Linux Today: Linux News On Internet Time.
Search Linux Today
search.internet.com
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Become a Marketplace Partner

internet.commerce
Be a Commerce Partner














The Linux Channel at internet.com
Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Subscribe News
Subscribe PR
Subscribe Security

internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

Mailing Lists Are Parties. Or They Should Be.

Project: Building An All-Text Linux Workstation

Cool: Or Hot? Linux really making your coffee, live a linux coffee machine

Editor's Note: All This Great Technology Just to Reinvent Television

Kubuntu is not Ubuntu

Claws Mail: Mail with Attitude

SimplyMEPIS 8.5 RC3 Is Here, the Final Release Candidate

Ten Years of OpenOffice.org

OpenOffice.org Project of the Month: the Irish community

Intel Atom: NVIDIA ION vs. Radeon HD 4330 Graphics




Systems Engineer Sr - Solaris - Linux (TX)
Next Step Systems
US-TX-Houston

Justtechjobs.com Post A Job | Post A Resume
:Advisories, June 8, 2006
Advisories, June 8, 2006
Jun 9, 2006, 04 :45 UTC (0 Talkback[s]) (2483 reads)

Debian GNU/Linux


Debian Security Advisory DSA 1091-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
June 8th, 2006 http://www.debian.org/security/faq


Package : tiff
Vulnerability : buffer overflows
Problem type : none or remote
Debian-specific: no
CVE ID : CVE-2006-2656 CVE-2006-2193
Debian Bug : 369819

Several problems have been discovered in the TIFF library. The Common Vulnerabilities and Exposures project identifies the following issues:

CVE-2006-2193

SuSE discovered a buffer overflow in the conversion of TIFF files into PDF documents which could be exploited when tiff2pdf is used e.g. in a printer filter.

CVE-2006-2656

The tiffsplit command from the TIFF library contains a buffer overflow in the commandline handling which could be exploited when the program is executed automatically on unknown filenames.

For the old stable distribution (woody) this problem has been fixed in version 3.5.5-7woody2.

For the stable distribution (sarge) this problem has been fixed in version 3.7.2-5.

For the unstable distribution (sid) this problem has been fixed in version 3.8.2-4.

We recommend that you upgrade your tiff packages.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given at the end of this advisory:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody


Source archives:

    http://security.debian.org/pool/updates/main/t/tiff/tiff_3.5.5-7woody2.dsc
      Size/MD5 checksum: 635 63c05c844a00a57f87f1804dc668ccbf
    http://security.debian.org/pool/updates/main/t/tiff/tiff_3.5.5-7woody2.diff.gz
      Size/MD5 checksum: 38682 5905ba8ea39b409b4aa2893b697f35bc
    http://security.debian.org/pool/updates/main/t/tiff/tiff_3.5.5.orig.tar.gz
      Size/MD5 checksum: 693641 3b7199ba793dec6ca88f38bb0c8cc4d8

Alpha architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-7woody2_alpha.deb
      Size/MD5 checksum: 141478 2e995b46f312ecf35858f06e50c2ae2e
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-7woody2_alpha.deb
      Size/MD5 checksum: 106182 c383b1a1f292525e60efa68750bda5ae
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-7woody2_alpha.deb
      Size/MD5 checksum: 423868 da0015dd297de4f4128488fca92c3a88

ARM architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-7woody2_arm.deb
      Size/MD5 checksum: 117012 fe039271e5e9a94f56a2ca4c8a38a373
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-7woody2_arm.deb
      Size/MD5 checksum: 91610 d52006c179bfc3a13a779dfab1afa8fd
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-7woody2_arm.deb
      Size/MD5 checksum: 404850 69dd0252a4e15f0bc84ddb0d53ce5c96

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-7woody2_i386.deb
      Size/MD5 checksum: 112058 cc978252d32d2e853ed08a655940b15b
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-7woody2_i386.deb
      Size/MD5 checksum: 82070 22733411e25f7fac444f148dcfb685a7
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-7woody2_i386.deb
      Size/MD5 checksum: 387442 dc8f36b0bfed0cc69d53c14f6b6e2fd4

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-7woody2_ia64.deb
      Size/MD5 checksum: 158834 dda97df687d64fef045e7dd425a9b01e
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-7woody2_ia64.deb
      Size/MD5 checksum: 136678 e43c8ca8bcbdb54d09cee79f7c2f5665
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-7woody2_ia64.deb
      Size/MD5 checksum: 447048 100db6566cc42766d93fd67913834096

HP Precision architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-7woody2_hppa.deb
      Size/MD5 checksum: 128284 43c94055d54efb3d3d0708f527617ca8
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-7woody2_hppa.deb
      Size/MD5 checksum: 107708 089f41dfe3629250ddc02cbe1c76c649
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-7woody2_hppa.deb
      Size/MD5 checksum: 420730 018d785c7890016dfab3cba41e949dc5

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-7woody2_m68k.deb
      Size/MD5 checksum: 107282 1719b7463ef81d07075c39453f793080
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-7woody2_m68k.deb
      Size/MD5 checksum: 80748 2020a4999f141c2b5ba47090c551de36
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-7woody2_m68k.deb
      Size/MD5 checksum: 380718 d75aa876cef53d488178caae1dc160f2

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-7woody2_mips.deb
      Size/MD5 checksum: 124022 7deeb5d1d0b5eb2c536143949e507fb0
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-7woody2_mips.deb
      Size/MD5 checksum: 88820 ef4eed05b2bb2f853c74997141bab9e6
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-7woody2_mips.deb
      Size/MD5 checksum: 411210 d9a0dd8ae266524ff80efcd88e74365a

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-7woody2_mipsel.deb
      Size/MD5 checksum: 123536 88738fa15be0cb199c006503a12e13df
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-7woody2_mipsel.deb
      Size/MD5 checksum: 89122 beaf555e5d72f290852777b750a676cc
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-7woody2_mipsel.deb
      Size/MD5 checksum: 411326 61a6b79d2fd527d1c3fcd41eac1bd408

PowerPC architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-7woody2_powerpc.deb
      Size/MD5 checksum: 116102 5bb725af64e1f4c2d4a9bc90ab2cc8e0
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-7woody2_powerpc.deb
      Size/MD5 checksum: 90618 2e4cfb7cd4e2dee6418fa7f88f01c68f
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-7woody2_powerpc.deb
      Size/MD5 checksum: 403142 39f179238a6d70f1a755c7a7751c6b1d

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-7woody2_s390.deb
      Size/MD5 checksum: 116912 a4c1ef170588a8be47985338e6f99074
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-7woody2_s390.deb
      Size/MD5 checksum: 92814 c33810f1cae1535ceb0d2f06a2cc4875
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-7woody2_s390.deb
      Size/MD5 checksum: 395670 0925a01ed6e686c24aecba121ee12a7f

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-7woody2_sparc.deb
      Size/MD5 checksum: 132896 653921fed0879588e859ec05555d25ad
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-7woody2_sparc.deb
      Size/MD5 checksum: 89798 7097a2950a1a40f46c91cccd97e9fef3
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-7woody2_sparc.deb
      Size/MD5 checksum: 397444 82752cc23951fc4e26838a704fd18561

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/t/tiff/tiff_3.7.2-5.dsc
      Size/MD5 checksum: 736 a818c1d8f13bba145e33b79f5b476707
    http://security.debian.org/pool/updates/main/t/tiff/tiff_3.7.2-5.diff.gz
      Size/MD5 checksum: 11836 91da082b84456d159fcea664b99012d2
    http://security.debian.org/pool/updates/main/t/tiff/tiff_3.7.2.orig.tar.gz
      Size/MD5 checksum: 1252995 221679f6d5c15670b3c242cbfff79a00

Alpha architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-opengl_3.7.2-5_alpha.deb
      Size/MD5 checksum: 46922 0c35a8df000764e528ae384ac325b8ad
    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.7.2-5_alpha.deb
      Size/MD5 checksum: 243676 b8745078cb5af1773f1b28e97a787343
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4_3.7.2-5_alpha.deb
      Size/MD5 checksum: 478368 6aa0652b69c62bfc7e51c6781d06fa19
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4-dev_3.7.2-5_alpha.deb
      Size/MD5 checksum: 309918 adb7022423ccd165188e8071e19cc442
    http://security.debian.org/pool/updates/main/t/tiff/libtiffxx0_3.7.2-5_alpha.deb
      Size/MD5 checksum: 41048 72d163b97923c66a8b632e1907bc0865

AMD64 architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-opengl_3.7.2-5_amd64.deb
      Size/MD5 checksum: 45848 f79893646f9c74fdef624f949fea88ad
    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.7.2-5_amd64.deb
      Size/MD5 checksum: 217914 b4abe50b4c24e899cbb961612ff3bdb2
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4_3.7.2-5_amd64.deb
      Size/MD5 checksum: 459378 d01fdb8c0c066e5e4503b006b696658d
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4-dev_3.7.2-5_amd64.deb
      Size/MD5 checksum: 266960 a13564cc4b1ab7cfe8e956a556c8ee25
    http://security.debian.org/pool/updates/main/t/tiff/libtiffxx0_3.7.2-5_amd64.deb
      Size/MD5 checksum: 40618 9114caa1d68c7197f9fa24c1747cd99d

ARM architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-opengl_3.7.2-5_arm.deb
      Size/MD5 checksum: 45362 fce43634a68f4a8867764f9b8649f07a
    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.7.2-5_arm.deb
      Size/MD5 checksum: 208490 64553848b27faef1fc6072623904db18
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4_3.7.2-5_arm.deb
      Size/MD5 checksum: 453542 16cde56a8e4d74ff39fec6f1cc664171
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4-dev_3.7.2-5_arm.deb
      Size/MD5 checksum: 265224 c1e43bfa93d33ea20c970485c2559ec1
    http://security.debian.org/pool/updates/main/t/tiff/libtiffxx0_3.7.2-5_arm.deb
      Size/MD5 checksum: 40112 835f54888f47687d80bd283956b6a433

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-opengl_3.7.2-5_i386.deb
      Size/MD5 checksum: 45226 fb6a72018e538b9c01be4f1d7b83f5ee
    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.7.2-5_i386.deb
      Size/MD5 checksum: 206256 bc2113c8fa422bfa43770aff225ef6a2
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4_3.7.2-5_i386.deb
      Size/MD5 checksum: 452596 ecd7de1fd8b95c90a20e8418781c129b
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4-dev_3.7.2-5_i386.deb
      Size/MD5 checksum: 251726 5d7ab853c833dbf09fecb7da82a90f1d
    http://security.debian.org/pool/updates/main/t/tiff/libtiffxx0_3.7.2-5_i386.deb
      Size/MD5 checksum: 40666 94f82a8a5aa26e51e6cb5d8dd2b2d6d7

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-opengl_3.7.2-5_ia64.deb
      Size/MD5 checksum: 48314 eced941bad1e44163b1732e7d140e47f
    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.7.2-5_ia64.deb
      Size/MD5 checksum: 268978 791e5bdfdc7ffc390156b80715c76511
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4_3.7.2-5_ia64.deb
      Size/MD5 checksum: 511152 6c74c5b71ae314d7332e5c717edb4a0b
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4-dev_3.7.2-5_ia64.deb
      Size/MD5 checksum: 330884 e73f9cd34760e6e90705a22a082e701b
    http://security.debian.org/pool/updates/main/t/tiff/libtiffxx0_3.7.2-5_ia64.deb
      Size/MD5 checksum: 42252 6b66dd7679be12ffe5927e6fb4fea6df

HP Precision architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-opengl_3.7.2-5_hppa.deb
      Size/MD5 checksum: 46654 d8f619cfa26dde8579513f6d0b81a0f1
    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.7.2-5_hppa.deb
      Size/MD5 checksum: 230166 1321bf6e1d105ddd339b7e5557aa5719
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4_3.7.2-5_hppa.deb
      Size/MD5 checksum: 473080 ab55bbf0033b1b650ee927d21ce9c738
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4-dev_3.7.2-5_hppa.deb
      Size/MD5 checksum: 281620 93cf9c2dfa23e2c20e8795dd62dfc1ff
    http://security.debian.org/pool/updates/main/t/tiff/libtiffxx0_3.7.2-5_hppa.deb
      Size/MD5 checksum: 41294 6ff9f727d5da771f334f75d58e118bfe

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-opengl_3.7.2-5_m68k.deb
      Size/MD5 checksum: 45238 4020963162aeba32e183855003f5282c
    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.7.2-5_m68k.deb
      Size/MD5 checksum: 193466 dd132dae95518b681b29f18dc72b5126
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4_3.7.2-5_m68k.deb
      Size/MD5 checksum: 442750 64ec9d1c9e3cc0bcf916b685437af60d
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4-dev_3.7.2-5_m68k.deb
      Size/MD5 checksum: 234514 7a50d86d056760ff37bbd585b136df14
    http://security.debian.org/pool/updates/main/t/tiff/libtiffxx0_3.7.2-5_m68k.deb
      Size/MD5 checksum: 40270 491986255b51eaccb5ddcece25ecc732

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-opengl_3.7.2-5_mips.deb
      Size/MD5 checksum: 46118 2a6f6b1f5e1557c3ef4297ee0eabc985
    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.7.2-5_mips.deb
      Size/MD5 checksum: 252258 a21f9c0fc9c53b13b14efd641a3cb8ae
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4_3.7.2-5_mips.deb
      Size/MD5 checksum: 458604 30db35156ea16a19a75edfb35ad2a14d
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4-dev_3.7.2-5_mips.deb
      Size/MD5 checksum: 280506 53f30322a6fc900b4f0ebc5f3d492676
    http://security.debian.org/pool/updates/main/t/tiff/libtiffxx0_3.7.2-5_mips.deb
      Size/MD5 checksum: 40894 170ea7645a3c5543cc5caae43ad5c0a6

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-opengl_3.7.2-5_mipsel.deb
      Size/MD5 checksum: 46080 43c5a8ea470cb03a0d2ef8b9933c7857
    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.7.2-5_mipsel.deb
      Size/MD5 checksum: 252690 857f1625966dbc12f508700a471ac831
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4_3.7.2-5_mipsel.deb
      Size/MD5 checksum: 458972 6f4c7d7ffe16f8c99ab81924da944985
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4-dev_3.7.2-5_mipsel.deb
      Size/MD5 checksum: 280370 cd2a531fa482b3e48c539e2dd3561494
    http://security.debian.org/pool/updates/main/t/tiff/libtiffxx0_3.7.2-5_mipsel.deb
      Size/MD5 checksum: 40880 a81fef82f1d0a9d7d1001e7a325fee30

PowerPC architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-opengl_3.7.2-5_powerpc.deb
      Size/MD5 checksum: 47288 24f1d1ac568afd55118a1fc57f903394
    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.7.2-5_powerpc.deb
      Size/MD5 checksum: 235464 69addcbeaeeba30abe98dcb1efc1a285
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4_3.7.2-5_powerpc.deb
      Size/MD5 checksum: 460614 651e56b2fd88160d3a43b92aba8875eb
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4-dev_3.7.2-5_powerpc.deb
      Size/MD5 checksum: 272120 17b13db9ffe5f47941db64522210a26e
    http://security.debian.org/pool/updates/main/t/tiff/libtiffxx0_3.7.2-5_powerpc.deb
      Size/MD5 checksum: 42466 eaa2cce3db4913037c21d73e59cfed63

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-opengl_3.7.2-5_s390.deb
      Size/MD5 checksum: 46240 826c2293b0729b990ee4e78f5d44d5c4
    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.7.2-5_s390.deb
      Size/MD5 checksum: 213880 b4caf3c3eec6f7261af4eaff0f764bbf
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4_3.7.2-5_s390.deb
      Size/MD5 checksum: 466012 2371e8d875c366fe532d447f9e4d185a
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4-dev_3.7.2-5_s390.deb
      Size/MD5 checksum: 266758 7b6b6981382dccaede04ffef2f5cfea1
    http://security.debian.org/pool/updates/main/t/tiff/libtiffxx0_3.7.2-5_s390.deb
      Size/MD5 checksum: 40886 9e4f621bc83ac85dcf2a56fa7aa59e88

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-opengl_3.7.2-5_sparc.deb
      Size/MD5 checksum: 45530 a6cc6e6db7136497800635f5cd991381
    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.7.2-5_sparc.deb
      Size/MD5 checksum: 205358 8f72175e2f33bc5ab15ea5e9b5c77b91
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4_3.7.2-5_sparc.deb
      Size/MD5 checksum: 454782 229cc03ccc4397b839a9545cbe6e6500
    http://security.debian.org/pool/updates/main/t/tiff/libtiff4-dev_3.7.2-5_sparc.deb
      Size/MD5 checksum: 257914 f99730a57980cf56a28dc1ce2a74e016
    http://security.debian.org/pool/updates/main/t/tiff/libtiffxx0_3.7.2-5_sparc.deb
      Size/MD5 checksum: 40616 8d38793d5c79a5498f7c5e0e2f9c37fe

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 1092-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
June 8th, 2006 http://www.debian.org/security/faq


Package : mysql-dfsg-4.1
Vulnerability : programming error
Problem type : remote
Debian-specific: no
CVE ID : CVE-2006-2753
BugTraq ID : 18219

Josh Berkus and Tom Lane discovered that MySQL 4.1, a popular SQL database, incorrectly parses astring escaped with mysql_real_escape() which could lead to SQL injection. This problem does only exist in versions 4.1 and 5.0.

