-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Debian Security Advisory DSA 997-1 security@xxxxxxxxxx http://www.debian.org/security/ Martin Schulze March 13th, 2006 http://www.debian.org/security/faq - -------------------------------------------------------------------------- Package : bomberclone Vulnerability : buffer overflows Problem type : remote Debian-specific: no CVE ID : CVE-2006-0460 BugTraq ID : 16697 Stefan Cornelius of Gentoo Security discovered that bomberclone, a free Bomberman-like game, crashes when receiving overly long error packets, which may also allow remote attackers to execute arbitrary code. The old stable distribution (woody) does not contain bomberclone packages. For the stable distribution (sarge) these problems have been fixed in version 0.11.5-1sarge1. For the unstable distribution (sid) these problems have been fixed in version 0.11.6.2-1. We recommend that you upgrade your bomberclone package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5-1sarge1.dsc Size/MD5 checksum: 668 e59985e92646e66e09f0c904cc777e82 http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5-1sarge1.diff.gz Size/MD5 checksum: 6985 a9d9696db932b11774b839d2b765fd31 http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5.orig.tar.gz Size/MD5 checksum: 7985803 cd2834d68980dd506038db44728cd2b1 Architecture independent components: http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone-data_0.11.5-1sarge1_all.deb Size/MD5 checksum: 7586908 c869506540ddfc25d3c452f32350d4ff Alpha architecture: http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5-1sarge1_alpha.deb Size/MD5 checksum: 128338 d97db6f509a94124fab9e20cdcabb2a4 AMD64 architecture: http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5-1sarge1_amd64.deb Size/MD5 checksum: 114644 827f5f7850204fd2166a34258f17a71d ARM architecture: http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5-1sarge1_arm.deb Size/MD5 checksum: 117114 3e0cf308c1cb3a93a032eddfb7331f9c Intel IA-32 architecture: http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5-1sarge1_i386.deb Size/MD5 checksum: 95614 626662760c83f79e2119e7e896970d4f Intel IA-64 architecture: http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5-1sarge1_ia64.deb Size/MD5 checksum: 171882 ed2ef72266943a1cc789f3b6f0ba7358 HP Precision architecture: http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5-1sarge1_hppa.deb Size/MD5 checksum: 107690 383b107de7545ced60bb5afa38b4ed92 Motorola 680x0 architecture: http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5-1sarge1_m68k.deb Size/MD5 checksum: 94488 32dc2741532866a837e1a6c8d7909b06 Big endian MIPS architecture: http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5-1sarge1_mips.deb Size/MD5 checksum: 116202 e8c5cb65dfcfd70ffe8b6320188a6728 Little endian MIPS architecture: http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5-1sarge1_mipsel.deb Size/MD5 checksum: 116026 29263ffcbf426c911e0b3d8a034a9b92 PowerPC architecture: http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5-1sarge1_powerpc.deb Size/MD5 checksum: 101888 0813f5ce3091cb8b7d482221c6b0a98f IBM S/390 architecture: http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5-1sarge1_s390.deb Size/MD5 checksum: 113050 b5298b8a579f76f1fd0751a64f2835d3 Sun Sparc architecture: http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone_0.11.5-1sarge1_sparc.deb Size/MD5 checksum: 102884 72313829a57423a10dd1d200775c9f0d These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main Mailing list: debian-security-announce@xxxxxxxxxxxxxxxx Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFEFcdlW5ql+IAeqTIRAv2nAKCcFsy64p2WGrw8Fid/KfyAOgUfJgCgimSn HrZvaLmB7XzuuTgqPdvwLpg= =jegp -----END PGP SIGNATURE-----