Updated fuse packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: fuse security update Advisory ID: RHSA-2011:1083-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:1083.html Issue date: 2011-07-20 CVE Names: CVE-2010-3879 CVE-2011-0541 CVE-2011-0542 CVE-2011-0543 ==================================================================== 1. Summary: Updated fuse packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 3. Description: FUSE (Filesystem in Userspace) can implement a fully functional file system in a user-space program. These packages provide the mount utility, fusermount, the tool used to mount FUSE file systems. Multiple flaws were found in the way fusermount handled the mounting and unmounting of directories when symbolic links were present. A local user in the fuse group could use these flaws to unmount file systems, which they wouldotherwise not be able to unmount and that were not mounted using FUSE, via a symbolic link attack. (CVE-2010-3879, CVE-2011-0541, CVE-2011-0542, CVE-2011-0543) Note: The util-linux-ng RHBA-2011:0699 update must also be installed to fully correct the above flaws. All users should upgrade to these updated packages, which contain backported patches to correct these issues. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 651183 - CVE-2010-3879 CVE-2011-0541 CVE-2011-0542 CVE-2011-0543 fuse: unprivileged user can unmount arbitrary locations via symlink attack 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: i386: fuse-2.8.3-3.el6_1.i686.rpm fuse-debuginfo-2.8.3-3.el6_1.i686.rpm fuse-libs-2.8.3-3.el6_1.i686.rpm x86_64: fuse-2.8.3-3.el6_1.x86_64.rpm fuse-debuginfo-2.8.3-3.el6_1.i686.rpm fuse-debuginfo-2.8.3-3.el6_1.x86_64.rpm fuse-libs-2.8.3-3.el6_1.i686.rpm fuse-libs-2.8.3-3.el6_1.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): Source: i386: fuse-debuginfo-2.8.3-3.el6_1.i686.rpm fuse-devel-2.8.3-3.el6_1.i686.rpm x86_64: fuse-debuginfo-2.8.3-3.el6_1.i686.rpm fuse-debuginfo-2.8.3-3.el6_1.x86_64.rpm fuse-devel-2.8.3-3.el6_1.i686.rpm fuse-devel-2.8.3-3.el6_1.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: fuse-debuginfo-2.8.3-3.el6_1.x86_64.rpm fuse-libs-2.8.3-3.el6_1.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: fuse-2.8.3-3.el6_1.x86_64.rpm fuse-debuginfo-2.8.3-3.el6_1.i686.rpm fuse-debuginfo-2.8.3-3.el6_1.x86_64.rpm fuse-devel-2.8.3-3.el6_1.i686.rpm fuse-devel-2.8.3-3.el6_1.x86_64.rpm fuse-libs-2.8.3-3.el6_1.i686.rpm Red Hat Enterprise Linux Server (v.6): Source: i386: fuse-2.8.3-3.el6_1.i686.rpm fuse-debuginfo-2.8.3-3.el6_1.i686.rpm fuse-devel-2.8.3-3.el6_1.i686.rpm fuse-libs-2.8.3-3.el6_1.i686.rpm ppc64: fuse-2.8.3-3.el6_1.ppc64.rpm fuse-debuginfo-2.8.3-3.el6_1.ppc.rpm fuse-debuginfo-2.8.3-3.el6_1.ppc64.rpm fuse-devel-2.8.3-3.el6_1.ppc.rpm fuse-devel-2.8.3-3.el6_1.ppc64.rpm fuse-libs-2.8.3-3.el6_1.ppc.rpm fuse-libs-2.8.3-3.el6_1.ppc64.rpm s390x: fuse-2.8.3-3.el6_1.s390x.rpm fuse-debuginfo-2.8.3-3.el6_1.s390.rpm fuse-debuginfo-2.8.3-3.el6_1.s390x.rpm fuse-devel-2.8.3-3.el6_1.s390.rpm fuse-devel-2.8.3-3.el6_1.s390x.rpm fuse-libs-2.8.3-3.el6_1.s390.rpm fuse-libs-2.8.3-3.el6_1.s390x.rpm x86_64: fuse-2.8.3-3.el6_1.x86_64.rpm fuse-debuginfo-2.8.3-3.el6_1.i686.rpm fuse-debuginfo-2.8.3-3.el6_1.x86_64.rpm fuse-devel-2.8.3-3.el6_1.i686.rpm fuse-devel-2.8.3-3.el6_1.x86_64.rpm fuse-libs-2.8.3-3.el6_1.i686.rpm fuse-libs-2.8.3-3.el6_1.