- --------------------------------------------------------------------------Debian Security Advisory DSA 1179-1                    security@debian.org
http://www.debian.org/security/                             Martin Schulze
September 19th, 2006                    http://www.debian.org/security/faq
- --------------------------------------------------------------------------Package        : alsaplayer
Vulnerability  : programming error
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2006-4089

Luigi Auriemma discovered several buffer overflows in alsaplayer, a
PCM player designed for ALSA, that can lead to a crash of the
application and maybe worse outcome.

For the stable distribution (sarge) these problems have been fixed in
version 0.99.76-0.3sarge1.

For the unstable distribution (sid) these problems will be fixed soon.

We recommend that you upgrade your alsaplayer package.


Upgrade Instructions
- --------------------wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given at the end of this advisory:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.1 alias sarge
- --------------------------------  Source archives:

          Size/MD5 checksum:     1141 eff945b0eaa70c5106bb55a84293d21b
          Size/MD5 checksum:    71698 da1c186e90ee418b1e11d5cfee54442f
          Size/MD5 checksum:   795398 ff78654c9ab74d14ad218dfb226db0a4

  Alpha architecture:

          Size/MD5 checksum:     1008 3886803356b57c4a4fcc9dacd72d5a85
          Size/MD5 checksum:     5348 0738a0a097a5012b0f0300d62f076528
          Size/MD5 checksum:   168008 4dc1223ca76ab4cd3f2c9f35b941d637
          Size/MD5 checksum:     5082 e138067311a19470e9f0f832394d4638
          Size/MD5 checksum:     3624 ffb6e02fbc95e13af2e31a20d3ca6f45
          Size/MD5 checksum:    88066 4a1dd2f2481a0a0eaede9776c6ff12f1
          Size/MD5 checksum:     7198 f97aadb32fd02c5d75cedcc2ee9a698f
          Size/MD5 checksum:     5458 236b5537e1af870f4af3db7738188955
          Size/MD5 checksum:     3732 4e06f3e9f039755a54ae69f647f3c183
          Size/MD5 checksum:     6182 2b9cf67b6da2d2a43cea040e78028e91
          Size/MD5 checksum:     5848 f67527cf5e2506748bb3729d82e40e7b
          Size/MD5 checksum:    47602 fceb03b849ec3e2c22d7930cf047aa48
          Size/MD5 checksum:    30170 a452343680a0e555023d75c44fb1f7de

  AMD64 architecture:

          Size/MD5 checksum:     1006 ed7aeaceaf35dc175c45f1e777e642b2
          Size/MD5 checksum:     4936 a422777c2693a404343ea2f7c34922a2
          Size/MD5 checksum:   152068 ebccc24f0f4958a28fe9639152e4ddfb
          Size/MD5 checksum:     4852 7b3ae1c5351e5313991ba0df1f5ace74
          Size/MD5 checksum:     3308 2eda687b819c7387a1d1b6d9ebd0578f
          Size/MD5 checksum:    81282 703799044ec824fe8249cf0d4c4d93f1
          Size/MD5 checksum:     6612 9b7f81d87e420c9de5b106c0a868913b
          Size/MD5 checksum:     4880 fe34728a070b729f4595e35588ae7d51
          Size/MD5 checksum:     3330 d06a3f9b93a44c94cc3c48d6e2772ddd
          Size/MD5 checksum:     5634 744d31172a347b515a89bb53ef4eeb1e
          Size/MD5 checksum:     5520 42125d4a2a7326346636dc08f45e01dc
          Size/MD5 checksum:    46330 3ca1e8e4a6ad277cab28f608d8f0e6d8
          Size/MD5 checksum:    29462 9394091793da095a3aaf5693b5e19e01

  ARM architecture:

