Red Hat 9313 Published by Philipp Esselbach 0

A kdegraphics security update is available for Red Hat Enterprise Linux 2.1 and 3

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: kdegraphics security update
Advisory ID: RHSA-2005:021-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-021.html
Issue date: 2005-04-12
Updated on: 2005-04-12
Product: Red Hat Enterprise Linux
CVE Names: CAN-2004-0803 CAN-2004-0886 CAN-2004-0804
----------------------------------------------------------------------

1. Summary:

Updated kdegraphics packages that resolve multiple security issues in kfax are now available.

This update has been rated as having moderate security impact by the Red Hat Security Response Team

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

Updated kdelibs packages are available for Red Hat Enterprise Linux 2.1 and 3

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: kdelibs security update
Advisory ID: RHSA-2005:307-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-307.html
Issue date: 2005-04-06
Updated on: 2005-04-06
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0396
----------------------------------------------------------------------

1. Summary:

Updated kdelibs packages that fix a local denial of service issue are now available.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A XFree86 security update is available for Red Hat Enterprise Linux 2.1

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: XFree86 security update
Advisory ID: RHSA-2005:044-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-044.html
Issue date: 2005-04-06
Updated on: 2005-04-06
Product: Red Hat Enterprise Linux
Keywords: Xpm legacy keyboard controller memory leak SEGV segfault crash
CVE Names: CAN-2005-0605
----------------------------------------------------------------------

1. Summary:

Updated XFree86 packages that fix a libXpm integer overflow flaw and a number of bugs are now available.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386

Red Hat 9313 Published by Philipp Esselbach 0

CentOS Errata and Security Advisory 2005:348

mysql-server security update for CentOS 3 i386:
https://rhn.redhat.com/errata/RHSA-2005-348.html

The following updated file has been uploaded and is currently syncing to the mirrors:

i386:
addons/i386/RPMS/mysql-server-3.23.58-16.RHEL3.1.i386.rpm

source:
updates/SRPMS/mysql-3.23.58-16.RHEL3.1.src.rpm

You may update your CentOS-3 i386 installations by running the command:

yum update mysql-server

Red Hat 9313 Published by Philipp Esselbach 0

Updated mysql-server packages are available for Red Hat Enterprise Linux 3

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: mysql-server security update
Advisory ID: RHSA-2005:348-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-348.html
Issue date: 2005-04-05
Updated on: 2005-04-05
Product: Red Hat Enterprise Linux Extras
CVE Names: CAN-2005-0709 CAN-2005-0710 CAN-2005-0711
----------------------------------------------------------------------

1. Summary:

Updated mysql-server packages that fix several vulnerabilities are now available.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 Extras - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 Extras - i386, x86_64
Red Hat Enterprise Linux ES version 3 Extras - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 Extras - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

Curl security updates are available for Red Hat Enterprise Linux 2.1, 3, and 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Low: curl security update
Advisory ID: RHSA-2005:340-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-340.html
Issue date: 2005-04-05
Updated on: 2005-04-05
Product: Red Hat Enterprise Linux
Keywords: curl overflows
CVE Names: CAN-2005-0490
----------------------------------------------------------------------

1. Summary:

Updated curl packages are now available.

This update has been rated as having low security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

gdk-pixbuf security updates are available for Red Hat Enterprise Linux 2.1, 3, and 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: gdk-pixbuf security update
Advisory ID: RHSA-2005:343-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-343.html
Issue date: 2005-04-05
Updated on: 2005-04-05
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0891
----------------------------------------------------------------------

1. Summary:

Updated gdk-pixbuf packages that fix a double free vulnerability are now available.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

An updated up2date package is available for Red Hat Enterprise Linux 4

----------------------------------------------------------------------
Red Hat Bug Fix Advisory

Synopsis: up2date bug fix update
Advisory ID: RHBA-2005:169-01
Advisory URL: https://rhn.redhat.com/errata/RHBA-2005-169.html
Issue date: 2005-04-01
Updated on: 2005-04-01
Product: Red Hat Enterprise Linux
Keywords: up2date RHN Red Hat Network
----------------------------------------------------------------------

1. Summary:

Updated up2date packages that fix a libgnat bug are now available for 64-bit platforms.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A tetex security update is available for Red HAt Enterprise Linux 2.1 and 3

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: tetex security update
Advisory ID: RHSA-2005:354-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-354.html
Issue date: 2005-04-01
Updated on: 2005-04-01
Product: Red Hat Enterprise Linux
CVE Names: CAN-2004-0803 CAN-2004-0804 CAN-2004-0886 CAN-2004-0888 CAN-2004-1125
----------------------------------------------------------------------

1. Summary:

Updated tetex packages that fix several integer overflows are now available.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A gtk2 security update has been released for Red Hat Enterprise Linux 3 and 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: gtk2 security update
Advisory ID: RHSA-2005:344-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-344.html
Issue date: 2005-04-01
Updated on: 2005-04-01
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0891
----------------------------------------------------------------------

1. Summary:

Updated gtk2 packages that fix a double free vulnerability are now available.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A XFree86 security update has been released for Red Hat Enterprise Linux 3

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: XFree86 security update
Advisory ID: RHSA-2005:331-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-331.html
Issue date: 2005-03-30
Updated on: 2005-03-30
Product: Red Hat Enterprise Linux
Keywords: Xpm Image Loader
CVE Names: CAN-2005-0605
----------------------------------------------------------------------

1. Summary:

Updated XFree86 packages that fix a libXpm integer overflow flaw are now available.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A krb5 security update is available for Red Hat Enterprise Linux 2.1, 3, and 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: krb5 security update
Advisory ID: RHSA-2005:330-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-330.html
Issue date: 2005-03-30
Updated on: 2005-03-30
Product: Red Hat Enterprise Linux
Keywords: telnet
CVE Names: CAN-2005-0468 CAN-2005-0469
----------------------------------------------------------------------

1. Summary:

Updated krb5 packages which fix two buffer overflow vulnerabilities in the included Kerberos-aware telnet client are now available.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A mysql security update is available for Red Hat Enterprise Linux 2.1, 3, and 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: mysql security update
Advisory ID: RHSA-2005:334-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-334.html
Issue date: 2005-03-28
Updated on: 2005-03-28
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0709 CAN-2005-0710 CAN-2005-0711
----------------------------------------------------------------------

1. Summary:

Updated mysql packages that fix several vulnerabilities are now available.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A telnet security update is available for Red Hat Enterprise Linux 2.1, 3, and 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: telnet security update
Advisory ID: RHSA-2005:327-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-327.html
Issue date: 2005-03-28
Updated on: 2005-03-28
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0468 CAN-2005-0469
----------------------------------------------------------------------

1. Summary:

Updated telnet packages that fix two buffer overflow vulnerabilities are now available.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A grip security update has been released for Red Hat Enterprise Linux 2.1

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: grip security update
Advisory ID: RHSA-2005:304-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-304.html
Issue date: 2005-03-28
Updated on: 2005-03-28
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0706
----------------------------------------------------------------------

1. Summary:

A new grip package is available that fixes a remote buffer overflow.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386

Red Hat 9313 Published by Philipp Esselbach 0

A Mozilla Firefox security update has been released for Gentoo Linux

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200503-31
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Normal
Title: Mozilla Firefox: Multiple vulnerabilities
Date: March 25, 2005
Bugs: #86148
ID: 200503-31

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
=======

Mozilla Firefox 1.0.2 fixes new security vulnerabilities, including the remote execution of arbitrary code through malicious GIF images or sidebars.

Red Hat 9313 Published by Philipp Esselbach 0

A Mozilla Suite security update is available for Gentoo Linux

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200503-30
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Normal
Title: Mozilla Suite: Multiple vulnerabilities
Date: March 25, 2005
Bugs: #84074
ID: 200503-30

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
=======

The Mozilla Suite is vulnerable to multiple issues ranging from the remote execution of arbitrary code to various issues allowing to trick the user into trusting fake web sites or interacting with privileged content.

Red Hat 9313 Published by Philipp Esselbach 0

An updated spamassassin package has been released for Fedora Core 1

---------------------------------------------------------------------
Fedora Legacy Update Advisory

Synopsis: Updated spamassassin package fixes security issues
Advisory ID: FLSA:2268
Issue date: 2005-03-24
Product: Fedora Core
Keywords: Bugfix
Cross references: https://bugzilla.fedora.us/show_bug.cgi?id=2268
CVE Names: CAN-2004-0796
---------------------------------------------------------------------


---------------------------------------------------------------------
1. Topic:

An updated spamassassin package that fixes a denial of service bug when parsing malformed messages is now available.

SpamAssassin provides a way to reduce unsolicited commercial email (SPAM) from incoming email.

2. Relevant releases/architectures:

Fedora Core 1 - i386

Red Hat 9313 Published by Philipp Esselbach 0

Updated mysql packages are available for Red Hat Linux 7.3, 9, and Fedora Core 1

---------------------------------------------------------------------
Fedora Legacy Update Advisory

Synopsis: Updated mysql packages fix security issues
Advisory ID: FLSA:2129
Issue date: 2005-03-24
Product: Red Hat Linux, Fedora Core
Keywords: Bugfix
Cross references: https://bugzilla.fedora.us/show_bug.cgi?id=2129
CVE Names: CAN-2004-0381 CAN-2004-0388 CAN-2004-0457
CAN-2004-0835 CAN-2004-0836 CAN-2004-0837
CAN-2004-0957 CAN-2005-0004
---------------------------------------------------------------------


---------------------------------------------------------------------
1. Topic:

Updated mysql packages that fix various security issues are now available.

MySQL is a multi-user, multi-threaded SQL database server.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - i386
Red Hat Linux 9 - i386
Fedora Core 1 - i386