Linux Today: Linux News On Internet Time.
Search Linux Today
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Server Daily
IT Management Daily
Subscribe News
Subscribe PR
Subscribe Security

internet.com
Internet News
Small Business

Advertise
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

Malware devs embrace open-source

A tale of two distros: Ubuntu and Linux Mint

Raspberry Pi benchmarked against Beagleboard, low price is long term

20 popular Ubuntu Linux apps you may want to try

A Selection of the Very Best Open Source Tutorials and Tools

Android Ice Cream Sandwich ported to x86 tablets, netbooks and notebooks

SECURITY: Google Chrome 17 Improves Security

How to read a CSV file in Perl?

Red Hat Brings Gluster to Amazon Cloud

New Linux kernel fixes power-saving issues



Applications Management Engineer Sr (NYC)
Next Step Systems
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume
:Advisories: October 5, 2005
Advisories: October 5, 2005
Oct 6, 2005, 04 :45 UTC (0 Talkback[s]) (3570 reads)

Debian GNU/Linux


Debian Security Advisory DSA 833-2 security@debian.org
http://www.debian.org/security/ Martin Schulze
October 4th, 2005 http://www.debian.org/security/faq


Package : mysql-dfsg-4.1
Vulnerability : buffer overflow
Problem type : remote
Debian-specific: no
CVE ID : CAN-2005-2558
BugTraq ID : 14509

A stack-based buffer overflow in the init_syms function of MySQL, a popular database, has been discovered that allows remote authenticated users who can create user-defined functions to execute arbitrary code via a long function_name field. The ability to create user-defined functions is not typically granted to untrusted users.

The following vulnerability matrix explains which version of MySQL in which distribution has this problem fixed:
 woodysargesid
mysql3.23.49-8.14n/an/a
mysql-dfsgn/a4.0.24-10sarge14.0.24-10sarge1
mysql-dfsg-4.1n/a4.1.11a-4sarge24.1.14-2
mysql-dfsg-5.0n/an/a5.0.11beta-3

This update only covers binary packages for the big endian MIPS architecture that was mysteriously forgotton in the earlier update.

We recommend that you upgrade your mysql-dfsg-4.1 packages.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-dfsg-4.1_4.1.11a-4sarge2.dsc
      Size/MD5 checksum: 1021 ef5b7f754fd69c6ddf96185a9ea99d8c
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-dfsg-4.1_4.1.11a-4sarge2.diff.gz
      Size/MD5 checksum: 163217 c22faa82cad1a38568146d03a316b4c3
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-dfsg-4.1_4.1.11a.orig.tar.gz
      Size/MD5 checksum: 15771855 3c0582606a8903e758c2014c2481c7c3

Architecture independent components:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-common-4.1_4.1.11a-4sarge2_all.deb
      Size/MD5 checksum: 35758 f4c17c57aaed4aba0d06b22391a443ff

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge2_mips.deb
      Size/MD5 checksum: 1477872 22fec72fd66a24a4f0d908dcaa23e64f
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge2_mips.deb
      Size/MD5 checksum: 6051732 6eb05337947f14fc0db2989a64db67d5
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge2_mips.deb
      Size/MD5 checksum: 903670 38af0c111d89ed2455f418da9aafdb56
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge2_mips.deb
      Size/MD5 checksum: 15407526 d728af32519bf4ca50b96dd37998631d

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 839-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
October 4th, 2005 http://www.debian.org/security/faq


Package : apachetop
Vulnerability : insecure temporary file Problem type : local
Debian-specific: no
CVE ID : CAN-2005-2660

Eric Romang discovered an insecurely created temporary file in apachetop, a realtime monitoring tool for the Apache webserver that could be exploited with a symlink attack to overwrite arbitrary files with the user id that runs apachetop.

The old stable distribution (woody) is not affected by this problem.

For the stable distribution (sarge) this problem has been fixed in version 0.12.5-1sarge1.

For the unstable distribution (sid) this problem has been fixed in version 0.12.5-5.

We recommend that you upgrade your apachetop package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5-1sarge1.dsc
      Size/MD5 checksum: 613 cf61395747017a6c8a4319be4cbafe83
    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5-1sarge1.diff.gz
      Size/MD5 checksum: 2956 76b0826270dcf4c51b191b9aaa3f58f8
    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5.orig.tar.gz
      Size/MD5 checksum: 126967 47c40c26319d57100008a2a56dcefe06

Alpha architecture:

    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5-1sarge1_alpha.deb
      Size/MD5 checksum: 36262 d532edba02bdf8d4dd2316b68866d906

AMD64 architecture:

    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5-1sarge1_amd64.deb
      Size/MD5 checksum: 31370 c8fdae994094269fbe3f597858c8ba14

ARM architecture:

    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5-1sarge1_arm.deb
      Size/MD5 checksum: 30572 dc820d6f5af5a89989705c919f5b8bdb

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5-1sarge1_i386.deb
      Size/MD5 checksum: 30160 cc20d5d7ab5798ec98966b944259fde4

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5-1sarge1_ia64.deb
      Size/MD5 checksum: 40446 06f813d834fc7566317c94d4ff07c9ff

HP Precision architecture:

    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5-1sarge1_hppa.deb
      Size/MD5 checksum: 34332 aea9a750be0952a46d1d03f9b0d8d8cd

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5-1sarge1_m68k.deb
      Size/MD5 checksum: 27844 df4e67fb0a58d32537dd4cb7c88c3e24

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5-1sarge1_mips.deb
      Size/MD5 checksum: 34964 ab8c82dec697e8567a0b819f25ff1c60

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5-1sarge1_mipsel.deb
      Size/MD5 checksum: 34864 48009e8eb7bf1cac0178d33bed3594e9

PowerPC architecture:

    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5-1sarge1_powerpc.deb
      Size/MD5 checksum: 33138 22c5a90df13d862497d4fd0060d2d53a

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5-1sarge1_s390.deb
      Size/MD5 checksum: 31172 120ff918508d38deaf737f22d8a1da96

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.12.5-1sarge1_sparc.deb
      Size/MD5 checksum: 30532 2a5637a3f94148621756e648b0e9cfdb

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 840-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
October 4th, 2005 http://www.debian.org/security/faq


Package : drupal
Vulnerability : missing input sanitising
Problem-Type : remote
Debian-specific: no
CVE ID : CAN-2005-2498

Stefan Esser of the Hardened-PHP Project reported a serious vulnerablility in the third-party XML-RPC library included with some Drupal versions. An attacker could execute arbitrary PHP code on a target site. This update pulls in the latest XML-RPC version from upstream.

The old stable distribution (woody) is not affected by this problem since no drupal is included.

For the stable distribution (sarge) this problem has been fixed in version 4.5.3-4.

For the unstable distribution (sid) this problem has been fixed in version 4.5.5-1.

We recommend that you upgrade your drupal package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/d/drupal/drupal_4.5.3-4.dsc
      Size/MD5 checksum: 609 eedec6415db7933b2583cd49953a29aa
    http://security.debian.org/pool/updates/main/d/drupal/drupal_4.5.3-4.diff.gz
      Size/MD5 checksum: 70443 877a0f759e9f3443cbf7075d84a4dc91
    http://security.debian.org/pool/updates/main/d/drupal/drupal_4.5.3.orig.tar.gz
      Size/MD5 checksum: 471540 bf093c4c8aca7bba62833ea1df35702f

Architecture independent components:

    http://security.debian.org/pool/updates/main/d/drupal/drupal_4.5.3-4_all.deb
      Size/MD5 checksum: 497672 0fa1c9826ea5d4528369d418c8bae13b

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 841-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
October 4th, 2005 http://www.debian.org/security/faq


Package : mailutils
Vulnerability : format string vulnerability
Problem type : remote
Debian-specific: no
CVE ID : CAN-2005-2878

A format string vulnerability has been discovered in GNU mailutils which contains utilities for handling mail that allows a remote attacker to execute arbitrary code on the IMAP server.

The old stable distribution (woody) is not affected by this problem.

For the stable distribution (sarge) this problem has been fixed in version 0.6.1-4sarge1.

For the unstable distribution (sid) this problem has been fixed in version 0.6.90-3.

We recommend that you upgrade your mailutils package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1-4sarge1.dsc
      Size/MD5 checksum: 1105 571f9dc4dd73866f6888f7ad40d445a9
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1-4sarge1.diff.gz
      Size/MD5 checksum: 37030 cdeaf9acb33abf47aadeb899163db03c
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1.orig.tar.gz
      Size/MD5 checksum: 3053948 47ff446d55909e2777efb9e912b23de5

Architecture independent components:

    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-doc_0.6.1-4sarge1_all.deb
      Size/MD5 checksum: 287326 f8cc3cd1b4d753c77a49a488768fed4a

Alpha architecture:

    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0_0.6.1-4sarge1_alpha.deb
      Size/MD5 checksum: 606384 f54df2eb18e6b761feb6e39c5c025898
    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0-dev_0.6.1-4sarge1_alpha.deb
      Size/MD5 checksum: 538700 4088fade15aa91790a4eeaf968e3deb1
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1-4sarge1_alpha.deb
      Size/MD5 checksum: 171206 ad50d9f2a50366a91134e355764e8db3
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-comsatd_0.6.1-4sarge1_alpha.deb
      Size/MD5 checksum: 48714 cde882256182f1efc3f65ee5fb8a5a91
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-imap4d_0.6.1-4sarge1_alpha.deb
      Size/MD5 checksum: 87216 b73d7281c7b568e00a09e6102c2f8bcb
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-mh_0.6.1-4sarge1_alpha.deb
      Size/MD5 checksum: 840400 a3896dfc973058db179400e793584849
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-pop3d_0.6.1-4sarge1_alpha.deb
      Size/MD5 checksum: 66522 14ae8401d93659894b73759b1b478f8b

AMD64 architecture:

    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0_0.6.1-4sarge1_amd64.deb
      Size/MD5 checksum: 572810 6f359d09d1146ca5ba91342cf47e8aed
    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0-dev_0.6.1-4sarge1_amd64.deb
      Size/MD5 checksum: 419252 63ffc694a1ae01ce93cff42a542a23f5
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1-4sarge1_amd64.deb
      Size/MD5 checksum: 156792 cbf58f684ae6016c66732100bc59549f
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-comsatd_0.6.1-4sarge1_amd64.deb
      Size/MD5 checksum: 47420 7819e7f8bedf0cb6a9e736cbbad0261b
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-imap4d_0.6.1-4sarge1_amd64.deb
      Size/MD5 checksum: 80310 c1c891e8de7f71ea1747e7345449bccf
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-mh_0.6.1-4sarge1_amd64.deb
      Size/MD5 checksum: 747904 b8a99a4c9ba9bd23a2d81c3e8b1873a1
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-pop3d_0.6.1-4sarge1_amd64.deb
      Size/MD5 checksum: 63066 7fd0d97ddbdd61306a690c5f135c5eac

ARM architecture:

    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0_0.6.1-4sarge1_arm.deb
      Size/MD5 checksum: 527430 4ddcccc6f44fc7df839b2c028fffe55a
    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0-dev_0.6.1-4sarge1_arm.deb
      Size/MD5 checksum: 398996 041963fa2132bf8473f119b9a0c46b98
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1-4sarge1_arm.deb
      Size/MD5 checksum: 139946 138bd36d955a0590663691da9a924e87
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-comsatd_0.6.1-4sarge1_arm.deb
      Size/MD5 checksum: 45920 395f7450d6d6808d9e650dd0191bdc98
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-imap4d_0.6.1-4sarge1_arm.deb
      Size/MD5 checksum: 73224 3d99823d12f33edbc4ba48a78785c065
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-mh_0.6.1-4sarge1_arm.deb
      Size/MD5 checksum: 611910 85de420573e56df18b696f99986d2e4e
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-pop3d_0.6.1-4sarge1_arm.deb
      Size/MD5 checksum: 58728 1713cfbb377dcf306f502766555e2c56

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0_0.6.1-4sarge1_i386.deb
      Size/MD5 checksum: 546638 33c7ba82e32cb44e60ccc11c898350aa
    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0-dev_0.6.1-4sarge1_i386.deb
      Size/MD5 checksum: 368170 eb33117e3ea1af53f9acb25b91d19802
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1-4sarge1_i386.deb
      Size/MD5 checksum: 143594 e031d8e9c5e66ace4391f915d8505199
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-comsatd_0.6.1-4sarge1_i386.deb
      Size/MD5 checksum: 46600 4e5ac10b6ccf7ce323d01631da6406db
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-imap4d_0.6.1-4sarge1_i386.deb
      Size/MD5 checksum: 75060 080e134a5b18a50691573fcb2587ceea
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-mh_0.6.1-4sarge1_i386.deb
      Size/MD5 checksum: 648372 0b390cfe6f739dc61b964c60b47b5f22
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-pop3d_0.6.1-4sarge1_i386.deb
      Size/MD5 checksum: 60458 88304f09d9508705d6689ba581380eb6

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0_0.6.1-4sarge1_ia64.deb
      Size/MD5 checksum: 686370 4cb54d890bc50a94b4c86abdbf33eee7
    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0-dev_0.6.1-4sarge1_ia64.deb
      Size/MD5 checksum: 560412 9ac160e35b8af32107d58726b5b64107
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1-4sarge1_ia64.deb
      Size/MD5 checksum: 198664 ee929d5849173c9ab70928bc61e69bee
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-comsatd_0.6.1-4sarge1_ia64.deb
      Size/MD5 checksum: 51238 9d39ff55ab465b23b5c661b47ae9630d
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-imap4d_0.6.1-4sarge1_ia64.deb
      Size/MD5 checksum: 96998 54e94843d30f4eff696ebcdd45c7a539
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-mh_0.6.1-4sarge1_ia64.deb
      Size/MD5 checksum: 990306 69e8b44efc1925b8ae388b37274b7b82
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-pop3d_0.6.1-4sarge1_ia64.deb
      Size/MD5 checksum: 72422 245ec7e13466de3d1d43eec6abdb741e

HP Precision architecture:

    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0_0.6.1-4sarge1_hppa.deb
      Size/MD5 checksum: 595258 d4ca564d255bdc33d1769c1b1063fe8e
    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0-dev_0.6.1-4sarge1_hppa.deb
      Size/MD5 checksum: 442204 5c238fde3c655bcf043180e90f47172a
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1-4sarge1_hppa.deb
      Size/MD5 checksum: 158120 b8f5748edf06712cb7dce347f93ef407
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-comsatd_0.6.1-4sarge1_hppa.deb
      Size/MD5 checksum: 47578 6e041420aea5d1edd31c5a34d69bbefa
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-imap4d_0.6.1-4sarge1_hppa.deb
      Size/MD5 checksum: 79582 9e03d9c6cbfb8ac2381a82c9098d3117
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-mh_0.6.1-4sarge1_hppa.deb
      Size/MD5 checksum: 743390 8039702fb15714fbf208e593387772ef
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-pop3d_0.6.1-4sarge1_hppa.deb
      Size/MD5 checksum: 62636 1974df850795b3c8e90f711feed74353

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0_0.6.1-4sarge1_m68k.deb
      Size/MD5 checksum: 530392 feb5047c2cb1b1aa622ce00f4fa88a8e
    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0-dev_0.6.1-4sarge1_m68k.deb
      Size/MD5 checksum: 342010 8be136e24deac85778b6aed825eedf4b
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1-4sarge1_m68k.deb
      Size/MD5 checksum: 137976 21192aff6dabf3ce2dd720ac621bdd79
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-comsatd_0.6.1-4sarge1_m68k.deb
      Size/MD5 checksum: 46002 11524c5af73a9230b396acfbc8ac70ef
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-imap4d_0.6.1-4sarge1_m68k.deb
      Size/MD5 checksum: 71980 b19b14b7d6fab2d65691841b237535c4
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-mh_0.6.1-4sarge1_m68k.deb
      Size/MD5 checksum: 585942 96fb6e0b0bd5c77135471137bf4e03f3
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-pop3d_0.6.1-4sarge1_m68k.deb
      Size/MD5 checksum: 58532 5e08996c218aed9d69df307dc5cfc25c

