Debians sikkerhedsbulletin

DSA-717-1 lsh-utils -- bufferoverløb, slåfejl

Rapporteret den:
27. apr 2005
Berørte pakker:
lsh-utils
Sårbar:
Ja
Referencer i sikkerhedsdatabaser:
I Debians fejlsporingssystem: Fejl 211662.
I Mitres CVE-ordbog: CVE-2003-0826, CVE-2005-0814.
Yderligere oplysninger:

Flere sikkerhedsrelaterede problemer er opdaget i lsh, den alternative secure shell v2 (SSH2)-protokolserver. Projektet Common Vulnerabilities and Exposures har fundet frem til følgende sårbarheder:

  • CAN-2003-0826

    Bennett Todd har opdaget et heap-bufferoverløb i lshd, hvilket kunne gøre det muligt at udføre vilkårlig kode.

  • CAN-2005-0814

    Niels Möller har opdaget et lammelsesangreb i lshd.

I den stabile distribution (woody) er disse problemer rettet i version 1.2.5-2woody3.

I den ustabile distribution (sid) er disse problemer rettet i version 2.0.1-2.

Vi anbefaler at du opgraderer din lsh-server-pakke.

Rettet i:

Debian GNU/Linux 3.0 (woody)

Kildekode:
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-utils_1.2.5-2woody3.dsc
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-utils_1.2.5-2woody3.diff.gz
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-utils_1.2.5.orig.tar.gz
Arkitekturuafhængig komponent:
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-utils-doc_1.2.5-2woody3_all.deb
Alpha:
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-client_1.2.5-2woody3_alpha.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-server_1.2.5-2woody3_alpha.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-utils_1.2.5-2woody3_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-client_1.2.5-2woody3_arm.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-server_1.2.5-2woody3_arm.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-utils_1.2.5-2woody3_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-client_1.2.5-2woody3_i386.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-server_1.2.5-2woody3_i386.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-utils_1.2.5-2woody3_i386.deb
Intel IA-64: Package does not build anymore and hence cannot be updated.
HPPA:
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-client_1.2.5-2woody3_hppa.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-server_1.2.5-2woody3_hppa.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-utils_1.2.5-2woody3_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-client_1.2.5-2woody3_m68k.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-server_1.2.5-2woody3_m68k.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-utils_1.2.5-2woody3_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-client_1.2.5-2woody3_mips.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-server_1.2.5-2woody3_mips.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-utils_1.2.5-2woody3_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-client_1.2.5-2woody3_mipsel.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-server_1.2.5-2woody3_mipsel.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-utils_1.2.5-2woody3_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-client_1.2.5-2woody3_powerpc.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-server_1.2.5-2woody3_powerpc.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-utils_1.2.5-2woody3_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-client_1.2.5-2woody3_s390.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-server_1.2.5-2woody3_s390.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-utils_1.2.5-2woody3_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-client_1.2.5-2woody3_sparc.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-server_1.2.5-2woody3_sparc.deb
http://security.debian.org/pool/updates/main/l/lsh-utils/lsh-utils_1.2.5-2woody3_sparc.deb

MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin.