-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                   ESB-2008.0352 -- [UNIX/Linux][Debian]
           New alsaplayer packages fix arbitrary code execution
                               7 April 2008

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              alsaplayer
Publisher:            Debian
Operating System:     Debian GNU/Linux 4.0
                      UNIX variants (UNIX, Linux, OSX)
Impact:               Execute Arbitrary Code/Commands
Access:               Remote/Unauthenticated
CVE Names:            CVE-2007-5301

Original Bulletin:    http://www.debian.org/security/2008/dsa-1538

Comment: This advisory references vulnerabilties in products which run on
         platforms other than Debian. It is recommended that administrators
         running alsaplayer check for an updated version of the software for
         their operating system.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - ------------------------------------------------------------------------
Debian Security Advisory DSA-1538-1                  security@debian.org
http://www.debian.org/security/                           Devin Carraway
April 04, 2008                        http://www.debian.org/security/faq
- - ------------------------------------------------------------------------

Package        : alsaplayer
Vulnerability  : buffer overrun
Problem type   : local (remote)
Debian-specific: no
CVE Id(s)      : CVE-2007-5301
Debian Bug     : 446034

Erik Sjölund discovered a buffer overflow vulnerability in the Ogg
Vorbis input plugin of the alsaplayer audio playback application.
Successful exploitation of this vulnerability through the opening of a
maliciously-crafted Vorbis file could lead to the execution of
arbitrary code.

For the stable distribution (etch), the problem has been fixed in
version 0.99.76-9+etch1.

For the unstable distribution (sid), the problem was fixed in version
0.99.80~rc4-1.

We recommend that you upgrade your alsaplayer packages.


Upgrade instructions
- - --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 4.0 alias etch
- - -------------------------------

Source archives:

  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer_0.99.76-9+etch1.dsc
    Size/MD5 checksum:     1411 f1cef8ce08af0bc84cc18f45bf54774b
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer_0.99.76-9+etch1.diff.gz
    Size/MD5 checksum:   179628 f2af0197803ce618482ecdc6c78b420e

alpha architecture (DEC Alpha)

  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-alsa_0.99.76-9+etch1_alpha.deb
    Size/MD5 checksum:    27560 e1b68d62513e27add20da78f6820b1f4
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-xosd_0.99.76-9+etch1_alpha.deb
    Size/MD5 checksum:    28082 c66cc4df7b809c81df49de084b462205
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-daemon_0.99.76-9+etch1_alpha.deb
    Size/MD5 checksum:    27270 6f75fda99af97920257383affe3c075f
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-jack_0.99.76-9+etch1_alpha.deb
    Size/MD5 checksum:    30272 46817a06719f8becbeb69b9359d4d91a
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-oss_0.99.76-9+etch1_alpha.deb
    Size/MD5 checksum:    25590 bb7c7149b6757eceb15357472bb4e2b6
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-common_0.99.76-9+etch1_alpha.deb
    Size/MD5 checksum:   195438 440ce88bb7f9a2d5b2a3e4bc0c35657b
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-esd_0.99.76-9+etch1_alpha.deb
    Size/MD5 checksum:    25420 4bc13bef3dab2646be6750fdd296358d
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-nas_0.99.76-9+etch1_alpha.deb
    Size/MD5 checksum:    27608 483288f19e1fe342240162cfa150a02d
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-gtk_0.99.76-9+etch1_alpha.deb
    Size/MD5 checksum:   137782 0b52ae9bc30a1314834e7ef5107f3659
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer0_0.99.76-9+etch1_alpha.deb
    Size/MD5 checksum:    31896 6f1227ba21196977efc12f41dfb30c0a
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer-dev_0.99.76-9+etch1_alpha.deb
    Size/MD5 checksum:    83198 edb8f259c9817a975f0d87f99108697f
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-text_0.99.76-9+etch1_alpha.deb
    Size/MD5 checksum:    28586 1af7443e262e60c7a38380124c2b488b

amd64 architecture (AMD x86_64 (AMD64))

