5815

[ 2 ] CVE-2006-6170

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6170

[ 3 ] CVE-2006-6171 (disputed)

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6171

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200611-26.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5

Mandriva Linux


Mandriva Linux Security Advisory MDKSA-2006:217-1
http://www.mandriva.com/security/


Package : proftpd
Date : November 30, 2006
Affected: 2006.0, 2007.0, Corporate 3.0, Corporate 4.0


Problem Description:

A stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier, allows remote attackers to cause a denial of service, as demonstrated by vd_proftpd.pm, a "ProFTPD remote exploit." (CVE-2006-5815)

Buffer overflow in the tls_x509nameoneline function in the mod_tls module, as used in ProFTPD 1.3.0a and earlier, and possibly other products, allows remote attackers to execute arbitrary code via a large data length argument, a different vulnerability than CVE-2006-5815. (CVE-2006-6170)

ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to an off-by-two buffer underflow. NOTE: in November 2006, the role of CommandBufferSize was originally associated with CVE-2006-5815, but this was an error stemming from an initial vague disclosure. NOTE: ProFTPD developers dispute this issue, saying that the relevant memory location is overwritten by assignment before further use within the affected function, so this is not a vulnerability. (CVE-2006-6171)

Packages have been patched to correct these issues.

Update:

The previous update incorrectly linked the vd_proftd.pm issue with the CommandBufferSize issue. These are two distinct issues and the previous update only addressed CommandBufferSize (CVE-2006-6171), and the mod_tls issue (CVE-2006-6170).


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5815
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6170
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6171


Updated Packages:

Mandriva Linux 2006.0:
b1cd1e2584e59418a20260b3f3332208 2006.0/i586/proftpd-1.2.10-13.3.20060mdk.i586.rpm
979d14f8aa6312dac64948e1e9445f33 2006.0/i586/proftpd-anonymous-1.2.10-13.3.20060mdk.i586.rpm
1d446921049eb39f91f0450a0ff74018 2006.0/SRPMS/proftpd-1.2.10-13.3.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
80f43de2dcf0aab1956552ef2a93c1b5 2006.0/x86_64/proftpd-1.2.10-13.3.20060mdk.x86_64.rpm
62862e2c1c5c870946406beb2b982237 2006.0/x86_64/proftpd-anonymous-1.2.10-13.3.20060mdk.x86_64.rpm
1d446921049eb39f91f0450a0ff74018 2006.0/SRPMS/proftpd-1.2.10-13.3.20060mdk.src.rpm

