-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 28 Aug 2013 00:40:42 +0100 Source: nas Binary: libaudio2 nas libaudio-dev nas-bin nas-doc Architecture: i386 Version: 1.9.3-5wheezy1 Distribution: wheezy-security Urgency: high Maintainer: amd64 / i386 Build Daemon (brahms) Changed-By: Steve McIntyre <93sam@debian.org> Description: libaudio-dev - Network Audio System - development files libaudio2 - Network Audio System - shared libraries nas - Network Audio System - local server nas-bin - Network Audio System - client binaries nas-doc - Network Audio System - extra documentation Closes: 720287 Changes: nas (1.9.3-5wheezy1) stable-security; urgency=high . * Fixes for various long-standing security issues found by Hamid Zamani . Closes: #720287 + Validate the port offset of nasd to fix a potential buffer overflow (CVE-2013-4256) + Use better string functions to guard against heap overflows (CVE-2013-4257) + Sanity-check the TCP_DEVICE environment variable to remove a format string bug (CVE-2013-4258) Checksums-Sha1: ec8e05abbfda1a4a9821299c15e7d8ef69b5c0b2 118078 nas_1.9.3-5wheezy1_i386.deb 84f7542a34e5b70f52444c21b70e09857fa72aef 178770 nas-bin_1.9.3-5wheezy1_i386.deb 720a0017a7e3ef5d1012935f152a111be552dc92 86992 libaudio2_1.9.3-5wheezy1_i386.deb 514c51ff9fc326c6ff6627c2c5a71a860bfa48b2 569106 libaudio-dev_1.9.3-5wheezy1_i386.deb Checksums-Sha256: 9cb083c3f810f01f43823159b5a7755b57a258e77306573cf2f3e983ed8fd691 118078 nas_1.9.3-5wheezy1_i386.deb 94bd466196c5bdf15952291d8769b1ce8942e536fdf7f0a552ea0d0ab33292ac 178770 nas-bin_1.9.3-5wheezy1_i386.deb 73a2c10fd2d1ea42b15f5c0b3d894f83489bc8dea839d2e4ade5f6bfb01447f5 86992 libaudio2_1.9.3-5wheezy1_i386.deb 7783e51783e5e0e6922fd0c1bd32a961d5be9903784638335c33b62272f9fa3a 569106 libaudio-dev_1.9.3-5wheezy1_i386.deb Files: 04e00fc697f00e57321ee26381bdaea2 118078 sound optional nas_1.9.3-5wheezy1_i386.deb b616414f05ba44347ddd701d08a8bf9c 178770 sound extra nas-bin_1.9.3-5wheezy1_i386.deb f4853142b36ee1e30289bae4757d874a 86992 libs optional libaudio2_1.9.3-5wheezy1_i386.deb 806f1113504ff6020e05d992c8127ffc 569106 libdevel optional libaudio-dev_1.9.3-5wheezy1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCAAGBQJSVFYuAAoJEK1hQZE4PeNyPlcP/2z7PugpucS3YPyJI2Pbx6J4 pClrRgwkwS8QIfNdpT23fwA1l4Z8HxrwY4l03Vz+2rxYyik3S1+tnSqksjsxs2xQ PaQbAuawhTprcORFF0i3c/S+Vt/pQ5nYdQmIFZJ9q00zZCwDqqCDBRpTNi5hgSYR A8UvSiwytkPcQuhWeTq6+Ip1yfUTrvnvduhs5TQQzb2ROIypbSeyDb619FfXT2B0 NllqUuVqPAkJiNftRB0s5CXkJPyLG0JWbTLvrBAH0bcde3CQD6dNautFbbEcbihR KUuI89QtyWacIm3SrET2xLbpvWnUIdSq5pCByFJQmDDLwsBwMgRG5FuuEZEIOflU OwBdSqVfvj62WLfkFxXb7dN/wJXf3G+fhDl3OKVLpJCfehGV9ODyuQQKACqv4S6W R6HlGDaIIB91oKLqZqw+e3ufBWht4JnrMp4NGpZuFHuTFeo//SDLWgBh1JkWnXts cdLPpFZZCpDIBVqeBr2gY3/U9j3jnA66kqjRlO9nhVMAKxw7KfY1GsMDJqgY8prV MsVNU3tzVLc4NZ1GqMSBdU/0jZt5uJ7vqtS3rD/cB+nPHrOSC1QQIhnllTfENLSG kwg5V8Qb9IeKfpA9CcnT+j76FnZR+55JK4qgf8Hrmm7nZtVPnmsG2UvShPHrhIQ8 X3PUxBxJcn1D6xwTBcIg =KL2s -----END PGP SIGNATURE-----