Fedora Update Notification
FEDORA-2004-091
2004-03-10
---------------------------------------------------------------------

Name        : coreutils
Version     : 5.0                      
Release     : 34.1                  
Summary     : The GNU core utilities: a set of tools commonly used in shell scripts
Description :
These are the GNU core utilities.  This package is the combination of
the old GNU fileutils, sh-utils, and textutils packages.

---------------------------------------------------------------------
Update Information:

An updated coreutils package is available fixing an issue in the ls(1)
utility, described at:
 
CVE -CVE-2003-0853

Note that this vulnerability affects Internet-facing services which execute
ls(1) with user-supplied input, and although wu-ftpd is one such service it
is not supplied with Fedora Core 1.

---------------------------------------------------------------------
* Wed Mar 03 2004 Tim Waugh <twaugh@redhat.com> 5.0-34.1

- Build for Fedora Core 1.

* Thu Dec 04 2003 Tim Waugh <twaugh@redhat.com> 5.0-34.sel

- Fix column widths problems in ls.

* Tue Dec 02 2003 Tim Waugh <twaugh@redhat.com> 5.0-33.sel

- Speed up md5sum by disabling speed-up asm.

* Wed Nov 19 2003 Dan Walsh <dwalsh@redhat.com> 5.0-32.sel

- Try again

* Wed Nov 19 2003 Dan Walsh <dwalsh@redhat.com> 5.0-31.sel

- Fix move on non SELinux kernels

* Fri Nov 14 2003 Tim Waugh <twaugh@redhat.com> 5.0-30.sel

- Fixed useless acl dependencies (bug #106141).

* Fri Oct 24 2003 Dan Walsh <dwalsh@redhat.com> 5.0-29.sel

- Fix id -Z

* Tue Oct 21 2003 Dan Walsh <dwalsh@redhat.com> 5.0-28.sel

- Turn on SELinux
- Fix chcon error handling

* Wed Oct 15 2003 Dan Walsh <dwalsh@redhat.com> 5.0-28

- Turn off SELinux

* Mon Oct 13 2003 Dan Walsh <dwalsh@redhat.com> 5.0-27.sel

- Turn on SELinux

* Mon Oct 13 2003 Dan Walsh <dwalsh@redhat.com> 5.0-27

- Turn off SELinux

* Mon Oct 13 2003 Dan Walsh <dwalsh@redhat.com> 5.0-26.sel

- Turn on SELinux


---------------------------------------------------------------------
This update can be downloaded from:
    

092a4490b17447ec40cf1ebd1a90334c  SRPMS/coreutils-5.0-34.1.src.rpm
9297d994a0837fca2d8727d6b63c33a6  i386/coreutils-5.0-34.1.i386.rpm
66bd92fef857384002c5e7a186c235ff  i386/debug/coreutils-debuginfo-5.0-34.1.i386.rpm
9318557a41978705b3696c5ce7dc897c  x86_64/coreutils-5.0-34.1.x86_64.rpm
5de0c3389976a04fbe8f40e36a5c6683  x86_64/debug/coreutils-debuginfo-5.0-34.1.x86_64.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.  
---------------------------------------------------------------------

Fedora: coreutils Integer overflow vulnerability

March 11, 2004
An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code.

Summary

These are the GNU core utilities. This package is the combination of

the old GNU fileutils, sh-utils, and textutils packages.

Update Information:

An updated coreutils package is available fixing an issue in the ls(1) utility, described at:

CVE -CVE-2003-0853

Note that this vulnerability affects Internet-facing services which execute ls(1) with user-supplied input, and although wu-ftpd is one such service it is not supplied with Fedora Core 1.

* Wed Mar 03 2004 Tim Waugh <twaugh@redhat.com> 5.0-34.1

- Build for Fedora Core 1.

* Thu Dec 04 2003 Tim Waugh <twaugh@redhat.com> 5.0-34.sel

- Fix column widths problems in ls.

* Tue Dec 02 2003 Tim Waugh <twaugh@redhat.com> 5.0-33.sel

- Speed up md5sum by disabling speed-up asm.

* Wed Nov 19 2003 Dan Walsh <dwalsh@redhat.com> 5.0-32.sel

- Try again

* Wed Nov 19 2003 Dan Walsh <dwalsh@redhat.com> 5.0-31.sel

- Fix move on non SELinux kernels

* Fri Nov 14 2003 Tim Waugh <twaugh@redhat.com> 5.0-30.sel

- Fixed useless acl dependencies (bug #106141).

* Fri Oct 24 2003 Dan Walsh <dwalsh@redhat.com> 5.0-29.sel

- Fix id -Z

* Tue Oct 21 2003 Dan Walsh <dwalsh@redhat.com> 5.0-28.sel

- Turn on SELinux - Fix chcon error handling

* Wed Oct 15 2003 Dan Walsh <dwalsh@redhat.com> 5.0-28

- Turn off SELinux

* Mon Oct 13 2003 Dan Walsh <dwalsh@redhat.com> 5.0-27.sel

- Turn on SELinux

* Mon Oct 13 2003 Dan Walsh <dwalsh@redhat.com> 5.0-27

- Turn off SELinux

* Mon Oct 13 2003 Dan Walsh <dwalsh@redhat.com> 5.0-26.sel

- Turn on SELinux


This update can be downloaded from:


092a4490b17447ec40cf1ebd1a90334c SRPMS/coreutils-5.0-34.1.src.rpm 9297d994a0837fca2d8727d6b63c33a6 i386/coreutils-5.0-34.1.i386.rpm 66bd92fef857384002c5e7a186c235ff i386/debug/coreutils-debuginfo-5.0-34.1.i386.rpm 9318557a41978705b3696c5ce7dc897c x86_64/coreutils-5.0-34.1.x86_64.rpm 5de0c3389976a04fbe8f40e36a5c6683 x86_64/debug/coreutils-debuginfo-5.0-34.1.x86_64.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.

Change Log

References

Fedora Update Notification FEDORA-2004-091 2004-03-10 Name : coreutils Version : 5.0 Release : 34.1 Summary : The GNU core utilities: a set of tools commonly used in shell scripts Description : These are the GNU core utilities. This package is the combination of the old GNU fileutils, sh-utils, and textutils packages.

Update Instructions

Severity
Name : coreutils
Version : 5.0
Release : 34.1
Summary : The GNU core utilities: a set of tools commonly used in shell scripts

Related News