[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

CSIRTUK ADVISORY - 3273 - Debian - Security Advisories gimp, mozilla-firefox,xulrunner, iceweasel, icceape, clamav, bind9



______________________________________________________________________________


CSIRTUK ADVISORY - 3273 dated 26.07.07 time 16:00

Centre for the Protection of National Infrastructure

______________________________________________________________________________

 Further details about CPNI, including information about our products can be

 found at www.cpni.gov.uk
______________________________________________________________________________

Title
=====
Several Debian Security Advisories

Detail
======

Several Debian Security Advisories
ID: 3273
Date: 26 July 2007 11:58

-------------------------------------------------------------------------------
Title: Several Debian Security Advisories

Abstract: Details of several Debian security advisories

Vendors affected:Debian
Operating Systems affected: Linux
Applications affected:gimp, mozilla-firefox,xulrunner, iceweasel, icceape,
clamav, bind9
Advisory type: Information
Warning Status: Information only
Availability of fix: Available
Type of fix: Patch
Source: Debian
Reliability of source: Known
Source URL: http://security.debian.org/

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 1335-1                    security@xxxxxxxxxx
http://www.debian.org/security/                         Moritz Muehlenhoff
July 18th, 2007                         http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : gimp
Vulnerability  : several
Problem-Type   : local(remote)
Debian-specific: no
CVE ID         : CVE-2006-4519 CVE-2007-2949

Several remote vulnerabilities have been discovered in Gimp, the GNU Image
Manipulation Program, which might lead to the execution of arbitrary code.
The Common Vulnerabilities and Exposures project identifies the following
problems:

CVE-2006-4519

    Sean Larsson discovered several integer overflows in the processing
    code for DICOM, PNM, PSD, RAS, XBM and XWD images, which might lead
    to the execution of arbitrary code if a user is tricked into opening
    such a malformed media file.

CVE-2007-2949

    Stefan Cornelius discovered an integer overflow in the processing
    code for PSD images, which might lead to the execution of arbitrary
    code if a user is tricked into opening such a malformed media file.

For the oldstable distribution (sarge) these problems have been fixed in
version 2.2.6-1sarge4. Packages for mips and mipsel are not yet available.

For the stable distribution (etch) these problems have been fixed in version
2.2.13-1etch4. Packages for mips are not yet available.

For the unstable distribution (sid) these problems have been fixed in version
2.2.17-1.

We recommend that you upgrade your gimp packages.


Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as
given below:

apt-get update
        will update the internal database apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the footer to the
proper configuration.


Debian GNU/Linux 3.1 alias sarge
- --------------------------------


  Source archives:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4.dsc
      Size/MD5 checksum:     1089 344f1d886ca3e9d1c9667a82d3bfe5c8
    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4.diff.gz
      Size/MD5 checksum:    33037 d311b98590cfc013a797b634d218cd70
    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6.orig.tar.gz
      Size/MD5 checksum: 20496404 a6450200858c59bb46ace6987f1fc6ee

  Architecture independent components:

    http://security.debian.org/pool/updates/main/g/gimp/gimp-data_2.2.6-1sarge4_all.deb
      Size/MD5 checksum:  6276298 3fb6080d9ae6e19ab433f8dedda6b998
    http://security.debian.org/pool/updates/main/g/gimp/gimp1.2_2.2.6-1sarge4_all.deb
      Size/MD5 checksum:    31856 485fe214852413df46436416a690e4c9
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-doc_2.2.6-1sarge4_all.deb
      Size/MD5 checksum:   515094 66bbc311d11232cf5b445cada1a1b78a

  Alpha architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_alpha.deb
      Size/MD5 checksum:  3892160 c82b24236425fde06cb0c637be2e6255
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_alpha.deb
      Size/MD5 checksum:    45364 0b6bc7fef786373f1bb69d3dbbe4ee91
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_alpha.deb
      Size/MD5 checksum:   127204 2db0f7923864de7445943114ad849e3f
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_alpha.deb
      Size/MD5 checksum:    45162 ae941c83c93a8f90a37462ddf285b8b2
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_alpha.deb
      Size/MD5 checksum:   577106 f662b5fecd51821f51f2d890e481ae76
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_alpha.deb
      Size/MD5 checksum:    99256 74c769611be9a5b8f26cc15d6912fe76

  AMD64 architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_amd64.deb
      Size/MD5 checksum:  3268176 62c840774d113ecf009d24eb928f092f
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_amd64.deb
      Size/MD5 checksum:    43898 953d58ebf20c56f15290655e562ef360
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_amd64.deb
      Size/MD5 checksum:   122184 4121ee3d5953b430207fad46542cf8eb
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_amd64.deb
      Size/MD5 checksum:    43646 f9004008612ffe6238eac0fbc8b994b1
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_amd64.deb
      Size/MD5 checksum:   543996 95741b9ea838a33f3db6cee5658d4672
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_amd64.deb
      Size/MD5 checksum:    98434 e04ef4ce3ae063940908e396f6bf9d74

  ARM architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_arm.deb
      Size/MD5 checksum:  2940312 2493d55605cfc6658d5aa3cc8c030ed0
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_arm.deb
      Size/MD5 checksum:    42112 d6314e21d289b262504237162bea5ff6
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_arm.deb
      Size/MD5 checksum:   114212 f8d53f138e916ba33fca401aeb0ad02d
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_arm.deb
      Size/MD5 checksum:    42458 d9d252d1c1cfbe1ca9e3c65f27b4068c
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_arm.deb
      Size/MD5 checksum:   507900 a73ff8bb7a989343e905133c63ffd1e9
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_arm.deb
      Size/MD5 checksum:    98598 08ab629c6deb1ead4cf335f0ded999b7

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_hppa.deb
      Size/MD5 checksum:  3470636 e7de1e4d1ec5bc9718af90549d9744e2
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_hppa.deb
      Size/MD5 checksum:    43566 f3f38b7ce093d53c2a4915382a12ceae
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_hppa.deb
      Size/MD5 checksum:   125852 41638214f7c8acd34af3d8034d7b3500
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_hppa.deb
      Size/MD5 checksum:    43892 08151f6d298e5741a586b6052c5ef03e
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_hppa.deb
      Size/MD5 checksum:   583230 a8088b3cb18abb2547e72d4f71d08363
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_hppa.deb
      Size/MD5 checksum:    98498 19d31834218921f77a8ba8e16dc088b7

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_i386.deb
      Size/MD5 checksum:  3089518 b473d9f9280b725d567ae96ebd082f34
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_i386.deb
      Size/MD5 checksum:    42880 784cc603f0c3d6ad709780b1aae0b151
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_i386.deb
      Size/MD5 checksum:   117196 2f695d3a2b9dec8cc125a591aae725a7
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_i386.deb
      Size/MD5 checksum:    43434 664262c600381bf091aa69088f6ad3da
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_i386.deb
      Size/MD5 checksum:   521946 25ffbded4a587c00d1b17a9afb9cef77
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_i386.deb
      Size/MD5 checksum:    98488 23fc02e84e4f1b7598caf0a71bc316a7

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_ia64.deb
      Size/MD5 checksum:  4585190 e38c9123c056ffc323bab598eb479875
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_ia64.deb
      Size/MD5 checksum:    46774 4b2bf244587c1bdce7d470453eb9408e
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_ia64.deb
      Size/MD5 checksum:   135982 a0e6ac478432aea34f74a2e3db6f3860
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_ia64.deb
      Size/MD5 checksum:    47034 c2bc3cdff704cb23e692786f974d9116
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_ia64.deb
      Size/MD5 checksum:   632496 ace8aa10d26a79fa1badcbeaedd7dc2e
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_ia64.deb
      Size/MD5 checksum:    98426 50b40fe8def3ac3f4fd8973a207cacc4

  Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_m68k.deb
      Size/MD5 checksum:  2699532 17c29208f228b8351321c3a98d561291
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_m68k.deb
      Size/MD5 checksum:    42492 9b97613be40d9eb9d55699005a56ed87
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_m68k.deb
      Size/MD5 checksum:   118584 5ef40a973b3d098b2da89252778be55d
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_m68k.deb
      Size/MD5 checksum:    42320 cb17d1f2e81926211723b23805895a4f
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_m68k.deb
      Size/MD5 checksum:   520286 46775f63f758ddfb629d2d0f18802e84
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_m68k.deb
      Size/MD5 checksum:    98800 79b8ae5f55fd7ac1273af0e5c318480a

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_powerpc.deb
      Size/MD5 checksum:  3343462 79b8a7e0910ae9fc973e8fff4b695fa2
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_powerpc.deb
      Size/MD5 checksum:    44110 74f74f9cf0a1d76badc99b7b56f6c77b
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_powerpc.deb
      Size/MD5 checksum:   118374 2a5e90f27e3c5c79aeb1d461c9cf0817
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_powerpc.deb
      Size/MD5 checksum:    44496 60078805dc7d6a7c389f7886e720cb33
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_powerpc.deb
      Size/MD5 checksum:   539680 bcb8da84b8ee954f3ed31605d0745c42
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_powerpc.deb
      Size/MD5 checksum:    98462 72848784cc2f1a7f0b199998ff1cef26

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_s390.deb
      Size/MD5 checksum:  3135354 83173a0c68154ed5721eb9d55858d463
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_s390.deb
      Size/MD5 checksum:    44078 4ccaa516d9575c8b1c5baf86f1e52776
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_s390.deb
      Size/MD5 checksum:   124092 189cab70a7a0e4bc2054d0e806fd1473
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_s390.deb
      Size/MD5 checksum:    43694 2759a8e54806525d3277be6dd2140bce
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_s390.deb
      Size/MD5 checksum:   555680 012596aeb64bf598d989d97d4fd02781
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_s390.deb
      Size/MD5 checksum:    98424 041750d88d93e72eb7af01a220a0525e

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.6-1sarge4_sparc.deb
      Size/MD5 checksum:  2930854 eed7a101771b1db48951a96bffd351b5
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.6-1sarge4_sparc.deb
      Size/MD5 checksum:    42422 a4a2ed8e81beb480747c23a4a9a6f812
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.6-1sarge4_sparc.deb
      Size/MD5 checksum:   116596 8f35f18d3254f1914e4e668e1b92c685
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.6-1sarge4_sparc.deb
      Size/MD5 checksum:    42620 8c78a5e81327ef350fd139e60459fa4f
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.6-1sarge4_sparc.deb
      Size/MD5 checksum:   527586 88012ea10fc33b2e04c661599fc65a03
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.6-1sarge4_sparc.deb
      Size/MD5 checksum:    98508 4ccd0cec811f0c0dc65c98715a93a423


Debian GNU/Linux 4.0 alias etch
- -------------------------------


  Source archives:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4.dsc
      Size/MD5 checksum:     1269 0596a7c11c1d70e55ba5590a225d3d5a
    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4.diff.gz
      Size/MD5 checksum:   125338 44ec8d280b8e086c69ef028efc4d920b
    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13.orig.tar.gz
      Size/MD5 checksum: 18816434 20c3cd6b730c11da4d70671ed047f803

  Architecture independent components:

    http://security.debian.org/pool/updates/main/g/gimp/gimp-data_2.2.13-1etch4_all.deb
      Size/MD5 checksum:  6754588 5a4d383bdd68ff44a61de72ed9c51250
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-doc_2.2.13-1etch4_all.deb
      Size/MD5 checksum:   556382 4913e9c4e8e0e55f35c9de72465511e3

  Alpha architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_alpha.deb
      Size/MD5 checksum:  3676040 50304f3a0da75b5f7e3d34645c76eba6
    http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_alpha.deb
      Size/MD5 checksum:  8302590 d5ffe3abf9edfdfd4d8fce47f60cd136
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_alpha.deb
      Size/MD5 checksum:    66302 6ab98691c5dade22b848a21aadfa54fd
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_alpha.deb
      Size/MD5 checksum:   148510 d36c93836e3e40514a26c6b2cd9a0d96
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_alpha.deb
      Size/MD5 checksum:    66706 463194d470bbd99c9f0a4519ef610f97
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_alpha.deb
      Size/MD5 checksum:   605170 b1f3f4b1029744e20123503ee9893f5f
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_alpha.deb
      Size/MD5 checksum:   120014 33819b44f9a51043e9aea671f1278cb3

  AMD64 architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_amd64.deb
      Size/MD5 checksum:  3223048 7790f925fd51e43cfb65259dd47cadfb
    http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_amd64.deb
      Size/MD5 checksum:  8388544 f2adc19ac6418c550b2f9e8a1805021f
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_amd64.deb
      Size/MD5 checksum:    64970 075509e7aac52204e669edee0a98777b
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_amd64.deb
      Size/MD5 checksum:   145760 985698d84cea9038c81fe7c0b9a429d4
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_amd64.deb
      Size/MD5 checksum:    65190 7a44fd97bd80e82e0b906a8bdc0e8306
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_amd64.deb
      Size/MD5 checksum:   574488 1b0756695599bee7718af646cdffdb52
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_amd64.deb
      Size/MD5 checksum:   119556 9d630b9492be0ffd4dfa75978ca1495f

  ARM architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_arm.deb
      Size/MD5 checksum:  2950052 2fef032b294422ea5f8542d710426814
    http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_arm.deb
      Size/MD5 checksum:  7985794 71994163262a31d834e6f6bf672f26c2
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_arm.deb
      Size/MD5 checksum:    63376 0c1b57927839172a25279ce302f56c3b
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_arm.deb
      Size/MD5 checksum:   137348 ac2a5d8b88759a73b4620107a2f69576
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_arm.deb
      Size/MD5 checksum:    64066 9e066f44626fcdeb072650f046e6c0de
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_arm.deb
      Size/MD5 checksum:   535542 2186220b55dfb47930aea58a63279911
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_arm.deb
      Size/MD5 checksum:   119762 80f49af1823c96a3983f8fba38bf0ba4

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_hppa.deb
      Size/MD5 checksum:  3482258 cf283dfeadb58c89305947f29dd36d15
    http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_hppa.deb
      Size/MD5 checksum:  7989724 42213931370d96182daa27797c37e994
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_hppa.deb
      Size/MD5 checksum:    65120 4397a44052c2368f3440834cd26214d7
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_hppa.deb
      Size/MD5 checksum:   150190 444fa222be9458e3038fd49b20c8f143
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_hppa.deb
      Size/MD5 checksum:    65628 b780260cdff279fc3f307d52b573398d
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_hppa.deb
      Size/MD5 checksum:   606218 9dc70700ffe03cd3b926b333c8d756ea
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_hppa.deb
      Size/MD5 checksum:   119620 9fbd3bd17be5f8aefd1fa2b86f5e02f0

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_i386.deb
      Size/MD5 checksum:  3069206 b0af23173d88f8fd5b88b2af4c2fce14
    http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_i386.deb
      Size/MD5 checksum:  7781816 b66e02681ca7785997d85302752b9e92
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_i386.deb
      Size/MD5 checksum:    64264 04a4e8c43f1a6363ea2670a35248662c
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_i386.deb
      Size/MD5 checksum:   139964 d7feadabc45564c2fd0a2c300a3ad42f
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_i386.deb
      Size/MD5 checksum:    64892 43bc0ccf10bd8dd4a9e3d03235112575
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_i386.deb
      Size/MD5 checksum:   547192 d22f64b9f76d890574f3ef6f3b29ce0a
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_i386.deb
      Size/MD5 checksum:   119598 a96aa6a76a31ba306e0e59ec934beaae

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_ia64.deb
      Size/MD5 checksum:  4801200 0e5927e3e3b23dba11a392ced2dfc384
    http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_ia64.deb
      Size/MD5 checksum:  8080924 5cbb57470b81a943ec1421e1d22fab9c
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_ia64.deb
      Size/MD5 checksum:    69698 8e7699d911747ed965587d2bf36707d2
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_ia64.deb
      Size/MD5 checksum:   162930 390622d0466fd4ee1d645ff24a486241
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_ia64.deb
      Size/MD5 checksum:    69726 ceb2833f35e0b2dd6df42c5b6f7a0924
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_ia64.deb
      Size/MD5 checksum:   674080 02d6349aa77a9598ce6c7ef538ce2d0f
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_ia64.deb
      Size/MD5 checksum:   119572 fa64c57058122edcf0f1c413d21557cb

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_mipsel.deb
      Size/MD5 checksum:  3316782 65ebad651b17863a9a7def60032e4672
    http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_mipsel.deb
      Size/MD5 checksum:  8368926 443e53afe7639aa6c3d159b6499218b4
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_mipsel.deb
      Size/MD5 checksum:    64718 1278a55f7345cefaf0bbde156a01852b
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_mipsel.deb
      Size/MD5 checksum:   138848 708f79acae6cda1521d1ac5c4f2f5e2e
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_mipsel.deb
      Size/MD5 checksum:    65306 1dcd3cb4aa8e75fc21517d034297e5e7
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_mipsel.deb
      Size/MD5 checksum:   552706 a44da4d486e01cadfb7d2f305be3be24
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_mipsel.deb
      Size/MD5 checksum:   119612 d13cbaeb0562086ca97cd33ac5b55f68

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_powerpc.deb
      Size/MD5 checksum:  3322580 34f0de0fa34506224ad8f0d4bb134da4
    http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_powerpc.deb
      Size/MD5 checksum:  8576426 a92e2a144d4bc2007c4426de63f53c9a
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_powerpc.deb
      Size/MD5 checksum:    65354 d82e9a5f80edbc335db4543b76368070
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_powerpc.deb
      Size/MD5 checksum:   141868 579bcf537af8b4160125cd9e37556a7b
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_powerpc.deb
      Size/MD5 checksum:    65918 58e71799fdee25a691e8a90d5da13401
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_powerpc.deb
      Size/MD5 checksum:   568094 b9165bf4d4629833de591e9c310e0ae9
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_powerpc.deb
      Size/MD5 checksum:   119582 2677fc64c5ff0daeb1661127cbccc0e0

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_s390.deb
      Size/MD5 checksum:  3153684 3111fdb75c87d140bde2c84867547e02
    http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_s390.deb
      Size/MD5 checksum:  8067256 e7e8921bba628e7e664eb74ccbb65798
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_s390.deb
      Size/MD5 checksum:    65318 543771b863775a0e5c8399a8bdadc478
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_s390.deb
      Size/MD5 checksum:   147020 88beac981ba8419b758f8ed062f47923
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_s390.deb
      Size/MD5 checksum:    65130 8c2d3e9740521f5b864e14e58ca99b78
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_s390.deb
      Size/MD5 checksum:   579226 5a386add556e7fe707c50a875134cbb6
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_s390.deb
      Size/MD5 checksum:   119550 0d8676805ac085717ec189e8c156a3f0

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/g/gimp/gimp_2.2.13-1etch4_sparc.deb
      Size/MD5 checksum:  2913146 938eb0705a8214f68ca74deb46fa585d
    http://security.debian.org/pool/updates/main/g/gimp/gimp-dbg_2.2.13-1etch4_sparc.deb
      Size/MD5 checksum:  7783506 ae99e650842552c3af62e1af49eecc81
    http://security.debian.org/pool/updates/main/g/gimp/gimp-helpbrowser_2.2.13-1etch4_sparc.deb
      Size/MD5 checksum:    63802 f7b381f9dd5da63857bb0a1e4703d8a0
    http://security.debian.org/pool/updates/main/g/gimp/gimp-python_2.2.13-1etch4_sparc.deb
      Size/MD5 checksum:   139670 5098cba15eee1a2536bb6ce37237f22f
    http://security.debian.org/pool/updates/main/g/gimp/gimp-svg_2.2.13-1etch4_sparc.deb
      Size/MD5 checksum:    64348 0f47f65a9d0edcec71e8c7024bf978c3
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0_2.2.13-1etch4_sparc.deb
      Size/MD5 checksum:   549708 9a5bd7f989b9bc838d46cb401aeab400
    http://security.debian.org/pool/updates/main/g/gimp/libgimp2.0-dev_2.2.13-1etch4_sparc.deb
      Size/MD5 checksum:   119602 761f5e951f018375b8eaad8a7c52984d


  These files will probably be moved into the stable distribution on
  its next update.

-
---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp:
ftp://security.debian.org/debian-security dists/stable/updates/main Mailing
list: debian-security-announce@xxxxxxxxxxxxxxxx
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGnopDXm3vHE4uyloRAoT9AJ9OaxGjxH8EtwDvh2qxMXrUhnlWvQCeJ++Q
YvuufGg53j283ES6nWIfUAM=
=J2DR
-----END PGP SIGNATURE-----

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 1336-1                    security@xxxxxxxxxx
http://www.debian.org/security/                         Moritz Muehlenhoff
July 22nd, 2007                         http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : mozilla-firefox
Vulnerability  : several
Problem-Type   : remote
Debian-specific: no
CVE ID         : CVE-2007-1282 CVE-2007-0994 CVE-2007-0995 CVE-2007-0996
CVE-2007-0981 CVE-2007-0008 CVE-2007-0009 CVE-2007-0775 CVE-2007-0778
CVE-2007-0045 CVE-2006-6077

Several remote vulnerabilities have been discovered in Mozilla Firefox.

This will be the last security update of Mozilla-based products for the
oldstable (sarge) distribution of Debian. We recommend to upgrade to stable
(etch) as soon as possible.

The Common Vulnerabilities and Exposures project identifies the following
vulnerabilities:

CVE-2007-1282

    It was discovered that an integer overflow in text/enhanced message
    parsing allows the execution of arbitrary code.

CVE-2007-0994

    It was discovered that a regression in the Javascript engine allows
    the execution of Javascript with elevated privileges.

CVE-2007-0995

    It was discovered that incorrect parsing of invalid HTML characters
    allows the bypass of content filters.

CVE-2007-0996

    It was discovered that insecure child frame handling allows cross-site
    scripting.

CVE-2007-0981

    It was discovered that Firefox handles URI withs a null byte in the
    hostname insecurely.

CVE-2007-0008

    It was discovered that a buffer overflow in the NSS code allows the
    execution of arbitrary code.

CVE-2007-0009

    It was discovered that a buffer overflow in the NSS code allows the
    execution of arbitrary code.

CVE-2007-0775

    It was discovered that multiple programming errors in the layout engine
    allow the execution of arbitrary code.

CVE-2007-0778

    It was discovered that the page cache calculates hashes in an insecure
    manner.

CVE-2006-6077

    It was discovered that the password manager allows the disclosure of
    passwords.

For the oldstable distribution (sarge) these problems have been fixed in
version 1.0.4-2sarge17. You should upgrade to etch as soon as possible.

The stable distribution (etch) isn't affected. These vulnerabilities have been
fixed prior to the release of Debian etch.

The unstable distribution (sid) no longer contains mozilla-firefox. Iceweasel
is already fixed.


Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as
given below:

apt-get update
        will update the internal database apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the footer to the
proper configuration.


