From debian-security-announce@lists.debian.org Sun Aug 3 03:43:51 2003 From: debian-security-announce@lists.debian.org Resent-From: list@murphy.debian.org (SmartList) To: full-disclosure@lists.netsys.com Date: Thu, 31 Jul 2003 22:08:02 -0400 Reply-To: full-disclosure@lists.netsys.com Subject: [Full-Disclosure] [SECURITY] [DSA-359-1] New atari800 packages fix buffer overflows -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Debian Security Advisory DSA 359-1 security@debian.org http://www.debian.org/security/ Matt Zimmerman July 31st, 2003 http://www.debian.org/security/faq - -------------------------------------------------------------------------- Package : atari800 Vulnerability : buffer overflows Problem-Type : local Debian-specific: no CVE Ids : CAN-2003-0630 Steve Kemp discovered multiple buffer overflows in atari800, an Atari emulator. In order to directly access graphics hardware, one of the affected programs is setuid root. A local attacker could exploit this vulnerability to gain root privileges. For the current stable distribution (woody) this problem has been fixed in version 1.2.2-1woody2. For the unstable distribution (sid) this problem will be fixed soon. Refer to Debian bug #203707. We recommend that you update your atari800 package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody2.dsc Size/MD5 checksum: 652 c94ddb722982b7da902c00012b2a8129 http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody2.diff.gz Size/MD5 checksum: 16878 02679759adbad8e098e98caa0531a121 http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2.orig.tar.gz Size/MD5 checksum: 460211 17f40bab7f2cdf2968df46e37285dcd1 Alpha architecture: http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody2_alpha.deb Size/MD5 checksum: 298624 77e3eda3b61dee3f414c3985e3580567 ARM architecture: http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody2_arm.deb Size/MD5 checksum: 236450 cc3ce3cd1c3e8ded97ced77219a5d999 Intel IA-32 architecture: http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody2_i386.deb Size/MD5 checksum: 281528 cc670a35e50196f2fd1e870c500e064f Intel IA-64 architecture: http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody2_ia64.deb Size/MD5 checksum: 337988 d33f4e2d8ad85873307fa3126c4a51aa HP Precision architecture: http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody2_hppa.deb Size/MD5 checksum: 256698 ce44ceea827dca9b9a23190025c32abd Motorola 680x0 architecture: http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody2_m68k.deb Size/MD5 checksum: 196942 b4e9b0bd6198513d9575963b3968810c Big endian MIPS architecture: http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody2_mips.deb Size/MD5 checksum: 259694 0e0b7450ba5bffe3cffd92922c769f90 Little endian MIPS architecture: http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody2_mipsel.deb Size/MD5 checksum: 258260 74da79b674cce4c04546275eb4e421f3 PowerPC architecture: http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody2_powerpc.deb Size/MD5 checksum: 238558 c778e667504ecc12210cee5fd37537b6 IBM S/390 architecture: http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody2_s390.deb Size/MD5 checksum: 234874 c973ad457dacf860f818376f03237be6 Sun Sparc architecture: http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody2_sparc.deb Size/MD5 checksum: 239580 b16410debdaa02b00902a7d943536969 These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main Mailing list: debian-security-announce@lists.debian.org Package info: `apt-cache show ' and http://packages.debian.org/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2 (GNU/Linux) iD8DBQE/KcsdArxCt0PiXR4RAtT2AJ90LyxF0SrvEv9VGp9tEPRM+vAZdgCgpyit hmMJvPJZ6ntQNosaiVd2Ljg= =pRAh -----END PGP SIGNATURE----- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html