A flaw was discovered affecting Kate, the KDE advanced text editor, and Kwrite. Depending on system settings it may be possible for a local user to read the backup files created by Kate or Kwrite.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-594 2005-07-19 ---------------------------------------------------------------------Product : Fedora Core 3 Name : kdelibs Version : 3.3.1 Release : 2.14.FC3 Summary : K Desktop Environment - Libraries Description : Libraries for the K Desktop Environment. KDE Libraries include: kdecore (KDE core library), kdeui (user interface), kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking), kspell (spelling checker), jscript (javascript), kab (addressbook), kimgio (image manipulation). ---------------------------------------------------------------------Update Information: A flaw was discovered affecting Kate, the KDE advanced text editor, and Kwrite. Depending on system settings it may be possible for a local user to read the backup files created by Kate or Kwrite. The Common Vulnerabilities and Exposures project assigned the name CAN-2005-1920 to this issue. Users of Kate or Kwrite should update to this erratum package which contains a backported patch from the KDE security team correcting this issue. ---------------------------------------------------------------------* Tue Jul 12 2005 Than Ngo 6:3.3.1-2.14.FC3 - Kate backup file permission leak, apply patch to fix this vulnerabilities CAN-2005-1920 - apply cvs patch to get rid of warning "Mutex destroy failure", #160922 * Wed May 4 2005 Than Ngo 6:3.3.1-2.13.FC3 - new patch to fix kimgio input validation vulnerabilities, CAN-2005-1046 ---------------------------------------------------------------------This update can be downloaded from: 7c16ace15f5c3cc17833062448f9a479 SRPMS/kdelibs-3.3.1-2.14.FC3.src.rpm ab43dbc1f7f8bd0ab15abbd1b81fa8b7 x86_64/kdelibs-3.3.1-2.14.FC3.x86_64.rpm 00ff507d1d9629744a0750c5dc36c0ca x86_64/kdelibs-devel-3.3.1-2.14.FC3.x86_64.rpm 3aab6b8bf911cc5915392cafd78c5da3 x86_64/debug/kdelibs-debuginfo-3.3.1-2.14.FC3.x86_64.rpm 4ea59323607d5df364a9ba9a0bb9a6c7 x86_64/kdelibs-3.3.1-2.14.FC3.i386.rpm 4ea59323607d5df364a9ba9a0bb9a6c7 i386/kdelibs-3.3.1-2.14.FC3.i386.rpm 99f32b21eb7cf1c5a612356bcd935bcc i386/kdelibs-devel-3.3.1-2.14.FC3.i386.rpm a1baca56812419ec7f261291bb86084b i386/debug/kdelibs-debuginfo-3.3.1-2.14.FC3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-349 2005-04-30 ---------------------------------------------------------------------Product : Fedora Core 3 Name : gimp Version : 2.2.6 Release : 0.fc3.2 Summary : The GNU Image Manipulation Program Description : The GIMP (GNU Image Manipulation Program) is a powerful image composition and editing program, which can be extremely useful for creating logos and other graphics for webpages. The GIMP has many of the tools and filters you would expect to find in similar commercial offerings, and some interesting extras as well. The GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo. ---------------------------------------------------------------------* Wed Apr 27 2005 Jeremy Katz - 2:2.2.6-0.fc3.2 - silence %post * Mon Apr 11 2005 Nils Philippsen - version 2.2.6 * Tue Mar 29 2005 Nils Philippsen - revert gtk requirement change * Mon Mar 28 2005 Matthias Clasen - Rebuild against newer libexif * Mon Mar 28 2005 Christopher Aillon - rebuilt * Fri Mar 25 2005 Christopher Aillon - Update the GTK+ theme icon cache on (un)install * Tue Mar 22 2005 Nils Philippsen - install convenience symlinks for man pages * Fri Mar 11 2005 Nils Philippsen - don't refer to freefonts and sharefonts in %description ---------------------------------------------------------------------This update can be downloaded from: c2731e858ac2a14e6ac326ac7710178c SRPMS/gimp-2.2.6-0.fc3.2.src.rpm 42f2ac543515f4cd765b767c92c02808 x86_64/gimp-2.2.6-0.fc3.2.x86_64.rpm 269d4b543f0228cad99ef0ab7226c514 x86_64/gimp-devel-2.2.6-0.fc3.2.x86_64.rpm 35ef6c591b5b33e96896f3879234ffb9 x86_64/debug/gimp-debuginfo-2.2.6-0.fc3.2.x86_64.rpm 2c79c1e294c4b6ad76e37b06cc4a48e5 i386/gimp-2.2.6-0.fc3.2.i386.rpm 6518cbb6a638145c43e952a4c841d7c1 i386/gimp-devel-2.2.6-0.fc3.2.i386.rpm 41e53c71830b2c6db46b43af99e237e5 i386/debug/gimp-debuginfo-2.2.6-0.fc3.2.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
