Debians sikkerhedsbulletin

DSA-224-1 canna -- bufferoverløb med mere

Rapporteret den:
8. jan 2003
Berørte pakker:
canna
Sårbar:
Ja
Referencer i sikkerhedsdatabaser:
I Bugtraq-databasen (hos SecurityFocus): BugTraq-id 6351, BugTraq-id 6354.
I Mitres CVE-ordbog: CVE-2002-1158, CVE-2002-1159.
Yderligere oplysninger:

Flere sårbarheder er blevet opdaget i canna, et japansk inddatasystem. Projektet Common Vulnerabilities and Exposures (CVE) har fundet frem til at følgende sårbarheder:

  • CAN-2002-1158 (BugTraq Id 6351): "hsj" fra Shadow Penguin Security opdagede en stakoverløbssårbarhed i canna-serverens irw_through-funktion.
  • CAN-2002-1159 (BugTraq Id 6354): Shinra Aida fra Canna-projektet har opdaget, at canna ikke kontrollerer forespørgsler korrekt, hvilket giver fjernangribere mulighed for at starte et overbelastningsangreb eller en informationslækage.

I den aktuelle stabile distribution (woody) er disse problemer rettet i version 3.5b2-46.2.

I den gamle stabile distribution (potato) er disse problemer rettet i version 3.5b2-25.2.

I den ustabile distribution (sid) er disse problemer rettet i version 3.6p1-1.

Vi anbefaler at du opgraderer dine canna-pakker.

Rettet i:

Debian GNU/Linux 2.2 (potato)

Kildekode:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2.dsc
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2.diff.gz
http://ftp.debian.org/debian/dists/potato/main/source/utils/canna_3.5b2.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_i386.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_m68k.deb
PowerPC:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_powerpc.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_sparc.deb

Debian GNU/Linux 3.0 (woody)

Kildekode:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2.dsc
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2.diff.gz
http://ftp.debian.org/debian/pool/main/c/canna/canna_3.5b2.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_ia64.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_ia64.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_ia64.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_hppa.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_hppa.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_hppa.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_mips.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_mips.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_mips.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_mipsel.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_mipsel.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_mipsel.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_s390.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_s390.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_s390.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_sparc.deb

MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin.