Debian: New affix packages fix arbitrary command and code execution

    Date19 Jul 2005
    CategoryDebian
    5544
    Posted ByLinuxSecurity Advisories
    Kevin Finisterre discovered two problems in the Bluetooth FTP client from affix, user space utilities for the Affix Bluetooth protocol stack.
    - --------------------------------------------------------------------------
    Debian Security Advisory DSA 762-1                     This email address is being protected from spambots. You need JavaScript enabled to view it.
    http://www.debian.org/security/                             Martin Schulze
    July 19th, 2005                         http://www.debian.org/security/faq
    - --------------------------------------------------------------------------
    
    Package        : affix
    Vulnerability  : several
    Problem-Type   : remote
    Debian-specific: no
    CVE ID         : CAN-2005-2250 CAN-2005-2277
    BugTraq ID     : 14230
    Debian Bug     : 318327 318328
    
    Kevin Finisterre discovered two problems in the Bluetooth FTP client
    from affix, user space utilities for the Affix Bluetooth protocol
    stack.  The Common Vulnerabilities and Exposures project identifies
    the following vulnerabilities:
    
    CAN-2005-2250
    
        A buffer overflow allows remote attackers to execute arbitrary
        code via a long filename in an OBEX file share.
    
    CAN-2005-2277
    
        Missing input sanitising before executing shell commands allow an
        attacker to execute arbitrary commands as root.
    
    The old stable distribution (woody) is not affected by these problems.
    
    For the stable distribution (sarge) these problems have been fixed in
    version 2.1.1-2.
    
    For the unstable distribution (sid) these problems have been fixed in
    version 2.1.2-2.
    
    We recommend that you upgrade your affix package.
    
    
    Upgrade Instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 3.1 alias sarge
    - --------------------------------
    
      Source archives:
    
        http://security.debian.org/pool/updates/main/a/affix/affix_2.1.1-2.dsc
          Size/MD5 checksum:      669 bb24e5747a984193075e7ad2cde94bd2
        http://security.debian.org/pool/updates/main/a/affix/affix_2.1.1-2.diff.gz
          Size/MD5 checksum:    81326 c1e434ed0667a4e0f60d6e8f431fbc11
        http://security.debian.org/pool/updates/main/a/affix/affix_2.1.1.orig.tar.gz
          Size/MD5 checksum:   415816 34af8e6b1d20d99d01427f7da5c777ef
    
      Alpha architecture:
    
        http://security.debian.org/pool/updates/main/a/affix/affix_2.1.1-2_alpha.deb
          Size/MD5 checksum:   103006 d897078ef26ac210835785a60f63ba40
        http://security.debian.org/pool/updates/main/a/affix/libaffix-dev_2.1.1-2_alpha.deb
          Size/MD5 checksum:    93410 d606fe680c82300c17f821ab0238517d
        http://security.debian.org/pool/updates/main/a/affix/libaffix2_2.1.1-2_alpha.deb
          Size/MD5 checksum:    75560 50dd674ab6f58b456152bd65232ef486
    
      ARM architecture:
    
        http://security.debian.org/pool/updates/main/a/affix/affix_2.1.1-2_arm.deb
          Size/MD5 checksum:    85840 47fe949ac3eaf11e40785d535df13de5
        http://security.debian.org/pool/updates/main/a/affix/libaffix-dev_2.1.1-2_arm.deb
          Size/MD5 checksum:    69494 17cbdd22f998e972d6d3719509766f1c
        http://security.debian.org/pool/updates/main/a/affix/libaffix2_2.1.1-2_arm.deb
          Size/MD5 checksum:    56790 a1f04650c5e0f086e95a3c90d87f0a14
    
      Intel IA-32 architecture:
    
        http://security.debian.org/pool/updates/main/a/affix/affix_2.1.1-2_i386.deb
          Size/MD5 checksum:    84860 7f5b869acb23ff4d03074e72c5848972
        http://security.debian.org/pool/updates/main/a/affix/libaffix-dev_2.1.1-2_i386.deb
          Size/MD5 checksum:    63308 c6931e79eb3f8ab121a6211bcb09d71c
        http://security.debian.org/pool/updates/main/a/affix/libaffix2_2.1.1-2_i386.deb
          Size/MD5 checksum:    59606 2b52f0d5ce8c700b50a2119c70e38330
    
      Intel IA-64 architecture:
    
        http://security.debian.org/pool/updates/main/a/affix/affix_2.1.1-2_ia64.deb
          Size/MD5 checksum:   122082 e674b494cc0738be0ca67fe58e6fd366
        http://security.debian.org/pool/updates/main/a/affix/libaffix-dev_2.1.1-2_ia64.deb
          Size/MD5 checksum:    93876 40a4a3b972b76d84839b22ec0047a1de
        http://security.debian.org/pool/updates/main/a/affix/libaffix2_2.1.1-2_ia64.deb
          Size/MD5 checksum:    83630 c5af3eee5c18f3783d306bfcf2e6a3cf
    
      HP Precision architecture:
    
        http://security.debian.org/pool/updates/main/a/affix/affix_2.1.1-2_hppa.deb
          Size/MD5 checksum:    94884 f1fc0e6bd41671594f4ee434cad99505
        http://security.debian.org/pool/updates/main/a/affix/libaffix-dev_2.1.1-2_hppa.deb
          Size/MD5 checksum:    76596 e1f3ed8b636875f9dfb744b71af2f172
        http://security.debian.org/pool/updates/main/a/affix/libaffix2_2.1.1-2_hppa.deb
          Size/MD5 checksum:    68508 a3312999b8c7fea595e12a67b8d10640
    
      Motorola 680x0 architecture:
    
        http://security.debian.org/pool/updates/main/a/affix/affix_2.1.1-2_m68k.deb
          Size/MD5 checksum:    79808 d2e87f6c2ccb4f8b47c863e0d487d80b
        http://security.debian.org/pool/updates/main/a/affix/libaffix-dev_2.1.1-2_m68k.deb
          Size/MD5 checksum:    58412 b118a825ac9844a648fe576389b3900c
        http://security.debian.org/pool/updates/main/a/affix/libaffix2_2.1.1-2_m68k.deb
          Size/MD5 checksum:    54900 6dea7ad75560dda0689e77b0325df561
    
      Big endian MIPS architecture:
    
        http://security.debian.org/pool/updates/main/a/affix/affix_2.1.1-2_mips.deb
          Size/MD5 checksum:    97384 c29b563a1f965492e4a50fe0f563ae67
        http://security.debian.org/pool/updates/main/a/affix/libaffix-dev_2.1.1-2_mips.deb
          Size/MD5 checksum:    76390 f0cc63d8b1cecdf0dc2947800e2f2452
        http://security.debian.org/pool/updates/main/a/affix/libaffix2_2.1.1-2_mips.deb
          Size/MD5 checksum:    61332 ecb60a17b182d2a2324f329c5a7564da
    
      Little endian MIPS architecture:
    
        http://security.debian.org/pool/updates/main/a/affix/affix_2.1.1-2_mipsel.deb
          Size/MD5 checksum:    97114 719915fc14b4892bc0f7bc5d5158cf46
        http://security.debian.org/pool/updates/main/a/affix/libaffix-dev_2.1.1-2_mipsel.deb
          Size/MD5 checksum:    76264 af38e4dc83f10cce8d5cee6da728be1b
        http://security.debian.org/pool/updates/main/a/affix/libaffix2_2.1.1-2_mipsel.deb
          Size/MD5 checksum:    60964 51af51daffb9106b7a882ac60ce603eb
    
      PowerPC architecture:
    
        http://security.debian.org/pool/updates/main/a/affix/affix_2.1.1-2_powerpc.deb
          Size/MD5 checksum:    94696 b2ffdb13a801392080093183099f564d
        http://security.debian.org/pool/updates/main/a/affix/libaffix-dev_2.1.1-2_powerpc.deb
          Size/MD5 checksum:    70040 3beda3ff644615921cb6f70670c0a712
        http://security.debian.org/pool/updates/main/a/affix/libaffix2_2.1.1-2_powerpc.deb
          Size/MD5 checksum:    65412 a05f1b318e88ce0f152558ed6919632f
    
      IBM S/390 architecture:
    
        http://security.debian.org/pool/updates/main/a/affix/affix_2.1.1-2_s390.deb
          Size/MD5 checksum:    92346 bbb62a4e6378d311414ee0740e94b712
        http://security.debian.org/pool/updates/main/a/affix/libaffix-dev_2.1.1-2_s390.deb
          Size/MD5 checksum:    72978 364b0841f0806b6cfdf4f1b10b3d270b
        http://security.debian.org/pool/updates/main/a/affix/libaffix2_2.1.1-2_s390.deb
          Size/MD5 checksum:    66764 41c5dad2e40c6771b6179b5567b39681
    
      Sun Sparc architecture:
    
        http://security.debian.org/pool/updates/main/a/affix/affix_2.1.1-2_sparc.deb
          Size/MD5 checksum:    84660 021fa0ec494ff7066f79ef40475ad5dd
        http://security.debian.org/pool/updates/main/a/affix/libaffix-dev_2.1.1-2_sparc.deb
          Size/MD5 checksum:    66050 b450abbd6079f564c4c285eeec220434
        http://security.debian.org/pool/updates/main/a/affix/libaffix2_2.1.1-2_sparc.deb
          Size/MD5 checksum:    57714 e09e4599c7bfc96493d0d6185d8c0ca0
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.
    
    You are not authorised to post comments.

    Comments powered by CComment

    LinuxSecurity Poll

    What do you think of the articles on LinuxSecurity?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/24-what-do-you-think-of-the-quality-of-the-articles-on-linuxsecurity?task=poll.vote&format=json
    24
    radio
    [{"id":"87","title":"Excellent, don't change a thing!","votes":"25","type":"x","order":"1","pct":54.35,"resources":[]},{"id":"88","title":"Should be more technical","votes":"5","type":"x","order":"2","pct":10.87,"resources":[]},{"id":"89","title":"Should include more HOWTOs","votes":"16","type":"x","order":"3","pct":34.78,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.