Secunia Logo  
 
Debian update for smstools
Secunia Advisory: SA18357
Release Date: 2006-01-09
Last Update: 2006-01-11
Popularity: 5,729 views

Critical:
Less critical
Impact: Privilege escalation
DoS
Where: Local system
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.0
Debian GNU/Linux 3.1
Debian GNU/Linux unstable alias sid

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2006-0083


Description:
Debian has issued an update for smstools. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially to gain escalated privileges.

For more information:
SA18343

Solution:
Apply updated packages.

-- Debian GNU/Linux 3.0 alias woody --

Source archives:

http://security.debian.org/pool/updat...s/smstools/smstools_1.5.0-2woody0.dsc
Size/MD5 checksum: 595 3b125f8d494769561c579a2afb8eedf3
http://security.debian.org/pool/updat...stools/smstools_1.5.0-2woody0.diff.gz
Size/MD5 checksum: 7441 8fd87155404a99eb88ff06e5e7bccd4b
http://security.debian.org/pool/updat...s/smstools/smstools_1.5.0.orig.tar.gz
Size/MD5 checksum: 42987 0286109d2011a5b8ab2fbd2cda6085be

Alpha architecture:

http://security.debian.org/pool/updat...ools/smstools_1.5.0-2woody0_alpha.deb
Size/MD5 checksum: 56840 8d84dd61b7002fbb5f5ff1411345cdf6

ARM architecture:

http://security.debian.org/pool/updat...stools/smstools_1.5.0-2woody0_arm.deb
Size/MD5 checksum: 44604 af22b10857060a0fe0f1db651ea54689

Intel IA-32 architecture:

http://security.debian.org/pool/updat...tools/smstools_1.5.0-2woody0_i386.deb
Size/MD5 checksum: 43106 af2b3c3a8a18d71481fbadeef60846f8

Intel IA-64 architecture:

http://security.debian.org/pool/updat...tools/smstools_1.5.0-2woody0_ia64.deb
Size/MD5 checksum: 74424 96904451a1a06e22d4fcee797dc68450

HP Precision architecture:

http://security.debian.org/pool/updat...tools/smstools_1.5.0-2woody0_hppa.deb
Size/MD5 checksum: 44432 70d55071bbdf08f2d3265da85cb43458

Motorola 680x0 architecture:

http://security.debian.org/pool/updat...tools/smstools_1.5.0-2woody0_m68k.deb
Size/MD5 checksum: 41598 d25cce8dcfed54f7f9b62e7764775907

Big endian MIPS architecture:

http://security.debian.org/pool/updat...tools/smstools_1.5.0-2woody0_mips.deb
Size/MD5 checksum: 52646 2edd9efcca5f608c09d6903335d7dc14

Little endian MIPS architecture:

http://security.debian.org/pool/updat...ols/smstools_1.5.0-2woody0_mipsel.deb
Size/MD5 checksum: 52290 5f019a902c94b8d4c0a6b9781afa2664

PowerPC architecture:

http://security.debian.org/pool/updat...ls/smstools_1.5.0-2woody0_powerpc.deb
Size/MD5 checksum: 43316 df4f00d5ccc813274a3936455ff39b70

IBM S/390 architecture:

http://security.debian.org/pool/updat...tools/smstools_1.5.0-2woody0_s390.deb
Size/MD5 checksum: 43812 9e6f27fb09a8e1152db4238eb851b659

Sun Sparc architecture:

http://security.debian.org/pool/updat...ools/smstools_1.5.0-2woody0_sparc.deb
Size/MD5 checksum: 51388 d98ca0bc6bbeecb8d19e630528c6fd9f

-- Debian GNU/Linux 3.1 alias sarge --

Source archives:

http://security.debian.org/pool/updat...tools/smstools_1.14.8-1sarge0.diff.gz
Size/MD5 checksum: 5106 ef55852ce6da003ef5f45df6eed1a8c5
http://security.debian.org/pool/updat.../smstools/smstools_1.14.8-1sarge0.dsc
Size/MD5 checksum: 624 1e69b0c4a20ce7f08bce8a8b51b8504d
http://security.debian.org/pool/updat.../smstools/smstools_1.14.8.orig.tar.gz
Size/MD5 checksum: 158423 85b342e53d7fdde89ef25ad21e1c5fe0