The old stable distribution (woody) is not affected by this problem.

For the stable distribution (sarge) this problem has been fixed in version 4.1.11a-4sarge4.

For the unstable distribution (sid) this problem has been fixed in version 5.0.21-4.

Version 4.0 in the stable distribution (sarge) is also not affected by this problem.

We recommend that you upgrade your mysql packages.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given at the end of this advisory:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-dfsg-4.1_4.1.11a-4sarge4.dsc
      Size/MD5 checksum: 1021 af71d3e6da11441dfd8ed93c20ca8729
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-dfsg-4.1_4.1.11a-4sarge4.diff.gz
      Size/MD5 checksum: 167558 438fd6709d74cb614901d0ea9a965745
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-dfsg-4.1_4.1.11a.orig.tar.gz
      Size/MD5 checksum: 15771855 3c0582606a8903e758c2014c2481c7c3

Architecture independent components:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-common-4.1_4.1.11a-4sarge4_all.deb
      Size/MD5 checksum: 36302 abaa8025885618451c598493b41d10bb

Alpha architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge4_alpha.deb
      Size/MD5 checksum: 1590578 754d9c9d253ba8488ee66efc92dcb1ca
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge4_alpha.deb
      Size/MD5 checksum: 7965338 b623f43445b37b8af9f91c09ed31d4ae
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge4_alpha.deb
      Size/MD5 checksum: 1000754 32ed105998bb4a23d52d861fac54e840
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge4_alpha.deb
      Size/MD5 checksum: 17488018 d3cda036d9920c18de5849ab3dc024c8

AMD64 architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge4_amd64.deb
      Size/MD5 checksum: 1451828 06f3945b95051a12f9f155a268094dcf
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge4_amd64.deb
      Size/MD5 checksum: 5551444 3663f19adb6b38a61682619ef19cfbc8
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge4_amd64.deb
      Size/MD5 checksum: 849336 42c8d15b1329e901a845dc74626a0f3e
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge4_amd64.deb
      Size/MD5 checksum: 14711198 aa976778d4cfdbfaab96fe4bcbeb8cb5

ARM architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge4_arm.deb
      Size/MD5 checksum: 1388714 4786d6136ff3d5d9d4258754eb64b356
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge4_arm.deb
      Size/MD5 checksum: 5558586 796c478d90a750e0a577434512fdaeb6
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge4_arm.deb
      Size/MD5 checksum: 836542 d62795e99b44d319626c15446c962d44
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge4_arm.deb
      Size/MD5 checksum: 14557476 ac7a7d39805b00b27872cdc339f688d5

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge4_i386.deb
      Size/MD5 checksum: 1417826 f8d012cb6a85554c0d94bfcac7f78791
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge4_i386.deb
      Size/MD5 checksum: 5643870 d02bb09d6cb1ba6b8014055eec3fc3be
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge4_i386.deb
      Size/MD5 checksum: 830518 f603306a8fec1c63b6e3ecc17107bd98
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge4_i386.deb
      Size/MD5 checksum: 14558102 591c67e79d72dd63e02dc166d0cb5300

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge4_ia64.deb
      Size/MD5 checksum: 1713084 09db38b7f9ff3567ef4d4ccc4c46ae3f
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge4_ia64.deb
      Size/MD5 checksum: 7782286 0c75c782e7873a327d69421933f36732
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge4_ia64.deb
      Size/MD5 checksum: 1050436 91bf76af1e2d978eb5472ddb84031bf1
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge4_ia64.deb
      Size/MD5 checksum: 18475506 7d96940c7e7a0623de3702651cf8c8a2

HP Precision architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge4_hppa.deb
      Size/MD5 checksum: 1550998 e4c6ae38e9a5dc7aae7cc15dff9bc0c0
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge4_hppa.deb
      Size/MD5 checksum: 6249966 91443fde830a3cbb343849afd6a2d0d8
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge4_hppa.deb
      Size/MD5 checksum: 909886 3ed733077d25aefe18bcf1cc21ad2215
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge4_hppa.deb
      Size/MD5 checksum: 15790412 bb7a33201295e66224bf4c491f0c56b9

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge4_m68k.deb
      Size/MD5 checksum: 1397768 e3c536ac8323986b4165abe26928f36f
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge4_m68k.deb
      Size/MD5 checksum: 5283732 bb01937d6e79d23947a89312cf160aa6
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge4_m68k.deb
      Size/MD5 checksum: 803692 2613a1adb8174a24efa485ade794db85
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge4_m68k.deb
      Size/MD5 checksum: 14071656 677a2a213c3fb5fe363f76625fe5e1c7

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge4_mips.deb
      Size/MD5 checksum: 1478750 48583310a2c865cc938566c6cd08a824
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge4_mips.deb
      Size/MD5 checksum: 6052854 dad954fb5c1cd13ad73cfd21c2819e5f
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge4_mips.deb
      Size/MD5 checksum: 904326 44f8ae166e7b30694eaad583eba40666
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge4_mips.deb
      Size/MD5 checksum: 15409878 5180ef322b2f6d4aa7dcc4fd60a521d4

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge4_mipsel.deb
      Size/MD5 checksum: 1446178 bd5a7f2d224da45b1e24a6a23038744f
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge4_mipsel.deb
      Size/MD5 checksum: 5971330 bedb92b0edc6e18dc83e504690c863c6
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge4_mipsel.deb
      Size/MD5 checksum: 889962 c75f34bfc318ac4cca4c04cd0bbe2c10
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge4_mipsel.deb
      Size/MD5 checksum: 15105354 e8100b4c7ba1de3c9e3b1afbaac0b825

PowerPC architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge4_powerpc.deb
      Size/MD5 checksum: 1476650 035fa1c4995fbc57d9b7ee6e20e85fde
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge4_powerpc.deb
      Size/MD5 checksum: 6027482 98a9b182121a9747a0e6e9c8ef1531b2
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge4_powerpc.deb
      Size/MD5 checksum: 907256 c8a0e5668a15b68aff1c108e7fc6afad
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge4_powerpc.deb
      Size/MD5 checksum: 15402696 3e020285d43a361111278d558d95bd6d

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge4_s390.deb
      Size/MD5 checksum: 1538332 604b1be5b4ca49165113d200cd3415c0
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge4_s390.deb
      Size/MD5 checksum: 5461442 b5b4bfa92a5c7d4269238a00fc320057
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge4_s390.deb
      Size/MD5 checksum: 884106 c1c2e15c37217bcbf96dfff23f19d5ab
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge4_s390.deb
      Size/MD5 checksum: 15055316 2fe79ed0e0242a75f4ecb016d39e491d

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14_4.1.11a-4sarge4_sparc.deb
      Size/MD5 checksum: 1460442 72b9ef109c9ef1951d8002b1dbe72735
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/libmysqlclient14-dev_4.1.11a-4sarge4_sparc.deb
      Size/MD5 checksum: 6207904 dd3e6e35dab09a603344a36b28916514
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-client-4.1_4.1.11a-4sarge4_sparc.deb
      Size/MD5 checksum: 868066 0cec4df9b02b3550fdf4a7c5f35af51b
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-server-4.1_4.1.11a-4sarge4_sparc.deb
      Size/MD5 checksum: 15391878 8f056ef97deef926d4b1ff843f762ced

These files will probably be moved into the stable distribution on its next update.



Debian Security Advisory DSA 1093-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
June 8th, 2006 http://www.debian.org/security/faq


Package : xine-ui
Vulnerability : format string
Problem type : local (remote)
Debian-specific: no
CVE ID : CVE-2006-2230

Several format string vulnerabilities have been discovered in xine-ui, the user interface of the xine video player, which may cause a denial of service.

The old stable distribution (woody) is not affected by these problems.

For the stable distribution (sarge) these problems have been fixed in version 0.99.3-1sarge1.

For the unstable distribution (sid) these problems will be fixed soon.

We recommend that you upgrade your xine-ui package.

Upgrade Instructions


wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given at the end of this advisory:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge


Source archives:

    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3-1sarge1.dsc
      Size/MD5 checksum: 746 527be88be68d5710bf5e0a5b09ffc839
    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3-1sarge1.diff.gz
      Size/MD5 checksum: 1288 64415eeb7634cc0dca6d7a44e7a8f404
    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3.orig.tar.gz
      Size/MD5 checksum: 2610080 aa7805a93e511e3d67dc1bf09a71fcdd

Alpha architecture:

    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3-1sarge1_alpha.deb
      Size/MD5 checksum: 1877496 56392abc6057d656c041bfbad49976ad

AMD64 architecture:

    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3-1sarge1_amd64.deb
      Size/MD5 checksum: 1766792 b093fcc76082ac6e95518f2ec9a27bd9

ARM architecture:

    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3-1sarge1_arm.deb
      Size/MD5 checksum: 1711066 856ce425a4db60d0d043b95ad0a7ec18

Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3-1sarge1_i386.deb
      Size/MD5 checksum: 1731748 5f971967308012850fecd3c9362cec9b

Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3-1sarge1_ia64.deb
      Size/MD5 checksum: 2041594 6f37253dad654f31f5bd12c2109e5726

HP Precision architecture:

    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3-1sarge1_hppa.deb
      Size/MD5 checksum: 1682926 1ac6f7faa43469e805c01be3d8756a2b

Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3-1sarge1_m68k.deb
      Size/MD5 checksum: 1588564 baea2fa096194f491dcf2438cfa489c7

Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3-1sarge1_mips.deb
      Size/MD5 checksum: 1762350 fbbaa304745c86021a0ffe463530a573

Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3-1sarge1_mipsel.deb
      Size/MD5 checksum: 1762594 6399a62f5e919c04333a2c5533e64cc0

PowerPC architecture:

    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3-1sarge1_powerpc.deb
      Size/MD5 checksum: 1776176 387dfa9a66f0fa3e26e9d26b5cc3aed0

IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3-1sarge1_s390.deb
      Size/MD5 checksum: 1742376 b41686f1d871c498d6f4185736317ff2

Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.99.3-1sarge1_sparc.deb
      Size/MD5 checksum: 1761044 f37b88d9d0a99ee2a6be783e403d634c

These files will probably be moved into the stable distribution on its next update.


For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

Fedora Legacy


Fedora Legacy Update Advisory

Synopsis: Updated mozilla packages fix security issues
Advisory ID: FLSA:189137-1
Issue date: 2006-06-06
Product: Red Hat Linux, Fedora Core
Keywords: Bugfix, Security
CVE Names: CVE-2006-0748 CVE-2006-0749 CVE-2006-0884 CVE-2006-1727 CVE-2006-1728 CVE-2006-1729 CVE-2006-1730 CVE-2006-1731 CVE-2006-1732 CVE-2006-1733 CVE-2006-1734 CVE-2006-1735 CVE-2006-1737 CVE-2006-1738 CVE-2006-1739 CVE-2006-1740 CVE-2006-1741 CVE-2006-1742 CVE-2006-1790



1. Topic:

Updated mozilla packages that fix several security bugs are now available.

Mozilla is an open source Web browser, advanced email and newsgroup client, IRC chat client, and HTML editor.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - i386
Red Hat Linux 9 - i386
Fedora Core 1 - i386
Fedora Core 2 - i386
Fedora Core 3 - i386, x86_64

3. Problem description:

Several bugs were found in the way Mozilla processes malformed javascript. A malicious web page could modify the content of a different open web page, possibly stealing sensitive information or conducting a cross-site scripting attack. (CVE-2006-1731, CVE-2006-1732, CVE-2006-1741)

Several bugs were found in the way Mozilla processes certain javascript actions. A malicious web page could execute arbitrary javascript instructions with the permissions of "chrome", allowing the page to steal sensitive information or install browser malware. (CVE-2006-1727, CVE-2006-1728, CVE-2006-1733, CVE-2006-1734, CVE-2006-1735, CVE-2006-1742)

Several bugs were found in the way Mozilla processes malformed web pages. A carefully crafted malicious web page could cause the execution of arbitrary code as the user running Mozilla. (CVE-2006-0748, CVE-2006-0749, CVE-2006-1730, CVE-2006-1737, CVE-2006-1738, CVE-2006-1739, CVE-2006-1790)

A bug was found in the way Mozilla displays the secure site icon. If a browser is configured to display the non-default secure site modal warning dialog, it may be possible to trick a user into believing they are viewing a secure site. (CVE-2006-1740)

A bug was found in the way Mozilla allows javascript mutation events on "input" form elements. A malicious web page could be created in such a way that when a user submits a form, an arbitrary file could be uploaded to the attacker. (CVE-2006-1729)

A bug was found in the way Mozilla executes in-line mail forwarding. If a user can be tricked into forwarding a maliciously crafted mail message as in-line content, it is possible for the message to execute javascript with the permissions of "chrome". (CVE-2006-0884)

Users of Mozilla are advised to upgrade to these updated packages containing Mozilla version 1.7.13 which corrects these issues.

4. Solution:

Before applying this update, make sure all previously released errata relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory only contains the desired RPMs.

Please note that this update is also available via yum and apt. Many people find this an easier way to apply updates. To use yum issue:

yum update

or to use apt:

apt-get update; apt-get upgrade

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. This assumes that you have yum or apt-get configured for obtaining Fedora Legacy content. Please visit http://www.fedoralegacy.org/docs for directions on how to configure yum and apt-get.

5. Bug IDs fixed:

https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189137

6. RPMs required:

Red Hat Linux 7.3:

SRPM:
http://download.fedoralegacy.org/redhat/7.3/updates/SRPMS/mozilla-1.7.13-0.73.1.legacy.src.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/SRPMS/galeon-1.2.14-0.73.6.legacy.src.rpm

i386:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-1.7.13-0.73.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-chat-1.7.13-0.73.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-devel-1.7.13-0.73.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-dom-inspector-1.7.13-0.73.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-js-debugger-1.7.13-0.73.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-mail-1.7.13-0.73.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-nspr-1.7.13-0.73.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-nspr-devel-1.7.13-0.73.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-nss-1.7.13-0.73.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-nss-devel-1.7.13-0.73.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/galeon-1.2.14-0.73.6.legacy.i386.rpm

Red Hat Linux 9:

SRPM:
http://download.fedoralegacy.org/redhat/9/updates/SRPMS/mozilla-1.7.13-0.90.1.legacy.src.rpm
http://download.fedoralegacy.org/redhat/9/updates/SRPMS/galeon-1.2.14-0.90.6.legacy.src.rpM

i386:
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-1.7.13-0.90.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-chat-1.7.13-0.90.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-devel-1.7.13-0.90.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-dom-inspector-1.7.13-0.90.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-js-debugger-1.7.13-0.90.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-mail-1.7.13-0.90.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nspr-1.7.13-0.90.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nspr-devel-1.7.13-0.90.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nss-1.7.13-0.90.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nss-devel-1.7.13-0.90.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/galeon-1.2.14-0.90.6.legacy.i386.rpm

Fedora Core 1:

SRPM:
http://download.fedoralegacy.org/fedora/1/updates/SRPMS/mozilla-1.7.13-1.1.1.legacy.src.rpm
http://download.fedoralegacy.org/fedora/1/updates/SRPMS/epiphany-1.0.8-1.fc1.6.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-1.7.13-1.1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-chat-1.7.13-1.1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-devel-1.7.13-1.1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-dom-inspector-1.7.13-1.1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-js-debugger-1.7.13-1.1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-mail-1.7.13-1.1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nspr-1.7.13-1.1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nspr-devel-1.7.13-1.1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nss-1.7.13-1.1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nss-devel-1.7.13-1.1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/epiphany-1.0.8-1.fc1.6.legacy.i386.rpm

Fedora Core 2:

SRPM:
http://download.fedoralegacy.org/fedora/2/updates/SRPMS/mozilla-1.7.13-1.2.1.legacy.src.rpm
http://download.fedoralegacy.org/fedora/2/updates/SRPMS/epiphany-1.2.10-0.2.7.legacy.src.rpm
http://download.fedoralegacy.org/fedora/2/updates/SRPMS/devhelp-0.9.1-0.2.10.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-1.7.13-1.2.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-chat-1.7.13-1.2.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-devel-1.7.13-1.2.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-dom-inspector-1.7.13-1.2.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-js-debugger-1.7.13-1.2.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-mail-1.7.13-1.2.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-nspr-1.7.13-1.2.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-nspr-devel-1.7.13-1.2.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-nss-1.7.13-1.2.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/2/updates/i386/mozilla-nss-devel-1.7.13-1.2.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/2/updates/i386/epiphany-1.2.10-0.2.7.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/2/updates/i386/devhelp-0.9.1-0.2.10.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/2/updates/i386/devhelp-devel-0.9.1-0.2.10.legacy.i386.rpm

Fedora Core 3:

SRPM:
http://download.fedoralegacy.org/fedora/3/updates/SRPMS/mozilla-1.7.13-1.3.1.legacy.src.rpm
http://download.fedoralegacy.org/fedora/3/updates/SRPMS/epiphany-1.4.9-1.1.legacy.src.rpm
http://download.fedoralegacy.org/fedora/3/updates/SRPMS/devhelp-0.9.2-2.3.7.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/3/updates/i386/mozilla-1.7.13-1.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/mozilla-chat-1.7.13-1.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/mozilla-devel-1.7.13-1.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/mozilla-dom-inspector-1.7.13-1.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/mozilla-js-debugger-1.7.13-1.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/mozilla-mail-1.7.13-1.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/mozilla-nspr-1.7.13-1.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/mozilla-nspr-devel-1.7.13-1.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/mozilla-nss-1.7.13-1.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/mozilla-nss-devel-1.7.13-1.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/epiphany-1.4.9-1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/epiphany-devel-1.4.9-1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/devhelp-0.9.2-2.3.7.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/devhelp-devel-0.9.2-2.3.7.legacy.i386.rpm

x86_64:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/mozilla-1.7.13-1.3.1.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/mozilla-chat-1.7.13-1.3.1.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/mozilla-devel-1.7.13-1.3.1.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/mozilla-dom-inspector-1.7.13-1.3.1.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/mozilla-js-debugger-1.7.13-1.3.1.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/mozilla-mail-1.7.13-1.3.1.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/mozilla-nspr-1.7.13-1.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/mozilla-nspr-1.7.13-1.3.1.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/mozilla-nspr-devel-1.7.13-1.3.1.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/mozilla-nss-1.7.13-1.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/mozilla-nss-1.7.13-1.3.1.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/mozilla-nss-devel-1.7.13-1.3.1.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/epiphany-1.4.9-1.1.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/epiphany-devel-1.4.9-1.1.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/devhelp-0.9.2-2.3.7.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/devhelp-devel-0.9.2-2.3.7.legacy.x86_64.rpm

7. Verification:

SHA1 sum Package Name


rh7.3:
b7616c52ee2776f3577fcda0a0628c5ec6cffae7 redhat/7.3/updates/i386/mozilla-1.7.13-0.73.1.legacy.i386.rpm
a6234bd3b89616ce5b924a36c95ba1421b6b8ecf redhat/7.3/updates/i386/mozilla-chat-1.7.13-0.73.1.legacy.i386.rpm
3d7b92d47b825f5a936c54ca63679916f428917e redhat/7.3/updates/i386/mozilla-devel-1.7.13-0.73.1.legacy.i386.rpm
2b4c765543b3f4fc5ac04127ca70c70a33fddaec redhat/7.3/updates/i386/mozilla-dom-inspector-1.7.13-0.73.1.legacy.i386.rpm
c15eceb55105a87f8d5dc0db24b9cf95e815a5a2 redhat/7.3/updates/i386/mozilla-js-debugger-1.7.13-0.73.1.legacy.i386.rpm
09dcdb176779a013efc6b1819e5391854d94a751 redhat/7.3/updates/i386/mozilla-mail-1.7.13-0.73.1.legacy.i386.rpm
5126d56d8ff98dfdcd69ed6864821120fc959c55 redhat/7.3/updates/i386/mozilla-nspr-1.7.13-0.73.1.legacy.i386.rpm
d2db357f5fe0d1ffce22db18f7d95c96dcfcffa3 redhat/7.3/updates/i386/mozilla-nspr-devel-1.7.13-0.73.1.legacy.i386.rpm
7b3a403f4981d5ffa676aa38e5699fca9e7c2f18 redhat/7.3/updates/i386/mozilla-nss-1.7.13-0.73.1.legacy.i386.rpm
3eea1812fa6a6ef13ed8826cd7734bd266c9b0fb redhat/7.3/updates/i386/mozilla-nss-devel-1.7.13-0.73.1.legacy.i386.rpm
46393b4afb72fcd8100de2c61b6531d9ffe1dbf5 redhat/7.3/updates/i386/galeon-1.2.14-0.73.6.legacy.i386.rpm
d7222582e0c6d2cb635e07d91f6ffd4f85d36a49 redhat/7.3/updates/SRPMS/mozilla-1.7.13-0.73.1.legacy.src.rpm
b437ce5a3b53a11730c42590f28f8a8437622a2f redhat/7.3/updates/SRPMS/galeon-1.2.14-0.73.6.legacy.src.rpm

rh9:
624c5f90520fba704ad4f66dbf90b1f1c957b13c redhat/9/updates/i386/mozilla-1.7.13-0.90.1.legacy.i386.rpm
d774d70acfa13e6fdfaed04fe99dc72f6d2ff9e8 redhat/9/updates/i386/mozilla-chat-1.7.13-0.90.1.legacy.i386.rpm
c97b2a1d23cdcec966ad0f578ae7ed54298e0539 redhat/9/updates/i386/mozilla-devel-1.7.13-0.90.1.legacy.i386.rpm
494506d66fe98871e624009969ac642c98a1f812 redhat/9/updates/i386/mozilla-dom-inspector-1.7.13-0.90.1.legacy.i386.rpm
b844468a52354d6e9233a3f2b423c21879c7ca2f redhat/9/updates/i386/mozilla-js-debugger-1.7.13-0.90.1.legacy.i386.rpm
2313fc46b0f7192d2e50675b978a6132fef9c7e3 redhat/9/updates/i386/mozilla-mail-1.7.13-0.90.1.legacy.i386.rpm
c37ce58b4bc86d84585e53c97ef63f3733ffa038 redhat/9/updates/i386/mozilla-nspr-1.7.13-0.90.1.legacy.i386.rpm
c99c3912597d83cdb161c1e2d4476985ebbe301f redhat/9/updates/i386/mozilla-nspr-devel-1.7.13-0.90.1.legacy.i386.rpm
82f292d71571e66844a0b6b59252271bcf26c5a9 redhat/9/updates/i386/mozilla-nss-1.7.13-0.90.1.legacy.i386.rpm
8da1e54eed9099c2dbb4c04e97157bf742128488 redhat/9/updates/i386/mozilla-nss-devel-1.7.13-0.90.1.legacy.i386.rpm
99041c948b0fb28092be0b817e2f631b76a05614 redhat/9/updates/i386/galeon-1.2.14-0.90.6.legacy.i386.rpm
d20d8e1985145c55a185f67e4209a01f1654c0ac redhat/9/updates/SRPMS/mozilla-1.7.13-0.90.1.legacy.src.rpm
aa35ab30634d4f5018e3f3e7bb4c290a23e8b1f0 redhat/9/updates/SRPMS/galeon-1.2.14-0.90.6.legacy.src.rpm

fc1:
3d510a0a221fd0af801d32075cfec02b54e07422 fedora/1/updates/i386/mozilla-1.7.13-1.1.1.legacy.i386.rpm
becd9c7a44a82ccfbe3cf6b03f051ecd4a273131 fedora/1/updates/i386/mozilla-chat-1.7.13-1.1.1.legacy.i386.rpm
1ba6d5e1f14397c25baebb208b3f94de04d46131 fedora/1/updates/i386/mozilla-devel-1.7.13-1.1.1.legacy.i386.rpm
bc3d9984f60bbe6794c205e3222c9ea2335bd42e fedora/1/updates/i386/mozilla-dom-inspector-1.7.13-1.1.1.legacy.i386.rpm
27b23b8f5be8a15c8294a1a40b62aafd0c8b8da8 fedora/1/updates/i386/mozilla-js-debugger-1.7.13-1.1.1.legacy.i386.rpm
fac226fb8ed3c08bd5c38729ca4bdcb7cbfa7155 fedora/1/updates/i386/mozilla-mail-1.7.13-1.1.1.legacy.i386.rpm
50de7263571cfdca103af679b2b4824cf5e4b733 fedora/1/updates/i386/mozilla-nspr-1.7.13-1.1.1.legacy.i386.rpm
6864171e9ad26571bc9fae8c22d9b713e790e217 fedora/1/updates/i386/mozilla-nspr-devel-1.7.13-1.1.1.legacy.i386.rpm
231222af647baca7cf8ad3aa70102baf065844ea fedora/1/updates/i386/mozilla-nss-1.7.13-1.1.1.legacy.i386.rpm
b2a45de48fd072f61c4887c9fb7b1e28d5ceb724 fedora/1/updates/i386/mozilla-nss-devel-1.7.13-1.1.1.legacy.i386.rpm
4278190ae02b1ba55ab8f7bff797aa0b7c6367cf fedora/1/updates/i386/epiphany-1.0.8-1.fc1.6.legacy.i386.rpm
d7698a730ded9bf23f9cf50af0b311344d6a32c9 fedora/1/updates/SRPMS/mozilla-1.7.13-1.1.1.legacy.src.rpm
98e8156234d0d70503b2e35958b6c16fd6af9839 fedora/1/updates/SRPMS/epiphany-1.0.8-1.fc1.6.legacy.src.rpm

fc2:
159c63cf7ea9fdc986cea0e5f5385dfb5b6305b4 fedora/2/updates/i386/mozilla-1.7.13-1.2.1.legacy.i386.rpm
f407853505e31c18da4b7f6cb381eda08f92e95a fedora/2/updates/i386/mozilla-chat-1.7.13-1.2.1.legacy.i386.rpm
34b9bfcbadd11a46d9c8e83bb74cadb20f5e4923 fedora/2/updates/i386/mozilla-devel-1.7.13-1.2.1.legacy.i386.rpm
dee1265fd2e11184729411971ebbf78cb563a0e5 fedora/2/updates/i386/mozilla-dom-inspector-1.7.13-1.2.1.legacy.i386.rpm
c04910085005cd7e6df6f94ef59c97df8825c07b fedora/2/updates/i386/mozilla-js-debugger-1.7.13-1.2.1.legacy.i386.rpm
4d7705a6ca92e8508dfc129f9d230b655fcaf1d5 fedora/2/updates/i386/mozilla-mail-1.7.13-1.2.1.legacy.i386.rpm
a77cbd95adaf8033fd41a79c8fa5834f5bf6966b fedora/2/updates/i386/mozilla-nspr-1.7.13-1.2.1.legacy.i386.rpm
bac22ca27bd47b5568016b836655c0205f412f07 fedora/2/updates/i386/mozilla-nspr-devel-1.7.13-1.2.1.legacy.i386.rpm
a2a5c35a60ce9a77776ca68f85540f4b36a5d687 fedora/2/updates/i386/mozilla-nss-1.7.13-1.2.1.legacy.i386.rpm
bc9bed78a37a55ee2c7c0447e28454117d75b2f5 fedora/2/updates/i386/mozilla-nss-devel-1.7.13-1.2.1.legacy.i386.rpm
82050caf931b8f86483430536d1044ca0e18e26c fedora/2/updates/i386/epiphany-1.2.10-0.2.7.legacy.i386.rpm
fd3a6e7733046ab57d5d0578942b63039f60549f fedora/2/updates/i386/devhelp-0.9.1-0.2.10.legacy.i386.rpm
dbfc536e2d5fb26ae710550517d00eb7b5c1c425 fedora/2/updates/i386/devhelp-devel-0.9.1-0.2.10.legacy.i386.rpm
7d3714941a249cf2706860c80d5fdd2f6f9d6a49 fedora/2/updates/SRPMS/mozilla-1.7.13-1.2.1.legacy.src.rpm
b63f40f2d2c84c6a23ba9668a0ad523600208b88 fedora/2/updates/SRPMS/epiphany-1.2.10-0.2.7.legacy.src.rpm
e0d504c88489904fe8c94cf552ba4c91ba78dd69 fedora/2/updates/SRPMS/devhelp-0.9.1-0.2.10.legacy.src.rpm

fc3:
fc30ba78ef98ffc0f4d7830a293a5a45532487a1 fedora/3/updates/i386/mozilla-1.7.13-1.3.1.legacy.i386.rpm
6046bfef309c48de5545ded1dff026bda82aa12a fedora/3/updates/i386/mozilla-chat-1.7.13-1.3.1.legacy.i386.rpm
2cb20e33c2931ce7f12a0149b8a2f1992ff47459 fedora/3/updates/i386/mozilla-devel-1.7.13-1.3.1.legacy.i386.rpm
182a9e1a32e9d354b6ffedb5b7be7dd49192b119 fedora/3/updates/i386/mozilla-dom-inspector-1.7.13-1.3.1.legacy.i386.rpm
fbac943985224c5bdbbce8b83157614f48f2c11d fedora/3/updates/i386/mozilla-js-debugger-1.7.13-1.3.1.legacy.i386.rpm
dc733cb3312c3d105e4414bf969e84ddfa5ff435 fedora/3/updates/i386/mozilla-mail-1.7.13-1.3.1.legacy.i386.rpm
fd7ef3c6ab771fd368c81bd1925c0194c0503dc7 fedora/3/updates/i386/mozilla-nspr-1.7.13-1.3.1.legacy.i386.rpm
6ca450fb3bda3d9acc3e9dcd86c7480fda7c881b fedora/3/updates/i386/mozilla-nspr-devel-1.7.13-1.3.1.legacy.i386.rpm
25d618ca1f740e9ce6a8d18878dcef447f0dcfbe fedora/3/updates/i386/mozilla-nss-1.7.13-1.3.1.legacy.i386.rpm
f61c46c5e3a6bbfcd84c1d1db0948ad351568cfb fedora/3/updates/i386/mozilla-nss-devel-1.7.13-1.3.1.legacy.i386.rpm
3d0a3210e82fe5059d4dd97dfad797522a8dd566 fedora/3/updates/i386/epiphany-1.4.9-1.1.legacy.i386.rpm
9e1b3c5029b1da72303b87566d0fe98ae80316ad fedora/3/updates/i386/epiphany-devel-1.4.9-1.1.legacy.i386.rpm
2700c95dbed803c53f4a632d818df4e6045abede fedora/3/updates/i386/devhelp-0.9.2-2.3.7.legacy.i386.rpm
0635473154c90a0654938e15eea3e0fab24cbcee fedora/3/updates/i386/devhelp-devel-0.9.2-2.3.7.legacy.i386.rpm
2b9902cc94ef38dac784342d1330cdb34a0308c2 fedora/3/updates/x86_64/mozilla-1.7.13-1.3.1.legacy.x86_64.rpm
d6c6635c7a9004b90a20ff32330f3e2aef755e7e fedora/3/updates/x86_64/mozilla-chat-1.7.13-1.3.1.legacy.x86_64.rpm
ec5ca5851ea31e60f5211d4f308b2d4eae65e97b fedora/3/updates/x86_64/mozilla-devel-1.7.13-1.3.1.legacy.x86_64.rpm
74ac4472c45fecb4562fe73c1aba2c8fbc381da6 fedora/3/updates/x86_64/mozilla-dom-inspector-1.7.13-1.3.1.legacy.x86_64.rpm
0b136eb099b9262271d29d1c55f08e3623fd9b9e fedora/3/updates/x86_64/mozilla-js-debugger-1.7.13-1.3.1.legacy.x86_64.rpm
45aaade65400ab18d12525de0949a96d06c1d784 fedora/3/updates/x86_64/mozilla-mail-1.7.13-1.3.1.legacy.x86_64.rpm
fd7ef3c6ab771fd368c81bd1925c0194c0503dc7 fedora/3/updates/x86_64/mozilla-nspr-1.7.13-1.3.1.legacy.i386.rpm
19919ed666049efdb10a571441b32733e3a928c9 fedora/3/updates/x86_64/mozilla-nspr-1.7.13-1.3.1.legacy.x86_64.rpm
2020bad33430a1c9cf6e9298fb3ea8f264262e23 fedora/3/updates/x86_64/mozilla-nspr-devel-1.7.13-1.3.1.legacy.x86_64.rpm
25d618ca1f740e9ce6a8d18878dcef447f0dcfbe fedora/3/updates/x86_64/mozilla-nss-1.7.13-1.3.1.legacy.i386.rpm
1c9d432246665f03ad4c24c7a21ed2d40eea736c fedora/3/updates/x86_64/mozilla-nss-1.7.13-1.3.1.legacy.x86_64.rpm
2e47b9e82c433533cd3e39c2380c511e03e9b320 fedora/3/updates/x86_64/mozilla-nss-devel-1.7.13-1.3.1.legacy.x86_64.rpm
8e763b21f9289a454484fa65ed27053f87b83527 fedora/3/updates/x86_64/epiphany-1.4.9-1.1.legacy.x86_64.rpm
a5b5f6d6dbbb2385a13d8b5290d92c119c837c43 fedora/3/updates/x86_64/epiphany-devel-1.4.9-1.1.legacy.x86_64.rpm
54b0234a8abf2b04f45b8062806bc500347a0ce2 fedora/3/updates/x86_64/devhelp-0.9.2-2.3.7.legacy.x86_64.rpm
18374065d2a67b4d0838e4c63bff44d25658ff53 fedora/3/updates/x86_64/devhelp-devel-0.9.2-2.3.7.legacy.x86_64.rpm
5a9ebd563c86b57673ee717a777b2b828cb6f7ae fedora/3/updates/SRPMS/mozilla-1.7.13-1.3.1.legacy.src.rpm
9b7f3d9405d50fb5f52931ef8f18d9e1f2b4fe58 fedora/3/updates/SRPMS/epiphany-1.4.9-1.1.legacy.src.rpm
71a4112fbd0411c57a8b37ba2179b7ec5b8f024e fedora/3/updates/SRPMS/devhelp-0.9.2-2.3.7.legacy.src.rpm

These packages are GPG signed by Fedora Legacy for security. Our key is available from http://www.fedoralegacy.org/about/security.php

You can verify each package with the following command:

rpm --checksig -v <filename>

If you only wish to verify that each package has not been corrupted or tampered with, examine only the sha1sum with the following command:

sha1sum <filename>

8. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0748
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0749
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0884
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1727
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1728
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1729
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1730
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1731
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1732
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1733
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1734
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1735
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1737
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1738
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1739
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1740
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1741
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1742
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1790

9. Contact:

The Fedora Legacy security contact is <secnotice@fedoralegacy.org>. More project details at http://www.fedoralegacy.org



Fedora Legacy Update Advisory

Synopsis: Updated firefox package fixes security issues
Advisory ID: FLSA:189137-2
Issue date: 2006-06-06
Product: Fedora Core
Keywords: Bugfix, Security
CVE Names: CVE-2006-0748 CVE-2006-0749 CVE-2006-1724 CVE-2006-1727 CVE-2006-1728 CVE-2006-1729 CVE-2006-1730 CVE-2006-1731 CVE-2006-1732 CVE-2006-1733 CVE-2006-1734 CVE-2006-1735 CVE-2006-1737 CVE-2006-1738 CVE-2006-1739 CVE-2006-1740 CVE-2006-1741 CVE-2006-1742 CVE-2006-1790



1. Topic:

An updated firefox package that fixes several security bugs is now available.

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.

2. Relevant releases/architectures:

Fedora Core 3 - i386, x86_64

3. Problem description:

Several bugs were found in the way Firefox processes malformed javascript. A malicious web page could modify the content of a different open web page, possibly stealing sensitive information or conducting a cross-site scripting attack. (CVE-2006-1731, CVE-2006-1732, CVE-2006-1741)

Several bugs were found in the way Firefox processes certain javascript actions. A malicious web page could execute arbitrary javascript instructions with the permissions of "chrome", allowing the page to steal sensitive information or install browser malware. (CVE-2006-1727, CVE-2006-1728, CVE-2006-1733, CVE-2006-1734, CVE-2006-1735, CVE-2006-1742)

Several bugs were found in the way Firefox processes malformed web pages. A carefully crafted malicious web page could cause the execution of arbitrary code as the user running Firefox. (CVE-2006-0748, CVE-2006-0749, CVE-2006-1724, CVE-2006-1730, CVE-2006-1737, CVE-2006-1738, CVE-2006-1739, CVE-2006-1790)

A bug was found in the way Firefox displays the secure site icon. If a browser is configured to display the non-default secure site modal warning dialog, it may be possible to trick a user into believing they are viewing a secure site. (CVE-2006-1740)

A bug was found in the way Firefox allows javascript mutation events on "input" form elements. A malicious web page could be created in such a way that when a user submits a form, an arbitrary file could be uploaded to the attacker. (CVE-2006-1729)

Users of Firefox are advised to upgrade to these updated packages containing Firefox version 1.0.8 which corrects these issues.

4. Solution:

Before applying this update, make sure all previously released errata relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory only contains the desired RPMs.

Please note that this update is also available via yum and apt. Many people find this an easier way to apply updates. To use yum issue:

yum update

or to use apt:

apt-get update; apt-get upgrade

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. This assumes that you have yum or apt-get configured for obtaining Fedora Legacy content. Please visit http://www.fedoralegacy.org/docs for directions on how to configure yum and apt-get.

5. Bug IDs fixed:

https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189137

6. RPMs required:

Fedora Core 3:

SRPM:
http://download.fedoralegacy.org/fedora/3/updates/SRPMS/firefox-1.0.8-1.1.fc3.1.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/3/updates/i386/firefox-1.0.8-1.1.fc3.1.legacy.i386.rpm

x86_64:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/firefox-1.0.8-1.1.fc3.1.legacy.x86_64.rpm

7. Verification:

SHA1 sum Package Name


8b719bb18c6dfe14b472c684ac5133d82d1b96d0 fedora/3/updates/i386/firefox-1.0.8-1.1.fc3.1.legacy.i386.rpm
946f2ccbc412675ee6959a3dee50c2cb3ba90c3a fedora/3/updates/x86_64/firefox-1.0.8-1.1.fc3.1.legacy.x86_64.rpm
0747aa65730e328a9274ec66c0de8dc30645dc1d fedora/3/updates/SRPMS/firefox-1.0.8-1.1.fc3.1.legacy.src.rpm

These packages are GPG signed by Fedora Legacy for security. Our key is available from http://www.fedoralegacy.org/about/security.php

You can verify each package with the following command:

rpm --checksig -v <filename>

If you only wish to verify that each package has not been corrupted or tampered with, examine only the sha1sum with the following command:

sha1sum <filename>

8. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0748
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0749
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1724
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1727
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1728
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1729
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1730
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1731
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1732
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1733
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1734
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1735
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1737
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1738
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1739
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1740
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1741
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1742
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1790

9. Contact:

The Fedora Legacy security contact is <secnotice@fedoralegacy.org>. More project details at http://www.fedoralegacy.org



Fedora Legacy Update Advisory

Synopsis: Updated X.org packages fix security issue
Advisory ID: FLSA:190777
Issue date: 2006-06-06
Product: Fedora Core
Keywords: Bugfix
CVE Names: CVE-2006-1526



1. Topic:

Updated X.org packages that fix a security issue are now available.

X.org is an open source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces (GUIs) such as GNOME and KDE are designed upon.

2. Relevant releases/architectures:

Fedora Core 3 - i386, x86_64

3. Problem description:

A buffer overflow flaw in the X.org server RENDER extension was discovered. A malicious authorized client could exploit this issue to cause a denial of service (crash) or potentially execute arbitrary code with root privileges on the X.org server. (CVE-2006-1526)

Users of X.org should upgrade to these updated packages, which contain a backported patch and is not vulnerable to this issue.

4. Solution:

Before applying this update, make sure all previously released errata relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory only contains the desired RPMs.

Please note that this update is also available via yum and apt. Many people find this an easier way to apply updates. To use yum issue:

yum update

or to use apt:

apt-get update; apt-get upgrade

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. This assumes that you have yum or apt-get configured for obtaining Fedora Legacy content. Please visit http://www.fedoralegacy.org/docs for directions on how to configure yum and apt-get.

5. Bug IDs fixed:

https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=190777

6. RPMs required:

Fedora Core 3:

SRPM:
http://download.fedoralegacy.org/fedora/3/updates/SRPMS/xorg-x11-6.8.2-1.FC3.45.3.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-deprecated-libs-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-deprecated-libs-devel-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-devel-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-doc-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-font-utils-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-libs-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-Mesa-libGL-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-Mesa-libGLU-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-sdk-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-tools-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-twm-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-xauth-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-xdm-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-Xdmx-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-xfs-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-Xnest-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/i386/xorg-x11-Xvfb-6.8.2-1.FC3.45.3.legacy.i386.rpm

x86_64:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-deprecated-libs-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-deprecated-libs-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-deprecated-libs-devel-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-devel-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-devel-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-doc-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-font-utils-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-libs-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-libs-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-Mesa-libGL-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-Mesa-libGL-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-Mesa-libGLU-6.8.2-1.FC3.45.3.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-Mesa-libGLU-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-sdk-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-tools-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-twm-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-xauth-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-xdm-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-Xdmx-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-xfs-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-Xnest-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
http://download.fedoralegacy.org/fedora/3/updates/x86_64/xorg-x11-Xvfb-6.8.2-1.FC3.45.3.legacy.x86_64.rpm

7. Verification:

SHA1 sum Package Name


6c4f8cc2a12da27bc7eba148b139bbbc0c16c877 fedora/3/updates/i386/xorg-x11-6.8.2-1.FC3.45.3.legacy.i386.rpm
3f94f87fb882c2f5116fc7e153db8a27b47902d9 fedora/3/updates/i386/xorg-x11-deprecated-libs-6.8.2-1.FC3.45.3.legacy.i386.rpm
7f4c16bed758307fc89963cdc0e60d6104690384 fedora/3/updates/i386/xorg-x11-deprecated-libs-devel-6.8.2-1.FC3.45.3.legacy.i386.rpm
07b928bdc56bc8d2fe0828afbe59d8dfcfabbede fedora/3/updates/i386/xorg-x11-devel-6.8.2-1.FC3.45.3.legacy.i386.rpm
c7adb504db755f139b2b8454c37b6add3204c2b0 fedora/3/updates/i386/xorg-x11-doc-6.8.2-1.FC3.45.3.legacy.i386.rpm
dd5caa2e8fadf2eff908615231819cf69cf130ea fedora/3/updates/i386/xorg-x11-font-utils-6.8.2-1.FC3.45.3.legacy.i386.rpm
8e30c1a599b8f2bb39abdce9dbd9c0559926f63e fedora/3/updates/i386/xorg-x11-libs-6.8.2-1.FC3.45.3.legacy.i386.rpm
23fc45993a3e83844ad2029653c580e9c9fba606 fedora/3/updates/i386/xorg-x11-Mesa-libGL-6.8.2-1.FC3.45.3.legacy.i386.rpm
13b96e8dca25068c884a5bdf2fd188f684472eb5 fedora/3/updates/i386/xorg-x11-Mesa-libGLU-6.8.2-1.FC3.45.3.legacy.i386.rpm
2ecbdbc243d2fed742d56b7183367625c318029a fedora/3/updates/i386/xorg-x11-sdk-6.8.2-1.FC3.45.3.legacy.i386.rpm
7bba05d923dde98a77233a5cb4ef7b67660ad345 fedora/3/updates/i386/xorg-x11-tools-6.8.2-1.FC3.45.3.legacy.i386.rpm
9d51ef13a3ba67eb4afe4e4417ff1735cf659829 fedora/3/updates/i386/xorg-x11-twm-6.8.2-1.FC3.45.3.legacy.i386.rpm
61201dd9054fbe6336381d9532f3d0ec60d9b537 fedora/3/updates/i386/xorg-x11-xauth-6.8.2-1.FC3.45.3.legacy.i386.rpm
8c0f9419d979a3defbe376693c1d39cbdb8eeabb fedora/3/updates/i386/xorg-x11-xdm-6.8.2-1.FC3.45.3.legacy.i386.rpm
132c26d0cc1fe2c5e3946aae493a6bf16ec8b659 fedora/3/updates/i386/xorg-x11-Xdmx-6.8.2-1.FC3.45.3.legacy.i386.rpm
9f71fe79b510f7dd06a41b01eeb5c4850ee88411 fedora/3/updates/i386/xorg-x11-xfs-6.8.2-1.FC3.45.3.legacy.i386.rpm
2b36b8679d782f6d1f0899262d1ad961fb3703e0 fedora/3/updates/i386/xorg-x11-Xnest-6.8.2-1.FC3.45.3.legacy.i386.rpm
aba6d27d8bb5befdb4694546b66cbc88d945973b fedora/3/updates/i386/xorg-x11-Xvfb-6.8.2-1.FC3.45.3.legacy.i386.rpm

9ac2f2b492165554bb358c39d8e4d031e1a4ee1b fedora/3/updates/x86_64/xorg-x11-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
3f94f87fb882c2f5116fc7e153db8a27b47902d9 fedora/3/updates/x86_64/xorg-x11-deprecated-libs-6.8.2-1.FC3.45.3.legacy.i386.rpm
26d851236ece4e649845a0923420b5a257cd1bde fedora/3/updates/x86_64/xorg-x11-deprecated-libs-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
c19744109a7e088d79f7ced7349af8ac8ed5d561 fedora/3/updates/x86_64/xorg-x11-deprecated-libs-devel-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
07b928bdc56bc8d2fe0828afbe59d8dfcfabbede fedora/3/updates/x86_64/xorg-x11-devel-6.8.2-1.FC3.45.3.legacy.i386.rpm
8f030968d84bcd3d602eb7aaf836a0d15b75c44d fedora/3/updates/x86_64/xorg-x11-devel-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
a1337070e3c6362133fde9d7779edf7533072133 fedora/3/updates/x86_64/xorg-x11-doc-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
a7feafa8ded15cf48d844366c1e3be37f23a1cfd fedora/3/updates/x86_64/xorg-x11-font-utils-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
8e30c1a599b8f2bb39abdce9dbd9c0559926f63e fedora/3/updates/x86_64/xorg-x11-libs-6.8.2-1.FC3.45.3.legacy.i386.rpm
0eaa41f3cf3ac8871444908aafc1691a0008e0d5 fedora/3/updates/x86_64/xorg-x11-libs-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
23fc45993a3e83844ad2029653c580e9c9fba606 fedora/3/updates/x86_64/xorg-x11-Mesa-libGL-6.8.2-1.FC3.45.3.legacy.i386.rpm
6a0b603f3acb00c85ea9d20148ecba46e7d21368 fedora/3/updates/x86_64/xorg-x11-Mesa-libGL-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
13b96e8dca25068c884a5bdf2fd188f684472eb5 fedora/3/updates/x86_64/xorg-x11-Mesa-libGLU-6.8.2-1.FC3.45.3.legacy.i386.rpm
1c479506c5b7ebd1d49063770233d431fc754004 fedora/3/updates/x86_64/xorg-x11-Mesa-libGLU-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
b4f4b333906a9eeed08eb6ffcb830f8584c478dd fedora/3/updates/x86_64/xorg-x11-sdk-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
0f661c108936ea85fe38a478ee45b5bf8058b3ca fedora/3/updates/x86_64/xorg-x11-tools-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
37ad2d9f35dd213b684dda7513d98420daf4834e fedora/3/updates/x86_64/xorg-x11-twm-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
33705cb293a6bfe37e55244153e5e23175d2c4e2 fedora/3/updates/x86_64/xorg-x11-xauth-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
2771026feae63c0362bfa5daa6d9666d5b8acc89 fedora/3/updates/x86_64/xorg-x11-xdm-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
5d03a8e36c3c9474d4de53d3d7cc2c7d7d936528 fedora/3/updates/x86_64/xorg-x11-Xdmx-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
46afe47ebc3548b092fa74d831cdbb80a1092213 fedora/3/updates/x86_64/xorg-x11-xfs-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
60276aa97510fc4be52aa3720a0d20a650a0c968 fedora/3/updates/x86_64/xorg-x11-Xnest-6.8.2-1.FC3.45.3.legacy.x86_64.rpm
21260daa99910a143934800229f7acfc9f256b75 fedora/3/updates/x86_64/xorg-x11-Xvfb-6.8.2-1.FC3.45.3.legacy.x86_64.rpm

699a18fb173a9e3a23e9fd653e152d73e7aae737 fedora/3/updates/SRPMS/xorg-x11-6.8.2-1.FC3.45.3.legacy.src.rpm

These packages are GPG signed by Fedora Legacy for security. Our key is available from http://www.fedoralegacy.org/about/security.php

You can verify each package with the following command:

rpm --checksig -v <filename>

If you only wish to verify that each package has not been corrupted or tampered with, examine only the sha1sum with the following command:

sha1sum <filename>

8. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1526

9. Contact:

The Fedora Legacy security contact is <secnotice@fedoralegacy.org>. More project details at http://www.fedoralegacy.org



Fedora Legacy Update Advisory

Synopsis: Updated squirrelmail package fixes security issues
Advisory ID: FLSA:190884
Issue date: 2006-06-06
Product: Red Hat Linux, Fedora Core
Keywords: Bugfix
CVE Names: CVE-2006-0188 CVE-2006-0195 CVE-2006-0377



1. Topic:

An updated squirrelmail package that fixes three security issues is now available.

SquirrelMail is a standards-based webmail package written in PHP4.

2. Relevant releases/architectures:

Red Hat Linux 9 - i386
Fedora Core 1 - i386
Fedora Core 2 - i386
Fedora Core 3 - i386, x86_64

3. Problem description:

A bug was found in the way SquirrelMail presents the right frame to the user. If a user can be tricked into opening a carefully crafted URL, it is possible to present the user with arbitrary HTML data. (CVE-2006-0188)

A bug was found in the way SquirrelMail filters incoming HTML email. It is possible to cause a victim's web browser to request remote content by opening a HTML email while running a web browser that processes certain types of invalid style sheets. Only Internet Explorer is known to process such malformed style sheets. (CVE-2006-0195)

A bug was found in the way SquirrelMail processes a request to select an IMAP mailbox. If a user can be tricked into opening a carefully crafted URL, it is possible to execute arbitrary IMAP commands as the user viewing their mail with SquirrelMail. (CVE-2006-0377)

Users of SquirrelMail are advised to upgrade to this updated package, which contains SquirrelMail version 1.4.6 and is not vulnerable to these issues.

4. Solution:

Before applying this update, make sure all previously released errata relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory only contains the desired RPMs.

Please note that this update is also available via yum and apt. Many people find this an easier way to apply updates. To use yum issue:

yum update

or to use apt:

apt-get update; apt-get upgrade

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. This assumes that you have yum or apt-get configured for obtaining Fedora Legacy content. Please visit http://www.fedoralegacy.org/docs for directions on how to configure yum and apt-get.

5. Bug IDs fixed:

https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=190884

6. RPMs required:

Red Hat Linux 9:

SRPM:
http://download.fedoralegacy.org/redhat/9/updates/SRPMS/squirrelmail-1.4.6-3.rh9.1.legacy.src.rpm

i386:
http://download.fedoralegacy.org/redhat/9/updates/i386/squirrelmail-1.4.6-3.rh9.1.legacy.noarch.rpm

Fedora Core 1:

SRPM:
http://download.fedoralegacy.org/fedora/1/updates/SRPMS/squirrelmail-1.4.6-4.fc1.1.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/1/updates/i386/squirrelmail-1.4.6-4.fc1.1.legacy.noarch.rpm

Fedora Core 2:

SRPM:
http://download.fedoralegacy.org/fedora/2/updates/SRPMS/squirrelmail-1.4.6-4.fc2.1.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/2/updates/i386/squirrelmail-1.4.6-4.fc2.1.legacy.noarch.rpm

Fedora Core 3:

SRPM:
http://download.fedoralegacy.org/fedora/3/updates/SRPMS/squirrelmail-1.4.6-4.fc3.1.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/3/updates/i386/squirrelmail-1.4.6-4.fc3.1.legacy.noarch.rpm

x86_64:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/squirrelmail-1.4.6-4.fc3.1.legacy.noarch.rpm

7. Verification:

SHA1 sum Package Name


rh9:
62ae72ed168667c97e1b6ccc5bc23dea6c374bcb redhat/9/updates/i386/squirrelmail-1.4.6-3.rh9.1.legacy.noarch.rpm
51264756a2f2bb5d8e6f5b6d1d33dcba40f41a68 redhat/9/updates/SRPMS/squirrelmail-1.4.6-3.rh9.1.legacy.src.rpm

fc1:
0e2dbf765d4df6592fad31ff331a3101fd33674e fedora/1/updates/i386/squirrelmail-1.4.6-4.fc1.1.legacy.noarch.rpm
7c6d183c795bfd1da1e872a74e7ff1f197afb93a fedora/1/updates/SRPMS/squirrelmail-1.4.6-4.fc1.1.legacy.src.rpm

fc2:
36bc9ae701f8844d6369dde0f2d4a537b2dce85c fedora/2/updates/i386/squirrelmail-1.4.6-4.fc2.1.legacy.noarch.rpm
60098c585bc6bab9df4e3883e3a0b0762fd4dc6d fedora/2/updates/SRPMS/squirrelmail-1.4.6-4.fc2.1.legacy.src.rpm

fc3:
9e96352495249c4aa526b24729128696467ca728 fedora/3/updates/i386/squirrelmail-1.4.6-4.fc3.1.legacy.noarch.rpm
9e96352495249c4aa526b24729128696467ca728 fedora/3/updates/x86_64/squirrelmail-1.4.6-4.fc3.1.legacy.noarch.rpm
3003904d9a5594cb6e3ebb190930bb9d82d83f60 fedora/3/updates/SRPMS/squirrelmail-1.4.6-4.fc3.1.legacy.src.rpm

These packages are GPG signed by Fedora Legacy for security. Our key is available from http://www.fedoralegacy.org/about/security.php

You can verify each package with the following command:

rpm --checksig -v <filename>

If you only wish to verify that each package has not been corrupted or tampered with, examine only the sha1sum with the following command:

sha1sum <filename>

8. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0188
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0195
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0377

9. Contact:

The Fedora Legacy security contact is <secnotice@fedoralegacy.org>. More project details at http://www.fedoralegacy.org



Fedora Legacy Update Advisory

Synopsis: Updated ipsec-tools package fixes security issue
Advisory ID: FLSA:190941
Issue date: 2006-06-06
Product: Fedora Core
Keywords: Bugfix
CVE Names: CVE-2005-3732



1. Topic:

An updated ipsec-tools package that fixes a bug in racoon is now available.

The ipsec-tools package is used in conjunction with the IPsec functionality in the linux kernel and includes racoon, an IKEv1 keying daemon.

2. Relevant releases/architectures:

Fedora Core 2 - i386
Fedora Core 3 - i386, x86_64

3. Problem description:

A denial of service flaw was found in the ipsec-tools racoon daemon. If a victim's machine has racoon configured in a non-recommended insecure manner, it is possible for a remote attacker to crash the racoon daemon. (CVE-2005-3732)

Users of ipsec-tools should upgrade to this updated package, which contains backported patches, and is not vulnerable to this issue.

4. Solution:

Before applying this update, make sure all previously released errata relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory only contains the desired RPMs.

Please note that this update is also available via yum and apt. Many people find this an easier way to apply updates. To use yum issue:

yum update

or to use apt:

apt-get update; apt-get upgrade

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. This assumes that you have yum or apt-get configured for obtaining Fedora Legacy content. Please visit http://www.fedoralegacy.org/docs for directions on how to configure yum and apt-get.

5. Bug IDs fixed:

https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=190941

6. RPMs required:

Fedora Core 2:

SRPM:
http://download.fedoralegacy.org/fedora/2/updates/SRPMS/ipsec-tools-0.5-2.fc2.1.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/2/updates/i386/ipsec-tools-0.5-2.fc2.1.legacy.i386.rpm

Fedora Core 3:

SRPM:
http://download.fedoralegacy.org/fedora/3/updates/SRPMS/ipsec-tools-0.5-2.fc3.1.legacy.src.rpm

i386:
http://download.fedoralegacy.org/fedora/3/updates/i386/ipsec-tools-0.5-2.fc3.1.legacy.i386.rpm

x86_64:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/ipsec-tools-0.5-2.fc3.1.legacy.x86_64.rpm

7. Verification:

SHA1 sum Package Name


fc2:
e8f91c085fb9533106c6ebc442572bd0b22f2470 fedora/2/updates/i386/ipsec-tools-0.5-2.fc2.1.legacy.i386.rpm
292a0a1426bc75abf0b34a3c91279a40ea78aac2 fedora/2/updates/SRPMS/ipsec-tools-0.5-2.fc2.1.legacy.src.rpm

fc3:
e49b07bcc0e3dbe56401056b65b36133dabb4b6c fedora/3/updates/i386/ipsec-tools-0.5-2.fc3.1.legacy.i386.rpm
10eed18767204b88c2811115d889c0a372079ec2 fedora/3/updates/x86_64/ipsec-tools-0.5-2.fc3.1.legacy.x86_64.rpm
0832eb1da62b597bc32b26ce9e8429d7e67f43d2 fedora/3/updates/SRPMS/ipsec-tools-0.5-2.fc3.1.legacy.src.rpm

These packages are GPG signed by Fedora Legacy for security. Our key is available from http://www.fedoralegacy.org/about/security.php

You can verify each package with the following command:

rpm --checksig -v <filename>

If you only wish to verify that each package has not been corrupted or tampered with, examine only the sha1sum with the following command:

sha1sum <filename>

8. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3732

9. Contact:

The Fedora Legacy security contact is <secnotice@fedoralegacy.org>. More project details at http://www.fedoralegacy.org


Gentoo Linux


Gentoo Linux Security Advisory GLSA 200606-01

http://security.gentoo.org/


Severity: Normal
Title: Opera: Buffer overflow
Date: June 07, 2006
Bugs: #129800
ID: 200606-01


Synopsis

Opera contains an integer signedness error resulting in a buffer overflow which may allow a remote attacker to execute arbitrary code.

Background

Opera is a multi-platform web browser.

Affected packages


Package / Vulnerable / Unaffected
1 www-client/opera < 8.54 >= 8.54

Description

SEC Consult has discovered a buffer overflow in the code processing style sheet attributes. It is caused by an integer signedness error in a length check followed by a call to a string function. It seems to be hard to exploit this buffer overflow to execute arbitrary code because of the very large amount memory that has to be copied.

Impact

A remote attacker can entice a user to visit a web page containing a specially crafted style sheet attribute that will crash the user's browser and maybe lead to the execution of arbitrary code.

Workaround

There is no known workaround at this time.

Resolution

All Opera users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=www-client/opera-8.54"

References

[ 1 ] CVE-2006-1834

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1834

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200606-01.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5


Gentoo Linux Security Advisory GLSA 200606-04

http://security.gentoo.org/


Severity: Normal
Title: Tor: Several vulnerabilities
Date: June 07, 2006
Bugs: #134329
ID: 200606-04


Synopsis

Tor is vulnerable to a possible buffer overflow, a Denial of Service, information disclosure and information leak.

Background

Tor is an implementation of second generation Onion Routing, a connection-oriented anonymizing communication service.

Affected packages


Package / Vulnerable / Unaffected
1 net-misc/tor < 0.1.1.20 >= 0.1.1.20

Description

Some integer overflows exist when adding elements to the smartlists. Non-printable characters received from the network are not properly sanitised before being logged. There are additional unspecified bugs in the directory server and in the internal circuits.

Impact

The possible buffer overflow may allow a remote attacker to execute arbitrary code on the server by sending large inputs. The other vulnerabilities can lead to a Denial of Service, a lack of logged information, or some information disclosure.

Workaround

There is no known workaround at this time.

Resolution

All Tor users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=net-misc/tor-0.1.1.20"

References

[ 1 ] CVE-2006-0414

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0414

[ 2 ] Tor ChangeLog

http://tor.eff.org/cvs/tor/ChangeLog

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200606-04.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5


Gentoo Linux Security Advisory GLSA 200606-05

http://security.gentoo.org/


Severity: Low
Title: Pound: HTTP request smuggling
Date: June 07, 2006
Bugs: #118541
ID: 200606-05


Synopsis

Pound is vulnerable to HTTP request smuggling, which could be exploited to bypass security restrictions or poison web caches.

Background

Pound is a reverse proxy, load balancer and HTTPS front-end. It allows to distribute the load on several web servers and offers a SSL wrapper for web servers that do not support SSL directly.

Affected packages


Package / Vulnerable / Unaffected
1 www-servers/pound < 2.0.5 >= 2.0.5

Description

Pound fails to handle HTTP requests with conflicting "Content-Length" and "Transfer-Encoding" headers correctly.

Impact

An attacker could exploit this vulnerability by sending HTTP requests with specially crafted "Content-Length" and "Transfer-Encoding" headers to bypass certain security restrictions or to poison the web proxy cache.

Workaround

There is no known workaround at this time.

Resolution

All Pound users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=www-servers/pound-2.0.5"

References

[ 1 ] CVE-2005-3751

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3751

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200606-05.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5


Gentoo Linux Security Advisory GLSA 200606-06

http://security.gentoo.org/


Severity: High
Title: AWStats: Remote execution of arbitrary code
Date: June 07, 2006
Bugs: #130487
ID: 200606-06


Synopsis

AWStats contains a bug in the sanitization of the input parameters which can lead to the remote execution of arbitrary code.

Background

AWStats is an advanced log file analyzer and statistics generator.

Affected packages


Package / Vulnerable / Unaffected
1 net-www/awstats < 6.5-r1 >= 6.5-r1

Description

Hendrik Weimer has found that if updating the statistics via the web frontend is enabled, it is possible to inject arbitrary code via a pipe character in the "migrate" parameter. Additionally, r0t has discovered that AWStats fails to properly sanitize user-supplied input in awstats.pl.

Impact

A remote attacker can execute arbitrary code on the server in the context of the application running the AWStats CGI script if updating of the statistics via web frontend is allowed. Nonetheless, all configurations are affected by a cross-site scripting vulnerability in awstats.pl, allowing a remote attacker to execute arbitrary scripts running in the context of the victim's browser.

Workaround

Disable statistics updates using the web frontend to avoid code injection. However, there is no known workaround at this time concerning the cross-site scripting vulnerability.

Resolution

All AWStats users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=net-www/awstats-6.5-r1"

References

[ 1 ] CVE-2006-1945

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1945

[ 2 ] CVE-2006-2237

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2237

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200606-06.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.

License

Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s).

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5

Mandriva Linux


Mandriva Linux Security Advisory MDKSA-2006:096
http://www.mandriva.com/security/


Package : openldap
Date : June 7, 2006
Affected: 10.2, 2006.0, Corporate 3.0


Problem Description:

A stack-based buffer overflow in st.c in slurpd for OpenLDAP might allow attackers to execute arbitrary code via a long hostname.

Packages have been patched to correct this issue.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2754


Updated Packages:

Mandriva Linux 10.2:
8a281bec432238a1f5b551ca9512bbe4 10.2/RPMS/libldap2.2_7-2.2.23-5.2.102mdk.i586.rpm
8da883025099c4a0a2d84e231537eb06 10.2/RPMS/libldap2.2_7-devel-2.2.23-5.2.102mdk.i586.rpm
e3d33c67cde6e42954855597bc8cbeb7 10.2/RPMS/libldap2.2_7-static-devel-2.2.23-5.2.102mdk.i586.rpm
39d447d7cfe1905f367866106e0a93c3 10.2/RPMS/openldap-2.2.23-5.2.102mdk.i586.rpm
7cf3ba7abc86585f2b20643a5534bc3e 10.2/RPMS/openldap-clients-2.2.23-5.2.102mdk.i586.rpm
0a392204252086e1f69e66a743651370 10.2/RPMS/openldap-doc-2.2.23-5.2.102mdk.i586.rpm
8e30d69b6f1d7a089f1f7888be736152 10.2/RPMS/openldap-migration-2.2.23-5.2.102mdk.i586.rpm
5721773fc4cb14db7cbd86ec80fa2026 10.2/RPMS/openldap-servers-2.2.23-5.2.102mdk.i586.rpm
d8ef3d7bf845b64d066ef932f7cef9ad 10.2/SRPMS/openldap-2.2.23-5.2.102mdk.src.rpm

Mandriva Linux 10.2/X86_64:
98a53d8c9a96b099e2870e5bcdbe70cc x86_64/10.2/RPMS/lib64ldap2.2_7-2.2.23-5.2.102mdk.x86_64.rpm
8c0b72d44fc6286ef03740166a5fed0c x86_64/10.2/RPMS/lib64ldap2.2_7-devel-2.2.23-5.2.102mdk.x86_64.rpm
a4e8ab2d4bdc1f9bc150197d1d28eba3 x86_64/10.2/RPMS/lib64ldap2.2_7-static-devel-2.2.23-5.2.102mdk.x86_64.rpm
8a281bec432238a1f5b551ca9512bbe4 x86_64/10.2/RPMS/libldap2.2_7-2.2.23-5.2.102mdk.i586.rpm
8da883025099c4a0a2d84e231537eb06 x86_64/10.2/RPMS/libldap2.2_7-devel-2.2.23-5.2.102mdk.i586.rpm
e3d33c67cde6e42954855597bc8cbeb7 x86_64/10.2/RPMS/libldap2.2_7-static-devel-2.2.23-5.2.102mdk.i586.rpm
09c1d4441880e7614efd28e0ce068721 x86_64/10.2/RPMS/openldap-2.2.23-5.2.102mdk.x86_64.rpm
9705881b0d0f255782a3611de6ffb760 x86_64/10.2/RPMS/openldap-clients-2.2.23-5.2.102mdk.x86_64.rpm
1583f53a26007650c8678fa6814f03ae x86_64/10.2/RPMS/openldap-doc-2.2.23-5.2.102mdk.x86_64.rpm
7184f0b73575647b498f0590cd089493 x86_64/10.2/RPMS/openldap-migration-2.2.23-5.2.102mdk.x86_64.rpm
c1025ea947b00cdebcd419fc817597ae x86_64/10.2/RPMS/openldap-servers-2.2.23-5.2.102mdk.x86_64.rpm
d8ef3d7bf845b64d066ef932f7cef9ad x86_64/10.2/SRPMS/openldap-2.2.23-5.2.102mdk.src.rpm

Mandriva Linux 2006.0:
ea8791b7c1d68b6d909b2400fb33319f 2006.0/RPMS/libldap2.3_0-2.3.6-4.1.20060mdk.i586.rpm
703493c59b9f4d461e61ef728124005f 2006.0/RPMS/libldap2.3_0-devel-2.3.6-4.1.20060mdk.i586.rpm
9efdee4dc7c3648022d7db3ff032273e 2006.0/RPMS/libldap2.3_0-static-devel-2.3.6-4.1.20060mdk.i586.rpm
e1bea8e181354cb9491412df980a55b5 2006.0/RPMS/openldap-2.3.6-4.1.20060mdk.i586.rpm
affa5cab856fe9a9c402136b8246cf53 2006.0/RPMS/openldap-clients-2.3.6-4.1.20060mdk.i586.rpm
5daac277569ffbac8995288ff0aeaced 2006.0/RPMS/openldap-doc-2.3.6-4.1.20060mdk.i586.rpm
a7ecd79a95ff817a349b032796332300 2006.0/RPMS/openldap-servers-2.3.6-4.1.20060mdk.i586.rpm
56f8cf3e40ab9ded4965b9e2ca528de3 2006.0/SRPMS/openldap-2.3.6-4.1.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
9808e28b5610e1eddd845db8ccee1f20 x86_64/2006.0/RPMS/lib64ldap2.3_0-2.3.6-4.1.20060mdk.x86_64.rpm
baf930097e1da0a4de75bfaef046025b x86_64/2006.0/RPMS/lib64ldap2.3_0-devel-2.3.6-4.1.20060mdk.x86_64.rpm
790382e365cd57aaea323be85419e512 x86_64/2006.0/RPMS/lib64ldap2.3_0-static-devel-2.3.6-4.1.20060mdk.x86_64.rpm
ea8791b7c1d68b6d909b2400fb33319f x86_64/2006.0/RPMS/libldap2.3_0-2.3.6-4.1.20060mdk.i586.rpm
703493c59b9f4d461e61ef728124005f x86_64/2006.0/RPMS/libldap2.3_0-devel-2.3.6-4.1.20060mdk.i586.rpm
9efdee4dc7c3648022d7db3ff032273e x86_64/2006.0/RPMS/libldap2.3_0-static-devel-2.3.6-4.1.20060mdk.i586.rpm
1bc7a0a1c76fda9e647061ae541c39a0 x86_64/2006.0/RPMS/openldap-2.3.6-4.1.20060mdk.x86_64.rpm
71770a09aeaf8d37b7e0c37ee5e84182 x86_64/2006.0/RPMS/openldap-clients-2.3.6-4.1.20060mdk.x86_64.rpm
40c969879aa467374342f0f8d597f564 x86_64/2006.0/RPMS/openldap-doc-2.3.6-4.1.20060mdk.x86_64.rpm
30ec0d98e7dd4a6289cb972517254ffd x86_64/2006.0/RPMS/openldap-servers-2.3.6-4.1.20060mdk.x86_64.rpm
56f8cf3e40ab9ded4965b9e2ca528de3 x86_64/2006.0/SRPMS/openldap-2.3.6-4.1.20060mdk.src.rpm

Corporate 3.0:
9f5b3d6bc1939e9cddc067b52a5c6905 corporate/3.0/RPMS/libldap2-2.1.25-7.2.C30mdk.i586.rpm
b145cedba5b300c27153caa7b35c7e33 corporate/3.0/RPMS/libldap2-devel-2.1.25-7.2.C30mdk.i586.rpm
37a25f61f47bbbde4d228784bde24813 corporate/3.0/RPMS/libldap2-devel-static-2.1.25-7.2.C30mdk.i586.rpm
290216ecd86c48f1d433572e9c854484 corporate/3.0/RPMS/openldap-2.1.25-7.2.C30mdk.i586.rpm
abdd42a6c4dc54290e03b51f57adf875 corporate/3.0/RPMS/openldap-back_dnssrv-2.1.25-7.2.C30mdk.i586.rpm
701c6b5f6462c96a8aaff141637fa242 corporate/3.0/RPMS/openldap-back_ldap-2.1.25-7.2.C30mdk.i586.rpm
0ca611e9d5a3eee7e999fc9947e09864 corporate/3.0/RPMS/openldap-back_passwd-2.1.25-7.2.C30mdk.i586.rpm
19adeb4cac1e48d9549458fe7313ff7c corporate/3.0/RPMS/openldap-back_sql-2.1.25-7.2.C30mdk.i586.rpm
41a1f32492dbc4c122e95a4dd84a0feb corporate/3.0/RPMS/openldap-clients-2.1.25-7.2.C30mdk.i586.rpm
9b9c504105bc677244d1090f8c5bb5b2 corporate/3.0/RPMS/openldap-doc-2.1.25-7.2.C30mdk.i586.rpm
f2902676cc7a397207281c829c27e6d1 corporate/3.0/RPMS/openldap-migration-2.1.25-7.2.C30mdk.i586.rpm
731c1b97a63a45ba756772760c59c6c0 corporate/3.0/RPMS/openldap-servers-2.1.25-7.2.C30mdk.i586.rpm
70f8323a5b1ee7cace35153eb8a4a977 corporate/3.0/SRPMS/openldap-2.1.25-7.2.C30mdk.src.rpm

Corporate 3.0/X86_64:
ea6b0511387ed89a04dcf814ba5d4174 x86_64/corporate/3.0/RPMS/lib64ldap2-2.1.25-7.2.C30mdk.x86_64.rpm
d5b1e13a6947c55a0e4fcce2e91b23f7 x86_64/corporate/3.0/RPMS/lib64ldap2-devel-2.1.25-7.2.C30mdk.x86_64.rpm
b4f1b6d44fd41861a75aa92aaafef04e x86_64/corporate/3.0/RPMS/lib64ldap2-devel-static-2.1.25-7.2.C30mdk.x86_64.rpm
08dfbb1f3eac003c4635031295cc791f x86_64/corporate/3.0/RPMS/openldap-2.1.25-7.2.C30mdk.x86_64.rpm
ca206f54b9573076cee3a7eaabadd418 x86_64/corporate/3.0/RPMS/openldap-back_dnssrv-2.1.25-7.2.C30mdk.x86_64.rpm
aa7ee91e2f51298c19b1d13c643c1a3c x86_64/corporate/3.0/RPMS/openldap-back_ldap-2.1.25-7.2.C30mdk.x86_64.rpm
76388eb3fb21ad49c5f60deb309f8055 x86_64/corporate/3.0/RPMS/openldap-back_passwd-2.1.25-7.2.C30mdk.x86_64.rpm
44d4127e8a071b4a4384e5e5d00abdb6 x86_64/corporate/3.0/RPMS/openldap-back_sql-2.1.25-7.2.C30mdk.x86_64.rpm
afc55cc7cc9b5b1d2d0d78328c71cef6 x86_64/corporate/3.0/RPMS/openldap-clients-2.1.25-7.2.C30mdk.x86_64.rpm
58397772050830e56cada4a725923422 x86_64/corporate/3.0/RPMS/openldap-doc-2.1.25-7.2.C30mdk.x86_64.rpm
a63018c5425a741cd9161efff32f1e06 x86_64/corporate/3.0/RPMS/openldap-migration-2.1.25-7.2.C30mdk.x86_64.rpm
138f61cb6117553b8766ef1a806f07bc x86_64/corporate/3.0/RPMS/openldap-servers-2.1.25-7.2.C30mdk.x86_64.rpm
70f8323a5b1ee7cace35153eb8a4a977 x86_64/corporate/3.0/SRPMS/openldap-2.1.25-7.2.C30mdk.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>


Mandriva Linux Security Advisory MDKSA-2006:097
http://www.mandriva.com/security/


Package : MySQL
Date : June 7, 2006
Affected: 10.2, 2006.0


Problem Description:

SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.

