[Security Announce] [ MDKA-2007:137 ] - Updated nss_ldap packages correct bad SIGPIPE handling
Posted on: 01/01/2008 12:10 AM

The Mandriva Security Team published a new security update for Mandriva Linux. Here the announcement:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Advisory MDKA-2007:137
http://www.mandriva.com/security/
_______________________________________________________________________

Package : nss_ldap
Date : December 31, 2007
Affected: 2007.1
_______________________________________________________________________

Problem Description:

This update corrects an issue in nss_ldap when handling SIGPIPE,
which could manifest itself in many different ways in systems running
with nss_ldap installed and configured, such as a simple application
silent error to a complete abort.
_______________________________________________________________________

References:

http://qa.mandriva.com/show_bug.cgi?id(962
http://qa.mandriva.com/show_bug.cgi?id2597
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2007.1:
a104f0e1ba57fbe6bb5133849d6ce999 2007.1/i586/nss_ldap-257-1.1mdv2007.1.i586.rpm
b1a2c346fdc994ee8da2db42ad9f0649 2007.1/SRPMS/nss_ldap-257-1.1mdv2007.1.src.rpm

Mandriva Linux 2007.1/X86_64:
414ec94ea062fa5473fbde8379fb4e8d 2007.1/x86_64/nss_ldap-257-1.1mdv2007.1.x86_64.rpm
b1a2c346fdc994ee8da2db42ad9f0649 2007.1/SRPMS/nss_ldap-257-1.1mdv2007.1.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
lt;security*mandriva.comgt;
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (GNU/Linux)

iEYEARECAAYFAkd5PIAACgkQmqjQ0CJFipii3QCfRzOx7QvAo804GzLY0YW388R7
00kAoNL/T4AfYnPxFZ0MtgT7VE02nnJW
=xMD3
-----END PGP SIGNATURE-----



Printed from Linux Compatible (http://www.linuxcompatible.org/news/story/security_announce_mdka_2007137__updated_nss_ldap_packages_correct_bad_sigpipe_handling.html)