Vissza a www.andrews.hu-ra

    [guru] Debian biztonsagi frissitesek


    DATE: Wed, 21 Jan 2009 00:42:30 +0100
    Több buffer overflow hibát találtak a streamripper csomag HTTP fejléc
    valamint playlist feldolgozásában.
    
    Stack buffer overflow valamint integer overflow hibát találtak az lcms
    rutinkönyvtárban.
    
    Több buffer overflow valamint NULL deref hibát is találtak az uw-imap
    szerverben.
    
    Buffer overflow hibát találtak a no-ip dinamikus dns kliens HTTP
    feldolgozójában.
    
    Több biztonsági hibát is találtak a 2.6-os kernel szériában: lokális
    DoS és esetleges kód futtatás a Virtual Dynamic Shared Objects (vDSO)
    implementációban, DoS lehetőség sérült ext2/ext3 fájlrendszerek
    használatakor, a splice() rendszerhívással akkor is felül lehet írni
    állományokat, ha azokat csak hozzáfűzésre nyitottuk meg, DoS lehetőség
    az SCTP alrendszerben, DoS lehetőség sérült hfsplus fájlrendszerek
    használatakor, DoS lehetőségek a unix domain socket-ek használatakor,
    DoS lehetőség az ATM alrendszerben, race miatt plusz jogok szerezhetőek
    az inotify alrendszer segítségével.
    
    SQL injection hibát találtak a courier-authlib csomagban, mind a MySQL
    mind a PostgreSQL backend érintett.
    
    Az előző File::Path::rmtree perl modul javítás hibát okozott, így most
    újabb javítást adtak ki.
    
    CSRF hibát találtak a ProFTPD-ben, túl hosszú parancsok két parancsként
    értelmeződnek.
    
    Két DoS hibát is találtak az avahi daemon-ban.
    
    Több biztonsági hibát (XSS, CSRF, SQL injection, plusz jogok szerzése)
    is találtak a moodle rendszerben.
    
    XSS hibát találtak a php-xajax csomagban.
    
    Több biztonsági hibát (XSS, directory traversal) is találtak a phppgadmin
    csomagban.
    
    Az xterm megfelelő escape szekvencia hatására megadott karaktersorozatot
    az input pufferbe helyez. E mellett biztonsági okokból még számtalan
    hasonló escape szekvenciát letiltottak.
    
    A ruby csomagok reguláris minta kezelője memleak-et tartalmazott. Az
    előző REXML XML parser javítás hibát okozott, így most ezt is korrigálták.
    
    Több biztonsági hibát is találtak az icedove, iceape, xulrunner és
    iceweasel csomagokban.
    
    SQL injection hibát találtak a gforge csomagban.
    
    Kernel buffer overflow hibát találtak a zaptel csomagban.
    
    Az OpenSSL csomag DSA aláírás ellenőrzési API-ját sokan hibásan használták,
    aminek hatására tévesen elfogadtak nem megfelelő certificate-eket is.
    
    A lasso, ntp, bind9 csomagok nem megfelelően használták az OpenSSL
    DSA_verify() API-ját, így nem hiteles certificate-eket is elfogadtak.
    
    Command injection hibát találtak a netatalk csomagban.
    
    Több integer overflow hibát is találtak az amarok csomagban.
    
    Shell command injection hibát találtak a git-core csomag gitweb
    alrendszerében.
    
    
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1683-1                  security@debian.org
    http://www.debian.org/security/                           Florian Weimer
    December 08, 2008                     http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : streamripper
    Vulnerability  : buffer overflow
    Problem type   : local (remote)
    Debian-specific: no
    CVE Id(s)      : CVE-2007-4337 CVE-2008-4829
    Debian Bug     : 506377
    
    Multiple buffer overflows involving HTTP header and playlist parsing
    have been discovered in streamripper (CVE-2007-4337, CVE-2008-4829).
    
    For the stable distribution (etch), these problems have been fixed in
    version 1.61.27-1+etch1.
    
    For the unstable distribution (sid) and the testing distribution
    (lenny), these problems have been fixed in version 1.63.5-2.
    
    We recommend that you upgrade your streamripper package.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/s/streamripper/streamripper_1.61.27.orig.tar.gz
        Size/MD5 checksum:   294218 8761dda030f92cbdfa38e73a981cc6bc
      http://security.debian.org/pool/updates/main/s/streamripper/streamripper_1.61.27-1+etch1.diff.gz
        Size/MD5 checksum:     5040 0a4fe994a155d07163b3455df5c2668b
      http://security.debian.org/pool/updates/main/s/streamripper/streamripper_1.61.27-1+etch1.dsc
        Size/MD5 checksum:      964 67ddf22de3c0642e41245e07e534c992
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/s/streamripper/streamripper_1.61.27-1+etch1_alpha.deb
        Size/MD5 checksum:    84142 9450efa0b7fcfce8e976a0a1acb9e837
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/s/streamripper/streamripper_1.61.27-1+etch1_amd64.deb
        Size/MD5 checksum:    75808 0d0d435b05e1c7b5bf2aa375b6569ae4
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/s/streamripper/streamripper_1.61.27-1+etch1_arm.deb
        Size/MD5 checksum:    70992 3d77dcfe3d7785aaed4544cdfd3a8489
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/s/streamripper/streamripper_1.61.27-1+etch1_hppa.deb
        Size/MD5 checksum:    77884 aff00b60cc13c3c46232f86a1bfab553
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/s/streamripper/streamripper_1.61.27-1+etch1_i386.deb
        Size/MD5 checksum:    71180 61c43e7298aac28f4e96287e7eb8b1b0
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/s/streamripper/streamripper_1.61.27-1+etch1_ia64.deb
        Size/MD5 checksum:    99678 b18634cd32a198e747aa99470d3863ab
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/s/streamripper/streamripper_1.61.27-1+etch1_mips.deb
        Size/MD5 checksum:    78584 a417879681280d7f4640557cf1b6085a
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/s/streamripper/streamripper_1.61.27-1+etch1_mipsel.deb
        Size/MD5 checksum:    78814 c92e229fc90db4cf408ee44a619545ee
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/s/streamripper/streamripper_1.61.27-1+etch1_powerpc.deb
        Size/MD5 checksum:    76114 45d0eaaea3a1ec5d874aa9f51221d89c
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/s/streamripper/streamripper_1.61.27-1+etch1_s390.deb
        Size/MD5 checksum:    75984 7aaff15041ece4095eaa1ab470aed7b6
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/s/streamripper/streamripper_1.61.27-1+etch1_sparc.deb
        Size/MD5 checksum:    70322 78e266c09b92286776216406420f1220
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJPW3fAAoJEL97/wQC1SS+xaIH/RD5w1SisDVPgeQ412g0TXVA
    wx1/cUqmJ2ZR7ShBryz/IPsBRrjzsyfdqd7kWKTofJow+pdFgJDzEPFtPo9w7Db+
    RVHSktWqc5qraUnIFW7qwH55TjTrPVFoUOL7uBbsJVdVHNH06tRvPpeQ4SRjdKvO
    jDms08jk4pcU/Uz2yBfQJ45Ql5TXedVE0E60CkEzOYmzabM/YfJkSO+yH2SfAl6g
    JYguCSe6O2HDQFkEXbKwGsWnZTdg5V2xrTZraU/XZMZc6QvefAv4djc7iM3nwtsi
    VNR2cKYpqVF5g+FeSPZtajG3uqZwuCWNmE4TzmjF4vnt59Wq8GmpX/5hpoALC/M=
    =gyJj
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1684                    security@debian.org
    http://www.debian.org/security/                           Devin Carraway
    December 10, 2008                     http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : lcms
    Vulnerability  : multiple vulnerabilities
    Problem type   : local (remote)
    Debian-specific: no
    CVE Id(s)      : CVE-2008-5316 CVE-2008-5317
    
    Two vulnerabilities have been found in lcms, a library and set of
    commandline utilities for image color management.  The Common
    Vulnerabilities and Exposures project identifies the following
    problems:
    
    CVE-2008-5316
    
        Inadequate enforcement of fixed-length buffer limits allows an
        attacker to overflow a buffer on the stack, potentially enabling
        the execution of arbitrary code when a maliciously-crafted
        image is opened.
    
    CVS-2008-5317
    
        An integer sign error in reading image gamma data could allow an
        attacker to cause an under-sized buffer to be allocated for
        subsequent image data, with unknown consequences potentially
        including the execution of arbitrary code if a maliciously-crafted
        image is opened.
    
    For the stable distribution (etch), these problems have been fixed in
    version 1.14-1.1+etch1.
    
    For the upcoming stable distribution (lenny), and the unstable
    distribution (sid), these problems are fixed in version 1.17.dfsg-1.
    
    We recommend that you upgrade your lcms packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Debian (stable)
    - ---------------
    
    Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/l/lcms/lcms_1.15-1.1+etch1.diff.gz
        Size/MD5 checksum:     2000 10fb445280ea38542701017292ffb1ca
      http://security.debian.org/pool/updates/main/l/lcms/lcms_1.15.orig.tar.gz
        Size/MD5 checksum:   791543 95a710dc757504f6b02677c1fab68e73
      http://security.debian.org/pool/updates/main/l/lcms/lcms_1.15-1.1+etch1.dsc
        Size/MD5 checksum:      636 188344016765736e5690a669a6dce88b
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1-dev_1.15-1.1+etch1_alpha.deb
        Size/MD5 checksum:   179622 a64aa233ae03aa942c34e28af411f5fe
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1_1.15-1.1+etch1_alpha.deb
        Size/MD5 checksum:   153452 12b7bbd297ef50a85f19da90d1c4f30f
      http://security.debian.org/pool/updates/main/l/lcms/liblcms-utils_1.15-1.1+etch1_alpha.deb
        Size/MD5 checksum:    61580 a821798d40f1d0990a053b825db129a8
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/l/lcms/liblcms-utils_1.15-1.1+etch1_amd64.deb
        Size/MD5 checksum:    53284 7eb60db022f80565251a0e4d9cadd8b2
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1_1.15-1.1+etch1_amd64.deb
        Size/MD5 checksum:   140288 2b3fa89b3757f0431e2ab3e44f7d1c08
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1-dev_1.15-1.1+etch1_amd64.deb
        Size/MD5 checksum:   147692 e8be34ecb4af9f7cfe1e51c759fc2c27
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1_1.15-1.1+etch1_arm.deb
        Size/MD5 checksum:   135546 523110a99549778b3a5a9ddf38b381e5
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1-dev_1.15-1.1+etch1_arm.deb
        Size/MD5 checksum:   135376 0e4f0fabbc9a04bc593f1887a1bcf35f
      http://security.debian.org/pool/updates/main/l/lcms/liblcms-utils_1.15-1.1+etch1_arm.deb
        Size/MD5 checksum:    50962 7f38a7371ca57f25080f227a3a3b373a
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1-dev_1.15-1.1+etch1_hppa.deb
        Size/MD5 checksum:   168420 e5aab4f34d88b9f8aefd43fed5f2fe78
      http://security.debian.org/pool/updates/main/l/lcms/liblcms-utils_1.15-1.1+etch1_hppa.deb
        Size/MD5 checksum:    59120 88bf9add52df55b353d0d26508486a96
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1_1.15-1.1+etch1_hppa.deb
        Size/MD5 checksum:   157652 30f8396d4f78363befd2e0d72b9e56a8
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1_1.15-1.1+etch1_i386.deb
        Size/MD5 checksum:   137296 46695836065eb7b734e02706191872f7
      http://security.debian.org/pool/updates/main/l/lcms/liblcms-utils_1.15-1.1+etch1_i386.deb
        Size/MD5 checksum:    50592 4a0ca0dc60e6e212bf3692b2785b088b
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1-dev_1.15-1.1+etch1_i386.deb
        Size/MD5 checksum:   143282 850ff5b97f347775c1daad08280a5b38
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1-dev_1.15-1.1+etch1_ia64.deb
        Size/MD5 checksum:   204162 abd829e3c02d54dc911aa4abe343e377
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1_1.15-1.1+etch1_ia64.deb
        Size/MD5 checksum:   195094 5766c05fb15abe32d908f7b607464bb7
      http://security.debian.org/pool/updates/main/l/lcms/liblcms-utils_1.15-1.1+etch1_ia64.deb
        Size/MD5 checksum:    78422 6176b8abb40f4dc50ed80472fe835fa5
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/l/lcms/liblcms-utils_1.15-1.1+etch1_mips.deb
        Size/MD5 checksum:    51508 20274ee9af873cf1760fad77d4cb5720
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1-dev_1.15-1.1+etch1_mips.deb
        Size/MD5 checksum:   172570 4dc3f233db7f2c15b26b39a04e7dd1ba
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1_1.15-1.1+etch1_mips.deb
        Size/MD5 checksum:   149190 db10ac87adfd9698890428f3119045fd
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1_1.15-1.1+etch1_mipsel.deb
        Size/MD5 checksum:   150390 62a81236533a4b708919367d5939d34c
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1-dev_1.15-1.1+etch1_mipsel.deb
        Size/MD5 checksum:   173934 d8618284820cf47bc677c185c6ea5c39
      http://security.debian.org/pool/updates/main/l/lcms/liblcms-utils_1.15-1.1+etch1_mipsel.deb
        Size/MD5 checksum:    52142 2213c852eaab6fbfee23031401214ecd
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1-dev_1.15-1.1+etch1_powerpc.deb
        Size/MD5 checksum:   147308 d0c6bcfe7a23740f15b4e8dae4b9ea74
      http://security.debian.org/pool/updates/main/l/lcms/liblcms-utils_1.15-1.1+etch1_powerpc.deb
        Size/MD5 checksum:    57630 cc7b4fc9ca44268952ef4b9fc97fe631
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1_1.15-1.1+etch1_powerpc.deb
        Size/MD5 checksum:   147710 8b586e00c2f39017bd2d51e0632297af
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1-dev_1.15-1.1+etch1_s390.deb
        Size/MD5 checksum:   142054 622fed5f31c26119ca611e5c5aa79b1d
      http://security.debian.org/pool/updates/main/l/lcms/liblcms-utils_1.15-1.1+etch1_s390.deb
        Size/MD5 checksum:    54150 45b3c4c471d977b53d40a2ab57e63591
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1_1.15-1.1+etch1_s390.deb
        Size/MD5 checksum:   144324 f8f15540a7cdbcfe5fc32fe40b3e459b
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1-dev_1.15-1.1+etch1_sparc.deb
        Size/MD5 checksum:   146618 2e09901e82467a8e02e12c958bf699db
      http://security.debian.org/pool/updates/main/l/lcms/liblcms-utils_1.15-1.1+etch1_sparc.deb
        Size/MD5 checksum:    51410 7622942be787382b8abc72e9d709aeb8
      http://security.debian.org/pool/updates/main/l/lcms/liblcms1_1.15-1.1+etch1_sparc.deb
        Size/MD5 checksum:   137480 111c3ff8c742773fc12237147f6d138c
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iD8DBQFJP2/RU5XKDemr/NIRArcDAJ9TXSCs0sUBywG2XSrK/8wZyiIldACeMIrt
    jE70wuDFt1ssn8saHIb/G2s=
    =Cn4v
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1685-1                  security@debian.org
    http://www.debian.org/security/                           Steffen Joeris
    December 12, 2008                     http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : uw-imap
    Vulnerability  : buffer overflows, null pointer dereference
    Problem type   : remote
    Debian-specific: no
    CVE Id(s)      : CVE-2008-5005 CVE-2008-5006
    
    Two vulnerabilities have been found in uw-imap, an IMAP
    implementation. The Common Vulnerabilities and Exposures project
    identifies the following problems:
    
    It was discovered that several buffer overflows can be triggered via a
    long folder extension argument to the tmail or dmail program. This
    could lead to arbitrary code execution (CVE-2008-5005).
    
    It was discovered that a NULL pointer dereference could be triggered by
    a malicious response to the QUIT command leading to a denial of service
    (CVE-2008-5006).
    
    For the stable distribution (etch), these problems have been fixed in
    version 2002edebian1-13.1+etch1.
    
    For the unstable distribution (sid) and the testing distribution
    (lenny), these problems have been fixed in version 2007d~dfsg-1.
    
    We recommend that you upgrade your uw-imap packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imap_2002edebian1.orig.tar.gz
        Size/MD5 checksum:  1517069 8ff277e7831326988d0ee0bfeca7c8ff
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imap_2002edebian1-13.1+etch1.dsc
        Size/MD5 checksum:      874 ac3703de07e1cf10e7aa72a10a5fb20b
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imap_2002edebian1-13.1+etch1.diff.gz
        Size/MD5 checksum:    99906 6c0172a213d199583e0d6c1dc5957a20
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/u/uw-imap/ipopd-ssl_2002edebian1-13.1+etch1_all.deb
        Size/MD5 checksum:    20760 b418a43ee29d858752497a83897588c9
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd-ssl_2002edebian1-13.1+etch1_all.deb
        Size/MD5 checksum:    20756 4381ee8fe7865bc2fbf4f83f44ddd0e3
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_alpha.deb
        Size/MD5 checksum:    50618 972cf2d773feb8547ba6cc0bd933dbea
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client2002edebian_2002edebian1-13.1+etch1_alpha.deb
        Size/MD5 checksum:   650718 1d084bff43e5efde07706f8b54134625
      http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_alpha.deb
        Size/MD5 checksum:    47364 d1550ecb166961b3dd7c948fd7333e18
      http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_alpha.deb
        Size/MD5 checksum:    26688 9a2ed6fd202bd4b7dfbd555170664979
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_alpha.deb
        Size/MD5 checksum:    80168 d26aa9867204cbc27107bc0eb046649a
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client-dev_2002edebian1-13.1+etch1_alpha.deb
        Size/MD5 checksum:  1196482 41dba8f6a0cc1b7c602060ddf3dae58c
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client-dev_2002edebian1-13.1+etch1_amd64.deb
        Size/MD5 checksum:  1040748 89a2bb86ee48bbc3ce0ce6ac06736e5d
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_amd64.deb
        Size/MD5 checksum:    76348 e2506d3191e383e511b73851f7b2403d
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_amd64.deb
        Size/MD5 checksum:    50416 9db96b845240094cb130050463e5b8da
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client2002edebian_2002edebian1-13.1+etch1_amd64.deb
        Size/MD5 checksum:   606040 458cf8d820a650978eed89b234c2d018
      http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_amd64.deb
        Size/MD5 checksum:    46470 a6f2e3922fdd861d7209635ffc03b35b
      http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_amd64.deb
        Size/MD5 checksum:    26394 847986887b14d0a038057478d2b30872
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_arm.deb
        Size/MD5 checksum:    46642 b0e4a64cf30e20dc069e3a57259235ce
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_arm.deb
        Size/MD5 checksum:    75798 b41386db73222899258e743a33c4f639
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client-dev_2002edebian1-13.1+etch1_arm.deb
        Size/MD5 checksum:   959814 d4589284f56b8e5746495c7ffb107a91
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client2002edebian_2002edebian1-13.1+etch1_arm.deb
        Size/MD5 checksum:   589126 91754725dff8d6cea245b24af8b963bb
      http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_arm.deb
        Size/MD5 checksum:    26082 fbe01ef72a463c603ee2802d5a83c863
      http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_arm.deb
        Size/MD5 checksum:    46566 f8e9a765ce2398f1361b2a3d23fc68ae
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_hppa.deb
        Size/MD5 checksum:    49834 38e164bb266c4ac2b64efb1823520ad2
      http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_hppa.deb
        Size/MD5 checksum:    26948 859538b21ee583afd0eae0fe23f5ccec
      http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_hppa.deb
        Size/MD5 checksum:    48276 fc635c859779ac21c7f3b5e1330ac96e
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_hppa.deb
        Size/MD5 checksum:    78030 13a4830e58146dada9a4312ea1c0878e
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client-dev_2002edebian1-13.1+etch1_hppa.deb
        Size/MD5 checksum:  1122112 6816e9ad9b34393fdc0a2a13d5e6c03a
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client2002edebian_2002edebian1-13.1+etch1_hppa.deb
        Size/MD5 checksum:   638360 a22f4b8a0309cb3f7f24281c4b180c40
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_i386.deb
        Size/MD5 checksum:    26270 918de156aad623e201675f53e5a7390b
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_i386.deb
        Size/MD5 checksum:    47736 635d0586f0067de7051a7b96da96489b
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_i386.deb
        Size/MD5 checksum:    73758 92a54d90386b2d791e7833491b1a16e1
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client-dev_2002edebian1-13.1+etch1_i386.deb
        Size/MD5 checksum:   976232 eda1d42fcf0a044eaf7b761090d203ef
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client2002edebian_2002edebian1-13.1+etch1_i386.deb
        Size/MD5 checksum:   598438 10c608db26e0313c24fa806ac841e47e
      http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_i386.deb
        Size/MD5 checksum:    45742 53defc689a358a10ecc885846c42f2bd
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_ia64.deb
        Size/MD5 checksum:    54828 10f59379b3b9710afca1ac83ca409ce8
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_ia64.deb
        Size/MD5 checksum:    89592 8981c9ce87c1a854e986c84ac0284b90
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client-dev_2002edebian1-13.1+etch1_ia64.deb
        Size/MD5 checksum:  1205586 6fe1eb318b9c51cc4ce7dce1c0c2d01e
      http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_ia64.deb
        Size/MD5 checksum:    27648 bb12979a5cf7ff84e0f233167e994b8c
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_ia64.deb
        Size/MD5 checksum:    62708 d601a2d1ef511702fd31c9953abc2dd0
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client2002edebian_2002edebian1-13.1+etch1_ia64.deb
        Size/MD5 checksum:   744690 33ddf81a4b04fe817c95c1f4e828d3d4
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client-dev_2002edebian1-13.1+etch1_mips.deb
        Size/MD5 checksum:  1103000 12bfd3f9698096d667d5623c246b17f6
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_mips.deb
        Size/MD5 checksum:    74734 a88fe50a66f89f4620cc88f0902d384e
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_mips.deb
        Size/MD5 checksum:    47006 3b171e1e0d591d05191e187154600ae0
      http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_mips.deb
        Size/MD5 checksum:    45228 f28bf5c2fb4ca704d151e07ddeb0b14c
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client2002edebian_2002edebian1-13.1+etch1_mips.deb
        Size/MD5 checksum:   606472 919acee3427f101ad7d929611c7b1fa7
      http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_mips.deb
        Size/MD5 checksum:    26006 c8b6b70bcaf09ca353cfcec8030c51ab
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_mipsel.deb
        Size/MD5 checksum:    26482 8a3e4fa1b89f5948ea5647fb56f01faf
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_mipsel.deb
        Size/MD5 checksum:    74914 b6aa38a2f191d317d2d4509670fa9337
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client-dev_2002edebian1-13.1+etch1_mipsel.deb
        Size/MD5 checksum:  1078056 103f0633e98faa29517a63c827109bc5
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_mipsel.deb
        Size/MD5 checksum:    47642 5cc42be0a5dc83fd8ca5b66cf422a974
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client2002edebian_2002edebian1-13.1+etch1_mipsel.deb
        Size/MD5 checksum:   605734 f0de3efdd6f797910ac856c624ec109e
      http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_mipsel.deb
        Size/MD5 checksum:    46028 1ba982a87d77197645a543dc8b27b6a7
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_powerpc.deb
        Size/MD5 checksum:    50206 f4fde759040b7520e72adeea14dd7587
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_powerpc.deb
        Size/MD5 checksum:    74158 b945eea07eec4357825cfc16fed7bf4e
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client2002edebian_2002edebian1-13.1+etch1_powerpc.deb
        Size/MD5 checksum:   605242 5914dedf470cfd20024c20224290e3b0
      http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_powerpc.deb
        Size/MD5 checksum:    26410 2c7881339151f91143572bdf7af420dd
      http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_powerpc.deb
        Size/MD5 checksum:    47642 ad645882db05a4d3fa1080c181eece39
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client-dev_2002edebian1-13.1+etch1_powerpc.deb
        Size/MD5 checksum:  1109820 d5e5f0f48b8edee35e29354119b7d2a3
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client2002edebian_2002edebian1-13.1+etch1_s390.deb
        Size/MD5 checksum:   623664 c635c4b77cef027eb42faef8e6727c59
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_s390.deb
        Size/MD5 checksum:    78150 b5a7a33230a9162e2308446b45466284
      http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_s390.deb
        Size/MD5 checksum:    26540 d45c1a7782161483c37a7e00c8fdc700
      http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_s390.deb
        Size/MD5 checksum:    48374 1fd3a101cd59eb59abec32014c397c18
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_s390.deb
        Size/MD5 checksum:    49490 7ea6ec2d1d99af8ac12a9fee77e3027d
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client-dev_2002edebian1-13.1+etch1_s390.deb
        Size/MD5 checksum:  1109484 0fac4ece552d53c1e5c36d39539c7947
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_sparc.deb
        Size/MD5 checksum:    47416 51529ae793ae7f166c47fb2e23a0413e
      http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_sparc.deb
        Size/MD5 checksum:    46480 81c03a62740ad668f8c008b1a71be6ab
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client-dev_2002edebian1-13.1+etch1_sparc.deb
        Size/MD5 checksum:   967750 8edd729d4e4a9380764efc693b1d50ad
      http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_sparc.deb
        Size/MD5 checksum:    26334 1dc5709d6db104eaf92e327b90b55130
      http://security.debian.org/pool/updates/main/u/uw-imap/libc-client2002edebian_2002edebian1-13.1+etch1_sparc.deb
        Size/MD5 checksum:   596486 3c3eb2be8fb28c59de0d2bb090e0e5b9
      http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_sparc.deb
        Size/MD5 checksum:    74884 39b9e029302ff6eebe08a731882181da
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJQgX7AAoJEL97/wQC1SS+oUQH/3thtH7e8l4AfK6fsgidhRv1
    I7g4omGUHQ86nbyizAOyZpumYBDg5DTOGs3diqDE5dSFYDv9/8vKttSNi/q23flV
    gmQvHHMbLLchzXWR0O6rNUvUBbegh/H+t23mYX3c5SZxaGGpyYHBfyhUeiUi1nMR
    6CoeQexTX1gTl4YeKR2VFwrbvBuWVJYXpKoi3jBL26gn/fUm3sAzDQTPjQURiQGY
    pd7RwvfO8Sx7Ur3XnLm/YYfY0yD9DwoHrnnFK7QQL4JMedip8jt4eiwJunKYzA3S
    jjS5q4U//7UhLolcWKl1rnIIjQk3b92DhN3phztbSRsfcySAnbyZ+4i6R4+kuMw=
    =1LWm
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1686-1                  security@debian.org
    http://www.debian.org/security/                       Moritz Muehlenhoff
    December 14, 2008                     http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : no-ip
    Vulnerability  : buffer overflow
    Problem type   : remote
    Debian-specific: no
    CVE Id(s)      : CVE-2008-5297
    Debian Bug     : 506179
    
    A buffer overflow has been discovered in the HTTP parser of the No-IP.com
    Dynamic DNS update client, which may result in the execution of arbitrary
    code.
    
    For the stable distribution (etch), this problem has been fixed in
    version 2.1.1-4+etch1.
    
    For the upcoming stable distribution (lenny) and the unstable distribution
    (sid), this problem has been fixed in version 2.1.7-11.
    
    We recommend that you upgrade your no-ip package.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/n/no-ip/no-ip_2.1.1-4+etch1.diff.gz
        Size/MD5 checksum:     5099 991539fbaabc7808f1e6540e6d2a7d37
      http://security.debian.org/pool/updates/main/n/no-ip/no-ip_2.1.1.orig.tar.gz
        Size/MD5 checksum:    70553 a743fcd40699596d25347083eca86d52
      http://security.debian.org/pool/updates/main/n/no-ip/no-ip_2.1.1-4+etch1.dsc
        Size/MD5 checksum:      573 a46cc0befc6409b256e76abceec2bba8
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/n/no-ip/no-ip_2.1.1-4+etch1_alpha.deb
        Size/MD5 checksum:    25552 72ada61d338c9ca7ccf22de55168de1b
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/n/no-ip/no-ip_2.1.1-4+etch1_amd64.deb
        Size/MD5 checksum:    22740 eea473fb4410d7b7953150139378b56c
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/n/no-ip/no-ip_2.1.1-4+etch1_arm.deb
        Size/MD5 checksum:    21486 eb86554f2e2b20c382810bcfce21ac96
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/n/no-ip/no-ip_2.1.1-4+etch1_hppa.deb
        Size/MD5 checksum:    23778 7212e0f6ef1b749de5531ff279fe63d1
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/n/no-ip/no-ip_2.1.1-4+etch1_i386.deb
        Size/MD5 checksum:    20838 44598c7737861f61e7c6f012c65228f7
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/n/no-ip/no-ip_2.1.1-4+etch1_ia64.deb
        Size/MD5 checksum:    30888 ba8e62cc6fe5bf70631710b699adb9da
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/n/no-ip/no-ip_2.1.1-4+etch1_mips.deb
        Size/MD5 checksum:    23936 f3d9215b718a083354e9b9426577aafb
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/n/no-ip/no-ip_2.1.1-4+etch1_mipsel.deb
        Size/MD5 checksum:    23854 69f6d783ff8345c565910877e2db4909
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/n/no-ip/no-ip_2.1.1-4+etch1_powerpc.deb
        Size/MD5 checksum:    22514 550fe870f5d0cb85e2ab96c510d70127
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/n/no-ip/no-ip_2.1.1-4+etch1_s390.deb
        Size/MD5 checksum:    22842 37f9132b2f6aae1a828405ae701a325c
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/n/no-ip/no-ip_2.1.1-4+etch1_sparc.deb
        Size/MD5 checksum:    21020 191248685382bb6051853bba9081f012
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    
    
    
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iEYEARECAAYFAklFavwACgkQXm3vHE4uylr6PACfecCxr6ytpCw+L6lwdkRCO1E+
    +osAoMrr6OmEO0SRfP5ViXSr4hglrye5
    =H5rj
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ----------------------------------------------------------------------
    Debian Security Advisory DSA-1687-1                security@debian.org
    http://www.debian.org/security/                           dann frazier
    Dec 15, 2008                        http://www.debian.org/security/faq
    - ----------------------------------------------------------------------
    
    Package        : linux-2.6
    Vulnerability  : denial of service/privilege escalation
    Problem type   : local/remote
    Debian-specific: no
    CVE Id(s)      : CVE-2008-3527 CVE-2008-3528 CVE-2008-4554 CVE-2008-4576
                     CVE-2008-4933 CVE-2008-4934 CVE-2008-5025 CVE-2008-5029
                     CVE-2008-5079 CVE_2008-5182 CVE-2008-5300
    
    Several vulnerabilities have been discovered in the Linux kernel that
    may lead to a denial of service or privilege escalation. The Common
    Vulnerabilities and Exposures project identifies the following
    problems:
    
    CVE-2008-3527
    
        Tavis Ormandy reported a local DoS and potential privilege
        escalation in the Virtual Dynamic Shared Objects (vDSO)
        implementation.
    
    CVE-2008-3528
    
        Eugene Teo reported a local DoS issue in the ext2 and ext3
        filesystems.  Local users who have been granted the privileges
        necessary to mount a filesystem would be able to craft a corrupted
        filesystem that causes the kernel to output error messages in an
        infinite loop.
    
    CVE-2008-4554
    
        Milos Szeredi reported that the usage of splice() on files opened
        with O_APPEND allows users to write to the file at arbitrary
        offsets, enabling a bypass of possible assumed semantics of the
        O_APPEND flag.
    
    CVE-2008-4576
    
        Vlad Yasevich reported an issue in the SCTP subsystem that may
        allow remote users to cause a local DoS by triggering a kernel
        oops.
    
    CVE-2008-4933
    
        Eric Sesterhenn reported a local DoS issue in the hfsplus
        filesystem.  Local users who have been granted the privileges
        necessary to mount a filesystem would be able to craft a corrupted
        filesystem that causes the kernel to overrun a buffer, resulting
        in a system oops or memory corruption.
    
    CVE-2008-4934
    
        Eric Sesterhenn reported a local DoS issue in the hfsplus
        filesystem.  Local users who have been granted the privileges
        necessary to mount a filesystem would be able to craft a corrupted
        filesystem that results in a kernel oops due to an unchecked
        return value.
    
    CVE-2008-5025
    
        Eric Sesterhenn reported a local DoS issue in the hfs filesystem.
        Local users who have been granted the privileges necessary to
        mount a filesystem would be able to craft a filesystem with a
        corrupted catalog name length, resulting in a system oops or
        memory corruption.
    
    CVE-2008-5029
    
        Andrea Bittau reported a DoS issue in the unix socket subsystem
        that allows a local user to cause memory corruption, resulting in
        a kernel panic.
    
    CVE-2008-5079
    
        Hugo Dias reported a DoS condition in the ATM subsystem that can
        be triggered by a local user by calling the svc_listen function
        twice on the same socket and reading /proc/net/atm/*vc.
    
    CVE_2008-5182
    
        Al Viro reported race conditions in the inotify subsystem that may
        allow local users to acquire elevated privileges.
    
    CVE-2008-5300
    
        Dann Frazier reported a DoS condition that allows local users to
        cause the out of memory handler to kill off privileged processes
        or trigger soft lockups due to a starvation issue in the unix
        socket subsystem.
    
    For the stable distribution (etch), this problem has been fixed in
    version 2.6.18.dfsg.1-23etch1.
    
    We recommend that you upgrade your linux-2.6, fai-kernels, and
    user-mode-linux packages.
    
    Note: Debian 'etch' includes linux kernel packages based upon both the
    2.6.18 and 2.6.24 linux releases.  All known security issues are
    carefully tracked against both packages and both packages will receive
    security updates until security support for Debian 'etch'
    concludes. However, given the high frequency at which low-severity
    security issues are discovered in the kernel and the resource
    requirements of doing an update, lower severity 2.6.18 and 2.6.24
    updates will typically release in a staggered or "leap-frog" fashion.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    The following matrix lists additional source packages that were rebuilt for
    compatability with or to take advantage of this update:
    
