:Advisories, November 30, 2006
Advisories, November 30, 2006 Dec 1, 2006, 04 :45 UTC (0 Talkback[s] ) (2759 reads)
Debian GNU/Linux
Debian Security Advisory DSA 1221-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
November 30th, 2006 http://www.debian.org/security/faq
Package : libgsf
Vulnerability : buffer overflow
Problem type : local (remote)
Debian-specific: no
"infamous41md" discovered a heap buffer overflow vulnerability in
libgsf, a GNOME library for reading and writing structured file
formats, which could lead to the execution of arbitrary code.
For the stable distribution (sarge) this problem has been fixed in
version 1.11.1-1sarge1
For the unstable distribution (sid) this problem has been fixed in
version 1.14.2-1
We recommend that you upgrade your libgsf packages.
Upgrade Instructions
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given at the end of this advisory:
apt-get update
will update the internal database
apt-get upgrade
will install corrected packages
You may use an automated update by adding the resources from the
footer to the proper configuration.
Debian GNU/Linux 3.1 alias sarge
Source archives:
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf_1.11.1-1sarge1.dsc
Size/MD5 checksum: 837 bc96a9630b2605bdd8091a0f3f934f09
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf_1.11.1-1sarge1.diff.gz
Size/MD5 checksum: 7678 23aa764ba57e0ec811916b78bf986917
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf_1.11.1.orig.tar.gz
Size/MD5 checksum: 572284 d3260e0411c3a972c4f5bf3f2d1fbdf3
Alpha architecture:
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_alpha.deb
Size/MD5 checksum: 107854 37c60803868436da0effcaaac0eb3261
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_alpha.deb
Size/MD5 checksum: 84542 869400c0b10cab3e7a1e353091c15138
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_alpha.deb
Size/MD5 checksum: 211104 d80136fdc38edad9f97f2fc335a13c87
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_alpha.deb
Size/MD5 checksum: 42524 3c201fc969af6fc144ddfa9d308ca7d9
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_alpha.deb
Size/MD5 checksum: 10796 56f4a381eaadbc54ad5da1515fc02a28
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_alpha.deb
Size/MD5 checksum: 50690 a134d813591188748c8237b76ca07eff
AMD64 architecture:
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_amd64.deb
Size/MD5 checksum: 95598 741f5e3cf1276c57a862c6c32989bf45
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_amd64.deb
Size/MD5 checksum: 72884 f1440dcac0f635ef12ecaf9321e19741
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_amd64.deb
Size/MD5 checksum: 172702 751adb98ffb3ae93b849c56bdfda3e35
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_amd64.deb
Size/MD5 checksum: 41496 5d8b547d18ec67bc74e577341e9127fe
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_amd64.deb
Size/MD5 checksum: 10274 c974e8cf41208991a4994274aed34cf4
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_amd64.deb
Size/MD5 checksum: 47474 36ccd40752ff3e33d220494388e82ba3
ARM architecture:
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_arm.deb
Size/MD5 checksum: 92054 81c8e51b0f1a565c2c7975ca00c54aef
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_arm.deb
Size/MD5 checksum: 71122 4983eeffaa1ef96a18eabbb6eff072d6
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_arm.deb
Size/MD5 checksum: 171650 addecc2d0f2e2e9b9e0973af85e4d6d5
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_arm.deb
Size/MD5 checksum: 41006 7631c2c831ccb352ee3eaafa1ae08501
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_arm.deb
Size/MD5 checksum: 9650 0bef0c46800914370452657c52827a7b
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_arm.deb
Size/MD5 checksum: 47752 6446fcefbd64ec916cac67dd7629746d
HP Precision architecture:
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_hppa.deb
Size/MD5 checksum: 109452 00cf9a2ea0ae3c7c77407ac31899f577
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_hppa.deb
Size/MD5 checksum: 87188 90c3ca91f8fadd35a892f94b975b4303
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_hppa.deb
Size/MD5 checksum: 184032 272c9099df0279b1da9eb533e64f4a8c
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_hppa.deb
Size/MD5 checksum: 42832 a4270866dd0ee896a1754ec02fdea6a2
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_hppa.deb
Size/MD5 checksum: 11366 6af045e1bd59419b2abbd1a065e83263
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_hppa.deb
Size/MD5 checksum: 48450 cfb513337e4b16dca1ae5b939739b02b
Intel IA-32 architecture:
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_i386.deb
Size/MD5 checksum: 94438 b70e154e2bc349b763da552b36563c41
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_i386.deb
Size/MD5 checksum: 71724 cc4fd9cd9e3150632fdb600f61926d16
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_i386.deb
Size/MD5 checksum: 165774 75f1cda5fe58d7fa1e32e059ff56aa5c
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_i386.deb
Size/MD5 checksum: 41418 0462a3a69e5f6391f2d84609803af28c
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_i386.deb
Size/MD5 checksum: 10002 2296a2ef95208dd25b1245e5596fad8a
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_i386.deb
Size/MD5 checksum: 47022 dad57213a389b1c396940c6420b2a6d3
Intel IA-64 architecture:
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_ia64.deb
Size/MD5 checksum: 120382 00ae4c44067d719530f10345b907b39d
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_ia64.deb
Size/MD5 checksum: 96808 219ae265d340982c4fcc625f0f4aac2e
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_ia64.deb
Size/MD5 checksum: 207722 321d9e0e5f245a1460934be4c53b3485
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_ia64.deb
Size/MD5 checksum: 44498 73ce9eb8ceb61f3eb5bdebc2f7fbd97a
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_ia64.deb
Size/MD5 checksum: 13112 7114570dd9b7d2ccae2482e8a9749836
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_ia64.deb
Size/MD5 checksum: 50314 0e341aa4f2d297c21b50c07ea5b022e5
Motorola 680x0 architecture:
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_m68k.deb
Size/MD5 checksum: 93418 3241ab0596f2a1be8758b0df6f0b1b91
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_m68k.deb
Size/MD5 checksum: 70380 76e2fbd85c632cc917dbdd4631eaeab1
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_m68k.deb
Size/MD5 checksum: 159350 ad3e05a11cfc6950f5366e586af28c44
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_m68k.deb
Size/MD5 checksum: 41064 ccc2b9e4e7cd38f48d633c509b8359ba
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_m68k.deb
Size/MD5 checksum: 9520 13f4d5efeeb5033221455c053b52ef8e
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_m68k.deb
Size/MD5 checksum: 46432 ba90a1e901880066827139232f828e41
Big endian MIPS architecture:
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_mips.deb
Size/MD5 checksum: 95486 47af6ae61145d336e6d67cb66572fa2c
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_mips.deb
Size/MD5 checksum: 71142 4d50bc59c572fb8de56626b17a96716c
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_mips.deb
Size/MD5 checksum: 181358 4680c5668264c0660f5915f5490a9862
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_mips.deb
Size/MD5 checksum: 41328 e14b22945be8551fe477286239829702
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_mips.deb
Size/MD5 checksum: 9502 a65d4536f7d5a7e217930f665acd1ce4
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_mips.deb
Size/MD5 checksum: 48412 062423f994430f2f458f72ff1c11aa60
Little endian MIPS architecture:
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_mipsel.deb
Size/MD5 checksum: 95064 12574be55cbd0f0d161d438eb3681132
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_mipsel.deb
Size/MD5 checksum: 71040 2ef8b71ca0069594121861ea8f1cb138
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_mipsel.deb
Size/MD5 checksum: 181248 5b1d0d0d255bd232630232b944c90de3
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_mipsel.deb
Size/MD5 checksum: 41342 61d8b2256e13a2f42101eaaac777f147
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_mipsel.deb
Size/MD5 checksum: 9534 090bc4a1110ad678cc31f878a7f625fe
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_mipsel.deb
Size/MD5 checksum: 48484 8e6b7e08584b30d39676e324e8d2f160
PowerPC architecture:
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_powerpc.deb
Size/MD5 checksum: 97424 a5fe077b6c128e6d3707f54f25446793
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_powerpc.deb
Size/MD5 checksum: 76080 80b8cfd0da0406e51e0650b31f6b855b
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_powerpc.deb
Size/MD5 checksum: 175872 c8608277b96bc3b9fe1c9acab58df7f5
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_powerpc.deb
Size/MD5 checksum: 42750 40d7d2fe820e4fe563ad45a52a993882
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_powerpc.deb
Size/MD5 checksum: 12502 f67804ec2e5e233f6eba20a306c87d0f
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_powerpc.deb
Size/MD5 checksum: 47456 67f2eab4c5e7626021e0203de6dd45b0
IBM S/390 architecture:
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_s390.deb
Size/MD5 checksum: 104934 b4f495487d1d69c57bae68b1710c3c34
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_s390.deb
Size/MD5 checksum: 82180 ce2e17b2cb7894fe75f70bf6c0e3e3c8
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_s390.deb
Size/MD5 checksum: 179024 a117c2b0ff8c3ba57c950872d1dcbe63
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_s390.deb
Size/MD5 checksum: 42410 1e4cd37bee40b3064120794ffa40ed61
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_s390.deb
Size/MD5 checksum: 10518 6bf95840b71480e8a040bf7795af7bae
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_s390.deb
Size/MD5 checksum: 47984 a8ffd9f03d9e884f1b919ef8e31a2ef0
Sun Sparc architecture:
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1_1.11.1-1sarge1_sparc.deb
Size/MD5 checksum: 95404 99a1f0843ed4865942a214b1f6cf5b2d
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dbg_1.11.1-1sarge1_sparc.deb
Size/MD5 checksum: 72240 af4c9ac2d4fb67f66f27cb7e2effd99f
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-1-dev_1.11.1-1sarge1_sparc.deb
Size/MD5 checksum: 168950 0848099749ef6395067268f3331b7da4
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1_1.11.1-1sarge1_sparc.deb
Size/MD5 checksum: 41156 ade5d9a99a9140a319fd885cb48d8161
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dbg_1.11.1-1sarge1_sparc.deb
Size/MD5 checksum: 9438 04f6af54df0a761be766ccab9deba73c
http://security.debian.org/pool/updates/main/libg/libgsf/libgsf-gnome-1-dev_1.11.1-1sarge1_sparc.deb
Size/MD5 checksum: 47262 97392dc7cab74baee5953c66d46fa894
These files will probably be moved into the stable distribution on
its next update.
Debian Security Advisory DSA 1222-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
November 30th, 2006 http://www.debian.org/security/faq
Package : proftpd
Vulnerability : several
Problem-Type : remote
Debian-specific: no
CVE ID : CVE-2006-5815 CVE-2006-6170 CVE-2006-6171
Debian Bug : 399070
Several remote vulnerabilities have been discovered in the proftpd FTP
daemon, which may lead to the execution of arbitrary code or denial
of service. The Common Vulnerabilities and Exposures project identifies
the following problems:
CVE-2006-5815
It was discovered that a buffer overflow in the sreplace() function
may lead to denial of service and possibly the execution of arbitrary
code.
CVE-2006-6170
It was discovered that a buffer overflow in the mod_tls addon module
may lead to the execution of arbitrary code.
CVE-2006-6171
It was discovered that insufficient validation of FTP command buffer
size limits may lead to denial of service. Due to unclear information
this issue was already fixed in DSA-1218 as CVE-2006-5815.
For the stable distribution (sarge) these problem has been fixed in version
1.2.10-15sarge3.
For the unstable distribution (sid) this problem has been fixed in
version 1.3.0-16 of the proftpd-dfsg package.
We recommend that you upgrade your proftpd package.
Upgrade Instructions
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upgrade
will install corrected packages
You may use an automated update by adding the resources from the
footer to the proper configuration.
