lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <m1EhPam-000ohtC__39448.5559816987$1133379309$gmane$org@finlandia.Infodrom.North.DE>
Date: Wed, 30 Nov 2005 11:53:40 +0100 (CET)
From: joey@...odrom.org (Martin Schulze)
To: bugtraq@...urityfocus.com
Subject: [SECURITY] [DSA 912-1] New centericq packages fix denial of service


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 912-1                     security@...ian.org
http://www.debian.org/security/                             Martin Schulze
November 30th, 2005                     http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : centericq
Vulnerability  : denial of service
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2005-3694
Debian Bug     : 334089

Wernfried Haas discovered that centericq, a text-mode multi-protocol
instant messenger client, can crash when it receives certain zero
length packets and is directly connected to the Internet.

For the old stable distribution (woody) this problem has been fixed in
version 4.5.1-1.1woody1.

For the stable distribution (sarge) this problem has been fixed in
version 4.20.0-1sarge3.

For the unstable distribution (sid) this problem has been fixed in
version 4.21.0-4.

We recommend that you upgrade your centericq package.


Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody
- --------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody1.dsc
      Size/MD5 checksum:      603 adc70e793721c0968ca4502ae3698e37
    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody1.diff.gz
      Size/MD5 checksum:     3655 582ef0aecc37162611871ae159a5a2a1
    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1.orig.tar.gz
      Size/MD5 checksum:   680625 e50121ea43a54140939b7bec8efdefe0

  Alpha architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody1_alpha.deb
      Size/MD5 checksum:   868548 43f1db770fa8fe7cf8d03e7bddbc97e7

  ARM architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody1_arm.deb
      Size/MD5 checksum:   809002 7af9b13e885f9a3e4bc2324fc74318d3

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody1_i386.deb
      Size/MD5 checksum:   648688 3229599d676695a14160215f39bb473d

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody1_ia64.deb
      Size/MD5 checksum:   930848 6d54ca84f2861499702019cd50d9c351

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody1_hppa.deb
      Size/MD5 checksum:   821280 2ca221ccebbf2dae0ff30a198defd08b

  Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody1_m68k.deb
      Size/MD5 checksum:   611984 a1e44d2f4cd3c52700295a72dfce1868

  Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody1_mips.deb
      Size/MD5 checksum:   649002 edd2b6f73fec90e3e7142093bb3c6b3e

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody1_mipsel.deb
      Size/MD5 checksum:   634442 987c44dbb499ab61b7d2b254bc9ff984

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody1_powerpc.deb
      Size/MD5 checksum:   633166 41ab0b819882d62ec6467a4d7542ce1f

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody1_s390.deb
      Size/MD5 checksum:   534784 7fb270cf1f195514510aef8445b2ece6

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.5.1-1.1woody1_sparc.deb
      Size/MD5 checksum:   617274 d284648d4388edddf349130e9ed13332


Debian GNU/Linux 3.1 alias sarge
- --------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge3.dsc
      Size/MD5 checksum:      875 5d132cb379014c621fc81232baf9ae4f
    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge3.diff.gz
      Size/MD5 checksum:   106011 259f44fb98da9322ff61a6ab36df6fbc
    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0.orig.tar.gz
      Size/MD5 checksum:  1796894 874165f4fbd40e3be677bdd1696cee9d

  Alpha architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge3_alpha.deb
      Size/MD5 checksum:  1650464 6757ab69461655c915f01c2ffb03e7cd
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge3_alpha.deb
      Size/MD5 checksum:   335886 7dcf13f17f952cc36802f7732dcf67a5
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge3_alpha.deb
      Size/MD5 checksum:  1651492 f3412af4c8f8310d2e21fc4155582ca8
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge3_alpha.deb
      Size/MD5 checksum:  1650508 9436f313af694fbe9ec97da7a168b9c4

  AMD64 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge3_amd64.deb
      Size/MD5 checksum:  1355448 6e94f8aa9438a489bd94369a1655c475
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge3_amd64.deb
      Size/MD5 checksum:   335908 bd7fb5325d61c02add148be10d8c2f40
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge3_amd64.deb
      Size/MD5 checksum:  1355704 399b6045d35c21d7d767ccc6755662e1
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge3_amd64.deb
      Size/MD5 checksum:  1355498 9da6bce36bfd754e09ad91d65484ba39

  ARM architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge3_arm.deb
      Size/MD5 checksum:  2185402 598cb4714af77dda74e956a7f13c0355
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge3_arm.deb
      Size/MD5 checksum:   336006 4f8fd48660de8d67581aeaaf7fc26dfa
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge3_arm.deb
      Size/MD5 checksum:  2186270 92a29d09e5630bf9e4029811b487aadf
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge3_arm.deb
      Size/MD5 checksum:  2185456 38e3f614efa5f448bdae8f2fd68eb929

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge3_i386.deb
      Size/MD5 checksum:  1348784 6d32e6d410250dbc7a220ad8d5a563a6
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge3_i386.deb
      Size/MD5 checksum:   336626 7628a48c891b62253369c5f6d0fd1272
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge3_i386.deb
      Size/MD5 checksum:  1349606 902e8f158e71b9a21de69d586941f090
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge3_i386.deb
      Size/MD5 checksum:  1348864 e38a08c798ad303c66c1ef313faee73f

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge3_ia64.deb
      Size/MD5 checksum:  1881326 29a00f7babe9fcbd3031d7b3d032bf53
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge3_ia64.deb
      Size/MD5 checksum:   335884 0d8612578ca347c502d04ea5cd1b4e4e
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge3_ia64.deb
      Size/MD5 checksum:  1882224 fc679fe6d852efb6e9e3d8d1888d525f
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge3_ia64.deb
      Size/MD5 checksum:  1881394 ffda1eed53efc1f8599fcb837cd66cc0

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge3_hppa.deb
      Size/MD5 checksum:  1812462 f253748c6a8bf09d31db8dd5f5554ad0
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge3_hppa.deb
      Size/MD5 checksum:   336634 1aa8cbb6f893217af25cc5af5e9bdc0c
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge3_hppa.deb
      Size/MD5 checksum:  1813518 3e6083c3e3438ebc40fd21ee414e2c3b
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge3_hppa.deb
      Size/MD5 checksum:  1812508 68a3677b2dac459f970834975f912b31

  Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge3_m68k.deb
      Size/MD5 checksum:  1399430 44c35ad2e854ab372a8a1491842e0956
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge3_m68k.deb
      Size/MD5 checksum:   336720 bd4440ba3d65a24caa97b0438aaaa5c0
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge3_m68k.deb
      Size/MD5 checksum:  1400044 7cda71a1524e83942e82c6de54dba1d3
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge3_m68k.deb
      Size/MD5 checksum:  1399462 37249094705dc33b8f56e8b042c6f519

  Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge3_mips.deb
      Size/MD5 checksum:  1493070 1dfa1f92a38b12c7643711db57d63d58
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge3_mips.deb
      Size/MD5 checksum:   336634 a1c3383dcd7a2be6a57c3b9e140b63ff
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge3_mips.deb
      Size/MD5 checksum:  1493688 bb4f5026b751a06335dddbbf10396726
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge3_mips.deb
      Size/MD5 checksum:  1493134 c1edf7389fa031bd22e93e87efaf56ad

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge3_mipsel.deb
      Size/MD5 checksum:  1483286 f41bb70b6c3e94b9d34382070f1b904a
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge3_mipsel.deb
      Size/MD5 checksum:   335926 95d59321de2d69437a51dd57cc3f3968
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge3_mipsel.deb
      Size/MD5 checksum:  1483854 5304d58c141da6d498bd1ca44257a00f
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge3_mipsel.deb
      Size/MD5 checksum:  1483342 965a7c6b445968094da416ef59155e94

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge3_powerpc.deb
      Size/MD5 checksum:  1385102 b461f814a843a99cf02279c38c2a13c1
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge3_powerpc.deb
      Size/MD5 checksum:   336630 c52ee41c89e18fe67ed255f6ed06b391
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge3_powerpc.deb
      Size/MD5 checksum:  1385672 561fd887df51fd281fb1b00a4705dec5
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge3_powerpc.deb
      Size/MD5 checksum:  1385268 5e2818805952871d4385d3f83dc1446e

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge3_s390.deb
      Size/MD5 checksum:  1193992 85972c3db828122d8bf3587b5aab56cf
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge3_s390.deb
      Size/MD5 checksum:   336612 d4ea593319ad2cd29ae841ba41dec7fc
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge3_s390.deb
      Size/MD5 checksum:  1194290 29fb2417371e7883551312f71e2cd452
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge3_s390.deb
      Size/MD5 checksum:  1194030 c383023e1dad16a48cba3699bf978bc4

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/c/centericq/centericq_4.20.0-1sarge3_sparc.deb
      Size/MD5 checksum:  1325960 2d36893524353a685bc15a02f7cdfcfe
    http://security.debian.org/pool/updates/main/c/centericq/centericq-common_4.20.0-1sarge3_sparc.deb
      Size/MD5 checksum:   336630 5903d1d68b6a0bc21fbd09e2b668827b
    http://security.debian.org/pool/updates/main/c/centericq/centericq-fribidi_4.20.0-1sarge3_sparc.deb
      Size/MD5 checksum:  1326906 6e5d6c3230ce3cef504608f8e7472c43
    http://security.debian.org/pool/updates/main/c/centericq/centericq-utf8_4.20.0-1sarge3_sparc.deb
      Size/MD5 checksum:  1325994 7192ffdae9ca8748d9cca9453789075d


  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@...ts.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFDjYS0W5ql+IAeqTIRAgdyAKCLetoesxdMuGpZTNt+O0fVWkGT8QCeI27n
+TR51zT0OCckUOTbizWQqVE=
=on4o
-----END PGP SIGNATURE-----



Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