                                                 Debian 4.0 (etch)
         fai-kernels                             1.17+etch.23etch1
         user-mode-linux                         2.6.18-1um-2etch.23etch1
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/u/user-mode-linux/user-mode-linux_2.6.18-1um-2etch.23etch1.diff.gz
        Size/MD5 checksum:    19360 f0384a843ffc8952cbff2e25fe627a6b
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-2.6_2.6.18.dfsg.1-23etch1.diff.gz
        Size/MD5 checksum:  5413401 4a10af0cabdc8530b9c0d72891db9a42
      http://security.debian.org/pool/updates/main/u/user-mode-linux/user-mode-linux_2.6.18-1um.orig.tar.gz
        Size/MD5 checksum:    14435 4d10c30313e11a24621f7218c31f3582
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-2.6_2.6.18.dfsg.1.orig.tar.gz
        Size/MD5 checksum: 52225460 6a1ab0948d6b5b453ea0fce0fcc29060
      http://security.debian.org/pool/updates/main/f/fai-kernels/fai-kernels_1.17+etch.23etch1.tar.gz
        Size/MD5 checksum:    57771 c453400f733526582aa19eec52109711
      http://security.debian.org/pool/updates/main/f/fai-kernels/fai-kernels_1.17+etch.23etch1.dsc
        Size/MD5 checksum:      740 f36c4fb705e5b9c7d698421d0aacf047
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-2.6_2.6.18.dfsg.1-23etch1.dsc
        Size/MD5 checksum:     5672 8293966d44f0bf254e9f9f5ed1630542
      http://security.debian.org/pool/updates/main/u/user-mode-linux/user-mode-linux_2.6.18-1um-2etch.23etch1.dsc
        Size/MD5 checksum:      892 c7b86a1845bc273e6a7f0471e0555e58
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-patch-debian-2.6.18_2.6.18.dfsg.1-23etch1_all.deb
        Size/MD5 checksum:  1682698 9a53cd9991cfb454d638dbad8cea00b3
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-source-2.6.18_2.6.18.dfsg.1-23etch1_all.deb
        Size/MD5 checksum: 41465432 23de1cd9c2a0fbb63065f924e5a9d00f
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-doc-2.6.18_2.6.18.dfsg.1-23etch1_all.deb
        Size/MD5 checksum:  3591554 d533d238b7e6864a72d0161a26ebb31a
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-tree-2.6.18_2.6.18.dfsg.1-23etch1_all.deb
        Size/MD5 checksum:    56918 822b3798ded87ac2b2729e55d410084e
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-manual-2.6.18_2.6.18.dfsg.1-23etch1_all.deb
        Size/MD5 checksum:  1090466 1f40c0abee8e501ef9ec411045f542f5
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-support-2.6.18-6_2.6.18.dfsg.1-23etch1_all.deb
        Size/MD5 checksum:  3720252 97794d565ab5db3db6cba485c2af80f0
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-alpha-generic_2.6.18.dfsg.1-23etch1_alpha.deb
        Size/MD5 checksum:   269882 c508165b7055b5193accbb4cdc037671
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-alpha-legacy_2.6.18.dfsg.1-23etch1_alpha.deb
        Size/MD5 checksum: 23468062 084f93a39246bf56e459ce5c831e0f36
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-alpha-legacy_2.6.18.dfsg.1-23etch1_alpha.deb
        Size/MD5 checksum:   270122 e14bc28b97a2ef24f619b5e16d72f175
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-vserver-alpha_2.6.18.dfsg.1-23etch1_alpha.deb
        Size/MD5 checksum:   270508 c85a852e5eaddd497fa52df9f54c426f
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-vserver-alpha_2.6.18.dfsg.1-23etch1_alpha.deb
        Size/MD5 checksum: 23540558 a415d6aa887683a04706d9a6274549ed
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all_2.6.18.dfsg.1-23etch1_alpha.deb
        Size/MD5 checksum:    56324 ffaae9d352af3b89e8166e2751ff3e47
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all-alpha_2.6.18.dfsg.1-23etch1_alpha.deb
        Size/MD5 checksum:    56358 913ae5005ebdf8f65944e0f86d5f5242
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6_2.6.18.dfsg.1-23etch1_alpha.deb
        Size/MD5 checksum:  3030252 2d943108a84cc4a642465732859ee59d
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-alpha-smp_2.6.18.dfsg.1-23etch1_alpha.deb
        Size/MD5 checksum:   269298 0e763ecd42cc9c8dca46a4abc14754ce
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-vserver_2.6.18.dfsg.1-23etch1_alpha.deb
        Size/MD5 checksum:  3055080 07159b547402fc8e14b8a02e0310a1c3
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-alpha-smp_2.6.18.dfsg.1-23etch1_alpha.deb
        Size/MD5 checksum: 23846502 aebc7b1a914bae3eec6c5ce06eae800a
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-alpha-generic_2.6.18.dfsg.1-23etch1_alpha.deb
        Size/MD5 checksum: 23488466 177f9079cdaa79bb409b8f79ad91db2f
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum:  3170560 255cf26cc9f2a0caa6ce02fda46d7070
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-modules-2.6.18-6-xen-amd64_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum: 15263274 af1df9c75bc768c64ce052962d81b8e7
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum:    56316 13388b32d4f08245e24a3055ad369d6a
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-xen-vserver-amd64_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum:   274084 1446f3f108c3ef6f710e1c83bdc7794c
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-vserver-amd64_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum: 16865488 e74a4409424bc37afd3cf8d84e7a88ef
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-amd64_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum:   273434 88baa6c7c91768f11cf7356963f0bb21
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-xen-vserver_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum:  3359676 1fe292880b5f92a74e6bca61695082f3
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all-amd64_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum:    56338 a5bcb5abdc16f269afeb96d50f725136
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-modules-2.6.18-6-xen-vserver-amd64_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum: 15276526 f2eec94a9296818d23e1e970abc78d37
      http://security.debian.org/pool/updates/main/f/fai-kernels/fai-kernels_1.17+etch.23etch1_amd64.deb
        Size/MD5 checksum:  5965696 94d7fd7aa223d2f54bcb64cbf553b299
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-vserver_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum:  3193726 368d1927a908710ac8a243776e32c3d5
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-xen_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum:  3336820 46a4ddc2261240174c15cc854ed4ff08
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-xen-amd64_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum:  1654746 c4a5b2789d28ab76a9bedebf0a8916c8
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-amd64_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum: 16821542 978c7d8f1be5b7489a9e566cfc91acc1
      http://security.debian.org/pool/updates/main/l/linux-2.6/xen-linux-system-2.6.18-6-xen-amd64_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum:    56294 3fa8984302102d25341ed91540c6ed1f
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-xen-vserver-amd64_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum:  1687270 8da6624be3045a0a6893d6038db454e3
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-vserver-amd64_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum:   273164 985a1e8e8719d786b32db0162f999b2f
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-xen-amd64_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum:   273524 f00fff5b0c7480e6e16a32d9ccaa2c03
      http://security.debian.org/pool/updates/main/l/linux-2.6/xen-linux-system-2.6.18-6-xen-vserver-amd64_2.6.18.dfsg.1-23etch1_amd64.deb
        Size/MD5 checksum:    56306 93073a5b9a30ea081f0e9c12c6488d62
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-ixp4xx_2.6.18.dfsg.1-23etch1_arm.deb
        Size/MD5 checksum:  8874552 a280220d21fc5f33397ceccb611b16d3
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-iop32x_2.6.18.dfsg.1-23etch1_arm.deb
        Size/MD5 checksum:   236070 b8d951c3d18f5850af73db2d5afe93a6
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-footbridge_2.6.18.dfsg.1-23etch1_arm.deb
        Size/MD5 checksum:   235742 5212f40bfeace58989418ae3d8eb6e85
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-rpc_2.6.18.dfsg.1-23etch1_arm.deb
        Size/MD5 checksum:   201472 d25b41af0a2f65cd399c754855680087
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-rpc_2.6.18.dfsg.1-23etch1_arm.deb
        Size/MD5 checksum:  4591646 e2480d80466cb9dd0f6a225d25c256a6
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-s3c2410_2.6.18.dfsg.1-23etch1_arm.deb
        Size/MD5 checksum:  5015244 e0db634e60cfd8182051d7fdc44b5961
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-iop32x_2.6.18.dfsg.1-23etch1_arm.deb
        Size/MD5 checksum:  7927900 94e7099950e3e48ec90a0a120ac48c3e
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6_2.6.18.dfsg.1-23etch1_arm.deb
        Size/MD5 checksum:  3412788 0d97a5df1ef81a19bb749f7eff564450
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all-arm_2.6.18.dfsg.1-23etch1_arm.deb
        Size/MD5 checksum:    56422 698a5a5e7869490e094876dee3ccb040
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all_2.6.18.dfsg.1-23etch1_arm.deb
        Size/MD5 checksum:    56370 92d68631cccf9193aa86be44565293b9
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-s3c2410_2.6.18.dfsg.1-23etch1_arm.deb
        Size/MD5 checksum:   206500 5ac78126922a636b71ee93be06a8efc0
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-ixp4xx_2.6.18.dfsg.1-23etch1_arm.deb
        Size/MD5 checksum:   241160 b3ba90c2e590d5f2d35b2ec87f0583e4
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-footbridge_2.6.18.dfsg.1-23etch1_arm.deb
        Size/MD5 checksum:  7571386 858738aafc789736b85a240abb06d6d1
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-parisc64-smp_2.6.18.dfsg.1-23etch1_hppa.deb
        Size/MD5 checksum: 11816650 3eb4a8a52b839f37522c13bf261c2baf
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-parisc-smp_2.6.18.dfsg.1-23etch1_hppa.deb
        Size/MD5 checksum:   198896 a243bf6d1631e669536291524fd97ba8
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all-hppa_2.6.18.dfsg.1-23etch1_hppa.deb
        Size/MD5 checksum:    56350 c692a9c128d4fb72bdf62443208b9afc
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-parisc-smp_2.6.18.dfsg.1-23etch1_hppa.deb
        Size/MD5 checksum: 11006106 0def26738a5c0a14e25159f54ef45c9e
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-parisc_2.6.18.dfsg.1-23etch1_hppa.deb
        Size/MD5 checksum:   197558 bd829e318bf0ca91e73fae9591baa333
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-parisc64_2.6.18.dfsg.1-23etch1_hppa.deb
        Size/MD5 checksum: 11410956 261b9a7e7b2404c6eacd2317b9e26973
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all_2.6.18.dfsg.1-23etch1_hppa.deb
        Size/MD5 checksum:    56326 6dcc57928f2d3ce4fb73d0450e66ceaf
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-parisc64-smp_2.6.18.dfsg.1-23etch1_hppa.deb
        Size/MD5 checksum:   199820 1a553bcc50cf8010f555eec232d633fc
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6_2.6.18.dfsg.1-23etch1_hppa.deb
        Size/MD5 checksum:  3024676 bf1f90dbddccc38ecdbabc350dbb080e
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-parisc64_2.6.18.dfsg.1-23etch1_hppa.deb
        Size/MD5 checksum:   198504 2b5266526f59cb83af41ea197cd14e3b
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-parisc_2.6.18.dfsg.1-23etch1_hppa.deb
        Size/MD5 checksum: 10559544 bd90bbbc7d8a8c6906a51bbf49b3e139
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-xen_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:  3212506 2f2838b74c687f49092cba088aaa5025
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-vserver-686_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:   285422 716cabff79e8d108409024beedd5c761
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:    56364 23fefb20fc7cfb2969c70ec3dcbfd7fc
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-xen-vserver_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:  3236014 280e515e4d33b74171f18d90192f2781
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-486_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:   289742 0291669c961118af2f8d392d83cc2009
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-modules-2.6.18-6-xen-686_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum: 14388800 1ef26929395c35dd69c68e7d7d539387
      http://security.debian.org/pool/updates/main/u/user-mode-linux/user-mode-linux_2.6.18-1um-2etch.23etch1_i386.deb
        Size/MD5 checksum: 25602042 8edf459235cf919e70db35db6e18a81c
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-686-bigmem_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum: 16540456 b64fd698fbb01314bd39b32b410ae487
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-xen-vserver-686_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:   278156 d87fae685c6799e42afdfb33ca8efd42
      http://security.debian.org/pool/updates/main/f/fai-kernels/fai-kernels_1.17+etch.23etch1_i386.deb
        Size/MD5 checksum:  5508624 94bb0b0b80f8036b518837d5ce029f2b
      http://security.debian.org/pool/updates/main/l/linux-2.6/xen-linux-system-2.6.18-6-xen-vserver-686_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:    56376 fbc3b44752cc24d54018e7500b7caa9c
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-k7_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum: 16601198 58ad14c5b7a86283125b9d73f98c40ce
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-xen-vserver-686_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:  1330892 02d869d6e62a29107871094dad2d2bfb
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-k7_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:   286882 017783780fc1c626df5e6a739713cd2c
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-xen-686_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:   278354 41e31611644a950b6a7b13e21c8fcb14
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-vserver_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:  3114734 cc9dc53c187d950a1d154a4f59cd54df
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-modules-2.6.18-6-xen-vserver-686_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum: 14399606 21d200751abc6f09ad0fe60d5c4655ec
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-amd64_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum: 16929578 4cc1238df2386a76dcd12ce916965be5
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-686-bigmem_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:   287314 383667c0683ced9603f2a21be6105158
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-686_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum: 16474612 6ffb3493ae7141c3af2b00e513bda9b2
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all-i386_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:    56422 eaad4bcfac9784563526b3ef77c3bbfe
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:  3228386 53af98a695ee7732f5b682f013e81c9d
      http://security.debian.org/pool/updates/main/l/linux-2.6/xen-linux-system-2.6.18-6-xen-686_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:    56348 def2ca9b2ceafe1170c6091f170d201d
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-vserver-k7_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:   285644 2494d714e732fe2ca909cd80e0d4fcc2
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-vserver-686_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum: 16514302 bbeabc71068d2664535d4d3b7d166b44
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-vserver-k7_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum: 16642362 1d69f5a6471d29ff481ccccdece1d5a3
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-686_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:   286868 76a6bbbb7810bab391fecd078ea713a6
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-486_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum: 16323394 ac86cb6986fc48439edf76d0e78c75c4
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-amd64_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:   276950 548444172100ee78f39b3cbddfb0bd73
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-xen-686_2.6.18.dfsg.1-23etch1_i386.deb
        Size/MD5 checksum:  1302696 a9988c16e715718a4d4547edf77d8c63
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all_2.6.18.dfsg.1-23etch1_ia64.deb
        Size/MD5 checksum:    56320 22738127d1c9ce4acc5538d0014fef5d
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all-ia64_2.6.18.dfsg.1-23etch1_ia64.deb
        Size/MD5 checksum:    56342 ecb66f5138131a351ea46167feda50a4
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6_2.6.18.dfsg.1-23etch1_ia64.deb
        Size/MD5 checksum:  3084404 5c6c1b42bc958427686de001a8f1a995
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-itanium_2.6.18.dfsg.1-23etch1_ia64.deb
        Size/MD5 checksum: 28020804 40c13c914b51a21a1a24023798899a7b
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-itanium_2.6.18.dfsg.1-23etch1_ia64.deb
        Size/MD5 checksum:   257864 475005498346a7d8b38a7c29509ccf4a
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-mckinley_2.6.18.dfsg.1-23etch1_ia64.deb
        Size/MD5 checksum: 28186348 8826f9beccdf15d89e6e93b453d512c1
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-mckinley_2.6.18.dfsg.1-23etch1_ia64.deb
        Size/MD5 checksum:   257820 0c8cc79934f006def209bb4a499c60ff
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-qemu_2.6.18.dfsg.1-23etch1_mips.deb
        Size/MD5 checksum:  6126884 792de360f86746a53710e5bd33b8f163
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all_2.6.18.dfsg.1-23etch1_mips.deb
        Size/MD5 checksum:    56368 9a395680eae076a224dad896da65691c
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-sb1a-bcm91480b_2.6.18.dfsg.1-23etch1_mips.deb
        Size/MD5 checksum:   189126 18b896582f9351dc09b6e0a70ef90831
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-r5k-ip32_2.6.18.dfsg.1-23etch1_mips.deb
        Size/MD5 checksum:   170032 3458ed1dbcdc45653181b5c0fc7ecdb8
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-qemu_2.6.18.dfsg.1-23etch1_mips.deb
        Size/MD5 checksum:   156908 2ff3f8ac181d494d7cb4ef7222d7b07e
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-r4k-ip22_2.6.18.dfsg.1-23etch1_mips.deb
        Size/MD5 checksum:   165172 7a17550dcdfa31d22bf8965127c2339f
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-sb1-bcm91250a_2.6.18.dfsg.1-23etch1_mips.deb
        Size/MD5 checksum: 15683930 4561323bdc5a9ad5c7c2a0ce0b6d5b76
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6_2.6.18.dfsg.1-23etch1_mips.deb
        Size/MD5 checksum:  3416968 6e47ae5cf9ac7bd360f619fcc3a75038
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all-mips_2.6.18.dfsg.1-23etch1_mips.deb
        Size/MD5 checksum:    56422 e924dcd73b5c94cabf01955f7f9a69ce
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-r5k-ip32_2.6.18.dfsg.1-23etch1_mips.deb
        Size/MD5 checksum:  9081586 6949edfa7335d4dc6b8758d40e4eafbd
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-r4k-ip22_2.6.18.dfsg.1-23etch1_mips.deb
        Size/MD5 checksum:  8315142 bedc220176f07a4d49a012acf38884aa
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-sb1-bcm91250a_2.6.18.dfsg.1-23etch1_mips.deb
        Size/MD5 checksum:   189364 765a041b2c8374633fac10555019d991
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-sb1a-bcm91480b_2.6.18.dfsg.1-23etch1_mips.deb
        Size/MD5 checksum: 15657240 01b773f5cebd3bcb5e82a3538afd9a43
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-r5k-cobalt_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum:  9865338 31f59099408adfc72436644f2f8d241f
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum:  3352366 25617a98b59a5bfa023619f4299105af
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-sb1-bcm91250a_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum:   185002 6e688580a5b5f19076b769ed6f3a04f8
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-sb1a-bcm91480b_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum:   184774 0e0657d343cc00aba89ef941f260cb8d
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-r4k-kn04_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum:   158046 200fe3fc8019dc123292003cdd13ffea
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-qemu_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum:  6035456 df357ca827f11be089babe11ea898b64
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-r5k-cobalt_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum:   180620 20de98111af4bad6a471d96e0089e038
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum:    56322 8c8613342248a855676af7a9051719ea
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-r3k-kn02_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum:  5949466 ec4818d43fa0c812535d528642cd97f6
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-r3k-kn02_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum:   158062 1fc66a76a56aea3b0acdad506c35afa4
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-sb1a-bcm91480b_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum: 15031350 7c814fc2adb6872726c73ac8798ea855
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-r4k-kn04_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum:  5929984 00c1d88fb99faa66fe1a4f96bf2ce23b
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-qemu_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum:   152628 fb85eaff880b8de07536a59b1717b7ff
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-sb1-bcm91250a_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum: 15060882 f3930b91f4a1cf543478cf1642fd99fd
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all-mipsel_2.6.18.dfsg.1-23etch1_mipsel.deb
        Size/MD5 checksum:    56380 67c590353ceebbd73e78eb7274b419a8
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-powerpc_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum:   254232 df3428d02b7caf4d8859ffa421d9fb47
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum:  3394788 bf95b7b549b0e5dff3c131f392f6df10
      http://security.debian.org/pool/updates/main/f/fai-kernels/fai-kernels_1.17+etch.23etch1_powerpc.deb
        Size/MD5 checksum:  3370368 67c60e48f8171e261b681c88a5eb49c1
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-powerpc64_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum: 18302236 b00e64cee1bd14e44416587727b3e4d8
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-powerpc-miboot_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum:   231830 db040067803ff3bb9a4677411a4cc25f
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-vserver-powerpc64_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum: 18357864 dde6c4a10d645a9a0a531fdc1cd17669
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-powerpc64_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum:   255932 4fbc330e627c9912e97d59f96eafb4e8
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all-powerpc_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum:    56372 9886fc5b03211e6c45c0f096a3a61f53
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-powerpc_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum: 16632328 c1c43bb84800ed32d9eb38638dd23d5a
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-powerpc-miboot_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum: 15163882 fe0bc4a175982e11cce21bb1cb8ab8e7
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-vserver-powerpc_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum: 17018420 77506217a84db6b8a788059b579a9c84
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-powerpc-smp_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum:   255024 30e5ea717182f1c0b6cac5bd441dccbb
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-vserver-powerpc64_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum:   255918 505c4c33c287dfdebeaa98698e97c9f3
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-prep_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum:   247514 f5b68002876185469625bf32d1e002be
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-prep_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum: 16408190 97416532c92c57c0e33f97e19853020e
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum:    56326 b058a9108e32625a78db5e411b750b6d
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-vserver-powerpc_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum:   255198 85fcc0cdb31720c9c0bdf6043c47c138
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-vserver_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum:  3417130 4aa20378bea17d7cd44d77155ff36674
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-powerpc-smp_2.6.18.dfsg.1-23etch1_powerpc.deb
        Size/MD5 checksum: 16974946 b132327c709f7a2a0b69c1aa3dda9ca7
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-vserver_2.6.18.dfsg.1-23etch1_s390.deb
        Size/MD5 checksum:  2968510 3d7773ed1afb8221e10da8e4b4eabdba
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-s390-tape_2.6.18.dfsg.1-23etch1_s390.deb
        Size/MD5 checksum:  1442824 840860b7a601870db6921de4c42e238b
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-s390_2.6.18.dfsg.1-23etch1_s390.deb
        Size/MD5 checksum:   145978 e495aa518a5281a63e1131887335a0f0
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-s390_2.6.18.dfsg.1-23etch1_s390.deb
        Size/MD5 checksum:  5406378 3b9556c4af25a6f611d087500ddaa6c2
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-s390x_2.6.18.dfsg.1-23etch1_s390.deb
        Size/MD5 checksum:   146542 d94c8a951655f053eb92ee574b964f65
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-s390x_2.6.18.dfsg.1-23etch1_s390.deb
        Size/MD5 checksum:  5624558 c9f8f23a2bbbc88c1d15be853cb1f3bb
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all-s390_2.6.18.dfsg.1-23etch1_s390.deb
        Size/MD5 checksum:    56342 55d68538e40adb1b9e35493b2b74915e
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all_2.6.18.dfsg.1-23etch1_s390.deb
        Size/MD5 checksum:    56318 832d1344921a7aba3dd12519427c5a6d
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-vserver-s390x_2.6.18.dfsg.1-23etch1_s390.deb
        Size/MD5 checksum:  5666984 b130f7034aec80a7bd91a4aad1bad5ab
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6_2.6.18.dfsg.1-23etch1_s390.deb
        Size/MD5 checksum:  2945466 a4efd6af72524aa0c66f5826b2ba64e0
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-vserver-s390x_2.6.18.dfsg.1-23etch1_s390.deb
        Size/MD5 checksum:   147214 ad3a2622e0e6a8f2320a9a588ed69703
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-vserver-sparc64_2.6.18.dfsg.1-23etch1_sparc.deb
        Size/MD5 checksum: 10742802 231ff49c22bbdbae0140dc9321cb38d2
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-sparc64_2.6.18.dfsg.1-23etch1_sparc.deb
        Size/MD5 checksum:   201818 a8207a5a4c9fe0477e199f0e3122a9ba
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-vserver-sparc64_2.6.18.dfsg.1-23etch1_sparc.deb
        Size/MD5 checksum:   203204 433d0d869346e23e8d8ac404dabc6f05
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all-sparc_2.6.18.dfsg.1-23etch1_sparc.deb
        Size/MD5 checksum:    56402 d153a7923ae65aa917033593d37431e3
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-sparc32_2.6.18.dfsg.1-23etch1_sparc.deb
        Size/MD5 checksum:  6462310 5ecc441c0a37c7f36e08d6ae7555f797
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-sparc64_2.6.18.dfsg.1-23etch1_sparc.deb
        Size/MD5 checksum: 10432952 a4b5abd32db9c00b8c675673da094c7a
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-all_2.6.18.dfsg.1-23etch1_sparc.deb
        Size/MD5 checksum:    56370 8d7ecca445ea50ab719944b89f5bfeb9
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-sparc64-smp_2.6.18.dfsg.1-23etch1_sparc.deb
        Size/MD5 checksum:   202588 bbffae6906ea1411033d990001e7bd45
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-vserver_2.6.18.dfsg.1-23etch1_sparc.deb
        Size/MD5 checksum:  3247520 bb5b20226d4c291646997f750b8e1735
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6-sparc32_2.6.18.dfsg.1-23etch1_sparc.deb
        Size/MD5 checksum:   170142 43370064b577b685f34d0b9613ce140b
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-image-2.6.18-6-sparc64-smp_2.6.18.dfsg.1-23etch1_sparc.deb
        Size/MD5 checksum: 10701158 a0233a7673dc3b128b49f97d3afd679b
      http://security.debian.org/pool/updates/main/l/linux-2.6/linux-headers-2.6.18-6_2.6.18.dfsg.1-23etch1_sparc.deb
        Size/MD5 checksum:  3223030 0a1a542113a8a800d0afcd562f5679aa
    
      These changes will probably be included in the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iD8DBQFJRsyKhuANDBmkLRkRAkCYAJ9pGRyJvEF9lIM3nETLDewjqb9cUQCcDLsn
    NlV6/qC8MrRZSAJ6B0DD3pE=
    =2la3
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1688                    security@debian.org
    http://www.debian.org/security/                           Steffen Joeris
    December 20, 2008                     http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : courier-authlib
    Vulnerability  : SQL injection
    Problem type   : remote
    Debian-specific: no
    CVE Id(s)      : CVE-2008-2380 CVE-2008-2667
    
    Two SQL injection vulnerabilities have beein found in courier-authlib,
    the courier authentification library.  The MySQL database interface used
    insufficient escaping mechanisms when constructing SQL statements,
    leading to SQL injection vulnerabilities if certain charsets are used
    (CVE-2008-2380).  A similar issue affects the PostgreSQL database
    interface (CVE-2008-2667).
    
    For the stable distribution (etch), these problems have been fixed in
    version 0.58-4+etch2.
    
    For the testing distribution (lenny) and the unstable distribution
    (sid), these problems have been fixed in version 0.61.0-1+lenny1.
    
    We recommend that you upgrade your courier-authlib packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58.orig.tar.gz
        Size/MD5 checksum:  3342115 75b5b2b72d550048ed1b29e687a1a60d
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch2.diff.gz
        Size/MD5 checksum:    44232 5345604d34a363e4519077032a9aeb1f
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch2.dsc
        Size/MD5 checksum:      970 9652de3cb3cd60fa91aee7cb1e0b8dca
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch2_alpha.deb
        Size/MD5 checksum:    23168 fadd251992d42011cc6a7ebd98fab8ec
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch2_alpha.deb
        Size/MD5 checksum:     6872 6a4b4a3b87e9d42347e7c5ee8e373cc1
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch2_alpha.deb
        Size/MD5 checksum:    20252 14b6526559b01af55bf98623d6a9dbc2
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch2_alpha.deb
        Size/MD5 checksum:    20360 7fd32c031bc84d59b48e229855d7e347
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch2_alpha.deb
        Size/MD5 checksum:    39046 0b4d0fe9ef5ecfa66d1cef14dc65bb89
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch2_alpha.deb
        Size/MD5 checksum:     8862 90e0a8316f719256734af61ca2bf147d
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch2_alpha.deb
        Size/MD5 checksum:   149956 19cb601a37c170b9de0d3090c56002ab
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch2_alpha.deb
        Size/MD5 checksum:    92666 f2c54e7b23aa10157cf8b9704a44ed66
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch2_amd64.deb
        Size/MD5 checksum:     6882 5607bf027063ab70597301e99401b57a
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch2_amd64.deb
        Size/MD5 checksum:    19774 ae1bee7da212b8996858b6e077fcc852
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch2_amd64.deb
        Size/MD5 checksum:    34296 d42351150f3a4e621c27608aeee9144a
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch2_amd64.deb
        Size/MD5 checksum:     8298 8318ba2b8d4cadcd55646686534c42ff
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch2_amd64.deb
        Size/MD5 checksum:   111816 985dd2b71cee857a8a44b1805dd03768
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch2_amd64.deb
        Size/MD5 checksum:    22182 b5fab407e60b9e7bec23535ea8030274
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch2_amd64.deb
        Size/MD5 checksum:    19942 780fbf86d2f64743d00bf82dccc45aef
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch2_amd64.deb
        Size/MD5 checksum:    81440 5ae5081441e0ea2e9e20ec037a25ed69
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch2_arm.deb
        Size/MD5 checksum:     6872 27f8dfabf8939a063a2725053d138b03
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch2_arm.deb
        Size/MD5 checksum:    97966 eba6aa3b836e90a1ff85ce72c97856e1
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch2_arm.deb
        Size/MD5 checksum:    18618 1446523e8fc2028b61c82874b9ddbfe9
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch2_arm.deb
        Size/MD5 checksum:    32644 5d4032a7948d90f9873eb256a35c473f
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch2_arm.deb
        Size/MD5 checksum:    20928 81b0bf0c3bb6a012178ea76be1412c0b
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch2_arm.deb
        Size/MD5 checksum:     7694 adfb37f7da5e86a051942defa5baeffb
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch2_arm.deb
        Size/MD5 checksum:    76054 31a727fe1fab3eef91954104ce9a5b40
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch2_arm.deb
        Size/MD5 checksum:    18700 2f0f1c6e62d65e1faedbc1f7229f8692
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch2_hppa.deb
        Size/MD5 checksum:    23602 5a8b12e1d2452b53077ad5b1cb4b08f3
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch2_hppa.deb
        Size/MD5 checksum:   123784 57c772189e1a7bfc0a6f991cff14ffdd
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch2_hppa.deb
        Size/MD5 checksum:    89110 07ce2983ceb249c9d9f631129d565acb
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch2_hppa.deb
        Size/MD5 checksum:    20682 102963eb336587215a76b993afb64c9b
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch2_hppa.deb
        Size/MD5 checksum:    37816 18f3284ede8bf567622b8279e410a37c
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch2_hppa.deb
        Size/MD5 checksum:    20784 1c1251971aaac18f500fda9566e2787c
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch2_hppa.deb
        Size/MD5 checksum:     8966 936f96deb13d2c7abde35912eb22110e
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch2_hppa.deb
        Size/MD5 checksum:     6878 a3e177edd667d1b89b2acd0d16529cb2
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch2_i386.deb
        Size/MD5 checksum:    76266 9abde4499ec4919ce1ee6633e2871aad
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch2_i386.deb
        Size/MD5 checksum:   100192 9f3bd2ea757c627fae011129bcf14bae
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch2_i386.deb
        Size/MD5 checksum:     7728 9cf2c4ddfe99f0db67e46e353f39d883
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch2_i386.deb
        Size/MD5 checksum:    33184 fb771a57caaac542a78141efb27f0b0d
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch2_i386.deb
        Size/MD5 checksum:    18754 3d19957c59c1ad0698523390fb19c5c7
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch2_i386.deb
        Size/MD5 checksum:    18692 f60e095965045a5bd389b052917dd98f
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch2_i386.deb
        Size/MD5 checksum:     6878 53ff4849663f484dd32b1cdcb2015e39
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch2_i386.deb
        Size/MD5 checksum:    21136 218beca3fda1b69bb92ee651c1216a6f
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch2_ia64.deb
        Size/MD5 checksum:    44658 63ccc17e4a93a71423a1cefccfd032d0
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch2_ia64.deb
        Size/MD5 checksum:   147862 b75faf449376d7f8d601e6fb610b28b2
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch2_ia64.deb
        Size/MD5 checksum:     6878 d892eeb8581570f4c9b3772d618bbb41
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch2_ia64.deb
        Size/MD5 checksum:   109816 5f52dc98ce62c00cfb3dd05ce7ae8ac4
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch2_ia64.deb
        Size/MD5 checksum:    10114 98ab7d1303bd6bfbd550bafb712d551f
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch2_ia64.deb
        Size/MD5 checksum:    23788 f0dd7e45dc8cefc82744622f426a9b16
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch2_ia64.deb
        Size/MD5 checksum:    28012 313a36d030a0f2d7e6c1a0ff057e0474
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch2_ia64.deb
        Size/MD5 checksum:    23670 6ae95423f408ff5b431536e4d934e09b
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch2_mips.deb
        Size/MD5 checksum:     6884 20dc9fbb351bf8c8ce0cbaf3625b4175
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch2_mips.deb
        Size/MD5 checksum:    81760 773ab2a44f73d8776f4c773c0f37ff47
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch2_mips.deb
        Size/MD5 checksum:   124568 955cb5ddad18933638b22d022817524a
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch2_mips.deb
        Size/MD5 checksum:    35150 ed3d846058245e93aaa8417ff4773761
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch2_mips.deb
        Size/MD5 checksum:    19394 5481da3efe4b88040ea1cc355ff664ac
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch2_mips.deb
        Size/MD5 checksum:    21814 c26ef062bfc68a6fb7f0f19640774a8d
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch2_mips.deb
        Size/MD5 checksum:     8112 ef79a0fc7f0425425488845b44ecbd14
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch2_mips.deb
        Size/MD5 checksum:    19340 6ab700571fe303005763cc55fa2a9d47
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch2_mipsel.deb
        Size/MD5 checksum:    81626 a98cb782eb9ac71dbc7cdc148190d4e8
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch2_mipsel.deb
        Size/MD5 checksum:    19402 0a22244477b87b572cb864ecb6de5e04
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch2_mipsel.deb
        Size/MD5 checksum:    21936 8be79200e34bc0772bc11bf440ef8155
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch2_mipsel.deb
        Size/MD5 checksum:    35924 660a86bbc151ac2326641f0c12d3ba2b
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch2_mipsel.deb
        Size/MD5 checksum:     6876 39554139fc894f21349284780882ad4e
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch2_mipsel.deb
        Size/MD5 checksum:   120836 c863a7ee2e9a024d017dc87f1384def5
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch2_mipsel.deb
        Size/MD5 checksum:     8124 3ebee4b6e23b4eb939c03f52d822dea7
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch2_mipsel.deb
        Size/MD5 checksum:    19396 96746e0f3577918cfbbb3118d78f6424
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch2_powerpc.deb
        Size/MD5 checksum:     8244 54f6e43f51140bf09f871658da742d4f
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch2_powerpc.deb
        Size/MD5 checksum:    35682 175f7cee84457c57dce1bd3915f9b48b
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch2_powerpc.deb
        Size/MD5 checksum:    88018 de4c18fbeb549d43de7189023a887b09
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch2_powerpc.deb
        Size/MD5 checksum:     6880 4ae52c04c9446d42b39a2340ed2e9ae7
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch2_powerpc.deb
        Size/MD5 checksum:    21996 54f45485b1f88781ee145dcd6847afc3
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch2_powerpc.deb
        Size/MD5 checksum:    19746 ba53ebc588b12d139e175e6a3b0e2315
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch2_powerpc.deb
        Size/MD5 checksum:    19596 aece91a5ad82c97d0f6f0b0c75a1e628
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch2_powerpc.deb
        Size/MD5 checksum:   110260 a7f3e9b62fa4dab338af7464562e7f29
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch2_s390.deb
        Size/MD5 checksum:    84426 12adf5edd57f25e8dda31417bffe5277
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch2_s390.deb
        Size/MD5 checksum:    22658 bff8b619d28a2c02c0e0d228b31a2828
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch2_s390.deb
        Size/MD5 checksum:    35816 f057afbbba8dafbc5827dfa504b842b6
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch2_s390.deb
        Size/MD5 checksum:     6872 60905c2b17770da18a483849809dd4b0
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch2_s390.deb
        Size/MD5 checksum:     8194 8102bda398f54234ebeabcb5c2bbcfff
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch2_s390.deb
        Size/MD5 checksum:    19886 120cc50919aefebe724141543173ff6a
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch2_s390.deb
        Size/MD5 checksum:   102794 5abef9d9db542efb812b1f40c331fe10
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch2_s390.deb
        Size/MD5 checksum:    19678 07d4fdb3dfe964f7770f99a29a8cc405
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch2_sparc.deb
        Size/MD5 checksum:     6882 19e4ec02b0d0a26482db9d1e0d1f168a
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch2_sparc.deb
        Size/MD5 checksum:    19080 347c0a4835423e986b618c38c4f3586c
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch2_sparc.deb
        Size/MD5 checksum:   102236 086d13b5f6c3c17b622135138a0e703d
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch2_sparc.deb
        Size/MD5 checksum:    21726 0485cac725699e762019d63304762eab
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch2_sparc.deb
        Size/MD5 checksum:    33400 4790920e8e38c0484caa4d8b4b6fa74f
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch2_sparc.deb
        Size/MD5 checksum:    75614 355dc789b011cd3b95485d08fcf093c5
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch2_sparc.deb
        Size/MD5 checksum:    19072 73849401eddf1746db3d399f17bdd788
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch2_sparc.deb
        Size/MD5 checksum:     7774 533a11e8ddb8bb68a0e2defbeecf6b0c
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJTQzXAAoJEL97/wQC1SS+ZowH/3qn5mXCDhGve59HqtxW3ngu
    M6ylx6jfaL9u8H45+UpTKi+GPB/WCaoJxpZjAdK3xIjpOKR1bSzfnxI0YtDsNsaR
    /0nbgWgg3bi6iVNyB5M84mF/BxqOdKrXcNvG/iwXwG+v0v8A8bZ/KeLBD6U14Pkl
    79N8/f2INwF1OvnOMWqRDjcYAj65sV9Ez8M8SMZDxQvfK2VNIEItw22th7HAbZ0K
    L0sGmrGvVa6KQJ5cuUCZW30jfBS52Jn3GLV7ws1oGlZyMefb1rJslfDKewvpv5IM
    3JLj9F6RLluer5eVoUhf8SVM0fgiH3Py0pk5LRN4M5JSSIW5OeW1VD7FZgSZG4c=
    =u7OX
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1678-2                  security@debian.org
    http://www.debian.org/security/                         Florian Weimer
    December 21, 2008                   http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : perl
    Vulnerability  : design flaws
    Problem type   : local
    Debian-specific: no
    CVE Id(s)      : CVE-2008-5302 CVE-2008-5303
    Debian Bug     : 286905 286922 479317
    
    The perl update in DSA-1678-1 contains a regression which is triggered
    by some Perl scripts which have changed into the directory tree
    removed by File::Path::rmtree.  In particular, this happens if
    File::Temp::tempdir is used.  This new update corrects this
    regression.
    
    For the stable distribution (etch), this problem has been fixed in
    version 5.8.8-7etch6.
    
    For the unstable distribution (sid), this problem will be fixed soon.
    
    We recommend that you upgrade your perl packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch6.diff.gz
        Size/MD5 checksum:   104841 38685bce67f7761753883e8e6073f5b7
      http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch6.dsc
        Size/MD5 checksum:      742 f9545587e032939494a6a9b22abd112c
      http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8.orig.tar.gz
        Size/MD5 checksum: 12829188 b8c118d4360846829beb30b02a6b91a7
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/p/perl/perl-doc_5.8.8-7etch6_all.deb
        Size/MD5 checksum:  7377460 cf3c6b08cfa947eb989e5a376790c4c3
      http://security.debian.org/pool/updates/main/p/perl/libcgi-fast-perl_5.8.8-7etch6_all.deb
        Size/MD5 checksum:    41276 f9e491829ef0ea295d2c5b88e48c895d
      http://security.debian.org/pool/updates/main/p/perl/perl-modules_5.8.8-7etch6_all.deb
        Size/MD5 checksum:  2328214 6d995effacda8ecc2a935dc4527ed342
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch6_alpha.deb
        Size/MD5 checksum:  4150250 3c575d6d8e1b101066a89e1482f081cf
      http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch6_alpha.deb
        Size/MD5 checksum:   821806 8d3bd143f7b3d6243b42277c5c63a93f
      http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch6_alpha.deb
        Size/MD5 checksum:   880284 5636ce04377a056db7d369b7b8770428
      http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch6_alpha.deb
        Size/MD5 checksum:  2928840 4d5717f310740a654eab999bc4993e5a
      http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch6_alpha.deb
        Size/MD5 checksum:     1010 9ccd001ddccacbf99510508937c9ca47
      http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch6_alpha.deb
        Size/MD5 checksum:    36236 db6be7a7cf887edfefcb7c2c50b0a3db
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch6_amd64.deb
        Size/MD5 checksum:     1014 6222c5da15781a0191a162ee74e0f9a2
      http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch6_amd64.deb
        Size/MD5 checksum:   806670 c654435b6632fb800929870df3f0daf8
      http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch6_amd64.deb
        Size/MD5 checksum:    32780 bcc928299ffd2e4d97ee2d9d7fdb1512
      http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch6_amd64.deb
        Size/MD5 checksum:  4249060 a10ee694a5d164b8ef12d0f566e4f02d
      http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch6_amd64.deb
        Size/MD5 checksum:   630778 f318294099b5c0ae4469073988731f7f
      http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch6_amd64.deb
        Size/MD5 checksum:  2735120 21c2ed7bba2de01983156e720c4eea14
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch6_arm.deb
        Size/MD5 checksum:    30346 1f51b45f45fd8a1bbc4732812c348b3a
      http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch6_arm.deb
        Size/MD5 checksum:   760238 a230824f93118e65af853c9a8448aeb5
      http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch6_arm.deb
        Size/MD5 checksum:   562086 e7fc6a0323bc5898dd09ff7a9c937ac1
      http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch6_arm.deb
        Size/MD5 checksum:     1010 9a67f67e98a45b6e02fe09aa50518794
      http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch6_arm.deb
        Size/MD5 checksum:  2548186 91c5ccb36e82705931c07d8a14d95490
      http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch6_arm.deb
        Size/MD5 checksum:  3410336 77df1024bf9e02b0cdce65423bc84eeb
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch6_i386.deb
        Size/MD5 checksum:  2492644 ebb57292ae6986f812c2233511565fb3
      http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch6_i386.deb
        Size/MD5 checksum:   585446 bedf9d40486ebab6ef251101ed0d2402
      http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch6_i386.deb
        Size/MD5 checksum:   762766 f667327e7cd4044ee6fb3c900b75a181
      http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch6_i386.deb
        Size/MD5 checksum:   527166 8770a7e8302aaa2ef7c99b8339a1579e
      http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch6_i386.deb
        Size/MD5 checksum:    32104 53085baadd6fa2a16f5ca27dbcae5b72
      http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch6_i386.deb
        Size/MD5 checksum:  3599182 6c141bd9447670a86b0691adafb51596
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch6_ia64.deb
        Size/MD5 checksum:  1154160 b640fe2f395f9161560fd9dd52532f85
      http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch6_ia64.deb
        Size/MD5 checksum:     1006 62ffe7a5b8823f925b2537941fe48ae1
      http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch6_ia64.deb
        Size/MD5 checksum:    51272 b93cfd432ead7fb85cab0acbe53c2994
      http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch6_ia64.deb
        Size/MD5 checksum:   978108 7e50dafffed7382b35042ad86032b7a4
      http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch6_ia64.deb
        Size/MD5 checksum:  4336650 fe46d1d4fa0b18770631f9d2a544d072
      http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch6_ia64.deb
        Size/MD5 checksum:  3364466 15f332c898209c5c5cb8d864762cf445
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch6_mips.deb
        Size/MD5 checksum:   786168 5da358d316af22485a29c364afee453c
      http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch6_mips.deb
        Size/MD5 checksum:     1008 0c27fb854eabf1e73840bf2cc07b8b3c
      http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch6_mips.deb
        Size/MD5 checksum:   694016 78af4921744de0e03ba173d79d7f7d39
      http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch6_mips.deb
        Size/MD5 checksum:    32220 fcd144768fee4a14664a962d0d1e4a55
      http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch6_mips.deb
        Size/MD5 checksum:  3679064 cdd8810ba2b3e8c293df4acc06510fb7
      http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch6_mips.deb
        Size/MD5 checksum:  2782124 a16a21e716647c74c24224b9752d56c2
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch6_mipsel.deb
        Size/MD5 checksum:    32326 55417bfc7195b2907c76a170ded4fb91
      http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch6_mipsel.deb
        Size/MD5 checksum:  2730626 7d13f3931edcdd3b22ff6e851de332d5
      http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch6_mipsel.deb
        Size/MD5 checksum:  3413592 f087bc2dcefcd3069ac7db96b84af4ab
      http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch6_mipsel.deb
        Size/MD5 checksum:   784946 a5b574a6e9e1bf919ab88bd1b5beb964
      http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch6_mipsel.deb
        Size/MD5 checksum:   687508 90078c3c9692c6e50c5a5cb0fe25ece2
      http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch6_mipsel.deb
        Size/MD5 checksum:     1016 10942b8d2f2c5441d0dd7d65afc83151
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch6_powerpc.deb
        Size/MD5 checksum:   811106 367dec1df2404742380c2c06e0809a20
      http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch6_powerpc.deb
        Size/MD5 checksum:  2710134 50f1c3ecb9f1023935f153c1d605aa41
      http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch6_powerpc.deb
        Size/MD5 checksum:     1014 16877860b93d044bf7f914a857737fc0
      http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch6_powerpc.deb
        Size/MD5 checksum:  3825218 b4f50f6735fc446fb22665cff53cd064
      http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch6_powerpc.deb
        Size/MD5 checksum:   653450 92671c8bcd39e6f4a84b2a01401ef408
      http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch6_powerpc.deb
        Size/MD5 checksum:    32904 adb2e70ca2b2f0cc809bcc2903036bdf
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch6_s390.deb
        Size/MD5 checksum:  4100084 14bc00f090ce3dc1ba7bfacfa5b88218
      http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch6_s390.deb
        Size/MD5 checksum:    33094 fb66e60a4fa21a647bc053920a842d5b
      http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch6_s390.deb
        Size/MD5 checksum:   633600 9df5a899f601a14ce3b0496df2bc116d
      http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch6_s390.deb
        Size/MD5 checksum:   823704 1b3f1afaef5fc0c5fb36048d82c1c3d6
      http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch6_s390.deb
        Size/MD5 checksum:  2796566 83e073cf9d1f2a22f366483d250a95c0
      http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch6_s390.deb
        Size/MD5 checksum:     1008 f983117eb556d27b343d6a64d5774cfd
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch6_sparc.deb
        Size/MD5 checksum:   594470 8bfdaa1611e2ce31f21dcb83714eed1f
      http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch6_sparc.deb
        Size/MD5 checksum:    31058 12713b89c5b12616fe4344c6e725b8a5
      http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch6_sparc.deb
        Size/MD5 checksum:  2565978 b062a3274b40bf1524a9d02315c711cd
      http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch6_sparc.deb
        Size/MD5 checksum:   782402 5c2d4e8b4eb521aecac7c496591c1e7a
      http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch6_sparc.deb
        Size/MD5 checksum:     1010 0fde672bbaad262571d8646364b3c10a
      http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch6_sparc.deb
        Size/MD5 checksum:  3813262 f1095b35b28e4d2eb80cba8b978d8119
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJThLvAAoJEL97/wQC1SS+WSYIAI0vvTnjN/DDAhxatTQhcqft
    M4KlTjE5xLF1qtLH+9XWmCf9nPGQyOfrZk8lRyAVG3xyI4shuMrRIrZlgW70Z9rk
    C5p0ApU81yIWEMXQI/OIawbx0gXqg5O26KMQHWYNOflXfg7P/S3PrlVRgtJeG3ED
    QptsDATvJaIFOBN/QGENr0vpJ70kxlO8xB/YqiRXecBVDBywL4xK6mDg11q3ZEt5
    2v+hn4by0mhd29xQz2rq0tG2K+xWidQd6UsbvekhAVBhzonH2fPgZX5YaqxT5m6i
    hAtwMXAnPIJXK1FWzEK0kdWuULkcNdXF5rKZnYgILF7opiXbzylPKwQmbK8biUA=
    =ttG8
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - --------------------------------------------------------------------------
    Debian Security Advisory DSA 1689-1                    security@debian.org
    http://www.debian.org/security/                             Martin Schulze
    December 21st, 2008                     http://www.debian.org/security/faq
    - --------------------------------------------------------------------------
    
    Package        : proftpd-dfsg
    Vulnerability  : missing input validation
    Problem type   : remote
    Debian-specific: no
    CVE ID         : CVE-2008-4242
    Debian Bug     : 502674
    BugTraq ID     : 31289
    
    Maksymilian Arciemowicz of securityreason.com reported that ProFTPD is
    vulnerable to cross-site request forgery (CSRF) attacks and executes
    arbitrary FTP commands via a long ftp:// URI that leverages an
    existing session from the FTP client implementation in a web browser.
    
    For the stable distribution (etch) this problem has been fixed in
    version 1.3.0-19etch2 and in version 1.3.1-15~bpo40+1 for backports.
    
    For the testing (lenny) and unstable (sid) distributions this problem
    has been fixed in version 1.3.1-15.
    
    We recommend that you upgrade your proftpd-dfsg package.
    
    
    Upgrade Instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given at the end of this advisory:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
      Source archives:
    
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-dfsg_1.3.0-19etch2.dsc
          Size/MD5 checksum:      944 609e4ce00fbd5064cbf939ce8f867782
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-dfsg_1.3.0-19etch2.diff.gz
          Size/MD5 checksum:   180899 b0b18721ebf58fb77026c0bf4f3d9be2
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-dfsg_1.3.0.orig.tar.gz
          Size/MD5 checksum:  1751265 b857aaf750244106d1991bcb3c48f4a0
    
      Architecture independent components:
    
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-doc_1.3.0-19etch2_all.deb
          Size/MD5 checksum:   493380 0267b116876ee92f620641d58d993841
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-ldap_1.3.0-19etch2_all.deb
          Size/MD5 checksum:   162716 8fd092997183b78a7088fd1532f89849
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mysql_1.3.0-19etch2_all.deb
          Size/MD5 checksum:   162722 7bb678b16043c24020f76783d38e15e6
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-pgsql_1.3.0-19etch2_all.deb
          Size/MD5 checksum:   162722 c649d5a0b0f32137849c2afa5cb132ed
    
      Alpha architecture:
    
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_alpha.deb
          Size/MD5 checksum:   997344 c69dfa653681879af1857f90897079fe
    
      AMD64 architecture:
    
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_amd64.deb
          Size/MD5 checksum:   854758 5d51e69ebbda89a96ccb3fcda3513803
    
      ARM architecture:
    
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_arm.deb
          Size/MD5 checksum:   794910 5c0d8a2c1aa18b40348d3d7b5a7e0408
    
      HP Precision architecture:
    
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_hppa.deb
          Size/MD5 checksum:   933032 949a306ac2046a27bff7f3797f9bfff5
    
      Intel IA-32 architecture:
    
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_i386.deb
          Size/MD5 checksum:   798104 4fe16756d76c8cdb2b3c41f8ad92fd4f
    
      Intel IA-64 architecture:
    
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_ia64.deb
          Size/MD5 checksum:  1188066 9291c65580b50a7c478829e3307e11b7
    
      Big endian MIPS architecture:
    
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_mips.deb
          Size/MD5 checksum:   870756 06570fae0e9a8ba786b56464512f5451
    
      Little endian MIPS architecture:
    
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_mipsel.deb
          Size/MD5 checksum:   855034 e7ae30d19a1806c69dc0d6afad5c59ef
    
      PowerPC architecture:
    
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_powerpc.deb
          Size/MD5 checksum:   885996 a5a81e9d5b86dda6462a7024f69aeac8
    
      IBM S/390 architecture:
    
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_s390.deb
          Size/MD5 checksum:   853294 460507c587a7165dfd00d5776af70c60
    
      Sun Sparc architecture:
    
        http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_sparc.deb
          Size/MD5 checksum:   827522 091f572d3565aae465046f11eccce143
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iD8DBQFJTlGVW5ql+IAeqTIRAjKvAKCJ1LslA52c7VPJPs3+58NvSZzTfgCfVica
    RHJMZjpj1nwjhN9jC5LVPLU=
    =oOwM
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1690-1                  security@debian.org
    http://www.debian.org/security/                           Florian Weimer
    December 22, 2008                     http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : avahi
    Vulnerability  : assert errors
    Problem type   : remote
    Debian-specific: no
    CVE Id(s)      : CVE-2007-3372 CVE-2008-5081
    Debian Bug     : 508700
    
    Two denial of service conditions were discovered in avahi, a Multicast
    DNS implementation.
    
    Huge Dias discovered that the avahi daemon aborts with an assert error
    if it encounters a UDP packet with source port 0 (CVE-2008-5081).
    
    It was discovered that the avahi daemon aborts with an assert error if
    it receives an empty TXT record over D-Bus (CVE-2007-3372).
    
    For the stable distribution (etch), these problems have been fixed in
    version 0.6.16-3etch2.
    
    For the unstable distribution (sid), these problems have been fixed in
    version 0.6.23-3.
    
    We recommend that you upgrade your avahi packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/a/avahi/avahi_0.6.16-3etch2.dsc
        Size/MD5 checksum:     1570 8ebff455c9264d5dbee95ab9577378e5
      http://security.debian.org/pool/updates/main/a/avahi/avahi_0.6.16.orig.tar.gz
        Size/MD5 checksum:   891970 3cbc460bbd55bae35f7b57443c063640
      http://security.debian.org/pool/updates/main/a/avahi/avahi_0.6.16-3etch2.diff.gz
        Size/MD5 checksum:    19735 a44b3f5fec53e6316da43c6a3b442e8c
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/a/avahi/avahi-discover_0.6.16-3etch2_all.deb
        Size/MD5 checksum:    25370 340795bc9ca2e64e801fddaac6d7a8bf
      http://security.debian.org/pool/updates/main/a/avahi/python-avahi_0.6.16-3etch2_all.deb
        Size/MD5 checksum:    25652 d6cf860ba2a5f8a098976473782c2a83
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core4_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:   106662 3fbdf722dfb11e2c4a1b17cefb7ea6b8
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl0_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    40364 f4b2ea3da302452e2a9cbd4379daa26c
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-data_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    23236 b05daf8a7a7b981dac5be1dd7e252913
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-1_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    27876 2056bc73e28aef4de30a9fa6f3bd6281
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-dev_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    26886 1163c86061b5a4eec1eec373d35992ea
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client-dev_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    69410 bd94273184beb53cafb16fabfe8df360
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd-dev_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    59406 2590be33f54a8cb30734813b32187b60
      http://security.debian.org/pool/updates/main/a/avahi/avahi-dnsconfd_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    32158 adbfd269dbc193711191cfc263732116
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib1_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    24982 6ef2e7c31116934bd7799239ea834662
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common3_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    39680 68b046de883b7e4a6b3251b9b0806a54
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core-dev_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:   190518 e82fd413940e3c5b4df71504295912d3
      http://security.debian.org/pool/updates/main/a/avahi/avahi-daemon_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    80352 cb5ab982034883bd47faa500fc7f8aa6
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-1_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    25702 019fbb7d0668482101bcbdb54e3a49b7
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-dev_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    29382 785a026351cc4ed289d6abb939eaafaa
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client3_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    45044 aca2b939624cbf22b2562fae405a6996
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl-dev_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    64010 d0cf4e59a93ccc42d7ed4f3877e4dc14
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd1_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    34164 ecc7e8f47701a32382703785fe5f9491
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib-dev_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    27868 04564fbd11c4150d2e1b6cb0fbc22cea
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-dev_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    65540 ec965810133a4ab5546702af49d3f678
      http://security.debian.org/pool/updates/main/a/avahi/avahi-utils_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    44190 fd1f6ea45614a3d5922507c66d9b8898
      http://security.debian.org/pool/updates/main/a/avahi/avahi-autoipd_0.6.16-3etch2_alpha.deb
        Size/MD5 checksum:    41910 3232185589d641841f471581bc7efbb7
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-1_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    25402 513e95ad6c2fb87c8316de0f21a958c0
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core-dev_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:   145820 b234cdf7647e3d8d6bd919876a729aed
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common3_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    40014 893b50c144cd39194393b8b2b48e6af5
      http://security.debian.org/pool/updates/main/a/avahi/avahi-autoipd_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    40732 3ca1605985570ae1c5e60fbda1da2a5b
      http://security.debian.org/pool/updates/main/a/avahi/avahi-daemon_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    78998 8ac6bf69b330ae356c93d11040b1ce92
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client3_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    45972 f65a50acee002fef7de31413a55188d3
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-dev_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    27602 cc94bd6ef246c0907e8239ecc63aced8
      http://security.debian.org/pool/updates/main/a/avahi/avahi-utils_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    44184 3352ec376add650e83b1445f076225dd
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd1_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    34556 86dfbb1540112c5d7f76f44e228b4f4e
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-dev_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    58170 99c0ba315980248ac30cc3741f543a47
      http://security.debian.org/pool/updates/main/a/avahi/avahi-dnsconfd_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    31888 6097f6fd4229243cb5456bd8eec2b8b2
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core4_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:   109494 6bbe277f75b34f90299b9371369b6d4d
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl-dev_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    53320 30431adf1d426ac45a259997cba31d3d
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-dev_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    25670 5e76611ac629222a1b296c6d31164055
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client-dev_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    53668 d1472f40bb294e10b9d60d49ce2cfe5b
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl0_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    39456 6f58090398ccee7ae34a425698a7e564
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd-dev_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    53434 c6e51db5ed2491e6b5712f9d5ab859f0
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib-dev_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    26584 366cca7021dc0f3a11096f56b10d1917
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-data_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    22952 a32b47c3d7246b6b4684570aeef8073a
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib1_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    25202 e1bbd694e3337905a27df1b5002247b0
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-1_0.6.16-3etch2_amd64.deb
        Size/MD5 checksum:    27528 a9675e1d025162d1f084274c76ecf15a
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-data_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    22912 15f25a3fa47daead5ac5e6726798f868
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-1_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    30470 e884ed20cd4e9372ab8bf7f058312a3d
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib1_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    27256 e784b9c093a6d1b4738e9e640e1a4183
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core4_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:   112406 ee560a6ecbdadd461097468dae9c9faf
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client3_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    46122 346a99034145ba0d2fa841dd8f5be168
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl0_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    40786 461cee0bd4f3d0e987c308daa70b0486
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-dev_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    26124 574f1a1c1a28431e5f087cc4f586910c
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl-dev_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    56718 f73efff9470440cfeb85fd1526f6d314
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client-dev_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    56198 0911a3c7851f103cf496e05e2d28dbf4
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common3_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    43422 6c007186fef8b3ef65d2aeb1905fce80
      http://security.debian.org/pool/updates/main/a/avahi/avahi-utils_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    43900 8ee1473948cb706b8ae20747db126037
      http://security.debian.org/pool/updates/main/a/avahi/avahi-dnsconfd_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    32070 274489d75dcf98d81ee3b728951c5150
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib-dev_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    26874 53cecb7746a23d8469abd841a6022b5a
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd1_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    34578 bcb55e3c180fa8d34955578e8c35a733
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-dev_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    61094 a20a57641eabb686ca3df5b83a8385f6
      http://security.debian.org/pool/updates/main/a/avahi/avahi-autoipd_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    43592 b1e4af50f06c1369414713f90c4cbb5b
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core-dev_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:   159974 ec67b38e546b51d8d3282e3aac5690c8
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-1_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    27958 275562493b65aed9efb3a8e9a5bacd46
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd-dev_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    54152 57746ebeca191c973941d9f22309261d
      http://security.debian.org/pool/updates/main/a/avahi/avahi-daemon_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    79584 ae8341ab2f4a6232f7a9e4e31f2628e0
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-dev_0.6.16-3etch2_hppa.deb
        Size/MD5 checksum:    28448 8279827bbe596cc31c8c92f855e4077a
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/a/avahi/avahi-autoipd_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    40232 0ab3fa7fc73fb609cdbec2d1d2ab514f
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client3_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    43358 f0a50ff65acb8ada30105bf9d5be6d43
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-1_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    27408 68e03f89a0a4ab49d3cf5631d81cefff
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core-dev_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:   131156 4f2d6816ff21fac92409300802b214c8
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl-dev_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    50306 95131a6cf96e271bc22b0a58f19d81c8
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd-dev_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    51264 b201facb01853a7feb377c476796faed
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-1_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    25214 2189bf23f2d2414c95f66de43fa9022e
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-dev_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    26904 d211581ca51292846f6e41501aab9f35
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client-dev_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    50050 55232395461a750e9589da67c4a6ce59
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib-dev_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    25932 a88e95d1f42acc1824ced261c034a6f8
      http://security.debian.org/pool/updates/main/a/avahi/avahi-daemon_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    76274 ee627ae2d4ae4675f36be9d773a60933
      http://security.debian.org/pool/updates/main/a/avahi/avahi-dnsconfd_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    31186 f598856b52c5338d76d08241d5147eba
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl0_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    37156 463df874fb4133e30f39efad5ae4c03c
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-data_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    22730 db3d21217b9d3a83c9ce61c2dc9088e9
      http://security.debian.org/pool/updates/main/a/avahi/avahi-utils_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    42082 710572c240f63df323ea5bc07981be0b
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-dev_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    55348 d759803be1ad6050495a8fcf7796528d
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd1_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    32504 d70eb6f318769fd7aba37dc9f27ffdd8
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib1_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    24736 b066f13687d60f3e30a76cc662c0de08
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core4_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:   101844 f0d31a9b2bf9491f1b2a11fe5527edd3
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-dev_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    25078 272eefbb1ebd24fb67392096bc092c91
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common3_0.6.16-3etch2_i386.deb
        Size/MD5 checksum:    38490 f1cabc135940e9b39eb9e9063023094f
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd-dev_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    59488 9428587d37d42799458cbab9909717f1
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common3_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    46170 e0bd94aba8196fda2b280d63512c8766
      http://security.debian.org/pool/updates/main/a/avahi/avahi-utils_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    51248 a0e4eae8360a037128e21fb77ae3d4b6
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core-dev_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:   204800 dca516b15da8a9e63fba9126b8e6dd2f
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd1_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    38584 cad1047d3aff3e09e48074a4ee00cb04
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-dev_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    69158 8a70000d6cbde8d4531af98f193b18a3
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-dev_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    28888 c63485e850a01b0f096c84fcbb8ae1d6
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-dev_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    26516 f5bffbc708792944bfb04b695bf28920
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-1_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    28750 e5981dddc42bf05306495bde1bcb69a0
      http://security.debian.org/pool/updates/main/a/avahi/avahi-dnsconfd_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    34536 cedfcaa6d06d244ff0fbc59193a964ef
      http://security.debian.org/pool/updates/main/a/avahi/avahi-daemon_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    98946 130de83abc67d61ae45c83613f7a21dd
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client-dev_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    69900 67c50228144e6f8f1cdb663bf34291b5
      http://security.debian.org/pool/updates/main/a/avahi/avahi-autoipd_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    48296 6d897886473453791d19e8baaa87e1a0
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib-dev_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    28854 d35e8426103f6138f856d0a362073096
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl0_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    44176 827f2e0285e80ac538f534bb95eb2e98
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core4_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:   141590 5e272abfae6ff63932525bd307a1b3ec
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-data_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    23558 97a2a8e9885f5d1341220cbd3298dd47
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib1_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    26874 56b6a319a4861628a192f60bb14c92e6
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-1_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    26324 d11423a1bccc2d7302217303b9d045d2
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client3_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    54430 d9c01e729dd9c015ca7f71176c950c06
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl-dev_0.6.16-3etch2_ia64.deb
        Size/MD5 checksum:    63530 d84b46e225352f225ed88a749a12243c
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common3_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    39062 ca723bee9a6e5410e1a735a3f20dcccc
      http://security.debian.org/pool/updates/main/a/avahi/avahi-daemon_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    76644 7f792c93523d2fa3d21578f9747e5ce1
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core-dev_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:   160222 4a5834dfed0ac7e5def3d15a9dcbef41
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-1_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    27150 80ace2ec5158ad7ff73ec24e0d80a4e3
      http://security.debian.org/pool/updates/main/a/avahi/avahi-dnsconfd_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    30594 a28b044ffa272fd1c75198ee6d85a37d
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd1_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    32046 685e72415a46c7b3dca6d3c8833644db
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-dev_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    25428 c19ba84c28c05d92854d0785f4f338dd
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-dev_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    61688 374affd3c59790335c0fa70232f88072
      http://security.debian.org/pool/updates/main/a/avahi/avahi-autoipd_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    42152 37adabb7dbda1a5570e5d379149b4a07
      http://security.debian.org/pool/updates/main/a/avahi/avahi-utils_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    42218 d478292bc207d24282ccd8bbc7a81115
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-dev_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    27530 f1f278c7db4bad5dddedca04dbf67ff1
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-1_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    24966 bf170de01e5bad060977ac7e24aee7c6
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl-dev_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    57638 51df4913d698c32c8a015fb58b42d0c9
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-data_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    22890 37ec8d28fdc6a18d394ff95071e7e7dc
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib-dev_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    26280 76dd8d7153a5f6e84fa69a7c3880baf5
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client-dev_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    56598 0c63d9c941a6cce4eab6b2a9684e930b
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client3_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    40948 9faf3265109106cb065c0fe5aa086642
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core4_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    96100 baf54e0411903850a46ba5576271f671
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd-dev_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    55806 df8a81ac560b5f28bf4ea36c4cc1a26e
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl0_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    36706 f9961f00521696c9a8ec2b9dc32c8c94
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib1_0.6.16-3etch2_mips.deb
        Size/MD5 checksum:    25030 cff1bf92ef2f4effad725b87bd7afc7f
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-1_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    27452 396227c19cc0440afcd7f66f520b691c
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-1_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    25268 f2da7b0ac786be1f96011d41dd307258
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-data_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    22730 3b9a531e735597b77786e78f3a4b7aca
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd-dev_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    54808 67ed267f9612b79298b03ef6a2b8b90d
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core-dev_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:   159894 da8f0d29aac2c3b1b50ceeb8b08e1094
      http://security.debian.org/pool/updates/main/a/avahi/avahi-daemon_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    76540 030f0f208cee6be149e1ef419e14dc0a
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib-dev_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    27000 222c6e0da176aa881af4e1d092219bd3
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib1_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    25356 9a92df6f379ca37026a1c39ecd3106ff
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common3_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    39546 91c5e1d4470200e09dd82ee382a8633b
      http://security.debian.org/pool/updates/main/a/avahi/avahi-autoipd_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    42914 0b70d2e0f267516636c91ddc0a84a255
      http://security.debian.org/pool/updates/main/a/avahi/avahi-dnsconfd_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    31714 53cd510e941b185166cda93b6debb541
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl-dev_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    56936 8437ca514d5fb2d1c424f82e693c2679
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-dev_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    60766 f213054d8dc5925a44e307eaf3ed3a42
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-dev_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    25832 0234ac09bab571badce2067046fe610a
      http://security.debian.org/pool/updates/main/a/avahi/avahi-utils_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    42708 b4b6b84c34ccee1f552501513e29954b
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core4_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    96710 ddf6b69fe99167a9ca54cfff0435c60b
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl0_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    36980 4b8ece44a6d39dd1835e045a328fb941
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd1_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    32478 1020b0ce7d271f79454d119860771a8e
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-dev_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    27958 6d56c836c7b15a7d16f843c44b561a5e
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client-dev_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    56822 289eab1fd823ab8984f65d963188b3ad
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client3_0.6.16-3etch2_mipsel.deb
        Size/MD5 checksum:    41350 d80e0d1131b242d092b3e9d677828750
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl-dev_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    54320 e0eb45c3939b33c0929529da547ebb12
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client-dev_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    55492 c9e644bdf556e1f1b12bcc32a748eb24
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib-dev_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    26630 2e82a49211a70f33e86d51089018d947
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-dev_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    59498 8b3528efd6a22b6cbca3878ce62bc704
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl0_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    40124 6f6a50b83fc9f5d8aa664389ccc9754d
      http://security.debian.org/pool/updates/main/a/avahi/avahi-dnsconfd_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    32988 4639ed2c075550cc078b48a5c8033f79
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-dev_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    25464 8469fe12d78de160635fc01202936d24
      http://security.debian.org/pool/updates/main/a/avahi/avahi-daemon_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    77110 f85c15c14072e4145e0cc498a0cef903
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-dev_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    27574 315464e08f3e0e6a4b84d464bc86aadc
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-1_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    26882 ee7da4cb60f72d06972eb2522d5f1990
      http://security.debian.org/pool/updates/main/a/avahi/avahi-autoipd_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    43214 06bfe4308c61b9403b07481d8a87eb5e
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-1_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    29050 339647e5cb3cb4d2209b0c9a656b2aa8
      http://security.debian.org/pool/updates/main/a/avahi/avahi-utils_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    46412 d3236deeea9871c52d51fd8438f79d74
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd-dev_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    53794 e88c2249cc6302bc77c6f993f068a28c
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-data_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    22780 3b9a489914ff6c7319f2baa808b4b31f
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd1_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    34458 3e73aee93c411e9dbd080d10294a190d
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core4_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:   103230 1dab76b2cd76cdfaa9a8aa331f46972f
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common3_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    42210 6a941389a00270c07cb925bac4b44156
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib1_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    26954 a92e1fe219959762796bbcea63879241
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core-dev_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:   151950 934a99c98b0f9c630841f7d4f632e508
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client3_0.6.16-3etch2_powerpc.deb
        Size/MD5 checksum:    45712 afcc8e5ac8e7997ce06520468295aa52
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd-dev_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    52806 2159bdeaeefbf1bac017b73749705aff
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core-dev_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:   140994 e162f4553aafa22521400fc71b6e2955
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl0_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    40320 41b52cef3da0c2f7860bb6018aaffd4d
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd1_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    34268 6ed4db82c9244c0c86e8862d1b668ecc
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-dev_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    25208 3e595d30390d3d8dea75b7687ea01145
      http://security.debian.org/pool/updates/main/a/avahi/avahi-autoipd_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    43310 1983b6a44495718e083fcf04c30b8885
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-dev_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    59028 7247f2d68bbd11fe458a17902cd4f84a
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-data_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    22766 3231740bb2714e9d96bf3f8a818f0b84
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client-dev_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    53398 8f31e87717384601b85a3c020c202375
      http://security.debian.org/pool/updates/main/a/avahi/avahi-daemon_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    78222 9432a0cb5952f14e5754e255b4548ee6
      http://security.debian.org/pool/updates/main/a/avahi/avahi-dnsconfd_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    31888 f892cb69987c96a5088fabf12c8db567
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib-dev_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    26336 acfc14090d1069f7895699809008f6ac
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-dev_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    27144 2f94f5c72bd1709968ed0946fe6dde5e
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client3_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    45010 ee4d2bb4fd8c93b3f54339ffa4e483b1
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib1_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    26506 af0412f20b0946f6c57703e4fb3141f5
      http://security.debian.org/pool/updates/main/a/avahi/avahi-utils_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    43278 bc2e6dc97e61d0f88219a3111de843f3
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-1_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    27498 7f2dca3b2590a17977c9621feddd0570
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core4_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:   110094 cfc97c2f30cbf1d2092a88edb0b14381
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common3_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    43640 9cbc6b8fc97602a76c65ab3cc0d92796
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-1_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    25256 cad699f41f1aba87816e9a450e16a439
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl-dev_0.6.16-3etch2_s390.deb
        Size/MD5 checksum:    53646 28867c1506bd6cb673215623799a5221
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common3_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    38934 d8d7908b29966e515435647eb6db62fb
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib-dev_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    26350 d09b0fe9e59806ef87fe4cafbe1cf7d5
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-glib1_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    24896 0fc371457328a895d43351e0ef16c2d2
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client3_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    42506 72960cd3ba10c89845e6d138e7ed1ad5
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl-dev_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    52418 1e2d174a6983314031395687e0211991
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd-dev_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    52150 dd71f008d3fca5975163a112efaf0704
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-data_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    22522 11908fe76ba8e584136571f3f3f6d4cb
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-libdnssd1_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    32536 e92426b7e13a25dcc30f2720d8329707
      http://security.debian.org/pool/updates/main/a/avahi/avahi-utils_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    41504 d1eb26b9cd2e5f86213a9a932fc95c18
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-1_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    24968 64d2a21a25fbcf4fbfaa4953eb6e917f
      http://security.debian.org/pool/updates/main/a/avahi/avahi-dnsconfd_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    31398 366c28cc71a4d918c1b3aebfa09d2045
      http://security.debian.org/pool/updates/main/a/avahi/avahi-daemon_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    74314 b24af46be9313860d40467d15b032942
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-compat-howl0_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    38332 148c8f33a6d54299ab115f28923cd7d1
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core4_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:   100272 2b036aaec882cc0ecb09eb3388ea2371
      http://security.debian.org/pool/updates/main/a/avahi/avahi-autoipd_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    40704 9236ea4606deb0830ea766a437587dd8
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-common-dev_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    57124 c08b1d9692d301b3a31db849c8439e8c
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-1_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    27154 51d9fb4f6c91df32124be411f6f61c3b
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt4-dev_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    25316 bca01b30524301a83c42051b9c31418d
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-core-dev_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:   139194 42d17949abd45f742a75f0a701287e84
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-client-dev_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    51700 f329d6851a0c242992aa99b2c12c3df7
      http://security.debian.org/pool/updates/main/a/avahi/libavahi-qt3-dev_0.6.16-3etch2_sparc.deb
        Size/MD5 checksum:    27302 928c835f4f822b6151af2e0142447e24
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJTzhSAAoJEL97/wQC1SS+aecH/382jMvurE73swrfBe1COnRV
    bbyIiU44e/2kxY8nhnh/R2s2xkXi/p9v2ltLexUInLKoiVttnxMET7cohlZ+XaQy
    TehYp3sFphu642elBB5n1kc/+tn3sFvkfwtg6zmD+S29rGx1p7/MQGEZIW8liXPg
    oF62I723s5tjYoiItcXMbsjpmSptW0VhtdTZP6ceBWeOheb1JloVs5QNw5V2xbE4
    E5JW/8G8tjzqqC3Hy3OyYlg1eFIpJcIg/Jjzdml/rEVANknI2xR70KsmpjOmf3hS
    vu8yzMuEIGx/f11TcVobxKz5mplwgeXevc7N6coXCA78DVmREJPGSKv/NkFjOrw=
    =BEqG
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1691-1                  security@debian.org
    http://www.debian.org/security/                          Thijs Kinkhorst
    December 22, 2008                     http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : moodle
    Vulnerability  : several
    Problem type   : remote
    Debian-specific: no
    CVE Id(s)      : CVE-2007-3555 CVE-2008-1502 CVE-2008-3325 CVE-2008-3326
                     CVE-2008-4796 CVE-2008-4810 CVE-2008-4811 CVE-2008-5432
    Debian Bugs    : 432264 471158 489533 492492 504235 504345 508593
    
    Several remote vulnerabilities have been discovered in Moodle, an online
    course management system. The following issues are addressed in this
    update, ranging from cross site scripting to remote code execution.
    
    Various cross site scripting issues in the Moodle codebase
    (CVE-2008-3326, CVE-2008-3325, CVE-2007-3555, CVE-2008-5432,
    MSA-08-0021, MDL-8849, MDL-12793, MDL-11414, MDL-14806,
    MDL-10276).
    
    Various cross site request forgery issues in the Moodle codebase
    (CVE-2008-3325, MSA-08-0023).
    
    Privilege escalation bugs in the Moodle codebase (MSA-08-0001, MDL-7755).
    
    SQL injection issue in the hotpot module (MSA-08-0010).
    
    An embedded copy of Smarty had several vulnerabilities
    (CVE-2008-4811, CVE-2008-4810).
    An embedded copy of Snoopy was vulnerable to cross site scripting
    (CVE-2008-4796).
    An embedded copy of Kses was vulnerable to cross site scripting
    (CVE-2008-1502).
    
    For the stable distribution (etch), these problems have been fixed in
    version 1.6.3-2+etch1.
    
    For the unstable distribution (sid), these problems have been fixed in
    version 1.8.2.dfsg-2.
    
    We recommend that you upgrade your moodle (1.6.3-2+etch1) package.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch1.diff.gz
        Size/MD5 checksum:    24019 d29c179786ca1dcadf232c5e9a601362
      http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3.orig.tar.gz
        Size/MD5 checksum:  7465709 2f9f3fcf83ab0f18c409f3a48e07eae2
      http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch1.dsc
        Size/MD5 checksum:      793 d9a1fceaf316b608709be372d97e667a
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch1_all.deb
        Size/MD5 checksum:  6592474 9a5fb5924faa639952c3171665bc347d
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.6 (GNU/Linux)
    
    iQEVAwUBSU9O3Wz0hbPcukPfAQJEwwf9Hw1Rvt1FLIzzB4OsBKS91yaM+lqDwmfu
    pi7w5JXmc42AmaoVRCs23LxyqC30qV+vO3ZheYM7qgCZcrdpsWnYCOTy8Var6T0U
    hdeE7UeRdlaCMkMEHt505YxNMy7h0Z3HmhZB8ysuSTT9iQ2AAZMeUFJB1MUM/Yf2
    8GiQcnIJMcaM8je0M7bjqzSYTA6H8EIuqZZk88FJHhWinMZLWGnKqUoG7cnFfOVd
    b0hKY093yf6hNT1pzx5a/a3PaKGjppGtZ+NnaBI8Q7YJvltqBb5lztWXFHuEJCWg
    4Oo86NEb8/ARXGxugv0MUFvGPULfMVOTtnvF2BuTZLGZuvprofLy6Q==
    =kHvM
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1688-2                  security@debian.org
    http://www.debian.org/security/                           Steffen Joeris
    December 22, 2008                     http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : courier-authlib
    Vulnerability  : SQL injection
    Problem type   : local/remote XXX
    Debian-specific: no
    CVE Id(s)      : CVE-2008-2380 CVE-2008-2667
    
    The update of courier-authlib in DSA 1688-1 caused a regression with
    setups that do not use mail addresses for authentification.  This update
    fixes this regression. For reference, the full advisory text is below.
    
    Two SQL injection vulnerabilities have beein found in courier-authlib,
    the courier authentification library.  The MySQL database interface used
    insufficient escaping mechanisms when constructing SQL statements,
    leading to SQL injection vulnerabilities if certain charsets are used
    (CVE-2008-2380).  A similar issue affects the PostgreSQL database
    interface (CVE-2008-2667).
    
    For the stable distribution (etch), these problems have been fixed in
    version 0.58-4+etch3.
    
    For the testing distribution (lenny) and the unstable distribution
    (sid), these problems have been fixed in version 0.61.0-1+lenny1.
    
    We recommend that you upgrade your courier-authlib packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch3.dsc
        Size/MD5 checksum:      970 eea6bc2a491339d1b06f0d9891906a4f
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58.orig.tar.gz
        Size/MD5 checksum:  3342115 75b5b2b72d550048ed1b29e687a1a60d
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch3.diff.gz
        Size/MD5 checksum:    44339 c051936ba955b33ac17bed1a7a062ed6
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch3_alpha.deb
        Size/MD5 checksum:   150150 c1fb3322ef09b7e5592cdb2e0e972e8b
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch3_alpha.deb
        Size/MD5 checksum:     6982 fdcfcee4cf7e92463d80fc52c31544c6
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch3_alpha.deb
        Size/MD5 checksum:     8958 d0d7c0c186dc70bf163fb56efdac13e0
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch3_alpha.deb
        Size/MD5 checksum:    92768 ad72b16c890b88f5878b044ba634d743
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch3_alpha.deb
        Size/MD5 checksum:    23274 072c28b73f51ec0c0853d2235cc43f7a
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch3_alpha.deb
        Size/MD5 checksum:    20456 9946cb154a436ad185e6ac59d219ee0d
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch3_alpha.deb
        Size/MD5 checksum:    20384 add1d85c7f9f1f951110112e57dd941c
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch3_alpha.deb
        Size/MD5 checksum:    39140 eb641b37baca55b34824e6ccc9123604
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch3_amd64.deb
        Size/MD5 checksum:   111930 9eadcaae493d99804507584da9a84ed3
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch3_amd64.deb
        Size/MD5 checksum:    22290 82ddefca4a28ee7b7138b769bdf70a46
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch3_amd64.deb
        Size/MD5 checksum:     8404 17f359e16622de5b346c4b6ec21b46d5
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch3_amd64.deb
        Size/MD5 checksum:    34396 3db1718272c4bd67cd9afb61176d6b93
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch3_amd64.deb
        Size/MD5 checksum:    81536 13269dedb780975742c82e8b132fc1e8
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch3_amd64.deb
        Size/MD5 checksum:    20070 0a0f9a90faff809bf7fcb6828146e1ca
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch3_amd64.deb
        Size/MD5 checksum:     6978 8046f6964e4b80c81bfb18f53a861808
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch3_amd64.deb
        Size/MD5 checksum:    19874 b6255a89d42af434881f4a70047b35af
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch3_hppa.deb
        Size/MD5 checksum:     6982 883a20dc2aa90969542ec955752bff73
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch3_hppa.deb
        Size/MD5 checksum:    37910 625d55b6bca6443e8a4815948a8be2f1
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch3_hppa.deb
        Size/MD5 checksum:    20838 ddedaa4084343959757826e6bff14bfc
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch3_hppa.deb
        Size/MD5 checksum:    20872 07755a04f444333e80f07b37057fc35a
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch3_hppa.deb
        Size/MD5 checksum:     9066 74c2fb5f4c6d5e56d4659746a92a3d51
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch3_hppa.deb
        Size/MD5 checksum:    89204 1b0afa7787fac7d6a28c94f667ced9fe
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch3_hppa.deb
        Size/MD5 checksum:    23672 f01834aacc18dab3bd4b6f6d963df347
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch3_hppa.deb
        Size/MD5 checksum:   123946 00826c1564cdae69df31a42418562c4c
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch3_i386.deb
        Size/MD5 checksum:    18984 3ba8eb6f6cca2ee36e0f244c4534ae06
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch3_i386.deb
        Size/MD5 checksum:    21244 711ee9c10e91535cb95574a40ed003bf
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch3_i386.deb
        Size/MD5 checksum:     6984 01ce4d9a33afd119261053e902ddf776
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch3_i386.deb
        Size/MD5 checksum:    76350 01bea1c85a49803f32a641d5c88aa47f
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch3_i386.deb
        Size/MD5 checksum:    18792 973c61fe45d343a5f6e733583677a660
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch3_i386.deb
        Size/MD5 checksum:    33270 9b64fa8ef06742b5c3c30b513380ed10
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch3_i386.deb
        Size/MD5 checksum:     7832 b32c9185e3e953f32198ac39c4b34658
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch3_i386.deb
        Size/MD5 checksum:   100350 20f136305d113cb313583524d99c2257
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch3_ia64.deb
        Size/MD5 checksum:   109912 f34ccc9736f6f983e3808609effe05d2
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch3_ia64.deb
        Size/MD5 checksum:    28118 83b5b87867515ef4ffb2c7f55d2bfd43
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch3_ia64.deb
        Size/MD5 checksum:     6976 1147d769c809e15bc774ac185f1b8b42
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch3_ia64.deb
        Size/MD5 checksum:    44760 2edbd453344c340ecbce8e7cc6680512
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch3_ia64.deb
        Size/MD5 checksum:    23770 c2482713d38f71c3df161e15266d9cc1
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch3_ia64.deb
        Size/MD5 checksum:    24068 e2e591dcc0b79db504364cff45925c1c
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch3_ia64.deb
        Size/MD5 checksum:   148148 aa9a24fe0797adce9743dad4a5a69f11
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch3_ia64.deb
        Size/MD5 checksum:    10212 9776f4d13b0f55805963dc9ebe0cb775
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch3_mips.deb
        Size/MD5 checksum:   124734 db5ac1f173860a9a8b0abdb81899eaf5
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch3_mips.deb
        Size/MD5 checksum:    21922 f905ce6714943afc4f99bde253ad06dd
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch3_mips.deb
        Size/MD5 checksum:    81866 342671c976b85df7f9cbdcd4e9944fbc
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch3_mips.deb
        Size/MD5 checksum:     6980 67f98c77898ebe0ad905c87a22df3765
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch3_mips.deb
        Size/MD5 checksum:     8212 8f102b2250c3d69e28dcc72a50e660b9
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch3_mips.deb
        Size/MD5 checksum:    19488 a7fc20bcbaafd8d6f0053b41b2e07e5e
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch3_mips.deb
        Size/MD5 checksum:    19506 782e5bf2a2ba56eba4f9836ffae51125
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch3_mips.deb
        Size/MD5 checksum:    35230 113b19cb398cdd1d9599a0cc21887e0c
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch3_mipsel.deb
        Size/MD5 checksum:    19500 69d3c6a55491a2b05e8e45a4dfb44c09
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch3_mipsel.deb
        Size/MD5 checksum:    22040 c20f1e9c94a4fb18fd395faea3166422
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch3_mipsel.deb
        Size/MD5 checksum:   120978 709261a8c1f12aa3a2c41f7927277219
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch3_mipsel.deb
        Size/MD5 checksum:    81726 30bd7b0c49f3c2e061dfd334a4228480
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch3_mipsel.deb
        Size/MD5 checksum:     6984 1abad4411b157633529b23495a10dbf9
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch3_mipsel.deb
        Size/MD5 checksum:    19534 423fc50987ba31f0fc36f9fa6b1a1996
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch3_mipsel.deb
        Size/MD5 checksum:    36020 b2503eacfd49e69405e0523b2116a05b
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch3_mipsel.deb
        Size/MD5 checksum:     8228 f3394eef4fe9fd4415b04398a434fd09
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch3_powerpc.deb
        Size/MD5 checksum:    88110 26ab00dd8ee3fc7614aec67c46672621
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch3_powerpc.deb
        Size/MD5 checksum:    19706 e3a473111e423e8238da8fa1e9fcc5f2
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch3_powerpc.deb
        Size/MD5 checksum:     8352 b5a2f944ca239eb5a333a8da10a8b745
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch3_powerpc.deb
        Size/MD5 checksum:    19890 22eab317e0e2158d748f9241f7aed0a3
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch3_powerpc.deb
        Size/MD5 checksum:    35768 8a1a598aed19939add47f6e65149c97d
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch3_powerpc.deb
        Size/MD5 checksum:     6980 0a5425ab814688d31b2d773941e5b56a
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch3_powerpc.deb
        Size/MD5 checksum:   110380 0e1c65ff5693adb9b0865aaba67bd5da
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch3_powerpc.deb
        Size/MD5 checksum:    22104 4ee5709bc224137a1733e75966c305dd
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch3_s390.deb
        Size/MD5 checksum:     8288 7d1547a5ddade9332cfd1dc618fd65dc
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch3_s390.deb
        Size/MD5 checksum:     6970 a1b9b7c977b68a50d3736d669f88bb8b
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch3_s390.deb
        Size/MD5 checksum:   102932 519d077f2a54fd34f3f9f86151ff2a85
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch3_s390.deb
        Size/MD5 checksum:    22768 91530b8b45b0c792a2430cafc8502c2b
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch3_s390.deb
        Size/MD5 checksum:    19778 c3252ded11e8694ac91f7458e54a0364
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch3_s390.deb
        Size/MD5 checksum:    84534 9d9b385748427bcd4a240365d5da651b
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch3_s390.deb
        Size/MD5 checksum:    20034 337f77aa4ddd3f32af8dac532bdef1d3
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch3_s390.deb
        Size/MD5 checksum:    35918 570f14e13e5541253b014dc5f707475e
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-userdb_0.58-4+etch3_sparc.deb
        Size/MD5 checksum:    33484 8dab32a63b1fc4ded9fbfdde33ef3639
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-dev_0.58-4+etch3_sparc.deb
        Size/MD5 checksum:   102396 8a2f9a0f833510ef53375926befda961
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authdaemon_0.58-4+etch3_sparc.deb
        Size/MD5 checksum:     6988 9b01eba47daf823d4f1198a90b784c6c
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib_0.58-4+etch3_sparc.deb
        Size/MD5 checksum:    75698 09c45f6116ca18e48c8e3702dada54b1
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-pipe_0.58-4+etch3_sparc.deb
        Size/MD5 checksum:     7878 3009ba4c1c2f042b5fe7e5e9ad4655b6
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-mysql_0.58-4+etch3_sparc.deb
        Size/MD5 checksum:    19218 64ed92e3620a8c3eb44a3655a93cf51d
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-ldap_0.58-4+etch3_sparc.deb
        Size/MD5 checksum:    21830 97997f7a1fde6c52f7d7ddffdbe66724
      http://security.debian.org/pool/updates/main/c/courier-authlib/courier-authlib-postgresql_0.58-4+etch3_sparc.deb
        Size/MD5 checksum:    19170 fe45e9811a4f95cd469f7f1dbd607098
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJUCBIAAoJEL97/wQC1SS+BVsH/335R5WqInHRraHk0JE3Owzt
    qV5xBgjWXnU7cxKEvsPmvhYanJs6kjd24S5d9GOQVVZhKS6zC6ToH+u7GwOnYChR
    +kLdtLziYSx8mcZUtrjWeL/iYaE3xClRTROgfYUXrMJ2RawU4kUgx7nxTPwF76ei
    axmURM4ImgoxVF7fMRRIoX/pgvl3dGoUPdzCepxTrrdjqfUhXZCaQ8l7xikKVcGV
    71oM7szbhZL6QIBxY2G4Oa/LByuj1UOSfo9y0M4+V46KyFYBjjKbzbqNpo2agLU+
    7LR0mtk7dYvVDDdr/gDBcTJ0y8UCkrJ3SVTJqHVXHx8CrDikc5IfOqEd+1sWA1g=
    =0+3H
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1692-1                  security@debian.org
    http://www.debian.org/security/                           Steffen Joeris
    December 27, 2008                     http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : php-xajax
    Vulnerability  : insufficient input sanitising
    Problem type   : remote
    Debian-specific: no
    CVE Id(s)      : CVE-2007-2739
    
    It was discovered that php-xajax, a library to develop Ajax
    applications, did not sufficiently sanitise URLs, which allows attackers
    to perform cross-site scripting attacks by using malicious URLs.
    
    For the stable distribution (etch) this problem has been fixed in
    version 0.2.4-2+etch1.
    
    For the testing (lenny) and unstable (sid) distributions this problem
    has been fixed in version 0.2.5-1.
    
    We recommend that you upgrade your php-xajax package.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/p/php-xajax/php-xajax_0.2.4-2+etch1.dsc
        Size/MD5 checksum:      648 f4bbc450f631e1a000679690858997ff
      http://security.debian.org/pool/updates/main/p/php-xajax/php-xajax_0.2.4-2+etch1.diff.gz
        Size/MD5 checksum:     3441 37934d6df03bca92b0ee2d029b46faa4
      http://security.debian.org/pool/updates/main/p/php-xajax/php-xajax_0.2.4.orig.tar.gz
        Size/MD5 checksum:    48261 58229c55be17c681a22699b564e6be26
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/p/php-xajax/php-xajax_0.2.4-2+etch1_all.deb
        Size/MD5 checksum:    44770 152e977b65bc603155947edf9738ab31
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJVflRAAoJEL97/wQC1SS+hcIH/0kGCBer0lWzivFYSjuomfpe
    vS3FmudLu7K4wf2HMhQkBYV9krH2S6Jyki16k6hmerh5cDDOlrZxKuLFkqUfPBIr
    Xd2XQC51gP7+/l6W3jEdsndiqPFx5uJhklzUddKrg665EqyDXxG2GIDwvJ67P7YG
    +GY2ngEEIkGnr9akEPVWXIUS2NTMm45RpS0l1ZjK7tuSNWwLYg66JLKhXcwV7THJ
    DUMex6/6HlZdXgezxpbM3hDwc6sa9bK+/LBIcgcxbLcdbV8ODGCvH+Z0OmYtEsov
    4/TGaNlI+OgdoCtC2t9+6HeA31SYyaxN79qhM8B7W5OI5gN+xGxjkAKsb29jA70=
    =xPXX
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1693-1                  security@debian.org
    http://www.debian.org/security/                          Thijs Kinkhorst
    December 27, 2008                     http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : phppgadmin
    Vulnerability  : several
    Problem type   : remote
    Debian-specific: no
    CVE Id(s)      : CVE-2007-2865 CVE-2007-5728 CVE-2008-5587
    Debian Bugs    : 427151 449103 508026
    
    Several remote vulnerabilities have been discovered in phpPgAdmin, a tool
    to administrate PostgreSQL database over the web. The Common
    Vulnerabilities and Exposures project identifies the following problems:
    
    CVE-2007-2865
    
        Cross-site scripting vulnerability allows remote attackers to inject
        arbitrary web script or HTML via the server parameter.
    
    CVE-2007-5728
    
        Cross-site scripting vulnerability allows remote attackers to inject
        arbitrary web script or HTML via PHP_SELF.
    
    CVE-2008-5587
    
        Directory traversal vulnerability allows remote attackers to read
        arbitrary files via _language parameter.
    
    For the stable distribution (etch), these problems have been fixed in
    version 4.0.1-3.1etch1.
    
    For the unstable distribution (sid), these problems have been fixed in
    version 4.2.1-1.1.
    
    We recommend that you upgrade your phppgadmin package.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4.0.1.orig.tar.gz
        Size/MD5 checksum:   703673 eedac65ce5d73aca2f92388c9766ba1b
      http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4.0.1-3.1etch1.dsc
        Size/MD5 checksum:      890 e6dea463d597f6dda40d774820e3bb03
      http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4.0.1-3.1etch1.diff.gz
        Size/MD5 checksum:    15678 1cbe0f619e65a8c49894e8c0fe015fb5
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4.0.1-3.1etch1_all.deb
        Size/MD5 checksum:   704386 1f5b68f6be269eb3c10646cd8d69c31c
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.6 (GNU/Linux)
    
    iQEVAwUBSVYXX2z0hbPcukPfAQL7Jgf8D01CiY6dpQO7AUmDCU/sNIHnMudx5ZEC
    y/Yk0b2raMmtJeejXpdD4zRpPGOIx4LBefh2BmyyC18vPzdjbX/5MbXvOewmeqm3
    6eI6clMf5rpbb7jnzL1SxqMwt+7YocmU30JiWMbuXggrCUpawsxROTMIJkVqT86c
    Yg8DKOWpLt43YAYl+IRx2sbmDP/kGN2omn6pBnkqcIeQh8wB7CNmSEeSlkH0iOTS
    EoTOyjTWhTFAz1T8bG6A6YSmgBSTZ+tEb1eqODMB1y8POQ7k4B4MmCA1OPNtJuoq
    EEB2KoaDJkkhS8anv2fyYEmufZBTqD8AGsFPGttqSMBQyR9XdYD5cg==
    =J4km
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1694-1                  security@debian.org
    http://www.debian.org/security/                           Florian Weimer
    January 02, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : xterm
    Vulnerability  : design flaw
    Problem type   : local (remote)
    Debian-specific: no
    CVE Id(s)      : CVE-2008-2383
    Debian Bug     : 510030
    
    Paul Szabo discovered that xterm, a terminal emulator for the X Window
    System, places arbitrary characters into the input buffer when
    displaying certain crafted escape sequences (CVE-2008-2383).
    
    As an additional precaution, this security update also disables font
    changing, user-defined keys, and X property changes through escape
    sequences.
    
    For the stable distribution (etch), this problem has been fixed in
    version 222-1etch3.
    
    For the unstable distribution (sid), this problem will be fixed soon.
    
    We recommend that you upgrade your xterm package.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3.dsc
        Size/MD5 checksum:     1123 3bcc850fe7c9057e5d5d03617cc95195
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3.diff.gz
        Size/MD5 checksum:    61664 f1e11e4f4c85db1e2ffa67c5d132d2e6
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222.orig.tar.gz
        Size/MD5 checksum:   802986 bb77882a33083632a9c6c9de004a54fb
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_alpha.deb
        Size/MD5 checksum:   437394 2a16b16a6ed79a908987769b9b5a68d8
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_amd64.deb
        Size/MD5 checksum:   416434 46ba9b4430c313464afeaa856d02f09a
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_arm.deb
        Size/MD5 checksum:   412020 9119d878ffedf54c843ec84a98022a3d
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_hppa.deb
        Size/MD5 checksum:   421890 9b3326921fbbd0ba014b3717b20c53fb
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_i386.deb
        Size/MD5 checksum:   403908 f54263828a01af2af86f25c1fedc7aa6
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_ia64.deb
        Size/MD5 checksum:   509374 052861cf2a23d7a414c038d510fc7f01
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_mips.deb
        Size/MD5 checksum:   428858 63615939a4de2f4e3ba0cc61adbf0e47
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_mipsel.deb
        Size/MD5 checksum:   425604 9d18da53eea366eb2688dfe629d95e82
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_powerpc.deb
        Size/MD5 checksum:   409986 824e743d4a6a1abeb5c1fdc0a9e7d006
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_s390.deb
        Size/MD5 checksum:   422196 9b78491ef8fb34da8d5e183e91fc6c65
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_sparc.deb
        Size/MD5 checksum:   409994 e284b9163d0da06f932f8e243ccaee2b
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJXmW3AAoJEL97/wQC1SS+B88IALCE/5QT8PKOspzA7s4TVrCx
    sZfNri9GsBaQv2fOVRT3QkXGDmKkDmoCxnYT2fsvZ7NoulKdrmoPlNtTNtNxi7y+
    sK7j2RVcOkAptxv/OVxwwPMh9KNriwbUnoGgds7vDVLDIAm2DrGqHuKgfyCS8ZxH
    RxaVDnqMAKrHLvTliGigu3yiiO08Mqbl95Wi5OI86L8NNAQ5KzkhoQyh8IQzIgm2
    kdKEDS/hu7oOCpB6TgHNX+FDVShZpSCVVp2SxIUY0WYdrFhHONv4T9aJCZTh5Lvq
    FxKq+zrdd0p4fASVc99p1dL1n8blqXgJVVFYXZIn04r8sbXhQ3Xj3zKezVC39MM=
    =mXuF
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1695-1                  security@debian.org
    http://www.debian.org/security/                           Florian Weimer
    January 02, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : ruby1.8, ruby1.9
    Vulnerability  : memory leak
    Problem type   : local (remote)
    Debian-specific: no
    CVE Id(s)      : CVE-2008-3443
    Debian Bug     : 494401
    
    The regular expression engine of Ruby, a scripting language, contains a
    memory leak which can be triggered remotely under certain circumstances,
    leading to a denial of service condition (CVE-2008-3443).
    
    In addition, this security update addresses a regression in the REXML
    XML parser of the ruby1.8 package; the regression was introduced in
    DSA-1651-1.
    
    For the stable distribution (etch), this problem has been fixed in version
    1.8.5-4etch4 of the ruby1.8 package, and version 1.9.0+20060609-1etch4
    of the ruby1.9 package.
    
    For the unstable distribution (sid), this problem has been fixed in
    version 1.8.7.72-1 of the ruby1.8 package.  The ruby1.9 package will be
    fixed soon.
    
    We recommend that you upgrade your Ruby packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.5.orig.tar.gz
        Size/MD5 checksum:  4434227 aae9676332fcdd52f66c3d99b289878f
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9_1.9.0+20060609-1etch4.dsc
        Size/MD5 checksum:     1102 1c38e939e74513153ee6677ef9f85b0d
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.5-4etch4.diff.gz
        Size/MD5 checksum:   176939 2fea21ebd5e29d26714843fa415d6310
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9_1.9.0+20060609-1etch4.diff.gz
        Size/MD5 checksum:    32843 859c9ba559722e156d6931f3c8c347a4
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9_1.9.0+20060609.orig.tar.gz
        Size/MD5 checksum:  4450198 483d9b46a973c7e14f7586f0b1129891
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.5-4etch4.dsc
        Size/MD5 checksum:     1379 cbcf9f41397f2658e1db5ebae0178ccd
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9-examples_1.9.0+20060609-1etch4_all.deb
        Size/MD5 checksum:   265870 fc302abc0465ab56ccd16fc0e724885c
      http://security.debian.org/pool/updates/main/r/ruby1.9/irb1.9_1.9.0+20060609-1etch4_all.deb
        Size/MD5 checksum:   255764 40a840e93b23abfe83f06fb68e411ecc
      http://security.debian.org/pool/updates/main/r/ruby1.8/rdoc1.8_1.8.5-4etch4_all.deb
        Size/MD5 checksum:   309788 1a32b37a2ae266825239d31479481202
      http://security.debian.org/pool/updates/main/r/ruby1.8/ri1.8_1.8.5-4etch4_all.deb
        Size/MD5 checksum:  1232694 0f2de56be8bf69925bdd69c0ebdb6e88
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9-elisp_1.9.0+20060609-1etch4_all.deb
        Size/MD5 checksum:   229450 c445df6488d98bba432cad422b2d26d2
      http://security.debian.org/pool/updates/main/r/ruby1.9/ri1.9_1.9.0+20060609-1etch4_all.deb
        Size/MD5 checksum:   694310 ba20a22e37fe3128ba68065e81b34be2
      http://security.debian.org/pool/updates/main/r/ruby1.9/rdoc1.9_1.9.0+20060609-1etch4_all.deb
        Size/MD5 checksum:   318608 107093187b68a01e89937e5595ada72f
      http://security.debian.org/pool/updates/main/r/ruby1.8/irb1.8_1.8.5-4etch4_all.deb
        Size/MD5 checksum:   235540 742511548e73ce861aec2ebced3bb820
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8-elisp_1.8.5-4etch4_all.deb
        Size/MD5 checksum:   210174 3f151d4c5e251849b7bc82a4c0cc6717
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8-examples_1.8.5-4etch4_all.deb
        Size/MD5 checksum:   243302 af6b1eacf4c03bc3fe53e3c2a8e13044
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/r/ruby1.8/libreadline-ruby1.8_1.8.5-4etch4_alpha.deb
        Size/MD5 checksum:   199212 7450977513c7006dd667426d5499092c
      http://security.debian.org/pool/updates/main/r/ruby1.9/libopenssl-ruby1.9_1.9.0+20060609-1etch4_alpha.deb
        Size/MD5 checksum:   324692 f53f9acfd76ea3a29a8ef4892f2b573a
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9_1.9.0+20060609-1etch4_alpha.deb
        Size/MD5 checksum:   237774 e9a60d0d7c8f73357b09bb6188070e21
      http://security.debian.org/pool/updates/main/r/ruby1.9/libdbm-ruby1.9_1.9.0+20060609-1etch4_alpha.deb
        Size/MD5 checksum:   217606 1479ee1a4b51cb0a75783b2f3844723b
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.5-4etch4_alpha.deb
        Size/MD5 checksum:   219472 952a4e672625ce7f2529493b00364604
      http://security.debian.org/pool/updates/main/r/ruby1.8/libopenssl-ruby1.8_1.8.5-4etch4_alpha.deb
        Size/MD5 checksum:   301142 fb710ce9d21ff1fb7f8a3808fcb78d60
      http://security.debian.org/pool/updates/main/r/ruby1.9/libgdbm-ruby1.9_1.9.0+20060609-1etch4_alpha.deb
        Size/MD5 checksum:   216946 515718544ab0101093c6a57e63cb1cb8
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8-dev_1.8.5-4etch4_alpha.deb
        Size/MD5 checksum:   903520 d39e018101c51c880e2cd9895a88a1f8
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9-dev_1.9.0+20060609-1etch4_alpha.deb
        Size/MD5 checksum:   961022 f6d226e51af5740c5bda5772cf20e8a8
      http://security.debian.org/pool/updates/main/r/ruby1.9/libreadline-ruby1.9_1.9.0+20060609-1etch4_alpha.deb
        Size/MD5 checksum:   217630 292a9b82a47bd1bc3c7b4ab440029cca
      http://security.debian.org/pool/updates/main/r/ruby1.8/libdbm-ruby1.8_1.8.5-4etch4_alpha.deb
        Size/MD5 checksum:   198300 653c076799344535ac9b6a791ffb132d
      http://security.debian.org/pool/updates/main/r/ruby1.9/libtcltk-ruby1.9_1.9.0+20060609-1etch4_alpha.deb
        Size/MD5 checksum:  1881422 2eb8f5dd96ced6eac7473eed467c5663
      http://security.debian.org/pool/updates/main/r/ruby1.8/libtcltk-ruby1.8_1.8.5-4etch4_alpha.deb
        Size/MD5 checksum:  1869092 3d45f58f803de6208f28d5267be89ecf
      http://security.debian.org/pool/updates/main/r/ruby1.8/libgdbm-ruby1.8_1.8.5-4etch4_alpha.deb
        Size/MD5 checksum:   199236 81f0b4078e9412536836f8b973756318
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8-dbg_1.8.5-4etch4_alpha.deb
        Size/MD5 checksum:  1074308 f3ec5b9b0349dbc5ef735942a997327c
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9_1.9.0+20060609-1etch4_alpha.deb
        Size/MD5 checksum:  1890052 5779555b10f64a438773cbf048ac545c
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9-dbg_1.9.0+20060609-1etch4_alpha.deb
        Size/MD5 checksum:   340202 69dd9f78aca79c5e05b191d7163a01b4
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8_1.8.5-4etch4_alpha.deb
        Size/MD5 checksum:  1638634 ed825a333226565b4b98b32b93cd1fe6
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9-dev_1.9.0+20060609-1etch4_amd64.deb
        Size/MD5 checksum:   807592 464c13292ce358b22247cc998f743562
      http://security.debian.org/pool/updates/main/r/ruby1.9/libdbm-ruby1.9_1.9.0+20060609-1etch4_amd64.deb
        Size/MD5 checksum:   216630 867bdeff043830d6bad157d1931dc948
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9_1.9.0+20060609-1etch4_amd64.deb
        Size/MD5 checksum:   235632 c4ad4cb0bb9cd697534a2c262100c6cc
      http://security.debian.org/pool/updates/main/r/ruby1.8/libreadline-ruby1.8_1.8.5-4etch4_amd64.deb
        Size/MD5 checksum:   198112 17cd7156a45a5aff5c27d82e268a3c4d
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8-dbg_1.8.5-4etch4_amd64.deb
        Size/MD5 checksum:  1070604 1bddf59e7b60371ff8099b08bf75ac30
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9_1.9.0+20060609-1etch4_amd64.deb
        Size/MD5 checksum:  1850656 aa571b58631a8557f7019d592636f481
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8-dev_1.8.5-4etch4_amd64.deb
        Size/MD5 checksum:   749162 af403f99a95355682a54909929e5199a
      http://security.debian.org/pool/updates/main/r/ruby1.9/libgdbm-ruby1.9_1.9.0+20060609-1etch4_amd64.deb
        Size/MD5 checksum:   216080 a43f4b0559aa2c9b50ea5d7973162aa2
      http://security.debian.org/pool/updates/main/r/ruby1.8/libdbm-ruby1.8_1.8.5-4etch4_amd64.deb
        Size/MD5 checksum:   197652 a9e00dc85e9f2cae38eb09e899130248
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.5-4etch4_amd64.deb
        Size/MD5 checksum:   217322 9e02a9f097c955e4400812f0c04d7508
      http://security.debian.org/pool/updates/main/r/ruby1.8/libtcltk-ruby1.8_1.8.5-4etch4_amd64.deb
        Size/MD5 checksum:  1830274 53805790080b4cd1daf1a4d63ed8256c
      http://security.debian.org/pool/updates/main/r/ruby1.9/libtcltk-ruby1.9_1.9.0+20060609-1etch4_amd64.deb
        Size/MD5 checksum:  1878288 01c7b13369a8758303404727fea129fd
      http://security.debian.org/pool/updates/main/r/ruby1.8/libopenssl-ruby1.8_1.8.5-4etch4_amd64.deb
        Size/MD5 checksum:   301112 987113850c63d29874841e5faff83d89
      http://security.debian.org/pool/updates/main/r/ruby1.8/libgdbm-ruby1.8_1.8.5-4etch4_amd64.deb
        Size/MD5 checksum:   198726 4d65ce2e10feab441a946a18023daf42
      http://security.debian.org/pool/updates/main/r/ruby1.9/libreadline-ruby1.9_1.9.0+20060609-1etch4_amd64.deb
        Size/MD5 checksum:   216568 93fe5252d04959e64dc6576d95b7c2b6
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8_1.8.5-4etch4_amd64.deb
        Size/MD5 checksum:  1584216 69ed7f6bca37c0c549bf528f773e2900
      http://security.debian.org/pool/updates/main/r/ruby1.9/libopenssl-ruby1.9_1.9.0+20060609-1etch4_amd64.deb
        Size/MD5 checksum:   323450 5baea37cc897959fc20d48ac89de0d74
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9-dbg_1.9.0+20060609-1etch4_amd64.deb
        Size/MD5 checksum:   345864 c39d9b07d0cb6e4099ca3efeafb5fa6e
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8_1.8.5-4etch4_arm.deb
        Size/MD5 checksum:  1526984 0e6ab8221858243c7145bbc41ecb4e8f
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9-dbg_1.9.0+20060609-1etch4_arm.deb
        Size/MD5 checksum:   365056 66c7f98e2bb319a62ee7c4c92672c731
      http://security.debian.org/pool/updates/main/r/ruby1.8/libdbm-ruby1.8_1.8.5-4etch4_arm.deb
        Size/MD5 checksum:   196710 9e8c6e4cb718dc719e8fde6b26f962e4
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8-dbg_1.8.5-4etch4_arm.deb
        Size/MD5 checksum:   991516 14a9b5cbf719d62dc8353a51afb555a9
      http://security.debian.org/pool/updates/main/r/ruby1.8/libtcltk-ruby1.8_1.8.5-4etch4_arm.deb
        Size/MD5 checksum:  1859122 e0c7c1e7d2ccf0e49bce45e7e7bf1278
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9_1.9.0+20060609-1etch4_arm.deb
        Size/MD5 checksum:  1792772 d56d498189d5406b5020d9d924117e7c
      http://security.debian.org/pool/updates/main/r/ruby1.8/libgdbm-ruby1.8_1.8.5-4etch4_arm.deb
        Size/MD5 checksum:   197418 d26ec8fb413c9ebab080bedea93722b1
      http://security.debian.org/pool/updates/main/r/ruby1.8/libreadline-ruby1.8_1.8.5-4etch4_arm.deb
        Size/MD5 checksum:   197808 a36c730da4bcea2d72f5d370322eb30f
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9-dev_1.9.0+20060609-1etch4_arm.deb
        Size/MD5 checksum:   792994 579ec1a30cd9a1cbd8bf67aa06dc4d24
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8-dev_1.8.5-4etch4_arm.deb
        Size/MD5 checksum:   697246 ca45d9a326d51f5434d1621abcece266
      http://security.debian.org/pool/updates/main/r/ruby1.9/libdbm-ruby1.9_1.9.0+20060609-1etch4_arm.deb
        Size/MD5 checksum:   216240 423493a419191c35b8b3e80a1f1f1c9c
      http://security.debian.org/pool/updates/main/r/ruby1.9/libreadline-ruby1.9_1.9.0+20060609-1etch4_arm.deb
        Size/MD5 checksum:   216324 a266f8778f5e7d613db6ba3f15adb763
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9_1.9.0+20060609-1etch4_arm.deb
        Size/MD5 checksum:   237202 5fc7e98291401cd3fe917ed05d9bd015
      http://security.debian.org/pool/updates/main/r/ruby1.8/libopenssl-ruby1.8_1.8.5-4etch4_arm.deb
        Size/MD5 checksum:   287576 eced197b837fe4d62c03b20bed6815be
      http://security.debian.org/pool/updates/main/r/ruby1.9/libtcltk-ruby1.9_1.9.0+20060609-1etch4_arm.deb
        Size/MD5 checksum:  1876264 bc351c3337a5d5987f6ddb836768922e
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.5-4etch4_arm.deb
        Size/MD5 checksum:   219386 3f0b1eb14311c982d63ebd0fab64f5f4
      http://security.debian.org/pool/updates/main/r/ruby1.9/libgdbm-ruby1.9_1.9.0+20060609-1etch4_arm.deb
        Size/MD5 checksum:   215572 2c0ccc988ac6ea3250f8dc367ccaa2a2
      http://security.debian.org/pool/updates/main/r/ruby1.9/libopenssl-ruby1.9_1.9.0+20060609-1etch4_arm.deb
        Size/MD5 checksum:   311564 8dfe07d2f7dcf8275e8ad8f41dcda0c0
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/r/ruby1.9/libreadline-ruby1.9_1.9.0+20060609-1etch4_hppa.deb
        Size/MD5 checksum:   218160 513b9ae768f77d80a13fa851e1c8f4f7
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8-dev_1.8.5-4etch4_hppa.deb
        Size/MD5 checksum:   824152 6146a8f873531c0ed8cf0d06d2e17d2c
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9-dbg_1.9.0+20060609-1etch4_hppa.deb
        Size/MD5 checksum:   395602 6cc76b78245992c6a68b9e078ae89d53
      http://security.debian.org/pool/updates/main/r/ruby1.8/libreadline-ruby1.8_1.8.5-4etch4_hppa.deb
        Size/MD5 checksum:   199900 d70a4e3bc2ced6217727543e7fe0f9b0
      http://security.debian.org/pool/updates/main/r/ruby1.8/libopenssl-ruby1.8_1.8.5-4etch4_hppa.deb
        Size/MD5 checksum:   316214 4e6641aa45421ffab8b99ab8a9e8d16a
      http://security.debian.org/pool/updates/main/r/ruby1.9/libgdbm-ruby1.9_1.9.0+20060609-1etch4_hppa.deb
        Size/MD5 checksum:   217620 85109a63b0b20068f6320cda8f3ec6ad
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9_1.9.0+20060609-1etch4_hppa.deb
        Size/MD5 checksum:   237090 a3d1415f5a1ad8238d56b050975189e9
      http://security.debian.org/pool/updates/main/r/ruby1.8/libgdbm-ruby1.8_1.8.5-4etch4_hppa.deb
        Size/MD5 checksum:   200304 783f82fe9eac7aa259a35479cc2a47e7
      http://security.debian.org/pool/updates/main/r/ruby1.9/libtcltk-ruby1.9_1.9.0+20060609-1etch4_hppa.deb
        Size/MD5 checksum:  1880858 9ab71d7b85b97c1f2d2aa3500b9ce7c1
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8-dbg_1.8.5-4etch4_hppa.deb
        Size/MD5 checksum:  1040322 02afc219d2b174b059881ec0a83356fc
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9_1.9.0+20060609-1etch4_hppa.deb
        Size/MD5 checksum:  1861536 432efb1fffc5c2b1d9cc7b74ae7baa39
      http://security.debian.org/pool/updates/main/r/ruby1.8/libdbm-ruby1.8_1.8.5-4etch4_hppa.deb
        Size/MD5 checksum:   199202 84de055812481012c4876c17833ce3b0
      http://security.debian.org/pool/updates/main/r/ruby1.8/libtcltk-ruby1.8_1.8.5-4etch4_hppa.deb
        Size/MD5 checksum:  1869258 834f2dbf84ab6697d7980d3658290cfd
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.5-4etch4_hppa.deb
        Size/MD5 checksum:   219214 801a3641d72145d568a6c0c88ef43bd8
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9-dev_1.9.0+20060609-1etch4_hppa.deb
        Size/MD5 checksum:   888950 464ded03bf97abbc0d417b089fa87d60
      http://security.debian.org/pool/updates/main/r/ruby1.9/libdbm-ruby1.9_1.9.0+20060609-1etch4_hppa.deb
        Size/MD5 checksum:   217980 2535726a60b609b1a55fc310328df532
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8_1.8.5-4etch4_hppa.deb
        Size/MD5 checksum:  1677084 d5b606c636b8cd27143ce002d0ed2ce9
      http://security.debian.org/pool/updates/main/r/ruby1.9/libopenssl-ruby1.9_1.9.0+20060609-1etch4_hppa.deb
        Size/MD5 checksum:   333772 38a4c8fef89fde902a0be85e59fe8a8f
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/r/ruby1.8/libgdbm-ruby1.8_1.8.5-4etch4_i386.deb
        Size/MD5 checksum:   197974 e282a6d8268ef83c156a860fb8a16a7c
      http://security.debian.org/pool/updates/main/r/ruby1.9/libreadline-ruby1.9_1.9.0+20060609-1etch4_i386.deb
        Size/MD5 checksum:   216404 82cf3992d705f2e9b88a915e352ca934
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8_1.8.5-4etch4_i386.deb
        Size/MD5 checksum:  1530904 7f21db178c88933c5e077890402de73f
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9_1.9.0+20060609-1etch4_i386.deb
        Size/MD5 checksum:  1752738 3291630941e3dbb88efb8a97f33c208b
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.5-4etch4_i386.deb
        Size/MD5 checksum:   217116 6d9fbeeb9354b35e033f036109c3187c
      http://security.debian.org/pool/updates/main/r/ruby1.9/libdbm-ruby1.9_1.9.0+20060609-1etch4_i386.deb
        Size/MD5 checksum:   216638 513608a225ce87330453e9b1bd910f34
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8-dbg_1.8.5-4etch4_i386.deb
        Size/MD5 checksum:  1001838 64e08e52fac509f2bcdec25fed6fdc07
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8-dev_1.8.5-4etch4_i386.deb
        Size/MD5 checksum:   719438 d568135366f021f1511e186201475268
      http://security.debian.org/pool/updates/main/r/ruby1.8/libdbm-ruby1.8_1.8.5-4etch4_i386.deb
        Size/MD5 checksum:   197348 8fec8e658d39d42c2857475ef279f08d
      http://security.debian.org/pool/updates/main/r/ruby1.8/libopenssl-ruby1.8_1.8.5-4etch4_i386.deb
        Size/MD5 checksum:   290114 69d7bdf1893fe305a003fbcaf264c9e4
      http://security.debian.org/pool/updates/main/r/ruby1.8/libtcltk-ruby1.8_1.8.5-4etch4_i386.deb
        Size/MD5 checksum:  1821730 a79338c8bfea54d6c6e78f85fb0aaa4d
      http://security.debian.org/pool/updates/main/r/ruby1.9/libtcltk-ruby1.9_1.9.0+20060609-1etch4_i386.deb
        Size/MD5 checksum:  1867788 9258d6168a057238d5dd1ead02513e74
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9-dev_1.9.0+20060609-1etch4_i386.deb
        Size/MD5 checksum:   758004 40c77b36b3a2b061db9c16b4a01f4391
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9_1.9.0+20060609-1etch4_i386.deb
        Size/MD5 checksum:   237546 2e1c1a544086d57780f3ae4bb02da9c0
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9-dbg_1.9.0+20060609-1etch4_i386.deb
        Size/MD5 checksum:   345762 cb32b33017f36b17cc06cc8ed90414b9
      http://security.debian.org/pool/updates/main/r/ruby1.9/libopenssl-ruby1.9_1.9.0+20060609-1etch4_i386.deb
        Size/MD5 checksum:   309632 3202e1f7f3c9eb0b6062148b9af7e788
      http://security.debian.org/pool/updates/main/r/ruby1.9/libgdbm-ruby1.9_1.9.0+20060609-1etch4_i386.deb
        Size/MD5 checksum:   215662 1cd102a588e1082716a0858dbc5891d0
      http://security.debian.org/pool/updates/main/r/ruby1.8/libreadline-ruby1.8_1.8.5-4etch4_i386.deb
        Size/MD5 checksum:   197442 c38974894410e79acf7931fc0e8dad54
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/r/ruby1.8/libopenssl-ruby1.8_1.8.5-4etch4_ia64.deb
        Size/MD5 checksum:   330612 0887a43e2d62199cc73660039d7f1919
      http://security.debian.org/pool/updates/main/r/ruby1.9/libopenssl-ruby1.9_1.9.0+20060609-1etch4_ia64.deb
        Size/MD5 checksum:   351174 1bb59b9997961359cb20c9fb6945a0f0
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9-dbg_1.9.0+20060609-1etch4_ia64.deb
        Size/MD5 checksum:   351444 5918b0c479ee79cc7466484c76e6dd98
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9_1.9.0+20060609-1etch4_ia64.deb
        Size/MD5 checksum:  2225792 c780194abaeac68b844bc6fcd411376d
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8-dev_1.8.5-4etch4_ia64.deb
        Size/MD5 checksum:   971834 e280240763deda9e120b41faf64b47e2
      http://security.debian.org/pool/updates/main/r/ruby1.8/libgdbm-ruby1.8_1.8.5-4etch4_ia64.deb
        Size/MD5 checksum:   203432 7430326aeac7519e33b7ca34a77c1779
      http://security.debian.org/pool/updates/main/r/ruby1.9/libreadline-ruby1.9_1.9.0+20060609-1etch4_ia64.deb
        Size/MD5 checksum:   220188 1b368e296ab170d1e005f600cada244f
      http://security.debian.org/pool/updates/main/r/ruby1.9/libtcltk-ruby1.9_1.9.0+20060609-1etch4_ia64.deb
        Size/MD5 checksum:  1864142 76176efd4132f6dd862946935368e2d6
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.5-4etch4_ia64.deb
        Size/MD5 checksum:   218646 4c1088b7f7002d3223ca0a33e27eaa0e
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9-dev_1.9.0+20060609-1etch4_ia64.deb
        Size/MD5 checksum:  1095818 64f6c9fd95b4c6af5cdfade1b958e9c8
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9_1.9.0+20060609-1etch4_ia64.deb
        Size/MD5 checksum:   236376 d8ffa9e36d27c315bf12543035067d4b
      http://security.debian.org/pool/updates/main/r/ruby1.9/libgdbm-ruby1.9_1.9.0+20060609-1etch4_ia64.deb
        Size/MD5 checksum:   220668 62f25d6880a721afac92d5fbd08ee714
      http://security.debian.org/pool/updates/main/r/ruby1.8/libdbm-ruby1.8_1.8.5-4etch4_ia64.deb
        Size/MD5 checksum:   202476 a5d3f5c7b7c963ecd5ab916315deb460
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8-dbg_1.8.5-4etch4_ia64.deb
        Size/MD5 checksum:  1024524 c406606563dae3bf9ad255a4c0c8344f
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8_1.8.5-4etch4_ia64.deb
        Size/MD5 checksum:  1895844 ea86b262fda8dc1dee04a1348abffbca
      http://security.debian.org/pool/updates/main/r/ruby1.8/libreadline-ruby1.8_1.8.5-4etch4_ia64.deb
        Size/MD5 checksum:   201506 22ba7b847e836fd960b0cb53358c106b
      http://security.debian.org/pool/updates/main/r/ruby1.9/libdbm-ruby1.9_1.9.0+20060609-1etch4_ia64.deb
        Size/MD5 checksum:   220662 6f066d4dbe40ba488e1ae2e883dc6262
      http://security.debian.org/pool/updates/main/r/ruby1.8/libtcltk-ruby1.8_1.8.5-4etch4_ia64.deb
        Size/MD5 checksum:  1861880 e3b9fcda55d44a6b921140fc49cdbecc
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/r/ruby1.9/libgdbm-ruby1.9_1.9.0+20060609-1etch4_mips.deb
        Size/MD5 checksum:   215262 4d2fe03f92af44b8362661b562b21754
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8-dbg_1.8.5-4etch4_mips.deb
        Size/MD5 checksum:  1084552 2d2dac8ed50123fdb90d733e9cf9b855
      http://security.debian.org/pool/updates/main/r/ruby1.9/libtcltk-ruby1.9_1.9.0+20060609-1etch4_mips.deb
        Size/MD5 checksum:  1862110 3b49c520a4ce20c6d6fcc11319a182e1
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9_1.9.0+20060609-1etch4_mips.deb
        Size/MD5 checksum:  1680280 bf7a624e97e372c4bbfc2fe769ff8974
      http://security.debian.org/pool/updates/main/r/ruby1.8/libreadline-ruby1.8_1.8.5-4etch4_mips.deb
        Size/MD5 checksum:   197456 8c980f163be8105285609fdd454e1977
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9_1.9.0+20060609-1etch4_mips.deb
        Size/MD5 checksum:   236198 81b996367fc453a8ceb3a531501253de
      http://security.debian.org/pool/updates/main/r/ruby1.9/libopenssl-ruby1.9_1.9.0+20060609-1etch4_mips.deb
        Size/MD5 checksum:   301628 bb1dc6aa3461335e4a9b419cd267ee65
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9-dev_1.9.0+20060609-1etch4_mips.deb
        Size/MD5 checksum:   874228 a5cc44dbd1cc80f8eef1a159ab3189f3
      http://security.debian.org/pool/updates/main/r/ruby1.9/libreadline-ruby1.9_1.9.0+20060609-1etch4_mips.deb
        Size/MD5 checksum:   216100 f2360af30afc204b9226bf5cc0863853
      http://security.debian.org/pool/updates/main/r/ruby1.8/libgdbm-ruby1.8_1.8.5-4etch4_mips.deb
        Size/MD5 checksum:   197594 fca3406a3b55cfdc69c8989b072ca031
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8-dev_1.8.5-4etch4_mips.deb
        Size/MD5 checksum:   802420 6699c1bd4709051c910fc0bfe68c9b37
      http://security.debian.org/pool/updates/main/r/ruby1.9/libdbm-ruby1.9_1.9.0+20060609-1etch4_mips.deb
        Size/MD5 checksum:   215980 2d9003c25275e1fd5ee6c53d959344f7
      http://security.debian.org/pool/updates/main/r/ruby1.8/libopenssl-ruby1.8_1.8.5-4etch4_mips.deb
        Size/MD5 checksum:   281536 fe8d5b309e7ab0be35e721e6b3ac97dd
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.5-4etch4_mips.deb
        Size/MD5 checksum:   217990 f096260bda09b34a2c2f8cf018c80ae1
      http://security.debian.org/pool/updates/main/r/ruby1.8/libtcltk-ruby1.8_1.8.5-4etch4_mips.deb
        Size/MD5 checksum:  1850962 60c4d783bcb2d0f852aa38fac3cad1d5
      http://security.debian.org/pool/updates/main/r/ruby1.8/libdbm-ruby1.8_1.8.5-4etch4_mips.deb
        Size/MD5 checksum:   196670 16d12b430464de86499d897c2a28b213
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8_1.8.5-4etch4_mips.deb
        Size/MD5 checksum:  1540332 5b40f3e2137e7753b54b3202a02f2fa9
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9-dbg_1.9.0+20060609-1etch4_mips.deb
        Size/MD5 checksum:   372286 2a9d8fc201caad40ceefb3cbd2a61d12
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.5-4etch4_mipsel.deb
        Size/MD5 checksum:   218178 0298e98b39cbf08fa18d4fe0d617df41
      http://security.debian.org/pool/updates/main/r/ruby1.9/libgdbm-ruby1.9_1.9.0+20060609-1etch4_mipsel.deb
        Size/MD5 checksum:   215442 2c78e52c5e2a619a0d3b436c1a887a53
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8_1.8.5-4etch4_mipsel.deb
        Size/MD5 checksum:  1538434 b88e43e5cec1aacf83a598dab477c3ab
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9_1.9.0+20060609-1etch4_mipsel.deb
        Size/MD5 checksum:  1667992 01b49904e244952345158c4e22006a42
      http://security.debian.org/pool/updates/main/r/ruby1.9/libopenssl-ruby1.9_1.9.0+20060609-1etch4_mipsel.deb
        Size/MD5 checksum:   299462 1e7905d97c9ec5f2dffdd8dd22b48002
      http://security.debian.org/pool/updates/main/r/ruby1.8/libopenssl-ruby1.8_1.8.5-4etch4_mipsel.deb
        Size/MD5 checksum:   279298 5823c4a9baf7975c73eb6d36047dfed4
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8-dbg_1.8.5-4etch4_mipsel.deb
        Size/MD5 checksum:  1059442 dba878a9064478b59f1548cf661041f7
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8-dev_1.8.5-4etch4_mipsel.deb
        Size/MD5 checksum:   793388 f945925d054d92aba8ca6f7e46a685ee
      http://security.debian.org/pool/updates/main/r/ruby1.9/libdbm-ruby1.9_1.9.0+20060609-1etch4_mipsel.deb
        Size/MD5 checksum:   216340 c676c1ea64ad2b41ee571249b99568d9
      http://security.debian.org/pool/updates/main/r/ruby1.8/libreadline-ruby1.8_1.8.5-4etch4_mipsel.deb
        Size/MD5 checksum:   197742 9dfdbf8675ab4a56dfbfdeaa7bb6f733
      http://security.debian.org/pool/updates/main/r/ruby1.9/libreadline-ruby1.9_1.9.0+20060609-1etch4_mipsel.deb
        Size/MD5 checksum:   216192 3ec8e74d7b723d246719dd9227862c8a
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9-dbg_1.9.0+20060609-1etch4_mipsel.deb
        Size/MD5 checksum:   367552 b0a7a4121cca96fc576497e5eeb7d664
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9-dev_1.9.0+20060609-1etch4_mipsel.deb
        Size/MD5 checksum:   858608 9f415ec47bba07a78331e26e35300a5b
      http://security.debian.org/pool/updates/main/r/ruby1.9/libtcltk-ruby1.9_1.9.0+20060609-1etch4_mipsel.deb
        Size/MD5 checksum:  1837532 6face0d7dcc576c00e564c66d5e78d42
      http://security.debian.org/pool/updates/main/r/ruby1.8/libgdbm-ruby1.8_1.8.5-4etch4_mipsel.deb
        Size/MD5 checksum:   198096 80b334507f4cbfc62b2a439e5d6f3f2e
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9_1.9.0+20060609-1etch4_mipsel.deb
        Size/MD5 checksum:   235700 826646ac1e00564ab805d15ac64659bd
      http://security.debian.org/pool/updates/main/r/ruby1.8/libdbm-ruby1.8_1.8.5-4etch4_mipsel.deb
        Size/MD5 checksum:   197150 b5c725b9fe159d6b3ddb9a1d607d5516
      http://security.debian.org/pool/updates/main/r/ruby1.8/libtcltk-ruby1.8_1.8.5-4etch4_mipsel.deb
        Size/MD5 checksum:  1830428 4123d91e58c7e5f0c4a784d5087f929e
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/r/ruby1.9/libreadline-ruby1.9_1.9.0+20060609-1etch4_powerpc.deb
        Size/MD5 checksum:   218314 45b937607b0c710f9651a88e3c77734a
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9_1.9.0+20060609-1etch4_powerpc.deb
        Size/MD5 checksum:  1808952 c905cd43d26918def2c2110b0d0787b8
      http://security.debian.org/pool/updates/main/r/ruby1.9/libtcltk-ruby1.9_1.9.0+20060609-1etch4_powerpc.deb
        Size/MD5 checksum:  1844840 4698433b87fa56b6f7c8cf581f9ad4c0
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9-dev_1.9.0+20060609-1etch4_powerpc.deb
        Size/MD5 checksum:   777146 a01b49460afc4733cff7d1da5c3892ca
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.5-4etch4_powerpc.deb
        Size/MD5 checksum:   219458 02100fb307634e08fd304f830fa73115
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9-dbg_1.9.0+20060609-1etch4_powerpc.deb
        Size/MD5 checksum:   372960 2e69a084e4ecc663d54a885b69cd4d87
      http://security.debian.org/pool/updates/main/r/ruby1.8/libreadline-ruby1.8_1.8.5-4etch4_powerpc.deb
        Size/MD5 checksum:   199768 14727fe59c8a774dc0ce5283bbe3adf4
      http://security.debian.org/pool/updates/main/r/ruby1.9/libdbm-ruby1.9_1.9.0+20060609-1etch4_powerpc.deb
        Size/MD5 checksum:   218562 6ef5bfa416e85714847e7911ad15b7bc
      http://security.debian.org/pool/updates/main/r/ruby1.8/libopenssl-ruby1.8_1.8.5-4etch4_powerpc.deb
        Size/MD5 checksum:   294044 404be1b8ba5d7b1de693949bf7509c50
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9_1.9.0+20060609-1etch4_powerpc.deb
        Size/MD5 checksum:   237306 abd5d03c1a8c5e730fbbb3b7cbfc13a3
      http://security.debian.org/pool/updates/main/r/ruby1.9/libgdbm-ruby1.9_1.9.0+20060609-1etch4_powerpc.deb
        Size/MD5 checksum:   217678 56fc7c04ec11e80b958592b53698f2cb
      http://security.debian.org/pool/updates/main/r/ruby1.9/libopenssl-ruby1.9_1.9.0+20060609-1etch4_powerpc.deb
        Size/MD5 checksum:   312482 489f3cd6e21ef98d9b3d4031313e0ff8
      http://security.debian.org/pool/updates/main/r/ruby1.8/libdbm-ruby1.8_1.8.5-4etch4_powerpc.deb
        Size/MD5 checksum:   199536 1a549205c85f26df75918ee1f5c5a5e6
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8-dbg_1.8.5-4etch4_powerpc.deb
        Size/MD5 checksum:  1107170 e3be222facad68b2ea2c1d743bfe7729
      http://security.debian.org/pool/updates/main/r/ruby1.8/libgdbm-ruby1.8_1.8.5-4etch4_powerpc.deb
        Size/MD5 checksum:   200076 a9030c3b873cf7feca45d7fb18b2c1c5
      http://security.debian.org/pool/updates/main/r/ruby1.8/libtcltk-ruby1.8_1.8.5-4etch4_powerpc.deb
        Size/MD5 checksum:  1837356 f519218b7727c4c0064d87052a32cd57
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8-dev_1.8.5-4etch4_powerpc.deb
        Size/MD5 checksum:   719018 ff1d0ace8eeec5d602e0cc94c3b834ae
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8_1.8.5-4etch4_powerpc.deb
        Size/MD5 checksum:  1592732 37cfd2a2da9ab0c297cd3e3e2d44d9b0
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/r/ruby1.9/libopenssl-ruby1.9_1.9.0+20060609-1etch4_s390.deb
        Size/MD5 checksum:   327762 27db76dd87740f49cf998c08d7ab567c
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9_1.9.0+20060609-1etch4_s390.deb
        Size/MD5 checksum:  1855938 622f315ff7c5c3e488b364102dff54bd
      http://security.debian.org/pool/updates/main/r/ruby1.9/libgdbm-ruby1.9_1.9.0+20060609-1etch4_s390.deb
        Size/MD5 checksum:   217518 c56bb0699f151595c7cea6cc0d002476
      http://security.debian.org/pool/updates/main/r/ruby1.9/libreadline-ruby1.9_1.9.0+20060609-1etch4_s390.deb
        Size/MD5 checksum:   217572 74f4d455673a8cedbbd19f03cd1a68bf
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8-dev_1.8.5-4etch4_s390.deb
        Size/MD5 checksum:   779594 1da6fea9a757a6147bccd1be029efc77
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9-dev_1.9.0+20060609-1etch4_s390.deb
        Size/MD5 checksum:   884422 dd7a11cbdee41fc9efbfeb616236c261
      http://security.debian.org/pool/updates/main/r/ruby1.9/libtcltk-ruby1.9_1.9.0+20060609-1etch4_s390.deb
        Size/MD5 checksum:  1849714 09fcada1e82f4f89b7cff7bb556ac055
      http://security.debian.org/pool/updates/main/r/ruby1.9/ruby1.9_1.9.0+20060609-1etch4_s390.deb
        Size/MD5 checksum:   235540 3431f6c302e74a70f0e31b13ee703c19
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8-dbg_1.8.5-4etch4_s390.deb
        Size/MD5 checksum:  1052398 95816bfd6638c6c6cf7c8c91f8a5a6df
      http://security.debian.org/pool/updates/main/r/ruby1.8/libopenssl-ruby1.8_1.8.5-4etch4_s390.deb
        Size/MD5 checksum:   305308 1123e31b1920e3e7f1ac216eddaaba37
      http://security.debian.org/pool/updates/main/r/ruby1.8/libtcltk-ruby1.8_1.8.5-4etch4_s390.deb
        Size/MD5 checksum:  1838936 4accc47fcb960eaa9b04a6ff450c678b
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.5-4etch4_s390.deb
        Size/MD5 checksum:   218044 d92f877014b653c14260db06cfa0844e
      http://security.debian.org/pool/updates/main/r/ruby1.8/libreadline-ruby1.8_1.8.5-4etch4_s390.deb
        Size/MD5 checksum:   199000 3c6e11cc181a6593505e20279d310a03
      http://security.debian.org/pool/updates/main/r/ruby1.8/libdbm-ruby1.8_1.8.5-4etch4_s390.deb
        Size/MD5 checksum:   198678 9b90584a77a43162a15087943f9596be
      http://security.debian.org/pool/updates/main/r/ruby1.8/libgdbm-ruby1.8_1.8.5-4etch4_s390.deb
        Size/MD5 checksum:   199480 65c1e5b6224a9a5ed5f1afe4053e9e97
      http://security.debian.org/pool/updates/main/r/ruby1.9/libdbm-ruby1.9_1.9.0+20060609-1etch4_s390.deb
        Size/MD5 checksum:   218054 147f93ceaf0c8119ca264957ffc7c51a
      http://security.debian.org/pool/updates/main/r/ruby1.9/libruby1.9-dbg_1.9.0+20060609-1etch4_s390.deb
        Size/MD5 checksum:   371520 61de55d36d7fadd6f885a4021bebc229
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8_1.8.5-4etch4_s390.deb
        Size/MD5 checksum:  1620382 7a7339edea525e5d5bc6f8c794a8c3e7
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/r/ruby1.8/libdbm-ruby1.8_1.8.5-4etch4_sparc.deb
        Size/MD5 checksum:   197218 5ddc1259eef42b0c05439cb8ab731942
      http://security.debian.org/pool/updates/main/r/ruby1.8/libgdbm-ruby1.8_1.8.5-4etch4_sparc.deb
        Size/MD5 checksum:   197994 3ab96c368edc3bce77e73b529c4c5b84
      http://security.debian.org/pool/updates/main/r/ruby1.8/libtcltk-ruby1.8_1.8.5-4etch4_sparc.deb
        Size/MD5 checksum:  1833286 c7f9f992093cacfb766259e889de13ba
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8-dbg_1.8.5-4etch4_sparc.deb
        Size/MD5 checksum:   960816 c43630f6bbb40fb21fffdc0ad516ddfe
      http://security.debian.org/pool/updates/main/r/ruby1.8/libreadline-ruby1.8_1.8.5-4etch4_sparc.deb
        Size/MD5 checksum:   197944 2d534c9e73f36b3b75e01f2f20bfb6c6
      http://security.debian.org/pool/updates/main/r/ruby1.8/libopenssl-ruby1.8_1.8.5-4etch4_sparc.deb
        Size/MD5 checksum:   296102 c192762dbeaf435d11e51448565bc9b1
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8-dev_1.8.5-4etch4_sparc.deb
        Size/MD5 checksum:   741330 59352ae48a97d10d96d23f84f8e3d4d7
      http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8_1.8.5-4etch4_sparc.deb
        Size/MD5 checksum:  1543188 313ab5a0048823ce919bf50a1b3f1de9
      http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.5-4etch4_sparc.deb
        Size/MD5 checksum:   217960 208c79695f22f705f70ecce79efa87b4
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJXor9AAoJEL97/wQC1SS+oOwIAJVvDM8u5mJ/kqi0l2SHkut5
    mrOthgaOi5PIT2vTo+GPil85zLZqYkNxRZDMO0CrNbO6cLk+Mk2DtseXm9oP38JU
    AbjaKkQzl7hUTiCDhHVe3ha45jh5++GOtpoyU7KRCpgjft3guz2U/D/y8KZ+uiMr
    9cZs5GSYWZGW7B8MfwtguJ0jJGMQLUO5UwShFWpXPm38A11eM6hwGgNM5F6BRJbD
    UeCeSKL7NQLxKl43KQW2vHIzFFhNfbmRF9PdP73V/JP8k32e2jLTzVjmy/VuZL+l
    8BWhJRB/+QFyT47dYq13kAK7tiWwcPhkws8AdcoHY4nd86rl6dcaCpzOhmkhCrw=
    =cx0C
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1694-2                  security@debian.org
    http://www.debian.org/security/                           Florian Weimer
    January 06, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : xterm
    Vulnerability  : design flaw
    Problem type   : local (remote)
    Debian-specific: no
    CVE Id(s)      : CVE-2008-2383
    Debian Bug     : 510030
    
    The xterm update in DSA-1694-1 disabled font changing as a precaution.
    However, users reported that they need this feature.  The update in this
    DSA makes font shifting through escape sequences configurable, using a
    new allowFontOps X resource, and unconditionally enables font changing
    through keyboard sequences.
    
    For the stable distribution (etch), this problem has been fixed in
    version 222-1etch4.
    
    For the testing distribution (lenny), this problem has been fixed in
    version 235-2.
    
    For the unstable distribution (sid), this problem has been fixed in
    version 238-2.
    
    We recommend that you upgrade your xterm package.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222.orig.tar.gz
        Size/MD5 checksum:   802986 bb77882a33083632a9c6c9de004a54fb
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4.diff.gz
        Size/MD5 checksum:    62608 acdbe0c106d90113e928b74c0fadd671
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4.dsc
        Size/MD5 checksum:     1123 28cd750577ddd92fe4806385758a4f4a
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_alpha.deb
        Size/MD5 checksum:   438792 83ff3b4478eb19fb1924a492d461da15
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_amd64.deb
        Size/MD5 checksum:   417496 b2a1d139d6dec04ed090a931b7cac542
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_hppa.deb
        Size/MD5 checksum:   423078 4edd0ffec0c3c0f0fb94c17675dc3998
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_i386.deb
        Size/MD5 checksum:   406764 b22526bdba3a5013a7e218c64497efe4
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_ia64.deb
        Size/MD5 checksum:   510656 708c1978c6cb406a39d7506a490df2a3
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_mips.deb
        Size/MD5 checksum:   429132 86547da89a11b4d9ef734a5586f38e90
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_mipsel.deb
        Size/MD5 checksum:   426508 3a875826919674e5833ec9687b922e03
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_powerpc.deb
        Size/MD5 checksum:   410788 51f94ca70632508db0a7e02b52ce7d3e
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_s390.deb
        Size/MD5 checksum:   423080 a73fa4e7aadaa0195772fee4791be0d2
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_sparc.deb
        Size/MD5 checksum:   411298 bc504d1dec3695fb614563c7e8f629bb
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJY0LjAAoJEL97/wQC1SS+PkcIAK7bRDF9Bwx7Habkwxq5VtPl
    U5Q4H2HtWrV3MhPiYQnVZlOlO59Y/BxtBijfsxir91D65FgZxz+7D4t1nQkoQ6Gz
    /+OC1sai84NuDUjyFN07pUJTCAXJ+wYFMuSecmFAe2sc5BYKv93LYIzHeLQdjMol
    OTNPjcssDxXraHQpNLGzwDQZGyzqeNSd+xSv0ke4KwODtWkwoktBffjaL13+sXPo
    pMxltXAsyFi3alNsfOJYgn2BjM87yuDzQO6PpNMSJEgByr27eDTIxEX5Qibxsz8f
    HN7K0VxHINmU0RxCmZ0aGxCdMMYjp2Vdwes/fnfpeZw7u31b5rfnCnHGUt3Fzzs=
    =M0EW
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1696-1                  security@debian.org
    http://www.debian.org/security/                           Steffen Joeris
    January 07, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : icedove
    Vulnerability  : several vulnerabilities
    Problem type   : remote
    Debian-specific: no
    CVE ID         : CVE-2008-0016 CVE-2008-1380 CVE-2008-3835 CVE-2008-4058
    CVE-2008-4059 CVE-2008-4060 CVE-2008-4061 CVE-2008-4062 CVE-2008-4065 CVE-2008-4067
    CVE-2008-4068 CVE-2008-4070 CVE-2008-5012 CVE-2008-5014 CVE-2008-5017 CVE-2008-5018
    CVE-2008-5021 CVE-2008-5022 CVE-2008-5024 CVE-2008-5500 CVE-2008-5503 CVE-2008-5506
    CVE-2008-5507 CVE-2008-5508 CVE-2008-5511 CVE-2008-5512
    
    Several remote vulnerabilities have been discovered in the Icedove
    mail client, an unbranded version of the Thunderbird mail client. The
    Common Vulnerabilities and Exposures project identifies the following
    problems:
    
    CVE-2008-0016
    
       Justin Schuh, Tom Cross and Peter Williams discovered a buffer
       overflow in the parser for UTF-8 URLs, which may lead to the execution
       of arbitrary code. (MFSA 2008-37)
    
    CVE-2008-1380
    
       It was discovered that crashes in the Javascript engine could
       potentially lead to the execution of arbitrary code. (MFSA 2008-20)  
    
    CVE-2008-3835
    
       "moz_bug_r_a4" discovered that the same-origin check in
       nsXMLDocument::OnChannelRedirect() could be bypassed. (MFSA 2008-38)
    
    CVE-2008-4058
    
       "moz_bug_r_a4" discovered a vulnerability which can result in
       Chrome privilege escalation through XPCNativeWrappers. (MFSA 2008-41)
    
    CVE-2008-4059
    
       "moz_bug_r_a4" discovered a vulnerability which can result in
       Chrome privilege escalation through XPCNativeWrappers. (MFSA 2008-41)
    
    CVE-2008-4060
    
       Olli Pettay and "moz_bug_r_a4" discovered a Chrome privilege
       escalation vulnerability in XSLT handling. (MFSA 2008-41)
    
    CVE-2008-4061
    
       Jesse Ruderman discovered a crash in the layout engine, which might
       allow the execution of arbitrary code. (MFSA 2008-42)
    
    CVE-2008-4062
    
       Igor Bukanov, Philip Taylor, Georgi Guninski and Antoine Labour
       discovered crashes in the Javascript engine, which might allow the
       execution of arbitrary code. (MFSA 2008-42)
    
    CVE-2008-4065
    
       Dave Reed discovered that some Unicode byte order marks are
       stripped from Javascript code before execution, which can result in
       code being executed, which were otherwise part of a quoted string.
       (MFSA 2008-43)
    
    CVE-2008-4067
    
       It was discovered that a directory traversal allows attackers to
       read arbitrary files via a certain characters. (MFSA 2008-44)
    
    CVE-2008-4068
    
       It was discovered that a directory traversal allows attackers to
       bypass security restrictions and obtain sensitive information.
       (MFSA 2008-44)
    
    CVE-2008-4070
    
       It was discovered that a buffer overflow could be triggered via a
       long header in a news article, which could lead to arbitrary code
       execution. (MFSA 2008-46)
    
    CVE-2008-4582
    
       Liu Die Yu and Boris Zbarsky discovered an information leak through
       local shortcut files. (MFSA 2008-47 MFSA 2008-59)
    
    CVE-2008-5012
    
       Georgi Guninski, Michal Zalewski and Chris Evan discovered that
       the canvas element could be used to bypass same-origin
       restrictions. (MFSA 2008-48)
    
    CVE-2008-5014
    
       Jesse Ruderman discovered that a programming error in the
       window.__proto__.__proto__ object could lead to arbitrary code
       execution. (MFSA 2008-50)
    
    CVE-2008-5017
    
       It was discovered that crashes in the layout engine could lead to
       arbitrary code execution. (MFSA 2008-52)
    
    CVE-2008-5018
    
       It was discovered that crashes in the Javascript engine could lead to
       arbitrary code execution. (MFSA 2008-52)
    
    CVE-2008-5021
    
       It was discovered that a crash in the nsFrameManager might lead to
       the execution of arbitrary code. (MFSA 2008-55)
    
    CVE-2008-5022
    
       "moz_bug_r_a4" discovered that the same-origin check in
       nsXMLHttpRequest::NotifyEventListeners() could be bypassed.
       (MFSA 2008-56)
    
    CVE-2008-5024
    
       Chris Evans discovered that quote characters were improperly
       escaped in the default namespace of E4X documents. (MFSA 2008-58)
    
    CVE-2008-5500
    
       Jesse Ruderman  discovered that the layout engine is vulnerable to
       DoS attacks that might trigger memory corruption and an integer
       overflow. (MFSA 2008-60)
    
    CVE-2008-5503
    
       Boris Zbarsky discovered that an information disclosure attack could
       be performed via XBL bindings. (MFSA 2008-61)
    
    CVE-2008-5506
    
       Marius Schilder discovered that it is possible to obtain sensible
       data via a XMLHttpRequest. (MFSA 2008-64)
    
    CVE-2008-5507
    
       Chris Evans discovered that it is possible to obtain sensible data
       via a JavaScript URL. (MFSA 2008-65)
    
    CVE-2008-5508
    
       Chip Salzenberg discovered possible phishing attacks via URLs with
       leading whitespaces or control characters. (MFSA 2008-66)
    
    CVE-2008-5511
    
       It was discovered that it is possible to perform cross-site scripting
       attacks via an XBL binding to an "unloaded document." (MFSA 2008-68)
    
    CVE-2008-5512
    
       It was discovered that it is possible to run arbitrary JavaScript
       with chrome privileges via unknown vectors. (MFSA 2008-68)
    
    
    For the stable distribution (etch) these problems have been fixed in
    version 1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1. Packages for
    s390 will be provided later.
    
    For the upcoming stable distribution (lenny) these problems will be
    fixed soon.
    
    For the unstable (sid) distribution these problems have been fixed in
    version 2.0.0.19-1.
    
    We recommend that you upgrade your icedove packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc and sparc.
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/i/icedove/icedove_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1.diff.gz
        Size/MD5 checksum:   632912 934c1af8ef52f687bd76100e038f031e
      http://security.debian.org/pool/updates/main/i/icedove/icedove_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i.orig.tar.gz
        Size/MD5 checksum: 35464904 bc7d4a8ac66249e890cc6b8053e1c403
      http://security.debian.org/pool/updates/main/i/icedove/icedove_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1.dsc
        Size/MD5 checksum:     1352 50f9d989748dcdc3b4fbe3dfe5c511e0
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/i/icedove/mozilla-thunderbird-typeaheadfind_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_all.deb
        Size/MD5 checksum:    30358 bda7c5e419dc5d8a9bce681f985b7b54
      http://security.debian.org/pool/updates/main/i/icedove/mozilla-thunderbird-dev_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_all.deb
        Size/MD5 checksum:    30344 440f59303f23a8b51555ec44536bc610
      http://security.debian.org/pool/updates/main/i/icedove/thunderbird-gnome-support_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_all.deb
        Size/MD5 checksum:    30344 85cca8031c7e802bbe8da34c57f4f49e
      http://security.debian.org/pool/updates/main/i/icedove/mozilla-thunderbird_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_all.deb
        Size/MD5 checksum:    30332 1d7b977f1f636a6119fecbaa5209b123
      http://security.debian.org/pool/updates/main/i/icedove/mozilla-thunderbird-inspector_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_all.deb
        Size/MD5 checksum:    30352 ac038bd3bfa58b2bd8de442a71e6e244
      http://security.debian.org/pool/updates/main/i/icedove/thunderbird-typeaheadfind_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_all.deb
        Size/MD5 checksum:    30352 43ad195fe32dc2fb2e94513fbf91a77c
      http://security.debian.org/pool/updates/main/i/icedove/thunderbird_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_all.deb
        Size/MD5 checksum:    30312 cbe2956ce57f0d8c4c8ff97ab3e2b73e
      http://security.debian.org/pool/updates/main/i/icedove/thunderbird-dbg_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_all.deb
        Size/MD5 checksum:    30324 6a39034c09e4126bb21cdc23c2487939
      http://security.debian.org/pool/updates/main/i/icedove/thunderbird-dev_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_all.deb
        Size/MD5 checksum:    30330 a16f184ecc39515f32fa6083b617641b
      http://security.debian.org/pool/updates/main/i/icedove/thunderbird-inspector_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_all.deb
        Size/MD5 checksum:    30338 242b59c55d9dee9589bb59fbd6658dc6
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dev_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_alpha.deb
        Size/MD5 checksum:  3962856 19a9dc3a453f2ca162e6e5bba2c689b6
      http://security.debian.org/pool/updates/main/i/icedove/icedove_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_alpha.deb
        Size/MD5 checksum: 13483784 7fcca7955d98bb3a15f6ec99d6639771
      http://security.debian.org/pool/updates/main/i/icedove/icedove-inspector_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_alpha.deb
        Size/MD5 checksum:   200634 057601dd1afc618d5f13e42c085f86c5
      http://security.debian.org/pool/updates/main/i/icedove/icedove-gnome-support_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_alpha.deb
        Size/MD5 checksum:    54840 c88c725218fc24b4a0b3190af5ac5a65
      http://security.debian.org/pool/updates/main/i/icedove/icedove-typeaheadfind_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_alpha.deb
        Size/MD5 checksum:    65550 40bedd8656c7957486f18aac306f7d12
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dbg_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_alpha.deb
        Size/MD5 checksum: 52488200 37055190c86d3ac57eec835a839bc419
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/i/icedove/icedove-typeaheadfind_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_amd64.deb
        Size/MD5 checksum:    62776 8d90b71b18c7d4b1d7e810f935d54e8d
      http://security.debian.org/pool/updates/main/i/icedove/icedove-inspector_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_amd64.deb
        Size/MD5 checksum:   197798 3b30dc78666876c8d0bb7b4787fdd8ca
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dev_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_amd64.deb
        Size/MD5 checksum:  3953624 6475fbe0b2b1c80b09028089ba67221d
      http://security.debian.org/pool/updates/main/i/icedove/icedove-gnome-support_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_amd64.deb
        Size/MD5 checksum:    53318 b9ec720b8da400758255f239813c20aa
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dbg_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_amd64.deb
        Size/MD5 checksum: 51569938 8f68e2681ee04a4db5f91ab45b5f86e3
      http://security.debian.org/pool/updates/main/i/icedove/icedove_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_amd64.deb
        Size/MD5 checksum: 12217532 43120cb3e4a16da07e47876b71cf55e3
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dev_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_arm.deb
        Size/MD5 checksum:  3926916 2471690066542ca1e81b565feeed8e70
      http://security.debian.org/pool/updates/main/i/icedove/icedove_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_arm.deb
        Size/MD5 checksum: 10910920 b80811bcd6f906f9464be3164efaddf6
      http://security.debian.org/pool/updates/main/i/icedove/icedove-typeaheadfind_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_arm.deb
        Size/MD5 checksum:    60542 f12328fb2be467a5ab8c664df5f166ec
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dbg_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_arm.deb
        Size/MD5 checksum: 50937432 355819c441f0af0756534c1b1d6befd7
      http://security.debian.org/pool/updates/main/i/icedove/icedove-gnome-support_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_arm.deb
        Size/MD5 checksum:    48438 84bf5cd63df4c78e1f7f7a46459e3163
      http://security.debian.org/pool/updates/main/i/icedove/icedove-inspector_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_arm.deb
        Size/MD5 checksum:   191338 e0866c1938dd6cf6463a6b8c0ccc4789
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dbg_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_hppa.deb
        Size/MD5 checksum: 52398756 9bfa968bcce1f1d84aead2c343d02433
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dev_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_hppa.deb
        Size/MD5 checksum:  3961020 8baebf6bcb9006393313f31a6bb02db0
      http://security.debian.org/pool/updates/main/i/icedove/icedove-inspector_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_hppa.deb
        Size/MD5 checksum:   202134 738c0a03afd26aa91c156d563d0de1cc
      http://security.debian.org/pool/updates/main/i/icedove/icedove-gnome-support_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_hppa.deb
        Size/MD5 checksum:    55074 fc4d7d7e32182f0f1861ae5d06540db2
      http://security.debian.org/pool/updates/main/i/icedove/icedove-typeaheadfind_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_hppa.deb
        Size/MD5 checksum:    67312 b5e4ae6d90452f2232a22161f8bb83da
      http://security.debian.org/pool/updates/main/i/icedove/icedove_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_hppa.deb
        Size/MD5 checksum: 13655932 a02bb8a7403602059fedafe832531844
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/i/icedove/icedove_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_i386.deb
        Size/MD5 checksum: 10950918 c972632df916e3304ae1657a2b301fdc
      http://security.debian.org/pool/updates/main/i/icedove/icedove-inspector_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_i386.deb
        Size/MD5 checksum:   192848 1fcb52f25725a7c106e12f29ef73bbe8
      http://security.debian.org/pool/updates/main/i/icedove/icedove-gnome-support_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_i386.deb
        Size/MD5 checksum:    49112 1d2b378e81e1753d0428e220a24e16cc
      http://security.debian.org/pool/updates/main/i/icedove/icedove-typeaheadfind_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_i386.deb
        Size/MD5 checksum:    59682 3d90785a8070f5a1e5711a0981abf800
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dev_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_i386.deb
        Size/MD5 checksum:  3950506 8bfd66cc1708346cac4cb92b099925ec
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dbg_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_i386.deb
        Size/MD5 checksum: 50850480 dbdbc7041b916f6e59dcac3ece619244
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dbg_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_ia64.deb
        Size/MD5 checksum: 51880702 56164c298160502414409173c1f04e13
      http://security.debian.org/pool/updates/main/i/icedove/icedove-inspector_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_ia64.deb
        Size/MD5 checksum:   206440 13c15460c07d898861196040360a773b
      http://security.debian.org/pool/updates/main/i/icedove/icedove-gnome-support_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_ia64.deb
        Size/MD5 checksum:    61352 6ea0c96ac063352e976c4466f6693445
      http://security.debian.org/pool/updates/main/i/icedove/icedove-typeaheadfind_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_ia64.deb
        Size/MD5 checksum:    75818 82b63c4e7a04d88563ebb026ab5442d7
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dev_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_ia64.deb
        Size/MD5 checksum:  3731302 69346f41cb47056702efc0681657c510
      http://security.debian.org/pool/updates/main/i/icedove/icedove_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_ia64.deb
        Size/MD5 checksum: 16577294 3146e1c829f3d194c388077931a47485
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dbg_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_mips.deb
        Size/MD5 checksum: 53214602 6207f3135c941b7348219ede580b6c92
      http://security.debian.org/pool/updates/main/i/icedove/icedove-inspector_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_mips.deb
        Size/MD5 checksum:   194438 84bef6e50347e0421f667e1148f85a6d
      http://security.debian.org/pool/updates/main/i/icedove/icedove-gnome-support_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_mips.deb
        Size/MD5 checksum:    49608 079ed1d622c23e8ef856e05f31435649
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dev_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_mips.deb
        Size/MD5 checksum:  3951628 f88b22d4ed68158bacbd5c51faf8e563
      http://security.debian.org/pool/updates/main/i/icedove/icedove-typeaheadfind_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_mips.deb
        Size/MD5 checksum:    60046 7afd997c7631d1e458a4c0075ba4cbbe
      http://security.debian.org/pool/updates/main/i/icedove/icedove_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_mips.deb
        Size/MD5 checksum: 11625186 e9166ce3e1de56e78022e70a28bdd0e8
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/i/icedove/icedove-typeaheadfind_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_mipsel.deb
        Size/MD5 checksum:    60396 3baa5cba57929c4401731de9039bb6c7
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dbg_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_mipsel.deb
        Size/MD5 checksum: 51774640 c89a79f9cbf93b583d1afd60ec8fc70d
      http://security.debian.org/pool/updates/main/i/icedove/icedove_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_mipsel.deb
        Size/MD5 checksum: 11373928 e83d17a1d63b8857d49b1efc9d74d586
      http://security.debian.org/pool/updates/main/i/icedove/icedove-gnome-support_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_mipsel.deb
        Size/MD5 checksum:    50710 7d8aa386b329e2d93f7fc85f245261a4
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dev_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_mipsel.deb
        Size/MD5 checksum:  3686850 67e7b75dd18d74fb45b3278cafa88db1
      http://security.debian.org/pool/updates/main/i/icedove/icedove-inspector_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_mipsel.deb
        Size/MD5 checksum:   193734 9522b8f3bf9570de7f99f7b0ae5744e0
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/i/icedove/icedove-inspector_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_powerpc.deb
        Size/MD5 checksum:   194474 aede4ace924b89ae12e6556a8444cc11
      http://security.debian.org/pool/updates/main/i/icedove/icedove-typeaheadfind_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_powerpc.deb
        Size/MD5 checksum:    62158 fef7361f1431e623e45fe8033060ab0d
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dbg_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_powerpc.deb
        Size/MD5 checksum: 53398506 c55370e9adb2b7d7f176ea43eea77f90
      http://security.debian.org/pool/updates/main/i/icedove/icedove_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_powerpc.deb
        Size/MD5 checksum: 11822454 3f7a8180cb276529fa883c702f28840f
      http://security.debian.org/pool/updates/main/i/icedove/icedove-gnome-support_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_powerpc.deb
        Size/MD5 checksum:    51334 ce1f2fb8863a23314f922a7b7fded0a1
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dev_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_powerpc.deb
        Size/MD5 checksum:  3681454 f2597c093b57efdca38a5c9ba9fb6622
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dev_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_sparc.deb
        Size/MD5 checksum:  3676578 3fbc08c0bba5dd0f14bf160018ec7034
      http://security.debian.org/pool/updates/main/i/icedove/icedove-typeaheadfind_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_sparc.deb
        Size/MD5 checksum:    59830 f39bda160f8d21f97bdc46ff37000898
      http://security.debian.org/pool/updates/main/i/icedove/icedove-gnome-support_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_sparc.deb
        Size/MD5 checksum:    49828 9cd015183ad1200e00bb0a6b4a5b544a
      http://security.debian.org/pool/updates/main/i/icedove/icedove-dbg_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_sparc.deb
        Size/MD5 checksum: 50726490 7dae68f748ccc5102320f4850170f946
      http://security.debian.org/pool/updates/main/i/icedove/icedove_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_sparc.deb
        Size/MD5 checksum: 11132208 8f00b97ee223c42904e2af342222b363
      http://security.debian.org/pool/updates/main/i/icedove/icedove-inspector_1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1_sparc.deb
        Size/MD5 checksum:   191926 54388142eaa943f4a31934c0ee111a74
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iEYEARECAAYFAkllHk0ACgkQXm3vHE4uylpc3wCfb1lyGUJ+/N9zFaLJqCZeiH31
    hUMAn3TBJgftWP2rUePL7CJUxJC2smY9
    =SeoM
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1697-1                  security@debian.org
    http://www.debian.org/security/                           Steffen Joeris
    January 07, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : iceape
    Vulnerability  : several vulnerabilities
    Problem type   : remote
    Debian-specific: no
    CVE ID         : CVE-2008-0016 CVE-2008-0304 CVE-2008-2785 CVE-2008-2798 CVE-2008-2799 CVE-2008-2800
    CVE-2008-2801 CVE-2008-2802 CVE-2008-2803 CVE-2008-2805 CVE-2008-2807 CVE-2008-2808 CVE-2008-2809
    CVE-2008-2810 CVE-2008-2811 CVE-2008-2933 CVE-2008-3835 CVE-2008-3836 CVE-2008-3837 CVE-2008-4058
    CVE-2008-4059 CVE-2008-4060 CVE-2008-4061 CVE-2008-4062 CVE-2008-4065 CVE-2008-4067 CVE-2008-4068
    CVE-2008-4069 CVE-2008-4070 CVE-2008-5012 CVE-2008-5013 CVE-2008-5014 CVE-2008-5017 CVE-2008-0017
    CVE-2008-5021 CVE-2008-5022 CVE-2008-5500 CVE-2008-5503 CVE-2008-5506 CVE-2008-5507 CVE-2008-5508
    CVE-2008-5511 CVE-2008-5512
    
    Several remote vulnerabilities have been discovered in Iceape an
    unbranded version of the Seamonkey internet suite. The Common
    Vulnerabilities and Exposures project identifies the following problems:
    
    CVE-2008-0016
    
       Justin Schuh, Tom Cross and Peter Williams discovered a buffer
       overflow in the parser for UTF-8 URLs, which may lead to the
       execution of arbitrary code. (MFSA 2008-37)
    
    CVE-2008-0304
    
        It was discovered that a buffer overflow in MIME decoding can lead
        to the execution of arbitrary code. (MFSA 2008-26)
    
    CVE-2008-2785
    
        It was discovered that missing boundary checks on a reference
        counter for CSS objects can lead to the execution of arbitrary code.
        (MFSA 2008-34)
    
    CVE-2008-2798
    
        Devon Hubbard, Jesse Ruderman and Martijn Wargers discovered
        crashes in the layout engine, which might allow the execution of
        arbitrary code. (MFSA 2008-21)
    
    CVE-2008-2799
    
        Igor Bukanov, Jesse Ruderman and Gary Kwong discovered crashes in
        the Javascript engine, which might allow the execution of arbitrary
        code. (MFSA 2008-21)
    
    CVE-2008-2800
    
        "moz_bug_r_a4" discovered several cross-site scripting vulnerabilities.
        (MFSA 2008-22)
    
    CVE-2008-2801
    
        Collin Jackson and Adam Barth discovered that Javascript code
        could be executed in the context or signed JAR archives. (MFSA 2008-23)
    
    CVE-2008-2802
    
        "moz_bug_r_a4" discovered that XUL documements can escalate
        privileges by accessing the pre-compiled "fastload" file.
        (MFSA 2008-24)
    
    CVE-2008-2803
    
        "moz_bug_r_a4" discovered that missing input sanitising in the
        mozIJSSubScriptLoader.loadSubScript() function could lead to the
        execution of arbitrary code. Iceape itself is not affected, but
        some addons are. (MFSA 2008-25)
    
    CVE-2008-2805
    
        Claudio Santambrogio discovered that missing access validation in
        DOM parsing allows malicious web sites to force the browser to
        upload local files to the server, which could lead to information
        disclosure. (MFSA 2008-27)
    
    CVE-2008-2807
    
        Daniel Glazman discovered that a programming error in the code for
        parsing .properties files could lead to memory content being
        exposed to addons, which could lead to information disclosure.
        (MFSA 2008-29)
    
    CVE-2008-2808
    
        Masahiro Yamada discovered that file URLS in directory listings
        were insufficiently escaped. (MFSA 2008-30)
    
    CVE-2008-2809
    
        John G. Myers, Frank Benkstein and Nils Toedtmann discovered that
        alternate names on self-signed certificates were handled
        insufficiently, which could lead to spoofings of secure connections.
        (MFSA 2008-31)
    
    CVE-2008-2810
    
       It was discovered that URL shortcut files could be used to bypass the
       same-origin restrictions. This issue does not affect current Iceape,
       but might occur with additional extensions installed. (MFSA 2008-32)
    
    CVE-2008-2811
    
        Greg McManus discovered a crash in the block reflow code, which might
        allow the execution of arbitrary code. (MFSA 2008-33)
    
    CVE-2008-2933
    
        Billy Rios discovered that passing an URL containing a pipe symbol
        to Iceape can lead to Chrome privilege escalation. (MFSA 2008-35)
    
    CVE-2008-3835
    
       "moz_bug_r_a4" discovered that the same-origin check in
       nsXMLDocument::OnChannelRedirect() could be bypassed. (MFSA 2008-38)
    
    CVE-2008-3836
    
       "moz_bug_r_a4" discovered that several vulnerabilities in
       feedWriter could lead to Chrome privilege escalation. (MFSA 2008-39)
    
    CVE-2008-3837
    
       Paul Nickerson discovered that an attacker could move windows
       during a mouse click, resulting in unwanted action triggered by
       drag-and-drop. (MFSA 2008-40)
    
    CVE-2008-4058
    
       "moz_bug_r_a4" discovered a vulnerability which can result in
       Chrome privilege escalation through XPCNativeWrappers. (MFSA 2008-41)
    
    CVE-2008-4059
    
       "moz_bug_r_a4" discovered a vulnerability which can result in
       Chrome privilege escalation through XPCNativeWrappers. (MFSA 2008-41)
    
    CVE-2008-4060
    
       Olli Pettay and "moz_bug_r_a4" discovered a Chrome privilege
       escalation vulnerability in XSLT handling. (MFSA 2008-41)
    
    CVE-2008-4061
    
       Jesse Ruderman discovered a crash in the layout engine, which might
       allow the execution of arbitrary code. (MFSA 2008-42)
    
    CVE-2008-4062
    
       Igor Bukanov, Philip Taylor, Georgi Guninski and Antoine Labour
       discovered crashes in the Javascript engine, which might allow the
       execution of arbitrary code. (MFSA 2008-42)
    
    CVE-2008-4065
    
       Dave Reed discovered that some Unicode byte order marks are
       stripped from Javascript code before execution, which can result in
       code being executed, which were otherwise part of a quoted string.
       (MFSA 2008-43)
    
    CVE-2008-4067
    
       Boris Zbarsky discovered that resource: URls allow directory
       traversal when using URL-encoded slashes. (MFSA 2008-44)
    
    CVE-2008-4068
    
       Georgi Guninski discovered that resource: URLs could bypass local
       access restrictions. (MFSA 2008-44)
    
    CVE-2008-4069
    
       Billy Hoffman discovered that the XBM decoder could reveal
       uninitialised memory. (MFSA 2008-45)
    
    CVE-2008-4070
    
       It was discovered that a buffer overflow could be triggered via a
       long header in a news article, which could lead to arbitrary code
       execution. (MFSA 2008-46)
    
    CVE-2008-5012
    
       Georgi Guninski, Michal Zalewski and Chris Evan discovered that
       the canvas element could be used to bypass same-origin
       restrictions. (MFSA 2008-48)
    
    CVE-2008-5013
    
       It was discovered that insufficient checks in the Flash plugin glue
       code could lead to arbitrary code execution. (MFSA 2008-49)
    
    CVE-2008-5014
    
       Jesse Ruderman discovered that a programming error in the
       window.__proto__.__proto__ object could lead to arbitrary code
       execution. (MFSA 2008-50)
    
    CVE-2008-5017
    
       It was discovered that crashes in the layout engine could lead to
       arbitrary code execution. (MFSA 2008-52)
    
    CVE-2008-0017
    
       Justin Schuh discovered that a buffer overflow in http-index-format
       parser could lead to arbitrary code execution. (MFSA 2008-54)
    
    CVE-2008-5021
    
       It was discovered that a crash in the nsFrameManager might lead to
       the execution of arbitrary code. (MFSA 2008-55)
    
    CVE-2008-5022
    
       "moz_bug_r_a4" discovered that the same-origin check in
       nsXMLHttpRequest::NotifyEventListeners() could be bypassed.
       (MFSA 2008-56)
    
    CVE-2008-5024
    
       Chris Evans discovered that quote characters were improperly
       escaped in the default namespace of E4X documents. (MFSA 2008-58)
    
    CVE-2008-4582
    
       Liu Die Yu discovered an information leak through local shortcut
       files. (MFSA 2008-59)
    
    CVE-2008-5500
    
       Jesse Ruderman  discovered that the layout engine is vulnerable to
       DoS attacks that might trigger memory corruption and an integer
       overflow. (MFSA 2008-60)
    
    CVE-2008-5503
    
       Boris Zbarsky discovered that an information disclosure attack could
       be performed via XBL bindings. (MFSA 2008-61)
    
    CVE-2008-5506
    
       Marius Schilder discovered that it is possible to obtain sensible
       data via a XMLHttpRequest. (MFSA 2008-64)
    
    CVE-2008-5507
    
       Chris Evans discovered that it is possible to obtain sensible data
       via a JavaScript URL. (MFSA 2008-65)
    
    CVE-2008-5508
    
       Chip Salzenberg discovered possible phishing attacks via URLs with
       leading whitespaces or control characters. (MFSA 2008-66)
    
    CVE-2008-5511
    
       It was discovered that it is possible to perform cross-site scripting
       attacks via an XBL binding to an "unloaded document." (MFSA 2008-68)
    
    CVE-2008-5512
    
       It was discovered that it is possible to run arbitrary JavaScript
       with chrome privileges via unknown vectors. (MFSA 2008-68)
    
    
    For the stable distribution (etch) these problems have been fixed in
    version 1.0.13~pre080614i-0etch1.
    
    For the upcoming stable distribution (lenny) distribution these problems
    will be fixed soon.
    
    For the unstable (sid) distribution these problems have been fixed in
    version 1.1.14-1.
    
    We recommend that you upgrade your iceape packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Stable updates are available for alpha, amd64, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/i/iceape/iceape_1.0.13~pre080614i-0etch1.dsc
        Size/MD5 checksum:     2104 b780c722d772cde416bfbda0e6750e3f
      http://security.debian.org/pool/updates/main/i/iceape/iceape_1.0.13~pre080614i-0etch1.diff.gz
        Size/MD5 checksum:  2033694 fadf6ae5717e05ff353c52b8e90825d0
      http://security.debian.org/pool/updates/main/i/iceape/iceape_1.0.13~pre080614i.orig.tar.gz
        Size/MD5 checksum: 42978498 b5f28ad30d5e15dc67efa370c7f9ee59
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/i/iceape/mozilla-mailnews_1.8+1.0.13~pre080614i-0etch1_all.deb
        Size/MD5 checksum:    29248 3c5939146bfc6801b54a5e0584dca482
      http://security.debian.org/pool/updates/main/i/iceape/mozilla-calendar_1.8+1.0.13~pre080614i-0etch1_all.deb
        Size/MD5 checksum:    29224 8027c7b507f7029d558846ad1e38db99
      http://security.debian.org/pool/updates/main/i/iceape/iceape-chatzilla_1.0.13~pre080614i-0etch1_all.deb
        Size/MD5 checksum:   281076 80fcf72ee4e4392b44e32f052ea70456
      http://security.debian.org/pool/updates/main/i/iceape/mozilla-psm_1.8+1.0.13~pre080614i-0etch1_all.deb
        Size/MD5 checksum:    29232 ffa20451394a1d05f5da58116f133916
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dev_1.0.13~pre080614i-0etch1_all.deb
        Size/MD5 checksum:  3667564 aec7efa1351f2f41289ec6edc5d1da6c
      http://security.debian.org/pool/updates/main/i/iceape/mozilla-browser_1.8+1.0.13~pre080614i-0etch1_all.deb
        Size/MD5 checksum:    30218 3a26ed7bbcdefc06ec0f34256733ad4e
      http://security.debian.org/pool/updates/main/i/iceape/mozilla-dev_1.8+1.0.13~pre080614i-0etch1_all.deb
        Size/MD5 checksum:    29358 b764c962b7bc3a9fc2a2c6c723b3129c
      http://security.debian.org/pool/updates/main/i/iceape/mozilla_1.8+1.0.13~pre080614i-0etch1_all.deb
        Size/MD5 checksum:    29222 dc21b8434b9b72375e8df9fa94a7709d
      http://security.debian.org/pool/updates/main/i/iceape/mozilla-js-debugger_1.8+1.0.13~pre080614i-0etch1_all.deb
        Size/MD5 checksum:    29260 9f827631e7c410da840ca7ae095ebe2d
      http://security.debian.org/pool/updates/main/i/iceape/iceape_1.0.13~pre080614i-0etch1_all.deb
        Size/MD5 checksum:    30676 a508e9e68d99676fd897ecb1095486b7
      http://security.debian.org/pool/updates/main/i/iceape/mozilla-chatzilla_1.8+1.0.13~pre080614i-0etch1_all.deb
        Size/MD5 checksum:    29244 33e0809ea09959c467e1379206e605ab
      http://security.debian.org/pool/updates/main/i/iceape/mozilla-dom-inspector_1.8+1.0.13~pre080614i-0etch1_all.deb
        Size/MD5 checksum:    29264 fc07419a1397db4a1f65f42123864c76
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.13~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum: 60708202 67b1488b6549084cccfe2939ad6da1c0
      http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.13~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:  2282516 c3e6e1ec7cd869c1205a79de1e090d7a
      http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.13~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:    56706 44defee7a96a0a632744acdec128e152
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.13~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:   200546 69a5be2dfec4f6690041bad98e80331e
      http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.13~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum: 12894314 ae3d3ef615ea4e13363a274912e1e99c
      http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.13~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:   629450 96d8b62fdaffdbd48ade90b1e3e4e032
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.13~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:  2094958 d25528c803f38c309c74427d5e0769c1
      http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.13~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum: 11683136 aff467dd69f1272dbcc1be14f0d96295
      http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.13~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:    55488 62268a914d78526df611190dbab5e6ca
      http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.13~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:   612120 45ce3f797e175feff8cbd20526008f7b
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.13~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum: 59742704 2c7625187ee32f93a01b0f822face8f7
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.13~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:   197202 50ea3e1f957a8c6ca761f651f25cba39
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.13~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:    56794 383de80565c8737055cbb7f854bfda21
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.13~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:   200226 f22a4d3ab31ce54792c41166669ecc66
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.13~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum: 60588594 5ddfcb5e1feca41bef601a181ab7c86c
      http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.13~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum: 13002074 0ba6c8340786bcd476e450fd9c227444
      http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.13~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:  2352360 74c84da1042f6509e7061f64779d37a6
      http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.13~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:   621258 e017d448d1cbdf589c4cbc1381187ff2
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.13~pre080614i-0etch1_i386.deb
        Size/MD5 checksum: 10493838 6ae4594756d565e0e8cbd5df76011736
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.13~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:   192010 9cc79d018eedc49931af793d1828bd95
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.13~pre080614i-0etch1_i386.deb
        Size/MD5 checksum: 58802216 6469dd02ef7db7da6e5ab347e6ce7d60
      http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.13~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:  1894534 519c11b7d16a9b18f2210808ae1d0d92
      http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.13~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:    50552 dd9e3a6356e265592d5eea54c4e44c21
      http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.13~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:   591248 2e54c039929b804d0d7d1fd5df38171a
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.13~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:   664100 38ab3addca82ff3cd814265777814a89
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.13~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:   206798 41237d984441d52d39fedc62d58514cf
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.13~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum: 59993870 48724db6f24e5b198ccd296ab5eae79d
      http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.13~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum: 15810684 ab38e3d118ee39b7f77bd0d6920f5f62
      http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.13~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:  2819586 5b71efd5233db1081bc5c71bed2c19e5
      http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.13~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:    64056 0841d4d6a5a5958a3ea3549f2536cbc7
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.13~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:   193922 fa7ef5ff71177f2ddd6842c335ff6b0e
      http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.13~pre080614i-0etch1_mips.deb
        Size/MD5 checksum: 11140164 9188919a54175217153ad1b7900397cd
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.13~pre080614i-0etch1_mips.deb
        Size/MD5 checksum: 61581874 31636d074d991a80a0e7b7d314999fd2
      http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.13~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:   601582 bdee14d2f4f81f6afa2d9b58be1d0c94
      http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.13~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:    52124 2f6b4f92e32bc1f1afb7ee1563faad8f
      http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.13~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:  1958828 84d9804ceea7404e213e883a970810eb
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.13~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum: 10925674 27894883c1de817d54cc4907a382d980
      http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.13~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:   598084 83e4d5bb9ac0d4d8e47ca121e99866ce
      http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.13~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:  1944652 32c2318db8b4bcaa5845b532d72de713
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.13~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:   193434 b3e49574473fe47d0017da5ebe20d7bc
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.13~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum: 59935110 dc8551b52c078a10192b9693a16ffe3b
      http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.13~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:    51936 96f5aca01dcedbd47c0576cbb72c8b6c
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.13~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum: 61714000 86246588c13b8ec2a2c678d2d22fb9c2
      http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.13~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:   598244 a800be58f01cfb5e95e2fad048f1d698
      http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.13~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:  2008442 ba78c3982162ae34e75fec4c5a942a85
      http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.13~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:    51290 70f98cf9e61d4a05282be3b751064c86
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.13~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:   194126 ed1919113692ba5fa791fa488a4f4439
      http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.13~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum: 11325232 77ae05048976e57731e988f141ae5bec
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.13~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:   614074 89cf267528c6f7c35e39935d2ed4040c
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.13~pre080614i-0etch1_s390.deb
        Size/MD5 checksum: 60468932 ef714afc155664d90f19528a9fc3ecc0
      http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.13~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:  2187836 38740bf0c2f5c87205ab9c990ea4177d
      http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.13~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:    56036 9b3deb1020cde420c9abf02fd66efd2f
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.13~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:   199010 115d1e007cf3f8731421eed4cfc6e90a
      http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.13~pre080614i-0etch1_s390.deb
        Size/MD5 checksum: 12300536 2811d12c7dee00fadcd9eb5c58ec8f4f
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.13~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum: 10694130 88813d3246501a19f576e420968f688b
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.13~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:   190218 c47a2036511b7338e757b2e42e035e7c
      http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.13~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:    49148 cec70f901ce76c3710026a2635315af0
      http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.13~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:   590140 ff8c1213e52c2d2bb0bab134db93f840
      http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.13~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:  1904008 6b2327e75595ba38f48139a7fc4776a0
      http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.13~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum: 58609342 8c945ce7ad5f770c780ec63653c8c033
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iEYEARECAAYFAkllIRQACgkQXm3vHE4uylpBjACdFteFcAr5MP75xXIpW78X+mVP
    Kj0AoNrlHNonnWlikx2TuYSgAs3xCnBU
    =Qq6H
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1698-1                  security@debian.org
    http://www.debian.org/security/                          Thijs Kinkhorst
    January 09, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : gforge
    Vulnerability  : insufficient input sanitising
    Problem type   : remote
    Debian-specific: no
    CVE Id(s)      : CVE-2008-2381
    
    It was discovered that GForge, a collaborative development tool,
    insufficiently sanitises some input allowing a remote attacker to
    perform SQL injection.
    
    For the stable distribution (etch), this problem has been fixed in
    version 4.5.14-22etch10.
    
    For the testing (lenny) and unstable distribution (sid), this problem
    has been fixed in version 4.7~rc2-7.
    
    We recommend that you upgrade your gforge package.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14.orig.tar.gz
        Size/MD5 checksum:  2161141 e85f82eff84ee073f80a2a52dd32c8a5
      http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch9.diff.gz
        Size/MD5 checksum:   199329 6414734bde3d1783cf0e2444132d64ff
      http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch10.diff.gz
        Size/MD5 checksum:   199610 73b60a0e768f798d14102b84e44cd9b1
      http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch10.dsc
        Size/MD5 checksum:      952 c2252c54ffade219203d006cdc64f91d
      http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch9.dsc
        Size/MD5 checksum:      950 157db49aeacbdbee525e922defce5f16
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch10_all.deb
        Size/MD5 checksum:    80422 a9b65d4e911add81e36120fbc544f81c
      http://security.debian.org/pool/updates/main/g/gforge/gforge-web-apache_4.5.14-22etch10_all.deb
        Size/MD5 checksum:   705076 633d26be5fa1f2ade140c7da64fa6e6c
      http://security.debian.org/pool/updates/main/g/gforge/gforge-dns-bind9_4.5.14-22etch10_all.deb
        Size/MD5 checksum:   103914 676482196214c4a12639a02521c53a7d
      http://security.debian.org/pool/updates/main/g/gforge/gforge-db-postgresql_4.5.14-22etch9_all.deb
        Size/MD5 checksum:   212550 85b6f53b1e4a4ead87d775f11c77b49a
      http://security.debian.org/pool/updates/main/g/gforge/gforge-web-apache_4.5.14-22etch9_all.deb
        Size/MD5 checksum:   705018 90f3187e48801bb2ec2db79378d2a591
      http://security.debian.org/pool/updates/main/g/gforge/gforge-mta-courier_4.5.14-22etch9_all.deb
        Size/MD5 checksum:    76138 243c034e04e560bda6c36bdc9dc7c507
      http://security.debian.org/pool/updates/main/g/gforge/gforge-db-postgresql_4.5.14-22etch10_all.deb
        Size/MD5 checksum:   212632 096dd8f5c46723d1380f9a167d6bb376
      http://security.debian.org/pool/updates/main/g/gforge/gforge-common_4.5.14-22etch9_all.deb
        Size/MD5 checksum:  1010976 9e60171c74bc627e73e062c30e169d7e
      http://security.debian.org/pool/updates/main/g/gforge/gforge-ftp-proftpd_4.5.14-22etch10_all.deb
        Size/MD5 checksum:    86194 8bb823343c71101fa959b45765b597b6
      http://security.debian.org/pool/updates/main/g/gforge/gforge-shell-postgresql_4.5.14-22etch9_all.deb
        Size/MD5 checksum:    87206 ece177d2a29bad7645fd3814903b2e8b
      http://security.debian.org/pool/updates/main/g/gforge/gforge-mta-postfix_4.5.14-22etch9_all.deb
        Size/MD5 checksum:    88566 6739e7cb336746e32645ed46f940e39f
      http://security.debian.org/pool/updates/main/g/gforge/gforge-common_4.5.14-22etch10_all.deb
        Size/MD5 checksum:  1011010 516e5203afff464172b02ffd5c30a89e
      http://security.debian.org/pool/updates/main/g/gforge/gforge-mta-exim_4.5.14-22etch9_all.deb
        Size/MD5 checksum:    88670 8562b858d5e691eed636c51ac97575fe
      http://security.debian.org/pool/updates/main/g/gforge/gforge-mta-postfix_4.5.14-22etch10_all.deb
        Size/MD5 checksum:    88650 ffb7e94dfcde242e63727afcbb5cf541
      http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch9_all.deb
        Size/MD5 checksum:    80324 a7a10e2bb6da8f71778d39885741d9d6
      http://security.debian.org/pool/updates/main/g/gforge/gforge-mta-exim4_4.5.14-22etch9_all.deb
        Size/MD5 checksum:    89178 4e859efc65d23de82d8254476467a092
      http://security.debian.org/pool/updates/main/g/gforge/gforge-mta-courier_4.5.14-22etch10_all.deb
        Size/MD5 checksum:    76234 7c50c3c5583f68804979efd5adf2992a
      http://security.debian.org/pool/updates/main/g/gforge/gforge-lists-mailman_4.5.14-22etch9_all.deb
        Size/MD5 checksum:    82138 3827dc51c27eeb10707339326e2af17c
      http://security.debian.org/pool/updates/main/g/gforge/gforge-shell-ldap_4.5.14-22etch9_all.deb
        Size/MD5 checksum:    86392 ae8fc096931982372d6926e2633dbbd2
      http://security.debian.org/pool/updates/main/g/gforge/gforge-mta-exim4_4.5.14-22etch10_all.deb
        Size/MD5 checksum:    89260 5508b317689cb6832109c3aed78cb58e
      http://security.debian.org/pool/updates/main/g/gforge/gforge-ldap-openldap_4.5.14-22etch10_all.deb
        Size/MD5 checksum:    95648 33598476706a7884652666ca2ca1af28
      http://security.debian.org/pool/updates/main/g/gforge/gforge-shell-ldap_4.5.14-22etch10_all.deb
        Size/MD5 checksum:    86482 0508b738b4b48b9f0f60f732b1e91d74
      http://security.debian.org/pool/updates/main/g/gforge/gforge-ldap-openldap_4.5.14-22etch9_all.deb
        Size/MD5 checksum:    95592 1743291eb91467798186579f3aaf1d25
      http://security.debian.org/pool/updates/main/g/gforge/gforge-shell-postgresql_4.5.14-22etch10_all.deb
        Size/MD5 checksum:    87286 cda968a4ac1f7b4827fd3494334d31b6
      http://security.debian.org/pool/updates/main/g/gforge/gforge-ftp-proftpd_4.5.14-22etch9_all.deb
        Size/MD5 checksum:    86104 e4ed2bb5eb3dd6571bf98ffbbe8042e6
      http://security.debian.org/pool/updates/main/g/gforge/gforge-lists-mailman_4.5.14-22etch10_all.deb
        Size/MD5 checksum:    82230 e816404997ed010acc59c6662b483317
      http://security.debian.org/pool/updates/main/g/gforge/gforge-dns-bind9_4.5.14-22etch9_all.deb
        Size/MD5 checksum:   103826 abd5c30fc9a5b6f8c5beb50056333688
      http://security.debian.org/pool/updates/main/g/gforge/gforge-mta-exim_4.5.14-22etch10_all.deb
        Size/MD5 checksum:    88752 579a75816591e7c458ad57dbf3c3b32f
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.6 (GNU/Linux)
    
    iQEVAwUBSWcEimz0hbPcukPfAQKprQf9EkpamLQdvesde75HK9xWYD4s7Vskczm8
    056nxgM8MHgE+TEWUIzX1vyFmbeqB9sNELo+EMvDKlaiqp28rwA9HtihQSPqiLsl
    q2d6O9+E2i5XnCytrMCpYqbMB/LgLbRHlqtIHAipz5allC+gWlNT3iJza/o1t4c8
    EdBAlYDURg9cA6KIVBNHbt/ywWMNBjqTPcO19XErGiF2xiFACUBMUnETP97OPW30
    r0GkeQadkHaQm0+FjJ3I+Z1brFth9slv43rSRnhN0fHXuIxdFbRJPCwnUGW1eI61
    sS27hJ8KH0b/ZMKjKtFEkEyPlYyJuIzX/0CY7OgkdR4VUUEZk3BBHg==
    =f8dF
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1699-1                  security@debian.org
    http://www.debian.org/security/                           Florian Weimer
    January 11, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : zaptel
    Vulnerability  : array index error
    Problem type   : local
    Debian-specific: no
    CVE Id(s)      : CVE-2008-5396 CVE-2008-5744
    Debian Bug     : 507459 510583
    
    An array index error in zaptel, a set of drivers for telephony hardware,
    could allow users to crash the system or escalate their privileges by
    overwriting kernel memory (CVE-2008-5396).
    
    For the stable distribution (etch), this problem has been fixed in version
    1.2.11.dfsg-1+etch1.
    
    For the unstable distribution (sid) and the testing distribution
    (lenny), this problem has been fixed in version 1.4.11~dfsg-3.
    
    We recommend that you upgrade your zaptel package.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/z/zaptel/zaptel_1.2.11.dfsg-1+etch1.diff.gz
        Size/MD5 checksum:   112903 deb886bbf7ec5183a8b8f2acdb282aca
      http://security.debian.org/pool/updates/main/z/zaptel/zaptel_1.2.11.dfsg.orig.tar.gz
        Size/MD5 checksum:  1192239 a8b32a69e6c6dd1caf526eef4d0c4487
      http://security.debian.org/pool/updates/main/z/zaptel/zaptel_1.2.11.dfsg-1+etch1.dsc
        Size/MD5 checksum:     1273 a76cdc21eb9bcecf25dcd5815f65fc2d
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/z/zaptel/zaptel-source_1.2.11.dfsg-1+etch1_all.deb
        Size/MD5 checksum:   928098 804dbf80db1756a21d25e78b339d04c6
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone-dev_1.2.11.dfsg-1+etch1_alpha.deb
        Size/MD5 checksum:    28412 da608a05b2dc20dc78ac7869d96ac8d9
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone1_1.2.11.dfsg-1+etch1_alpha.deb
        Size/MD5 checksum:    27152 dc847d4d989985cc64de8cf5ddc9c278
      http://security.debian.org/pool/updates/main/z/zaptel/zaptel_1.2.11.dfsg-1+etch1_alpha.deb
        Size/MD5 checksum:   118832 52a926c91d66dc696ceb1adcde3e8766
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/z/zaptel/zaptel_1.2.11.dfsg-1+etch1_amd64.deb
        Size/MD5 checksum:   112450 b97b640e292ec75039d88a149048bf37
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone1_1.2.11.dfsg-1+etch1_amd64.deb
        Size/MD5 checksum:    26040 4644fc0debb57cb63d0ecd2a065628d2
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone-dev_1.2.11.dfsg-1+etch1_amd64.deb
        Size/MD5 checksum:    26898 a816ba6f8001ce15f21436e55086c0ba
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/z/zaptel/zaptel_1.2.11.dfsg-1+etch1_arm.deb
        Size/MD5 checksum:   111358 1ea716a259d884d2f60587e0c0bff0d5
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone1_1.2.11.dfsg-1+etch1_arm.deb
        Size/MD5 checksum:    26418 53817f46e87cdffc0ff1f7f552f0abcd
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone-dev_1.2.11.dfsg-1+etch1_arm.deb
        Size/MD5 checksum:    26830 2b3cfe526622aef8c8a013ed488a3618
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone-dev_1.2.11.dfsg-1+etch1_i386.deb
        Size/MD5 checksum:    27560 c83b30d1fa4c97736612490b4a3315a5
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone1_1.2.11.dfsg-1+etch1_i386.deb
        Size/MD5 checksum:    26514 9512ab4bcdefd131908e5dcba7544054
      http://security.debian.org/pool/updates/main/z/zaptel/zaptel_1.2.11.dfsg-1+etch1_i386.deb
        Size/MD5 checksum:   109262 0be95fc29308efcbc541d4666caf77c4
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone-dev_1.2.11.dfsg-1+etch1_ia64.deb
        Size/MD5 checksum:    28766 58c733396e6c7306917ae9afba6ad500
      http://security.debian.org/pool/updates/main/z/zaptel/zaptel_1.2.11.dfsg-1+etch1_ia64.deb
        Size/MD5 checksum:   136616 f09671965e51b3a0c6151735b5a470bc
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone1_1.2.11.dfsg-1+etch1_ia64.deb
        Size/MD5 checksum:    28400 8c55b47382faede9b16afd6ecca8f883
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/z/zaptel/zaptel_1.2.11.dfsg-1+etch1_mips.deb
        Size/MD5 checksum:   112786 bb7b9050df100c78fb21227a4bcdd4bb
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone1_1.2.11.dfsg-1+etch1_mips.deb
        Size/MD5 checksum:    26088 550da9590e11841dba8652209fe24e7c
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone-dev_1.2.11.dfsg-1+etch1_mips.deb
        Size/MD5 checksum:    27218 f6ae1b88b22c6dd2ff2376adc739c13c
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone-dev_1.2.11.dfsg-1+etch1_powerpc.deb
        Size/MD5 checksum:    27432 6b94c97d24e9caa31b6f091f1e7aa4fe
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone1_1.2.11.dfsg-1+etch1_powerpc.deb
        Size/MD5 checksum:    28420 f1eae93d4742fe5786465bea8a8599f0
      http://security.debian.org/pool/updates/main/z/zaptel/zaptel_1.2.11.dfsg-1+etch1_powerpc.deb
        Size/MD5 checksum:   113630 09a921631b767f79b652808ca49e6831
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/z/zaptel/zaptel_1.2.11.dfsg-1+etch1_s390.deb
        Size/MD5 checksum:   114156 247c08c3342bcac8a41b6211d69581a9
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone-dev_1.2.11.dfsg-1+etch1_s390.deb
        Size/MD5 checksum:    27532 8fefbe0635e726df678199120adc28c2
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone1_1.2.11.dfsg-1+etch1_s390.deb
        Size/MD5 checksum:    26946 908083d23841896ce931c625ea6f632e
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone1_1.2.11.dfsg-1+etch1_sparc.deb
        Size/MD5 checksum:    26758 306a85a06dad10720e3783e9b3566a4e
      http://security.debian.org/pool/updates/main/z/zaptel/libtonezone-dev_1.2.11.dfsg-1+etch1_sparc.deb
        Size/MD5 checksum:    27776 4f8098832f55f4b13900cf8f684bf68b
      http://security.debian.org/pool/updates/main/z/zaptel/zaptel_1.2.11.dfsg-1+etch1_sparc.deb
        Size/MD5 checksum:   111288 c8e4caf317b017bf3987f34c656c9434
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJad91AAoJEL97/wQC1SS+VQYH/i/zPmpOCQqatn4Bj/F6/Jav
    FNvGH716/FL5lCTAaA+geclZA7oO8TpDKRtXGIuWmjOAF4Gvqy4nmcJohnG561Yu
    Gw9Jk4q/HJKL41whdDRysD9ITN9T7L6Ysdfylwc6JVh+LvW3nq+TUA2jX8V8ghgU
    MK2lA5gExyqnHvpvl63b+APtajfpMIFJgaWKkZ3aLo7adIa/9Y+z0YoyMs9RQCiv
    djTjLORg/uLuXTg6rSrDBZCotA0UKJ3tVNlLHd1vsOvGIrE6abeHOnI2iU0dPPQm
    1wLqM1jsg5WkykTdWSws5HjIojijhB6ih3+BVYW25btHTzB7F585XvR7F22+DTU=
    =SrwA
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1700-1                  security@debian.org
    http://www.debian.org/security/                       Moritz Muehlenhoff
    January 11, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : lasso
    Vulnerability  : incorrect API usage
    Problem type   : local(remote)
    Debian-specific: no
    CVE Id(s)      : CVE-2009-0050
    Debian Bug     : 511262
    
    It was discovered that Lasso, a library for Liberty Alliance and SAML
    protocols performs incorrect validation of the return value of OpenSSL's
    DSA_verify() function.
    
    For the stable distribution (etch), this problem has been fixed in
    version 0.6.5-3+etch1.
    
    For the upcoming stable distribution (lenny) and the unstable
    distribution (sid), this problem has been fixed in version 2.2.1-2.
    
    We recommend that you upgrade your lasso package.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/l/lasso/lasso_0.6.5-3+etch1.diff.gz
        Size/MD5 checksum:     7571 1795008d78e35b8e3a098e5f72fabe68
      http://security.debian.org/pool/updates/main/l/lasso/lasso_0.6.5.orig.tar.gz
        Size/MD5 checksum:  1420093 6263375e5910577258a04882b50d58cd
      http://security.debian.org/pool/updates/main/l/lasso/lasso_0.6.5-3+etch1.dsc
        Size/MD5 checksum:     1149 a2975d5f40cc77b4416189c91b640626
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/l/lasso/python-lasso_0.6.5-3+etch1_alpha.deb
        Size/MD5 checksum:   188988 52db78dd66b6ee7af8e952423a5bae69
      http://security.debian.org/pool/updates/main/l/lasso/liblasso-java_0.6.5-3+etch1_alpha.deb
        Size/MD5 checksum:   202066 25f98352704c905d0ec9e50a876eca5b
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3-dev_0.6.5-3+etch1_alpha.deb
        Size/MD5 checksum:   243412 7f7cc9c581abcb282255437e0347a4a5
      http://security.debian.org/pool/updates/main/l/lasso/php4-lasso_0.6.5-3+etch1_alpha.deb
        Size/MD5 checksum:   199052 7846d19823e3f0f3920e225565612241
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3_0.6.5-3+etch1_alpha.deb
        Size/MD5 checksum:   102330 3162bda7c4114d1077de147f74fedca2
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/l/lasso/liblasso-java_0.6.5-3+etch1_amd64.deb
        Size/MD5 checksum:   190932 9d0ad6de3244a13c21ffd9c9f84c84cb
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3_0.6.5-3+etch1_amd64.deb
        Size/MD5 checksum:    96332 3826a242c6c8d970d16947da4f9ebad8
      http://security.debian.org/pool/updates/main/l/lasso/python-lasso_0.6.5-3+etch1_amd64.deb
        Size/MD5 checksum:   197730 2df1a9f5846da409446cf2fe639fdd18
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3-dev_0.6.5-3+etch1_amd64.deb
        Size/MD5 checksum:   181050 33a215818d3127efe4783f6450a65e38
      http://security.debian.org/pool/updates/main/l/lasso/php4-lasso_0.6.5-3+etch1_amd64.deb
        Size/MD5 checksum:   203192 7bf3acad905bc1d1d3db1dc6a2376fb2
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/l/lasso/python-lasso_0.6.5-3+etch1_arm.deb
        Size/MD5 checksum:   160002 98cd9c31a9c5cc6e2d00af6994df275f
      http://security.debian.org/pool/updates/main/l/lasso/php4-lasso_0.6.5-3+etch1_arm.deb
        Size/MD5 checksum:   170136 ffdf6a636e0976dc2453c3c4cdde6148
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3_0.6.5-3+etch1_arm.deb
        Size/MD5 checksum:    79320 b7e55e0058211a978b081d34200b6dd2
      http://security.debian.org/pool/updates/main/l/lasso/liblasso-java_0.6.5-3+etch1_arm.deb
        Size/MD5 checksum:   171604 20252678b9734a661bb9d1de85bcc19f
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3-dev_0.6.5-3+etch1_arm.deb
        Size/MD5 checksum:   162136 27d611c443da457449aae51e1886d850
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/l/lasso/python-lasso_0.6.5-3+etch1_hppa.deb
        Size/MD5 checksum:   205932 81450e57634addeaf1184fbd22e77e8a
      http://security.debian.org/pool/updates/main/l/lasso/php4-lasso_0.6.5-3+etch1_hppa.deb
        Size/MD5 checksum:   196804 115fb72d48047215dde67725977f4776
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3_0.6.5-3+etch1_hppa.deb
        Size/MD5 checksum:   107412 3531a223c7c38a90ad18c1cdb305f056
      http://security.debian.org/pool/updates/main/l/lasso/liblasso-java_0.6.5-3+etch1_hppa.deb
        Size/MD5 checksum:   194800 e76b5149eb02bab77a2748e56b1fa607
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3-dev_0.6.5-3+etch1_hppa.deb
        Size/MD5 checksum:   190720 16abaafbdf73a532c807f4fc08cb826a
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/l/lasso/python-lasso_0.6.5-3+etch1_i386.deb
        Size/MD5 checksum:   166418 105a00318a2b57dea1c3957c976ba73e
      http://security.debian.org/pool/updates/main/l/lasso/php4-lasso_0.6.5-3+etch1_i386.deb
        Size/MD5 checksum:   184638 b4ba5bb2f5d38d3b60493433425c3a11
      http://security.debian.org/pool/updates/main/l/lasso/liblasso-java_0.6.5-3+etch1_i386.deb
        Size/MD5 checksum:   182136 594c2da1dfaea16e7f52245b5eed87aa
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3_0.6.5-3+etch1_i386.deb
        Size/MD5 checksum:    86676 0926b46ed2e93ddf24693fdf61828521
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3-dev_0.6.5-3+etch1_i386.deb
        Size/MD5 checksum:   161366 68f12ada6b09b127957371f95f77df77
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/l/lasso/liblasso-java_0.6.5-3+etch1_ia64.deb
        Size/MD5 checksum:   192958 32455f398eae4f66e7c0826d82e23081
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3-dev_0.6.5-3+etch1_ia64.deb
        Size/MD5 checksum:   216814 b5a48191d251e59687f8b4baeeba19f7
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3_0.6.5-3+etch1_ia64.deb
        Size/MD5 checksum:   121722 50a3c1e995450eb0a0f8150cf02a88d3
      http://security.debian.org/pool/updates/main/l/lasso/php4-lasso_0.6.5-3+etch1_ia64.deb
        Size/MD5 checksum:   266790 311b79245a32bb66b30dceea1cb6d3da
      http://security.debian.org/pool/updates/main/l/lasso/python-lasso_0.6.5-3+etch1_ia64.deb
        Size/MD5 checksum:   216200 ad8b63cede6787ae731aee94d7edab16
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3_0.6.5-3+etch1_mips.deb
        Size/MD5 checksum:    78310 70edbabaad959ab6a17b676fe0ea03c6
      http://security.debian.org/pool/updates/main/l/lasso/php4-lasso_0.6.5-3+etch1_mips.deb
        Size/MD5 checksum:   141498 2809cae134e9d1854764975184191798
      http://security.debian.org/pool/updates/main/l/lasso/python-lasso_0.6.5-3+etch1_mips.deb
        Size/MD5 checksum:   135898 0c3e46f010c591e99f56eacf57108940
      http://security.debian.org/pool/updates/main/l/lasso/liblasso-java_0.6.5-3+etch1_mips.deb
        Size/MD5 checksum:   174772 4b6269ed3502850709d2e649aec05851
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3-dev_0.6.5-3+etch1_mips.deb
        Size/MD5 checksum:   183986 4e38bdb6f27ec82719a63b2a47a50a22
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3_0.6.5-3+etch1_mipsel.deb
        Size/MD5 checksum:    78006 47ed53cb8c5f3dcd0c60bc6f748629dc
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3-dev_0.6.5-3+etch1_mipsel.deb
        Size/MD5 checksum:   178412 192198be8b38252e0e9c37c84e3f9129
      http://security.debian.org/pool/updates/main/l/lasso/php4-lasso_0.6.5-3+etch1_mipsel.deb
        Size/MD5 checksum:   139602 7d6fba843d9ffbde9c6867e6293b50ef
      http://security.debian.org/pool/updates/main/l/lasso/python-lasso_0.6.5-3+etch1_mipsel.deb
        Size/MD5 checksum:   130842 79d8fdde15e1651da4967c132768ef11
      http://security.debian.org/pool/updates/main/l/lasso/liblasso-java_0.6.5-3+etch1_mipsel.deb
        Size/MD5 checksum:   173854 a4217a9f17adae1ddb4d1e9002fecb43
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/l/lasso/php4-lasso_0.6.5-3+etch1_powerpc.deb
        Size/MD5 checksum:   196058 38b56e6e3ddc7f56567c74ec643fec81
      http://security.debian.org/pool/updates/main/l/lasso/liblasso-java_0.6.5-3+etch1_powerpc.deb
        Size/MD5 checksum:   177630 f528eb20a85f706ab9f3f3758f9414f4
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3_0.6.5-3+etch1_powerpc.deb
        Size/MD5 checksum:    87580 87cc0b0cb0f50f80ac0d6a75d3cbb5a5
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3-dev_0.6.5-3+etch1_powerpc.deb
        Size/MD5 checksum:   157740 aba541317a5ea52fc2a9a17e14e96db7
      http://security.debian.org/pool/updates/main/l/lasso/python-lasso_0.6.5-3+etch1_powerpc.deb
        Size/MD5 checksum:   183172 c179334bd068ed62b5453b88b982eeb5
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/l/lasso/php4-lasso_0.6.5-3+etch1_s390.deb
        Size/MD5 checksum:   162292 891dc34494011b354427ff7797a41e24
      http://security.debian.org/pool/updates/main/l/lasso/liblasso-java_0.6.5-3+etch1_s390.deb
        Size/MD5 checksum:   190198 706bb4e0969bcc6c3b273dc9344c7da4
      http://security.debian.org/pool/updates/main/l/lasso/python-lasso_0.6.5-3+etch1_s390.deb
        Size/MD5 checksum:   161716 711db09fd4150bc1f068f5b5fb1e9dbf
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3_0.6.5-3+etch1_s390.deb
        Size/MD5 checksum:    96562 157be6e89308bfbf1bb53e30e4d0d8da
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3-dev_0.6.5-3+etch1_s390.deb
        Size/MD5 checksum:   175634 706adfdb4bc526064399360616de2007
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/l/lasso/php4-lasso_0.6.5-3+etch1_sparc.deb
        Size/MD5 checksum:   179674 09b871dbcaeaf3108bd6860c2fc81363
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3_0.6.5-3+etch1_sparc.deb
        Size/MD5 checksum:    88132 f2fd28ccab190a99e2398725e4fd8b90
      http://security.debian.org/pool/updates/main/l/lasso/liblasso-java_0.6.5-3+etch1_sparc.deb
        Size/MD5 checksum:   173448 5e1fa2fe243214d922308bf324da7e87
      http://security.debian.org/pool/updates/main/l/lasso/liblasso3-dev_0.6.5-3+etch1_sparc.deb
        Size/MD5 checksum:   170024 4b80b359d3a1150818c50d92eaa37c5b
      http://security.debian.org/pool/updates/main/l/lasso/python-lasso_0.6.5-3+etch1_sparc.deb
        Size/MD5 checksum:   181308 db23cb9d622527c4032d8a98865b828f
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iEYEARECAAYFAklqaMQACgkQXm3vHE4uylo0/wCg55JaJ9uBKz7/6BHVxqFQr6qs
    ggcAn0vx2xkAYwHnCNM0nCjwMW/bCgMW
    =4obR
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1701-1                  security@debian.org
    http://www.debian.org/security/                           Florian Weimer
    January 12, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : openssl, openssl097
    Vulnerability  : interpretation conflict
    Problem type   : remote
    Debian-specific: no
    CVE Id(s)      : CVE-2008-5077
    Debian Bug     : 511196
    
    It was discovered that OpenSSL does not properly verify DSA signatures
    on X.509 certificates due to an API misuse, potentially leading to the
    acceptance of incorrect X.509 certificates as genuine (CVE-2008-5077).
    
