-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sun, 17 Feb 2008 23:49:12 -0700 Source: kernel-image-2.4.27-sparc Binary: kernel-headers-2.4.27-4-sparc64 kernel-headers-2.4.27-4-sparc32-smp kernel-headers-2.4.27-4-sparc32 kernel-headers-2.4.27-4 kernel-image-2.4.27-4-sparc64 kernel-image-2.4.27-4-sparc32 kernel-headers-2.4.27-4-sparc64-smp kernel-image-2.4.27-4-sparc64-smp kernel-image-2.4.27-4-sparc32-smp kernel-build-2.4.27-4 Architecture: source sparc Version: 2.4.27-9sarge6 Distribution: oldstable-security Urgency: high Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org> Changed-By: dann frazier <dannf@debian.org> Description: kernel-build-2.4.27-4 - Headers for building modules for Linux 2.4.27 kernel-headers-2.4.27-4 - Header files related to Linux kernel version 2.4.27 kernel-headers-2.4.27-4-sparc32 - Header files for Linux kernel 2.4.27 on uniprocessor 32-bit SPARC kernel-headers-2.4.27-4-sparc32-smp - Header files for Linux kernel 2.4.27 on multiprocessor 32-bit SPA kernel-headers-2.4.27-4-sparc64 - Header files for Linux kernel 2.4.27 on uniprocessor 64-bit SPARC kernel-headers-2.4.27-4-sparc64-smp - Header files for Linux kernel 2.4.27 on multiprocessor 64-bit SPA kernel-image-2.4.27-4-sparc32 - Linux kernel binary image for sun4c, sun4m and sun4d kernel-image-2.4.27-4-sparc32-smp - Linux kernel binary image for SMP sun4m and sun4d kernel-image-2.4.27-4-sparc64 - Linux kernel binary image for UltraSPARC (sparc64) systems kernel-image-2.4.27-4-sparc64-smp - Linux kernel binary image for SMP UltraSPARC (sparc64) systems Changes: kernel-image-2.4.27-sparc (2.4.27-9sarge6) oldstable-security; urgency=high . * Build against kernel-tree-2.4.27-10sarge6: * 239_mincore-hang.diff [SECURITY] Fix a potential deadlock in mincore See CVE-2006-4814 * [ERRATA] 240_smbfs-honor-mount-opts-2.diff Fix some regressions with respect to file types (e.g., symlinks) introduced by the fix for CVE-2006-5871 in 2.4.27-10sarge5 * 241_bluetooth-capi-size-checks.diff [SECURITY] Add additional length checks to avoid potential remote DoS attacks in the handling of CAPI messages in the bluetooth driver See CVE-2006-6106 * 242_ext3-fsfuzz.diff [SECURITY] Fix a DoS vulnerability that can be triggered by a local user with the ability to mount a corrupted ext3 filesystem See CVE-2006-6053 * 243_ipv6_fl_socklist-no-share.diff [SECURITY] Fix local DoS vulnerability caused by inadvertently sharing ipv6_fl_socklist between the listening socket and the socket created for connection. See CVE-2007-1592 * 244_bluetooth-l2cap-hci-info-leaks.diff 245_bluetooth-l2cap-hci-info-leaks-2.diff [SECURITY] Fix information leaks in setsockopt() implementations See CVE-2007-1353 * 246_dn_fib-out-of-bounds.diff 266_ipv4-fib_props-out-of-bounds.diff 267_ipv4-fib_props-out-of-bounds-2.diff [SECURITY] Fix out of bounds condition in dn_fib_props[] See CVE-2007-2172 * 247_reset-pdeathsig-on-suid.diff [SECURITY] Fix potential privilege escalation caused by improper clearing of the child process' pdeath signal. Thanks to Marcel Holtmann for the patch. See CVE-2007-3848 * 248_random-reseed-sizeof-fix.diff [SECURITY] Fix a bug in the random driver reseeding code that reduces entropy by reseeding a smaller buffer size than expected See CVE-2007-4311 * 249_openpromfs-signedness-bug.diff 250_openpromfs-checks-1.diff 251_openpromfs-checks-2.diff 252_openpromfs-checks-3.diff [SECURITY] Fix a number of data checks in openprom code See CVE-2004-2731 * 253_coredump-only-to-same-uid.diff [SECURITY] Fix an issue where core dumping over a file that already exists retains the ownership of the original file See CVE-2007-6206 * 254_cramfs-check-block-length.diff [SECURITY] Add a sanity check of the block length in cramfs_readpage to avoid a potential oops condition See CVE-2006-5823 * 255_pppoe-socket-release-mem-leak.diff [SECURITY] fix unpriveleged memory leak when a PPPoE socket is released after connect but before PPPIOCGCHAN ioctl is called upon it See CVE-2007-2525 * 256_i4l-isdn_ioctl-mem-overrun.diff [SECURITY] Fix potential isdn ioctl memory overrun See CVE-2007-6151 * 257_isdn-net-overflow.diff [SECURITY] Fix potential overflows in the ISDN subsystem See CVE-2007-6063 * 258_ext2_readdir-f_pos-fix.diff, 259_ext2_readdir-infinite-loop.diff, 260_ext2-skip-pages-past-num-blocks.diff [SECURITY] Add some sanity checking for a corrupted i_size in ext2_find_entry() See CVE-2006-6054 * 261_listxattr-mem-corruption.diff [SECURITY] Fix userspace corruption vulnerability caused by incorrectly promoted return values in bad_inode_ops This patches changes the kernel ABI. See CVE-2006-5753 * 262_aacraid-ioctl-perm-check.diff [SECURITY] Require admin capabilities to issue ioctls to aacraid devices See CVE-2007-4308 * 263_usb-pwc-disconnect-block.diff [SECURITY] Fix issue with unplugging webcams that use the pwc driver. If userspace still has the device open it can result, the driver would wait for the device to close, blocking the USB subsystem. See CVE-2007-5093 * 264_mmap-VM_DONTEXPAND.diff [SECURITY] Add VM_DONTEXPAND to vm_flags in drivers that register a fault handler but do not bounds check the offset argument See CVE-2008-0007 * 265_powerpc-chrp-null-deref.diff [SECURITY][powerpc] Fix NULL pointer dereference if get_property fails on the subarchitecture See CVE-2007-6694 * ABI changing update, increment ABI number to 4. If you don't understand what this means, see http://wiki.debian.org/DebianKernelABIChanges Files: 872a5a07e8a19c0544ca02dccc59730c 1074 devel optional kernel-image-2.4.27-sparc_2.4.27-9sarge6.dsc 6401b539084d362190963c16487ac91d 26268 devel optional kernel-image-2.4.27-sparc_2.4.27-9sarge6.tar.gz 5f91e658e46a6d7b7bdf184bc51d5868 2063174 devel optional kernel-headers-2.4.27-4_2.4.27-9sarge6_sparc.deb a659ec6ca6d0fbd1514c5423bac879e9 206334 devel optional kernel-headers-2.4.27-4-sparc64-smp_2.4.27-9sarge6_sparc.deb 1df415fa9711c74f3c344271bf8ecf0d 6555152 base optional kernel-image-2.4.27-4-sparc64-smp_2.4.27-9sarge6_sparc.deb ee5ba57e8ee80b5e7aedd28223db597f 166596 devel optional kernel-headers-2.4.27-4-sparc32_2.4.27-9sarge6_sparc.deb a5c1e2b59cb0c343a22ea70a1c125692 3607258 base optional kernel-image-2.4.27-4-sparc32_2.4.27-9sarge6_sparc.deb a0c16b5ed34ca2a6f7b2ed8bdab19f84 168392 devel optional kernel-headers-2.4.27-4-sparc32-smp_2.4.27-9sarge6_sparc.deb c3c25c364e5c6c8eaf5fc73c95d53095 3796458 base optional kernel-image-2.4.27-4-sparc32-smp_2.4.27-9sarge6_sparc.deb f8d2bd0fa36e751487006104cad3edc8 204932 devel optional kernel-headers-2.4.27-4-sparc64_2.4.27-9sarge6_sparc.deb 95135f6d77474f138d24322ccb7d505f 6390868 base optional kernel-image-2.4.27-4-sparc64_2.4.27-9sarge6_sparc.deb a1c148d768477fc35842fdd0250869d6 12010 devel optional kernel-build-2.4.27-4_2.4.27-9sarge6_sparc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFHvNTmhuANDBmkLRkRAn7pAJ4vZqL7KgZxfw2E2PiTpA4DQKQqzACfeBLk rf6aYZOWYpWMYE7m6+tDLKY= =buUK -----END PGP SIGNATURE----- Accepted: kernel-build-2.4.27-4_2.4.27-9sarge6_sparc.deb to pool/main/k/kernel-image-2.4.27-sparc/kernel-build-2.4.27-4_2.4.27-9sarge6_sparc.deb kernel-headers-2.4.27-4-sparc32-smp_2.4.27-9sarge6_sparc.deb to pool/main/k/kernel-image-2.4.27-sparc/kernel-headers-2.4.27-4-sparc32-smp_2.4.27-9sarge6_sparc.deb kernel-headers-2.4.27-4-sparc32_2.4.27-9sarge6_sparc.deb to pool/main/k/kernel-image-2.4.27-sparc/kernel-headers-2.4.27-4-sparc32_2.4.27-9sarge6_sparc.deb kernel-headers-2.4.27-4-sparc64-smp_2.4.27-9sarge6_sparc.deb to pool/main/k/kernel-image-2.4.27-sparc/kernel-headers-2.4.27-4-sparc64-smp_2.4.27-9sarge6_sparc.deb kernel-headers-2.4.27-4-sparc64_2.4.27-9sarge6_sparc.deb to pool/main/k/kernel-image-2.4.27-sparc/kernel-headers-2.4.27-4-sparc64_2.4.27-9sarge6_sparc.deb kernel-headers-2.4.27-4_2.4.27-9sarge6_sparc.deb to pool/main/k/kernel-image-2.4.27-sparc/kernel-headers-2.4.27-4_2.4.27-9sarge6_sparc.deb kernel-image-2.4.27-4-sparc32-smp_2.4.27-9sarge6_sparc.deb to pool/main/k/kernel-image-2.4.27-sparc/kernel-image-2.4.27-4-sparc32-smp_2.4.27-9sarge6_sparc.deb kernel-image-2.4.27-4-sparc32_2.4.27-9sarge6_sparc.deb to pool/main/k/kernel-image-2.4.27-sparc/kernel-image-2.4.27-4-sparc32_2.4.27-9sarge6_sparc.deb kernel-image-2.4.27-4-sparc64-smp_2.4.27-9sarge6_sparc.deb to pool/main/k/kernel-image-2.4.27-sparc/kernel-image-2.4.27-4-sparc64-smp_2.4.27-9sarge6_sparc.deb kernel-image-2.4.27-4-sparc64_2.4.27-9sarge6_sparc.deb to pool/main/k/kernel-image-2.4.27-sparc/kernel-image-2.4.27-4-sparc64_2.4.27-9sarge6_sparc.deb kernel-image-2.4.27-sparc_2.4.27-9sarge6.dsc to pool/main/k/kernel-image-2.4.27-sparc/kernel-image-2.4.27-sparc_2.4.27-9sarge6.dsc kernel-image-2.4.27-sparc_2.4.27-9sarge6.tar.gz to pool/main/k/kernel-image-2.4.27-sparc/kernel-image-2.4.27-sparc_2.4.27-9sarge6.tar.gz