Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA-1971-1] New libthai packages fix arbitrary code executi

    From Giuseppe Iuculano@1:229/2 to All on Fri Jan 15 10:30:02 2010
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1971-1 [email protected] http://www.debian.org/security/ Giuseppe Iuculano January 15, 2010 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : libthai
    Vulnerability : integer overflow
    Problem type : local (remote)
    Debian-specific: no
    CVE Id : CVE-2009-4012


    Tim Starling discovered that libthai, a set of Thai language support routines, is vulnerable of integer/heap overflow.
    This vulnerability could allow an attacker to run arbitrary code by sending a very
    long string.


    For the oldstable distribution (etch), this problem has been fixed in
    version 0.1.6-1+etch1.

    For the stable distribution (lenny), this problem has been fixed in
    version 0.1.9-4+lenny1.

    For the testing distribution (squeeze), and the unstable distribution (sid), this problem will be fixed soon.


    We recommend that you upgrade your libthai package.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian (oldstable)
    - ------------------

    Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

    Source archives:

    http://security.debian.org/pool/updates/main/libt/libthai/libthai_0.1.6-1+etch1.dsc
    Size/MD5 checksum: 683 c43a718e2d05c2b47af4bac86903e896
    http://security.debian.org/pool/updates/main/libt/libthai/libthai_0.1.6.orig.tar.gz
    Size/MD5 checksum: 847074 f085d66dc46c166c278c252898035076
    http://security.debian.org/pool/updates/main/libt/libthai/libthai_0.1.6-1+etch1.diff.gz
    Size/MD5 checksum: 11695 71127f5e7afcdcbfd5af6780505c7a1a

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/libt/libthai/libthai-doc_0.1.6-1+etch1_all.deb
    Size/MD5 checksum: 50312 317992ee889c0de0fe9dc9ea97a57fc6

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/libt/libthai/libthai0_0.1.6-1+etch1_alpha.deb
    Size/MD5 checksum: 275028 428557ab4a790fc85b0733d1b28dc801
    http://security.debian.org/pool/updates/main/libt/libthai/libthai-dev_0.1.6-1+etch1_alpha.deb
    Size/MD5 checksum: 316330 ffc67c38acf68cd77c8f6a236de187c1

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/libt/libthai/libthai0_0.1.6-1+etch1_amd64.deb
    Size/MD5 checksum: 275070 aac7f0edfc5b53640626dd7843e9bf1f
    http://security.debian.org/pool/updates/main/libt/libthai/libthai-dev_0.1.6-1+etch1_amd64.deb
    Size/MD5 checksum: 311134 2f471ee3c58d737ddc9b5f298b45476e

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/libt/libthai/libthai-dev_0.1.6-1+etch1_hppa.deb
    Size/MD5 checksum: 376960 a42594c08a9e2dc461bf6d41b1ffa843
    http://security.debian.org/pool/updates/main/libt/libthai/libthai0_0.1.6-1+etch1_hppa.deb
    Size/MD5 checksum: 339122 97710ae2e6a4110fed1d708e5480f718

    i386 architecture (Intel ia32)

    http://security.debian.org/pool/updates/main/libt/libthai/libthai0_0.1.6-1+etch1_i386.deb
    Size/MD5 checksum: 273352 8500dbe477de0cd29299ba211a45f7ae
    http://security.debian.org/pool/updates/main/libt/libthai/libthai-dev_0.1.6-1+etch1_i386.deb
    Size/MD5 checksum: 313540 1e7854db6cef8b1e2b9bf5065e62bcd4

    ia64 architecture (Intel ia64)

    http://security.debian.org/pool/updates/main/libt/libthai/libthai-dev_0.1.6-1+etch1_ia64.deb
    Size/MD5 checksum: 319442 092a822857a37961e6796773c033d3a8
    http://security.debian.org/pool/updates/main/libt/libthai/libthai0_0.1.6-1+etch1_ia64.deb
    Size/MD5 checksum: 278182 c225f2e441ea5e2aa4b8aadcb928cd38

    mips architecture (MIPS (Big Endian))

    http://security.debian.org/pool/updates/main/libt/libthai/libthai-dev_0.1.6-1+etch1_mips.deb
    Size/MD5 checksum: 376754 467ff44afe323bae6c3dbb988da7e089
    http://security.debian.org/pool/updates/main/libt/libthai/libthai0_0.1.6-1+etch1_mips.deb
    Size/MD5 checksum: 337592 1dabc2d5d7ad3baedcec607bffc4a55a

    mipsel architecture (MIPS (Little Endian))

    http://security.debian.org/pool/updates/main/libt/libthai/libthai-dev_0.1.6-1+etch1_mipsel.deb
    Size/MD5 checksum: 314592 fa20d463d069f95cda9638a3113fcd51
    http://security.debian.org/pool/updates/main/libt/libthai/libthai0_0.1.6-1+etch1_mipsel.deb
    Size/MD5 checksum: 274038 1e210dff44b35d320903c915a07bf4f7

    powerpc architecture (PowerPC)

    http://security.debian.org/pool/updates/main/libt/libthai/libthai-dev_0.1.6-1+etch1_powerpc.deb
    Size/MD5 checksum: 376180 4eaf094301d96f7db8823986275c1336
    http://security.debian.org/pool/updates/main/libt/libthai/libthai0_0.1.6-1+etch1_powerpc.deb
    Size/MD5 checksum: 338226 ac8eb480c5f790cd9e6c9bdf6837027c

    s390 architecture (IBM S/390)

    http://security.debian.org/pool/updates/main/libt/libthai/libthai0_0.1.6-1+etch1_s390.deb
    Size/MD5 checksum: 338280 c2ca43fc46bf76c10e580b5b021ce5f7
    http://security.debian.org/pool/updates/main/libt/libthai/libthai-dev_0.1.6-1+etch1_s390.deb
    Size/MD5 checksum: 377418 ea0936d056392d9aef116c3ebdcdb1b3

    sparc architecture (Sun SPARC/UltraSPARC)

    http://security.debian.org/pool/updates/main/libt/libthai/libthai-dev_0.1.6-1+etch1_sparc.deb
    Size/MD5 checksum: 374490 40b15de3062e64a1528f188d6b10a646
    http://security.debian.org/pool/updates/main/libt/libthai/libthai0_0.1.6-1+etch1_sparc.deb
    Size/MD5 checksum: 336808 124b46ae02cd1d558dac1123f93ed72c

    Debian (stable)
    - ---------------

    Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

    Source archives:

    http://security.debian.org/pool/updates/main/libt/libthai/libthai_0.1.9.orig.tar.gz
    Size/MD5 checksum: 491038 7002d111b293f202d20b28aa2b4ed68f

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Ab Cadd
      Sat Jun 6 15:42:53 2026
      from Sheboygan, Wi via Telnet
    • Centurion
      Sat Jun 6 15:32:28 2026
      from Berea, Ohio via Telnet
    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Fri Jun 5 17:52:51 2026
      from Sheboygan, Wi via Telnet
    • Gwylbert
      Fri Jun 5 06:28:52 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Thu Jun 4 23:42:23 2026
      from Berea, Ohio via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 149:38:04
    Calls: 12,091
    Calls today: 4
    Files: 15,000
    Messages: 6,517,580

© >>> Magnum BBS <<<, 2026