Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· CompatDB Updates 05/22/13
· Removing and Wiping Drivers Guide and more
· Windows Server 2012 Essentials SDK Installer 1.1
· Xbox One hardware and specs: 8-core CPU, 8GB RAM, 500GB hard drive and more
· Tim Cook: US-made Macs will be assembled in Texas
· Microsoft software satisfaction slumps
· Photos of Likely 802.11ac 'Gigabit Wi-Fi' Card From Next-Generation iMac Surface
· Mageia 3 released
· Understanding Email Bounce Messages and more
· How to Prepare for Windows 8 Even Though Its Not Coming to Enterprises

Upcoming News
· What You Need To Know about the Xbox One @ ThinkComputers.org
· PQI Air Drive External Wireless Storage Device Product and Video Review
· PoINT Storage Manager 4.0 now available
· [CentOS-announce] CEEA-2013:0852 CentOS 5 rgmanager Update
· i-Mego Throne Gold Over Ear Headphones Review @ TestFreaks
· Xbox One: Entertainment Hub First, Gaming Console Second -- But Could It Disrupt TV?
· Star Wars: The Old Republic Gaming Mouse Review @ Madshrimps
· Samsung SSD 840 comparison @ Hardwareoverclock.com
· Leawo Total Media Converter Ultimate @ Benchmark Reviews
· Icy Dock FlexCage MB975SP-B 5x3.5" in 3x5.25" HDD Cage Review @ Hi Tech Legion

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6426 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 682 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4542 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 752 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1136 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » May 2007 » RHSA-2007:0235-02 Low: util-linux security and bug fix update

RHSA-2007:0235-02 Low: util-linux security and bug fix update

Posted by Bob on: 05/01/2007 07:10 PM [ Print | 0 comment(s) ]

A new update is available for Red Hat Enterprise Linux. Here the announcement:




-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ---------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Low: util-linux security and bug fix update
Advisory ID: RHSA-2007:0235-02
Advisory URL: https://rhn.redhat.com/errata/RHSA-2007-0235.html
Issue date: 2007-05-01
Updated on: 2007-05-01
Product: Red Hat Enterprise Linux
Keywords: mount fdisk login
CVE Names: CVE-2006-7108
- ---------------------------------------------------------------------

1. Summary:

An updated util-linux package that corrects a security issue and fixes
several bugs is now available.

This update has been rated as having low security impact by the Red Hat
Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Problem description:

The util-linux package contains a collection of basic system utilities.

A flaw was found in the way the login process handled logins which did not
require authentication. Certain processes which conduct their own
authentication could allow a remote user to bypass intended access policies
which would normally be enforced by the login process. (CVE-2006-7108)

This update also fixes the following bugs:

* The partx, addpart and delpart commands were not documented.

* The "umount -l" command did not work on hung NFS mounts with cached data.

* The mount command did not mount NFS V3 share where sec=none was specified.

* The mount command did not read filesystem LABEL from unpartitioned disks.

* The mount command did not recognize labels on VFAT filesystems.

* The fdisk command did not support 4096 sector size for the "-b" option.

* The mount man page did not list option "mand" or information about
/etc/mtab limitations.

All users of util-linux should upgrade to these updated packages, which
contain backported patches to correct these issues.

4. Solution:

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

5. Bug IDs fixed (http://bugzilla.redhat.com/):

169299 - umount -l should work on hung NFS mounts with cached data
177331 - CVE-2006-7108 login omits pam_acct_mgmt pam_chauthtok when authentication is skipped.
187370 - Unable to mount NFS V3 share where sec=none is specified
188099 - can't mount iscsi ext3 fs by label.
197768 - man mount' does not list option 'mand'

6. RPMs required:

Red Hat Enterprise Linux AS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/util-linux-2.12a-16.EL4.25.src.rpm
b55ecbe0eac80ed7482e5e31265eb372 util-linux-2.12a-16.EL4.25.src.rpm

i386:
ff7c2ff0b317f3d23d8c86f07d101c55 util-linux-2.12a-16.EL4.25.i386.rpm
5d8435d17fd695098f82bab92b67894f util-linux-debuginfo-2.12a-16.EL4.25.i386.rpm

ia64:
111cedb53d72339a1eb57880a463f669 util-linux-2.12a-16.EL4.25.ia64.rpm
952ccc2d0f0255f9d534b45e3e4d5f56 util-linux-debuginfo-2.12a-16.EL4.25.ia64.rpm

ppc:
900880d8faadebd6216952c6eaa8ee31 util-linux-2.12a-16.EL4.25.ppc.rpm
46ed5fd2cb84f16380a5f538b2cc6d53 util-linux-debuginfo-2.12a-16.EL4.25.ppc.rpm

s390:
85ab4e837ed645340d8d31687c9c2543 util-linux-2.12a-16.EL4.25.s390.rpm
1f839d8cac1ce9eea1f33364f46ae04b util-linux-debuginfo-2.12a-16.EL4.25.s390.rpm

s390x:
051a5321c719ee77c56f218a4f360b7d util-linux-2.12a-16.EL4.25.s390x.rpm
735b7dda37760e12c3ec62eb2ff6f42e util-linux-debuginfo-2.12a-16.EL4.25.s390x.rpm

x86_64:
4566fc204cdc0b6420f71f87959b82e2 util-linux-2.12a-16.EL4.25.x86_64.rpm
4728ab213aa22b059794f61e8800c465 util-linux-debuginfo-2.12a-16.EL4.25.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/util-linux-2.12a-16.EL4.25.src.rpm
b55ecbe0eac80ed7482e5e31265eb372 util-linux-2.12a-16.EL4.25.src.rpm

i386:
ff7c2ff0b317f3d23d8c86f07d101c55 util-linux-2.12a-16.EL4.25.i386.rpm
5d8435d17fd695098f82bab92b67894f util-linux-debuginfo-2.12a-16.EL4.25.i386.rpm

x86_64:
4566fc204cdc0b6420f71f87959b82e2 util-linux-2.12a-16.EL4.25.x86_64.rpm
4728ab213aa22b059794f61e8800c465 util-linux-debuginfo-2.12a-16.EL4.25.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/util-linux-2.12a-16.EL4.25.src.rpm
b55ecbe0eac80ed7482e5e31265eb372 util-linux-2.12a-16.EL4.25.src.rpm

i386:
ff7c2ff0b317f3d23d8c86f07d101c55 util-linux-2.12a-16.EL4.25.i386.rpm
5d8435d17fd695098f82bab92b67894f util-linux-debuginfo-2.12a-16.EL4.25.i386.rpm

ia64:
111cedb53d72339a1eb57880a463f669 util-linux-2.12a-16.EL4.25.ia64.rpm
952ccc2d0f0255f9d534b45e3e4d5f56 util-linux-debuginfo-2.12a-16.EL4.25.ia64.rpm

x86_64:
4566fc204cdc0b6420f71f87959b82e2 util-linux-2.12a-16.EL4.25.x86_64.rpm
4728ab213aa22b059794f61e8800c465 util-linux-debuginfo-2.12a-16.EL4.25.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/util-linux-2.12a-16.EL4.25.src.rpm
b55ecbe0eac80ed7482e5e31265eb372 util-linux-2.12a-16.EL4.25.src.rpm

i386:
ff7c2ff0b317f3d23d8c86f07d101c55 util-linux-2.12a-16.EL4.25.i386.rpm
5d8435d17fd695098f82bab92b67894f util-linux-debuginfo-2.12a-16.EL4.25.i386.rpm

ia64:
111cedb53d72339a1eb57880a463f669 util-linux-2.12a-16.EL4.25.ia64.rpm
952ccc2d0f0255f9d534b45e3e4d5f56 util-linux-debuginfo-2.12a-16.EL4.25.ia64.rpm

x86_64:
4566fc204cdc0b6420f71f87959b82e2 util-linux-2.12a-16.EL4.25.x86_64.rpm
4728ab213aa22b059794f61e8800c465 util-linux-debuginfo-2.12a-16.EL4.25.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7108
http://www.redhat.com/security/updates/classification/#low

8. Contact:

The Red Hat security contact is lt;secalert@redhat.comgt;. More contact
details at https://www.redhat.com/security/team/contact/

Copyright 2007 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFGN34/XlSAg2UNWIIRAsRYAKCBZzphgxrf6JIz6YAktAR9h/YwyACgmRWH
NGsEmdj4N88WM8pv0rjV9Tw=
=Khfp
-----END PGP SIGNATURE-----


Bookmark and Share

« RHSA-2007:0244-02 Low: busybox security update · RHSA-2007:0229-02 Low: gdb security and bug fix update »

Linux Compatible » News » May 2007 » RHSA-2007:0235-02 Low: util-linux security and bug fix update
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition