Linux Today: Linux News On Internet Time.
Search Linux Today
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Server Daily
IT Management Daily
Subscribe News
Subscribe PR
Subscribe Security

internet.com
Internet News
Small Business

Advertise
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

20 popular Ubuntu Linux apps you may want to try

A Selection of the Very Best Open Source Tutorials and Tools

Android Ice Cream Sandwich ported to x86 tablets, netbooks and notebooks

SECURITY: Google Chrome 17 Improves Security

How to read a CSV file in Perl?

Red Hat Brings Gluster to Amazon Cloud

New Linux kernel fixes power-saving issues

Using Wii remote with Android Device- Taking Gaming to the Next Level

Commercial Support now available for the open-source NGINX Web server

Linux Top 5: Linux's New Fellow



Applications Management Engineer Sr (NYC)
Next Step Systems
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume
:Security Digest: February 10, 2005
Security Digest: February 10, 2005
Feb 11, 2005, 04 :45 UTC (0 Talkback[s]) (2645 reads)

Debian GNU/Linux


Debian Security Advisory DSA 672-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
February 9th, 2005 http://www.debian.org/security/faq


Package : xview
Vulnerability : buffer overflows
Problem-Type : local
Debian-specific: no
CVE ID : CAN-2005-0076

Erik Sjölund discovered that programs linked against xview are vulnerable to a number of buffer overflows in the XView library. When the overflow is triggered in a program which is installed setuid root a malicious user could perhaps execute arbitrary code as privileged user.

For the stable distribution (woody) these problems have been fixed in version 3.2p1.4-16woody2.

For the unstable distribution (sid) these problems have been fixed in version 3.2p1.4-19.

We recommend that you upgrade your xview packages.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody


Source archives:

http://security.debian.org/pool/updates/main/x/xview/xview_3.2p1.4-16woody2.dsc
Size/MD5 checksum: 682 73f2ebae0581f04e9edf62333da56353
http://security.debian.org/pool/updates/main/x/xview/xview_3.2p1.4-16woody2.diff.gz
Size/MD5 checksum: 65663 526f16dcd2164713e792e19b9c9a42c2
http://security.debian.org/pool/updates/main/x/xview/xview_3.2p1.4.orig.tar.gz
Size/MD5 checksum: 3227552 b9ff26d6ad378af320bac45154ceaeba

Alpha architecture:

http://security.debian.org/pool/updates/main/x/xview/olvwm_4.4.3.2p1.4-16woody2_alpha.deb
Size/MD5 checksum: 242538 b02d3c329cd137288360c8dfa1d279ef
http://security.debian.org/pool/updates/main/x/xview/olwm_3.2p1.4-16woody2_alpha.deb
Size/MD5 checksum: 166874 01c86265b4b1bb03924dc39f03d16e26
http://security.debian.org/pool/updates/main/x/xview/xview-clients_3.2p1.4-16woody2_alpha.deb
Size/MD5 checksum: 82184 c90e02f6824b1966cab7c843f866f366
http://security.debian.org/pool/updates/main/x/xview/xview-examples_3.2p1.4-16woody2_alpha.deb
Size/MD5 checksum: 282748 0f0d74d37511ef359a9cfa073d1c7a2e
http://security.debian.org/pool/updates/main/x/xview/xviewg_3.2p1.4-16woody2_alpha.deb
Size/MD5 checksum: 830458 396d5dcd0896c25bd5ef3db05356c29c
http://security.debian.org/pool/updates/main/x/xview/xviewg-dev_3.2p1.4-16woody2_alpha.deb
Size/MD5 checksum: 1336468 15932deabc7a32861bca5dec52749ccc

ARM architecture:

http://security.debian.org/pool/updates/main/x/xview/olvwm_4.4.3.2p1.4-16woody2_arm.deb
Size/MD5 checksum: 213546 31b52257f06f8c5c9b75cc7d0d45cd25
http://security.debian.org/pool/updates/main/x/xview/olwm_3.2p1.4-16woody2_arm.deb
Size/MD5 checksum: 146328 d3e5511c12ef36547e86b1798f000ef1
http://security.debian.org/pool/updates/main/x/xview/xview-clients_3.2p1.4-16woody2_arm.deb
Size/MD5 checksum: 72314 b77af29123fa25750f470bcd3b9fa555
http://security.debian.org/pool/updates/main/x/xview/xview-examples_3.2p1.4-16woody2_arm.deb
Size/MD5 checksum: 233808 f7feda439c8e0367a5b0270895924351
http://security.debian.org/pool/updates/main/x/xview/xviewg_3.2p1.4-16woody2_arm.deb
Size/MD5 checksum: 740040 28a2d8eb135764c7fe0026a65df32d9c
http://security.debian.org/pool/updates/main/x/xview/xviewg-dev_3.2p1.4-16woody2_arm.deb
Size/MD5 checksum: 1119956 2e0e9dfc6641d46d6daac559bb32b233

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/x/xview/olvwm_4.4.3.2p1.4-16woody2_i386.deb
Size/MD5 checksum: 183850 acf639933b6eb260f027a546c57d4136
http://security.debian.org/pool/updates/main/x/xview/olwm_3.2p1.4-16woody2_i386.deb
Size/MD5 checksum: 127802 c6cc52741c73598aa3fc5e4158ecec0c
http://security.debian.org/pool/updates/main/x/xview/xview-clients_3.2p1.4-16woody2_i386.deb
Size/MD5 checksum: 64396 d7770705890e14eee88d28768a483e5f
http://security.debian.org/pool/updates/main/x/xview/xview-examples_3.2p1.4-16woody2_i386.deb
Size/MD5 checksum: 223156 5f3a95acb70658bfc66df2896e1223d9
http://security.debian.org/pool/updates/main/x/xview/xviewg_3.2p1.4-16woody2_i386.deb
Size/MD5 checksum: 646392 6055e545d592579dd5c012608a464752
http://security.debian.org/pool/updates/main/x/xview/xviewg-dev_3.2p1.4-16woody2_i386.deb
Size/MD5 checksum: 934796 2f3c3c124dc19d5d14aa1dbf54c64784

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/x/xview/olvwm_4.4.3.2p1.4-16woody2_ia64.deb
Size/MD5 checksum: 317404 576da684ffdf28de0b0715fdb4dcdcd3
http://security.debian.org/pool/updates/main/x/xview/olwm_3.2p1.4-16woody2_ia64.deb
Size/MD5 checksum: 220186 316ad06d0819a284884bcb06a4114ff9
http://security.debian.org/pool/updates/main/x/xview/xview-clients_3.2p1.4-16woody2_ia64.deb
Size/MD5 checksum: 95106 2b2e5ec4a072aac2d958e91c8c41c8f9
http://security.debian.org/pool/updates/main/x/xview/xview-examples_3.2p1.4-16woody2_ia64.deb
Size/MD5 checksum: 287570 7b7967de5eedab4b9e34a66fe887a63d
http://security.debian.org/pool/updates/main/x/xview/xviewg_3.2p1.4-16woody2_ia64.deb
Size/MD5 checksum: 1079586 7200cb22efc8b346e4eaa83ec1897f74
http://security.debian.org/pool/updates/main/x/xview/xviewg-dev_3.2p1.4-16woody2_ia64.deb
Size/MD5 checksum: 1482648 55b93aca51484c25e38c6a75f716cade

HP Precision architecture:

http://security.debian.org/pool/updates/main/x/xview/olvwm_4.4.3.2p1.4-16woody2_hppa.deb
Size/MD5 checksum: 230118 5282c987f39795033ef181fc52fb0361
http://security.debian.org/pool/updates/main/x/xview/olwm_3.2p1.4-16woody2_hppa.deb
Size/MD5 checksum: 159716 57a57cc876a7d51f9e15e0dab24fc373
http://security.debian.org/pool/updates/main/x/xview/xview-clients_3.2p1.4-16woody2_hppa.deb
Size/MD5 checksum: 77650 41d67effdaac9bbfae93b35c2d1a99e8
http://security.debian.org/pool/updates/main/x/xview/xview-examples_3.2p1.4-16woody2_hppa.deb
Size/MD5 checksum: 257698 e49c1614bb05f896d4c0d2ea64567710
http://security.debian.org/pool/updates/main/x/xview/xviewg_3.2p1.4-16woody2_hppa.deb
Size/MD5 checksum: 830414 f0544907dd17dce7fbf5e0b2c48f044c
http://security.debian.org/pool/updates/main/x/xview/xviewg-dev_3.2p1.4-16woody2_hppa.deb
Size/MD5 checksum: 1221342 e8f00721366a9bb20f2c65cc9ff51849

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/x/xview/olvwm_4.4.3.2p1.4-16woody2_m68k.deb
Size/MD5 checksum: 174654 e9d4846e4431980b742f8fef19274d95
http://security.debian.org/pool/updates/main/x/xview/olwm_3.2p1.4-16woody2_m68k.deb
Size/MD5 checksum: 121528 27740085ec299dc2f152824242880226
http://security.debian.org/pool/updates/main/x/xview/xview-clients_3.2p1.4-16woody2_m68k.deb
Size/MD5 checksum: 62152 cd34146cd2266f438ffd8dde794244b2
http://security.debian.org/pool/updates/main/x/xview/xview-examples_3.2p1.4-16woody2_m68k.deb
Size/MD5 checksum: 221572 d60602e378f194426fe223311429a76e
http://security.debian.org/pool/updates/main/x/xview/xviewg_3.2p1.4-16woody2_m68k.deb
Size/MD5 checksum: 609756 21606f2051ff57c2feadacd072129b16
http://security.debian.org/pool/updates/main/x/xview/xviewg-dev_3.2p1.4-16woody2_m68k.deb
Size/MD5 checksum: 891654 833ce26f040f64bc4cc3b684416b5c25

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/x/xview/olvwm_4.4.3.2p1.4-16woody2_mips.deb
Size/MD5 checksum: 233608 d1e233b9724bdc330fc65be9b053292c
http://security.debian.org/pool/updates/main/x/xview/olwm_3.2p1.4-16woody2_mips.deb
Size/MD5 checksum: 162770 e792cab975f9a1fc4f1cb1b20548732d
http://security.debian.org/pool/updates/main/x/xview/xview-clients_3.2p1.4-16woody2_mips.deb
Size/MD5 checksum: 73522 7b28384a8a7b0786752af6aed4bde04d
http://security.debian.org/pool/updates/main/x/xview/xview-examples_3.2p1.4-16woody2_mips.deb
Size/MD5 checksum: 242610 a3b5ab6c3fa2586fcd6cc756ed276e6f
http://security.debian.org/pool/updates/main/x/xview/xviewg_3.2p1.4-16woody2_mips.deb
Size/MD5 checksum: 718426 feeba8a97bf24eead7e186f7954adec1
http://security.debian.org/pool/updates/main/x/xview/xviewg-dev_3.2p1.4-16woody2_mips.deb
Size/MD5 checksum: 1152450 3b52fdfd2abcba003a40f62161e97249

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/x/xview/olvwm_4.4.3.2p1.4-16woody2_mipsel.deb
Size/MD5 checksum: 232930 4c7ba7912711277c3bd43e906f182b86
http://security.debian.org/pool/updates/main/x/xview/olwm_3.2p1.4-16woody2_mipsel.deb
Size/MD5 checksum: 162148 5a74c1afae73c463ad735d7b6d95e36c
http://security.debian.org/pool/updates/main/x/xview/xview-clients_3.2p1.4-16woody2_mipsel.deb
Size/MD5 checksum: 73550 f7bfee56646b67b45234b9ff45e686c0
http://security.debian.org/pool/updates/main/x/xview/xview-examples_3.2p1.4-16woody2_mipsel.deb
Size/MD5 checksum: 240548 db21fa02e89c56f2de7650c7c436c72c
http://security.debian.org/pool/updates/main/x/xview/xviewg_3.2p1.4-16woody2_mipsel.deb
Size/MD5 checksum: 713016 546f6ffb970b55020066d425b57b10b1
http://security.debian.org/pool/updates/main/x/xview/xviewg-dev_3.2p1.4-16woody2_mipsel.deb
Size/MD5 checksum: 1148214 597d06b001a2840e3b833b0fbdceee8c

PowerPC architecture:

http://security.debian.org/pool/updates/main/x/xview/olvwm_4.4.3.2p1.4-16woody2_powerpc.deb
Size/MD5 checksum: 203952 e12cef8460e96bb8442e802a7dadfd2f
http://security.debian.org/pool/updates/main/x/xview/olwm_3.2p1.4-16woody2_powerpc.deb
Size/MD5 checksum: 141172 a5b5baaf8985cb50f8af76a1f66bdb80
http://security.debian.org/pool/updates/main/x/xview/xview-clients_3.2p1.4-16woody2_powerpc.deb
Size/MD5 checksum: 71612 373ec845cde8c0507a7bb0534550ad0b
http://security.debian.org/pool/updates/main/x/xview/xview-examples_3.2p1.4-16woody2_powerpc.deb
Size/MD5 checksum: 235564 09c30509e8d8197fe408ec7548a8cd72
http://security.debian.org/pool/updates/main/x/xview/xviewg_3.2p1.4-16woody2_powerpc.deb
Size/MD5 checksum: 708600 b4637a98855afa87cd1f0f0852350409
http://security.debian.org/pool/updates/main/x/xview/xviewg-dev_3.2p1.4-16woody2_powerpc.deb
Size/MD5 checksum: 1078698 8502065905a3e47870287397de3ec478

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/x/xview/olvwm_4.4.3.2p1.4-16woody2_s390.deb
Size/MD5 checksum: 196944 52b2322fc1b8449d0621460cc9f148c8
http://security.debian.org/pool/updates/main/x/xview/olwm_3.2p1.4-16woody2_s390.deb
Size/MD5 checksum: 138124 1dee9a95eff97d2efc1a57035da9d519
http://security.debian.org/pool/updates/main/x/xview/xview-clients_3.2p1.4-16woody2_s390.deb
Size/MD5 checksum: 69010 fba4d2583f26b3824935630f1da4211d
http://security.debian.org/pool/updates/main/x/xview/xview-examples_3.2p1.4-16woody2_s390.deb
Size/MD5 checksum: 238726 3d07b2a9aec170e5785dc625501a9247
http://security.debian.org/pool/updates/main/x/xview/xviewg_3.2p1.4-16woody2_s390.deb
Size/MD5 checksum: 718966 be18b0d190dbea53a46ac986d8c9ebed
http://security.debian.org/pool/updates/main/x/xview/xviewg-dev_3.2p1.4-16woody2_s390.deb
Size/MD5 checksum: 996136 df7958201a7d422f838c699b58ce3457

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/x/xview/olvwm_4.4.3.2p1.4-16woody2_sparc.deb
Size/MD5 checksum: 196302 13ac28d455799ff897e7c18d6d7e9162
http://security.debian.org/pool/updates/main/x/xview/olwm_3.2p1.4-16woody2_sparc.deb
Size/MD5 checksum: 139756 d3428077114ef61a236991156daddf13
http://security.debian.org/pool/updates/main/x/xview/xview-clients_3.2p1.4-16woody2_sparc.deb
Size/MD5 checksum: 82644 60d3b85b20b5331408f361265e5cfba6
http://security.debian.org/pool/updates/main/x/xview/xview-examples_3.2p1.4-16woody2_sparc.deb
Size/MD5 checksum: 375160 1aa0dafb2e393a13b9de921c05641448
http://security.debian.org/pool/updates/main/x/xview/xviewg_3.2p1.4-16woody2_sparc.deb
Size/MD5 checksum: 695008 57e61ce2f7d51ca1adbbe80fe5de78f6
http://security.debian.org/pool/updates/main/x/xview/xviewg-dev_3.2p1.4-16woody2_sparc.deb
Size/MD5 checksum: 1031568 e9793f290c3b3aae31168fe0d5ccfa32

These files will probably be moved into the stable distribution on its next update.


Debian Security Advisory DSA 673-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
February 10th, 2005 http://www.debian.org/security/faq


Package : evolution
Vulnerability : integer overflow
Problem-Type : local
Debian-specific: no
CVE ID : CAN-2005-0102
BugTraq ID : 12354

Max Vozeler discovered an integer overflow in a helper application inside of Evolution, a free grouware suite. A local attacker could cause the setuid root helper to execute arbitrary code with elevated privileges.

For the stable distribution (woody) this problem has been fixed in version 1.0.5-1woody2.

For the unstable distribution (sid) this problem has been fixed in version 2.0.3-1.2.

We recommend that you upgrade your evolution package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody


Source archives:

http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0.5-1woody2.dsc
Size/MD5 checksum: 990 135eae823f6a0159a5f7ec6bc72c72b0
http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0.5-1woody2.diff.gz
Size/MD5 checksum: 16718 fdcc1244d1cfbe4c297cc49a577491b8
http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0.5.orig.tar.gz
Size/MD5 checksum: 15010672 d2ffe374b453d28f5456db5af0a7983c

Alpha architecture:

http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0.5-1woody2_alpha.deb
Size/MD5 checksum: 10271422 207d01d4b051c5350a6c1952bc5221ee
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_1.0.5-1woody2_alpha.deb
Size/MD5 checksum: 947952 b74d9c65882ae4bafa47d6614a96596c
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0.5-1woody2_alpha.deb
Size/MD5 checksum: 623002 5b864fe6659626050ac55ebf5e8572e0

ARM architecture:

http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0.5-1woody2_arm.deb
Size/MD5 checksum: 9282272 57853c1bd08388274b34399548bff183
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_1.0.5-1woody2_arm.deb
Size/MD5 checksum: 663850 30e04aac4fbcda4e6b709aa1eb378f74
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0.5-1woody2_arm.deb
Size/MD5 checksum: 492650 96a58d81835fe40c118613994898a99f

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0.5-1woody2_i386.deb
Size/MD5 checksum: 8905428 cc4885b6fff4f47cc3b729765454ea3d
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_1.0.5-1woody2_i386.deb
Size/MD5 checksum: 585986 53373ed37020c508d50c7f1c5006e6d3
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0.5-1woody2_i386.deb
Size/MD5 checksum: 470658 615259b21a7c889e8c7203b10e4e7b15

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0.5-1woody2_ia64.deb
Size/MD5 checksum: 11454804 a4545f6efeb590b2602f8b8c44c9072d
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_1.0.5-1woody2_ia64.deb
Size/MD5 checksum: 948252 f24c513391cdbd5cf51e0ec5a01def13
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0.5-1woody2_ia64.deb
Size/MD5 checksum: 771184 2dbb984644f181bd46d996c6f06c2ac2

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0.5-1woody2_m68k.deb
Size/MD5 checksum: 8876466 b47fd595352d5535199dc889d9aa653d
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_1.0.5-1woody2_m68k.deb
Size/MD5 checksum: 578364 821686bde02e2ab5a86a3f07f272af26
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0.5-1woody2_m68k.deb
Size/MD5 checksum: 483950 0927332469d079b3118ff012038b2865

PowerPC architecture:

http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0.5-1woody2_powerpc.deb
Size/MD5 checksum: 9339162 e0df2bad032a3a996981b3483223f0f0
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_1.0.5-1woody2_powerpc.deb
Size/MD5 checksum: 680544 be4b5ade6dcbe9264d30becd3f3789e1
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0.5-1woody2_powerpc.deb
Size/MD5 checksum: 511292 2bcda2165950f94d01630b13cb1264d1

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0.5-1woody2_s390.deb
Size/MD5 checksum: 9219484 065504345356c2993a8ff479c7ac4653
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_1.0.5-1woody2_s390.deb
Size/MD5 checksum: 640874 627f5efbeccefd384ae0335dd784c82b
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0.5-1woody2_s390.deb
Size/MD5 checksum: 522850 d7055f0f6a273a52cd09fd783f88c525

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0.5-1woody2_sparc.deb
Size/MD5 checksum: 9393318 4325f6d1bccd22cda371be7dd0a3add8
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_1.0.5-1woody2_sparc.deb
Size/MD5 checksum: 670336 f58f241480dbdd3b6f673fb038e100d4
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0.5-1woody2_sparc.deb
Size/MD5 checksum: 510008 adc53f31cc22856e321f2e200a4f0d20

These files will probably be moved into the stable distribution on its next update.


Debian Security Advisory DSA 674-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
February 10th, 2005 http://www.debian.org/security/faq


Package : mailman
Vulnerability : cross-site scripting, directory traversal
Problem-Type : remote
Debian-specific: no
CVE ID : CAN-2004-1177 CAN-2005-0202

Two security related problems have been discovered in mailman, web-based GNU mailing list manager. The Common Vulnerabilities and Exposures project identifies the following problems:

CAN-2004-1177

Florian Weimer discovered a cross-site scripting vulnerability in mailman's automatically generated error messages. An attacker could craft an URL containing JavaScript (or other content embedded into HTML) which triggered a mailman error page that would include the malicious code verbatim.

CAN-2005-0202

Several listmasters have noticed unauthorised access to archives of private lists and the list configuration itself, including the users passwords. Administrators are advised to check the webserver logfiles for requests that contain "/...../" and the path to the archives or cofiguration. This does only seem to affect installations running on web servers that do not strip slashes, such as Apache 1.3.

For the stable distribution (woody) these problems have been fixed in version 2.0.11-1woody9.

For the unstable distribution (sid) these problems have been fixed in version 2.1.5-6.

We recommend that you upgrade your mailman package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody


Source archives:

http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11-1woody9.dsc
Size/MD5 checksum: 595 774821799ef4968703a7e44ed9bbf648
http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11-1woody9.diff.gz
Size/MD5 checksum: 32974 3987fa82ba9a2fe22f0a8f131acbca33
http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11.orig.tar.gz
Size/MD5 checksum: 415129 915264cb1ac8d7b78ea9eff3ba38ee04

Alpha architecture:

http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11-1woody9_alpha.deb
Size/MD5 checksum: 461524 5080358514f761e483b13fb4e369847a

ARM architecture:

http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11-1woody9_arm.deb
Size/MD5 checksum: 459168 7c5ed235d7c1520f08a98a4f39d0a9bf

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11-1woody9_i386.deb
Size/MD5 checksum: 452242 cbde3d89ad2f09776c1f498f22858919

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11-1woody9_ia64.deb
Size/MD5 checksum: 462126 eb6151c02a2992afd21a6e04fecd75a5

HP Precision architecture:

http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11-1woody9_hppa.deb
Size/MD5 checksum: 459788 5e6bcc87fbe00e4825ff25b9a8dd2fcd

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11-1woody9_m68k.deb
Size/MD5 checksum: 459270 932ff0948e56d6507c296323533a360f

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11-1woody9_mips.deb
Size/MD5 checksum: 459832 f049c56c07a33b4299241a459b832a1a

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11-1woody9_mipsel.deb
Size/MD5 checksum: 459964 2e0d7c83ace834ab970265e6ff61a6ea

PowerPC architecture:

http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11-1woody9_powerpc.deb
Size/MD5 checksum: 460084 d32a6a4122bd26451ab40aa3da95711b

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11-1woody9_s390.deb
Size/MD5 checksum: 460116 7b727e56ca3cbf29dbbe147eadd3fec7

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11-1woody9_sparc.deb
Size/MD5 checksum: 464776 64bfb2a76c42b520f4fcd343f695701b

These files will probably be moved into the stable distribution on its next update.


Debian Security Advisory DSA 675-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
February 10th, 2005 http://www.debian.org/security/faq


Package : hztty
Vulnerability : privilege escalation
Problem-Type : local
Debian-specific: no
CVE ID : CAN-2005-0019

Erik Sjölund discovered that hztty, a converter for GB, Big5 and zW/HZ Chinese encodings in a tty session, can be triggered to execute arbitrary commands with group utmp privileges.

For the stable distribution (woody) this problem has been fixed in version 2.0-5.2woody2.

For the unstable distribution (sid) this problem has been fixed in version 2.0-6.1.

We recommend that you upgrade your hztty package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody


Source archives:

http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2woody2.dsc
Size/MD5 checksum: 560 921462207b6301fc73d8d2613fbaa856
http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2woody2.diff.gz
Size/MD5 checksum: 4158 910c17cb2807c3cd7d2df62d28f016a5
http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0.orig.tar.gz
Size/MD5 checksum: 229189 7ec5907ad55825780274b8a77b217e21

Alpha architecture:

http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2woody2_alpha.deb
Size/MD5 checksum: 153974 56ea5146bfcbed6392913a2dd697ac4d

ARM architecture:

http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2woody2_arm.deb
Size/MD5 checksum: 149808 a509091afb9f413571030158d8e172d8

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2woody2_i386.deb
Size/MD5 checksum: 149432 b5b290876059e43bf376d3f22546ad06

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2woody2_ia64.deb
Size/MD5 checksum: 157178 652c2a0a544458bca793e3b26fe64cdc

HP Precision architecture:

http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2woody2_hppa.deb
Size/MD5 checksum: 153452 ca39d351f20620a31679b21312bf5d57

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2woody2_m68k.deb
Size/MD5 checksum: 149214 b2a2faee53606c7a2599da89e7dc0779

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2woody2_mips.deb
Size/MD5 checksum: 152704 2c94a83690bfaf39d26d5dadddfdd63e

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2woody2_mipsel.deb
Size/MD5 checksum: 152788 3ef6e11ca5cec6b8e077c22b99552bc5

PowerPC architecture:

http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2woody2_powerpc.deb
Size/MD5 checksum: 150376 a9742687aec8d26f95bef974bb4de317

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2woody2_s390.deb
Size/MD5 checksum: 151002 7607b570894e11c9d3eeb8c84bf5e009

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2woody2_sparc.deb
Size/MD5 checksum: 153880 3b8cc02ca85fcb1add110a01c700446f

These files will probably be moved into the stable distribution on its next update.


For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show ' and http://packages.debian.org/

Fedora Core


Fedora Update Notification
FEDORA-2005-131
2005-02-10

Product : Fedora Core 2
Name : mailman
Version : 2.1.5
Release : 8.fc2
Summary : Mailing list manager with built in Web access.

Description :
Mailman is software to help manage email discussion lists, much like Majordomo and Smartmail. Unlike most similar products, Mailman gives each mailing list a webpage, and allows users to subscribe, unsubscribe, etc. over the Web. Even the list manager can administer his or her list entirely from the Web. Mailman also integrates most things people want to do with mailing lists, including archiving, mail <-> news gateways, and so on.

Documentation can be found in: /usr/share/doc/mailman-2.1.5


Update Information:

There is a critical security flaw in Mailman 2.1.5 which will allow attackers to read arbitrary files.

The extent of the vulnerability depends on what version of Apache (httpd) you are running, and (possibly) how you have configured your web server. It is believed the vulnerability is not available when Mailman is paired with a version of Apache >= 2.0, however earlier versions of Apache, e.g. version 1.3, will allow the exploit when executing a Mailman CGI script. All versions of Fedora have shipped with the later 2.0 version of Apache and thus if you are running a Fedora release you are not likely to be vulnerable to the exploit unless you have explicitly downgraded the version of your web server. However, installing this version of mailman with a security patch represents a prudent safeguard.

This issue has been assigned CVE number CAN-2005-0202.

The bug report associated with this is: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=147343

The errata associated with this for RHEL releases is: http://rhn.redhat.com/errata/RHSA-2005-136.html

For additional piece of mind, it is recommended that you regenerate your list member passwords. Instructions on how to do this, and more information about this vulnerability are available here:

http://www.list.org/security.html


  • Tue Feb 08 2005 John Dennis - 3:2.1.5-8.fc2
    • fix security vulnerability CAN-2005-0202, errata RHSA-2005:136, bug #147343

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

4664674e6a2f8cf94457f87541f6fdee SRPMS/mailman-2.1.5-8.fc2.src.rpm
c66f11090b5c284d5e5d0b804e844788 x86_64/mailman-2.1.5-8.fc2.x86_64.rpm
9f79a60e105043526ea9fe0b951c4310 x86_64/debug/mailman-debuginfo-2.1.5-8.fc2.x86_64.rpm
c9537949ed7ee6c9a96316d72277bbe4 i386/mailman-2.1.5-8.fc2.i386.rpm
52e1f9a0ec60bc34c84f52f8442355ac i386/debug/mailman-debuginfo-2.1.5-8.fc2.i386.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.



Fedora Update Notification
FEDORA-2005-132
2005-02-10

Product : Fedora Core 3
Name : mailman
Version : 2.1.5
Release : 30.fc3
Summary : Mailing list manager with built in Web access.

Description :
Mailman is software to help manage email discussion lists, much like Majordomo and Smartmail. Unlike most similar products, Mailman gives each mailing list a webpage, and allows users to subscribe, unsubscribe, etc. over the Web. Even the list manager can administer his or her list entirely from the Web. Mailman also integrates most things people want to do with mailing lists, including archiving, mail <-> news gateways, and so on.

Documentation can be found in: /usr/share/doc/mailman-2.1.5


Update Information:

There is a critical security flaw in Mailman 2.1.5 which will allow attackers to read arbitrary files.

The extent of the vulnerability depends on what version of Apache (httpd) you are running, and (possibly) how you have configured your web server. It is believed the vulnerability is not available when Mailman is paired with a version of Apache >= 2.0, however earlier versions of Apache, e.g. version 1.3, will allow the exploit when executing a Mailman CGI script. All versions of Fedora have shipped with the later 2.0 version of Apache and thus if you are running a Fedora release you are not likely to be vulnerable to the exploit unless you have explicitly downgraded the version of your web server. However, installing this version of mailman with a security patch represents a prudent safeguard.

This issue has been assigned CVE number CAN-2005-0202.

The bug report associated with this is: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=147343

The errata associated with this for RHEL releases is: http://rhn.redhat.com/errata/RHSA-2005-136.html

For additional piece of mind, it is recommended that you regenerate your list member passwords. Instructions on how to do this, and more information about this vulnerability are available here:

http://www.list.org/security.html


  • Tue Feb 08 2005 John Dennis - 3:2.1.5-30.fc3
    • fix security vulnerability CAN-2005-0202, errata RHSA-2005:137, bug #147343
  • Tue Nov 09 2004 John Dennis 3:2.1.5-29.fc3
    • fix bug #137863, buildroot path in .pyc files
  • Mon Nov 08 2004 John Dennis 3:2.1.5-27
    • rebuild to fix bug #137863, python embeds build root in .pyc files

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

457b27f2f15c18b8de0e5fcff977d171 SRPMS/mailman-2.1.5-30.fc3.src.rpm
da424d3d5227650d843654acb22e23c3 x86_64/mailman-2.1.5-30.fc3.x86_64.rpm
e408bc622edf77f04680ead0cdae36cf x86_64/debug/mailman-debuginfo-2.1.5-30.fc3.x86_64.rpm
ec264fec376555f5af505f9b320020c6 i386/mailman-2.1.5-30.fc3.i386.rpm
fad64f3280cfdb4fcdd4520cf79a16b9 i386/debug/mailman-debuginfo-2.1.5-30.fc3.i386.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.



Fedora Update Notification
FEDORA-2005-139
2005-02-10

Product : Fedora Core 2
Name : mod_python
Version : 3.1.3
Release : 1.fc2.2
Summary : An embedded Python interpreter for the Apache Web server.

Description :
Mod_python is a module that embeds the Python language interpreter within the server, allowing Apache handlers to be written in Python.

Mod_python brings together the versatility of Python and the power of the Apache Web server for a considerable boost in flexibility and performance over the traditional CGI approach.


Update Information:

Graham Dumpleton discovered a flaw affecting the publisher handler of mod_python, used to make objects inside modules callable via URL. A remote user could visit a carefully crafted URL that would gain access to objects that should not be visible, leading to an information leak. The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the name CAN-2005-0088 to this issue.

This update includes a patch which fixes this issue.


* Mon Jan 31 2005 Joe Orton <jorton@redhat.com> 3.1.3-1.fc2.2
  • add security fix for CVE CAN-2005-0088 (#146656)

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

cf23151b04a255effb2a138aaceb94f6 SRPMS/mod_python-3.1.3-1.fc2.2.src.rpm
59f9678fa03b908065cd3944bf7808a7 x86_64/mod_python-3.1.3-1.fc2.2.x86_64.rpm
d07a9c2cc5a95feb3ff830dd20d25ef5 x86_64/debug/mod_python-debuginfo-3.1.3-1.fc2.2.x86_64.rpm
e660f1f9839de749e7818cdaba49a2fb i386/mod_python-3.1.3-1.fc2.2.i386.rpm
24ff630cfbdbda45808def9370f06231 i386/debug/mod_python-debuginfo-3.1.3-1.fc2.2.i386.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.



Fedora Update Notification
FEDORA-2005-140
2005-02-10

Product : Fedora Core 3
Name : mod_python
Version : 3.1.3
Release : 5.2
Summary : An embedded Python interpreter for the Apache Web server.

Description :
Mod_python is a module that embeds the Python language interpreter within the server, allowing Apache handlers to be written in Python.

Mod_python brings together the versatility of Python and the power of the Apache Web server for a considerable boost in flexibility and performance over the traditional CGI approach.


Update Information:

Graham Dumpleton discovered a flaw affecting the publisher handler of mod_python, used to make objects inside modules callable via URL. A remote user could visit a carefully crafted URL that would gain access to objects that should not be visible, leading to an information leak. The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the name CAN-2005-0088 to this issue.

This update includes a patch which fixes this issue.


* Mon Jan 31 2005 Joe Orton <jorton@redhat.com> 3.1.3-5.2
  • add security fix for CVE CAN-2005-0088 (#146655)

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

2f8f27de0ed294fb0df1dbcc4b459d1b SRPMS/mod_python-3.1.3-5.2.src.rpm
14821a1a3b89506fddc51b338f93a800 x86_64/mod_python-3.1.3-5.2.x86_64.rpm
07653b192939283ac05b094f6963af43 x86_64/debug/mod_python-debuginfo-3.1.3-5.2.x86_64.rpm
5908a986650071f30ab180724d3a461b i386/mod_python-3.1.3-5.2.i386.rpm
24f5c62133e734b1b2b109d3fe19a83b i386/debug/mod_python-debuginfo-3.1.3-5.2.i386.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.


Fedora Legacy


Fedora Legacy Update Advisory

Synopsis: Updated abiword resolves security vulnerabilities
Advisory ID: FLSA:1906
Issue date: 2005-02-08
Product: Red Hat Linux
Keywords: Security
Cross references: https://bugzilla.fedora.us/show_bug.cgi?id=3D1906
CVE Names: CAN-2004-0645



1. Topic:

Updated abiword packages that fix a security vulnerability are now available.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - i386
Red Hat Linux 9 - i386

3. Problem description:

AbiWord is a cross-platform, open-source word processor.

A buffer overflow in the wv library included in abiword allows remote attackers to execute arbitrary code via a document with a long DateTime field.

All users are advised to upgrade to these updated packages, which contain a= =20
backported fix and are not vulnerable to this issue.

Fedora Legacy would like to thank Marc Deslauriers for reporting this issue, and Dave Botsch and Marc Deslauriers and preparing updated RPMs.

4. Solution:

Before applying this update, make sure all previously released errata=20 relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory only contains the desired RPMs.

Please note that this update is also available via yum and apt. Many people find this an easier way to apply updates. To use yum issue:

yum update

or to use apt:

apt-get update; apt-get upgrade

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. This assumes that you have yum or apt-get configured for obtaining Fedora Legacy content. Please visit http://www.fedoralegacy.org/docs for directions on how to configure yum and apt-get.

5. Bug IDs fixed:

http://bugzilla.fedora.us - 1906 - CAN-2004-0645-Abiword wv component buffer overflow

6. RPMs required:

Red Hat Linux 7.3:

SRPM:
http://download.fedoralegacy.org/redhat/7.3/updates/SRPMS/abiword-0.99.5-5.legacy.src.rpm

i386:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/abiword-0.99.5-5.legacy.i386.rpm

Red Hat Linux 9:

SRPM:
http://download.fedoralegacy.org/redhat/9/updates/SRPMS/abiword-1.0.4-5.legacy.src.rpm

i386:
http://download.fedoralegacy.org/redhat/9/updates/i386/abiword-1.0.4-5.legacy.i386.rpm

7. Verification:

SHA1 sum Package Name


00dd8f5f01ce6682a351cff89fc7e3ae146ce2fb redhat/7.3/updates/SRPMS/abiword-0.99.5-5.legacy.src.rpm
6fae7b296b25173f3c275e5b6d57e44a1e8dd453 redhat/7.3/updates/i386/abiword-0.99.5-5.legacy.i386.rpm

40ec194cf69f56ee176e6c7bb995a6b34bad5cb2 redhat/9/updates/SRPMS/abiword-1.0.4-5.legacy.src.rpm
fadc8f407110a121ced851d20748c7807f2f71a2 redhat/9/updates/i386/abiword-1.0.4-5.legacy.i386.rpm

These packages are GPG signed by Fedora Legacy for security. Our key is available from http://www.fedoralegacy org/about/security.php

You can verify each package with the following command:

rpm --checksig -v

If you only wish to verify that each package has not been corrupted or=20 tampered with, examine only the sha1sum with the following command:

sha1sum

8. References:

http://www.abisource.com/release-notes/2.0.9.phtml
http://xforce.iss.net/xforce/xfdb/16660
http://www.idefense.com/application/poi/display?id=3D115&type=3Dvulnerabilities&flashstatus=3Dtrue

9. Contact:

The Fedora Legacy security contact is <secnotice@fedoralegacy.org>. More project details at http://www.fedoralegacy.org



Fedora Legacy Update Advisory

Synopsis: Updated libpng resolves security vulnerabilities
Advisory ID: FLSA:1943
Issue date: 2005-02-08
Product: Red Hat Linux Fedora Core
Keywords: Security
Cross references: https://bugzilla.fedora.us/show_bug.cgi?id=3D1943
https://bugzilla.fedora.us/show_bug.cgi?id=3D1550
CVE Names: CVE-2002-1363, CAN-2004-0597, CAN-2004-0598, CAN-2004-0599, CAN-2004-0768



1. Topic:

Updated libpng packages that fix security vulnerabilities are now available.

The libpng package contains a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. PNG is a bit-mapped graphics format similar to the GIF format. PNG was created to replace the GIF format, since GIF uses a patented data compression algorithm.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - i386
Red Hat Linux 9 - i386
Fedora Core 1 - i386

3. Problem description:

During a source code audit, Chris Evans discovered several buffer overflows in libpng. An attacker could create a carefully crafted PNG file in such a way that it would cause an application linked with libpng to execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the name CAN-2004-0597 to these issues.

In addition, this audit discovered a potential NULL pointer dereference in libpng (CAN-2004-0598) and several integer overflow issues (CAN-2004-0599). An attacker could create a carefully crafted PNG file in such a way that it would cause an application linked with libpng to crash when the file was opened by the victim.

These patches also include a more complete fix for the out of bounds memory access flaw (CVE-2002-1363), in which there was a buffer overrun while adding filler bytes to 16-bit RGBA samples, and a similar patch (CAN-2004-0768) that fixes a buffer overrun while adding filler bytes to 16-bit grayscale samples.

All users are advised to update to the updated libpng packages which contain backported security patches and are not vulnerable to these issues.

4. Solution:

Before applying this update, make sure all previously released errata relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory only contains the desired RPMs.

Please note that this update is also available via yum and apt. Many people find this an easier way to apply updates. To use yum issue:

yum update

or to use apt:

apt-get update; apt-get upgrade

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. This assumes that you have yum or apt-get configured for obtaining Fedora Legacy content. Please visit http://www.fedoralegacy.org/docs/ for directions on how to configure yum and apt-get.

5. Bug IDs fixed:

http://bugzilla.fedora.us - 1943 - CAN-2004-0597to0599 libpng buffer overflows

6. RPMs required:

Red Hat Linux 7.3:

SRPM:
http://download.fedoralegacy.org/redhat/7.3/updates/SRPMS/libpng-1.0.15-0.7x.1.legacy.src.rpm

i386:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/libpng-1.0.15-0.7x.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/libpng-devel-1.0.15-0.7x.1.legacy.i386.rpm

Red Hat Linux 9:

SRPM:
http://download.fedoralegacy.org/redhat/9/updates/SRPMS/libpng-1.2.2-20.3.legacy.src.rpm
http://download.fedoralegacy.org/redhat/9/updates/SRPMS/libpng10-1.0.15-0.9.1.legacy.src.rpm

i386:=20
http://download.fedoralegacy.org/redhat/9/updates/i386/libpng10-1.0.15-0.9.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/libpng10-devel-1.0.15-0.9.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/libpng-1.2.2-20.3.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/libpng-devel-1.2.2-20.3.legacy.i386.rpm

Fedora Core 1

SRPM:
http://download.fedoralegacy.org/fedora/1/updates/SRPMS/libpng-1.2.5-7.1.legacy.src.rpm
http://download.fedoralegacy.org/fedora/1/updates/SRPMS/libpng10-1.0.15-7.1.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/1/updates/i386/libpng10-1.0.15-7.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/libpng10-devel-1.0.15-7.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/libpng-1.2.5-7.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/libpng-devel-1.2.5-7.1.legacy.i386.rpm

7. Verification:

SHA1 sum Package Name


e291de4ff9cfdb558b38722a12481c3807f21983 redhat/7.3/updates/SRPMS/libpng-1.0.15-0.7x.1.legacy.src.rpm
1c286b40e2ad76146a9a4480e9db26bc04aaadb7 redhat/7.3/updates/i386/libpng-1.0.15-0.7x.1.legacy.i386.rpm
0dc1beac1fa548eeb4d59fab754c4b42e05ff541 redhat/7.3/updates/i386/libpng-devel-1.0.15-0.7x.1.legacy.i386.rpm

cdd4dd5844581c8aa9b16e9738f9529f77a9804d redhat/9/updates/SRPMS/libpng10-1.0.15-0.9.1.legacy.src.rpm
be705f7823d379c5c99f88f4b2c2364e333379cb redhat/9/updates/SRPMS/libpng-1.2.2-20.3.legacy.src.rpm
d71f34a57a80386cdbe2bc9738f0e2b778c639e7 redhat/9/updates/i386/libpng10-1.0.15-0.9.1.legacy.i386.rpm
e89ca650e1839e4ad3155097cf6c70e239befe7c redhat/9/updates/i386/libpng10-devel-1.0.15-0.9.1.legacy.i386.rpm
7cd0d3d36280449e6cb0fe1b4478d14701ec11c5 redhat/9/updates/i386/libpng-1.2.2-20.3.legacy.i386.rpm
36ddbdaac4cc3ec1f9e23521a0ad1029714a80a2 redhat/9/updates/i386/libpng-devel-1.2.2-20.3.legacy.i386.rpm

8c0ab7f220cfd7022f682772098d5efbd2811526 fedora/1/updates/SRPMS/libpng10-1.0.15-7.1.legacy.src.rpm
6a6643b6e1f01e6f8540f36e9a7518c44826a783 fedora/1/updates/SRPMS/libpng-1.2.5-7.1.legacy.src.rpm
0afca5b729899b1fedeed263ddd2ac7aa506eb5b fedora/1/updates/i386/libpng10-1.0.15-7.1.legacy.i386.rpm
6a7a6ecaa0435e2254e48bc5ea4c2d1724d5b160 fedora/1/updates/i386/libpng10-devel-1.0.15-7.1.legacy.i386.rpm
8e28d39029ff88510d3899c2848273a76b6e71f4 fedora/1/updates/i386/libpng-1.2.5-7.1.legacy.i386.rpm
405443b2e0e56b3d5e5f3f9b6a89bd3a83c24afb fedora/1/updates/i386/libpng-devel-1.2.5-7.1.legacy.i386.rpm

These packages are GPG signed by Fedora Legacy for security. Our key is available from http://www.fedoralegacy org/about/security.php

You can verify each package with the following command:

rpm --checksig -v

If you only wish to verify that each package has not been corrupted or tampered with, examine only the sha1sum with the following command:

sha1sum


8. References:

https://rhn.redhat.com/errata/RHSA-2004-402.html

9. Contact:

The Fedora Legacy security contact is <secnotice@fedoralegacy.org>. More project details at http://www.fedoralegacy.org


Gentoo Linux


Gentoo Linux Security Advisory GLSA 200502-11

http://security.gentoo.org/


Severity: Normal
Title: Mailman: Directory traversal vulnerability
Date: February 10, 2005
Bugs: #81109
ID: 200502-11


Synopsis

Mailman fails to properly sanitize input, leading to information disclosure.

Background

Mailman is a Python-based mailing list server with an extensive web interface.

Affected packages


Package / Vulnerable / Unaffected
1 net-mail/mailman < 2.1.5-r4 >= 2.1.5-r4

Description

Mailman contains an error in private.py which fails to properly sanitize input paths.

Impact

An attacker could exploit this flaw to obtain arbitrary files on the web server.

Workaround

There is no known workaround at this time.

Resolution

All Mailman users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=net-mail/mailman-2.1.5-r4"

References

[ 1 ] Full Disclosure Announcement

http://lists.netsys.com/pipermail/full-disclosure/2005-February/031562.html [ 2 ] CAN-2005-0202

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0202

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200502-11.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0

Mandrakelinux


Mandrakelinux Security Update Advisory


Package name: MySQL
Advisory ID: MDKSA-2005:036
Date: February 10th, 2005
Affected versions: 10.0, 10.1, Corporate 3.0, Corporate Server 2.1


Problem Description:

A temporary file vulnerability in the mysqlaccess script in MySQL was discovered by Javier Fernandez-Sanguino Pena. This flaw could allow an unprivileged user to let root overwrite arbitrary files via a symlink attack. It could also be used to view the contents of a temporary file which could contain sensitive information.

The updated packages have been patched to prevent these problems.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0004


Updated Packages:

Mandrakelinux 10.0:
50574ec1c70d78d0b4f7da1bd7d7d380 10.0/RPMS/libmysql12-4.0.18-1.3.100mdk.i586.rpm
25710d5c4844ca1d123944ac0861bc0f 10.0/RPMS/libmysql12-devel-4.0.18-1.3.100mdk.i586.rpm
8c056d72fa1d02c231ed321bfa0108af 10.0/RPMS/libqt3-mysql-3.2.3-19.6.100mdk.i586.rpm
94dcd13a633ef96a31b0f7da452afed1 10.0/RPMS/MySQL-4.0.18-1.3.100mdk.i586.rpm
8df8f4a9d6cdce677d630ac134081898 10.0/RPMS/MySQL-Max-4.0.18-1.3.100mdk.i586.rpm
bbe03440aa22bdf38204607f290915f8 10.0/RPMS/MySQL-bench-4.0.18-1.3.100mdk.i586.rpm
64015efdb83f79c9a1fbedce63ea1f78 10.0/RPMS/MySQL-client-4.0.18-1.3.100mdk.i586.rpm
5481c9bbc5daf2632c36f6dc7d2521c0 10.0/RPMS/MySQL-common-4.0.18-1.3.100mdk.i586.rpm
2f8f209e44f7fbe18395e6e815e8cc5b 10.0/SRPMS/MySQL-4.0.18-1.3.100mdk.src.rpm

Mandrakelinux 10.0/AMD64:
38bc4a1e8a79ec174569dfdfa98f022d amd64/10.0/RPMS/lib64mysql12-4.0.18-1.3.100mdk.amd64.rpm
6c3eea8562548a88e80d98c40af4bc68 amd64/10.0/RPMS/lib64mysql12-devel-4.0.18-1.3.100mdk.amd64.rpm
48feba0f77d5ead04e2226f50595494d amd64/10.0/RPMS/lib64qt3-mysql-3.2.3-19.6.100mdk.amd64.rpm
7bcddb4ae89e5f1934f272a4c4910dbe amd64/10.0/RPMS/MySQL-4.0.18-1.3.100mdk.amd64.rpm
c503b7cefabdfa0c49b658037190c6c5 amd64/10.0/RPMS/MySQL-Max-4.0.18-1.3.100mdk.amd64.rpm
3815a6a61e37a70e63c3794c6d4ab807 amd64/10.0/RPMS/MySQL-bench-4.0.18-1.3.100mdk.amd64.rpm
aaebba0d883e9abbb2bfa58b19b1a57e amd64/10.0/RPMS/MySQL-client-4.0.18-1.3.100mdk.amd64.rpm
353006ae3541483c666416679841c1f6 amd64/10.0/RPMS/MySQL-common-4.0.18-1.3.100mdk.amd64.rpm
2f8f209e44f7fbe18395e6e815e8cc5b amd64/10.0/SRPMS/MySQL-4.0.18-1.3.100mdk.src.rpm

Mandrakelinux 10.1:
bd3a35f3ba7440aa79f3940f20422b19 10.1/RPMS/libmysql12-4.0.20-3.2.101mdk.i586.rpm
c3fd2f49a144ec27d8bad808a89cbb31 10.1/RPMS/libmysql12-devel-4.0.20-3.2.101mdk.i586.rpm
3e2967952b1ddaa05561bf17b88fe24d 10.1/RPMS/libqt3-mysql-3.3.3-27.1.101mdk.i586.rpm
f6b68d795599ec5a51b2c3c5cf3ada86 10.1/RPMS/MySQL-4.0.20-3.2.101mdk.i586.rpm
514e962fbfb48e2d6e18baf8c6ad86b8 10.1/RPMS/MySQL-Max-4.0.20-3.2.101mdk.i586.rpm
71624f3454fa8892b123104e1e9e7260 10.1/RPMS/MySQL-bench-4.0.20-3.2.101mdk.i586.rpm
06fde75abed6b50838161eb95e375135 10.1/RPMS/MySQL-client-4.0.20-3.2.101mdk.i586.rpm
fd3f8ed0bea7dee2e20fdf09a26c8715 10.1/RPMS/MySQL-common-4.0.20-3.2.101mdk.i586.rpm
195735730d0535bef4dbe1fbb5c5cec7 10.1/SRPMS/MySQL-4.0.20-3.2.101mdk.src.rpm

Mandrakelinux 10.1/X86_64:
841beab56f637c1148348685b39daf6f x86_64/10.1/RPMS/lib64mysql12-4.0.20-3.2.101mdk.x86_64.rpm
7aa4b9a407252d5a333cd25b2f11d39d x86_64/10.1/RPMS/lib64mysql12-devel-4.0.20-3.2.101mdk.x86_64.rpm
ec4bb6dd0693f48a5960d30d48496839 x86_64/10.1/RPMS/lib64qt3-mysql-3.3.3-27.1.101mdk.x86_64.rpm
3e2967952b1ddaa05561bf17b88fe24d x86_64/10.1/RPMS/libqt3-mysql-3.3.3-27.1.101mdk.i586.rpm
4683c29eac58dfea8c5d2d0aa7afc5e7 x86_64/10.1/RPMS/MySQL-4.0.20-3.2.101mdk.x86_64.rpm
31a8ca40e7da9f3b311bff981c3f5614 x86_64/10.1/RPMS/MySQL-Max-4.0.20-3.2.101mdk.x86_64.rpm
2783b732a61d2eb87422daf0f18913b7 x86_64/10.1/RPMS/MySQL-bench-4.0.20-3.2.101mdk.x86_64.rpm
f034044d8fda605eeba6db49da02c4c4 x86_64/10.1/RPMS/MySQL-client-4.0.20-3.2.101mdk.x86_64.rpm
ef4ce84d6cc648cf3e3cc938bafa8918 x86_64/10.1/RPMS/MySQL-common-4.0.20-3.2.101mdk.x86_64.rpm
195735730d0535bef4dbe1fbb5c5cec7 x86_64/10.1/SRPMS/MySQL-4.0.20-3.2.101mdk.src.rpm

Corporate Server 2.1:
f4cd6b3d833a0a5d190b7d5defd6f18a corporate/2.1/RPMS/libmysql10-3.23.56-1.7.C21mdk.i586.rpm
1e2afd78697dfe26bfc9f5327f2f3108 corporate/2.1/RPMS/libmysql10-devel-3.23.56-1.7.C21mdk.i586.rpm
a6f2168c5faffff7872ba6a5c4bc2dd2 corporate/2.1/RPMS/MySQL-3.23.56-1.7.C21mdk.i586.rpm
7f41d3536345a283812301a9b1416616 corporate/2.1/RPMS/MySQL-Max-3.23.56-1.7.C21mdk.i586.rpm
c8632bb5f0f31862aa764efe8aedab19 corporate/2.1/RPMS/MySQL-bench-3.23.56-1.7.C21mdk.i586.rpm
81c7febbb3be7b9c2c6f8eba26f6b040 corporate/2.1/RPMS/MySQL-client-3.23.56-1.7.C21mdk.i586.rpm
fbb22ec4f0087ea2df640f2e99786334 corporate/2.1/SRPMS/MySQL-3.23.56-1.7.C21mdk.src.rpm

Corporate Server 2.1/X86_64:
d1c474ac0d94e181d9955f33843ea1e5 x86_64/corporate/2.1/RPMS/libmysql10-3.23.56-1.7.C21mdk.x86_64.rpm
6180ac0c3820243fc97191fc0e388618 x86_64/corporate/2.1/RPMS/libmysql10-devel-3.23.56-1.7.C21mdk.x86_64.rpm
94629c4d41e9e5b041fd87a10f4626c6 x86_64/corporate/2.1/RPMS/MySQL-3.23.56-1.7.C21mdk.x86_64.rpm
7c6e305fbbd13bda3ca09175931452b0 x86_64/corporate/2.1/RPMS/MySQL-Max-3.23.56-1.7.C21mdk.x86_64.rpm
4a5697b1822bae029b07e2f1d1907086 x86_64/corporate/2.1/RPMS/MySQL-bench-3.23.56-1.7.C21mdk.x86_64.rpm
66c8261cd44333d3457331fe65acb8d5 x86_64/corporate/2.1/RPMS/MySQL-client-3.23.56-1.7.C21mdk.x86_64.rpm
fbb22ec4f0087ea2df640f2e99786334 x86_64/corporate/2.1/SRPMS/MySQL-3.23.56-1.7.C21mdk.src.rpm

Corporate 3.0:
2f0f9a15805949a8b1c4f707b495065a corporate/3.0/RPMS/libmysql12-4.0.18-1.3.C30mdk.i586.rpm
96e08808e0abdb36562d9d1326f024fa corporate/3.0/RPMS/libmysql12-devel-4.0.18-1.3.C30mdk.i586.rpm
e64e068fc62211319dbaa20574ec32cf corporate/3.0/RPMS/MySQL-4.0.18-1.3.C30mdk.i586.rpm
18737baa96e918b9319b0f624e8279db corporate/3.0/RPMS/MySQL-Max-4.0.18-1.3.C30mdk.i586.rpm
e002a2b1053995d8e18a43f1472154d6 corporate/3.0/RPMS/MySQL-bench-4.0.18-1.3.C30mdk.i586.rpm
e6ac405500f65b0ab00ea7238218cea7 corporate/3.0/RPMS/MySQL-client-4.0.18-1.3.C30mdk.i586.rpm
35b216ccea7ac198c0e855e89789b0b9 corporate/3.0/RPMS/MySQL-common-4.0.18-1.3.C30mdk.i586.rpm
7fc62e5799ef5dd03aa2cf973dec3220 corporate/3.0/SRPMS/MySQL-4.0.18-1.3.C30mdk.src.rpm

Corporate 3.0/X86_64:
ec3dd6d37697ef1832afd5abc07ef072 x86_64/corporate/3.0/RPMS/lib64mysql12-4.0.18-1.3.C30mdk.x86_64.rpm
486940c54412a6a06ea2985fdd805cc3 x86_64/corporate/3.0/RPMS/lib64mysql12-devel-4.0.18-1.3.C30mdk.x86_64.rpm
48feba0f77d5ead04e2226f50595494d x86_64/corporate/3.0/RPMS/lib64qt3-mysql-3.2.3-19.6.100mdk.amd64.rpm
3ca0207824ba315b9856e363831e8238 x86_64/corporate/3.0/RPMS/MySQL-4.0.18-1.3.C30mdk.x86_64.rpm
64446e7f63df7df74426a47cf2de6625 x86_64/corporate/3.0/RPMS/MySQL-Max-4.0.18-1.3.C30mdk.x86_64.rpm
390c3074eac1aac97b249979fa467741 x86_64/corporate/3.0/RPMS/MySQL-bench-4.0.18-1.3.C30mdk.x86_64.rpm
f9b9bb7f21cdd8d53cbad39f37385143 x86_64/corporate/3.0/RPMS/MySQL-client-4.0.18-1.3.C30mdk.x86_64.rpm
870eac0d47223dcf88ee24072e84dfc3 x86_64/corporate/3.0/RPMS/MySQL-common-4.0.18-1.3.C30mdk.x86_64.rpm
7fc62e5799ef5dd03aa2cf973dec3220 x86_64/corporate/3.0/SRPMS/MySQL-4.0.18-1.3.C30mdk.src.rpm


To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandrakesoft for security. You can obtain the GPG public key of the Mandrakelinux Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandrakelinux at:

http://www.mandrakesoft.com/security/advisories

If you want to report vulnerabilities, please contact

security_linux-mandrake.com

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Linux Mandrake Security Team


Mandrakelinux Security Update Advisory


Package name: python
Advisory ID: MDKSA-2005:035
Date: February 10th, 2005
Affected versions: 10.0, 10.1, 9.2, Corporate 3.0, Corporate Server 2.1


Problem Description:

A flaw in the python language was found by the development team. The SimpleXMLRPCServer library module could permit remote attackers unintended access to internals of the registered object or it's module, or possibly even other modules. This only affects python XML-RPC servers that use the register_instance() method to register an object without a _dispatch() method. Servers that only use the register_function() method are not affected.

The updated packages have been patched to prevent these problems.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0089
http://www.python.org/security/PSF-2005-001/


Updated Packages:

Mandrakelinux 10.0:
8beb720d0eae578c43ca467f9a1af0f0 10.0/RPMS/libpython2.3-2.3.3-2.1.100mdk.i586.rpm
ef66feb9f7b7c165064fc9c7835cdb11 10.0/RPMS/libpython2.3-devel-2.3.3-2.1.100mdk.i586.rpm
87538481a96b416bacaf24ba8e3f1cd2 10.0/RPMS/python-2.3.3-2.1.100mdk.i586.rpm
8d1970207ff9e2476aafb904bc2358b8 10.0/RPMS/python-base-2.3.3-2.1.100mdk.i586.rpm
f00152d2ac6dbee6c49d804bcb1d4dcd 10.0/RPMS/python-docs-2.3.3-2.1.100mdk.i586.rpm
01b64afd5de30bd99df9e73da2f97ef9 10.0/RPMS/tkinter-2.3.3-2.1.100mdk.i586.rpm
d360151e4588581e7d47c273e8a28abe 10.0/SRPMS/python-2.3.3-2.1.100mdk.src.rpm

Mandrakelinux 10.0/AMD64:
9fdbab4d563592fe73e221d46d0088d8 amd64/10.0/RPMS/lib64python2.3-2.3.3-2.1.100mdk.amd64.rpm
0140b944f6f09185236c1e1026eb4edd amd64/10.0/RPMS/lib64python2.3-devel-2.3.3-2.1.100mdk.amd64.rpm
0214045b468514f641c912aed17184ff amd64/10.0/RPMS/python-2.3.3-2.1.100mdk.amd64.rpm
ed2373ac815649687a0775fe675a23f2 amd64/10.0/RPMS/python-base-2.3.3-2.1.100mdk.amd64.rpm
8078413cf31c8e248f41b2a1435cd172 amd64/10.0/RPMS/python-docs-2.3.3-2.1.100mdk.amd64.rpm
d60fc339f824778e9cdc4c4ad71e90de amd64/10.0/RPMS/tkinter-2.3.3-2.1.100mdk.amd64.rpm
d360151e4588581e7d47c273e8a28abe amd64/10.0/SRPMS/python-2.3.3-2.1.100mdk.src.rpm

Mandrakelinux 10.1:
f2b6b56ef68da39ece17679c19974f5a 10.1/RPMS/libpython2.3-2.3.4-6.1.101mdk.i586.rpm
5b5dfa7242a64c974cb9924258db0b7c 10.1/RPMS/libpython2.3-devel-2.3.4-6.1.101mdk.i586.rpm
fd96e90717ac3f12ca2547cd131ab647 10.1/RPMS/python-2.3.4-6.1.101mdk.i586.rpm
d1be4187307bcec359fce591a42cb735 10.1/RPMS/python-base-2.3.4-6.1.101mdk.i586.rpm
44317eba795d6080caa84dc5110e6b93 10.1/RPMS/python-docs-2.3.4-6.1.101mdk.i586.rpm
28997aa409843358d58fac301705d577 10.1/RPMS/tkinter-2.3.4-6.1.101mdk.i586.rpm
c5f72acab1469acca0c82d147a5f9d53 10.1/SRPMS/python-2.3.4-6.1.101mdk.src.rpm

Mandrakelinux 10.1/X86_64:
e01470376f25024cdba630bf0f262601 x86_64/10.1/RPMS/lib64python2.3-2.3.4-6.1.101mdk.x86_64.rpm
373bc691f9863209895a70d3fd6b3a0e x86_64/10.1/RPMS/lib64python2.3-devel-2.3.4-6.1.101mdk.x86_64.rpm
2f60f873c8ff1e4b263f31245dd552ec x86_64/10.1/RPMS/python-2.3.4-6.1.101mdk.x86_64.rpm
cba9bd7fedc1d0baa19e50d537630758 x86_64/10.1/RPMS/python-base-2.3.4-6.1.101mdk.x86_64.rpm
e075976730591898d3384407d2881a1b x86_64/10.1/RPMS/python-docs-2.3.4-6.1.101mdk.x86_64.rpm
5107f719c5019d6fb106e9b7994609ca x86_64/10.1/RPMS/tkinter-2.3.4-6.1.101mdk.x86_64.rpm
c5f72acab1469acca0c82d147a5f9d53 x86_64/10.1/SRPMS/python-2.3.4-6.1.101mdk.src.rpm

Corporate Server 2.1:
4d5f7f0b4afe43618dd0bc498ff8d3e0 corporate/2.1/RPMS/libpython2.2-2.2.1-14.5.C21mdk.i586.rpm
f8867fc6df620f53119e5615d2fa22f9 corporate/2.1/RPMS/libpython2.2-devel-2.2.1-14.5.C21mdk.i586.rpm
bf6059fdb24ea5d3dbe8dce8d072e455 corporate/2.1/RPMS/python-2.2.1-14.5.C21mdk.i586.rpm
da122b29af94b70fefd7925fc4609905 corporate/2.1/RPMS/python-base-2.2.1-14.5.C21mdk.i586.rpm
ae65a5f9311fc6bdb4cc3da19e3e6cb2 corporate/2.1/RPMS/python-docs-2.2.1-14.5.C21mdk.i586.rpm
1c3cf551abd546c49db7564e7a066494 corporate/2.1/RPMS/tkinter-2.2.1-14.5.C21mdk.i586.rpm
57971ed8b6aa2b2aa0ae008d6f98cdee corporate/2.1/SRPMS/python-2.2.1-14.5.C21mdk.src.rpm

Corporate Server 2.1/X86_64:
d0942542d1e4830db22e0328f92c75ee x86_64/corporate/2.1/RPMS/libpython2.2-2.2.1-14.5.C21mdk.x86_64.rpm
1da495831b1b25fe84fc30473b216669 x86_64/corporate/2.1/RPMS/libpython2.2-devel-2.2.1-14.5.C21mdk.x86_64.rpm
a174a8cd8d0c63fa468816163cd97706 x86_64/corporate/2.1/RPMS/python-2.2.1-14.5.C21mdk.x86_64.rpm
8f8dcf92d7f0bebdb9866a2e92726344 x86_64/corporate/2.1/RPMS/python-base-2.2.1-14.5.C21mdk.x86_64.rpm
24fe305bc5de288af4b760f3e26dba5d x86_64/corporate/2.1/RPMS/python-docs-2.2.1-14.5.C21mdk.x86_64.rpm
a636d96a37886c29bc85bc1e0ddb9442 x86_64/corporate/2.1/RPMS/tkinter-2.2.1-14.5.C21mdk.x86_64.rpm
57971ed8b6aa2b2aa0ae008d6f98cdee x86_64/corporate/2.1/SRPMS/python-2.2.1-14.5.C21mdk.src.rpm

Corporate 3.0:
2aaeb1239ffaa4cad46f0d9c4265032b corporate/3.0/RPMS/libpython2.3-2.3.3-2.1.C30mdk.i586.rpm
6822876c43310eccf3a5a56c43a1c63a corporate/3.0/RPMS/libpython2.3-devel-2.3.3-2.1.C30mdk.i586.rpm
1e4e4af576af783b4cfea4c57f709ce4 corporate/3.0/RPMS/python-2.3.3-2.1.C30mdk.i586.rpm
2afaede9d73bd6eb6e05e0c21fb51582 corporate/3.0/RPMS/python-base-2.3.3-2.1.C30mdk.i586.rpm
8631fc6d9d7703a4505254072e53ec23 corporate/3.0/RPMS/python-docs-2.3.3-2.1.C30mdk.i586.rpm
3e521c99c2f3fecb08d0725e34124c31 corporate/3.0/RPMS/tkinter-2.3.3-2.1.C30mdk.i586.rpm
ab6ecb0920b653d919a1457b975885c0 corporate/3.0/SRPMS/python-2.3.3-2.1.C30mdk.src.rpm

Corporate 3.0/X86_64:
2f4267d5c0daafa12985b1eb684982e6 x86_64/corporate/3.0/RPMS/lib64python2.3-2.3.3-2.1.C30mdk.x86_64.rpm
8b27c37138ea5f059fa5fb77b8139191 x86_64/corporate/3.0/RPMS/lib64python2.3-devel-2.3.3-2.1.C30mdk.x86_64.rpm
99b2278e72154e47e9daf66eeabf1277 x86_64/corporate/3.0/RPMS/python-2.3.3-2.1.C30mdk.x86_64.rpm
83e1a95c63a61187a6aa4b53cb30cbfa x86_64/corporate/3.0/RPMS/python-base-2.3.3-2.1.C30mdk.x86_64.rpm
770042e98bdbeb6549c45f7c1a20de03 x86_64/corporate/3.0/RPMS/python-docs-2.3.3-2.1.C30mdk.x86_64.rpm
5ab7162344890c5a86ce2993ae61e546 x86_64/corporate/3.0/RPMS/tkinter-2.3.3-2.1.C30mdk.x86_64.rpm
ab6ecb0920b653d919a1457b975885c0 x86_64/corporate/3.0/SRPMS/python-2.3.3-2.1.C30mdk.src.rpm

Mandrakelinux 9.2:
a892b22a7e1f89c019e1670d7cdd60f0 9.2/RPMS/libpython2.3-2.3-3.1.92mdk.i586.rpm
05871f84d666ea3ba9dcbfe1981b44ae 9.2/RPMS/libpython2.3-devel-2.3-3.1.92mdk.i586.rpm
e1c0e145784a9c28dbc8d4e0ce8f564f 9.2/RPMS/python-2.3-3.1.92mdk.i586.rpm
ecaececfba4689432bf40232ad82de34 9.2/RPMS/python-base-2.3-3.1.92mdk.i586.rpm
95c699992a960020a837c119ac349d75 9.2/RPMS/python-docs-2.3-3.1.92mdk.i586.rpm
b643ebf76e8283d533600179d9b64806 9.2/RPMS/tkinter-2.3-3.1.92mdk.i586.rpm
8b7b22bd98ee80fa30889f1de4500431 9.2/SRPMS/python-2.3-3.1.92mdk.src.rpm

Mandrakelinux 9.2/AMD64:
f4b9e7152e31dc1c199cbb137a1a1cf0 amd64/9.2/RPMS/lib64python2.3-2.3-3.1.92mdk.amd64.rpm
5da8eeff579d07a3a39730f962ac0360 amd64/9.2/RPMS/lib64python2.3-devel-2.3-3.1.92mdk.amd64.rpm
7d24517e15c9ef41a6cf5796982d4c93 amd64/9.2/RPMS/python-2.3-3.1.92mdk.amd64.rpm
dda09aea00c4688fef2baa171c64b94a amd64/9.2/RPMS/python-base-2.3-3.1.92mdk.amd64.rpm
7ecf9b85490cde267f81370dc41d918a amd64/9.2/RPMS/python-docs-2.3-3.1.92mdk.amd64.rpm
76ae48434564bc7522cbdf006d09ed27 amd64/9.2/RPMS/tkinter-2.3-3.1.92mdk.amd64.rpm
8b7b22bd98ee80fa30889f1de4500431 amd64/9.2/SRPMS/python-2.3-3.1.92mdk.src.rpm


To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandrakesoft for security. You can obtain the GPG public key of the Mandrakelinux Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandrakelinux at:

http://www.mandrakesoft.com/security/advisories

If you want to report vulnerabilities, please contact

security_linux-mandrake.com

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Linux Mandrake Security Team


Mandrakelinux Security Update Advisory


Package name: squid
Advisory ID: MDKSA-2005:034
Date: February 10th, 2005
Affected versions: 10.0, 10.1, 9.2, Corporate 3.0, Corporate Server 2.1


Problem Description:

More vulnerabilities were discovered in the squid server:

The LDAP handling of search filters was inadequate which could be abused to allow logins using severial variants of a single login name, possibly bypassing explicit access controls (CAN-2005-0173).

Minor problems in the HTTP header parsing code that could be used for cache poisoning (CAN-2005-0174 and CAN-2005-0175).

A buffer overflow in the WCCP handling code allowed remote attackers to cause a Denial of Service and could potentially allow for the execution of arbitrary code by using a long WCCP packet.

The updated packages have been patched to prevent these problems.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0211
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0173
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0174
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0175
http://www.squid-cache.org/Advisories/SQUID-2005_3.txt


Updated Packages:

Mandrakelinux 10.0:
656b659ee9ba2c1a08e24d1187a2c29f 10.0/RPMS/squid-2.5.STABLE4-2.4.100mdk.i586.rpm
d856951204f2d02932e7bb413bb31bfa 10.0/SRPMS/squid-2.5.STABLE4-2.4.100mdk.src.rpm

Mandrakelinux 10.0/AMD64:
432ea3eabd02f1f3b18919b23a3f19fe amd64/10.0/RPMS/squid-2.5.STABLE4-2.4.100mdk.amd64.rpm
d856951204f2d02932e7bb413bb31bfa amd64/10.0/SRPMS/squid-2.5.STABLE4-2.4.100mdk.src.rpm

Mandrakelinux 10.1:
a5bf0588457cd842d2326f647ebcbc25 10.1/RPMS/squid-2.5.STABLE6-2.3.101mdk.i586.rpm
b726f35ab93d4a12576a7923e374e5bf 10.1/SRPMS/squid-2.5.STABLE6-2.3.101mdk.src.rpm

Mandrakelinux 10.1/X86_64:
96e84ddeb61f432b7358344da7608f25 x86_64/10.1/RPMS/squid-2.5.STABLE6-2.3.101mdk.x86_64.rpm
b726f35ab93d4a12576a7923e374e5bf x86_64/10.1/SRPMS/squid-2.5.STABLE6-2.3.101mdk.src.rpm

Corporate Server 2.1:
50c44984c30f4c8e0db630da66411c70 corporate/2.1/RPMS/squid-2.4.STABLE7-2.4.C21mdk.i586.rpm
d706be0b04a5ac2e5b28b5b151181bda corporate/2.1/SRPMS/squid-2.4.STABLE7-2.4.C21mdk.src.rpm

Corporate Server 2.1/X86_64:
4cd111cf43876cc401eccfc49b48148c x86_64/corporate/2.1/RPMS/squid-2.4.STABLE7-2.4.C21mdk.x86_64.rpm
d706be0b04a5ac2e5b28b5b151181bda x86_64/corporate/2.1/SRPMS/squid-2.4.STABLE7-2.4.C21mdk.src.rpm

Corporate 3.0:
be661ea6526f37cf0efdb097319a2a46 corporate/3.0/RPMS/squid-2.5.STABLE4-2.4.C30mdk.i586.rpm
8fd70e360e772d30e8668000a6954a1d corporate/3.0/SRPMS/squid-2.5.STABLE4-2.4.C30mdk.src.rpm

Corporate 3.0/X86_64:
13a4a4ac0b02deb4366482e3f2317b22 x86_64/corporate/3.0/RPMS/squid-2.5.STABLE4-2.4.C30mdk.x86_64.rpm
8fd70e360e772d30e8668000a6954a1d x86_64/corporate/3.0/SRPMS/squid-2.5.STABLE4-2.4.C30mdk.src.rpm

Mandrakelinux 9.2:
c421d3df715cefb0a97995269f16e931 9.2/RPMS/squid-2.5.STABLE3-3.6.92mdk.i586.rpm
1fd8fdf79dbd6f647d00bea37be5400b 9.2/SRPMS/squid-2.5.STABLE3-3.6.92mdk.src.rpm

Mandrakelinux 9.2/AMD64:
21d4c2e94050161a6192e63304852ec7 amd64/9.2/RPMS/squid-2.5.STABLE3-3.6.92mdk.amd64.rpm
1fd8fdf79dbd6f647d00bea37be5400b amd64/9.2/SRPMS/squid-2.5.STABLE3-3.6.92mdk.src.rpm


To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandrakesoft for security. You can obtain the GPG public key of the Mandrakelinux Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandrakelinux at:

http://www.mandrakesoft.com/security/advisories

If you want to report vulnerabilities, please contact

security_linux-mandrake.com

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Linux Mandrake Security Team


Mandrakelinux Security Update Advisory


Package name: enscript
Advisory ID: MDKSA-2005:033
Date: February 10th, 2005
Affected versions: 10.0, 10.1, Corporate 3.0, Corporate Server 2.1


Problem Description:

A vulnerability in the enscript program's handling of the epsf command used to insert inline EPS file into a document was found. An attacker could create a carefully crafted ASCII file which would make used of the epsf pipe command in such a way that it could execute arbitrary commands if the file was opened with enscript (CAN-2004-1184).

Additionally, flaws were found in enscript that could be abused by executing enscript with carefully crafted command-line arguments. These flaws only have a security impact if enscript is executed by other programs and passed untrusted data from remote users (CAN-2004-1185 and CAN-2004-1186).

The updated packages have been patched to prevent these problems.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1184
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1185
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1186


Updated Packages:

Mandrakelinux 10.0:
f3eb5a56cf8e961908e9014306fd096a 10.0/RPMS/enscript-1.6.4-1.1.100mdk.i586.rpm
1ca9b9369578bc27057366a9c0757671 10.0/SRPMS/enscript-1.6.4-1.1.100mdk.src.rpm

Mandrakelinux 10.0/AMD64:
f316e4e8b11dde6155ddca1517fa8954 amd64/10.0/RPMS/enscript-1.6.4-1.1.100mdk.amd64.rpm
1ca9b9369578bc27057366a9c0757671 amd64/10.0/SRPMS/enscript-1.6.4-1.1.100mdk.src.rpm

Mandrakelinux 10.1:
2454e55d7ac2edad3c5513a60fb6dbe0 10.1/RPMS/enscript-1.6.4-1.1.101mdk.i586.rpm
47a3782c9ed270eb92d418fac3f9b390 10.1/SRPMS/enscript-1.6.4-1.1.101mdk.src.rpm

Mandrakelinux 10.1/X86_64:
9416aa90cf93d61755c815f9c38bac05 x86_64/10.1/RPMS/enscript-1.6.4-1.1.101mdk.x86_64.rpm
47a3782c9ed270eb92d418fac3f9b390 x86_64/10.1/SRPMS/enscript-1.6.4-1.1.101mdk.src.rpm

Corporate Server 2.1:
e14356e6a6bac0eb66a52bad164853b1 corporate/2.1/RPMS/enscript-1.6.3-1.1.C21mdk.i586.rpm
155cc925d6139bbd27272c2e7aab677f corporate/2.1/SRPMS/enscript-1.6.3-1.1.C21mdk.src.rpm

Corporate Server 2.1/X86_64:
633c80cff58745b0a1e907103267aed5 x86_64/corporate/2.1/RPMS/enscript-1.6.3-1.1.C21mdk.x86_64.rpm
155cc925d6139bbd27272c2e7aab677f x86_64/corporate/2.1/SRPMS/enscript-1.6.3-1.1.C21mdk.src.rpm

Corporate 3.0:
083cf4b5704f105f0aad21b82d3a2414 corporate/3.0/RPMS/enscript-1.6.4-1.1.C30mdk.i586.rpm
4ec9da427f7db5e0d2e4cac21e07e2c3 corporate/3.0/SRPMS/enscript-1.6.4-1.1.C30mdk.src.rpm

Corporate 3.0/X86_64:
2c6023e776b04c8ca7745e70ca8fe464 x86_64/corporate/3.0/RPMS/enscript-1.6.4-1.1.C30mdk.x86_64.rpm
4ec9da427f7db5e0d2e4cac21e07e2c3 x86_64/corporate/3.0/SRPMS/enscript-1.6.4-1.1.C30mdk.src.rpm


To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandrakesoft for security. You can obtain the GPG public key of the Mandrakelinux Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandrakelinux at:

http://www.mandrakesoft.com/security/advisories

If you want to report vulnerabilities, please contact

security_linux-mandrake.com

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Linux Mandrake Security Team


Mandrakelinux Security Update Advisory


Package name: cpio
Advisory ID: MDKSA-2005:032
Date: February 10th, 2005
Affected versions: 10.0, 10.1, 9.2, Corporate 3.0, Corporate Server 2.1


Problem Description:

A vulnerability in cpio was discovered where cpio would create worldwriteable files when used in -o/--create mode and giving an output file (with -O). This would allow any user to modify the created cpio archive. The updated packages have been patched so that cpio now respects the current umask setting of the user.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-1999-1572


Updated Packages:

Mandrakelinux 10.0:
d57c7da9aeb61ac87d7d7fb6bdef4d22 10.0/RPMS/cpio-2.5-4.1.100mdk.i586.rpm
ddb4e640cdd6b4b51f773b186cdefe9c 10.0/SRPMS/cpio-2.5-4.1.100mdk.src.rpm

Mandrakelinux 10.0/AMD64:
e747606a775c27a647a2260e1b3b9b7c amd64/10.0/RPMS/cpio-2.5-4.1.100mdk.amd64.rpm
ddb4e640cdd6b4b51f773b186cdefe9c amd64/10.0/SRPMS/cpio-2.5-4.1.100mdk.src.rpm

Mandrakelinux 10.1:
f861823b9c86ab3b676773c0a9167d82 10.1/RPMS/cpio-2.5-4.1.101mdk.i586.rpm
a222263ac25744908a43599920ef94d8 10.1/SRPMS/cpio-2.5-4.1.101mdk.src.rpm

Mandrakelinux 10.1/X86_64:
024cc31f46723f5e0dc36f30deded9d6 x86_64/10.1/RPMS/cpio-2.5-4.1.101mdk.x86_64.rpm
a222263ac25744908a43599920ef94d8 x86_64/10.1/SRPMS/cpio-2.5-4.1.101mdk.src.rpm

Corporate Server 2.1:
ffd629c3f731da92a47b2928bb75284f corporate/2.1/RPMS/cpio-2.5-4.1.C21mdk.i586.rpm
f14c2506f6be97b9bf6f5611677a92af corporate/2.1/SRPMS/cpio-2.5-4.1.C21mdk.src.rpm

Corporate Server 2.1/X86_64:
6b8a131de0dfc58532e2db1b1d8182ef x86_64/corporate/2.1/RPMS/cpio-2.5-4.1.C21mdk.x86_64.rpm
f14c2506f6be97b9bf6f5611677a92af x86_64/corporate/2.1/SRPMS/cpio-2.5-4.1.C21mdk.src.rpm

Corporate 3.0:
39962bf94864f9cf46ef2d262300a578 corporate/3.0/RPMS/cpio-2.5-4.1.C30mdk.i586.rpm
e96898c7bb40865035e30807d697504a corporate/3.0/SRPMS/cpio-2.5-4.1.C30mdk.src.rpm

Corporate 3.0/X86_64:
515b55c66e0bcf791bf1412a145a22d6 x86_64/corporate/3.0/RPMS/cpio-2.5-4.1.C30mdk.x86_64.rpm
e96898c7bb40865035e30807d697504a x86_64/corporate/3.0/SRPMS/cpio-2.5-4.1.C30mdk.src.rpm

Mandrakelinux 9.2:
c1556a3b2c0e71395d3142c407f7818a 9.2/RPMS/cpio-2.5-4.1.92mdk.i586.rpm
7f6ff46548e0a49568dcdafcd731166e 9.2/SRPMS/cpio-2.5-4.1.92mdk.src.rpm

Mandrakelinux 9.2/AMD64:
11bdf70272c80c81e723b75f58745033 amd64/9.2/RPMS/cpio-2.5-4.1.92mdk.amd64.rpm
7f6ff46548e0a49568dcdafcd731166e amd64/9.2/SRPMS/cpio-2.5-4.1.92mdk.src.rpm


To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandrakesoft for security. You can obtain the GPG public key of the Mandrakelinux Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandrakelinux at:

http://www.mandrakesoft.com/security/advisories

If you want to report vulnerabilities, please contact

security_linux-mandrake.com

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Linux Mandrake Security Team

SUSE Linux


SUSE Security Announcement

Package: squid
Announcement-ID: SUSE-SA:2005:006
Date: Thursday, Feb 10th 2005 13:30 MET
Affected products: 8.1, 8.2, 9.0, 9.1, 9.2 SUSE Linux Enterprise Server 8, 9
Vulnerability Type: remote command execution
Severity (1-10): 8
SUSE default package: no
Cross References: CAN-2005-0094 CAN-2005-0095 CAN-2005-0096 CAN-2005-0097 CAN-2005-0173 CAN-2005-0174 CAN-2005-0175 CAN-2005-0211 CAN-2005-0241

Content of this advisory:

  1. security vulnerability resolved:
    • buffer overflow in gopher parser
    • integer overflow in WCCP handling code
    • memory leak in the NTLM fakeauth_auth helper
    • denial-of-service in NTLM component
    • lax LDAP account name handling
    • cache poisoning by malformed HTTP packets
    • cache poisoning by splitted HTTP responses
    • buffer overflow in WCCP handling code
    • httpProcessReplyHeader function does not properly set the debug context problem description
  2. solution/workaround
  3. special instructions and notes
  4. package location and checksums
  5. pending vulnerabilities, solutions, workarounds:
  6. standard appendix (further information)

1) problem description, brief discussion

Squid is a feature-rich web-proxy with support for various web-related protocols.
The last two squid updates from February the 1st and 10th fix several vulnerabilities. The impact of them range from remote denial-of-service over cache poisoning to possible remote command execution. Due to the hugh amount of bugs the vulnerabilities are just summarized here.

CAN-2005-0094
A buffer overflow in the Gopher responses parser leads to memory corruption and usually crash squid. CAN-2005-0095
An integer overflow in the receiver of WCCP (Web Cache Communication Protocol) messages can be exploited remotely by sending a specially crafted UDP datagram to crash squid. CAN-2005-0096
A memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial-of-service due to uncontrolled memory consumption. CAN-2005-0097
The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a crash od squid by sending a malformed NTLM message. CAN-2005-0173
LDAP handles search filters very laxly. This behaviour can be abused to log in using several variants of a login name, possibly bypassing explicit access controls or confusing accounting. CAN-2005-0175 and CAN-2005-0174
Minor problems in the HTTP header parsing code that can be used for cache poisoning. CAN-2005-0211
A buffer overflow in the WCCP handling code in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial-of-service and possibly execute arbitrary code by using a long WCCP packet. CAN-2005-0241
The httpProcessReplyHeader function in Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers. The impact is unknown.

2) solution/workaround

There is no workaround known.

3) special instructions and notes

Please make sure squid is restarted after the update. Execute 'rcsquid restart' as user root.

4) package location and checksums

Download the update package for your distribution and verify its integrity by the methods listed in section 3) of this announcement. Then, install the package using the command "rpm -Fhv file.rpm" to apply the update.
Our maintenance customers are being notified individually. The packages are being offered for installation from the maintenance web.

x86 Platform:

SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/squid-2.5.STABLE6-6.6.i586.rpm 1002a1c5d0841a698e76f6e9879b91e9
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/squid-2.5.STABLE6-6.6.i586.patch.rpm 10f2257aa1238835ede8cd820a16c684
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/src/squid-2.5.STABLE6-6.6.src.rpm 9d54a80127df60cad2b254c1e4a434b8

SUSE Linux 9.1:
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/squid-2.5.STABLE5-42.27.i586.rpm 95dc251f27d87496e73b74f15c8030c6
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/squid-2.5.STABLE5-42.27.i586.patch.rpm f8b5486243cc2369c8f577fdc7ff3de2
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/src/squid-2.5.STABLE5-42.27.src.rpm d8d805a1062e9759c21cd19affdcd3b5

SUSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/squid-2.5.STABLE3-118.i586.rpm 8e94548f94fc7bf7f07ae2005fceb47e
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/squid-2.5.STABLE3-118.i586.patch.rpm eec32d15c7a3ae21accb69d0c02cc8b2
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/src/squid-2.5.STABLE3-118.src.rpm 6d8a366925335c44a0727cf53a0062cf

SUSE Linux 8.2:
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/squid-2.5.STABLE1-106.i586.rpm 7457d43267f88b26faf83695c87eaf89
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/squid-2.5.STABLE1-106.i586.patch.rpm 8393c0a5791f0390030d86b71337c96e
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/src/squid-2.5.STABLE1-106.src.rpm 189f57b8b006afdf3e13da058518491b

SUSE Linux 8.1:
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/squid-2.4.STABLE7-288.i586.rpm 177fc495629e0b4d2c2e3f5fd92a8ed4
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/squid-2.4.STABLE7-288.i586.patch.rpm 2bfe53711f0a4937760be18a5fe77189
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/src/squid-2.4.STABLE7-288.src.rpm 148c812936f32d9dfb14684f081efc8d

x86-64 Platform:

SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/squid-2.5.STABLE6-6.6.x86_64.rpm 5ea1d0c4217095aa6416fb5524d4f5ea
patch rpm(s):
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/squid-2.5.STABLE6-6.6.x86_64.patch.rpm 44a8568ac14a2799cd2424088ab48a15
source rpm(s):
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/src/squid-2.5.STABLE6-6.6.src.rpm 9d54a80127df60cad2b254c1e4a434b8

SUSE Linux 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/squid-2.5.STABLE5-42.27.x86_64.rpm 928be9deeadb7d0c5abb02518225fd0b
patch rpm(s):
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/squid-2.5.STABLE5-42.27.x86_64.patch.rpm 48acc169a1d84e77ad861517b12a49f6
source rpm(s):
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/src/squid-2.5.STABLE5-42.27.src.rpm e3a8028984ea67f0b9becfd8d00e86eb

SUSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/squid-2.5.STABLE3-118.x86_64.rpm f2501c3be9d3c1f70e65fe41628ef494
patch rpm(s):
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/squid-2.5.STABLE3-118.x86_64.patch.rpm 3b77d4262e1e8cbc4c71e8ec4aa48162
source rpm(s):
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/src/squid-2.5.STABLE3-118.src.rpm 4f3fcad35b37467922a9d710c2ea84a2


5) Pending vulnerabilities in SUSE Distributions and Workarounds:

Please see the SUSE Security Summary Report.


6) standard appendix: authenticity verification, additional information

  • Package authenticity verification:

    SUSE update packages are available on many mirror ftp servers all over the world. While this service is being considered valuable and important to the free and open source software community, many users wish to be sure about the origin of the package and its content before installing the package. There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or rpm package:

    1. md5sums as provided in the (cryptographically signed) announcement.
    2. using the internal gpg signatures of the rpm package.
    3. execute the command md5sum after you downloaded the file from a SUSE ftp server or its mirrors. Then, compare the resulting md5sum with the one that is listed in the announcement. Since the announcement containing the checksums is cryptographically signed (usually using the key security@suse.de), the checksums show proof of the authenticity of the package. We recommend against subscribing to security lists that cause the e-mail message containing the announcement to be modified so that the signature does not match after transport through the mailing list software. Downsides: You must be able to verify the authenticity of the announcement in the first place. If RPM packages are being rebuilt and a new version of a package is published on the ftp server, all md5 sums for the files are useless.
    4. rpm package signatures provide an easy way to verify the authenticity of an rpm package. Use the command rpm -v --checksig to verify the signature of the package, where is the file name of the rpm package that you have downloaded. Of course, package authenticity verification can only target an uninstalled rpm package file. Prerequisites:
      1. gpg is installed
      2. The package is signed using a certain key. The public part of this key must be installed by the gpg program in the directory ~/.gnupg/ under the user's home directory who performs the signature verification (usually root). You can import the key that is used by SUSE in rpm packages for SUSE Linux by saving this announcement to a file ("announcement.txt") and running the command (do "su -" to be root): gpg --batch; gpg < announcement.txt | gpg --import SUSE Linux distributions version 7.1 and thereafter install the key "build@suse.de" upon installation or upgrade, provided that the package gpg is installed. The file containing the public key is placed at the top-level directory of the first CD (pubring.gpg) and at ftp://ftp.suse.com/pub/suse/pubring.gpg-build.suse.de .
  • SUSE runs two security mailing lists to which any interested party may subscribe:
    suse-security@suse.com
  • general/linux/SUSE security discussion.
    All SUSE security announcements are sent to this list. To subscribe, send an email to
    <suse-security-subscribe@suse.com>.

    suse-security-announce@suse.com

  • SUSE's announce-only mailing list.
    Only SUSE's security announcements are sent to this list. To subscribe, send an email to

    <suse-security-announce-subscribe@suse.com>.

For general information or the frequently asked questions (faq) send mail to:

<suse-security-info@suse.com> or
<suse-security-faq@suse.com> respectively.


SUSE's security contact is <security@suse.com> or <security@suse.de>.
The <security@suse.de> public key is listed below.

The information in this advisory may be distributed or reproduced, provided that the advisory is not modified in any way. In particular, it is desired that the clear-text signature shows proof of the authenticity of the text.
SUSE Linux AG makes no warranties of any kind whatsoever with respect to the information contained in this security advisory.

Type Bits/KeyID Date User ID
pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security@suse.de>
pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build@suse.de>

Ubuntu Linux


Ubuntu Security Notice USN-78-1 February 09, 2005
mailman vulnerabilities
CAN-2005-0202

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)

The following packages are affected:

mailman

The problem can be corrected by upgrading the affected package to version 2.1.5-1ubuntu2.3. In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

An path traversal vulnerability has been discovered in the "private" module of Mailman. A flawed path sanitation algorithm allowed the construction of URLS to arbitrary files readable by Mailman. This allowed a remote attacker to retrieve configuration and password databases, private list archives, and other files.

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/m/mailman/mailman_2.1.5-1ubuntu2.3.diff.gz
Size/MD5: 127209 e37f6db6c8865ce3ef25f059b2eb953d
http://security.ubuntu.com/ubuntu/pool/main/m/mailman/mailman_2.1.5-1ubuntu2.3.dsc
Size/MD5: 658 01146e7ec488733d760c14c58f5267db
http://security.ubuntu.com/ubuntu/pool/main/m/mailman/mailman_2.1.5.orig.tar.gz
Size/MD5: 5745912 f5f56f04747cd4aff67427e7a45631af

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/main/m/mailman/mailman_2.1.5-1ubuntu2.3_amd64.deb
Size/MD5: 6602410 4f9448fabe11cb71d8946820988cd92c

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/main/m/mailman/mailman_2.1.5-1ubuntu2.3_i386.deb
Size/MD5: 6601808 dda12aca142243dac243268acd9109e8

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/main/m/mailman/mailman_2.1.5-1ubuntu2.3_powerpc.deb
Size/MD5: 6610862 135e0c700546df9a4ff65025a9edaeea


Ubuntu Security Notice USN-79-1 February 10, 2005
postgresql vulnerabilities
CAN-2005-0244 CAN-2005-0245 CAN-2005-0246 CAN-2005-0247

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)

The following packages are affected:

postgresql
postgresql-contrib

The problem can be corrected by upgrading the affected package to version 7.4.5-3ubuntu0.4. In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

The execution of custom PostgreSQL functions can be restricted with the EXECUTE privilege. However, previous versions did not check this privilege when executing a function which was part of an aggregate. As a result, any database user could circumvent the EXECUTE restriction of functions with a particular (but very common) parameter structure by creating an aggregate wrapper around the function. (CAN-2005-0244)

Several buffer overflows have been discovered in the SQL parser. These could be exploited by any database user to crash the PostgreSQL server or execute arbitrary code with the privileges of the server. (CAN-2005-0245, CAN-2005-0247)

Finally, this update fixes a Denial of Service vulnerability of the contributed "intagg" module. By constructing specially crafted arrays, a database user was able to corrupt and crash the PostgreSQL server. (CAN-2005-0246). Please note that this module is part of the "postgresql-contrib" package, which is not officially supported by Ubuntu.

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/postgresql_7.4.5-3ubuntu0.4.diff.gz
Size/MD5: 147348 eb787b982a2fce502e8c1c7aa55c3576
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/postgresql_7.4.5-3ubuntu0.4.dsc
Size/MD5: 991 30358e2ea343002967cf2f3213b9d1a2
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/postgresql_7.4.5.orig.tar.gz
Size/MD5: 9895913 a295885a36ed8e7ec7a7e887218ceabc

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/postgresql-doc_7.4.5-3ubuntu0.4_all.deb
Size/MD5: 2256436 1c9ed621c3ac0dc2a00b26c58d2a3c07

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libecpg-dev_7.4.5-3ubuntu0.4_amd64.deb
Size/MD5: 206808 1e9bc9dc3cdc1cf79c9ef599ce265cba
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libecpg4_7.4.5-3ubuntu0.4_amd64.deb
Size/MD5: 91246 5533e6428b30d353bf3526be2829f4f2
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libpgtcl-dev_7.4.5-3ubuntu0.4_amd64.deb
Size/MD5: 48944 73a24322ee5588d75bdea7a516df6f77
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libpgtcl_7.4.5-3ubuntu0.4_amd64.deb
Size/MD5: 73842 4f0fdbc694b096f09382c65dfb4dd206
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libpq3_7.4.5-3ubuntu0.4_amd64.deb
Size/MD5: 115736 958218a2a2b8a0dcf0dd6fa770d56b3d
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/postgresql-client_7.4.5-3ubuntu0.4_amd64.deb
Size/MD5: 518388 b0379cca9944bb2c6982d2f17d279052
http://security.ubuntu.com/ubuntu/pool/universe/p/postgresql/postgresql-contrib_7.4.5-3ubuntu0.4_amd64.deb
Size/MD5: 624558 b79caefd6810cc614417932482bd522e
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/postgresql-dev_7.4.5-3ubuntu0.4_amd64.deb
Size/MD5: 509454 f474b7a6266e89277cbfa61f163b71fd
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/postgresql_7.4.5-3ubuntu0.4_amd64.deb
Size/MD5: 3880354 5702813c84b8ed415f84b6256a6b04f6

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libecpg-dev_7.4.5-3ubuntu0.4_i386.deb
Size/MD5: 194924 6c938748460c8fcd7b5d37a394263600
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libecpg4_7.4.5-3ubuntu0.4_i386.deb
Size/MD5: 85752 157dd27476e72f60ee01735801904956
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libpgtcl-dev_7.4.5-3ubuntu0.4_i386.deb
Size/MD5: 47926 b7abfc71a11e604732b6773bce037eac
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libpgtcl_7.4.5-3ubuntu0.4_i386.deb
Size/MD5: 70730 8f25f953703068cc97924c339a5232b8
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libpq3_7.4.5-3ubuntu0.4_i386.deb
Size/MD5: 108982 a786da05d2d92418550c108b2565d40d
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/postgresql-client_7.4.5-3ubuntu0.4_i386.deb
Size/MD5: 492222 589dff2665eadeb0ea4c2920e5d63a95
http://security.ubuntu.com/ubuntu/pool/universe/p/postgresql/postgresql-contrib_7.4.5-3ubuntu0.4_i386.deb
Size/MD5: 577778 4a37c5989e0c7bc2ddf31d0e1be7017e
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/postgresql-dev_7.4.5-3ubuntu0.4_i386.deb
Size/MD5: 502618 68eabd4e511edbc839a33c1b5f549760
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/postgresql_7.4.5-3ubuntu0.4_i386.deb
Size/MD5: 3703434 70665efa7b0e107fced12f1dafcceea6

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libecpg-dev_7.4.5-3ubuntu0.4_powerpc.deb
Size/MD5: 203326 4bff9a2f466eeb420a2598479e1863d7
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libecpg4_7.4.5-3ubuntu0.4_powerpc.deb
Size/MD5: 92782 3ed41b6926e9ce5291d85a180f10ac2b
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libpgtcl-dev_7.4.5-3ubuntu0.4_powerpc.deb
Size/MD5: 48680 e82965a2ab2066257c50313d00e73ccd
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libpgtcl_7.4.5-3ubuntu0.4_powerpc.deb
Size/MD5: 77338 805f090c7abb09954b0f64c55dae69f6
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/libpq3_7.4.5-3ubuntu0.4_powerpc.deb
Size/MD5: 109990 2f6a558821fb44058992821a38d3c620
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/postgresql-client_7.4.5-3ubuntu0.4_powerpc.deb
Size/MD5: 511140 7c6f178d64f49f1e9761dba7be2a421a
http://security.ubuntu.com/ubuntu/pool/universe/p/postgresql/postgresql-contrib_7.4.5-3ubuntu0.4_powerpc.deb
Size/MD5: 636722 4781ee88b2c58c8eb25921a86b21f4b0
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/postgresql-dev_7.4.5-3ubuntu0.4_powerpc.deb
Size/MD5: 506202 1133027e8da57b754ae1ff21d79e923a
http://security.ubuntu.com/ubuntu/pool/main/p/postgresql/postgresql_7.4.5-3ubuntu0.4_powerpc.deb
Size/MD5: 4103732 6af566d887140b80873568c649ac852a



No talkbacks posted.
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!

..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP