-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 28 Aug 2013 00:40:42 +0100 Source: nas Binary: libaudio2 nas libaudio-dev nas-bin nas-doc Architecture: mipsel Version: 1.9.3-5wheezy1 Distribution: wheezy-security Urgency: high Maintainer: mipsel Build Daemon (eysler) Changed-By: Steve McIntyre <93sam@debian.org> Description: libaudio-dev - Network Audio System - development files libaudio2 - Network Audio System - shared libraries nas - Network Audio System - local server nas-bin - Network Audio System - client binaries nas-doc - Network Audio System - extra documentation Closes: 720287 Changes: nas (1.9.3-5wheezy1) stable-security; urgency=high . * Fixes for various long-standing security issues found by Hamid Zamani . Closes: #720287 + Validate the port offset of nasd to fix a potential buffer overflow (CVE-2013-4256) + Use better string functions to guard against heap overflows (CVE-2013-4257) + Sanity-check the TCP_DEVICE environment variable to remove a format string bug (CVE-2013-4258) Checksums-Sha1: 287b66a0ccae8dacc60fa0a43c2c1bb735eb2499 117442 nas_1.9.3-5wheezy1_mipsel.deb 156ddc8a8e5939c0a39111bd183d1258b2fec051 176290 nas-bin_1.9.3-5wheezy1_mipsel.deb 23199c05fb5aad58f6ce2ec844ca8d759679317e 82328 libaudio2_1.9.3-5wheezy1_mipsel.deb 535cdd52ae0e0a6bbd06b0c8a5e44e328815d50b 545076 libaudio-dev_1.9.3-5wheezy1_mipsel.deb Checksums-Sha256: 8b9c4fa71cd1e46111695b502bb69cb42f582b021a6ec003008e0574a33e7878 117442 nas_1.9.3-5wheezy1_mipsel.deb 7871c7348c66f1b749b42c812ec191f3e1d655103b13264e757676550730325e 176290 nas-bin_1.9.3-5wheezy1_mipsel.deb 49217454caaf82e2a05dde66cda7298500515b3dff82c91d17352198c7e21a89 82328 libaudio2_1.9.3-5wheezy1_mipsel.deb ec0b64c0fe94d89d3103648fe5dfe9d15d6a56dd4b91b5a319c65cae1f47fe73 545076 libaudio-dev_1.9.3-5wheezy1_mipsel.deb Files: da85f25f9e05c48408a64db4de3d0fd3 117442 sound optional nas_1.9.3-5wheezy1_mipsel.deb 551937cce760b5ae16e22541393f0d1d 176290 sound extra nas-bin_1.9.3-5wheezy1_mipsel.deb ce97064b2973d108c4a1517940ccd172 82328 libs optional libaudio2_1.9.3-5wheezy1_mipsel.deb 825b4a76b04c753137faf33ba129a194 545076 libdevel optional libaudio-dev_1.9.3-5wheezy1_mipsel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBAgAGBQJSVFlsAAoJEFv65QRu5sfCB8EP/RG/EK+HnK/nK3aTU3UbJvcH M/7Gv+XeuseRVEP6O49GpiHwkGdtjrS6RhXv3Vv+r07ICm5WH0XdwHa+eYPRxtXe OFhy/BzmmkNCG3jTt/8EE7qpOF6lGXLeuuYVYEgSaz3BdtyYKNRt8uiatTfLGRnZ GxLH4Dn59QphGnnCHl3dKJQjsFQrrQwmulq+DKi49sXWL2ti3a7VBzik8OZ62xYK kgxazvVZI4bYaGBsnoQoxQn2LP4qElfYjVoUXXhwf7nFb7RhTkwTmagaRgjrQqVd gGyZ8okwp6UUP3UlQXooaJPQGG2wCobgeCOG5cA8+VdF3DcGPdFf03WsyAfXwzgN 171ROgyEu/sS/CLCKLPTewrNEZW7SbFlnJwOSB8iU5jvrkGSXQPrtI5e1lSg8V6R zTZJCB1ipc6gtV/9Dvaxb1hiFMDNImTp3gsEjdbB3SzW2NaHhFeY+Yv3Zi2KSeTf u6jkR/Ddt6HmOEotxL84Wz2VlJEuRhaisFrwxOPGA4GdFQJXnYFUXvlut26jjXt3 AQAkfkdVU3m2yiengXIOKyTfbHcAjvtcfX3aIPdhnHokVE3P6dq8DEySjWTlYqen k9HM7jGZFuTRIQPzHtWshSyTuxNMIgI4FOxelg5PfXNiumUon1dgO9++Psf/9WkN WgDC2lpgciCmLGUoYcPC =bjZD -----END PGP SIGNATURE-----