Debian セキュリティ勧告

DSA-214-1 kdenetwork -- バッファオーバーフロー

報告日時:
2002-12-20
影響を受けるパッケージ:
kdenetwork
危険性:
あり
参考セキュリティデータベース:
Mitre の CVE 辞書: CVE-2002-1306.
詳細:

SuSE Linux AG の Olaf Kirch さんは、klisa パッケージに別の 脆弱性を発見しました。klisa は、"ネットワーク上での近さ" のような、 LAN に関する情報を提供するものです。 lisa デーモンにはバッファオーバーフローの脆弱性があり、 そのため、ローカルのユーザおよび LISa ポート (デフォルトでは 7741) を 制御可能な LAN 上のリモートの攻撃者は、 root 権限を奪取することができ る可能性があります。 さらに、リモートの攻撃者は、HTML ページの中で "rlan://" URL を 入れたり、他の KDE アプリケーションを経由するなどして、被害者の アカウントでのアクセスができる可能性があります。

この問題は、現安定版 (stable)(woody) ではバージョン 2.2.2-14.5 で、 不安定版 (unstable)(sid) ではバージョン 2.2.2-14.20 で各々修正されて います。旧安定版 (potato) は、kdenetwork パッケージを含まないため、 この問題の影響を受けることはありません。

klisa パッケージを早急にアップグレードすることをお勧めします。

修正:

Debian GNU/Linux 3.0 (woody)

ソース:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdenetwork_2.2.2-14.5.dsc
http://security.debian.org/pool/updates/main/k/kdenetwork/kdenetwork_2.2.2-14.5.diff.gz
http://security.debian.org/pool/updates/main/k/kdenetwork/kdenetwork_2.2.2.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.5_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.5_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.5_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.5_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.5_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.5_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.5_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.5_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.5_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.5_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.5_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.5_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.5_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.5_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.5_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.5_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.5_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.5_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.5_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.5_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.5_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.5_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.5_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.5_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.5_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.5_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.5_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.5_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.5_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.5_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.5_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.5_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.5_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.5_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.5_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.5_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.5_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.5_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.5_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.5_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.5_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.5_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.5_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.5_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.5_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.5_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.5_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.5_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.5_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.5_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.5_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.5_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.5_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.5_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.5_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.5_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.5_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.5_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.5_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.5_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.5_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.5_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.5_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.5_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.5_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.5_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.5_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.5_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.5_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.5_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.5_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.5_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.5_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.5_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.5_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.5_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.5_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.5_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.5_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.5_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.5_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.5_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.5_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.5_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.5_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.5_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.5_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.5_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.5_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.5_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.5_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.5_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.5_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.5_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.5_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.5_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.5_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.5_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.5_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.5_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.5_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.5_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.5_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.5_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.5_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.5_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.5_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.5_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.5_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.5_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.5_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.5_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.5_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.5_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.5_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.5_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.5_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.5_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.5_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.5_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.5_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.5_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.5_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.5_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.5_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.5_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.5_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.5_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.5_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.5_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.5_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.5_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.5_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.5_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.5_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.5_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.5_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.5_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.5_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.5_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.5_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.5_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.5_sparc.deb

一覧にあるファイルの MD5 チェックサムは勧告の原文にあります。