-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 19 Jul 2011 22:21:04 +1000 Source: opie Binary: opie-client opie-server libopie-dev Architecture: mipsel Version: 2.32.dfsg.1-0.2+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: mipsel Build Daemon (mayer) Changed-By: Steffen Joeris Description: libopie-dev - OPIE library development files. opie-client - OPIE programs for generating OTPs on client machines opie-server - OPIE programs for maintaining an OTP key file Closes: 631344 631345 Changes: opie (2.32.dfsg.1-0.2+squeeze1) stable-security; urgency=high . * Non-maintainer upload by the security team * Fix off-by-one and privilege escalation via missing check for setuid() (Closes: #631344, #631345) Fixes: CVE-2011-2489 CVE-2011-2490 Checksums-Sha1: a8a6165b1d26ab408a60b1ed667e4f5814b98acd 44722 opie-client_2.32.dfsg.1-0.2+squeeze1_mipsel.deb 1f89b75603802b2b5a4ffde36acf000672cb3d99 47598 opie-server_2.32.dfsg.1-0.2+squeeze1_mipsel.deb dec38e39c43c3ff66698b9fba2ec2217bb3326a8 33520 libopie-dev_2.32.dfsg.1-0.2+squeeze1_mipsel.deb Checksums-Sha256: 47a87805475acf7b8912d8b27bdb77e20e35dba549e602531b0b8b1db9e88a9f 44722 opie-client_2.32.dfsg.1-0.2+squeeze1_mipsel.deb a868504161899528f8ccc53ef70ac40bf14853608249cc748890f0dca116c439 47598 opie-server_2.32.dfsg.1-0.2+squeeze1_mipsel.deb 4575059935b0198c5b947f5219c5901af3993ddbbe6c6070f27c365104faf84b 33520 libopie-dev_2.32.dfsg.1-0.2+squeeze1_mipsel.deb Files: 1351044eb43feb03331c3a34a0aa085f 44722 admin optional opie-client_2.32.dfsg.1-0.2+squeeze1_mipsel.deb be5df29c7a0d579bbbf6ceeed13da8d1 47598 admin optional opie-server_2.32.dfsg.1-0.2+squeeze1_mipsel.deb 0cc247026c2fdf1b5c34eaa3d5cde9ad 33520 devel optional libopie-dev_2.32.dfsg.1-0.2+squeeze1_mipsel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQIcBAEBCAAGBQJOJgB9AAoJEGebSaJo0bAiLaMQAIq78go7b/gSgJ/BcISD3tg6 hfhhnJsRuI+g3DI4rWL103WfZBifFPUmU+2QofWaLMPOb/ooqrgSYMTNFEqCb0+S kNlnTJzdfwhskJIYSrRPmMF50toGlU68VEdm1tqr5Pb+1wC+viiNiWXt+bQJOqrI C1JmC8ko44jzHw2u/9ev8icdtyAkoGtV+/U43QzzX+OrxgvAgtgVXLR43Oiz0Jek LnpOiXIUa96NwCgAUhkN5qwTqdhLZbBV8rGqwZak0bPZ1tZmiW1teTgbYUJ1o7n/ qyxVcz69Qwaq6JC7gcgkjdtZLFUQiAQaiK8J9eESqf5frEaehfOFjwNkdzLdtMuo O09Jzf1Z0CdLiPUmoAls9n9j7ev5jwbQ4NTbxu77Atn0S57Y6jWLvm+7MrLNom/o y6Xo0GKtt+p/BoCHc74VSyY0RNqWxlml4RhiwDbhThis0zh4vDq+2u41bmm7fNLK 8L5fhdhydcqq37WKrJnni00wxU+oszAV7v8n/hX1X0XRv5py3nP6Wc19TXGf8C3U x1EW3Cig8yElaUwwvjkpjKt2iBEEaUHx/YgFplk4vafI3RMo1vGBQE0C8gBNL8lA pt0d+Qy0LsNMKtE3Rch2NuFf9YiqrbMatQIBp4XZS70c65yU63+dZRdpoR0H8Peh htFIdS3YbVA1RUyNVxZE =oSAn -----END PGP SIGNATURE-----