-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 28 Aug 2013 00:40:42 +0100 Source: nas Binary: libaudio2 nas libaudio-dev nas-bin nas-doc Architecture: s390x Version: 1.9.3-5wheezy1 Distribution: wheezy-security Urgency: high Maintainer: s390/s390x Build Daemon (zandonai) Changed-By: Steve McIntyre <93sam@debian.org> Description: libaudio-dev - Network Audio System - development files libaudio2 - Network Audio System - shared libraries nas - Network Audio System - local server nas-bin - Network Audio System - client binaries nas-doc - Network Audio System - extra documentation Closes: 720287 Changes: nas (1.9.3-5wheezy1) stable-security; urgency=high . * Fixes for various long-standing security issues found by Hamid Zamani . Closes: #720287 + Validate the port offset of nasd to fix a potential buffer overflow (CVE-2013-4256) + Use better string functions to guard against heap overflows (CVE-2013-4257) + Sanity-check the TCP_DEVICE environment variable to remove a format string bug (CVE-2013-4258) Checksums-Sha1: ba6616139a116372be6aa19ac1f9b70de85be660 124096 nas_1.9.3-5wheezy1_s390x.deb f162d77c12ce6518a9f9e439d324686353138bfa 191062 nas-bin_1.9.3-5wheezy1_s390x.deb 7ccc4a32bd02fc5ff57b3063564854b273036cb1 88894 libaudio2_1.9.3-5wheezy1_s390x.deb c622886efe55cf672fc6a2ab8fe24249c4aaea6e 722072 libaudio-dev_1.9.3-5wheezy1_s390x.deb Checksums-Sha256: 9cbb54a926902f1d6a3a1290d45cda8c24cb13b14c2f7dd3bc02a6fedb3340a9 124096 nas_1.9.3-5wheezy1_s390x.deb 83bf9aed26d5ccd58ffdf5268b7a5237f19047e091baa2b206c16f369de18e59 191062 nas-bin_1.9.3-5wheezy1_s390x.deb f220552e13057d763f251686feb76510eafe647aded1ea6a227ac87972e2d41d 88894 libaudio2_1.9.3-5wheezy1_s390x.deb 6fbf8c0853c105cbbe689336aa82e989bb7d863a30da341dfa5db21749c51b48 722072 libaudio-dev_1.9.3-5wheezy1_s390x.deb Files: 2a48da3bdbd786008dafbca599affb85 124096 sound optional nas_1.9.3-5wheezy1_s390x.deb 3a131ebeb327d5b57eaec73261e13011 191062 sound extra nas-bin_1.9.3-5wheezy1_s390x.deb 5f2107ac2a2eeb07d05cff2c09c65146 88894 libs optional libaudio2_1.9.3-5wheezy1_s390x.deb 47d675ec787e3d0199e9f6df81d00d07 722072 libdevel optional libaudio-dev_1.9.3-5wheezy1_s390x.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJSVFWZAAoJEA0sFBQG2rC+WJ4P/jaDWnOf6uXR0qfiXcg4NN17 TYt/6dCFb82IZyuyEHwEqsCohHdht9xVA91f8rBMIN2l15ZXyQhKykFhAlhHW6Zh 0IJHglZrEyllyKKgRJyIar6IB3TxXOFZPAmaNdulgdi3XErnOzrh1GB1Lz+0eqEK /+axFzjlrxWT/sM6uMtJbEhEmD309cT551iM56PBz2ZYhdCFDol8963nXNiDMD3I kHfrGRwy4of7ywoLL33uMQd1Cn2uHW5P9kTZ6NJ57S0NWSGctUDPODDB6CMjmDnU qSn0pvW1d1/dNZQaFHeLaHxAABpjPWGXLsMPbzNYQ+Zbbi8YvsbELU9pnhyd7gA/ sVta12osQYyoZFTbmnoJUdCjQY9Yy/6RtKQWGcqGpdqi3LtsGOW6quK2Qn+c0ses eFq3k/KN9CfmGQFhL9vdxXk3COobPjk3so8qctHktsRU/eoDbgOd0Fi9zfb+EBlB 4Wvd01nQjq/toaU0Oos3wGsyL3YjypSGXFhNnqBYGy5FY0COMzrw5mHN4STb7nGD 6JLF7RB6c0eX7zsx23duAwEOGtheumTM0MSgvXkTT5unGlEUaVJooeirIKJ+ISAn 9HRAwho1ich/udlffn7P6KTHkjj8wqERlBkfs+OldEVdnsRJrQxBYALIFtQKruCb 5dosaIokqllGjQAC/DRD =liF5 -----END PGP SIGNATURE-----