Debian GNU/Linux 3.1 alias sarge
- --------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge17.dsc
      Size/MD5 checksum:     1641 36715bb647cb3b7cd117edee90a34bfd
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge17.diff.gz
      Size/MD5 checksum:   553311 4ba992e60e5c6b156054c5105b1134ae
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4.orig.tar.gz
      Size/MD5 checksum: 40212297 8e4ba81ad02c7986446d4e54e978409d

  Alpha architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge17_alpha.deb
      Size/MD5 checksum: 11221890 5d8d1de73d162edf8ddbaa40844bb454
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge17_alpha.deb
      Size/MD5 checksum:   172696 42d5c31ec7a2e3163846c347f04773df
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge17_alpha.deb
      Size/MD5 checksum:    63574 238529b9d4ae396dc01d786d4fb843b4

  AMD64 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge17_amd64.deb
      Size/MD5 checksum:  9429140 8394fcd85a7218db784160702efc5249
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge17_amd64.deb
      Size/MD5 checksum:   166496 795a8ec3e1aa1b0a718ad6f4439670ef
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge17_amd64.deb
      Size/MD5 checksum:    62022 ef315cc90c3780ff151cd2271e913859

  ARM architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge17_arm.deb
      Size/MD5 checksum:  8244544 71eaf9cb5418a77410ff12c7f36eb32b
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge17_arm.deb
      Size/MD5 checksum:   157966 5e2e22d04a33ccbc0e6b19b4c4d43492
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge17_arm.deb
      Size/MD5 checksum:    57358 6f34a7a02114e48cadc6860b86f75130

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge17_hppa.deb
      Size/MD5 checksum: 10301620 3700a0b7dcb0ab061b3521e2a3f232f9
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge17_hppa.deb
      Size/MD5 checksum:   169432 387b8fa52d406dfdd26c3adc3ccac615
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge17_hppa.deb
      Size/MD5 checksum:    62500 80addaf2d87b6952fdc9104c5fc9dfde

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge17_i386.deb
      Size/MD5 checksum:  8919924 8fc67257357687c8611b3e4e5389aee4
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge17_i386.deb
      Size/MD5 checksum:   161684 6c989c4276e34c6031b6185418a8ddb1
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge17_i386.deb
      Size/MD5 checksum:    58896 7e48aa697c8c17f7d22de860a17e7dfd

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge17_ia64.deb
      Size/MD5 checksum: 11664142 aa008699700ba3c8b45d3a8961e99192
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge17_ia64.deb
      Size/MD5 checksum:   172030 e79af50f04490de310cda7f6ce652d44
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge17_ia64.deb
      Size/MD5 checksum:    66718 8cabdbf0919ac447c5d492ef6227d9af

  Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge17_m68k.deb
      Size/MD5 checksum:  8196148 e3544446b371fd7ed4b79e53f69b556a
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge17_m68k.deb
      Size/MD5 checksum:   160556 0164d4c0f675a020643ccedf94a55eb8
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge17_m68k.deb
      Size/MD5 checksum:    58168 b429907e69e8daa7d51e45552659da27

  Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge17_mips.deb
      Size/MD5 checksum:  9954006 0eb0513fc950e7cd8abcae9666b24a7b
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge17_mips.deb
      Size/MD5 checksum:   159496 ca0585a663a5470d3a62ae0786864beb
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge17_mips.deb
      Size/MD5 checksum:    59170 22ea96156de56d046a7afd73d4857419

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge17_mipsel.deb
      Size/MD5 checksum:  9831728 dda6865c7290fce658847f0909617c73
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge17_mipsel.deb
      Size/MD5 checksum:   159060 e7a7c4db0f5df82f84ceef6827df2bea
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge17_mipsel.deb
      Size/MD5 checksum:    58984 b0b02ac1c62041db8d377a7ff40c013c

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge15_powerpc.deb
      Size/MD5 checksum:  8587718 8d219ce9e684b86babfe31db9d7d9658
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge15_powerpc.deb
      Size/MD5 checksum:   159762 41f3707945d5edae6ee1ac90bdef5cab
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge15_powerpc.deb
      Size/MD5 checksum:    60936 1a79408acd12828a3710393e05d99914

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge17_s390.deb
      Size/MD5 checksum:  9667078 5838d957637b4d4c2c19afea0dd68db5
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge17_s390.deb
      Size/MD5 checksum:   167092 4dd6de7299014d5e0c13da8e480a7f3c
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge17_s390.deb
      Size/MD5 checksum:    61472 64d10c667ed4c6c12947c49f5cca8ff6

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox_1.0.4-2sarge17_sparc.deb
      Size/MD5 checksum:  8680322 241cddabdf91eb14b0a6529ffc84a51d
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-dom-inspector_1.0.4-2sarge17_sparc.deb
      Size/MD5 checksum:   160304 7887081b85d3ead3994a997608bbe22a
    http://security.debian.org/pool/updates/main/m/mozilla-firefox/mozilla-firefox-gnome-support_1.0.4-2sarge17_sparc.deb
      Size/MD5 checksum:    57718 4a4eeeb0815cb03d51f74965403911ad

  These files will probably be moved into the oldstable distribution on
  its next update.

-
---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp:
ftp://security.debian.org/debian-security dists/stable/updates/main Mailing
list: debian-security-announce@xxxxxxxxxxxxxxxx
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGo5b7Xm3vHE4uyloRAsdgAKDTo6NxeylHh30syJpFeyF5/Yr/XwCdH188
NdI5zd36oN5mVqIDUsqYC3o=
=/qY/
-----END PGP SIGNATURE-----

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 1337-1                    security@xxxxxxxxxx
http://www.debian.org/security/                         Moritz Muehlenhoff
July 22nd, 2007                         http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : xulrunner
Vulnerability  : several
Problem-Type   : remote
Debian-specific: no
CVE ID         : CVE-2007-3089 CVE-2007-3285 CVE-2007-3656 CVE-2007-3734
CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3738

Several remote vulnerabilities have been discovered in Xulrunner, a runtime
environment for XUL applications. The Common Vulnerabilities and Exposures
project identifies the following problems:

CVE-2007-3089

    Ronen Zilberman and Michal Zalewski discovered that a timing race
    allows the injection of content into about:blank frames.

CVE-2007-3656

    Michal Zalewski discovered that same-origin policies for wyciwyg://
    documents are insufficiently enforced.

CVE-2007-3734

    Bernd Mielke, Boris Zbarsky, David Baron, Daniel Veditz, Jesse Ruderman,
    Lukas Loehrer, Martijn Wargers, Mats Palmgren, Olli Pettay, Paul
    Nickerson and Vladimir Sukhoy discovered crashes in the layout engine,
    which might allow the execution of arbitrary code.

CVE-2007-3735

    Asaf Romano, Jesse Ruderman and Igor Bukanov discovered crashes in the
    javascript engine, which might allow the execution of arbitrary code.

CVE-2007-3736

    "moz_bug_r_a4" discovered that the addEventListener() and setTimeout()
    functions allow cross-site scripting.

CVE-2007-3737

    "moz_bug_r_a4" discovered that a programming error in event handling
    allows privilege escalation.

CVE-2007-3738

    "shutdown" and "moz_bug_r_a4" discovered that the XPCNativeWrapper allows
    the execution of arbitrary code.

The oldstable distribution (sarge) doesn't include xulrunner.

For the stable distribution (etch) these problems have been fixed in version
1.8.0.13~pre070720-0etch1. A build for the mips architecture is not yet
available, it will be provided later.

For the unstable distribution (sid) these problems have been fixed in version
1.8.1.5-1.

We recommend that you upgrade your xulrunner packages.


Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as
given below:

apt-get update
        will update the internal database apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the footer to the
proper configuration.


Debian GNU/Linux 4.0 alias etch
- -------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.13~pre070720-0etch1.dsc
      Size/MD5 checksum:     1343 a37a2616fb763e235c302c9447130812
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.13~pre070720-0etch1.diff.gz
      Size/MD5 checksum:   142519 da13edae4972a96bbde266c42a4080b5
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.13~pre070720.orig.tar.gz
      Size/MD5 checksum: 41410770 e30ab38e9926b780baf7b500fb6201ab

  Architecture independent components:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozillainterfaces-java_1.8.0.13~pre070720-0etch1_all.deb
      Size/MD5 checksum:  1025740 1bed1974e10bc6a292c22be8dd819fd1
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs-dev_1.8.0.13~pre070720-0etch1_all.deb
      Size/MD5 checksum:   175032 12d259d28f639b20cc6c1a96dd645d45
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-dev_1.8.0.13~pre070720-0etch1_all.deb
      Size/MD5 checksum:   206146 a7949a4cf99cba9f089dc7d303dbad84
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-dev_1.8.0.13~pre070720-0etch1_all.deb
      Size/MD5 checksum:   229660 30268c95ecffd8cfb4c897245a7705e3
    http://security.debian.org/pool/updates/main/x/xulrunner/libsmjs-dev_1.8.0.13~pre070720-0etch1_all.deb
      Size/MD5 checksum:    34914 49bd1763b6490ff9eb2ceabaf8d3dc6b
    http://security.debian.org/pool/updates/main/x/xulrunner/libsmjs1_1.8.0.13~pre070720-0etch1_all.deb
      Size/MD5 checksum:    34880 e70de907f7cbc32e087b85a86854d37e
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul-common_1.8.0.13~pre070720-0etch1_all.deb
      Size/MD5 checksum:  1047844 34c67cfdd585938584649af591864a1a
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul-dev_1.8.0.13~pre070720-0etch1_all.deb
      Size/MD5 checksum:  2677434 729ad3cda351343ba59870966ef78310

  Alpha architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.13~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:   384226 49e4fd4f6daf42865a788d3f239355be
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.13~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:   763516 ea36a68584fc53818285dd95cd4ba638
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.13~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:   160340 c602e3a6e9504fd25ccae845186da028
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.13~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:   300018 e53d34ab2d9937505716ae1ad9a4b028
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.13~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:   905424 e687ea634f69dd3ecb09eddde23da52c
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.13~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:  3185396 b842677c51a4585b8fb96ceb29cdf9b0
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.13~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:   737202 f92b112b08dcdb08196078c9c8ef2f59
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.13~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:  7341736 f2bb4260738d9d58e6ce654acbbf2150
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.13~pre070720-0etch1_alpha.deb
      Size/MD5 checksum: 45940198 693086bc53dbb9e7bddbdae82ade920e
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.13~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:   129174 e11e05f51217045c806e58783cb324bf
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.13~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:    51286 82447d369e6b54fdb32fd8b99fdeec78
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.13~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:   290148 1929a88d12d92c10858b56ed96f15f50
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.13~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:    69802 db7f38b2b4891270c91d951e3e531af6

  AMD64 architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.13~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:   353704 f904d5b91cbb15b3afd16919f24abeea
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.13~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:   752222 0294d565c58bd68faf33817686a15dc1
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.13~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:   146970 0f0bc28c79a70746e9febbd45c716a74
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.13~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:   302830 093653c6ea466e3a488023501200de3c
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.13~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:   807700 0a0fe9389cb441bb789968bb5db9f4ac
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.13~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:  3172316 7cb81a354de70930421be1810b35bea9
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.13~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:   668910 44140365bc2d4bba7a3a14d963984c30
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.13~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:  6333286 745843de1b04342520a039a23ca6715b
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.13~pre070720-0etch1_amd64.deb
      Size/MD5 checksum: 45144466 bc976beb2ba2059acfe2d14ddce3ce5f
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.13~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:   124182 5129c32b688ab5ecca3957cc27e1df37
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.13~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:    51132 a6f38984c04d0fbd093679a18b29d88b
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.13~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:   276186 1577497acbe906a6c7325df67dd8ac41
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.13~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:    67610 0a525071a676a3c8fe165bb910cc08d3

  ARM architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.13~pre070720-0etch1_arm.deb
      Size/MD5 checksum:   324216 460015c130ddc6d88b181282f1645d73
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.13~pre070720-0etch1_arm.deb
      Size/MD5 checksum:   702114 b2fea4d3338fd8502bbbc3f2a88fc6c4
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.13~pre070720-0etch1_arm.deb
      Size/MD5 checksum:   134312 eb0926da00f3ab3d71b3513feb1fd858
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.13~pre070720-0etch1_arm.deb
      Size/MD5 checksum:   289600 55676ca5f859a1bb7e5abf19d9c473e7
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.13~pre070720-0etch1_arm.deb
      Size/MD5 checksum:   730032 07e86c2228a6a019c715f58c0f8fe493
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.13~pre070720-0etch1_arm.deb
      Size/MD5 checksum:  2965754 8476eabb89bdcb26bd71ffb5c2bf8944
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.13~pre070720-0etch1_arm.deb
      Size/MD5 checksum:   592682 ad05902149de42addeeb21c617f80ad8
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.13~pre070720-0etch1_arm.deb
      Size/MD5 checksum:  5364248 19bd9f4ae26314ea2c306e4eb768838e
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.13~pre070720-0etch1_arm.deb
      Size/MD5 checksum: 44661564 7a95c8b5445168a85b92e3f990f5f59f
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.13~pre070720-0etch1_arm.deb
      Size/MD5 checksum:   116332 99365e41653a10dc7d8ecd4328276c7f
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.13~pre070720-0etch1_arm.deb
      Size/MD5 checksum:    49540 dedd1cffe8938800a1ffd4411975c1a6
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.13~pre070720-0etch1_arm.deb
      Size/MD5 checksum:   263372 67a410af596759150051eec7d5348800
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.13~pre070720-0etch1_arm.deb
      Size/MD5 checksum:    61746 50928856c82910c6a7cde36c2e53fcb3