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0_0.6.1-4sarge1_mips.deb
      Size/MD5 checksum: 546328 fd4c71af25939af23fef5f3264282fb2
    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0-dev_0.6.1-4sarge1_mips.deb
      Size/MD5 checksum: 435486 3e0e0384e04a09384d770b1ab4baea32
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1-4sarge1_mips.deb
      Size/MD5 checksum: 170178 91bdf8e9f748cc7d59720bde9a2902ea
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-comsatd_0.6.1-4sarge1_mips.deb
      Size/MD5 checksum: 47324 92c7228dab7e3eef27830516725d92c2
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-imap4d_0.6.1-4sarge1_mips.deb
      Size/MD5 checksum: 79408 9a53d5edbbde3e22891c17e46d963df4
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-mh_0.6.1-4sarge1_mips.deb
      Size/MD5 checksum: 736470 05e81cdbde2a46b0390395673a08cc1f
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-pop3d_0.6.1-4sarge1_mips.deb
      Size/MD5 checksum: 63246 23f641022bea23e89754fcfdbe6a0ee7

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0_0.6.1-4sarge1_mipsel.deb
      Size/MD5 checksum: 543782 d3b0685929f7a7509593070bd6c3cb24
    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0-dev_0.6.1-4sarge1_mipsel.deb
      Size/MD5 checksum: 435074 0b429dc39083c2f1d297fe74109d9ff1
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1-4sarge1_mipsel.deb
      Size/MD5 checksum: 169236 8f8baa1b0c29f740c6df24eef4be72f4
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-comsatd_0.6.1-4sarge1_mipsel.deb
      Size/MD5 checksum: 47348 928829f7677458a3a98a172de42845bf
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-imap4d_0.6.1-4sarge1_mipsel.deb
      Size/MD5 checksum: 79370 af3aac9553ed1b32b5e202be0c5f25ee
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-mh_0.6.1-4sarge1_mipsel.deb
      Size/MD5 checksum: 733964 4896c6d726bf6bb55ca3799bf16316b1
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-pop3d_0.6.1-4sarge1_mipsel.deb
      Size/MD5 checksum: 63062 0b6a4acd7abdce23cc5453eb74fe0ace

PowerPC architecture:

    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0_0.6.1-4sarge1_powerpc.deb
      Size/MD5 checksum: 562656 f67259ab832b0f8c0603cdc67dbe7da5
    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0-dev_0.6.1-4sarge1_powerpc.deb
      Size/MD5 checksum: 413256 52af6f53afe953e2b61c6963a7767fa4
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1-4sarge1_powerpc.deb
      Size/MD5 checksum: 157132 dbea4cf9d3c13eb64dbfb6c45afc4656
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-comsatd_0.6.1-4sarge1_powerpc.deb
      Size/MD5 checksum: 48140 a17f9d5f6819a01c43203bba60bd1318
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-imap4d_0.6.1-4sarge1_powerpc.deb
      Size/MD5 checksum: 77740 a49bb18465fd525432408f04a1a5e2eb
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-mh_0.6.1-4sarge1_powerpc.deb
      Size/MD5 checksum: 703556 0313c6d7732ea9dc02fdfe761d19d285
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-pop3d_0.6.1-4sarge1_powerpc.deb
      Size/MD5 checksum: 62720 b872dc38bd68f37eade1d93122b06d5d

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0_0.6.1-4sarge1_s390.deb
      Size/MD5 checksum: 588272 9b08cf5bf32808febe51d504f7a1de28
    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0-dev_0.6.1-4sarge1_s390.deb
      Size/MD5 checksum: 414258 e4dfb8ba1d2c9ae961f4266535b1db13
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1-4sarge1_s390.deb
      Size/MD5 checksum: 156044 e3a2c3bc8577fe048961dfafd65af520
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-comsatd_0.6.1-4sarge1_s390.deb
      Size/MD5 checksum: 47764 12c866ffaf0c4bdf3e1740b3204159af
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-imap4d_0.6.1-4sarge1_s390.deb
      Size/MD5 checksum: 80440 972141900eb33f9f5af71f2dbd7735af
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-mh_0.6.1-4sarge1_s390.deb
      Size/MD5 checksum: 751338 41c5a8f2321793932ed0b656d6d2ab5d
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-pop3d_0.6.1-4sarge1_s390.deb
      Size/MD5 checksum: 63234 c7c4a9cddd4883057bf48259fc48da4d

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0_0.6.1-4sarge1_sparc.deb
      Size/MD5 checksum: 538590 c087d0acbb5aaa85a2a604d502405ef2
    http://security.debian.org/pool/updates/main/m/mailutils/libmailutils0-dev_0.6.1-4sarge1_sparc.deb
      Size/MD5 checksum: 377926 afe33096c3f86adb272ead55253ee886
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils_0.6.1-4sarge1_sparc.deb
      Size/MD5 checksum: 139886 9138582e6bdd999321b9073ed8164b64
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-comsatd_0.6.1-4sarge1_sparc.deb
      Size/MD5 checksum: 46012 d13c45d9852f0400e61ec550da0f427e
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-imap4d_0.6.1-4sarge1_sparc.deb
      Size/MD5 checksum: 73622 0ecb0584c1652b26373dd22c457f1a5a
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-mh_0.6.1-4sarge1_sparc.deb
      Size/MD5 checksum: 624018 ad86570361a60694083e945abd2a5ff6
    http://security.debian.org/pool/updates/main/m/mailutils/mailutils-pop3d_0.6.1-4sarge1_sparc.deb
      Size/MD5 checksum: 58758 b4c553eaee679c961775fcac89cbd168

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 842-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
October 4th, 2005 http://www.debian.org/security/faq


Package : egroupware
Vulnerability : missing input sanitising
Problem type : remote
Debian-specific: no
CVE ID : CAN-2005-2498
Debian Bug : 323350

Stefan Esser discovered a vulnerability in the XML-RPC libraries which are also present in egroupware, a web-based groupware suite, that allows injection of arbitrary PHP code into eval() statements.

The old stable distribution (woody) does not contain egroupware packages.

For the stable distribution (sarge) this problem has been fixed in version 1.0.0.007-2.dfsg-2sarge2.

For the unstable distribution (sid) this problem has been fixed in version 1.0.0.009.dfsg-1.

We recommend that you upgrade your egroupware packages.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/e/egroupware/egroupware_1.0.0.007-2.dfsg-2sarge2.dsc
      Size/MD5 checksum: 1285 3d6f6f4ce438e4ebcd70225e9a24e692
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware_1.0.0.007-2.dfsg-2sarge2.diff.gz
      Size/MD5 checksum: 49855 a1739526a8d1c05ddc2dadb47363c8df
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware_1.0.0.007-2.dfsg.orig.tar.gz
      Size/MD5 checksum: 12699187 462f5ea377c4d0c04f16ffe8037b9d6a

Architecture independent components:

    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-addressbook_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 148852 e750bfd56785d6a940c2a2d88fb94aa2
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-bookmarks_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 124982 3ff7fdf44cb275daffeabb48fc0d4308
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-calendar_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 382090 787e7db0a8df6cb7ab4b3a80987071ec
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-comic_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 255918 79eabb6d2b0174c16fdf966f3ab9e6ee
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-core_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 3774984 8289fa81d3b180d5dc67b8a282c8686d
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-developer-tools_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 53300 3f2a59360e8bd317eef86d5af7858c1f
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-email_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 1243750 161aa84bc1bcf1d4a49499fa5ba0cad3
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-emailadmin_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 37960 714cd583a86b9b4b1a8b05c2c9aa0f66
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-etemplate_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 1363118 63a866ae67145b939d64db25d0158870
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-felamimail_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 275250 2db7b6c8f830f7cb6d00150b33c540da
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-filemanager_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 172724 3ce24e53c034d01404d3f7f7158713bc
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-forum_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 51170 7797b69c2929da061b6be28b39e268d4
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-ftp_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 37888 8c32110dcebcd17859b69587d2b403d4
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-fudforum_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 1486376 2ab734c6cdb6f3dad2026afe837d74af
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-headlines_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 74774 6a9b286b59af81235d82fcf08f61d04d
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-infolog_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 202136 65add5519ec01aa6f280f2f94a7b173c
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-jinn_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 204852 2ff54e99c7af6e015e9d97d294525837
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-ldap_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 6990 c54a40cb045d634c0291c14a9e0ffc92
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-manual_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 17150 c68a5a178735f1a7c6c4c136825fa562
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-messenger_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 32010 ad9e7c62d2ab3f682f3270bbc7a71b23
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-news-admin_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 50574 316eac825edd3445437794305059a925
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-phpbrain_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 119122 c6a4302ed448ee7525fa1cd76953b284
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-phpldapadmin_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 139434 7288958a380aa265c387a7318a926f5d
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-phpsysinfo_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 115804 3992f299e8a522851680b3f2852f5874
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-polls_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 35936 1729874da8403e275ace5d2233e5ef5e
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-projects_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 302090 540892c7605cce8c170c35b2ceea89a3
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-registration_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 99668 d9ec849c53dce3255b5ffd878a9a78e0
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-sitemgr_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 486416 d2b53f213aa3f703eaf8548a16417276
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-stocks_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 26374 6820f8f0081f049c381e72e5f48a5cec
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-tts_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 92498 8f96075774eabc0351bb7f77180a75f9
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware-wiki_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 92456 906fc6675229b6ba352b16c32f547b04
    http://security.debian.org/pool/updates/main/e/egroupware/egroupware_1.0.0.007-2.dfsg-2sarge2_all.deb
      Size/MD5 checksum: 4260 d776246f9cd720063d6f89f4ea6851ed

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 843-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
October 5th, 2005 http://www.debian.org/security/faq


Package : arc
Vulnerability : insecure temporary file
Problem type : local
Debian-specific: no
CVE ID : CAN-2005-2945 CAN-2005-2992

Two vulnerabilities have been discovered in the ARC archive program under Unix. The Common Vulnerabilities and Exposures project identifies the following problems:

CAN-2005-2945

Eric Romang discovered that the ARC archive program under Unix creates a temporary file with insecure permissions which may lead to an attacker stealing sensitive information.

CAN-2005-2992

Joey Schulze discovered that the temporary file was created in an insecure fashion as well, leaving it open to a classic symlink attack.

The old stable distribution (woody) does not contain arc packages.

For the stable distribution (sarge) these problems have been fixed in version 5.21l-1sarge1.

For the unstable distribution (sid) these problems have been fixed in version 5.21m-1.

We recommend that you upgrade your arc package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l-1sarge1.dsc
      Size/MD5 checksum: 552 4ebba22896668e091043fb909dd7f0b7
    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l-1sarge1.diff.gz
      Size/MD5 checksum: 3323 1c70a26064195b6664b296313c73cbc0
    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l.orig.tar.gz
      Size/MD5 checksum: 82134 f30654fbe80640f0219c33d0f2f64021

Alpha architecture:

    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l-1sarge1_alpha.deb
      Size/MD5 checksum: 67312 081b0a1573d4f3a2ce35e937200a56bd

AMD64 architecture:

    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l-1sarge1_amd64.deb
      Size/MD5 checksum: 60646 c8edb347de5f20d8f17a93bde98fc9fd

ARM architecture:

    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l-1sarge1_arm.deb
      Size/MD5 checksum: 57442 2ad784c9a055046c2e47990ae8155001

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l-1sarge1_i386.deb
      Size/MD5 checksum: 55506 f8c3fb1adb553abbcceabdeb5a3aea82

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l-1sarge1_ia64.deb
      Size/MD5 checksum: 73842 d70cebf9b47a8630692450476fe9062c

HP Precision architecture:

    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l-1sarge1_hppa.deb
      Size/MD5 checksum: 62028 a33d986f66f7ca3d5f582fbf495bb45f

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l-1sarge1_m68k.deb
      Size/MD5 checksum: 52462 51ad27d071bb88b938de56b58dbe6d0e

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l-1sarge1_mips.deb
      Size/MD5 checksum: 64456 6991489144d5381fe19b73edc104f7a3

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l-1sarge1_mipsel.deb
      Size/MD5 checksum: 64228 c0ba8aaac79f6547d13db04ba13b39bd

PowerPC architecture:

    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l-1sarge1_powerpc.deb
      Size/MD5 checksum: 60004 85870f99024711bdf1bc5ed32398ce07

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l-1sarge1_s390.deb
      Size/MD5 checksum: 60052 5adb2907170ef095d50daf397193cfa2

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/a/arc/arc_5.21l-1sarge1_sparc.deb
      Size/MD5 checksum: 57084 88ec040ae647afb844d1c98a4c7a77a7

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 844-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
October 5th, 2005 http://www.debian.org/security/faq


Package : mod-auth-shadow
Vulnerability : programming error
Problem type : remote
Debian-specific: no
CVE ID : CAN-2005-2963
Debian Bug : 323789

A vulnerability in mod_auth_shadow, an Apache module that lets users perform HTTP authentication against /etc/shadow, has been discovered. The module runs for all locations that use the 'require group' directive which would bypass access restrictions controlled by another authorisation mechanism, such as AuthGroupFile file, if the username is listed in the password file and in the gshadow file in the proper group and the supplied password matches against the one in the shadow file.

This update requires an explicit "AuthShadow on" statement if website authentication should be checked against /etc/shadow.

For the old stable distribution (woody) this problem has been fixed in version 1.3-3.1woody.2.

For the stable distribution (sarge) this problem has been fixed in version 1.4-1sarge1.

For the unstable distribution (sid) this problem has been fixed in version 1.4-2.

