Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Scientific Linux: CVE-2008-1036 Moderate: ICU Security Fix for SL5.x

Scientific Large Esm H446
Moderate: icu security update
Date: Wed, 11 Mar 2009 14:04:23 -0500
Reply-To: Troy Dawson 
Sender: Security Errata for Scientific Linux
 
From: Troy Dawson 
Subject: FASTBUGS for SL 5.x i386/x86_64
Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it."
 

The following FASTBUGS have been uploaded to

 i386:
device-mapper-multipath-0.4.7-23.el5_3.1.i386.rpm
gfs2-utils-0.1.53-1.el5_3.1.i386.rpm
htdig-3.2.0b6-11.el5.i386.rpm
htdig-web-3.2.0b6-11.el5.i386.rpm
kernel-module-openafs-2.6.18-128.1.1.el5-1.4.7-68.1.SL5.i686.rpm
kernel-module-openafs-2.6.18-128.1.1.el5PAE-1.4.7-68.1.SL5.i686.rpm
kernel-module-openafs-2.6.18-128.1.1.el5xen-1.4.7-68.1.SL5.i686.rpm
kpartx-0.4.7-23.el5_3.1.i386.rpm
mod_authz_ldap-0.26-9.el5.i386.rpm
openafs-1.4.7-68.1.SL5.i686.rpm
openafs-authlibs-1.4.7-68.1.SL5.i686.rpm
openafs-authlibs-devel-1.4.7-68.1.SL5.i686.rpm
openafs-client-1.4.7-68.1.SL5.i686.rpm
openafs-compat-1.4.7-68.1.SL5.i686.rpm
openafs-debug-1.4.7-68.1.SL5.i686.rpm
openafs-devel-1.4.7-68.1.SL5.i686.rpm
openafs-kernel-source-1.4.7-68.1.SL5.i686.rpm
openafs-kpasswd-1.4.7-68.1.SL5.i686.rpm
openafs-krb5-1.4.7-68.1.SL5.i686.rpm
openafs-server-1.4.7-68.1.SL5.i686.rpm
 x86_64:
device-mapper-multipath-0.4.7-23.el5_3.1.x86_64.rpm
gfs2-utils-0.1.53-1.el5_3.1.x86_64.rpm
htdig-3.2.0b6-11.el5.x86_64.rpm
htdig-web-3.2.0b6-11.el5.x86_64.rpm
kernel-module-openafs-2.6.18-128.1.1.el5-1.4.7-68.1.SL5.x86_64.rpm
kernel-module-openafs-2.6.18-128.1.1.el5xen-1.4.7-68.1.SL5.x86_64.rpm
kpartx-0.4.7-23.el5_3.1.x86_64.rpm
mod_authz_ldap-0.26-9.el5.x86_64.rpm
openafs-1.4.7-68.1.SL5.x86_64.rpm
openafs-authlibs-1.4.7-68.1.SL5.x86_64.rpm
openafs-authlibs-devel-1.4.7-68.1.SL5.x86_64.rpm
openafs-client-1.4.7-68.1.SL5.x86_64.rpm
openafs-compat-1.4.7-68.1.SL5.x86_64.rpm
openafs-debug-1.4.7-68.1.SL5.x86_64.rpm
openafs-devel-1.4.7-68.1.SL5.x86_64.rpm
openafs-kernel-source-1.4.7-68.1.SL5.x86_64.rpm
openafs-kpasswd-1.4.7-68.1.SL5.x86_64.rpm
openafs-krb5-1.4.7-68.1.SL5.x86_64.rpm
openafs-server-1.4.7-68.1.SL5.x86_64.rpm

-Connie Sieh
-Troy Dawson
Date: Thu, 12 Mar 2009 15:52:07 -0500
Reply-To: Troy Dawson 
Sender: Security Errata for Scientific Linux
 
From: Troy Dawson 
Subject: Security ERRATA Moderate: icu on SL5.x i386/x86_64
Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it."
 

Synopsis:	Moderate: icu security update
Issue date:	2009-03-12
CVE Names:	CVE-2008-1036

A flaw was found in the way ICU processed certain, invalid, encoded
data. If an application used ICU to decode malformed, multibyte,
character data, it may have been possible to bypass certain content
protection mechanisms, or display information in a manner misleading to
the user. (CVE-2008-1036)

SL 5.x

 SRPMS:
icu-3.6-5.11.2.src.rpm
 i386:
icu-3.6-5.11.2.i386.rpm
libicu-3.6-5.11.2.i386.rpm
libicu-devel-3.6-5.11.2.i386.rpm
libicu-doc-3.6-5.11.2.i386.rpm
 x86_64:
icu-3.6-5.11.2.x86_64.rpm
libicu-3.6-5.11.2.i386.rpm
libicu-3.6-5.11.2.x86_64.rpm
libicu-devel-3.6-5.11.2.i386.rpm
libicu-devel-3.6-5.11.2.x86_64.rpm
libicu-doc-3.6-5.11.2.x86_64.rpm

-Connie Sieh
-Troy Dawson