Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 11: 2009-10237 Critical Update for zlib Issue in Deltarpm

fedora
Calendar Grey October 8, 2009
Dist Fedora Esm H88
Upgrade deltarpm in Fedora 11 to mitigate zlib security issues and enhance the overall security posture of the system.
deltarpm prior to the current build ships with a bundled copy of zlib

Summary

A deltarpm contains the difference between an old

and a new version of a rpm, which makes it possible

to recreate the new rpm from the deltarpm and the old

one. You don't have to have a copy of the old rpm,

deltarpms can also work with installed rpms.

Update Information:

deltarpm prior to the current build ships with a bundled copy of zlib. This version of zlib has a known vulnerability with CVE identifier: CAN-2005-1849 This build of deltarpm patches the program to use the system zlib (which was fixed when the vulnerability was first discovered) instead of the bundled copy.

Change Log

* Wed Sep 30 2009 Toshio Kuratomi - 3.4-17 - Work around cvs tag problem * Wed Sep 30 2009 Toshio Kuratomi - 3.4-16 - Build against the system zlib, not the bundled library. This remedies the fact that the included zlib is affected by CAN-2005-1849. - Fix cfile_detect_rsync() to detect rsync even if we don't have a zlib capable of making rsync-friendly compressed files.

References


[ 1 ] Bug #526432 - deltarpm contains an own, modified copy of zlib https://bugzilla.redhat.com/show_bug.cgi?id=526432

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update deltarpm' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: deltarpm
Product: Fedora 11
Version: 3.4
Release: 17.fc11
URL: Summary : Create deltas between rpms

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here