• [SECURITY] [DSA 2281-1] opie security update

    From Steffen Joeris@1:229/2 to All on Thu Jul 21 13:20:02 2011
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2281-1 [email protected] http://www.debian.org/security/ Steffen Joeris
    July 21, 2011 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : opie
    Vulnerability : several
    Problem type : remote
    Debian-specific: no
    CVE IDs : CVE-2011-2489 CVE-2011-2490 CVE-2010-1938
    Debian Bugs : 631344 631345 584932

    Sebastian Krahmer discovered that opie, a system that makes it simple to
    use One-Time passwords in applications, is prone to a privilege
    escalation (CVE-2011-2490) and an off-by-one error, which can lead to
    the execution of arbitrary code (CVE-2011-2489). Adam Zabrocki and
    Maksymilian Arciemowicz also discovered another off-by-one error (CVE-2010-1938), which only affects the lenny version as the fix was
    already included for squeeze.


    For the oldstable distribution (lenny), these problems have been fixed in version 2.32-10.2+lenny2.

    For the stable distribution (squeeze), these problems have been fixed in version 2.32.dfsg.1-0.2+squeeze1

    The testing distribution (wheezy) and the unstable distribution (sid) do
    not contain opie.


    We recommend that you upgrade your opie packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.11 (GNU/Linux)

    iEYEARECAAYFAk4nk6EACgkQ62zWxYk/rQfjAACfUmlzQ0haXhy9vk04RuGM+A5u bW0An2vThf6CqKRaqNmoZ82MP3INON2d
    =REWR
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)