[ubuntu/maverick-security] radvd 1:1.6-1ubuntu0.1 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Thu Nov 10 17:03:36 UTC 2011


radvd (1:1.6-1ubuntu0.1) maverick-security; urgency=low

  * SECURITY UPDATE: arbitrary file overwrite via interface name
    - debian/patches/CVE-2011-3602.patch: check for path traversal in
      device-linux.c.
    - CVE-2011-3602
  * SECURITY UPDATE: incorrect privilege dropping handling
    - debian/patches/CVE-2011-3603.patch: fail on errors in
      privsep-linux.c, radvd.c.
    - CVE-2011-3603
  * SECURITY UPDATE: denial or service via buffer overreads
    - debian/patches/CVE-2011-3604.patch: properly check length in
      process.c.
    - CVE-2011-3604
  * SECURITY UPDATE: temporary denial of service via delay
    - debian/patches/CVE-2011-3605.patch: remove delay in process.c.
    - CVE-2011-3605

Date: Wed, 12 Oct 2011 09:57:54 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/maverick/+source/radvd/1:1.6-1ubuntu0.1
-------------- next part --------------
Format: 1.8
Date: Wed, 12 Oct 2011 09:57:54 -0400
Source: radvd
Binary: radvd
Architecture: source
Version: 1:1.6-1ubuntu0.1
Distribution: maverick-security
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 radvd      - Router Advertisement Daemon
Changes: 
 radvd (1:1.6-1ubuntu0.1) maverick-security; urgency=low
 .
   * SECURITY UPDATE: arbitrary file overwrite via interface name
     - debian/patches/CVE-2011-3602.patch: check for path traversal in
       device-linux.c.
     - CVE-2011-3602
   * SECURITY UPDATE: incorrect privilege dropping handling
     - debian/patches/CVE-2011-3603.patch: fail on errors in
       privsep-linux.c, radvd.c.
     - CVE-2011-3603
   * SECURITY UPDATE: denial or service via buffer overreads
     - debian/patches/CVE-2011-3604.patch: properly check length in
       process.c.
     - CVE-2011-3604
   * SECURITY UPDATE: temporary denial of service via delay
     - debian/patches/CVE-2011-3605.patch: remove delay in process.c.
     - CVE-2011-3605
Checksums-Sha1: 
 9a983e82a8a1cb1ea888ab7f03037c26e68d3f5a 1697 radvd_1.6-1ubuntu0.1.dsc
 ad3e624185787635a828808cc19520a679476db5 9439 radvd_1.6-1ubuntu0.1.diff.gz
Checksums-Sha256: 
 1e399b00a3195ff9e3169d7f6a0afd15daf9911cc7226d85ef0791dbb457684f 1697 radvd_1.6-1ubuntu0.1.dsc
 e67143aaca708ae12b06ce9fb984034aa79fb2ba97a1c86c3328be6fc506a313 9439 radvd_1.6-1ubuntu0.1.diff.gz
Files: 
 92d341ea8c0499484741be83285cf81f 1697 net optional radvd_1.6-1ubuntu0.1.dsc
 eecd7234f7fcf4a15f635584e6f703ca 9439 net optional radvd_1.6-1ubuntu0.1.diff.gz
Original-Maintainer: Ghe Rivero <ghe at debian.org>


More information about the Maverick-changes mailing list