- -------------------------------------------------------------------------- Debian Security Advisory DSA 359-1 security@debian.org Debian -- Security Information Matt Zimmerman July 31st, 2003 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : atari800 Vulnerability : buffer overflows Problem-Type : local Debian-specific: no CVE Ids : CAN-2003-0630 Steve Kemp discovered multiple buffer overflows in atari800, an Atari emulator. In order to directly access graphics hardware, one of the affected programs is setuid root. A local attacker could exploit this vulnerability to gain root privileges. For the current stable distribution (woody) this problem has been fixed in version 1.2.2-1woody2. For the unstable distribution (sid) this problem will be fixed soon. Refer to Debian bug #203707. We recommend that you update your atari800 package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 652 c94ddb722982b7da902c00012b2a8129 Size/MD5 checksum: 16878 02679759adbad8e098e98caa0531a121 Size/MD5 checksum: 460211 17f40bab7f2cdf2968df46e37285dcd1 Alpha architecture: Size/MD5 checksum: 298624 77e3eda3b61dee3f414c3985e3580567 ARM architecture: Size/MD5 checksum: 236450 cc3ce3cd1c3e8ded97ced77219a5d999 Intel IA-32 architecture: Size/MD5 checksum: 281528 cc670a35e50196f2fd1e870c500e064f Intel IA-64 architecture: Size/MD5 checksum: 337988 d33f4e2d8ad85873307fa3126c4a51aa HP Precision architecture: Size/MD5 checksum: 256698 ce44ceea827dca9b9a23190025c32abd Motorola 680x0 architecture: Size/MD5 checksum: 196942 b4e9b0bd6198513d9575963b3968810c Big endian MIPS architecture: Size/MD5 checksum: 259694 0e0b7450ba5bffe3cffd92922c769f90 Little endian MIPS architecture: Size/MD5 checksum: 258260 74da79b674cce4c04546275eb4e421f3 PowerPC architecture: Size/MD5 checksum: 238558 c778e667504ecc12210cee5fd37537b6 IBM S/390 architecture: Size/MD5 checksum: 234874 c973ad457dacf860f818376f03237be6 Sun Sparc architecture: Size/MD5 checksum: 239580 b16410debdaa02b00902a7d943536969 These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: debian-security-announce@lists.debian.org Package info: `apt-cache show' and https://packages.debian.org/