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: i386: fuse-2.8.3-3.el6_1.i686.rpm fuse-debuginfo-2.8.3-3.el6_1.i686.rpm fuse-devel-2.8.3-3.el6_1.i686.rpm fuse-libs-2.8.3-3.el6_1.i686.rpm x86_64: fuse-2.8.3-3.el6_1.x86_64.rpm fuse-debuginfo-2.8.3-3.el6_1.i686.rpm fuse-debuginfo-2.8.3-3.el6_1.x86_64.rpm fuse-devel-2.8.3-3.el6_1.i686.rpm fuse-devel-2.8.3-3.el6_1.x86_64.rpm fuse-libs-2.8.3-3.el6_1.i686.rpm fuse-libs-2.8.3-3.el6_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2010-3879 https://access.redhat.com/security/cve/CVE-2011-0541 https://access.redhat.com/security/cve/CVE-2011-0542 https://access.redhat.com/security/cve/CVE-2011-0543 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/errata/RHBA-2011:0699.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2011 Red Hat, Inc. -----BEGINPGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFOJx2RXlSAg2UNWIIRAk6bAKCyMvXD1zybttx43g4pOCFNdioBxwCfcnrb Il4ASTA04l2l0QYBfSRG3FE=u6xH -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Low: bash security and bug fix update. Date: Fri, 18 Feb 2011 11:47:56 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Low: bash on SL4.x i386/x86_64 Comments: To: "
Updated vim packages that fix a security vulnerability are now available. This update has been rated as having low security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Low: vim security update Advisory ID: RHSA-2005:122-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:122.html Issue date: 2005-02-18 Updated on: 2005-02-18 Product: Red Hat Enterprise Linux CVE Names: CAN-2005-0069 - ---------------------------------------------------------------------1. Summary: Updated vim packages that fix a security vulnerability are now available. This update has been rated as having low security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: VIM (Vi IMproved) is an updated and improved version of the vi screen-based editor. The Debian Security Audit Project discovered an insecure temporary file usage in VIM. A local user could overwrite or create files as a different user who happens to run one of the the vulnerable utilities. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0069 to this issue. All users of VIM are advised to upgrade to these erratum packages, which contain a backported patche for this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have beenapplied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 144695 - CAN-2005-0069 vim unsafe temporary file usage. 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 25a0d0da8e8dcd06a732260aed6092de vim-6.0-7.21.src.rpm i386: 858074120fd8d3aacfa597234bd2bf9e vim-X11-6.0-7.21.i386.rpm 2dc635b4493df94730bda4f0ce6c3537 vim-common-6.0-7.21.i386.rpm 55afb35d89ef238125ec9742ff5bb71c vim-enhanced-6.0-7.21.i386.rpm 57de71f48376a1aeb896e4d2ee824b87 vim-minimal-6.0-7.21.i386.rpm ia64: 00f330fbc80b4e95f575128b13266604 vim-X11-6.0-7.21.ia64.rpm 0f2e04e3039df74739f56e3ebcf64076 vim-common-6.0-7.21.ia64.rpm a1eb0b17a2c76bf46ec90442f7e99885 vim-enhanced-6.0-7.21.ia64.rpm 4a0c680069a6eff71523ecfc7effbeae vim-minimal-6.0-7.21.