We recommend that you upgrade your libapache-mod-auth-shadow package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody


Source archives:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/mod-auth-shadow_1.3-3.1woody.2.dsc
      Size/MD5 checksum: 628 78a6276d158c96247f87c2a82ad337c9
    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/mod-auth-shadow_1.3-3.1woody.2.diff.gz
      Size/MD5 checksum: 5818 e57059b3d026f4490e83ef48e7c64551
    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/mod-auth-shadow_1.3.orig.tar.gz
      Size/MD5 checksum: 7476 3ad4432193ac603049ad0f2fa94f2054

Alpha architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.3-3.1woody.2_alpha.deb
      Size/MD5 checksum: 12204 4f659abcf88fe710a35c09a24f6294d4

ARM architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.3-3.1woody.2_arm.deb
      Size/MD5 checksum: 11306 ed1b93be804e3233000e7bc9951ee836

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.3-3.1woody.2_i386.deb
      Size/MD5 checksum: 11334 a384bb22d08d3d8ad2ee76803517866f

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.3-3.1woody.2_ia64.deb
      Size/MD5 checksum: 13488 63798f86c1cd944d5f635890b1ae7edb

HP Precision architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.3-3.1woody.2_hppa.deb
      Size/MD5 checksum: 12048 cea187ef3898639b248c9b6f8b36e7a0

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.3-3.1woody.2_m68k.deb
      Size/MD5 checksum: 11302 8887098ee92b1be61470b8a00ac72df9

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.3-3.1woody.2_mips.deb
      Size/MD5 checksum: 11466 9846f15f1c98a3cbb01b12d8e8563d93

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.3-3.1woody.2_mipsel.deb
      Size/MD5 checksum: 11458 d2ae47a2320ef6a8b45aa2354c9eebe9

PowerPC architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.3-3.1woody.2_powerpc.deb
      Size/MD5 checksum: 11372 1ce0c98e16ea699726c0e45b98de5ec6

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.3-3.1woody.2_s390.deb
      Size/MD5 checksum: 11516 e92c004036842d0f6f79b0e5d9f64455

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.3-3.1woody.2_sparc.deb
      Size/MD5 checksum: 14484 524248ef32be0bffef4dcc147eece09b

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/mod-auth-shadow_1.4-1sarge1.dsc
      Size/MD5 checksum: 618 8a413e53ca39d904d95dccd1b0705693
    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/mod-auth-shadow_1.4-1sarge1.diff.gz
      Size/MD5 checksum: 5816 4b010699db55a2c3446e71cc4af6e167
    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/mod-auth-shadow_1.4.orig.tar.gz
      Size/MD5 checksum: 7982 7da6ea1d72640c334fefab4e078eadd4

Alpha architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.4-1sarge1_alpha.deb
      Size/MD5 checksum: 13462 9a035f44ccbfec2ddedeb97ba25de685

AMD64 architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.4-1sarge1_amd64.deb
      Size/MD5 checksum: 12978 ffdd9eab120efbd6ad58befb069ead8d

ARM architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.4-1sarge1_arm.deb
      Size/MD5 checksum: 12332 20edffd17e6cfed8bf60d50f0cf918da

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.4-1sarge1_i386.deb
      Size/MD5 checksum: 12426 7e27802cc15e0478e06f00cff72c4133

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.4-1sarge1_ia64.deb
      Size/MD5 checksum: 14444 b1a34f75958df70ee4566445ceb80a26

HP Precision architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.4-1sarge1_hppa.deb
      Size/MD5 checksum: 13602 448068ac275fe81e7ba0d997b8bc3566

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.4-1sarge1_m68k.deb
      Size/MD5 checksum: 12258 ae4ef5bdca2baaeb0067cf908e57ac09

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.4-1sarge1_mips.deb
      Size/MD5 checksum: 13238 e0a0f68fb3a164bc80607ba974a05f3d

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.4-1sarge1_mipsel.deb
      Size/MD5 checksum: 13248 24218030e050490cbe0578474ec46403

PowerPC architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.4-1sarge1_powerpc.deb
      Size/MD5 checksum: 14120 85d7a92000946e11db7ae213960c4927

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.4-1sarge1_s390.deb
      Size/MD5 checksum: 12964 46951fcacb6c99c779e31c7aa21d8bf3

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapache-mod-auth-shadow_1.4-1sarge1_sparc.deb
      Size/MD5 checksum: 12300 e05d59189d387427c9017180631aeba4

These files will probably be moved into the stable distribution on its next update.


For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

Gentoo Linux


Gentoo Linux Security Advisory GLSA 200510-01

http://security.gentoo.org/


Severity: Normal
Title: gtkdiskfree: Insecure temporary file creation
Date: October 03, 2005
Bugs: #104565
ID: 200510-01


Synopsis

gtkdiskfree is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.

Background

gtkdiskfree is a GTK-based GUI to show free disk space.

Affected packages


Package / Vulnerable / Unaffected
1 app-admin/gtkdiskfree < 1.9.3-r1 >= 1.9.3-r1

Description

Eric Romang discovered that gtkdiskfree insecurely creates a predictable temporary file to handle command output.

Impact

A local attacker could create a symbolic link in the temporary files directory, pointing to a valid file somewhere on the filesystem. When gtkdiskfree is executed, this would result in the file being overwritten with the rights of the user running the application.

Workaround

There is no known workaround at this time.

Resolution

All gtkdiskfree users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=app-admin/gtkdiskfree-1.9.3-r1"

References

[ 1 ] CAN-2005-2918

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2918

[ 2 ] Original Advisory

http://www.zataz.net/adviso/gtkdiskfree-09052005.txt

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200510-01.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0


Gentoo Linux Security Advisory GLSA 200510-02

http://security.gentoo.org/


Severity: Normal
Title: Berkeley MPEG Tools: Multiple insecure temporary files
Date: October 03, 2005
Bugs: #107344
ID: 200510-02


Synopsis

The Berkeley MPEG Tools use temporary files in various insecure ways, potentially allowing a local user to overwrite arbitrary files.

Background

The Berkeley MPEG Tools are a collection of utilities for manipulating MPEG video technology, including an encoder (mpeg_encode) and various conversion utilities.

Affected packages


Package / Vulnerable / Unaffected
1 media-video/mpeg-tools < 1.5b-r2 >= 1.5b-r2

Description

Mike Frysinger of the Gentoo Security Team discovered that mpeg_encode and the conversion utilities were creating temporary files with predictable or fixed filenames. The 'test' make target of the MPEG Tools also relied on several temporary files created insecurely.

Impact

A local attacker could create symbolic links in the temporary files directory, pointing to a valid file somewhere on the filesystem. When the utilities are executed (or 'make test' is run), this would result in the file being overwritten with the rights of the user running the command.

Workaround

There is no known workaround at this time.

Resolution

All Berkeley MPEG Tools users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=media-video/mpeg-tools-1.5b-r2"

References

[ 1 ] CAN-2005-3115

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3115

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200510-02.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0


Gentoo Linux Security Advisory GLSA 200510-03

http://security.gentoo.org/


Severity: Normal
Title: Uim: Privilege escalation vulnerability
Date: October 04, 2005
Bugs: #107748
ID: 200510-03


Synopsis

Under certain conditions, applications linked against Uim suffer from a privilege escalation vulnerability.

Background

Uim is a multilingual input method library which provides secure and useful input method for all languages.

Affected packages


Package / Vulnerable / Unaffected
1 app-i18n/uim < 0.4.9.1 >= 0.4.9.1

Description

Masanari Yamamoto discovered that Uim uses environment variables incorrectly. This bug causes a privilege escalation if setuid/setgid applications are linked to libuim. This bug only affects immodule-enabled Qt (if you build Qt 3.3.2 or later versions with USE="immqt" or USE="immqt-bc").

Impact

A malicious local user could exploit this vulnerability to execute arbitrary code with escalated privileges.

Workaround

There is no known workaround at this time.

Resolution

All Uim users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=app-i18n/uim-0.4.9.1"

References

[ 1 ] Original advisory

http://lists.freedesktop.org/pipermail/uim/2005-September/001346.html

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200510-03.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0


Gentoo Linux Security Advisory GLSA 200510-04

http://security.gentoo.org/


Severity: Normal
Title: Texinfo: Insecure temporary file creation
Date: October 05, 2005
Bugs: #106105
ID: 200510-04


Synopsis

Texinfo is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.

Background

Texinfo is the official documentation system created by the GNU project.

Affected packages


Package / Vulnerable / Unaffected
1 sys-apps/texinfo < 4.8-r1 >= 4.8-r1

Description

Frank Lichtenheld has discovered that the "sort_offline()" function in texindex insecurely creates temporary files with predictable filenames.

Impact

A local attacker could create symbolic links in the temporary files directory, pointing to a valid file somewhere on the filesystem. When texindex is executed, this would result in the file being overwritten with the rights of the user running the application.

Workaround

There is no known workaround at this time.

Resolution

All Texinfo users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=sys-apps/texinfo-4.8-r1"

References

[ 1 ] CAN-2005-3011

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3011

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200510-04.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0

Red Hat Linux


Red Hat Security Advisory

Synopsis: Low: slocate security update
Advisory ID: RHSA-2005:346-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-346.html
Issue date: 2005-10-05
Updated on: 2005-10-05
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-2499


1. Summary:

An updated slocate package that fixes a denial of service and various bugs is available.

This update has been rated as having low security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Problem description:

Slocate is a security-enhanced version of locate. Like locate, slocate searches through a central database (updated nightly) for files that match a given pattern. Slocate allows you to quickly find files anywhere on your system.

A bug was found in the way slocate scans the local filesystem. A carefully prepared directory structure could cause updatedb's file system scan to fail silently, resulting in an incomplete slocate database. The Common Vulnerabilities and Exposures project has assigned the name CAN-2005-2499 to this issue.

Additionally this update addresses the following issues:

  • - File system type exclusions were processed only when starting updatedb and did not reflect file systems mounted while updatedb was running (for example, automounted file systems.)
  • - File system type exclusions were ignored for file systems that were mounted to a path containing a symbolic link.
  • - Databases created by slocate were owned by the slocate group even if they were created by regular users.
  • - The default configuration excluded /mnt/floppy, but not /media.
  • - The default configuration did not exclude nfs4 file systems.

Users of slocate are advised to upgrade to this updated package, which contains backported patches and is not affected by these issues.

4. Solution:

Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system:

    http://www.redhat.com/docs/manuals/enterprise/

5. Bug IDs fixed (http://bugzilla.redhat.com/):

139950 - slocate collects .automount files over nfs
152253 - Incorrect path in /etc/updatedb.conf
156091 - updatedb indexes nfs4 filesystems
165430 - CAN-2005-2499 slocate DOS

6. RPMs required:

Red Hat Enterprise Linux AS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/slocate-2.7-13.el4.6.src.rpm
c7c0214f195ee403dac138a588bc3e8e slocate-2.7-13.el4.6.src.rpm

i386:
631c577185c94d9eb435ad0a792b04a4
slocate-2.7-13.el4.6.i386.rpm

ia64:
637f060239a27fc84e57f0c0877840be
slocate-2.7-13.el4.6.ia64.rpm

ppc:
790b0129014db4f62fb735cc6da16773
slocate-2.7-13.el4.6.ppc.rpm

s390:
d990745ab56de4211e3912c915d8f8ef
slocate-2.7-13.el4.6.s390.rpm

s390x:
441e2ccafcd7f1aed2a17b26d310eaf4
slocate-2.7-13.el4.6.s390x.rpm

x86_64:
76d6a19aafbca5f63e04fd28bceea094
slocate-2.7-13.el4.6.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/slocate-2.7-13.el4.6.src.rpm
c7c0214f195ee403dac138a588bc3e8e slocate-2.7-13.el4.6.src.rpm

i386:
631c577185c94d9eb435ad0a792b04a4
slocate-2.7-13.el4.6.i386.rpm

x86_64:
76d6a19aafbca5f63e04fd28bceea094
slocate-2.7-13.el4.6.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/slocate-2.7-13.el4.6.src.rpm
c7c0214f195ee403dac138a588bc3e8e slocate-2.7-13.el4.6.src.rpm

i386:
631c577185c94d9eb435ad0a792b04a4
slocate-2.7-13.el4.6.i386.rpm

ia64:
637f060239a27fc84e57f0c0877840be
slocate-2.7-13.el4.6.ia64.rpm

x86_64:
76d6a19aafbca5f63e04fd28bceea094
slocate-2.7-13.el4.6.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/slocate-2.7-13.el4.6.src.rpm
c7c0214f195ee403dac138a588bc3e8e slocate-2.7-13.el4.6.src.rpm

i386:
631c577185c94d9eb435ad0a792b04a4
slocate-2.7-13.el4.6.i386.rpm

ia64:
637f060239a27fc84e57f0c0877840be
slocate-2.7-13.el4.6.ia64.rpm

x86_64:
76d6a19aafbca5f63e04fd28bceea094
slocate-2.7-13.el4.6.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2499

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact details at https://www.redhat.com/security/team/contact/

Copyright 2005 Red Hat, Inc.


Red Hat Security Advisory

Synopsis: Low: vixie-cron security update
Advisory ID: RHSA-2005:361-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-361.html
Issue date: 2005-10-05
Updated on: 2005-10-05
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-1038


1. Summary:

An updated vixie-cron package that fixes various bugs and a security issue is now available.

This update has been rated as having low security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Problem description:

The vixie-cron package contains the Vixie version of cron. Cron is a standard UNIX daemon that runs specified programs at scheduled times.

A bug was found in the way vixie-cron installs new crontab files. It is possible for a local attacker to execute the crontab command in such a way that they can view the contents of another user's crontab file. The Common Vulnerabilities and Exposures project assigned the name CAN-2005-1038 to this issue.

Additionally, this update addresses the following issues:

  • Fixed improper limits on filename and command line lengths
  • Improved PAM access control conforming to EAL certification requirements
  • Improved reliability when running in a chroot environment
  • Mail recipient name checking disabled by default, can be re-enabled
  • Added '-p' "permit all crontabs" option to disable crontab mode checking

All users of vixie-cron should upgrade to this updated package, which contains backported patches and is not vulnerable to these issues.

4. Solution:

Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system:

    http://www.redhat.com/docs/manuals/enterprise/

5. Bug IDs fixed (http://bugzilla.redhat.com/):

147636 - cron fails to run user jobs and gives vague error message
154920 - CAN-2005-1038 vixie-cron information leak
159216 - vixie-cron updates for new audit system
163881 - Cron no longer allows read-only crontabs, enforces write access
163882 - cron fails with pam_access
163885 - crontab truncates file names greater than 100 characters.
163888 - CAN-2005-1038 vixie-cron information leak
163889 - [PATCH] List corruption when items are removed from /etc/cron.d

6. RPMs required:

Red Hat Enterprise Linux AS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/vixie-cron-4.1-36.EL4.src.rpm
e3fd76e5ba9887c8e11e1bc82d5fd485 vixie-cron-4.1-36.EL4.src.rpm

i386:
e8243ed213f8cfa5b50ac8f42a7ec9c7
vixie-cron-4.1-36.EL4.i386.rpm

ia64:
97380fd176e344f7df2d40d8e47f954c
vixie-cron-4.1-36.EL4.ia64.rpm

ppc:
2388e466c3e485de7b9e0a340d55d3b2
vixie-cron-4.1-36.EL4.ppc.rpm

s390:
85d62715dd6471e87b7bfbc14463c8bd
vixie-cron-4.1-36.EL4.s390.rpm

s390x:
14772968639ea37dc713e2f73e3292e0
vixie-cron-4.1-36.EL4.s390x.rpm

x86_64:
b3e6bbc02843e4e09d6488ab9c962cc2
vixie-cron-4.1-36.EL4.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/vixie-cron-4.1-36.EL4.src.rpm
e3fd76e5ba9887c8e11e1bc82d5fd485 vixie-cron-4.1-36.EL4.src.rpm

i386:
e8243ed213f8cfa5b50ac8f42a7ec9c7
vixie-cron-4.1-36.EL4.i386.rpm

x86_64:
b3e6bbc02843e4e09d6488ab9c962cc2
vixie-cron-4.1-36.EL4.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/vixie-cron-4.1-36.EL4.src.rpm
e3fd76e5ba9887c8e11e1bc82d5fd485 vixie-cron-4.1-36.EL4.src.rpm

i386:
e8243ed213f8cfa5b50ac8f42a7ec9c7
vixie-cron-4.1-36.EL4.i386.rpm

ia64:
97380fd176e344f7df2d40d8e47f954c
vixie-cron-4.1-36.EL4.ia64.rpm

x86_64:
b3e6bbc02843e4e09d6488ab9c962cc2
vixie-cron-4.1-36.EL4.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/vixie-cron-4.1-36.EL4.src.rpm
e3fd76e5ba9887c8e11e1bc82d5fd485 vixie-cron-4.1-36.EL4.src.rpm

i386:
e8243ed213f8cfa5b50ac8f42a7ec9c7
vixie-cron-4.1-36.EL4.i386.rpm

ia64:
97380fd176e344f7df2d40d8e47f954c
vixie-cron-4.1-36.EL4.ia64.rpm

x86_64:
b3e6bbc02843e4e09d6488ab9c962cc2
vixie-cron-4.1-36.EL4.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://www.redhat.com/security/team/key/#package

7. References:

http://www.securityfocus.com/archive/1/395093
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1038

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact details at https://www.redhat.com/security/team/contact/

Copyright 2005 Red Hat, Inc.


