Red Hat 9313 Published by Philipp Esselbach 0

A krb5 security update has been released for Red Hat Enterprise Linux

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: krb5 security update
Advisory ID: RHSA-2005:567-02
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-567.html
Issue date: 2005-07-12
Updated on: 2005-07-12
Product: Red Hat Enterprise Linux
Cross references: RHSA-2005:562
Obsoletes: RHSA-2005:330
CVE Names: CAN-2004-0175 CAN-2005-1174 CAN-2005-1175 CAN-2005-1689
----------------------------------------------------------------------

1. Summary:

Updated krb5 packages that fix multiple security issues are now available for Red Hat Enterprise Linux 4.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A krb5 update has been released for Red Hat Enterprise Linux

- ---------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Critical: krb5 security update
Advisory ID: RHSA-2005:562-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-562.html
Issue date: 2005-07-12
Updated on: 2005-07-12
Product: Red Hat Enterprise Linux
Cross references: RHSA-2005:567
Obsoletes: RHSA-2005:330
CVE Names: CAN-2004-0175 CAN-2005-0488 CAN-2005-1175 CAN-2005-1689
- ---------------------------------------------------------------------

1. Summary:

Updated krb5 packages which fix multiple security issues are now available for Red Hat Enterprise Linux 2.1 and 3.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

Updated openssh packages are available for Red Hat Linux 7.3/9 and Fedora Core 1/2

---------------------------------------------------------------------
Fedora Legacy Update Advisory

Synopsis: Updated openssh packages fix a security issue
Advisory ID: FLSA:123014
Issue date: 2005-07-11
Product: Red Hat Linux, Fedora Core
Keywords: Bugfix
CVE Names: CAN-2004-0175
---------------------------------------------------------------------


---------------------------------------------------------------------
1. Topic:

Updated openssh packages that fix a potential security vulnerability are now available.

OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. SSH replaces rlogin and rsh, and provides secure encrypted communications between two untrusted hosts over an insecure network. X11 connections and arbitrary TCP/IP ports can also be forwarded over a secure channel. Public key authentication can be used for "passwordless" access to servers.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - i386
Red Hat Linux 9 - i386
Fedora Core 1 - i386
Fedora Core 2 - i386

Red Hat 9313 Published by Philipp Esselbach 0

Updated telnet packages are available for Red Hat Linux 7.3/9 and Fedora Core 1

---------------------------------------------------------------------
Fedora Legacy Update Advisory

Synopsis: Updated telnet packages fix security issues
Advisory ID: FLSA:152583
Issue date: 2005-07-11
Product: Red Hat Linux, Fedora Core
Keywords: Bugfix
CVE Names: CAN-2005-0468 CAN-2005-0469
---------------------------------------------------------------------


---------------------------------------------------------------------
1. Topic:

Updated telnet packages that fix two buffer overflow vulnerabilities are now available.

The telnet package provides a command line telnet client. The telnet-server package includes a telnet daemon, telnetd, that supports remote login to the host machine.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - i386
Red Hat Linux 9 - i386
Fedora Core 1 - i386

Red Hat 9313 Published by Philipp Esselbach 0

Updated dhcp packages are available for Red Hat Linux 7.3

---------------------------------------------------------------------
Fedora Legacy Update Advisory

Synopsis: Updated dhcp package fixes security issue
Advisory ID: FLSA:152835
Issue date: 2005-07-10
Product: Red Hat Linux
Keywords: Bugfix
CVE Names: CAN-2004-1006
---------------------------------------------------------------------


---------------------------------------------------------------------
1. Topic:

Updated dhcp packages that fix a security issue are now available.

dhcp is a DHCP (Dynamic Host Configuration Protocol) server and relay agent.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - i386

Red Hat 9313 Published by Philipp Esselbach 0

An updated mailman package has been released for Red Hat Linux 7.3/9 and Fedora Core 1

---------------------------------------------------------------------
Fedora Legacy Update Advisory

Synopsis: Updated mailman package fixes security issue
Advisory ID: FLSA:152895
Issue date: 2005-07-10
Product: Red Hat Linux, Fedora Core
Keywords: Bugfix
CVE Names: CAN-2005-0202
---------------------------------------------------------------------


---------------------------------------------------------------------
1. Topic:

Updated mailman packages that correct a mailman security issue are now available.

