Fedora Essential and Critical Security Patch Updates - Page 787

Find the information you need for your favorite open source distribution .

Fedora 9 Update: thunderbird-2.0.0.19-1.fc9

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Update to the new upstream Thunderbird 2.0.0.19 fixing multiple security issues: https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird-2.0/ Note: after the updated packages are installed, Thunderbird must be restarted for the update to take effect.

Fedora 10 Update: thunderbird-2.0.0.19-1.fc10

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Update to the new upstream Thunderbird 2.0.0.19 fixing multiple security issues: https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird-2.0/ Note: after the updated packages are installed, Thunderbird must be restarted for the update to take effect.

Fedora 8 Update: xterm-238-1.fc8

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This update fixes the following security issue: CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.

Fedora 8 Update: dovecot-1.0.15-16.fc8

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

new possibility to store ssl passwords in different file linked to dovecot.conf via !include_try directive change permissions of deliver and dovecot.conf to prevent possible password exposure change permissions of deliver and dovecot.conf to prevent possible password exposure

Fedora 10 Update: xterm-238-1.fc10

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This update fixes the following security issue: CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.

Fedora 8 Update: thunderbird-2.0.0.19-1.fc8

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Update to the new upstream Thunderbird 2.0.0.19 fixing multiple security issues: https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird-2.0/ Note: after the updated packages are installed, Thunderbird must be restarted for the update to take effect.

Fedora 9 Update: xterm-238-1.fc9

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This update fixes the following security issue: CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.

Fedora 9 Update: cups-1.3.9-2.fc9

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Security update to fix CVE-2008-5183. Also fixed in this update are a bug that caused cups-polld to fail to resolve hostnames, a bug that could cause libcups to get stuck in a loop, and incorrect form-feed handling in the textonly filter.

Fedora 10 Update: cups-1.3.9-4.fc10

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Security update to fix CVE-2008-5183. Also changed in this update: * a bug that caused cups-polld to fail to resolve hostnames has been fixed * a bug that could cause libcups to get stuck in a loop has been fixed * the dnssd backend has been removed as it is not working correctly and can prevent printers being added

Fedora 8 Update: clamav-0.92.1-4.fc8

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Security fixes from upstream 0.94 and 0.94.1: CVE-2008-3912 (#461461): Multiple out-of-memory NULL pointer dereferences CVE-2008-3913 (#461461): Fix memory leak in the error code path in freshclam CVE-2008-3914 (#461461): File descriptor leak on the error code path CVE-2008-5050 (#470783): get_unicode_name() off-by-one buffer overflow