From 04604f46ae92d8214e69f47f6b03566fdd1368bc Mon Sep 17 00:00:00 2001 From: Neil McGovern Date: Thu, 1 Feb 2007 10:44:18 +0000 Subject: release DTSA-32-1.html (bcfg2) git-svn-id: svn+ssh://svn.debian.org/svn/secure-testing@5396 e39458fd-73e7-0310-bf30-c45bca0a0e42 --- website/DTSA/DTSA-32-1.html | 90 +++++++++++++++++++++++++++++++++++++++++++++ website/list.html | 6 ++- 2 files changed, 95 insertions(+), 1 deletion(-) create mode 100644 website/DTSA/DTSA-32-1.html (limited to 'website') diff --git a/website/DTSA/DTSA-32-1.html b/website/DTSA/DTSA-32-1.html new file mode 100644 index 0000000000..37a29575b0 --- /dev/null +++ b/website/DTSA/DTSA-32-1.html @@ -0,0 +1,90 @@ + + + Debian testing security team - Advisory + + + + +
+ + + + + Debian Project +
+
+ + + + + + + + + + + +
+ Debian testing security team - Advisory +
+ + +
+ + +

DTSA-32-1

+
+
Date Reported:
+
February 1st, 2007
+
Affected Package:
+
bcfg2
+
Vulnerability:
+
programming error
+
Problem-Scope:
+
local
+
Debian-specific:
+
No
+
CVE:
+
+None so far +
+
More information:
+
Incorrect permissions for the bcfg2 configuration file could lead to password 
+disclosure to unprivileged users. 

+Please note that bcfg2 is not present in sarge. 
+
+
For the testing distribution (etch) this is fixed in version 0.8.6.1-1.1etch1
+
For the unstable distribution (sid) this is fixed in version 0.8.7.3-1
+
This upgrade is recommended if you use bcfg2.
+
If you have the secure testing lines in your sources.list, you can update by running this command as root:
+ +
apt-get update && apt-get install bcfg2
+
+ +
+
To use the Debian testing security archive, add the following lines to your /etc/apt/sources.list:
+
+
deb http://security.debian.org/ testing/updates main contrib non-free
+
deb-src http://security.debian.org/ testing/updates main contrib non-free
+
+
The archive signing key can be downloaded from
+
http://secure-testing.debian.net/ziyi-2005-7.asc
+ +
+ + +
+ + Valid HTML 4.01! + + Valid CSS! + + + + diff --git a/website/list.html b/website/list.html index b4f78fb1b7..95fcccf557 100644 --- a/website/list.html +++ b/website/list.html @@ -91,8 +91,12 @@
potential data corruption when installed seduid root
[January 25th, 2005] DTSA-28-1 gpdf
multiple vulnerabilities
-
[June 15th, 2006] DTSA-29-1 Blender
+
[June 15th, 2006] DTSA-29-1 blender
heap-based buffer overflow
+
[September 27th, 2006] DTSA-31-1 hyperestraier
+
cross-site request forgery (CSRF) vulnerability
+
[February 1st, 2007] DTSA-32-1 bcfg2
+
programming error

-- cgit v1.2.3