Lesezeichen hinzufügen
Originalnachricht
-----BEGIN PGP SIGNED MESSAGE-----Hash: SHA1- --------------------------------------------------------------------------Debian Security Advisory DSA 1365-2 security@debian.orghttp://www.debian.org/security/ Moritz MuehlenhoffSeptember 9th, 2007 http://www.debian.org/security/faq- --------------------------------------------------------------------------Package : id3lib3.8.3Vulnerability : programming errorProblem-Type : localDebian-specific: noCVE ID : CVE-2007-4460Debian Bug : 438540Nikolaus Schulz discovered that a programming error in id3lib, an ID3 TagLibrary, may lead to denial of service through symlink attacks.This update to DSA 1365-2 provides fixes packages for the stabledistribution (etch).We recommend that you upgrade your id3lib3.8.3 packages.Upgrade Instructions- --------------------wget url will fetch the file for youdpkg -i file.deb will install the referenced file.If you are using the apt-get package manager, use the line forsources.list as given below:apt-get update will update the internal databaseapt-get upgrade will install corrected packagesYou may use an automated update by adding the resources from thefooter to the proper configuration.Debian GNU/Linux 4.0 alias etch- ------------------------------- Source archives: id3lib3.8.3_3.8.3-6etch1.dsc Size/MD5 checksum: 652 ada1a9d686cbfe925a34b2173227b47e id3lib3.8.3_3.8.3-6etch1.diff.gz Size/MD5 checksum: 135226 495cb5f4610853f02a740e9b7c1a71c5 id3lib3.8.3_3.8.3.orig.tar.gz Size/MD5 checksum: 950726 19f27ddd2dda4b2d26a559a4f0f402a7 Alpha architecture: libid3-3.8.3-dev_3.8.3-6etch1_alpha.deb Size/MD5 checksum: 341286 c074664c96375662596d490ce9e59e2f libid3-3.8.3c2a_3.8.3-6etch1_alpha.deb Size/MD5 checksum: 187286 a6cb95da944dfe5e1a28cbf5136f3b6f AMD64 architecture: libid3-3.8.3-dev_3.8.3-6etch1_amd64.deb Size/MD5 checksum: 283136 6fe99daa8aab3fd9549ab7d2db11aedc libid3-3.8.3c2a_3.8.3-6etch1_amd64.deb Size/MD5 checksum: 176214 e35c8545fe42ae16362144e23772735a ARM architecture: libid3-3.8.3-dev_3.8.3-6etch1_arm.deb Size/MD5 checksum: 277156 4f1e8102266eb7fe3f42dd613274c02a libid3-3.8.3c2a_3.8.3-6etch1_arm.deb Size/MD5 checksum: 179072 fa3c352ad012326b3753fa1b7b189eaf HP Precision architecture: libid3-3.8.3-dev_3.8.3-6etch1_hppa.deb Size/MD5 checksum: 305654 f9d69c8cdb5585e5b1dc3a9742b5edce libid3-3.8.3c2a_3.8.3-6etch1_hppa.deb Size/MD5 checksum: 196342 fa9087816b58d9ed207e25401906c64a Intel IA-32 architecture: libid3-3.8.3-dev_3.8.3-6etch1_i386.deb Size/MD5 checksum: 263064 6b7e0823707843fa76158a0e1ba7f42f libid3-3.8.3c2a_3.8.3-6etch1_i386.deb Size/MD5 checksum: 176662 05ca5942a44486b658a44e4bee16154d Intel IA-64 architecture: libid3-3.8.3-dev_3.8.3-6etch1_ia64.deb Size/MD5 checksum: 351960 6fd56a95a8aa66fa890a99a3264a7cbd libid3-3.8.3c2a_3.8.3-6etch1_ia64.deb Size/MD5 checksum: 202690 e1c25a15ff7a480cafd1ac5d95ea0083 Big endian MIPS architecture: libid3-3.8.3-dev_3.8.3-6etch1_mips.deb Size/MD5 checksum: 285984 576083197b0d3778f9963ff697f0dd6f libid3-3.8.3c2a_3.8.3-6etch1_mips.deb Size/MD5 checksum: 173660 221f900fe4f7bb66fc1cfdae380844c5 PowerPC architecture: libid3-3.8.3-dev_3.8.3-6etch1_powerpc.deb Size/MD5 checksum: 283208 8d6f0c3417ba62980ff80c5084ba0cad libid3-3.8.3c2a_3.8.3-6etch1_powerpc.deb Size/MD5 checksum: 176614 89b9c136ae81ebd9918420d7d6915c28 IBM S/390 architecture: libid3-3.8.3-dev_3.8.3-6etch1_s390.deb Size/MD5 checksum: 269674 d8dd6f6d7d76a46063c0723f974198da libid3-3.8.3c2a_3.8.3-6etch1_s390.deb Size/MD5 checksum: 177402 028a696232d95ddf67ae6acb7a3aac9c Sun Sparc architecture: libid3-3.8.3-dev_3.8.3-6etch1_sparc.deb Size/MD5 checksum: 251852 2356b2546559f20403987530357a68fc libid3-3.8.3c2a_3.8.3-6etch1_sparc.deb Size/MD5 checksum: 176600 80690cceeeb56b25d0cd30381ee28ad4 These files will probably be moved into the stable distribution on its next update.- ---------------------------------------------------------------------------------For apt-get: deb http://security.debian.org/ stable/updates mainFor dpkg-ftp: ftp://security.debian.org/debian-securitydists/stable/updates/mainMailing list: debian-security-announce@lists.debian.orgPackage info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>-----BEGIN PGP SIGNATURE-----Version: GnuPG v1.4.6 (GNU/Linux)iD8DBQFG5GVDXm3vHE4uyloRAovSAJ4iSCS/3RgjdjMcPF4qyaTzqPXBOwCdGYfZcnQvDQcaDAQSQlk3j/WxSkw==6zz7-----END PGP SIGNATURE------- To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.orgwith a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org