Debian GNU/Linux 3.1 alias sarge
Source archives:
http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3.dsc
Size/MD5 checksum: 897 d4dea6caa9438bea9d260f20761393ec
http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3.diff.gz
Size/MD5 checksum: 128340 4f14cee4723b725983eed3d7d9e7fe39
http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10.orig.tar.gz
Size/MD5 checksum: 920495 7d2bc5b4b1eef459a78e55c027a4f3c4
Architecture independent components:
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-doc_1.2.10-15sarge3_all.deb
Size/MD5 checksum: 422614 c673d2a4e9db616bca66e8c2f992a95d
Alpha architecture:
http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_alpha.deb
Size/MD5 checksum: 444532 d4950ecc709597f04a379e4a3f5644f9
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_alpha.deb
Size/MD5 checksum: 200874 92481cca4bbbce0f0db4fb16ac0c53af
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_alpha.deb
Size/MD5 checksum: 457334 b730aa7d3ff1c08d08bca66168686626
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_alpha.deb
Size/MD5 checksum: 476906 15a84985231a886c2d9cfaa108edad31
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_alpha.deb
Size/MD5 checksum: 476588 3ae27f992a26986872cfc4e26af3add5
ARM architecture:
http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_arm.deb
Size/MD5 checksum: 373966 1c371d644b23ffa23ae4cdb847237048
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_arm.deb
Size/MD5 checksum: 188856 094b34ff2e629e4a2e34a40632130782
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_arm.deb
Size/MD5 checksum: 384130 3a073b4e2ce0a4c006b021bc2a70713c
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_arm.deb
Size/MD5 checksum: 399002 52a258d6db3529dc42f93b3377166f48
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_arm.deb
Size/MD5 checksum: 398846 010ff68a50710591d79e6791a36ebe4e
HP Precision architecture:
http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_hppa.deb
Size/MD5 checksum: 403768 625a4174453f9aae518fecf9e4f6cffd
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_hppa.deb
Size/MD5 checksum: 194534 d69950a0728249287a953efd0e256d95
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_hppa.deb
Size/MD5 checksum: 414946 26cd4464a72e49bf3dd7bae1e6bcb4c5
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_hppa.deb
Size/MD5 checksum: 431866 880875bdcf2aa45c40af333a205a9386
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_hppa.deb
Size/MD5 checksum: 431612 82c75ec629e6408d19f8b7f4e1704e0b
Intel IA-32 architecture:
http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_i386.deb
Size/MD5 checksum: 371322 3fa4ccac9c73bc8c19e075ed49f01a42
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_i386.deb
Size/MD5 checksum: 188924 2bdb4609055c6a77ef45e376f43bb6b8
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_i386.deb
Size/MD5 checksum: 381022 5cc5974e4124b09a5c3a7a04fc4c0dfb
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_i386.deb
Size/MD5 checksum: 396780 1e05de59c612c3b59a0384c6b728909c
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_i386.deb
Size/MD5 checksum: 396546 e7e49a7c96f3c5f1a335bdce31b4a41d
Intel IA-64 architecture:
http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_ia64.deb
Size/MD5 checksum: 519752 379b681d8139096f30c07adaf360a258
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_ia64.deb
Size/MD5 checksum: 207072 6a7a86411c903cfe92848369d8939dc9
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_ia64.deb
Size/MD5 checksum: 535426 f6e1da6b7febf2b374ce3d9cf844596e
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_ia64.deb
Size/MD5 checksum: 562386 6b9476b33d3eb98e87cda796ef3e1cba
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_ia64.deb
Size/MD5 checksum: 562222 ddaf242f3d24e951b9578f2bf37ae4c7
Motorola 680x0 architecture:
http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_m68k.deb
Size/MD5 checksum: 332616 7f28eb7a6612422159554511d20c565c
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_m68k.deb
Size/MD5 checksum: 187212 97853824e6e354d30d08e5d4f92f866a
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_m68k.deb
Size/MD5 checksum: 340948 7cb0f9de38603efd2becbaf8a767860d
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_m68k.deb
Size/MD5 checksum: 353236 b8afaa29deb9a2aaa5826fefd92ee051
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_m68k.deb
Size/MD5 checksum: 352866 dddab5e89fc109de3892f100d5ea702d
Big endian MIPS architecture:
http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_mips.deb
Size/MD5 checksum: 382502 88e5ef3fca660e28577a39db65f0743b
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_mips.deb
Size/MD5 checksum: 201698 9a79029722afde2e9f9881323f09f523
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_mips.deb
Size/MD5 checksum: 391960 847c19048ee9c921abbcedb0742be96d
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_mips.deb
Size/MD5 checksum: 406524 d89d533478c0e5f9997869122173e627
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_mips.deb
Size/MD5 checksum: 406246 f12661492861e6c6f94f5f2ae57318d4
Little endian MIPS architecture:
http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_mipsel.deb
Size/MD5 checksum: 384380 83f0858fa68da448e561f9cfd48fedab
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_mipsel.deb
Size/MD5 checksum: 201916 8a197d293f4c7d735bd0584ec6ec74ee
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_mipsel.deb
Size/MD5 checksum: 393456 45fb0f0a6f79be0ebab17ebf7305340f
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_mipsel.deb
Size/MD5 checksum: 409566 4d33f9e7c059949a27704379228b7119
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_mipsel.deb
Size/MD5 checksum: 409366 5ee8e0e4dc1c831a2f56ff92404ea1c8
PowerPC architecture:
http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_powerpc.deb
Size/MD5 checksum: 384536 67c443041e0f5fdc280952fe849f6905
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_powerpc.deb
Size/MD5 checksum: 195440 cf7b974f9f75e96ff9eb60afd64ceac0
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_powerpc.deb
Size/MD5 checksum: 395224 3ef2ae27f6234f181b2934f8656d47a0
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_powerpc.deb
Size/MD5 checksum: 412098 160500875d6d666fe89ff3590767f205
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_powerpc.deb
Size/MD5 checksum: 411734 baf2f4a518503428bd46c7528adf3ed0
IBM S/390 architecture:
http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_s390.deb
Size/MD5 checksum: 379718 c33ac1f5e3afa17837d6b8a6b46173bc
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_s390.deb
Size/MD5 checksum: 193048 f1533436a3741501e67ca8a10781b274
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_s390.deb
Size/MD5 checksum: 390196 865bc00469365ae23db91d9a86ef201f
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_s390.deb
Size/MD5 checksum: 404046 022be9231922608c55613044285a367e
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_s390.deb
Size/MD5 checksum: 403780 a182f9bada4a850d9103f76a6024521a
Sun Sparc architecture:
http://security.debian.org/pool/updates/main/p/proftpd/proftpd_1.2.10-15sarge3_sparc.deb
Size/MD5 checksum: 369766 1ebaaa6c12ee1db33142347ad7bd2256
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-common_1.2.10-15sarge3_sparc.deb
Size/MD5 checksum: 189086 370817d19ca97068c40263ebc64a4345
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-ldap_1.2.10-15sarge3_sparc.deb
Size/MD5 checksum: 379560 5d3c311d57939b9d6ccc262ad9226845
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-mysql_1.2.10-15sarge3_sparc.deb
Size/MD5 checksum: 394922 119cdba979f469fce53f1311d15b9ab1
http://security.debian.org/pool/updates/main/p/proftpd/proftpd-pgsql_1.2.10-15sarge3_sparc.deb
Size/MD5 checksum: 394722 ebb293c93ebceaa14edd1ceacc64a3d8
These files will probably be moved into the stable distribution on
its next update.
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
Gentoo Linux
Gentoo Linux Security Advisory GLSA 200611-26
http://security.gentoo.org/
Severity: High
Title: ProFTPD: Remote execution of arbitrary code
Date: November 30, 2006
Bugs: #154650
ID: 200611-26
ProFTPD is affected by mutiple vulnerabilities allowing for the remote
execution of arbitrary code.
ProFTPD is a highly-configurable FTP server.
Package / Vulnerable / Unaffected
1 net-ftp/proftpd < 1.3.0a >= 1.3.0a
Evgeny Legerov discovered a stack-based buffer overflow in the
s_replace() function in support.c, as well as a buffer overflow in in
the mod_tls module. Additionally, an off-by-two error related to the
CommandBufferSize configuration directive was reported.
An authenticated attacker could exploit the s_replace() vulnerability
by uploading a crafted .message file or sending specially crafted
commands to the server, possibly resulting in the execution of
arbitrary code with the rights of the user running ProFTPD. An
unauthenticated attacker could send specially crafted data to the
server with mod_tls enabled which could result in the execution of
arbitrary code with the rights of the user running ProFTPD. Finally,
the off-by-two error related to the CommandBufferSize configuration
directive was fixed - exploitability of this error is disputed. Note
that the default configuration on Gentoo is to run ProFTPD as an
unprivileged user, and has mod_tls disabled.
There is no known workaround at this time.
All ProFTPD users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-ftp/proftpd-1.3.0a"
[ 1 ] CVE-2006-5815
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5815
[ 2 ] CVE-2006-6170
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6170
[ 3 ] CVE-2006-6171 (disputed)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6171
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
http://security.gentoo.org/glsa/glsa-200611-26.xml
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org .
Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
http://creativecommons.org/licenses/by-sa/2.5
Mandriva Linux
Mandriva Linux Security Advisory MDKSA-2006:217-1
http://www.mandriva.com/security/
Package : proftpd
Date : November 30, 2006
Affected: 2006.0, 2007.0, Corporate 3.0, Corporate 4.0
Problem Description:
A stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0
and earlier, allows remote attackers to cause a denial of service, as
demonstrated by vd_proftpd.pm, a "ProFTPD remote exploit."
(CVE-2006-5815)
Buffer overflow in the tls_x509name oneline function in the mod_tls
module, as used in ProFTPD 1.3.0a and earlier, and possibly other
products, allows remote attackers to execute arbitrary code via a large
data length argument, a different vulnerability than CVE-2006-5815.
(CVE-2006-6170)
ProFTPD 1.3.0a and earlier does not properly set the buffer size limit
when CommandBufferSize is specified in the configuration file, which
leads to an off-by-two buffer underflow. NOTE: in November 2006, the
role of CommandBufferSize was originally associated with CVE-2006-5815,
but this was an error stemming from an initial vague disclosure. NOTE:
ProFTPD developers dispute this issue, saying that the relevant memory
location is overwritten by assignment before further use within the
affected function, so this is not a vulnerability. (CVE-2006-6171)
Packages have been patched to correct these issues.
Update:
The previous update incorrectly linked the vd_proftd.pm issue with the
CommandBufferSize issue. These are two distinct issues and the previous
update only addressed CommandBufferSize (CVE-2006-6171), and the
mod_tls issue (CVE-2006-6170).
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5815
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6170
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6171
Updated Packages:
Mandriva Linux 2006.0:
b1cd1e2584e59418a20260b3f3332208 2006.0/i586/proftpd-1.2.10-13.3.20060mdk.i586.rpm
979d14f8aa6312dac64948e1e9445f33 2006.0/i586/proftpd-anonymous-1.2.10-13.3.20060mdk.i586.rpm
1d446921049eb39f91f0450a0ff74018 2006.0/SRPMS/proftpd-1.2.10-13.3.20060mdk.src.rpm
Mandriva Linux 2006.0/X86_64:
80f43de2dcf0aab1956552ef2a93c1b5 2006.0/x86_64/proftpd-1.2.10-13.3.20060mdk.x86_64.rpm
62862e2c1c5c870946406beb2b982237 2006.0/x86_64/proftpd-anonymous-1.2.10-13.3.20060mdk.x86_64.rpm
1d446921049eb39f91f0450a0ff74018 2006.0/SRPMS/proftpd-1.2.10-13.3.20060mdk.src.rpm
Mandriva Linux 2007.0:
a37912e678d6dbfe2ed21a2c432e029c 2007.0/i586/proftpd-1.3.0-4.3mdv2007.0.i586.rpm
89b3d4beac485d4879295ad99a17cd1b 2007.0/i586/proftpd-anonymous-1.3.0-4.3mdv2007.0.i586.rpm
c206fc94fd81a8f79a158efe6e0fa8fb 2007.0/i586/proftpd-mod_autohost-1.3.0-4.3mdv2007.0.i586.rpm
6ba12b916446da7651ced303cd5c2f0a 2007.0/i586/proftpd-mod_case-1.3.0-4.3mdv2007.0.i586.rpm
a3d6b7c829345d6edf9f22efb8369b58 2007.0/i586/proftpd-mod_clamav-1.3.0-4.3mdv2007.0.i586.rpm
a51a76a0e93f638018a15a28d67d1bc6 2007.0/i586/proftpd-mod_ctrls_admin-1.3.0-4.3mdv2007.0.i586.rpm
458913aaa82dd80691b08e69c2d7a68e 2007.0/i586/proftpd-mod_facl-1.3.0-4.3mdv2007.0.i586.rpm
3e929da8229f69a9c2c8702f2c79bbfe 2007.0/i586/proftpd-mod_gss-1.3.0-4.3mdv2007.0.i586.rpm
9c7ad69945b176c59f682a750ba0da86 2007.0/i586/proftpd-mod_ifsession-1.3.0-4.3mdv2007.0.i586.rpm
de0dd2a5354bdd79842c84dd0698ae80 2007.0/i586/proftpd-mod_ldap-1.3.0-4.3mdv2007.0.i586.rpm
84255d9b701a430fdebc8ffa0804462d 2007.0/i586/proftpd-mod_load-1.3.0-4.3mdv2007.0.i586.rpm
5a9dea0cc961f50a772f0c7f6d04fb2c 2007.0/i586/proftpd-mod_quotatab-1.3.0-4.3mdv2007.0.i586.rpm
da44806b650245adadee9227d60fed35 2007.0/i586/proftpd-mod_quotatab_file-1.3.0-4.3mdv2007.0.i586.rpm
c2fd38d0ab3e324e377a0a83449bdcfc 2007.0/i586/proftpd-mod_quotatab_ldap-1.3.0-4.3mdv2007.0.i586.rpm
db3864770f8aa649190e84ac04c7d26a 2007.0/i586/proftpd-mod_quotatab_sql-1.3.0-4.3mdv2007.0.i586.rpm
1f1a0e13808bfe3179c1142d2cfc76bd 2007.0/i586/proftpd-mod_radius-1.3.0-4.3mdv2007.0.i586.rpm
93f3736a42145559e9faffa16c68271d 2007.0/i586/proftpd-mod_ratio-1.3.0-4.3mdv2007.0.i586.rpm
ce6ce9b9340c328ff0956481fe9ee5ff 2007.0/i586/proftpd-mod_rewrite-1.3.0-4.3mdv2007.0.i586.rpm
8c7089d22b32a863691fcf1ff3c1b6bf 2007.0/i586/proftpd-mod_shaper-1.3.0-4.3mdv2007.0.i586.rpm
23b8d3f76708ce59d83bf07a6c19034d 2007.0/i586/proftpd-mod_site_misc-1.3.0-4.3mdv2007.0.i586.rpm
845b77cc6c4c2f4eb8c4a41d369afe3d 2007.0/i586/proftpd-mod_sql-1.3.0-4.3mdv2007.0.i586.rpm
7d98b511040ce3a9c16ca38fad98cdc7 2007.0/i586/proftpd-mod_sql_mysql-1.3.0-4.3mdv2007.0.i586.rpm
44bdd048bac956a52adae56b429419a8 2007.0/i586/proftpd-mod_sql_postgres-1.3.0-4.3mdv2007.0.i586.rpm
bece7d223e81935362115874debc625f 2007.0/i586/proftpd-mod_time-1.3.0-4.3mdv2007.0.i586.rpm
b655b11679c1d46750397f647499d113 2007.0/i586/proftpd-mod_tls-1.3.0-4.3mdv2007.0.i586.rpm
f051af523f306a8547cc232df6af61b0 2007.0/i586/proftpd-mod_wrap-1.3.0-4.3mdv2007.0.i586.rpm
ea415328f16a7c86c530b1628e9e7119 2007.0/i586/proftpd-mod_wrap_file-1.3.0-4.3mdv2007.0.i586.rpm
40cc7355b7baea00dc0ca3d9fbb23d54 2007.0/i586/proftpd-mod_wrap_sql-1.3.0-4.3mdv2007.0.i586.rpm
56f9c85b919e81120ef5c9f95c5fbb70 2007.0/SRPMS/proftpd-1.3.0-4.3mdv2007.0.src.rpm
Mandriva Linux 2007.0/X86_64:
a3f7f06d36e939decedbfbd73b068a00 2007.0/x86_64/proftpd-1.3.0-4.3mdv2007.0.x86_64.rpm
e57974563e6a6a856997ece7ae4223f3 2007.0/x86_64/proftpd-anonymous-1.3.0-4.3mdv2007.0.x86_64.rpm
351f1bcb4148bb3e2d42e4f8b63866bb 2007.0/x86_64/proftpd-mod_autohost-1.3.0-4.3mdv2007.0.x86_64.rpm
5244e4fe2899727b8ed9ff8c2108e835 2007.0/x86_64/proftpd-mod_case-1.3.0-4.3mdv2007.0.x86_64.rpm
6945e72c1af1e29f0e8a4f851fde7c04 2007.0/x86_64/proftpd-mod_clamav-1.3.0-4.3mdv2007.0.x86_64.rpm
eaeba816574a28d65c243d70c55a2be7 2007.0/x86_64/proftpd-mod_ctrls_admin-1.3.0-4.3mdv2007.0.x86_64.rpm
4b61ef08a72e13acf1c245efda94e14d 2007.0/x86_64/proftpd-mod_facl-1.3.0-4.3mdv2007.0.x86_64.rpm
599338063d6b3358c92bc675748a5276 2007.0/x86_64/proftpd-mod_gss-1.3.0-4.3mdv2007.0.x86_64.rpm
113e48693e6f717523f53d7bd362f167 2007.0/x86_64/proftpd-mod_ifsession-1.3.0-4.3mdv2007.0.x86_64.rpm
0afda1fa0eb473074bbf591b87c205f5 2007.0/x86_64/proftpd-mod_ldap-1.3.0-4.3mdv2007.0.x86_64.rpm
d5f67ae4a0057ac1574446d53a2b01c2 2007.0/x86_64/proftpd-mod_load-1.3.0-4.3mdv2007.0.x86_64.rpm
24598aaa7594f1c3cce8104c0691fd89 2007.0/x86_64/proftpd-mod_quotatab-1.3.0-4.3mdv2007.0.x86_64.rpm
ae6875064975d76b2f2ce5c2cee3c4cf 2007.0/x86_64/proftpd-mod_quotatab_file-1.3.0-4.3mdv2007.0.x86_64.rpm
a383a4b78ec3e492563c9ef542c2a701 2007.0/x86_64/proftpd-mod_quotatab_ldap-1.3.0-4.3mdv2007.0.x86_64.rpm
eccf357b396c651538df038d7c480516 2007.0/x86_64/proftpd-mod_quotatab_sql-1.3.0-4.3mdv2007.0.x86_64.rpm
0b41852744c4493629eb1d71c8091c8a 2007.0/x86_64/proftpd-mod_radius-1.3.0-4.3mdv2007.0.x86_64.rpm
93d8f354acd5a7e25478b9bbd3319617 2007.0/x86_64/proftpd-mod_ratio-1.3.0-4.3mdv2007.0.x86_64.rpm
332c8e76e5a93e5011caeb3fbf9d8d7d 2007.0/x86_64/proftpd-mod_rewrite-1.3.0-4.3mdv2007.0.x86_64.rpm
03aed52b479f6bf0affa3a697aebe47d 2007.0/x86_64/proftpd-mod_shaper-1.3.0-4.3mdv2007.0.x86_64.rpm
4ea161e9f3821a3f90a2e19f22fdb487 2007.0/x86_64/proftpd-mod_site_misc-1.3.0-4.3mdv2007.0.x86_64.rpm
ef8473f399c9fab49b174438e9f57f1a 2007.0/x86_64/proftpd-mod_sql-1.3.0-4.3mdv2007.0.x86_64.rpm
e77455dd400984b833dd3bf52b6c9876 2007.0/x86_64/proftpd-mod_sql_mysql-1.3.0-4.3mdv2007.0.x86_64.rpm
b194fe453ab8f2d900f49a8fee4d8a43 2007.0/x86_64/proftpd-mod_sql_postgres-1.3.0-4.3mdv2007.0.x86_64.rpm
26177d8de2b31e25d54458f125a4bef6 2007.0/x86_64/proftpd-mod_time-1.3.0-4.3mdv2007.0.x86_64.rpm
27cab8a3a4bf0162e4e4aeb8f2235c18 2007.0/x86_64/proftpd-mod_tls-1.3.0-4.3mdv2007.0.x86_64.rpm
0eebacf7e2aacf1893e6f077a05deade 2007.0/x86_64/proftpd-mod_wrap-1.3.0-4.3mdv2007.0.x86_64.rpm
e1c973141f23a99f1a1e5cfad06ba507 2007.0/x86_64/proftpd-mod_wrap_file-1.3.0-4.3mdv2007.0.x86_64.rpm
ea8918c00be656f8c5c1be6e7e5c29cc 2007.0/x86_64/proftpd-mod_wrap_sql-1.3.0-4.3mdv2007.0.x86_64.rpm
56f9c85b919e81120ef5c9f95c5fbb70 2007.0/SRPMS/proftpd-1.3.0-4.3mdv2007.0.src.rpm
Corporate 3.0:
05c8ada8f0f64c13e392bacea28a57c3 corporate/3.0/i586/proftpd-1.2.9-3.6.C30mdk.i586.rpm
38d0c4fb80b8511d4fc60e29b76c2329 corporate/3.0/i586/proftpd-anonymous-1.2.9-3.6.C30mdk.i586.rpm
fd2a42044333ba3528899e65e6028b28 corporate/3.0/SRPMS/proftpd-1.2.9-3.6.C30mdk.src.rpm
Corporate 3.0/X86_64:
c76e71ec99c373b351a69b33d09e0328 corporate/3.0/x86_64/proftpd-1.2.9-3.6.C30mdk.x86_64.rpm
6a7866fb417a3ba020caad45f7696a1d corporate/3.0/x86_64/proftpd-anonymous-1.2.9-3.6.C30mdk.x86_64.rpm
fd2a42044333ba3528899e65e6028b28 corporate/3.0/SRPMS/proftpd-1.2.9-3.6.C30mdk.src.rpm
Corporate 4.0:
3a74dd621c2836818d884faa26577379 corporate/4.0/i586/proftpd-1.2.10-20.3.20060mlcs4.i586.rpm
75fa75338ed57f5d0aeb137ca7efe521 corporate/4.0/i586/proftpd-anonymous-1.2.10-20.3.20060mlcs4.i586.rpm
f2f48f3379be27c86e4edc1a9cb53d53 corporate/4.0/SRPMS/proftpd-1.2.10-20.3.20060mlcs4.src.rpm
Corporate 4.0/X86_64:
b2e043f4ad4b4045ae0f09074be55327 corporate/4.0/x86_64/proftpd-1.2.10-20.3.20060mlcs4.x86_64.rpm
8524b1da761c3f24f3b0dd0d9a0139b7 corporate/4.0/x86_64/proftpd-anonymous-1.2.10-20.3.20060mlcs4.x86_64.rpm
f2f48f3379be27c86e4edc1a9cb53d53 corporate/4.0/SRPMS/proftpd-1.2.10-20.3.20060mlcs4.src.rpm
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/security/advisories
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
Ubuntu
Ubuntu Security Notice USN-389-1 November 29, 2006
gnupg vulnerability
http://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000241.html
A security issue affects the following Ubuntu releases:
Ubuntu 5.10
Ubuntu 6.06 LTS
Ubuntu 6.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 5.10:
gnupg 1.4.1-1ubuntu1.5
Ubuntu 6.06 LTS:
gnupg 1.4.2.2-1ubuntu2.3
Ubuntu 6.10:
gnupg 1.4.3-2ubuntu3.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
A buffer overflow was discovered in GnuPG. By tricking a user into
running gpg interactively on a specially crafted message, an attacker
could execute arbitrary code with the user's privileges. This
vulnerability is not exposed when running gpg in batch mode.
Updated packages for Ubuntu 5.10:
Source archives:
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.1-1ubuntu1.5.diff.gz
Size/MD5: 21914 9c398c7ad981984ce7e2d5c73d39646c
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.1-1ubuntu1.5.dsc
Size/MD5: 684 99674acf9842bede50bfc9cee94233bc
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.1.orig.tar.gz
Size/MD5: 4059170 1cc77c6943baaa711222e954bbd785e5
amd64 architecture (Athlon64, Opteron, EM64T Xeon)
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.1-1ubuntu1.5_amd64.deb
Size/MD5: 1136516 6f95cee543adea0d34af0db0270e8301
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.1-1ubuntu1.5_amd64.udeb
Size/MD5: 152280 91e6fec1a7cac200e6607a5aca8e283c
i386 architecture (x86 compatible Intel/AMD)
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.1-1ubuntu1.5_i386.deb
Size/MD5: 1044704 511314c5de795b3f732fbc48fa9bc245
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.1-1ubuntu1.5_i386.udeb
Size/MD5: 130672 c2af84edf925cf93e92df0afd1747a8b
powerpc architecture (Apple Macintosh G3/G4/G5)
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.1-1ubuntu1.5_powerpc.deb
Size/MD5: 1119908 d942ad0abd5921bb771fd6180d32f28b
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.1-1ubuntu1.5_powerpc.udeb
Size/MD5: 140214 ac880f5f3a32fe0bba76d61ef5374f61
sparc architecture (Sun SPARC/UltraSPARC)
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.1-1ubuntu1.5_sparc.deb
Size/MD5: 1064488 49125a2b181ce9e4ca22b67b6712b153
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.1-1ubuntu1.5_sparc.udeb
Size/MD5: 139606 f97c2b5b2f406afb0cc8478df8529a1c
Updated packages for Ubuntu 6.06 LTS:
Source archives:
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.2.2-1ubuntu2.3.diff.gz
Size/MD5: 20808 4208a73338b5624d39f355e553927548
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.2.2-1ubuntu2.3.dsc
Size/MD5: 690 858b47da7b535136aa99ab7ccbd2aaef
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.2.2.orig.tar.gz
Size/MD5: 4222685 50d8fd9c5715ff78b7db0e5f20d08550
amd64 architecture (Athlon64, Opteron, EM64T Xeon)
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.2.2-1ubuntu2.3_amd64.deb
Size/MD5: 1066374 7e03df9183620a5c23db7caefb3f5b2b
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.2.2-1ubuntu2.3_amd64.udeb
Size/MD5: 140312 9384b3aa9a950db2bb80ad20f820529c
i386 architecture (x86 compatible Intel/AMD)
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.2.2-1ubuntu2.3_i386.deb
Size/MD5: 981392 75eba5633769eb5c8e4fbd863d0ffed9
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.2.2-1ubuntu2.3_i386.udeb
Size/MD5: 120284 5ab02d409b4b475657f5c52081d3ccf9
powerpc architecture (Apple Macintosh G3/G4/G5)
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.2.2-1ubuntu2.3_powerpc.deb
Size/MD5: 1053850 43d575debcff4457419d48f78d164449
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.2.2-1ubuntu2.3_powerpc.udeb
Size/MD5: 130154 9491f62000cc12df6f23b8d66fd97859
sparc architecture (Sun SPARC/UltraSPARC)
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.2.2-1ubuntu2.3_sparc.deb
Size/MD5: 994040 09848e3252cae2efeefeef913e4ef9d5
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.2.2-1ubuntu2.3_sparc.udeb
Size/MD5: 127412 56d3912d3002bf3f0377a6437a6f851c
Updated packages for Ubuntu 6.10:
Source archives:
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.3-2ubuntu3.1.diff.gz
Size/MD5: 25822 be04724ca7e6d4dcf2a016ebe2d4bd25
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.3-2ubuntu3.1.dsc
Size/MD5: 697 446e892916ea052627a78152037651d9
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.3.orig.tar.gz
Size/MD5: 4320394 fcdf572a33dd037653707b128dd150a7
amd64 architecture (Athlon64, Opteron, EM64T Xeon)
http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg/gnupg-udeb_1.4.3-2ubuntu3.1_amd64.udeb
Size/MD5: 379748 635660a16621f2d7cc752e61cf926208
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.3-2ubuntu3.1_amd64.deb
Size/MD5: 1112036 daa0230d7072a2b25996d5ef387d5312
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.3-2ubuntu3.1_amd64.udeb
Size/MD5: 142628 db13e0940956c59d2efd2467e30dd27c
i386 architecture (x86 compatible Intel/AMD)
http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg/gnupg-udeb_1.4.3-2ubuntu3.1_i386.udeb
Size/MD5: 357538 0cfa39e8bf18bd48991298bc01a733ec
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.3-2ubuntu3.1_i386.deb
Size/MD5: 1055538 67ba9574b18247de52f32ba976d941ef
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.3-2ubuntu3.1_i386.udeb
Size/MD5: 129146 1fb42163be150d7fa7b73dfcbfbcb244
powerpc architecture (Apple Macintosh G3/G4/G5)
http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg/gnupg-udeb_1.4.3-2ubuntu3.1_powerpc.udeb
Size/MD5: 372472 f2b7b44029ff56d7911590d4285be8bd
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.3-2ubuntu3.1_powerpc.deb
Size/MD5: 1107214 8ac1d1de40130c0b61334fde37692c9b
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.3-2ubuntu3.1_powerpc.udeb
Size/MD5: 136288 023825eced954075f8e3443a227a5aa3
sparc architecture (Sun SPARC/UltraSPARC)
http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg/gnupg-udeb_1.4.3-2ubuntu3.1_sparc.udeb
Size/MD5: 366138 d98c8c252f725be2895a99a2f1ffd23d
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gnupg_1.4.3-2ubuntu3.1_sparc.deb
Size/MD5: 1042190 01e8b454133f351081d6fab5fdea0443
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg/gpgv-udeb_1.4.3-2ubuntu3.1_sparc.udeb
Size/MD5: 132764 d961891ab18f423819b766f3ce670e39
Ubuntu Security Notice USN-390-1 November 30, 2006
evince vulnerability
CVE-2006-5864
A security issue affects the following Ubuntu releases:
Ubuntu 5.10
Ubuntu 6.06 LTS
Ubuntu 6.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 5.10:
evince 0.4.0-0ubuntu4.2
Ubuntu 6.06 LTS:
evince 0.5.2-0ubuntu3.1
Ubuntu 6.10:
evince 0.6.1-0ubuntu1.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
A buffer overflow was discovered in the PostScript processor included in
evince. By tricking a user into opening a specially crafted PS file, an
attacker could crash evince or execute arbitrary code with the user's
privileges.
Updated packages for Ubuntu 5.10:
Source archives:
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.4.0-0ubuntu4.2.diff.gz
Size/MD5: 11664 d17128192e807a0cfdaeb23fa3dd9946
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.4.0-0ubuntu4.2.dsc
Size/MD5: 1873 53d40d023740b9f9cc991d63ae5d8481
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.4.0.orig.tar.gz
Size/MD5: 1172276 9c1009e3dae55bcda1bc5204f021ad1b
amd64 architecture (Athlon64, Opteron, EM64T Xeon)
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.4.0-0ubuntu4.2_amd64.deb
Size/MD5: 652460 28031556b7536ff3ffaf319e622bc999
i386 architecture (x86 compatible Intel/AMD)
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.4.0-0ubuntu4.2_i386.deb
Size/MD5: 602850 63e55c43013743abe8f5c38a9534ecec
powerpc architecture (Apple Macintosh G3/G4/G5)
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.4.0-0ubuntu4.2_powerpc.deb
Size/MD5: 637284 db38bf03b1ecbc4ae880e6585fdf40e2
sparc architecture (Sun SPARC/UltraSPARC)
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.4.0-0ubuntu4.2_sparc.deb
Size/MD5: 616858 5ba7ba196a16f81bee54e89f90ede0fd
Updated packages for Ubuntu 6.06 LTS:
Source archives:
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.5.2-0ubuntu3.1.diff.gz
Size/MD5: 11759 35cfd8a410ff4b3c007a801d3cc8301b
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.5.2-0ubuntu3.1.dsc
Size/MD5: 1977 a7a2cca76d367a7b0b35814dd7c0cdcf
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.5.2.orig.tar.gz
Size/MD5: 1362513 5020afb1768d89c251ad8c2a233d9fcf
amd64 architecture (Athlon64, Opteron, EM64T Xeon)
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.5.2-0ubuntu3.1_amd64.deb
Size/MD5: 747764 5057f66869023293d377de9003b73e56
i386 architecture (x86 compatible Intel/AMD)
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.5.2-0ubuntu3.1_i386.deb
Size/MD5: 692842 3099a22c4805e72fb337ba80459ab6cf
powerpc architecture (Apple Macintosh G3/G4/G5)
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.5.2-0ubuntu3.1_powerpc.deb
Size/MD5: 729082 b22cba1dabdaf7cf893c24ae67db34b7
sparc architecture (Sun SPARC/UltraSPARC)
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.5.2-0ubuntu3.1_sparc.deb
Size/MD5: 704802 70d63563e2049dbeb5d4dffe449ac9c9
Updated packages for Ubuntu 6.10:
Source archives:
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.6.1-0ubuntu1.1.diff.gz
Size/MD5: 7695 fd708fce54e71ab4527677314735ae07
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.6.1-0ubuntu1.1.dsc
Size/MD5: 1679 3433864ecb96560fa08bd45b0cf7fd7a
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.6.1.orig.tar.gz
Size/MD5: 1687870 665387e278d4da97f7540aeddeaae57d
amd64 architecture (Athlon64, Opteron, EM64T Xeon)
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.6.1-0ubuntu1.1_amd64.deb
Size/MD5: 944176 3e208ca20e0c86c14e80eb0ceb5188ff
i386 architecture (x86 compatible Intel/AMD)
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.6.1-0ubuntu1.1_i386.deb
Size/MD5: 901790 a8b3eb5076b1517d1f26a4673ae4ba7c
powerpc architecture (Apple Macintosh G3/G4/G5)
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.6.1-0ubuntu1.1_powerpc.deb
Size/MD5: 926206 c5cda586a630eddf194acd40a86ffb08
sparc architecture (Sun SPARC/UltraSPARC)
http://security.ubuntu.com/ubuntu/pool/main/e/evince/evince_0.6.1-0ubuntu1.1_sparc.deb
Size/MD5: 895884 6b331297cff754b3011c3fde319f1d20