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.13~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:   388058 97bfa8de83aa23a8680f6d0df27f2b11
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.13~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:   749702 e058f65d7379a929c46ea18f02ab1580
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.13~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:   158726 9eed84454e4615811bc6ada70068c5da
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.13~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:   300052 f080ac5916f63548c97e2198d1b581ee
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.13~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:   873308 56ab45ca6b507a6ed03a8bfe94ad5a94
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.13~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:  3101744 4ba6a39ed4d2332e81045bcf0e54047f
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.13~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:   701938 34d4bf800824022b59737dae8ba768f7
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.13~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:  7539288 5fe18cdabebe377b07b23b4186a79f48
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.13~pre070720-0etch1_hppa.deb
      Size/MD5 checksum: 46054122 fb5e177e30ce3798b19dfce37d6a61f4
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.13~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:   131514 d6e0d2d8afc89d4e5eeebf3a9062c145
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.13~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:    51774 186a1cfd16e2f30c6608f173d8a0c052
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.13~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:   285572 30251f598f29344016623e3980cab9c2
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.13~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:    69304 c1f4fa6060e2a17b7b85206d9b602fb8

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.13~pre070720-0etch1_i386.deb
      Size/MD5 checksum:   333778 afc6c1dfcf0a13ec363edd9dc6a106bd
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.13~pre070720-0etch1_i386.deb
      Size/MD5 checksum:   709674 bcd72b32ce726f68920ae204e5dbe9f0
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.13~pre070720-0etch1_i386.deb
      Size/MD5 checksum:   137850 8539a74fa8554eec7845a7e61de676ab
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.13~pre070720-0etch1_i386.deb
      Size/MD5 checksum:   294632 d5b43b7d8e290ee1b8bb3e75d50a3d95
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.13~pre070720-0etch1_i386.deb
      Size/MD5 checksum:   740826 8d420008c5e6af3fb07652fd43ac7cf0
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.13~pre070720-0etch1_i386.deb
      Size/MD5 checksum:  3032348 3b1bffa5aa1b9372a5de574ae1a31242
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.13~pre070720-0etch1_i386.deb
      Size/MD5 checksum:   626480 0e1b89439106a6fd3d58f7c291681709
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.13~pre070720-0etch1_i386.deb
      Size/MD5 checksum:  5374874 3747b94c0d2c10482f82ea2b8de0cfb5
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.13~pre070720-0etch1_i386.deb
      Size/MD5 checksum: 44624882 3c96b0793162c62972ecebad4cf99cee
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.13~pre070720-0etch1_i386.deb
      Size/MD5 checksum:   116412 bd2b5f7ab7330addb6d216b95920c841
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.13~pre070720-0etch1_i386.deb
      Size/MD5 checksum:    49854 946af6ea16eabb6144e3a2365480e91d
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.13~pre070720-0etch1_i386.deb
      Size/MD5 checksum:   266188 f670f69dca0ebff10b43458492fab338
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.13~pre070720-0etch1_i386.deb
      Size/MD5 checksum:    62034 83e93c48394a4f1ad6efb0237a943a9e

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.13~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:   529936 5e10979d8e3cf394509a2862f1529e8b
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.13~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:   755256 d3bcdd705902f591b8f0d72ed46a86be
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.13~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:   197246 63609bb230956aa2634b14404c666220
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.13~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:   285446 eda38a7b2bf22b48ea65117b83076951
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.13~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:  1121024 88320d0e1bc26d4318cff5f1dd990982
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.13~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:  3050964 8f7baa762b9cce943b0ef120c5ce2662
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.13~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:   936436 a31388ad1798d67f8833576e6b5b5073
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.13~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:  9671706 b43189258f79b6ae1bd8f99cc1043101
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.13~pre070720-0etch1_ia64.deb
      Size/MD5 checksum: 45346358 1b0aefb6338eaab7d1f0ed02591c421a
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.13~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:   147942 c0c4cfe96c33021d9b6fbaaa35b745cb
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.13~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:    55666 b32ef0c675ddbb2d8430c1965c8e0aeb
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.13~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:   331716 ccfb06857aa66a0dc667915b87031035
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.13~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:    79192 52b68c2c6fe90d4a922890f4c2215ce4

  Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   349536 c3f8a5e52e2a157a718c54188b6d747b
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   781874 4395ac1529b801a872843d088b2370ff
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   144602 55dc285ccb8dd769e4c0be65e5cf7207
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   310762 9eca6f68c5af19311b86b83160d44c7f
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   807352 48c80607d8cc12eec3dd437a7bc56320
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:  3286276 05a113a3e38b9ec7a3a26d99d80d6c5d
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   668994 9cfdd64f8ae34e2a9e59b2eeb5951646
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:  5925444 489c55633bbb6f247cb557feee9f2d86
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum: 46607494 9415e46c465361981edc5d88d99a34ee
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   117052 0d87aad09b87ff8e9bab1e5645fa8c49
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:    50130 dee6b13d3a36b40e1f5614e21e1d0cf9
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:   271768 ee71dceff7b6ae6d1395d9de76da71d8
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.12-0etch1_mips.deb
      Size/MD5 checksum:    63332 f3f0723efe5610ca01c627f8e574183f

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.13~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:   349168 25e46a8bd8ede428a1dd0999a7d58f1d
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.13~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:   764282 5504c0c01a4061bdf98ea33b5fed720a
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.13~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:   144390 81ae74a38845dd26a9d002afee3201d4
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.13~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:   304224 a298e9ea9c9cc04dcde9815407c5ec19
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.13~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:   783974 16a85fc3ccd455b045088f36fe855b6e
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.13~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:  3185088 5b3977099a21fa0454a06e56a6bde8b3
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.13~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:   668878 56027c2fb43894b921a84bfc6d81a5be
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.13~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:  5749206 99bb12a1d85b9367f7bc56de24726a51
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.13~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum: 45284626 4de8f4671d503d10430e57ddd12a6a92
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.13~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:   116994 602d0e08f2e3bb1b5c0f42607e4adb95
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.13~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:    50370 6d68e143852e3a2d07ade9a8029dae26
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.13~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:   272792 ccfcfa6a03bcbedadf6d2f7566dfbe1b
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.13~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:    63312 5b43ec8d6593476a1368e80a333fe59b

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.13~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:   347630 0f51a5efeb2105d7a7d86e597682afe1
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.13~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:   771798 920ffc7f0dc3144aa581b5e3617dcb9c
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.13~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:   146156 8c9a553fd24d1ca9c7a83e0c951c8901
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.13~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:   309478 55be9230e8bbb080f535c618586b3c17
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.13~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:   808510 3deaee53cb057cf27175d1a70ba0470a
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.13~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:  3206530 8a2bac743acaaa5c4692317ea9305cbd
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.13~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:   638514 112c741af25f06ccfabb9292abec4d95
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.13~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:  6103874 76c70b54fe8a66d5c3e7c44740193c82
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.13~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum: 46863120 6524d2668028e288535f46993215da0f
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.13~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:   121962 f563bac1fb7a1c00f0b2858e8270f483
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.13~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:    51626 a433ad0678918cc2e7f8ffc1c8f08fc6
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.13~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:   276920 c072f3e6893d201974a15fb5b4f65436
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.13~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:    63272 fe4dee078dd340e1632852a65e33d6e9

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.13~pre070720-0etch1_s390.deb
      Size/MD5 checksum:   370562 987f2d217b3933958d04e9bfaa026fd2
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.13~pre070720-0etch1_s390.deb
      Size/MD5 checksum:   754508 c3c46b56b530c6c1824d55e9a7e7ff91
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.13~pre070720-0etch1_s390.deb
      Size/MD5 checksum:   158756 0db2cba12a04b6728743b2de7b7f0726
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.13~pre070720-0etch1_s390.deb
      Size/MD5 checksum:   304874 86418bdc99b55da342d0cbdbec2ed85b
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.13~pre070720-0etch1_s390.deb
      Size/MD5 checksum:   896980 f530118cb473269bb8e33624cd9129ad
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.13~pre070720-0etch1_s390.deb
      Size/MD5 checksum:  3179304 ccea3269dedf61aca3b104742b75150f
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.13~pre070720-0etch1_s390.deb
      Size/MD5 checksum:   687136 0ee2ff991754107da815509f865c9f53
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.13~pre070720-0etch1_s390.deb
      Size/MD5 checksum:  6808332 cda9b1e23f17fc0584d38647469a1eb7
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.13~pre070720-0etch1_s390.deb
      Size/MD5 checksum: 46005704 6618e4d41dd1a812246ae882855f6781
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.13~pre070720-0etch1_s390.deb
      Size/MD5 checksum:   125006 4a4c7ea8a2d39fc32baae9f38f47efed
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.13~pre070720-0etch1_s390.deb
      Size/MD5 checksum:    51860 f0de3bacd4f97999d7211dc1b2ae1163
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.13~pre070720-0etch1_s390.deb
      Size/MD5 checksum:   280662 d76094362d7a19a07b7e773f355b9521
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.13~pre070720-0etch1_s390.deb
      Size/MD5 checksum:    68224 25a45aa492c012f7208f863c0de92c4a

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d_1.8.0.13~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:   321478 91532495bbf468c3883a10d1cf17fd41
    http://security.debian.org/pool/updates/main/x/xulrunner/libmozjs0d-dbg_1.8.0.13~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:   673296 7ffcc75590013dcb7000c990a80c3eff
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d_1.8.0.13~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:   134954 84762ce7c699145d181de963675af14d
    http://security.debian.org/pool/updates/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.13~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:   282336 ff5f9bb58057677497079ba588ccbb74
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d_1.8.0.13~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:   718148 23b8206d6d7b889575eeaedee9f0a8c0
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-0d-dbg_1.8.0.13~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:  2853614 591d4486884bcfdc8dbb0b4e2cbdf919
    http://security.debian.org/pool/updates/main/x/xulrunner/libnss3-tools_1.8.0.13~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:   584290 732b982e5c40c0eee53d2c010dc19318
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d_1.8.0.13~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:  5683190 061b322a4b9ee87a392fbea1a5a0b60b
    http://security.debian.org/pool/updates/main/x/xulrunner/libxul0d-dbg_1.8.0.13~pre070720-0etch1_sparc.deb
      Size/MD5 checksum: 44718882 2ea151ce2755ab369c64ce2086c5575f
    http://security.debian.org/pool/updates/main/x/xulrunner/python-xpcom_1.8.0.13~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:   117194 42b8be9054303e97bed848726d4fa0a0
    http://security.debian.org/pool/updates/main/x/xulrunner/spidermonkey-bin_1.8.0.13~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:    49744 1a52ba881d47e917a8717f80cc4415bd
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner_1.8.0.13~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:   259212 bd504f6540dfd200692c7696b43e5fdd
    http://security.debian.org/pool/updates/main/x/xulrunner/xulrunner-gnome-support_1.8.0.13~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:    61580 080f81f35ca584886c6e05870c29aba3


  These files will probably be moved into the stable distribution on
  its next update.

-
---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp:
ftp://security.debian.org/debian-security dists/stable/updates/main Mailing
list: debian-security-announce@xxxxxxxxxxxxxxxx
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGo61TXm3vHE4uyloRAi61AKCX1cJh5J65lkppA4PTmxrMhftDUQCgu+aw
C7cr/aeoRI7t8i74QaiguIU=
=l7SR
-----END PGP SIGNATURE-----

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 1338-1                    security@xxxxxxxxxx
http://www.debian.org/security/                         Moritz Muehlenhoff
July 23rd, 2007                         http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : iceweasel
Vulnerability  : several
Problem-Type   : remote
Debian-specific: no
CVE ID         : CVE-2007-3089 CVE-2007-3656 CVE-2007-3734 CVE-2007-3735
CVE-2007-3736 CVE-2007-3737 CVE-2007-3738

Several remote vulnerabilities have been discovered in the Iceweasel web
browser, an unbranded version of the Firefox browser. The Common
Vulnerabilities and Exposures project identifies the following problems:

CVE-2007-3089

    Ronen Zilberman and Michal Zalewski discovered that a timing race
    allows the injection of content into about:blank frames.

CVE-2007-3656

    Michal Zalewski discovered that same-origin policies for wyciwyg://
    documents are insufficiently enforced.

CVE-2007-3734

    Bernd Mielke, Boris Zbarsky, David Baron, Daniel Veditz, Jesse Ruderman,
    Lukas Loehrer, Martijn Wargers, Mats Palmgren, Olli Pettay, Paul
    Nickerson,and Vladimir Sukhoy discovered crashes in the layout engine,
    which might allow the execution of arbitrary code.

CVE-2007-3735

    Asaf Romano, Jesse Ruderman and Igor Bukanov discovered crashes in the
    javascript engine, which might allow the execution of arbitrary code.

CVE-2007-3736

    "moz_bug_r_a4" discovered that the addEventListener() and setTimeout()
    functions allow cross-site scripting.

CVE-2007-3737

    "moz_bug_r_a4" discovered that a programming error in event handling
    allows privilege escalation.

CVE-2007-3738

    "shutdown" and "moz_bug_r_a4" discovered that the XPCNativeWrapper allows
    the execution of arbitrary code.

The Mozilla products in the oldstable distribution (sarge) are no longer
supported with with security updates. You're strongly encouraged to upgrade to
stable as soon as possible.

For the stable distribution (etch) these problems have been fixed in version
2.0.0.5-0etch1. Builds for alpha and mips are not yet available, they will be
provided later.

For the unstable distribution (sid) these problems have been fixed in version
2.0.0.5-1.

We recommend that you upgrade your iceweasel packages.


Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as
given below:

apt-get update
        will update the internal database apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the footer to the
proper configuration.


Debian GNU/Linux 4.0 alias etch
- -------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.5-0etch1.dsc
      Size/MD5 checksum:     1286 59238f560ecb32cdbc56a63ddb209e55
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.5-0etch1.diff.gz
      Size/MD5 checksum:   185146 6524cf51c9e4b107d72600123967d6ef
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.5.orig.tar.gz
      Size/MD5 checksum: 43667811 06e1bbe4d44d5b3333cabf8584844ca0

  Architecture independent components:

    http://security.debian.org/pool/updates/main/i/iceweasel/firefox-dom-inspector_2.0.0.5-0etch1_all.deb
      Size/MD5 checksum:    53580 934bffd016c2040ae56d1701ab9ef8b0
    http://security.debian.org/pool/updates/main/i/iceweasel/firefox-gnome-support_2.0.0.5-0etch1_all.deb
      Size/MD5 checksum:    53548 01ec3b09cb5305f60952e8e7c8ac775f
    http://security.debian.org/pool/updates/main/i/iceweasel/firefox_2.0.0.5-0etch1_all.deb
      Size/MD5 checksum:    53702 d3ecadf21b84c62c473a658892510d73
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dom-inspector_2.0.0.5-0etch1_all.deb
      Size/MD5 checksum:   234160 bcf465cec9f922ad5e28c434cc9bce9a
    http://security.debian.org/pool/updates/main/i/iceweasel/mozilla-firefox-dom-inspector_2.0.0.5-0etch1_all.deb
      Size/MD5 checksum:    53432 cd14d22874e960c485e4cec1e559ef20
    http://security.debian.org/pool/updates/main/i/iceweasel/mozilla-firefox-gnome-support_2.0.0.5-0etch1_all.deb
      Size/MD5 checksum:    53428 b2d685e70ff5a9c0be04c24efe8cd660
    http://security.debian.org/pool/updates/main/i/iceweasel/mozilla-firefox_2.0.0.5-0etch1_all.deb
      Size/MD5 checksum:    54232 72be77489c8bc90232f09c3e4a37d2a8

  AMD64 architecture:

    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.5-0etch1_amd64.deb
      Size/MD5 checksum: 10131746 6509776fdd7f65552627b22b7f0e5d5f
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.5-0etch1_amd64.deb
      Size/MD5 checksum: 50034750 34db9be3f1aacd877fabacf163a716cf
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.5-0etch1_amd64.deb
      Size/MD5 checksum:    87376 42ac4a2436251a5023a4122234a9b433

  ARM architecture:

    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.5-0etch1_arm.deb
      Size/MD5 checksum:  9172536 d5a6afa28d7202a28151791944c6cbe4
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.5-0etch1_arm.deb
      Size/MD5 checksum: 49133408 d8bfcda8c8f3675bbf4dfc2f84f88fb0
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.5-0etch1_arm.deb
      Size/MD5 checksum:    80786 547a41d33735a51c539fd93f8584ca8c

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.5-0etch1_hppa.deb
      Size/MD5 checksum: 11038942 73a12aae1df5a9ff435fdbf111641271
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.5-0etch1_hppa.deb
      Size/MD5 checksum: 50416604 d1dd0fa25fac83208fbee1e5016bea40
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.5-0etch1_hppa.deb
      Size/MD5 checksum:    88872 33dce9b617f9772f706ad4d711ccbacf

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.5-0etch1_i386.deb
      Size/MD5 checksum:  9104036 31bd4e0e97fc842cfb36332222227701
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.5-0etch1_i386.deb
      Size/MD5 checksum: 49439820 c7760fc3be07338899256b1bf00883e7
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.5-0etch1_i386.deb
      Size/MD5 checksum:    81298 b9479b0ba634c0456301effa7f69ef14

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.5-0etch1_ia64.deb
      Size/MD5 checksum: 14134080 497b02f80092d16b883a0fe5543e865a
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.5-0etch1_ia64.deb
      Size/MD5 checksum: 50396004 1eefae991deb0610dfee10f5fc25929a
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.5-0etch1_ia64.deb
      Size/MD5 checksum:    99638 ab6b8c85a7d7f796f6aa83c567d81f7a

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.5-0etch1_mipsel.deb
      Size/MD5 checksum: 10744354 de1cb2892c1a5f2474301c967002db40
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.5-0etch1_mipsel.deb
      Size/MD5 checksum: 52394050 8c57505e91c9ee8137d7f596de85cb20
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.5-0etch1_mipsel.deb
      Size/MD5 checksum:    82468 624046892b6bc835db7ad352a58193b1

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.5-0etch1_powerpc.deb
      Size/MD5 checksum:  9918324 b55975975e333962fbe7700f394e4efc
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.5-0etch1_powerpc.deb
      Size/MD5 checksum: 51849604 a382e26d5f81f3cba80d3c74c803bfba
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.5-0etch1_powerpc.deb
      Size/MD5 checksum:    82998 5b3f148c7e5115779efb9eab5f7ec085

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.5-0etch1_s390.deb
      Size/MD5 checksum: 10343876 392bd7c3b4498f16a18af4f33433cdec
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.5-0etch1_s390.deb
      Size/MD5 checksum: 50714240 4fcb5751ac1f74858e77ec55511ebfe3
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.5-0etch1_s390.deb
      Size/MD5 checksum:    87386 78d93550b19df51bb0ecde33117dc657

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel_2.0.0.5-0etch1_sparc.deb
      Size/MD5 checksum:  9125776 96b405d93d02e5a80933fba0658c18d3
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-dbg_2.0.0.5-0etch1_sparc.deb
      Size/MD5 checksum: 49052276 615dac8bcaeb9a4c5cdb6500fe519f8a
    http://security.debian.org/pool/updates/main/i/iceweasel/iceweasel-gnome-support_2.0.0.5-0etch1_sparc.deb
      Size/MD5 checksum:    81150 63d0482567e238eae0d201b43696ca02

  These files will probably be moved into the stable distribution on
  its next update.

-
---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp:
ftp://security.debian.org/debian-security dists/stable/updates/main Mailing
list: debian-security-announce@xxxxxxxxxxxxxxxx
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGpOTIXm3vHE4uyloRAv+8AKC05/P7bBqBBc0uHLkpPPwhHYG4RACdFEXQ
ctLOPU4DkXtE5veonKQZoI4=
=oobc
-----END PGP SIGNATURE-----

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 1339-1                    security@xxxxxxxxxx
http://www.debian.org/security/                         Moritz Muehlenhoff
July 23rd, 2007                         http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : iceape
Vulnerability  : several
Problem-Type   : remote
Debian-specific: no
CVE ID         : CVE-2007-3089 CVE-2007-3656 CVE-2007-3734 CVE-2007-3735
CVE-2007-3736 CVE-2007-3737 CVE-2007-3738

Several remote vulnerabilities have been discovered in the Iceape internet
suite, an unbranded version of the Seamonkey Internet Suite. The Common
Vulnerabilities and Exposures project identifies the following problems:

CVE-2007-3089

    Ronen Zilberman and Michal Zalewski discovered that a timing race
    allows the injection of content into about:blank frames.

CVE-2007-3656

    Michal Zalewski discovered that same-origin policies for wyciwyg://
    documents are insufficiently enforced.

CVE-2007-3734

    Bernd Mielke, Boris Zbarsky, David Baron, Daniel Veditz, Jesse Ruderman,
    Lukas Loehrer, Martijn Wargers, Mats Palmgren, Olli Pettay, Paul
    Nickerson,and Vladimir Sukhoy discovered crashes in the layout engine,
    which might allow the execution of arbitrary code.

CVE-2007-3735

    Asaf Romano, Jesse Ruderman and Igor Bukanov discovered crashes in the
    javascript engine, which might allow the execution of arbitrary code.

CVE-2007-3736

    "moz_bug_r_a4" discovered that the addEventListener() and setTimeout()
    functions allow cross-site scripting.

CVE-2007-3737

    "moz_bug_r_a4" discovered that a programming error in event handling
    allows privilege escalation.

CVE-2007-3738

    "shutdown" and "moz_bug_r_a4" discovered that the XPCNativeWrapper allows
    the execution of arbitrary code.

The Mozilla products in the oldstable distribution (sarge) are no longer
supported with security updates. You're strongly encouraged to upgrade to
stable as soon as possible.

For the stable distribution (etch) these problems have been fixed in version
1.0.10~pre070720-0etch1. A build for the mips architecture is not yet
available, it will be provided later.

For the unstable distribution (sid) these problems have been fixed in version
1.1.3-1.

We recommend that you upgrade your iceape packages.


Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as
given below:

apt-get update
        will update the internal database apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the footer to the
proper configuration.


Debian GNU/Linux 4.0 alias etch
- -------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/i/iceape/iceape_1.0.10~pre070720-0etch1.dsc
      Size/MD5 checksum:     1436 a5ddcea94b97d0eb7d88da94a72ca627
    http://security.debian.org/pool/updates/main/i/iceape/iceape_1.0.10~pre070720-0etch1.diff.gz
      Size/MD5 checksum:   267008 018274eb404a0e83606ce0d21e87ad01
    http://security.debian.org/pool/updates/main/i/iceape/iceape_1.0.10~pre070720.orig.tar.gz
      Size/MD5 checksum: 43473332 245a8a7774ff47ef91177724130f8ea4

  Architecture independent components:

    http://security.debian.org/pool/updates/main/i/iceape/iceape-chatzilla_1.0.10~pre070720-0etch1_all.deb
      Size/MD5 checksum:   278618 ee0d7c0bf576089522f4e9f72c8c3add
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dev_1.0.10~pre070720-0etch1_all.deb
      Size/MD5 checksum:  3707920 4bea22fd5361596b66969d7858dd3ad4
    http://security.debian.org/pool/updates/main/i/iceape/iceape_1.0.10~pre070720-0etch1_all.deb
      Size/MD5 checksum:    27756 7b7b835dae8ca15c7ec1592ff702ebb6
    http://security.debian.org/pool/updates/main/i/iceape/mozilla-browser_1.8+1.0.10~pre070720-0etch1_all.deb
      Size/MD5 checksum:    27278 0cc3f8a430af60e0dbcb83576879689e
    http://security.debian.org/pool/updates/main/i/iceape/mozilla-calendar_1.8+1.0.10~pre070720-0etch1_all.deb
      Size/MD5 checksum:    26354 d33b0ec877535b4fa4bf1aa07350f932
    http://security.debian.org/pool/updates/main/i/iceape/mozilla-chatzilla_1.8+1.0.10~pre070720-0etch1_all.deb
      Size/MD5 checksum:    26364 ff123607a7884ee5a3865464c76021ea
    http://security.debian.org/pool/updates/main/i/iceape/mozilla-dev_1.8+1.0.10~pre070720-0etch1_all.deb
      Size/MD5 checksum:    26486 4ca53a0ad06db0acb0b879fadfdd4fd5
    http://security.debian.org/pool/updates/main/i/iceape/mozilla-dom-inspector_1.8+1.0.10~pre070720-0etch1_all.deb
      Size/MD5 checksum:    26390 2420778740bf3e57de6ecd5d343d65dd
    http://security.debian.org/pool/updates/main/i/iceape/mozilla-js-debugger_1.8+1.0.10~pre070720-0etch1_all.deb
      Size/MD5 checksum:    26390 f6fb1d696a8fbd326204419b73ab98e1
    http://security.debian.org/pool/updates/main/i/iceape/mozilla-mailnews_1.8+1.0.10~pre070720-0etch1_all.deb
      Size/MD5 checksum:    26374 84203bd26fc8360bbb82535d81a823eb
    http://security.debian.org/pool/updates/main/i/iceape/mozilla-psm_1.8+1.0.10~pre070720-0etch1_all.deb
      Size/MD5 checksum:    26362 440d3f62c74c42ffcbb5ad73f2069e5c
    http://security.debian.org/pool/updates/main/i/iceape/mozilla_1.8+1.0.10~pre070720-0etch1_all.deb
      Size/MD5 checksum:    26346 ce97b31d46e18455189a03940aa72b92

