Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Libreoffice 4.0.3 released and PPA installation instructions included
· MySQL 5.5.31 for Debian Squeeze
· Gigabyte Intel Z87 Motherboard Lineup Preview and more
· Microsoft to roll out Xbox dashboard UI alterations before next-gen console
· Adobe Photoshop Express now available for Windows 8 and RT
· GNOME 3.8.2 Released
· Windows 8 is an enterprise 'non-starter' because IT sees no value in changes
· What to Expect from Unity in Ubuntu 13.10
· Analysts praise Nokia's new Lumia 925
· Best Business Laptops - May 2013 and more

Upcoming News
· Sumo Lounge Emperor
· Gigabyte Intel Z87 Motherboard Lineup Preview
· [ANNOUNCE] libchamplain 0.12.4
· [security-announce] SUSE-SU-2013:0810-1: important: Security update for oracle-update
· [security-announce] SUSE-SU-2013:0811-1: important: Security update for oracle-update
· [security-announce] SUSE-SU-2013:0809-1: important: Security update for Acrobat Reader
· Rosewill RDEE-12002 USB 3.0 Hard Drive Enclosure @ techPowerUp
· ASUS M5A97 R2.0 Motherboard @ Hardware Secrets
· Samsung Galaxy S4 Smartphone Review @ HardwareHeaven.com
· [RHSA-2013:0832-01] Important: kernel security update

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6288 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 627 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4478 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 690 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1077 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » May 2004 » DSA 507-1: New cadaver packages fix buffer overflow

DSA 507-1: New cadaver packages fix buffer overflow

Posted by Philipp Esselbach on: 05/19/2004 10:29 AM [ Print | 0 comment(s) ]

New cadaver packages has been released for Debian GNU/Linux

---------------------------------------------------------------------------
Debian Security Advisory DSA 507-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
May 19th, 2004 http://www.debian.org/security/faq
---------------------------------------------------------------------------

Package : cadaver
Vulnerability : buffer overflow
Problem-Type : remote
Debian-specific: no
CVE ID : CAN-2004-0398

Stefan Esser discovered a problem in neon, an HTTP and WebDAV client library, which is also present in cadaver, a command-line client for WebDAV server. User input is copied into variables not large enough for all cases. This can lead to an overflow of a static heap variable.

For the stable distribution (woody) this problem has been fixed in version 0.18.0-1woody3.

For the unstable distribution (sid) this problem has been fixed in version 0.22.1-3.

We recommend that you upgrade your cadaver package.




Upgrade Instructions
---------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody
---------------------------------

Source archives:

http://security.debian.org/pool/updates/main/c/cadaver/cadaver_0.18.0-1woody3.dsc
Size/MD5 checksum: 668 cc085f1e27ca315d3443c7e536c9b349
http://security.debian.org/pool/updates/main/c/cadaver/cadaver_0.18.0-1woody3.diff.gz
Size/MD5 checksum: 1674 d60b429cc57107856ffd180f3cb2836f
http://security.debian.org/pool/updates/main/c/cadaver/cadaver_0.18.0.orig.tar.gz
Size/MD5 checksum: 405643 40fc8cf38c71b2f74692a91ba891845b

Alpha architecture:

http://security.debian.org/pool/updates/main/c/cadaver/cadaver_0.18.0-1woody3_alpha.deb
Size/MD5 checksum: 102242 3b45e150425b73405453f03c2e45f63b

ARM architecture:

http://security.debian.org/pool/updates/main/c/cadaver/cadaver_0.18.0-1woody3_arm.deb
Size/MD5 checksum: 83448 1a8f45defcd34ef51b3cb678e3106d27

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/c/cadaver/cadaver_0.18.0-1woody3_i386.deb
Size/MD5 checksum: 81472 e5476b51ea6efbcff662258effdfd5ee

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/c/cadaver/cadaver_0.18.0-1woody3_ia64.deb
Size/MD5 checksum: 125782 7b7dbd87a96e73ef3116c22c406d4bbb

HP Precision architecture:

http://security.debian.org/pool/updates/main/c/cadaver/cadaver_0.18.0-1woody3_hppa.deb
Size/MD5 checksum: 96250 f37a834f4a1cb9e80d36e50188e1bddf

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/c/cadaver/cadaver_0.18.0-1woody3_m68k.deb
Size/MD5 checksum: 77522 c1c630fba52ac06d9e54a35d31922fb6

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/c/cadaver/cadaver_0.18.0-1woody3_mips.deb
Size/MD5 checksum: 95090 e74a612892d09b1e80fdc2129497bc6a

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/c/cadaver/cadaver_0.18.0-1woody3_mipsel.deb
Size/MD5 checksum: 94924 51eae2cf3b195cb7f25ec7b685bf18d2

PowerPC architecture:

http://security.debian.org/pool/updates/main/c/cadaver/cadaver_0.18.0-1woody3_powerpc.deb
Size/MD5 checksum: 87566 43894c27a77b6e5e64224aec283f1a39

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/c/cadaver/cadaver_0.18.0-1woody3_s390.deb
Size/MD5 checksum: 84718 3787dd1d00c5b415822b3ec9763bbec9

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/c/cadaver/cadaver_0.18.0-1woody3_sparc.deb
Size/MD5 checksum: 84288 13421f421d7a8f712b7047d6d69de01c


These files will probably be moved into the stable distribution on its next update.


Bookmark and Share

« GLSA 200405-09: ProFTPD · Shuttle SN85G4V2 Review »

Linux Compatible » News » May 2004 » DSA 507-1: New cadaver packages fix buffer overflow
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition