Red Hat 9313 Published by Philipp Esselbach 0

A PHP security update has been released for Red Hat Enterprise Linux 3

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: PHP security update
Advisory ID: RHSA-2005:405-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-405.html
Issue date: 2005-04-28
Updated on: 2005-04-28
Product: Red Hat Enterprise Linux
CVE Names: CAN-2004-1392 CAN-2005-0524 CAN-2005-0525 CAN-2005-1042 CAN-2005-1043
----------------------------------------------------------------------

1. Summary:

Updated PHP packages that fix various security issues are now available.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A Mozilla security update has been released for Red Hat Enterprise Linux 2.1 and 3

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: Mozilla security update
Advisory ID: RHSA-2005:384-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-384.html
Issue date: 2005-04-28
Updated on: 2005-04-28
Product: Red Hat Enterprise Linux
CVE Names: CAN-2004-1156 CAN-2005-0142 CAN-2005-0143 CAN-2005-0146 CAN-2005-0231 CAN-2005-0232 CAN-2005-0233 CAN-2005-0401 CAN-2005-0527 CAN-2005-0578 CAN-2005-0584 CAN-2005-0585 CAN-2005-0586 CAN-2005-0588 CAN-2005-0590 CAN-2005-0591 CAN-2005-0593 CAN-2005-0989 CAN-2005-1153 CAN-2005-1154 CAN-2005-1155 CAN-2005-1156 CAN-2005-1157 CAN-2005-1159 CAN-2005-1160
----------------------------------------------------------------------

1. Summary:

Updated Mozilla packages that fix various security bugs are now available.

This update has been rated as having Important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

An updated 64 Bit kernel is available for Red Hat Enterprise Linux 2.1

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: kernel security update
Advisory ID: RHSA-2005:284-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-284.html
Issue date: 2005-04-28
Updated on: 2005-04-28
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0135 CAN-2005-0137 CAN-2005-0384 CAN-2005-0449 CAN-2005-0750
----------------------------------------------------------------------

1. Summary:

Updated kernel packages are now available as part of ongoing support and maintenance of Red Hat Enterprise Linux version 2.1 for 64-bit architectures. This is the seventh regular update.

This security advisory has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - ia64
Red Hat Linux Advanced Workstation 2.1 - ia64

Red Hat 9313 Published by Philipp Esselbach 0

A kernel update is available for Red Hat Enterprise Linux 2.1

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: kernel security update
Advisory ID: RHSA-2005:283-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-283.html
Issue date: 2005-04-28
Updated on: 2005-04-28
Product: Red Hat Enterprise Linux
CVE Names: CAN-2004-0619 CAN-2005-0384 CAN-2005-0449 CAN-2005-0750
----------------------------------------------------------------------

1. Summary:

Updated kernel packages are now available as part of ongoing support and maintenance of Red Hat Enterprise Linux version 2.1. This is the seventh regular update.

This security advisory has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386

Red Hat 9313 Published by Philipp Esselbach 0

A glibc security update is available for Red Hat Enterprise Linux 2.1

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Low: glibc security update
Advisory ID: RHSA-2005:261-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-261.html
Issue date: 2005-04-28
Updated on: 2005-04-28
Product: Red Hat Enterprise Linux
Keywords: glibc LD_DEBUG catchsegv glibcbug
CVE Names: CAN-2004-0968 CAN-2004-1382 CAN-2004-1453
----------------------------------------------------------------------

1. Summary:

Updated glibc packages that address several bugs are now available.

This update has been rated as having low security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386

Red Hat 9313 Published by Philipp Esselbach 0

A Mozilla security update has been released for Red Hat Enterprise Linux 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: Mozilla security update
Advisory ID: RHSA-2005:386-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-386.html
Issue date: 2005-04-26
Updated on: 2005-04-26
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0989 CAN-2005-1153 CAN-2005-1154 CAN-2005-1155 CAN-2005-1156 CAN-2005-1157 CAN-2005-1159 CAN-2005-1160
----------------------------------------------------------------------

1. Summary:

Updated mozilla packages that fix various security bugs are now available.

This update has been rated as having Important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A sharutils security update is available for Red Hat Enterprise Linux

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Low: sharutils security update
Advisory ID: RHSA-2005:377-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-377.html
Issue date: 2005-04-26
Updated on: 2005-04-26
Product: Red Hat Enterprise Linux
CVE Names: CAN-2004-1772 CAN-2004-1773 CAN-2005-0990
----------------------------------------------------------------------

1. Summary:

An updated sharutils package is now available.

This update has been rated as having low security impact by the Red Hat Security Response Team.

2. Problem description:

The sharutils package contains a set of tools for encoding and decoding packages of files in binary or text format.

A stack based overflow bug was found in the way shar handles the -o option. If a user can be tricked into running a specially crafted command, it could lead to arbitrary code execution. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1772 to this issue. Please note that this issue does not affect Red Hat Enterprise Linux 4.

Two buffer overflow bugs were found in sharutils. If an attacker can place a malicious 'wc' command on a victim's machine, or trick a victim into running a specially crafted command, it could lead to arbitrary code execution. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1773 to this issue.

A bug was found in the way unshar creates temporary files. A local user could use symlinks to overwrite arbitrary files the victim running unshar has write access to. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0990 to this issue.

All users of sharutils should upgrade to this updated package, which includes backported fixes to correct these issues.

Red Hat 9313 Published by Philipp Esselbach 0

A cvs security update are available for Red Hat Enterprise Linux 2.1, 3, and 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: cvs security update
Advisory ID: RHSA-2005:387-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-387.html
Issue date: 2005-04-25
Updated on: 2005-04-25
Product: Red Hat Enterprise Linux
Keywords: cvs buffer overflow
CVE Names: CAN-2005-0753
----------------------------------------------------------------------

1. Summary:

An updated cvs package that fixes security bugs is now available.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

An openoffice.org security update has been released for Red Hat Enterprise Linux

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: openoffice.org security update
Advisory ID: RHSA-2005:375-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-375.html
Issue date: 2005-04-25
Updated on: 2005-04-25
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0941
----------------------------------------------------------------------

1. Summary:

Updated openoffice.org packages are now available.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Problem description:

OpenOffice.org is an office productivity suite that includes desktop applications such as a word processor, spreadsheet, presentation manager, formula editor, and drawing program.

A heap based buffer overflow bug was found in the OpenOffice.org DOC file processor. An attacker could create a carefully crafted DOC file in such a way that it could cause OpenOffice.org to execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0941 to this issue.

All users of OpenOffice.org are advised to upgrade to these updated packages, which contain backported fixes for these issues.

Red Hat 9313 Published by Philipp Esselbach 0

A kernel security update is available for Red Hat Enterprise Linux 3

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: kernel security update
Advisory ID: RHSA-2005:293-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-293.html
Issue date: 2005-04-22
Updated on: 2005-04-22
Product: Red Hat Enterprise Linux
Keywords: taroon
Obsoletes: RHSA-2005:043
CVE Names: CAN-2004-0075 CAN-2004-0177 CAN-2004-0814 CAN-2004-1058 CAN-2004-1073 CAN-2005-0135 CAN-2005-0137 CAN-2005-0204 CAN-2005-0384 CAN-2005-0403 CAN-2005-0449 CAN-2005-0736 CAN-2005-0749 CAN-2005-0750
----------------------------------------------------------------------

1. Summary:

Updated kernel packages that fix several security issues in the Red Hat Enterprise Linux 3 kernel are now available.

This security advisory has been rated as having important security impact by the Red Hat Security Response Team.

The Linux kernel handles the basic functions of the operating system.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A firefox security update is available for Red Hat Enterprise Linux 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: firefox security update
Advisory ID: RHSA-2005:383-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-383.html
Issue date: 2005-04-21
Updated on: 2005-04-21
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0752 CAN-2005-0989 CAN-2005-1153 CAN-2005-1154 CAN-2005-1155 CAN-2005-1156 CAN-2005-1157 CAN-2005-1158 CAN-2005-1159 CAN-2005-1160
----------------------------------------------------------------------

1. Summary:

Updated firefox packages that fix various security bugs are now available.

This update has been rated as having Important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A RealPlayer security update is available for Red Hat Enterprise Linux 3

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Critical: RealPlayer security update
Advisory ID: RHSA-2005:394-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-394.html
Issue date: 2005-04-20
Updated on: 2005-04-20
Product: Red Hat Enterprise Linux Extras
CVE Names: CAN-2005-0755
----------------------------------------------------------------------

1. Summary:

An updated RealPlayer package that fixes a buffer overflow issue is now available.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 Extras - i386, x86_64
Red Hat Desktop version 3 Extras - i386, x86_64
Red Hat Enterprise Linux ES version 3 Extras - i386, x86_64
Red Hat Enterprise Linux WS version 3 Extras - i386, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A HelixPlayer security update has been released for Red Hat Enterprise Linux 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Critical: HelixPlayer security update
Advisory ID: RHSA-2005:392-03
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-392.html
Issue date: 2005-04-20
Updated on: 2005-04-20
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0755
----------------------------------------------------------------------

1. Summary:

An updated HelixPlayer package that fixes a buffer overflow issue is now available.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ppc, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, x86_64
Red Hat Enterprise Linux WS version 4 - i386, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A RealPlayer security update has been released for Red Hat Enterprise Linux 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Critical: RealPlayer security update
Advisory ID: RHSA-2005:363-03
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-363.html
Issue date: 2005-04-20
Updated on: 2005-04-20
Product: Red Hat Enterprise Linux Extras
CVE Names: CAN-2005-0755
----------------------------------------------------------------------

1. Summary:

An updated RealPlayer package that fixes a buffer overflow issue is now available.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 Extras - i386, x86_64
Red Hat Desktop version 4 Extras - i386, x86_64
Red Hat Enterprise Linux ES version 4 Extras - i386, x86_64
Red Hat Enterprise Linux WS version 4 Extras - i386, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A logwatch security update is available for Red Hat Enterprise Linux 2.1

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: logwatch security update
Advisory ID: RHSA-2005:364-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-364.html
Issue date: 2005-04-19
Updated on: 2005-04-19
Product: Red Hat Enterprise Linux
Keywords: logwatch
CVE Names: CAN-2005-1061
----------------------------------------------------------------------

1. Summary:

An updated logwatch package that fixes a denial of service issue is now available.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - noarch
Red Hat Linux Advanced Workstation 2.1 - noarch
Red Hat Enterprise Linux ES version 2.1 - noarch
Red Hat Enterprise Linux WS version 2.1 - noarch

Red Hat 9313 Published by Philipp Esselbach 0

An important kernel security update has been released for Red Hat Enterprise Linux 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: kernel security update
Advisory ID: RHSA-2005:366-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-366.html
Issue date: 2005-04-19
Updated on: 2005-04-19
Product: Red Hat Enterprise Linux
Keywords: nahant kernel errata
CVE Names: CAN-2005-0135 CAN-2005-0207 CAN-2005-0209 CAN-2005-0384 CAN-2005-0400 CAN-2005-0449 CAN-2005-0529 CAN-2005-0530 CAN-2005-0531 CAN-2005-0736 CAN-2005-0749 CAN-2005-0750 CAN-2005-0767 CAN-2005-0815 CAN-2005-0839 CAN-2005-0867 CAN-2005-0977 CAN-2005-1041
----------------------------------------------------------------------

1. Summary:

Updated kernel packages that fix several security issues are now available for Red Hat Enterprise Linux 4.

This update has been rated as having important security impact by the Red Hat Security Response Team.

The Linux kernel handles the basic functions of the operating system.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, noarch, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, noarch, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, noarch, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, noarch, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A xloadimage security updates has been released for Red Hat Enterprise Linux 2.1, 3, and 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Low: xloadimage security update
Advisory ID: RHSA-2005:332-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-332.html
Issue date: 2005-04-19
Updated on: 2005-04-19
Product: Red Hat Enterprise Linux
----------------------------------------------------------------------

1. Summary:

A new xloadimage package that fixes bugs in handling malformed tiff and pbm/pnm/ppm images, and in handling metacharacters in filenames is now available.

This update has been rated as having low security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

An important gaim security update is available for both Red Hat Enterprise Linux 3 and 4

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: gaim security update
Advisory ID: RHSA-2005:365-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-365.html
Issue date: 2005-04-12
Updated on: 2005-04-12
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-0965 CAN-2005-0966 CAN-2005-0967
----------------------------------------------------------------------

1. Summary:

An updated gaim package that fixes multiple denial of service issues is now available.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A dhcp security update is available for Red Hat Enterprise Linux 2.1

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: dhcp security update
Advisory ID: RHSA-2005:212-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-212.html
Issue date: 2005-04-12
Updated on: 2005-04-12
Product: Red Hat Enterprise Linux
CVE Names: CAN-2004-1006
----------------------------------------------------------------------

1. Summary:

An updated dhcp package that fixes a string format issue is now available for Red Hat Enterprise Linux 2.1.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386