-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Tue, 19 Jul 2011 22:21:04 +1000 Source: opie Binary: opie-client opie-server libopie-dev Architecture: kfreebsd-amd64 Version: 2.32.dfsg.1-0.2+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: kfreebsd-amd64 Build Daemon (fano) Changed-By: Steffen Joeris Description: libopie-dev - OPIE library development files. opie-client - OPIE programs for generating OTPs on client machines opie-server - OPIE programs for maintaining an OTP key file Closes: 631344 631345 Changes: opie (2.32.dfsg.1-0.2+squeeze1) stable-security; urgency=high . * Non-maintainer upload by the security team * Fix off-by-one and privilege escalation via missing check for setuid() (Closes: #631344, #631345) Fixes: CVE-2011-2489 CVE-2011-2490 Checksums-Sha1: ac9e45afac2ba6fe169dc87b5ec94ea8bc039fca 43900 opie-client_2.32.dfsg.1-0.2+squeeze1_kfreebsd-amd64.deb 6fcf71ae61f813fa13f9ecf7b4e3c7f9ead793c9 46958 opie-server_2.32.dfsg.1-0.2+squeeze1_kfreebsd-amd64.deb 7bd933d8ed15003f3e88654dfa842a89a6bcc407 32262 libopie-dev_2.32.dfsg.1-0.2+squeeze1_kfreebsd-amd64.deb Checksums-Sha256: cd272812e2882e6726427592493eaf2b504eecdeebb7940887b8aa361438813f 43900 opie-client_2.32.dfsg.1-0.2+squeeze1_kfreebsd-amd64.deb 6d761fd969bf3067fd02f71c5527f3a7f25413849210987ce32ad694e5f6e3ae 46958 opie-server_2.32.dfsg.1-0.2+squeeze1_kfreebsd-amd64.deb 587b2993c68bf632c0ad9fe4f9371bb03a2e06d81f7fddc63e84c5d0ac3b7c79 32262 libopie-dev_2.32.dfsg.1-0.2+squeeze1_kfreebsd-amd64.deb Files: 4ef124ef4feece700d474daa5eda3374 43900 admin optional opie-client_2.32.dfsg.1-0.2+squeeze1_kfreebsd-amd64.deb 7e3b74fbda33979a2d5afeba0ebe0acd 46958 admin optional opie-server_2.32.dfsg.1-0.2+squeeze1_kfreebsd-amd64.deb a5ecc64425561d86f53d8a2c083534c2 32262 devel optional libopie-dev_2.32.dfsg.1-0.2+squeeze1_kfreebsd-amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/kFreeBSD) iQIcBAEBAgAGBQJOJfT5AAoJELNpU9eREWlmjxIP/0oujw1XTw+4vIdVO3qsNJ+C S097wZGASVMbMp6UUxsEVwQu+jDyhRwHS/ky7JmBbLZnDIqes9khwjM4tlqhfdUq rAHCbmDeZICEX7MnXaT6wlvVoS+8wa9xDf7SQHGTKPBD7nTs3qFqrTLX2To9nnXu ZgLq+OmOnnE/VkrKdbPJCZqKsQSiKEL8s5n5aPhUFduKVS1XlnxMurzj4GmWAOll joyuC+IpXVKXviOLIJSEClxjIu2tB4bV//6pAQFCUt6dx8HD0Lc2dEeYXExLgsn9 IcSlfzNTisw/Y0GBHvtKXhkGXM8WXUsZqAY2+pZmG/Rog/fKn7PPmW1nPEbtbGdl keqQMVmrD2QHGY2DVNQ1fvJnaypmhh78Ktfe66GxBm19j4ZOP8ef/RhursPndoCR Ry1JMigqWYpT5H6x3ai4oqaXQLQXB4XssC24kWqitOpJ6c+vLl7SmS6L0DJSVbhi DjMRl1VhQyT3n8whdFQWx+uyxxW9yBXW8Y8e3DfS94wPyg1J+bXuYZzgWwILguES id3u0402fXDtNpYlbQCUQ9jDoPkySK8zzjOzuMbA2JWlckZYCZDFKVqlEMXolmJ9 3RRcE1nm+Eg9NSznVizWrZ2w0Hif5GjY1ZAkXDjOJvq9WZMPzwvco++OpoVCDHCP 01XFgyVDA8ybOzjzYuyH =bwvs -----END PGP SIGNATURE-----