Debian セキュリティ勧告

DSA-660-1 kdebase -- 戻り値チェックの抜け

報告日時:
2005-01-26
影響を受けるパッケージ:
kdebase
危険性:
あり
参考セキュリティデータベース:
Mitre の CVE 辞書: CVE-2005-0078.
詳細:

Raphaël Enrici さんは、KDE スクリーンセーバを特定のローカルな条件下でクラッシュさせるのが可能なことを発見しました。 攻撃者が物理的にワークステーションにアクセス可能な場合、 これを利用してデスクトップのセッションを乗っ取ることが可能です。

安定版ディストリビューション (stable、コードネーム woody) では、この問題はバージョン 2.2.2-14.9 で修正されています。

この問題は、開発元では KDE 3.0.5 で修正されています。 よって、不安定版 (unstable、コードネーム sid) およびテスト版 (testing、コードネーム sarge) ディストリビューションはすでに修正済みとなっています。

kscreensaver パッケージのアップグレードをお勧めします。

修正:

Debian GNU/Linux 3.0 (woody)

ソース:
http://security.debian.org/pool/updates/main/k/kdebase/kdebase_2.2.2-14.9.dsc
http://security.debian.org/pool/updates/main/k/kdebase/kdebase_2.2.2-14.9.diff.gz
http://security.debian.org/pool/updates/main/k/kdebase/kdebase_2.2.2.orig.tar.gz
アーキテクチャ非依存コンポーネント:
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-doc_2.2.2-14.9_all.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdewallpapers_2.2.2-14.9_all.deb
Alpha:
http://security.debian.org/pool/updates/main/k/kdebase/kate_2.2.2-14.9_alpha.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase_2.2.2-14.9_alpha.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-audiolibs_2.2.2-14.9_alpha.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-dev_2.2.2-14.9_alpha.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-libs_2.2.2-14.9_alpha.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdm_2.2.2-14.9_alpha.deb
http://security.debian.org/pool/updates/main/k/kdebase/konqueror_2.2.2-14.9_alpha.deb
http://security.debian.org/pool/updates/main/k/kdebase/konsole_2.2.2-14.9_alpha.deb
http://security.debian.org/pool/updates/main/k/kdebase/kscreensaver_2.2.2-14.9_alpha.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq-dev_2.2.2-14.9_alpha.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq3_2.2.2-14.9_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/k/kdebase/kate_2.2.2-14.9_arm.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase_2.2.2-14.9_arm.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-audiolibs_2.2.2-14.9_arm.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-dev_2.2.2-14.9_arm.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-libs_2.2.2-14.9_arm.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdm_2.2.2-14.9_arm.deb
http://security.debian.org/pool/updates/main/k/kdebase/konqueror_2.2.2-14.9_arm.deb
http://security.debian.org/pool/updates/main/k/kdebase/konsole_2.2.2-14.9_arm.deb
http://security.debian.org/pool/updates/main/k/kdebase/kscreensaver_2.2.2-14.9_arm.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq-dev_2.2.2-14.9_arm.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq3_2.2.2-14.9_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/k/kdebase/kate_2.2.2-14.9_i386.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase_2.2.2-14.9_i386.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-audiolibs_2.2.2-14.9_i386.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-dev_2.2.2-14.9_i386.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-libs_2.2.2-14.9_i386.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdm_2.2.2-14.9_i386.deb
http://security.debian.org/pool/updates/main/k/kdebase/konqueror_2.2.2-14.9_i386.deb
http://security.debian.org/pool/updates/main/k/kdebase/konsole_2.2.2-14.9_i386.deb
http://security.debian.org/pool/updates/main/k/kdebase/kscreensaver_2.2.2-14.9_i386.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq-dev_2.2.2-14.9_i386.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq3_2.2.2-14.9_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/k/kdebase/kate_2.2.2-14.9_ia64.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase_2.2.2-14.9_ia64.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-audiolibs_2.2.2-14.9_ia64.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-dev_2.2.2-14.9_ia64.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-libs_2.2.2-14.9_ia64.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdm_2.2.2-14.9_ia64.deb
http://security.debian.org/pool/updates/main/k/kdebase/konqueror_2.2.2-14.9_ia64.deb
http://security.debian.org/pool/updates/main/k/kdebase/konsole_2.2.2-14.9_ia64.deb
http://security.debian.org/pool/updates/main/k/kdebase/kscreensaver_2.2.2-14.9_ia64.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq-dev_2.2.2-14.9_ia64.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq3_2.2.2-14.9_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/k/kdebase/kate_2.2.2-14.9_hppa.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase_2.2.2-14.9_hppa.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-audiolibs_2.2.2-14.9_hppa.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-dev_2.2.2-14.9_hppa.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-libs_2.2.2-14.9_hppa.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdm_2.2.2-14.9_hppa.deb
http://security.debian.org/pool/updates/main/k/kdebase/konqueror_2.2.2-14.9_hppa.deb
http://security.debian.org/pool/updates/main/k/kdebase/konsole_2.2.2-14.9_hppa.deb
http://security.debian.org/pool/updates/main/k/kdebase/kscreensaver_2.2.2-14.9_hppa.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq-dev_2.2.2-14.9_hppa.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq3_2.2.2-14.9_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/k/kdebase/kate_2.2.2-14.9_m68k.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase_2.2.2-14.9_m68k.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-audiolibs_2.2.2-14.9_m68k.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-dev_2.2.2-14.9_m68k.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-libs_2.2.2-14.9_m68k.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdm_2.2.2-14.9_m68k.deb
http://security.debian.org/pool/updates/main/k/kdebase/konqueror_2.2.2-14.9_m68k.deb
http://security.debian.org/pool/updates/main/k/kdebase/konsole_2.2.2-14.9_m68k.deb
http://security.debian.org/pool/updates/main/k/kdebase/kscreensaver_2.2.2-14.9_m68k.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq-dev_2.2.2-14.9_m68k.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq3_2.2.2-14.9_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/k/kdebase/kate_2.2.2-14.9_mips.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase_2.2.2-14.9_mips.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-audiolibs_2.2.2-14.9_mips.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-dev_2.2.2-14.9_mips.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-libs_2.2.2-14.9_mips.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdm_2.2.2-14.9_mips.deb
http://security.debian.org/pool/updates/main/k/kdebase/konqueror_2.2.2-14.9_mips.deb
http://security.debian.org/pool/updates/main/k/kdebase/konsole_2.2.2-14.9_mips.deb
http://security.debian.org/pool/updates/main/k/kdebase/kscreensaver_2.2.2-14.9_mips.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq-dev_2.2.2-14.9_mips.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq3_2.2.2-14.9_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/k/kdebase/kate_2.2.2-14.9_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase_2.2.2-14.9_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-audiolibs_2.2.2-14.9_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-dev_2.2.2-14.9_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-libs_2.2.2-14.9_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdm_2.2.2-14.9_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdebase/konqueror_2.2.2-14.9_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdebase/konsole_2.2.2-14.9_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdebase/kscreensaver_2.2.2-14.9_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq-dev_2.2.2-14.9_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq3_2.2.2-14.9_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/k/kdebase/kate_2.2.2-14.9_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase_2.2.2-14.9_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-audiolibs_2.2.2-14.9_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-dev_2.2.2-14.9_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-libs_2.2.2-14.9_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdm_2.2.2-14.9_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdebase/konqueror_2.2.2-14.9_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdebase/konsole_2.2.2-14.9_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdebase/kscreensaver_2.2.2-14.9_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq-dev_2.2.2-14.9_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq3_2.2.2-14.9_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/k/kdebase/kate_2.2.2-14.9_s390.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase_2.2.2-14.9_s390.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-audiolibs_2.2.2-14.9_s390.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-dev_2.2.2-14.9_s390.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-libs_2.2.2-14.9_s390.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdm_2.2.2-14.9_s390.deb
http://security.debian.org/pool/updates/main/k/kdebase/konqueror_2.2.2-14.9_s390.deb
http://security.debian.org/pool/updates/main/k/kdebase/konsole_2.2.2-14.9_s390.deb
http://security.debian.org/pool/updates/main/k/kdebase/kscreensaver_2.2.2-14.9_s390.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq-dev_2.2.2-14.9_s390.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq3_2.2.2-14.9_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/k/kdebase/kate_2.2.2-14.9_sparc.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase_2.2.2-14.9_sparc.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-audiolibs_2.2.2-14.9_sparc.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-dev_2.2.2-14.9_sparc.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdebase-libs_2.2.2-14.9_sparc.deb
http://security.debian.org/pool/updates/main/k/kdebase/kdm_2.2.2-14.9_sparc.deb
http://security.debian.org/pool/updates/main/k/kdebase/konqueror_2.2.2-14.9_sparc.deb
http://security.debian.org/pool/updates/main/k/kdebase/konsole_2.2.2-14.9_sparc.deb
http://security.debian.org/pool/updates/main/k/kdebase/kscreensaver_2.2.2-14.9_sparc.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq-dev_2.2.2-14.9_sparc.deb
http://security.debian.org/pool/updates/main/k/kdebase/libkonq3_2.2.2-14.9_sparc.deb

一覧にあるファイルの MD5 チェックサムは勧告の原文にあります。