-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 28 Aug 2013 00:40:42 +0100 Source: nas Binary: libaudio2 nas libaudio-dev nas-bin nas-doc Architecture: sparc Version: 1.9.3-5wheezy1 Distribution: wheezy-security Urgency: high Maintainer: sparc Build Daemon (schroeder) Changed-By: Steve McIntyre <93sam@debian.org> Description: libaudio-dev - Network Audio System - development files libaudio2 - Network Audio System - shared libraries nas - Network Audio System - local server nas-bin - Network Audio System - client binaries nas-doc - Network Audio System - extra documentation Closes: 720287 Changes: nas (1.9.3-5wheezy1) stable-security; urgency=high . * Fixes for various long-standing security issues found by Hamid Zamani . Closes: #720287 + Validate the port offset of nasd to fix a potential buffer overflow (CVE-2013-4256) + Use better string functions to guard against heap overflows (CVE-2013-4257) + Sanity-check the TCP_DEVICE environment variable to remove a format string bug (CVE-2013-4258) Checksums-Sha1: be8af09466b078b2cf6705fc36cb7df083026251 114640 nas_1.9.3-5wheezy1_sparc.deb 7e050d386d3907923480d7ceb73c402aaad9aa2a 170646 nas-bin_1.9.3-5wheezy1_sparc.deb 928d7910060b647408d0b2f4c16efe9016375b1d 79722 libaudio2_1.9.3-5wheezy1_sparc.deb 8c93845849ed46c2e75ea39d67efb3189663590f 538536 libaudio-dev_1.9.3-5wheezy1_sparc.deb Checksums-Sha256: b0a28bb8dbfc7b82ce9973d0f560a45502ec2a0689330d1ec98f073fd1b95870 114640 nas_1.9.3-5wheezy1_sparc.deb f157df5024130fd746ccda52d94e2741f05ff3a698af4311950dc4c58ee19c32 170646 nas-bin_1.9.3-5wheezy1_sparc.deb 5014aecbe2c70706a2f9e0cd5feda1b192e679ec7be42dffe97b3340c525bf09 79722 libaudio2_1.9.3-5wheezy1_sparc.deb 4f6f320c01199cc9c61b215f4ae1734d512fb83e84f3a6855008852fd8a11a2f 538536 libaudio-dev_1.9.3-5wheezy1_sparc.deb Files: 876100ad86726f5eaa5f5b77ab87da42 114640 sound optional nas_1.9.3-5wheezy1_sparc.deb 6702e13df1e889a5ed6a32c42d8f5f63 170646 sound extra nas-bin_1.9.3-5wheezy1_sparc.deb 7c311865a2d708a9c388bf92cad49fee 79722 libs optional libaudio2_1.9.3-5wheezy1_sparc.deb 378a64c720fcf6142e2409e0670d917f 538536 libdevel optional libaudio-dev_1.9.3-5wheezy1_sparc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCAAGBQJSVFZzAAoJEH9+c0mzZmMyj04P+wcGIMolBssCq/ZGrkmOUId7 0hlNBSkQrrVNlT5/qaMG2IbImoUjrqjkUllNWIhH1ja9nD1A8YYSGWYLPNUoFcS8 hj6iDPSRTytneBSXrOGv+iAruya6Zml4v6LBOwj0BMnDxAE9+h3BZffNtAnxHci2 z67z79A7vElvfc2KIIs1oaoqRRaWr3QobC9qF87U4jqDrIdgSsm7DWIYiSBDD4YA uUQJGN8NzMJ/cMLdjVjD6P/V7vAnJfyaQkDITD2jX06d4rT+LqL2AVv1zBXZab2P bpmxlbERWqVCusbaoEipJHneV2ODD0xmc02GNbDbVVBHpYPWTfq+gzzcntUqxREZ onWNHs0JgxCqFQUqF74y6XM32z6Fcv2QnOD9XckIfTQUfZfeFdjrvX3YYWof525v GSwWG1IneQCzJLwFZSl3VtfwYiR96enc/b4hStTIQgMsXX6YOUrR7U5TdnmUuggq vRcCCsCF3wtRsqm1DReAJaE2GUf1rpuB84lNQOy9KC92BJ6qZnpFpigwrqkeMobC 0j4E7pwGeZ7RkmxCkBc91WyamoilEsejKAL1OmGg4SyNOKf6v1SDLcJXr7cxQUoJ Y4/xiXDwTMy0Ou9qxntaH0Ik8ly98PhaCCwogICjL9rbFHQgxtQ2aVdSXfrwIVtU KXmtN4z0ZBBeqCRc5PP2 =cAhB -----END PGP SIGNATURE-----