Updated cups packages that fix a security issue are now available for Red Hat Enterprise Linux 3. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: cups security update Advisory ID: RHSA-2008:1028-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2008:1028.html Issue date: 2008-12-15 CVE Names: CVE-2008-5286 ==================================================================== 1. Summary: Updated cups packages that fix a security issue are now available for Red Hat Enterprise Linux 3. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Description: The Common UNIX® Printing System (CUPS) provides a portable printing layer for UNIX operating systems. An integer overflow flaw, leading to a heap buffer overflow, was discovered in the Portable Network Graphics (PNG) decoding routines used by the CUPS image-converting filters, "imagetops" and "imagetoraster". An attacker could create a malicious PNG file that could, potentially, execute arbitrary code as the "lp" user if the file was printed. (CVE-2008-5286) CUPS users should upgrade to these updated packages, which contain a backported patch to correct this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5.Package List: Red Hat Enterprise Linux AS version 3: Source: i386: cups-1.1.17-13.3.55.i386.rpm cups-debuginfo-1.1.17-13.3.55.i386.rpm cups-devel-1.1.17-13.3.55.i386.rpm cups-libs-1.1.17-13.3.55.i386.rpm ia64: cups-1.1.17-13.3.55.ia64.rpm cups-debuginfo-1.1.17-13.3.55.i386.rpm cups-debuginfo-1.1.17-13.3.55.ia64.rpm cups-devel-1.1.17-13.3.55.ia64.rpm cups-libs-1.1.17-13.3.55.i386.rpm cups-libs-1.1.17-13.3.55.ia64.rpm ppc: cups-1.1.17-13.3.55.ppc.rpm cups-debuginfo-1.1.17-13.3.55.ppc.rpm cups-debuginfo-1.1.17-13.3.55.ppc64.rpm cups-devel-1.1.17-13.3.55.ppc.rpm cups-libs-1.1.17-13.3.55.ppc.rpm cups-libs-1.1.17-13.3.55.ppc64.rpm s390: cups-1.1.17-13.3.55.s390.rpm cups-debuginfo-1.1.17-13.3.55.s390.rpm cups-devel-1.1.17-13.3.55.s390.rpm cups-libs-1.1.17-13.3.55.s390.rpm s390x: cups-1.1.17-13.3.55.s390x.rpm cups-debuginfo-1.1.17-13.3.55.s390.rpm cups-debuginfo-1.1.17-13.3.55.s390x.rpm cups-devel-1.1.17-13.3.55.s390x.rpm cups-libs-1.1.17-13.3.55.s390.rpm cups-libs-1.1.17-13.3.55.s390x.rpm x86_64: cups-1.1.17-13.3.55.x86_64.rpm cups-debuginfo-1.1.17-13.3.55.i386.rpm cups-debuginfo-1.1.17-13.3.55.x86_64.rpm cups-devel-1.1.17-13.3.55.x86_64.rpm cups-libs-1.1.17-13.3.55.i386.rpm cups-libs-1.1.17-13.3.55.x86_64.rpm Red Hat Desktop version 3: Source: i386: cups-1.1.17-13.3.55.i386.rpm cups-debuginfo-1.1.17-13.3.55.i386.rpm cups-devel-1.1.17-13.3.55.i386.rpm cups-libs-1.1.17-13.3.55.i386.rpm x86_64: cups-1.1.17-13.3.55.x86_64.rpm cups-debuginfo-1.1.17-13.3.55.i386.rpm cups-debuginfo-1.1.17-13.3.55.x86_64.rpm cups-devel-1.1.17-13.3.55.x86_64.rpm cups-libs-1.1.17-13.3.55.i386.rpm cups-libs-1.1.17-13.3.55.x86_64.rpm Red Hat Enterprise Linux ES version3: Source: i386: cups-1.1.17-13.3.55.i386.rpm cups-debuginfo-1.1.17-13.3.55.i386.rpm cups-devel-1.1.17-13.3.55.i386.rpm cups-libs-1.1.17-13.3.55.i386.rpm ia64: cups-1.1.17-13.3.55.ia64.rpm cups-debuginfo-1.1.17-13.3.55.i386.rpm cups-debuginfo-1.1.17-13.3.55.ia64.rpm cups-devel-1.1.17-13.3.55.ia64.rpm cups-libs-1.1.17-13.3.55.i386.rpm cups-libs-1.1.17-13.3.55.ia64.rpm x86_64: cups-1.1.17-13.3.55.x86_64.rpm cups-debuginfo-1.1.17-13.3.55.i386.rpm cups-debuginfo-1.1.17-13.3.55.x86_64.rpm cups-devel-1.1.17-13.3.55.x86_64.rpm cups-libs-1.1.17-13.3.55.i386.rpm cups-libs-1.1.17-13.3.55.x86_64.rpm Red Hat Enterprise Linux WS version 3: Source: i386: cups-1.1.17-13.3.55.i386.rpm cups-debuginfo-1.1.17-13.3.55.i386.rpm cups-devel-1.1.17-13.3.55.i386.rpm cups-libs-1.1.17-13.3.55.i386.rpm ia64: cups-1.1.17-13.3.55.ia64.rpm cups-debuginfo-1.1.17-13.3.55.i386.rpm cups-debuginfo-1.1.17-13.3.55.ia64.rpm cups-devel-1.1.17-13.3.55.ia64.rpm cups-libs-1.1.17-13.3.55.i386.rpm cups-libs-1.1.17-13.3.55.ia64.rpm x86_64: cups-1.1.17-13.3.55.x86_64.rpm cups-debuginfo-1.1.17-13.3.55.i386.rpm cups-debuginfo-1.1.17-13.3.55.x86_64.rpm cups-devel-1.1.17-13.3.55.x86_64.rpm cups-libs-1.1.17-13.3.55.i386.rpm cups-libs-1.1.17-13.3.55.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 6. References: https://www.cve.org/CVERecord?id=CVE-2008-5286 https://access.redhat.com/security/updates/classification#moderate 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2008 Red Hat, Inc. . Recent updates to CUPS packages for Red Hat Enterprise Linux have fixed a significant security vulnerability, enhancing the protection of the system.. CUPS Update, Red Hat Enterprise, Moderate Risk, Security Patch. . LinuxSecurity.com Team
An updated lesstif package that fixes flaws in the Xpm library is now available for Red Hat Enterprise Linux 2.1.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated lesstif package fixes image vulnerability Advisory ID: RHSA-2005:004-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:004.html Issue date: 2005-01-12 Updated on: 2005-01-12 Product: Red Hat Enterprise Linux CVE Names: CAN-2004-0687 CAN-2004-0688 CAN-2004-0914 - ---------------------------------------------------------------------1. Summary: An updated lesstif package that fixes flaws in the Xpm library is now available for Red Hat Enterprise Linux 2.1. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 3. Problem description: LessTif provides libraries which implement the Motif industry standard graphical user interface. During a source code audit, Chris Evans discovered several stack overflow flaws and an integer overflow flaw in the libXpm library used to decode XPM (X PixMap) images. A vulnerable version of this library was found within Lesstif. An attacker could create a carefully crafted XPM file which would cause an application to crash or potentially execute arbitrary code if opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0687,CAN-2004-0688, and CAN-2004-0914 to these issues. Users of LessTif are advised to upgrade to this erratum package, which contains backported security patches to the embedded libXpm library. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download andupdate your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 135076 - CAN-2004-0687 buffer overflows in libXpm 135079 - CAN-2004-0688 integer overflows in libXpm (CAN-2004-0914) 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 59665437349ef5bad3f7b373e1dd6001 lesstif-0.93.15-4.AS21.4.src.rpm i386: 9c49c91a9d0668505b1218b60705bd56 lesstif-0.93.15-4.AS21.4.i386.rpm c9b3a89ad94af645dba780da9e3d86bb lesstif-devel-0.93.15-4.AS21.4.i386.rpm ia64: 9345984ef75ef4878bffe381e6964647 lesstif-0.93.15-4.AS21.4.ia64.rpm 09670ebdb668df8c2281eea87ce42ce8 lesstif-devel-0.93.15-4.AS21.4.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 59665437349ef5bad3f7b373e1dd6001 lesstif-0.93.15-4.AS21.4.src.rpm ia64: 9345984ef75ef4878bffe381e6964647 lesstif-0.93.15-4.AS21.4.ia64.rpm 09670ebdb668df8c2281eea87ce42ce8 lesstif-devel-0.93.15-4.AS21.4.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: 59665437349ef5bad3f7b373e1dd6001 lesstif-0.93.15-4.AS21.4.src.rpm i386: 9c49c91a9d0668505b1218b60705bd56 lesstif-0.93.15-4.AS21.4.i386.rpm c9b3a89ad94af645dba780da9e3d86bb lesstif-devel-0.93.15-4.AS21.4.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 59665437349ef5bad3f7b373e1dd6001 lesstif-0.93.15-4.AS21.4.src.rpm i386: 9c49c91a9d0668505b1218b60705bd56 lesstif-0.93.15-4.AS21.4.i386.rpm c9b3a89ad94af645dba780da9e3d86bb lesstif-devel-0.93.15-4.AS21.4.i386.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7.References: https://www.cve.org/CVERecord?id=CAN-2004-0687 https://www.cve.org/CVERecord?id=CAN-2004-0688 https://www.cve.org/CVERecord?id=CAN-2004-0914 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2005 Red Hat, Inc. . Improvements addressing visual anomalies in the lesstif toolkit on Red Hat Enterprise Linux bolster overall security and system reliability.. Lesstif Package, Image Flaw, Red Hat Security. . Severity: Important. LinuxSecurity.com Team
Updated openmotif packages that fix flaws in the Xpm image library are now available.. --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated openmotif packages fix image vulnerability Advisory ID: RHSA-2004:537-01 Advisory URL: https://access.redhat.com/errata/RHSA-2004:537.html Issue date: 2004-12-02 Updated on: 2004-12-02 Product: Red Hat Enterprise Linux CVE Names: CAN-2004-0687 CAN-2004-0688 CAN-2004-0914 ---------------------------------------------------------------------1. Summary: Updated openmotif packages that fix flaws in the Xpm image library are now available. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: OpenMotif provides libraries which implement the Motif industry standard graphical user interface. During a source code audit, Chris Evans and others discovered several stack overflow flaws and an integer overflow flaw in the libXpm library used to decode XPM (X PixMap) images. A vulnerable version of this library was found within OpenMotif. An attacker could create a carefully crafted XPM file which would cause an application to crash or potentially execute arbitrary code if opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0687, CAN-2004-0688, and CAN-2004-0914 to these issues. Users of OpenMotif are advised to upgrade to these erratum packages, which contain backported security patches to theembedded libXpm library. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/ for more info): 134631 - CAN-2004-0687 libxpm flaws affect OpenMotif (CAN-2004-0688, CAN-2004-0914) 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 934693e91035b60ef8d5c9999c1b2358 openmotif-2.1.30-13.21AS.4.src.rpm i386: c931f464eff5908b6f4aec50b0cb41a2 openmotif-2.1.30-13.21AS.4.i386.rpm e2e94a9a588d2d7f5a2c5f802d24ae7b openmotif-devel-2.1.30-13.21AS.4.i386.rpm ia64: 7bf67d78ffdab37daa13d5ff6bc52f31 openmotif-2.1.30-13.21AS.4.ia64.rpm a6adcf1007eaca5b48667cde4e509087 openmotif-devel-2.1.30-13.21AS.4.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 934693e91035b60ef8d5c9999c1b2358 openmotif-2.1.30-13.21AS.4.src.rpm ia64: 7bf67d78ffdab37daa13d5ff6bc52f31 openmotif-2.1.30-13.21AS.4.ia64.rpm a6adcf1007eaca5b48667cde4e509087 openmotif-devel-2.1.30-13.21AS.4.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: 934693e91035b60ef8d5c9999c1b2358 openmotif-2.1.30-13.21AS.4.src.rpm i386: c931f464eff5908b6f4aec50b0cb41a2 openmotif-2.1.30-13.21AS.4.i386.rpm e2e94a9a588d2d7f5a2c5f802d24ae7b openmotif-devel-2.1.30-13.21AS.4.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 934693e91035b60ef8d5c9999c1b2358 openmotif-2.1.30-13.21AS.4.src.rpm i386: c931f464eff5908b6f4aec50b0cb41a2 openmotif-2.1.30-13.21AS.4.i386.rpm e2e94a9a588d2d7f5a2c5f802d24ae7b openmotif-devel-2.1.30-13.21AS.4.i386.rpm Red Hat Enterprise LinuxAS version 3: SRPMS: 967c888fcf57ff1a758f6971ae1fd6a5 openmotif-2.2.3-4.RHEL3.4.src.rpm a0ca6fe8bffb142ba092cf8b6ae45f75 openmotif21-2.1.30-9.RHEL3.4.src.rpm i386: 24e7c10209eb33424076763c6ec48a1f openmotif-2.2.3-4.RHEL3.4.i386.rpm d630df4ca693f4aebfdb491a0d7aff0a openmotif-devel-2.2.3-4.RHEL3.4.i386.rpm 30c7228d526c6697be8b2ffe3f334cdf openmotif21-2.1.30-9.RHEL3.4.i386.rpm ia64: 74fefe0a77b7bfb3232855481f1fc083 openmotif-2.2.3-4.RHEL3.4.ia64.rpm 24e7c10209eb33424076763c6ec48a1f openmotif-2.2.3-4.RHEL3.4.i386.rpm f23a071559437772dee63c6e0a87e47d openmotif-devel-2.2.3-4.RHEL3.4.ia64.rpm 23c9973a64d22a435622e9a439cf32a8 openmotif21-2.1.30-9.RHEL3.4.ia64.rpm ppc: 89c616208ed1094ca3e38f617b553d29 openmotif-2.2.3-4.RHEL3.4.ppc.rpm b32ab945f39635238fe265fcf7264d6a openmotif-2.2.3-4.RHEL3.4.ppc64.rpm 82631cc7816ba3c492fcdba9198b4235 openmotif-devel-2.2.3-4.RHEL3.4.ppc.rpm s390: 0444b7e5f530bc3110de99a0b967cf29 openmotif-2.2.3-4.RHEL3.4.s390.rpm 406b810f6b0dd6c868d60ebdb9fbd7da openmotif-devel-2.2.3-4.RHEL3.4.s390.rpm s390x: 91fb177f7c04c121bfe8b54696447353 openmotif-2.2.3-4.RHEL3.4.s390x.rpm 0444b7e5f530bc3110de99a0b967cf29 openmotif-2.2.3-4.RHEL3.4.s390.rpm 2308d16cee4d5ea0b535ecbefcec2c1a openmotif-devel-2.2.3-4.RHEL3.4.s390x.rpm x86_64: 4578050dd8b7e640444524c04115a3b8 openmotif-2.2.3-4.RHEL3.4.x86_64.rpm 24e7c10209eb33424076763c6ec48a1f openmotif-2.2.3-4.RHEL3.4.i386.rpm f793165407f112b0486cf9e029bd1c04 openmotif-devel-2.2.3-4.RHEL3.4.x86_64.rpm 30c7228d526c6697be8b2ffe3f334cdf openmotif21-2.1.30-9.RHEL3.4.i386.rpm Red Hat Desktop version 3: SRPMS: 967c888fcf57ff1a758f6971ae1fd6a5 openmotif-2.2.3-4.RHEL3.4.src.rpm a0ca6fe8bffb142ba092cf8b6ae45f75 openmotif21-2.1.30-9.RHEL3.4.src.rpm