-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 28 Aug 2013 00:40:42 +0100 Source: nas Binary: libaudio2 nas libaudio-dev nas-bin nas-doc Architecture: armhf Version: 1.9.3-5wheezy1 Distribution: wheezy-security Urgency: high Maintainer: armhf Build Daemon (henze) Changed-By: Steve McIntyre <93sam@debian.org> Description: libaudio-dev - Network Audio System - development files libaudio2 - Network Audio System - shared libraries nas - Network Audio System - local server nas-bin - Network Audio System - client binaries nas-doc - Network Audio System - extra documentation Closes: 720287 Changes: nas (1.9.3-5wheezy1) stable-security; urgency=high . * Fixes for various long-standing security issues found by Hamid Zamani . Closes: #720287 + Validate the port offset of nasd to fix a potential buffer overflow (CVE-2013-4256) + Use better string functions to guard against heap overflows (CVE-2013-4257) + Sanity-check the TCP_DEVICE environment variable to remove a format string bug (CVE-2013-4258) Checksums-Sha1: 5c253ae1c03f7bf00c6f0aa4323ee3e8b7ad916f 107690 nas_1.9.3-5wheezy1_armhf.deb b0d9774bedc7a9c14a7626931513443fdebd05f3 173162 nas-bin_1.9.3-5wheezy1_armhf.deb c6237728d40ce4dca316bd203a03d1bb1f2f4b43 77562 libaudio2_1.9.3-5wheezy1_armhf.deb 97acaf825a4cefdab4c5ac302f1c170f59fa2a78 525300 libaudio-dev_1.9.3-5wheezy1_armhf.deb Checksums-Sha256: 481f122ef0b35b704dfbe26396d87ada970e3c0775ba6ba93c849aeeb74b4b24 107690 nas_1.9.3-5wheezy1_armhf.deb 27a88342388bbe58f15804401e20fe5e613eebe6cd4921b1f61453beae2eb06c 173162 nas-bin_1.9.3-5wheezy1_armhf.deb b214b7476c0e176ba3db27b956e4f40a10139e2db473265e33af356a290b37bf 77562 libaudio2_1.9.3-5wheezy1_armhf.deb 1bab1f537d6e4347bb4005d8997e40d6cafa6c6e68500d9b9e07c0ac22506c6d 525300 libaudio-dev_1.9.3-5wheezy1_armhf.deb Files: 8aa09404afe000d50795ecee8770828c 107690 sound optional nas_1.9.3-5wheezy1_armhf.deb cf2af5ff101feed3ef90c6e718c1da1e 173162 sound extra nas-bin_1.9.3-5wheezy1_armhf.deb 93443a87f7e569a811984b1812fa0698 77562 libs optional libaudio2_1.9.3-5wheezy1_armhf.deb c7df61064455be33d744fbafbd9aa241 525300 libdevel optional libaudio-dev_1.9.3-5wheezy1_armhf.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBAgAGBQJSVFm6AAoJELb5DjdLUwKeBAoP/jGGSIbzbnO1YJFKDgrRs63Q f7rlBGQyQ7Pkx1pKZHG/Y0vtwUH0HrbVxr4PNOHjyyINV2ETzGNP43i541IreDTM hu7cBxoLY7RcwZTJXwxj+jfIm9yw7tFhByxUFl5zri72nuw5V3xEZIMz5N/gFew/ v1CeQ4CgyCNU7ClGy7X0ElgtqqMdS3LXX4ibRzSqi8Je6IFVAQCjKorwYA086wno /2xd37kNGz7fjtkhTn9ZzVoggydCvK44/v05W9MHRx9CtHgxENkkzpgV020Oysyv bT2fH3vOdvnxaWupYocTSUjOyYO7y2am3roNUnht0BYK0yyupwl/6IBcDYiE18wX RD6LxVip8+uwdJvqwWHQn6r4KdjVTo9tbOJFazaOJXj0KxpGtfCGGQW7eMjUqg+i qwXqcWKAhlyv4hETIKcK/1jun3+KsPdBnx0220CfzxW9VHHRbhBkLX8y6VEyxUTB VaB2wiBXb6mclbEGU5IxpLcoWrpv/lT0/c1wg6xviou6c3RKnPqBXok4iK1u0ji/ 2a1eggqzo/97B1JI9dMgp9zmW5atj1qizBRHvCvQbVVA1n1xFLVVBOAD7XlvljAE 9+vqZu1Tr/fsbAp65f/MCbLWTMT6qKxZCXT+a/5E0scjqsIjh0i6flJyb3dYANjn f/usooP+2chWo/hi5Q0I =kmv3 -----END PGP SIGNATURE-----