    For the stable distribution (etch), this problem has been fixed in
    version 0.9.8c-4etch4 of the openssl package, and version
    0.9.7k-3.1etch2 of the openssl097 package.
    
    For the unstable distribution (sid), this problem has been fixed in
    version 0.9.8g-15.
    
    The testing distribution (lenny) will be fixed soon.
    
    We recommend that you upgrade your OpenSSL packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/o/openssl097/openssl097_0.9.7k-3.1etch2.dsc
        Size/MD5 checksum:     1069 fb69818a28ead5b3026dcafc1f5e92d5
      http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c.orig.tar.gz
        Size/MD5 checksum:  3313857 78454bec556bcb4c45129428a766c886
      http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4.diff.gz
        Size/MD5 checksum:    56230 ad913155fe55d659741976a1be02ee48
      http://security.debian.org/pool/updates/main/o/openssl097/openssl097_0.9.7k.orig.tar.gz
        Size/MD5 checksum:  3292692 be6bba1d67b26eabb48cf1774925416f
      http://security.debian.org/pool/updates/main/o/openssl097/openssl097_0.9.7k-3.1etch2.diff.gz
        Size/MD5 checksum:    34518 845a986c8a5170953c1e88c2d9965176
      http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4.dsc
        Size/MD5 checksum:     1107 fd0b477d237c473e3f1491e8821b155d
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.8c-4etch4_alpha.deb
        Size/MD5 checksum:  2561904 e0499757c84819b0cb4919de45e733c4
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7-dbg_0.9.7k-3.1etch2_alpha.deb
        Size/MD5 checksum:  3822008 a63ea4834f1be21cf7dacd7a60817914
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7_0.9.7k-3.1etch2_alpha.deb
        Size/MD5 checksum:  2209796 1d008a2d9fcb466c0e1393fd6cf1dced
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8-dbg_0.9.8c-4etch4_alpha.deb
        Size/MD5 checksum:  4558410 af0dcd956ae91457c01c5152bea8c775
      http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4_alpha.deb
        Size/MD5 checksum:  1026098 957ee2ef34a7aa24c41903eea6d1db51
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8_0.9.8c-4etch4_alpha.deb
        Size/MD5 checksum:  2621108 d42a2d70f27723a8dc9aab1dfb83ad10
      http://security.debian.org/pool/updates/main/o/openssl/libcrypto0.9.8-udeb_0.9.8c-4etch4_alpha.udeb
        Size/MD5 checksum:   677162 039dd8968e77f09312fc4e502601b6fe
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8_0.9.8c-4etch4_amd64.deb
        Size/MD5 checksum:   891116 0d771317a58430e6ecea1e38e6889ef4
      http://security.debian.org/pool/updates/main/o/openssl/libcrypto0.9.8-udeb_0.9.8c-4etch4_amd64.udeb
        Size/MD5 checksum:   580208 f08c5d2e4649dd9f077b440d3cd35963
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8-dbg_0.9.8c-4etch4_amd64.deb
        Size/MD5 checksum:  1655264 ec946f04aa2fae3a001be8c7ae330839
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7_0.9.7k-3.1etch2_amd64.deb
        Size/MD5 checksum:   753788 e5521b844646e69b1b8f2daa872b83b8
      http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4_amd64.deb
        Size/MD5 checksum:   992378 417077b8de5a56b9dad0667f2ab5b6e2
      http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.8c-4etch4_amd64.deb
        Size/MD5 checksum:  2178820 effca1afcd65d7e418f3cb75dd875b1d
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7-dbg_0.9.7k-3.1etch2_amd64.deb
        Size/MD5 checksum:  1326428 670a34f7c39343a7939ba43c4658821c
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8-dbg_0.9.8c-4etch4_hppa.deb
        Size/MD5 checksum:  1586088 66b4b504f0e67fc74c9a98e1f6e8cbac
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7-dbg_0.9.7k-3.1etch2_hppa.deb
        Size/MD5 checksum:  1274896 2dc2191758d272e05461f574bd50031b
      http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4_hppa.deb
        Size/MD5 checksum:  1030994 cfe12740f5f0492a05646851dc042ba8
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8_0.9.8c-4etch4_hppa.deb
        Size/MD5 checksum:   945354 e001f9834b3a7fbfd69963118afc7922
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7_0.9.7k-3.1etch2_hppa.deb
        Size/MD5 checksum:   793836 489e8472b5b300e2627cd25be399f42f
      http://security.debian.org/pool/updates/main/o/openssl/libcrypto0.9.8-udeb_0.9.8c-4etch4_hppa.udeb
        Size/MD5 checksum:   631120 18fb83375c2b5a6689703c1219ad4f65
      http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.8c-4etch4_hppa.deb
        Size/MD5 checksum:  2248436 0c045e8c6dcc0ee3e89d1808b3818eed
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7_0.9.7k-3.1etch2_i386.deb
        Size/MD5 checksum:  2285788 a1b0456725a0ca95457c74672a235097
      http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4_i386.deb
        Size/MD5 checksum:  1015498 04dd57145bc4d8fbd728bba329e7dc72
      http://security.debian.org/pool/updates/main/o/openssl/libcrypto0.9.8-udeb_0.9.8c-4etch4_i386.udeb
        Size/MD5 checksum:   554698 e30b6a20efd74af8bbd5bfb5e9241113
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8_0.9.8c-4etch4_i386.deb
        Size/MD5 checksum:  2721068 abec8c0872781f622454d14ae4e39bad
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7-dbg_0.9.7k-3.1etch2_i386.deb
        Size/MD5 checksum:  4646314 e0a3f1a4d622f7a6a8886bb1bdf56bbe
      http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.8c-4etch4_i386.deb
        Size/MD5 checksum:  2094162 fe95acfa9d541760bbb0c0ed86982bcb
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8-dbg_0.9.8c-4etch4_i386.deb
        Size/MD5 checksum:  5582804 aa194f9d43a3890d810e81086b4ee473
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7-dbg_0.9.7k-3.1etch2_ia64.deb
        Size/MD5 checksum:  1263564 be2a79505ff0ae08e19c8ceeafdf7a08
      http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.8c-4etch4_ia64.deb
        Size/MD5 checksum:  2593624 3a198fb3a4a51e81340d2a1175766c91
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8-dbg_0.9.8c-4etch4_ia64.deb
        Size/MD5 checksum:  1569658 4dbd1a9c3f4d0fe2b8906a8555e26105
      http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4_ia64.deb
        Size/MD5 checksum:  1071264 45a62ed67f0ad2168cab559b45aa7de6
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8_0.9.8c-4etch4_ia64.deb
        Size/MD5 checksum:  1192358 c28adf2245854e3b368d7f88590fc730
      http://security.debian.org/pool/updates/main/o/openssl/libcrypto0.9.8-udeb_0.9.8c-4etch4_ia64.udeb
        Size/MD5 checksum:   801742 ce515f87f93a6364b22f94c5840a4729
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7_0.9.7k-3.1etch2_ia64.deb
        Size/MD5 checksum:  1010004 4222d05c1eb0ce929c68f7c8cc11ecd3
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8-dbg_0.9.8c-4etch4_mips.deb
        Size/MD5 checksum:  1693440 29a8f61c5cfb619d20235fb91cf9ff3b
      http://security.debian.org/pool/updates/main/o/openssl/libcrypto0.9.8-udeb_0.9.8c-4etch4_mips.udeb
        Size/MD5 checksum:   580128 fc3af402963b6fa4d24b89a4afcd8bc3
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8_0.9.8c-4etch4_mips.deb
        Size/MD5 checksum:   876210 f87b4773e3c70539302f5af3b51800b9
      http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4_mips.deb
        Size/MD5 checksum:   993434 02a232c80759b81c67df2e6e6a2cca26
      http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.8c-4etch4_mips.deb
        Size/MD5 checksum:  2258938 be0d32157248efd6f87f450630ce22ef
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4_mipsel.deb
        Size/MD5 checksum:   992856 85a14404d0cae1d5100721d014d5ee29
      http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.8c-4etch4_mipsel.deb
        Size/MD5 checksum:  2255990 1bd0adee660543138600882fc2e42d81
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8-dbg_0.9.8c-4etch4_mipsel.deb
        Size/MD5 checksum:  1649560 22c06f600378978e094230c172db8ca4
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8_0.9.8c-4etch4_mipsel.deb
        Size/MD5 checksum:   860700 bc11dc6212a74c8ca4bf6d314f929dff
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7_0.9.7k-3.1etch2_mipsel.deb
        Size/MD5 checksum:   718942 4ad8442b8812dfe2fd4fcbe06591c3c2
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7-dbg_0.9.7k-3.1etch2_mipsel.deb
        Size/MD5 checksum:  1317060 1d35b7e67204b5b31ab16c2514c69e02
      http://security.debian.org/pool/updates/main/o/openssl/libcrypto0.9.8-udeb_0.9.8c-4etch4_mipsel.udeb
        Size/MD5 checksum:   566226 1300061de87860cdf5ecfaeb26839c5f
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7_0.9.7k-3.1etch2_powerpc.deb
        Size/MD5 checksum:   743386 7e189844da3112f289ff8f96458b7d6e
      http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4_powerpc.deb
        Size/MD5 checksum:  1002204 24f2f0ec4aa965ff9057f7055322b70e
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8-dbg_0.9.8c-4etch4_powerpc.deb
        Size/MD5 checksum:  1728492 6074f055c8257f19962341a29c0dc1c2
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7-dbg_0.9.7k-3.1etch2_powerpc.deb
        Size/MD5 checksum:  1382114 41b6f5900e7a6361625a7fde3329d389
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8_0.9.8c-4etch4_powerpc.deb
        Size/MD5 checksum:   895634 495901098cb75b870810b6abcb82c187
      http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.8c-4etch4_powerpc.deb
        Size/MD5 checksum:  2210874 5b27bc4f2f2fc1c15957242a383b9921
      http://security.debian.org/pool/updates/main/o/openssl/libcrypto0.9.8-udeb_0.9.8c-4etch4_powerpc.udeb
        Size/MD5 checksum:   585332 5cb7f5d282dd56d2825253006fc4ac29
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7-dbg_0.9.7k-3.1etch2_s390.deb
        Size/MD5 checksum:  1317066 0e843e8f68a84557d8f9306c61609283
      http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.8c-4etch4_s390.deb
        Size/MD5 checksum:  2193894 d3d5eeb042d82e5b383177e08136b3cc
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8_0.9.8c-4etch4_s390.deb
        Size/MD5 checksum:   951570 621f50aae93efdd5c31a94071e93eaa9
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8-dbg_0.9.8c-4etch4_s390.deb
        Size/MD5 checksum:  1633204 4e6a635c45caa90a0f28f58286b5b2bf
      http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4_s390.deb
        Size/MD5 checksum:  1014480 639c707aed6efc331f1c3b6b14322ee0
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7_0.9.7k-3.1etch2_s390.deb
        Size/MD5 checksum:   794236 3bc1224270f26fb7b85eae99b18a1e97
      http://security.debian.org/pool/updates/main/o/openssl/libcrypto0.9.8-udeb_0.9.8c-4etch4_s390.udeb
        Size/MD5 checksum:   643020 41a09437ea5130fe0daed09edd4e6423
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/o/openssl/libcrypto0.9.8-udeb_0.9.8c-4etch4_sparc.udeb
        Size/MD5 checksum:   539054 4807d481d7878ea7032d7aa9747e95e0
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8_0.9.8c-4etch4_sparc.deb
        Size/MD5 checksum:  2124310 91c54b669eae9e38ae65486d5f082c6b
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7-dbg_0.9.7k-3.1etch2_sparc.deb
        Size/MD5 checksum:  3418866 a6805a9c7125b04e0c226b2a90c9d5d2
      http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7_0.9.7k-3.1etch2_sparc.deb
        Size/MD5 checksum:  1801340 af40fbabcf27d1c8a81d18f3e3d4ac4d
      http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.8c-4etch4_sparc.deb
        Size/MD5 checksum:  2113338 c5e7dd09e9c4133e9a06a286ace5b7ed
      http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4_sparc.deb
        Size/MD5 checksum:  1020946 713c98cac975ec8c0c64c96812353f82
      http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8-dbg_0.9.8c-4etch4_sparc.deb
        Size/MD5 checksum:  4089498 b1c0f345c3d51a9dea6dd07a003e6e4e
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJa6HkAAoJEL97/wQC1SS+dUoIAIgbRbI+KFz78+o576VGENxO
    wNUutfUiutwNWzwzZem6flZolGIbSzOl7N89Sf1CQ1/TH3KxSrTTmjIi9T11A1iM
    U85uv7VFaSaLCwKjQli1bfErrFyXLLs3S2WvXDLxRRy1YEdJw45sI49R068wilzy
    XWq2x9bOvJeLSK9IyNorFkt9MI/ZWuFvHY+uQxUTqiF4rd4IU/1hZpMhG0L5KKO5
    Rnz9KkbaRIc4z2wO7fgnTIG0ML5VUSdEWdrosmygkbqKTqfwzInVqpY9sj4R9T/1
    2tsRWeXSU6JEFxDQhyn5VitYu5Cmo1rvzFVg/Ea6Wi0iAzWMD5D0ICKFbOc/I4s=
    =7mYv
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1702-1                  security@debian.org
    http://www.debian.org/security/                           Florian Weimer
    January 12, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : ntp
    Vulnerability  : interpretation conflict
    Problem type   : remote
    Debian-specific: no
    CVE Id(s)      : CVE-2009-0021
    Debian Bug     : 511227
    
    It has been discovered that NTP, an implementation of the Network Time
    Protocol, does not properly check the result of an OpenSSL function
    for verifying cryptographic signatures, which may ultimately lead to
    the acceptance of unauthenticated time information.  (Note that
    cryptographic authentication of time servers is often not enabled in
    the first place.)
    
    For the stable distribution (etch), this problem has been fixed in
    version 4.2.2.p4+dfsg-2etch1.
    
    For the unstable distribution (sid), this problem has been fixed in
    version 4.2.4p4+dfsg-8.
    
    The testing distribution (lenny) will be fixed soon.
    
    We recommend that you upgrade your ntp package.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/n/ntp/ntp_4.2.2.p4+dfsg-2etch1.dsc
        Size/MD5 checksum:      906 e0ae8fa9aad8606ad51a06511159c27d
      http://security.debian.org/pool/updates/main/n/ntp/ntp_4.2.2.p4+dfsg.orig.tar.gz
        Size/MD5 checksum:  2199764 ad746cda2d90dbb9ed06fe164273c5d0
      http://security.debian.org/pool/updates/main/n/ntp/ntp_4.2.2.p4+dfsg-2etch1.diff.gz
        Size/MD5 checksum:   176270 339515bd8d7e653a9fedb2bcad03bb74
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/n/ntp/ntp-doc_4.2.2.p4+dfsg-2etch1_all.deb
        Size/MD5 checksum:   910396 fc7d395c11365e371d58da5ab0d34bba
      http://security.debian.org/pool/updates/main/n/ntp/ntp-simple_4.2.2.p4+dfsg-2etch1_all.deb
        Size/MD5 checksum:    28380 4b4c4955ecd354a4bc884027786c368f
      http://security.debian.org/pool/updates/main/n/ntp/ntp-refclock_4.2.2.p4+dfsg-2etch1_all.deb
        Size/MD5 checksum:    28382 31adec52e5d82d9d3026a41b37dc6936
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/n/ntp/ntpdate_4.2.2.p4+dfsg-2etch1_alpha.deb
        Size/MD5 checksum:    64790 9f577a186d01ad00e9882cd3424d2cac
      http://security.debian.org/pool/updates/main/n/ntp/ntp_4.2.2.p4+dfsg-2etch1_alpha.deb
        Size/MD5 checksum:   407826 3e07d1ea475302dd39019d1bdc982ce7
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/n/ntp/ntpdate_4.2.2.p4+dfsg-2etch1_amd64.deb
        Size/MD5 checksum:    61274 0aedd7774998dfb1641860d66821af35
      http://security.debian.org/pool/updates/main/n/ntp/ntp_4.2.2.p4+dfsg-2etch1_amd64.deb
        Size/MD5 checksum:   359176 a0e6375e933a8e591f34122fdf8b2bb0
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/n/ntp/ntpdate_4.2.2.p4+dfsg-2etch1_hppa.deb
        Size/MD5 checksum:    61736 9230c434db7c6b89c8ca032262653d91
      http://security.debian.org/pool/updates/main/n/ntp/ntp_4.2.2.p4+dfsg-2etch1_hppa.deb
        Size/MD5 checksum:   373162 36909f95cddcfda62096aa9052441189
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/n/ntp/ntp_4.2.2.p4+dfsg-2etch1_i386.deb
        Size/MD5 checksum:   328564 91103db311d21a9da3fa7fbd3c3d076a
      http://security.debian.org/pool/updates/main/n/ntp/ntpdate_4.2.2.p4+dfsg-2etch1_i386.deb
        Size/MD5 checksum:    57832 fc544d64adaac58dde6aef81a18a70fa
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/n/ntp/ntpdate_4.2.2.p4+dfsg-2etch1_ia64.deb
        Size/MD5 checksum:    74470 19e2e2b4124a7ca1a82e43a29b3b99b5
      http://security.debian.org/pool/updates/main/n/ntp/ntp_4.2.2.p4+dfsg-2etch1_ia64.deb
        Size/MD5 checksum:   523072 9b004e17c3541978ee1abdf2e02494bb
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/n/ntp/ntp_4.2.2.p4+dfsg-2etch1_mipsel.deb
        Size/MD5 checksum:   389912 45526855df18c76e2eb826983c3d450f
      http://security.debian.org/pool/updates/main/n/ntp/ntpdate_4.2.2.p4+dfsg-2etch1_mipsel.deb
        Size/MD5 checksum:    63888 5bbabab2a3c5571b3c2fd82a80bb5582
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/n/ntp/ntp_4.2.2.p4+dfsg-2etch1_powerpc.deb
        Size/MD5 checksum:   358632 187ec033929b189b6cd3dcb3f9377fbf
      http://security.debian.org/pool/updates/main/n/ntp/ntpdate_4.2.2.p4+dfsg-2etch1_powerpc.deb
        Size/MD5 checksum:    61452 3e0560060aee1113105db444eddad1be
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/n/ntp/ntpdate_4.2.2.p4+dfsg-2etch1_s390.deb
        Size/MD5 checksum:    60998 2dd5ba10abba0a55e5f22c76b67460fb
      http://security.debian.org/pool/updates/main/n/ntp/ntp_4.2.2.p4+dfsg-2etch1_s390.deb
        Size/MD5 checksum:   349954 adeac4a7f39c3a2e945cfaf76e8159dc
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/n/ntp/ntp_4.2.2.p4+dfsg-2etch1_sparc.deb
        Size/MD5 checksum:   331972 a56d5e21ed84396f7439d7d49a5884ab
      http://security.debian.org/pool/updates/main/n/ntp/ntpdate_4.2.2.p4+dfsg-2etch1_sparc.deb
        Size/MD5 checksum:    58316 78936a99f622964adb9f08f1739f77c9
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJa6iSAAoJEL97/wQC1SS+EtYH/31LUTH27dQlayvZAAuBC5HK
    NVdKUIjUWtU7uWVFipPNyr/eETH4pQ1tklSC1bYsi4poeXLnvjaqYIbAI0PQGNPK
    5B7R4Kb5LgRNJcVz0aCdKeMgtOUO6l1H7A9TELANLg0kX+BZPCKXdRrlHCZmOQuQ
    S7gN0Q+BCxcpdAfgQjzGEDPHLDMIwEazjUDaXDwIX+tU1vr0zr2GFsJDT2aGhlpx
    4XAVhfcC3GBu6/wLR6h5Lcnu3/p30sjT8IRGAC9+q+VFZXyla5lLAqntQSVUWs91
    IXBpmGa65AoU34mAx/AHhVzzcSINp+Dttk9hD02oQKvjcRnU9fFFbF1rZVVPbDc=
    =XPnW
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1703-1                  security@debian.org
    http://www.debian.org/security/                           Florian Weimer
    January 12, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : bind9
    Vulnerability  : interpretation conflict
    Problem type   : remote
    Debian-specific: no
    CVE Id(s)      : CVE-2009-0025
    
    It was discovered that BIND, an implementation of the DNS protocol
    suite, does not properly check the result of an OpenSSL function which
    is used to verify DSA cryptographic signatures.  As a result,
    incorrect DNS resource records in zones protected by DNSSEC could be
    accepted as genuine.
    
    For the stable distribution (etch), this problem has been fixed in
    version 9.3.4-2etch4.
    
    For the unstable distribution (sid) and the testing distribution
    (lenny), this problem will be fixed soon.
    
    We recommend that you upgrade your BIND packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch4.dsc
        Size/MD5 checksum:     1197 aa679c6e3106b422fa8de952556cc98e
      http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch4.diff.gz
        Size/MD5 checksum:   302859 12d089f391d6ac1a60e2a7b7b8c49f42
      http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4.orig.tar.gz
        Size/MD5 checksum:  4043577 198181d47c58a0a9c0265862cd5557b0
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/b/bind9/bind9-doc_9.3.4-2etch4_all.deb
        Size/MD5 checksum:   187564 d3609a90363331288018fcdbba29a047
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch4_alpha.deb
        Size/MD5 checksum:   226154 9adec25147fa3f2c85cef36c75148335
      http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch4_alpha.deb
        Size/MD5 checksum:    96576 8ca632cac9163decf3c3dd24a373cc1b
      http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch4_alpha.deb
        Size/MD5 checksum:   112678 273ba2508722416d3a7090153922c01e
      http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch4_alpha.deb
        Size/MD5 checksum:    98226 eef74b1024e184fcea8a09f3800cf544
      http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch4_alpha.deb
        Size/MD5 checksum:   190164 7eac73aae4fabfcfec8e9ecdcde45ff5
      http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch4_alpha.deb
        Size/MD5 checksum:   322348 a5a5ea6ddbfaab6c8aeaf247d1c95874
      http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch4_alpha.deb
        Size/MD5 checksum:   116594 61d56b68f75ef2693169176efa07512e
      http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch4_alpha.deb
        Size/MD5 checksum:   564948 2827fe2266733bd0439ec8a22f167f25
      http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch4_alpha.deb
        Size/MD5 checksum:   115860 0bb76803abf4d4799c7d2a64cd0af449
      http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch4_alpha.deb
        Size/MD5 checksum:  1407512 95c550a74d02dbe81886f33499e249cc
      http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch4_alpha.deb
        Size/MD5 checksum:   188806 420104ba72fe220ae0e7eff269fc086d
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch4_amd64.deb
        Size/MD5 checksum:   317636 d5841784354f118901f08f48a0e886e8
      http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch4_amd64.deb
        Size/MD5 checksum:    96156 ce4d2168a261c296f6b60dc2c52a0ac0
      http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch4_amd64.deb
        Size/MD5 checksum:   224438 460704b96b0b279f5f54346a02356f18
      http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch4_amd64.deb
        Size/MD5 checksum:   190758 21f6b7f6dca59161cf1ba423b97a013e
      http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch4_amd64.deb
        Size/MD5 checksum:   552562 4cdcf10ca2572737e63c6269e4d7ef6b
      http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch4_amd64.deb
        Size/MD5 checksum:   117040 24dd657bb0b671a48fb1498948fdca41
      http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch4_amd64.deb
        Size/MD5 checksum:   114878 02b9e3b075f638e91b92248e40f46cea
      http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch4_amd64.deb
        Size/MD5 checksum:  1107812 587e9613589665f4ccecac2d1bb7c4e7
      http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch4_amd64.deb
        Size/MD5 checksum:   187666 e359081c8f81d6380655bc563a844803
      http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch4_amd64.deb
        Size/MD5 checksum:    96942 07f2b24d6f2815bb4fcad64a206d21b2
      http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch4_amd64.deb
        Size/MD5 checksum:   111304 f85b9997f97e24dd1c972a6c25d3713f
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch4_arm.deb
        Size/MD5 checksum:    95824 cd0dbfd76dc1a9a7ae66c3d17dd2c076
      http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch4_arm.deb
        Size/MD5 checksum:   187430 4d066c4c8fda96616654f0e5c5f269d4
      http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch4_arm.deb
        Size/MD5 checksum:   532276 f15132b68c23e3a2b7bcbb1d0c7e9e1c
      http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch4_arm.deb
        Size/MD5 checksum:   116148 821abd04e8459db5bd026dce7c5007c8
      http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch4_arm.deb
        Size/MD5 checksum:   112778 b0737de9602f9844b17f8c79c0c7bee9
      http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch4_arm.deb
        Size/MD5 checksum:   107920 93094487c134673000797d03326bcfbb
      http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch4_arm.deb
        Size/MD5 checksum:   183016 668007a69bc0bcb174fb3af007a06a2d
      http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch4_arm.deb
        Size/MD5 checksum:   217782 fe30c568a6f694e31f323c5a7c65a489
      http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch4_arm.deb
        Size/MD5 checksum:   311142 a5ad717d9c53e22fc559e2b846af6761
      http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch4_arm.deb
        Size/MD5 checksum:    95240 bec7ba6d11e71d4a5203ffd8775ce61b
      http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch4_arm.deb
        Size/MD5 checksum:  1074544 a8d33e799364caf2a1a6119ba980fb5c
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch4_hppa.deb
        Size/MD5 checksum:    96486 780b5f6edcb2594c074faaacac84a506
      http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch4_hppa.deb
        Size/MD5 checksum:   217580 f4eb031a7c5a6c4454d84cd784c218aa
      http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch4_hppa.deb
        Size/MD5 checksum:   188274 b8428b8e5c42e5f809d9180196435023
      http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch4_hppa.deb
        Size/MD5 checksum:   115708 144ebf381de71a09bca8bd0dd0899969
      http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch4_hppa.deb
        Size/MD5 checksum:  1258938 60e891b0432a731536a921964a5ba3e7
      http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch4_hppa.deb
        Size/MD5 checksum:   185524 291fd0feff440c39dcdfa77b19fb70dd
      http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch4_hppa.deb
        Size/MD5 checksum:   314068 441b640e2d300524bf352d613833afdf
      http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch4_hppa.deb
        Size/MD5 checksum:   543334 89560b776cd247e6dfbc37b5a8ad541d
      http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch4_hppa.deb
        Size/MD5 checksum:   114236 452ab3e612e68e21df601d3a1f3016bc
      http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch4_hppa.deb
        Size/MD5 checksum:    96668 749a3664788afdf253d40123630c913d
      http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch4_hppa.deb
        Size/MD5 checksum:   113042 c77ab83bf8b702a0f221299f63f84275
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch4_i386.deb
        Size/MD5 checksum:   110234 cb2d13c313d5061d6af864325b9b7d0d
      http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch4_i386.deb
        Size/MD5 checksum:    95040 b8d8c02291c6fa58cfc6405902c39ba0
      http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch4_i386.deb
        Size/MD5 checksum:   206548 05f6acbfc0982ed87a378e35f3ad8be9
      http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch4_i386.deb
        Size/MD5 checksum:   472778 22d8b1ea77e191686c5affab4c869240
      http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch4_i386.deb
        Size/MD5 checksum:   296242 86357a0f5353674fb5b73ddf97d8a242
      http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch4_i386.deb
        Size/MD5 checksum:   170214 163fdc7612a950d7a32b0992af767b23
      http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch4_i386.deb
        Size/MD5 checksum:   995236 a747c1d27a79515936517d301a534e07
      http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch4_i386.deb
        Size/MD5 checksum:   180794 4bc0c43e3454131453454d08d6029de4
      http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch4_i386.deb
        Size/MD5 checksum:    95042 7656f21f85e5489d595a5fc43627199b
      http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch4_i386.deb
        Size/MD5 checksum:   106106 6b5985e30d0536eb56dfd5b31b479b58
      http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch4_i386.deb
        Size/MD5 checksum:   113194 3ae945c6b46bda56b407e81bf285fad6
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch4_ia64.deb
        Size/MD5 checksum:   117816 c06945e1506470a93158549c6e94ec80
      http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch4_ia64.deb
        Size/MD5 checksum:   102474 4cd35b5a1cfb24b1fb156441fae565e9
      http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch4_ia64.deb
        Size/MD5 checksum:  1584324 7e7b49e71bde1abc7fec8a6845b4e376
      http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch4_ia64.deb
        Size/MD5 checksum:   216428 682aa4769f46a7dfb2b2bdaf7ec53dde
      http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch4_ia64.deb
        Size/MD5 checksum:   127650 7206fa330fc8b115a95f8a20073b2683
      http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch4_ia64.deb
        Size/MD5 checksum:   232106 e8a5ae82b88f1288ee91fb6879a38035
      http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch4_ia64.deb
        Size/MD5 checksum:   393396 f6d1ec1bdd9b7d3bf0543c1f72184c5e
      http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch4_ia64.deb
        Size/MD5 checksum:   100022 b080abf8bcf2f7d33944c0f5ab07d5db
      http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch4_ia64.deb
        Size/MD5 checksum:   740278 684ee73762dc6a569e0ad5458cb39a63
      http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch4_ia64.deb
        Size/MD5 checksum:   280944 434b3f2bf7b6eac8c8eadbc9ff71b88a
      http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch4_ia64.deb
        Size/MD5 checksum:   125878 78c533671d65799444a6abeecb066102
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch4_mips.deb
        Size/MD5 checksum:    95048 1a1adcb72a4a988eb862dbfa70a05993
      http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch4_mips.deb
        Size/MD5 checksum:    94272 494f78dca4285c9784f92779d08516a0
      http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch4_mips.deb
        Size/MD5 checksum:   180574 d4bace2add3362896bdb17e794642d80
      http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch4_mips.deb
        Size/MD5 checksum:   211456 a317473e059e7670b6bb603a1fb532b2
      http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch4_mips.deb
        Size/MD5 checksum:   107968 9d86c2744569db8b9110c37be4de8aba
      http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch4_mips.deb
        Size/MD5 checksum:   110378 ab471c9ce1bb5a666413d00253c84c71
      http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch4_mips.deb
        Size/MD5 checksum:   491896 984d83789bb28f65d78130b5ffe58783
      http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch4_mips.deb
        Size/MD5 checksum:  1229560 6bae9ceb7a1a604f3a45c6df905fb2c8
      http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch4_mips.deb
        Size/MD5 checksum:   301540 084df4d5378ecb47eee2715a709005ef
      http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch4_mips.deb
        Size/MD5 checksum:   174080 29e62329993fe21bd2d412b659a3c220
      http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch4_mips.deb
        Size/MD5 checksum:   113348 c697f17d93aa609ef448edf740ca132a
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch4_mipsel.deb
        Size/MD5 checksum:    94150 0177400160d90cc2d662ca3a6688178e
      http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch4_mipsel.deb
        Size/MD5 checksum:   179698 310f99bbfb09db4f5ea5dff07b66bb63
      http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch4_mipsel.deb
        Size/MD5 checksum:   107218 c6b342a831948a7bf7801d46d38290c4
      http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch4_mipsel.deb
        Size/MD5 checksum:   113072 a27b2fe4ed7a345d258313ddc4f8346f
      http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch4_mipsel.deb
        Size/MD5 checksum:   110300 fb55450e28a08d2010b6e93e17b895ae
      http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch4_mipsel.deb
        Size/MD5 checksum:    94980 fb919221192449e70239f8991f01636b
      http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch4_mipsel.deb
        Size/MD5 checksum:   488288 8a089d802fd33105a3699e81480439c9
      http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch4_mipsel.deb
        Size/MD5 checksum:   210968 e5c3f788c66086cf7dcd26215a17a0f8
      http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch4_mipsel.deb
        Size/MD5 checksum:  1205504 260e40c7c015eca2a29612c725d8dd35
      http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch4_mipsel.deb
        Size/MD5 checksum:   174202 765ab3865c5a811dac4ac157e358a318
      http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch4_mipsel.deb
        Size/MD5 checksum:   299586 5f5e170a809055667994b7b76b0745a1
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch4_powerpc.deb
        Size/MD5 checksum:   301350 a20ea0a911818a574701d68e29f3a2d1
      http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch4_powerpc.deb
        Size/MD5 checksum:   183376 c550243d0a3b401d2970a3973f656120
      http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch4_powerpc.deb
        Size/MD5 checksum:    96210 4116f47d69a3f83ce9022b306b1e6826
      http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch4_powerpc.deb
        Size/MD5 checksum:    96250 112e99a3eead25467bbb19895cc1eb3a
      http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch4_powerpc.deb
        Size/MD5 checksum:   173642 27ea1f6607f69941e718884d7b90b626
      http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch4_powerpc.deb
        Size/MD5 checksum:   109316 2158dc4b86fcc4b841776df478bafe2d
      http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch4_powerpc.deb
        Size/MD5 checksum:   206910 0f1968d555573c2fd230ffb92109e729
      http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch4_powerpc.deb
        Size/MD5 checksum:   488474 8fc4aa4a58958441f5cda10c83a24e05
      http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch4_powerpc.deb
        Size/MD5 checksum:  1167916 45c319145305d976c147af786f10f65a
      http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch4_powerpc.deb
        Size/MD5 checksum:   113906 a908806289ae42f4947557f82952d1c6
      http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch4_powerpc.deb
        Size/MD5 checksum:   112320 3bf75de9190d5c0012510fffacd4d980
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch4_s390.deb
        Size/MD5 checksum:   114300 d5ab339f6f1505b6efe1caab0f91b4b0
      http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch4_s390.deb
        Size/MD5 checksum:    95710 23cc9069086681ec048ab64d04150b78
      http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch4_s390.deb
        Size/MD5 checksum:   196642 a135997ee33f30d6a9656563cf398ce1
      http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch4_s390.deb
        Size/MD5 checksum:   331958 3c560c643e1a60548ef5c4f567b3bbf6
      http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch4_s390.deb
        Size/MD5 checksum:   194782 bd4744eff4c131183da5c32fa9197b81
      http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch4_s390.deb
        Size/MD5 checksum:   118206 ddd094acc29a60f0ad39deb9ffcc3b53
      http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch4_s390.deb
        Size/MD5 checksum:   579538 6b6bb21b3ba7fcc3d0a96fb29e32b24e
      http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch4_s390.deb
        Size/MD5 checksum:  1137454 2b639e2c0c5e2bed36db838611141876
      http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch4_s390.deb
        Size/MD5 checksum:   116708 bab63e3ca69977baa87b07181ca5d1a4
      http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch4_s390.deb
        Size/MD5 checksum:    97832 5e3591957078a61702b71fdb2e24fdfc
      http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch4_s390.deb
        Size/MD5 checksum:   234026 dcf706e32b50ab97068af14126bb65bd
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch4_sparc.deb
        Size/MD5 checksum:   183878 eee08db142d1871d4b692dbbcd15999a
      http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch4_sparc.deb
        Size/MD5 checksum:   111224 261734b90a58046ad8ccd7ecf45629c3
      http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch4_sparc.deb
        Size/MD5 checksum:   114294 b9d3bc689a758181f7a6068db8970fe5
      http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch4_sparc.deb
        Size/MD5 checksum:  1122546 27f759bbc75c0da9c82cb26769d122c2
      http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch4_sparc.deb
        Size/MD5 checksum:   175962 9a2373e0bb287efc7eb53697b91de147
      http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch4_sparc.deb
        Size/MD5 checksum:   107672 348e2faed12a7a66d00c3d3eed509605
      http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch4_sparc.deb
        Size/MD5 checksum:   210612 0f479f72667f152c97491331fd3a7ed8
      http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch4_sparc.deb
        Size/MD5 checksum:   494486 69c393bf175654857ec2151d4ee47a4e
      http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch4_sparc.deb
        Size/MD5 checksum:    95434 34974e2951421e842ea394dbba268bb2
      http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch4_sparc.deb
        Size/MD5 checksum:    95384 429ec6ce3ab7f33b25e008277b542a03
      http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch4_sparc.deb
        Size/MD5 checksum:   300876 a0a9ae53e63e2dbb54b6db43dfbb1c72
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJa7VHAAoJEL97/wQC1SS+y50H/A5YPrLJyzVFbWrBoGtQlsYy
    4XigQsKK16mPXuBkjlonghHbgCgHbjoeuBh6FRWB6WJ32N+jvBid0c84sJ3m8J2+
    7lr4d7tIrhWsMHlhcC1w/l9FUbl03By4OjTlXimbIxZa41gxCmckYU5Xppb4Ywhc
    rc8THcuncUI5USuFtgt0JXczligi4uOpYD4aAEVGPGJXXCheKOOmAusi1lKqdM8Q
    PC+v+Xu2Et3iE0zNTMPBpf0g1JuOYBo80iJtA0t/AsIe76ptX088BUhe8PvGILZt
    wF+na1j7rg2lBfQgOwst3VnGncNNrCEITEEy/u2JmizRGwHk0usS+j5Q6Rk3mj0=
    =5Um+
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1704                    security@debian.org
    http://www.debian.org/security/                           Steffen Joeris
    January 14, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : xulrunner
    Vulnerability  : several vulnerabilities
    Problem type   : remote
    Debian-specific: no
    CVE ID         : CVE-2008-5500 CVE-2008-5503 CVE-2008-5506 CVE-2008-5507 CVE-2008-5508 CVE-2008-5511 CVE-2008-5512
    
    Several remote vulnerabilities have been discovered in Xulrunner, a
    runtime environment for XUL applications. The Common Vulnerabilities and
    Exposures project identifies the following problems:
    
    CVE-2008-5500
    
       Jesse Ruderman  discovered that the layout engine is vulnerable to
       DoS attacks that might trigger memory corruption and an integer
       overflow. (MFSA 2008-60)
    
    CVE-2008-5503
    
       Boris Zbarsky discovered that an information disclosure attack could
       be performed via XBL bindings. (MFSA 2008-61)
    
    CVE-2008-5506
    
       Marius Schilder discovered that it is possible to obtain sensible
       data via a XMLHttpRequest. (MFSA 2008-64)
    
    CVE-2008-5507
    
       Chris Evans discovered that it is possible to obtain sensible data
       via a JavaScript URL. (MFSA 2008-65)
    
    CVE-2008-5508
    
       Chip Salzenberg discovered possible phishing attacks via URLs with
       leading whitespaces or control characters. (MFSA 2008-66)
    
    CVE-2008-5511
    
       It was discovered that it is possible to perform cross-site scripting
       attacks via an XBL binding to an "unloaded document." (MFSA 2008-68)
    
    CVE-2008-5512
    
       It was discovered that it is possible to run arbitrary JavaScript
       with chrome privileges via unknown vectors. (MFSA 2008-68)
    
    For the stable distribution (etch) these problems have been fixed in
    version 1.8.0.15~pre080614i-0etch1.
    