i386: 24e7c10209eb33424076763c6ec48a1f openmotif-2.2.3-4.RHEL3.4.i386.rpm d630df4ca693f4aebfdb491a0d7aff0a openmotif-devel-2.2.3-4.RHEL3.4.i386.rpm 30c7228d526c6697be8b2ffe3f334cdf openmotif21-2.1.30-9.RHEL3.4.i386.rpm x86_64: 4578050dd8b7e640444524c04115a3b8 openmotif-2.2.3-4.RHEL3.4.x86_64.rpm 24e7c10209eb33424076763c6ec48a1f openmotif-2.2.3-4.RHEL3.4.i386.rpm f793165407f112b0486cf9e029bd1c04 openmotif-devel-2.2.3-4.RHEL3.4.x86_64.rpm 30c7228d526c6697be8b2ffe3f334cdf openmotif21-2.1.30-9.RHEL3.4.i386.rpm Red Hat Enterprise Linux ES version 3: SRPMS: 967c888fcf57ff1a758f6971ae1fd6a5 openmotif-2.2.3-4.RHEL3.4.src.rpm a0ca6fe8bffb142ba092cf8b6ae45f75 openmotif21-2.1.30-9.RHEL3.4.src.rpm i386: 24e7c10209eb33424076763c6ec48a1f openmotif-2.2.3-4.RHEL3.4.i386.rpm d630df4ca693f4aebfdb491a0d7aff0a openmotif-devel-2.2.3-4.RHEL3.4.i386.rpm 30c7228d526c6697be8b2ffe3f334cdf openmotif21-2.1.30-9.RHEL3.4.i386.rpm ia64: 74fefe0a77b7bfb3232855481f1fc083 openmotif-2.2.3-4.RHEL3.4.ia64.rpm 24e7c10209eb33424076763c6ec48a1f openmotif-2.2.3-4.RHEL3.4.i386.rpm f23a071559437772dee63c6e0a87e47d openmotif-devel-2.2.3-4.RHEL3.4.ia64.rpm 23c9973a64d22a435622e9a439cf32a8 openmotif21-2.1.30-9.RHEL3.4.ia64.rpm x86_64: 4578050dd8b7e640444524c04115a3b8 openmotif-2.2.3-4.RHEL3.4.x86_64.rpm 24e7c10209eb33424076763c6ec48a1f openmotif-2.2.3-4.RHEL3.4.i386.rpm f793165407f112b0486cf9e029bd1c04 openmotif-devel-2.2.3-4.RHEL3.4.x86_64.rpm 30c7228d526c6697be8b2ffe3f334cdf openmotif21-2.1.30-9.RHEL3.4.i386.rpm Red Hat Enterprise Linux WS version 3: SRPMS: 967c888fcf57ff1a758f6971ae1fd6a5 openmotif-2.2.3-4.RHEL3.4.src.rpm a0ca6fe8bffb142ba092cf8b6ae45f75 openmotif21-2.1.30-9.RHEL3.4.src.rpm i386: 24e7c10209eb33424076763c6ec48a1f openmotif-2.2.3-4.RHEL3.4.i386.rpm d630df4ca693f4aebfdb491a0d7aff0a openmotif-devel-2.2.3-4.RHEL3.4.i386.rpm 30c7228d526c6697be8b2ffe3f334cdf openmotif21-2.1.30-9.RHEL3.4.i386.rpm ia64: 74fefe0a77b7bfb3232855481f1fc083 openmotif-2.2.3-4.RHEL3.4.ia64.rpm 24e7c10209eb33424076763c6ec48a1f openmotif-2.2.3-4.RHEL3.4.i386.rpm f23a071559437772dee63c6e0a87e47d openmotif-devel-2.2.3-4.RHEL3.4.ia64.rpm 23c9973a64d22a435622e9a439cf32a8 openmotif21-2.1.30-9.RHEL3.4.ia64.rpm x86_64: 4578050dd8b7e640444524c04115a3b8 openmotif-2.2.3-4.RHEL3.4.x86_64.rpm 24e7c10209eb33424076763c6ec48a1f openmotif-2.2.3-4.RHEL3.4.i386.rpm f793165407f112b0486cf9e029bd1c04 openmotif-devel-2.2.3-4.RHEL3.4.x86_64.rpm 30c7228d526c6697be8b2ffe3f334cdf openmotif21-2.1.30-9.RHEL3.4.i386.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from 7. References: https://www.cve.org/CVERecord?id=CAN-2004-0687 https://www.cve.org/CVERecord?id=CAN-2004-0688 https://www.cve.org/CVERecord?id=CAN-2004-0914 8. Contact: The Red Hat security contact is . More contact details at Copyright 2004 Red Hat, Inc. . Ubuntu has launched a significant patch for the libxrender library to mitigate potential vulnerabilities and enhance overall system integrity and safety.. OpenMotif Packages, Image Flaw, Red Hat Update, Library Security, Stack Overflow. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.