Debian Security Advisory
DSA-224-1 canna -- buffer overflow and more
- Date Reported:
- 08 Jan 2003
- Affected Packages:
- canna
- Vulnerable:
- Yes
- Security database references:
- In the Bugtraq database (at SecurityFocus): BugTraq ID 6351, BugTraq ID 6354.
In Mitre's CVE dictionary: CVE-2002-1158, CVE-2002-1159. - More information:
-
Several vulnerabilities have been discovered in canna, a Japanese input system. The Common Vulnerabilities and Exposures (CVE) project identified the following vulnerabilities:
- CAN-2002-1158 (BugTraq Id 6351): "hsj" of Shadow Penguin Security discovered a heap overflow vulnerability in the irw_through function in canna server.
- CAN-2002-1159 (BugTraq Id 6354): Shinra Aida of the Canna project discovered that canna does not properly validate requests, which allows remote attackers to cause a denial of service or information leak.
For the current stable distribution (woody) these problems have been fixed in version 3.5b2-46.2.
For the old stable distribution (potato) these problems have been fixed in version 3.5b2-25.2.
For the unstable distribution (sid) these problems have been fixed in version 3.6p1-1.
We recommend that you upgrade your canna packages.
- Fixed in:
-
Debian GNU/Linux 2.2 (potato)
- Source:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2.dsc
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2.diff.gz
- http://ftp.debian.org/debian/dists/potato/main/source/utils/canna_3.5b2.orig.tar.gz
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2.diff.gz
- Alpha:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_alpha.deb
- ARM:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_i386.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_m68k.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_powerpc.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_sparc.deb
Debian GNU/Linux 3.0 (woody)
- Source:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2.dsc
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2.diff.gz
- http://ftp.debian.org/debian/pool/main/c/canna/canna_3.5b2.orig.tar.gz
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2.diff.gz
- Alpha:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_alpha.deb
- ARM:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_ia64.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_ia64.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_ia64.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_ia64.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_ia64.deb
- HPPA:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_hppa.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_hppa.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_hppa.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_hppa.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_hppa.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_m68k.deb
- Big endian MIPS:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_mips.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_mips.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_mips.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_mips.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_mips.deb
- Little endian MIPS:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_mipsel.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_mipsel.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_mipsel.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_mipsel.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_s390.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_s390.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_s390.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_s390.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_sparc.deb
MD5 checksums of the listed files are available in the original advisory.