Debian-Sicherheitsankündigung

DSA-224-1 canna -- Pufferüberlauf und weiteres

Datum des Berichts:
08. Jan 2003
Betroffene Pakete:
canna
Verwundbar:
Ja
Sicherheitsdatenbanken-Referenzen:
In der Bugtraq-Datenbank (bei SecurityFocus): BugTraq ID 6351, BugTraq ID 6354.
In Mitres CVE-Verzeichnis: CVE-2002-1158, CVE-2002-1159.
Weitere Informationen:

Mehrere Verwundbarkeiten wurden in canna entdeckt, einem japanischen Eingabe-System. Das Common Vulnerabilities and Exposures (CVE) Projekt identifiziert die folgenden Verwundbarkeiten:

  • CAN-2002-1158 (BugTraq Id 6351): "hsj" von Shadow Penguin Security entdeckte eine Heap-Überlaufs-Verwundbarkeit in der irw_through-Funktion im canna-Server.
  • CAN-2002-1159 (BugTraq Id 6354): Shinra Aida vom Canna-Projekt entdeckte, dass canna Anfragen nicht ordentlich prüft, was es einem entfernten Angreifer erlaubt, ein Denial-of-Service zu verursachen oder ein Informations-Leck zu erstellen.

Für die aktuelle stable Distribution (Woody) wurden diese Probleme in Version 3.5b2-46.2 behoben.

Für die alte stable Distribution (Potato) wurden diese Probleme in Version 3.5b2-25.2 behoben.

Für die unstable Distribution (Sid) wurden diese Probleme in Version 3.6p1-1 behoben.

Wir empfehlen Ihnen, Ihre canna-Pakete zu aktualisieren.

Behoben in:

Debian GNU/Linux 2.2 (potato)

Quellcode:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2.dsc
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2.diff.gz
http://ftp.debian.org/debian/dists/potato/main/source/utils/canna_3.5b2.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_i386.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_m68k.deb
PowerPC:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_powerpc.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_sparc.deb

Debian GNU/Linux 3.0 (woody)

Quellcode:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2.dsc
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2.diff.gz
http://ftp.debian.org/debian/pool/main/c/canna/canna_3.5b2.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_ia64.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_ia64.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_ia64.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_hppa.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_hppa.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_hppa.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_mips.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_mips.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_mips.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_mipsel.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_mipsel.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_mipsel.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_s390.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_s390.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_s390.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_sparc.deb

MD5-Prüfsummen der aufgeführten Dateien stehen in der ursprünglichen Sicherheitsankündigung zur Verfügung.