-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- --------------------------------------------------------------------------
Trustix Secure Linux Security Advisory #2006-0016
Package names: curl, kernel
Summary: Multiple vulnerabilities
Date: 2006-03-24
Affected versions: Trustix Secure Linux 2.2
Trustix Secure Linux 3.0
- --------------------------------------------------------------------------
Package description:
curl
Curl is a client to get documents/files from servers, using any of the
supported protocols. The command is designed to work without user
interaction or any kind of interactivity. Curl offers a busload of
useful tricks like proxy support, user authentication, ftp upload,
HTTP post, file transfer resume and more.
kernel
The kernel package contains the Linux kernel (vmlinuz), the core of your
Trustix Secure Linux operating system. The kernel handles the basic
functions of the operating system: memory allocation, process allocation,
device input and output, etc.
Problem description:
curl < TSL 3.0 > < TSL 2.2 >
- New Upstream.
- SECURITY Fix: Ulf Harnhammar has reported a vulnerability in cURL
caused due to a boundary error within the parsing of a URL that
contains the TFTP protocol prefix "tftp://". This can be exploited to
cause a heap-based buffer overflow via a specially-crafted URL that
consist of a valid hostname and a path that is longer than 512 bytes.
The Common Vulnerabilities and Exposures project has assigned the
name CVE-2006-1061 to this issue.
kernel < TSL 3.0 >
- New Upstream.
- Upgraded 3ware 9xxx RAID driver.
- SECURITY Fix: An integer overflow error exists within the "do_replace()"
function in Netfilter. This can be exploited to cause a buffer overflow
and allows the overwrite of arbitrary amounts of kernel memory when
data is copied from user space.
- Insufficient memory allocation in "drivers/usb/gadget/rndis.c" when
handling NDIS response to OID_GEN_SUPPORTED_LIST may cause kernel memory
corruption.
Action:
We recommend that all systems with this package installed be upgraded.
Please note that if you do not need the functionality provided by this
package, you may want to remove it from your system.
Location:
All Trustix Secure Linux updates are available from
<URI:http://http.trustix.org/pub/trustix/updates/>
<URI:ftp://ftp.trustix.org/pub/trustix/updates/>
About Trustix Secure Linux:
Trustix Secure Linux is a small Linux distribution for servers. With focus
on security and stability, the system is painlessly kept safe and up to
date from day one using swup, the automated software updater.
Automatic updates:
Users of the SWUP tool can enjoy having updates automatically
installed using 'swup --upgrade'.
Questions?
Check out our mailing lists:
<URI:http://www.trustix.org/support/>
Verification:
This advisory along with all Trustix packages are signed with the
TSL sign key.
This key is available from:
<URI:http://www.trustix.org/TSL-SIGN-KEY>
The advisory itself is available from the errata pages at
<URI:http://www.trustix.org/errata/trustix-2.2/> and
<URI:http://www.trustix.org/errata/trustix-3.0/>
or directly at
<URI:http://www.trustix.org/errata/2006/0016/>
MD5sums of the packages:
- --------------------------------------------------------------------------
6fce50e6035dbc3ab0ca578927844415 3.0/rpms/curl-7.15.3-1tr.i586.rpm
ba3003155801b89b93fb177db6e07f5e 3.0/rpms/curl-devel-7.15.3-1tr.i586.rpm
4bc68c32d094eda0ae60ae933180fdd2 3.0/rpms/kernel-2.6.16-1tr.i586.rpm
98e1697712799b460909414755dd94c4 3.0/rpms/kernel-doc-2.6.16-1tr.i586.rpm
218e3140d646b56c98c3d70c7b1745e2 3.0/rpms/kernel-headers-2.6.16-1tr.i586.rpm
2a7db5d25906e63849ceb25d3525ab15 3.0/rpms/kernel-smp-2.6.16-1tr.i586.rpm
acd6e200b71765f84a12ccdc76376723
3.0/rpms/kernel-smp-headers-2.6.16-1tr.i586.rpm
b113bbb4c13e02318aed8d3fca9b946f 3.0/rpms/kernel-source-2.6.16-1tr.i586.rpm
46240360c9c165dd56c3adced2e650d9 3.0/rpms/kernel-utils-2.6.16-1tr.i586.rpm
514b06393d2ba282231b25854a66ffca 2.2/rpms/curl-7.15.3-1tr.i586.rpm
a10c16ca3b9fadbd477a9aa414f9e8fe 2.2/rpms/curl-devel-7.15.3-1tr.i586.rpm
- --------------------------------------------------------------------------
Trustix Security Team
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
iD8DBQFEI+UMi8CEzsK9IksRAqLmAJ9GtBPHmzB+ix8CcOslJUHti36eYACdFINE
BKD67VkTnXyWleFR+ZOu1R8=
=QVXJ
-----END PGP SIGNATURE-----
_______________________________________________
tsl-announce mailing list
[email protected]
http://lists.trustix.org/mailman/listinfo/tsl-announce
_______________________________________________
tsl-discuss mailing list
[email protected]
http://lists.trustix.org/mailman/listinfo/tsl-discuss