Alpha architecture:

http://security.debian.org/pool/updat...ols/smstools_1.14.8-1sarge0_alpha.deb
Size/MD5 checksum: 184268 59ca41ecd61cc94de2b63c8698464732

AMD64 architecture:

http://security.debian.org/pool/updat...ols/smstools_1.14.8-1sarge0_amd64.deb
Size/MD5 checksum: 178130 f957b798e9de3075e013521bbf6241d6

ARM architecture:

http://security.debian.org/pool/updat...tools/smstools_1.14.8-1sarge0_arm.deb
Size/MD5 checksum: 173506 aa2b0df1d47ad50070aebacc266f729d

HP Precision architecture:

http://security.debian.org/pool/updat...ools/smstools_1.14.8-1sarge0_hppa.deb
Size/MD5 checksum: 180032 168dba93586bc10214fbb6a5914f962e

Intel IA-32 architecture:

http://security.debian.org/pool/updat...ools/smstools_1.14.8-1sarge0_i386.deb
Size/MD5 checksum: 166816 aee3afc84707f7190c255ed3739c2958

Intel IA-64 architecture:

http://security.debian.org/pool/updat...ools/smstools_1.14.8-1sarge0_ia64.deb
Size/MD5 checksum: 201440 9868ead0f8885bc3851137b23d76877d

Motorola 680x0 architecture:

http://security.debian.org/pool/updat...ools/smstools_1.14.8-1sarge0_m68k.deb
Size/MD5 checksum: 166452 d713ee667bee3c3186ba477f9d0f91a8

Big endian MIPS architecture:

http://security.debian.org/pool/updat...ools/smstools_1.14.8-1sarge0_mips.deb
Size/MD5 checksum: 182332 846d0a829680db2b3662982c9fe49d4f

Little endian MIPS architecture:

http://security.debian.org/pool/updat...ls/smstools_1.14.8-1sarge0_mipsel.deb
Size/MD5 checksum: 182004 db7200f1504ea22681e23e749435c22a

PowerPC architecture:

http://security.debian.org/pool/updat...s/smstools_1.14.8-1sarge0_powerpc.deb
Size/MD5 checksum: 172100 183e00f44548fce56df228441593bb90

IBM S/390 architecture:

http://security.debian.org/pool/updat...ools/smstools_1.14.8-1sarge0_s390.deb
Size/MD5 checksum: 179978 ab77f608c71a908bc51e7781b51c416d

Sun Sparc architecture:

http://security.debian.org/pool/updat...ols/smstools_1.14.8-1sarge0_sparc.deb
Size/MD5 checksum: 175994 a03ff752a8910e397e73f53649c5a931

-- Debian GNU/Linux unstable alias sid --

The vulnerability will reportedly be fixed soon.

Changelog:
2006-01-10: Updated "Original Advisory" section.
2006-01-11: Vendor released fixed packages for Debian 3.0.

Original Advisory:
http://www.debian.org/security/2006/dsa-930

Other References:
SA18343:
http://secunia.com/advisories/18343/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Drupal Project Module File Upload and Cross-Site Scripting // 47 views
2. Sun Java JDK / JRE Multiple Vulnerabilities // 40 views
3. Internet Explorer Data Binding Memory Corruption Vulnerability // 40 views
4. SmbFTPD Long Command Processing Vulnerability // 37 views
5. Drupal Project Issue Tracking Module Multiple Vulnerabilities // 30 views
6. Cisco Global Site Selector DNS Request Denial of Service // 27 views
7. NTP OpenSSL "EVP_VerifyFinal()" Spoofing Vulnerability // 26 views
8. Symantec Mail Security for SMTP Response Handling Denial of Service // 25 views
9. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 25 views
10. OpenSSL DSA / ECDSA "EVP_VerifyFinal()" Spoofing Vulnerability // 24 views