Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded . MGASA-2024-0002 - Updated libssh2 packages fix a security vulnerability (Terrapin Attack) Publication date: 08 Jan 2024 URL: https://advisories.mageia.org/MGASA-2024-0002.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-48795 The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. Our libssh2 packages were also affected, this update fixes the issue. References: - https://bugs.mageia.org/show_bug.cgi?id=32662 - https://github.com/libssh2/libssh2/issues/1290 - https://www.cve.org/CVERecord?id=CVE-2023-48795 SRPMS: - 9/core/libssh2-1.10.0-3.1.mga9 . A major update for libssh2 addresses integrity downgrade issues exposing SSH connections to potential threats.. Mageia Security Advisory, Libssh2 Update, SSH Integrity Check, Remote Attack Vulnerability. . LinuxSecurity.com Team
Updated freetds packages fix security vulnerability: Felix Wilhelm discovered that FreeTDS incorrectly handled certain types after a protocol downgrade. A remote attacker could use this issue to cause FreeTDS to crash, resulting in a denial of service, or possibly . MGASA-2019-0319 - Updated freetds packages fix security vulnerability Publication date: 07 Nov 2019 URL: https://advisories.mageia.org/MGASA-2019-0319.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-13508 Updated freetds packages fix security vulnerability: Felix Wilhelm discovered that FreeTDS incorrectly handled certain types after a protocol downgrade. A remote attacker could use this issue to cause FreeTDS to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2019-13508). References: - https://bugs.mageia.org/show_bug.cgi?id=25653 - https://ubuntu.com/security/notices/USN-4173-1 - https://www.cve.org/CVERecord?id=CVE-2019-13508 SRPMS: - 7/core/freetds-1.00.83-2.1.mga7 . Recent updates to FreeTDS packages fix a major security flaw that may allow denial of service attacks or unauthorized code execution. Learn more about this update. FreeTDS Security Update, Mageia Security Advisories, Remote Attacks Threat, Protocol Downgrade Issues. . LinuxSecurity.com Team
Cherry-pick a fix for the protocol downgrade attack (CVE-2014-9721). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-8635 2015-05-20 22:16:42 -------------------------------------------------------------------------------- Name : zeromq Product : Fedora 22 Version : 4.0.5 Release : 3.fc22 URL : https://zeromq.org/ Summary : Software library for fast, message-based applications Description : The 0MQ lightweight messaging kernel is a library which extends the standard socket interfaces with features traditionally provided by specialized messaging middle-ware products. 0MQ sockets provide an abstraction of asynchronous message queues, multiple messaging patterns, message filtering (subscriptions), seamless access to multiple transport protocols and more. This package contains the ZeroMQ shared library. -------------------------------------------------------------------------------- Update Information: Cherry-pick a fix for the protocol downgrade attack (CVE-2014-9721) -------------------------------------------------------------------------------- ChangeLog: * Tue May 19 2015 Thomas Spura - 4.0.5-3 - Cherry-pick patch for protocol downgrade attack (#1221666) - Remove Provides:zeromq-utils - Remove %defattr * Sat May 2 2015 Kalev Lember - 4.0.5-2 - Rebuilt for GCC 5 C++11 ABI change -------------------------------------------------------------------------------- References: [ 1 ] Bug #1221666 - CVE-2014-9721 zeromq: protocol downgrade attack on sockets using the ZMTP v3 protocol https://bugzilla.redhat.com/show_bug.cgi?id=1221666 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update zeromq' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
An update that fixes 9 vulnerabilities is now available. It An update that fixes 9 vulnerabilities is now available. It An update that fixes 9 vulnerabilities is now available. It includes three new package versions. includes three new package versions.. SUSE Security Update: Security update for MozillaFirefox ______________________________________________________________________________ Announcement ID: SUSE-SU-2014:1458-2 Rating: important References: #900941 #905056 #905528 Cross-References: CVE-2014-1574 CVE-2014-1575 CVE-2014-1576 CVE-2014-1577 CVE-2014-1578 CVE-2014-1581 CVE-2014-1583 CVE-2014-1585 CVE-2014-1586 Affected Products: SUSE Linux Enterprise Server 11 SP2 LTSS ______________________________________________________________________________ An update that fixes 9 vulnerabilities is now available. It includes three new package versions. Description: This version update of Mozilla Firefox to 31.2.0ESR brings improvements, stability fixes and also security fixes for the following CVEs: CVE-2014-1574, CVE-2014-1575, CVE-2014-1576 ,CVE-2014-1577, CVE-2014-1578, CVE-2014-1581, CVE-2014-1583, CVE-2014-1585, CVE-2014-1586 It also disables SSLv3 by default to mitigate the protocol downgrade attack known as POODLE. This update fixes some regressions introduced by the previously released update. Security Issues: * CVE-2014-1574 * CVE-2014-1575 * CVE-2014-1576 * CVE-2014-1577 * CVE-2014-1578 * CVE-2014-1581 * CVE-2014-1583 * CVE-2014-1585 * CVE-2014-1586 Indications: Everybody should update. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP2 LTSS: zypper in -t patch slessp2-firefox31-201411-9973 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11 SP2 LTSS (i586 s390x x86_64) [New Version: 3.17.2,31.2.0esr and 4.10.7]: MozillaFirefox-31.2.0esr-0.11.11.1 MozillaFirefox-branding-SLED-31.0-0.5.5.1 MozillaFirefox-translations-31.2.0esr-0.11.11.1 libfreebl3-3.17.2-0.3.1 mozilla-nspr-4.10.7-0.3.3 mozilla-nspr-devel-4.10.7-0.3.3 mozilla-nss-3.17.2-0.3.1 mozilla-nss-devel-3.17.2-0.3.1 mozilla-nss-tools-3.17.2-0.3.1 - SUSE Linux Enterprise Server 11 SP2 LTSS (s390x x86_64) [New Version: 3.17.2 and 4.10.7]: libfreebl3-32bit-3.17.2-0.3.1 mozilla-nspr-32bit-4.10.7-0.3.3 mozilla-nss-32bit-3.17.2-0.3.1 References: https://www.suse.com/security/cve/CVE-2014-1574.html https://www.suse.com/security/cve/CVE-2014-1575.html https://www.suse.com/security/cve/CVE-2014-1576.html https://www.suse.com/security/cve/CVE-2014-1577.html https://www.suse.com/security/cve/CVE-2014-1578.html https://www.suse.com/security/cve/CVE-2014-1581.html https://www.suse.com/security/cve/CVE-2014-1583.html https://www.suse.com/security/cve/CVE-2014-1585.html https://www.suse.com/security/cve/CVE-2014-1586.html https://bugzilla.suse.com/show_bug.cgi?id=900941 https://bugzilla.suse.com/show_bug.cgi?id=905056 https://bugzilla.suse.com/show_bug.cgi?id=905528 https://scc.suse.com:443/patches/ . SUSE launched a new security patch for Mozilla Firefox, addressing several flaws and enhancing protection mechanisms against potential threats.. Mozilla Firefox Security Update,SUSE Linux Security Advisory,Firefox Vulnerabilities Fix. . Severity: Important. LinuxSecurity.com Team
Updated openssl packages that contain a backported patch to mitigate the CVE-2014-3566 issue are now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having Moderate security impact.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openssl security update Advisory ID: RHSA-2014:1653-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2014:1653.html Issue date: 2014-10-16 ==================================================================== 1. Summary: Updated openssl packages that contain a backported patch to mitigate the CVE-2014-3566 issue are now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having Moderate security impact. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. Description: OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL), Transport Layer Security (TLS), and Datagram Transport Layer Security (DTLS) protocols, as well as a full-strength, general purpose cryptography library. This update adds support for the TLS Fallback Signaling Cipher Suite Value (TLS_FALLBACK_SCSV), which can be used to prevent protocol downgrade attacks against applications which re-connect using a lower SSL/TLS protocol version when the initial connection indicating the highest supported protocol version fails. This can prevent a forceful downgrade of the communication to SSL 3.0. The SSL 3.0 protocol was found to be vulnerable to the padding oracle attack when using block cipher suites in cipher block chaining (CBC) mode. This issue is identified as CVE-2014-3566, and also known under the alias POODLE. This SSL 3.0 protocol flaw willnot be addressed in a future update; it is recommended that users configure their applications to require at least TLS protocol version 1.0 for secure communication. For additional information about this flaw, see the Knowledgebase article at https://access.redhat.com/articles/1232123 All OpenSSL users are advised to upgrade to these updated packages, which contain a backported patch to mitigate the CVE-2014-3566 issue. For the update to take effect, all services linked to the OpenSSL library (such as httpd and other SSL-enabled services) must be restarted or the system rebooted. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1152789 - CVE-2014-3566 openssl: Padding Oracle On Downgraded Legacy Encryption attack 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: openssl-0.9.8e-31.el5_11.src.rpm i386: openssl-0.9.8e-31.el5_11.i386.rpm openssl-0.9.8e-31.el5_11.i686.rpm openssl-debuginfo-0.9.8e-31.el5_11.i386.rpm openssl-debuginfo-0.9.8e-31.el5_11.i686.rpm openssl-perl-0.9.8e-31.el5_11.i386.rpm x86_64: openssl-0.9.8e-31.el5_11.i686.rpm openssl-0.9.8e-31.el5_11.x86_64.rpm openssl-debuginfo-0.9.8e-31.el5_11.i686.rpm openssl-debuginfo-0.9.8e-31.el5_11.x86_64.rpm openssl-perl-0.9.8e-31.el5_11.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: openssl-0.9.8e-31.el5_11.src.rpm i386: openssl-debuginfo-0.9.8e-31.el5_11.i386.rpm openssl-devel-0.9.8e-31.el5_11.i386.rpm x86_64: openssl-debuginfo-0.9.8e-31.el5_11.i386.rpm openssl-debuginfo-0.9.8e-31.el5_11.x86_64.rpm openssl-devel-0.9.8e-31.el5_11.i386.rpm openssl-devel-0.9.8e-31.el5_11.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: openssl-0.9.8e-31.el5_11.src.rpm i386: openssl-0.9.8e-31.el5_11.i386.rpm openssl-0.9.8e-31.el5_11.i686.rpm openssl-debuginfo-0.9.8e-31.el5_11.i386.rpm openssl-debuginfo-0.9.8e-31.el5_11.i686.rpm openssl-devel-0.9.8e-31.el5_11.i386.rpm openssl-perl-0.9.8e-31.el5_11.i386.rpm ia64: openssl-0.9.8e-31.el5_11.i686.rpm openssl-0.9.8e-31.el5_11.ia64.rpm openssl-debuginfo-0.9.8e-31.el5_11.i686.rpm openssl-debuginfo-0.9.8e-31.el5_11.ia64.rpm openssl-devel-0.9.8e-31.el5_11.ia64.rpm openssl-perl-0.9.8e-31.el5_11.ia64.rpm ppc: openssl-0.9.8e-31.el5_11.ppc.rpm openssl-0.9.8e-31.el5_11.ppc64.rpm openssl-debuginfo-0.9.8e-31.el5_11.ppc.rpm openssl-debuginfo-0.9.8e-31.el5_11.ppc64.rpm openssl-devel-0.9.8e-31.el5_11.ppc.rpm openssl-devel-0.9.8e-31.el5_11.ppc64.rpm openssl-perl-0.9.8e-31.el5_11.ppc.rpm s390x: openssl-0.9.8e-31.el5_11.s390.rpm openssl-0.9.8e-31.el5_11.s390x.rpm openssl-debuginfo-0.9.8e-31.el5_11.s390.rpm openssl-debuginfo-0.9.8e-31.el5_11.s390x.rpm openssl-devel-0.9.8e-31.el5_11.s390.rpm openssl-devel-0.9.8e-31.el5_11.s390x.rpm openssl-perl-0.9.8e-31.el5_11.s390x.rpm x86_64: openssl-0.9.8e-31.el5_11.i686.rpm openssl-0.9.8e-31.el5_11.x86_64.rpm openssl-debuginfo-0.9.8e-31.el5_11.i386.rpm openssl-debuginfo-0.9.8e-31.el5_11.i686.rpm openssl-debuginfo-0.9.8e-31.el5_11.x86_64.rpm openssl-devel-0.9.8e-31.el5_11.i386.rpm openssl-devel-0.9.8e-31.el5_11.x86_64.rpm openssl-perl-0.9.8e-31.el5_11.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/articles/1232123 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2014 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFUP95tXlSAg2UNWIIRAkc5AJ9nmEF3JBRZonktefvvJetST/IDwACfRLlK kXhpxz+knoilme+6qGxo2rQ=PYRu -----ENDPGP SIGNATURE----- -- Enterprise-watch-list mailing list
Moderate: openssl security update. Date: Thu, 16 Oct 2014 18:46:12 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Bonnie King Subject: Security ERRATA Moderate: openssl on SL5.x i386/x86_64 MIME-Version: 1.0 Synopsis: Moderate: openssl security update Advisory ID: SLSA-2014:1653-1 Issue Date: 2014-10-16 CVE Numbers: CVE-2014-3566 -- This update adds support for the TLS Fallback Signaling Cipher Suite Value (TLS_FALLBACK_SCSV), which can be used to prevent protocol downgrade attacks against applications which re-connect using a lower SSL/TLS protocol version when the initial connection indicating the highest supported protocol version fails. This can prevent a forceful downgrade of the communication to SSL 3.0. The SSL 3.0 protocol was found to be vulnerable to the padding oracle attack when using block cipher suites in cipher block chaining (CBC) mode. This issue is identified as CVE-2014-3566, and also known under the alias POODLE. This SSL 3.0 protocol flaw will not be addressed in a future update; it is recommended that users configure their applications to require at least TLS protocol version 1.0 for secure communication. For additional information about this flaw, see Upstream's Knowledgebase article at https://access.redhat.com/articles/1232123 For the update to take effect, all services linked to the OpenSSL library (such as httpd and other SSL-enabled services) must be restarted or the system rebooted. -- SL5 x86_64 openssl-0.9.8e-31.el5_11.i686.rpm openssl-0.9.8e-31.el5_11.x86_64.rpm openssl-debuginfo-0.9.8e-31.el5_11.i686.rpm openssl-debuginfo-0.9.8e-31.el5_11.x86_64.rpm openssl-perl-0.9.8e-31.el5_11.x86_64.rpm openssl-debuginfo-0.9.8e-31.el5_11.i386.rpm openssl-devel-0.9.8e-31.el5_11.i386.rpm openssl-devel-0.9.8e-31.el5_11.x86_64.rpm i386 openssl-0.9.8e-31.el5_11.i386.rpm openssl-0.9.8e-31.el5_11.i686.rpm openssl-debuginfo-0.9.8e-31.el5_11.i386.rpm openssl-debuginfo-0.9.8e-31.el5_11.i686.rpm openssl-perl-0.9.8e-31.el5_11.i386.rpm openssl-devel-0.9.8e-31.el5_11.i386.rpm - Scientific Linux Development Team . Enhance your OpenSSL security on Scientific Linux SL5.x against downgrade attacks by updating the SSL/TLS Fallback Signaling Cipher with these detailed steps. Scientific Linux, OpenSSL Update, Security Advisory, Moderate Threat, TLS Protocol. . LinuxSecurity.com Team
Important: openssl security update. Date: Thu, 16 Oct 2014 18:43:44 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Bonnie King Subject: Security ERRATA Important: openssl on SL6.x, SL7.x i386/x86_64 MIME-Version: 1.0 Synopsis: Important: openssl security update Advisory ID: SLSA-2014:1652-1 Issue Date: 2014-10-16 CVE Numbers: CVE-2014-3566 CVE-2014-3513 CVE-2014-3567 -- This update adds support for the TLS Fallback Signaling Cipher Suite Value (TLS_FALLBACK_SCSV), which can be used to prevent protocol downgrade attacks against applications which re-connect using a lower SSL/TLS protocol version when the initial connection indicating the highest supported protocol version fails. This can prevent a forceful downgrade of the communication to SSL 3.0. The SSL 3.0 protocol was found to be vulnerable to the padding oracle attack when using block cipher suites in cipher block chaining (CBC) mode. This issue is identified as CVE-2014-3566, and also known under the alias POODLE. This SSL 3.0 protocol flaw will not be addressed in a future update; it is recommended that users configure their applications to require at least TLS protocol version 1.0 for secure communication. For additional information about this flaw, see Upstream's Knowledgebase article at https://access.redhat.com/articles/1232123 A memory leak flaw was found in the way OpenSSL parsed the DTLS Secure Real-time Transport Protocol (SRTP) extension data. A remote attacker could send multiple specially crafted handshake messages to exhaust all available memory of an SSL/TLS or DTLS server. (CVE-2014-3513) A memory leak flaw was found in the way an OpenSSL handled failed session ticket integrity checks. A remote attacker could exhaust all available memory of an SSL/TLS or DTLS server by sending a large number of invalid session tickets to that server. (CVE-2014-3567) CVE-2014-3566 issue and correct the CVE-2014-3513 and CVE-2014-3567 issues. For the update to take effect, all services linked to theOpenSSL library (such as httpd and other SSL-enabled services) must be restarted or the system rebooted. -- SL6 x86_64 openssl-1.0.1e-30.el6_6.2.i686.rpm openssl-1.0.1e-30.el6_6.2.x86_64.rpm openssl-debuginfo-1.0.1e-30.el6_6.2.i686.rpm openssl-debuginfo-1.0.1e-30.el6_6.2.x86_64.rpm openssl-devel-1.0.1e-30.el6_6.2.i686.rpm openssl-devel-1.0.1e-30.el6_6.2.x86_64.rpm openssl-perl-1.0.1e-30.el6_6.2.x86_64.rpm openssl-static-1.0.1e-30.el6_6.2.x86_64.rpm i386 openssl-1.0.1e-30.el6_6.2.i686.rpm openssl-debuginfo-1.0.1e-30.el6_6.2.i686.rpm openssl-devel-1.0.1e-30.el6_6.2.i686.rpm openssl-perl-1.0.1e-30.el6_6.2.i686.rpm openssl-static-1.0.1e-30.el6_6.2.i686.rpm SL7 x86_64 openssl-1.0.1e-34.el7_0.6.x86_64.rpm openssl-debuginfo-1.0.1e-34.el7_0.6.i686.rpm openssl-debuginfo-1.0.1e-34.el7_0.6.x86_64.rpm openssl-libs-1.0.1e-34.el7_0.6.i686.rpm openssl-libs-1.0.1e-34.el7_0.6.x86_64.rpm openssl-devel-1.0.1e-34.el7_0.6.i686.rpm openssl-devel-1.0.1e-34.el7_0.6.x86_64.rpm openssl-perl-1.0.1e-34.el7_0.6.x86_64.rpm openssl-static-1.0.1e-34.el7_0.6.i686.rpm openssl-static-1.0.1e-34.el7_0.6.x86_64.rpm - Scientific Linux Development Team . Important OpenSSL upgrade published for Scientific Linux SL6.x and SL7.x mitigates significant security vulnerabilities. Update advised.. openssl update, Scientific Linux, security advisory. . Severity: Important. LinuxSecurity.com Team
The openssl cryptographic libraries have been updated to fix The openssl cryptographic libraries have been updated to fix a protocol downgrading attack which allows a man-in-the-middle a protocol downgrading attack which allows a man-in-the-middle attacker to force the usage of SSLv2. This happens due to the work-around code of SSL_OP_MSIE_SSLV2_RSA_PADDING which is included in SSL_OP_ALL (which i [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Announcement Package: openssl Announcement ID: SUSE-SA:2005:061 Date: Wed, 19 Oct 2005 12:00:00 +0000 Affected Products: SUSE LINUX 10.0 SuSE Linux 9.0 SUSE LINUX 9.1 SUSE LINUX 9.2 SUSE LINUX 9.3 SuSE Linux Desktop 1.0 SuSE Linux Enterprise Server 8 SUSE Linux Enterprise Server 9 UnitedLinux 1.0 Novell Linux Desktop 9 Open Enterprise Server Vulnerability Type: protocol downgrade attack Severity (1-10): 7 SUSE Default Package: yes Cross-References: CAN-2005-2969 Content of This Advisory: 1) Security Vulnerability Resolved: openssl protocol downgrading attack Problem Description 2) Solution or Work-Around 3) Special Instructions and Notes 4) Package Location and Checksums 5) Pending Vulnerabilities, Solutions, and Work-Arounds: See SUSE Security Summary Report. 6) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Problem Description and Brief Discussion The openssl cryptographiclibraries have been updated to fix a protocol downgrading attack which allows a man-in-the-middle attacker to force the usage of SSLv2. This happens due to the work-around code of SSL_OP_MSIE_SSLV2_RSA_PADDING which is included in SSL_OP_ALL (which is commonly used in applications). (CAN-2005-2969) Additionally this update adds the Geotrusts Equifax Root1 CA certificate to allow correct certification against Novell Inc. websites and services. The same CA is already included in Mozilla, KDE, and curl, which use separate certificate stores. 2) Solution or Work-Around Please install the updated packages. A work-around would be to disable SSL v2 support in the applications. 3) Special Instructions and Notes Restart all services using SSL communication. 4) Package Location and Checksums The preferred method for installing security updates is to use the YaST Online Update (YOU) tool. YOU detects which updates are required and automatically performs the necessary steps to verify and install them. Alternatively, download the update packages for your distribution manually and verify their integrity by the methods listed in Section 6 of this announcement. Then install the packages using the command rpm -Fhv to apply the update, replacing with the filename of the downloaded RPM package. x86 Platform: SUSE LINUX 10.0: e3327b60cd67e05c69fbad39787dccc9 24865cb7cc369352f0be0f6681c0337e SUSE LINUX 9.3: 83537e24205a2add698e1b3bdabd47da 24b05ddf75b1b1c1630f489c73009782 SUSE LINUX 9.2: eb5845c52c418f6c4dd54922854f282f 3489d04736d818da68ef83d148aadddd SUSE LINUX 9.1: 44fa57fcbdf8f3889bacb9cff6b1a09f 1faa73fc6dac13b05e40f5714f88b226 d4b72038c4552fcba9fa11b554af2eac 6b4b1eeaa0592fd7a92816ceb4658494 SuSE Linux 9.0: cf17f027255eabe00df743ead5052f1a 9ffd642f59150064dbb04644990d22b8 b411a2e07c627174edf3e59c36e2afea 9dc0fcfe4741f1d8d4a173bc850d9e7d Power PC Platform: SUSE LINUX 10.0: b0e8a0c17fbd8f49cfdbac754fd3c0ab 58cf5958a728dcaa51948c65b643e384 x86-64 Platform: SUSE LINUX 10.0: c3936949ff35609e24aa3ff916660c7b fd553f55be7b1853e6094493da3e07e6 665de86c4ae6b403f7e89b911b671ce6 b141bae445d418406c0287627746aa34 SUSE LINUX 9.3: 3133ea05502fd5ebdecd906dbb751ff8 025292747aed0b549b21dd6286afa4ee 9b50c10172a3cffd6e5095dc6487382f ab9d47dc1d0ef66219ed6363c2d1234f SUSE LINUX 9.2: 265519514837b9cc0a5e185b963e58c8 28376541a6f7cb041cafb39eab6e669f df48531e0db3877bda1f8e631c96440e c1012b7d66aab61fc5ba932ce3b3ddd5 SUSE LINUX 9.1: 97cbb139fac0a59b7e1ab5590cdd7911 4807e04cddbf761eb5da4fc1979822e5 SuSE Linux 9.0: 96767379ee26179d81231112da76ebc4 eaacfac00c7fe69bee685e427b908ede Sources: SUSE LINUX 10.0: 96f81c596120ea526f80925c928ba18d SUSE LINUX 9.3: 0e80ac579c04e13dc737c1efe57e1905 SUSE LINUX 9.2: a378099cce54b5660349de48228f97b9 SUSE LINUX 9.1: bd45e590bccf5bb6dfc24756bc5a857f 94d6dfafd61ccd20355f92907ffb8a72 SuSE Linux 9.0: af0b9e588250c2970687b518613e897a 29afc1febd81c7765e56aefe0b083ebb Our maintenance customers are notified individually. The packages are offered for installation from the maintenance web: https://www.suse.com:443/ https://www.suse.com:443/ ______________________________________________________________________________ 5) Pending Vulnerabilities, Solutions, and Work-Arounds: See SUSE Security Summary Report. ______________________________________________________________________________ 6) Authenticity Verification and Additional Information - Announcementauthenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file where you saved the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and the integrity of a package needs to be verified to ensure that it has not been tampered with. There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or RPM package: 1) Using the internal gpg signatures of the rpm package 2) MD5 checksums as provided in this announcement 1) The internal rpm package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from
Get the latest Linux and open source security news straight to your inbox.