Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Utemper can be userd to overwrite privileged files with symlink.. Red Hat Security Advisory Synopsis: Updated utempter package fixes vulnerability Advisory ID: RHSA-2004:175-01 Issue date: 2004-04-30 Updated on: 2004-04-30 Product: Red Hat Linux Keywords: Cross references: Obsoletes: CVE Names: CAN-2004-0233 - --------------------------------------------------------------------- 1. Topic: An updated utempter package that fixes a potential symlink vulnerability is now available. 2. Relevant releases/architectures: Red Hat Linux 9 - i386 3. Problem description: Utempter is a utility that allows terminal applications such as xterm and screen to update utmp and wtmp without requiring root privileges. Steve Grubb discovered a flaw in Utempter which allowed device names containing directory traversal sequences such as '/../'. In combination with an application that trusts the utmp or wtmp files, this could allow a local attacker the ability to overwrite privileged files using a symlink. Users should upgrade to this new version of utempter, which fixes this vulnerability. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. If up2date fails to connectto Red Hat Network due to SSL Certificate Errors, you need to install a version of the up2date client with an updated certificate. The latest version of up2date is available from the Red Hat FTP site and may also be downloaded directly from the RHN website: https://access.redhat.com 5. RPMs required: Red Hat Linux 9: SRPMS: i386: 6. Verification: MD5 sum Package Name - -------------------------------------------------------------------------- b7f13df830c3f64eef6c6895edfb3b1f 9/en/os/SRPMS/utempter-0.5.5-2.RHL9.0.src.rpm b207cd5661c7d687c3503399ce3bb611 9/en/os/i386/utempter-0.5.5-2.RHL9.0.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available from You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: CVE -CVE-2004-0233 8. Contact: The Red Hat security contact is . More contact details at Copyright 2004 Red Hat, Inc. . The updated configuration tool from Red Hat tackles a critical symlink flaw that permits unauthorized file overwriting.. Red Hat Linux,Utempter Update,Symlink Security,Critical Patch,RPM Security Fix. . Severity: Critical. LinuxSecurity.com Team
Updated OpenSSL packages that fix several remote denial of servicevulnerabilities are now available.. Red Hat Security Advisory Synopsis: Updated OpenSSL packages fix vulnerabilities Advisory ID: RHSA-2004:121-01 Issue date: 2004-03-17 Updated on: 2004-03-17 Product: Red Hat Linux Keywords: DoS Cross references: Obsoletes: RHBA-2003:292 CVE Names: CAN-2004-0079 CAN-2004-0081 CAN-2004-0112 - --------------------------------------------------------------------- 1. Topic: Updated OpenSSL packages that fix several remote denial of service vulnerabilities are now available. 2. Relevant releases/architectures: Red Hat Linux 9 - i386, i686 3. Problem description: OpenSSL is a toolkit that implements Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols as well as a full-strength general purpose cryptography library. Testing performed by the OpenSSL group using the Codenomicon TLS Test Tool uncovered a null-pointer assignment in the do_change_cipher_spec() function in OpenSSL 0.9.6c-0.9.6l and 0.9.7a-0.9.7c. A remote attacker could perform a carefully-crafted SSL/TLS handshake against a server that used the OpenSSL library in such a way as to cause OpenSSL to crash. Depending on the application this could lead to a denial of service. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0079 to this issue. Stephen Henson discovered a flaw in the SSL/TLS handshaking code when using Kerberos ciphersuites in OpenSSL 0.9.7a-0.9.7c. A remote attacker could perform a carefully-crafted SSL/TLS handshake against a server configured to use Kerberos ciphersuites in such a way as to cause OpenSSL to crash. Most applications have no ability to use Kerberos ciphersuites and are therefore unaffected by this issue. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0112 to this issue. Testing performed by the OpenSSL group using theCodenomicon TLS Test Tool uncovered a bug in older versions of OpenSSL 0.9.6 prior to 0.9.6d that can lead to a denial of service attack (infinite loop). The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0081 to this issue. This issue affects only the OpenSSL compatibility packages shipped with Red Hat Linux 9. These updated packages contain patches provided by the OpenSSL group that protect against these issues. NOTE: Because server applications are affected by this issue, users are advised to either restart all services using OpenSSL functionality or restart their system after installing these updated packages. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. If up2date fails to connect to Red Hat Network due to SSL Certificate Errors, you need to install a version of the up2date client with an updated certificate. The latest version of up2date is available from the Red Hat FTP site and may also be downloaded directly from the RHN website: https://access.redhat.com 5. RPMs required: Red Hat Linux 9: SRPMS: i386: i686: 6. Verificationx: MD5 sum Package Name --------------------------------------------------------------------------- fccbfa420f0e35abf2e3f1b7cfda504b 9/en/os/SRPMS/openssl-0.9.7a-20.2.src.rpm 6596a94a38bab238fcdf44f39fa9286a 9/en/os/SRPMS/openssl096-0.9.6-25.9.src.rpm aec0dff60087c0deb0a3c7dbfe913b09 9/en/os/SRPMS/openssl096b-0.9.6b-15.src.rpm 9fbb1bc859dc155cfcb697b08d47c2b4 9/en/os/i386/openssl-0.9.7a-20.2.i386.rpm 2e29e4f4d0d2094f4adef29bda25f33f 9/en/os/i386/openssl-devel-0.9.7a-20.2.i386.rpm edc37f7dea6dd4eb9ef3b04546f58661 9/en/os/i386/openssl-perl-0.9.7a-20.2.i386.rpm efba1c47b07e268b6181dd3d712813fa 9/en/os/i386/openssl096-0.9.6-25.9.i386.rpm b49b6268f779cfd8284a375bf03d6641 9/en/os/i386/openssl096b-0.9.6b-15.i386.rpm e39bbb9c8235f9b6584eb8472f68a68c 9/en/os/i686/openssl-0.9.7a-20.2.i686.rpm These packages are GPG signed by Red Hat for security. Our key is available from https://access.redhat.com/security/team/key You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: CVE -CVE-2004-0079 CVE -CVE-2004-0081 CVE -CVE-2004-0112 8. Contact: The Red Hat security contact is . More contact details at https://www.redhat.com/en/technologies/all-products Copyright 2003 Red Hat, Inc. . Updated OpenSSL iterations released by Red Hat tackle numerous remote denial of service flaws critical for protecting system reliability.. OpenSSL Update, Red Hat Linux, Denial of Service. . Severity: Critical. LinuxSecurity.com Team
Malformed BMP file can segfault mail reader.. Red Hat Security Advisory Synopsis: Updated gdk-pixbuf packages fix denial of service vulnerability Advisory ID: RHSA-2004:102-01 Issue date: 2004-03-10 Updated on: 2004-03-10 Product: Red Hat Linux Keywords: DoS Cross references: Obsoletes: CVE Names: CAN-2004-0111 - --------------------------------------------------------------------- 1. Topic: Updated gdk-pixbuf packages that fix a denial of service vulnerability that could affect applications such as Evolution are now available. 2. Relevant releases/architectures: Red Hat Linux 9 - i386 3. Problem description: The gdk-pixbuf package contains an image loading library used with the GNOME GUI desktop environment. In Red Hat Linux 9 this library is used by applications, such as Evolution, to load images. Thomas Kristensen discovered a bitmap file that would cause the Evolution mail reader to crash. This issue was caused by a flaw that affects versions of the gdk-pixbuf package prior to 0.20. To exploit this flaw, a remote attacker could send (via email) a carefully-crafted BMP file, which would cause Evolution to crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0111 to this issue. Users are advised to upgrade to these updated packages containing gdk-pixbuf version 0.22, which is not vulnerable to this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red HatNetwork. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. If up2date fails to connect to Red Hat Network due to SSL Certificate Errors, you need to install a version of the up2date client with an updated certificate. The latest version of up2date is available from the Red Hat FTP site and may also be downloaded directly from the RHN website: https://access.redhat.com 5. RPMs required: Red Hat Linux 9: SRPMS: i386: 6. Verification: MD5 sum Package Name - -------------------------------------------------------------------------- df19bd665aba2b00d36ced57aa4d6ffe 9/en/os/SRPMS/gdk-pixbuf-0.22.0-6.1.0.src.rpm 4b0dd19751fc5fdd00222e556af8bc02 9/en/os/i386/gdk-pixbuf-0.22.0-6.1.0.i386.rpm 73781fffcb9cb8109d0391454d821ecf 9/en/os/i386/gdk-pixbuf-devel-0.22.0-6.1.0.i386.rpm 38fe3fce4d19ea79df588f62182d3e26 9/en/os/i386/gdk-pixbuf-gnome-0.22.0-6.1.0.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available from https://access.redhat.com/security/team/key You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: CVE -CVE-2004-0111 8. Contact: The Red Hat security contact is . More contact details at https://www.redhat.com/en/technologies/all-products Copyright 2003 Red Hat, Inc. . Red Hat has identified a critical flaw in gdk-pixbuf, posing a Denial of Service risk to email apps like Evolution, necessitating urgent updates and patches for security.. gdk-pixbuf update, red hat advisory, DoS issue, mail reader crash. . Severity: Critical. LinuxSecurity.com Team
Updated mod_python packages that fix a denial of service vulnerability are now available for Red Hat Linux.. Red Hat Security Advisory Synopsis: Updated mod_python packages fix denial of service vulnerability Advisory ID: RHSA-2004:063-01 Issue date: 2004-02-26 Updated on: 2004-02-26 Product: Red Hat Linux Keywords: mod_python DoS Cross references: Obsoletes: CVE Names: CAN-2003-0973 - --------------------------------------------------------------------- 1. Topic: Updated mod_python packages that fix a denial of service vulnerability are now available for Red Hat Linux. 2. Relevant releases/architectures: Red Hat Linux 9 - i386 3. Problem description: mod_python embeds the Python language interpreter within the Apache httpd server. A bug has been found in mod_python versions 3.0.3 and earlier that can lead to a denial of service vulnerability. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0973 to this issue. Although Red Hat Linux 9 shipped with a version of mod_python that contains this bug, our testing was unable to trigger the denial of service vulnerability. mod_python users are, however, advised to upgrade to these errata packages, which contain a backported patch that corrects this bug. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat UpdateAgent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. If up2date fails to connect to Red Hat Network due to SSL Certificate Errors, you need to install a version of the up2date client with an updated certificate. The latest version of up2date is available from the Red Hat FTP site and may also be downloaded directly from the RHN website: https://access.redhat.com 5. RPMs required: Red Hat Linux 9: SRPMS: i386: 6. Verification: MD5 sum Package Name - -------------------------------------------------------------------------- b7b838c6152fa51ccdc376a788fcd799 9/en/os/SRPMS/mod_python-3.0.1-4.src.rpm bba40347ca46775a0f4545c08776b149 9/en/os/i386/mod_python-3.0.1-4.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available from https://access.redhat.com/security/team/key You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: [mod_python] [ANNOUNCE] Mod_python 3.0.4 and 2.7.9 CVE -CVE-2003-0973 8. Contact: The Red Hat security contact is . More contact details at https://www.redhat.com/en/technologies/all-products Copyright 2003 Red Hat, Inc. . Revised mod_python modules for Red Hat resolve service interruption vulnerabilities, bolstering system defense.. Red Hat Linux, Mod_python Update, Security Patch, Deny Service. . Severity: Critical. LinuxSecurity.com Team