Mandriva Linux 2007.0:
a37912e678d6dbfe2ed21a2c432e029c 2007.0/i586/proftpd-1.3.0-4.3mdv2007.0.i586.rpm
89b3d4beac485d4879295ad99a17cd1b 2007.0/i586/proftpd-anonymous-1.3.0-4.3mdv2007.0.i586.rpm
c206fc94fd81a8f79a158efe6e0fa8fb 2007.0/i586/proftpd-mod_autohost-1.3.0-4.3mdv2007.0.i586.rpm
6ba12b916446da7651ced303cd5c2f0a 2007.0/i586/proftpd-mod_case-1.3.0-4.3mdv2007.0.i586.rpm
a3d6b7c829345d6edf9f22efb8369b58 2007.0/i586/proftpd-mod_clamav-1.3.0-4.3mdv2007.0.i586.rpm
a51a76a0e93f638018a15a28d67d1bc6 2007.0/i586/proftpd-mod_ctrls_admin-1.3.0-4.3mdv2007.0.i586.rpm
458913aaa82dd80691b08e69c2d7a68e 2007.0/i586/proftpd-mod_facl-1.3.0-4.3mdv2007.0.i586.rpm
3e929da8229f69a9c2c8702f2c79bbfe 2007.0/i586/proftpd-mod_gss-1.3.0-4.3mdv2007.0.i586.rpm
9c7ad69945b176c59f682a750ba0da86 2007.0/i586/proftpd-mod_ifsession-1.3.0-4.3mdv2007.0.i586.rpm
de0dd2a5354bdd79842c84dd0698ae80 2007.0/i586/proftpd-mod_ldap-1.3.0-4.3mdv2007.0.i586.rpm
84255d9b701a430fdebc8ffa0804462d 2007.0/i586/proftpd-mod_load-1.3.0-4.3mdv2007.0.i586.rpm
5a9dea0cc961f50a772f0c7f6d04fb2c 2007.0/i586/proftpd-mod_quotatab-1.3.0-4.3mdv2007.0.i586.rpm
da44806b650245adadee9227d60fed35 2007.0/i586/proftpd-mod_quotatab_file-1.3.0-4.3mdv2007.0.i586.rpm
c2fd38d0ab3e324e377a0a83449bdcfc 2007.0/i586/proftpd-mod_quotatab_ldap-1.3.0-4.3mdv2007.0.i586.rpm
db3864770f8aa649190e84ac04c7d26a 2007.0/i586/proftpd-mod_quotatab_sql-1.3.0-4.3mdv2007.0.i586.rpm
1f1a0e13808bfe3179c1142d2cfc76bd 2007.0/i586/proftpd-mod_radius-1.3.0-4.3mdv2007.0.i586.rpm
93f3736a42145559e9faffa16c68271d 2007.0/i586/proftpd-mod_ratio-1.3.0-4.3mdv2007.0.i586.rpm
ce6ce9b9340c328ff0956481fe9ee5ff 2007.0/i586/proftpd-mod_rewrite-1.3.0-4.3mdv2007.0.i586.rpm
8c7089d22b32a863691fcf1ff3c1b6bf 2007.0/i586/proftpd-mod_shaper-1.3.0-4.3mdv2007.0.i586.rpm
23b8d3f76708ce59d83bf07a6c19034d 2007.0/i586/proftpd-mod_site_misc-1.3.0-4.3mdv2007.0.i586.rpm
845b77cc6c4c2f4eb8c4a41d369afe3d 2007.0/i586/proftpd-mod_sql-1.3.0-4.3mdv2007.0.i586.rpm
7d98b511040ce3a9c16ca38fad98cdc7 2007.0/i586/proftpd-mod_sql_mysql-1.3.0-4.3mdv2007.0.i586.rpm
44bdd048bac956a52adae56b429419a8 2007.0/i586/proftpd-mod_sql_postgres-1.3.0-4.3mdv2007.0.i586.rpm
bece7d223e81935362115874debc625f 2007.0/i586/proftpd-mod_time-1.3.0-4.3mdv2007.0.i586.rpm
b655b11679c1d46750397f647499d113 2007.0/i586/proftpd-mod_tls-1.3.0-4.3mdv2007.0.i586.rpm
f051af523f306a8547cc232df6af61b0 2007.0/i586/proftpd-mod_wrap-1.3.0-4.3mdv2007.0.i586.rpm
ea415328f16a7c86c530b1628e9e7119 2007.0/i586/proftpd-mod_wrap_file-1.3.0-4.3mdv2007.0.i586.rpm
40cc7355b7baea00dc0ca3d9fbb23d54 2007.0/i586/proftpd-mod_wrap_sql-1.3.0-4.3mdv2007.0.i586.rpm
56f9c85b919e81120ef5c9f95c5fbb70 2007.0/SRPMS/proftpd-1.3.0-4.3mdv2007.0.src.rpm

