USN-446-1: NAS vulnerabilities
===========================================================
Ubuntu Security Notice USN-446-1 March 28, 2007
nas vulnerabilities
CVE-2007-1543, CVE-2007-1544, CVE-2007-1545, CVE-2007-1546, CVE-2007-1547
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 5.10
Ubuntu 6.06 LTS
Ubuntu 6.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 5.10:
nas 1.7-2ubuntu2.1
Ubuntu 6.06 LTS:
nas 1.7-3ubuntu3.2
Ubuntu 6.10:
nas 1.8-2ubuntu0.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Luigi Auriemma discovered multiple flaws in the Network Audio System
server. Remote attackers could send specially crafted network requests
that could lead to a denial of service or execution of arbitrary code.
Note that default Ubuntu installs do not include the NAS server.



