From debian-security-announce@lists.debian.org Wed Sep 17 15:28:35 2003 From: debian-security-announce@lists.debian.org Resent-From: list@murphy.debian.org (SmartList) To: full-disclosure@lists.netsys.com Date: Wed, 17 Sep 2003 13:27:29 +0200 Reply-To: full-disclosure@lists.netsys.com Subject: [Full-Disclosure] [SECURITY] [DSA-382-2] OpenSSH buffer management fix -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-382-2 security@debian.org http://www.debian.org/security/ Wichert Akkerman September 17, 2003 - ------------------------------------------------------------------------ Package : ssh Vulnerability : buffer handling Problem type : possible remote Debian-specific: no CVS references : CAN-2003-0693 CAN-2003-0695 This advisory is an addition to the earlier DSA-382-1 advisory: two more buffer handling problems have been found in addition to the one described in DSA-382-1. It is not known if these bugs are exploitable, but as a precaution an upgrade is advised. For the Debian stable distribution these bugs have been fixed in version 1:3.4p1-1.woody.2 . Please note that if a machine is setup to install packages from proposed-updates it will not automatically install this update. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: http://security.debian.org/pool/updates/main/o/openssh/openssh_3.4p1.orig.tar.gz Size/MD5 checksum: 837668 459c1d0262e939d6432f193c7a4ba8a8 http://security.debian.org/pool/updates/main/o/openssh/openssh_3.4p1-1.woody.2.dsc Size/MD5 checksum: 815 99e4e39a5347fe8e5619761060bf9d2b http://security.debian.org/pool/updates/main/o/openssh/openssh_3.4p1-1.woody.2.diff.gz Size/MD5 checksum: 35975 8c6a44e3c8cbfd5dccb010be5cdf564d alpha architecture (DEC Alpha) http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_3.4p1-1.woody.2_alpha.deb Size/MD5 checksum: 35840 77fcccedb2ac13fd027abba4c8656e38 http://security.debian.org/pool/updates/main/o/openssh/ssh_3.4p1-1.woody.2_alpha.deb Size/MD5 checksum: 850086 52c511f04447dc6d3bbc3fff19c6f0fd arm architecture (ARM) http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_3.4p1-1.woody.2_arm.deb Size/MD5 checksum: 35074 f42db667b183a1551544ec0ac05bc0ba http://security.debian.org/pool/updates/main/o/openssh/ssh_3.4p1-1.woody.2_arm.deb Size/MD5 checksum: 658234 94b2f66ad21fca6acd61cdffebb5af35 hppa architecture (HP PA RISC) http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_3.4p1-1.woody.2_hppa.deb Size/MD5 checksum: 35432 d6b3856b13d7ea28ea87cf158074b247 http://security.debian.org/pool/updates/main/o/openssh/ssh_3.4p1-1.woody.2_hppa.deb Size/MD5 checksum: 755812 0d98e1f72ae21c92a45c81f08ac55ea5 i386 architecture (Intel ia32) http://security.debian.org/pool/updates/main/o/openssh/ssh_3.4p1-1.woody.2_i386.deb Size/MD5 checksum: 642524 88ca624e0b28087e918e3e7ee5b1e75f http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_3.4p1-1.woody.2_i386.deb Size/MD5 checksum: 35346 b6a6e4cbc599a4ff13918bf41b1f24c7 ia64 architecture (Intel ia64) http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_3.4p1-1.woody.2_ia64.deb Size/MD5 checksum: 36838 75534178ba2118d8cd2bcbb15966c8bb http://security.debian.org/pool/updates/main/o/openssh/ssh_3.4p1-1.woody.2_ia64.deb Size/MD5 checksum: 1002662 1633a52473a4dedd0aed1d606c91f45a mips architecture (MIPS (Big Endian)) http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_3.4p1-1.woody.2_mips.deb Size/MD5 checksum: 35366 7a9b4c554c46e70d91e545a352be3fe1 http://security.debian.org/pool/updates/main/o/openssh/ssh_3.4p1-1.woody.2_mips.deb Size/MD5 checksum: 729978 245ad86a030f8abe236ee7e79c0a7eb6 mipsel architecture (MIPS (Little Endian)) http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_3.4p1-1.woody.2_mipsel.deb Size/MD5 checksum: 35326 4f6d478143b4d0775a70639efcbf349a http://security.debian.org/pool/updates/main/o/openssh/ssh_3.4p1-1.woody.2_mipsel.deb Size/MD5 checksum: 727424 e0fd2c4d7ce937f33071aaa9505e5f5e powerpc architecture (PowerPC) http://security.debian.org/pool/updates/main/o/openssh/ssh_3.4p1-1.woody.2_powerpc.deb Size/MD5 checksum: 681518 71f51665606d40f711a5f726b961dcb0 http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_3.4p1-1.woody.2_powerpc.deb Size/MD5 checksum: 35088 0e9e0faa18c89a1851b7c47dc609bb71 s390 architecture (IBM S/390) http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_3.4p1-1.woody.2_s390.deb Size/MD5 checksum: 35726 3fd0240ab71a05f7b5ca5f68f695ee72 http://security.debian.org/pool/updates/main/o/openssh/ssh_3.4p1-1.woody.2_s390.deb Size/MD5 checksum: 718054 660d30ccc42e85ab02f3c19b7dca8ee8 sparc architecture (Sun SPARC/UltraSPARC) http://security.debian.org/pool/updates/main/o/openssh/ssh_3.4p1-1.woody.2_sparc.deb Size/MD5 checksum: 686044 de5978b63c24074f28935c73d143e8fd http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_3.4p1-1.woody.2_sparc.deb Size/MD5 checksum: 35146 a3c936f9274de7182f8b00616f67249e - -- - ---------------------------------------------------------------------------- Debian Security team http://www.debian.org/security/ Mailing-List: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2 (GNU/Linux) iD8DBQE/aETJPLiSUC+jvC0RAmL6AKCSY2w9v30vNxMsodUhNgtnBhfwEgCcDPyF kTaUACXWX2kPsdervTYuNuw= =52mi -----END PGP SIGNATURE----- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html