Mandriva Linux 2007.0/X86_64:
a3f7f06d36e939decedbfbd73b068a00 2007.0/x86_64/proftpd-1.3.0-4.3mdv2007.0.x86_64.rpm
e57974563e6a6a856997ece7ae4223f3 2007.0/x86_64/proftpd-anonymous-1.3.0-4.3mdv2007.0.x86_64.rpm
351f1bcb4148bb3e2d42e4f8b63866bb 2007.0/x86_64/proftpd-mod_autohost-1.3.0-4.3mdv2007.0.x86_64.rpm
5244e4fe2899727b8ed9ff8c2108e835 2007.0/x86_64/proftpd-mod_case-1.3.0-4.3mdv2007.0.x86_64.rpm
6945e72c1af1e29f0e8a4f851fde7c04 2007.0/x86_64/proftpd-mod_clamav-1.3.0-4.3mdv2007.0.x86_64.rpm
eaeba816574a28d65c243d70c55a2be7 2007.0/x86_64/proftpd-mod_ctrls_admin-1.3.0-4.3mdv2007.0.x86_64.rpm
4b61ef08a72e13acf1c245efda94e14d 2007.0/x86_64/proftpd-mod_facl-1.3.0-4.3mdv2007.0.x86_64.rpm
599338063d6b3358c92bc675748a5276 2007.0/x86_64/proftpd-mod_gss-1.3.0-4.3mdv2007.0.x86_64.rpm
113e48693e6f717523f53d7bd362f167 2007.0/x86_64/proftpd-mod_ifsession-1.3.0-4.3mdv2007.0.x86_64.rpm
0afda1fa0eb473074bbf591b87c205f5 2007.0/x86_64/proftpd-mod_ldap-1.3.0-4.3mdv2007.0.x86_64.rpm
d5f67ae4a0057ac1574446d53a2b01c2 2007.0/x86_64/proftpd-mod_load-1.3.0-4.3mdv2007.0.x86_64.rpm
24598aaa7594f1c3cce8104c0691fd89 2007.0/x86_64/proftpd-mod_quotatab-1.3.0-4.3mdv2007.0.x86_64.rpm
ae6875064975d76b2f2ce5c2cee3c4cf 2007.0/x86_64/proftpd-mod_quotatab_file-1.3.0-4.3mdv2007.0.x86_64.rpm
a383a4b78ec3e492563c9ef542c2a701 2007.0/x86_64/proftpd-mod_quotatab_ldap-1.3.0-4.3mdv2007.0.x86_64.rpm
eccf357b396c651538df038d7c480516 2007.0/x86_64/proftpd-mod_quotatab_sql-1.3.0-4.3mdv2007.0.x86_64.rpm
0b41852744c4493629eb1d71c8091c8a 2007.0/x86_64/proftpd-mod_radius-1.3.0-4.3mdv2007.0.x86_64.rpm
93d8f354acd5a7e25478b9bbd3319617 2007.0/x86_64/proftpd-mod_ratio-1.3.0-4.3mdv2007.0.x86_64.rpm
332c8e76e5a93e5011caeb3fbf9d8d7d 2007.0/x86_64/proftpd-mod_rewrite-1.3.0-4.3mdv2007.0.x86_64.rpm
03aed52b479f6bf0affa3a697aebe47d 2007.0/x86_64/proftpd-mod_shaper-1.3.0-4.3mdv2007.0.x86_64.rpm
4ea161e9f3821a3f90a2e19f22fdb487 2007.0/x86_64/proftpd-mod_site_misc-1.3.0-4.3mdv2007.0.x86_64.rpm
ef8473f399c9fab49b174438e9f57f1a 2007.0/x86_64/proftpd-mod_sql-1.3.0-4.3mdv2007.0.x86_64.rpm
e77455dd400984b833dd3bf52b6c9876 2007.0/x86_64/proftpd-mod_sql_mysql-1.3.0-4.3mdv2007.0.x86_64.rpm
b194fe453ab8f2d900f49a8fee4d8a43 2007.0/x86_64/proftpd-mod_sql_postgres-1.3.0-4.3mdv2007.0.x86_64.rpm
26177d8de2b31e25d54458f125a4bef6 2007.0/x86_64/proftpd-mod_time-1.3.0-4.3mdv2007.0.x86_64.rpm
27cab8a3a4bf0162e4e4aeb8f2235c18 2007.0/x86_64/proftpd-mod_tls-1.3.0-4.3mdv2007.0.x86_64.rpm
0eebacf7e2aacf1893e6f077a05deade 2007.0/x86_64/proftpd-mod_wrap-1.3.0-4.3mdv2007.0.x86_64.rpm
e1c973141f23a99f1a1e5cfad06ba507 2007.0/x86_64/proftpd-mod_wrap_file-1.3.0-4.3mdv2007.0.x86_64.rpm
ea8918c00be656f8c5c1be6e7e5c29cc 2007.0/x86_64/proftpd-mod_wrap_sql-1.3.0-4.3mdv2007.0.x86_64.rpm
56f9c85b919e81120ef5c9f95c5fbb70 2007.0/SRPMS/proftpd-1.3.0-4.3mdv2007.0.src.rpm

