Date: Tue, 25 Aug 2009 15:29:29 -0500 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: FASTBUGS for SL 4.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" The following FASTBUGS have been uploaded to i386: syslinux-2.11-2.i386.rpm x86_64: syslinux-2.11-2.x86_64.rpm -Connie Sieh -Troy Dawson Date: Tue, 25 Aug 2009 15:35:41 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: FASTBUGS for SL 5.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" The following FASTBUGS have been uploaded to i386: cups-1.2.4-11.14.el5.i386.rpm cups-devel-1.2.4-11.14.el5.i386.rpm cups-libs-1.2.4-11.14.el5.i386.rpm cups-lpd-1.2.4-11.14.el5.i386.rpm ksh-20080202-2.el5_3.1.i386.rpm net-snmp-5.3.2.2-5.el5_3.2.i386.rpm net-snmp-devel-5.3.2.2-5.el5_3.2.i386.rpm net-snmp-libs-5.3.2.2-5.el5_3.2.i386.rpm net-snmp-perl-5.3.2.2-5.el5_3.2.i386.rpm net-snmp-utils-5.3.2.2-5.el5_3.2.i386.rpm x86_64: cups-1.2.4-11.14.el5.x86_64.rpm cups-devel-1.2.4-11.14.el5.i386.rpm cups-devel-1.2.4-11.14.el5.x86_64.rpm cups-libs-1.2.4-11.14.el5.i386.rpm cups-libs-1.2.4-11.14.el5.x86_64.rpm cups-lpd-1.2.4-11.14.el5.x86_64.rpm ksh-20080202-2.el5_3.1.x86_64.rpm net-snmp-5.3.2.2-5.el5_3.2.x86_64.rpm net-snmp-devel-5.3.2.2-5.el5_3.2.i386.rpm net-snmp-devel-5.3.2.2-5.el5_3.2.x86_64.rpm net-snmp-libs-5.3.2.2-5.el5_3.2.i386.rpm net-snmp-libs-5.3.2.2-5.el5_3.2.x86_64.rpm net-snmp-perl-5.3.2.2-5.el5_3.2.x86_64.rpm net-snmp-utils-5.3.2.2-5.el5_3.2.x86_64.rpm -Connie Sieh -Troy Dawson Date: Thu, 27 Aug 2009 13:00:29 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Moderate: gnutls on SL4.x, SL5.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Moderate: gnutls security update Issue date: 2009-08-26 CVE Names: CVE-2009-2730 CVE-2009-2730 gnutls: incorrect verification of SSL certificate with NUL in name (GNUTLS-SA-2009-4) A flaw was discovered in the way GnuTLS handles NULL characters in certain fields of X.509 certificates. If an attacker is able to get a carefully-crafted certificate signed by a Certificate Authority trusted by an application using GnuTLS, the attacker could use the certificate during a man-in-the-middle attack and potentially confuse the application into accepting it by mistake. (CVE-2009-2730) SL 4.x SRPMS: gnutls-1.0.20-4.el4_8.3.src.rpm i386: gnutls-1.0.20-4.el4_8.3.i386.rpm gnutls-devel-1.0.20-4.el4_8.3.i386.rpm x86_64: gnutls-1.0.20-4.el4_8.3.i386.rpm gnutls-1.0.20-4.el4_8.3.x86_64.rpm gnutls-devel-1.0.20-4.el4_8.3.x86_64.rpm SL 5.x SRPMS: gnutls-1.4.1-3.el5_3.5.src.rpm i386: gnutls-1.4.1-3.el5_3.5.i386.rpm gnutls-devel-1.4.1-3.el5_3.5.i386.rpm gnutls-utils-1.4.1-3.el5_3.5.i386.rpm x86_64: gnutls-1.4.1-3.el5_3.5.i386.rpm gnutls-1.4.1-3.el5_3.5.x86_64.rpm gnutls-devel-1.4.1-3.el5_3.5.i386.rpm gnutls-devel-1.4.1-3.el5_3.5.x86_64.rpm gnutls-utils-1.4.1-3.el5_3.5.x86_64.rpm -Connie Sieh -Troy Dawson