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 25a0d0da8e8dcd06a732260aed6092de vim-6.0-7.21.src.rpm ia64: 00f330fbc80b4e95f575128b13266604 vim-X11-6.0-7.21.ia64.rpm 0f2e04e3039df74739f56e3ebcf64076 vim-common-6.0-7.21.ia64.rpm a1eb0b17a2c76bf46ec90442f7e99885 vim-enhanced-6.0-7.21.ia64.rpm 4a0c680069a6eff71523ecfc7effbeae vim-minimal-6.0-7.21.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: 25a0d0da8e8dcd06a732260aed6092de vim-6.0-7.21.src.rpm i386: 858074120fd8d3aacfa597234bd2bf9e vim-X11-6.0-7.21.i386.rpm 2dc635b4493df94730bda4f0ce6c3537 vim-common-6.0-7.21.i386.rpm 55afb35d89ef238125ec9742ff5bb71c vim-enhanced-6.0-7.21.i386.rpm 57de71f48376a1aeb896e4d2ee824b87 vim-minimal-6.0-7.21.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 25a0d0da8e8dcd06a732260aed6092de vim-6.0-7.21.src.rpm i386: 858074120fd8d3aacfa597234bd2bf9e vim-X11-6.0-7.21.i386.rpm 2dc635b4493df94730bda4f0ce6c3537 vim-common-6.0-7.21.i386.rpm 55afb35d89ef238125ec9742ff5bb71c vim-enhanced-6.0-7.21.i386.rpm 57de71f48376a1aeb896e4d2ee824b87 vim-minimal-6.0-7.21.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: d0c6d095fc3fd947b96f48cf80fb75d2 vim-6.3.046-0.30E.3.src.rpm i386: 5ecea903ba72a0e85b5e035b28b4aef9 vim-X11-6.3.046-0.30E.3.i386.rpm d814d3d83213dfa0517dff6cc27f453a vim-common-6.3.046-0.30E.3.i386.rpm ec4d0de61e6d0b20bfdbe0a29bb8a41f vim-enhanced-6.3.046-0.30E.3.i386.rpm f7890066d7cbc0220355c538043e1d56 vim-minimal-6.3.046-0.30E.3.i386.rpm ia64: 6d5b53a1d2ff995eaa980957f448f23d vim-X11-6.3.046-0.30E.3.ia64.rpm ff174d2a96c64ec41312c3a7da5494b4 vim-common-6.3.046-0.30E.3.ia64.rpm 9461ef263141b100edaf384fa44f1262 vim-enhanced-6.3.046-0.30E.3.ia64.rpm 78dc091a9c3d1e111988eced0b81d697 vim-minimal-6.3.046-0.30E.3.ia64.rpm ppc: 1e7ce04e602be9cc364d55f71f1e700e vim-X11-6.3.046-0.30E.3.ppc.rpm e4dd0527a573d86a9a9f39953377459b vim-common-6.3.046-0.30E.3.ppc.rpm cf3f4b6152b2c40683bdb5c7308e35be vim-enhanced-6.3.046-0.30E.3.ppc.rpm 775f2116d03996ce9ccea101ca7250b0 vim-minimal-6.3.046-0.30E.3.ppc.rpm s390: 93c551ed8fcaa5884a46bc4cfa2b5d2a vim-X11-6.3.046-0.30E.3.s390.rpm 9d17aa93c46223feb88dd957606173a6 vim-common-6.3.046-0.30E.3.s390.rpm 0426391991938cca456ce7ddd2684227 vim-enhanced-6.3.046-0.30E.3.s390.rpm 4ad9e677f5a154733a84eef2fa76167f vim-minimal-6.3.046-0.30E.3.s390.rpm s390x: 5adf3d0ac7c6b060fb3a595852614442 vim-X11-6.3.046-0.30E.3.s390x.rpm c677152124ad31ac7f7c853f36dd9538 vim-common-6.3.046-0.30E.3.s390x.rpm 43324fd6361cef7eb591cba2a9344885 vim-enhanced-6.3.046-0.30E.3.s390x.rpm ecab3cd04492c2ef6cef5b6558cf26fe vim-minimal-6.3.046-0.30E.3.s390x.rpm x86_64: 8c9d5111273676a1c6f16eef3b2f0822 vim-X11-6.3.046-0.30E.3.x86_64.rpm 32a2aa7b56236079908bb8decdc4877f vim-common-6.3.046-0.30E.3.x86_64.rpm 7e46ae1ba637e5d95c532962853943ca