Alerta de Segurança Debian

DSA-224-1 canna -- buffer overflow e mais

Data do Alerta:
08 Jan 2003
Pacotes Afetados:
canna
Vulnerável:
Sim
Referência à base de dados de segurança:
Na base de dados do BugTraq (na SecurityFocus): ID BugTraq 6351, ID BugTraq 6354.
No dicionário CVE do Mitre: CVE-2002-1158, CVE-2002-1159.
Informações adicionais:

Várias vulnerabilidades foram encontradas no canna, um sistema de saída japonês. O projeto Common Vulnerabilities and Exposures (CVE) identificou as seguintes vulnerabilidades:

  • CAN-2002-1158 (Id BugTraq 6351): "hsj" do Shadow Penguin Security descobriu uma vulnerabilidade de estouro de pilha na função irw_through do servidor canna.
  • CAN-2002-1159 (Id BugTraq 6354): Shinra Aida do projeto Canna descobriu que o canna não valida adequadamente algumas requisições, o que permite que atacantes remotos causem uma negação de serviço ou causar um vazamento de informações.

Para a atual distribuição estável (woody), estes problemas foram corrigidos na versão 3.5b2-46.2.

Para a antiga distribuição estável (potato), estes problemas foram corrigidos na versão 3.5b2-25.2.

Para a distribuição instável (sid), estes problemas foram corrigidos na versão 3.6p1-1.

Nós recomendamos que você atualize seus pacotes canna.

Corrigido em:

Debian GNU/Linux 2.2 (potato)

Fonte:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2.dsc
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2.diff.gz
http://ftp.debian.org/debian/dists/potato/main/source/utils/canna_3.5b2.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_i386.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_m68k.deb
PowerPC:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_powerpc.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_sparc.deb

Debian GNU/Linux 3.0 (woody)

Fonte:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2.dsc
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2.diff.gz
http://ftp.debian.org/debian/pool/main/c/canna/canna_3.5b2.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_alpha.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_arm.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_i386.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_ia64.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_ia64.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_ia64.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_hppa.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_hppa.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_hppa.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_m68k.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_mips.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_mips.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_mips.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_mipsel.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_mipsel.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_mipsel.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_s390.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_s390.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_s390.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_sparc.deb
http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_sparc.deb

Checksums MD5 dos arquivos listados estão disponíveis no alerta original.