          Size/MD5 checksum:     1008 ad9848dbce0c6d4b2d8ddbb07910434b
          Size/MD5 checksum:     4774 82f1fef9bdd583c2a5683a1e4527bba9
          Size/MD5 checksum:   161822 f772920be5abf0deaa0e62c18d906a83
          Size/MD5 checksum:     4676 c90fcff20cdd5ee4975a5606d39156f9
          Size/MD5 checksum:     3164 932b2c93008edc314db91df704b031be
          Size/MD5 checksum:    80186 7bc3b57418006ce29bd9624a64649c41
          Size/MD5 checksum:     6182 c9e68f55285ed051a2dfea1921d1fe4d
          Size/MD5 checksum:     4800 7957a2a4a051da5315eb819d452a4d4b
          Size/MD5 checksum:     3272 312ef322bc8aa8d79b5f82ec622eb85c
          Size/MD5 checksum:     5372 b83eca928c29b1bfeb1dec7536c1cdae
          Size/MD5 checksum:     5116 b918de60c1e6ee897c5aa26106d1007a
          Size/MD5 checksum:    46308 cafda498c872d179d82bf8c5361ddd91
          Size/MD5 checksum:    27868 56c58d8c4ae03d622b0e860172cc137b

  HP Precision architecture:

          Size/MD5 checksum:     1010 95fd42dd29b47609c97675b50654521f
          Size/MD5 checksum:     5648 a2e3775fc45afdba1c40e46f38e1889c
          Size/MD5 checksum:   176312 4d8635b691b564f628e3cd777cde49dc
          Size/MD5 checksum:     5334 2ec4595cd5d408e9a88ce06f2333226c
          Size/MD5 checksum:     3910 f0db9042664df6e3e20f899034fc19ce
          Size/MD5 checksum:    92878 68f9756b4e3922e28771827a9d2fc185
          Size/MD5 checksum:     7734 6cce32f75c1038d3144cfdc6fc9ffdac
          Size/MD5 checksum:     5562 160eb33f4cf9d00ce9c83b024fded0ca
          Size/MD5 checksum:     3966 00aa8e1a0099be20386e1d18949bb217
          Size/MD5 checksum:     6420 dcfa17f97f71320f34c660ef5f803de6
          Size/MD5 checksum:     5984 5bf3ca4c2104c7488b4987f9c5053acf
          Size/MD5 checksum:    46504 877555af8bd94184dcc6bab5cca1a80f
          Size/MD5 checksum:    29292 ce79d3076c56381e06f0a17adc333ded

  Intel IA-32 architecture:

          Size/MD5 checksum:     1008 84cf5f9c18e577bf8d31beabe6237b1b
          Size/MD5 checksum:     4592 7ec0ac3c4d1b910dc17bf4d972976a40
          Size/MD5 checksum:   141548 066e141be6d5e03da5eb25c15f308bc6
          Size/MD5 checksum:     4794 d9a8b8b2d66b5255645a3a2adee720bc
          Size/MD5 checksum:     3100 bd520a40de6392c83a45a52b086595c6
          Size/MD5 checksum:    75182 12b41f8305f8466dce83c74bc4d17778
          Size/MD5 checksum:     6412 00e9a807d1d9b448b21b2387cc2350f7
          Size/MD5 checksum:     4506 7c9c4398f18a7bb2660e072c8ce5097c
          Size/MD5 checksum:     3100 9a0c643428e819d9118b3aeedcdd83fe
          Size/MD5 checksum:     5544 200e838cc22484c7b7db6d05ae778f50
          Size/MD5 checksum:     5438 098088aa53f63d2bc68a0d64dc992c82
          Size/MD5 checksum:    44808 4feb5206fbf4c477a65b430826860574
          Size/MD5 checksum:    28238 f465cfebfc0deedaf60fe7827ab2af1b

  Intel IA-64 architecture:

          Size/MD5 checksum:     1008 6003f600c2c85986f83aef21988bf4b6
          Size/MD5 checksum:     6716 6e341344182cb022aa805a5912cdab4f
          Size/MD5 checksum:   205564 c877877881696b0f6d693a4b497f37b2
          Size/MD5 checksum:     5560 738cd183c2094f80ae5a083c507facf9
          Size/MD5 checksum:     4212 57ba737f4174a14272200964f1ff8bb3
          Size/MD5 checksum:   104992 6980b880bdaaa13a3898cd4e4de49571
          Size/MD5 checksum:     8436 fd32a0ef78bc3203dfa5c4ab9bbf80e0
          Size/MD5 checksum:     6836 79f438d2cd9b7ea2eae6cce1fb222a68
          Size/MD5 checksum:     4316 3766470e4bcd82338e27d4a0e0619bbd
          Size/MD5 checksum:     6720 d919e07750cc042203ce25170123a08a
          Size/MD5 checksum:     6346 6d06e5c69835889c8430ea26cdbbd5b8
          Size/MD5 checksum:    49620 ac05ad04ba41ff6c03cf02a403a589c7
          Size/MD5 checksum:    31988 ccb93a73dec8827662c172db8d7b8852