  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-daemon_0.99.76-9+etch1_amd64.deb
    Size/MD5 checksum:    26924 a35d711c0e01c370415d59549b8a5f23
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-gtk_0.99.76-9+etch1_amd64.deb
    Size/MD5 checksum:   121774 4e04fcd7739a1905e48ba49fda0a807b
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-common_0.99.76-9+etch1_amd64.deb
    Size/MD5 checksum:   163868 8bef80d9dc227726d2f2024549265bd9
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-oss_0.99.76-9+etch1_amd64.deb
    Size/MD5 checksum:    25192 7157a8d0c576f791154d85d305d5ee4e
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-jack_0.99.76-9+etch1_amd64.deb
    Size/MD5 checksum:    28990 20a25a4f3fbb7635fc92f4bd3db34123
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-text_0.99.76-9+etch1_amd64.deb
    Size/MD5 checksum:    27816 3e7b0fd06c61fb07636e9a8ad4223925
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-xosd_0.99.76-9+etch1_amd64.deb
    Size/MD5 checksum:    27596 a030d22d8d0a04f5c944e4f1acd95ad0
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-alsa_0.99.76-9+etch1_amd64.deb
    Size/MD5 checksum:    26884 4e2f9a0a5570680075d8e723ded3af4d
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-nas_0.99.76-9+etch1_amd64.deb
    Size/MD5 checksum:    27050 f1e36292510e1c6800381c1687de72f2
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer0_0.99.76-9+etch1_amd64.deb
    Size/MD5 checksum:    31348 e2e95c3d77565abcb77fc3016ac94318
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer-dev_0.99.76-9+etch1_amd64.deb
    Size/MD5 checksum:    82202 47f4dd3eac22823b20eac1d5ac2a593c
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-esd_0.99.76-9+etch1_amd64.deb
    Size/MD5 checksum:    25118 ddea153c747bbac0286b2fe9708da9b4

arm architecture (ARM)

  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-text_0.99.76-9+etch1_arm.deb
    Size/MD5 checksum:    27736 86b887e84550c7288c773fc8a888dfb7
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-alsa_0.99.76-9+etch1_arm.deb
    Size/MD5 checksum:    26672 1dc88ad32d415f5a2c6624b69e7998ca
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-nas_0.99.76-9+etch1_arm.deb
    Size/MD5 checksum:    27216 736ce1ccaafae5f9e3625dbdf8b5899d
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-gtk_0.99.76-9+etch1_arm.deb
    Size/MD5 checksum:   120772 4aefd3462f4256965914286c1a7061e8
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer-dev_0.99.76-9+etch1_arm.deb
    Size/MD5 checksum:    83954 48d8e598299a15b90b61a920e141ed85
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-daemon_0.99.76-9+etch1_arm.deb
    Size/MD5 checksum:    26752 f9de177fea822cbf3080d4edacc74db6
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-jack_0.99.76-9+etch1_arm.deb
    Size/MD5 checksum:    28656 05d55679345622f1a87ff2f1cca7e5bd
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-xosd_0.99.76-9+etch1_arm.deb
    Size/MD5 checksum:    27358 dfa10d528760e3e9de65c20ea9d9dae6
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-oss_0.99.76-9+etch1_arm.deb
    Size/MD5 checksum:    25152 b1c6124426d3193df76eaf30d434c8bb
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-common_0.99.76-9+etch1_arm.deb
    Size/MD5 checksum:   173496 76c2bfe4990607494b9e6d39de7c394c
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-esd_0.99.76-9+etch1_arm.deb
    Size/MD5 checksum:    25004 f9298a89ec2e3cf70f255d6a0dedd22b
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer0_0.99.76-9+etch1_arm.deb
    Size/MD5 checksum:    29410 45c2839bd4b65d5fbc6ad6fda9761f96

hppa architecture (HP PA RISC)

  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-jack_0.99.76-9+etch1_hppa.deb
    Size/MD5 checksum:    30830 d32c6b62cc1d4a50af1b2f340c60e295
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-alsa_0.99.76-9+etch1_hppa.deb
    Size/MD5 checksum:    27870 46dff50cec7b6122ad8f056e42e07bf0
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-xosd_0.99.76-9+etch1_hppa.deb
    Size/MD5 checksum:    28772 2aa591d9ebe3f8e5a7996a31fae9f093
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-nas_0.99.76-9+etch1_hppa.deb
    Size/MD5 checksum:    27926 604e9ddc8a8e48031934c1d8ff44278f
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer0_0.99.76-9+etch1_hppa.deb
    Size/MD5 checksum:    31560 956ddd8afc906f9c1ef658348d3eedf0
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-oss_0.99.76-9+etch1_hppa.deb
    Size/MD5 checksum:    25962 3ebcd9cc144bb8386a1ca0f9a410985d
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-text_0.99.76-9+etch1_hppa.deb
    Size/MD5 checksum:    29106 71dcd89706a5d8862d20228f3a65d9d1
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-gtk_0.99.76-9+etch1_hppa.deb
    Size/MD5 checksum:   139484 ed32063973b85fb4b22d7dc0fe5f1eba
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-daemon_0.99.76-9+etch1_hppa.deb
    Size/MD5 checksum:    27858 84a05b131e76039bb03b854428cd6ed9
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-common_0.99.76-9+etch1_hppa.deb
    Size/MD5 checksum:   191314 094ec3d9963ff0641a5748e51da11592
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-esd_0.99.76-9+etch1_hppa.deb
    Size/MD5 checksum:    25812 5e7339d56deb8c88cd83f83895a716c5
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer-dev_0.99.76-9+etch1_hppa.deb
    Size/MD5 checksum:    85944 8c484572699fd8e8ae9e437c8c8f0777

i386 architecture (Intel ia32)

  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer0_0.99.76-9+etch1_i386.deb
    Size/MD5 checksum:    30404 152b14037ca04c15f98d61da207d8d46
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-text_0.99.76-9+etch1_i386.deb
    Size/MD5 checksum:    28100 f1ef493cd0e41107102a7d552b83563c
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-nas_0.99.76-9+etch1_i386.deb
    Size/MD5 checksum:    26938 9fd4b50433e0e8059e841156d89265c8
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer-dev_0.99.76-9+etch1_i386.deb
    Size/MD5 checksum:    81112 63d46351fcfaf549e0602289d9fd7139
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-oss_0.99.76-9+etch1_i386.deb
    Size/MD5 checksum:    25102 2b54d8b1f00a371d22b59d83e5cde354
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-gtk_0.99.76-9+etch1_i386.deb
    Size/MD5 checksum:   115288 902924f6ef4f2e63b66b183dc0c35334
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-daemon_0.99.76-9+etch1_i386.deb
    Size/MD5 checksum:    26996 9d0e04a29f76e31f8b076ab3a689a23f
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-alsa_0.99.76-9+etch1_i386.deb
    Size/MD5 checksum:    26732 a4c34cf4a0ab302a9ec079830bc078a5
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-jack_0.99.76-9+etch1_i386.deb
    Size/MD5 checksum:    28900 9153f6bcfa7b63b15a48f28a599bbc72
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-common_0.99.76-9+etch1_i386.deb
    Size/MD5 checksum:   158866 c35adec287030905bf0db4e27ab81d63
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-xosd_0.99.76-9+etch1_i386.deb
    Size/MD5 checksum:    27682 122a2eaf526f4566d7a7486900bf31b3
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-esd_0.99.76-9+etch1_i386.deb
    Size/MD5 checksum:    24994 1a43a121d1a49ca6873ba5095d859e62

ia64 architecture (Intel ia64)

  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-esd_0.99.76-9+etch1_ia64.deb
    Size/MD5 checksum:    26008 b582458d4fd4c5a0b38bab8b2f0459b9
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-text_0.99.76-9+etch1_ia64.deb
    Size/MD5 checksum:    29332 5f4ccdc8009a1370188025e7efba87eb
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-xosd_0.99.76-9+etch1_ia64.deb
    Size/MD5 checksum:    28878 dc628fa779e8485c9c3dab8363d5726c
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-nas_0.99.76-9+etch1_ia64.deb
    Size/MD5 checksum:    29486 3035fc70c59b1d1edd17725987f19bad
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-oss_0.99.76-9+etch1_ia64.deb
    Size/MD5 checksum:    26340 6db7a892db68580708265873f6ce52b2
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-jack_0.99.76-9+etch1_ia64.deb
    Size/MD5 checksum:    32072 20a46904c43bb27f793bcbbd38079156
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-alsa_0.99.76-9+etch1_ia64.deb
    Size/MD5 checksum:    28608 467d81086aa8141c67490d0c7b92f9e4
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer-dev_0.99.76-9+etch1_ia64.deb
    Size/MD5 checksum:    81542 5d309e66d4abe81b83e1e086575d10f5
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-common_0.99.76-9+etch1_ia64.deb
    Size/MD5 checksum:   239982 8c1cf0558be5c8735b41160db61be0d3
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer0_0.99.76-9+etch1_ia64.deb
    Size/MD5 checksum:    33344 6b6c4685c617583e6a7e2619bc3be82c
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-daemon_0.99.76-9+etch1_ia64.deb
    Size/MD5 checksum:    28184 2fe8caf134eb15304354c3796e453a35
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-gtk_0.99.76-9+etch1_ia64.deb
    Size/MD5 checksum:   164272 48f8eb0310511c326642264a8a3cb63d

mips architecture (MIPS (Big Endian))

  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-common_0.99.76-9+etch1_mips.deb
    Size/MD5 checksum:   165842 b16d5d2344a40bc23ab0e03094669839
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-xosd_0.99.76-9+etch1_mips.deb
    Size/MD5 checksum:    27652 0a22b61200a7a29553c8ee85dd6a4f07
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-nas_0.99.76-9+etch1_mips.deb
    Size/MD5 checksum:    27092 f0afc829883f7f794b7d1675746f7d58
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-text_0.99.76-9+etch1_mips.deb
    Size/MD5 checksum:    28030 c9ae0b3f54a88a4e11cded00fccba67c
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-oss_0.99.76-9+etch1_mips.deb
    Size/MD5 checksum:    25222 a9c8b5bfdafd442d5b286814c2ce680d
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-esd_0.99.76-9+etch1_mips.deb
    Size/MD5 checksum:    25072 07b4f0bf800449ab08c8015650c72776
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-alsa_0.99.76-9+etch1_mips.deb
    Size/MD5 checksum:    26806 16b2d718d3acf15eb383bfd920c10480
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-daemon_0.99.76-9+etch1_mips.deb
    Size/MD5 checksum:    27066 3314a50149ea5dceae3e5467e76c77a0
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer-dev_0.99.76-9+etch1_mips.deb
    Size/MD5 checksum:    85636 fefda097b64dab1279376fe0f0b35fdb
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-gtk_0.99.76-9+etch1_mips.deb
    Size/MD5 checksum:   117694 f05708f5ce8cea7bc95e65a54e29f687
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-jack_0.99.76-9+etch1_mips.deb
    Size/MD5 checksum:    29316 02487afba03040ba13ba21c01025b16e
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer0_0.99.76-9+etch1_mips.deb
    Size/MD5 checksum:    29670 c4ddd404db7fd3bdc1ef9a123924418e

mipsel architecture (MIPS (Little Endian))

  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-esd_0.99.76-9+etch1_mipsel.deb
    Size/MD5 checksum:    25148 dabdc1d59a6ae032838dea3353102093
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-alsa_0.99.76-9+etch1_mipsel.deb
    Size/MD5 checksum:    27016 519022c9eb3b6c96a3afa44381f64366
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-text_0.99.76-9+etch1_mipsel.deb
    Size/MD5 checksum:    28224 fbe850b98a06e6b96c7a7bbd733c22f0
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-daemon_0.99.76-9+etch1_mipsel.deb
    Size/MD5 checksum:    27230 7ac0f034f092d2b16857a796def98e2b
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer0_0.99.76-9+etch1_mipsel.deb
    Size/MD5 checksum:    29932 f2da5578e585c2933e8fef32c724aa99
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer-dev_0.99.76-9+etch1_mipsel.deb
    Size/MD5 checksum:    79724 50953a15fe437b4a1a19fa55e2c4bde1
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-common_0.99.76-9+etch1_mipsel.deb
    Size/MD5 checksum:   166054 9b6e96349f4bdd877a8a91b922ee20dc
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-nas_0.99.76-9+etch1_mipsel.deb
    Size/MD5 checksum:    27272 bce2fdec07e84698e63b28317ecf2de6
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-oss_0.99.76-9+etch1_mipsel.deb
    Size/MD5 checksum:    25320 edf3f4f18c7692d0aba2406c9023f322
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-jack_0.99.76-9+etch1_mipsel.deb
    Size/MD5 checksum:    29578 cce9ee89957dcfa6b0f59563d782f3f0
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-xosd_0.99.76-9+etch1_mipsel.deb
    Size/MD5 checksum:    27820 073b5d172915d9a5e57b6732b88be36e
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-gtk_0.99.76-9+etch1_mipsel.deb
    Size/MD5 checksum:   117138 f00516877e9bba7f95bd28daa2ec3735

powerpc architecture (PowerPC)

  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-alsa_0.99.76-9+etch1_powerpc.deb
    Size/MD5 checksum:    28758 435a5cd0d7a2154f7de5795c0c639a34
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer-dev_0.99.76-9+etch1_powerpc.deb
    Size/MD5 checksum:    78298 3366d969c599537dbfbd71cfae4e8913
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-text_0.99.76-9+etch1_powerpc.deb
    Size/MD5 checksum:    29788 ed8a38ed1e7f6dc67fd26ed75f1eeded
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-daemon_0.99.76-9+etch1_powerpc.deb
    Size/MD5 checksum:    28890 18b6b83140d2cfa47cfacbf26d254fd6
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-esd_0.99.76-9+etch1_powerpc.deb
    Size/MD5 checksum:    26942 f899716736bbf2a23d3e165f9b0f1bc9
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-xosd_0.99.76-9+etch1_powerpc.deb
    Size/MD5 checksum:    29490 fd8f760c694e23c51f984c136f0271b3
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer0_0.99.76-9+etch1_powerpc.deb
    Size/MD5 checksum:    31720 11b35992acfa3cde29d8edf00c0afb1d
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-jack_0.99.76-9+etch1_powerpc.deb
    Size/MD5 checksum:    31352 0ac9167acdf80a7b80aac9323981f720
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-nas_0.99.76-9+etch1_powerpc.deb
    Size/MD5 checksum:    28974 12bca0fb5a143e69788d19516de3c9a2
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-oss_0.99.76-9+etch1_powerpc.deb
    Size/MD5 checksum:    27172 baeeb5593985237037a4ec5dcd6fc063
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-common_0.99.76-9+etch1_powerpc.deb
    Size/MD5 checksum:   182962 11f96fe3adf8fe0facfebb59a0abc423
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-gtk_0.99.76-9+etch1_powerpc.deb
    Size/MD5 checksum:   130974 b60fc57e8681ecb09e67001c26650df9

s390 architecture (IBM S/390)

  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-xosd_0.99.76-9+etch1_s390.deb
    Size/MD5 checksum:    27974 d96577d4acff264dee6487bbedf0a970
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-alsa_0.99.76-9+etch1_s390.deb
    Size/MD5 checksum:    27448 936a4b1de8dc976891f6eb04197fbc92
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-text_0.99.76-9+etch1_s390.deb
    Size/MD5 checksum:    28130 1a37d675e87df59e60823d86bb3b079a
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-esd_0.99.76-9+etch1_s390.deb
    Size/MD5 checksum:    25306 1ec0e9272b6b77231ba4236f3ef5b0c5
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-daemon_0.99.76-9+etch1_s390.deb
    Size/MD5 checksum:    27160 ff4273b1f78919238579ebcbbc361c2d
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-common_0.99.76-9+etch1_s390.deb
    Size/MD5 checksum:   164762 7dc9d8881ce9779e211de5b0f10bfb24
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer-dev_0.99.76-9+etch1_s390.deb
    Size/MD5 checksum:    79096 7d8be3542791df96a6df738b134fa60e
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-gtk_0.99.76-9+etch1_s390.deb
    Size/MD5 checksum:   123358 69ffb56b564c13ef1735fa4d5bf45725
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-jack_0.99.76-9+etch1_s390.deb
    Size/MD5 checksum:    29786 1707fbd54e4782fc1c4a756c9b3b1be8
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-nas_0.99.76-9+etch1_s390.deb
    Size/MD5 checksum:    27404 df369a2d65ceca9281b6e9f42eb13080
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-oss_0.99.76-9+etch1_s390.deb
    Size/MD5 checksum:    25458 f7148876d165801bddea3f8370d77cff
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer0_0.99.76-9+etch1_s390.deb
    Size/MD5 checksum:    31298 799599d2ee4ba08d0024f1ae14bf2b71

sparc architecture (Sun SPARC/UltraSPARC)

  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer-dev_0.99.76-9+etch1_sparc.deb
    Size/MD5 checksum:    77596 b082cb4dc6228cd4dd604b6080d80fc0
  http://security.debian.org/pool/updates/main/a/alsaplayer/libalsaplayer0_0.99.76-9+etch1_sparc.deb
    Size/MD5 checksum:    29638 7ca739cc15f4328730f588707267c973
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-daemon_0.99.76-9+etch1_sparc.deb
    Size/MD5 checksum:    26900 177580129b807bd9fe97f82c7752039b
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-gtk_0.99.76-9+etch1_sparc.deb
    Size/MD5 checksum:   118620 63df839b875a82977feac0bb6800fb23
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-nas_0.99.76-9+etch1_sparc.deb
    Size/MD5 checksum:    26862 ccae6c55156046f553c8aa4f0baa4232
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-alsa_0.99.76-9+etch1_sparc.deb
    Size/MD5 checksum:    26764 6481a032bf418dd73f7da67f0874def0
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-jack_0.99.76-9+etch1_sparc.deb
    Size/MD5 checksum:    29272 36d7b51e3f48189ada1ff54ccb59a5d0
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-xosd_0.99.76-9+etch1_sparc.deb
    Size/MD5 checksum:    27716 76976b49916283774b2a5e3200048ccc
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-common_0.99.76-9+etch1_sparc.deb
    Size/MD5 checksum:   156806 a0c4129dc4d8b94b8baf9a56ead2edf4
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-esd_0.99.76-9+etch1_sparc.deb
    Size/MD5 checksum:    25040 f7c83edbd6586a0feca68de38fab2817
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-oss_0.99.76-9+etch1_sparc.deb
    Size/MD5 checksum:    25132 70717e12ed7d77e82f3a02ad8802c513
  http://security.debian.org/pool/updates/main/a/alsaplayer/alsaplayer-text_0.99.76-9+etch1_sparc.deb
    Size/MD5 checksum:    27858 13cbdbec99958a329403b805d1ba98b3


  These files will probably be moved into the stable distribution on
  its next update.

- - ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iQEVAwUBR/aOQWz0hbPcukPfAQIosQf+NqCIRGSUDewiVCtXVnb1saTrvMIr2dWk
0AyDVJmhJ5n8/nQbzO0kv1+FfhkwQohLCBTWMPoMP5GzMU3hhhHCgkwnrtXrv1B9
zUu9SN7qB66Vic6C9XmhS3zXr2bpvZ+TCA5R0iUiM1v+OLAGK/m1kCzR14fV76zi
p9336i16EqwltoyPKBOjdpSOQ68Q4ZD6UbHRKe2rtmXFfxNd0KxbpSV9uQ5s5dm9
MwEzVBuSPhx7C5gUe8W45d0UCFEFszQ1GV3hCTT3V47Mhua4IKL2qamKDBIAcczB
09tMZuH26DXVkuZt6yZTI/+/08LjkZi2Jjn4e5NlQKukHd6kQGzQ+A==
=ulIC
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

If you believe that your computer system has been compromised or attacked in 
any way, we encourage you to let us know by completing the secure National IT 
Incident Reporting Form at:

        http://www.auscert.org.au/render.html?it=3192

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================

-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQCVAwUBR/lv5Ch9+71yA2DNAQJ+swP/Q92ygpmGe4dYVZUWmkWJsmw6Z2HABfkT
4UqJGzE9RZOkPA/1x6OTpycP5fNenNlo5RvzlVCUNFfWsaQXGOdSv8bSfr1qbcP8
sdoU7GTPH7CrkWa706qMbnTa7CGX9x+ddiNOGPGl/s1wnpeZRxMfJH3IiOoNERoB
s0YnWJkkCeY=
=7G1y
-----END PGP SIGNATURE-----