Content-Type: text/plain
debian-changes-digest Digest Volume 2007 : Issue 102
Today's Topics:
Accepted clamav 0.90.1-3etch6 (sourc [ Stephen Gran ]
Accepted linux-2.6 2.6.18.dfsg.1-13e [ dann frazier ]
Accepted fai-kernels 1.17+etch5 (sou [ dann frazier ]
Accepted user-mode-linux 2.6.18-1um- [ dann frazier ]
Accepted pptpd 1.3.0-2etch2 (source [ Moritz Muehlenhoff ]
Accepted libdbi-perl 1.53-1etch1 (so [ Christian Hammers ]
Accepted librpcsecgss 0.14-2etch1 (s [ Moritz Muehlenhoff ]
Date: Sat, 01 Sep 2007 19:56:25 +0000
From: Stephen Gran <sgran@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted clamav 0.90.1-3etch6 (source i386 all)
Message-Id: <E1IRZ4z-0006q0-8X@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Tue, 21 Aug 2007 22:09:28 +0100
Source: clamav
Binary: clamav libclamav-dev clamav-dbg clamav-milter clamav-base clamav-freshclam clamav-testfiles clamav-daemon libclamav2 clamav-docs
Architecture: source i386 all
Version: 0.90.1-3etch6
Distribution: stable-security
Urgency: low
Maintainer: Stephen Gran <sgran@debian.org>
Changed-By: Stephen Gran <sgran@debian.org>
Description:
clamav - antivirus scanner for Unix
clamav-base - base package for clamav, an anti-virus utility for Unix
clamav-daemon - antivirus scanner daemon
clamav-dbg - debug symbols for clamav
clamav-docs - documentation package for clamav, an anti-virus utility for Unix
clamav-freshclam - downloads clamav virus databases from the Internet
clamav-milter - antivirus scanner for sendmail
clamav-testfiles - use these files to test that your Antivirus program works
libclamav-dev - clam Antivirus library development files
libclamav2 - virus scanner library
Changes:
clamav (0.90.1-3etch6) stable-security; urgency=low
.
- Correct 33_htmlnorm.c.crash.dpatch
Files:
481114c643a13627d77677c830a6227b 886 utils optional clamav_0.90.1-3etch6.dsc
1a4932a53dba39b40e665f25ed9d35bc 202537 utils optional clamav_0.90.1-3etch6.diff.gz
8dde7e600cc9d1e739cc56d570d7adda 201570 utils optional clamav-base_0.90.1-3etch6_all.deb
0763ed8d1c70c4cc7a8d0964d3facbf9 157750 utils optional clamav-testfiles_0.90.1-3etch6_all.deb
6a5645bfec5e7794dbd8a71a970fcaf9 1003360 utils optional clamav-docs_0.90.1-3etch6_all.deb
9b74635d83983b13b6d94b4b0a3d6860 365812 libs optional libclamav2_0.90.1-3etch6_i386.deb
16f64dbca484e66322fff06427694e93 853862 utils optional clamav_0.90.1-3etch6_i386.deb
ce06cd39900b0d0a84cd8cadc743c1f5 174734 utils optional clamav-daemon_0.90.1-3etch6_i386.deb
ceaf3a3c5c4b27c698bacd7b6d4f7f97 9300140 utils optional clamav-freshclam_0.90.1-3etch6_i386.deb
840217da64ba8cb77968b73588080002 174870 utils extra clamav-milter_0.90.1-3etch6_i386.deb
2318e4ff6542196a4f9a10f4aaa3d340 367778 libdevel optional libclamav-dev_0.90.1-3etch6_i386.deb
d666bedc8d1160119ad69ec3d862be77 603878 utils extra clamav-dbg_0.90.1-3etch6_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGy1YkSYIMHOpZA44RArOGAKCBl5DMp4EinbZpCA1g1t4ImdezCQCgu4IF
9LCVt/ym0ZddSmjHvLyzjkw=
=ljzs
-----END PGP SIGNATURE-----
Accepted:
clamav-base_0.90.1-3etch6_all.deb
to pool/main/c/clamav/clamav-base_0.90.1-3etch6_all.deb
