int(2682)

Boletines de Vulnerabilidades


Directorio transversal en FastJar

Clasificación de la vulnerabilidad

Propiedad Valor
Nivel de Confianza Oficial
Impacto Integridad
Dificultad Experto
Requerimientos del atacante Acceso remoto sin cuenta a un servicio exotico

Información sobre el sistema

Propiedad Valor
Fabricante afectado GNU/Linux
Software afectado FastJar 0.93

Descripción

Se ha descubierto una vulnerabilidad de tipo directorio transversal en FastJar versión 0.93, usado por Gnu GCC 4.1.1 y anteriores, y 3.4.6 y anteriores. La vulnerabilidad reside en un error al manejar ficheros ".jar".

Un atacante remoto podría sobrescribir ficheros arbitrarios mediante un fichero ".jar" que contenga nombres de ficheros con secuencias "../".

Solución



Actualización de software

Debian

Debian Linux 3.1
Source
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3-13sarge1.dsc
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3-13sarge1.diff.gz
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3.orig.tar.gz
Architecture independent
http://security.debian.org/pool/updates/main/g/gcc-3.4/cpp-3.4-doc_3.4.3-13sarge1_all.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g77-3.4-doc_3.4.3-13sarge1_all.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4-doc_3.4.3-13sarge1_all.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gnat-3.4-doc_3.4.3-13sarge1_all.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gpc-2.1-3.4-doc_3.4.3-13sarge1_all.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-common_3.4.3-13sarge1_all.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-doc_3.4.3-13sarge1_all.deb
Alpha
http://security.debian.org/pool/updates/main/g/gcc-3.4/cpp-3.4_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/fastjar_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g++-3.4_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g77-3.4_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4-base_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcj-3.4_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gij-3.4_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gnat-3.4_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gobjc-3.4_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gpc-2.1-3.4_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3-dev_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcc1_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-awt_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-dev_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dbg_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dev_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-pic_3.4.3-13sarge1_alpha.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/treelang-3.4_3.4.3-13sarge1_alpha.deb
AMD64
http://security.debian.org/pool/updates/main/g/gcc-3.4/cpp-3.4_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/fastjar_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g++-3.4_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g77-3.4_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4-base_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcj-3.4_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gij-3.4_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gnat-3.4_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gobjc-3.4_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gpc-2.1-3.4_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/lib32gcc1_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/lib32stdc++6_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3-dev_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcc1_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-awt_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-dev_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgnat-3.4_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dbg_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dev_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-pic_3.4.3-13sarge1_amd64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/treelang-3.4_3.4.3-13sarge1_amd64.deb
ARM
http://security.debian.org/pool/updates/main/g/gcc-3.4/cpp-3.4_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/fastjar_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g++-3.4_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g77-3.4_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4-base_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcj-3.4_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gij-3.4_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gobjc-3.4_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gpc-2.1-3.4_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3-dev_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcc1_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-awt_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-dev_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-0_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-0-dbg_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-0-dev_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-0-pic_3.4.3-13sarge1_arm.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/treelang-3.4_3.4.3-13sarge1_arm.deb
HP Precision
http://security.debian.org/pool/updates/main/g/gcc-3.4/cpp-3.4_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/fastjar_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g++-3.4_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g77-3.4_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4-base_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4-hppa64_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcj-3.4_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gij-3.4_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gnat-3.4_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gobjc-3.4_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gpc-2.1-3.4_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3-dev_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcc2_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-awt_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-dev_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgnat-3.4_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dbg_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dev_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-pic_3.4.3-13sarge1_hppa.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/treelang-3.4_3.4.3-13sarge1_hppa.deb
Intel IA-32
http://security.debian.org/pool/updates/main/g/gcc-3.4/cpp-3.4_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/fastjar_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g++-3.4_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g77-3.4_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4-base_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcj-3.4_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gij-3.4_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gnat-3.4_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gobjc-3.4_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gpc-2.1-3.4_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/lib64gcc1_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/lib64stdc++6_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3-dev_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcc1_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-awt_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-dev_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgnat-3.4_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dbg_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dev_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-pic_3.4.3-13sarge1_i386.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/treelang-3.4_3.4.3-13sarge1_i386.deb
Intel IA-64
http://security.debian.org/pool/updates/main/g/gcc-3.4/cpp-3.4_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/fastjar_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g++-3.4_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g77-3.4_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4-base_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcj-3.4_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gij-3.4_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gnat-3.4_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gobjc-3.4_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gpc-2.1-3.4_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3-dev_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcc1_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-awt_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-dev_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgnat-3.4_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dbg_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dev_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-pic_3.4.3-13sarge1_ia64.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/treelang-3.4_3.4.3-13sarge1_ia64.deb
Motorola 680x0
http://security.debian.org/pool/updates/main/g/gcc-3.4/cpp-3.4_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/fastjar_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g++-3.4_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g77-3.4_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4-base_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcj-3.4_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gij-3.4_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gobjc-3.4_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gpc-2.1-3.4_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3-dev_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcc2_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-awt_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-dev_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dbg_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dev_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-pic_3.4.3-13sarge1_m68k.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/treelang-3.4_3.4.3-13sarge1_m68k.deb
Big endian MIPS
http://security.debian.org/pool/updates/main/g/gcc-3.4/cpp-3.4_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/fastjar_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g++-3.4_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g77-3.4_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4-base_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gnat-3.4_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gobjc-3.4_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gpc-2.1-3.4_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3-dev_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcc1_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dbg_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dev_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-pic_3.4.3-13sarge1_mips.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/treelang-3.4_3.4.3-13sarge1_mips.deb
Little endian MIPS
http://security.debian.org/pool/updates/main/g/gcc-3.4/cpp-3.4_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/fastjar_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g++-3.4_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g77-3.4_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4-base_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gnat-3.4_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gobjc-3.4_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gpc-2.1-3.4_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3-dev_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcc1_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dbg_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dev_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-pic_3.4.3-13sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/treelang-3.4_3.4.3-13sarge1_mipsel.deb
PowerPC
http://security.debian.org/pool/updates/main/g/gcc-3.4/cpp-3.4_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/fastjar_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g++-3.4_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g77-3.4_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4-base_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcj-3.4_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gij-3.4_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gnat-3.4_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gobjc-3.4_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gpc-2.1-3.4_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3-dev_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcc1_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-awt_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-dev_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dbg_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dev_3.4.3-13sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-pic_3.4.3-13sarge1_powerpc.deb
IBM S/390
http://security.debian.org/pool/updates/main/g/gcc-3.4/cpp-3.4_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/fastjar_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g++-3.4_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g77-3.4_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4-base_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcj-3.4_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gij-3.4_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gnat-3.4_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gobjc-3.4_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gpc-2.1-3.4_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/lib64gcc1_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/lib64stdc++6_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3-dev_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcc1_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-awt_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-dev_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dbg_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dev_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-pic_3.4.3-13sarge1_s390.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/treelang-3.4_3.4.3-13sarge1_s390.deb
Sun Sparc
http://security.debian.org/pool/updates/main/g/gcc-3.4/cpp-3.4_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/fastjar_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g++-3.4_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/g77-3.4_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcc-3.4-base_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gcj-3.4_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gij-3.4_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gnat-3.4_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gobjc-3.4_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/gpc-2.1-3.4_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/lib64gcc1_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/lib64stdc++6_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libffi3-dev_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcc1_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-awt_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libgcj5-dev_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dbg_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-dev_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/libstdc++6-pic_3.4.3-13sarge1_sparc.deb
http://security.debian.org/pool/updates/main/g/gcc-3.4/treelang-3.4_3.4.3-13sarge1_sparc.deb

Red Hat (RHSA-2007:0473-2)
Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
https://rhn.redhat.com/

SGI
Advanced Linux Environment 3 / RPM / Patch 10421
ftp://oss.sgi.com/projects/sgi_propack/download/3/updates/RPMS
Advanced Linux Environment 3 / SRPM / Patch 10421
ftp://oss.sgi.com/projects/sgi_propack/download/3/updates/SRPMS

VMware (VMSA-2007-0006)
VMware Workstation 6.0.1
VMware Workstation 5.5.5
http://www.vmware.com/download/ws/
http://www.vmware.com/download/ws/ws5.html
VMware Player 2.0.1
VMware Player 1.0.5
http://www.vmware.com/download/server/
VMware Server 1.0.4
http://www.vmware.com/download/server/
VMware ACE 2.0.1
VMware ACE 1.0.4
http://www.vmware.com/download/ace/
VMware ESX 3.0.2 / patches ESX-1001725 ESX-1001731 ESX-1001726 ESX-1001727 ESX-1001728 ESX-1001729 ESX-1001730
VMware ESX 3.0.1 / patches ESX-8258730 ESX-1001213 ESX-1001691 ESX-1001723 ESX-1001214 ESX-1001692 ESX-1001693 ESX-1001694 ESX-8253547 ESX-8567382
VMware ESX 3.0.0 / patches ESX-4809553 ESX-1001204 ESX-1001206 ESX-1001212 ESX-1001205 ESX-1001207 ESX-1001208 ESX-1001209 ESX-1001210 ESX-1001211
VMware ESX 2.5.4 / patch 10
http://www.vmware.com/support/esx25/doc/esx-254-200708-patch.html
VMware ESX 2.5.3 / patch 13
http://www.vmware.com/support/esx25/doc/esx-253-200708-patch.html
VMware ESX 2.1.3 / patch 8
http://www.vmware.com/support/esx21/doc/esx-213-200708-patch.html
VMware ESX 2.0.2 / patch 8
http://www.vmware.com/support/esx2/doc/esx-202-200708-patch.html

Identificadores estándar

Propiedad Valor
CVE CVE-2006-3619
BID 15669

Recursos adicionales

Debian Security Advisory (DSA 1170-1)
http://lists.debian.org/debian-security-announce/debian-security-announce-2006/msg00260.html

Red Hat Security Advisory (RHSA-2007:0473-2)
https://rhn.redhat.com/errata/RHSA-2007-0473.html

SGI Security Advisory (20070602-01-P)
ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc

VMware security advisory (VMSA-2007-0006)
http://archives.neohapsis.com/archives/fulldisclosure/2007-09/0356.html

Histórico de versiones

Versión Comentario Fecha
1.0 Aviso emitido 2006-09-07
1.1 Aviso emitido por Red Hat (RHSA-2007:0473-2) 2007-06-12
1.2 Aviso emitido por SGI (20070602-01-P) 2007-06-29
1.3 Aviso emitido por VMware (VMSA-2007-0006) 2007-09-25

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT