-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 28 Aug 2013 00:40:42 +0100 Source: nas Binary: libaudio2 nas libaudio-dev nas-bin nas-doc Architecture: kfreebsd-amd64 Version: 1.9.3-5wheezy1 Distribution: wheezy-security Urgency: high Maintainer: kfreebsd-amd64 Build Daemon (fano) Changed-By: Steve McIntyre <93sam@debian.org> Description: libaudio-dev - Network Audio System - development files libaudio2 - Network Audio System - shared libraries nas - Network Audio System - local server nas-bin - Network Audio System - client binaries nas-doc - Network Audio System - extra documentation Closes: 720287 Changes: nas (1.9.3-5wheezy1) stable-security; urgency=high . * Fixes for various long-standing security issues found by Hamid Zamani . Closes: #720287 + Validate the port offset of nasd to fix a potential buffer overflow (CVE-2013-4256) + Use better string functions to guard against heap overflows (CVE-2013-4257) + Sanity-check the TCP_DEVICE environment variable to remove a format string bug (CVE-2013-4258) Checksums-Sha1: d7041559eb4349facd3d70d9f93c00e750d7acdf 120450 nas_1.9.3-5wheezy1_kfreebsd-amd64.deb 6230342e7f637c042ede675bffb77a0931c99378 182496 nas-bin_1.9.3-5wheezy1_kfreebsd-amd64.deb 37283d1c4e237bd95069b6364e29334e106cfd7f 87152 libaudio2_1.9.3-5wheezy1_kfreebsd-amd64.deb db90479d6138d42ad3e7b72decc0c264682bb553 610948 libaudio-dev_1.9.3-5wheezy1_kfreebsd-amd64.deb Checksums-Sha256: 81d6a7edc9bb29d7e95863f17cb747058ec916f9b942b5bfdea8be9af7e440d8 120450 nas_1.9.3-5wheezy1_kfreebsd-amd64.deb 223e90a55d43342936232c4d002d907d1b5cd4b528d7c739a1e73bc64f754dcb 182496 nas-bin_1.9.3-5wheezy1_kfreebsd-amd64.deb 490b7a63e5c0428a625e5532574d18161b6995682afd40c040966091d0d7ae27 87152 libaudio2_1.9.3-5wheezy1_kfreebsd-amd64.deb 741b619d04d0e2e915a28eceb6dfab23873b09041fd8416c82c0ee995f6360ce 610948 libaudio-dev_1.9.3-5wheezy1_kfreebsd-amd64.deb Files: ba2a320e8ea7e26722960ea27401e4f8 120450 sound optional nas_1.9.3-5wheezy1_kfreebsd-amd64.deb 1bcd58bfe997daa53dd077d320c126af 182496 sound extra nas-bin_1.9.3-5wheezy1_kfreebsd-amd64.deb 95602863d88c145a51999103d24c1069 87152 libs optional libaudio2_1.9.3-5wheezy1_kfreebsd-amd64.deb 0640184b58ea71358de701789e2771de 610948 libdevel optional libaudio-dev_1.9.3-5wheezy1_kfreebsd-amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/kFreeBSD) iQIcBAEBAgAGBQJSVFZgAAoJEPf9aZobCECdvmcP/0emNvyyzRZMxZe7iH5P5QM9 h+AdnnkT9ph8pnClnVqTvesA2gKpiDeZr+/f5rrGVcSb0epK3VfTgcx+rk2nWP1r 2v5d3tCyKbIKxo/Hrf6NtBlRjaOXKhqaWDtMiMVJVGmmQmxS//D8j27km+1DXc4M oY+1JqM1ZU2r8AExPXW2pTbQL4784Y5sjkiC4xlEuCds7JNztMm9q7WbUXT3U3Ly 1APn1MQY3zYH5e9uPfQSFlynuSQAd29ODVEVnDpAmsWc2BeGHz79ujhknkq8QpEZ WCLEfNY4vHoxVhQeGldjdwRJ0vmn9debng96HAUiBm5rWt7X0f3oXr1BnViNGTyC xiEpuGCuCXzwd+uCrSQcmqZq6Xkylzpas6eRng7mZ5OZ+15OCNbstUqd/6fB6nPH RCuMejlujAvqwywCr0gxQgUZ59rz1BiscWbiMYDx4zu+Q8l+tNlgvpucfmvSrtg4 Iikqkj9mXHucd2TrYi6CSjBZk5wbWlnBQTLwjwdD+t/g61HfJquDDgN07BAJCcQz fDWZ2TDnHgcMi6srJ+pZfci9A5pTAOE2c2gVTWgTjHtR4V9WlCdle9TI+NKKI+uS a97cMs6HrLK+gC3PcaWovPT3cE382B/vPqazBADSRwpfZ4kxXoX50D4MsiXfkvbV yRQJxORcBurc74EZuozv =3yi3 -----END PGP SIGNATURE-----