-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 05 Jul 2011 12:01:35 -0400 Source: krb5-appl Binary: krb5-clients krb5-rsh-server krb5-ftpd krb5-telnetd Architecture: armel Version: 1:1.0.1-1.1 Distribution: squeeze-security Urgency: high Maintainer: armel Build Daemon (arnold) Changed-By: Sam Hartman Description: krb5-clients - Secure replacements for ftp, telnet and rsh using MIT Kerberos krb5-ftpd - Secure FTP server supporting MIT Kerberos krb5-rsh-server - Secure replacements for rshd and rlogind using MIT Kerberos krb5-telnetd - Secure telnet server supporting MIT Kerberos Changes: krb5-appl (1:1.0.1-1.1) stable-security; urgency=high . * cve-2011-1526, mit-sa-2011-005: Krb5 ftpd fails to set correct group permissions. The ftp daemon always runs with the group permissions of the user it is started as, probably the root group. Checksums-Sha1: 766ed85e182478e7021339355242e486b05cfb6c 157568 krb5-clients_1.0.1-1.1_armel.deb cdd562bcf9e685f5f6af2d4ad1087c638ca5fa7b 59102 krb5-rsh-server_1.0.1-1.1_armel.deb 229c992a88ab935e375a9d9f78966aaf9096aef2 43862 krb5-ftpd_1.0.1-1.1_armel.deb 8cf2af487986052410d0a3da4934022e0d1aae59 48408 krb5-telnetd_1.0.1-1.1_armel.deb Checksums-Sha256: 42a1d2b764ee42292152a226e0e5839325dff5a6fda78524b805ef546562c03d 157568 krb5-clients_1.0.1-1.1_armel.deb a309f8806f9efb2975fdf26668b1cf8689328f7ecd0a7f567d56ce1eadd6c8f7 59102 krb5-rsh-server_1.0.1-1.1_armel.deb 8c5042fab8b1ce335048361b016e693ddc5ddd5bfe9695c56ca250fa43292ef9 43862 krb5-ftpd_1.0.1-1.1_armel.deb 038ccf39e8df6d88ece0dfe4ed4c86e955d124734a303ce4e549cbac4395c3df 48408 krb5-telnetd_1.0.1-1.1_armel.deb Files: c4a104587190d82d99bf6236c9526f4d 157568 net optional krb5-clients_1.0.1-1.1_armel.deb 1b91fe40a3b30dd2a87b8920ca8f969e 59102 net extra krb5-rsh-server_1.0.1-1.1_armel.deb e883797405964f411e84b4453a2c8f85 43862 net extra krb5-ftpd_1.0.1-1.1_armel.deb a09f02c8ad8e4318bdd9f30e6ab192ee 48408 net extra krb5-telnetd_1.0.1-1.1_armel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iQIcBAEBCAAGBQJOjKUXAAoJEMXOXcLFQs1Z0fgP/jIdpKCdcxO5XYBdf4Se2iK7 DmjF2QElPav/EWXSo+HaLay/9xcj0GhQ6DfIBEMCmhcQdwfjUx9ymTB72GPHfOOC gujFFqvbPFISahBkdjXpAqZt1DOF6Bq9hUgG1cc+UEfO6fMKma+pCN3fQsHtnywd QwMe+fRq89xtdR3IVT3DECXNUZdj0MhPSzefjdR29b/F8knkCVLgR8wxvKJy1zQo PlryhiMqfmejRILk0T0QAnGMBj0H4q/esLWec2+FsxKaCJT3ut3thG6CMFYJlwd7 9HEhleJ6XwDr5DMp+X4l4qTRbR9Vhnb9DKL6qixqPlZMaIntRA8rrI3PoL+RcaiA v5BtSkl5BWljUqcgZQMhCXW+Trk7KQPszHJZ1MLpsajd7IWTErhl9PJ47VWIiNBr s/elvb6FX52P7gLaxVnwvG0dc5FblQXRPge4VyPNzZQx7YydUlj8iBMVOtd7FSuI T8fZvjGm235o83fBJLfhFJbnG6ev6wtJPDOMxSyAkj/Gd8GlWkx5rep/8gWB3iCe C/1MdluBbmNEWvO9FKC6vB9vHIZIy8YxNqK2Bh1D+o4NRCKBLzujNByUPntc2okm hiEkg8MC4B25zfQ6EG31oH9swoZpnZ5I4Izwr7bSZomXEBVh4fZpVbMABed0astT b4h2u+rnG2+tde1mafsE =s0SS -----END PGP SIGNATURE-----