Corporate 3.0:
05c8ada8f0f64c13e392bacea28a57c3 corporate/3.0/i586/proftpd-1.2.9-3.6.C30mdk.i586.rpm
38d0c4fb80b8511d4fc60e29b76c2329 corporate/3.0/i586/proftpd-anonymous-1.2.9-3.6.C30mdk.i586.rpm
fd2a42044333ba3528899e65e6028b28 corporate/3.0/SRPMS/proftpd-1.2.9-3.6.C30mdk.src.rpm

Corporate 3.0/X86_64:
c76e71ec99c373b351a69b33d09e0328 corporate/3.0/x86_64/proftpd-1.2.9-3.6.C30mdk.x86_64.rpm
6a7866fb417a3ba020caad45f7696a1d corporate/3.0/x86_64/proftpd-anonymous-1.2.9-3.6.C30mdk.x86_64.rpm
fd2a42044333ba3528899e65e6028b28 corporate/3.0/SRPMS/proftpd-1.2.9-3.6.C30mdk.src.rpm

Corporate 4.0:
3a74dd621c2836818d884faa26577379 corporate/4.0/i586/proftpd-1.2.10-20.3.20060mlcs4.i586.rpm
75fa75338ed57f5d0aeb137ca7efe521 corporate/4.0/i586/proftpd-anonymous-1.2.10-20.3.20060mlcs4.i586.rpm
f2f48f3379be27c86e4edc1a9cb53d53 corporate/4.0/SRPMS/proftpd-1.2.10-20.3.20060mlcs4.src.rpm

Corporate 4.0/X86_64:
b2e043f4ad4b4045ae0f09074be55327 corporate/4.0/x86_64/proftpd-1.2.10-20.3.20060mlcs4.x86_64.rpm
8524b1da761c3f24f3b0dd0d9a0139b7 corporate/4.0/x86_64/proftpd-anonymous-1.2.10-20.3.20060mlcs4.x86_64.rpm
f2f48f3379be27c86e4edc1a9cb53d53 corporate/4.0/SRPMS/proftpd-1.2.10-20.3.20060mlcs4.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>

Ubuntu


Ubuntu Security Notice USN-389-1 November 29, 2006
gnupg vulnerability
http://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000241.html

A security issue affects the following Ubuntu releases:

Ubuntu 5.10
Ubuntu 6.06 LTS
Ubuntu 6.10

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

Ubuntu 5.10:
gnupg 1.4.1-1ubuntu1.5

Ubuntu 6.06 LTS:
gnupg 1.4.2.2-1ubuntu2.3

Ubuntu 6.10:
gnupg 1.4.3-2ubuntu3.1

In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

A buffer overflow was discovered in GnuPG. By tricking a user into running gpg interactively on a specially crafted message, an attacker could execute arbitrary code with the user's privileges. This vulnerability is not exposed when running gpg in batch mode.

Updated packages for Ubuntu 5.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.1-1ubuntu1.5.diff.gz
      Size/MD5: 21914 9c398c7ad981984ce7e2d5c73d39646c
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.1-1ubuntu1.5.dsc
      Size/MD5: 684 99674acf9842bede50bfc9cee94233bc
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.1.orig.tar.gz
      Size/MD5: 4059170 1cc77c6943baaa711222e954bbd785e5

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.1-1ubuntu1.5_amd64.deb
      Size/MD5: 1136516 6f95cee543adea0d34af0db0270e8301
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.1-1ubuntu1.5_amd64.udeb
      Size/MD5: 152280 91e6fec1a7cac200e6607a5aca8e283c

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.1-1ubuntu1.5_i386.deb
      Size/MD5: 1044704 511314c5de795b3f732fbc48fa9bc245
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.1-1ubuntu1.5_i386.udeb
      Size/MD5: 130672 c2af84edf925cf93e92df0afd1747a8b

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.1-1ubuntu1.5_powerpc.deb
      Size/MD5: 1119908 d942ad0abd5921bb771fd6180d32f28b
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.1-1ubuntu1.5_powerpc.udeb
      Size/MD5: 140214 ac880f5f3a32fe0bba76d61ef5374f61

sparc architecture (Sun SPARC/UltraSPARC)

    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.1-1ubuntu1.5_sparc.deb
      Size/MD5: 1064488 49125a2b181ce9e4ca22b67b6712b153
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.1-1ubuntu1.5_sparc.udeb
      Size/MD5: 139606 f97c2b5b2f406afb0cc8478df8529a1c

Updated packages for Ubuntu 6.06 LTS:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.2.2-1ubuntu2.3.diff.gz
      Size/MD5: 20808 4208a73338b5624d39f355e553927548
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.2.2-1ubuntu2.3.dsc
      Size/MD5: 690 858b47da7b535136aa99ab7ccbd2aaef
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.2.2.orig.tar.gz
      Size/MD5: 4222685 50d8fd9c5715ff78b7db0e5f20d08550

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.2.2-1ubuntu2.3_amd64.deb
      Size/MD5: 1066374 7e03df9183620a5c23db7caefb3f5b2b
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.2.2-1ubuntu2.3_amd64.udeb
      Size/MD5: 140312 9384b3aa9a950db2bb80ad20f820529c

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.2.2-1ubuntu2.3_i386.deb
      Size/MD5: 981392 75eba5633769eb5c8e4fbd863d0ffed9
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.2.2-1ubuntu2.3_i386.udeb
      Size/MD5: 120284 5ab02d409b4b475657f5c52081d3ccf9

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.2.2-1ubuntu2.3_powerpc.deb
      Size/MD5: 1053850 43d575debcff4457419d48f78d164449
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.2.2-1ubuntu2.3_powerpc.udeb
      Size/MD5: 130154 9491f62000cc12df6f23b8d66fd97859

sparc architecture (Sun SPARC/UltraSPARC)

    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.2.2-1ubuntu2.3_sparc.deb
      Size/MD5: 994040 09848e3252cae2efeefeef913e4ef9d5
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.2.2-1ubuntu2.3_sparc.udeb
      Size/MD5: 127412 56d3912d3002bf3f0377a6437a6f851c

Updated packages for Ubuntu 6.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.3-2ubuntu3.1.diff.gz
      Size/MD5: 25822 be04724ca7e6d4dcf2a016ebe2d4bd25
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.3-2ubuntu3.1.dsc
      Size/MD5: 697 446e892916ea052627a78152037651d9
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.3.orig.tar.gz
      Size/MD5: 4320394 fcdf572a33dd037653707b128dd150a7

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg/gnupg-udeb_1.4.3-2ubuntu3.1_amd64.udeb
      Size/MD5: 379748 635660a16621f2d7cc752e61cf926208
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.3-2ubuntu3.1_amd64.deb
      Size/MD5: 1112036 daa0230d7072a2b25996d5ef387d5312
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.3-2ubuntu3.1_amd64.udeb
      Size/MD5: 142628 db13e0940956c59d2efd2467e30dd27c

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg/gnupg-udeb_1.4.3-2ubuntu3.1_i386.udeb
      Size/MD5: 357538 0cfa39e8bf18bd48991298bc01a733ec
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.3-2ubuntu3.1_i386.deb
      Size/MD5: 1055538 67ba9574b18247de52f32ba976d941ef
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.3-2ubuntu3.1_i386.udeb
      Size/MD5: 129146 1fb42163be150d7fa7b73dfcbfbcb244

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg/gnupg-udeb_1.4.3-2ubuntu3.1_powerpc.udeb
      Size/MD5: 372472 f2b7b44029ff56d7911590d4285be8bd
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.3-2ubuntu3.1_powerpc.deb
      Size/MD5: 1107214 8ac1d1de40130c0b61334fde37692c9b
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.3-2ubuntu3.1_powerpc.udeb
      Size/MD5: 136288 023825eced954075f8e3443a227a5aa3

sparc architecture (Sun SPARC/UltraSPARC)

    http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg/gnupg-udeb_1.4.3-2ubuntu3.1_sparc.udeb
      Size/MD5: 366138 d98c8c252f725be2895a99a2f1ffd23d
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.3-2ubuntu3.1_sparc.deb
      Size/MD5: 1042190 01e8b454133f351081d6fab5fdea0443
    http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.3-2ubuntu3.1_sparc.udeb
      Size/MD5: 132764 d961891ab18f423819b766f3ce670e39


Ubuntu Security Notice USN-390-1 November 30, 2006
evince vulnerability
CVE-2006-5864

A security issue affects the following Ubuntu releases:

Ubuntu 5.10
Ubuntu 6.06 LTS
Ubuntu 6.10

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

Ubuntu 5.10:
evince 0.4.0-0ubuntu4.2

Ubuntu 6.06 LTS:
evince 0.5.2-0ubuntu3.1

Ubuntu 6.10:
evince 0.6.1-0ubuntu1.1

In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

A buffer overflow was discovered in the PostScript processor included in evince. By tricking a user into opening a specially crafted PS file, an attacker could crash evince or execute arbitrary code with the user's privileges.

Updated packages for Ubuntu 5.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.4.0-0ubuntu4.2.diff.gz
      Size/MD5: 11664 d17128192e807a0cfdaeb23fa3dd9946
    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.4.0-0ubuntu4.2.dsc
      Size/MD5: 1873 53d40d023740b9f9cc991d63ae5d8481
    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.4.0.orig.tar.gz
      Size/MD5: 1172276 9c1009e3dae55bcda1bc5204f021ad1b

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.4.0-0ubuntu4.2_amd64.deb
      Size/MD5: 652460 28031556b7536ff3ffaf319e622bc999

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.4.0-0ubuntu4.2_i386.deb
      Size/MD5: 602850 63e55c43013743abe8f5c38a9534ecec

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.4.0-0ubuntu4.2_powerpc.deb
      Size/MD5: 637284 db38bf03b1ecbc4ae880e6585fdf40e2

sparc architecture (Sun SPARC/UltraSPARC)

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.4.0-0ubuntu4.2_sparc.deb
      Size/MD5: 616858 5ba7ba196a16f81bee54e89f90ede0fd

Updated packages for Ubuntu 6.06 LTS:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.5.2-0ubuntu3.1.diff.gz
      Size/MD5: 11759 35cfd8a410ff4b3c007a801d3cc8301b
    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.5.2-0ubuntu3.1.dsc
      Size/MD5: 1977 a7a2cca76d367a7b0b35814dd7c0cdcf
    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.5.2.orig.tar.gz
      Size/MD5: 1362513 5020afb1768d89c251ad8c2a233d9fcf

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.5.2-0ubuntu3.1_amd64.deb
      Size/MD5: 747764 5057f66869023293d377de9003b73e56

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.5.2-0ubuntu3.1_i386.deb
      Size/MD5: 692842 3099a22c4805e72fb337ba80459ab6cf

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.5.2-0ubuntu3.1_powerpc.deb
      Size/MD5: 729082 b22cba1dabdaf7cf893c24ae67db34b7

sparc architecture (Sun SPARC/UltraSPARC)

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.5.2-0ubuntu3.1_sparc.deb
      Size/MD5: 704802 70d63563e2049dbeb5d4dffe449ac9c9

Updated packages for Ubuntu 6.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.6.1-0ubuntu1.1.diff.gz
      Size/MD5: 7695 fd708fce54e71ab4527677314735ae07
    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.6.1-0ubuntu1.1.dsc
      Size/MD5: 1679 3433864ecb96560fa08bd45b0cf7fd7a
    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.6.1.orig.tar.gz
      Size/MD5: 1687870 665387e278d4da97f7540aeddeaae57d

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.6.1-0ubuntu1.1_amd64.deb
      Size/MD5: 944176 3e208ca20e0c86c14e80eb0ceb5188ff

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.6.1-0ubuntu1.1_i386.deb
      Size/MD5: 901790 a8b3eb5076b1517d1f26a4673ae4ba7c

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.6.1-0ubuntu1.1_powerpc.deb
      Size/MD5: 926206 c5cda586a630eddf194acd40a86ffb08

sparc architecture (Sun SPARC/UltraSPARC)

    http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.6.1-0ubuntu1.1_sparc.deb
      Size/MD5: 895884 6b331297cff754b3011c3fde319f1d20



No talkbacks posted.
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!

..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP