Moderate: kernel security and bug fix update
Date: Tue, 6 Nov 2012 09:31:57 -0600
Reply-To: Pat Riehecky
Sender: Security Errata for Scientific Linux
From: Pat Riehecky
Organization: Fermilab
Subject: FASTBUGS for SL 6x i386, x86_64 now available
MIME-Version: 1.0
The following FASTBUGS have been uploaded to
i386:
cc-eal4-config-rhel62-0.33-1.el6_2.noarch.rpm
geronimo-specs-1.0-3.5.M2.el6.noarch.rpm
geronimo-specs-compat-1.0-3.5.M2.el6.noarch.rpm
glibc-2.12-1.80.el6_3.6.i686.rpm
glibc-common-2.12-1.80.el6_3.6.i686.rpm
glibc-devel-2.12-1.80.el6_3.6.i686.rpm
glibc-headers-2.12-1.80.el6_3.6.i686.rpm
glibc-static-2.12-1.80.el6_3.6.i686.rpm
glibc-utils-2.12-1.80.el6_3.6.i686.rpm
libblkid-2.17.2-12.7.el6_3.i686.rpm
libblkid-devel-2.17.2-12.7.el6_3.i686.rpm
libuuid-2.17.2-12.7.el6_3.i686.rpm
libuuid-devel-2.17.2-12.7.el6_3.i686.rpm
nscd-2.12-1.80.el6_3.6.i686.rpm
python-Updateinfo-0.1.5-1.sl6.noarch.rpm
rdma-3.3-4.el6_3.noarch.rpm
resource-agents-3.9.2-12.el6_3.1.i686.rpm
util-linux-ng-2.17.2-12.7.el6_3.i686.rpm
uuidd-2.17.2-12.7.el6_3.i686.rpm
x86_64:
cc-eal4-config-rhel62-0.33-1.el6_2.noarch.rpm
geronimo-specs-1.0-3.5.M2.el6.noarch.rpm
geronimo-specs-compat-1.0-3.5.M2.el6.noarch.rpm
glibc-2.12-1.80.el6_3.6.i686.rpm
glibc-2.12-1.80.el6_3.6.x86_64.rpm
glibc-common-2.12-1.80.el6_3.6.x86_64.rpm
glibc-devel-2.12-1.80.el6_3.6.i686.rpm
glibc-devel-2.12-1.80.el6_3.6.x86_64.rpm
glibc-headers-2.12-1.80.el6_3.6.x86_64.rpm
glibc-static-2.12-1.80.el6_3.6.i686.rpm
glibc-static-2.12-1.80.el6_3.6.x86_64.rpm
glibc-utils-2.12-1.80.el6_3.6.x86_64.rpm
libblkid-2.17.2-12.7.el6_3.i686.rpm
libblkid-2.17.2-12.7.el6_3.x86_64.rpm
libblkid-devel-2.17.2-12.7.el6_3.i686.rpm
libblkid-devel-2.17.2-12.7.el6_3.x86_64.rpm
libuuid-2.17.2-12.7.el6_3.i686.rpm
libuuid-2.17.2-12.7.el6_3.x86_64.rpm
libuuid-devel-2.17.2-12.7.el6_3.i686.rpm
libuuid-devel-2.17.2-12.7.el6_3.x86_64.rpm
nscd-2.12-1.80.el6_3.6.x86_64.rpm
python-Updateinfo-0.1.5-1.sl6.noarch.rpm
rdma-3.3-4.el6_3.noarch.rpm
resource-agents-3.9.2-12.el6_3.1.x86_64.rpm
util-linux-ng-2.17.2-12.7.el6_3.i686.rpm
util-linux-ng-2.17.2-12.7.el6_3.x86_64.rpm
uuidd-2.17.2-12.7.el6_3.x86_64.rpm
Date: Tue, 6 Nov 2012 09:31:59 -0600
Reply-To: Pat Riehecky
Sender: Security Errata for Scientific Linux
From: Pat Riehecky
Organization: Fermilab
Subject: FASTBUGS for SL 5x i386, x86_64 now available
MIME-Version: 1.0
The following FASTBUGS have been uploaded to
i386:
iptables-1.3.5-9.2.el5_8.i386.rpm
iptables-devel-1.3.5-9.2.el5_8.i386.rpm
iptables-ipv6-1.3.5-9.2.el5_8.i386.rpm
x86_64:
iptables-1.3.5-9.2.el5_8.x86_64.rpm
iptables-devel-1.3.5-9.2.el5_8.i386.rpm
iptables-devel-1.3.5-9.2.el5_8.x86_64.rpm
iptables-ipv6-1.3.5-9.2.el5_8.x86_64.rpm
Date: Wed, 7 Nov 2012 10:19:41 -0600
Reply-To: Pat Riehecky
Sender: Security Errata for Scientific Linux
From: Pat Riehecky
Organization: Fermilab
Subject: Security ERRATA Moderate: kernel on SL6.x i386/x86_64
MIME-Version: 1.0
Synopsis: Moderate: kernel security and bug fix update
Issue Date: 2012-11-06
CVE Numbers: CVE-2012-1568
CVE-2012-2133
CVE-2012-3400
CVE-2012-3511
--
This update fixes the following security issues:
* A use-after-free flaw was found in the Linux kernel's memory management
subsystem in the way quota handling for huge pages was performed. A local,
unprivileged user could use this flaw to cause a denial of service or,
potentially, escalate their privileges. (CVE-2012-2133, Moderate)
* A use-after-free flaw was found in the madvise() system call
implementation in the Linux kernel. A local, unprivileged user could use
this flaw to cause a denial of service or, potentially, escalate their
privileges. (CVE-2012-3511, Moderate)
* It was found that when running a 32-bit binary that uses a large number
of shared libraries, one of the libraries would always be loaded at a
predictable address in memory. An attacker could use this flaw to bypass
the Address Space Layout Randomization (ASLR) security feature.
(CVE-2012-1568, Low)
* Buffer overflow flaws were found in the udf_load_logicalvol() function
in the Universal Disk Format (UDF) file system implementation in the Linux
kernel. An attacker with physical access to a system could use these flaws
to cause a denial of service or escalate their privileges. (CVE-2012-3400,
Low)
This update also fixes several bugs.
The system must be rebooted for this update to take effect.
--
SL6
x86_64
kernel-2.6.32-279.14.1.el6.x86_64.rpm
kernel-debug-2.6.32-279.14.1.el6.x86_64.rpm
kernel-debug-devel-2.6.32-279.14.1.el6.x86_64.rpm
kernel-devel-2.6.32-279.14.1.el6.x86_64.rpm
kernel-headers-2.6.32-279.14.1.el6.x86_64.rpm
perf-2.6.32-279.14.1.el6.x86_64.rpm
python-perf-2.6.32-279.14.1.el6.x86_64.rpm
i386
kernel-2.6.32-279.14.1.el6.i686.rpm
kernel-debug-2.6.32-279.14.1.el6.i686.rpm
kernel-debug-devel-2.6.32-279.14.1.el6.i686.rpm
kernel-devel-2.6.32-279.14.1.el6.i686.rpm
kernel-headers-2.6.32-279.14.1.el6.i686.rpm
perf-2.6.32-279.14.1.el6.i686.rpm
python-perf-2.6.32-279.14.1.el6.i686.rpm
noarch
kernel-doc-2.6.32-279.14.1.el6.noarch.rpm
kernel-firmware-2.6.32-279.14.1.el6.noarch.rpm
- Scientific Linux Development Team