Home · Compatibility Lists · Support Forums · FAQ · News Archive · Articles · Submit News/Upcoming News
Linux Compatible
advertisement


USN-663-1: system-tools-backends regression
Posted by Bob on: 2008-11-05 19:25:01 [ Print | Permalink ]

A new system-tools-backends regression update is available for Ubuntu Linux. Here the announcement:

"Ubuntu Security Notice USN-663-1 November 05, 2008
system-tools-backends regression
https://launchpad.net/bugs/287134
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 8.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.10:
system-tools-backends 2.6.0-1ubuntu1.1

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

It was discovered that passwords changed (or new users created) via the
"Users and Groups" tool were created with 3DES hashing. This reduced the
security of stored user passwords, and was a regression from the correct
MD5 hashing. This update fixes the problem; future password changes
will correct the hashing used. We apologize for the inconvenience.


Updated packages for Ubuntu 8.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/s/system-tools-backends/system-tools-backends_2.6.0-1ubuntu1.1.diff.gz
Size/MD5: 11981 0a9e19e908466dca073aafdbca052e10
http://security.ubuntu.com/ubuntu/pool/main/s/system-tools-backends/system-tools-backends_2.6.0-1ubuntu1.1.dsc
Size/MD5: 1585 cc8c71def106ad81fa59c45bae82790d
http://security.ubuntu.com/ubuntu/pool/main/s/system-tools-backends/system-tools-backends_2.6.0.orig.tar.gz
Size/MD5: 567711 913530493fa6cff6e797f4c888641d42

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/s/system-tools-backends/system-tools-backends-dev_2.6.0-1ubuntu1.1_all.deb
Size/MD5: 14022 b1ba12e53953c0ee1449a8605232fabb

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/s/system-tools-backends/system-tools-backends_2.6.0-1ubuntu1.1_amd64.deb
Size/MD5: 113012 89e50d2b48202e6e5b4c2da8b06dff1c

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/s/system-tools-backends/system-tools-backends_2.6.0-1ubuntu1.1_i386.deb
Size/MD5: 111786 f4f2c2a8808320cde6b1ee8105550dec

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/main/s/system-tools-backends/system-tools-backends_2.6.0-1ubuntu1.1_lpia.deb
Size/MD5: 111740 23882632c5460e7afbc3e04c6782c8dc

powerpc architecture (Apple Macintosh G3/G4/G5):

http://ports.ubuntu.com/pool/main/s/system-tools-backends/system-tools-backends_2.6.0-1ubuntu1.1_powerpc.deb
Size/MD5: 114390 1fcb07972e510878a1cb8668efb26f5b

sparc architecture (Sun SPARC/UltraSPARC):

http://ports.ubuntu.com/pool/main/s/system-tools-backends/system-tools-backends_2.6.0-1ubuntu1.1_sparc.deb
Size/MD5: 112456 6e27917fa2fa9371f518e9f04cc34c6d


--PW0Eas8rCkcu1VkF
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Kees Cook <kees@outflux.net>

iEYEARECAAYFAkkR48wACgkQH/9LqRcGPm1p+wCeNXYWtTq13w5bnFhXPS/M+iZ2
N2gAoJL1YfNbqv7yGXEByX6uL3mAbfqT
=fl9p
-----END PGP SIGNATURE-----
"

Digg it! Slashdot Del.icio.us Technorati Fark it! Binklist Furl Newsvine Windows Live Netscape Google Bookmarks Reddit! LinkaGoGo Tailrank Wink Dzone Simpy Spurl Yahoo! MyWeb NetVouz RawSugar Smarking Scuttle Magnolia BlogMarks Nowpublic FeedMeLinks Wists Onlywire Connotia Shadows Co.mments
News Source: Ubuntu Security Team

Post New Comment


All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2009 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Website powered by Esselbach Storyteller CMS System