  Motorola 680x0 architecture:

          Size/MD5 checksum:     1010 dddfb7c026d8c30b1309dd9ebd64893a
          Size/MD5 checksum:     4798 82f1a5ce76a3ff58412f58a44b296397
          Size/MD5 checksum:   142406 f840de80253e5209f7e09e1333677a4c
          Size/MD5 checksum:     4532 faa6a8257ec052e056e431eb17685078
          Size/MD5 checksum:     3122 72486f2d12cf9b40d12755ca98b99623
          Size/MD5 checksum:    77460 e660fb3ed984079d7f754380eaf1e0ce
          Size/MD5 checksum:     6202 6cfe985c82e4a7e52693046f74793789
          Size/MD5 checksum:     4528 6bb21d82111238a6943c0a7963ddd079
          Size/MD5 checksum:     3204 6cdd0e6330c078e618822efc556a0396
          Size/MD5 checksum:     5276 8f7686552e6ae1c3606a1162706f1619
          Size/MD5 checksum:     5274 8f48d4e088456f772c296e9b8e0a09b3
          Size/MD5 checksum:    44874 9f47a11fa0fd909e822bbaa7c83b3b83
          Size/MD5 checksum:    28092 104948ab466f175e06effa4c67f641a5

  Big endian MIPS architecture:

          Size/MD5 checksum:     1008 8d26b8fc92a385461c85271d6d7e6e40
          Size/MD5 checksum:     4822 e0d8f793d31660785332432f72506a5b
          Size/MD5 checksum:   148744 73731f391d7831c44f85c20dd89d1ca7
          Size/MD5 checksum:     4842 1a584eaa590bab877528a0f9b15c2808
          Size/MD5 checksum:     3374 366cd47e562b60ed62ce3b2cfc5f5598
          Size/MD5 checksum:    72736 86379b0d04a45bbd9a64c0b879653915
          Size/MD5 checksum:     6490 29bdd5aed37899a3a0323b23b292730b
          Size/MD5 checksum:     4742 817ebe5d81f56974233e341fec7eda48
          Size/MD5 checksum:     3406 09e3917b8044e46693e9bc15bc3104f8
          Size/MD5 checksum:     5640 c58621e8311c4513b807a4babd2c41b6
          Size/MD5 checksum:     5420 4db110ccfa363e72c6a13400fbf6394d
          Size/MD5 checksum:    46470 b912c96e0977fea5d512165bf2b994d9
          Size/MD5 checksum:    27746 d8a39b9c55235e3d66030cb1351fe9fc

  Little endian MIPS architecture:

          Size/MD5 checksum:     1008 663a635cc2442f7ae9c18d9ac0ff3598
          Size/MD5 checksum:     4804 897185c7ad56ee9acff7f2250b4ab67f
          Size/MD5 checksum:   147614 952ea420bb93357058a6887792be1e36
          Size/MD5 checksum:     4836 c88eba42b46f25b19127bc7e7354889e
          Size/MD5 checksum:     3380 e164d5cb3e4a5813288384a653b43e79
          Size/MD5 checksum:    71808 230f0c001f7c60fa3165911f9ca3d6ec
          Size/MD5 checksum:     6528 5c546b2e1bad80dc92380470ac6e94a8
          Size/MD5 checksum:     4756 905b74172bad0eaa7349a414b8cc04d7
          Size/MD5 checksum:     3390 76e52bcb669c4511cb4dafd208cc8569
          Size/MD5 checksum:     5636 9a65d5ae87d79a5f3febce12b1620e85
          Size/MD5 checksum:     5400 b7f71f4f894e7dab969be53693f7b997
          Size/MD5 checksum:    46478 cc65c1883feb1e10bb8e13038cd7d7ac
          Size/MD5 checksum:    27700 0afe4acebf1e021a1ab44c618ea93b61

  PowerPC architecture:

          Size/MD5 checksum:     1012 4094f3358604525f88b6d9816c1c290b
          Size/MD5 checksum:     6420 d09e6563dc2d8088447ff7df76f4f087
          Size/MD5 checksum:   162218 59b4e2abfb54cb3e870dd64ae82bdb65
          Size/MD5 checksum:     6454 7716ff35bd4e2265cbd0b2a581148e65
          Size/MD5 checksum:     4936 aec7dbbc140511e687890c0c83c0da35
          Size/MD5 checksum:    85740 362e6fcb31ee83765163b17417e1b314
          Size/MD5 checksum:     8486 51112fe8d2297d3f6d3d030f2f7adb7e
          Size/MD5 checksum:     6332 a361032d3f9f17fbad5f5a696c4240a0
          Size/MD5 checksum:     4948 23826dc1b13a075bf364b8a800c11ad9
          Size/MD5 checksum:     7310 d38f39e30594940e8e6950ce7b6b3d9b
          Size/MD5 checksum:     7102 7178fb17b16dad58553d6776805beb1d
          Size/MD5 checksum:    45500 0b93bdc27789f527a33cd1490e337755
          Size/MD5 checksum:    29702 3141ac7997d60b5a64986eebb1a2cc2d

  IBM S/390 architecture:

          Size/MD5 checksum:     1008 c24c029a9374708ec959f5412a367a5b
          Size/MD5 checksum:     5290 8b8766f639b4ca04f1b610105e85314e
          Size/MD5 checksum:   152742 05e1c82d648e06eccb280922926fd583
          Size/MD5 checksum:     5020 036e26a11d604c5ce9e356a941e86258
          Size/MD5 checksum:     3534 3cce59d630ab69454adea66418595343
          Size/MD5 checksum:    78658 dd42d758e7e5c7fb0bbd9b6c89e75c43
          Size/MD5 checksum:     7022 415162f488cbd3042044ddb9b85edaa3
          Size/MD5 checksum:     5146 fdf0b5fc881267bd392fd50c27f0b085
          Size/MD5 checksum:     3572 e494ebf79753d5780be1cd2d16dcdc6a
          Size/MD5 checksum:     5864 1e1725a25e79d5ad46d07a651eab4aa8
          Size/MD5 checksum:     5732 517339e286154e07ec7f71ee7df90315
          Size/MD5 checksum:    46416 7987e8f166fe510697dff430dd41b224
          Size/MD5 checksum:    30134 e19b50e074e130e4b3c0de844ee5fbad

  Sun Sparc architecture:

          Size/MD5 checksum:     1010 a95ae157e6a4abb2ed99d95beef74fdd
          Size/MD5 checksum:     4860 0dc1d90d835b86bc169ce829c7786111
          Size/MD5 checksum:   146062 ea6dd70ea5fb883eee70f0bf702440db
          Size/MD5 checksum:     4848 fb1f1bff0ce38903a218b73234fcca2a
          Size/MD5 checksum:     3280 bdb432b71f2543768b50b6d10a683dc5
          Size/MD5 checksum:    78066 00c17c38b4ea8a74ae890f082e436dc0
          Size/MD5 checksum:     6762 e1bf425a003a56c6177dad6dffdd243a
          Size/MD5 checksum:     4766 fe39ef8c6a289af3dbfd10a76a25e667
          Size/MD5 checksum:     3322 977a312a3d18e5407660f5daf4286f04
          Size/MD5 checksum:     5650 ecc7e9c0b2c7c65e9b34c6bd1b8d0e83
          Size/MD5 checksum:     5486 989cb8a37e551a6b09dd1c8dabfe19d9
          Size/MD5 checksum:    45252 912b3135d7384879a6945fe6947ddc87
          Size/MD5 checksum:    28024 221df6c03f93ed01df9942d55a410180


  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp:  dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org

Debian: New alsaplayer packages fix denial of service

September 19, 2006
Updated package.

Summary

Severity

Related News