-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 28 Aug 2013 00:40:42 +0100 Source: nas Binary: libaudio2 nas libaudio-dev nas-bin nas-doc Architecture: armel Version: 1.9.3-5wheezy1 Distribution: wheezy-security Urgency: high Maintainer: armel Build Daemon (arnold) Changed-By: Steve McIntyre <93sam@debian.org> Description: libaudio-dev - Network Audio System - development files libaudio2 - Network Audio System - shared libraries nas - Network Audio System - local server nas-bin - Network Audio System - client binaries nas-doc - Network Audio System - extra documentation Closes: 720287 Changes: nas (1.9.3-5wheezy1) stable-security; urgency=high . * Fixes for various long-standing security issues found by Hamid Zamani . Closes: #720287 + Validate the port offset of nasd to fix a potential buffer overflow (CVE-2013-4256) + Use better string functions to guard against heap overflows (CVE-2013-4257) + Sanity-check the TCP_DEVICE environment variable to remove a format string bug (CVE-2013-4258) Checksums-Sha1: 249b876664611c4f9c304bf06756cfac61cfad5f 113346 nas_1.9.3-5wheezy1_armel.deb 1beeec051c1b42b6a888d4c3d9c01d12b691da92 186396 nas-bin_1.9.3-5wheezy1_armel.deb 13a600a0e89815ce096c4f255b0007a91458538d 81256 libaudio2_1.9.3-5wheezy1_armel.deb d159c3ac5e69f2b576324b0a9c7cfb3d1a7b1722 528362 libaudio-dev_1.9.3-5wheezy1_armel.deb Checksums-Sha256: 7a6592a9c029f9afbc24deccd10557f63f1635e1077febf76a62746a6d7bc5aa 113346 nas_1.9.3-5wheezy1_armel.deb dfdaf013021486195c76f5634afdb24a309958217741300caadffbfbe73f17ea 186396 nas-bin_1.9.3-5wheezy1_armel.deb 86f66132b8b4c5d67ae1f49695e05d3777f82bf2da26d21fcb3baca8d05eb58b 81256 libaudio2_1.9.3-5wheezy1_armel.deb c7aa68921d79d070ded57c5955017361f46c6a90253269837cc676b899e7d850 528362 libaudio-dev_1.9.3-5wheezy1_armel.deb Files: b1645399ff9cf555833bdc5939bfa4c8 113346 sound optional nas_1.9.3-5wheezy1_armel.deb 339c09d94d1adf46bf071ca0452a806f 186396 sound extra nas-bin_1.9.3-5wheezy1_armel.deb 330f4b4d215d341d7bfbad040133e38c 81256 libs optional libaudio2_1.9.3-5wheezy1_armel.deb 01b50f6e6c15b6710da1a50dbeb38d6d 528362 libdevel optional libaudio-dev_1.9.3-5wheezy1_armel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBAgAGBQJSVFrFAAoJED1tEnPPHc2O0Y0P/3yWGE1uAZHW31XtrSKER/Dc p+8G8YrtlcCSWowNkSMyV66S3VKr5ocu+8guBBhDpuRK5JQNjkKmL62ajkpDQqa8 M7cFgL/KpytGB7Zv83zROcF21oUdNHW5aeva+uZexIBjwGHv9xfoyXfN/91vjQl8 Nzv4OJ4wm51npBs2OavxWmRE6hG4+/eYf0gUNSp4o0330yxd5YAoF6+lZXaOxqFr 1qEQvLwr9AW6MNwTwntyBeSAgOx/r/LYR6uU2K3imawLcGeAlR25hK0/AKtDzNmG uJyAucm5lUPkNy9KhiF8Xr712b9Voc4PFwSJ9paT8z/yJiC8SANfnNl055i6nwCd ht4yc//zSPNZHI7+Vysa+trxViI2Ot/6HfrIeIFWpLpXe4Q1ZTcigFSvH1+lYJVJ W85oZhHA/hNMQaw4DW8jbHWryIxg6X3UHTNH7uhDGxWEkVa8qJ42z56+TbVCkaug 8VXDNqahDA2cl07tgQSBBK48akLG5pV4ib9oGXobZojcsvvPV16DBkMMqfML1mjw 09O4bq3JG+hcr+xrI4jPPlvKJ3imv4QBd9yTBCbdapBtdgEwmTq6wmVY6iZHT0vO HN9SzyJ+cN3cYxPv6+q3Xc+qhv6INhNZo7j3ZW6/4b+SvsLCJz7+V5r5yh8zcNk1 5nrGAFkUTPcMqI/y0Yef =aUh2 -----END PGP SIGNATURE-----