-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 28 Aug 2013 00:40:42 +0100 Source: nas Binary: libaudio2 nas libaudio-dev nas-bin nas-doc Architecture: s390 Version: 1.9.3-5wheezy1 Distribution: wheezy-security Urgency: high Maintainer: s390/s390x Build Daemon (zandonai) Changed-By: Steve McIntyre <93sam@debian.org> Description: libaudio-dev - Network Audio System - development files libaudio2 - Network Audio System - shared libraries nas - Network Audio System - local server nas-bin - Network Audio System - client binaries nas-doc - Network Audio System - extra documentation Closes: 720287 Changes: nas (1.9.3-5wheezy1) stable-security; urgency=high . * Fixes for various long-standing security issues found by Hamid Zamani . Closes: #720287 + Validate the port offset of nasd to fix a potential buffer overflow (CVE-2013-4256) + Use better string functions to guard against heap overflows (CVE-2013-4257) + Sanity-check the TCP_DEVICE environment variable to remove a format string bug (CVE-2013-4258) Checksums-Sha1: 7b26181995baa401712532c060e327875357c14b 121368 nas_1.9.3-5wheezy1_s390.deb d21453cb509acd7d6491a9bfd6f314fd14bef2c3 185258 nas-bin_1.9.3-5wheezy1_s390.deb 6fa66b1541d408d799b8f4e5ffb26630395f06ee 88450 libaudio2_1.9.3-5wheezy1_s390.deb ac5c64f69961b4f2d9ce877daec163bc5e15fe7f 624310 libaudio-dev_1.9.3-5wheezy1_s390.deb Checksums-Sha256: 29cb9a6d6e882c89eab237d6cb2260c8262eb95c54db140c23925750cbedc294 121368 nas_1.9.3-5wheezy1_s390.deb 242a7c8a796eed91cb19f868a4a984973823bf6f54b415220b4af1d1fe1dce18 185258 nas-bin_1.9.3-5wheezy1_s390.deb d68d6cf35cbb9ec8c1c78c16762ddc0b1692e5c2a2bd4a073f202325ae459f2e 88450 libaudio2_1.9.3-5wheezy1_s390.deb 33f7a96a236224ccb50f4d2038fb7187ad61109ec592035ff8c2ffee7d02326c 624310 libaudio-dev_1.9.3-5wheezy1_s390.deb Files: 1d1850335cdcd165239f61cbf0756bb9 121368 sound optional nas_1.9.3-5wheezy1_s390.deb 9b40425e61b03d6df0a3d5c085d08bdd 185258 sound extra nas-bin_1.9.3-5wheezy1_s390.deb 9349143cfc13bffdb1769fc351f887fe 88450 libs optional libaudio2_1.9.3-5wheezy1_s390.deb dea8450eae43bcf1dae76a5cb79acff3 624310 libdevel optional libaudio-dev_1.9.3-5wheezy1_s390.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJSVFXdAAoJEMD/Scu25lHQSvwP/jhwDpw/XnsZqHpU15gyfO3X p5Pjh7v0ckUmzST/EZHn8C48cHlOxZxH8fkwEpIKkzSIPrA1YJJYyO9q5Zx4iY7Z ioLu5Yd20CVK2EyMuefXu6xZXgqMKkRhiRYAnXoMCwg2OgJymn0oE6Lr+MMfPAd0 KjexYqpapLe8AMiDj2sEgIsXkTICKPPYqwdi7wxS4WwYRF3wweOd8zIF715tMCLj 7/3qc+oGtrq2oTZMK60EpZspDvLrL+xYHVbvR9KhL0VXypBwBfZGdlRwDUgbnQ23 FGrqJMwTYD/p7oT83gQlXUE9LjegOG+zzkd49QaedmElIy+fKGM/MtapKC1XRWg8 qAFKjg9QUa//KiFqS4YwxExzEUX+ODnQVh7Xj8aNRnXqwpBytu2BDyHRg4NAXjkJ 7mKvOt6ABS2iZYuMK3nbv6hzoZbUZH9KePaXQa7+KUg7LQW7qBC1C96uD3NdHPW+ ivOtr+jqDnLh3J3VcNdT3ZaUvsXyODsnSeL5Pa7G29buSFP50wzvTvqqqsyXOaz1 imm/OLzJr3S/y2MQe0/aynmesQomD9dYCyN3sgG6BdugaTpiCnUNAezJzF2CQGxx q9pOzxA2x0rI/nLW5qk4a/zBE/WoeaweYT8zbhRNGnxAzkYfYQbfp7IQuJ/CDhcp x5196KTKlZhmRfjzlst8 =cUE3 -----END PGP SIGNATURE-----