Debians sikkerhedsbulletin

DSA-1705-1 netatalk -- manglende kontrol af inddata

Rapporteret den:
15. jan 2009
Berørte pakker:
netatalk
Sårbar:
Ja
Referencer i sikkerhedsdatabaser:
I Debians fejlsporingssystem: Fejl 510585.
I Mitres CVE-ordbog: CVE-2008-5718.
Yderligere oplysninger:

Man opdagede at netatalk, en implementering af AppleTalk-suiten, var påvirket af en kommandoindspøjtningssårbarhed når PostScript-streams via papd blev behandlet. Dette kunne føre til udførelse af vilkårlig kode. Bemærk at dette kun påvirker installationer, som er opsat til at anvende en pipe-kommando kombineret med wildcard-symboler erstattet af værdier hørende til det udskrevne job.

I den stabile distribution (etch) er dette problem rettet i version 2.0.3-4+etch1.

I den kommende stabile distribution (lenny) er dette problem rettet i version 2.0.3-11+lenny1.

I den ustabile distribution (sid) er dette problem rettet i version 2.0.4~beta2-1.

Vi anbefaler at du opgraderer din netatalk-pakke.

Rettet i:

Debian GNU/Linux 4.0 (etch)

Kildekode:
http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1.diff.gz
http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3.orig.tar.gz
http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1.dsc
Alpha:
http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_alpha.deb
AMD64:
http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_amd64.deb
ARM:
http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_arm.deb
HP Precision:
http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_hppa.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_ia64.deb
Big-endian MIPS:
http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_mips.deb
Little-endian MIPS:
http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_sparc.deb

MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin.