Moderate: mikmod security update. Date: Wed, 29 Sep 2010 09:57:16 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Moderate: mikmod on SL3.x, SL4.x, SL5.x i386/x86_64 Comments: To: "
Updated mikmod packages that fix multiple security issues are now available for Red Hat Enterprise Linux 3, 4, and 5. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: mikmod security update Advisory ID: RHSA-2010:0720-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2010:0720.html Issue date: 2010-09-28 CVE Names: CVE-2007-6720 CVE-2009-3995 CVE-2009-3996 ==================================================================== 1. Summary: Updated mikmod packages that fix multiple security issues are now available for Red Hat Enterprise Linux 3, 4, and 5. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Description: MikMod is a MOD music file player for Linux, UNIX, and similar operating systems. It supports various file formatsincluding MOD, STM, S3M, MTM, XM, ULT, and IT. Multiple input validation flaws, resulting in buffer overflows, were discovered in MikMod. Specially-crafted music files in various formats could, when played, cause an application using the MikMod library to crash or, potentially, execute arbitrary code. (CVE-2009-3995, CVE-2009-3996, CVE-2007-6720) All MikMod users should upgrade to these updated packages, which contain backported patches to correct these issues. All running applications using the MikMod library must be restarted for this update to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 479829 - CVE-2007-6720 mikmod: crash or abort when loading/playing multiple files with different number of channels 614643 - CVE-2009-3995 CVE-2009-3996 libmikmod: arbitrary code execution via crafted Impulse Tracker or Ultratracker files 6. Package List: Red Hat Enterprise Linux AS version3: Source: i386: mikmod-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-devel-3.1.6-23.el3.i386.rpm ia64: mikmod-3.1.6-23.el3.i386.rpm mikmod-3.1.6-23.el3.ia64.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.ia64.rpm mikmod-devel-3.1.6-23.el3.ia64.rpm ppc: mikmod-3.1.6-23.el3.ppc.rpm mikmod-3.1.6-23.el3.ppc64.rpm mikmod-debuginfo-3.1.6-23.el3.ppc.rpm mikmod-debuginfo-3.1.6-23.el3.ppc64.rpm mikmod-devel-3.1.6-23.el3.ppc.rpm s390: mikmod-3.1.6-23.el3.s390.rpm mikmod-debuginfo-3.1.6-23.el3.s390.rpm mikmod-devel-3.1.6-23.el3.s390.rpm s390x: mikmod-3.1.6-23.el3.s390.rpm mikmod-3.1.6-23.el3.s390x.rpm mikmod-debuginfo-3.1.6-23.el3.s390.rpm mikmod-debuginfo-3.1.6-23.el3.s390x.rpm mikmod-devel-3.1.6-23.el3.s390x.rpm x86_64: mikmod-3.1.6-23.el3.i386.rpm mikmod-3.1.6-23.el3.x86_64.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.x86_64.rpm mikmod-devel-3.1.6-23.el3.x86_64.rpm Red Hat Desktop version 3: Source: i386: mikmod-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-devel-3.1.6-23.el3.i386.rpm x86_64: mikmod-3.1.6-23.el3.i386.rpm mikmod-3.1.6-23.el3.x86_64.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.x86_64.rpm mikmod-devel-3.1.6-23.el3.x86_64.rpm Red Hat Enterprise Linux ES version 3: Source: i386: mikmod-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-devel-3.1.6-23.el3.i386.rpm ia64: mikmod-3.1.6-23.el3.i386.rpm mikmod-3.1.6-23.el3.ia64.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.ia64.rpm mikmod-devel-3.1.6-23.el3.ia64.rpm x86_64: mikmod-3.1.6-23.el3.i386.rpm mikmod-3.1.6-23.el3.x86_64.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.x86_64.rpm mikmod-devel-3.1.6-23.el3.x86_64.rpm Red Hat Enterprise Linux WS version3: Source: i386: mikmod-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-devel-3.1.6-23.el3.i386.rpm ia64: mikmod-3.1.6-23.el3.i386.rpm mikmod-3.1.6-23.el3.ia64.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.ia64.rpm mikmod-devel-3.1.6-23.el3.ia64.rpm x86_64: mikmod-3.1.6-23.el3.i386.rpm mikmod-3.1.6-23.el3.x86_64.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.x86_64.rpm mikmod-devel-3.1.6-23.el3.x86_64.rpm Red Hat Enterprise Linux AS version 4: Source: i386: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-devel-3.1.6-33.el4_8.1.i386.rpm ia64: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-3.1.6-33.el4_8.1.ia64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.ia64.rpm mikmod-devel-3.1.6-33.el4_8.1.ia64.rpm ppc: mikmod-3.1.6-33.el4_8.1.ppc.rpm mikmod-3.1.6-33.el4_8.1.ppc64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.ppc.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.ppc64.rpm mikmod-devel-3.1.6-33.el4_8.1.ppc.rpm s390: mikmod-3.1.6-33.el4_8.1.s390.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.s390.rpm mikmod-devel-3.1.6-33.el4_8.1.s390.rpm s390x: mikmod-3.1.6-33.el4_8.1.s390.rpm mikmod-3.1.6-33.el4_8.1.s390x.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.s390.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.s390x.rpm mikmod-devel-3.1.6-33.el4_8.1.s390x.rpm x86_64: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-3.1.6-33.el4_8.1.x86_64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.x86_64.rpm mikmod-devel-3.1.6-33.el4_8.1.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-devel-3.1.6-33.el4_8.1.i386.rpm x86_64: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-3.1.6-33.el4_8.1.x86_64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.x86_64.rpm mikmod-devel-3.1.6-33.el4_8.1.x86_64.rpm Red Hat Enterprise Linux ES version4: Source: i386: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-devel-3.1.6-33.el4_8.1.i386.rpm ia64: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-3.1.6-33.el4_8.1.ia64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.ia64.rpm mikmod-devel-3.1.6-33.el4_8.1.ia64.rpm x86_64: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-3.1.6-33.el4_8.1.x86_64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.x86_64.rpm mikmod-devel-3.1.6-33.el4_8.1.x86_64.rpm Red Hat Enterprise Linux WS version 4: Source: i386: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-devel-3.1.6-33.el4_8.1.i386.rpm ia64: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-3.1.6-33.el4_8.1.ia64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.ia64.rpm mikmod-devel-3.1.6-33.el4_8.1.ia64.rpm x86_64: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-3.1.6-33.el4_8.1.x86_64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.x86_64.rpm mikmod-devel-3.1.6-33.el4_8.1.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: mikmod-3.1.6-39.el5_5.1.i386.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.i386.rpm x86_64: mikmod-3.1.6-39.el5_5.1.i386.rpm mikmod-3.1.6-39.el5_5.1.x86_64.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.i386.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: mikmod-debuginfo-3.1.6-39.el5_5.1.i386.rpm mikmod-devel-3.1.6-39.el5_5.1.i386.rpm x86_64: mikmod-debuginfo-3.1.6-39.el5_5.1.i386.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.x86_64.rpm mikmod-devel-3.1.6-39.el5_5.1.i386.rpm mikmod-devel-3.1.6-39.el5_5.1.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: mikmod-3.1.6-39.el5_5.1.i386.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.i386.rpm mikmod-devel-3.1.6-39.el5_5.1.i386.rpm ia64: mikmod-3.1.6-39.el5_5.1.ia64.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.ia64.rpm mikmod-devel-3.1.6-39.el5_5.1.ia64.rpm ppc: mikmod-3.1.6-39.el5_5.1.ppc.rpm mikmod-3.1.6-39.el5_5.1.ppc64.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.ppc.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.ppc64.rpm mikmod-devel-3.1.6-39.el5_5.1.ppc.rpm mikmod-devel-3.1.6-39.el5_5.1.ppc64.rpm s390x: mikmod-3.1.6-39.el5_5.1.s390.rpm mikmod-3.1.6-39.el5_5.1.s390x.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.s390.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.s390x.rpm mikmod-devel-3.1.6-39.el5_5.1.s390.rpm mikmod-devel-3.1.6-39.el5_5.1.s390x.rpm x86_64: mikmod-3.1.6-39.el5_5.1.i386.rpm mikmod-3.1.6-39.el5_5.1.x86_64.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.i386.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.x86_64.rpm mikmod-devel-3.1.6-39.el5_5.1.i386.rpm mikmod-devel-3.1.6-39.el5_5.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2007-6720 https://access.redhat.com/security/cve/CVE-2009-3995 https://access.redhat.com/security/cve/CVE-2009-3996 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2010 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFMogRYXlSAg2UNWIIRApxrAJsFXKp84IXXGWJm9bywiZgDkJzVVACeL1SC AyL9AAkSC0qOoPf403u858Q=BBzu -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Updated mikmod packages that fix multiple security issues are now available for Red Hat Enterprise Linux 3, 4, and 5. The Red Hat Security Response Team has rated this update as having moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: mikmod security update Advisory ID: RHSA-2010:0720-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2010:0720.html Issue date: 2010-09-28 CVE Names: CVE-2007-6720 CVE-2009-3995 CVE-2009-3996 ==================================================================== 1. Summary: Updated mikmod packages that fix multiple security issues are now available for Red Hat Enterprise Linux 3, 4, and 5. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Description: MikMod is a MOD music file player for Linux, UNIX, and similar operating systems. It supports various file formats including MOD, STM, S3M, MTM, XM, ULT, and IT. Multiple input validation flaws, resulting in bufferoverflows, were discovered in MikMod. Specially-crafted music files in various formats could, when played, cause an application using the MikMod library to crash or, potentially, execute arbitrary code. (CVE-2009-3995, CVE-2009-3996, CVE-2007-6720) All MikMod users should upgrade to these updated packages, which contain backported patches to correct these issues. All running applications using the MikMod library must be restarted for this update to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 479829 - CVE-2007-6720 mikmod: crash or abort when loading/playing multiple files with different number of channels 614643 - CVE-2009-3995 CVE-2009-3996 libmikmod: arbitrary code execution via crafted Impulse Tracker or Ultratracker files 6. Package List: Red Hat Enterprise Linux AS version 3: Source: i386: mikmod-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-devel-3.1.6-23.el3.i386.rpm ia64: mikmod-3.1.6-23.el3.i386.rpm mikmod-3.1.6-23.el3.ia64.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.ia64.rpm mikmod-devel-3.1.6-23.el3.ia64.rpm ppc: mikmod-3.1.6-23.el3.ppc.rpm mikmod-3.1.6-23.el3.ppc64.rpm mikmod-debuginfo-3.1.6-23.el3.ppc.rpm mikmod-debuginfo-3.1.6-23.el3.ppc64.rpm mikmod-devel-3.1.6-23.el3.ppc.rpm s390: mikmod-3.1.6-23.el3.s390.rpm mikmod-debuginfo-3.1.6-23.el3.s390.rpm mikmod-devel-3.1.6-23.el3.s390.rpm s390x: mikmod-3.1.6-23.el3.s390.rpm mikmod-3.1.6-23.el3.s390x.rpm mikmod-debuginfo-3.1.6-23.el3.s390.rpm mikmod-debuginfo-3.1.6-23.el3.s390x.rpm mikmod-devel-3.1.6-23.el3.s390x.rpm x86_64: mikmod-3.1.6-23.el3.i386.rpm mikmod-3.1.6-23.el3.x86_64.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.x86_64.rpm mikmod-devel-3.1.6-23.el3.x86_64.rpm Red Hat Desktop version3: Source: i386: mikmod-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-devel-3.1.6-23.el3.i386.rpm x86_64: mikmod-3.1.6-23.el3.i386.rpm mikmod-3.1.6-23.el3.x86_64.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.x86_64.rpm mikmod-devel-3.1.6-23.el3.x86_64.rpm Red Hat Enterprise Linux ES version 3: Source: i386: mikmod-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-devel-3.1.6-23.el3.i386.rpm ia64: mikmod-3.1.6-23.el3.i386.rpm mikmod-3.1.6-23.el3.ia64.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.ia64.rpm mikmod-devel-3.1.6-23.el3.ia64.rpm x86_64: mikmod-3.1.6-23.el3.i386.rpm mikmod-3.1.6-23.el3.x86_64.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.x86_64.rpm mikmod-devel-3.1.6-23.el3.x86_64.rpm Red Hat Enterprise Linux WS version 3: Source: i386: mikmod-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-devel-3.1.6-23.el3.i386.rpm ia64: mikmod-3.1.6-23.el3.i386.rpm mikmod-3.1.6-23.el3.ia64.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.ia64.rpm mikmod-devel-3.1.6-23.el3.ia64.rpm x86_64: mikmod-3.1.6-23.el3.i386.rpm mikmod-3.1.6-23.el3.x86_64.rpm mikmod-debuginfo-3.1.6-23.el3.i386.rpm mikmod-debuginfo-3.1.6-23.el3.x86_64.rpm mikmod-devel-3.1.6-23.el3.x86_64.rpm Red Hat Enterprise Linux AS version4: Source: i386: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-devel-3.1.6-33.el4_8.1.i386.rpm ia64: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-3.1.6-33.el4_8.1.ia64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.ia64.rpm mikmod-devel-3.1.6-33.el4_8.1.ia64.rpm ppc: mikmod-3.1.6-33.el4_8.1.ppc.rpm mikmod-3.1.6-33.el4_8.1.ppc64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.ppc.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.ppc64.rpm mikmod-devel-3.1.6-33.el4_8.1.ppc.rpm s390: mikmod-3.1.6-33.el4_8.1.s390.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.s390.rpm mikmod-devel-3.1.6-33.el4_8.1.s390.rpm s390x: mikmod-3.1.6-33.el4_8.1.s390.rpm mikmod-3.1.6-33.el4_8.1.s390x.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.s390.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.s390x.rpm mikmod-devel-3.1.6-33.el4_8.1.s390x.rpm x86_64: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-3.1.6-33.el4_8.1.x86_64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.x86_64.rpm mikmod-devel-3.1.6-33.el4_8.1.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-devel-3.1.6-33.el4_8.1.i386.rpm x86_64: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-3.1.6-33.el4_8.1.x86_64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.x86_64.rpm mikmod-devel-3.1.6-33.el4_8.1.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-devel-3.1.6-33.el4_8.1.i386.rpm ia64: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-3.1.6-33.el4_8.1.ia64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.ia64.rpm mikmod-devel-3.1.6-33.el4_8.1.ia64.rpm x86_64: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-3.1.6-33.el4_8.1.x86_64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.x86_64.rpm mikmod-devel-3.1.6-33.el4_8.1.x86_64.rpm Red Hat Enterprise Linux WSversion 4: Source: i386: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-devel-3.1.6-33.el4_8.1.i386.rpm ia64: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-3.1.6-33.el4_8.1.ia64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.ia64.rpm mikmod-devel-3.1.6-33.el4_8.1.ia64.rpm x86_64: mikmod-3.1.6-33.el4_8.1.i386.rpm mikmod-3.1.6-33.el4_8.1.x86_64.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.i386.rpm mikmod-debuginfo-3.1.6-33.el4_8.1.x86_64.rpm mikmod-devel-3.1.6-33.el4_8.1.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: mikmod-3.1.6-39.el5_5.1.i386.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.i386.rpm x86_64: mikmod-3.1.6-39.el5_5.1.i386.rpm mikmod-3.1.6-39.el5_5.1.x86_64.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.i386.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: mikmod-debuginfo-3.1.6-39.el5_5.1.i386.rpm mikmod-devel-3.1.6-39.el5_5.1.i386.rpm x86_64: mikmod-debuginfo-3.1.6-39.el5_5.1.i386.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.x86_64.rpm mikmod-devel-3.1.6-39.el5_5.1.i386.rpm mikmod-devel-3.1.6-39.el5_5.1.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: mikmod-3.1.6-39.el5_5.1.i386.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.i386.rpm mikmod-devel-3.1.6-39.el5_5.1.i386.rpm ia64: mikmod-3.1.6-39.el5_5.1.ia64.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.ia64.rpm mikmod-devel-3.1.6-39.el5_5.1.ia64.rpm ppc: mikmod-3.1.6-39.el5_5.1.ppc.rpm mikmod-3.1.6-39.el5_5.1.ppc64.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.ppc.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.ppc64.rpm mikmod-devel-3.1.6-39.el5_5.1.ppc.rpm mikmod-devel-3.1.6-39.el5_5.1.ppc64.rpm s390x: mikmod-3.1.6-39.el5_5.1.s390.rpm mikmod-3.1.6-39.el5_5.1.s390x.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.s390.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.s390x.rpm mikmod-devel-3.1.6-39.el5_5.1.s390.rpm mikmod-devel-3.1.6-39.el5_5.1.s390x.rpm x86_64: mikmod-3.1.6-39.el5_5.1.i386.rpm mikmod-3.1.6-39.el5_5.1.x86_64.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.i386.rpm mikmod-debuginfo-3.1.6-39.el5_5.1.x86_64.rpm mikmod-devel-3.1.6-39.el5_5.1.i386.rpm mikmod-devel-3.1.6-39.el5_5.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2007-6720 https://access.redhat.com/security/cve/CVE-2009-3995 https://access.redhat.com/security/cve/CVE-2009-3996 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2010 Red Hat, Inc. . Oracle has issued a significant patch to resolve memory overflow vulnerabilities in libxml for various Linux distributions. Update without delay!. Red Hat Enterprise,mikmod update,security patch,buffer overflow issues. . LinuxSecurity.com Team
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-405 2005-06-16 ---------------------------------------------------------------------Product : Fedora Core 4 Name : mikmod Version : 3.1.6 Release : 35.FC4 Summary : A MOD music file player. Description : MikMod is one of the best and most well known MOD music file players for UNIX-like systems. This particular distribution is intended to compile fairly painlessly in a Linux environment. MikMod uses the OSS /dev/dsp driver including all recent kernels for output, and will also write .wav files. Supported file formats include MOD, STM, S3M, MTM, XM, ULT, and IT. The player uses ncurses for console output and supports transparent loading from gzip/pkzip/zoo archives and the loading/saving of playlists. Install the mikmod package if you need a MOD music file player. ---------------------------------------------------------------------* Mon Jun 6 2005 Martin Stransky 3.1.6-35.FC4 - fixed #159290,#159291 - CAN-2003-0427 - fixed playing mod files from tar archive ---------------------------------------------------------------------This update can be downloaded from: 944a009b899e348614059aa2bd2e6b5e SRPMS/mikmod-3.1.6-35.FC4.src.rpm 546b2d73b402c71965443d4c5e02a865 ppc/mikmod-3.1.6-35.FC4.ppc.rpm 6d15dbacb1c0e470a4598c97819e2dd4 ppc/mikmod-devel-3.1.6-35.FC4.ppc.rpm 97234e209388dbd3f4ea7adf3e9aba06 ppc/debug/mikmod-debuginfo-3.1.6-35.FC4.ppc.rpm 212959d733c66dc0c60d132d2ef13737 ppc/mikmod-3.1.6-35.FC4.ppc64.rpm b48ef75ce3df5f3b54df0e2b5ea77e4c x86_64/mikmod-3.1.6-35.FC4.x86_64.rpm 066f3e934045ade26ae8ce724d8004e3 x86_64/mikmod-devel-3.1.6-35.FC4.x86_64.rpm 70b85c2ba5619571d404b14e83080340 x86_64/debug/mikmod-debuginfo-3.1.6-35.FC4.x86_64.rpm f96c91607f003eb6f6421d9efa825508 x86_64/mikmod-3.1.6-35.FC4.i386.rpm f96c91607f003eb6f6421d9efa825508 i386/mikmod-3.1.6-35.FC4.i386.rpm 309a045a718fb0def0ad25339797753b i386/mikmod-devel-3.1.6-35.FC4.i386.rpm b6a3a0e31dda9c37e71e4ff639ee3dae i386/debug/mikmod-debuginfo-3.1.6-35.FC4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Moderate: sysreport security update. Date: Tue, 14 Jun 2005 14:47:58 -0500 Reply-To: Connie Sieh Sender: Security Errata for Scientific Linux From: Connie Sieh Subject: ERRATA for SL 302/303/304 x86_64 now available Comments: To: scientific ,
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-404 2005-06-09 ---------------------------------------------------------------------Product : Fedora Core 3 Name : mikmod Version : 3.1.6 Release : 31.FC3 Summary : A MOD music file player. Description : MikMod is one of the best and most well known MOD music file players for UNIX-like systems. This particular distribution is intended to compile fairly painlessly in a Linux environment. MikMod uses the OSS /dev/dsp driver including all recent kernels for output, and will also write .wav files. Supported file formats include MOD, STM, S3M, MTM, XM, ULT, and IT. The player uses ncurses for console output and supports transparent loading from gzip/pkzip/zoo archives and the loading/saving of playlists. Install the mikmod package if you need a MOD music file player. ---------------------------------------------------------------------* Mon Jun 06 2005 Martin Stransky 3.1.6-31.FC3 - fixed #159290,#159291 - CAN-2003-0427 - fixed playing mod files from tar archive ---------------------------------------------------------------------This update can be downloaded from: 6eaa5e5a0c34e4748fd5dc9a4470acfe SRPMS/mikmod-3.1.6-31.FC3.src.rpm f40950005dce20456bc2617ac6a91791 x86_64/mikmod-3.1.6-31.FC3.x86_64.rpm 897d4347baf7238978aec2646e9d36ff x86_64/mikmod-devel-3.1.6-31.FC3.x86_64.rpm eaba37c3831a42091f03bb75d19a8156 x86_64/debug/mikmod-debuginfo-3.1.6-31.FC3.x86_64.rpm 3125e1813d27a03859ebb11e9b2afcc8 x86_64/mikmod-3.1.6-31.FC3.i386.rpm 3125e1813d27a03859ebb11e9b2afcc8 i386/mikmod-3.1.6-31.FC3.i386.rpm 9ab0f85bebda27e9167c17a6201061c5 i386/mikmod-devel-3.1.6-31.FC3.i386.rpm 7a1634ceca6e647f54df921b55c7f36b i386/debug/mikmod-debuginfo-3.1.6-31.FC3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date'command. --------------------------------------------------------------------- --fedora-announce-list mailing list
This moves 'mikmod' back to the main package. It was incorrectly in the mikmod-devel package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2004-545 2004-12-13 ---------------------------------------------------------------------Product : Fedora Core 3 Name : mikmod Version : 3.1.6 Release : 30.2 Summary : A MOD music file player. Description : MikMod is one of the best and most well known MOD music file players for UNIX-like systems. This particular distribution is intended to compile fairly painlessly in a Linux environment. MikMod uses the OSS /dev/dsp driver including all recent kernels for output, and will also write .wav files. Supported file formats include MOD, STM, S3M, MTM, XM, ULT, and IT. The player uses ncurses for console output and supports transparent loading from gzip/pkzip/zoo archives and the loading/saving of playlists. Install the mikmod package if you need a MOD music file player. ---------------------------------------------------------------------Update Information: This moves 'mikmod' back to the main package. It was incorrectly in the mikmod-devel package. ---------------------------------------------------------------------* Mon Dec 13 2004 Bill Nottingham 3.1.6-30.2 - move mikmod binary back to main package (#142668) ---------------------------------------------------------------------This update can be downloaded from: c11f544ef954c4d5058dba9d30852590 SRPMS/mikmod-3.1.6-30.2.src.rpm 1d89ab10eba2f04b4d06cdd15444ed9d x86_64/mikmod-3.1.6-30.2.x86_64.rpm 9705672b94b153fc5cd41cfe71f9c268 x86_64/mikmod-devel-3.1.6-30.2.x86_64.rpm 2a807365bbbb37ef98448a5062a357a3 x86_64/debug/mikmod-debuginfo-3.1.6-30.2.x86_64.rpm 19b3a9ecaafe9493fb94951bff5b45a4 x86_64/mikmod-3.1.6-30.2.i386.rpm 19b3a9ecaafe9493fb94951bff5b45a4 i386/mikmod-3.1.6-30.2.i386.rpm 1fa09936b8b4cfc34ce606cbb1da6d60 i386/mikmod-devel-3.1.6-30.2.i386.rpm 5bb0687017c0d738591e8911d1a6522b i386/debug/mikmod-debuginfo-3.1.6-30.2.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to execute arbitrary code via an archive file that contains a file with a long filename.. - - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200307-01 - - - --------------------------------------------------------------------- PACKAGE : mikmod SUMMARY : buffer overflow DATE : 2003-07-02 21:27 UTC EXPLOIT : local VERSIONS AFFECTED : =mikmod-3.1.6a CVE : CAN-2003-0427 - - - --------------------------------------------------------------------- quote from cve: "Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to execute arbitrary code via an archive file that contains a file with a long filename." SOLUTION It is recommended that all Gentoo Linux users who are running media-sound/mikmod upgrade to mikmod-3.1.6a as follows emerge sync emerge mikmod emerge clean - - - ---------------------------------------------------------------------
Get the latest Linux and open source security news straight to your inbox.