Updated Debian 6.0: 6.0.7 released

Francesca Ciceri <[email protected]> Sat, 23 Feb 2013 14:24:22 +0100
Newsgroups gmane.linux.debian.user.announce
Message-ID <[email protected]>
--BQPnanjtCNWHyqYD
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

------------------------------------------------------------------------
The Debian Project                                http://www.debian.org/
Updated Debian 6.0: 6.0.7 released                      [email protected]
February 23rd, 2013             http://www.debian.org/News/2013/20130223
------------------------------------------------------------------------


The Debian project is pleased to announce the seventh update of its
stable distribution Debian 6.0 (codename "squeeze"). This update mainly
adds corrections for security problems to the stable release, along with
a few adjustments for serious problems. Security advisories were already
published separately and are referenced where available.

Please note that this update does not constitute a new version of Debian
6.0 but only updates some of the packages included. There is no need to
throw away 6.0 CDs or DVDs but only to update via an up-to-date Debian
mirror after an installation, to cause any out of date packages to be
updated.

Those who frequently install updates from security.debian.org won't have
to update many packages and most updates from security.debian.org are
included in this update.

New installation media and CD and DVD images containing updated packages
will be available soon at the regular locations.

Upgrading to this revision online is usually done by pointing the
aptitude (or apt) package tool (see the sources.list(5) manual page) to
one of Debian's many FTP or HTTP mirrors. A comprehensive list of
mirrors is available at:

http://www.debian.org/mirror/list



Miscellaneous Bugfixes
----------------------

This stable update adds a few important corrections to the following
packages:

 Package                       Reason                              =20

 apt-show-versions             Fix detection of squeeze-updates and=20
                               squeeze; update official            =20
                               distribution list                   =20
                                                                   =20
 base-files=C2=A0                   Update for the point release        =20
                                                                   =20
 bcron=C2=A0                        Don't allow jobs access to other    =20
                               jobs' temporary files               =20
                                                                   =20
 bind9=C2=A0                        Update IP for  "D"  root server     =20
                                                                   =20
 bugzilla=C2=A0                     Add dependency on liburi-perl, used =20
                               during package configuration        =20
                                                                   =20
 choose-mirror=C2=A0                Update URL for master mirror list   =20
                                                                   =20
 clamav=C2=A0                       New upstream version                =20
                                                                   =20
 claws-mail=C2=A0                   Fix NULL pointer dereference        =20
                                                                   =20
 clive=C2=A0                        Adapt for youtube.com changes       =20
                                                                   =20
 cups=C2=A0                         Ship cups-files.conf's manpage      =20
                                                                   =20
 dbus=C2=A0                         Avoid code execution in setuid/     =20
                               setgid binaries                     =20
                                                                   =20
 dbus-glib=C2=A0                    Fix authentication bypass through   =20
                               insufficient checks (CVE-2013-0292) =20
                                                                   =20
 debian-installer=C2=A0             Rebuild for 6.0.7                   =20
                                                                   =20
 debian-installer-netboot-     Rebuild against debian-installer    =20
 images=C2=A0                       20110106+squeeze4+b3                =20
                                                                   =20
 dtach=C2=A0                        Properly handle close request       =20
                               (CVE-2012-3368)                     =20
                                                                   =20
 ettercap=C2=A0                     Fix hosts list parsing (CVE-2013-   =20
                               0722)                               =20
                                                                   =20
 fglrx-driver=C2=A0                 Fix diversion-related issues with   =20
                               upgrades from lenny                 =20
                                                                   =20
 flashplugin-nonfree=C2=A0          Use gpg --verify                    =20
                                                                   =20
 fusionforge=C2=A0                  Lenny to squeeze upgrade fix        =20
                                                                   =20
 gmime2.2=C2=A0                     Add Conflicts: libgmime2.2-cil to   =20
                               fix upgrades from lenny             =20
                                                                   =20
 gzip=C2=A0                         Avoid using memcpy on overlapping   =20
                               regions                             =20
                                                                   =20
 ia32-libs=C2=A0                    Update included packages from       =20
                               stable / security.d.o               =20
                                                                   =20
 ia32-libs-core=C2=A0               Update included packages from       =20
                               stable / security.d.o               =20
                                                                   =20
 kfreebsd-8=C2=A0                   Fix CVE-2012-4576: memory access    =20
                               without proper validation in linux  =20
                               compat system                       =20
                                                                   =20
 libbusiness-onlinepayment-    Backport changes to IPPay gateway's =20
 ippay-perl=C2=A0                   server name and path                =20
                                                                   =20
 libproc-processtable-         Fix unsafe temporary file usage     =20
 perl=C2=A0                         (CVE-2011-4363)                     =20
                                                                   =20
 libzorpll=C2=A0                    Add missing Breaks/Replaces:        =20
                               libzorp2-dev to libzorpll-dev       =20
                                                                   =20
 linux-2.6=C2=A0                    Update to stable release 2.6.32.60. =20
                               Backport hpsa, isci and megaraid_sas=20
                               driver updates. Fix r8169 hangs     =20
                                                                   =20
 linux-kernel-di-amd64-        Rebuild against linux-2.6 2.6.32-48 =20
 2.6=C2=A0                                                              =20
                                                                   =20
 linux-kernel-di-              Rebuild against linux-2.6 2.6.32-48 =20
 armel-2.6=C2=A0                                                        =20
                                                                   =20
 linux-kernel-di-i386-         Rebuild against linux-2.6 2.6.32-48 =20
 2.6=C2=A0                                                              =20
                                                                   =20
 linux-kernel-di-ia64-         Rebuild against linux-2.6 2.6.32-48 =20
 2.6=C2=A0                                                          =20
                                                                   =20
 linux-kernel-di-              Rebuild against linux-2.6 2.6.32-48 =20
 mips-2.6=C2=A0                                                     =20
                                                                   =20
 linux-kernel-di-              Rebuild against linux-2.6 2.6.32-48 =20
 mipsel-2.6=C2=A0                                                   =20
                                                                   =20
 linux-kernel-di-              Rebuild against linux-2.6 2.6.32-48 =20
 powerpc-2.6=C2=A0                                                  =20
                                                                   =20
 linux-kernel-di-s390-         Rebuild against linux-2.6 2.6.32-48 =20
 2.6=C2=A0                                                          =20
                                                                   =20
 linux-kernel-di-              Rebuild against linux-2.6 2.6.32-48 =20
 sparc-2.6=C2=A0                                                    =20
                                                                   =20
 magpierss=C2=A0                    Fix upgrade issue                   =20
                                                                   =20
 maradns=C2=A0                      Fix CVE-2012-1570 (deleted domain   =20
                               record cache persistence flaw)      =20
                                                                   =20
 mediawiki=C2=A0                    Prevent session fixation in         =20
                               Special:UserLogin (CVE-2012-5391);  =20
                               prevent linker regex from exceeding =20
                               backtrack limit                     =20
                                                                   =20
 moodle=C2=A0                       Multiple security fixes             =20
                                                                   =20
 nautilus=C2=A0                     Add Breaks: samba-common (<< 2:3.5) =20
                               to fix a lenny to squeeze upgrade   =20
                               issue                               =20
                                                                   =20
 openldap=C2=A0                     Dump the database in prerm on       =20
                               upgrades to help upgrades to        =20
                               releases with newer libdb versions  =20
                                                                   =20
 openssh=C2=A0                      Improve DoS resistance (CVE-2010-   =20
                               5107)                               =20
                                                                   =20
 pam-pgsql=C2=A0                    Fix issue with NULL passwords       =20
                                                                   =20
 pam-shield=C2=A0                   Correctly block IPs when            =20
                               allow_missing_dns is  "no"          =20
                                                                   =20
 perl=C2=A0                         Fix misparsing of maketext strings  =20
                               (CVE-2012-6329)                     =20
                                                                   =20
 poppler=C2=A0                      Security fixes; CVE-2010-0206,      =20
                               CVE-2010-0207, CVE-2012-4653; fix   =20
                               GooString::insert, correctly        =20
                               initialise variables                =20
                                                                   =20
 portmidi=C2=A0                     Fix crash                           =20
                                                                   =20
 postgresql-8.4=C2=A0               New upstream micro-release          =20
                                                                   =20
 sdic=C2=A0                         Move bzip2 from Suggests to Depends =20
                               as it is used during installation   =20
                                                                   =20
 snack=C2=A0                        Fix buffer overflow (CVE-2012-6303) =20
                                                                   =20
 sphinx=C2=A0                       Fix incompatibility with jQuery>=3D   =
=20
                               1.4                                 =20
                                                                   =20
 swath=C2=A0                        Fix potential buffer overflow in    =20
                               Mule mode                           =20
                                                                   =20
 swi-prolog=C2=A0                   Fix buffer overruns                 =20
                                                                   =20
 ttf-ipafont=C2=A0                  Fix removal of alternatives         =20
                                                                   =20
 tzdata=C2=A0                       New upstream version; fix DST for   =20
                               America/Bahia (Brazil)              =20
                                                                   =20
 unbound=C2=A0                      Update IP address hints for D.ROOT- =20
                               SERVERS.NET                         =20
                                                                   =20
 xen=C2=A0                          Fix clock breakage                  =20
                                                                   =20
 xnecview=C2=A0                     Fix FTBFS on armel                  =20
                                                                   =20


   =20
Security Updates
----------------

This revision adds the following security updates to the stable release.
The Security Team has already released an advisory for each of these
updates:


 Advisory ID     Package         Correction(s)            =20
=20
 DSA-2550=C2=A0   asterisk=C2=A0           Multiple issues          =20
                                                                  =20
 DSA-2551=C2=A0   isc-dhcp=C2=A0           Denial of service        =20
                                                                  =20
 DSA-2552=C2=A0   tiff=C2=A0               Multiple issues          =20
                                                                  =20
 DSA-2553=C2=A0   iceweasel=C2=A0          Multiple issues          =20
                                                                  =20
 DSA-2554=C2=A0   iceape=C2=A0             Multiple issues          =20
                                                                  =20
 DSA-2555=C2=A0   libxslt=C2=A0            Multiple issues          =20
                                                                  =20
 DSA-2556=C2=A0   icedove=C2=A0            Multiple issues          =20
                                                                  =20
 DSA-2557=C2=A0   hostapd=C2=A0            Denial of service        =20
                                                                  =20
 DSA-2558=C2=A0   bacula=C2=A0             Information disclosure   =20
                                                                  =20
 DSA-2559=C2=A0   libexif=C2=A0            Multiple issues          =20
                                                                  =20
 DSA-2560=C2=A0   bind9=C2=A0              Denial of service        =20
                                                                  =20
 DSA-2561=C2=A0   tiff=C2=A0               Buffer overflow          =20
                                                                  =20
 DSA-2562=C2=A0   cups-pk-helper=C2=A0     Privilege escalation     =20
                                                                  =20
 DSA-2563=C2=A0   viewvc=C2=A0             Multiple issues          =20
                                                                  =20
 DSA-2564=C2=A0   tinyproxy=C2=A0          Denial of service        =20
                                                                  =20
 DSA-2565=C2=A0   iceweasel=C2=A0          Multiple issues          =20
                                                                  =20
 DSA-2566=C2=A0   exim4=C2=A0              Heap overflow            =20
                                                                  =20
 DSA-2567=C2=A0   request-tracker3.8  Multiple issues          =20
                                                                  =20
 DSA-2568=C2=A0   rtfm=C2=A0               Privilege escalation     =20
                                                                  =20
 DSA-2569=C2=A0   icedove=C2=A0            Multiple issues          =20
                                                                  =20
 DSA-2570=C2=A0  openoffice.org=C2=A0      Multiple issues          =20
                                                                  =20
 DSA-2571=C2=A0  libproxy=C2=A0            Buffer overflow          =20
                                                                  =20
 DSA-2572=C2=A0  iceape=C2=A0              Multiple issues          =20
                                                                  =20
 DSA-2573=C2=A0  radsecproxy=C2=A0         SSL certificate          =20
                                 verification weakness    =20
                                                                  =20
 DSA-2574=C2=A0  typo3-src=C2=A0           Multiple issues          =20
                                                                  =20
 DSA-2575=C2=A0  tiff=C2=A0                Heap overflow            =20
                                                                  =20
 DSA-2576=C2=A0  trousers=C2=A0            Denial of service        =20
                                                                  =20
 DSA-2577=C2=A0  libssh=C2=A0              Multiple issues          =20
                                                                  =20
 DSA-2578=C2=A0  rssh=C2=A0                Multiple issues          =20
                                                                  =20
 DSA-2579=C2=A0  apache2=C2=A0             Multiple issues          =20
                                                                  =20
 DSA-2580=C2=A0  libxml2=C2=A0             Buffer overflow          =20
                                                                  =20
 DSA-2582=C2=A0  xen=C2=A0                 Denial of service        =20
                                                                  =20
 DSA-2583=C2=A0  iceweasel=C2=A0           Multiple issues          =20
                                                                  =20
 DSA-2584=C2=A0  iceape=C2=A0              Multiple issues          =20
                                                                  =20
 DSA-2585=C2=A0  bogofilter=C2=A0          Heap-based buffer        =20
                                 overflow                 =20
                                                                  =20
 DSA-2586=C2=A0  perl=C2=A0                Multiple issues          =20
                                                                  =20
 DSA-2587=C2=A0  libcgi-pm-perl=C2=A0      HTTP header injection    =20
                                                                  =20
 DSA-2588=C2=A0  icedove=C2=A0             Multiple issues          =20
                                                                  =20
 DSA-2589=C2=A0  tiff=C2=A0                Buffer overflow          =20
                                                                  =20
