Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Date: Fri, 6 Jan 2006 18:21:08 -0600 Reply-To: Connie SiehSender: Security Errata for Scientific Linux From: Connie Sieh Subject: Re: ERRATA for SL 301,302,303,304,305 i386 now available Comments: To: Jon Peatfield Comments: cc: This email address is being protected from spambots. You need JavaScript enabled to view it. In-Reply-To:They are available now. -connie sieh On Thu, 5 Jan 2006, Jon Peatfield wrote: > On Thu, 8 Dec 2005, Connie Sieh wrote: > > > The following ERRATA for SL 301,302,303,304,305 i386 are now available from: > > > > Since this message the Vendor has released 5 further EL3 security updates: > > RHSA-2006:0159 Moderate: httpd security update 2006-01-05 > RHSA-2005:840 Important: xpdf security update 2005-12-20 > RHSA-2005:843 Moderate: netpbm security update 2005-12-20 > RHSA-2005:878 Important: cups security update 2005-12-20 > RHSA-2005:881 Moderate: perl security update 2005-12-20 > > We don't use cups here, and actually use the xpdf from the EL4 tree (long > story!), so I rebuilt that myself anyway. > > On our local Vendor's mirror we see: > > perl-5.8.0-90.4.src.rpm > cups-1.1.17-13.3.34.src.rpm > netpbm-9.24-11.30.4.src.rpm > xpdf-2.02-9.8.src.rpm > > though not yet the httpd (though there is httpd-2.0.46-54.ent.src.rpm > which I never saw any announcement for!). httpd-2.0.46-56.ent.src.rpm is > already on the Vendor's ftp site so will probably hit our mirror tomorrow. > > I don't know if there is anything I can do to help with the testing/qa of > rebuilds of those packages. > > Or perhaps there is no-one else left still using SL3... If so I'll just > rebuild the packages for myself! > > -- Jon > Date: Fri, 6 Jan 2006 18:24:06 -0600 Reply-To: Connie Sieh Sender: Security Errata for Scientific Linux From: Connie Sieh Subject: ERRATA for SL 302,305 ia64 now available Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. The following ERRATA for SL 302,305 ia64 are now available from: Synopsis: Important: cups security update Advisory ID: RHSA-2005:878-01 CVE Names: CVE-2005-3191 CVE-2005-3192 CVE-2005-3193 cups-1.1.17-13.3.34.ia64.rpm cups-devel-1.1.17-13.3.34.ia64.rpm cups-libs-1.1.17-13.3.34.i386.rpm cups-libs-1.1.17-13.3.34.ia64.rpm Synopsis: Moderate: httpd security update Advisory ID: RHSA-2006:0159-01 CVE Names: CVE-2005-2970 CVE-2005-3352 CVE-2005-3357 httpd-2.0.46-56.ent.ia64.rpm httpd-devel-2.0.46-56.ent.ia64.rpm mod_ssl-2.0.46-56.ent.ia64.rpm Synopsis: Critical: mod_auth_pgsql security update Advisory ID: RHSA-2006:0164-01 CVE Names: CVE-2005-3656 mod_auth_pgsql-2.0.1-4.ent.1.ia64.rpm Synopsis: Moderate: netpbm security update Advisory ID: RHSA-2005:843-01 CVE Names: CVE-2005-3632 CVE-2005-3662 netpbm-9.24-11.30.4.i386.rpm netpbm-9.24-11.30.4.ia64.rpm netpbm-devel-9.24-11.30.4.ia64.rpm netpbm-progs-9.24-11.30.4.ia64.rpm Synopsis: Moderate: perl security update Advisory ID: RHSA-2005:881-01 CVE Names: CVE-2004-0976 CVE-2005-0448 CVE-2005-3962 perl-5.8.0-90.4.i386.rpm perl-5.8.0-90.4.ia64.rpm perl-CGI-2.89-90.4.ia64.rpm perl-CPAN-1.61-90.4.ia64.rpm perl-DB_File-1.806-90.4.ia64.rpm perl-suidperl-5.8.0-90.4.ia64.rpm Synopsis: Important: xpdf security update Advisory ID: RHSA-2005:840-02 CVE Names: CVE-2005-3191 CVE-2005-3192 CVE-2005-3193 xpdf-2.02-9.8.ia64.rpm -Jarek Polok -Connie Sieh