-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 19 Jul 2011 22:21:04 +1000 Source: opie Binary: opie-client opie-server libopie-dev Architecture: i386 Version: 2.32.dfsg.1-0.2+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: i386 Build Daemon Changed-By: Steffen Joeris Description: libopie-dev - OPIE library development files. opie-client - OPIE programs for generating OTPs on client machines opie-server - OPIE programs for maintaining an OTP key file Closes: 631344 631345 Changes: opie (2.32.dfsg.1-0.2+squeeze1) stable-security; urgency=high . * Non-maintainer upload by the security team * Fix off-by-one and privilege escalation via missing check for setuid() (Closes: #631344, #631345) Fixes: CVE-2011-2489 CVE-2011-2490 Checksums-Sha1: 6aa471bc63669eedf5cc5d773f31ff9783d72f58 43448 opie-client_2.32.dfsg.1-0.2+squeeze1_i386.deb 55c2f9c911e5c76df07c853805dbf901b763e486 45084 opie-server_2.32.dfsg.1-0.2+squeeze1_i386.deb 1aabe2dc89ef4acac38671aa8fbeb568379d159d 30624 libopie-dev_2.32.dfsg.1-0.2+squeeze1_i386.deb Checksums-Sha256: 1f972d9a6b4fbdca903413935f2a48951a6dccca37a341001e28a020d450e276 43448 opie-client_2.32.dfsg.1-0.2+squeeze1_i386.deb 44f12309f0cd4a8e17c2f84ec7320b819fffae2fd1a88fd0db1fa78d5e25bc54 45084 opie-server_2.32.dfsg.1-0.2+squeeze1_i386.deb e8917aeed7955c16894982a0aad26af01080ae66f648a87ace72a79c7ce2c2ec 30624 libopie-dev_2.32.dfsg.1-0.2+squeeze1_i386.deb Files: ab02468626ad7ff13bb5995f183197f6 43448 admin optional opie-client_2.32.dfsg.1-0.2+squeeze1_i386.deb ee7a5d3a5be7011198a0a31a969226e5 45084 admin optional opie-server_2.32.dfsg.1-0.2+squeeze1_i386.deb c0cca9b7f458937c5fbad5501b7ca82f 30624 devel optional libopie-dev_2.32.dfsg.1-0.2+squeeze1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJOJfR1AAoJEHY75GREw+rHPS4P/3LZydGjpWCqfDgS7I4HcUpq /S7EdJNAVKVH91qwML5bRqFb7RiTsWrrt5K98XTF6KwrpnVQ98UEr/anXareEkUI yyxSQCbW8nR/ImilaJIFsQ4UbKQvJS/0VRyLcxLPy9uTLCa+VjKlB0CBGewGhAkV YGqa+5gh19Ksnt2L9nvoyIryHkHQ/3ItkJuuLLqHY6k24sAN4x8uLi8cku2Aw5Nm yej3ZxoucMn+JMz4RIl9m8Yl8+BPkN+XIrDUdpwI/zY4rCMgwewMkrfCWOCfzZE3 1RyaFyFuLcwKJgTNKrwBS7B534hsSVB5Ea6mp7CkrMuJzrjzi1gBQIqz1uNaXdXX dBSUVuy+7HxzpQ8x7Wda3/P4i7CUJU86m0SAEwK+Hoo6v5JpgfH5PCN3o+GOF1e/ XQERWfnQnQk50humh8KvsaBnyg9tbFeoJN7KIt8FOyeAOAQCm7XEibaqB4QO+S+G diW3VE/UZby5FEraNiMyQla8W/m0gPl8x0p2TVIgWgSD+T8XwBVa158JU0zWR+Qv tvRjOo42FBA68X9K+Nnq1R/5u3tgPTg9FEzBx4rX5wFCUs6u6+DVbw17Bop4+XZS 161qfxgfvkbIT+ZQNcWCLT8XpSDEAAsLdPLR5XVO3AO7IUDqr4jW8bo+xEqWfXNl vzKSvOjcXl5gcgeXBuZX =ToW3 -----END PGP SIGNATURE-----