---------------------------------------------------------------------- Do you have VARM strategy implemented? (Vulnerability Assessment Remediation Management) If not, then implement it through the most reliable vulnerability intelligence source on the market. Implement it through Secunia. For more information visit: http://secunia.com/advisories/business_solutions/ Alternatively request a call from a Secunia representative today to discuss how we can help you with our capabilities contact us at: sales@secunia.com ---------------------------------------------------------------------- TITLE: Debian update for devscripts SECUNIA ADVISORY ID: SA36514 VERIFY ADVISORY: http://secunia.com/advisories/36514/ DESCRIPTION: Debian has issued an update for devscripts. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to the uscan program downloading and running Perl code from untrusted sources and can be exploited to execute arbitrary commands. SOLUTION: Apply updated packages. -- Debian GNU/Linux 4.0 alias etch -- Source archives: http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4.tar.gz Size/MD5 checksum: 432330 6d13d4ec0e161a62d0babd45b58e9f75 http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4.dsc Size/MD5 checksum:682 0cd547c5e78642f16762e0d687997563 alpha architecture (DEC Alpha) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_alpha.deb Size/MD5 checksum: 389730 42458f68b3f75d87bb0397e6befde980 amd64 architecture (AMD x86_64 (AMD64)) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_amd64.deb Size/MD5 checksum: 399454 8f648a32c698f15d4c6c2a90f9cdc19a arm architecture (ARM) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_arm.deb Size/MD5 checksum: 396212 3187e3df12e04da5b2abb3aabf63f293 hppa architecture (HP PA RISC) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_hppa.deb Size/MD5 checksum: 400058 bc84514b7d6e87c2bace8ee054cea2b6 i386 architecture (Intel ia32) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_i386.deb Size/MD5 checksum: 394688 35c9379172ffb63d89f512e7b46653db ia64 architecture (Intel ia64) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_ia64.deb Size/MD5 checksum: 391116 f0d5a42de7f2f36d1433c550655c9cc9 mips architecture (MIPS (Big Endian)) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_mips.deb Size/MD5 checksum: 396716 30793d09ae26fdd5fbcf47fc011fb7d9 mipsel architecture (MIPS (Little Endian)) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_mipsel.deb Size/MD5 checksum: 389640 750928f91a3066a5288f807cd5afa953 powerpc architecture (PowerPC) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_powerpc.deb Size/MD5 checksum: 391870 5b5b3fcbf001a6d390515fb64829ba80 s390 architecture (IBM S/390) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_s390.deb Size/MD5 checksum: 389540 40471968ab5a26bb0227b4954814a270 sparc architecture (Sun SPARC/UltraSPARC) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.9.26etch4_sparc.deb Size/MD5 checksum: 397816 5f773402f6ebf2b00170d46686ee0418 -- Debian GNU/Linux 5.0 alias lenny -- Source archives: http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6.tar.gz Size/MD5 checksum: 602179 4bc83fe370d730667e9fe8fe222bf115 http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6.dsc Size/MD5 checksum: 1417 6cd189a95491bdd4ce32e908acd55cd8 alpha architecture (DEC Alpha) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_alpha.deb Size/MD5 checksum: 509058 dd02c9afaf74b8633699b7e5aee3aef3 amd64 architecture (AMD x86_64 (AMD64)) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_amd64.deb Size/MD5 checksum: 519036 3f274c25fabc3d22cb329c621dd0f630 arm architecture (ARM) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_arm.deb Size/MD5 checksum: 520644 e4ee996772f786c6883c779420125dda armel architecture (ARM EABI) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_armel.deb Size/MD5 checksum: 520300 eae935b7a416989bb2cddabae3870e37 hppa architecture (HP PA RISC) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_hppa.deb Size/MD5 checksum: 524510 648acee4d3d9ed48eb2415ce36c5519e i386 architecture (Intel ia32) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_i386.deb Size/MD5 checksum: 517734 f5e74325fdfda2cf7cfb690be807a1de ia64 architecture (Intel ia64) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_ia64.deb Size/MD5 checksum: 510044 bde1efc77895c33d6e0ff5e49fcea63f mips architecture (MIPS (Big Endian)) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_mips.deb Size/MD5 checksum: 508946 2e3c9714a01e41655c467c2fd4f41f09 mipsel architecture (MIPS (Little Endian)) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_mipsel.deb Size/MD5 checksum: 508980 4cc636a2e0391f8405808b80529020a6 powerpc architecture (PowerPC) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_powerpc.deb Size/MD5 checksum: 511348 96628900942da87fed1133f6d97ed8ea s390 architecture (IBM S/390) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_s390.deb Size/MD5 checksum: 508898 f6eaf845971c27830890021c1106c19b sparc architecture (Sun SPARC/UltraSPARC) http://security.debian.org/pool/updates/main/d/devscripts/devscripts_2.10.35lenny6_sparc.deb Size/MD5 checksum: 523130 773b2a7f70551467601af5d1daf8a776 PROVIDED AND/OR DISCOVERED BY: Debian credits Raphael Geissert. ORIGINAL ADVISORY: DSA-1878-1: http://www.us.debian.org/security/2009/dsa-1878 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------