Red Hat Security Advisory

Synopsis: Low: net-snmp security update
Advisory ID: RHSA-2005:395-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-395.html
Issue date: 2005-10-05
Updated on: 2005-10-05
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-1740 CAN-2005-2177


1. Summary:

Updated net-snmp packages that fix two security issues and various bugs are now available.

This update has been rated as having low security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Problem description:

SNMP (Simple Network Management Protocol) is a protocol used for network management.

A denial of service bug was found in the way net-snmp uses network stream protocols. It is possible for a remote attacker to send a net-snmp agent a specially crafted packet that will crash the agent. The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the name CAN-2005-2177 to this issue.

An insecure temporary file usage bug was found in net-snmp's fixproc command. It is possible for a local user to modify the content of temporary files used by fixproc that can lead to arbitrary command execution. The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the name CAN-2005-1740 to this issue.

Additionally, the following bugs have been fixed:
- - The lmSensors are correctly recognized, snmp deamon no longer segfaults
- - The larger swap partition sizes are correctly reported
- - Querying hrSWInstalledLastUpdateTime no longer crashes the snmp deamon
- - Fixed error building ASN.1 representation
- - The 64-bit network counters correctly wrap
- - Large file systems are correctly handled
- - Snmptrapd initscript correctly reads options from its configuration
file /etc/snmp/snmptrapd.options
- - Snmp deamon no longer crashes when restarted using the agentX protocol
- - snmp daemon now reports gigabit Ethernet speeds correctly
- - MAC adresses are shown when requested instead of IP adresses

All users of net-snmp should upgrade to these updated packages, which resolve these issues.

4. Solution:

Before applying this update, make sure all previously released errata relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory only contains the desired RPMs.

Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system.

If up2date fails to connect to Red Hat Network due to SSL Certificate Errors, you need to install a version of the up2date client with an updated certificate. The latest version of up2date is available from the Red Hat FTP site and may also be downloaded directly from the RHN website:

https://rhn.redhat.com/help/latest-up2date.pxt

5. Bug IDs fixed (http://bugzilla.redhat.com/):

150084 - snmpd dies when getting enterprises.ucdavis.memory.memTotalSwap.0
150199 - snmpd exits without a diagnostic: SIGSEGV
154455 - 64bit network counters peg instead of wrapping
154798 - /etc/init.d/snmptrapd wrong order in setting variables...
155038 - x86_64: net-snmp dies when querying hrSWInstalledLastUpdateTime
158769 - CAN-2005-1740 net-snmp insecure temporary file usage
163688 - CAN-2005-2177 net-snmp denial of service

6. RPMs required:

Red Hat Enterprise Linux AS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/net-snmp-5.1.2-11.EL4.6.src.rpm
21a7852edcba0fe4e6f36da6a44bacbe net-snmp-5.1.2-11.EL4.6.src.rpm

i386:
120ec018b119e6b5ac27c3aa8299fbd6
net-snmp-5.1.2-11.EL4.6.i386.rpm
a109507ca1dc31a5b3feea46a46b79df
net-snmp-devel-5.1.2-11.EL4.6.i386.rpm
68db1a5a0fb3ff62a3714ef424012caa
net-snmp-libs-5.1.2-11.EL4.6.i386.rpm
d2bbe2634e4aea210403ff99243c081e
net-snmp-perl-5.1.2-11.EL4.6.i386.rpm
7b4d1f269c2e336124e1f5e425f565dc
net-snmp-utils-5.1.2-11.EL4.6.i386.rpm

ia64:
0a71089d87ace55a82f7e2a4c344c34d
net-snmp-5.1.2-11.EL4.6.ia64.rpm
9b368d3917851e2170b89f118d0c6365
net-snmp-devel-5.1.2-11.EL4.6.ia64.rpm
68db1a5a0fb3ff62a3714ef424012caa
net-snmp-libs-5.1.2-11.EL4.6.i386.rpm
8d2de3b650fa8d6e82695f79d9675758
net-snmp-libs-5.1.2-11.EL4.6.ia64.rpm
890a703ad611379fcd0413f0e8e73df0
net-snmp-perl-5.1.2-11.EL4.6.ia64.rpm
a375cde21874c713ad6c16746519cc4b
net-snmp-utils-5.1.2-11.EL4.6.ia64.rpm

ppc:
c9ca217a48da0a7aa035629ae1a315b6
net-snmp-5.1.2-11.EL4.6.ppc.rpm
717983be7c1f8ec261ffb7914b10bcb5
net-snmp-devel-5.1.2-11.EL4.6.ppc.rpm
1813f94dcaa10f1c5e9910c473220187
net-snmp-libs-5.1.2-11.EL4.6.ppc.rpm
6423451346096dc668635ea9ec6d0154
net-snmp-libs-5.1.2-11.EL4.6.ppc64.rpm
4d5d7f0732e0476a5052914d8ba03408
net-snmp-perl-5.1.2-11.EL4.6.ppc.rpm
de9792ce34d8fe0cf828e143e55a6e86
net-snmp-utils-5.1.2-11.EL4.6.ppc.rpm

s390:
b6d060cfaeb06f0898fef46280bc6dda
net-snmp-5.1.2-11.EL4.6.s390.rpm
2874be600171af40fdedc29190122677
net-snmp-devel-5.1.2-11.EL4.6.s390.rpm
c2895f557db41fa371ecdec220780150
net-snmp-libs-5.1.2-11.EL4.6.s390.rpm
b680f8bdc4669c2292950fb6db4e47d3
net-snmp-perl-5.1.2-11.EL4.6.s390.rpm
2bb808e9ef394ce25855822ef91af2cf
net-snmp-utils-5.1.2-11.EL4.6.s390.rpm

s390x:
9c212ed0a8aefd7db9cd57bf31d22e25
net-snmp-5.1.2-11.EL4.6.s390x.rpm
157b79487d0044c226ddf567294aa261
net-snmp-devel-5.1.2-11.EL4.6.s390x.rpm
c2895f557db41fa371ecdec220780150
net-snmp-libs-5.1.2-11.EL4.6.s390.rpm
cb9cf209f3281f9aede6305d2acc29a7
net-snmp-libs-5.1.2-11.EL4.6.s390x.rpm
af281e7c2985218b76eebe495a8c62bf
net-snmp-perl-5.1.2-11.EL4.6.s390x.rpm
ff879a134c8c06cc52633ca05af552b0
net-snmp-utils-5.1.2-11.EL4.6.s390x.rpm

x86_64:
3f41e093b4bd63b26f0882223f938ba8
net-snmp-5.1.2-11.EL4.6.x86_64.rpm
257a00d2957784b1547de58b568eadf2
net-snmp-devel-5.1.2-11.EL4.6.x86_64.rpm
68db1a5a0fb3ff62a3714ef424012caa
net-snmp-libs-5.1.2-11.EL4.6.i386.rpm
e667da22eed9f976533b5ac85914d519
net-snmp-libs-5.1.2-11.EL4.6.x86_64.rpm
6b7712c783fb96d776603199c0e29297
net-snmp-perl-5.1.2-11.EL4.6.x86_64.rpm
1bad984449842d093ef0c29b45cbc2f6
net-snmp-utils-5.1.2-11.EL4.6.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/net-snmp-5.1.2-11.EL4.6.src.rpm
21a7852edcba0fe4e6f36da6a44bacbe net-snmp-5.1.2-11.EL4.6.src.rpm

i386:
120ec018b119e6b5ac27c3aa8299fbd6
net-snmp-5.1.2-11.EL4.6.i386.rpm
a109507ca1dc31a5b3feea46a46b79df
net-snmp-devel-5.1.2-11.EL4.6.i386.rpm
68db1a5a0fb3ff62a3714ef424012caa
net-snmp-libs-5.1.2-11.EL4.6.i386.rpm
d2bbe2634e4aea210403ff99243c081e
net-snmp-perl-5.1.2-11.EL4.6.i386.rpm
7b4d1f269c2e336124e1f5e425f565dc
net-snmp-utils-5.1.2-11.EL4.6.i386.rpm

x86_64:
3f41e093b4bd63b26f0882223f938ba8
net-snmp-5.1.2-11.EL4.6.x86_64.rpm
257a00d2957784b1547de58b568eadf2
net-snmp-devel-5.1.2-11.EL4.6.x86_64.rpm
68db1a5a0fb3ff62a3714ef424012caa
net-snmp-libs-5.1.2-11.EL4.6.i386.rpm
e667da22eed9f976533b5ac85914d519
net-snmp-libs-5.1.2-11.EL4.6.x86_64.rpm
6b7712c783fb96d776603199c0e29297
net-snmp-perl-5.1.2-11.EL4.6.x86_64.rpm
1bad984449842d093ef0c29b45cbc2f6
net-snmp-utils-5.1.2-11.EL4.6.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/net-snmp-5.1.2-11.EL4.6.src.rpm
21a7852edcba0fe4e6f36da6a44bacbe net-snmp-5.1.2-11.EL4.6.src.rpm

i386:
120ec018b119e6b5ac27c3aa8299fbd6
net-snmp-5.1.2-11.EL4.6.i386.rpm
a109507ca1dc31a5b3feea46a46b79df
net-snmp-devel-5.1.2-11.EL4.6.i386.rpm
68db1a5a0fb3ff62a3714ef424012caa
net-snmp-libs-5.1.2-11.EL4.6.i386.rpm
d2bbe2634e4aea210403ff99243c081e
net-snmp-perl-5.1.2-11.EL4.6.i386.rpm
7b4d1f269c2e336124e1f5e425f565dc
net-snmp-utils-5.1.2-11.EL4.6.i386.rpm

ia64:
0a71089d87ace55a82f7e2a4c344c34d
net-snmp-5.1.2-11.EL4.6.ia64.rpm
9b368d3917851e2170b89f118d0c6365
net-snmp-devel-5.1.2-11.EL4.6.ia64.rpm
68db1a5a0fb3ff62a3714ef424012caa
net-snmp-libs-5.1.2-11.EL4.6.i386.rpm
8d2de3b650fa8d6e82695f79d9675758
net-snmp-libs-5.1.2-11.EL4.6.ia64.rpm
890a703ad611379fcd0413f0e8e73df0
net-snmp-perl-5.1.2-11.EL4.6.ia64.rpm
a375cde21874c713ad6c16746519cc4b
net-snmp-utils-5.1.2-11.EL4.6.ia64.rpm

x86_64:
3f41e093b4bd63b26f0882223f938ba8
net-snmp-5.1.2-11.EL4.6.x86_64.rpm
257a00d2957784b1547de58b568eadf2
net-snmp-devel-5.1.2-11.EL4.6.x86_64.rpm
68db1a5a0fb3ff62a3714ef424012caa
net-snmp-libs-5.1.2-11.EL4.6.i386.rpm
e667da22eed9f976533b5ac85914d519
net-snmp-libs-5.1.2-11.EL4.6.x86_64.rpm
6b7712c783fb96d776603199c0e29297
net-snmp-perl-5.1.2-11.EL4.6.x86_64.rpm
1bad984449842d093ef0c29b45cbc2f6
net-snmp-utils-5.1.2-11.EL4.6.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/net-snmp-5.1.2-11.EL4.6.src.rpm
21a7852edcba0fe4e6f36da6a44bacbe net-snmp-5.1.2-11.EL4.6.src.rpm

i386:
120ec018b119e6b5ac27c3aa8299fbd6
net-snmp-5.1.2-11.EL4.6.i386.rpm
a109507ca1dc31a5b3feea46a46b79df
net-snmp-devel-5.1.2-11.EL4.6.i386.rpm
68db1a5a0fb3ff62a3714ef424012caa
net-snmp-libs-5.1.2-11.EL4.6.i386.rpm
d2bbe2634e4aea210403ff99243c081e
net-snmp-perl-5.1.2-11.EL4.6.i386.rpm
7b4d1f269c2e336124e1f5e425f565dc
net-snmp-utils-5.1.2-11.EL4.6.i386.rpm

ia64:
0a71089d87ace55a82f7e2a4c344c34d
net-snmp-5.1.2-11.EL4.6.ia64.rpm
9b368d3917851e2170b89f118d0c6365
net-snmp-devel-5.1.2-11.EL4.6.ia64.rpm
68db1a5a0fb3ff62a3714ef424012caa
net-snmp-libs-5.1.2-11.EL4.6.i386.rpm
8d2de3b650fa8d6e82695f79d9675758
net-snmp-libs-5.1.2-11.EL4.6.ia64.rpm
890a703ad611379fcd0413f0e8e73df0
net-snmp-perl-5.1.2-11.EL4.6.ia64.rpm
a375cde21874c713ad6c16746519cc4b
net-snmp-utils-5.1.2-11.EL4.6.ia64.rpm

x86_64:
3f41e093b4bd63b26f0882223f938ba8
net-snmp-5.1.2-11.EL4.6.x86_64.rpm
257a00d2957784b1547de58b568eadf2
net-snmp-devel-5.1.2-11.EL4.6.x86_64.rpm
68db1a5a0fb3ff62a3714ef424012caa
net-snmp-libs-5.1.2-11.EL4.6.i386.rpm
e667da22eed9f976533b5ac85914d519
net-snmp-libs-5.1.2-11.EL4.6.x86_64.rpm
6b7712c783fb96d776603199c0e29297
net-snmp-perl-5.1.2-11.EL4.6.x86_64.rpm
1bad984449842d093ef0c29b45cbc2f6
net-snmp-utils-5.1.2-11.EL4.6.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1740
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2177

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact details at https://www.redhat.com/security/team/contact/

Copyright 2005 Red Hat, Inc.


Red Hat Security Advisory

Synopsis: Updated kernel packages available for Red Hat Enterprise Linux 4 Update 2
Advisory ID: RHSA-2005:514-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-514.html
Issue date: 2005-10-05
Updated on: 2005-10-05
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0756 CAN-2005-1265 CAN-2005-1761 CAN-2005-1762 CAN-2005-1763 CAN-2005-2098 CAN-2005-2099 CAN-2005-2100 CAN-2005-2456 CAN-2005-2490 CAN-2005-2492 CAN-2005-2555 CAN-2005-2801 CAN-2005-2872


1. Summary:

Updated kernel packages are now available as part of ongoing support and maintenance of Red Hat Enterprise Linux version 4. This is the second regular update.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, noarch, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, noarch, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, noarch, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, noarch, x86_64

3. Problem description:

The Linux kernel handles the basic functions of the operating system.

This is the second regular kernel update to Red Hat Enterprise Linux 4.

New features introduced in this update include:
- - Audit support
- - systemtap - kprobes, relayfs
- - Keyring support
- - ISCI - iscsi_sfnet 4:0.1.11-1
- - Device mapper mirroring and multipath support
- - Intel dual core support
- - esb2 chipset support
- - Increased exec-shield coverage
- - Dirty page tracking for HA systems
- - Diskdump -- allow partial diskdumps and directing to swap

There were several bug fixes in various parts of the kernel. The ongoing effort to resolve these problems has resulted in a marked improvement in the reliability and scalability of Red Hat Enterprise Linux 4.

The following security bugs were fixed in this update, detailed below with corresponding CAN names available from the Common Vulnerabilities and Exposures project (cve.mitre.org/):

  • - flaws in ptrace() syscall handling on 64-bit systems that allowed a local user to cause a denial of service (crash) (CAN-2005-0756, CAN-2005-1761, CAN-2005-1762, CAN-2005-1763)
  • - flaws in IPSEC network handling that allowed a local user to cause a denial of service or potentially gain privileges (CAN-2005-2456, CAN-2005-2555)
  • - a flaw in sendmsg() syscall handling on 64-bit systems that allowed a local user to cause a denial of service or potentially gain privileges (CAN-2005-2490)
  • - a flaw in sendmsg() syscall handling that allowed a local user to cause a denial of service by altering hardware state (CAN-2005-2492)
  • - a flaw that prevented the topdown allocator from allocating mmap areas all the way down to address zero (CAN-2005-1265)
  • - flaws dealing with keyrings that could cause a local denial of service (CAN-2005-2098, CAN-2005-2099)
  • - a flaw in the 4GB split patch that could allow a local denial of service (CAN-2005-2100)
  • - a xattr sharing bug in the ext2 and ext3 file systems that could cause default ACLs to disappear (CAN-2005-2801)
  • - a flaw in the ipt_recent module on 64-bit architectures which could allow a remote denial of service (CAN-2005-2872)

The following device drivers have been upgraded to new versions:

qla2100 --------- 8.00.00b21-k to 8.01.00b5-rh2
qla2200 --------- 8.00.00b21-k to 8.01.00b5-rh2
qla2300 --------- 8.00.00b21-k to 8.01.00b5-rh2
qla2322 --------- 8.00.00b21-k to 8.01.00b5-rh2
qla2xxx --------- 8.00.00b21-k to 8.01.00b5-rh2
qla6312 --------- 8.00.00b21-k to 8.01.00b5-rh2
megaraid_mbox --- 2.20.4.5 to 2.20.4.6
megaraid_mm ----- 2.20.2.5 to 2.20.2.6
lpfc ------------ 0:8.0.16.6_x2 to 0:8.0.16.17 cciss ----------- 2.6.4 to 2.6.6
ipw2100 --------- 1.0.3 to 1.1.0
tg3 ------------- 3.22-rh to 3.27-rh
e100 ------------ 3.3.6-k2-NAPI to 3.4.8-k2-NAPI
e1000 ----------- 5.6.10.1-k2-NAPI to 6.0.54-k2-NAPI
3c59x ----------- LK1.1.19
mptbase --------- 3.01.16 to 3.02.18
ixgb ------------ 1.0.66 to 1.0.95-k2-NAPI
libata ---------- 1.10 to 1.11
sata_via -------- 1.0 to 1.1
sata_ahci ------- 1.00 to 1.01
sata_qstor ------ 0.04
sata_sil -------- 0.8 to 0.9
sata_svw -------- 1.05 to 1.06
s390: crypto ---- 1.31 to 1.57
s390: zfcp ------
s390: CTC-MPC ---
s390: dasd -------
s390: cio -------
s390: qeth ------

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels to the packages associated with their machine architectures and configurations as listed in this erratum.

4. Solution:

Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system:

    http://www.redhat.com/docs/manuals/enterprise/

5. Bug IDs fixed (http://bugzilla.redhat.com/):

114578 - RHEL4 U1: File Delegation, at least read-only.
130914 - RHEL4: keyring support (OpenAFS enabler)
134790 - Inspiron 8500 practically hangs when configuring b44 NIC with 1.5G memory
135669 - tcsendbreak fails in compat mode
137343 - RH40-beta1, embedded IDE/PCI drivers not honoring Sub ID's/Class code
140002 - [PATCH] i2o_block timeout Adaptec 2400A raid card
141783 - domain validation fails on DVD-305 when CD in drive
142989 - Terminated threads' resource usage is hidden from procps
144668 - System doesn't reboot even if kernel.panic is > 0 on RHEL-4 Beta-2.
145575 - [RHEL4-U2][Diskdump] Partial dump
145648 - Socket option IP_FREEBIND has no effect on SCTP socket.
145659 - Socket option SO_BINDTODEVICE problems with SCTP listening socket.
145976 - Sub-second mtime changes without modifying file
146187 - [RHEL4RC1] chicony usb keyboard fails, with side effects
147233 - NFSv3 over Kerberos: gss_get_mic FAILED during xdm login attempt
147496 - Sense data errors are seen when trying to access a travan tape device
149478 - Bug / data corruption on error handling in Ext3 under I/O failure condition
149919 - highmem.c: fix bio error propagation
149979 - kernel panic when tar'ing data to IDE Tape device
150152 - nfsv4 callback authentication patch
151222 - smp_apic_timer_interrupt() executes on kernel thread stack
151315 - kernel BUG() at pageattr:107 with rmmod e1000
151323 - Kernel BUG at pageattr:107
151429 - Fusion MPT doesn't handle multiple PCI domains correctly
152162 - LVM snapshots over md raid1 cause corruption
152440 - ppc64 arches can crash when single setpping a debugger through syscall return code
152619 - openipmi drivers missing compat_ioctl's on x86_64 kernel
152982 - fail to mount nfs4 servers
154055 - RHEL4 U1 Oracle 10G 10.0.3 aio hang running tpc-c
154100 - assertion failrue in semaphore.h caused by perfmon
154347 - spin_lock already locked by xfrm4_output
154435 - kernel dm-emc: Fix spinlock reset
154442 - kernel dm-multipath: multiple pg_inits can be issued in parallel
154451 - CAN-2005-1762 x86_64 sysret exception leads to DoS
154733 - oops when catting /proc/net/ip_conntrack_expect
155278 - Debugger killed by kernel when looking at the lowest addressed vmalloc page
155354 - 20050313 SCSI tape security
155706 - CAN-2005-2801 xattr sharing bug
155932 - [RHEL4-U2][Diskdump] hangs when SCSI drive is busy
156010 - [RHEL4-U2] Diskdump - swap partition support
156705 - Serial console corrupt on boot
157239 - Systemtap patches to be ported to RHEL4 U2 kernel
157725 - sysctl -A returns an error
157900 - [not quite PATCH] tg3 driver crashes kernel with BCM5752 chip, newer driver is OK
158107 - Serial console turns into garbage after initialising 16550A
158293 - nfs server intermitently claims ENOENT on existing files or directories
158878 - CAN-2005-1265 Prevent NULL mmap in topdown model
158883 - Annoying i2o_config kernel module messages during raidutil run
158930 - 32-bit GETBLKSIZE ioctl overflows incorrectly on 64-bit hosts.
158974 - [Patch] modprobling a module signed with a key not known to the kernel can result in a panic.
159640 - proc and sysctl interface for lockd grace period do not work
159671 - CAN-2005-1761 local user can use ptrace to crash system
159739 - [Stratus RHEL4U2] csb5 functions are tagged with __init. This causes a crash in a hot-plug environment
159765 - RHEL4 Data corruption in spite of using O_SYNC
159918 - CAN-2005-0756 x86_64 crash (ptrace-check-segment)
159921 - CAN-2005-1763 x86_64 crash (x86_64-ptrace-overflow)
160028 - Kernel BUG at pageattr:107
160518 - audit: file system and user space filtering by auid
160522 - audit: teach OOM killer about auditd
160524 - audit: file system attribute change tracking
160526 - audit:PATH record mode flags are wrong sometimes
160528 - audit: file system watch on block device
160547 - when removing scsi hosts commands are not leaked
160548 - when removing scsi hosts commands are not leaked
160654 - audit: kernel audits auditd
160663 - cable link state ignored on ethernet card (b44).
160812 - fixes exec-shield to not randomize to between end-of-binary and start-of-brk
160882 - i2o RAID monitoring memory leak
161143 - Need export of generic_drop_inode for OCFS2 support
161156 - 'mt tell' fails - backported kernel bug likely
161314 - Bluetooth paring did not work anymore since update to 2.6.9-11.EL
161789 - GET_INDEX macro in aspm pci fixup code can overwrite end of the array
161995 - kernel panic when rm -rf directory structure on tmpfs filesystem
162108 - only the main thread is shown by top(1)
162257 - irq stacks not being used for hardirqs
162548 - interrupt handlers run on thread's kernel stack
162728 - JBD race during shutdown of a journal
163528 - /dev/tty won't open during blocking /dev/ttyS1 open
164094 - Placeholder for 2.6.x SATA update 20050724-1
164228 - Export sys_recvmesg for cluster snapshot
164338 - fix aio hang when reading beyond EOF
164449 - RHEL4 [NETFILTER]: Fix deadlock in ip6_queue.
164450 - [NETFILTER]: Fix potential memory corruption in NAT code (aka memory NAT)
164628 - pci_scan_device can cause master abort
164630 - panic while running fsstress to a filesystem on a mirror
164979 - CAN-2005-2098 Error during attempt to join key management session can leave semaphore pinned
164991 - CAN-2005-2099 Destruction of failed keyring oopses
165127 - acpi_processor_get_performance_states fails on empty table entries (_PSS)
165163 - audit - syscall performance
165242 - mirrors possibly reporting invalid blocks to the filesystem
165384 - cpufreq driver hangs when using SMP Powernow
165547 - CAN-2005-2100 4G/4G split bounds checking
165560 - CAN-2005-2456 IPSEC overflow
165717 - ext on top of mirror attempts to access beyond end of device: dm-5: rw=0, want=16304032720, limit=20971520
166131 - CAN-2005-2555 IPSEC lacks restrictions
166248 - CAN-2005-2490 sendmsg compat stack overflow
166830 - CAN-2005-2492 sendmsg DoS
167126 - bad elf check in module-verify.c
167412 - [RFC] [RHEL4 U2 patch] dual-core detection gap for i386 build
167668 - LTC17960-Kernel panic at key_put+0x4/0x19 [REGRESSION]
167703 - CAN-2005-2872 ipt_recent crash
167711 - LTC18014-powernow-k8 debug messages are enabled

6. RPMs required:

Red Hat Enterprise Linux AS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/kernel-2.6.9-22.EL.src.rpm
d7cf602d54f72e89550ab6212f63d64f kernel-2.6.9-22.EL.src.rpm

i386:
a90d57e29a5a57bd0249f61f24ee21ac
kernel-2.6.9-22.EL.i686.rpm
6d81ff3a6ee57be6cf3f93066afac875
kernel-devel-2.6.9-22.EL.i686.rpm
6591a9886ecda87f164042f015bc1920
kernel-hugemem-2.6.9-22.EL.i686.rpm
f39546e6d5a80353878b6087b64ef23b
kernel-hugemem-devel-2.6.9-22.EL.i686.rpm
73e68b49d3ed6b658e6ee716e45d4b2f
kernel-smp-2.6.9-22.EL.i686.rpm
0348f9239ec05111b2ef4cbdb9efebb8
kernel-smp-devel-2.6.9-22.EL.i686.rpm

ia64:
db70258b904e1f87b59226b77729c182
kernel-2.6.9-22.EL.ia64.rpm
74dca9054b5cd29a265b0b2dbc06393d
kernel-devel-2.6.9-22.EL.ia64.rpm

noarch:
dacf6c96256e842e031359e2a00914f6
kernel-doc-2.6.9-22.EL.noarch.rpm

ppc:
7ee94732c4cdab19a3684c08eafec929
kernel-2.6.9-22.EL.ppc64.rpm
ef79ea0618694258e1c607ef406e121e
kernel-2.6.9-22.EL.ppc64iseries.rpm
3828e3ed47289360e0e310a69b920062
kernel-devel-2.6.9-22.EL.ppc64.rpm
420ceaa39206ab620c8d994b358001a0
kernel-devel-2.6.9-22.EL.ppc64iseries.rpm

s390:
63b72f836b261391e592f86613cccd29
kernel-2.6.9-22.EL.s390.rpm
bf0e19ae76243b7449b2d5d8317c8f01
kernel-devel-2.6.9-22.EL.s390.rpm

s390x:
262170f75c72b397b7bf0cad781f5a0e
kernel-2.6.9-22.EL.s390x.rpm
6aceef8a0446aceecc7cebe09232bee3
kernel-devel-2.6.9-22.EL.s390x.rpm

x86_64:
c91230d67ed857a4726d8d810717b571
kernel-2.6.9-22.EL.x86_64.rpm
00908911201abd482b8ff69e6ab91d4d
kernel-devel-2.6.9-22.EL.x86_64.rpm
e6a37366e53f94b361199c10b03f5f73
kernel-smp-2.6.9-22.EL.x86_64.rpm
a34cfbb4d3620d537dbdcb6ffca5ba20
kernel-smp-devel-2.6.9-22.EL.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/kernel-2.6.9-22.EL.src.rpm
d7cf602d54f72e89550ab6212f63d64f kernel-2.6.9-22.EL.src.rpm

i386:
a90d57e29a5a57bd0249f61f24ee21ac
kernel-2.6.9-22.EL.i686.rpm
6d81ff3a6ee57be6cf3f93066afac875
kernel-devel-2.6.9-22.EL.i686.rpm
6591a9886ecda87f164042f015bc1920
kernel-hugemem-2.6.9-22.EL.i686.rpm
f39546e6d5a80353878b6087b64ef23b
kernel-hugemem-devel-2.6.9-22.EL.i686.rpm
73e68b49d3ed6b658e6ee716e45d4b2f
kernel-smp-2.6.9-22.EL.i686.rpm
0348f9239ec05111b2ef4cbdb9efebb8
kernel-smp-devel-2.6.9-22.EL.i686.rpm

noarch:
dacf6c96256e842e031359e2a00914f6
kernel-doc-2.6.9-22.EL.noarch.rpm

x86_64:
c91230d67ed857a4726d8d810717b571
kernel-2.6.9-22.EL.x86_64.rpm
00908911201abd482b8ff69e6ab91d4d
kernel-devel-2.6.9-22.EL.x86_64.rpm
e6a37366e53f94b361199c10b03f5f73
kernel-smp-2.6.9-22.EL.x86_64.rpm
a34cfbb4d3620d537dbdcb6ffca5ba20
kernel-smp-devel-2.6.9-22.EL.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/kernel-2.6.9-22.EL.src.rpm
d7cf602d54f72e89550ab6212f63d64f kernel-2.6.9-22.EL.src.rpm

i386:
a90d57e29a5a57bd0249f61f24ee21ac
kernel-2.6.9-22.EL.i686.rpm
6d81ff3a6ee57be6cf3f93066afac875
kernel-devel-2.6.9-22.EL.i686.rpm
6591a9886ecda87f164042f015bc1920
kernel-hugemem-2.6.9-22.EL.i686.rpm
f39546e6d5a80353878b6087b64ef23b
kernel-hugemem-devel-2.6.9-22.EL.i686.rpm
73e68b49d3ed6b658e6ee716e45d4b2f
kernel-smp-2.6.9-22.EL.i686.rpm
0348f9239ec05111b2ef4cbdb9efebb8
kernel-smp-devel-2.6.9-22.EL.i686.rpm

ia64:
db70258b904e1f87b59226b77729c182
kernel-2.6.9-22.EL.ia64.rpm
74dca9054b5cd29a265b0b2dbc06393d
kernel-devel-2.6.9-22.EL.ia64.rpm

noarch:
dacf6c96256e842e031359e2a00914f6
kernel-doc-2.6.9-22.EL.noarch.rpm

x86_64:
c91230d67ed857a4726d8d810717b571
kernel-2.6.9-22.EL.x86_64.rpm
00908911201abd482b8ff69e6ab91d4d
kernel-devel-2.6.9-22.EL.x86_64.rpm
e6a37366e53f94b361199c10b03f5f73
kernel-smp-2.6.9-22.EL.x86_64.rpm
a34cfbb4d3620d537dbdcb6ffca5ba20
kernel-smp-devel-2.6.9-22.EL.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/kernel-2.6.9-22.EL.src.rpm
d7cf602d54f72e89550ab6212f63d64f kernel-2.6.9-22.EL.src.rpm

i386:
a90d57e29a5a57bd0249f61f24ee21ac
kernel-2.6.9-22.EL.i686.rpm
6d81ff3a6ee57be6cf3f93066afac875
kernel-devel-2.6.9-22.EL.i686.rpm
6591a9886ecda87f164042f015bc1920
kernel-hugemem-2.6.9-22.EL.i686.rpm
f39546e6d5a80353878b6087b64ef23b
kernel-hugemem-devel-2.6.9-22.EL.i686.rpm
73e68b49d3ed6b658e6ee716e45d4b2f
kernel-smp-2.6.9-22.EL.i686.rpm
0348f9239ec05111b2ef4cbdb9efebb8
kernel-smp-devel-2.6.9-22.EL.i686.rpm

ia64:
db70258b904e1f87b59226b77729c182
kernel-2.6.9-22.EL.ia64.rpm
74dca9054b5cd29a265b0b2dbc06393d
kernel-devel-2.6.9-22.EL.ia64.rpm

noarch:
dacf6c96256e842e031359e2a00914f6
kernel-doc-2.6.9-22.EL.noarch.rpm

x86_64:
c91230d67ed857a4726d8d810717b571
kernel-2.6.9-22.EL.x86_64.rpm
00908911201abd482b8ff69e6ab91d4d
kernel-devel-2.6.9-22.EL.x86_64.rpm
e6a37366e53f94b361199c10b03f5f73
kernel-smp-2.6.9-22.EL.x86_64.rpm
a34cfbb4d3620d537dbdcb6ffca5ba20
kernel-smp-devel-2.6.9-22.EL.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0756
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1265
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1761
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1762
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1763
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2098
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2099
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2100
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2456
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2490
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2492
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2555
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2801
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2872

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact details at https://www.redhat.com/security/team/contact/

Copyright 2005 Red Hat, Inc.


