-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Wed, 13 Jun 2007 13:31:23 -0700 Source: krb5 Binary: krb5-doc libkrb5-dev krb5-rsh-server krb5-user krb5-ftpd libkadm55 libkrb53 krb5-clients krb5-telnetd krb5-kdc krb5-admin-server libkrb5-dbg Architecture: source i386 all Version: 1.4.4-7etch2 Distribution: stable-security Urgency: emergency Maintainer: Sam Hartman <hartmans@debian.org> Changed-By: Russ Allbery <rra@debian.org> Description: krb5-admin-server - MIT Kerberos master server (kadmind) krb5-clients - Secure replacements for ftp, telnet and rsh using MIT Kerberos krb5-doc - Documentation for MIT Kerberos krb5-ftpd - Secure FTP server supporting MIT Kerberos krb5-kdc - MIT Kerberos key server (KDC) krb5-rsh-server - Secure replacements for rshd and rlogind using MIT Kerberos krb5-telnetd - Secure telnet server supporting MIT Kerberos krb5-user - Basic programs to authenticate using MIT Kerberos libkadm55 - MIT Kerberos administration runtime libraries libkrb5-dbg - Debugging files for MIT Kerberos libkrb5-dev - Headers and development libraries for MIT Kerberos libkrb53 - MIT Kerberos runtime libraries Changes: krb5 (1.4.4-7etch2) stable-security; urgency=emergency . * MIT-SA-2007-4: The kadmin RPC library can free an uninitialized pointer or write past the end of a stack buffer. This may lead to execution of arbitrary code. (CVE-2007-2442, CVE-2007-2443) * MIT-SA-2007-5: kadmind is vulnerable to a stack buffer overflow that may lead to execution of arbitrary code. (CVE-2007-2798) Files: e3cd71d7eabf49400b3d8a1d95211f4f 876 net standard krb5_1.4.4-7etch2.dsc a675e5953bb8a29b5c6eb6f4ab0bb32a 11017910 net standard krb5_1.4.4.orig.tar.gz e75d8f6c78b237293d7304a3841555ae 1586282 net standard krb5_1.4.4-7etch2.diff.gz 3d366afb24799688b4fabd7ecc5e007a 1806006 doc optional krb5-doc_1.4.4-7etch2_all.deb 95173cebbb49797f2bde06a5a3736e46 173712 libs optional libkadm55_1.4.4-7etch2_i386.deb 47a0ae9a146e6da1dd86e95a04117024 408042 libs standard libkrb53_1.4.4-7etch2_i386.deb 808e5c1834fe320210b6a7369df44b36 123894 net optional krb5-user_1.4.4-7etch2_i386.deb 87ea7485f3693951fcabd3f873a000d2 196160 net optional krb5-clients_1.4.4-7etch2_i386.deb e081e7fb29751bd212b567327ca6fb37 79976 net optional krb5-rsh-server_1.4.4-7etch2_i386.deb ecab97060f8c6900a5d8bc8e9c6e896e 57706 net extra krb5-ftpd_1.4.4-7etch2_i386.deb dfde91574f4cfb577d6a991cec074c79 62098 net extra krb5-telnetd_1.4.4-7etch2_i386.deb c76e322bb6167e1906555527237496cd 132882 net optional krb5-kdc_1.4.4-7etch2_i386.deb 5154337142097dce09983caf06d5f56b 78266 net optional krb5-admin-server_1.4.4-7etch2_i386.deb d539aa8fcabac7a48c90599eb91701f1 679788 libdevel extra libkrb5-dev_1.4.4-7etch2_i386.deb afe34de0a092d270f109baa7ef5084e5 1037402 libdevel extra libkrb5-dbg_1.4.4-7etch2_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGgTfA+YXjQAr8dHYRAnNEAKCUPt+gGyZMqPkJG6tA/BZFR8ycsQCfQxiy 36gVGvEnRGY2bBW77QvS1Y4= =uOeq -----END PGP SIGNATURE----- Accepted: krb5-admin-server_1.4.4-7etch2_i386.deb to pool/main/k/krb5/krb5-admin-server_1.4.4-7etch2_i386.deb krb5-clients_1.4.4-7etch2_i386.deb to pool/main/k/krb5/krb5-clients_1.4.4-7etch2_i386.deb krb5-doc_1.4.4-7etch2_all.deb to pool/main/k/krb5/krb5-doc_1.4.4-7etch2_all.deb krb5-ftpd_1.4.4-7etch2_i386.deb to pool/main/k/krb5/krb5-ftpd_1.4.4-7etch2_i386.deb krb5-kdc_1.4.4-7etch2_i386.deb to pool/main/k/krb5/krb5-kdc_1.4.4-7etch2_i386.deb krb5-rsh-server_1.4.4-7etch2_i386.deb to pool/main/k/krb5/krb5-rsh-server_1.4.4-7etch2_i386.deb krb5-telnetd_1.4.4-7etch2_i386.deb to pool/main/k/krb5/krb5-telnetd_1.4.4-7etch2_i386.deb krb5-user_1.4.4-7etch2_i386.deb to pool/main/k/krb5/krb5-user_1.4.4-7etch2_i386.deb krb5_1.4.4-7etch2.diff.gz to pool/main/k/krb5/krb5_1.4.4-7etch2.diff.gz krb5_1.4.4-7etch2.dsc to pool/main/k/krb5/krb5_1.4.4-7etch2.dsc libkadm55_1.4.4-7etch2_i386.deb to pool/main/k/krb5/libkadm55_1.4.4-7etch2_i386.deb libkrb5-dbg_1.4.4-7etch2_i386.deb to pool/main/k/krb5/libkrb5-dbg_1.4.4-7etch2_i386.deb libkrb5-dev_1.4.4-7etch2_i386.deb to pool/main/k/krb5/libkrb5-dev_1.4.4-7etch2_i386.deb libkrb53_1.4.4-7etch2_i386.deb to pool/main/k/krb5/libkrb53_1.4.4-7etch2_i386.deb