Accepted kernel-image-2.4.27-alpha 2.4.27-10sarge3 (source alpha)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Mon, 29 May 2006 17:08:03 -0600
Source: kernel-image-2.4.27-alpha
Binary: kernel-image-2.4.27-3-generic kernel-headers-2.4.27-3-generic kernel-headers-2.4.27-3 kernel-build-2.4.27-3 kernel-image-2.4.27-3-smp kernel-headers-2.4.27-3-smp
Architecture: source alpha
Version: 2.4.27-10sarge3
Distribution: stable-security
Urgency: high
Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
Changed-By: dann frazier <dannf@debian.org>
Description:
kernel-build-2.4.27-3 - Headers for building modules for Linux 2.4.27
kernel-headers-2.4.27-3 - Header files related to Linux kernel version 2.4.27
kernel-headers-2.4.27-3-generic - Linux kernel headers 2.4.27 on Alpha
kernel-headers-2.4.27-3-smp - Linux kernel headers 2.4.27 on Alpha SMP
kernel-image-2.4.27-3-generic - Linux kernel image for version 2.4.27 on Alpha.
kernel-image-2.4.27-3-smp - Linux kernel image for version 2.4.27 on Alpha SMP.
Changes:
kernel-image-2.4.27-alpha (2.4.27-10sarge3) stable-security; urgency=high
.
* Build against kernel-tree-2.4.27-10sarge3:
* 207_smbfs-chroot-escape.diff
[SECURITY] Fix directory traversal vulnerability in smbfs that permits
local users to escape chroot restrictions
See CVE-2006-1864
* 208_ia64-die_if_kernel-returns.diff
[SECURITY][ia64] Fix a potential local DoS on ia64 systems caused by
an incorrect 'noreturn' attribute on die_if_kernel()
See CVE-2006-0742
* 209_sctp-discard-unexpected-in-closed.diff
[SECURITY] Fix remote DoS in SCTP code by discarding unexpected chunks
received in CLOSED state instead of calling BUG()
See CVE-2006-2271
* 210_ipv4-id-no-increment.diff
[SECURITY] Fix vulnerability that allows remote attackers to conduct an
Idle Scan attack, bypassing intended protections against such attacks
See CVE-2006-1242
* 211_usb-gadget-rndis-bufoverflow.diff
[SECURITY] Fix buffer overflow in the USB Gadget RNDIS implementation
that allows for a remote DoS attack (kmalloc'd memory corruption)
See CVE-2006-1368
* 212_ipv4-sin_zero_clear.diff
[SECURITY] Fix local information leak in af_inet code
See CVE-2006-1343
* 213_madvise_remove-restrict.diff
[SECURITY] Fix vulnerability that allows local users to bypass IPC
permissions and replace portions of read-only tmpfs files with zeroes.
See CVE-2006-1524
* 214_mcast-ip-route-null-deref.diff
[SECURITY] Fix local DoS vulnerability that allows local users to panic
a system by requesting a route for a multicast IP
See CVE-2006-1525
* 215_sctp-fragment-recurse.diff
[SECURITY] Fix remote DoS vulnerability that can lead to infinite
recursion when a packet containing two or more DATA fragments is received
See CVE-2006-2274
* 216_sctp-fragmented-receive-fix.diff
[SECURITY] Fix remote DoS vulnerability that allows IP fragmented
COOKIE_ECHO and HEARTBEAT SCTP control chunks to cause a kernel panic
See CVE-2006-2272
* 217_amd64-fp-reg-leak.diff
[SECURITY][amd64] Fix an information leak that allows a process to see
a portion of the floating point state of other processes, possibly
exposing sensitive information.
See CVE-2006-1056
* 218_do_add_counters-race.diff
[SECURITY] Fix race condition in the do_add_counters() function in
netfilter that allows local users with CAP_NET_ADMIN capabilities to
read kernel memory
See CVE-2006-0039
* 219_sctp-hb-ack-overflow.diff
[SECURITY] Fix a remote buffer overflow that can result from a badly
formatted HB-ACK chunk
See CVE-2006-1857
* 220_sctp-param-bound-checks.diff
[SECURITY] Fix a bound checking error (remote DoS) in the SCTP parameter
checking code
See CVE-2006-1858
* 221_netfilter-do_replace-overflow.diff
[SECURITY] Fix buffer overflow in netfilter do_replace which can could
be triggered by users with CAP_NET_ADMIN rights.
See CVE-2006-0038
* 222_binfmt-bad-elf-entry-address.diff
[SECURITY][amd64] Fix potential local DoS vulnerability in the binfmt_elf
code on em64t processors
See CVE-2006-0741
Files:
4aa4330d08a7829fbe9a548d1d8bab2f 831 devel optional kernel-image-2.4.27-alpha_2.4.27-10sarge3.dsc
2d05a7a176dba04f37719199efa494b7 31177 devel optional kernel-image-2.4.27-alpha_2.4.27-10sarge3.tar.gz
ad755c6e0a640be87f44d0eeb3cb0b9d 4573588 devel optional kernel-headers-2.4.27-3_2.4.27-10sarge3_alpha.deb
b675644b9520620077d740f5033e311c 274064 devel optional kernel-headers-2.4.27-3-smp_2.4.27-10sarge3_alpha.deb
9bb2d088907ead2c2e689c139e945ef9 16966302 base optional kernel-image-2.4.27-3-smp_2.4.27-10sarge3_alpha.deb
56ec516e9425c915a04a2a7184d15192 272284 devel optional kernel-headers-2.4.27-3-generic_2.4.27-10sarge3_alpha.deb
4975ec76eb158179d36de7746cab88ba 16521602 base optional kernel-image-2.4.27-3-generic_2.4.27-10sarge3_alpha.deb
5af591a1a57ca5b7b5ce7af39d0c30f8 6930 devel optional kernel-build-2.4.27-3_2.4.27-10sarge3_alpha.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (GNU/Linux)
iD8DBQFEfGSihuANDBmkLRkRArnZAJ494godk1DDDLPjBnFzyRD7u5SJeACgieX9
iPTAC7RF0lnl2aeyEw0Vp7g=
=0Df+
-----END PGP SIGNATURE-----
Accepted:
kernel-build-2.4.27-3_2.4.27-10sarge3_alpha.deb
to pool/main/k/kernel-image-2.4.27-alpha/kernel-build-2.4.27-3_2.4.27-10sarge3_alpha.deb
kernel-headers-2.4.27-3-generic_2.4.27-10sarge3_alpha.deb
to pool/main/k/kernel-image-2.4.27-alpha/kernel-headers-2.4.27-3-generic_2.4.27-10sarge3_alpha.deb
kernel-headers-2.4.27-3-smp_2.4.27-10sarge3_alpha.deb
to pool/main/k/kernel-image-2.4.27-alpha/kernel-headers-2.4.27-3-smp_2.4.27-10sarge3_alpha.deb
kernel-headers-2.4.27-3_2.4.27-10sarge3_alpha.deb
to pool/main/k/kernel-image-2.4.27-alpha/kernel-headers-2.4.27-3_2.4.27-10sarge3_alpha.deb
kernel-image-2.4.27-3-generic_2.4.27-10sarge3_alpha.deb
to pool/main/k/kernel-image-2.4.27-alpha/kernel-image-2.4.27-3-generic_2.4.27-10sarge3_alpha.deb
kernel-image-2.4.27-3-smp_2.4.27-10sarge3_alpha.deb
to pool/main/k/kernel-image-2.4.27-alpha/kernel-image-2.4.27-3-smp_2.4.27-10sarge3_alpha.deb
kernel-image-2.4.27-alpha_2.4.27-10sarge3.dsc
to pool/main/k/kernel-image-2.4.27-alpha/kernel-image-2.4.27-alpha_2.4.27-10sarge3.dsc
kernel-image-2.4.27-alpha_2.4.27-10sarge3.tar.gz
to pool/main/k/kernel-image-2.4.27-alpha/kernel-image-2.4.27-alpha_2.4.27-10sarge3.tar.gz
Reply to: