Download Debian 6.0.3

Spread the love

The third update of version 6.0 of Debian has been released. Debian is an open source operating system, which can be used for both desktops and servers, with an emphasis on stability and security. It is therefore used as the basis for various Linux distributions. In version 6.0, codenamed ‘Squeeze’, we also see a GNU/kFreeBSD implementation for the first time. In version 6.0.3 we don’t find any major changes; However, various improvements have been made to existing components.

Updated Debian 6.0: 6.0.3 released

The Debian project is pleased to announce the third update of its stable distribution Debian 6.0 (codename squeeze). This update mainly adds corrections for security problems to the stable release, along with a few adjustments to serious problems. Security advisories were already published separately and are referenced where available.

Please note that this update does not constitute a new version of Debian 6.0 but only updates some of the packages included. There is no need to throw away 6.0 CDs or DVDs but only to update via an up-to-date Debian mirror after an installation, to cause any out of date packages to be updated.

Those who frequently install updates from security.debian.org won’t have to update many packages and most updates from security.debian.org are included in this update.

New installation media and CD and DVD images containing updated packages will be available soon at the regular locations.

Upgrading to this revision online is usually done by pointing the aptitude (or apt) package tool (see the sources.list(5) manual page) to one of Debian’s many FTP or HTTP mirrors. A comprehensive list of mirrors is available at:

Miscellaneous Bug Fixes

This stable update adds a few important corrections to the following packages:

PackageReason
aceRebuild to drop non-distributable files
akonadiSupport the use of network-mounted $HOME
amispammerUpdate service used for discovering the local IP address
apache2Fix CVE-2011-3348: Possible denial of service in mod_proxy_ajp; various documentation and init script fixes
aptitudeFix symlink attack in hierarchy editor
arcbootFix netinstall on IP22 / IP32
atopInsecure use of temporary files
base filesUpdate /etc/debian_version for the point release
brlttyFix parsing brltty= when not all parameters are provided; setup gconf even if no table was specified
clamavuNew upstream release; fix off-by-one and opcode 20 not implemented errors
cliveAdapt for youtube.com changes
conkyFix file overwrite vulnerability
ctdbFix path to ethtool and activation of httpd service
debian-installer-utilsSet SUDO_FORCE_REMOVE=yes to allow sudo-ldap to be installed from di
deja-dupExplicitly pass environment to subprocesses to ensure correct GPG operation on restores
dokuwikiRSS XSS security fix
dputUpdate backports configuration to use the new .do hosts
drupal6Security fix for XSS in color module
firmware-nonfreeAdd VIA VT6656, Realtek RTL8105E-1 and RTL8168E-1/2/3 firmware
foo2zjsFix secure use of temporary file
freebsd-libsMove libsbuf.so.0 and libipx.so.2 to /lib
freebsd-utilsProvide config files and init.d script for devd; enable ieee80211 (wireless) in ifconfig
gajimFix high CPU load on connection
gdebiTry to determine correctly localized value for Y
gdm3Only show shutdown options when requested; fix double free; only set WINDOWPATH if not NULL; remove beep in PAM dialog patch
gitFix off-by-one parsing commit subjects; prevent deadlock when shallow cloning; documentation updates
grub installerAllow use of grub-legacy to be pre-seeded (if appropriate)
grub2Handle Xen split-partition disk image devices; ensure uniqueness of RAID array numbers; fix grub-probe detection for ATA devices using ata driver on kFreeBSD 9
heimdalAllow DES to be used with NFS
httpcomponents clientFix bug causing Proxy-Authorization header to be passed to target hosts
ia32-libsRefresh packages from stable and security
ia32-libs-gtkRefresh packages from stable and security
ibidFix various security issues; make the HTTP source work again
ipmitoolFix segfault
kde4libsPrevent marked text being cut when switching documents in kate
kernel wedgeStop considering acpi.ko as part of the kernel for kFreeBSD
kfreebsd-8Fix net802.11 stack kernel memory disclosure (CVE-2011-2480); merge backported if_msk driver from 8-STABLE; re-enable building of some modules
kfreebsd-kernel-di-amd64Rebuild against kfreebsd-8 8.1+dfsg-8+squeeze1
kfreebsd-kernel-di-i386Rebuild against kfreebsd-8 8.1+dfsg-8+squeeze1
krb5Permit gss_set_allowable_enctypes to restrict acceptor enctypes, allowing newer clients to use a Squeeze NFS server without degrading security for non-NFS applications
cupferDon’t crash if Evolution address book not present
libpcapFix corruption of snapshot length on live captures; fix device detection when bonding in use
lintianFix information disclosure issues
linux-2.6Update to long-term release 2.6.32.46; backport network driver changes
linux-kernel-di-amd64-2.6Rebuild against linux-2.6 2.6.32-38
linux-kernel-di-armel-2.6Rebuild against linux-2.6 2.6.32-38
linux-kernel-di-i386-2.6Rebuild against linux-2.6 2.6.32-38
linux-kernel-di-ia64-2.6Rebuild against linux-2.6 2.6.32-38
linux-kernel-di-mips-2.6Rebuild against linux-2.6 2.6.32-38
linux-kernel-di-mipsel-2.6Rebuild against linux-2.6 2.6.32-38
linux-kernel-di-powerpc-2.6Rebuild against linux-2.6 2.6.32-38
linux-kernel-di-s390-2.6Rebuild against linux-2.6 2.6.32-38
linux-kernel-di-sparc-2.6Rebuild against linux-2.6 2.6.32-38
mesaGLX: suppress BadRequest from DRI2Connect (expected for non-local clients)
mod-gnutlsFix segmentation faults
nagvisInstall documentation; properly apply FollowSymlinks; only call ucf if available
nss-pam-ldapdFix uninitialized memory while parsing the tls_ciphers; fix problem with partial attribute name matches in DN; make all string buffers able to represent 64-bit numbers; treat the hard value for tls_reqcert as if it was demand
open arenaFix arbitrary code execution by malicious bytecode
opencvFix install path of opencv doc; optimize i386 package for i486
opensshQuieten logs when multiple from= restrictions are used in different authorized_keys lines for the same key
opensslFix CVE-2011-3210: SSL memory handling for (EC)DH ciphersuites
piano barSupport XMLRPC API version 31
pmakeFix symlink attack via temporary files
postgresql-8.4Fix regression due to fix plpgsql’s issues with dropped columns in rowtypes in 8.4 branch
python-recaptchaUpdate URLs for web service move to google.com
quasselFix DoS via CTCP
red5Add missing dependency on glassfish-javaee
sbclFix reference to undefined asdf::split in the asdf-install module
shelldapExit with a nicer error message if IO::Socket::SSL isn’t installed, but SSL/TLS was requested
system-tools-backendsProperly handle config file rename
tesseractFix file overwrite vulnerability by disabling xterm-based debug windows
typo3-srcFix cache flooding via improper error handling
tzdataNew upstream version
update-inetdFix breakage with non-default inetd packages
usbutilsUpdate USB ID list; build-depend on libusb2-dev on kFreeBSD
user-mode-linuxRebuild against linux-2.6 2.6.32-37
v86dFix CVE-2011-1070: failure to validate netlink message sender; do not include random kernel headers in CFLAGS
vftoolFix a buffer overflow in linetoken() in parseAFM.c
fteFix DoS
widelandsFix network play on official maps (regression introduced by previous update)
win32 loaderAdd Built-Using header; allow suite-specific versions; document versions of embedded software
xapian-omegaFix escaping issues in templates
zfsutilsUpdate LSB init headers to ensure clean startup/shutdown; add bash completion script

Version number6.0.3
Release statusFinal
Operating systemsLinux, BSD
WebsiteDebian
Download
License typeConditions (GNU/BSD/etc.)
You might also like