David Costanzo found a bug in the way GTK+ processes BMP images. It is possible that a specially crafted BMP image could cause a denial of service attack in applications linked against GTK+. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0891 to this issue.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-268 2005-03-30 ---------------------------------------------------------------------Product : Fedora Core 3 Name : gtk2 Version : 2.4.14 Release : 3.fc3 Summary : The GIMP ToolKit (GTK+), a library for creating GUIs for X. Description : GTK+ is a multi-platform toolkit for creating graphical user interfaces. Offering a complete set of widgets, GTK+ is suitable for projects ranging from small one-off tools to complete application suites. ---------------------------------------------------------------------Update Information: David Costanzo found a bug in the way GTK+ processes BMP images. It is possible that a specially crafted BMP image could cause a denial of service attack in applications linked against GTK+. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0891 to this issue. ---------------------------------------------------------------------* Mon Mar 28 2005 Matthias Clasen - 2.4.14-3.fc3 - Fix a double free in the bmp loader ---------------------------------------------------------------------This update can be downloaded from: 8c9c1a539e15629f204038597c57e75a SRPMS/gtk2-2.4.14-3.fc3.src.rpm 6491f2ebf95a79a0fafdd90256033189 x86_64/gtk2-2.4.14-3.fc3.x86_64.rpm 7facd80dc1c9ffc2e1745cb1505096c0 x86_64/gtk2-devel-2.4.14-3.fc3.x86_64.rpm 922ad9d8b24a4a580bca1f3461c1fcde x86_64/debug/gtk2-debuginfo-2.4.14-3.fc3.x86_64.rpm 9351093394765c34bc5a6b28e8db301b x86_64/gtk2-2.4.14-3.fc3.i386.rpm 9351093394765c34bc5a6b28e8db301b i386/gtk2-2.4.14-3.fc3.i386.rpm abb369e8b7dbcbe785a23d9cf52ca2a0 i386/gtk2-devel-2.4.14-3.fc3.i386.rpm 816116449734868587e069851dc57a62 i386/debug/gtk2-debuginfo-2.4.14-3.fc3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- --fedora-announce-list mailing list
The updated packages fix a bug which could cause segfaults when writing TIFF images to the standard output.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-221 2005-03-15 ---------------------------------------------------------------------Product : Fedora Core 3 Name : ImageMagick Version : 6.0.7.1 Release : 5.fc3 Summary : An X application for displaying and manipulating images. Description : ImageMagick(TM) is an image display and manipulation tool for the X Window System. ImageMagick can read and write JPEG, TIFF, PNM, GIF, and Photo CD image formats. It can resize, rotate, sharpen, color reduce, or add special effects to an image, and when finished you can either save the completed work in the original format or a different one. ImageMagick also includes command line programs for creating animated or transparent .gifs, creating composite images, creating thumbnail images, and more. ImageMagick is one of your choices if you need a program to manipulate and dis play images. If you want to develop your own applications which use ImageMagick code or APIs, you need to install ImageMagick-devel as well. ---------------------------------------------------------------------Update Information: The updated packages fix a bug which could cause segfaults when writing TIFF images to the standard output. ---------------------------------------------------------------------* Fri Mar 11 2005 Matthias Clasen - 6.0.7.1-5.fc3 - Make writing tiff to stdout work. * Tue Nov 23 2004 Jonathan Blandford - 6.0.7.1-4.1 - buffer overflow in ImageMagick's EXIF parser, CAN-2004-0981 ---------------------------------------------------------------------This update can be downloaded from: 639ebfb8335fd48a128189793f9f8574 SRPMS/ImageMagick-6.0.7.1-5.fc3.src.rpm 2c76c4007d9aecf1de9ada82b241d026 x86_64/ImageMagick-6.0.7.1-5.fc3.x86_64.rpm 5eeaf49a9f1b35c6681cc9c71749eab3 x86_64/ImageMagick-devel-6.0.7.1-5.fc3.x86_64.rpm 27f4b3ace89e2a10fb4d1e10f7ddb5e2 x86_64/ImageMagick-perl-6.0.7.1-5.fc3.x86_64.rpm d61a0a23b96776a4c37aa0e5cfeeee3f x86_64/ImageMagick-c+ +-6.0.7.1-5.fc3.x86_64.rpm b71232a0c0efec0000dbc85fc6a3a07a x86_64/ImageMagick-c++-devel-6.0.7.1-5.fc3.x86_64.rpm 21feb8f46c9a78bc2b95f8ea5f729046 x86_64/debug/ImageMagick-debuginfo-6.0.7.1-5.fc3.x86_64.rpm 8e5bced31488e81c6e6303f908851891 x86_64/ImageMagick-6.0.7.1-5.fc3.i386.rpm 40038a7a475d0ebec894172e05b870c4 x86_64/ImageMagick-c+ +-6.0.7.1-5.fc3.i386.rpm 8e5bced31488e81c6e6303f908851891 i386/ImageMagick-6.0.7.1-5.fc3.i386.rpm 377eaa945c95636108a4525548b8bb63 i386/ImageMagick-devel-6.0.7.1-5.fc3.i386.rpm 6c1f53ef2f9d83f099db56977d6387b3 i386/ImageMagick-perl-6.0.7.1-5.fc3.i386.rpm 40038a7a475d0ebec894172e05b870c4 i386/ImageMagick-c+ +-6.0.7.1-5.fc3.i386.rpm 20406dd1a81f466094e73965512377c6 i386/ImageMagick-c++-devel-6.0.7.1-5.fc3.i386.rpm 7e4f863d98bb8cc84da56c3e977ebcac i386/debug/ImageMagick-debuginfo-6.0.7.1-5.fc3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- --fedora-announce-list mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-207 2005-03-12 ---------------------------------------------------------------------Product : Fedora Core 3 Name : openoffice.org Version : 1.1.3 Release : 9.5.0.fc3 Summary : OpenOffice.org comprehensive office suite. Description : OpenOffice.org is an Open Source, community-developed, multi-platform office productivity suite. It includes the key desktop applications, such as a word processor, spreadsheet, presentation manager, formula editor and drawing program, with a user interface and feature set similar to other office suites. Sophisticated and flexible, OpenOffice.org also works transparently with a variety of file formats, including Microsoft Office. Usage: Simply type "ooffice" to run OpenOffice.org or select the requested component (Writer, Calc, Draw, Impress, etc.) from your desktop menu. The ooffice wrapper script will install a few files in the user's home, if necessary. The OpenOffice.org team hopes you enjoy working with OpenOffice.org! Note: Non-.vor templates covered under the GPL license. ---------------------------------------------------------------------Update Information: Some notable fixes since 6.5.fc3: - #rh139032# OO Writer crashes when enabling automatic hyphenation in Polish document - #rh146431# OOcalc: Printouts cut off at bottom of page when "fit printout to number of pages" used - #rh147257# Can't edit sequence of dates - #rh146883# Fill Series behavior broken in Calc - #rh144440# New auto-fill doesn't work right for date formatted cells - #rh126701# Incorrect Instructions in Help file for managing fonts - #rh140171# Auto Pilot Forms reports missing files - #rh146758# Cannot unhide rows in calc ---------------------------------------------------------------------* Thu Mar 3 2005 Dan Williams - 1.1.3-9 - #rh139032# OO Writer crashes whenenabling automatic hyphenation in Polish document * Wed Mar 2 2005 Dan Williams - 1.1.3-8 - Ensure that wrapper scripts have correct permissions * Mon Feb 28 2005 Dan Williams - 1.1.3-7 - #rh146431# OOcalc: Printouts cut off at bottom of page when "fit printout to number of pages" used - #rh147257# Can't edit sequence of dates - #rh146883# Fill Series behavior broken in Calc - #rh144440# New auto-fill doesn't work right for date formatted cells - #rh126701# Incorrect Instructions in Help file for managing fonts - #rh140171# Auto Pilot Forms reports missing files - #rh146758# Cannot unhide rows in calc ---------------------------------------------------------------------This update can be downloaded from: a3f80289046eefdd03bbff792389e1ec SRPMS/openoffice.org-1.1.3-9.5.0.fc3.src.rpm 6fdae704c985d8b9725af39715e47865 x86_64/openoffice.org-1.1.3-9.5.0.fc3.i386.rpm 9b6421a908d15f59b155abbae889a3b7 x86_64/openoffice.org-libs-1.1.3-9.5.0.fc3.i386.rpm ab16a7ecfd029543e51dbb82f61cb932 x86_64/openoffice.org-i18n-1.1.3-9.5.0.fc3.i386.rpm 6fdae704c985d8b9725af39715e47865 i386/openoffice.org-1.1.3-9.5.0.fc3.i386.rpm 9b6421a908d15f59b155abbae889a3b7 i386/openoffice.org-libs-1.1.3-9.5.0.fc3.i386.rpm ab16a7ecfd029543e51dbb82f61cb932 i386/openoffice.org-i18n-1.1.3-9.5.0.fc3.i386.rpm 35764843873f972e3a3024b04ac68723 i386/openoffice.org-kde-1.1.3-9.5.0.fc3.i386.rpm 5989e35e1a3dfc9c6c6327e00493c25b i386/debug/openoffice.org-debuginfo-1.1.3-9.5.0.fc3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.