Multiple buffer overflows that affect versions of Gaim 0.75 and earlier.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated Gaim packages fix various vulnerabiliies Advisory ID: RHSA-2004:032-01 Issue date: 2004-01-19 Updated on: 2004-01-23 Product: Red Hat Linux Keywords: gaim im Cross references: Obsoletes: CVE Names: CAN-2004-0006 CAN-2004-0007 CAN-2004-0008 - --------------------------------------------------------------------- 1. Topic: Updated Gaim packages that fix a number of serious vulnerabilities are now available. 2. Relevant releases/architectures: Red Hat Linux 9 - i386 3. Problem description: Gaim is an instant messenger client that can handle multiple protocols. Stefan Esser audited the Gaim source code and found a number of bugs that have security implications. Due to the nature of instant messaging many of these bugs require man-in-the-middle attacks between client and server. However at least one of the buffer overflows could be exploited by an attacker sending a carefully-constructed malicious message through a server. The issues include: Multiple buffer overflows that affect versions of Gaim 0.75 and earlier. 1) When parsing cookies in a Yahoo web connection, 2) YMSG protocol overflows parsing the Yahoo login webpage, 3) a YMSG packet overflow, 4) flaws in the URL parser, and 5) flaws in HTTP Proxy connect. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0006 to these issues. A buffer overflow in Gaim 0.74 and earlier in the Extract Info Field Function used for MSN and YMSG protocol handlers. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0007 to this issue. An integer overflow in Gaim 0.74 and earlier, when allocating memory for a directIM packet results in heap overflow. The Common Vulnerabilities and Exposures project(cve.mitre.org) has assigned the name CAN-2004-0008 to this issue. All users of Gaim should upgrade to these erratum packages, which contain backported security patches correcting these issues. Red Hat would like to thank Steffan Esser for finding and reporting these issues and Jacques A. Vidrine for providing initial patches. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. If up2date fails to connect to Red Hat Network due to SSL Certificate Errors, you need to install a version of the up2date client with an updated certificate. The latest version of up2date is available from the Red Hat FTP site and may also be downloaded directly from the RHN website: https://access.redhat.com 5. Bug IDs fixed ( for more info): 113845 - CAN-2004-0006/7/8 Multiple vulnerabilities in Gaim 6. RPMs required: Red Hat Linux 9: SRPMS: i386: 7. Verification: MD5 sum Package Name - -------------------------------------------------------------------------- eaf62f33af192f2cb049cc8593f35aae 9/en/os/SRPMS/gaim-0.75-0.9.0.src.rpm 27835ea8b63b3e876ab18c73e8e7fbd6 9/en/os/i386/gaim-0.75-0.9.0.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available fromhttps://access.redhat.com/security/team/key You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 8. References: CVE -CVE-2004-0006 CVE -CVE-2004-0007 CVE -CVE-2004-0008 9. Contact: The Red Hat security contact is . More contact details at https://www.redhat.com/en/products Copyright 2003 Red Hat, Inc. . Recent enhancements to Gaim by Red Hat tackle significant buffer overflow issues, bolstering the security framework for messaging software.. Gaim Security Update, Red Hat Linux, Buffer Overflow Risks, IM Client Security. . Severity: Important. LinuxSecurity.com Team
Phong Nguyen identified a severe bug in the way GnuPG creates and usesElGamal keys, when those keys are used both to sign and encrypt data. Thisvulnerability can be used to trivially recover the private key.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated gnupg packages disable ElGamal keys Advisory ID: RHSA-2003:390-01 Issue date: 2003-12-10 Updated on: 2003-12-10 Product: Red Hat Linux Keywords: gnupg elgamal sign encrypt Cross references: Obsoletes: RHSA-2003-175 RHSA-2001:073 RHSA-2001:063 CVE Names: CAN-2003-0971 - --------------------------------------------------------------------- 1. Topic: Updated gnupg packages are now available for Red Hat Linux. These updates disable the ability to generate ElGamal keys (used for both signing and encrypting) and disable the ability to use ElGamal public keys for encrypting data. 2. Relevant releases/architectures: Red Hat Linux 7.1 - i386 Red Hat Linux 7.2 - i386, ia64 Red Hat Linux 7.3 - i386 Red Hat Linux 8.0 - i386 Red Hat Linux 9 - i386 3. Problem description: GnuPG is a utility for encrypting data and creating digital signatures. Phong Nguyen identified a severe bug in the way GnuPG creates and uses ElGamal keys, when those keys are used both to sign and encrypt data. This vulnerability can be used to trivially recover the private key. While the default behavior of GnuPG when generating keys does not lead to the creation of unsafe keys, by overriding the default settings an unsafe key could have been created. If you are using ElGamal keys, you should revoke those keys immediately. The packages included in this update do not make ElGamal keys safe to use; they merely include a patch by David Shaw that disables functions that would generate or use ElGamal keys. To determine if your key is affected, run the following command to obtain a list ofsecret keys that you have on your secret keyring: gpg --list-secret-keys The output of this command includes both the size and type of the keys found, and will look similar to this example: /home/example/.gnupg/secring.gpg - ---------------------------------------------------- sec 1024D/01234567 2000-10-17 Example User uid Example User The key length, type, and ID are listed together, separated by a forward slash. In the example output above, the key's type is "D" (DSA, sign and encrypt). Your key is unsafe if and only if the key type is "G" (ElGamal, sign and encrypt). In the above example, the secret key is safe to use, while the secret key in the following example is not: /home/example/.gnupg/secring.gpg - ---------------------------------------------------- sec 1024G/01234567 2000-10-17 Example User uid Example User For more details regarding this issue, as well as instructions on how to revoke any keys that are unsafe, refer to the advisory available from the GnuPG web site: The GNU Privacy Guard 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. If up2date fails to connect to Red Hat Network due to SSL Certificate Errors, you need to installa version of the up2date client with an updated certificate. The latest version of up2date is available from the Red Hat FTP site and may also be downloaded directly from the RHN website: 5. RPMs required: Red Hat Linux 7.1: SRPMS: i386: Red Hat Linux 7.2: SRPMS: i386: ia64: Red Hat Linux 7.3: SRPMS: i386: Red Hat Linux 8.0: SRPMS: i386: Red Hat Linux 9: SRPMS: i386: 6. Verification: MD5 sum Package Name - -------------------------------------------------------------------------- 4d62554490e85b7cc1f0cfef6518a979 7.1/en/os/SRPMS/gnupg-1.0.7-12.src.rpm 0591a2079aff5e7979b0225b568bceaa 7.1/en/os/i386/gnupg-1.0.7-12.i386.rpm b619c30c293094d7dcd18487d8e62a43 7.2/en/os/SRPMS/gnupg-1.0.7-13.src.rpm e7e3e75afd1ccd2267ccc7847c76ebb4 7.2/en/os/i386/gnupg-1.0.7-13.i386.rpm 6fb21011ca42ff395b8cfc7dce4c2936 7.2/en/os/ia64/gnupg-1.0.7-13.ia64.rpm b619c30c293094d7dcd18487d8e62a43 7.3/en/os/SRPMS/gnupg-1.0.7-13.src.rpm e7e3e75afd1ccd2267ccc7847c76ebb4 7.3/en/os/i386/gnupg-1.0.7-13.i386.rpm bc375882f13e5c10eb29eb3615de911d 8.0/en/os/SRPMS/gnupg-1.0.7-14.src.rpm a3de0844778cd994258f121330ff6d62 8.0/en/os/i386/gnupg-1.0.7-14.i386.rpm e1f31f4a07ebb5b4040f8f6ca3816cc4 9/en/os/SRPMS/gnupg-1.2.1-9.src.rpm 604a2fb5b809ec99280871f46507f4a1 9/en/os/i386/gnupg-1.2.1-9.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available from https://access.redhat.com/security/team/key You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: How can one tell what kind of a key one has set up? CVE -CVE-2003-0971 8. Contact: The Red Hat security contact is . More contact details at https://www.redhat.com/en/products Copyright 2003 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7(GNU/Linux) iD8DBQE/19/bXlSAg2UNWIIRApHAAKDDT9iYhOHv0ld977q+en9pERGINgCffIEe p12aGFwXHe+nF62Bq5NPSGk=/+7o -----END PGP SIGNATURE----- _______________________________________________ Red Hat-watch-list mailing list To unsubscribe, visit: Hat-watch-list . Serious GnuPG signing key flaw resolved. Update now to protect against possible key breach risks. Comprehensive information provided.. GnuPG Sign Key, ElGamal Key Security, Red Hat Update, Cryptography Advisory. . Severity: Critical. LinuxSecurity.com Team
Updated CUPS packages that fix a problem where CUPS can hang are now available.. ` - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated CUPS packages fix denial of service Advisory ID: RHSA-2003:275-01 Issue date: 2003-11-03 Updated on: 2003-11-03 Product: Red Hat Linux Keywords: Cross references: Obsoletes: CVE Names: CAN-2003-0788 - --------------------------------------------------------------------- 1. Topic: Updated CUPS packages that fix a problem where CUPS can hang are now available. 2. Relevant releases/architectures: Red Hat Linux 8.0 - i386 Red Hat Linux 9 - i386 3. Problem description: CUPS is a print spooler. Paul Mitcheson reported a situation where the CUPS Internet Printing Protocol (IPP) implementation in CUPS versions prior to 1.1.19 would get into a busy loop. This could result in a denial of service. In order to exploit this bug an attacker would need to have the ability to make a TCP connection to the IPP port (by default 631). Users of CUPS are advised to install these updated packages, which contain a backported security patch and are not vulnerable to this issue. These packages also fix a problem with the LPD backend that could cause jobs to be repeated. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch theRed Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. If up2date fails to connect to Red Hat Network due to SSL Certificate Errors, you need to install a version of the up2date client with an updated certificate. The latest version of up2date is available from the Red Hat FTP site and may also be downloaded directly from the RHN website: 5. Bug IDs fixed ( for more info): 97958 - IPP at 100% processor doing nothing useful. 107256 - duplicated printing 6. RPMs required: Red Hat Linux 8.0: SRPMS: i386: Red Hat Linux 9: SRPMS: i386: 7. Verification: MD5 sum Package Name - -------------------------------------------------------------------------- b1a11f2d32869f71d81a51699d0d1161 8.0/en/os/SRPMS/cups-1.1.17-0.9.src.rpm 58703f2e272be1f437dc08afdfd56cbf 8.0/en/os/i386/cups-1.1.17-0.9.i386.rpm 0f4fd001995c32f1073170506e551c7f 8.0/en/os/i386/cups-devel-1.1.17-0.9.i386.rpm 51e4409b5ba1c4a36b5c4a9448379d68 8.0/en/os/i386/cups-libs-1.1.17-0.9.i386.rpm 0a0d87d587bc144f43fbc358e7ddc3b0 9/en/os/SRPMS/cups-1.1.17-13.3.0.3.src.rpm 4419de18b94b013ae0ec939ae5bf415b 9/en/os/i386/cups-1.1.17-13.3.0.3.i386.rpm b1af1f42aae099e96e29113e0bab0e6f 9/en/os/i386/cups-devel-1.1.17-13.3.0.3.i386.rpm bef46344f1619d0be4ad0bc6f04dafdf 9/en/os/i386/cups-libs-1.1.17-13.3.0.3.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available from https://access.redhat.com/security/team/key You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 8. References: CVE -CVE-2003-0788 9. Contact: The Red Hat security contact is . More contact details at https://www.redhat.com/en/technologies/all-products Copyright 2003 Red Hat, Inc. -----BEGIN PGPSIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQE/ph8gXlSAg2UNWIIRAiuGAJ4pDVFSA4l5EXiESmoAVqfhmDPHdQCeJrsi 5UqixEKtXSqYnZ492V7g+cQ=B7Na -----END PGP SIGNATURE----- `. Canonical has issued a notice regarding updates for OpenSSH that tackle a severe security flaw, recommending immediate implementation of fixes to safeguard SSH services.. Red Hat CUPS update, DoS Fix, CUPS Security Patch, Linux Service Update. . Severity: Critical. LinuxSecurity.com Team
An off-by-one bug has been discovered in versions of wu-ftpd up to andincluding 2.6.2.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated wu-ftpd packages fix remote vulnerability. Advisory ID: RHSA-2003:245-01 Issue date: 2003-07-31 Updated on: 2003-07-31 Product: Red Hat Linux Keywords: ftpd Cross references: Obsoletes: RHSA-2001:157 CVE Names: CAN-2003-0466 - --------------------------------------------------------------------- 1. Topic: Updated wu-ftpd packages are now available that fix a remotely exploitable security issue. 2. Relevant releases/architectures: Red Hat Linux 7.1 - i386 Red Hat Linux 7.1 for iSeries (64 bit) - ppc Red Hat Linux 7.1 for pSeries (64 bit) - ppc Red Hat Linux 7.2 - i386, ia64 Red Hat Linux 7.3 - i386 Red Hat Linux 8.0 - i386 3. Problem description: The wu-ftpd package contains the Washington University FTP (File Transfer Protocol) server daemon. FTP is a method of transferring files between computers on a network. An off-by-one bug has been discovered in versions of wu-ftpd up to and including 2.6.2. On a vulnerable system, a remote attacker would be able to exploit this bug to gain root privileges. Red Hat Linux 7.1 and 7.2 contain a version of wu-ftpd that is affected by this bug, although it is believed this issue will not be remotely exploitable due to compiler padding of the buffer targeted for the overflow. Red Hat Linux 7.3 and 8.0 contain a version of wu-ftpd that is remotely exploitable. Red Hat advises all users of wu-ftpd to upgrade to these erratum packages, which contain a security patch and is not vulnerable to this issue. Red Hat would like to thank Wojciech Purczynski and Janusz Niewiadomski of ISEC Security Research for their responsible disclosure of this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. Toupdate all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. RPMs required: Red Hat Linux 7.1: SRPMS: i386: Red Hat Linux 7.1 for iSeries (64 bit): SRPMS: ppc: Red Hat Linux 7.1 for pSeries (64 bit): SRPMS: ppc: Red Hat Linux 7.2: SRPMS: i386: ia64: Red Hat Linux 7.3: SRPMS: i386: Red Hat Linux 8.0: SRPMS: i386: 6. Verification: MD5 sum Package Name - -------------------------------------------------------------------------- eaad5f7ffbf2399c13623da2c6ff4e83 7.1/en/os/SRPMS/wu-ftpd-2.6.2-11.71.1.src.rpm ecbd80d787844a3ab579e6058b0704c2 7.1/en/os/i386/wu-ftpd-2.6.2-11.71.1.i386.rpm eaad5f7ffbf2399c13623da2c6ff4e83 7.1/en/os/iSeries/SRPMS/wu-ftpd-2.6.2-11.71.1.src.rpm cf9324b0e936ffb3aa7a738f26108eb6 7.1/en/os/iSeries/ppc/wu-ftpd-2.6.2-11.71.1.ppc.rpm eaad5f7ffbf2399c13623da2c6ff4e83 7.1/en/os/pSeries/SRPMS/wu-ftpd-2.6.2-11.71.1.src.rpm cf9324b0e936ffb3aa7a738f26108eb6 7.1/en/os/pSeries/ppc/wu-ftpd-2.6.2-11.71.1.ppc.rpm 3f526a5e04806d71560c7357189c08fa 7.2/en/os/SRPMS/wu-ftpd-2.6.2-11.72.1.src.rpm 22ce902ae1255927825bec7a6cbd9a68 7.2/en/os/i386/wu-ftpd-2.6.2-11.72.1.i386.rpm 8587632893b8a74580b50cdf1a4923f6 7.2/en/os/ia64/wu-ftpd-2.6.2-11.72.1.ia64.rpm a25b0c5c9575cfa2e18578b8ec30e7ab 7.3/en/os/SRPMS/wu-ftpd-2.6.2-11.73.1.src.rpm 3c53df7e43666c6b1dfc6b9bbbe4da067.3/en/os/i386/wu-ftpd-2.6.2-11.73.1.i386.rpm dca07c4e90f308b49f8ac6b8d463536f 8.0/en/os/SRPMS/wu-ftpd-2.6.2-12.src.rpm d7b8fc5c0f9c0938dbddcea76f8e1e22 8.0/en/os/i386/wu-ftpd-2.6.2-12.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available from Product Signing Keys - Red Hat Customer Portal You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: isec CVE -CVE-2003-0466 8. Contact: The Red Hat security contact is . More contact details at All Red Hat products Copyright 2003 Red Hat, Inc. . A significant flaw in the openssh suite for Debian Linux could lead to possible unauthorized entry. Take immediate action to patch and protect your environments.. Red Hat Linux, wu-ftpd update, critical patch, remote exploit fix, off-by-one issue. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.