Debian: krb5 fix arbitrary code execution DSA-703-1
Summary
- --------------------------------------------------------------------------Debian Security Advisory DSA 703-1 security@debian.org http://www.debian.org/security/ Martin Schulze April 1st, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : krb5 Vulnerability : buffer overflows Problem-Type : remote Debian-specific: no CVE IDs : CAN-2005-0468 CAN-2005-0469 CERT advisories: VU#341908 VU#291924 Several problems have been discovered in telnet clients that could be exploited by malicious daemons the client connects to. The Common Vulnerabilities and Exposures project identifies the following problems: CAN-2005-0468 Gaël Delalleau discovered a buffer overflow in the env_opt_add() function that allow a remote attacker to execute arbitrary code. CAN-2005-0469 Gaël Delalleau discovered a buffer overflow in the handling of the LINEMODE suboptions in telnet clients. This can lead to the execution of arbitrary code when connected to a malicious server. For the stable distribution (woody) these problems have been fixed in version 1.2.4-5woody8. For the unstable distribution (sid) these problems have been fixed in version 1.3.6-1. We recommend that you upgrade your krb5 package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 750 51c3ea6dcf74a9d82bef016509870c3d Size/MD5 checksum: 83173 97d5ce1eeec763cc67d56b0758891a0f Size/MD5 checksum: 5443051 663add9b5942be74a86fa860a3fa4167 Architecture independent components: Size/MD5 checksum: 512968 88dea0dcf727a6fe03457485e6c98ea4 Alpha architecture: Size/MD5 checksum: 253798 4124ad89c3d6698ae5ce09cc0a810e77 Size/MD5 checksum: 217536 02bdd8e928ce65cfc415de890106cde7 Size/MD5 checksum: 63072 9aa2b092cc3d4729f6d309160b27117c Size/MD5 checksum: 252162 0f2b0638347b34b07ab919c05b7a404a Size/MD5 checksum: 76452 4eab68ade26bdd00dc733183f673cf7e Size/MD5 checksum: 59106 4c00e1ad73ba0be9631ed3b20846cf31 Size/MD5 checksum: 207478 f94b1e493f4a35a9244ab0a71f714f61 Size/MD5 checksum: 83948 b4870cfb49811f9e9bfc182004d6e72a Size/MD5 checksum: 633440 f794455df495082bd8c40b2f0a6e0f22 Size/MD5 checksum: 367446 248fced4d354d47649deaa0c5d349354 ARM architecture: Size/MD5 checksum: 197342 11591d7d943ee2d38f0117b53ec59026 Size/MD5 checksum: 160678 f4118cf6266830f7db9553329dcc1532 Size/MD5 checksum: 48830 dc4986db69fc9fa3aacd9487a1a57004 Size/MD5 checksum: 198672 6e11c792134a4d9bd602a7461895c42c Size/MD5 checksum: 63738 01cee2e685f3bc973f7cce7e5ec08f56 Size/MD5 checksum: 49406 03755be7fa950f05c099aff6dc847e7d Size/MD5 checksum: 166018 b8000d9c82076d7134aacf28a3ae7a98 Size/MD5 checksum: 73626 3070b54d29b8174b78886e37bc25c112 Size/MD5 checksum: 493632 b74a2e03c250019f25ff58387792d666 Size/MD5 checksum: 295230 bd4ccc64814aeebd0071b68dc964080d Intel IA-32 architecture: Size/MD5 