-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 28 Aug 2013 00:40:42 +0100 Source: nas Binary: libaudio2 nas libaudio-dev nas-bin nas-doc Architecture: mips Version: 1.9.3-5wheezy1 Distribution: wheezy-security Urgency: high Maintainer: mips Build Daemon (corelli) Changed-By: Steve McIntyre <93sam@debian.org> Description: libaudio-dev - Network Audio System - development files libaudio2 - Network Audio System - shared libraries nas - Network Audio System - local server nas-bin - Network Audio System - client binaries nas-doc - Network Audio System - extra documentation Closes: 720287 Changes: nas (1.9.3-5wheezy1) stable-security; urgency=high . * Fixes for various long-standing security issues found by Hamid Zamani . Closes: #720287 + Validate the port offset of nasd to fix a potential buffer overflow (CVE-2013-4256) + Use better string functions to guard against heap overflows (CVE-2013-4257) + Sanity-check the TCP_DEVICE environment variable to remove a format string bug (CVE-2013-4258) Checksums-Sha1: 4661fdfadf2c26e42f501ca7d91e48aecc6dee13 115902 nas_1.9.3-5wheezy1_mips.deb fb1f29f57cb7ada2cfbdea6f898c0e457b1a4057 176024 nas-bin_1.9.3-5wheezy1_mips.deb fe02cbbc9b7945186f36229b33b8e533fab48a44 82164 libaudio2_1.9.3-5wheezy1_mips.deb a76844e5a60bf3385e13bf252b098d093b7567f4 549658 libaudio-dev_1.9.3-5wheezy1_mips.deb Checksums-Sha256: 95f8257343e7dd0ee38207b827f39add1d6ecc26e6105298734df52f1ae8b9ed 115902 nas_1.9.3-5wheezy1_mips.deb 9faa55cf9f3e91f4e7508ebb87f43a0f5a3a0cfe79d7f7b071b36c205f76f6af 176024 nas-bin_1.9.3-5wheezy1_mips.deb 701c1830afde55be3c54832bb7b7a428408a1defda883e84e9a4a4fe2f380758 82164 libaudio2_1.9.3-5wheezy1_mips.deb 66915847303b3d2865248cd1bcd391580416edffb5c77271692e80855f0a39e2 549658 libaudio-dev_1.9.3-5wheezy1_mips.deb Files: 634c6ebe63c687f0296335b1c9b8e51c 115902 sound optional nas_1.9.3-5wheezy1_mips.deb e5a7d7501e9b9fb1c51168c98c17ba09 176024 sound extra nas-bin_1.9.3-5wheezy1_mips.deb d29f2cbcd150537f6d286c5d85f771d0 82164 libs optional libaudio2_1.9.3-5wheezy1_mips.deb 87c51c3c7f1274374fc9efc78e7f3a8e 549658 libdevel optional libaudio-dev_1.9.3-5wheezy1_mips.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBAgAGBQJSVGTCAAoJEPfjxpjzVGItf/kQAJaNI4BYPxdbphPgku0HSyc+ K7q5D6lzUXpDGf7/hMg+D2IQYgFeNFVmMrTJx9x/9hrJYvQNLTkJ6G82/YuzeY/f ddhVfL7ccNunzcaWDIN2RSoOKqGwK+Z34QOP8D5mWAJYsbN8ndj+AB13Ds9Kigyt 7y7CCbLTLEZ5OCqz5AQy2FdEovSNeSxV/a1AgrbOTYBRmzL5RTQxMQp16X9rYrFX 4Z18QY0tr52FVMAtbSqG8Bin8Uu+KzIUT31xnjhzC8N/r8C0IcZ2xNTpMlCYYd6M R4UR4VdLKEn4WIFx0yIGssPoIsz+ZFuN6gtoz1FiRzV83iLiI/7DRtwv/xGMor+X eP16NbSMx3t2VhSqQEW5OL/72SVPHzgkQsZEKO7GFA0ZZLrakMYk2NlyH1946XI5 Pg/614M6hrA2JzeoABngg5o1PaSBcH5tciGMLmhF/uhB5c1AEEH7954zS+t+BJ+x mjALQQrZjB5lGozMnEXiFJvgyi73CXBBoRtqoySzYXTpu4LVMiRyyr0KxyZhpuQr xja9CkbGjRxofVVz52tkP79xanuDMODpHEaYXlkDtfySolZhDzzTr7uNo0+ATtcy jXJO61kVzCVBIZzD9Q3j44WS5Uh4fTQGDh8ST0XEfc8+BuRyKoj/F+LfCgTErE/X OoSD3n3k/rIRdPtumiog =qB5j -----END PGP SIGNATURE-----