clamav-daemon_0.90.1-3etch6_i386.deb
to pool/main/c/clamav/clamav-daemon_0.90.1-3etch6_i386.deb
clamav-dbg_0.90.1-3etch6_i386.deb
to pool/main/c/clamav/clamav-dbg_0.90.1-3etch6_i386.deb
clamav-docs_0.90.1-3etch6_all.deb
to pool/main/c/clamav/clamav-docs_0.90.1-3etch6_all.deb
clamav-freshclam_0.90.1-3etch6_i386.deb
to pool/main/c/clamav/clamav-freshclam_0.90.1-3etch6_i386.deb
clamav-milter_0.90.1-3etch6_i386.deb
to pool/main/c/clamav/clamav-milter_0.90.1-3etch6_i386.deb
clamav-testfiles_0.90.1-3etch6_all.deb
to pool/main/c/clamav/clamav-testfiles_0.90.1-3etch6_all.deb
clamav_0.90.1-3etch6.diff.gz
to pool/main/c/clamav/clamav_0.90.1-3etch6.diff.gz
clamav_0.90.1-3etch6.dsc
to pool/main/c/clamav/clamav_0.90.1-3etch6.dsc
clamav_0.90.1-3etch6_i386.deb
to pool/main/c/clamav/clamav_0.90.1-3etch6_i386.deb
libclamav-dev_0.90.1-3etch6_i386.deb
to pool/main/c/clamav/libclamav-dev_0.90.1-3etch6_i386.deb
libclamav2_0.90.1-3etch6_i386.deb
to pool/main/c/clamav/libclamav2_0.90.1-3etch6_i386.deb
Date: Sun, 02 Sep 2007 19:56:21 +0000
From: dann frazier <dannf@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted linux-2.6 2.6.18.dfsg.1-13etch2 (ia64 source all)
Message-Id: <E1IRvYT-0007sh-5p@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Mon, 27 Aug 2007 23:29:31 -0600
Source: linux-2.6
Binary: linux-image-2.6.18-5-s3c2410 linux-headers-2.6.18-5-all-s390 linux-headers-2.6.18-5-all-m68k linux-headers-2.6.18-5-xen-amd64 linux-image-2.6.18-5-iop32x linux-headers-2.6.18-5-all-alpha linux-image-2.6.18-5-r5k-cobalt linux-image-2.6.18-5-r5k-ip32 linux-headers-2.6.18-5-vserver-686 linux-headers-2.6.18-5-xen-vserver xen-linux-system-2.6.18-5-xen-686 linux-image-2.6.18-5-xen-amd64 linux-image-2.6.18-5-powerpc xen-linux-system-2.6.18-5-xen-vserver-686 linux-image-2.6.18-5-atari linux-headers-2.6.18-5-r3k-kn02 linux-headers-2.6.18-5-xen-vserver-amd64 linux-image-2.6.18-5-xen-vserver-686 linux-image-2.6.18-5-rpc linux-image-2.6.18-5-xen-686 linux-headers-2.6.18-5-vserver-s390x linux-image-2.6.18-5-parisc64-smp linux-headers-2.6.18-5-parisc64 linux-image-2.6.18-5-r4k-ip22 linux-headers-2.6.18-5 linux-headers-2.6.18-5-r5k-ip32 linux-headers-2.6.18-5-r5k-cobalt linux-headers-2.6.18-5-all-mipsel linux-headers-2.6.18-5-486 linux-headers-2.6.18-5-footbridge linux-image-2.6.18-
5-vserver-powerpc64 linux-manual-2.6.18 linux-image-2.6.18-5-xen-vserver-amd64 linux-image-2.6.18-5-vserver-sparc64 linux-headers-2.6.18-5-vserver-k7 linux-headers-2.6.18-5-mckinley linux-headers-2.6.18-5-alpha-legacy linux-image-2.6.18-5-parisc-smp linux-headers-2.6.18-5-vserver linux-headers-2.6.18-5-xen linux-headers-2.6.18-5-rpc linux-modules-2.6.18-5-xen-686 linux-headers-2.6.18-5-k7 linux-image-2.6.18-5-r3k-kn02 linux-headers-2.6.18-5-qemu linux-headers-2.6.18-5-vserver-powerpc linux-headers-2.6.18-5-all-sparc linux-headers-2.6.18-5-alpha-smp linux-image-2.6.18-5-vserver-s390x linux-image-2.6.18-5-vserver-alpha linux-image-2.6.18-5-vserver-amd64 linux-headers-2.6.18-5-all-powerpc linux-headers-2.6.18-5-iop32x linux-image-2.6.18-5-footbridge linux-image-2.6.18-5-prep linux-headers-2.6.18-5-all-amd64 linux-image-2.6.18-5-powerpc64 linux-image-2.6.18-5-sb1a-bcm91480b linux-image-2.6.18-5-powerpc-smp linux-headers-2.6.18-5-all-arm linux-headers-2.6.18-5-itanium linux-heade
