Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Date: Tue, 6 Nov 2012 09:31:57 -0600 Reply-To: Pat RieheckySender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: FASTBUGS for SL 6x i386, x86_64 now available MIME-Version: 1.0 The following FASTBUGS have been uploaded to i386: cc-eal4-config-rhel62-0.33-1.el6_2.noarch.rpm geronimo-specs-1.0-3.5.M2.el6.noarch.rpm geronimo-specs-compat-1.0-3.5.M2.el6.noarch.rpm glibc-2.12-1.80.el6_3.6.i686.rpm glibc-common-2.12-1.80.el6_3.6.i686.rpm glibc-devel-2.12-1.80.el6_3.6.i686.rpm glibc-headers-2.12-1.80.el6_3.6.i686.rpm glibc-static-2.12-1.80.el6_3.6.i686.rpm glibc-utils-2.12-1.80.el6_3.6.i686.rpm libblkid-2.17.2-12.7.el6_3.i686.rpm libblkid-devel-2.17.2-12.7.el6_3.i686.rpm libuuid-2.17.2-12.7.el6_3.i686.rpm libuuid-devel-2.17.2-12.7.el6_3.i686.rpm nscd-2.12-1.80.el6_3.6.i686.rpm python-Updateinfo-0.1.5-1.sl6.noarch.rpm rdma-3.3-4.el6_3.noarch.rpm resource-agents-3.9.2-12.el6_3.1.i686.rpm util-linux-ng-2.17.2-12.7.el6_3.i686.rpm uuidd-2.17.2-12.7.el6_3.i686.rpm x86_64: cc-eal4-config-rhel62-0.33-1.el6_2.noarch.rpm geronimo-specs-1.0-3.5.M2.el6.noarch.rpm geronimo-specs-compat-1.0-3.5.M2.el6.noarch.rpm glibc-2.12-1.80.el6_3.6.i686.rpm glibc-2.12-1.80.el6_3.6.x86_64.rpm glibc-common-2.12-1.80.el6_3.6.x86_64.rpm glibc-devel-2.12-1.80.el6_3.6.i686.rpm glibc-devel-2.12-1.80.el6_3.6.x86_64.rpm glibc-headers-2.12-1.80.el6_3.6.x86_64.rpm glibc-static-2.12-1.80.el6_3.6.i686.rpm glibc-static-2.12-1.80.el6_3.6.x86_64.rpm glibc-utils-2.12-1.80.el6_3.6.x86_64.rpm libblkid-2.17.2-12.7.el6_3.i686.rpm libblkid-2.17.2-12.7.el6_3.x86_64.rpm libblkid-devel-2.17.2-12.7.el6_3.i686.rpm libblkid-devel-2.17.2-12.7.el6_3.x86_64.rpm libuuid-2.17.2-12.7.el6_3.i686.rpm libuuid-2.17.2-12.7.el6_3.x86_64.rpm libuuid-devel-2.17.2-12.7.el6_3.i686.rpm libuuid-devel-2.17.2-12.7.el6_3.x86_64.rpm nscd-2.12-1.80.el6_3.6.x86_64.rpm python-Updateinfo-0.1.5-1.sl6.noarch.rpm rdma-3.3-4.el6_3.noarch.rpm resource-agents-3.9.2-12.el6_3.1.x86_64.rpm util-linux-ng-2.17.2-12.7.el6_3.i686.rpm util-linux-ng-2.17.2-12.7.el6_3.x86_64.rpm uuidd-2.17.2-12.7.el6_3.x86_64.rpm Date: Tue, 6 Nov 2012 09:31:59 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: FASTBUGS for SL 5x i386, x86_64 now available MIME-Version: 1.0 The following FASTBUGS have been uploaded to i386: iptables-1.3.5-9.2.el5_8.i386.rpm iptables-devel-1.3.5-9.2.el5_8.i386.rpm iptables-ipv6-1.3.5-9.2.el5_8.i386.rpm x86_64: iptables-1.3.5-9.2.el5_8.x86_64.rpm iptables-devel-1.3.5-9.2.el5_8.i386.rpm iptables-devel-1.3.5-9.2.el5_8.x86_64.rpm iptables-ipv6-1.3.5-9.2.el5_8.x86_64.rpm Date: Wed, 7 Nov 2012 10:19:41 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Moderate: kernel on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Moderate: kernel security and bug fix update Issue Date: 2012-11-06 CVE Numbers: CVE-2012-1568 CVE-2012-2133 CVE-2012-3400 CVE-2012-3511 -- This update fixes the following security issues: * A use-after-free flaw was found in the Linux kernel's memory management subsystem in the way quota handling for huge pages was performed. A local, unprivileged user could use this flaw to cause a denial of service or, potentially, escalate their privileges. (CVE-2012-2133, Moderate) * A use-after-free flaw was found in the madvise() system call implementation in the Linux kernel. A local, unprivileged user could use this flaw to cause a denial of service or, potentially, escalate their privileges. (CVE-2012-3511, Moderate) * It was found that when running a 32-bit binary that uses a large number of shared libraries, one of the libraries would always be loaded at a predictable address in memory. An attacker could use this flaw to bypass the Address Space Layout Randomization (ASLR) security feature. (CVE-2012-1568, Low) * Buffer overflow flaws were found in the udf_load_logicalvol() function in the Universal Disk Format (UDF) file system implementation in the Linux kernel. An attacker with physical access to a system could use these flaws to cause a denial of service or escalate their privileges. (CVE-2012-3400, Low) This update also fixes several bugs. The system must be rebooted for this update to take effect. -- SL6 x86_64 kernel-2.6.32-279.14.1.el6.x86_64.rpm kernel-debug-2.6.32-279.14.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-279.14.1.el6.x86_64.rpm kernel-devel-2.6.32-279.14.1.el6.x86_64.rpm kernel-headers-2.6.32-279.14.1.el6.x86_64.rpm perf-2.6.32-279.14.1.el6.x86_64.rpm python-perf-2.6.32-279.14.1.el6.x86_64.rpm i386 kernel-2.6.32-279.14.1.el6.i686.rpm kernel-debug-2.6.32-279.14.1.el6.i686.rpm kernel-debug-devel-2.6.32-279.14.1.el6.i686.rpm kernel-devel-2.6.32-279.14.1.el6.i686.rpm kernel-headers-2.6.32-279.14.1.el6.i686.rpm perf-2.6.32-279.14.1.el6.i686.rpm python-perf-2.6.32-279.14.1.el6.i686.rpm noarch kernel-doc-2.6.32-279.14.1.el6.noarch.rpm kernel-firmware-2.6.32-279.14.1.el6.noarch.rpm - Scientific Linux Development Team