    For the testing distribution (lenny) and the unstable distribution (sid)
    these problems have been fixed in version 1.9.0.5-1.
    
    We recommend that you upgrade your xulrunner packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614i-0etch1.diff.gz
        Size/MD5 checksum:      971 73ec26e81ce6e401845eb070aa26d909
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614i-0etch1.dsc
        Size/MD5 checksum:     1981 87dd485ac774e78373be5a196cbc8320
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614i.orig.tar.gz
        Size/MD5 checksum: 43320191 82b3061f947787bf267a36513a6bd2dd
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-dev_1.8.0.15~pre080614i-0etch1_all.deb
        Size/MD5 checksum:   231436 f692e056f6eccb9633771a1b5d56d115
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul-common_1.8.0.15~pre080614i-0etch1_all.deb
        Size/MD5 checksum:  1052120 9935f278d06c5256a1cb6d34f6b43777
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.8.0.15~pre080614i-0etch1_all.deb
        Size/MD5 checksum:   176532 03d96486a1cb92ca65b39376add42232
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul-dev_1.8.0.15~pre080614i-0etch1_all.deb
        Size/MD5 checksum:  2638014 f4c9fed2489696b18ecedf945729ffa7
      http://security.debian.org/pool/updates/main/x/xulrunner/libsmjs1_1.8.0.15~pre080614i-0etch1_all.deb
        Size/MD5 checksum:    37402 033e412379eab51f4608530af659596a
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozillainterfaces-java_1.8.0.15~pre080614i-0etch1_all.deb
        Size/MD5 checksum:  1032570 b8277c4699e9f2edc9131c525c72ac2a
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-dev_1.8.0.15~pre080614i-0etch1_all.deb
        Size/MD5 checksum:   208008 d6685b7c5a83eb2fc383ad2284e0c300
      http://security.debian.org/pool/updates/main/x/xulrunner/libsmjs-dev_1.8.0.15~pre080614i-0etch1_all.deb
        Size/MD5 checksum:    37436 a668ef6417fe2f868964b2e1f1cd9028
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum: 46039574 068112b86f727680427633606c026ee8
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:   905956 ab2dae7df915ed9df912a45332feda25
      http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:    53462 1211c97fa83041bfdd3d89c5d0cbe49c
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:   739356 038af743b90f988367f7cae810adca30
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:   302966 7cf37ed3bd131afd5d77ac4b6a4a0e80
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:   293396 ebda2282ee4f81e8e972254522ab98ee
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:    71512 167d644c17e1fbeb7db1b586e1416516
      http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:   130252 738d7bacc1f2037e6fd34e094382a414
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:  7348590 9b48fd7155a90c0d4b42a60b3ca87e21
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:   162918 b4fb7360352ff7e3d3f4a1e4692f0399
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:   386930 4b9a91448ef45dc0512a11197b568653
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:  3189364 8375722343ed726036dafe752298217b
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614i-0etch1_alpha.deb
        Size/MD5 checksum:   765528 e30aa7d614c04ed6ba755184d53b0f83
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:   149212 19ab1c22cd55db2bc8ee33be7fff759b
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:   810610 5493e297887f037ed4cdd9c2150e68ed
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:    69626 4825855bdb9b5a8bb2c62436fde8ad7c
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:  6345322 f975d16444059b3b9ae1b43c1a9c0cda
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:   756112 af22a3727a03e9bda037a329ee21df65
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:   305094 4855bb5ffe73a231bb2a0d701616e7eb
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:   279116 b7f981650c4b20db874b70a2bd6bc059
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:   356260 dbec2df715586df57acd7228a3175ef9
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum: 45243162 2aba2e701aac5639822ce0e6ed911948
      http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:    53664 5d946fe8bf84c2e5514f0114ce77ac71
      http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:   126976 76ebe8f1cc4eb9a881fdea16732c2674
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:   671242 269e0391c1bffea6f26c283457fdb5a3
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614i-0etch1_amd64.deb
        Size/MD5 checksum:  3180000 ba7dcb523f47170cf40f8d07f078ff38
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614i-0etch1_arm.deb
        Size/MD5 checksum: 44767070 ff1a7f0d6d410e514b4fec797c978577
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614i-0etch1_arm.deb
        Size/MD5 checksum:   732710 a077246fbfa402b28df5b7c94ca64f03
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614i-0etch1_arm.deb
        Size/MD5 checksum:   326560 97d77b72fb59380c6dd65f2464b17748
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614i-0etch1_arm.deb
        Size/MD5 checksum:   260802 b517d6273306a6b2620717924d451c1e
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614i-0etch1_arm.deb
        Size/MD5 checksum:    63374 14f5f6627a23585127b48559da6e0b3e
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614i-0etch1_arm.deb
        Size/MD5 checksum:   291166 727015b23b21585ad8bc15fa0c3c01c4
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614i-0etch1_arm.deb
        Size/MD5 checksum:   594490 b3eb4a04bdc1d00d6d735c651de116f9
      http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614i-0etch1_arm.deb
        Size/MD5 checksum:    51382 5cbc748af5b9198cb129ce1fafd7a8d0
      http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614i-0etch1_arm.deb
        Size/MD5 checksum:   119438 6f3288cc981b5e5799bacf6befa8ce7c
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614i-0etch1_arm.deb
        Size/MD5 checksum:   137188 8f3727780153f49902d4dd440f7a48ff
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614i-0etch1_arm.deb
        Size/MD5 checksum:   705428 18ee2b57007cf41e8bc2888757c247c9
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614i-0etch1_arm.deb
        Size/MD5 checksum:  5371364 d6ad1248c0949aaf3430662fbf367ded
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614i-0etch1_arm.deb
        Size/MD5 checksum:  2970288 4b6793a379f21fc5eb06b98bd349a3e2
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum: 46155188 c37a7bf2fe01cb20fbe83b23c22c76c4
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:   161944 c7498923bbb2ac0917b89f5e1bc1335d
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:   302552 64dfa94053b2f5ebeca61307c7c687cf
      http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:   132346 77b099b16d12baab295fbbb44b8e4705
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:   391234 9b574c8782603f7f12caa0c622b79c57
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:  7553990 1ae462d397b8c4de85ed9bb44398fa68
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:   288610 2ee1dd5d5f8b1f2dc2f31f1b47ee0401
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:    71188 f22b185182ded01cad34df565e33fa34
      http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:    53706 4ecb4b3c07ace717767c0ac6ab631816
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:   875004 3841afcdff3a1cf37041560718db619f
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:  3105180 5d9c78af9a11d310200260b1862e1b77
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:   753304 421db187ed2aaa135d7c6d1d72475cc1
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614i-0etch1_hppa.deb
        Size/MD5 checksum:   704006 10305d20ffbd30ee9a8304b281ed410f
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614i-0etch1_i386.deb
        Size/MD5 checksum: 44716280 14630037caf61026b23b89cd2d7ee906
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:  3033738 a8d8501331ee08577ddc4c6ac79f8c82
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:   337330 52fc267a0badecc2f6ee63fdefbb6b27
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:  5385268 656b0080011c0922718459ae8d57a65f
      http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:   118962 f4dcddae42b65530be240a88a1fb0dce
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:   268382 2a9f3e60120236105c636de6eeec6b16
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:   140106 77d0dc883aca560cddda828961d8eb69
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:    64110 1acc5d5b8309b9ddecb5ee1e5565083b
      http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:    51204 6be1abbf15a3a7bef4972047be976c5d
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:   743240 e9497985c4d89ae570b7a32347002733
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:   715094 2eb3ec027c357d16e522ddfba8a677c6
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:   296684 2c92c0cfc031d09f2b064e9195f6832b
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614i-0etch1_i386.deb
        Size/MD5 checksum:   628686 962d21ec6b9ecf88bec3a6e65fc51d5c
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:   287808 d87e43a55b54420373bf40db42e91152
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:   937358 91e2ec2a7b2c406b96a9c912e9e8ca36
      http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:    58184 71a0cd0e35e1743698a3a246f20f4d0a
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:   533280 985c52b70f2dc075da26cea1a97df109
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:  1121834 19c744b9995ccdd855212e4ad6eb07ad
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:   756020 a7cbe4174c6a39f3b8e1365193ed80ef
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:  9685590 763fa7e7d9cf7ad6cc95b2b924a894ce
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:   199030 bab7b1f432fc24acc1ff56857ee18a0f
      http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:   151088 560b8d6be4b0ad31fcc2159ac3d72649
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:   334942 81225ca738fb8f78974f321af108d866
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:  3052352 ab57bb5032c35aa66bdf47e777e72b37
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum: 45460812 9c2a67cf26debcdea09421c2e330b120
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614i-0etch1_ia64.deb
        Size/MD5 checksum:    81142 2cf21c543bbb34561f6c2828ab7a08d0
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614i-0etch1_mips.deb
        Size/MD5 checksum: 46786690 9ccb2a732e0a2a49d1f1f9d5d68cef86
      http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:   119034 0a10831d2377b7278cfbdb2e90574535
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:  5955860 db51379ca6bba623c738ec7cae30271a
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:   809332 94a939e3ca873e217ef215fce9b63dc1
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:   671304 fd3252bd400f87abc8350617d3a31c25
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:    65610 632f5a86ddeed0e5ff6747189b4d9169
      http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:    52820 b1a2dccc6643955c7763fd2920f22418
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:   274358 10a1723ef97b4c11a3bb081d571e20c6
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:   312858 bf8db163f331cfbc9f1df9982813eab3
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:   786828 9a1b768ccfae0c4dc5688c3362a2d9fc
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:   352918 47b68c4cd5fdb3b5c8b2252e4cec0bd1
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:  3290808 61bae851c0f69a4a8499855db0a2bf44
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614i-0etch1_mips.deb
        Size/MD5 checksum:   147064 c220f1717506e0f721b214c23344aae4
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:   146654 66f51faead5bb8643b378056f7e91200
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:   351756 cdbd6d5cc056fe7ab22e99c0b4b17303
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:  5758508 d2a8f3588c96dbd86a313415f942b796
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:    65448 2e91580fd824a483cf15e41329ee54d6
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:   670958 9ce924c9c7c373bcb66c3d142598b960
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:   767374 db65bedd1451e3d002996607504f832c
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:  3187790 205442831b53abed47347494afd74c13
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum: 45388864 53ba9135abdeb81b127319c2965d654c
      http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:   118792 ebeeb6e0b3fa9697fc4d519dbf3445e3
      http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:    52882 9a492c7f088e33795f4f519e6d1fdb00
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:   785634 15195ea21bea73366c040ec35205b411
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:   305972 7c6cf13047b77819016441211306def6
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614i-0etch1_mipsel.deb
        Size/MD5 checksum:   275352 7b73a4f8d7961a9e2e5be4a5edac6bb6
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:   311370 dcc549b27be17ce12ad677571f7cd96c
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:   775168 dc939366bb688b507d7f02e281f49ff9
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:    65310 08e712f2c7efc1ff4711a3fed99de972
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum: 46973282 628962bbf1d65f90cd45c289f4e57eb2
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:   810170 3911108f3ad4ec7249de89579692a889
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:  3207248 c779f30b9617ce71eff5c7e38a50e700
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:   350370 89f7abf6fe0374a40df224d17547a326
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:   148354 e573866688369e0f33668e197ceb954a
      http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:    54152 137b9de7b7d101e6751448f9b376c542
      http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:   125070 9f3c03fc4dcf3b92af90f6dbb028ec3b
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:   641078 0d6cc0d69937519ec2a8b11c79620bba
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:  6113688 f14ea71428bbb9adc65fc9300af4dfaf
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614i-0etch1_powerpc.deb
        Size/MD5 checksum:   280116 934b5afcd4d54c8a9334209394725b76
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:   757252 fbbf4aa51c254501839c5239898a1966
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:   688966 eadd50708786aa35fe3352133362268a
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614i-0etch1_s390.deb
        Size/MD5 checksum: 46106184 f900f01b8a4d665783b488dba85e5368
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:  3183730 7570c50c80b825f39b21faae4304c39c
      http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:    54394 14206509134b8cab968b770409f2721d
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:   283734 e8f93eadcfedd43817fdef860a9b18f2
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:   900078 2fc17c17b2db9069640e5a5a8da4c55c
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:   307054 fad889ae074b09fe590bb6d256cea5e1
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:    70250 83853ab4be095ccad382c53ecb31a2b8
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:  6818036 e8b4b094912ad1dc2eaa4246f4072b33
      http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:   127826 35a3df9656c60848ee92ad37426f0e26
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:   160986 51635e7052198336a4560f42a8534809
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614i-0etch1_s390.deb
        Size/MD5 checksum:   372762 44c448ce0bdd1fb906ce3fc0f1cae4db
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.15~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:  5691378 fb92fb8595fe77b778bf2f10cec49c59
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:   720372 d6905da5cd02841a3a1504bc2414e6c0
      http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:   119274 6ce21aa1465d61eab2441dea7e7dda47
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:    63586 04418e16def13078bdfb58e30864bec5
      http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:    51632 f4100de3c8fde3d8b45dc81af6a1d375
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:   587454 7e843d8cbedddd2e158bbcceca21f109
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:   677262 85da1319d7f5eb22a66c11947d3eb447
      http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:  2853912 6aaad890cf6475d08323566c1d45d3c6
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:   137004 23c70ffb48e7fe2f77314a19a731435e
      http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:   323878 c27c6e54a5f9bae01bec83548ade9ea9
      http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.15~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:   260544 b3703da635436037b1cbed4cc04567d4
      http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum:   284548 afec3eadc60217b0f63bfd4efbb17a53
      http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614i-0etch1_sparc.deb
        Size/MD5 checksum: 44808802 f7dd5d65267da83f9050a83d3131f953
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iEYEARECAAYFAkluSlEACgkQXm3vHE4uylqaSQCdHEKoQIiWiXHOm48S2S3v6cHS
    kiQAoMoAN/iBzrG1wqUSgCr4Vq3R6Gd7
    =KctC
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - --------------------------------------------------------------------------
    Debian Security Advisory DSA 1705-1                    security@debian.org
    http://www.debian.org/security/                                 Nico Golde
    January 15th, 2009                      http://www.debian.org/security/faq
    - --------------------------------------------------------------------------
    
    Package        : netatalk
    Vulnerability  : missing input sanitising
    Problem type   : local(remote)
    Debian-specific: no
    CVE ID         : CVE-2008-5718
    Debian Bug     : 510585
    
    It was discovered that netatalk, an implementation of the AppleTalk
    suite, is affected by a command injection vulnerability when processing
    PostScript streams via papd.  This could lead to the execution of
    arbitrary code.  Please note that this only affects installations that are
    configured to use a pipe command in combination with wildcard symbols
    substituted with values of the printed job.
    
    For the stable distribution (etch) this problem has been fixed in
    version 2.0.3-4+etch1.
    
    For the upcoming stable distribution (lenny) this problem has been fixed
    in version 2.0.3-11+lenny1.
    
    For the unstable distribution (sid) this problem has been fixed in
    version 2.0.4~beta2-1.
    
    We recommend that you upgrade your netatalk package.
    
    
    Upgrade Instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given at the end of this advisory:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1.diff.gz
        Size/MD5 checksum:    27582 efc06139ef2adba4ca71c4ff9effefd2
      http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3.orig.tar.gz
        Size/MD5 checksum:  1920570 17917abd7d255d231cc0c6188ccd27fb
      http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1.dsc
        Size/MD5 checksum:      822 eb3fc44340caed42978dea8b8e8cc53d
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_alpha.deb
        Size/MD5 checksum:   869526 2a7d4250ee8380227231cd68cc70b5e4
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_amd64.deb
        Size/MD5 checksum:   751530 67f12f90fa7e11d8dfa791f36ee05e22
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_arm.deb
        Size/MD5 checksum:   729204 14b32580e4d93588404c1669074f9f09
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_hppa.deb
        Size/MD5 checksum:   800306 26eb091564c8077955d41ac42b585868
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_i386.deb
        Size/MD5 checksum:   706600 542cfc6b12f76ed4a068a389fa059372
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_ia64.deb
        Size/MD5 checksum:  1007572 a5393f96b01e65c8daece94babe663c2
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_mips.deb
        Size/MD5 checksum:   776996 5d25c6809bfd2c3a6d3b29be1bd5e5e4
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_mipsel.deb
        Size/MD5 checksum:   773318 c6393e566664dbd1959e7c154ae90e37
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_powerpc.deb
        Size/MD5 checksum:   757606 ba364451858fc30ce3a4e2996ab316b0
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_s390.deb
        Size/MD5 checksum:   770290 7970c3e8038bd51b6089cf824af789d6
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/n/netatalk/netatalk_2.0.3-4+etch1_sparc.deb
        Size/MD5 checksum:   711964 fe24e2794125763c9548f522fd152a88
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iEYEARECAAYFAklvo3wACgkQXm3vHE4uylrXCwCgsIdRo/L8Sf2ObeKwzj8Feuix
    d+EAn1s6asea2Ygbs5BJjptm9xC+56wn
    =uODl
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1706-1                  security@debian.org
    http://www.debian.org/security/                       Moritz Muehlenhoff
    January 15, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : amarok
    Vulnerability  : integer overflows
    Problem type   : local(remote)
    Debian-specific: no
    CVE Id(s)      : not assigned yet
    
    Tobias Klein discovered that integer overflows in the code the Amarok
    media player uses to parse Audible files may lead to the execution of
    arbitrary code.
    
    For the stable distribution (etch), this problem has been fixed in
    version 1.4.4-4etch1. Updated packages for sparc and arm will be
    provided later.
    
    For the upcoming stable distribution (lenny) and the unstable
    distribution (sid), this problem has been fixed in version 1.4.10-2.
    
    We recommend that you upgrade your amarok packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Stable updates are available for alpha, amd64, hppa, i386, ia64, mips, mipsel, powerpc, s390.
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/a/amarok/amarok_1.4.4.orig.tar.gz
        Size/MD5 checksum: 17628566 0adbbd8373da2198b80e509618a2dab9
      http://security.debian.org/pool/updates/main/a/amarok/amarok_1.4.4-4etch1.diff.gz
        Size/MD5 checksum:    42402 c29b0538c033ededacc6d31339d17700
      http://security.debian.org/pool/updates/main/a/amarok/amarok_1.4.4-4etch1.dsc
        Size/MD5 checksum:      986 f8e80af55fbd8386e6b13b0b12d798f4
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/a/amarok/amarok-engines_1.4.4-4etch1_alpha.deb
        Size/MD5 checksum:    70238 16f3f3c09abb731a18a3dc48c473de6b
      http://security.debian.org/pool/updates/main/a/amarok/amarok-xine_1.4.4-4etch1_alpha.deb
        Size/MD5 checksum:   129504 287d891eceb758b606dca22be1c00373
      http://security.debian.org/pool/updates/main/a/amarok/amarok_1.4.4-4etch1_alpha.deb
        Size/MD5 checksum: 17689706 f50edbcb0ecf4e4b9eb3c7bfcccdab16
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/a/amarok/amarok-engines_1.4.4-4etch1_amd64.deb
        Size/MD5 checksum:    69932 7fa4c35fe5ec1bf5c3622beaadfd9d55
      http://security.debian.org/pool/updates/main/a/amarok/amarok_1.4.4-4etch1_amd64.deb
        Size/MD5 checksum: 17559012 516c270247fbb4470ec5d453edd45240
      http://security.debian.org/pool/updates/main/a/amarok/amarok-xine_1.4.4-4etch1_amd64.deb
        Size/MD5 checksum:   126688 f4dc3d7e22c5716df018e1d198756523
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/a/amarok/amarok-engines_1.4.4-4etch1_hppa.deb
        Size/MD5 checksum:    70028 ee3d6e27e1bb5412a729cda758bb4c79
      http://security.debian.org/pool/updates/main/a/amarok/amarok_1.4.4-4etch1_hppa.deb
        Size/MD5 checksum: 17799030 a9ab6605a349108354a1c3642b3e017b
      http://security.debian.org/pool/updates/main/a/amarok/amarok-xine_1.4.4-4etch1_hppa.deb
        Size/MD5 checksum:   133110 025ed372785d76ee8489debf6ec06b59
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/a/amarok/amarok-xine_1.4.4-4etch1_i386.deb
        Size/MD5 checksum:   122606 af13d7d1948840398e2e0865c002f1be
      http://security.debian.org/pool/updates/main/a/amarok/amarok-engines_1.4.4-4etch1_i386.deb
        Size/MD5 checksum:    69978 d9e962dbb56755409c73e1d29d76e8ca
      http://security.debian.org/pool/updates/main/a/amarok/amarok_1.4.4-4etch1_i386.deb
        Size/MD5 checksum: 17426752 7e3dd482184056066d73844fea495000
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/a/amarok/amarok-engines_1.4.4-4etch1_ia64.deb
        Size/MD5 checksum:    69978 eaeea421c5d986247d68b24fa43645b4
      http://security.debian.org/pool/updates/main/a/amarok/amarok-xine_1.4.4-4etch1_ia64.deb
        Size/MD5 checksum:   143310 55bcb806b1ed036e0b1bf1e14cab97d1
      http://security.debian.org/pool/updates/main/a/amarok/amarok_1.4.4-4etch1_ia64.deb
        Size/MD5 checksum: 18256184 8ee9cdea2583aa0efdd577a91ccb1037
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/a/amarok/amarok-engines_1.4.4-4etch1_mips.deb
        Size/MD5 checksum:    69978 2e39ff39e8a9ef544f4f9e3d00c4708e
      http://security.debian.org/pool/updates/main/a/amarok/amarok-xine_1.4.4-4etch1_mips.deb
        Size/MD5 checksum:   118582 956b27a45db711471b8a1647a7e13893
      http://security.debian.org/pool/updates/main/a/amarok/amarok_1.4.4-4etch1_mips.deb
        Size/MD5 checksum: 17189438 a0cd5cbf3e68a9a481cbd42a13d0c717
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/a/amarok/amarok-xine_1.4.4-4etch1_mipsel.deb
        Size/MD5 checksum:   118316 73af2daa439ee61d07781f42fbb9bdf2
      http://security.debian.org/pool/updates/main/a/amarok/amarok-engines_1.4.4-4etch1_mipsel.deb
        Size/MD5 checksum:    69976 084e0fabd90d5dcbc3cdaf7727a8e7c9
      http://security.debian.org/pool/updates/main/a/amarok/amarok_1.4.4-4etch1_mipsel.deb
        Size/MD5 checksum: 17131354 d5a809e1e78f60ffb91ed99e697dbc13
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/a/amarok/amarok_1.4.4-4etch1_powerpc.deb
        Size/MD5 checksum: 17423852 1c2428cbb97b045f3880538db423e6f4
      http://security.debian.org/pool/updates/main/a/amarok/amarok-xine_1.4.4-4etch1_powerpc.deb
        Size/MD5 checksum:   123234 224605d1f56406132ab7acc9314301c0
      http://security.debian.org/pool/updates/main/a/amarok/amarok-engines_1.4.4-4etch1_powerpc.deb
        Size/MD5 checksum:    69978 6d0d183ed614b4627fb306aeec628b72
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/a/amarok/amarok-engines_1.4.4-4etch1_s390.deb
        Size/MD5 checksum:    69974 300b343297ec84c5520052014d237df6
      http://security.debian.org/pool/updates/main/a/amarok/amarok-xine_1.4.4-4etch1_s390.deb
        Size/MD5 checksum:   125914 48ca5f8f754297d200c4d87d69d6c345
      http://security.debian.org/pool/updates/main/a/amarok/amarok_1.4.4-4etch1_s390.deb
        Size/MD5 checksum: 17480270 865a5a65b3c5ad28858d7c7538f0bbc7
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iEYEARECAAYFAklvrVcACgkQXm3vHE4uylqxMgCfQjy6089bPkBn6j6oqOK5jDj1
    D90AoN/I9JrH2veMq185ZjvW4Csol/k+
    =5I+6
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1707-1                  security@debian.org
    http://www.debian.org/security/                           Steffen Joeris
    January 15, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : iceweasel
    Vulnerability  : several vulnerabilities
    Problem type   : remote
    Debian-specific: no
    CVE ID         : CVE-2008-5500 CVE-2008-5503 CVE-2008-5504 CVE-2008-5506 CVE-2008-5507 CVE-2008-5508 CVE-2008-5510 CVE-2008-5511 CVE-2008-5512 CVE-2008-5513
    
    Several remote vulnerabilities have been discovered in the Iceweasel web
    browser, an unbranded version of the Firefox browser. The Common
    Vulnerabilities and Exposures project identifies the following problems:
    
    CVE-2008-5500
    
       Jesse Ruderman  discovered that the layout engine is vulnerable to
       DoS attacks that might trigger memory corruption and an integer
       overflow. (MFSA 2008-60)
    
    CVE-2008-5503
    
       Boris Zbarsky discovered that an information disclosure attack could
       be performed via XBL bindings. (MFSA 2008-61)
    
    CVE-2008-5504
    
       It was discovered that attackers could run arbitrary JavaScript with
       chrome privileges via vectors related to the feed preview.
       (MFSA 2008-62)
    
    CVE-2008-5506
    
       Marius Schilder discovered that it is possible to obtain sensible
       data via a XMLHttpRequest. (MFSA 2008-64)
    
    CVE-2008-5507
    
       Chris Evans discovered that it is possible to obtain sensible data
       via a JavaScript URL. (MFSA 2008-65)
    
    CVE-2008-5508
    
       Chip Salzenberg discovered possible phishing attacks via URLs with
       leading whitespaces or control characters. (MFSA 2008-66)
    
    CVE-2008-5510
    
       Kojima Hajime and Jun Muto discovered that escaped null characters
       were ignored by the CSS parser and could lead to the bypass of
       protection mechanisms (MFSA 2008-67)
    
    CVE-2008-5511
    
       It was discovered that it is possible to perform cross-site scripting
       attacks via an XBL binding to an "unloaded document." (MFSA 2008-68)
    
    CVE-2008-5512
    
       It was discovered that it is possible to run arbitrary JavaScript
       with chrome privileges via unknown vectors. (MFSA 2008-68)
    
    CVE-2008-5513
    
       moz_bug_r_a4 discovered that the session-restore feature does not
       properly sanitise input leading to arbitrary injections. This issue
       could be used to perform an XSS attack or run arbitrary JavaScript
       with chrome privileges. (MFSA 2008-69)
    
    For the stable distribution (etch) these problems have been fixed in
    version 2.0.0.19-0etch1.
    
    For the testing distribution (lenny) and the unstable distribution (sid)
    these problems have been fixed in version 3.0.5-1. Please note iceweasel
    in Lenny links dynamically against xulrunner.
    
    We recommend that you upgrade your iceweasel package.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.19-0etch1.diff.gz
        Size/MD5 checksum:   186830 9bf2b415ae6550f234fb4287f1ffc178
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.19.orig.tar.gz
        Size/MD5 checksum: 47265190 487603397f7f68e720088f5a9fff7568
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.19-0etch1.dsc
        Size/MD5 checksum:     1289 a84453d1fcc2392126ee0a86a5f876bc
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dom-inspector_2.0.0.19-0etch1_all.deb
        Size/MD5 checksum:   239862 2beb51f15a93ff0fbb52bf9ee2bf9262
      http://security.debian.org/pool/updates/main/i/iceweasel/firefox-gnome-support_2.0.0.19-0etch1_all.deb
        Size/MD5 checksum:    54674 7cc2d42685bfeb9f569c27fa81ebed6c
      http://security.debian.org/pool/updates/main/i/iceweasel/firefox-dom-inspector_2.0.0.19-0etch1_all.deb
        Size/MD5 checksum:    54706 16e2a91256b94fca61df51819750f7e9
      http://security.debian.org/pool/updates/main/i/iceweasel/mozilla-firefox_2.0.0.19-0etch1_all.deb
        Size/MD5 checksum:    55348 23c72591d917fdcd02d9cb404bdb69e6
      http://security.debian.org/pool/updates/main/i/iceweasel/firefox_2.0.0.19-0etch1_all.deb
        Size/MD5 checksum:    54822 d9c2d70c48526a6ca4a1f8e68351594d
      http://security.debian.org/pool/updates/main/i/iceweasel/mozilla-firefox-gnome-support_2.0.0.19-0etch1_all.deb
        Size/MD5 checksum:    54554 5b00fd2d4da794af564602b8b7a0b3d3
      http://security.debian.org/pool/updates/main/i/iceweasel/mozilla-firefox-dom-inspector_2.0.0.19-0etch1_all.deb
        Size/MD5 checksum:    54554 0cca6bf32447364088bc7e56aa19e86f
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.19-0etch1_alpha.deb
        Size/MD5 checksum: 51217632 a2b608d43acfc489dd7cc2643f2ee0dd
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.19-0etch1_alpha.deb
        Size/MD5 checksum:    90436 e68e1a34c49991ee33ea393bec5a57c4
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.19-0etch1_alpha.deb
        Size/MD5 checksum: 11589982 68aca123bcd86eecc9f1558774c24883
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.19-0etch1_amd64.deb
        Size/MD5 checksum: 50215664 82c643c05f80127c7e9f2277d3dfffaa
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.19-0etch1_amd64.deb
        Size/MD5 checksum:    88098 64cabf94ccd7d9c9b4e8b381af267ae6
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.19-0etch1_amd64.deb
        Size/MD5 checksum: 10215628 90d907685372f725dc97e5acfc8cc432
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.19-0etch1_arm.deb
        Size/MD5 checksum:    81772 efc524b4734c7cee83b0daf8ed8ea2cf
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.19-0etch1_arm.deb
        Size/MD5 checksum:  9264144 9289cb0bfcb3fc3434c168668a76e9c7
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.19-0etch1_arm.deb
        Size/MD5 checksum: 49303134 3c16bb32854e946e42106a82a080da05
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.19-0etch1_hppa.deb
        Size/MD5 checksum: 50588512 172ab29c5ec07664e23dbbf28398d629
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.19-0etch1_hppa.deb
        Size/MD5 checksum: 11121980 18aa56c1311a6f6f87b451a4ea7ce05a
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.19-0etch1_hppa.deb
        Size/MD5 checksum:    89966 b23137551797adaeb5fe54074db359c4
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.19-0etch1_i386.deb
        Size/MD5 checksum:    82250 9741fc1cf64da52a1a63f71b4dc9dda1
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.19-0etch1_i386.deb
        Size/MD5 checksum:  9128396 99802e5988c010dc9d4cbb31df658e8d
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.19-0etch1_i386.deb
        Size/MD5 checksum: 49608400 315e2030a2eb2199e31310d8df1bcbae
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.19-0etch1_ia64.deb
        Size/MD5 checksum: 50564776 3061c2cbb88f38b44bf02c69e1224416
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.19-0etch1_ia64.deb
        Size/MD5 checksum:   100448 4785c7ceb4a7e4b8c38baabb490dac6e
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.19-0etch1_ia64.deb
        Size/MD5 checksum: 14168992 5221b7d6f3e10229b8a8c6d63eedabe1
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.19-0etch1_mips.deb
        Size/MD5 checksum: 54013020 984b11ab87dcf807a07c3991c15aa9d4
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.19-0etch1_mips.deb
        Size/MD5 checksum: 11071524 9da549588b944ec2b5ad361fa7217c25
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.19-0etch1_mips.deb
        Size/MD5 checksum:    83390 370745389f99d8bc4f42f24febeaf6d0
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.19-0etch1_mipsel.deb
        Size/MD5 checksum:    83414 b7e92ca268149e5fe58539b820f5180e
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.19-0etch1_mipsel.deb
        Size/MD5 checksum: 52564564 38aa4d8ecfe74a61849b5cfcfa1f88c4
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.19-0etch1_mipsel.deb
        Size/MD5 checksum: 10769220 cf754cd9e5359608df250d1108950226
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.19-0etch1_powerpc.deb
        Size/MD5 checksum: 52014042 5d81eed61cb8c881234da9694e14afba
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.19-0etch1_powerpc.deb
        Size/MD5 checksum:  9946484 b54594ac22f61385df030ed6252437de
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.19-0etch1_powerpc.deb
        Size/MD5 checksum:    83960 79fbeedf1eb4edf09f89d85155e9ec17
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.19-0etch1_s390.deb
        Size/MD5 checksum: 50887766 98173828e5f028031f5ec0516aef756a
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.19-0etch1_s390.deb
        Size/MD5 checksum: 10370674 0e5f34597932031b191d51661a35b183
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.19-0etch1_s390.deb
        Size/MD5 checksum:    88368 90a01cb64baf1b646f0e68780b37fca1
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.19-0etch1_sparc.deb
        Size/MD5 checksum:  9208238 e39539d8dd3011da585894a93e80b7dd
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.19-0etch1_sparc.deb
        Size/MD5 checksum:    82142 c4c052611d01d175ea5590c50f9852c7
      http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.19-0etch1_sparc.deb
        Size/MD5 checksum: 49223972 ccbc30d1113bdc8b26ebc4bf4fa08fe9
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iEYEARECAAYFAklvsmQACgkQXm3vHE4uylqpZgCfQV2pmGEXNLnRrSr3eGT0zuwM
    dOYAoKxG4D0mpPNsoXkw5y2LMQOXzXN4
    =/+IP
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1708-1                  security@debian.org
    http://www.debian.org/security/                           Florian Weimer
    January 19, 2009                      http://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : git-core
    Vulnerability  : shell command injection
    Problem type   : remote
    Debian-specific: no
    CVE Id(s)      : CVE-2008-5516 CVE-2008-5517
    Debian Bug     : 512330
    
    It was discovered that gitweb, the web interface for the Git version
    control system, contained several vulnerabilities:
    
    Remote attackers could use crafted requests to execute shell commands on
    the web server, using the snapshot generation and pickaxe search
    functionality (CVE-2008-5516).
    
    Local users with write access to the configuration of a Git repository
    served by gitweb could cause gitweb to execute arbitrary shell commands
    with the permission of the web server (CVE-2008-5517).
    
    For the stable distribution (etch), these problems have been fixed in
    version 1.4.4.4-4+etch1.
    
    For the unstable distribution (sid) and testing distribution (lenny),
    the remote shell command injection issuei (CVE-2008-5516) has been fixed
    in version 1.5.6-1.  The other issue will be fixed soon.
    
    We recommend that you upgrade your Git packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 4.0 alias etch
    - -------------------------------
    
    Source archives:
    
      http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4.orig.tar.gz
        Size/MD5 checksum:  1054130 99bc7ea441226f792b6f796a838e7ef0
      http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1.diff.gz
        Size/MD5 checksum:    88583 47033ef17360b441eb508094a3ab6b2b
      http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1.dsc
        Size/MD5 checksum:     1097 b907083d358ff2dc892790569fe3a164
    
    Architecture independent packages:
    
      http://security.debian.org/pool/updates/main/g/git-core/gitweb_1.4.4.4-4+etch1_all.deb
        Size/MD5 checksum:    89094 1dc1b790f989600d62ba2d347d890a43
      http://security.debian.org/pool/updates/main/g/git-core/git-daemon-run_1.4.4.4-4+etch1_all.deb
        Size/MD5 checksum:    55504 7d1a4bf7bf17f179f94f513fc56f1ffc
      http://security.debian.org/pool/updates/main/g/git-core/git-svn_1.4.4.4-4+etch1_all.deb
        Size/MD5 checksum:   100426 149f0e2dda76e4d7613200d530db9e67
      http://security.debian.org/pool/updates/main/g/git-core/gitk_1.4.4.4-4+etch1_all.deb
        Size/MD5 checksum:    99598 800ea1d003baf1e348fda3b661fc16ed
      http://security.debian.org/pool/updates/main/g/git-core/git-doc_1.4.4.4-4+etch1_all.deb
        Size/MD5 checksum:   453076 4d102f5051116516cf4cc45b10637871
      http://security.debian.org/pool/updates/main/g/git-core/git-email_1.4.4.4-4+etch1_all.deb
        Size/MD5 checksum:    62792 201df12660ca0b6180e5fa3c5e0a3543
      http://security.debian.org/pool/updates/main/g/git-core/git-arch_1.4.4.4-4+etch1_all.deb
        Size/MD5 checksum:    68508 1489a2af3d016ff8b1a4c612365870b8
      http://security.debian.org/pool/updates/main/g/git-core/git-cvs_1.4.4.4-4+etch1_all.deb
        Size/MD5 checksum:    94516 afef0aca9b13d1d50af28cbb0d9cc1aa
    
    alpha architecture (DEC Alpha)
    
      http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_alpha.deb
        Size/MD5 checksum:  3101926 6422c5ad17a7248820c3c27195051b0c
    
    amd64 architecture (AMD x86_64 (AMD64))
    
      http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_amd64.deb
        Size/MD5 checksum:  2642144 b81b341dce9b234eb193d40decd1283b
    
    arm architecture (ARM)
    
      http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_arm.deb
        Size/MD5 checksum:  2322772 d5c371c8f6f3923edaf880df795870e4
    
    hppa architecture (HP PA RISC)
    
      http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_hppa.deb
        Size/MD5 checksum:  2693958 c519a9e4cfeda0f11fe92e23756c6759
    
    i386 architecture (Intel ia32)
    
      http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_i386.deb
        Size/MD5 checksum:  2340718 94abafaa8e010240a6a2da50ca717217
    
    ia64 architecture (Intel ia64)
    
      http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_ia64.deb
        Size/MD5 checksum:  3815660 9b0970058eecaf9abd12e5cc472d0434
    
    mips architecture (MIPS (Big Endian))
    
      http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_mips.deb
        Size/MD5 checksum:  2784146 b345d0ffd96b307025924f99fed33e9e
    
    mipsel architecture (MIPS (Little Endian))
    
      http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_mipsel.deb
        Size/MD5 checksum:  2801244 7067901dea12981db4f09e186888e5b3
    
    powerpc architecture (PowerPC)
    
      http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_powerpc.deb
        Size/MD5 checksum:  2638996 23afd3d0fc61699d0850793c2dbd0047
    
    s390 architecture (IBM S/390)
    
      http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_s390.deb
        Size/MD5 checksum:  2628016 8f29e9b8b465bf570e8ee7bf78e3437d
    
    sparc architecture (Sun SPARC/UltraSPARC)
    
      http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_sparc.deb
        Size/MD5 checksum:  2301444 93f43ba8edfb78438a6d7d66b96e4816
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announce@lists.debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.9 (GNU/Linux)
    
    iQEcBAEBAgAGBQJJdOgyAAoJEL97/wQC1SS+aaAIAKft8eWfOYqWyNxCeWRoD+v9
    Y83tWBlrIoVkEJQqwm/l5L2YVlzZ0uEE7w/OxOVg31SmibwBsnx1OF2IefSmryHe
    kUM2TIHfA4/V0kjgs8E1IaQT/3TSRWmSfgQPlUACti4ijsWU/o4pDreyFh+fa0sN
    pldwxqxojCo8QVlosJDII8wyZ75DjMlam2UujQAbZrdd7j16SHh/LfZ0vbxTO+PX
    mqAOMicVz2b/1IFYjL4YK0NThxvyivtTVT8Nc7nb7As8kUZAF+Uu3yvXFzavObBQ
    6Qs6rCThVf+HXE6pDw3MmDU869pfP4H8Irxh6Jy6/2gaJcjNXVqCuCA+v44CJqg=
    =6LbJ
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---

    Vissza a www.andrews.hu-ra