Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· OCZ Vertex 450 SSD Reviews and more
· Proxmox VE 3.0 released
· More Windows 8.1 features discovered in WinRT?
· New Colors Rumored for iPhone 5S and Lower-Cost iPhone, Dual LED Flash for iPhone 5S?
· NVIDIA GeForce 320.18 WHQL Drivers
· 20 Debian Updates
· OCZ Vertex 450 Series Solid State Drives announced
· NVIDIA GeForce GTX 780 Reviews Roundup
· Apple's 'iWatch' to come in late 2014 with focus on biometrics, analyst says
· Windows 8.1 laptops with AMDs new chips to support wireless display

Upcoming News
· A Futurelooks News Flash - An Affordable Titan – N?= VIDIA’s GEFORCE GTX 780 Reviewed
· News: AMD's A4-5000 'Kabini' APU reviewed
· Wine release 1.5.31
· NVIDIA GeForce Chips Comparison Table @ Hardware Secrets
· Resident Evil Revelations Video Review with Kaeyi Dream @ HardwareHeaven.com
· [security-announce] openSUSE-SU-2013:0825-1: important: MozillaFirefox: update to version 21.0
· [security-announce] SUSE-SU-2013:0819-2: critical: Security update for Linux kernel
· Fractal Design Node 605 Silent HTPC Case Review @ Legit Reviews
· SevenTeam X6 Power Bank Review (smartphones/tablets)
· Case Mod Friday: Smokey Green Giant @ ThinkComputers.org

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6498 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 711 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4599 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 786 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1173 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » March 2006 » DSA 1012-1: New unzip packages fix arbitrary code execution

DSA 1012-1: New unzip packages fix arbitrary code execution

Posted by Bob on: 03/21/2006 09:42 AM [ Print | 0 comment(s) ]

The Debian Security Team published a new security update for Debian GNU/Linux. Here the announcement:




-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 1012-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
March 21st, 2006 http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package : unzip
Vulnerability : buffer overflow
Problem type : local (remote)
Debian-specific: no
CVE ID : CVE-2005-4667
CERT advisory :
BugTraq ID : 15968
Debian Bug : 349794.

A buffer overflow in the command line argument parsing has been
discovered in unzip, the de-archiver for ZIP files that could lead to
the execution of arbitrary code.

For the old stable distribution (woody) this problem has been fixed in
version 5.50-1woody6.

For the stable distribution (sarge) this problem has been fixed in
version 5.52-1sarge4.

For the unstable distribution (sid) this problem has been fixed in
version 5.52-7.

We recommend that you upgrade your unzip package.


Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody
- --------------------------------

Source archives:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6.dsc
Size/MD5 checksum: 571 cc14465fbe413ef3a7f5c5d9ffc117ce
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6.diff.gz
Size/MD5 checksum: 7373 6964744843adce4de0913f5ff9a0e710
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50.orig.tar.gz
Size/MD5 checksum: 1068379 6d27bcdf9b51d0ad0f78161d0f99582e

Alpha architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_alpha.deb
Size/MD5 checksum: 160670 5314de93efaf4eb391d151fc99b76385

ARM architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_arm.deb
Size/MD5 checksum: 139532 52ce821cdbeb1055acf4000adcbecf10

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_i386.deb
Size/MD5 checksum: 122950 783758b4c93d0be1c2aad7b2cf41a4a4

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_ia64.deb
Size/MD5 checksum: 191146 90a66edf48109c217d9da2615a99e32a

HP Precision architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_hppa.deb
Size/MD5 checksum: 147126 4b49f39b4fe4142716df95c08f61a66b

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_m68k.deb
Size/MD5 checksum: 119684 51c36fc99310866c4158b4962f80354f

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_mips.deb
Size/MD5 checksum: 143092 988785cbcb0ef2d656c82396b1a3d084

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_mipsel.deb
Size/MD5 checksum: 143534 6f4ee2d9bcadf4aef4dadaf16c270024

PowerPC architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_powerpc.deb
Size/MD5 checksum: 136544 41839b724b2f0f5faee98bb410b92015

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_s390.deb
Size/MD5 checksum: 137202 e55b19543ea9b5526daf45506e07a373

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_sparc.deb
Size/MD5 checksum: 147670 9e0bcfaa072cf09b67b3af6361b6941c


Debian GNU/Linux 3.1 alias sarge
- --------------------------------

Source archives:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4.dsc
Size/MD5 checksum: 528 fa94e70012ca87d3c47a32cc1a5ee8d1
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4.diff.gz
Size/MD5 checksum: 5970 d90c45ee99376216714a74619e9dd241
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52.orig.tar.gz
Size/MD5 checksum: 1140291 9d23919999d6eac9217d1f41472034a9

Alpha architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_alpha.deb
Size/MD5 checksum: 175568 2c937f3342f888c177d14b508c5bcfc2

AMD64 architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_amd64.deb
Size/MD5 checksum: 154984 a4b1a683d280713aa81e19b2b2576894

ARM architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_arm.deb
Size/MD5 checksum: 155496 ae1fe7b4d009fa7cfb838e86e53c3017

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_i386.deb
Size/MD5 checksum: 145018 8e5def26db7c48b5c13374d8721c78f0

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_ia64.deb
Size/MD5 checksum: 206712 72bccff65305290aeb40a548ee134b72

HP Precision architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_hppa.deb
Size/MD5 checksum: 162914 4e946c0b5fbdb669f9b4dcc7b04dcffa

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_m68k.deb
Size/MD5 checksum: 133792 5cb71bb725b0f0e12b14103ad31832d2

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_mips.deb
Size/MD5 checksum: 163458 c11e854b0131f93c9debf23b18e3e49a

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_mipsel.deb
Size/MD5 checksum: 164040 049471a42b402971801375b6bc40825a

PowerPC architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_powerpc.deb
Size/MD5 checksum: 157426 d717ec6573055c17931206906dc8b580

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_s390.deb
Size/MD5 checksum: 156594 6e200ece0aa56e8c67958568e43ea33c

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_sparc.deb
Size/MD5 checksum: 155024 ebba4fa2a38e5be774a06288860a4757


These files will probably be moved into the stable distribution on
its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show lt;pkggt;' and http://packages.debian.org/lt;pkggt;

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)

iD8DBQFEH7gxW5ql+IAeqTIRAjLJAJ9oEqOnyW2zSratMQbPszTx8+PPkACghnYe
9Br+3LC2nrRifCxVyH6Oox4=
=I8b7
-----END PGP SIGNATURE-----


Bookmark and Share

« Get Microsoft Visual Studio 2005 Standard Edition for free · SUSE Security Announcement: xorg-x11-server local privilege escalation (SUSE-SA:2006:016) »

Linux Compatible » News » March 2006 » DSA 1012-1: New unzip packages fix arbitrary code execution
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition