I created a new blog for technical/geeky/Debian stuff. I'm keeping my LiveJournal for social and private matters and syndicating this one to Planet Debian.
I hope this separation will make me less afraid of boring LiveJournal readers with technical minutiae and Debian politics or boring Planet Debian readers with local social stuff, so I actually write more. Don't get too hopeful though.
There is a potential buffer overflow in logging of CAPI messages in libcapi20 (part of isdnutils; bug 408530). The same broken code from libcapi20 is present in the Linux kernel (bug 411294). Also, the affected functions are not thread-safe and are unlikely to be made so without API changes; multithreaded programs calling them must use a mutex to avoid another security flaw; (such as asterisk-chan-capi; bug 411293).
I have prepared updates of asterisk-chan-capi and isdnutils for sarge and sid but I have no ISDN hardware to test them with. I would appreciate it if users of these packages would test the updates and report their results to the associated bugs.
The patches can be found attached to the bug reports. Updated packages are at:
deb http://womble.decadent.org.uk/debian/ distribution/ deb-src http://womble.decadent.org.uk/debian/ distribution/
(the repository is signed with my personal GPG key).
| S | M | T | W | T | F | S |
|---|---|---|---|---|---|---|
| 1 | 2 | 3 | 4 | 5 | ||
| 6 | 7 | 8 | 9 | 10 | 11 | 12 |
| 13 | 14 | 15 | 16 | 17 | 18 | 19 |
| 20 | 21 | 22 | 23 | 24 | 25 | 26 |
| 27 | 28 |