Vr Nov 6 09:21:25 CET 2009

linux-2.6 (2.6.26-19lenny2) stable-security; urgency=high

  * tc: Fix uninitialized kernel memory leak (CVE-2009-3228)
  * random: make get_random_int() more random (CVE-2009-3238)
  * netlink: fix typo in initialization (CVE-2009-3612)
  * drm/r128: Add test for initialisation to all ioctls that require it
  * AF_UNIX: Fix deadlock on connecting to shutdown socket (CVE-2009-3621)
  * fs: pipe.c null pointer dereference (CVE-2009-3547)
  * KVM: Prevent overflow in KVM_GET_SUPPORTED_CPUID (CVE-2009-3638)

 -- dann frazier <dannf op debian.org>  Wed, 04 Nov 2009 12:33:37 -0700

proftpd-dfsg (1.3.1-17lenny4) stable-security; urgency=high

  * Security: added 3275.dpatch as taken from 1.3.2b branch to fix CVE-2009-3639.

 -- Francesco Paolo Lovergine <frankie op debian.org>  Tue, 27 Oct 2009 11:02:58 +0100

proftpd-dfsg (1.3.1-17lenny3) stable; urgency=low

  * [PATCH] Added 3284.dpatch to fix TCP_NODELAY misuse in inet.c core file.
    It negatively impacts >= 1.3.1 versions. Backported from 1.3.2 branch.
    See http://bugs.proftpd.org/show_bug.cgi?id=3284 for more information.

 -- Francesco Paolo Lovergine <frankie op debian.org>  Tue, 15 Sep 2009 14:36:19 +0200

