-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Tue, 30 May 2006 21:15:07 -0600 Source: kernel-patch-powerpc-2.4.27 Binary: kernel-patch-2.4.27-powerpc kernel-build-2.4.27-nubus kernel-image-2.4.27-nubus kernel-headers-2.4.27-powerpc kernel-image-2.4.27-powerpc kernel-patch-2.4.27-apus kernel-build-2.4.27-apus kernel-headers-2.4.27-nubus kernel-image-2.4.27-powerpc-small kernel-build-2.4.27-powerpc-smp kernel-image-2.4.27-powerpc-smp kernel-image-2.4.27-apus kernel-patch-2.4.27-nubus kernel-headers-2.4.27-apus kernel-build-2.4.27-powerpc kernel-build-2.4.27-powerpc-small Architecture: source powerpc Version: 2.4.27-10sarge3 Distribution: stable-security Urgency: high Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org> Changed-By: dann frazier <dannf@debian.org> Description: kernel-build-2.4.27-apus - build infrastructure for kernel version 2.4.27-apus kernel-build-2.4.27-nubus - build infrastructure for kernel version 2.4.27-nubus kernel-build-2.4.27-powerpc - build infrastructure for kernel version 2.4.27-powerpc kernel-build-2.4.27-powerpc-small - build infrastructure for kernel version 2.4.27-powerpc-small kernel-build-2.4.27-powerpc-smp - build infrastructure for kernel version 2.4.27-powerpc-smp kernel-headers-2.4.27-apus - Linux/APUS kernel headers. kernel-headers-2.4.27-nubus - Linux/nubus kernel headers. kernel-headers-2.4.27-powerpc - Linux/nubus kernel headers. kernel-image-2.4.27-apus - Linux/APUS kernel binary image. kernel-image-2.4.27-nubus - Linux/nubus kernel binary image. kernel-image-2.4.27-powerpc - Linux/PowerPC kernel binary image for the powerpc flavour kernel-image-2.4.27-powerpc-small - Linux/PowerPC kernel binary image for the powerpc-small flavour kernel-image-2.4.27-powerpc-smp - Linux/PowerPC kernel binary image for the powerpc-smp flavour kernel-patch-2.4.27-apus - Diffs to the kernel source for APUS kernel-patch-2.4.27-nubus - Diffs to the kernel source for nubus kernel-patch-2.4.27-powerpc - Diffs to the kernel source for nubus Changes: kernel-patch-powerpc-2.4.27 (2.4.27-10sarge3) stable-security; urgency=high . * Add missing build dependency on modutils * Build against kernel-tree-2.4.27-10sarge3: * 207_smbfs-chroot-escape.diff [SECURITY] Fix directory traversal vulnerability in smbfs that permits local users to escape chroot restrictions See CVE-2006-1864 * 208_ia64-die_if_kernel-returns.diff [SECURITY][ia64] Fix a potential local DoS on ia64 systems caused by an incorrect 'noreturn' attribute on die_if_kernel() See CVE-2006-0742 * 209_sctp-discard-unexpected-in-closed.diff [SECURITY] Fix remote DoS in SCTP code by discarding unexpected chunks received in CLOSED state instead of calling BUG() See CVE-2006-2271 * 210_ipv4-id-no-increment.diff [SECURITY] Fix vulnerability that allows remote attackers to conduct an Idle Scan attack, bypassing intended protections against such attacks See CVE-2006-1242 * 211_usb-gadget-rndis-bufoverflow.diff [SECURITY] Fix buffer overflow in the USB Gadget RNDIS implementation that allows for a remote DoS attack (kmalloc'd memory corruption) See CVE-2006-1368 * 212_ipv4-sin_zero_clear.diff [SECURITY] Fix local information leak in af_inet code See CVE-2006-1343 * 213_madvise_remove-restrict.diff [SECURITY] Fix vulnerability that allows local users to bypass IPC permissions and replace portions of read-only tmpfs files with zeroes. See CVE-2006-1524 * 214_mcast-ip-route-null-deref.diff [SECURITY] Fix local DoS vulnerability that allows local users to panic a system by requesting a route for a multicast IP See CVE-2006-1525 * 215_sctp-fragment-recurse.diff [SECURITY] Fix remote DoS vulnerability that can lead to infinite recursion when a packet containing two or more DATA fragments is received See CVE-2006-2274 * 216_sctp-fragmented-receive-fix.diff [SECURITY] Fix remote DoS vulnerability that allows IP fragmented COOKIE_ECHO and HEARTBEAT SCTP control chunks to cause a kernel panic See CVE-2006-2272 * 217_amd64-fp-reg-leak.diff [SECURITY][amd64] Fix an information leak that allows a process to see a portion of the floating point state of other processes, possibly exposing sensitive information. See CVE-2006-1056 * 218_do_add_counters-race.diff [SECURITY] Fix race condition in the do_add_counters() function in netfilter that allows local users with CAP_NET_ADMIN capabilities to read kernel memory See CVE-2006-0039 * 219_sctp-hb-ack-overflow.diff [SECURITY] Fix a remote buffer overflow that can result from a badly formatted HB-ACK chunk See CVE-2006-1857 * 220_sctp-param-bound-checks.diff [SECURITY] Fix a bound checking error (remote DoS) in the SCTP parameter checking code See CVE-2006-1858 * 221_netfilter-do_replace-overflow.diff [SECURITY] Fix buffer overflow in netfilter do_replace which can could be triggered by users with CAP_NET_ADMIN rights. See CVE-2006-0038 * 222_binfmt-bad-elf-entry-address.diff [SECURITY][amd64] Fix potential local DoS vulnerability in the binfmt_elf code on em64t processors See CVE-2006-0741 Files: 47ebcb365d37d7321eeee65b23920a29 1139 devel optional kernel-patch-powerpc-2.4.27_2.4.27-10sarge3.dsc 1df6018893f9772d156ccf8e3080fb2b 1463783 devel optional kernel-patch-powerpc-2.4.27_2.4.27-10sarge3.tar.gz 0f1a666913413ccac067b519949b64be 66712 devel optional kernel-patch-2.4.27-apus_2.4.27-10sarge3_powerpc.deb 1dc1ed36b3052d676aece64519c79067 4683234 devel optional kernel-headers-2.4.27-apus_2.4.27-10sarge3_powerpc.deb 6c3464992e5fd4f0c76bd6e456603b69 2499398 base optional kernel-image-2.4.27-apus_2.4.27-10sarge3_powerpc.deb 23beb8633e1bc6c71cd7c85549ddc547 141508 devel optional kernel-build-2.4.27-apus_2.4.27-10sarge3_powerpc.deb b5f469592bb45ae907c251aa762e5cdb 9944 devel optional kernel-patch-2.4.27-nubus_2.4.27-10sarge3_powerpc.deb 489de2e942db258045c9a759940ae7a7 4693350 devel optional kernel-headers-2.4.27-nubus_2.4.27-10sarge3_powerpc.deb 168aae93e0888603a192acfb55c17ea4 1817290 base optional kernel-image-2.4.27-nubus_2.4.27-10sarge3_powerpc.deb 627427945710a84e25f9a6e81cf52871 141276 devel optional kernel-build-2.4.27-nubus_2.4.27-10sarge3_powerpc.deb 61edb2922c82b932b5a51aabd4e3e962 9868 devel optional kernel-patch-2.4.27-powerpc_2.4.27-10sarge3_powerpc.deb 668fb5a82d4ac36e66da1abff65e531f 4800960 devel optional kernel-headers-2.4.27-powerpc_2.4.27-10sarge3_powerpc.deb 3e7a96afb9b6bb0618a69d490d3df3e6 13478728 base optional kernel-image-2.4.27-powerpc_2.4.27-10sarge3_powerpc.deb c357bb9b9fe6ce282b9bba63a0bdaec4 155366 devel optional kernel-build-2.4.27-powerpc_2.4.27-10sarge3_powerpc.deb b44ad17d6469962e8ad89a36e0069b0a 13785644 base optional kernel-image-2.4.27-powerpc-smp_2.4.27-10sarge3_powerpc.deb 29ef8c314e3ff4ad80a159e336f30cdd 155380 devel optional kernel-build-2.4.27-powerpc-smp_2.4.27-10sarge3_powerpc.deb 7f6aa3d1cc7c8990cf5ca2d8f5d5c128 12750476 base optional kernel-image-2.4.27-powerpc-small_2.4.27-10sarge3_powerpc.deb df66fe84dfcd04edc663ecfc295d5a60 155614 devel optional kernel-build-2.4.27-powerpc-small_2.4.27-10sarge3_powerpc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (GNU/Linux) iD8DBQFEfSt6huANDBmkLRkRAtJnAJ9KY76o2OYhdFRxOaXx4lJFxsEgGwCfRzXv ji9ZtTfr+mgBkMzC3k0KwfE= =3JKs -----END PGP SIGNATURE----- Accepted: kernel-build-2.4.27-apus_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-build-2.4.27-apus_2.4.27-10sarge3_powerpc.deb kernel-build-2.4.27-nubus_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-build-2.4.27-nubus_2.4.27-10sarge3_powerpc.deb kernel-build-2.4.27-powerpc-small_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-build-2.4.27-powerpc-small_2.4.27-10sarge3_powerpc.deb kernel-build-2.4.27-powerpc-smp_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-build-2.4.27-powerpc-smp_2.4.27-10sarge3_powerpc.deb kernel-build-2.4.27-powerpc_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-build-2.4.27-powerpc_2.4.27-10sarge3_powerpc.deb kernel-headers-2.4.27-apus_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-headers-2.4.27-apus_2.4.27-10sarge3_powerpc.deb kernel-headers-2.4.27-nubus_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-headers-2.4.27-nubus_2.4.27-10sarge3_powerpc.deb kernel-headers-2.4.27-powerpc_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-headers-2.4.27-powerpc_2.4.27-10sarge3_powerpc.deb kernel-image-2.4.27-apus_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-image-2.4.27-apus_2.4.27-10sarge3_powerpc.deb kernel-image-2.4.27-nubus_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-image-2.4.27-nubus_2.4.27-10sarge3_powerpc.deb kernel-image-2.4.27-powerpc-small_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-image-2.4.27-powerpc-small_2.4.27-10sarge3_powerpc.deb kernel-image-2.4.27-powerpc-smp_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-image-2.4.27-powerpc-smp_2.4.27-10sarge3_powerpc.deb kernel-image-2.4.27-powerpc_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-image-2.4.27-powerpc_2.4.27-10sarge3_powerpc.deb kernel-patch-2.4.27-apus_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-patch-2.4.27-apus_2.4.27-10sarge3_powerpc.deb kernel-patch-2.4.27-nubus_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-patch-2.4.27-nubus_2.4.27-10sarge3_powerpc.deb kernel-patch-2.4.27-powerpc_2.4.27-10sarge3_powerpc.deb to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-patch-2.4.27-powerpc_2.4.27-10sarge3_powerpc.deb kernel-patch-powerpc-2.4.27_2.4.27-10sarge3.dsc to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-patch-powerpc-2.4.27_2.4.27-10sarge3.dsc kernel-patch-powerpc-2.4.27_2.4.27-10sarge3.tar.gz to pool/main/k/kernel-patch-powerpc-2.4.27/kernel-patch-powerpc-2.4.27_2.4.27-10sarge3.tar.gz