[ubuntu/lucid-security] opie, opie (delayed) 2.40~dfsg-0ubuntu1.10.04.1 (Accepted)

Ubuntu Installer archive at ubuntu.com
Mon Jun 21 19:03:22 BST 2010


opie (2.40~dfsg-0ubuntu1.10.04.1) lucid-security; urgency=low

  * SECURITY UPDATE: denial of service and possible code execution via
    off-by-one
    - libopie/readrec.c: use strncpy so we don't overflow principal.
    - http://security.freebsd.org/patches/SA-10:05/opie.patch
    - CVE-2010-1938
  * libopie/newseed.c: fix snprintf's length argument so opiepasswd will
    generate valid seeds. (LP: #569292)

Date: Tue, 08 Jun 2010 11:19:07 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/lucid/+source/opie/2.40~dfsg-0ubuntu1.10.04.1
-------------- next part --------------
Format: 1.8
Date: Tue, 08 Jun 2010 11:19:07 -0400
Source: opie
Binary: opie-client opie-server libopie-dev
Architecture: source
Version: 2.40~dfsg-0ubuntu1.10.04.1
Distribution: lucid-security
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 libopie-dev - OPIE library development files.
 opie-client - OPIE programs for generating OTPs on client machines
 opie-server - OPIE programs for maintaining an OTP key file
Launchpad-Bugs-Fixed: 569292
Changes: 
 opie (2.40~dfsg-0ubuntu1.10.04.1) lucid-security; urgency=low
 .
   * SECURITY UPDATE: denial of service and possible code execution via
     off-by-one
     - libopie/readrec.c: use strncpy so we don't overflow principal.
     - http://security.freebsd.org/patches/SA-10:05/opie.patch
     - CVE-2010-1938
   * libopie/newseed.c: fix snprintf's length argument so opiepasswd will
     generate valid seeds. (LP: #569292)
Checksums-Sha1: 
 7e0e665b083e77f8fbbc3cc4a1470d4490af322a 1143 opie_2.40~dfsg-0ubuntu1.10.04.1.dsc
 e90220cef60cfe99ed8a38b09fbff247a9b8c93c 9417 opie_2.40~dfsg-0ubuntu1.10.04.1.diff.gz
Checksums-Sha256: 
 989de68e1bfa9f7c048d5b632aaf72ff2d4e9e7f759dead4f6ef8ee7eab3cf5f 1143 opie_2.40~dfsg-0ubuntu1.10.04.1.dsc
 6485c277c7a67c1140ef93aa513efc73c493643b2ded759765b5a266c7066959 9417 opie_2.40~dfsg-0ubuntu1.10.04.1.diff.gz
Files: 
 b5ef0adf98f91a9ad6e47d51c30545ce 1143 admin optional opie_2.40~dfsg-0ubuntu1.10.04.1.dsc
 7d69bcb66c523fabb6bcb77f6f49a75a 9417 admin optional opie_2.40~dfsg-0ubuntu1.10.04.1.diff.gz
Original-Maintainer: Michael Stone <mstone at debian.org>


More information about the Lucid-changes mailing list