-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sat, 22 Dec 2007 13:29:41 +0000 Source: util-linux Binary: util-linux fdisk-udeb util-linux-locales bsdutils mount Architecture: source i386 all Version: 2.12p-4sarge2 Distribution: oldstable-security Urgency: high Maintainer: LaMont Jones <lamont@debian.org> Changed-By: Steffen Joeris <white@debian.org> Description: bsdutils - Basic utilities from 4.4BSD-Lite fdisk-udeb - Partition a hard drive (manual, cfdisk) (udeb) mount - Tools for mounting and manipulating filesystems util-linux - Miscellaneous system utilities util-linux-locales - Locales files for util-linux Changes: util-linux (2.12p-4sarge2) oldstable-security; urgency=high . * Non-maintainer upload by the security team * Fix privilege escalation by calling setuid() and setgid() in the wrong order and not checking the return values in mount and umount Fixes: CVE-2007-5191 Files: c16f823e59f4e6e844abb42a5d0d74c5 712 base required util-linux_2.12p-4sarge2.dsc 9e13a2463ef33b2bd1596072742f8da8 74396 base required util-linux_2.12p-4sarge2.diff.gz c2cba4219351e9af5a90e772461d7015 380538 base required util-linux_2.12p-4sarge2_i386.deb f73c85cc3e687ce28163e1ec10aa25e6 541402 debian-installer extra fdisk-udeb_2.12p-4sarge2_i386.udeb 41d4c24fcd78ef78253ffe7d0dceab22 140038 base required mount_2.12p-4sarge2_i386.deb 198a771b904f201e49d04a0a401f02ea 65834 base required bsdutils_2.12p-4sarge2_i386.deb a6404671c68d7f06a9da77b1dafc7a42 1070176 utils optional util-linux-locales_2.12p-4sarge2_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFHbRSj62zWxYk/rQcRAj6HAKCKdmdNMs9FmAekqKdC/ziBGq+rvwCfV2lY WrJ1cJm+06VfCxPvG9o9KZI= =E7jO -----END PGP SIGNATURE----- Accepted: bsdutils_2.12p-4sarge2_i386.deb to pool/main/u/util-linux/bsdutils_2.12p-4sarge2_i386.deb fdisk-udeb_2.12p-4sarge2_i386.udeb to pool/main/u/util-linux/fdisk-udeb_2.12p-4sarge2_i386.udeb mount_2.12p-4sarge2_i386.deb to pool/main/u/util-linux/mount_2.12p-4sarge2_i386.deb util-linux-locales_2.12p-4sarge2_all.deb to pool/main/u/util-linux/util-linux-locales_2.12p-4sarge2_all.deb util-linux_2.12p-4sarge2.diff.gz to pool/main/u/util-linux/util-linux_2.12p-4sarge2.diff.gz util-linux_2.12p-4sarge2.dsc to pool/main/u/util-linux/util-linux_2.12p-4sarge2.dsc util-linux_2.12p-4sarge2_i386.deb to pool/main/u/util-linux/util-linux_2.12p-4sarge2_i386.deb