vim-enhanced-6.3.046-0.30E.3.x86_64.rpm 53726767c2dcb8b26c81445c41cc4abf vim-minimal-6.3.046-0.30E.3.x86_64.rpm Red Hat Desktop version 3: SRPMS: d0c6d095fc3fd947b96f48cf80fb75d2 vim-6.3.046-0.30E.3.src.rpm i386: 5ecea903ba72a0e85b5e035b28b4aef9 vim-X11-6.3.046-0.30E.3.i386.rpm d814d3d83213dfa0517dff6cc27f453a vim-common-6.3.046-0.30E.3.i386.rpm ec4d0de61e6d0b20bfdbe0a29bb8a41f vim-enhanced-6.3.046-0.30E.3.i386.rpm f7890066d7cbc0220355c538043e1d56 vim-minimal-6.3.046-0.30E.3.i386.rpm x86_64: 8c9d5111273676a1c6f16eef3b2f0822 vim-X11-6.3.046-0.30E.3.x86_64.rpm 32a2aa7b56236079908bb8decdc4877f vim-common-6.3.046-0.30E.3.x86_64.rpm 7e46ae1ba637e5d95c532962853943ca vim-enhanced-6.3.046-0.30E.3.x86_64.rpm 53726767c2dcb8b26c81445c41cc4abf vim-minimal-6.3.046-0.30E.3.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: d0c6d095fc3fd947b96f48cf80fb75d2 vim-6.3.046-0.30E.3.src.rpm i386: 5ecea903ba72a0e85b5e035b28b4aef9 vim-X11-6.3.046-0.30E.3.i386.rpm d814d3d83213dfa0517dff6cc27f453a vim-common-6.3.046-0.30E.3.i386.rpm ec4d0de61e6d0b20bfdbe0a29bb8a41f vim-enhanced-6.3.046-0.30E.3.i386.rpm f7890066d7cbc0220355c538043e1d56 vim-minimal-6.3.046-0.30E.3.i386.rpm ia64: 6d5b53a1d2ff995eaa980957f448f23d vim-X11-6.3.046-0.30E.3.ia64.rpm ff174d2a96c64ec41312c3a7da5494b4 vim-common-6.3.046-0.30E.3.ia64.rpm 9461ef263141b100edaf384fa44f1262 vim-enhanced-6.3.046-0.30E.3.ia64.rpm 78dc091a9c3d1e111988eced0b81d697 vim-minimal-6.3.046-0.30E.3.ia64.rpm x86_64: 8c9d5111273676a1c6f16eef3b2f0822 vim-X11-6.3.046-0.30E.3.x86_64.rpm 32a2aa7b56236079908bb8decdc4877f vim-common-6.3.046-0.30E.3.x86_64.rpm 7e46ae1ba637e5d95c532962853943ca vim-enhanced-6.3.046-0.30E.3.x86_64.rpm 53726767c2dcb8b26c81445c41cc4abf vim-minimal-6.3.046-0.30E.3.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: d0c6d095fc3fd947b96f48cf80fb75d2 vim-6.3.046-0.30E.3.src.rpm i386: 5ecea903ba72a0e85b5e035b28b4aef9 vim-X11-6.3.046-0.30E.3.i386.rpm d814d3d83213dfa0517dff6cc27f453a vim-common-6.3.046-0.30E.3.i386.rpm ec4d0de61e6d0b20bfdbe0a29bb8a41f vim-enhanced-6.3.046-0.30E.3.i386.rpm f7890066d7cbc0220355c538043e1d56 vim-minimal-6.3.046-0.30E.3.i386.rpm ia64: 6d5b53a1d2ff995eaa980957f448f23d vim-X11-6.3.046-0.30E.3.ia64.rpm ff174d2a96c64ec41312c3a7da5494b4 vim-common-6.3.046-0.30E.3.ia64.rpm 9461ef263141b100edaf384fa44f1262 vim-enhanced-6.3.046-0.30E.3.ia64.rpm 78dc091a9c3d1e111988eced0b81d697 vim-minimal-6.3.046-0.30E.3.ia64.rpm x86_64: 8c9d5111273676a1c6f16eef3b2f0822 vim-X11-6.3.046-0.30E.3.x86_64.rpm 32a2aa7b56236079908bb8decdc4877f vim-common-6.3.046-0.30E.3.x86_64.rpm 7e46ae1ba637e5d95c532962853943ca vim-enhanced-6.3.046-0.30E.3.x86_64.rpm 53726767c2dcb8b26c81445c41cc4abf vim-minimal-6.3.046-0.30E.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-CAN-2005-0069 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2005 Red Hat, Inc. . Uncover the most recent Red Hat announcement regarding vim, which tackles minor security flaws and crucial enhancements.. Red Hat Security Update, Vim Insecure File Handling, Linux Advisory. . Severity: Low. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.