  Alpha architecture:

    http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.10~pre070720-0etch1_alpha.deb
      Size/MD5 checksum: 12890534 11930d8d5ba846c22095362a46a3ff74
    http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.10~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:   625330 05c5e03df278bc31932846e1d30a00f9
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.10~pre070720-0etch1_alpha.deb
      Size/MD5 checksum: 60600154 5741efb22728c62acf22154c8a1f3e86
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.10~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:   196866 c64af9533b850bbbd57f9bb87685f9ca
    http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.10~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:    53100 7193be3a3787964216f4bfa83c7b2789
    http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.10~pre070720-0etch1_alpha.deb
      Size/MD5 checksum:  2281920 46540cf88b15c9e7455fce6389be88ed

  AMD64 architecture:

    http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.10~pre070720-0etch1_amd64.deb
      Size/MD5 checksum: 11668032 c3b8626d19c52f840fe80b39232b0cd7
    http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.10~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:   608632 f198d453bbbee84201acc69dd9fa5a1a
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.10~pre070720-0etch1_amd64.deb
      Size/MD5 checksum: 59611854 900bf6f48f9df4d30dfd8313b127cfb3
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.10~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:   194016 5adc494eaac9ba8f09c16441c5213318
    http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.10~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:    52592 4dab2583ccce4830b516fc68ef90bfbd
    http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.10~pre070720-0etch1_amd64.deb
      Size/MD5 checksum:  2090564 2ad1c710c8f3d7e1a5aa4f8b29b469e7

  ARM architecture:

    http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.10~pre070720-0etch1_arm.deb
      Size/MD5 checksum: 10404318 a3d00ba7cfe0c715fb15bedf1015e601
    http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.10~pre070720-0etch1_arm.deb
      Size/MD5 checksum:   582112 b0b849a2ffcf26a9441ace8ccdc8e398
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.10~pre070720-0etch1_arm.deb
      Size/MD5 checksum: 58762556 1a0f50dcbd272bc05c34d254d4507a4b
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.10~pre070720-0etch1_arm.deb
      Size/MD5 checksum:   188056 c0b5504ff4183a9e1fef78983a929e67
    http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.10~pre070720-0etch1_arm.deb
      Size/MD5 checksum:    47298 3c45d2f04093d8a0c5fc41a42251ec73
    http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.10~pre070720-0etch1_arm.deb
      Size/MD5 checksum:  1907106 b7918528c3b9213502f528adc95c58ab

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.10~pre070720-0etch1_hppa.deb
      Size/MD5 checksum: 12968358 ea1453f3ffa54ee3120ac58cfb293a10
    http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.10~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:   614490 83b15ddde3c3b657ad44447802c18261
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.10~pre070720-0etch1_hppa.deb
      Size/MD5 checksum: 60467066 e26575d92f3d6d34e98bd8bab228a010
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.10~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:   197064 7d50bb4f9866918e3ef4981c738e650b
    http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.10~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:    53686 442e54332b114ea0a63fec012912d164
    http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.10~pre070720-0etch1_hppa.deb
      Size/MD5 checksum:  2338858 47f729c72d8843241cb88407e2e99e47

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.10~pre070720-0etch1_i386.deb
      Size/MD5 checksum: 10477338 deab48630b8aeb248bfa9397e88fd489
    http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.10~pre070720-0etch1_i386.deb
      Size/MD5 checksum:   587938 2f19c0f151b456a0c0e84b0812cb0dc6
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.10~pre070720-0etch1_i386.deb
      Size/MD5 checksum: 58688874 8e26e07fc8e55d38cde9091093e8ff08
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.10~pre070720-0etch1_i386.deb
      Size/MD5 checksum:   188700 2b399a919d4ee6ee8c5cf22db90e741c
    http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.10~pre070720-0etch1_i386.deb
      Size/MD5 checksum:    47678 a85d86cd967b44370ec1b3329b9728a5
    http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.10~pre070720-0etch1_i386.deb
      Size/MD5 checksum:  1889676 66d798529d1f56ce668f8d7eda66abd6

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.10~pre070720-0etch1_ia64.deb
      Size/MD5 checksum: 15794104 7cce099248b412a4189ad2d3243ed7b7
    http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.10~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:   660672 c7a44faa5e50d8e9c4613c482d4815cd
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.10~pre070720-0etch1_ia64.deb
      Size/MD5 checksum: 59877166 2fe2866b66428866cfed2ab068829bf0
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.10~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:   203708 775d91256820711eb33d3b4af4c1cfbb
    http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.10~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:    61198 5f258d8b03704153bc66d2114d60fe55
    http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.10~pre070720-0etch1_ia64.deb
      Size/MD5 checksum:  2815616 ff8fbcd7ba8273161a4db64af91dd950

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.10~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum: 10913650 a40d4caf40bf9b5d989b0cdbf12e9479
    http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.10~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:   594990 bf9e81b7f1498d5c60b673b08ba283a7
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.10~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum: 59826020 60a3a22c5a6e42da3c3981ff89fd40ee
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.10~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:   190212 bad4a1f57643aa25603d6a1fdf85f83f
    http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.10~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:    48982 ec96058415e4b33329b6fc5d481f8c56
    http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.10~pre070720-0etch1_mipsel.deb
      Size/MD5 checksum:  1940378 3a1182500597f8f8d6db4671f187afd2

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.10~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum: 11312338 4f853beb774f7aecaca500031c0e182e
    http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.10~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:   595304 4ff550a168faee0f2dffd96b3839c097
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.10~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum: 61603172 37d3070543aae6795d1f95eb1d97b1b1
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.10~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:   191070 c11775a74df72fe1965aeb50f0f5e2e7
    http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.10~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:    48634 031194e9c64f17085308d05dc47de49f
    http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.10~pre070720-0etch1_powerpc.deb
      Size/MD5 checksum:  2005522 2c4907581d26e19441faed3a2a76a87e

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.10~pre070720-0etch1_s390.deb
      Size/MD5 checksum: 12291720 be79de8e773f1cbf83d34f837f0d3637
    http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.10~pre070720-0etch1_s390.deb
      Size/MD5 checksum:   610698 4f6e4f45769b6cf87a498b7dece5157c
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.10~pre070720-0etch1_s390.deb
      Size/MD5 checksum: 60372220 a25f1221df24b6d51d66b5f3d4751210
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.10~pre070720-0etch1_s390.deb
      Size/MD5 checksum:   195860 25f6e1809320a9b0d111908cec8e309a
    http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.10~pre070720-0etch1_s390.deb
      Size/MD5 checksum:    53194 754ae50a15664184d0e70de39cee22b5
    http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.10~pre070720-0etch1_s390.deb
      Size/MD5 checksum:  2184640 8dffbcd81a31d460d94243fab5ce8049

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/i/iceape/iceape-browser_1.0.10~pre070720-0etch1_sparc.deb
      Size/MD5 checksum: 10657254 83e7468e55d66d7f36d6903f5bb25fcd
    http://security.debian.org/pool/updates/main/i/iceape/iceape-calendar_1.0.10~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:   584296 8a64241ccc10cda38927ad6f15af34ce
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dbg_1.0.10~pre070720-0etch1_sparc.deb
      Size/MD5 checksum: 58501456 3e53e44bd0b33aaed55a6feab1839fc5
    http://security.debian.org/pool/updates/main/i/iceape/iceape-dom-inspector_1.0.10~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:   188616 4807d32457222d895b243cd44e390328
    http://security.debian.org/pool/updates/main/i/iceape/iceape-gnome-support_1.0.10~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:    47260 3b1cf8ec9939812c886ba3378554e73a
    http://security.debian.org/pool/updates/main/i/iceape/iceape-mailnews_1.0.10~pre070720-0etch1_sparc.deb
      Size/MD5 checksum:  1894688 b8a4207b5edc44f0e24e362db96a6ff7


  These files will probably be moved into the stable distribution on
  its next update.

-
---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp:
ftp://security.debian.org/debian-security dists/stable/updates/main Mailing
list: debian-security-announce@xxxxxxxxxxxxxxxx
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGpUB+Xm3vHE4uyloRAtK+AKCFyK4tO8NzTFh/dsfPkCjMt+kYmgCg52na
gYCMrox+ckaLZhG90jKyiXM=
=OOIl
-----END PGP SIGNATURE-----

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 1340-1                    security@xxxxxxxxxx
http://www.debian.org/security/                             Martin Schulze
July 24th, 2007                         http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : clamav
Vulnerability  : null pointer dereference
Problem type   : local (remote)
Debian-specific: no
CVE ID         : CVE-2007-3725

A NULL pointer dereference has been discovered in the RAR VM of Clam Antivirus
(ClamAV) which allows user-assisted remote attackers to cause a denial of
service via a specially crafted RAR archives.

We are currently unable to provide fixed packages for the MIPS architectures. 
Those packages will be installed in the security archive when they become
available.

The old stable distribution (sarge) is not affected by this problem.

For the stable distribution (etch) this problem has been fixed in version
0.90.1-3etch4.

For the unstable distribution (sid) this problem has been fixed in version
0.91-1.

We recommend that you upgrade your clamav packages.


Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as
given at the end of this advisory:

apt-get update
        will update the internal database apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the footer to the
proper configuration.


Debian GNU/Linux 4.0 alias etch
- -------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1-3etch4.dsc
      Size/MD5 checksum:      886 4322482c1fb82b108aa43cb9db54efd1
    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1-3etch4.diff.gz
      Size/MD5 checksum:   201403 a5c2bfc45cc81fd1f85c3bfca605c2eb
    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1.orig.tar.gz
      Size/MD5 checksum: 11643310 cd11c05b5476262eaea4fa3bd7dc25bf

  Architecture independent components:

    http://security.debian.org/pool/updates/main/c/clamav/clamav-base_0.90.1-3etch4_all.deb
      Size/MD5 checksum:   201448 cf1df37f823c25b62bb341da58b13cb9
    http://security.debian.org/pool/updates/main/c/clamav/clamav-docs_0.90.1-3etch4_all.deb
      Size/MD5 checksum:  1003244 fda3003977260e1b5cea1547167d492c
    http://security.debian.org/pool/updates/main/c/clamav/clamav-testfiles_0.90.1-3etch4_all.deb
      Size/MD5 checksum:   157626 548abf569b73b094e3807888f2f5038d

  Alpha architecture:

    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1-3etch4_alpha.deb
      Size/MD5 checksum:   863288 10878c8e050e17086aeea82678293c08
    http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1-3etch4_alpha.deb
      Size/MD5 checksum:   184482 cc5eca7ca9f6c3d7c9cb64557b975d8b
    http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1-3etch4_alpha.deb
      Size/MD5 checksum:   644222 71b240e73b41ea5a62a2e481c3ed3147
    http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1-3etch4_alpha.deb
      Size/MD5 checksum:  9303578 91aa4799771e9f6a366a84f8be4a0154
    http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1-3etch4_alpha.deb
      Size/MD5 checksum:   179638 16cb1cdf55b0f6cc983ef3c224b6ad42
    http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1-3etch4_alpha.deb
      Size/MD5 checksum:   510846 dfd5016fdaa269c808d1585eeb29b682
    http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1-3etch4_alpha.deb
      Size/MD5 checksum:   406172 76b0ab23e443a074b089e23f63c1b996

  AMD64 architecture:

    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1-3etch4_amd64.deb
      Size/MD5 checksum:   856292 ae79ee69acb68b7edc2938e74df07572
    http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1-3etch4_amd64.deb
      Size/MD5 checksum:   178250 919ffe6a6d8f087f7c64f561de240dcb
    http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1-3etch4_amd64.deb
      Size/MD5 checksum:   637868 96df7a341a13a1dcfa3726da88270285
    http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1-3etch4_amd64.deb
      Size/MD5 checksum:  9301706 97194c4ceb5cc69c897becba8509f5c6
    http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1-3etch4_amd64.deb
      Size/MD5 checksum:   176744 e9870bb2dbb4cae1415e7da8043f6d83
    http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1-3etch4_amd64.deb
      Size/MD5 checksum:   386328 cb0f86bd159db1925ec39157c345f20e
    http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1-3etch4_amd64.deb
      Size/MD5 checksum:   367102 f79837717dee7f6a9aaa9c1817fed77e

  ARM architecture:

    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1-3etch4_arm.deb
      Size/MD5 checksum:   851824 9fc5cd7039da4dde8f570720c08fdc99
    http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1-3etch4_arm.deb
      Size/MD5 checksum:   173452 ce3d61f700ed0607ebb71307928976da
    http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1-3etch4_arm.deb
      Size/MD5 checksum:   597194 f38f065738f1cafba9a3c42922223709
    http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1-3etch4_arm.deb
      Size/MD5 checksum:  9299488 10799147def77a149669c56346cc287a
    http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1-3etch4_arm.deb
      Size/MD5 checksum:   174552 e16ae0c225af49669e082239fc39a76c
    http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1-3etch4_arm.deb
      Size/MD5 checksum:   366682 8a95f23f368df1453b461a3da2c7e23c
    http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1-3etch4_arm.deb
      Size/MD5 checksum:   362572 39aba5c87cc8a8023c512926f095611b

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1-3etch4_hppa.deb
      Size/MD5 checksum:   857062 5fa4607f52271c43e9f277c69ea934f6
    http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1-3etch4_hppa.deb
      Size/MD5 checksum:   177964 17e85986371220f8bb54a9cd8368309a
    http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1-3etch4_hppa.deb
      Size/MD5 checksum:   617892 c27423a2aa54314d371cd517f52b0c61
    http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1-3etch4_hppa.deb
      Size/MD5 checksum:  9303060 034452cd5c442565ec7d150ed5b46e06
    http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1-3etch4_hppa.deb
      Size/MD5 checksum:   176816 27a3c13573a79dc97e7aea6a79c53ef4
    http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1-3etch4_hppa.deb
      Size/MD5 checksum:   432748 96afeaa27862183bea23b961600d93fe
    http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1-3etch4_hppa.deb
      Size/MD5 checksum:   404838 0573b674780cbc47d19ac0ddcf183496

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1-3etch4_i386.deb
      Size/MD5 checksum:   853720 51d46ae39ed2a720e584b5b52b2d3409
    http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1-3etch4_i386.deb
      Size/MD5 checksum:   174618 d07358cba9e467fdf2159739016d00a7
    http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1-3etch4_i386.deb
      Size/MD5 checksum:   603774 2987ddb46e82447f8e6e20d33080aa37
    http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1-3etch4_i386.deb
      Size/MD5 checksum:  9300044 d9f5a5d77235452c19669d71a6a13a93
    http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1-3etch4_i386.deb
      Size/MD5 checksum:   174752 c863d6372b97823c5cd052b22ade00b0
    http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1-3etch4_i386.deb
      Size/MD5 checksum:   367668 b1380aa6e0fe222916605f08a89c16f9
    http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1-3etch4_i386.deb
      Size/MD5 checksum:   365686 156a20aba1b91eb24f8a8b668e3a46cd

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1-3etch4_ia64.deb
      Size/MD5 checksum:   878298 2a2420da2db40f69e7654689845fa2b0
    http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1-3etch4_ia64.deb
      Size/MD5 checksum:   201470 70a6f87e38268e27afd74951851eca94
    http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1-3etch4_ia64.deb
      Size/MD5 checksum:   656106 f92e7ef6ab087b48e264e4628b87a785
    http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1-3etch4_ia64.deb
      Size/MD5 checksum:  9315074 f72f2a6a7445f23a2ab5652ac79237bc
    http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1-3etch4_ia64.deb
      Size/MD5 checksum:   191134 f79c94fa3326f59a37546f6e49a25303
    http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1-3etch4_ia64.deb
      Size/MD5 checksum:   521332 c5a2c75acf87f4e41160ec1e9fd3af72
    http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1-3etch4_ia64.deb
      Size/MD5 checksum:   474822 b5c2e4e6a30d056e05677055d220c283

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1-3etch4_powerpc.deb
      Size/MD5 checksum:   857106 5da0964bfba1524143595c0ea23dfde9
    http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1-3etch4_powerpc.deb
      Size/MD5 checksum:   181682 9805bff29a56e84a23a904ef1604723c
    http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1-3etch4_powerpc.deb
      Size/MD5 checksum:   636886 5a2a9d659d39f9363b0faa092f0ae32f
    http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1-3etch4_powerpc.deb
      Size/MD5 checksum:  9302070 0d906d48dd85f6ea63263e0580e55de8
    http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1-3etch4_powerpc.deb
      Size/MD5 checksum:   175854 2cc7ed815f9882cd268112c4ac8e0aa1
    http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1-3etch4_powerpc.deb
      Size/MD5 checksum:   405626 aa7a50f217ddb1a2637c79a3e83aad4a
    http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1-3etch4_powerpc.deb
      Size/MD5 checksum:   378180 a14d2b513f173bfbf3ce486b45d383bb

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1-3etch4_s390.deb
      Size/MD5 checksum:   855060 bbf174ba8e4b8185f093a368a4fd3068
    http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1-3etch4_s390.deb
      Size/MD5 checksum:   176256 08b08bf7eccd915ced8b284af52e2c0b
    http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1-3etch4_s390.deb
      Size/MD5 checksum:   627908 2453d58f7113081a6ba90f45c6448dc0
    http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1-3etch4_s390.deb
      Size/MD5 checksum:  9300764 19ab312ca93be29295380d0f0f965c97
    http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1-3etch4_s390.deb
      Size/MD5 checksum:   176424 c2ed7fde9ba790fb495428f318a4c6a7
    http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1-3etch4_s390.deb
      Size/MD5 checksum:   401622 18ea76e737dfa67aebfd7b62b68dbd94
    http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1-3etch4_s390.deb
      Size/MD5 checksum:   391172 795d593d6bdfcf5cbf16ba692fc54395

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1-3etch4_sparc.deb
      Size/MD5 checksum:   851152 110dd04af9f54ee83c7312e096cd9201
    http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1-3etch4_sparc.deb
      Size/MD5 checksum:   171902 53ce9d7055da42e07f28685a03a52592
    http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1-3etch4_sparc.deb
      Size/MD5 checksum:   584004 c859bae90ea21251b8faa4114eb7b9df
    http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1-3etch4_sparc.deb
      Size/MD5 checksum:  9298608 de87f85e9dd4e74fb3f1b3d85bcb53c0
    http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1-3etch4_sparc.deb
      Size/MD5 checksum:   173534 9cca508f4a123f194872d6c6f8b5af0b
    http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1-3etch4_sparc.deb
      Size/MD5 checksum:   389104 5432b26c75aa4ba4579d0c0eaaa42fdd
    http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1-3etch4_sparc.deb
      Size/MD5 checksum:   377310 0ecb88683024a0cc7ec48f715419cd0e


  These files will probably be moved into the stable distribution on
  its next update.

-
---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp:
ftp://security.debian.org/debian-security dists/stable/updates/main Mailing
list: debian-security-announce@xxxxxxxxxxxxxxxx
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGpakUW5ql+IAeqTIRAqbvAJ9vOXlEgRCXOoveSIztfNE3alRAUwCeN6/Z
ycgTsKuTI/fIPW5ekwqtGGU=
=w//P
-----END PGP SIGNATURE-----

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 1341-1                    security@xxxxxxxxxx
http://www.debian.org/security/                         Moritz Muehlenhoff
July 25th, 2007                         http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : bind9
Vulnerability  : design error
Problem-Type   : remote
Debian-specific: no
CVE ID         : CVE-2007-2926

Amit Klein discovered that the BIND name server generates predictable DNS
query IDs, which may lead to cache poisoning attacks.

An update for the oldstable distribution (sarge) is in preparation. It will be
released soon.

For the stable distribution (etch) this problem has been fixed in version
9.3.4-2etch1. An update for mips is not yet available, it will be released
soon.

For the unstable distribution (sid) this problem will be fixed soon.

We recommend that you upgrade your BIND packages.


Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as
given below:

apt-get update
        will update the internal database apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the footer to the
proper configuration.


Debian GNU/Linux 4.0 alias etch
- -------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch1.dsc
      Size/MD5 checksum:      758 428b3a45636c78046dbb77d9335a9973
    http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch1.diff.gz
      Size/MD5 checksum:   287783 47a34c979ee9db072b37e2ae0ad0bdec
    http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4.orig.tar.gz
      Size/MD5 checksum:  4043577 198181d47c58a0a9c0265862cd5557b0

  Architecture independent components:

    http://security.debian.org/pool/updates/main/b/bind9/bind9-doc_9.3.4-2etch1_all.deb
      Size/MD5 checksum:   186546 3ac7d54f57348ac941d5e0812ccc12f5

  Alpha architecture:

    http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch1_alpha.deb
      Size/MD5 checksum:   322456 dfe4b93bc4f56fd5dd0d8e2d1998ad28
    http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch1_alpha.deb
      Size/MD5 checksum:   115188 9e79109d03b06a82561bb3245d85b53c
    http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch1_alpha.deb
      Size/MD5 checksum:   188024 9df9116f4e4d87dd6d1f310506762d05
    http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch1_alpha.deb
      Size/MD5 checksum:  1407446 2c263eb7c5a053db9127f5bb4ea3e63a
    http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch1_alpha.deb
      Size/MD5 checksum:    96012 39238a7c31a2f36fcd55152cf3c3314e
    http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch1_alpha.deb
      Size/MD5 checksum:   566696 a5cb0c0f4e1935fd836d17baed691184
    http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch1_alpha.deb
      Size/MD5 checksum:   189572 8ec031302a94a02a09b0af196bd300dc
    http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch1_alpha.deb
      Size/MD5 checksum:    97650 0075b972a1a8893cd71c66bcaaff95d4
    http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch1_alpha.deb
      Size/MD5 checksum:   111912 cae6cf777332ed408fd6b122198d325f
    http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch1_alpha.deb
      Size/MD5 checksum:   115874 fc5f861aad1689c7aeba2f1f012324ba
    http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch1_alpha.deb
      Size/MD5 checksum:   225398 f4b2582ac5d26563becd0b83e7f054ba

  AMD64 architecture:

    http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch1_amd64.deb
      Size/MD5 checksum:   317188 4426301631236673c7501c63d7d1be64
    http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch1_amd64.deb
      Size/MD5 checksum:   116584 8485c57afdaefb85a77c2cec61bb0b7b
    http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch1_amd64.deb
      Size/MD5 checksum:   190490 8081ccaac50c67c51e9a49804d22e2f1
    http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch1_amd64.deb
      Size/MD5 checksum:  1110612 dfa5a6f773e5cc985ca15b08cf868afc
    http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch1_amd64.deb
      Size/MD5 checksum:    95162 de0fd449293c68f17886b9fcf8aaf3e0
    http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch1_amd64.deb
      Size/MD5 checksum:   553466 7a6494a6bd042ccf5df4d99d6c5c2542
    http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch1_amd64.deb
      Size/MD5 checksum:   186922 83db82dca4032d2326be7b1bb8624d19
    http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch1_amd64.deb
      Size/MD5 checksum:    95958 76cf006f35ab0fe0d5db1bea77902e7c
    http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch1_amd64.deb
      Size/MD5 checksum:   110608 099dbfa728bbd0ba230362327b96af33
    http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch1_amd64.deb
      Size/MD5 checksum:   113880 b90a561a40975ea4cddd3f59dc2d5a6b
    http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch1_amd64.deb
      Size/MD5 checksum:   223960 34ce7a0693aadc21ece63efc42717dc3

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch1_hppa.deb
      Size/MD5 checksum:   311286 ddc9ebd93f06b76792798a6a5bc01d34
    http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch1_hppa.deb
      Size/MD5 checksum:   115332 36e51f58ed0be288c2ab066bd0e1e763
    http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch1_hppa.deb
      Size/MD5 checksum:   187714 7ade5d593bef956f1dd7769c29f6551f
    http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch1_hppa.deb
      Size/MD5 checksum:  1257768 dcffd2d0af9262b3b3c2d1b8166d9c65
    http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch1_hppa.deb
      Size/MD5 checksum:    96256 c10cd5cc0d827b485e7a6b1d06342992
    http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch1_hppa.deb
      Size/MD5 checksum:   545018 c8a2f5a0a086a858ce4ae4e9c096d28c
    http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch1_hppa.deb
      Size/MD5 checksum:   185090 039d93f2286fa4974c360745f6e7ec89
    http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch1_hppa.deb
      Size/MD5 checksum:    96074 98b897d5f0c8ff086514d86801122d30
    http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch1_hppa.deb
      Size/MD5 checksum:   112556 16330ecebbd5be5dcfbfa7acb67c89aa
    http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch1_hppa.deb
      Size/MD5 checksum:   113746 ccb0abb76e39395ec051eac5b10ab3bb
    http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch1_hppa.deb
      Size/MD5 checksum:   216754 94ea9e9fc614f3ae44e184d4a070dee8

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch1_i386.deb
      Size/MD5 checksum:   294096 a54d3779c21bc3d3ea13b8991aedd55c
    http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch1_i386.deb
      Size/MD5 checksum:   112686 91b9f6ad1fe1d3bed4473e844060755d
    http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch1_i386.deb
      Size/MD5 checksum:   180052 acdaa5225d7a8a46dfa018d33b85917f
    http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch1_i386.deb
      Size/MD5 checksum:   995710 8d44e9f8b65868d201cc0593c035a0b2
    http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch1_i386.deb
      Size/MD5 checksum:    94040 208d791ca231d336850b8526b61dc547
    http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch1_i386.deb
      Size/MD5 checksum:   473758 f0ca4e1c62970bcdb4ca0e4fec82bd20
    http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch1_i386.deb
      Size/MD5 checksum:   168910 f1be1c9a61bb8c1a7b28a73144a0febc
    http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch1_i386.deb
      Size/MD5 checksum:    94014 3927f50039cb5a3815d37ee60b8f0805
    http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch1_i386.deb
      Size/MD5 checksum:   105664 24dd5215d1eb5aabe10f68bd379dfbf5
    http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch1_i386.deb
      Size/MD5 checksum:   109552 9211a8f796f460cb1674ad233f99f0b8
    http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch1_i386.deb
      Size/MD5 checksum:   206122 5f581d25b7eac5d9924633c48374cfd9

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch1_ia64.deb
      Size/MD5 checksum:   392704 fbb60f8a53e1df4370f6b1fa04dcaa7f
    http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch1_ia64.deb
      Size/MD5 checksum:   125346 d7b91c0fd8c935dc80d5c2f10dfb71cd
    http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch1_ia64.deb
      Size/MD5 checksum:   215892 d8b6b3e6a35d326074763dcb6f2a02d1
    http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch1_ia64.deb
      Size/MD5 checksum:  1585738 f246e3455fdcc4bede6aaa4feb7e5a4c
    http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch1_ia64.deb
      Size/MD5 checksum:    99586 a6a90361dbe16b55fac090b6221bb2b6
    http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch1_ia64.deb
      Size/MD5 checksum:   742434 2d827017a7f76dbaae60ac1c827c7375
    http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch1_ia64.deb
      Size/MD5 checksum:   231552 8968c74dabdb69eeb4091e8a8d4b2139
    http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch1_ia64.deb
      Size/MD5 checksum:   102034 da5aec0bfc2e2f8c659f563a8774596a
    http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch1_ia64.deb
      Size/MD5 checksum:   117356 99c85d5fd4b7790a8a3fbe0b66c55ce8
    http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch1_ia64.deb
      Size/MD5 checksum:   127150 3f764e3176185b773ddfa988105dce93
    http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch1_ia64.deb
      Size/MD5 checksum:   280214 ca7ba1f13de17522a302538390731a11

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch1_mipsel.deb
      Size/MD5 checksum:   298960 386cfb4312bfed69a2ed12304609a3ed
    http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch1_mipsel.deb
      Size/MD5 checksum:   112532 92eb6f06d4a18dca899f5d23caddea3b
    http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch1_mipsel.deb
      Size/MD5 checksum:   179148 4ca657710b1071bac2ebd2a27ac1122c
    http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch1_mipsel.deb
      Size/MD5 checksum:  1206278 03496e479c5e92c1e4e6bbb63c54f73b
    http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch1_mipsel.deb
      Size/MD5 checksum:    93742 cb50eb9cce7422e8879aa796dfdb7b8d
    http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch1_mipsel.deb
      Size/MD5 checksum:   489944 ab86bfaff22e47af0bfd3fc57c0db801
    http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch1_mipsel.deb
      Size/MD5 checksum:   173664 03c3008a5493f50b453ac239e843a5db
    http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch1_mipsel.deb
      Size/MD5 checksum:    94564 5c1aab5f8cee9fac9e678737b5171ecc
    http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch1_mipsel.deb
      Size/MD5 checksum:   106766 7d53ee8d69117fdde48a1074cfdd3f1b
    http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch1_mipsel.deb
      Size/MD5 checksum:   109844 13abaab553f3c76403b948fea9d0cc1c
    http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch1_mipsel.deb
      Size/MD5 checksum:   210372 4bdb416e4876166765b8aa3987d8e339

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch1_powerpc.deb
      Size/MD5 checksum:   300740 b8f07903829e88e7dd495cb0866a1be4
    http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch1_powerpc.deb
      Size/MD5 checksum:   113376 20cdab8f8babc1e60bcc6e34824be459
    http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch1_powerpc.deb
      Size/MD5 checksum:   182824 7eb696a4324c5ad3f8b403a977c62c55
    http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch1_powerpc.deb
      Size/MD5 checksum:  1169274 289ca4f005063dec3ad819896ba0afb1
    http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch1_powerpc.deb
      Size/MD5 checksum:    95760 ca5d0db4143552b8570c766acea14a71
    http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch1_powerpc.deb
      Size/MD5 checksum:   490474 ef3bc644324fd9293b8f132e3bdf6eef
    http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch1_powerpc.deb
      Size/MD5 checksum:   173214 49a7fec7735be2fa5143280197d2e34d
    http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch1_powerpc.deb
      Size/MD5 checksum:    95768 6970420c1ca23d748ed7bdf9efc029e1
    http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch1_powerpc.deb
      Size/MD5 checksum:   108868 a0be0fc5c4c666348cc11d3502fa8a30
    http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch1_powerpc.deb
      Size/MD5 checksum:   111876 899a074f3970c21cb97e2d0b5a3b3606
    http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch1_powerpc.deb
      Size/MD5 checksum:   206322 24bce060644edb83c85a83e1c0d81087

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch1_s390.deb
      Size/MD5 checksum:   331352 1d686878f52e8d8a3a1a10dd5d1eeae2
    http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch1_s390.deb
      Size/MD5 checksum:   117686 53039a718a231df07de1020ae4062d04
    http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch1_s390.deb
      Size/MD5 checksum:   194230 4fefe9085f9c27fd11f63b944ebe1583
    http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch1_s390.deb
      Size/MD5 checksum:  1138900 d511892e9f7b30f034d30d9b10722f67
    http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch1_s390.deb
      Size/MD5 checksum:    95298 6f5505c5815bd05d5acca2a7bc918f52
    http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch1_s390.deb
      Size/MD5 checksum:   581310 338f8914e14bfdc50835252d76f0fd42
    http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch1_s390.deb
      Size/MD5 checksum:   196206 543df937ea45c7b5f784c1c952a7f5e0
    http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch1_s390.deb
      Size/MD5 checksum:    97416 fa1af3cf8a7416f3ed5b7d42c836b8b2
    http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch1_s390.deb
      Size/MD5 checksum:   113884 2ec66079b2d2e11cf897f0977729a4c1
    http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch1_s390.deb
      Size/MD5 checksum:   116232 f5fa31d37e78bbb36f73d53da5da27ea
    http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch1_s390.deb
      Size/MD5 checksum:   233484 1dffc0d674f30381bbe5a7ffdbc30518

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/b/bind9/bind9_9.3.4-2etch1_sparc.deb
      Size/MD5 checksum:   299544 d87837fe5a3f20c6a14fdf3318dd2262
    http://security.debian.org/pool/updates/main/b/bind9/bind9-host_9.3.4-2etch1_sparc.deb
      Size/MD5 checksum:   113810 f403041c08435061da227325811fa162
    http://security.debian.org/pool/updates/main/b/bind9/dnsutils_9.3.4-2etch1_sparc.deb
      Size/MD5 checksum:   183572 8af8396c1de389c5d59c043f957f6ffc
    http://security.debian.org/pool/updates/main/b/bind9/libbind-dev_9.3.4-2etch1_sparc.deb
      Size/MD5 checksum:  1122852 f127cc8eaf19ea1afc0e75d95dddfe01
    http://security.debian.org/pool/updates/main/b/bind9/libbind9-0_9.3.4-2etch1_sparc.deb
      Size/MD5 checksum:    94460 5a3a6e60c48ea5a2430852e8f0bdccde
    http://security.debian.org/pool/updates/main/b/bind9/libdns22_9.3.4-2etch1_sparc.deb
      Size/MD5 checksum:   495516 6be9e70176aea0f4103f66638d1ddb4e
    http://security.debian.org/pool/updates/main/b/bind9/libisc11_9.3.4-2etch1_sparc.deb
      Size/MD5 checksum:   174856 af7512793320752e3607994adcdf5192
    http://security.debian.org/pool/updates/main/b/bind9/libisccc0_9.3.4-2etch1_sparc.deb
      Size/MD5 checksum:    94450 607818b14e52d297085cf59f207afce7
    http://security.debian.org/pool/updates/main/b/bind9/libisccfg1_9.3.4-2etch1_sparc.deb
      Size/MD5 checksum:   107158 67c296d0d2ca2bd11260b9433bb8b444
    http://security.debian.org/pool/updates/main/b/bind9/liblwres9_9.3.4-2etch1_sparc.deb
      Size/MD5 checksum:   110702 0237570eab7e9344b78728b6ff4c3a55
    http://security.debian.org/pool/updates/main/b/bind9/lwresd_9.3.4-2etch1_sparc.deb
      Size/MD5 checksum:   210042 3d5b39b5e149149d314c3d3b0693e057


  These files will probably be moved into the stable distribution on
  its next update.

-
---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp:
ftp://security.debian.org/debian-security dists/stable/updates/main Mailing
list: debian-security-announce@xxxxxxxxxxxxxxxx
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGp7yHXm3vHE4uyloRAmPkAJ0d9LV4wpLbtbYfVvg599mOZGgPagCeIleR
7/s4k59bitmpC29AHyMI5VE=
=1VmY
-----END PGP SIGNATURE-----



______________________________________________________________________________

CPNI values your feedback.

1. Which of the following most reflects the value of the advisory to you?
(Place an 'X' next to your choice)

Very useful:__ Useful:__ Not useful:__

2. If you did not find it useful, why not?


3. Any other comments? How could we improve our advisories?


Thank you for your contribution.
______________________________________________________________________________

For additional information or assistance, please contact our help desk by
telephone.

You may send Not Protectively Marked information via e-mail to
csirtuk@xxxxxxxxxxxxxxxx

Office hours:

Mon - Fri: 09:00 - 16:30 hours
Tel: +44 (0) 870 487 0748 and follow the voice prompts
Fax: +44 (0) 870 487 0749

On-call duty officer outside office hours:
Tel: +44 (0) 870 487 0748 and follow the voice prompts

______________________________________________________________________________

This advisory contains information released by the original author. Some of
the information may have changed since it was released. If the issue affects
you, it may be prudent to retrieve the advisory from the site of the original
source to ensure that you receive the most current information concerning that
problem. Reference to any specific commercial product, process, or service by
trade name, trademark manufacturer, or otherwise, does not constitute or imply
its endorsement, recommendation, or favouring by CPNI.

The views and opinions of authors expressed within this notice shall not be
used for advertising or product endorsement purposes. CPNI shall not accept
responsibility for any errors or omissions contained within this advisory. In
particular, they shall not be liable for any loss or damage whatsoever,
arising from or in connection with the usage of information contained within
this advisory.

CSIRTUK is a member of the Forum of Incident Response and Security Teams
(FIRST) and has contacts with other international Incident Response Teams
(IRTs) in order to foster cooperation and coordination in incident prevention,
to prompt rapid reaction to incidents, and to promote information sharing
amongst its members and the community at large.
______________________________________________________________________________

<End of CSIRTUK Advisory>






______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email 
______________________________________________________________________