rs-2.6.18-5-amd64 linux-image-2.6.18-5-powerpc-miboot xen-linux-system-2.6.18-5-xen-vserver-amd64 linux-headers-2.6.18-5-686-bigmem linux-headers-2.6.18-5-prep linux-headers-2.6.18-5-parisc-smp linux-headers-2.6.18-5-powerpc-miboot linux-headers-2.6.18-5-powerpc64 linux-image-2.6.18-5-vserver-k7 linux-headers-2.6.18-5-vserver-powerpc64 linux-image-2.6.18-5-alpha-smp linux-image-2.6.18-5-486 linux-headers-2.6.18-5-s390x linux-image-2.6.18-5-itanium linux-image-2.6.18-5-686-bigmem linux-headers-2.6.18-5-s390 linux-headers-2.6.18-5-mac linux-headers-2.6.18-5-xen-vserver-686 linux-doc-2.6.18 linux-headers-2.6.18-5-sparc64 linux-image-2.6.18-5-parisc64 linux-headers-2.6.18-5-all-i386 linux-headers-2.6.18-5-powerpc-smp linux-image-2.6.18-5-s390 linux-image-2.6.18-5-s390-tape linux-image-2.6.18-5-vserver-powerpc linux-headers-2.6.18-5-parisc linux-headers-2.6.18-5-xen-686 linux-headers-2.6.18-5-sparc64-smp linux-headers-2.6.18-5-686 linux-source-2.6.18 linux-headers-2.6.18-5-vserve
r-alpha linux-image-2.6.18-5-alpha-legacy linux-headers-2.6.18-5-sb1-bcm91250a linux-headers-2.6.18-5-ixp4xx linux-image-2.6.18-5-amiga linux-image-2.6.18-5-alpha-generic linux-modules-2.6.18-5-xen-vserver-686 linux-modules-2.6.18-5-xen-vserver-amd64 linux-image-2.6.18-5-r4k-kn04 linux-image-2.6.18-5-amd64 linux-headers-2.6.18-5-parisc64-smp linux-headers-2.6.18-5-powerpc linux-image-2.6.18-5-ixp4xx linux-image-2.6.18-5-parisc linux-support-2.6.18-5 linux-image-2.6.18-5-sparc64 linux-image-2.6.18-5-mac linux-headers-2.6.18-5-sparc32 linux-image-2.6.18-5-sparc64-smp linux-image-2.6.18-5-686 linux-headers-2.6.18-5-alpha-generic linux-headers-2.6.18-5-sb1a-bcm91480b linux-image-2.6.18-5-sb1-bcm91250a linux-headers-2.6.18-5-r4k-ip22 linux-image-2.6.18-5-s390x linux-patch-debian-2.6.18 xen-linux-system-2.6.18-5-xen-amd64 linux-headers-2.6.18-5-all-ia64 linux-headers-2.6.18-5-vserver-amd64 linux-headers-2.6.18-5-atari linux-image-2.6.18-5-vserver-686 linux-tree-2.6.18 linux-header
s-2.6.18-5-amiga linux-image-2.6.18-5-sparc32 linux-headers-2.6.18-5-all-hppa linux-headers-2.6.18-5-s3c2410 linux-image-2.6.18-5-qemu linux-headers-2.6.18-5-r4k-kn04 linux-image-2.6.18-5-k7 linux-image-2.6.18-5-mckinley linux-headers-2.6.18-5-all linux-headers-2.6.18-5-all-mips linux-headers-2.6.18-5-vserver-sparc64 linux-modules-2.6.18-5-xen-amd64
Architecture: source ia64 all
Version: 2.6.18.dfsg.1-13etch2
Distribution: stable-security
Urgency: high
Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
Changed-By: dann frazier <dannf@debian.org>
Description:
linux-doc-2.6.18 - Linux kernel specific documentation for version 2.6.18
linux-headers-2.6.18-5 - Common header files for Linux 2.6.18
linux-headers-2.6.18-5-all - All header files for Linux 2.6.18
linux-headers-2.6.18-5-all-ia64 - All header files for Linux 2.6.18
linux-headers-2.6.18-5-itanium - Header files for Linux 2.6.18 on Itanium
