-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Thu, 27 Sep 2007 13:01:20 -0600 Source: user-mode-linux Binary: user-mode-linux Architecture: source i386 Version: 2.6.18-1um-2etch.13etch3 Distribution: stable-security Urgency: high Maintainer: User Mode Linux Maintainers <pkg-uml-pkgs@lists.alioth.debian.org> Changed-By: dann frazier <dannf@debian.org> Description: user-mode-linux - User-mode Linux (kernel) Changes: user-mode-linux (2.6.18-1um-2etch.13etch3) stable-security; urgency=high . * NMU by the Security Team * Rebuild against linux-source-2.6.18 (2.6.18.dfsg.1-13etch3): * bugfix/ptrace-handle-bogus-selector.patch, bugfix/fixup-trace_irq-breakage.patch [SECURITY] Handle an invalid LDT segment selector %cs (the xcs field) during ptrace single-step operations that can be used to trigger a NULL-pointer dereference causing an Oops. See CVE-2007-3731 * bugfix/prevent-stack-growth-into-hugetlb-region.patch [SECURITY] Prevent OOPS during stack expansion when the VMA crosses into address space reserved for hugetlb pages. See CVE-2007-3739 * bugfix/cifs-honor-umask.patch [SECURITY] Make CIFS honor a process' umask See CVE-2007-3740 * bugfix/amd64-zero-extend-32bit-ptrace.patch [SECURITY] Zero extend all registers after ptrace in 32-bit entry path. See CVE-2007-4573 * bugfix/jffs2-ACL-vs-mode-handling.patch [SECURITY] Write correct legacy modes to the medium on inode creation to prevent incorrect permissions upon remount. See CVE-2007-4849 Files: 76ffc1795c64ab756e04659d71b448f7 892 misc extra user-mode-linux_2.6.18-1um-2etch.13etch3.dsc 80979b335d9db66a3994b5c0f9f6136b 14307 misc extra user-mode-linux_2.6.18-1um-2etch.13etch3.diff.gz 52cae7bf537d4606dd2c81ad2fecdab2 25581668 misc extra user-mode-linux_2.6.18-1um-2etch.13etch3_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFG/AUlhuANDBmkLRkRAsWgAKCLx21t07Dksp6qmakiNCqCZMR8UgCfaLFr yjecLx7P0OBKJEfAUyDkHQw= =Rxln -----END PGP SIGNATURE----- Accepted: user-mode-linux_2.6.18-1um-2etch.13etch3.diff.gz to pool/main/u/user-mode-linux/user-mode-linux_2.6.18-1um-2etch.13etch3.diff.gz user-mode-linux_2.6.18-1um-2etch.13etch3.dsc to pool/main/u/user-mode-linux/user-mode-linux_2.6.18-1um-2etch.13etch3.dsc user-mode-linux_2.6.18-1um-2etch.13etch3_i386.deb to pool/main/u/user-mode-linux/user-mode-linux_2.6.18-1um-2etch.13etch3_i386.deb