Mailman is software to help manage email discussion lists, much like Majordomo and Smartmail.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - i386
Red Hat Linux 9 - i386
Fedora Core 1 - i386

Red Hat 9313 Published by Philipp Esselbach 0

Updated gftp packages are available for Red Hat Linux 7.3/9 and Fedora Core 1

---------------------------------------------------------------------
Fedora Legacy Update Advisory

Synopsis: Updated gftp package fixes security issue
Advisory ID: FLSA:152908
Issue date: 2005-07-10
Product: Red Hat Linux, Fedora Core
Keywords: Bugfix
CVE Names: CAN-2005-0372
---------------------------------------------------------------------


---------------------------------------------------------------------
1. Topic:

Updated gftp packages that fix a security issue are now available.

gFTP is a multi-threaded FTP client for the X Window System.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - i386
Red Hat Linux 9 - i386
Fedora Core 1 - i386

Red Hat 9313 Published by Philipp Esselbach 0

Updated php packages are available for Red Hat Linux 7.3/9 and Fedora Core 1/2

---------------------------------------------------------------------
Fedora Legacy Update Advisory

Synopsis: Updated php packages fix security issues
Advisory ID: FLSA:155505
Issue date: 2005-07-10
Product: Red Hat Linux, Fedora Core
Keywords: Bugfix
CVE Names: CAN-2005-0524 CAN-2005-0525 CAN-2005-1042
CAN-2005-1043
---------------------------------------------------------------------


---------------------------------------------------------------------
1. Topic:

Updated php packages that fix various security issues are now available.

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Web server.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - i386
Red Hat Linux 9 - i386
Fedora Core 1 - i386
Fedora Core 2 - i386

Red Hat 9313 Published by Philipp Esselbach 0

Updated sharutils packages are available for Red Hat Linux 7.3/9 and Fedora Core 1/2

---------------------------------------------------------------------
Fedora Legacy Update Advisory

Synopsis: Updated sharutils package fixes security issue
Advisory ID: FLSA:154991
Issue date: 2005-07-10
Product: Red Hat Linux, Fedora Core
Keywords: Bugfix
CVE Names: CAN-2005-0990
---------------------------------------------------------------------


---------------------------------------------------------------------
1. Topic:

Updated packages for sharutils which fix a security vulnerability are now available.

The sharutils package contains a set of tools for encoding and decoding packages of files in binary or text format.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - i386
Red Hat Linux 9 - i386
Fedora Core 1 - i386
Fedora Core 2 - i386

Red Hat 9313 Published by Philipp Esselbach 0

An Adobe Acrobat Reader security update is available for Red Hat Enterprise Linux

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Critical: Adobe Acrobat Reader security update
Advisory ID: RHSA-2005:575-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-575.html
Issue date: 2005-07-08
Updated on: 2005-07-08
Product: Red Hat Enterprise Linux Extras
CVE Names: CAN-2005-1625 CAN-2005-1841
----------------------------------------------------------------------

1. Summary:

Updated acroread packages that fix a security issue are now available.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 Extras - i386, x86_64
Red Hat Desktop version 3 Extras - i386, x86_64
Red Hat Enterprise Linux ES version 3 Extras - i386, x86_64
Red Hat Enterprise Linux WS version 3 Extras - i386, x86_64
Red Hat Enterprise Linux AS version 4 Extras - i386, x86_64
Red Hat Desktop version 4 Extras - i386, x86_64
Red Hat Enterprise Linux ES version 4 Extras - i386, x86_64
Red Hat Enterprise Linux WS version 4 Extras - i386, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A php security update has been released for Red Hat Enterprise Linux

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: php security update
Advisory ID: RHSA-2005:564-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-564.html
Issue date: 2005-07-07
Updated on: 2005-07-07
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-1751 CAN-2005-1921
----------------------------------------------------------------------

1. Summary:

Updated PHP packages that fix two security issues are now available.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A zlib security update has been released for Red Hat Enterprise Linux

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Important: zlib security update
Advisory ID: RHSA-2005:569-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-569.html
Issue date: 2005-07-06
Updated on: 2005-07-06
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-2096
----------------------------------------------------------------------

1. Summary:

Updated Zlib packages that fix a buffer overflow are now available for Red Hat Enterprise Linux 4.

