exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

debian.canna.txt

debian.canna.txt
Posted Jul 4, 2000
Site debian.org

Debian Security Advisory - The canna package as distributed in Debian GNU/Linux 2.1 can be remotely exploited to gain access. This could be done by overflowing a buffer by sending a SR_INIT command with a very long usernamd or groupname.

tags | overflow
systems | linux, debian
SHA-256 | be478a463b446020b571954efb53fbf74e2093f37d872dee19a68560f2f3dee7

debian.canna.txt

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----

- ------------------------------------------------------------------------
Debian Security Advisory security@debian.org
http://www.debian.org/security/ Wichert Akkerman
July 2, 2000
- ------------------------------------------------------------------------


Package : canna
Problem type : remote exploit
Debian-specific: no

The canna package as distributed in Debian GNU/Linux 2.1 can be
remotely exploited to gain access. This could be done by overflowing
a buffer by sending a SR_INIT command with a very long usernamd or
groupname.

This has been fixed in version 3.5b2-24slink1, and recommend that you
upgrade your canna package immediately.

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

Debian GNU/Linux 2.1 alias slink
- --------------------------------

This version of Debian was released only for Intel, the Motorola
680x0, the alpha and the Sun sparc architecture.

The packages for the Sun sparc architecture are not available at
this moment; they will be announced on http://security.debian.org/
when they are.

Source archives:
http://security.debian.org/dists/stable/updates/source/canna_3.5b2-24slink1.diff.gz
MD5 checksum: 7220bdad24aa3be2fdfc4f1bfd978235
http://security.debian.org/dists/stable/updates/source/canna_3.5b2-24slink1.dsc
MD5 checksum: b62f0558dc852ed61930157236622e3d
http://security.debian.org/dists/stable/updates/source/canna_3.5b2.orig.tar.gz
MD5 checksum: 5e1d8527d397c3914ce6104dac3db466

Alpha architecture:
http://security.debian.org/dists/stable/updates/binary-alpha/canna-utils_3.5b2-24slink1_alpha.deb
MD5 checksum: b9318bb7dcb1936c3d16c54f8c799564
http://security.debian.org/dists/stable/updates/binary-alpha/canna_3.5b2-24slink1_alpha.deb
MD5 checksum: 1bcbbd1c4ad3146d66b2ca10b4914ccf
http://security.debian.org/dists/stable/updates/binary-alpha/libcanna1g-dev_3.5b2-24slink1_alpha.deb
MD5 checksum: 05df65c96e2adfc6d1cde593ef76ca33
http://security.debian.org/dists/stable/updates/binary-alpha/libcanna1g_3.5b2-24slink1_alpha.deb
MD5 checksum: b1e30d11faaccbf0014c42e56949c87c

Intel ia32 architecture:
http://security.debian.org/dists/stable/updates/binary-i386/canna-utils_3.5b2-24slink1_i386.deb
MD5 checksum: 45705fd8a8d230d3dd0094707eb2fac3
http://security.debian.org/dists/stable/updates/binary-i386/canna_3.5b2-24slink1_i386.deb
MD5 checksum: c15a54507be2fc745d55718efbae4f74

Motorola 680x0 architecture:
http://security.debian.org/dists/stable/updates/binary-m68k/canna-utils_3.5b2-24slink1_m68k.deb
MD5 checksum: aa0ef7ffe8ca29a99ba882513dd29888
http://security.debian.org/dists/stable/updates/binary-m68k/canna_3.5b2-24slink1_m68k.deb
MD5 checksum: 4069ed58591b44a5c670fd0a91e77ae1
http://security.debian.org/dists/stable/updates/binary-m68k/libcanna1g-dev_3.5b2-24slink1_m68k.deb
MD5 checksum: 005a4f8f6dbdafc1f1ccdc8443ddc8ad
http://security.debian.org/dists/stable/updates/binary-m68k/libcanna1g_3.5b2-24slink1_m68k.deb
MD5 checksum: 5aff2c0b7b089900faff113ce8a0abab


These files will be moved into
ftp://ftp.debian.org/debian/dists/stable/*/binary-$arch/ soon.

Debian GNU/Linux 2.2 alias potato
- ---------------------------------

Please note that potato has not been released yet. However since it is in
the final stages of the release process security updates are already being
distributed.

The updated packages for potato have already been installed in the
archive.

For not yet released architectures please refer to the appropriate
directory ftp://ftp.debian.org/debian/dists/sid/binary-$arch/ .

- --
- ----------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable updates
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates
Mailing list: debian-security-announce@lists.debian.org

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv

iQB1AwUBOV9E7qjZR/ntlUftAQFv5QL9H3s/REAWPFBBj8XsAIQNUOWoqD3LhSXt
csdcD5gKmeV8QKsZsvmS819cq3IW7nF+ORJjgpNzKKkd0fRE1/9io1POqu5CjbAP
h82uUG1LRWMD9z/YY80wDtbzNuXQYygh
=ZphM
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-security-announce-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close