-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 19 Jul 2011 22:21:04 +1000 Source: opie Binary: opie-client opie-server libopie-dev Architecture: mips Version: 2.32.dfsg.1-0.2+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: mips Build Daemon (lucatelli) Changed-By: Steffen Joeris Description: libopie-dev - OPIE library development files. opie-client - OPIE programs for generating OTPs on client machines opie-server - OPIE programs for maintaining an OTP key file Closes: 631344 631345 Changes: opie (2.32.dfsg.1-0.2+squeeze1) stable-security; urgency=high . * Non-maintainer upload by the security team * Fix off-by-one and privilege escalation via missing check for setuid() (Closes: #631344, #631345) Fixes: CVE-2011-2489 CVE-2011-2490 Checksums-Sha1: 944acf70e7ac65400887cce9f781592487b083cc 44992 opie-client_2.32.dfsg.1-0.2+squeeze1_mips.deb b3db126783022f1d039dcb25995eeba8c8a109ad 47358 opie-server_2.32.dfsg.1-0.2+squeeze1_mips.deb 9d481791c1a7be149b88c8db25a62fa0ca5b3ab2 33330 libopie-dev_2.32.dfsg.1-0.2+squeeze1_mips.deb Checksums-Sha256: c452f4395cc599be8883565f02756da38f124104424424e9309e0e3ac12641dc 44992 opie-client_2.32.dfsg.1-0.2+squeeze1_mips.deb d089564ba545e994587a6481485dc3ff302f7e1b3f0f023fa587975680092b25 47358 opie-server_2.32.dfsg.1-0.2+squeeze1_mips.deb 26085ee0ca5d62ece8d705c63283fb14b6f080dc15e466523783a69fdc530b41 33330 libopie-dev_2.32.dfsg.1-0.2+squeeze1_mips.deb Files: 82a0616279a2251f9a4b89bdfb3418c1 44992 admin optional opie-client_2.32.dfsg.1-0.2+squeeze1_mips.deb 04f05a348c5c495b770c2696b259684a 47358 admin optional opie-server_2.32.dfsg.1-0.2+squeeze1_mips.deb 79b2b2be2a69e42f50ed1c69e6b714e5 33330 devel optional libopie-dev_2.32.dfsg.1-0.2+squeeze1_mips.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQIcBAEBCAAGBQJOJfbbAAoJEL8uxsT0xpRwpPgP/jBEGn1ipQULtDDCcvAUPxvd qkGGCAEwP9sc74SxPYeXb8c/+vOUEm7uT6tnRSn/YoHJPN4Ihf8n4goERqYSzYnR 76ZvpQoCgB9RMpkSwhOl1fz1AOe7CUfulz1hQN6sFtWv8R75k3szCv+CDPILcDBF JbBEgNE1lbE0EN33bLtEmCm2HZ5XTV/k4waFctWxvyOIF2bFVBQa5iU2cF4OEKkn V06g4sZ4g3qDrJ0MEQl65bDLIHuus1ddhREkzB0L+XdLLwtoL5ZgiIqCZOIJOFmZ rNLfhYgtmOR54snqtA5lqeZm++5lICV8tO/+cp59hwyl+zV64t07LW1Hgh8D3zgY 6tLDmY4VoC+wtO2mTat7QeGp/mGOS7lxwcG7p9qUDF0Ek9tax2V8Vqq3hfL9Aghv N3XoiDGgd8pvCNqYOGWeCJZkwfh7AO2ox59iYHuE++ohb1IgjZy9tDV9LtTn0sUV PWgxR2fnp3c/UTNLYffG/fkNi/bjjUytJAdHg4rOl4OJ0KuzxYUO79Dc33rMkgS/ oBmUILMXlBOP3bx2RynCbJAx/FOcewdoRd3B8Vtea3wO3AoZ8/Gd+vI0cLRGarfI 6WLuNhmIR60dcTsTeMnXRsJS5eg8ACctaWCRGcIlwvMV/9l87Ug48c4Ge1frrmMh ZvHae7KqjRpEFW5G2XXV =Wnqe -----END PGP SIGNATURE-----