checksum: 179362 e38dffa6b1e44da9c05ab5569283141b Size/MD5 checksum: 152348 eb2d37aca6f5aeb2ecd3dc7a66b351fc Size/MD5 checksum: 46370 dda52cc0f381955716025f4f3f210630 Size/MD5 checksum: 178578 3d9e28bc8bbd83161cd8c9781db99e76 Size/MD5 checksum: 61358 846936ed49d43dddf11c8239e7ecb74f Size/MD5 checksum: 46652 4b12ff1ef17b81aadec2cf27c249b263 Size/MD5 checksum: 156624 2a626d8694742a825242085d83efb40f Size/MD5 checksum: 72022 678e924f12886c54cb3ca9bdee6a8da4 Size/MD5 checksum: 433960 9a90e0a4c79b81f2d00945fb7bdf84da Size/MD5 checksum: 293706 be17bc6de25438a34466e7a47c5e4a0f Intel IA-64 architecture: Size/MD5 checksum: 322390 bd8deae9fe5e2fd0d0e304d93c676c95 Size/MD5 checksum: 266614 fa5fedbcc5ce19cf0fd6e0f019988aaa Size/MD5 checksum: 73742 3b21c0fd054d80e979808c47bef49b15 Size/MD5 checksum: 322348 b893958f43de292d927b49cd9dda434b Size/MD5 checksum: 92050 2c1a3cf4ae7311dc95a696bf919148e9 Size/MD5 checksum: 70700 38b66040685eb5421abcb92cdcb682df Size/MD5 checksum: 256278 5440c691dcc69e168105b60a4433332d Size/MD5 checksum: 107650 0b12f0212a2e8ee31654a605e7b74219 Size/MD5 checksum: 705942 9dc21d18876a435f5ecbae3c1fa90fac Size/MD5 checksum: 475034 072e1682115dd9c556d2eca5c65780af HP Precision architecture: Size/MD5 checksum: 214666 50a69b51ec610a919c00e13dad97c237 Size/MD5 checksum: 189950 ed974a7360091fe4ea8a5dee5f310a93 Size/MD5 checksum: 54064 87d03aa246e3a8bed874ea20aab5c90c Size/MD5 checksum: 214092 fdb3544036609131e218f1293d59ab62 Size/MD5 checksum: 68802 6476e62e8872de28da85a6d7ff6a91a8 Size/MD5 checksum: 55892 ae903fa8671838a64061748b150503ae Size/MD5 checksum: 183066 bde3354927006d85aed74b4ce67f379b Size/MD5 checksum: 85122 160ea9c72f59ee814853092ba414f37e Size/MD5 checksum: 558094 4b5f91e312a31a075cf0ee5f5abb28f4 Size/MD5 checksum: 362152 bf33b679c8e3023f1baa81dedc1c9e32 Motorola 680x0 architecture: Size/MD5 checksum: 164376 695f5090f6f02ef5ffcdb94994923d1d Size/MD5 checksum: 144904 f03b67ac31422c20cd2024a7f530f077 Size/MD5 checksum: 44522 7bb04f7623ecb06934e615790364744e Size/MD5 checksum: 164106 460978cf8ba185277681491f91269bd3 Size/MD5 checksum: 57054 8bcee8e9061c204cc1d53f310603f647 Size/MD5 checksum: 44838 c57524e8c13e8f007451617b6c99374f Size/MD5 checksum: 146184 ef14d19fd5d0d4bb4a4ee88287e556cd Size/MD5 checksum: 70032 1bccace886d6c662ab3b10b0cfaa29d9 Size/MD5 checksum: 409054 be8e8f2a4573bb15ec6024f00a1c4087 Size/MD5 checksum: 277330 c78d56b08e2e4c37bc7d9d1aae9272f6 Big endian MIPS architecture: Size/MD5 checksum: 206742 9881404c18f586f88b60322f6ac46e11 Size/MD5 checksum: 191334 637743e42bdcbd990a8a8eaec03f04e6 Size/MD5 checksum: 53510 c194be0f6dedfbaa82f3f7f51bbafe48 Size/MD5 checksum: 209794 7ad1a3ae1a623910446a89d44f4d7c0a Size/MD5 checksum: 66606 0921f3d4930ad9501eba05cb48c86093 Size/MD5 checksum: 55072 22603859834a0c66169b9c6b3438296b Size/MD5 checksum: 175416 edcbd96200fec2b725a64df310856287 Size/MD5 checksum: 72292 afa180a53f462b42ada57f4183e481b2 Size/MD5 checksum: 541350 be00fa435c03a2474310c03b3aadb3d0 Size/MD5 checksum: 308518 db69345f0ad3df1e0b3b70310ffa6ed6 Little endian MIPS architecture: Size/MD5 checksum: 210850 d7831efe581155af02fbf4cd4b298577 Size/MD5 checksum: 190990 facf8459bd0684335304e2a9af7b8ec1 Size/MD5 checksum: 53694 cbae172d0491dd9f259b31f502d3f0ef Size/MD5 checksum: 213350 9b2e3742c660d42556e790503cfa73c2 Size/MD5 checksum: 66918 cf9b408405283ea6cda2dc7d79dc5187 Size/MD5 checksum: 54936 13d0e562fea89e39cecffe02caa5184f Size/MD5 checksum: 177270 6e92b594956acc65452e8c351222fb53 Size/MD5 checksum: 72106 54a3fbae7e86134d48ee49befcb00c99 Size/MD5 checksum: 540884 a93fd74e3cfce1d61e81dc15adeede7d Size/MD5 checksum: 307184 e725f0ab101cf33b1eb127eb3d18df81 PowerPC architecture: Size/MD5 checksum: 188456 1605cd80b08025be71477d33bae41d53 Size/MD5 checksum: 164152 0e3d09352a72b78dce03519b297a87c3 Size/MD5 checksum: 49372 9289fc6a3d9a4a1e35e55a8f536b2762 Size/MD5 checksum: 189546 cee053d38c1f38de08966f6957ed914a Size/MD5 checksum: 62728 e6f98290ed591d955d5c80eb58d9f6dd Size/MD5 checksum: 49338 bf451f9b226dd16dac16ee9c59d97783 Size/MD5 checksum: 162762 2edc9dee6e7672c838626cd391820de9 Size/MD5 checksum: 74060 5c6ce5c10f005fa31786354fd60c4616 Size/MD5 checksum: 490920 1a5ee5de494c46f5c00598b2ef5dff3d Size/MD5 checksum: 303574 0972361a36370e77050b37e46aeaed66 IBM S/390 architecture: Size/MD5 checksum: 189308 1b5d39163a97cb6ea829810afb1a648c Size/MD5 checksum: 166440 0709eaf98f958d5190afbe956a277995 Size/MD5 checksum: 50302 f8721e09d7b159a5e16b293a8999d43c Size/MD5 checksum: 190628 cd1c66f7eaa63239aee8fbb4a26bed76 Size/MD5 checksum: 67096 a191f8826271cfe94a8aef0d8e6aece1 Size/MD5 checksum: 50278 b0fccd0d25256f8357e8f32e815bf6f6 Size/MD5 checksum: 164334 ce022c07d1815b0df8b5f9a46e8c2ed8 Size/MD5 checksum: 76638 4aa46656e9c0293fb5e28e56391e77bc Size/MD5 checksum: 453482 b52bf2d4a664c52c350f80c1593ea5c2 Size/MD5 checksum: 319656 7b7d0c4b136d99b9dfaf798d4f94d0c9 Sun Sparc architecture: Size/MD5 checksum: 183454 aa907094cbdaac57da2f0eca9b8eb5bd Size/MD5 checksum: 173036 7f173f3267bcab3e66922ea6d40b9108 Size/MD5 checksum: 49792 ce46cc950c54a24025647cec765c6e6b Size/MD5 checksum: 184358 1ae257a74f7e385a2e4e186a26e86da6 Size/MD5 checksum: 64400 6429cb02f6d8c3948ef94176ee077c9e Size/MD5 checksum: 49780 dc7690038fd1b4125179157411f96396 Size/MD5 checksum: 159528 4c9938799737182f5fd4455f7ba08508 Size/MD5 checksum: 73406 83f33192e1d069af16c155136117b331 Size/MD5 checksum: 463024 94916989bafb9975e1d973cc0210b1d0 Size/MD5 checksum: 301464 ebf61bee3343e02ea2d64066a6713424 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: debian-security-announce@lists.debian.org