Red Hat Security Advisory

Synopsis: Moderate: openssh security update
Advisory ID: RHSA-2005:527-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-527.html
Issue date: 2005-10-05
Updated on: 2005-10-05
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-2798


1. Summary:

Updated openssh packages that fix a security issue, bugs, and add support for recording login user IDs for audit are now available for Red Hat Enterprise Linux 4.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Problem description:

OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation.

An error in the way OpenSSH handled GSSAPI credential delegation was discovered. OpenSSH as distributed with Red Hat Enterprise Linux 4 contains support for GSSAPI user authentication, typically used for supporting Kerberos. On OpenSSH installations which have GSSAPI enabled, this flaw could allow a user who sucessfully authenticates using a method other than GSSAPI to be delegated with GSSAPI credentials. The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the name CAN-2005-2798 to this issue.

Additionally, the following bugs have been addressed:

The ssh command incorrectly failed when it was issued by the root user with a non-default group set.

The sshd daemon could fail to properly close the client connection if multiple X clients were forwarded over the connection and the client session exited.

The sshd daemon could bind only on the IPv6 address family for X forwarding if the port on IPv4 address family was already bound. The X forwarding did not work in such cases.

This update also adds support for recording login user IDs for the auditing service. The user ID is attached to the audit records generated from the user's session.

All users of openssh should upgrade to these updated packages, which contain backported patches to resolve these issues.

4. Solution:

Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system:

    http://www.redhat.com/docs/manuals/enterprise/

5. Bug IDs fixed (http://bugzilla.redhat.com/):

159331 - sshd update for new audit system 167444 - CAN-2005-2798 Improper GSSAPI credential delegation

6. RPMs required:

Red Hat Enterprise Linux AS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/openssh-3.9p1-8.RHEL4.9.src.rpm
2cbb0102ce3dc2c36c328819f8522bbc openssh-3.9p1-8.RHEL4.9.src.rpm

i386:
4a5add7335d6b6bcf9a202e45e782eee
openssh-3.9p1-8.RHEL4.9.i386.rpm
77cc6d8b6be9c613f80cd7d52c9f91e3
openssh-askpass-3.9p1-8.RHEL4.9.i386.rpm
76c9ac8255dbc25184887dd93cfdb047
openssh-askpass-gnome-3.9p1-8.RHEL4.9.i386.rpm
45350fbd7c5356467ebfc2e2a7bfc55a
openssh-clients-3.9p1-8.RHEL4.9.i386.rpm
32e69cc88f09f6785badd3b82fdccb31
openssh-server-3.9p1-8.RHEL4.9.i386.rpm

ia64:
f27d73d28c920358dcb434c3ed8489cf
openssh-3.9p1-8.RHEL4.9.ia64.rpm
512632b31d333408cf2e05a3e567e16a
openssh-askpass-3.9p1-8.RHEL4.9.ia64.rpm
6771aafbd50b0ead67418404cbd63711
openssh-askpass-gnome-3.9p1-8.RHEL4.9.ia64.rpm
0355970673f296c38ee961549665b64d
openssh-clients-3.9p1-8.RHEL4.9.ia64.rpm
40fa71b924423c63af6215255cc21198
openssh-server-3.9p1-8.RHEL4.9.ia64.rpm

ppc:
e97bdb7f35c89a540f9c3204064c4b7e
openssh-3.9p1-8.RHEL4.9.ppc.rpm
93dbfdb6052e0e4532d183b2dab9cb95
openssh-askpass-3.9p1-8.RHEL4.9.ppc.rpm
9e8e056a8677d7bdd45479be6c12f47d
openssh-askpass-gnome-3.9p1-8.RHEL4.9.ppc.rpm
3af1774ffe5f61d7d0f89a1e0093bcff
openssh-clients-3.9p1-8.RHEL4.9.ppc.rpm
3ec577e0d009372ed16343f8d7ddef4d
openssh-server-3.9p1-8.RHEL4.9.ppc.rpm

s390:
dc7368330098bd6b02babcf62ae31773
openssh-3.9p1-8.RHEL4.9.s390.rpm
bbe31ee642601ed16e64aebca844adf3
openssh-askpass-3.9p1-8.RHEL4.9.s390.rpm
b45278314ff79575284af2a0ddf09f8f
openssh-askpass-gnome-3.9p1-8.RHEL4.9.s390.rpm
eb0871dc10d5eb1541f2bd240b86d1bb
openssh-clients-3.9p1-8.RHEL4.9.s390.rpm
fa1669804538da84a5b312d237eb65bc
openssh-server-3.9p1-8.RHEL4.9.s390.rpm

s390x:
a26f854317e26af188704d5df98b302b
openssh-3.9p1-8.RHEL4.9.s390x.rpm
7386e0e001ec6534c5666316f6ac1aa6
openssh-askpass-3.9p1-8.RHEL4.9.s390x.rpm
26e80a25582afc8665b853b9fd844907
openssh-askpass-gnome-3.9p1-8.RHEL4.9.s390x.rpm
65a0209831ac79f162f75e491ec7696a
openssh-clients-3.9p1-8.RHEL4.9.s390x.rpm
2856776521344601307cdcbb9e6af2e6
openssh-server-3.9p1-8.RHEL4.9.s390x.rpm

x86_64:
8e2c46e097fff0172553d821e6810f91
openssh-3.9p1-8.RHEL4.9.x86_64.rpm
14a78c2264965373c6c56d63f73f60e5
openssh-askpass-3.9p1-8.RHEL4.9.x86_64.rpm
b799e4ed3d8d6aaf3439e06c5ee29b21
openssh-askpass-gnome-3.9p1-8.RHEL4.9.x86_64.rpm
e15d265ea0f955724b27cb15f2230f4f
openssh-clients-3.9p1-8.RHEL4.9.x86_64.rpm
56bab36b63f94a4adcaa79ef026df03e
openssh-server-3.9p1-8.RHEL4.9.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/openssh-3.9p1-8.RHEL4.9.src.rpm
2cbb0102ce3dc2c36c328819f8522bbc openssh-3.9p1-8.RHEL4.9.src.rpm

i386:
4a5add7335d6b6bcf9a202e45e782eee
openssh-3.9p1-8.RHEL4.9.i386.rpm
77cc6d8b6be9c613f80cd7d52c9f91e3
openssh-askpass-3.9p1-8.RHEL4.9.i386.rpm
76c9ac8255dbc25184887dd93cfdb047
openssh-askpass-gnome-3.9p1-8.RHEL4.9.i386.rpm
45350fbd7c5356467ebfc2e2a7bfc55a
openssh-clients-3.9p1-8.RHEL4.9.i386.rpm
32e69cc88f09f6785badd3b82fdccb31
openssh-server-3.9p1-8.RHEL4.9.i386.rpm

x86_64:
8e2c46e097fff0172553d821e6810f91
openssh-3.9p1-8.RHEL4.9.x86_64.rpm
14a78c2264965373c6c56d63f73f60e5
openssh-askpass-3.9p1-8.RHEL4.9.x86_64.rpm
b799e4ed3d8d6aaf3439e06c5ee29b21
openssh-askpass-gnome-3.9p1-8.RHEL4.9.x86_64.rpm
e15d265ea0f955724b27cb15f2230f4f
openssh-clients-3.9p1-8.RHEL4.9.x86_64.rpm
56bab36b63f94a4adcaa79ef026df03e
openssh-server-3.9p1-8.RHEL4.9.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/openssh-3.9p1-8.RHEL4.9.src.rpm
2cbb0102ce3dc2c36c328819f8522bbc openssh-3.9p1-8.RHEL4.9.src.rpm

i386:
4a5add7335d6b6bcf9a202e45e782eee
openssh-3.9p1-8.RHEL4.9.i386.rpm
77cc6d8b6be9c613f80cd7d52c9f91e3
openssh-askpass-3.9p1-8.RHEL4.9.i386.rpm
76c9ac8255dbc25184887dd93cfdb047
openssh-askpass-gnome-3.9p1-8.RHEL4.9.i386.rpm
45350fbd7c5356467ebfc2e2a7bfc55a
openssh-clients-3.9p1-8.RHEL4.9.i386.rpm
32e69cc88f09f6785badd3b82fdccb31
openssh-server-3.9p1-8.RHEL4.9.i386.rpm

ia64:
f27d73d28c920358dcb434c3ed8489cf
openssh-3.9p1-8.RHEL4.9.ia64.rpm
512632b31d333408cf2e05a3e567e16a
openssh-askpass-3.9p1-8.RHEL4.9.ia64.rpm
6771aafbd50b0ead67418404cbd63711
openssh-askpass-gnome-3.9p1-8.RHEL4.9.ia64.rpm
0355970673f296c38ee961549665b64d
openssh-clients-3.9p1-8.RHEL4.9.ia64.rpm
40fa71b924423c63af6215255cc21198
openssh-server-3.9p1-8.RHEL4.9.ia64.rpm

x86_64:
8e2c46e097fff0172553d821e6810f91
openssh-3.9p1-8.RHEL4.9.x86_64.rpm
14a78c2264965373c6c56d63f73f60e5
openssh-askpass-3.9p1-8.RHEL4.9.x86_64.rpm
b799e4ed3d8d6aaf3439e06c5ee29b21
openssh-askpass-gnome-3.9p1-8.RHEL4.9.x86_64.rpm
e15d265ea0f955724b27cb15f2230f4f
openssh-clients-3.9p1-8.RHEL4.9.x86_64.rpm
56bab36b63f94a4adcaa79ef026df03e
openssh-server-3.9p1-8.RHEL4.9.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/openssh-3.9p1-8.RHEL4.9.src.rpm
2cbb0102ce3dc2c36c328819f8522bbc openssh-3.9p1-8.RHEL4.9.src.rpm

i386:
4a5add7335d6b6bcf9a202e45e782eee
openssh-3.9p1-8.RHEL4.9.i386.rpm
77cc6d8b6be9c613f80cd7d52c9f91e3
openssh-askpass-3.9p1-8.RHEL4.9.i386.rpm
76c9ac8255dbc25184887dd93cfdb047
openssh-askpass-gnome-3.9p1-8.RHEL4.9.i386.rpm
45350fbd7c5356467ebfc2e2a7bfc55a
openssh-clients-3.9p1-8.RHEL4.9.i386.rpm
32e69cc88f09f6785badd3b82fdccb31
openssh-server-3.9p1-8.RHEL4.9.i386.rpm

ia64:
f27d73d28c920358dcb434c3ed8489cf
openssh-3.9p1-8.RHEL4.9.ia64.rpm
512632b31d333408cf2e05a3e567e16a
openssh-askpass-3.9p1-8.RHEL4.9.ia64.rpm
6771aafbd50b0ead67418404cbd63711
openssh-askpass-gnome-3.9p1-8.RHEL4.9.ia64.rpm
0355970673f296c38ee961549665b64d
openssh-clients-3.9p1-8.RHEL4.9.ia64.rpm
40fa71b924423c63af6215255cc21198
openssh-server-3.9p1-8.RHEL4.9.ia64.rpm

x86_64:
8e2c46e097fff0172553d821e6810f91
openssh-3.9p1-8.RHEL4.9.x86_64.rpm
14a78c2264965373c6c56d63f73f60e5
openssh-askpass-3.9p1-8.RHEL4.9.x86_64.rpm
b799e4ed3d8d6aaf3439e06c5ee29b21
openssh-askpass-gnome-3.9p1-8.RHEL4.9.x86_64.rpm
e15d265ea0f955724b27cb15f2230f4f
openssh-clients-3.9p1-8.RHEL4.9.x86_64.rpm
56bab36b63f94a4adcaa79ef026df03e
openssh-server-3.9p1-8.RHEL4.9.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2798

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact details at https://www.redhat.com/security/team/contact/

Copyright 2005 Red Hat, Inc.


Red Hat Security Advisory

Synopsis: Low: binutils security update
Advisory ID: RHSA-2005:673-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-673.html
Issue date: 2005-10-05
Updated on: 2005-10-05
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-1704


1. Summary:

An updated binutils package that fixes several bugs and minor security issues is now available.

This update has been rated as having low security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Problem description:

Binutils is a collection of utilities used for the creation of executable code. A number of bugs were found in various binutils tools.

If a user is tricked into processing a specially crafted executable with utilities such as readelf, size, strings, objdump, or nm, it may allow the execution of arbitrary code as the user. The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the name CAN-2005-1704 to this issue.

In addition, the following bugs have been fixed:

  • -- by default issue an error if IA-64 hint@pause instruction is put into the B slot, add assembler command line switch to override this behaviour
  • -- fix linker's --emit-relocs with .gnu.warning.* section symbols
  • -- fix gprof on 64-bit ppc binaries and libraries
  • -- fix gas mapping of register names to dwarf2 register numbers in CFI directives

All users of binutils should upgrade to this updated package, which contains patches to resolve these issues.

4. Solution:

Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system:

    http://www.redhat.com/docs/manuals/enterprise/

5. Bug IDs fixed (http://bugzilla.redhat.com/):

159894 - CAN-2005-1704 Integer overflow in the Binary File Descriptor (BFD) library 162545 - wrong dwarf register numbers generated

6. RPMs required:

Red Hat Enterprise Linux AS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/binutils-2.15.92.0.2-15.src.rpm
ba506648fc5d8ca830f54378f673e6a6 binutils-2.15.92.0.2-15.src.rpm

i386:
de3bdca323b48830513598fb4916e3f6
binutils-2.15.92.0.2-15.i386.rpm

ia64:
3722f6c68903eda7b979ea334f0c8e9f
binutils-2.15.92.0.2-15.ia64.rpm

ppc:
6582041cd1f4c02feaff94a4322dbad2
binutils-2.15.92.0.2-15.ppc.rpm

s390:
6c8ba333b98e7baacd9a8e8364fa7c9c
binutils-2.15.92.0.2-15.s390.rpm

s390x:
81ca4322941de30d486e855b594c307a
binutils-2.15.92.0.2-15.s390x.rpm

x86_64:
dc07ac2ef96372526039ee642a1475ba
binutils-2.15.92.0.2-15.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/binutils-2.15.92.0.2-15.src.rpm
ba506648fc5d8ca830f54378f673e6a6 binutils-2.15.92.0.2-15.src.rpm

i386:
de3bdca323b48830513598fb4916e3f6
binutils-2.15.92.0.2-15.i386.rpm

x86_64:
dc07ac2ef96372526039ee642a1475ba
binutils-2.15.92.0.2-15.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/binutils-2.15.92.0.2-15.src.rpm
ba506648fc5d8ca830f54378f673e6a6 binutils-2.15.92.0.2-15.src.rpm

i386:
de3bdca323b48830513598fb4916e3f6
binutils-2.15.92.0.2-15.i386.rpm

ia64:
3722f6c68903eda7b979ea334f0c8e9f
binutils-2.15.92.0.2-15.ia64.rpm

x86_64:
dc07ac2ef96372526039ee642a1475ba
binutils-2.15.92.0.2-15.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/binutils-2.15.92.0.2-15.src.rpm
ba506648fc5d8ca830f54378f673e6a6 binutils-2.15.92.0.2-15.src.rpm

i386:
de3bdca323b48830513598fb4916e3f6
binutils-2.15.92.0.2-15.i386.rpm

ia64:
3722f6c68903eda7b979ea334f0c8e9f
binutils-2.15.92.0.2-15.ia64.rpm

x86_64:
dc07ac2ef96372526039ee642a1475ba
binutils-2.15.92.0.2-15.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1704

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact details at https://www.redhat.com/security/team/contact/

Copyright 2005 Red Hat, Inc.


Red Hat Security Advisory

Synopsis: Low: perl security update
Advisory ID: RHSA-2005:674-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-674.html
Issue date: 2005-10-05
Updated on: 2005-10-05
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0448


1. Summary:

Updated Perl packages that fix security issues and contain several bug fixes are now available for Red Hat Enterprise Linux 4.

This update has been rated as having low security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Problem description:

Perl is a high-level programming language commonly used for system administration utilities and Web programming.

Paul Szabo discovered a bug in the way Perl's File::Path::rmtree module removed directory trees. If a local user has write permissions to a subdirectory within the tree being removed by File::Path::rmtree, it is possible for them to create setuid binary files. The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the name CAN-2005-0448 to this issue.

This update also addresses the following issues:

  • -- Perl interpreter caused a segmentation fault when environment changes occurred during runtime.
  • -- Code in lib/FindBin contained a regression that caused problems with MRTG software package.
  • -- Perl incorrectly declared it provides an FCGI interface where it in fact did not.

Users of Perl are advised to upgrade to these updated packages, which contain backported patches to correct these issues.

4. Solution:

Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system:

    http://www.redhat.com/docs/manuals/enterprise/

5. Bug IDs fixed (http://bugzilla.redhat.com/):

127023 - perl fails "lib/FindBin" test (breaks MRTG)
148848 - Packing fault with perl and FCGI
155888 - perl-suidperl package has an extra .1 release suffix
157694 - CAN-2005-0448 perl File::Path.pm rmtree race condition

6. RPMs required:

Red Hat Enterprise Linux AS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/perl-5.8.5-16.RHEL4.src.rpm
680ce92a9da6cccf344e1b13123d9aaa perl-5.8.5-16.RHEL4.src.rpm

i386:
9ec1570c81d4034b22e5b4e10d1b9e18
perl-5.8.5-16.RHEL4.i386.rpm
cfe9e85adc4c8faa977e56f3ff06abd3
perl-suidperl-5.8.5-16.RHEL4.i386.rpm

ia64:
453283cb6c5d392580a318ddf0a5fbb5
perl-5.8.5-16.RHEL4.ia64.rpm
9f01a4ef79fc601ac34892d5df64a7a4
perl-suidperl-5.8.5-16.RHEL4.ia64.rpm

ppc:
89dad8dbc4dc1ca219ad353c0ebce105
perl-5.8.5-16.RHEL4.ppc.rpm
d768e18d710ed0ddf9ff928cd7b62991
perl-suidperl-5.8.5-16.RHEL4.ppc.rpm

s390:
d2b9782e99e123ada2a42c0719d4286b
perl-5.8.5-16.RHEL4.s390.rpm
786148799901a80afa9ae8ecd8a08c88
perl-suidperl-5.8.5-16.RHEL4.s390.rpm

s390x:
d2a24c5fbc21634c1242477a1f959df8
perl-5.8.5-16.RHEL4.s390x.rpm
ef1e3ff9dfeb8bb39807841fdabbc3c9
perl-suidperl-5.8.5-16.RHEL4.s390x.rpm

x86_64:
0d14d35ee0f24120c7e3e36e17ee3ea1
perl-5.8.5-16.RHEL4.x86_64.rpm
41c3d79fba9d74c3e7da6f57d4d167ee
perl-suidperl-5.8.5-16.RHEL4.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/perl-5.8.5-16.RHEL4.src.rpm
680ce92a9da6cccf344e1b13123d9aaa perl-5.8.5-16.RHEL4.src.rpm

i386:
9ec1570c81d4034b22e5b4e10d1b9e18
perl-5.8.5-16.RHEL4.i386.rpm
cfe9e85adc4c8faa977e56f3ff06abd3
perl-suidperl-5.8.5-16.RHEL4.i386.rpm

x86_64:
0d14d35ee0f24120c7e3e36e17ee3ea1
perl-5.8.5-16.RHEL4.x86_64.rpm
41c3d79fba9d74c3e7da6f57d4d167ee
perl-suidperl-5.8.5-16.RHEL4.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/perl-5.8.5-16.RHEL4.src.rpm
680ce92a9da6cccf344e1b13123d9aaa perl-5.8.5-16.RHEL4.src.rpm

i386:
9ec1570c81d4034b22e5b4e10d1b9e18
perl-5.8.5-16.RHEL4.i386.rpm
cfe9e85adc4c8faa977e56f3ff06abd3
perl-suidperl-5.8.5-16.RHEL4.i386.rpm

ia64:
453283cb6c5d392580a318ddf0a5fbb5
perl-5.8.5-16.RHEL4.ia64.rpm
9f01a4ef79fc601ac34892d5df64a7a4
perl-suidperl-5.8.5-16.RHEL4.ia64.rpm

x86_64:
0d14d35ee0f24120c7e3e36e17ee3ea1
perl-5.8.5-16.RHEL4.x86_64.rpm
41c3d79fba9d74c3e7da6f57d4d167ee
perl-suidperl-5.8.5-16.RHEL4.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/perl-5.8.5-16.RHEL4.src.rpm
680ce92a9da6cccf344e1b13123d9aaa perl-5.8.5-16.RHEL4.src.rpm

i386:
9ec1570c81d4034b22e5b4e10d1b9e18
perl-5.8.5-16.RHEL4.i386.rpm
cfe9e85adc4c8faa977e56f3ff06abd3
perl-suidperl-5.8.5-16.RHEL4.i386.rpm

ia64:
453283cb6c5d392580a318ddf0a5fbb5
perl-5.8.5-16.RHEL4.ia64.rpm
9f01a4ef79fc601ac34892d5df64a7a4
perl-suidperl-5.8.5-16.RHEL4.ia64.rpm

x86_64:
0d14d35ee0f24120c7e3e36e17ee3ea1
perl-5.8.5-16.RHEL4.x86_64.rpm
41c3d79fba9d74c3e7da6f57d4d167ee
perl-suidperl-5.8.5-16.RHEL4.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0448

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact details at https://www.redhat.com/security/team/contact/

Copyright 2005 Red Hat, Inc.


Red Hat Security Advisory

Synopsis: Low: mysql security update
Advisory ID: RHSA-2005:685-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-685.html
Issue date: 2005-10-05
Updated on: 2005-10-05
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-1636


1. Summary:

Updated mysql packages that fix a temporary file flaw and a number of bugs are now available.

This update has been rated as having low security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Problem description:

MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries.

An insecure temporary file handling bug was found in the mysql_install_db script. It is possible for a local user to create specially crafted files in /tmp which could allow them to execute arbitrary SQL commands during database installation. The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the name CAN-2005-1636 to this issue.

These packages update mysql to version 4.1.12, fixing a number of problems. Also, support for SSL-encrypted connections to the database server is now provided.

All users of mysql are advised to upgrade to these updated packages.

4. Solution:

Before applying this update, make sure all previously released errata relevant to your system have been applied.

This update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system.

5. Bug IDs fixed (http://bugzilla.redhat.com/):

158688 - CAN-2005-1636 mysql insecure temporary file creation
163694 - Parser issue with subqueries involving unions

6. RPMs required:

Red Hat Enterprise Linux AS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/mysql-4.1.12-3.RHEL4.1.src.rpm
06e04af590c86c1563668213e4d9a2af mysql-4.1.12-3.RHEL4.1.src.rpm

i386:
d42c715e724da17f9e1bdd922fdb2f34
mysql-4.1.12-3.RHEL4.1.i386.rpm
020b65a1397177687bd7455a2946739e
mysql-bench-4.1.12-3.RHEL4.1.i386.rpm
6db5ab9c7b09d927988e39a9d53b8261
mysql-devel-4.1.12-3.RHEL4.1.i386.rpm
6694cc9ad90191d03cdc67ad9614d26c
mysql-server-4.1.12-3.RHEL4.1.i386.rpm

ia64:
d42c715e724da17f9e1bdd922fdb2f34
mysql-4.1.12-3.RHEL4.1.i386.rpm
bb35d80e1f827aa5de0f01aee29faa6a
mysql-4.1.12-3.RHEL4.1.ia64.rpm
47cb300d4bf12c8563eb1c8babfd103b
mysql-bench-4.1.12-3.RHEL4.1.ia64.rpm
47f9b68213f3037db70832795eb3a5b0
mysql-devel-4.1.12-3.RHEL4.1.ia64.rpm
0613e4169cee5ac1bde69212803b6aaa
mysql-server-4.1.12-3.RHEL4.1.ia64.rpm

ppc:
b54a2d7a5a9029db69c3cf0307003f8d
mysql-4.1.12-3.RHEL4.1.ppc.rpm
9d53cef62c768f37a223d90cafdfe4c4
mysql-4.1.12-3.RHEL4.1.ppc64.rpm
7a0d7f6729411842fbcab18a558c25f9
mysql-bench-4.1.12-3.RHEL4.1.ppc.rpm
ff15dfca4f080127a684753711c2c705
mysql-devel-4.1.12-3.RHEL4.1.ppc.rpm
5e18e3db31abbd644f798537b505febd
mysql-server-4.1.12-3.RHEL4.1.ppc.rpm

s390:
a4f9deb608170942ef88157f16bc9559
mysql-4.1.12-3.RHEL4.1.s390.rpm
cf62bace4cd06dab150abd0571b6e927
mysql-bench-4.1.12-3.RHEL4.1.s390.rpm
54fa0f151e8322cfb0f677bbf3a0d618
mysql-devel-4.1.12-3.RHEL4.1.s390.rpm
b302582504491c3fcdf496ed13b20c3f
mysql-server-4.1.12-3.RHEL4.1.s390.rpm

s390x:
a4f9deb608170942ef88157f16bc9559
mysql-4.1.12-3.RHEL4.1.s390.rpm
6882bb7f89b988c796c5694c6e133921
mysql-4.1.12-3.RHEL4.1.s390x.rpm
7997f5fa03a7cb80c1e8da506f82a61f
mysql-bench-4.1.12-3.RHEL4.1.s390x.rpm
0d61968abd9ae0d268ee77a7f893427e
mysql-devel-4.1.12-3.RHEL4.1.s390x.rpm
18ff4f1f10b15f1446e3bac9d5f16aa0
mysql-server-4.1.12-3.RHEL4.1.s390x.rpm

x86_64:
d42c715e724da17f9e1bdd922fdb2f34
mysql-4.1.12-3.RHEL4.1.i386.rpm
c93a847cf892e5b9ff0941221dc17891
mysql-4.1.12-3.RHEL4.1.x86_64.rpm
d28e2f3914e10b19212b969193c20386
mysql-bench-4.1.12-3.RHEL4.1.x86_64.rpm
c4bc3aa53d8f14d35c13f6bff7cd9d9c
mysql-devel-4.1.12-3.RHEL4.1.x86_64.rpm
c8426a10d3f2a56ccf30eae19dc78a01
mysql-server-4.1.12-3.RHEL4.1.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/mysql-4.1.12-3.RHEL4.1.src.rpm
06e04af590c86c1563668213e4d9a2af mysql-4.1.12-3.RHEL4.1.src.rpm

i386:
d42c715e724da17f9e1bdd922fdb2f34
mysql-4.1.12-3.RHEL4.1.i386.rpm
020b65a1397177687bd7455a2946739e
mysql-bench-4.1.12-3.RHEL4.1.i386.rpm
6db5ab9c7b09d927988e39a9d53b8261
mysql-devel-4.1.12-3.RHEL4.1.i386.rpm
6694cc9ad90191d03cdc67ad9614d26c
mysql-server-4.1.12-3.RHEL4.1.i386.rpm

x86_64:
d42c715e724da17f9e1bdd922fdb2f34
mysql-4.1.12-3.RHEL4.1.i386.rpm
c93a847cf892e5b9ff0941221dc17891
mysql-4.1.12-3.RHEL4.1.x86_64.rpm
d28e2f3914e10b19212b969193c20386
mysql-bench-4.1.12-3.RHEL4.1.x86_64.rpm
c4bc3aa53d8f14d35c13f6bff7cd9d9c
mysql-devel-4.1.12-3.RHEL4.1.x86_64.rpm
c8426a10d3f2a56ccf30eae19dc78a01
mysql-server-4.1.12-3.RHEL4.1.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/mysql-4.1.12-3.RHEL4.1.src.rpm
06e04af590c86c1563668213e4d9a2af mysql-4.1.12-3.RHEL4.1.src.rpm

i386:
d42c715e724da17f9e1bdd922fdb2f34
mysql-4.1.12-3.RHEL4.1.i386.rpm
020b65a1397177687bd7455a2946739e
mysql-bench-4.1.12-3.RHEL4.1.i386.rpm
6db5ab9c7b09d927988e39a9d53b8261
mysql-devel-4.1.12-3.RHEL4.1.i386.rpm
6694cc9ad90191d03cdc67ad9614d26c
mysql-server-4.1.12-3.RHEL4.1.i386.rpm

ia64:
d42c715e724da17f9e1bdd922fdb2f34
mysql-4.1.12-3.RHEL4.1.i386.rpm
bb35d80e1f827aa5de0f01aee29faa6a
mysql-4.1.12-3.RHEL4.1.ia64.rpm
47cb300d4bf12c8563eb1c8babfd103b
mysql-bench-4.1.12-3.RHEL4.1.ia64.rpm
47f9b68213f3037db70832795eb3a5b0
mysql-devel-4.1.12-3.RHEL4.1.ia64.rpm
0613e4169cee5ac1bde69212803b6aaa
mysql-server-4.1.12-3.RHEL4.1.ia64.rpm

x86_64:
d42c715e724da17f9e1bdd922fdb2f34
mysql-4.1.12-3.RHEL4.1.i386.rpm
c93a847cf892e5b9ff0941221dc17891
mysql-4.1.12-3.RHEL4.1.x86_64.rpm
d28e2f3914e10b19212b969193c20386
mysql-bench-4.1.12-3.RHEL4.1.x86_64.rpm
c4bc3aa53d8f14d35c13f6bff7cd9d9c
mysql-devel-4.1.12-3.RHEL4.1.x86_64.rpm
c8426a10d3f2a56ccf30eae19dc78a01
mysql-server-4.1.12-3.RHEL4.1.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/mysql-4.1.12-3.RHEL4.1.src.rpm
06e04af590c86c1563668213e4d9a2af mysql-4.1.12-3.RHEL4.1.src.rpm

i386:
d42c715e724da17f9e1bdd922fdb2f34
mysql-4.1.12-3.RHEL4.1.i386.rpm
020b65a1397177687bd7455a2946739e
mysql-bench-4.1.12-3.RHEL4.1.i386.rpm
6db5ab9c7b09d927988e39a9d53b8261
mysql-devel-4.1.12-3.RHEL4.1.i386.rpm
6694cc9ad90191d03cdc67ad9614d26c
mysql-server-4.1.12-3.RHEL4.1.i386.rpm

ia64:
d42c715e724da17f9e1bdd922fdb2f34
mysql-4.1.12-3.RHEL4.1.i386.rpm
bb35d80e1f827aa5de0f01aee29faa6a
mysql-4.1.12-3.RHEL4.1.ia64.rpm
47cb300d4bf12c8563eb1c8babfd103b
mysql-bench-4.1.12-3.RHEL4.1.ia64.rpm
47f9b68213f3037db70832795eb3a5b0
mysql-devel-4.1.12-3.RHEL4.1.ia64.rpm
0613e4169cee5ac1bde69212803b6aaa
mysql-server-4.1.12-3.RHEL4.1.ia64.rpm

x86_64:
d42c715e724da17f9e1bdd922fdb2f34
mysql-4.1.12-3.RHEL4.1.i386.rpm
c93a847cf892e5b9ff0941221dc17891
mysql-4.1.12-3.RHEL4.1.x86_64.rpm
d28e2f3914e10b19212b969193c20386
mysql-bench-4.1.12-3.RHEL4.1.x86_64.rpm
c4bc3aa53d8f14d35c13f6bff7cd9d9c
mysql-devel-4.1.12-3.RHEL4.1.x86_64.rpm
c8426a10d3f2a56ccf30eae19dc78a01
mysql-server-4.1.12-3.RHEL4.1.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1636

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact details at https://www.redhat.com/security/team/contact/

Copyright 2005 Red Hat, Inc.


Red Hat Security Advisory

Synopsis: Low: gdb security update
Advisory ID: RHSA-2005:709-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-709.html
Issue date: 2005-10-05
Updated on: 2005-10-05
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-1704 CAN-2005-1705


1. Summary:

An updated gdb package that fixes several bugs and minor security issues is now available.

This update has been rated as having low security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Problem description:

GDB, the GNU debugger, allows debugging of programs written in C, C++, and other languages by executing them in a controlled fashion, then printing their data.

Several integer overflow bugs were found in gdb. If a user is tricked into processing a specially crafted executable file, it may allow the execution of arbitrary code as the user running gdb. The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the name CAN-2005-1704 to this issue.

A bug was found in the way gdb loads .gdbinit files. When a user executes gdb, the local directory is searched for a .gdbinit file which is then loaded. It is possible for a local user to execute arbitrary commands as the victim running gdb by placing a malicious .gdbinit file in a location where gdb may be run. The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the name CAN-2005-1705 to this issue.

This updated package also addresses the following issues:

  • - GDB on ia64 had previously implemented a bug fix to work-around a kernel problem when creating a core file via gcore. The bug fix caused a significant slow-down of gcore.
  • - GDB on ia64 issued an extraneous warning when gcore was used.
  • - GDB on ia64 could not backtrace over a sigaltstack.
  • - GDB on ia64 could not successfully do an info frame for a signal trampoline.
  • - GDB on AMD64 and Intel EM64T had problems attaching to a 32-bit process.
  • - GDB on AMD64 and Intel EM64T was not properly handling threaded watchpoints.
  • - GDB could not build with gcc4 when -Werror flag was set.
  • - GDB had problems printing inherited members of C++ classes.
  • - A few updates from mainline sources concerning Dwarf2 partial die in cache support, follow-fork support, interrupted syscall support, and DW_OP_piece read support.

All users of gdb should upgrade to this updated package, which resolves these issues.

4. Solution:

Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system:

    http://www.redhat.com/docs/manuals/enterprise/

5. Bug IDs fixed (http://bugzilla.redhat.com/):

158680 - CAN-2005-1704 Integer overflow in gdb
158684 - CAN-2005-1705 gdb arbitrary command execution
160339 - GDB fails to correctly report frame information

6. RPMs required:

Red Hat Enterprise Linux AS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/gdb-6.3.0.0-1.63.src.rpm
a5415cbe08fdb27c05eaff709734e6f5 gdb-6.3.0.0-1.63.src.rpm

i386:
345dd8705bf465cd80e161e7cc96ac72
gdb-6.3.0.0-1.63.i386.rpm

ia64:
345dd8705bf465cd80e161e7cc96ac72
gdb-6.3.0.0-1.63.i386.rpm
eeee08a208c4b8cb238657d1f13d319b
gdb-6.3.0.0-1.63.ia64.rpm

ppc:
6956fc6e07f46783aa075d78a185dff3
gdb-6.3.0.0-1.63.ppc64.rpm

s390:
036d82e926fe0a8c101a2d62447257f3
gdb-6.3.0.0-1.63.s390.rpm

s390x:
239453b89d6f08e3b5e8c7c1b4f2ac0a
gdb-6.3.0.0-1.63.s390x.rpm

x86_64:
ef221fad920c658c7a1c98f053f738d1
gdb-6.3.0.0-1.63.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/gdb-6.3.0.0-1.63.src.rpm
a5415cbe08fdb27c05eaff709734e6f5 gdb-6.3.0.0-1.63.src.rpm

i386:
345dd8705bf465cd80e161e7cc96ac72
gdb-6.3.0.0-1.63.i386.rpm

x86_64:
ef221fad920c658c7a1c98f053f738d1
gdb-6.3.0.0-1.63.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/gdb-6.3.0.0-1.63.src.rpm
a5415cbe08fdb27c05eaff709734e6f5 gdb-6.3.0.0-1.63.src.rpm

i386:
345dd8705bf465cd80e161e7cc96ac72
gdb-6.3.0.0-1.63.i386.rpm

ia64:
345dd8705bf465cd80e161e7cc96ac72
gdb-6.3.0.0-1.63.i386.rpm
eeee08a208c4b8cb238657d1f13d319b
gdb-6.3.0.0-1.63.ia64.rpm

x86_64:
ef221fad920c658c7a1c98f053f738d1
gdb-6.3.0.0-1.63.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/gdb-6.3.0.0-1.63.src.rpm
a5415cbe08fdb27c05eaff709734e6f5 gdb-6.3.0.0-1.63.src.rpm

i386:
345dd8705bf465cd80e161e7cc96ac72
gdb-6.3.0.0-1.63.i386.rpm

ia64:
345dd8705bf465cd80e161e7cc96ac72
gdb-6.3.0.0-1.63.i386.rpm
eeee08a208c4b8cb238657d1f13d319b
gdb-6.3.0.0-1.63.ia64.rpm

x86_64:
ef221fad920c658c7a1c98f053f738d1
gdb-6.3.0.0-1.63.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1704
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1705

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact details at https://www.redhat.com/security/team/contact/

Copyright 2005 Red Hat, Inc.

Slackware Linux

[slackware-security] Thunderbird email client (SSA:2005-278-01)

New Thunderbird packages are available for Slackware 10.2 and -current to fix a security issue:

MFSA 2005-59 Command-line handling on Linux allows shell execution

More details about this issue may be found on the Mozilla web site:

http://www.mozilla.org/projects/security/known-vulnerabilities.html#Thunderbird

Here are the details from the Slackware 10.2 ChangeLog:
+--------------------------+
patches/packages/mozilla-thunderbird-1.0.7-i686-1.tgz:
Upgraded to thunderbird-1.0.7.
This fixes a security issue where URLs passed on the command line to the thunderbird shell script were not correctly protected against interpretation by the shell. As a result, a malicious URL could contain embedded shell commands which would then be executed as the user running Thunderbird.
For more information, see:
    http://www.mozilla.org/projects/security/known-vulnerabilities.html#Thunderbird (* Security fix *)
+--------------------------+

Where to find the new package:

Updated package for Slackware 10.2:
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/mozilla-thunderbird-1.0.7-i686-1.tgz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/mozilla-thunderbird-1.0.7-i686-1.tgz

MD5 signatures:

Slackware 10.2 package:
2957fa535b1333abd2dc5204d1a4cd5d mozilla-thunderbird-1.0.7-i686-1.tgz

Slackware -current package:
2957fa535b1333abd2dc5204d1a4cd5d mozilla-thunderbird-1.0.7-i686-1.tgz

Installation instructions:

Upgrade the package as root:
# upgradepkg mozilla-thunderbird-1.0.7-i686-1.tgz

+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

Ubuntu Linux


Ubuntu Security Notice USN-155-3 October 04, 2005
mozilla-locale-... updates
https://bugzilla.ubuntu.com/show_bug.cgi?id=14577

A security issue affects the following Ubuntu releases:

Ubuntu 5.04 (Hoary Hedgehog)

The following packages are affected:

mozilla-locale-da
mozilla-locale-de-at
mozilla-locale-fr

The problem can be corrected by upgrading the affected package to version 1.7.6-1ubuntu0.1 (mozilla-locale-de-at), 1.7.6-2ubuntu0.1 (mozilla-locale-da) and 2:1.7.6-1ubuntu0.1 (mozilla-locale-fr). In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

USN-155-3 and USN-186-3 updated the version of the mozilla-browser package to fix several vulnerabilities. It was determined that this rendered the Dansk, German, and French locale packages uninstallable since their dependencies were too specific. The updated locale packages work with all present and future versions of mozilla-browser.

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-locale-da/mozilla-locale-da_1.7.6-2ubuntu0.1.diff.gz
      Size/MD5: 12208 fbf3ce3abe604929f6450b356d651270
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-locale-da/mozilla-locale-da_1.7.6-2ubuntu0.1.dsc
      Size/MD5: 635 01e6beeb146ba1c4f0bb1662c53b6ca3
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-locale-da/mozilla-locale-da_1.7.6.orig.tar.gz
      Size/MD5: 584471 5b10854a7dbfa255dfffc1c97f71e6b1
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-locale-de-at/mozilla-locale-de-at_1.7.6-1ubuntu0.1.diff.gz
      Size/MD5: 30600 93115b792faeb1345386d455fc209f58
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-locale-de-at/mozilla-locale-de-at_1.7.6-1ubuntu0.1.dsc
      Size/MD5: 696 0c347a5fcf3e311b9e80a4dce24148a7
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-locale-de-at/mozilla-locale-de-at_1.7.6.orig.tar.gz
      Size/MD5: 1743794 0b378dc62951888d838efc6458c4c52a
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-locale-fr/mozilla-locale-fr_1.7.6-1ubuntu0.1.diff.gz
      Size/MD5: 17496 8def692010e62fa99ace976f787ab5a4
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-locale-fr/mozilla-locale-fr_1.7.6-1ubuntu0.1.dsc
      Size/MD5: 681 165981edffb2eecf0e49ff6669486638
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-locale-fr/mozilla-locale-fr_1.7.6.orig.tar.gz
      Size/MD5: 1641139 43b6ccf5e6f46167b5edfb605e108069

Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-locale-da/mozilla-locale-da_1.7.6-2ubuntu0.1_all.deb
      Size/MD5: 586032 009d4840b3ee79f105fd05183cd6dc32
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-locale-de-at/mozilla-locale-de-at_1.7.6-1ubuntu0.1_all.deb
      Size/MD5: 726206 b70a064453e77e55c5bb581d2c9b448a
    http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-locale-fr/mozilla-locale-fr_1.7.6-1ubuntu0.1_all.deb
      Size/MD5: 846828 a94a110d86d2452eb3e2af4cfb8a3828


Ubuntu Security Notice USN-193-1 October 04, 2005
dia vulnerability
CAN-2005-2966

A security issue affects the following Ubuntu releases:

Ubuntu 5.04 (Hoary Hedgehog)

The following packages are affected:

dia-common

The problem can be corrected by upgrading the affected package to version 0.94.0-5ubuntu1.1. After a standard system upgrade you have to restart dia to effect the necessary changes.

Details follow:

Joxean Koret discovered that the SVG import plugin did not properly sanitise data read from an SVG file. By tricking an user into opening a specially crafted SVG file, an attacker could exploit this to execute arbitrary code with the privileges of the user.

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/d/dia/dia_0.94.0-5ubuntu1.1.diff.gz
      Size/MD5: 14159 e9704dd46e24cb3cd11874a499692b6e
    http://security.ubuntu.com/ubuntu/pool/main/d/dia/dia_0.94.0-5ubuntu1.1.dsc
      Size/MD5: 1408 9d47820c11fde0876377ec119bdd6a7e
    http://security.ubuntu.com/ubuntu/pool/main/d/dia/dia_0.94.0.orig.tar.gz
      Size/MD5: 5241128 d2afdc10f55df29314250d98dbfd7a79

Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/main/d/dia/dia-common_0.94.0-5ubuntu1.1_all.deb
      Size/MD5: 2148620 255d09ecefe04651433da82730b2b17d

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/d/dia/dia-gnome_0.94.0-5ubuntu1.1_amd64.deb
      Size/MD5: 194718 c8d54ed3e5ac7a0cc006a951e08be9d0
    http://security.ubuntu.com/ubuntu/pool/main/d/dia/dia-libs_0.94.0-5ubuntu1.1_amd64.deb
      Size/MD5: 658936 b80672bede2ca8081017f0a9dc70a483
    http://security.ubuntu.com/ubuntu/pool/universe/d/dia/dia_0.94.0-5ubuntu1.1_amd64.deb
      Size/MD5: 193040 ed010c5c285236d0306f3faf1a31142d

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/d/dia/dia-gnome_0.94.0-5ubuntu1.1_i386.deb
      Size/MD5: 176774 dbfd08f4eb1a3ac2c03708f642e0b669
    http://security.ubuntu.com/ubuntu/pool/main/d/dia/dia-libs_0.94.0-5ubuntu1.1_i386.deb
      Size/MD5: 579934 2f8e713d629000abccb740c17e108b01
    http://security.ubuntu.com/ubuntu/pool/universe/d/dia/dia_0.94.0-5ubuntu1.1_i386.deb
      Size/MD5: 175298 2b760f4256be15ee369b300dc46d6d94

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/d/dia/dia-gnome_0.94.0-5ubuntu1.1_powerpc.deb
      Size/MD5: 184416 1f3ee515f8addd2716141de23dc66833
    http://security.ubuntu.com/ubuntu/pool/main/d/dia/dia-libs_0.94.0-5ubuntu1.1_powerpc.deb
      Size/MD5: 674436 7988c9c44120c67552248aedb5129b67
    http://security.ubuntu.com/ubuntu/pool/universe/d/dia/dia_0.94.0-5ubuntu1.1_powerpc.deb
      Size/MD5: 182920 411970ed6af036ebd895b7f8659f9944



No talkbacks posted.
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!

..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP