Red Hat 9377 Published by Philipp Esselbach 0

A Mozilla Firefox security update has been released for Gentoo Linux

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200503-31
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Normal
Title: Mozilla Firefox: Multiple vulnerabilities
Date: March 25, 2005
Bugs: #86148
ID: 200503-31

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
=======

Mozilla Firefox 1.0.2 fixes new security vulnerabilities, including the remote execution of arbitrary code through malicious GIF images or sidebars.

Red Hat 9377 Published by Philipp Esselbach 0

A Mozilla Suite security update is available for Gentoo Linux

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200503-30
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Normal
Title: Mozilla Suite: Multiple vulnerabilities
Date: March 25, 2005
Bugs: #84074
ID: 200503-30

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
=======

The Mozilla Suite is vulnerable to multiple issues ranging from the remote execution of arbitrary code to various issues allowing to trick the user into trusting fake web sites or interacting with privileged content.

Red Hat 9377 Published by Philipp Esselbach 0

An updated spamassassin package has been released for Fedora Core 1

---------------------------------------------------------------------
Fedora Legacy Update Advisory

Synopsis: Updated spamassassin package fixes security issues
Advisory ID: FLSA:2268
Issue date: 2005-03-24
Product: Fedora Core
Keywords: Bugfix
Cross references: https://bugzilla.fedora.us/show_bug.cgi?id=2268
CVE Names: CAN-2004-0796
---------------------------------------------------------------------


---------------------------------------------------------------------
1. Topic:

An updated spamassassin package that fixes a denial of service bug when parsing malformed messages is now available.

SpamAssassin provides a way to reduce unsolicited commercial email (SPAM) from incoming email.

2. Relevant releases/architectures:

Fedora Core 1 - i386

Red Hat 9377 Published by Philipp Esselbach 0

Updated mysql packages are available for Red Hat Linux 7.3, 9, and Fedora Core 1

---------------------------------------------------------------------
Fedora Legacy Update Advisory

Synopsis: Updated mysql packages fix security issues
Advisory ID: FLSA:2129
Issue date: 2005-03-24
Product: Red Hat Linux, Fedora Core
Keywords: Bugfix
Cross references: https://bugzilla.fedora.us/show_bug.cgi?id=2129
CVE Names: CAN-2004-0381 CAN-2004-0388 CAN-2004-0457
CAN-2004-0835 CAN-2004-0836 CAN-2004-0837
CAN-2004-0957 CAN-2005-0004
---------------------------------------------------------------------


---------------------------------------------------------------------
1. Topic:

Updated mysql packages that fix various security issues are now available.

MySQL is a multi-user, multi-threaded SQL database server.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - i386
Red Hat Linux 9 - i386
Fedora Core 1 - i386

Red Hat 9377 Published by Philipp Esselbach 0

An updated sharutils package has been released for Red Hat Linux 7.3, 9, and Fedora Core 1

---------------------------------------------------------------------
Fedora Legacy Update Advisory

Synopsis: Updated sharutils package fixes security issues
Advisory ID: FLSA:2155
Issue date: 2005-03-24
Product: Red Hat Linux, Fedora Core
Keywords: Bugfix
Cross references: https://bugzilla.fedora.us/show_bug.cgi?id=2155
CVE Names: N/A
---------------------------------------------------------------------


---------------------------------------------------------------------
1. Topic:

Updated sharutils packages that fix several security issues are now available.

The sharutils package contains a set of tools for encoding and decoding packages of files in binary or text format.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - i386
Red Hat Linux 9 - i386
Fedora Core 1 - i386

Red Hat 9377 Published by Philipp Esselbach 0

A thunderbird security update is available for Red Hat Enterprise Linux 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Critical: thunderbird security update
Advisory ID: RHSA-2005:337-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-337.html
Issue date: 2005-03-23
Updated on: 2005-03-23
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0399 CAN-2005-0255
----------------------------------------------------------------------

1. Summary:

Updated thunderbird packages that fix various bugs are now available.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9377 Published by Philipp Esselbach 0

A firefox security update is available for Red Hat Enterprise Linux 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Critical: firefox security update
Advisory ID: RHSA-2005:336-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-336.html
Issue date: 2005-03-23
Updated on: 2005-03-23
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0399 CAN-2005-0401 CAN-2005-0402
----------------------------------------------------------------------

1. Summary:

Updated firefox packages that fix various bugs are now available.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9377 Published by Philipp Esselbach 0

A Mozilla security update is available for Red Hat Enterprise Linux 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Critical: mozilla security update
Advisory ID: RHSA-2005:335-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-335.html
Issue date: 2005-03-23
Updated on: 2005-03-23
Product: Red Hat Enterprise Linux
CVE Names: CAN-2004-1380 CAN-2005-0141 CAN-2005-0142 CAN-2005-0143 CAN-2005-0144 CAN-2005-0146 CAN-2005-0149 CAN-2005-0399 CAN-2005-0401
----------------------------------------------------------------------

1. Summary:

Updated mozilla packages that fix various bugs are now available.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9377 Published by Philipp Esselbach 0

A mozilla security update is available for Red Hat Enterprise Linux 2.1 and 3

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Critical: mozilla security update
Advisory ID: RHSA-2005:323-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-323.html
Issue date: 2005-03-23
Updated on: 2005-03-23
Product: Red Hat Enterprise Linux
CVE Names: CAN-2004-0906 CAN-2004-1380 CAN-2004-1613 CAN-2005-0141 CAN-2005-0144 CAN-2005-0147 CAN-2005-0149 CAN-2005-0232 CAN-2005-0399
----------------------------------------------------------------------

1. Summary:

Updated mozilla packages that fix various bugs are now available.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64

Red Hat 9377 Published by Philipp Esselbach 0

A kdelibs security update is avaiable for Red Hat Enterprise Linux 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: kdelibs security update
Advisory ID: RHSA-2005:325-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-325.html
Issue date: 2005-03-23
Updated on: 2005-03-23
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0237 CAN-2005-0365 CAN-2005-0396
----------------------------------------------------------------------

1. Summary:

Updated kdelibs packages that fix several security issues are now available for Red Hat Enterprise Linux 4.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9377 Published by Philipp Esselbach 0

An ImageMagick security update is available for Red Hat Enterprise Linux 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: ImageMagick security update
Advisory ID: RHSA-2005:320-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-320.html
Issue date: 2005-03-23
Updated on: 2005-03-23
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0397
----------------------------------------------------------------------

1. Summary:

Updated ImageMagick packages that fix a format string bug are now available for Red Hat Enterprise Linux 4.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9377 Published by Philipp Esselbach 0

An ipsec-tools security update is available for Red Hat Enterprise Linux 3 and 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: ipsec-tools security update
Advisory ID: RHSA-2005:232-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-232.html
Issue date: 2005-03-23
Updated on: 2005-03-23
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0398
----------------------------------------------------------------------

1. Summary:

An updated ipsec-tools package that fixes a bug in parsing of ISAKMP headers is now available.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9377 Published by Philipp Esselbach 0

An ImageMagick security update is available for Red Hat Enterprise Linux 2.1 and 3

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: ImageMagick security update
Advisory ID: RHSA-2005:070-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-070.html
Issue date: 2005-03-23
Updated on: 2005-03-23
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0005 CAN-2005-0397 CAN-2005-0759 CAN-2005-0760 CAN-2005-0761 CAN-2005-0762
----------------------------------------------------------------------

1. Summary:

Updated ImageMagick packages that fix a heap based buffer overflow are now available.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64

Red Hat 9377 Published by Philipp Esselbach 0

A libexif security update is available for Red Hat Enterprise Linux 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Low: libexif security update
Advisory ID: RHSA-2005:300-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-300.html
Issue date: 2005-03-21
Updated on: 2005-03-21
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0664
----------------------------------------------------------------------

1. Summary:

Updated libexif packages that fix a buffer overflow issue are now available.

This update has been rated as having low security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9377 Published by Philipp Esselbach 0

A realplayer security update is available for Red Hat Enterprise Linux 3

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: realplayer security update
Advisory ID: RHSA-2005:299-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-299.html
Issue date: 2005-03-21
Updated on: 2005-03-21
Product: Red Hat Enterprise Linux Extras
Keywords: LACD
----------------------------------------------------------------------

1. Summary:

Updated realplayer packages that fix a number of security issues are now available for Red Hat Enterprise Linux 3 Extras.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 Extras - i386
Red Hat Desktop version 3 Extras - i386
Red Hat Enterprise Linux ES version 3 Extras - i386
Red Hat Enterprise Linux WS version 3 Extras - i386

Red Hat 9377 Published by Philipp Esselbach 0

A mailman security update is available for Red Hat Enterprise Linux 3 and 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: mailman security update
Advisory ID: RHSA-2005:235-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-235.html
Issue date: 2005-03-21
Updated on: 2005-03-21
Product: Red Hat Enterprise Linux
Keywords: XSS
CVE Names: CAN-2004-1177
----------------------------------------------------------------------

1. Summary:

An updated mailman package that corrects a cross-site scripting flaw is now available.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9377 Published by Philipp Esselbach 0

Ethereal security updates are available for Red Hat Enterprise Linux 2.1, 3, and 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: ethereal security update
Advisory ID: RHSA-2005:306-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-306.html
Issue date: 2005-03-18
Updated on: 2005-03-18
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0699 CAN-2005-0704 CAN-2005-0705 CAN-2005-0739
----------------------------------------------------------------------

1. Summary:

Updated Ethereal packages that fix various security vulnerabilities are now available.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9377 Published by Philipp Esselbach 0

A sylpheed security update is available for Red Hat Enterprise Linux 2.1

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: sylpheed security update
Advisory ID: RHSA-2005:303-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-303.html
Issue date: 2005-03-18
Updated on: 2005-03-18
Product: Red Hat Enterprise Linux
Keywords: buffer overflow
CVE Names: CAN-2005-0667
----------------------------------------------------------------------

1. Summary:

An updated sylpheed package that fixes a buffer overflow issue is now available.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386

Red Hat 9377 Published by Philipp Esselbach 0

A postfix security update is available for Red Hat Enterprise Linux 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Low: postfix security update
Advisory ID: RHSA-2005:152-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-152.html
Issue date: 2005-03-16
Updated on: 2005-03-16
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0337
----------------------------------------------------------------------

1. Summary:

Updated postfix packages that include a security fix and two other bug fixes are now available for Red Hat Enterprise Linux 4.

This update has been rated as having low security impact by the Red Hat Security Response Team

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9377 Published by Philipp Esselbach 0

A squid security update has been released for Red Hat Enterprise Linux 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: squid security update
Advisory ID: RHSA-2005:201-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-201.html
Issue date: 2005-03-16
Updated on: 2005-03-16
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0446
----------------------------------------------------------------------

1. Summary:

An updated squid package that fixes a denial of service issue is now available for Red Hat Enterprise Linux 4.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64