Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2009.1251 New devscripts packages fix remote code execution 3 September 2009 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: devscripts Publisher: Debian Operating System: Debian GNU/Linux 4 Impact/Access: Reduced Security -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2009-2946 Original Bulletin: http://www.debian.org/security/2009/dsa-1878 - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - ------------------------------------------------------------------------ Debian Security Advisory DSA-1878-1 security@debian.org http://www.debian.org/security/ Florian Weimer September 02, 2009 http://www.debian.org/security/faq - - ------------------------------------------------------------------------ Package : devscripts Vulnerability : missing input sanitation Problem type : remote Debian-specific: yes CVE Id(s) : CVE-2009-2946 Raphael Geissert discovered that uscan, a program to check for availability of new source code versions which is part of the devscripts package, runs Perl code downloaded from potentially untrusted sources to implement its URL and version mangling functionality. This update addresses this issue by reimplementing the relevant Perl operators without relying on the Perl interpreter, trying to preserve backwards compatibility as much as possible. For the old stable distribution (etch), this problem has been fixed in version 2.9.26etch4. For the stable distribution (lenny), this problem has been fixed in version 2.10.35lenny6. For the unstable distribution (sid), this problem will be fixed in version 2.10.54. We recommend that you upgrade your devscripts package. Upgrade instructions - - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - - ------------------------------- Source archives: http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4.tar.gz Size/MD5 checksum: 432330 6d13d4ec0e161a62d0babd45b58e9f75 http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4.dsc Size/MD5 checksum: 682 0cd547c5e78642f16762e0d687997563 alpha architecture (DEC Alpha) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_alpha.deb Size/MD5 checksum: 389730 42458f68b3f75d87bb0397e6befde980 amd64 architecture (AMD x86_64 (AMD64)) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_amd64.deb Size/MD5 checksum: 399454 8f648a32c698f15d4c6c2a90f9cdc19a arm architecture (ARM) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_arm.deb Size/MD5 checksum: 396212 3187e3df12e04da5b2abb3aabf63f293 hppa architecture (HP PA RISC) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_hppa.deb Size/MD5 checksum: 400058 bc84514b7d6e87c2bace8ee054cea2b6 i386 architecture (Intel ia32) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_i386.deb Size/MD5 checksum: 394688 35c9379172ffb63d89f512e7b46653db ia64 architecture (Intel ia64) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_ia64.deb Size/MD5 checksum: 391116 f0d5a42de7f2f36d1433c550655c9cc9 mips architecture (MIPS (Big Endian)) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_mips.deb Size/MD5 checksum: 396716 30793d09ae26fdd5fbcf47fc011fb7d9 mipsel architecture (MIPS (Little Endian)) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_mipsel.deb Size/MD5 checksum: 389640 750928f91a3066a5288f807cd5afa953 powerpc architecture (PowerPC) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_powerpc.deb Size/MD5 checksum: 391870 5b5b3fcbf001a6d390515fb64829ba80 s390 architecture (IBM S/390) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_s390.deb Size/MD5 checksum: 389540 40471968ab5a26bb0227b4954814a270 sparc architecture (Sun SPARC/UltraSPARC) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_sparc.deb Size/MD5 checksum: 397816 5f773402f6ebf2b00170d46686ee0418 Debian GNU/Linux 5.0 alias lenny - - -------------------------------- Source archives: http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6.tar.gz Size/MD5 checksum: 602179 4bc83fe370d730667e9fe8fe222bf115 http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6.dsc Size/MD5 checksum: 1417 6cd189a95491bdd4ce32e908acd55cd8 alpha architecture (DEC Alpha) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_alpha.deb Size/MD5 checksum: 509058 dd02c9afaf74b8633699b7e5aee3aef3 amd64 architecture (AMD x86_64 (AMD64)) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_amd64.deb Size/MD5 checksum: 519036 3f274c25fabc3d22cb329c621dd0f630 arm architecture (ARM) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_arm.deb Size/MD5 checksum: 520644 e4ee996772f786c6883c779420125dda armel architecture (ARM EABI) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_armel.deb Size/MD5 checksum: 520300 eae935b7a416989bb2cddabae3870e37 hppa architecture (HP PA RISC) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_hppa.deb Size/MD5 checksum: 524510 648acee4d3d9ed48eb2415ce36c5519e i386 architecture (Intel ia32) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_i386.deb Size/MD5 checksum: 517734 f5e74325fdfda2cf7cfb690be807a1de ia64 architecture (Intel ia64) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_ia64.deb Size/MD5 checksum: 510044 bde1efc77895c33d6e0ff5e49fcea63f mips architecture (MIPS (Big Endian)) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_mips.deb Size/MD5 checksum: 508946 2e3c9714a01e41655c467c2fd4f41f09 mipsel architecture (MIPS (Little Endian)) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_mipsel.deb Size/MD5 checksum: 508980 4cc636a2e0391f8405808b80529020a6 powerpc architecture (PowerPC) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_powerpc.deb Size/MD5 checksum: 511348 96628900942da87fed1133f6d97ed8ea s390 architecture (IBM S/390) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_s390.deb Size/MD5 checksum: 508898 f6eaf845971c27830890021c1106c19b sparc architecture (Sun SPARC/UltraSPARC) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_sparc.deb Size/MD5 checksum: 523130 773b2a7f70551467601af5d1daf8a776 These files will probably be moved into the stable distribution on its next update. - - --------------------------------------------------------------------------------- For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main Mailing list: debian-security-announce@lists.debian.org Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg> - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQEcBAEBAgAGBQJKnsCQAAoJEL97/wQC1SS+jq4IAK6B72weqFDOyezbc0PsTxsA Ipgg6bkbtRXwqOvllAP9wngvYLz+Az0GLoYFUVsyCUcRzqPWbDJQQKo+uWkPfliE ArEFHHz4Vsk7NYohT2R4DrWvkIA4fI621hUOHJb7pDa7jP2BDInm30fiZHkBIir5 FrUdabAUl9FU2SYq0dWucxTPSCoZOaS5ZjImwYTzIAeLV4NL8uOpR42lZjg2mCa3 7MZ6EauIhCCV4RmA+5wHyggDa6uCXL1x9UQU3f5vah0HCHT5VehwxFzCgmSx0v9Z v0deqHKEe/9P+7J8hJ97wHFOd9VV9ViE3W55IirzMqRioOrpZxoeAXlsZ/gEqf8= =A/Xm - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: http://www.auscert.org.au/render.html?cid=1980 If you believe that your computer system has been compromised or attacked in any way, we encourage you to let us know by completing the secure National IT Incident Reporting Form at: http://www.auscert.org.au/render.html?it=3192 =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iD8DBQFKnzGGNVH5XJJInbgRAkaWAJ9lWCPnV3/XiT9yNRYaUySlxGSltwCffZP8 +T635Xks8dzCzKs6TadfeMI= =7ArV -----END PGP SIGNATURE-----