-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 19 Jul 2011 22:21:04 +1000 Source: opie Binary: opie-client opie-server libopie-dev Architecture: armel Version: 2.32.dfsg.1-0.2+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: armel Build Daemon (antheil) Changed-By: Steffen Joeris Description: libopie-dev - OPIE library development files. opie-client - OPIE programs for generating OTPs on client machines opie-server - OPIE programs for maintaining an OTP key file Closes: 631344 631345 Changes: opie (2.32.dfsg.1-0.2+squeeze1) stable-security; urgency=high . * Non-maintainer upload by the security team * Fix off-by-one and privilege escalation via missing check for setuid() (Closes: #631344, #631345) Fixes: CVE-2011-2489 CVE-2011-2490 Checksums-Sha1: 7c5835269cd07d9916fdc510acf9d77d5b9dbf2d 43748 opie-client_2.32.dfsg.1-0.2+squeeze1_armel.deb f5f294cf3bf1333a33f14241775bd0cbe25dda1b 45272 opie-server_2.32.dfsg.1-0.2+squeeze1_armel.deb 343e96cbdedb42b9e6b52020d51448ab8296242a 30890 libopie-dev_2.32.dfsg.1-0.2+squeeze1_armel.deb Checksums-Sha256: 910d2114ae53720ccfc872961d3d62a4e2cc97f67eb92931f430d58c8d1abfa5 43748 opie-client_2.32.dfsg.1-0.2+squeeze1_armel.deb 77f85017c1cca59df05277ea15f0499acfa1885e6109d52e319f339f574c9aef 45272 opie-server_2.32.dfsg.1-0.2+squeeze1_armel.deb 59022a6324bcdced84bf1c3773d52ea99a6e10e3b8cd288f5296ab03de785f7f 30890 libopie-dev_2.32.dfsg.1-0.2+squeeze1_armel.deb Files: e39c58b1940426605ad495468d06e84d 43748 admin optional opie-client_2.32.dfsg.1-0.2+squeeze1_armel.deb b8a51a06838381225ac899717679ccb3 45272 admin optional opie-server_2.32.dfsg.1-0.2+squeeze1_armel.deb 23ac86e08aeea016504276adbda9f7e4 30890 devel optional libopie-dev_2.32.dfsg.1-0.2+squeeze1_armel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQIcBAEBCAAGBQJOJfcCAAoJEJm1mXdcYikhgLMP/3hbmMEUBPIDbxIylkrS4QVk WtT7moYtKqErIXssMsHPK7kSovmm4PYkI0ANCYlt4ZOM69nJQYCzdc5OdMlTnDzR mw7D6iOto/esVU6sjb30h11d9SFw6fESkU2CSJGyRdF6L+OtPEUJzpkGJXo1LOWR Wa5y+wd5tm0xNchfMT8cbXfsvrBm5VjYf/Q5BWivH899K7x98+kV3Ay0LDVU5m/P jQ0LRDOs8rcmW6pe8eaxkYxgAqfqUXukE2IfIR6hc6DxbQ2CqjBKizAfivlOg6KX lHmvImns0E+jSK7X1PMbG0SjgTQsXTrulkQe1YQMjEnlojw9eOXdg2qfyDXEfaVC w59ZO1Me9FqZLallDEPCGxSHRavclznQEBFMZtIzbaufem72/FetUUQe3yD6IF/J SK757c7ZcJ/5cK1UHR50nh2mgc1nrkhrCQmupnnhhBY43hah2kvZUPw+UaQsT2vA YY4AhdVTF6PbRvHF7CUWoPuJL3hxkgCYIxhjYIAgCu+OGxlGHZYNF3/+k75aBmiL mgx3tD8tqY5CtJsxZCCEJBUX8gEKH8/g7Lh5ljDZa+XLBI8Kf3Xemhvw5u8+kNDc 0UeoBojBXESOUYwVNbsSSeH+GhIXJ9i6fsvbpyE+WnhBljC5roMDJMZi/FdUcSmA ek/AW5aQ2DyAqdgFd2e2 =4QLl -----END PGP SIGNATURE-----