 DSA-2590=C2=A0  wireshark=C2=A0           Multiple issues          =20
                                                                  =20
 DSA-2591=C2=A0  mahara=C2=A0              Multiple issues          =20
                                                                  =20
 DSA-2592=C2=A0  elinks=C2=A0              Programming error        =20
                                                                  =20
 DSA-2593=C2=A0  moin=C2=A0                Multiple issues          =20
                                                                  =20
 DSA-2594=C2=A0  virtualbox-ose=C2=A0      Programming error        =20
                                                                  =20
 DSA-2595=C2=A0  ghostscript=C2=A0         Buffer overflow          =20
                                                                  =20
 DSA-2596=C2=A0  mediawiki-           Cross-site scripting in  =20
                 extensions=C2=A0     RSSReader extension      =20
                                                                  =20
 DSA-2597=C2=A0  rails=C2=A0               Input validation error   =20
                                                                  =20
 DSA-2598=C2=A0  weechat=C2=A0             Multiple issues          =20
                                                                  =20
 DSA-2599=C2=A0  nss=C2=A0                 Mis-issued intermediates =20
                                                                  =20
 DSA-2600=C2=A0  cups=C2=A0                Privilege escalation     =20
                                                                  =20
 DSA-2601=C2=A0  gnupg2=C2=A0              Missing input sanitation =20
                                                                  =20
 DSA-2601=C2=A0  gnupg=C2=A0               Missing input sanitation =20
                                                                  =20
 DSA-2602=C2=A0  zendframework=C2=A0       XML external entity      =20
                                 inclusion                =20
                                                                  =20
 DSA-2603=C2=A0  emacs23=C2=A0             Programming error        =20
                                                                  =20
 DSA-2604=C2=A0  rails=C2=A0               Insufficient input       =20
                                 validation               =20
                                                                  =20
 DSA-2605=C2=A0  asterisk=C2=A0            Multiple issues          =20
                                                                  =20
 DSA-2606=C2=A0  proftpd-dfsg=C2=A0        Symlink race             =20
                                                                  =20
 DSA-2607=C2=A0  qemu-kvm=C2=A0            Buffer overflow          =20
                                                                  =20
 DSA-2608=C2=A0  qemu=C2=A0                Buffer overflow          =20
                                                                  =20
 DSA-2609=C2=A0  rails=C2=A0               SQL query manipulation   =20
                                                                  =20
 DSA-2610=C2=A0  ganglia=C2=A0             Remote code execution    =20
                                                                  =20
 DSA-2611=C2=A0  movabletype-         Multiple issues          =20
                 opensource=C2=A0                                 =20
                                                                  =20
 DSA-2612=C2=A0  ircd-ratbox=C2=A0         Remote crash             =20
                                                                  =20
 DSA-2613=C2=A0  rails=C2=A0               Insufficient input       =20
                                 validation               =20
                                                                  =20
 DSA-2614=C2=A0  libupnp=C2=A0             Multiple issues          =20
                                                                  =20
 DSA-2615=C2=A0  libupnp4=C2=A0            Multiple issues          =20
                                                                  =20
 DSA-2616=C2=A0  nagios3=C2=A0             Buffer overflow          =20
                                 vulnerability            =20
                                                                  =20
 DSA-2617=C2=A0  samba=C2=A0               Multiple issues          =20
                                                                  =20
 DSA-2618=C2=A0  ircd-hybrid=C2=A0         Denial of service        =20
                                                                  =20
 DSA-2619=C2=A0  xen-qemu-dm-4.0=C2=A0     Buffer overflow          =20
                                                                  =20
 DSA-2620=C2=A0  rails=C2=A0               Multiple issues          =20
                                                                  =20
 DSA-2621=C2=A0  openssl=C2=A0             Multiple issues          =20
                                                                  =20
 DSA-2622=C2=A0  polarssl=C2=A0            Multiple issues          =20
                                                                  =20
 DSA-2623=C2=A0  openconnect=C2=A0         Buffer overflow          =20
                                                                  =20
 DSA-2624=C2=A0  ffmpeg=C2=A0              Multiple issues          =20
                                                                  =20
 DSA-2625=C2=A0  wireshark=C2=A0           Multiple issues          =20
                                                                  =20
 DSA-2626=C2=A0  lighttpd=C2=A0            Multiple issues          =20
                                                                  =20
 DSA-2627=C2=A0  nginx=C2=A0               Information leak         =20
                                                                  =20

Debian Installer
----------------

The installer has been rebuilt to include the fixes incorporated into
stable by the point release.

Removed packages
----------------

The following packages were removed due to circumstances beyond our
control:

 Package         Reason                          =20

 elmerfem=C2=A0  	License problems (GPL + non-GPL)=20
                                                 =20

URLs
----

The complete lists of packages that have changed with this revision:

http://ftp.debian.org/debian/dists/squeeze/ChangeLog


The current stable distribution:

http://ftp.debian.org/debian/dists/stable/


Proposed updates to the stable distribution:

http://ftp.debian.org/debian/dists/proposed-updates/


stable distribution information (release notes, errata etc.):

http://www.debian.org/releases/stable/


Security announcements and information:

http://security.debian.org/=C2=A0


About Debian
------------

The Debian Project is an association of Free Software developers who
volunteer their time and effort in order to produce the completely free
operating system Debian.


Contact Information
-------------------

For further information, please visit the Debian web pages at
http://www.debian.org/, send mail to <[email protected]>, or contact the
stable release team at <[email protected]>.

--BQPnanjtCNWHyqYD
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBAgAGBQJRKMMGAAoJENtobJLZ1Z9hdEoQANux5NHk8QeM4Q1/YvhjQnn+
tTzwgcYG9v1Nqn0iAl92J8nF1Fn6FIMJrVh58uceC26E6ByEvlOkoQPi0Ox+l38W
7GTb5CTDq9ft3/gH5IWd68cVhqKioUMb5LqfAvlz0/kXB5lA8HMYBaLuFdy+8aar
F/f1rJHyzT4JWSODULeaGBH0GJDIRLkpO7AB4+tbxJgMPaAd+EUTHNbA4lhN5HTq
vc5NbpjROLglrmTlXIKsQ8/fY+JNh5sbkIQtW7SdfpDHDLolAY5bdh3mfJswt03+
gLtXWjV++KGIvvoPN+4Tz4L1b00p66/HNFEdvw6BsrQFWEcniP+b8jS+HlQnmtP/
wFXo6PZTWC1xyZE33gbCE7VkVepFygIuXOh0Wtp/jyBQIsPY+ZEIIYCl5IMqbjtu
21JXP5Cb6967Myn2ghKFqtGFKNIBFjSKXSoj4h9NKKTp6qjkHpMuLm/mQHiF797U
QnpkeK+O/niV4Rfyh5GbfXXyi6dFRI9br2MKPWbbfoUXIMdjmvCs8AvmtgmFs1oY
UO+2Om89hwDVDYjCJbvUY0bKaQCdz08GUuWJnE4mT9Gc+XrMCGkgY667nz/LLWeO
Apf8XAzuj5FWx+WW9fAe8u3Q+9kdsiewTASOO1EJAz7XxeQRMW3KKKVTsR90ouxm
+FYrcTfTv2ywQud3CGzh
=3El7
-----END PGP SIGNATURE-----

--BQPnanjtCNWHyqYD--