Search This Blog

Monday, April 22, 2013

[SECURITY] [DSA 2663-1] tinc security update

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-2663-1 security@debian.org
http://www.debian.org/security/ Yves-Alexis Perez
April 22, 2013 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : tinc
Vulnerability : stack based buffer overflow
Problem type : remote
Debian-specific: no
CVE ID : CVE-2013-1428

Martin Schobert discovered a stack-based vulnerability in tinc, a virtual
private network daemon.

When packets are forwarded via TCP, packet length is not checked against
the stack buffer length. Authenticated peers could use this to crash the
tinc daemon and maybe execute arbitrary code.

Note that on Wheezy and Sid, tinc is built using hardening flags and
especially stack smashing protection, which should help protect against
arbitrary code execution.

For the stable distribution (squeeze), this problem has been fixed in
version 1.0.13-1+squeeze1.

For the testing distribution (wheezy), this problem has been fixed in
version 1.0.19-3.

For the unstable distribution (sid), this problem has been fixed in
version 1.0.19-3.

We recommend that you upgrade your tinc packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.19 (GNU/Linux)

iQEcBAEBCgAGBQJRdaZuAAoJEG3bU/KmdcClqMIH/0gueevwYrOuGpJ3A943ZgWT
B6R7uKlvMrZshmFQX9tvzFiT9YrTC5/oADF9ujo4abeMaODUhVBoXoFOGuWKV8iV
zi3ue09NNxhE5kyA6UQpaEnbamdIegP2cKfmte/s4PePO6tTSb2VpdbqvRGonKWK
R1kah9mUOwnZpr6S2hVlyEo3xzD4I+mK/v8Zpj5fy8U63e0vt9NIcB289UO9XaK2
mKHD82C8Y/80SJktRyqWtAfBrboVaggGyHH9OssU6F9SobFSGUWFaGo4HfpcQmdy
Lr5J0eVhEOk83nUpV908lWJRm4T+i9oOWmp/MMlCWO/UxnixBLNX3XTw1Y8dXjY=
=Ctrc
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: http://lists.debian.org/20130422210659.GA25173@scapa.corsac.net

14 comments:

Anonymous said...

Hey I know this is off topic but I was wondering if you knew of any widgets I could add to
my blog that automatically tweet my newest twitter updates.

I've been looking for a plug-in like this for quite some time and was hoping maybe you would have some experience with something like this. Please let me know if you run into anything. I truly enjoy reading your blog and I look forward to your new updates.

Also visit my blog; white retriever

Anonymous said...

You actually make it seem so easy with your presentation
but I find this matter to be really something which I think I would never understand.

It seems too complicated and very broad for me.
I'm looking forward for your next post, I will try to get the hang of it!

Feel free to surf to my web-site: click for http://www.golden-retriever-guide.com/golden-retriever-temperament/ details

Anonymous said...

Heya i am for the first time here. I found this board and I find It truly useful & it helped
me out a lot. I hope to give something back and help others like you aided me.


Here is my blog post; read this

Anonymous said...

Yes! Finally something about medium dog breeds and pictures.


my site: check my source

Anonymous said...

I think the admin of this site is truly working hard in support of his website, as here
every information is quality based stuff.

Check out my web page; golden lab puppies

Anonymous said...

Unquestionably imagine that which you said. Your favourite
reason seemed to be at the internet the easiest factor to take into account of.

I say to you, I certainly get annoyed even as people consider
issues that they just do not understand about.
You controlled to hit the nail upon the highest and defined out the whole
thing without having side-effects , other folks can take a signal.

Will likely be back to get more. Thank you

Also visit my homepage - more about the author

Anonymous said...

I believe this is among the most vital information for me.

And i am happy studying your article. But should observation on few normal things, The web site style is wonderful, the articles is truly excellent : D.
Just right job, cheers

Feel free to visit my web-site Click This Link

Anonymous said...

We stumbled over here from a different page and thought I might as well check things out.
I like what I see so now i'm following you. Look forward to finding out about your web page again.

My web page - click for information on golden retrievers details

Anonymous said...

Good write-up. I absolutely love this site. Stick with it!


my webpage ... training golden retriever puppies

Anonymous said...

For latest information you have to pay a quick visit world-wide-web
and on world-wide-web I found this web page as a finest web page for latest updates.



My webpage - Go To My Site

Anonymous said...

Very quickly this website will be famous among all blogging and site-building viewers,
due to it's fastidious articles or reviews

Take a look at my webpage golden retriever lab mix breeders

Anonymous said...

Peculiar article, exactly what I wanted to find.


my web-site - good information on golden retrievers tips

Anonymous said...

Nice post. I learn something new and challenging on sites I stumbleupon on a daily basis.
It will always be exciting to read articles from other authors and use a little something from
their web sites.

Also visit my web site - black lab golden retriever

Anonymous said...

I used to be recommended this website by my
cousin. I'm now not sure whether or not this submit is written by means of him as no one else recognize such specific about my problem. You are incredible! Thanks!

Feel free to surf to my web blog; click for source