MySQL 4.0.18 in Corporate 3.0 and MNF 2.0 is not affected by this issue.

Packages have been patched to correct this issue.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2753


Updated Packages:

Mandriva Linux 10.2:
5124c38a0018835bae02c529e839c2ec 10.2/RPMS/libmysql14-4.1.11-1.5.102mdk.i586.rpm
461aafb5d81f3cc1aae5ca0c3a57ff7b 10.2/RPMS/libmysql14-devel-4.1.11-1.5.102mdk.i586.rpm
5b975a40589e1c9b21570aacfe71cfc2 10.2/RPMS/MySQL-4.1.11-1.5.102mdk.i586.rpm
ee11c783d49a43d560a9013961f13b8a 10.2/RPMS/MySQL-bench-4.1.11-1.5.102mdk.i586.rpm
cd42ca4423287a9d5a69d26e006e03cb 10.2/RPMS/MySQL-client-4.1.11-1.5.102mdk.i586.rpm
ddfe045b6d2c0d5d8280f3755428726c 10.2/RPMS/MySQL-common-4.1.11-1.5.102mdk.i586.rpm
4d00eea0471f81a11b7437168bd1d91c 10.2/RPMS/MySQL-Max-4.1.11-1.5.102mdk.i586.rpm
470cf8560a7020d0ee05a875be139389 10.2/RPMS/MySQL-NDB-4.1.11-1.5.102mdk.i586.rpm
7e0571514e7a3761bb68a009658a5c12 10.2/SRPMS/MySQL-4.1.11-1.5.102mdk.src.rpm

Mandriva Linux 10.2/X86_64:
cd0e5aba35ad68dbbc880a0405af94d3 x86_64/10.2/RPMS/lib64mysql14-4.1.11-1.5.102mdk.x86_64.rpm
2acaaa74a097b9b2a935d9f08a0bda67 x86_64/10.2/RPMS/lib64mysql14-devel-4.1.11-1.5.102mdk.x86_64.rpm
989dd5ebcf132fed17e912d6f6c61d26 x86_64/10.2/RPMS/MySQL-4.1.11-1.5.102mdk.x86_64.rpm
f165db3cb9ea3d1decc102faf1fd49ca x86_64/10.2/RPMS/MySQL-bench-4.1.11-1.5.102mdk.x86_64.rpm
3babf05f2d130008711af23f1636b3f5 x86_64/10.2/RPMS/MySQL-client-4.1.11-1.5.102mdk.x86_64.rpm
b0814e05d8cff5b37a24a7f2d045d256 x86_64/10.2/RPMS/MySQL-common-4.1.11-1.5.102mdk.x86_64.rpm
bd6c36a4ee7e606e46feda8197a46dd1 x86_64/10.2/RPMS/MySQL-Max-4.1.11-1.5.102mdk.x86_64.rpm
92e4a5a9533b51eb4307921618e40911 x86_64/10.2/RPMS/MySQL-NDB-4.1.11-1.5.102mdk.x86_64.rpm
7e0571514e7a3761bb68a009658a5c12 x86_64/10.2/SRPMS/MySQL-4.1.11-1.5.102mdk.src.rpm

Mandriva Linux 2006.0:
cdfcbf1bff46a87975838a6acef3347b 2006.0/RPMS/libmysql14-4.1.12-3.3.20060mdk.i586.rpm
46eb7b15b586747f230d343e04669254 2006.0/RPMS/libmysql14-devel-4.1.12-3.3.20060mdk.i586.rpm
216c29b19afe9d9a460158ab44078f1b 2006.0/RPMS/MySQL-4.1.12-3.3.20060mdk.i586.rpm
9c1c3ce9ba1780699628d544675b513d 2006.0/RPMS/MySQL-bench-4.1.12-3.3.20060mdk.i586.rpm
11a768efef34c19b0a357dc63bf86297 2006.0/RPMS/MySQL-client-4.1.12-3.3.20060mdk.i586.rpm
2c9c2d9114844e635924c57deb13ab03 2006.0/RPMS/MySQL-common-4.1.12-3.3.20060mdk.i586.rpm
93e4be31a33683d450a1e66b667a191d 2006.0/RPMS/MySQL-Max-4.1.12-3.3.20060mdk.i586.rpm
75b641bc8e77844cb0c963b22cd3b8dd 2006.0/RPMS/MySQL-NDB-4.1.12-3.3.20060mdk.i586.rpm
0833ddf397921824b5e107c80c2b3719 2006.0/SRPMS/MySQL-4.1.12-3.3.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
e91a5d0a6640f2b2cfabe2f58e943783 x86_64/2006.0/RPMS/lib64mysql14-4.1.12-3.3.20060mdk.x86_64.rpm
65ce59f185b2cd97bfba0f81375ce31d x86_64/2006.0/RPMS/lib64mysql14-devel-4.1.12-3.3.20060mdk.x86_64.rpm
f9e7ebfd3caf11ad3c6b96687bec3bb3 x86_64/2006.0/RPMS/MySQL-4.1.12-3.3.20060mdk.x86_64.rpm
b804caa1877bb5e73139ca3125ba7e29 x86_64/2006.0/RPMS/MySQL-bench-4.1.12-3.3.20060mdk.x86_64.rpm
28465c5560636598d9d8dcad66f748dd x86_64/2006.0/RPMS/MySQL-client-4.1.12-3.3.20060mdk.x86_64.rpm
6ba9e3655de80fee76c3fb5654e633b7 x86_64/2006.0/RPMS/MySQL-common-4.1.12-3.3.20060mdk.x86_64.rpm
0225b166b7262e315fc1751e336bef8b x86_64/2006.0/RPMS/MySQL-Max-4.1.12-3.3.20060mdk.x86_64.rpm
b9d64e331f0e5e7b721db66ad69b7033 x86_64/2006.0/RPMS/MySQL-NDB-4.1.12-3.3.20060mdk.x86_64.rpm
0833ddf397921824b5e107c80c2b3719 x86_64/2006.0/SRPMS/MySQL-4.1.12-3.3.20060mdk.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>


Mandriva Linux Security Advisory MDKSA-2006:098
http://www.mandriva.com/security/


Package : postgresql
Date : June 7, 2006
Affected: 10.2, 2006.0, Corporate 3.0


Problem Description:

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications via invalid encodings of multibyte characters, aka one variant of "Encoding-Based SQL Injection." (CVE-2006-2313)

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem. (CVE-2006-2314)

Packages have been patched or updated to correct these issues.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2313
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2314


Updated Packages:

Mandriva Linux 10.2:
7d7748c7f83651e1a31e111d7da0ffc4 10.2/RPMS/libecpg5-8.0.8-0.1.102mdk.i586.rpm
4a0e6f957da380bdd548785a069df2fa 10.2/RPMS/libecpg5-devel-8.0.8-0.1.102mdk.i586.rpm
7b15c9cf319e0eb6c5160bd6ae2f094c 10.2/RPMS/libpq4-8.0.8-0.1.102mdk.i586.rpm
b4bc2a4cc570f460b583bedac744655e 10.2/RPMS/libpq4-devel-8.0.8-0.1.102mdk.i586.rpm
46f522cbf070062413a59783d185551e 10.2/RPMS/postgresql-8.0.8-0.1.102mdk.i586.rpm
cf6d3b66f83c08f9285f05929e44eac0 10.2/RPMS/postgresql-contrib-8.0.8-0.1.102mdk.i586.rpm
a213ae15b71714cc7471a475dff69dec 10.2/RPMS/postgresql-devel-8.0.8-0.1.102mdk.i586.rpm
a778d339105a4a51d9457cf80758d539 10.2/RPMS/postgresql-docs-8.0.8-0.1.102mdk.i586.rpm
c57042c163736aa50ca3f94acdb812b6 10.2/RPMS/postgresql-jdbc-8.0.8-0.1.102mdk.i586.rpm
0a3d055bff42d982a28c33c9785c7534 10.2/RPMS/postgresql-pl-8.0.8-0.1.102mdk.i586.rpm
c4ce05d84d96ea30f520e03052c2b9af 10.2/RPMS/postgresql-plperl-8.0.8-0.1.102mdk.i586.rpm
3fa919d2a099eb4df0b05150b7d9187c 10.2/RPMS/postgresql-plpgsql-8.0.8-0.1.102mdk.i586.rpm
557a6ecae7b745bb96117209b00f548c 10.2/RPMS/postgresql-plpython-8.0.8-0.1.102mdk.i586.rpm
dba76cc2c9e39a58924a1311ae0d2642 10.2/RPMS/postgresql-pltcl-8.0.8-0.1.102mdk.i586.rpm
7087b905bbc1c217dbb3442a6c028f0b 10.2/RPMS/postgresql-server-8.0.8-0.1.102mdk.i586.rpm
ff16fa0a010db99ce67994bc94b5536a 10.2/RPMS/postgresql-test-8.0.8-0.1.102mdk.i586.rpm
0806b379df8b7c9b955f0bd519cf213f 10.2/SRPMS/postgresql-8.0.8-0.1.102mdk.src.rpm

Mandriva Linux 10.2/X86_64:
5c49f14f6581d8be74619a342c3e2526 x86_64/10.2/RPMS/lib64ecpg5-8.0.8-0.1.102mdk.x86_64.rpm
913b509d69a4814d039d662f70af1a9f x86_64/10.2/RPMS/lib64ecpg5-devel-8.0.8-0.1.102mdk.x86_64.rpm
68939e3bea560c1152144adb9ec53c05 x86_64/10.2/RPMS/lib64pq4-8.0.8-0.1.102mdk.x86_64.rpm
5c5058a573ff735fbf55f66b36070525 x86_64/10.2/RPMS/lib64pq4-devel-8.0.8-0.1.102mdk.x86_64.rpm
870d11274b7e44c0a640254c66186e7d x86_64/10.2/RPMS/postgresql-8.0.8-0.1.102mdk.x86_64.rpm
c0b236b3758bc047c7cb89a1bf2e19cf x86_64/10.2/RPMS/postgresql-contrib-8.0.8-0.1.102mdk.x86_64.rpm
de72f56defe74e0e636b9f9f9a542dda x86_64/10.2/RPMS/postgresql-devel-8.0.8-0.1.102mdk.x86_64.rpm
2335bcdcae87d9210594d1c7e52b5719 x86_64/10.2/RPMS/postgresql-docs-8.0.8-0.1.102mdk.x86_64.rpm
d6db4aa274296935a3c52ac4250e097e x86_64/10.2/RPMS/postgresql-jdbc-8.0.8-0.1.102mdk.x86_64.rpm
7309113d835e1facf24f07600ea4e0bb x86_64/10.2/RPMS/postgresql-pl-8.0.8-0.1.102mdk.x86_64.rpm
b6c476b046c1a3c83252210f62b6fa7a x86_64/10.2/RPMS/postgresql-plperl-8.0.8-0.1.102mdk.x86_64.rpm
c79be6051bd388783c067c69cf9784e3 x86_64/10.2/RPMS/postgresql-plpgsql-8.0.8-0.1.102mdk.x86_64.rpm
33e9e0047ff25fe0b1d866bb1d2b9043 x86_64/10.2/RPMS/postgresql-plpython-8.0.8-0.1.102mdk.x86_64.rpm
13a7c2a73beea45caba038572fb77508 x86_64/10.2/RPMS/postgresql-pltcl-8.0.8-0.1.102mdk.x86_64.rpm
54f0c1c62319716d3d6d372162656c0e x86_64/10.2/RPMS/postgresql-server-8.0.8-0.1.102mdk.x86_64.rpm
8ed0ce1d8932b1d1b5e47300cf436ae5 x86_64/10.2/RPMS/postgresql-test-8.0.8-0.1.102mdk.x86_64.rpm
0806b379df8b7c9b955f0bd519cf213f x86_64/10.2/SRPMS/postgresql-8.0.8-0.1.102mdk.src.rpm

Mandriva Linux 2006.0:
2b9e406b4646a1ae6657b1bd0fafe0a3 2006.0/RPMS/libecpg5-8.0.8-0.1.20060mdk.i586.rpm
243ddb16f72e02221c2188b0d5b09594 2006.0/RPMS/libecpg5-devel-8.0.8-0.1.20060mdk.i586.rpm
10a9c8bce7c1361d2a9e1e213e628e2a 2006.0/RPMS/libpq4-8.0.8-0.1.20060mdk.i586.rpm
0ba3382f18b64288b1314fdf337c05ee 2006.0/RPMS/libpq4-devel-8.0.8-0.1.20060mdk.i586.rpm
13c88ef9b006a32ce6cccb5e6a20edcf 2006.0/RPMS/postgresql-8.0.8-0.1.20060mdk.i586.rpm
04c1e95d8a38ef41ab44d6fd1925cca3 2006.0/RPMS/postgresql-contrib-8.0.8-0.1.20060mdk.i586.rpm
e9af4ed2860766dea84f09e97f3238da 2006.0/RPMS/postgresql-devel-8.0.8-0.1.20060mdk.i586.rpm
adfdd91733e3aa04d86d25a40a101381 2006.0/RPMS/postgresql-docs-8.0.8-0.1.20060mdk.i586.rpm
b49599532eee6d806f644ca833e01217 2006.0/RPMS/postgresql-jdbc-8.0.8-0.1.20060mdk.i586.rpm
5ec0d9ce965a5cdad6456d628977c39b 2006.0/RPMS/postgresql-pl-8.0.8-0.1.20060mdk.i586.rpm
978c15526ba8a61fef212796ddc61463 2006.0/RPMS/postgresql-plperl-8.0.8-0.1.20060mdk.i586.rpm
91830da3acb37b022c4fbdb5836bf632 2006.0/RPMS/postgresql-plpgsql-8.0.8-0.1.20060mdk.i586.rpm
cc0f900c787437928f380e645d17d37c 2006.0/RPMS/postgresql-plpython-8.0.8-0.1.20060mdk.i586.rpm
3708cb949b4c8603960ed44c9b513df5 2006.0/RPMS/postgresql-pltcl-8.0.8-0.1.20060mdk.i586.rpm
696143a0a2883c8ced5437f21c5dbdf2 2006.0/RPMS/postgresql-server-8.0.8-0.1.20060mdk.i586.rpm
16d7bdc245d2ce5b1811222bf1c6e360 2006.0/RPMS/postgresql-test-8.0.8-0.1.20060mdk.i586.rpm
903a96aaa883cb62f0be8c0ba26d6b0c 2006.0/SRPMS/postgresql-8.0.8-0.1.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
3c6c8898c78e75eba130fa873f938535 x86_64/2006.0/RPMS/lib64ecpg5-8.0.8-0.1.20060mdk.x86_64.rpm
3e670208f7426f7269a861840e3f442b x86_64/2006.0/RPMS/lib64ecpg5-devel-8.0.8-0.1.20060mdk.x86_64.rpm
4b773b4fcc75c32827e0f0e0ecb77250 x86_64/2006.0/RPMS/lib64pq4-8.0.8-0.1.20060mdk.x86_64.rpm
ad28bfc29df3a742724ef29b0d1ba0fd x86_64/2006.0/RPMS/lib64pq4-devel-8.0.8-0.1.20060mdk.x86_64.rpm
538aa8c9317953b6484fd6a190f6d89c x86_64/2006.0/RPMS/postgresql-8.0.8-0.1.20060mdk.x86_64.rpm
c75a24e068fd9405ef942d9c081dcb4f x86_64/2006.0/RPMS/postgresql-contrib-8.0.8-0.1.20060mdk.x86_64.rpm
f7247dc49eb9693eaadb24aa317fd20d x86_64/2006.0/RPMS/postgresql-devel-8.0.8-0.1.20060mdk.x86_64.rpm
442188ad9654ce43eed5f4475bfcb38c x86_64/2006.0/RPMS/postgresql-docs-8.0.8-0.1.20060mdk.x86_64.rpm
936340667b8c25af2a3991361e53b83e x86_64/2006.0/RPMS/postgresql-jdbc-8.0.8-0.1.20060mdk.x86_64.rpm
e9d824016ecb58efffe335c6d26d7f18 x86_64/2006.0/RPMS/postgresql-pl-8.0.8-0.1.20060mdk.x86_64.rpm
ddb424def79f631061365d3cbe85ef09 x86_64/2006.0/RPMS/postgresql-plperl-8.0.8-0.1.20060mdk.x86_64.rpm
0b6426978856e248528b791652fe880c x86_64/2006.0/RPMS/postgresql-plpgsql-8.0.8-0.1.20060mdk.x86_64.rpm
99ef20d223d5ba314ff90eac22fa4d33 x86_64/2006.0/RPMS/postgresql-plpython-8.0.8-0.1.20060mdk.x86_64.rpm
fbce3702380d2ff8eb89e47e792142b0 x86_64/2006.0/RPMS/postgresql-pltcl-8.0.8-0.1.20060mdk.x86_64.rpm
9bceb314082b2800a710157cce5b80f9 x86_64/2006.0/RPMS/postgresql-server-8.0.8-0.1.20060mdk.x86_64.rpm
540a0e2cb80e4aada968f09633dbbcfc x86_64/2006.0/RPMS/postgresql-test-8.0.8-0.1.20060mdk.x86_64.rpm
903a96aaa883cb62f0be8c0ba26d6b0c x86_64/2006.0/SRPMS/postgresql-8.0.8-0.1.20060mdk.src.rpm

Corporate 3.0:
cd86a91e81c16b73b56e22795cc75ac1 corporate/3.0/RPMS/libecpg3-7.4.1-2.6.C30mdk.i586.rpm
81032809705e397ff92a36473cac3d46 corporate/3.0/RPMS/libecpg3-devel-7.4.1-2.6.C30mdk.i586.rpm
8ed7ddb1e22609f94619fb5ebf8f7a58 corporate/3.0/RPMS/libpgtcl2-7.4.1-2.6.C30mdk.i586.rpm
e1a85f2ebb03443f752e2ddd1c0b778d corporate/3.0/RPMS/libpgtcl2-devel-7.4.1-2.6.C30mdk.i586.rpm
b0ef1692772d939198d84cccdcfc30da corporate/3.0/RPMS/libpq3-7.4.1-2.6.C30mdk.i586.rpm
f076ba31f6a477b8be7a74f793293770 corporate/3.0/RPMS/libpq3-devel-7.4.1-2.6.C30mdk.i586.rpm
be6f85d3fd05ee59f482b90c00e79225 corporate/3.0/RPMS/postgresql-7.4.1-2.6.C30mdk.i586.rpm
f4f9b314a43f04c93ba6a456c46eec3f corporate/3.0/RPMS/postgresql-contrib-7.4.1-2.6.C30mdk.i586.rpm
cb0baf3e3b998127640e7c3573eda77b corporate/3.0/RPMS/postgresql-devel-7.4.1-2.6.C30mdk.i586.rpm
16fe11d7990e297e56ffb2f8e34eb3ff corporate/3.0/RPMS/postgresql-docs-7.4.1-2.6.C30mdk.i586.rpm
f6acadb8c1d3c3e78bb5a7d7e233b73b corporate/3.0/RPMS/postgresql-jdbc-7.4.1-2.6.C30mdk.i586.rpm
cd1088e858b39ac9c86865048e6e91dc corporate/3.0/RPMS/postgresql-pl-7.4.1-2.6.C30mdk.i586.rpm
2a2f6db2c65c6ec72a00cf22c77d25ed corporate/3.0/RPMS/postgresql-server-7.4.1-2.6.C30mdk.i586.rpm
e6dbad550a75cbdaafb882646094b18e corporate/3.0/RPMS/postgresql-tcl-7.4.1-2.6.C30mdk.i586.rpm
1d9bfb14ee7e32157364c02fdb5d39c8 corporate/3.0/RPMS/postgresql-test-7.4.1-2.6.C30mdk.i586.rpm
9e2f9744dbdd29fb5005585f8f0b9c08 corporate/3.0/SRPMS/postgresql-7.4.1-2.6.C30mdk.src.rpm

Corporate 3.0/X86_64:
d8ed626768c69eb97004d42d47322a4a x86_64/corporate/3.0/RPMS/lib64ecpg3-7.4.1-2.6.C30mdk.x86_64.rpm
19639e5f855af780586871e60365b8f1 x86_64/corporate/3.0/RPMS/lib64ecpg3-devel-7.4.1-2.6.C30mdk.x86_64.rpm
79163d1d52df819b3807445a28a4748f x86_64/corporate/3.0/RPMS/lib64pgtcl2-7.4.1-2.6.C30mdk.x86_64.rpm
b4356183d45cdb448e7e8c2195a419e6 x86_64/corporate/3.0/RPMS/lib64pgtcl2-devel-7.4.1-2.6.C30mdk.x86_64.rpm
04732f900babe887c77606063dfe78a0 x86_64/corporate/3.0/RPMS/lib64pq3-7.4.1-2.6.C30mdk.x86_64.rpm
a86004f195f5bd3d910b80bd2194b503 x86_64/corporate/3.0/RPMS/lib64pq3-devel-7.4.1-2.6.C30mdk.x86_64.rpm
da154afe1362c980ede81914ccf412be x86_64/corporate/3.0/RPMS/postgresql-7.4.1-2.6.C30mdk.x86_64.rpm
0517399d099bd7aa39c0000b5b7eaa73 x86_64/corporate/3.0/RPMS/postgresql-contrib-7.4.1-2.6.C30mdk.x86_64.rpm
094cd54dd316f12b0dc45710f5ec4e22 x86_64/corporate/3.0/RPMS/postgresql-devel-7.4.1-2.6.C30mdk.x86_64.rpm
98f90c8828ae548035cab3dc1a633aa6 x86_64/corporate/3.0/RPMS/postgresql-docs-7.4.1-2.6.C30mdk.x86_64.rpm
2434237858aec19e8e65a4c7b429df9c x86_64/corporate/3.0/RPMS/postgresql-jdbc-7.4.1-2.6.C30mdk.x86_64.rpm
4414a59d5929668161aa932ea6e74787 x86_64/corporate/3.0/RPMS/postgresql-pl-7.4.1-2.6.C30mdk.x86_64.rpm
202b10907a8c365fb9408ab31ec4b7f4 x86_64/corporate/3.0/RPMS/postgresql-server-7.4.1-2.6.C30mdk.x86_64.rpm
ef3f8cb2101ce12ef4a9d39dba3ef69d x86_64/corporate/3.0/RPMS/postgresql-tcl-7.4.1-2.6.C30mdk.x86_64.rpm
5f38e8842f16de0a78d297542f36381f x86_64/corporate/3.0/RPMS/postgresql-test-7.4.1-2.6.C30mdk.x86_64.rpm
9e2f9744dbdd29fb5005585f8f0b9c08 x86_64/corporate/3.0/SRPMS/postgresql-7.4.1-2.6.C30mdk.src.rpm


To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com>

Ubuntu Linux


Ubuntu Security Notice USN-291-1 June 08, 2006
freetype vulnerabilities
CVE-2006-0747, CVE-2006-1861, CVE-2006-2493, CVE-2006-2661

A security issue affects the following Ubuntu releases:

Ubuntu 5.04
Ubuntu 5.10
Ubuntu 6.06 LTS

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

Ubuntu 5.04:
libfreetype6 2.1.7-2.3ubuntu0.1

Ubuntu 5.10:
libfreetype6 2.1.7-2.4ubuntu1.1

Ubuntu 6.06 LTS:
libfreetype6 2.1.10-1ubuntu2.1

After a standard system upgrade you need to reboot your computer to effect the necessary changes.

Details follow:

Several integer overflows have been discovered in the FreeType library. By tricking a user into installing and/or opening a specially crafted font file, these could be exploited to execute arbitrary code with the privileges of that user.

Updated packages for Ubuntu 5.04:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/freetype_2.1.7-2.3ubuntu0.1.diff.gz
      Size/MD5: 55085 0be8f928fd34db525db66f8cd07f79e2
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/freetype_2.1.7-2.3ubuntu0.1.dsc
      Size/MD5: 695 55710d777fdc8cee093e4eb17d03b8e4
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/freetype_2.1.7.orig.tar.gz
      Size/MD5: 1245623 991ff86e88b075ba363e876f4ea58680

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-demos_2.1.7-2.3ubuntu0.1_amd64.deb
      Size/MD5: 76248 654defa84e451a720843e160d9e0ad4b
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-dev_2.1.7-2.3ubuntu0.1_amd64.deb
      Size/MD5: 723698 ac752c537fcd86b0e15366f75237c8c4
    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype6-udeb_2.1.7-2.3ubuntu0.1_amd64.udeb
      Size/MD5: 238246 7bcc9b311d84ac923693484563415fc0
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2.1.7-2.3ubuntu0.1_amd64.deb
      Size/MD5: 389494 0c1c61803010adc6ac4303e0ed34cab4

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-demos_2.1.7-2.3ubuntu0.1_i386.deb
      Size/MD5: 57070 96143b6b668cdf1301a1f0d8cb935f38
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-dev_2.1.7-2.3ubuntu0.1_i386.deb
      Size/MD5: 688162 c16278b396bc6a3932e6488f6a4302d6
    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype6-udeb_2.1.7-2.3ubuntu0.1_i386.udeb
      Size/MD5: 208092 ce4669a078ce4c5cd25e53e372fbc0f2
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2.1.7-2.3ubuntu0.1_i386.deb
      Size/MD5: 358818 1e05d62b7c8fd3ed25ce9590289038b7

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-demos_2.1.7-2.3ubuntu0.1_powerpc.deb
      Size/MD5: 81974 261cb107a20048a653b7363e5e763095
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-dev_2.1.7-2.3ubuntu0.1_powerpc.deb
      Size/MD5: 730026 45f7603197520093383be1bc4ef71768
    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype6-udeb_2.1.7-2.3ubuntu0.1_powerpc.udeb
      Size/MD5: 227736 82ba5fdb752f1e14a168356eb58040d4
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2.1.7-2.3ubuntu0.1_powerpc.deb
      Size/MD5: 378628 560ddb84ab50151db4950def5ca94f20

Updated packages for Ubuntu 5.10:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/freetype_2.1.7-2.4ubuntu1.1.diff.gz
      Size/MD5: 56497 c0d09dab367b91d60391bfbe1614a751
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/freetype_2.1.7-2.4ubuntu1.1.dsc
      Size/MD5: 695 baa464576ecff8f71180b69c43f3d3d7
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/freetype_2.1.7.orig.tar.gz
      Size/MD5: 1245623 991ff86e88b075ba363e876f4ea58680

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-demos_2.1.7-2.4ubuntu1.1_amd64.deb
      Size/MD5: 75536 763397ace4438b17c1d553e742164392
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-dev_2.1.7-2.4ubuntu1.1_amd64.deb
      Size/MD5: 722918 ab4ac77fc4c341c5b9e3e5d8b7cd03ad
    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype6-udeb_2.1.7-2.4ubuntu1.1_amd64.udeb
      Size/MD5: 241670 71a3a0944b74daf49d428096258481d4
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2.1.7-2.4ubuntu1.1_amd64.deb
      Size/MD5: 392814 ac0b9929a7839fe770b81d8934811f91

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-demos_2.1.7-2.4ubuntu1.1_i386.deb
      Size/MD5: 52860 a37576a3dbe5adfed3a05c4fbddb19b2
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-dev_2.1.7-2.4ubuntu1.1_i386.deb
      Size/MD5: 686328 4f072876bcec9df39915a566ac49e2a2
    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype6-udeb_2.1.7-2.4ubuntu1.1_i386.udeb
      Size/MD5: 209218 a9d8c9cab213fbe51a8eef52a4267ea8
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2.1.7-2.4ubuntu1.1_i386.deb
      Size/MD5: 361040 66daf7be5122e8369b7085911474324c

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-demos_2.1.7-2.4ubuntu1.1_powerpc.deb
      Size/MD5: 80650 225e45de7b0bef7738099c6ab540d837
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-dev_2.1.7-2.4ubuntu1.1_powerpc.deb
      Size/MD5: 729230 389b6d1fff87a233ac1069f2f6e8eeda
    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype6-udeb_2.1.7-2.4ubuntu1.1_powerpc.udeb
      Size/MD5: 230578 78766403e83e824b01f3766536aef1b6
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2.1.7-2.4ubuntu1.1_powerpc.deb
      Size/MD5: 382364 042a895f84a516016cf9bf7356c2b447

Updated packages for Ubuntu 6.06 LTS:

Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/freetype_2.1.10-1ubuntu2.1.diff.gz
      Size/MD5: 58558 79b6094aa1485cb4b51492a694ad2467
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/freetype_2.1.10-1ubuntu2.1.dsc
      Size/MD5: 712 6618f5ae25407290002cd630a1cb192c
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/freetype_2.1.10.orig.tar.gz
      Size/MD5: 1323617 adf145ce51196ad1b3054d5fb032efe6

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-demos_2.1.10-1ubuntu2.1_amd64.deb
      Size/MD5: 133860 b0e59ff50e7416e9a2c4fc8ba1788c9e
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-dev_2.1.10-1ubuntu2.1_amd64.deb
      Size/MD5: 717390 0fcd39ae070d8a8430a8cd543ce8b704
    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype6-udeb_2.1.10-1ubuntu2.1_amd64.udeb
      Size/MD5: 251578 1fb9bc4ea48ec0ae313ccd5c8168dcbc
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2.1.10-1ubuntu2.1_amd64.deb
      Size/MD5: 439670 fad383210a9aa49c63860ad8a1e289e7

i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-demos_2.1.10-1ubuntu2.1_i386.deb
      Size/MD5: 117362 a685d9019bb23650e2f283dd059ed095
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-dev_2.1.10-1ubuntu2.1_i386.deb
      Size/MD5: 677390 7e56e5fd91125b15d28f59f15bb38689
    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype6-udeb_2.1.10-1ubuntu2.1_i386.udeb
      Size/MD5: 227202 6655ab5bcef72341109e6a9ac070a945
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2.1.10-1ubuntu2.1_i386.deb
      Size/MD5: 415304 a3cd03083f522a103c4580cbfc335297

powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-demos_2.1.10-1ubuntu2.1_powerpc.deb
      Size/MD5: 134240 47d1ce7690132ebaf7e0f434a0f0b25a
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-dev_2.1.10-1ubuntu2.1_powerpc.deb
      Size/MD5: 708398 f76b4949a148fe47b55fe17de22ccc64
    http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype6-udeb_2.1.10-1ubuntu2.1_powerpc.udeb
      Size/MD5: 241400 7837a5d97bba618e35fcfc085e91e9ae
    http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2.1.10-1ubuntu2.1_powerpc.deb
      Size/MD5: 429784 93f21b206f517f81b6498fe791e5ef3a



No talkbacks posted.
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!






..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP


The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers