-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Debian Security Advisory DSA 1365-2 security@xxxxxxxxxx http://www.debian.org/security/ Moritz Muehlenhoff September 9th, 2007 http://www.debian.org/security/faq - -------------------------------------------------------------------------- Package : id3lib3.8.3 Vulnerability : programming error Problem-Type : local Debian-specific: no CVE ID : CVE-2007-4460 Debian Bug : 438540 Nikolaus Schulz discovered that a programming error in id3lib, an ID3 Tag Library, may lead to denial of service through symlink attacks. This update to DSA 1365-2 provides fixes packages for the stable distribution (etch). We recommend that you upgrade your id3lib3.8.3 packages. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - ------------------------------- Source archives: http://security.debian.org/pool/updates/main/i/id3lib3.8.3/id3lib3.8.3_3.8.3-6etch1.dsc Size/MD5 checksum: 652 ada1a9d686cbfe925a34b2173227b47e http://security.debian.org/pool/updates/main/i/id3lib3.8.3/id3lib3.8.3_3.8.3-6etch1.diff.gz Size/MD5 checksum: 135226 495cb5f4610853f02a740e9b7c1a71c5 http://security.debian.org/pool/updates/main/i/id3lib3.8.3/id3lib3.8.3_3.8.3.orig.tar.gz Size/MD5 checksum: 950726 19f27ddd2dda4b2d26a559a4f0f402a7 Alpha architecture: http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3-dev_3.8.3-6etch1_alpha.deb Size/MD5 checksum: 341286 c074664c96375662596d490ce9e59e2f http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3c2a_3.8.3-6etch1_alpha.deb Size/MD5 checksum: 187286 a6cb95da944dfe5e1a28cbf5136f3b6f AMD64 architecture: http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3-dev_3.8.3-6etch1_amd64.deb Size/MD5 checksum: 283136 6fe99daa8aab3fd9549ab7d2db11aedc http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3c2a_3.8.3-6etch1_amd64.deb Size/MD5 checksum: 176214 e35c8545fe42ae16362144e23772735a ARM architecture: http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3-dev_3.8.3-6etch1_arm.deb Size/MD5 checksum: 277156 4f1e8102266eb7fe3f42dd613274c02a http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3c2a_3.8.3-6etch1_arm.deb Size/MD5 checksum: 179072 fa3c352ad012326b3753fa1b7b189eaf HP Precision architecture: http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3-dev_3.8.3-6etch1_hppa.deb Size/MD5 checksum: 305654 f9d69c8cdb5585e5b1dc3a9742b5edce http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3c2a_3.8.3-6etch1_hppa.deb Size/MD5 checksum: 196342 fa9087816b58d9ed207e25401906c64a Intel IA-32 architecture: http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3-dev_3.8.3-6etch1_i386.deb Size/MD5 checksum: 263064 6b7e0823707843fa76158a0e1ba7f42f http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3c2a_3.8.3-6etch1_i386.deb Size/MD5 checksum: 176662 05ca5942a44486b658a44e4bee16154d Intel IA-64 architecture: http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3-dev_3.8.3-6etch1_ia64.deb Size/MD5 checksum: 351960 6fd56a95a8aa66fa890a99a3264a7cbd http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3c2a_3.8.3-6etch1_ia64.deb Size/MD5 checksum: 202690 e1c25a15ff7a480cafd1ac5d95ea0083 Big endian MIPS architecture: http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3-dev_3.8.3-6etch1_mips.deb Size/MD5 checksum: 285984 576083197b0d3778f9963ff697f0dd6f http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3c2a_3.8.3-6etch1_mips.deb Size/MD5 checksum: 173660 221f900fe4f7bb66fc1cfdae380844c5 PowerPC architecture: http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3-dev_3.8.3-6etch1_powerpc.deb Size/MD5 checksum: 283208 8d6f0c3417ba62980ff80c5084ba0cad http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3c2a_3.8.3-6etch1_powerpc.deb Size/MD5 checksum: 176614 89b9c136ae81ebd9918420d7d6915c28 IBM S/390 architecture: http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3-dev_3.8.3-6etch1_s390.deb Size/MD5 checksum: 269674 d8dd6f6d7d76a46063c0723f974198da http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3c2a_3.8.3-6etch1_s390.deb Size/MD5 checksum: 177402 028a696232d95ddf67ae6acb7a3aac9c Sun Sparc architecture: http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3-dev_3.8.3-6etch1_sparc.deb Size/MD5 checksum: 251852 2356b2546559f20403987530357a68fc http://security.debian.org/pool/updates/main/i/id3lib3.8.3/libid3-3.8.3c2a_3.8.3-6etch1_sparc.deb Size/MD5 checksum: 176600 80690cceeeb56b25d0cd30381ee28ad4 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main Mailing list: debian-security-announce@xxxxxxxxxxxxxxxx Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFG5GVDXm3vHE4uyloRAovSAJ4iSCS/3RgjdjMcPF4qyaTzqPXBOwCdGYfZ cnQvDQcaDAQSQlk3j/WxSkw= =6zz7 -----END PGP SIGNATURE-----