-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

            ESB-2004.0514 -- Debian Security Advisory DSA 537-1
           New Ruby packages fix insecure CGI session management
                              17 August 2004

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:                ruby
Publisher:              Debian
Operating System:       Debian GNU/Linux 3.0
                        Linux variants
Impact:                 Access Confidential Data
CVE Names:              CAN-2004-0755

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - --------------------------------------------------------------------------
Debian Security Advisory DSA 537-1                     security@debian.org
http://www.debian.org/security/                             Martin Schulze
August 16th, 2004                       http://www.debian.org/security/faq
- - --------------------------------------------------------------------------

Package        : ruby
Vulnerability  : insecure file permissions
Problem-Type   : local
Debian-specific: no
CVE ID         : CAN-2004-0755
Debian Bug     : 260779

Andres Salomon no ticed a problem in the CGI session management of
Ruby, an object-oriented scripting language.  CGI::Session's FileStore
(and presumably PStore, but not in Debian woody) implementations store
session information insecurely.  They simply create files, ignoring
permission issues.  This can lead an attacker who has also shell
access to the webserver to take over a session.

For the stable distribution (woody) this problem has been fixed in
version 1.6.7-3woody3.

For the unstable and testing distributions (sarge and sid) this
problem has been fixed in version 1.8.1+1.8.2pre1-4.

We recommend that you upgrade your libruby package.


Upgrade Instructions
- - --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody
- - --------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/r/ruby/ruby_1.6.7-3woody3.dsc
      Size/MD5 checksum:      909 42ca59c34d2cc849dfc30ba472f7f116
    http://security.debian.org/pool/updates/main/r/ruby/ruby_1.6.7-3woody3.diff.gz
      Size/MD5 checksum:    43087 3a0e24b55c7456379ba74851c41ddcf6
    http://security.debian.org/pool/updates/main/r/ruby/ruby_1.6.7.orig.tar.gz
      Size/MD5 checksum:   996835 a8859c679ee9acbfdf5056cdf26fcad3

  Architecture independent components:

    http://security.debian.org/pool/updates/main/r/ruby/irb_1.6.7-3woody3_all.deb
      Size/MD5 checksum:    51094 5005ad418261ec712d19d4ca56367bed
    http://security.debian.org/pool/updates/main/r/ruby/ruby-elisp_1.6.7-3woody3_all.deb
      Size/MD5 checksum:    30158 2d205cd7e31956b474030ce54bcda454
    http://security.debian.org/pool/updates/main/r/ruby/ruby-examples_1.6.7-3woody3_all.deb
      Size/MD5 checksum:    37748 ea0251a91042ed3b93f606518b75c786

  Alpha architecture:

    http://security.debian.org/pool/updates/main/r/ruby/libcurses-ruby_1.6.7-3woody3_alpha.deb
      Size/MD5 checksum:   129428 3ec30ca16953da2763d04511c717d945
    http://security.debian.org/pool/updates/main/r/ruby/libdbm-ruby_1.6.7-3woody3_alpha.deb
      Size/MD5 checksum:   128344 0af6a10407582b9818612c4495ca518b
    http://security.debian.org/pool/updates/main/r/ruby/libgdbm-ruby_1.6.7-3woody3_alpha.deb
      Size/MD5 checksum:   129688 690b91f05a43a0984002751cf950f19f
    http://security.debian.org/pool/updates/main/r/ruby/libnkf-ruby_1.6.7-3woody3_alpha.deb
      Size/MD5 checksum:   135336 bb4b3de1453c6f58f2ed3099ffef1c7d
    http://security.debian.org/pool/updates/main/r/ruby/libpty-ruby_1.6.7-3woody3_alpha.deb
      Size/MD5 checksum:   132566 31c934c152702a4e1578a30a4acc3f4c
    http://security.debian.org/pool/updates/main/r/ruby/libreadline-ruby_1.6.7-3woody3_alpha.deb
      Size/MD5 checksum:   128284 73e5eb41e96be599bae70588f4e4fffc
    http://security.debian.org/pool/updates/main/r/ruby/libruby_1.6.7-3woody3_alpha.deb
      Size/MD5 checksum:   648420 971c038b44db8e5f6aded126c579b8bf
    http://security.debian.org/pool/updates/main/r/ruby/libsdbm-ruby_1.6.7-3woody3_alpha.deb
      Size/MD5 checksum:   132208 d0eee6f08dc2402bd789e02897f1a39c
    http://security.debian.org/pool/updates/main/r/ruby/libsyslog-ruby_1.6.7-3woody3_alpha.deb
      Size/MD5 checksum:   129086 59bd5e286b27d597e3577ecc01571de8
    http://security.debian.org/pool/updates/main/r/ruby/libtcltk-ruby_1.6.7-3woody3_alpha.deb
      Size/MD5 checksum:   146886 19edd9ef017acce324eaf5644aff7dca
    http://security.debian.org/pool/updates/main/r/ruby/libtk-ruby_1.6.7-3woody3_alpha.deb
      Size/MD5 checksum:   162686 cc53b5bcc2fc25b49e7079ebd799db8b
    http://security.debian.org/pool/updates/main/r/ruby/ruby_1.6.7-3woody3_alpha.deb
      Size/MD5 checksum:   144072 8e56491cbc6b5c66453a00f827276280
    http://security.debian.org/pool/updates/main/r/ruby/ruby-dev_1.6.7-3woody3_alpha.deb
      Size/MD5 checksum:   625932 dc6c60f17084fdd0ad07d48e9cafeff3

  ARM architecture:

    http://security.debian.org/pool/updates/main/r/ruby/libcurses-ruby_1.6.7-3woody3_arm.deb
      Size/MD5 checksum:   128308 c79f0e8abdc5a34b9582d59b986ab5be
    http://security.debian.org/pool/updates/main/r/ruby/libdbm-ruby_1.6.7-3woody3_arm.deb
      Size/MD5 checksum:   127186 416b7a94fcdfcc3a59a2327107940e4c
    http://security.debian.org/pool/updates/main/r/ruby/libgdbm-ruby_1.6.7-3woody3_arm.deb
      Size/MD5 checksum:   128156 65f56dd2918b860e04fe1eb99db8db5d
    http://security.debian.org/pool/updates/main/r/ruby/libnkf-ruby_1.6.7-3woody3_arm.deb
      Size/MD5 checksum:   134318 c1869b828d5f3a6d1046505b437991b3
    http://security.debian.org/pool/updates/main/r/ruby/libpty-ruby_1.6.7-3woody3_arm.deb
      Size/MD5 checksum:   131060 0c26c9e5c66e0ada36f9cee2d6f04569
    http://security.debian.org/pool/updates/main/r/ruby/libreadline-ruby_1.6.7-3woody3_arm.deb
      Size/MD5 checksum:   127204 0db378fead41a8e7f64e766ef4a545ef
    http://security.debian.org/pool/updates/main/r/ruby/libruby_1.6.7-3woody3_arm.deb
      Size/MD5 checksum:   602496 4394a092060e68bc1d34736f264f9e27
    http://security.debian.org/pool/updates/main/r/ruby/libsdbm-ruby_1.6.7-3woody3_arm.deb
      Size/MD5 checksum:   130326 78d57ddc347234cc0496e6eec12a430b
    http://security.debian.org/pool/updates/main/r/ruby/libsyslog-ruby_1.6.7-3woody3_arm.deb
      Size/MD5 checksum:   128030 9d7a4feebef499766224a56d5b02afcf
    http://security.debian.org/pool/updates/main/r/ruby/libtcltk-ruby_1.6.7-3woody3_arm.deb
      Size/MD5 checksum:   146566 063abfcaf36bef42f926b04b0b4d8c3d
    http://security.debian.org/pool/updates/main/r/ruby/libtk-ruby_1.6.7-3woody3_arm.deb
      Size/MD5 checksum:   161120 d627766263ef715f8e643ca76065c2eb
    http://security.debian.org/pool/updates/main/r/ruby/ruby_1.6.7-3woody3_arm.deb
      Size/MD5 checksum:   142138 aae80e5b907df2f7638397ceb41e2ece
    http://security.debian.org/pool/updates/main/r/ruby/ruby-dev_1.6.7-3woody3_arm.deb
      Size/MD5 checksum:   572424 a7cef1fe976dabdb8cc45c1742099388

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/r/ruby/libcurses-ruby_1.6.7-3woody3_i386.deb
      Size/MD5 checksum:   127790 e1205c5e304db4f4da1b72cfba06a201
    http://security.debian.org/pool/updates/main/r/ruby/libdbm-ruby_1.6.7-3woody3_i386.deb
      Size/MD5 checksum:   127004 f18b4ca42b5ed6ed660d0b1f16f94d23
    http://security.debian.org/pool/updates/main/r/ruby/libgdbm-ruby_1.6.7-3woody3_i386.deb
      Size/MD5 checksum:   127794 c16d67ffb44d890b1c6695325a40db88
    http://security.debian.org/pool/updates/main/r/ruby/libnkf-ruby_1.6.7-3woody3_i386.deb
      Size/MD5 checksum:   132546 fd2418e723e9593e6fb2a0b8ddb560f2
    http://security.debian.org/pool/updates/main/r/ruby/libpty-ruby_1.6.7-3woody3_i386.deb
      Size/MD5 checksum:   130850 9db0ae40218699d051b8f5380e982a4c
    http://security.debian.org/pool/updates/main/r/ruby/libreadline-ruby_1.6.7-3woody3_i386.deb
      Size/MD5 checksum:   126956 a83ee07e8b69b03c54731249be14fb2c
    http://security.debian.org/pool/updates/main/r/ruby/libruby_1.6.7-3woody3_i386.deb
      Size/MD5 checksum:   561040 c434f5bd8ff8de6a346e5eb82df2372e
    http://security.debian.org/pool/updates/main/r/ruby/libsdbm-ruby_1.6.7-3woody3_i386.deb
      Size/MD5 checksum:   129828 291fd61e32d5f3986979b01abc980547
    http://security.debian.org/pool/updates/main/r/ruby/libsyslog-ruby_1.6.7-3woody3_i386.deb
      Size/MD5 checksum:   127250 30db287268d9fa0f23e4712a59176dbb
    http://security.debian.org/pool/updates/main/r/ruby/libtcltk-ruby_1.6.7-3woody3_i386.deb
      Size/MD5 checksum:   146198 6c8440063e379b3e60d6ea4001a5926e
    http://security.debian.org/pool/updates/main/r/ruby/libtk-ruby_1.6.7-3woody3_i386.deb
      Size/MD5 checksum:   161140 11a8a2aa9bbe7c01ab53ca6c920c98c5
    http://security.debian.org/pool/updates/main/r/ruby/ruby_1.6.7-3woody3_i386.deb
      Size/MD5 checksum:   142178 6a5aab98d048a03c958ced24dcac31ac
    http://security.debian.org/pool/updates/main/r/ruby/ruby-dev_1.6.7-3woody3_i386.deb
      Size/MD5 checksum:   492314 2fa7dc937bae7f456f6c466fcd3689fb

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/r/ruby/libcurses-ruby_1.6.7-3woody3_ia64.deb
      Size/MD5 checksum:   132964 e60b61f854e12dff1c7dc2dc152f9a94
    http://security.debian.org/pool/updates/main/r/ruby/libdbm-ruby_1.6.7-3woody3_ia64.deb
      Size/MD5 checksum:   132486 fe7965b42c0360b6427626f63788c548
    http://security.debian.org/pool/updates/main/r/ruby/libgdbm-ruby_1.6.7-3woody3_ia64.deb
      Size/MD5 checksum:   134522 d82ca720a60a86ab6ee1c972433abd1d
    http://security.debian.org/pool/updates/main/r/ruby/libnkf-ruby_1.6.7-3woody3_ia64.deb
      Size/MD5 checksum:   139674 6f6b2aec3d5f308af1e3eaeffee52f45
    http://security.debian.org/pool/updates/main/r/ruby/libpty-ruby_1.6.7-3woody3_ia64.deb
      Size/MD5 checksum:   133842 2ee528129c72ca691df2ba5bbb49daf4
    http://security.debian.org/pool/updates/main/r/ruby/libreadline-ruby_1.6.7-3woody3_ia64.deb
      Size/MD5 checksum:   131428 fc1c5020fb099724b75ae9d943f598fa
    http://security.debian.org/pool/updates/main/r/ruby/libruby_1.6.7-3woody3_ia64.deb
      Size/MD5 checksum:   853762 66df1237cbf7482132f3c1e7d5fc9478
    http://security.debian.org/pool/updates/main/r/ruby/libsdbm-ruby_1.6.7-3woody3_ia64.deb
      Size/MD5 checksum:   140176 8434621b3798fef58519967011622175
    http://security.debian.org/pool/updates/main/r/ruby/libsyslog-ruby_1.6.7-3woody3_ia64.deb
      Size/MD5 checksum:   130570 6f2e029eb940ce8703ea224634bddb84
    http://security.debian.org/pool/updates/main/r/ruby/libtcltk-ruby_1.6.7-3woody3_ia64.deb
      Size/MD5 checksum:   150160 ed95d384f39bbf915db5f3db3b66bd18
    http://security.debian.org/pool/updates/main/r/ruby/libtk-ruby_1.6.7-3woody3_ia64.deb
      Size/MD5 checksum:   162156 2f74ce0a43569708fc072f24c7aadab0
    http://security.debian.org/pool/updates/main/r/ruby/ruby_1.6.7-3woody3_ia64.deb
      Size/MD5 checksum:   143016 d387f4b4284a8c6a431596575fe5c209
    http://security.debian.org/pool/updates/main/r/ruby/ruby-dev_1.6.7-3woody3_ia64.deb
      Size/MD5 checksum:   754776 e92c1fd410a3b2f508924e33d4a0a776

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/r/ruby/libcurses-ruby_1.6.7-3woody3_hppa.deb
      Size/MD5 checksum:   130348 aa5745400400f66d82761d2982b495f4
    http://security.debian.org/pool/updates/main/r/ruby/libdbm-ruby_1.6.7-3woody3_hppa.deb
      Size/MD5 checksum:   129070 a790b197582972daf1d33e398cd383e7
    http://security.debian.org/pool/updates/main/r/ruby/libgdbm-ruby_1.6.7-3woody3_hppa.deb
      Size/MD5 checksum:   130582 b9b750829364db4dba472f13cdc53ecd
    http://security.debian.org/pool/updates/main/r/ruby/libnkf-ruby_1.6.7-3woody3_hppa.deb
      Size/MD5 checksum:   135830 b3050e8f32cc8b4d9a429166ced30b63
    http://security.debian.org/pool/updates/main/r/ruby/libpty-ruby_1.6.7-3woody3_hppa.deb
      Size/MD5 checksum:   132058 af3dc5ba678a627ca2477dc7a29d5929
    http://security.debian.org/pool/updates/main/r/ruby/libreadline-ruby_1.6.7-3woody3_hppa.deb
      Size/MD5 checksum:   128414 2db8ed7a954b4a53ab5b058f5d5b54af
    http://security.debian.org/pool/updates/main/r/ruby/libruby_1.6.7-3woody3_hppa.deb
      Size/MD5 checksum:   685786 ec5083b3b273920b0bc8e8fed2bb36e2
    http://security.debian.org/pool/updates/main/r/ruby/libsdbm-ruby_1.6.7-3woody3_hppa.deb
      Size/MD5 checksum:   132742 0dfa2492e892b330af5aa25921758d00
    http://security.debian.org/pool/updates/main/r/ruby/libsyslog-ruby_1.6.7-3woody3_hppa.deb
      Size/MD5 checksum:   128866 c94fbb1fc8133fd5b5361f8c8870e4e4
    http://security.debian.org/pool/updates/main/r/ruby/libtcltk-ruby_1.6.7-3woody3_hppa.deb
      Size/MD5 checksum:   147806 04fa22f21bec2a1e093a535908a6466e
    http://security.debian.org/pool/updates/main/r/ruby/libtk-ruby_1.6.7-3woody3_hppa.deb
      Size/MD5 checksum:   161644 b04ab74d55eaa1cfe8fc93f791475767
    http://security.debian.org/pool/updates/main/r/ruby/ruby_1.6.7-3woody3_hppa.deb
      Size/MD5 checksum:   142414 a51b05df9f4406f8a2ff12cc88ba9ec2
    http://security.debian.org/pool/updates/main/r/ruby/ruby-dev_1.6.7-3woody3_hppa.deb
      Size/MD5 checksum:   666922 25404242d3f1fcc5183930652ecf1cd1

  Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/r/ruby/libcurses-ruby_1.6.7-3woody3_m68k.deb
      Size/MD5 checksum:   128200 9a0b2868f76f87979c168cf834a7da95
    http://security.debian.org/pool/updates/main/r/ruby/libdbm-ruby_1.6.7-3woody3_m68k.deb
      Size/MD5 checksum:   127016 c87cfda620b8d3d74ee53fce603f75a7
    http://security.debian.org/pool/updates/main/r/ruby/libgdbm-ruby_1.6.7-3woody3_m68k.deb
      Size/MD5 checksum:   128160 db81705d34af1dddb4334348d8fba6df
    http://security.debian.org/pool/updates/main/r/ruby/libnkf-ruby_1.6.7-3woody3_m68k.deb
      Size/MD5 checksum:   132594 93b9f11e3f95741cf89fc4d57a8da2af
    http://security.debian.org/pool/updates/main/r/ruby/libpty-ruby_1.6.7-3woody3_m68k.deb
      Size/MD5 checksum:   131148 c2d5e93d16fa341067e9632af2aea9d0
    http://security.debian.org/pool/updates/main/r/ruby/libreadline-ruby_1.6.7-3woody3_m68k.deb
      Size/MD5 checksum:   127194 8c8517ceb7d782cd68e8202e52172e2d
    http://security.debian.org/pool/updates/main/r/ruby/libruby_1.6.7-3woody3_m68k.deb
      Size/MD5 checksum:   561272 c137e55dcdf3efd294f3351ed41a025a
    http://security.debian.org/pool/updates/main/r/ruby/libsdbm-ruby_1.6.7-3woody3_m68k.deb
      Size/MD5 checksum:   129550 5b588283bb536406cda1129d075f9647
    http://security.debian.org/pool/updates/main/r/ruby/libsyslog-ruby_1.6.7-3woody3_m68k.deb
      Size/MD5 checksum:   128008 5e2158999321a43eb786ba950ba8d5e4
    http://security.debian.org/pool/updates/main/r/ruby/libtcltk-ruby_1.6.7-3woody3_m68k.deb
      Size/MD5 checksum:   146452 0f18fff973a279b642e49fd55a15674a
    http://security.debian.org/pool/updates/main/r/ruby/libtk-ruby_1.6.7-3woody3_m68k.deb
      Size/MD5 checksum:   161208 ab176231465ba41be9b7e1e296fa973b
    http://security.debian.org/pool/updates/main/r/ruby/ruby_1.6.7-3woody3_m68k.deb
      Size/MD5 checksum:   142150 677ca204cf61f2894cb40b9bf8c496d2
    http://security.debian.org/pool/updates/main/r/ruby/ruby-dev_1.6.7-3woody3_m68k.deb
      Size/MD5 checksum:   470588 dd7b834f52328f1c3eaaebffb163dd8e

  Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/r/ruby/libcurses-ruby_1.6.7-3woody3_mips.deb
      Size/MD5 checksum:   128066 34b998262be7c5da5240b43e85b4b05a
    http://security.debian.org/pool/updates/main/r/ruby/libdbm-ruby_1.6.7-3woody3_mips.deb
      Size/MD5 checksum:   126726 de79abd46651e1bd473177977c188cb6
    http://security.debian.org/pool/updates/main/r/ruby/libgdbm-ruby_1.6.7-3woody3_mips.deb
      Size/MD5 checksum:   127896 f08e2626552f649847ba8adde79bd1ad
    http://security.debian.org/pool/updates/main/r/ruby/libnkf-ruby_1.6.7-3woody3_mips.deb
      Size/MD5 checksum:   133518 8d4d2cb8bde4849b99b1b7301e006559
    http://security.debian.org/pool/updates/main/r/ruby/libpty-ruby_1.6.7-3woody3_mips.deb
      Size/MD5 checksum:   130760 d58504211ca8fd4fa2c9d5194b20d9f2
    http://security.debian.org/pool/updates/main/r/ruby/libreadline-ruby_1.6.7-3woody3_mips.deb
      Size/MD5 checksum:   127002 9645e4b25425e1e2d0c0d91f9d191f99
    http://security.debian.org/pool/updates/main/r/ruby/libruby_1.6.7-3woody3_mips.deb
      Size/MD5 checksum:   581684 a9cc975831de3ea9851c76c3a34561f4
    http://security.debian.org/pool/updates/main/r/ruby/libsdbm-ruby_1.6.7-3woody3_mips.deb
      Size/MD5 checksum:   130244 c4bb6e1bc8b3abecbe1a335cc16d6ae7
    http://security.debian.org/pool/updates/main/r/ruby/libsyslog-ruby_1.6.7-3woody3_mips.deb
      Size/MD5 checksum:   127616 2f8d40963f952305943fd659b2fa9793
    http://security.debian.org/pool/updates/main/r/ruby/libtcltk-ruby_1.6.7-3woody3_mips.deb
      Size/MD5 checksum:   146388 4696135eed267896b3725ada82e24ee0
    http://security.debian.org/pool/updates/main/r/ruby/libtk-ruby_1.6.7-3woody3_mips.deb
      Size/MD5 checksum:   161234 8f8d2eb85ba3144fea9ba01fea19a5ca
    http://security.debian.org/pool/updates/main/r/ruby/ruby_1.6.7-3woody3_mips.deb
      Size/MD5 checksum:   142536 e33a261393e89cd4785245fd8e86c6a3
    http://security.debian.org/pool/updates/main/r/ruby/ruby-dev_1.6.7-3woody3_mips.deb
      Size/MD5 checksum:   587196 efe9473b91750f8e996dae6ac538d9c7

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/r/ruby/libcurses-ruby_1.6.7-3woody3_mipsel.deb
      Size/MD5 checksum:   128016 75f5960936046948e0dd00f07b665b84
    http://security.debian.org/pool/updates/main/r/ruby/libdbm-ruby_1.6.7-3woody3_mipsel.deb
      Size/MD5 checksum:   126752 896fca2b2fc4005f7ddb433572fb8e6a
    http://security.debian.org/pool/updates/main/r/ruby/libgdbm-ruby_1.6.7-3woody3_mipsel.deb
      Size/MD5 checksum:   127918 6647f61287bbc520bdcfaf84854f5fc4
    http://security.debian.org/pool/updates/main/r/ruby/libnkf-ruby_1.6.7-3woody3_mipsel.deb
      Size/MD5 checksum:   133524 6a21349453635e818d08add29ffb347c
    http://security.debian.org/pool/updates/main/r/ruby/libpty-ruby_1.6.7-3woody3_mipsel.deb
      Size/MD5 checksum:   130740 85ea023518438b3c238a9ff20f3ebcfc
    http://security.debian.org/pool/updates/main/r/ruby/libreadline-ruby_1.6.7-3woody3_mipsel.deb
      Size/MD5 checksum:   126946 4de6fe2ffbdaa0e1509cacf4a51dd8ee
    http://security.debian.org/pool/updates/main/r/ruby/libruby_1.6.7-3woody3_mipsel.deb
      Size/MD5 checksum:   581236 03ef54fe90f13013a6cacf55a7ae1e03
    http://security.debian.org/pool/updates/main/r/ruby/libsdbm-ruby_1.6.7-3woody3_mipsel.deb
      Size/MD5 checksum:   130244 9b883c0e1254194f0cfc112572220b80
    http://security.debian.org/pool/updates/main/r/ruby/libsyslog-ruby_1.6.7-3woody3_mipsel.deb
      Size/MD5 checksum:   127602 596f768ee52bac9ee0f98a7dacd5fef6
    http://security.debian.org/pool/updates/main/r/ruby/libtcltk-ruby_1.6.7-3woody3_mipsel.deb
      Size/MD5 checksum:   146326 9f4767c8bb9a39ce830a6fbf4457a31a
    http://security.debian.org/pool/updates/main/r/ruby/libtk-ruby_1.6.7-3woody3_mipsel.deb
      Size/MD5 checksum:   161246 b57777443a07272bb8efb89e8fc26a24
    http://security.debian.org/pool/updates/main/r/ruby/ruby_1.6.7-3woody3_mipsel.deb
      Size/MD5 checksum:   142548 4345d7e4803a7d49d79841e5c4aed051
    http://security.debian.org/pool/updates/main/r/ruby/ruby-dev_1.6.7-3woody3_mipsel.deb
      Size/MD5 checksum:   577834 8d24ebec0af643b9674792a26d217755

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/r/ruby/libcurses-ruby_1.6.7-3woody3_powerpc.deb
      Size/MD5 checksum:   128172 47b817c6e43f28ae76ebc5dfd85c6995
    http://security.debian.org/pool/updates/main/r/ruby/libdbm-ruby_1.6.7-3woody3_powerpc.deb
      Size/MD5 checksum:   127382 9a7ed4a6bc2a1dc6ea62cab893259229
    http://security.debian.org/pool/updates/main/r/ruby/libgdbm-ruby_1.6.7-3woody3_powerpc.deb
      Size/MD5 checksum:   128482 91f7d646ac48dab065275b18edac2761
    http://security.debian.org/pool/updates/main/r/ruby/libnkf-ruby_1.6.7-3woody3_powerpc.deb
      Size/MD5 checksum:   134216 33b37873348bc1fdf014fe18f9bc423e
    http://security.debian.org/pool/updates/main/r/ruby/libpty-ruby_1.6.7-3woody3_powerpc.deb
      Size/MD5 checksum:   131116 1f820aaf2fcba567e0422d19defefbc1
    http://security.debian.org/pool/updates/main/r/ruby/libreadline-ruby_1.6.7-3woody3_powerpc.deb
      Size/MD5 checksum:   127278 120ede9817ce6974720ac6b2414382e4
    http://security.debian.org/pool/updates/main/r/ruby/libruby_1.6.7-3woody3_powerpc.deb
      Size/MD5 checksum:   606934 625ed15414c5e2627a870339f0cf8ae5
    http://security.debian.org/pool/updates/main/r/ruby/libsdbm-ruby_1.6.7-3woody3_powerpc.deb
      Size/MD5 checksum:   130350 f8bbbc383a6a10374db4ec0266be8461
    http://security.debian.org/pool/updates/main/r/ruby/libsyslog-ruby_1.6.7-3woody3_powerpc.deb
      Size/MD5 checksum:   128092 22bc2b894ed585d13ae95f9fadaf147f
    http://security.debian.org/pool/updates/main/r/ruby/libtcltk-ruby_1.6.7-3woody3_powerpc.deb
      Size/MD5 checksum:   146812 47fba2a53629cac0182f4b0cbcc918c1
    http://security.debian.org/pool/updates/main/r/ruby/libtk-ruby_1.6.7-3woody3_powerpc.deb
      Size/MD5 checksum:   161218 a097f25640ec69988347417c12efe480
    http://security.debian.org/pool/updates/main/r/ruby/ruby_1.6.7-3woody3_powerpc.deb
      Size/MD5 checksum:   142240 b683fb03d99a77b4ef2223f7c3a7585a
    http://security.debian.org/pool/updates/main/r/ruby/ruby-dev_1.6.7-3woody3_powerpc.deb
      Size/MD5 checksum:   529108 7d327e355f206dd22c7a032b7b21b803

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/r/ruby/libcurses-ruby_1.6.7-3woody3_s390.deb
      Size/MD5 checksum:   128400 d7e26d77fbeac9971b3de3372164e526
    http://security.debian.org/pool/updates/main/r/ruby/libdbm-ruby_1.6.7-3woody3_s390.deb
      Size/MD5 checksum:   127588 0676b34845df277c3ccfbb69972579cb
    http://security.debian.org/pool/updates/main/r/ruby/libgdbm-ruby_1.6.7-3woody3_s390.deb
      Size/MD5 checksum:   128650 472ec34761e12ed275441b67b5b285ad
    http://security.debian.org/pool/updates/main/r/ruby/libnkf-ruby_1.6.7-3woody3_s390.deb
      Size/MD5 checksum:   133426 4f4718e01e004b5aec64f36ee8a0d0ac
    http://security.debian.org/pool/updates/main/r/ruby/libpty-ruby_1.6.7-3woody3_s390.deb
      Size/MD5 checksum:   131590 04fc7f96792b3d3b172ca6556e0d9910
    http://security.debian.org/pool/updates/main/r/ruby/libreadline-ruby_1.6.7-3woody3_s390.deb
      Size/MD5 checksum:   127676 6daed5ee2add1b98b1337bccae744c5d
    http://security.debian.org/pool/updates/main/r/ruby/libruby_1.6.7-3woody3_s390.deb
      Size/MD5 checksum:   600520 306cc308c856c597f264b903b0565823
    http://security.debian.org/pool/updates/main/r/ruby/libsdbm-ruby_1.6.7-3woody3_s390.deb
      Size/MD5 checksum:   130602 b939f0917470cf49328fc5db5eb5993d
    http://security.debian.org/pool/updates/main/r/ruby/libsyslog-ruby_1.6.7-3woody3_s390.deb
      Size/MD5 checksum:   127668 c1c7ab0f2dbc2ef52ad0722598f0ee30
    http://security.debian.org/pool/updates/main/r/ruby/libtcltk-ruby_1.6.7-3woody3_s390.deb
      Size/MD5 checksum:   146974 cbbdd5c64e65578dfeda33a660f9c4b9
    http://security.debian.org/pool/updates/main/r/ruby/libtk-ruby_1.6.7-3woody3_s390.deb
      Size/MD5 checksum:   161290 418a07ac22ac6e74a7ebfbf0a3a70ab1
    http://security.debian.org/pool/updates/main/r/ruby/ruby_1.6.7-3woody3_s390.deb
      Size/MD5 checksum:   142404 e927d838e8bf933e3bcdfa5049e96a24
    http://security.debian.org/pool/updates/main/r/ruby/ruby-dev_1.6.7-3woody3_s390.deb
      Size/MD5 checksum:   532116 20e3927ba7a286ceb96e643c99c96aee

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/r/ruby/libcurses-ruby_1.6.7-3woody3_sparc.deb
      Size/MD5 checksum:   128160 a02e144293b556d8d28ef90ef8f84e6a
    http://security.debian.org/pool/updates/main/r/ruby/libdbm-ruby_1.6.7-3woody3_sparc.deb
      Size/MD5 checksum:   127210 cbc0e9f60c120e68abd615dbc7782482
    http://security.debian.org/pool/updates/main/r/ruby/libgdbm-ruby_1.6.7-3woody3_sparc.deb
      Size/MD5 checksum:   128650 7b94be80efa7afad55e2452022f42c5f
    http://security.debian.org/pool/updates/main/r/ruby/libnkf-ruby_1.6.7-3woody3_sparc.deb
      Size/MD5 checksum:   134058 40d4148e8c427214c223795ba909ef97
    http://security.debian.org/pool/updates/main/r/ruby/libpty-ruby_1.6.7-3woody3_sparc.deb
      Size/MD5 checksum:   131100 73c4a60be604896dc04699d0efb72020
    http://security.debian.org/pool/updates/main/r/ruby/libreadline-ruby_1.6.7-3woody3_sparc.deb
      Size/MD5 checksum:   127176 e1699aa9fe7fe7aed61832d3ab43c871
    http://security.debian.org/pool/updates/main/r/ruby/libruby_1.6.7-3woody3_sparc.deb
      Size/MD5 checksum:   602908 61ab4131e4bc3d0c9da2327de4522e7b
    http://security.debian.org/pool/updates/main/r/ruby/libsdbm-ruby_1.6.7-3woody3_sparc.deb
      Size/MD5 checksum:   129948 1b1eb23ba0ed3da96cf972c04f14a912
    http://security.debian.org/pool/updates/main/r/ruby/libsyslog-ruby_1.6.7-3woody3_sparc.deb
      Size/MD5 checksum:   128022 669453179d94866792cfe27789fe504a
    http://security.debian.org/pool/updates/main/r/ruby/libtcltk-ruby_1.6.7-3woody3_sparc.deb
      Size/MD5 checksum:   146514 6f09f6d77b874d4da0ee48e4d388c100
    http://security.debian.org/pool/updates/main/r/ruby/libtk-ruby_1.6.7-3woody3_sparc.deb
      Size/MD5 checksum:   161268 0f7d07a0d11521604045ecd43f981f90
    http://security.debian.org/pool/updates/main/r/ruby/ruby_1.6.7-3woody3_sparc.deb
      Size/MD5 checksum:   142164 f1202001ac69b03f4ba8f92c7bcb6bd2
    http://security.debian.org/pool/updates/main/r/ruby/ruby-dev_1.6.7-3woody3_sparc.deb
      Size/MD5 checksum:   561030 da13206ba8649404543b6acb2be343cb


  These files will probably be moved into the stable distribution on
  its next update.

- - ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQFBIDRBW5ql+IAeqTIRAkZXAJ0XCGbxciUaAH8mjeAOXUKVW/I2hgCgt30R
bij4qdWdlNSPH/2tNwd9qzM=
=jPJo
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

If you believe that your computer system has been compromised or attacked in 
any way, we encourage you to let us know by completing the secure National IT 
Incident Reporting Form at:

        http://www.auscert.org.au/render.html?it=3192

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================

-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQCVAwUBQSFZzyh9+71yA2DNAQKyeAP/atjeb7tuR9K0rYgvgEn6hwDFlbDd5nyU
25dNMicu5CJ33t3w69/DqVco08CjaEkF+Helr+yP/Ql9n1vFU7hmqP9JAhvtKt83
SQ2c6evFrscFjkupkqNPF+jcg4ZVOA5khH6MaonIGtx/b+Mg8oNrmVG7LFUd1sYk
p/yabMLef+0=
=TxB1
-----END PGP SIGNATURE-----