-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Fri, 27 Sep 2013 16:29:32 -0600 Source: user-mode-linux Binary: user-mode-linux Architecture: source amd64 Version: 2.6.32-1um-4+48squeeze4 Distribution: squeeze-security Urgency: high Maintainer: User Mode Linux Maintainers <pkg-uml-pkgs@lists.alioth.debian.org> Changed-By: dann frazier <dannf@debian.org> Description: user-mode-linux - User-mode Linux (kernel) Changes: user-mode-linux (2.6.32-1um-4+48squeeze4) squeeze-security; urgency=high . * Rebuild against linux-source-2.6.32 (2.6.32-48squeeze4): * drivers/cdrom/cdrom.c: use kzalloc() for failing hardware (CVE-2013-2164) * ipv6: ip6_sk_dst_check() must not assume ipv6 dst (CVE-2013-2232) * af_key: fix info leaks in notify messages (CVE-2013-2234) * af_key: initialize satype in key_notify_policy_flush() (CVE-2013-2237) * block: do not pass disk names as format strings (CVE-2013-2851) * b43: stop format string leaking into error msgs (CVE-2013-2852) * sctp: Use correct sideffect command in duplicate cookie handling (CVE-2013-2206) * kernel/signal.c: stop info leak via the tkill and the tgkill syscalls (CVE-2013-2141) * HID: validate HID report id size (CVE-2013-2888) * HID: check for NULL field when setting values * Information leak in openvz quota implementation (CVE-2013-2239) * HID: pantherlord: validate output report details (CVE-2013-2892) Checksums-Sha1: 8f6883fe0c6bde9fc1ac4fa9c6b9a79ba64c6291 2070 user-mode-linux_2.6.32-1um-4+48squeeze4.dsc 1ed7d2440bef8d2b10baa0bbe41fcc7fe9d7c606 25398 user-mode-linux_2.6.32-1um-4+48squeeze4.diff.gz 705e86cff4fbe0f44243533bc839060fe704ea75 7096656 user-mode-linux_2.6.32-1um-4+48squeeze4_amd64.deb Checksums-Sha256: 395d482b3499306c47801ceee8cd97030ec642afb34b856f6d2b08638ebc8e24 2070 user-mode-linux_2.6.32-1um-4+48squeeze4.dsc bf049f9569949eab422b546875f66a293d53afd31966a3ba8355ab50b03b19cb 25398 user-mode-linux_2.6.32-1um-4+48squeeze4.diff.gz bd19df0a78576aca1baf6b7a78a0091ca7e3768721c1ac3d02a40d528339c27c 7096656 user-mode-linux_2.6.32-1um-4+48squeeze4_amd64.deb Files: fa578ea07665578f30d8f9d10cffaeae 2070 kernel extra user-mode-linux_2.6.32-1um-4+48squeeze4.dsc 925d8a6644c044da4c1cd6ef8b6baa71 25398 kernel extra user-mode-linux_2.6.32-1um-4+48squeeze4.diff.gz 541f69e7b2288f7b04b571999fa2777d 7096656 kernel extra user-mode-linux_2.6.32-1um-4+48squeeze4_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (GNU/Linux) iQIcBAEBAgAGBQJSRiwyAAoJEBv4PF5U/IZADioP/RuYOVJSrKCyVj2EC8Ri9cf5 9BqAVNu4FWme/sTQfZCPOZHi5ghSe/flMiBP7cWLp1+U7zE6UVhrJyvRCEIfbO8V 8MnULRw/3YkU/Q/m4zrqby6RVN0Z03mbwSGA1QTkN46K3RxSTAG9D8CPWNQKw1ox 1xjSWZM3gtUavuMDKalndgQKR5RuzBN2BB+eQaeGSlU3md07q29SsVdLNtgjJHv2 QkXRmNNAHXG3dhHqGRD35lq79q00VOikUO53vf6xHAtxR8EYLTA1OmxEV+QPWRI6 FPO4/JL5vRV2SEdw8OsPGMYviFtAqYNUGNR7lTaSh6inVpEjln2h1VnteSZRocA6 QeJpaviwW+v5SRNAoOmpStrZ68zKWkdDFfbCo+i5r8FknX9Zh8v4EwcB67wRQkc+ 15KlfkX3O8SL4QPut/Osw4UDbHgVm2o0BUNIQBZyS2H1+wvIYit0slovi5X3RjoT z8k9rbvbVi/dDsBWTQvqc+NP7PaRCvAwcbDBAoRHyCGdRCWiH09MXvgXi4y5XUii duztsZ0tn3GdYpiD0FT59XJ8eancMNYkpw91dVyTCFLyENatKKE3a47N9swGgy9x UKE7U9tMEse2EU6/PAHIyPiisxK0j7J0V5rA4tq2vcNVJOsqQyPL+OerHZUOVqA1 7J/XdtuRfeFf/9Eibtsf =2Qve -----END PGP SIGNATURE-----