linux-headers-2.6.18-5-mckinley - Header files for Linux 2.6.18 on Itanium II
linux-image-2.6.18-5-itanium - Linux 2.6.18 image on Itanium
linux-image-2.6.18-5-mckinley - Linux 2.6.18 image on Itanium II
linux-manual-2.6.18 - Linux kernel API manual pages for version 2.6.18
linux-patch-debian-2.6.18 - Debian patches to version 2.6.18 of the Linux kernel
linux-source-2.6.18 - Linux kernel source for version 2.6.18 with Debian patches
linux-support-2.6.18-5 - Support files for Linux 2.6.18
linux-tree-2.6.18 - Linux kernel source tree for building Debian kernel images
Changes:
linux-2.6 (2.6.18.dfsg.1-13etch2) stable-security; urgency=high
.
- bugfix/ipv4-fib_props-out-of-bounds.patch
[SECURITY] Fix a typo which caused fib_props[] to be of the wrong size
and check for out of bounds condition in index provided by userspace
See CVE-2007-2172
- bugfix/cpuset_tasks-underflow.patch
[SECURITY] Fix integer underflow in /dev/cpuset/tasks which could allow
local attackers to read sensitive kernel memory if the cpuset filesystem
is mounted.
See CVE-2007-2875
- bugfix/random-bound-check-ordering.patch
[SECURITY] Fix stack-based buffer overflow in the random number
generator
See CVE-2007-3105
- bugfix/cifs-fix-sign-settings.patch
[SECURITY] Fix overriding the server to force signing on caused by
checking the wrong gloal variable.
See CVE-2007-3843
- bugfix/aacraid-ioctl-perm-check.patch
[SECURITY] Require admin capabilities to issue ioctls to aacraid devices
See CVE-2007-4308
Files:
0d32469058eb990ded360c98a66d027e 5672 devel optional linux-2.6_2.6.18.dfsg.1-13etch2.dsc
a99b3fdf8cd187d5209849229202d75c 5310664 devel optional linux-2.6_2.6.18.dfsg.1-13etch2.diff.gz
152d52b161fda741f7cab6b52035ede0 3587232 doc optional linux-doc-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
5b702a589ad09771ade968eeba946998 1082150 doc optional linux-manual-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
c9d942021c5cacb75b443c2f63965632 1482942 devel optional linux-patch-debian-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
6d28d791ee48f4e20a4c3c7a772298f1 41417314 devel optional linux-source-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
570762f56596a615a46b654f9e96bda8 3738432 devel optional linux-support-2.6.18-5_2.6.18.dfsg.1-13etch2_all.deb
1ab0d6ab43a0f1f87446178bf4cbb4d3 51396 devel optional linux-tree-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
3014173e9aa751c0dbc632f0130116a2 50944 devel optional linux-headers-2.6.18-5-all_2.6.18.dfsg.1-13etch2_ia64.deb
3109b9df0c3a19e6f0a195887e8b8ddd 50966 devel optional linux-headers-2.6.18-5-all-ia64_2.6.18.dfsg.1-13etch2_ia64.deb
cd0b4c38cfd220ad24931447bc523c10 3078660 devel optional linux-headers-2.6.18-5_2.6.18.dfsg.1-13etch2_ia64.deb
cc75ba0a8fe7b8326e3270408c1c3840 28007304 admin optional linux-image-2.6.18-5-itanium_2.6.18.dfsg.1-13etch2_ia64.deb
bd38da689cc65f7b9deef7fc3a079735 251958 devel optional linux-headers-2.6.18-5-itanium_2.6.18.dfsg.1-13etch2_ia64.deb
529c24f23f7c1aacf71656dd7b43ec55 28177892 admin optional linux-image-2.6.18-5-mckinley_2.6.18.dfsg.1-13etch2_ia64.deb
