-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 19 Jul 2011 22:21:04 +1000 Source: opie Binary: opie-client opie-server libopie-dev Architecture: sparc Version: 2.32.dfsg.1-0.2+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: sparc Build Daemon (schroeder) Changed-By: Steffen Joeris Description: libopie-dev - OPIE library development files. opie-client - OPIE programs for generating OTPs on client machines opie-server - OPIE programs for maintaining an OTP key file Closes: 631344 631345 Changes: opie (2.32.dfsg.1-0.2+squeeze1) stable-security; urgency=high . * Non-maintainer upload by the security team * Fix off-by-one and privilege escalation via missing check for setuid() (Closes: #631344, #631345) Fixes: CVE-2011-2489 CVE-2011-2490 Checksums-Sha1: 28621b0cfa903f38b121ea151dcafc09b2ebe6f4 44192 opie-client_2.32.dfsg.1-0.2+squeeze1_sparc.deb 92b7f7535d022cb4df782a316b2f090c2db726f2 46252 opie-server_2.32.dfsg.1-0.2+squeeze1_sparc.deb ee95223dd067ed2ddd5e747df1e5cce7b74f7f01 30534 libopie-dev_2.32.dfsg.1-0.2+squeeze1_sparc.deb Checksums-Sha256: 05a8f4428a71172dff08d152356ab24874bfa5f9efc4073d54f6709837a60350 44192 opie-client_2.32.dfsg.1-0.2+squeeze1_sparc.deb afdaf73b669ca5030b4cd4e2d888381806286fe406977cb34ac5e5e0d30fc6d9 46252 opie-server_2.32.dfsg.1-0.2+squeeze1_sparc.deb 8eb009320c324d931d70924e141aa3ec6dc9dd7cbc7ef9579746c8310a785f03 30534 libopie-dev_2.32.dfsg.1-0.2+squeeze1_sparc.deb Files: eb10cbedf3d81c234162284df6f7db1a 44192 admin optional opie-client_2.32.dfsg.1-0.2+squeeze1_sparc.deb 86e80b6ec18e465c602cbcd3733f2534 46252 admin optional opie-server_2.32.dfsg.1-0.2+squeeze1_sparc.deb 197fe874c590a38336ef712fba542177 30534 devel optional libopie-dev_2.32.dfsg.1-0.2+squeeze1_sparc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJOJfSBAAoJEIrxMlmbu2eKOQQP/03uUrKet2nZmbN9kkROUg2b ISE8yDPNLYJ9VhdQt5nc9jE6D20U2F1I28D+KgMJEwj7u+rhBJalTB5z3G+Yzaau duvP4CDuoHVOyPmDq8VHfSmiU3ovoqhC9m8yYGZnZgP5gBw/PeYlitLWdqTjEw2D ZNNI5NkWHSK3euB45Tt+sddRV6JarrFAx6EP0CSiB9b1LYMq8lFOj02XhZfPDFoE GUhqGuL/ZoJJrULl7ine1kYJnxLEFRoUDnOJZOYWz7WkNQo6li+Js8of6pO1cBGH D4bif9qNlK/SxApo1/PR5siDOfsWVFFgLlXqtrZ9hB7v0p15YFcC8IGbVIpv5sKD La0zQuvQWTgX0aPicAbOqJXNGuUCUgJ0VM3c8Y6VwNdNI2dvOqdnYDgnRq05iaxA J+DXoCfE0AWLOzyGjh3i3kCjticAaCUs0s91J6b+SEzf4RKxrrPzKlNUUxX8dm9T 7PV+NMsCzyoEq/5+rmLC2XP9tCJ7BFLRAu0OKAKMupqj1DTnMGHBOJlm2kCPSOCx R+ox5LsYO/qwXjyVdyTl7pVBZye0Mo+X7Kjt5oefjLt1Cqh8LndmTDi9jA0NFwdc vFtWHPNmosZYpDwt0ZzSvUjxT6qbUhKHzqxfvG1oiuh45gZ3SJa789KygeIAT+ui hgk9lOjhCMza20U8NbWk =JNrP -----END PGP SIGNATURE-----