This update has been rated as having important security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A RealPlayer security update has been released for Red Hat Enterprise Linux

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Critical: RealPlayer security update
Advisory ID: RHSA-2005:523-02
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-523.html
Issue date: 2005-06-23
Updated on: 2005-07-05
Product: Red Hat Enterprise Linux Extras
CVE Names: CAN-2005-1766
----------------------------------------------------------------------

1. Summary:

An updated RealPlayer package that fixes a buffer overflow issue is now
available.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

[Updated 05 Jul 2005]
The previous package for Red Hat Enterprise Linux 4 did not contain the proper fix for this issue. This erratum has been updated with a replacement package that corrects this issue

Red Hat 9313 Published by Philipp Esselbach 0

RAMDISK: Couldn't find valid RAM disk image starting at 0.
VFS: Cannot open root device "<NULL>" or unknown-block(8,3)
Please append a correct "root=" boot option
Kernel panic - not syncing: VFS: Unable to mount root fs on
unknown-block(8,3)

http://people.redhat.com/wtogami/archive/fc4-installer-syslinux-crash.jpg
If you boot the FC4 CD or DVD installer and see an error something like the above text or picture, then your motherboard chipset may be affected by the syslinux crash bug. This bug reportedly happens most often on Intel Pentium4 or Nocona chipsets 845, 865, 875, 915, 925, 945, 955, and very rarely on some AMD64 motherboards.

Simple Workaround
The majority of users can easily workaround this problem by using the "garbage" workaround. Simply boot the CD/DVD, and at the first prompt type any line of garbage (the string "garbage" works fine), then ENTER. At this point you can use any regular installer command to start the installer, or simply ENTER.

Less than Simple Workaround
http://people.redhat.com/pjones/i915/booti915.iso
For some rare users the "garbage" workaround does not work. For these
users, this 6MB sized i386 boot.iso replacement should theoretically
work. Note that boot.iso is only usable with a network-based install.

http://forums.fedoraforum.org/showthread.php?t=62400
See the latest version of this notice with new information as it is known at this URL.

Red Hat 9313 Published by Philipp Esselbach 0

A sudo security update has been released for Red Hat Enterprise Linux

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: sudo security update
Advisory ID: RHSA-2005:535-04
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-535.html
Issue date: 2005-06-29
Updated on: 2005-06-29
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-1993
----------------------------------------------------------------------

1. Summary:

An updated sudo package is available that fixes a race condition in sudo's pathname validation.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A RealPlayer security update is available for Red Hat Enterprise Linux

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Critical: RealPlayer security update
Advisory ID: RHSA-2005:523-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-523.html
Issue date: 2005-06-23
Updated on: 2005-06-23
Product: Red Hat Enterprise Linux Extras
CVE Names: CAN-2005-1766
----------------------------------------------------------------------

1. Summary:

An updated RealPlayer package that fixes a buffer overflow issue is now available.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 Extras - i386, x86_64
Red Hat Desktop version 3 Extras - i386, x86_64
Red Hat Enterprise Linux ES version 3 Extras - i386, x86_64
Red Hat Enterprise Linux WS version 3 Extras - i386, x86_64
Red Hat Enterprise Linux AS version 4 Extras - i386, x86_64
Red Hat Desktop version 4 Extras - i386, x86_64
Red Hat Enterprise Linux ES version 4 Extras - i386, x86_64
Red Hat Enterprise Linux WS version 4 Extras - i386, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A freeradius security update is available for Red Hat Enterprise Linux

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: freeradius security update
Advisory ID: RHSA-2005:524-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-524.html
Issue date: 2005-06-23
Updated on: 2005-06-23
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-1454 CAN-2005-1455
----------------------------------------------------------------------

1. Summary:

Updated freeradius packages that fix a buffer overflow and possible SQL injection attacks in the sql module are now available.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A Helix Player security update is available for Red Hat Enterprise Linux

----------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Critical: HelixPlayer security update
Advisory ID: RHSA-2005:517-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-517.html
Issue date: 2005-06-23
Updated on: 2005-06-23
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-1766
----------------------------------------------------------------------

1. Summary:

An updated HelixPlayer package that fixes a buffer overflow issue is now available.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ppc, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, x86_64
Red Hat Enterprise Linux WS version 4 - i386, x86_64

Red Hat 9313 Published by Philipp Esselbach 0

A spamassassin security update is available for Red Hat Enterprise Linux

- ---------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Moderate: spamassassin security update
Advisory ID: RHSA-2005:498-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-498.html
Issue date: 2005-06-23
Updated on: 2005-06-23
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-1266
- ---------------------------------------------------------------------

1. Summary:

An updated spamassassin package that fixes a denial of service bug when parsing malformed messages is now available.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64