42d0e8fb18f6ad667ec7ef1e2a6cb87a 251842 devel optional linux-headers-2.6.18-5-mckinley_2.6.18.dfsg.1-13etch2_ia64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFG1hUChuANDBmkLRkRAiD1AKCK+xvb4QddeZDLNI78Fj7Bk9E1wQCgjHn7
YXjk+6Jbj7Lcwm3mO4CbVi8=
=9ahn
-----END PGP SIGNATURE-----
Accepted:
linux-2.6_2.6.18.dfsg.1-13etch2.diff.gz
to pool/main/l/linux-2.6/linux-2.6_2.6.18.dfsg.1-13etch2.diff.gz
linux-2.6_2.6.18.dfsg.1-13etch2.dsc
to pool/main/l/linux-2.6/linux-2.6_2.6.18.dfsg.1-13etch2.dsc
linux-doc-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
to pool/main/l/linux-2.6/linux-doc-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
linux-headers-2.6.18-5-all-ia64_2.6.18.dfsg.1-13etch2_ia64.deb
to pool/main/l/linux-2.6/linux-headers-2.6.18-5-all-ia64_2.6.18.dfsg.1-13etch2_ia64.deb
linux-headers-2.6.18-5-all_2.6.18.dfsg.1-13etch2_ia64.deb
to pool/main/l/linux-2.6/linux-headers-2.6.18-5-all_2.6.18.dfsg.1-13etch2_ia64.deb
linux-headers-2.6.18-5-itanium_2.6.18.dfsg.1-13etch2_ia64.deb
to pool/main/l/linux-2.6/linux-headers-2.6.18-5-itanium_2.6.18.dfsg.1-13etch2_ia64.deb
linux-headers-2.6.18-5-mckinley_2.6.18.dfsg.1-13etch2_ia64.deb
to pool/main/l/linux-2.6/linux-headers-2.6.18-5-mckinley_2.6.18.dfsg.1-13etch2_ia64.deb
linux-headers-2.6.18-5_2.6.18.dfsg.1-13etch2_ia64.deb
to pool/main/l/linux-2.6/linux-headers-2.6.18-5_2.6.18.dfsg.1-13etch2_ia64.deb
linux-image-2.6.18-5-itanium_2.6.18.dfsg.1-13etch2_ia64.deb
to pool/main/l/linux-2.6/linux-image-2.6.18-5-itanium_2.6.18.dfsg.1-13etch2_ia64.deb
linux-image-2.6.18-5-mckinley_2.6.18.dfsg.1-13etch2_ia64.deb
to pool/main/l/linux-2.6/linux-image-2.6.18-5-mckinley_2.6.18.dfsg.1-13etch2_ia64.deb
linux-manual-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
to pool/main/l/linux-2.6/linux-manual-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
linux-patch-debian-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
to pool/main/l/linux-2.6/linux-patch-debian-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
linux-source-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
to pool/main/l/linux-2.6/linux-source-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
linux-support-2.6.18-5_2.6.18.dfsg.1-13etch2_all.deb
to pool/main/l/linux-2.6/linux-support-2.6.18-5_2.6.18.dfsg.1-13etch2_all.deb
linux-tree-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
to pool/main/l/linux-2.6/linux-tree-2.6.18_2.6.18.dfsg.1-13etch2_all.deb
Date: Mon, 03 Sep 2007 07:56:17 +0000
From: dann frazier <dannf@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted fai-kernels 1.17+etch5 (source i386)
Message-Id: <E1IS6nB-0001b5-RA@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Fri, 31 Aug 2007 15:20:11 -0600
Source: fai-kernels
Binary: fai-kernels
Architecture: source i386
Version: 1.17+etch5
Distribution: stable-security
Urgency: high
Maintainer: Holger Levsen <holger@debian.org>
Changed-By: dann frazier <dannf@debian.org>
Description:
fai-kernels - special kernels for FAI (Fully Automatic Installation)
Changes:
fai-kernels (1.17+etch5) stable-security; urgency=high
.
- NMU by the Security Team
- Rebuild against linux-source-2.6.18 (2.6.18.dfsg.1-13etch2):
- bugfix/ipv4-fib_props-out-of-bounds.patch
[SECURITY] Fix a typo which caused fib_props[] to be of the wrong size
and check for out of bounds condition in index provided by userspace
See CVE-2007-2172
- bugfix/cpuset_tasks-underflow.patch
[SECURITY] Fix integer underflow in /dev/cpuset/tasks which could allow
local attackers to read sensitive kernel memory if the cpuset filesystem
is mounted.
See CVE-2007-2875
- bugfix/random-bound-check-ordering.patch
[SECURITY] Fix stack-based buffer overflow in the random number
generator
See CVE-2007-3105
- bugfix/cifs-fix-sign-settings.patch
[SECURITY] Fix overriding the server to force signing on caused by
checking the wrong gloal variable.
See CVE-2007-3843
- bugfix/aacraid-ioctl-perm-check.patch
[SECURITY] Require admin capabilities to issue ioctls to aacraid devices
See CVE-2007-4308
Files:
8638783c5d0539cc7b139d9c2ea6f655 711 admin extra fai-kernels_1.17+etch5.dsc
9a1e452ebcd28641d593029563531e12 53930 admin extra fai-kernels_1.17+etch5.tar.gz
0778c9f776abe2a4a5447df3c26e8a6d 5500284 admin extra fai-kernels_1.17+etch5_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFG2JHNhuANDBmkLRkRAhLUAJ92cnEOJfUu0gC3vYz5zVN6YXfMsgCeMFv4
CxOJUupnNmA3xaV4vyOWCvg=
=EDqZ
-----END PGP SIGNATURE-----
Accepted:
fai-kernels_1.17+etch5.dsc
to pool/main/f/fai-kernels/fai-kernels_1.17+etch5.dsc
fai-kernels_1.17+etch5.tar.gz
to pool/main/f/fai-kernels/fai-kernels_1.17+etch5.tar.gz
fai-kernels_1.17+etch5_i386.deb
to pool/main/f/fai-kernels/fai-kernels_1.17+etch5_i386.deb
Date: Mon, 03 Sep 2007 07:56:22 +0000
From: dann frazier <dannf@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted user-mode-linux 2.6.18-1um-2etch4 (source i386)
Message-Id: <E1IS6nG-0001bd-DV@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Fri, 31 Aug 2007 15:22:56 -0600
Source: user-mode-linux
Binary: user-mode-linux
Architecture: source i386
Version: 2.6.18-1um-2etch4
Distribution: stable-security
Urgency: high
Maintainer: User Mode Linux Maintainers <pkg-uml-pkgs@lists.alioth.debian.org>
Changed-By: dann frazier <dannf@debian.org>
Description:
user-mode-linux - User-mode Linux (kernel)
Changes:
user-mode-linux (2.6.18-1um-2etch4) stable-security; urgency=high
.
- NMU by the Security Team
- Rebuild against linux-source-2.6.18 (2.6.18.dfsg.1-13etch2):
- bugfix/ipv4-fib_props-out-of-bounds.patch
[SECURITY] Fix a typo which caused fib_props[] to be of the wrong size
and check for out of bounds condition in index provided by userspace
See CVE-2007-2172
- bugfix/cpuset_tasks-underflow.patch
[SECURITY] Fix integer underflow in /dev/cpuset/tasks which could allow
local attackers to read sensitive kernel memory if the cpuset filesystem
is mounted.
See CVE-2007-2875
- bugfix/random-bound-check-ordering.patch
[SECURITY] Fix stack-based buffer overflow in the random number
generator
See CVE-2007-3105
- bugfix/cifs-fix-sign-settings.patch
[SECURITY] Fix overriding the server to force signing on caused by
checking the wrong gloal variable.
See CVE-2007-3843
- bugfix/aacraid-ioctl-perm-check.patch
[SECURITY] Require admin capabilities to issue ioctls to aacraid devices
See CVE-2007-4308
Files:
d8b11da8ad4e4b4332c149b315134316 865 misc extra user-mode-linux_2.6.18-1um-2etch4.dsc
448eaa6589f4939670c4b23f077c7989 13902 misc extra user-mode-linux_2.6.18-1um-2etch4.diff.gz
5cd79093834616eda03bc69f6da100ad 25581340 misc extra user-mode-linux_2.6.18-1um-2etch4_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFG2JHahuANDBmkLRkRAieiAJ424+P5Jd+6QF+dTktX4x/qHSLquwCgil0B
glRAGSomRBKHcUupTYtzRBk=
=qIRq
-----END PGP SIGNATURE-----
Accepted:
user-mode-linux_2.6.18-1um-2etch4.diff.gz
to pool/main/u/user-mode-linux/user-mode-linux_2.6.18-1um-2etch4.diff.gz
user-mode-linux_2.6.18-1um-2etch4.dsc
to pool/main/u/user-mode-linux/user-mode-linux_2.6.18-1um-2etch4.dsc
user-mode-linux_2.6.18-1um-2etch4_i386.deb
to pool/main/u/user-mode-linux/user-mode-linux_2.6.18-1um-2etch4_i386.deb
Date: Mon, 03 Sep 2007 07:56:19 +0000
From: Moritz Muehlenhoff <jmm@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted pptpd 1.3.0-2etch2 (source i386)
Message-Id: <E1IS6nD-0001bE-Rg@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Wed, 22 Aug 2007 20:53:13 +0000
Source: pptpd
Binary: bcrelay pptpd
Architecture: source i386
Version: 1.3.0-2etch2
Distribution: stable-security
Urgency: low
Maintainer: Rene Mayrhofer <rmayr@debian.org>
Changed-By: Moritz Muehlenhoff <jmm@debian.org>
Description:
bcrelay - Broadcast relay daemon
pptpd - PoPToP Point to Point Tunneling Server
Changes:
pptpd (1.3.0-2etch2) stable-security; urgency=low
.
- Fix regression in GRE reordering
Files:
9098a1a6ebac37015c1159a2c6a21655 599 net optional pptpd_1.3.0-2etch2.dsc
495273aeca7469ef97b157af54b8b89e 11339 net optional pptpd_1.3.0-2etch2.diff.gz
4ac1a61fbec2faba596b3ff4b8c7dc85 57504 net optional pptpd_1.3.0-2etch2_i386.deb
ddbd3620e2252b06c58850f0c9470f2f 20182 net optional bcrelay_1.3.0-2etch2_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGzKJ+Xm3vHE4uyloRAhnrAJwOmpfWgQTVINLuVeDT1mFu0oNh4gCffLB4
g3MH+soFrhM9DL7CZh9IyUo=
=VYtt
-----END PGP SIGNATURE-----
Accepted:
bcrelay_1.3.0-2etch2_i386.deb
to pool/main/p/pptpd/bcrelay_1.3.0-2etch2_i386.deb
pptpd_1.3.0-2etch2.diff.gz
to pool/main/p/pptpd/pptpd_1.3.0-2etch2.diff.gz
pptpd_1.3.0-2etch2.dsc
to pool/main/p/pptpd/pptpd_1.3.0-2etch2.dsc
pptpd_1.3.0-2etch2_i386.deb
to pool/main/p/pptpd/pptpd_1.3.0-2etch2_i386.deb
Date: Tue, 04 Sep 2007 19:56:17 +0000
From: Christian Hammers <ch@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted libdbi-perl 1.53-1etch1 (source amd64)
Message-Id: <E1ISeVV-0008RX-7C@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sun, 19 Aug 2007 19:53:18 +0200
Source: libdbi-perl
Binary: libdbi-perl
Architecture: source amd64
Version: 1.53-1etch1
Distribution: stable
Urgency: medium
Maintainer: Christian Hammers <ch@debian.org>
Changed-By: Christian Hammers <ch@debian.org>
Description:
libdbi-perl - Perl5 database interface by Tim Bunce
Changes:
libdbi-perl (1.53-1etch1) stable; urgency=medium
.
- Applied a backported 2-line patch for a "potential" dataloss
problem (confirmed in the changelog of 1.57) which turned out to be a
real problem as written by a user. I applied only the second part of
the user submitted patch as suggested by the DBI author.
Files:
d5be284e1bbc043234283bffdd0b90c4 612 perl optional libdbi-perl_1.53-1etch1.dsc
d7f9c67a5b38cab14bcd9b13f2621b94 6133 perl optional libdbi-perl_1.53-1etch1.diff.gz
973903acceb97bdaa4d820df8b071f48 678832 perl optional libdbi-perl_1.53-1etch1_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iEYEARECAAYFAkbJ8+4ACgkQkR9K5oahGOZzewCcDPt/8pMxs+7w77f2K5jWXlBo
PUcAoMKBraFV/yu25rz5e53REpBuFg8e
=GHid
-----END PGP SIGNATURE-----
Accepted:
libdbi-perl_1.53-1etch1.diff.gz
to pool/main/libd/libdbi-perl/libdbi-perl_1.53-1etch1.diff.gz
libdbi-perl_1.53-1etch1.dsc
to pool/main/libd/libdbi-perl/libdbi-perl_1.53-1etch1.dsc
libdbi-perl_1.53-1etch1_amd64.deb
to pool/main/libd/libdbi-perl/libdbi-perl_1.53-1etch1_amd64.deb
Date: Wed, 05 Sep 2007 07:56:21 +0000
From: Moritz Muehlenhoff <jmm@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted librpcsecgss 0.14-2etch1 (source i386)
Message-Id: <E1ISpkL-0005KB-Nx@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sun, 26 Aug 2007 20:54:40 +0000
Source: librpcsecgss
Binary: librpcsecgss-dev librpcsecgss3
Architecture: source i386
Version: 0.14-2etch1
Distribution: stable-security
Urgency: high
Maintainer: Anibal Monsalve Salazar <anibal@debian.org>
Changed-By: Moritz Muehlenhoff <jmm@debian.org>
Description:
librpcsecgss-dev - header files and docs for librpcsecgss
librpcsecgss3 - allows secure rpc communication using the rpcsec_gss protocol
Changes:
librpcsecgss (0.14-2etch1) stable-security; urgency=high
.
- Fix buffer overflow in RPCSEC_GSS (CVE-2007-3799).
Files:
253bb12cce7ac18b200108dfcb430b6a 746 libs optional librpcsecgss_0.14-2etch1.dsc
0d4cdee46a98731b1b71e30504589281 363503 libs optional librpcsecgss_0.14.orig.tar.gz
b655fc49163d87b9b0a61ae4ead7721b 1479 libs optional librpcsecgss_0.14-2etch1.diff.gz
f5482b2709d90570e398c191ccd1893f 41846 libdevel optional librpcsecgss-dev_0.14-2etch1_i386.deb
56656d7169d4ac2339a1e5ec705ff68d 31140 libs standard librpcsecgss3_0.14-2etch1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFG0zzAXm3vHE4uyloRAgKoAJ98+SzGrYEQQxP6THvYjJ3WGYxwyQCgyT/f
tLLKzCYLk+I8zoxMuoabGLU=
=IgmG
-----END PGP SIGNATURE-----
Accepted:
librpcsecgss-dev_0.14-2etch1_i386.deb
to pool/main/libr/librpcsecgss/librpcsecgss-dev_0.14-2etch1_i386.deb
librpcsecgss3_0.14-2etch1_i386.deb
to pool/main/libr/librpcsecgss/librpcsecgss3_0.14-2etch1_i386.deb
librpcsecgss_0.14-2etch1.diff.gz
to pool/main/libr/librpcsecgss/librpcsecgss_0.14-2etch1.diff.gz
librpcsecgss_0.14-2etch1.dsc
to pool/main/libr/librpcsecgss/librpcsecgss_0.14-2etch1.dsc
End of debian-changes-digest Digest V2007 Issue #102
Received on Wed Sep 5 04:04:09 2007