Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security fix for CVE-2018-17336. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-77431ab417 2018-09-30 01:08:56.541387 --------------------------------------------------------------------------------Name : udisks2 Product : Fedora 28 Version : 2.7.6 Release : 2.fc28 URL : https://github.com/storaged-project/udisks Summary : Disk Manager Description : The Udisks project provides a daemon, tools and libraries to access and manipulate disks, storage devices and technologies. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2018-17336 --------------------------------------------------------------------------------ChangeLog: * Wed Sep 26 2018 Vojtech Trefny - 2.7.6-2 - Fix string format vulnerability --------------------------------------------------------------------------------References: [ 1 ] Bug #1632828 - CVE-2018-17336 udisks: Format string vulnerability in udisks_log in udiskslogging.c https://bugzilla.redhat.com/show_bug.cgi?id=1632828 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-77431ab417' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Updated XEmacs packages that fix a string format issue are now available for Red Hat Enterprise Linux 4. This update has been rated as having important security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Important: xemacs security update Advisory ID: RHSA-2005:133-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:133.html Issue date: 2005-02-15 Updated on: 2005-02-15 Product: Red Hat Enterprise Linux CVE Names: CAN-2005-0100 - ---------------------------------------------------------------------1. Summary: Updated XEmacs packages that fix a string format issue are now available for Red Hat Enterprise Linux 4. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Problem description: XEmacs is a powerful, customizable, self-documenting, modeless text editor. Max Vozeler discovered several format string vulnerabilities in the movemail utility of XEmacs. If a user connects to a malicious POP server, an attacker can execute arbitrary code as the user running xemacs. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0100 to this issue. Users of XEmacs are advised to upgrade to these updated packages, which contain backported patches to correct this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use thefollowing command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 146706 - CAN-2005-0100 Arbitrary code execution in *emacs* 6. RPMs required: Red Hat Enterprise Linux AS version 4: SRPMS: 3578571b8fbfa877446ff2bf2aba4d33 xemacs-21.4.15-10.EL.1.src.rpm i386: 32769fed540b952fa0b13099656c99df xemacs-21.4.15-10.EL.1.i386.rpm 7ea9196d920a918309f882b4ec36daff xemacs-common-21.4.15-10.EL.1.i386.rpm 28a03178e6cda6a0f9ae41a63cf604ce xemacs-el-21.4.15-10.EL.1.i386.rpm 7edc52f8b80c8c108bc8144736a758be xemacs-info-21.4.15-10.EL.1.i386.rpm 7adf376bc1a202d1509c39e17b6ca47d xemacs-nox-21.4.15-10.EL.1.i386.rpm ia64: 5da6d5f42eaf911e2d3531dd6bb3a438 xemacs-21.4.15-10.EL.1.ia64.rpm 0d62c335e2dd1f2b97f6d7700882ce73 xemacs-common-21.4.15-10.EL.1.ia64.rpm 6a55af1abbe00a4ff5fc8bea3f8f362b xemacs-el-21.4.15-10.EL.1.ia64.rpm b014369cff4e33efb41d2e1926f1ebe6 xemacs-info-21.4.15-10.EL.1.ia64.rpm 170a29a6e539d290a8a1e0a4aa04f80a xemacs-nox-21.4.15-10.EL.1.ia64.rpm ppc: 604b838be1c70f78a069838aedd3583f xemacs-21.4.15-10.EL.1.ppc.rpm 19ca8f80d9150c61a4e4532003caa40a xemacs-common-21.4.15-10.EL.1.ppc.rpm 98623c7463fa2f35562a7bac89f24a59 xemacs-el-21.4.15-10.EL.1.ppc.rpm 659cf3c867f3c1089936c0eae8646995 xemacs-info-21.4.15-10.EL.1.ppc.rpm ce04905c75b1c1b4e250ec64b646c088 xemacs-nox-21.4.15-10.EL.1.ppc.rpm s390: 67c1e30c3da90c9f929a0454cda90480 xemacs-21.4.15-10.EL.1.s390.rpm 87f1b473112c1417e3e5005898aeaba7 xemacs-common-21.4.15-10.EL.1.s390.rpm 62b74ac3cc227f94c7385616e6e98bb9 xemacs-el-21.4.15-10.EL.1.s390.rpm 931788a7c98b15bf3971f512e74f6c9a xemacs-info-21.4.15-10.EL.1.s390.rpm 1c4fc34a77f266dd46036f28f2355552 xemacs-nox-21.4.15-10.EL.1.s390.rpm s390x: 43e7f05b16a56833fba58286f84aff3a xemacs-21.4.15-10.EL.1.s390x.rpm 9d5ab2fcf69ede7e50beca7d057c364e xemacs-common-21.4.15-10.EL.1.s390x.rpm 705516d8db6bfae82a7c600db243a55e xemacs-el-21.4.15-10.EL.1.s390x.rpm 0d10cc5bb25fcf0e7f8a135c5d59dfb9 xemacs-info-21.4.15-10.EL.1.s390x.rpm 0f2a83207bd62d69ad51e35c8ba7713a xemacs-nox-21.4.15-10.EL.1.s390x.rpm x86_64: 60675f3441482c33d304cb6ba1c055fc xemacs-21.4.15-10.EL.1.x86_64.rpm 625de01c2f5f6385597ce95fb636a88b xemacs-common-21.4.15-10.EL.1.x86_64.rpm 3dcd4dabcf9e7967ff381f74f8a55804 xemacs-el-21.4.15-10.EL.1.x86_64.rpm 2b0b2d67309d87609dd1d3e7d0cd457f xemacs-info-21.4.15-10.EL.1.x86_64.rpm 2ba03342b10f3002db64e4247eab39e2 xemacs-nox-21.4.15-10.EL.1.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: SRPMS: 3578571b8fbfa877446ff2bf2aba4d33 xemacs-21.4.15-10.EL.1.src.rpm i386: 32769fed540b952fa0b13099656c99df xemacs-21.4.15-10.EL.1.i386.rpm 7ea9196d920a918309f882b4ec36daff xemacs-common-21.4.15-10.EL.1.i386.rpm 28a03178e6cda6a0f9ae41a63cf604ce xemacs-el-21.4.15-10.EL.1.i386.rpm 7edc52f8b80c8c108bc8144736a758be xemacs-info-21.4.15-10.EL.1.i386.rpm 7adf376bc1a202d1509c39e17b6ca47d xemacs-nox-21.4.15-10.EL.1.i386.rpm x86_64: 60675f3441482c33d304cb6ba1c055fc xemacs-21.4.15-10.EL.1.x86_64.rpm 625de01c2f5f6385597ce95fb636a88b xemacs-common-21.4.15-10.EL.1.x86_64.rpm 3dcd4dabcf9e7967ff381f74f8a55804 xemacs-el-21.4.15-10.EL.1.x86_64.rpm 2b0b2d67309d87609dd1d3e7d0cd457f xemacs-info-21.4.15-10.EL.1.x86_64.rpm 2ba03342b10f3002db64e4247eab39e2 xemacs-nox-21.4.15-10.EL.1.x86_64.rpm Red Hat Enterprise Linux ES version 4: SRPMS: 3578571b8fbfa877446ff2bf2aba4d33 xemacs-21.4.15-10.EL.1.src.rpm i386: 32769fed540b952fa0b13099656c99df xemacs-21.4.15-10.EL.1.i386.rpm 7ea9196d920a918309f882b4ec36daff xemacs-common-21.4.15-10.EL.1.i386.rpm 28a03178e6cda6a0f9ae41a63cf604ce xemacs-el-21.4.15-10.EL.1.i386.rpm 7edc52f8b80c8c108bc8144736a758be xemacs-info-21.4.15-10.EL.1.i386.rpm 7adf376bc1a202d1509c39e17b6ca47d xemacs-nox-21.4.15-10.EL.1.i386.rpm ia64: 5da6d5f42eaf911e2d3531dd6bb3a438 xemacs-21.4.15-10.EL.1.ia64.rpm 0d62c335e2dd1f2b97f6d7700882ce73 xemacs-common-21.4.15-10.EL.1.ia64.rpm 6a55af1abbe00a4ff5fc8bea3f8f362b xemacs-el-21.4.15-10.EL.1.ia64.rpm b014369cff4e33efb41d2e1926f1ebe6 xemacs-info-21.4.15-10.EL.1.ia64.rpm 170a29a6e539d290a8a1e0a4aa04f80a xemacs-nox-21.4.15-10.EL.1.ia64.rpm x86_64: 60675f3441482c33d304cb6ba1c055fc xemacs-21.4.15-10.EL.1.x86_64.rpm 625de01c2f5f6385597ce95fb636a88b xemacs-common-21.4.15-10.EL.1.x86_64.rpm 3dcd4dabcf9e7967ff381f74f8a55804 xemacs-el-21.4.15-10.EL.1.x86_64.rpm 2b0b2d67309d87609dd1d3e7d0cd457f xemacs-info-21.4.15-10.EL.1.x86_64.rpm 2ba03342b10f3002db64e4247eab39e2 xemacs-nox-21.4.15-10.EL.1.x86_64.rpm Red Hat Enterprise Linux WS version 4: SRPMS: 3578571b8fbfa877446ff2bf2aba4d33 xemacs-21.4.15-10.EL.1.src.rpm i386: 32769fed540b952fa0b13099656c99df xemacs-21.4.15-10.EL.1.i386.rpm 7ea9196d920a918309f882b4ec36daff xemacs-common-21.4.15-10.EL.1.i386.rpm 28a03178e6cda6a0f9ae41a63cf604ce xemacs-el-21.4.15-10.EL.1.i386.rpm 7edc52f8b80c8c108bc8144736a758be xemacs-info-21.4.15-10.EL.1.i386.rpm 7adf376bc1a202d1509c39e17b6ca47d xemacs-nox-21.4.15-10.EL.1.i386.rpm ia64: 5da6d5f42eaf911e2d3531dd6bb3a438 xemacs-21.4.15-10.EL.1.ia64.rpm 0d62c335e2dd1f2b97f6d7700882ce73 xemacs-common-21.4.15-10.EL.1.ia64.rpm 6a55af1abbe00a4ff5fc8bea3f8f362b xemacs-el-21.4.15-10.EL.1.ia64.rpm b014369cff4e33efb41d2e1926f1ebe6 xemacs-info-21.4.15-10.EL.1.ia64.rpm 170a29a6e539d290a8a1e0a4aa04f80a xemacs-nox-21.4.15-10.EL.1.ia64.rpm x86_64: 60675f3441482c33d304cb6ba1c055fc xemacs-21.4.15-10.EL.1.x86_64.rpm 625de01c2f5f6385597ce95fb636a88b xemacs-common-21.4.15-10.EL.1.x86_64.rpm 3dcd4dabcf9e7967ff381f74f8a55804 xemacs-el-21.4.15-10.EL.1.x86_64.rpm 2b0b2d67309d87609dd1d3e7d0cd457f xemacs-info-21.4.15-10.EL.1.x86_64.rpm 2ba03342b10f3002db64e4247eab39e2 xemacs-nox-21.4.15-10.EL.1.x86_64.rpm These packages are GPG signed by Red Hat forsecurity. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CAN-2005-0100 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2005 Red Hat, Inc. . Crucial XEmacs patch for CentOS addresses character encoding bug with potential security risks.. XEmacs Security Update, Red Hat Code Execution, XEmacs Risk Mitigation. . Severity: Important. LinuxSecurity.com Team
Update to 21.4.17 stable release, which also fixes the CAN-2005-0100 movemail string format vulnerability and the AltGr issue for European input.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-146 2005-02-14 ---------------------------------------------------------------------Product : Fedora Core 3 Name : xemacs Version : 21.4.17 Release : 0.FC3 Summary : A different version of Emacs. Description : XEmacs is a highly customizable open source text editor and application development system. It is protected under the GNU Public License and related to other versions of Emacs, in particular GNU Emacs. Its emphasis is on modern graphical user interface support and an open software development model, similar to Linux. This package contains xemacs built for X Windows with MULE support. ---------------------------------------------------------------------Update Information: Update to 21.4.17 stable release, which also fixes the CAN-2005-0100 movemail string format vulnerability and the AltGr issue for European input. ---------------------------------------------------------------------* Mon Feb 7 2005 Jens Petersen - 21.4.17-1 - update to 21.4.17 - fixes movemail format string vulnerability (CAN-2005-0100, 146705) - xemacs-21.4.16-xutil-keysym-144601.patch no longer needed * Tue Jan 25 2005 Jens Petersen - 21.4.16-2 - workaround xorg-x11 issue with iso-level3-shift (Ville Skyttä, 144601) * Mon Dec 13 2004 Jens Petersen - 21.4.16-1 - update to new stable release - no longer need configure-ppc-ldscript.patch and xemacs-21.4.15-pui-120437.patch - default to unified diff in .xemacs/init.el * Thu Nov 18 2004 Jens Petersen - 21.4.15-10 - show xemacs again in the desktop menu (132567) ---------------------------------------------------------------------This update can be downloaded from: 0643ce40c75e63bd0c3517b0fd37dd8e SRPMS/xemacs-21.4.17-0.FC3.src.rpm c22ed89c0629b8032d2c15019e3df91c x86_64/xemacs-21.4.17-0.FC3.x86_64.rpm 3f9d4f981e55ba4a34f1a462b7b045c0 x86_64/xemacs-common-21.4.17-0.FC3.x86_64.rpm 7473de9e737937b8a959edc6605c6b2d x86_64/xemacs-nox-21.4.17-0.FC3.x86_64.rpm d203f83f9cb7c3a9ef9e50e047fdb899 x86_64/xemacs-el-21.4.17-0.FC3.x86_64.rpm d103de529ad9e9c349dd4e15328a8a76 x86_64/xemacs-info-21.4.17-0.FC3.x86_64.rpm be715c074a3d8b07ec012db026eb7d99 x86_64/debug/xemacs-debuginfo-21.4.17-0.FC3.x86_64.rpm f61b8ed753232bc0bcba0393d3fb90fb i386/xemacs-21.4.17-0.FC3.i386.rpm dd33128ed8cf0862f19c0640c9c5fa84 i386/xemacs-common-21.4.17-0.FC3.i386.rpm c3d709f47ea784b06fb2d732ee9fb34e i386/xemacs-nox-21.4.17-0.FC3.i386.rpm ab6db513be70fa76a9cccd463f889c53 i386/xemacs-el-21.4.17-0.FC3.i386.rpm 58fc1b5ef9e53620b8eb8950e8e0cabe i386/xemacs-info-21.4.17-0.FC3.i386.rpm 7f2c7dda2f84409df7c48d1912215fd8 i386/debug/xemacs-debuginfo-21.4.17-0.FC3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Update to 21.4.17 stable release, which also fixes the CAN-2005-0100 movemail string format vulnerability.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-145 2005-02-14 ---------------------------------------------------------------------Product : Fedora Core 2 Name : xemacs Version : 21.4.17 Release : 0.FC2 Summary : A different version of Emacs. Description : XEmacs is a highly customizable open source text editor and application development system. It is protected under the GNU Public License and related to other versions of Emacs, in particular GNU Emacs. Its emphasis is on modern graphical user interface support and an open software development model, similar to Linux. This package contains xemacs built for X Windows with MULE support. ---------------------------------------------------------------------Update Information: Update to 21.4.17 stable release, which also fixes the CAN-2005-0100 movemail string format vulnerability. ---------------------------------------------------------------------* Mon Feb 7 2005 Jens Petersen - update to 21.4.17 - fixes movemail format string vulnerability (CAN-2005-0100, 146705) - xemacs-21.4.16-xutil-keysym-144601.patch no longer needed * Tue Jan 25 2005 Jens Petersen - 21.4.16-2 - workaround xorg-x11 issue with iso-level3-shift (Ville Skyttä, 144601) * Mon Dec 13 2004 Jens Petersen - 21.4.16-1 - update to new stable release - no longer need configure-ppc-ldscript.patch and xemacs-21.4.15-pui-120437.patch - default to unified diff in .xemacs/init.el * Thu Nov 18 2004 Jens Petersen - 21.4.15-10 - show xemacs again in the desktop menu (132567) * Mon Oct 18 2004 Jens Petersen - 21.4.15-9 - fix etag alternatives removal when uninstalling (Karsten Hopp, 136137) * Wed Oct 6 2004 Jens Petersen - xemacs-el no longer requires xemacs for -nox users (Lars Hupfeldt Nielsen, 134479) * Thu Sep 302004 Jens Petersen - 21.4.15-8 - cleanup and update .desktop file - make xemacs not appear in the desktop menu (Seth Nickell,132567) - move the desktop file from -common to main package - etags is now handled by alternatives (92256) - no longer require ctags - turn back on wnn support and add xemacs-21.4.15-wnnfix-128362.patch (Yukihiro Nakai, 128362) * Tue Jun 15 2004 Elliot Lee - rebuilt * Mon Jun 7 2004 Jens Petersen - 21.4.15-6 - don't link with -export-dynamic on ia64 to stop dumped function pointers from breaking (Roland McGrath & Jakub Jelinek, #106744) - disable dynamic module support on ia64 - change the xemacs-info uninstall script from %postun to %preun and move the post/preun install-info requires to xemacs-info - simplify coding-system setup somewhat in site-start.el - fix up the desktop file (Ville Skyttä, 123135) - xemacs-nox now requires xemacs-sumo - build without xfs since it seems to cause some problem with fonts missing * Wed May 5 2004 Jens Petersen - move install-info requirement to xemacs-info - drop unnecessary Canna-libs requirement ---------------------------------------------------------------------This update can be downloaded from: d97d1380dba413cbddedda2fa141394a SRPMS/xemacs-21.4.17-0.FC2.src.rpm 303906a89774a0bd34d84354859264c6 x86_64/xemacs-21.4.17-0.FC2.x86_64.rpm 104f72f402d2e83af7a6c067c9d37333 x86_64/xemacs-common-21.4.17-0.FC2.x86_64.rpm 0c90a50234004203cfe7e97c3d08ca8d x86_64/xemacs-nox-21.4.17-0.FC2.x86_64.rpm 07f12cb446ffa6c92aada9b2a3411680 x86_64/xemacs-el-21.4.17-0.FC2.x86_64.rpm 9cd30580fc3b572a0bd7defe19d3fa6b x86_64/xemacs-info-21.4.17-0.FC2.x86_64.rpm 18a67f26082b215599a07f2818bd434a x86_64/debug/xemacs-debuginfo-21.4.17-0.FC2.x86_64.rpm 3c01ec4518483f5c39e1fefb7a896d60 i386/xemacs-21.4.17-0.FC2.i386.rpm e640edccfe9d85c6d78b73ab00843662 i386/xemacs-common-21.4.17-0.FC2.i386.rpm bbbef68286645419681a3e5625532d29 i386/xemacs-nox-21.4.17-0.FC2.i386.rpm 68f22b910cefcc42bc020e3331721661 i386/xemacs-el-21.4.17-0.FC2.i386.rpm 2a3bb0839ad8c3a0c173b5791cba6b8d i386/xemacs-info-21.4.17-0.FC2.i386.rpm 69fef3ec6d429bc548a2c602b0a919be i386/debug/xemacs-debuginfo-21.4.17-0.FC2.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- --------------enig9404029E17EA88AA57787F95 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE-----Version: GnuPG v1.2.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - iD8DBQFCEX8e8SXyPe8n7dERAiXFAJ9XQFuZ7cNbZKJrlouuqomX5iFdmACfXqQw gu8f/zjzjca00TfoeeUzPNU=IPht -----END PGP SIGNATURE-------------------enig9404029E17EA88AA57787F95-- --===============1329973991=Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --fedora-announce-list mailing list
Updated XEmacs packages that fix a string format issue are now available.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated xemacs packages fix security issue Advisory ID: RHSA-2005:134-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:134.html Issue date: 2005-02-10 Updated on: 2005-02-10 Product: Red Hat Enterprise Linux CVE Names: CAN-2005-0100 - ---------------------------------------------------------------------1. Summary: Updated XEmacs packages that fix a string format issue are now available. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: XEmacs is a powerful, customizable, self-documenting, modeless text editor. Max Vozeler discovered several format string vulnerabilities in the movemail utility of XEmacs. If a user connects to a malicious POP server, an attacker can execute arbitrary code as the user running xemacs. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0100 to this issue. Users of XEmacs are advised to upgrade to these updated packages, which contain backported patches to correct this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to installpackages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 146704 - CAN-2005-0100 Arbitrary code execution in *emacs* 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 4d31836bc71ca0e31ffdcd2601699d85 xemacs-21.4.6-6.9.1.src.rpm i386: 9b918791022dbd365d1c2ffc7487ad37 xemacs-21.4.6-6.9.1.i386.rpm e951c1189a2098befdb5f3e7c7806e38 xemacs-el-21.4.6-6.9.1.i386.rpm 0ae98221a5979e4d22c6c5a82ec88682 xemacs-info-21.4.6-6.9.1.i386.rpm ia64: f4ef0907a0a8b648307095916e59e5e2 xemacs-21.4.6-6.9.1.ia64.rpm 165bffd4faf333bef4d6f1c9d1be28f4 xemacs-el-21.4.6-6.9.1.ia64.rpm 42fdb40e2f69005f5d574e633c889ca7 xemacs-info-21.4.6-6.9.1.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 4d31836bc71ca0e31ffdcd2601699d85 xemacs-21.4.6-6.9.1.src.rpm ia64: f4ef0907a0a8b648307095916e59e5e2 xemacs-21.4.6-6.9.1.ia64.rpm 165bffd4faf333bef4d6f1c9d1be28f4 xemacs-el-21.4.6-6.9.1.ia64.rpm 42fdb40e2f69005f5d574e633c889ca7 xemacs-info-21.4.6-6.9.1.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: 4d31836bc71ca0e31ffdcd2601699d85 xemacs-21.4.6-6.9.1.src.rpm i386: 9b918791022dbd365d1c2ffc7487ad37 xemacs-21.4.6-6.9.1.i386.rpm e951c1189a2098befdb5f3e7c7806e38 xemacs-el-21.4.6-6.9.1.i386.rpm 0ae98221a5979e4d22c6c5a82ec88682 xemacs-info-21.4.6-6.9.1.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 4d31836bc71ca0e31ffdcd2601699d85 xemacs-21.4.6-6.9.1.src.rpm i386: 9b918791022dbd365d1c2ffc7487ad37 xemacs-21.4.6-6.9.1.i386.rpm e951c1189a2098befdb5f3e7c7806e38 xemacs-el-21.4.6-6.9.1.i386.rpm 0ae98221a5979e4d22c6c5a82ec88682 xemacs-info-21.4.6-6.9.1.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: 6366093e19b29b094e694f9c98dd247b xemacs-21.4.13-8.ent.1.src.rpm i386: cf850b6ef4f2d8cb5b135d64d06603e7 xemacs-21.4.13-8.ent.1.i386.rpm 20ce76b7491f4925c6eb50988c1ee6fd xemacs-el-21.4.13-8.ent.1.i386.rpm 30591934bda8c960d6a4a7413a0c99b9 xemacs-info-21.4.13-8.ent.1.i386.rpm ia64: 92b20d9de180d11b88c5fa58ad5a0dbf xemacs-21.4.13-8.ent.1.ia64.rpm c3070054bc6a0b31744538b5e007d4ba xemacs-el-21.4.13-8.ent.1.ia64.rpm 9e025747828aab85df935b8549a7785d xemacs-info-21.4.13-8.ent.1.ia64.rpm ppc: 108e7a89e0a3fa98f68eb577a27d282c xemacs-21.4.13-8.ent.1.ppc.rpm ffa9533b7ce42210266485f03a23415c xemacs-el-21.4.13-8.ent.1.ppc.rpm f72e70f4cd85f1ad8313984d3d4107fc xemacs-info-21.4.13-8.ent.1.ppc.rpm s390: 59a254a6ceab69616f83826e50ae7a30 xemacs-21.4.13-8.ent.1.s390.rpm c50eacecae3000edd5fbc8a878c72142 xemacs-el-21.4.13-8.ent.1.s390.rpm d25d73f36604c415b8ec6e7c95fda9fe xemacs-info-21.4.13-8.ent.1.s390.rpm s390x: 2788db105bb473b1d773495006d7aee7 xemacs-21.4.13-8.ent.1.s390x.rpm c337eb51c51849a1d1d3580b206a0dd3 xemacs-el-21.4.13-8.ent.1.s390x.rpm 2accf5d242d37dd20a194c3f9231cd4d xemacs-info-21.4.13-8.ent.1.s390x.rpm x86_64: 8b043f8ee239f9ddfc3fd06fea0a2610 xemacs-21.4.13-8.ent.1.x86_64.rpm da4c3c22771c470f641156ae392364b3 xemacs-el-21.4.13-8.ent.1.x86_64.rpm e3eee7414558f7da341a7544fd2de084 xemacs-info-21.4.13-8.ent.1.x86_64.rpm Red Hat Desktop version 3: SRPMS: 6366093e19b29b094e694f9c98dd247b xemacs-21.4.13-8.ent.1.src.rpm i386: cf850b6ef4f2d8cb5b135d64d06603e7 xemacs-21.4.13-8.ent.1.i386.rpm 20ce76b7491f4925c6eb50988c1ee6fd xemacs-el-21.4.13-8.ent.1.i386.rpm 30591934bda8c960d6a4a7413a0c99b9 xemacs-info-21.4.13-8.ent.1.i386.rpm x86_64: 8b043f8ee239f9ddfc3fd06fea0a2610 xemacs-21.4.13-8.ent.1.x86_64.rpm da4c3c22771c470f641156ae392364b3 xemacs-el-21.4.13-8.ent.1.x86_64.rpm e3eee7414558f7da341a7544fd2de084 xemacs-info-21.4.13-8.ent.1.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: 6366093e19b29b094e694f9c98dd247b xemacs-21.4.13-8.ent.1.src.rpm i386: cf850b6ef4f2d8cb5b135d64d06603e7 xemacs-21.4.13-8.ent.1.i386.rpm 20ce76b7491f4925c6eb50988c1ee6fd xemacs-el-21.4.13-8.ent.1.i386.rpm 30591934bda8c960d6a4a7413a0c99b9 xemacs-info-21.4.13-8.ent.1.i386.rpm ia64: 92b20d9de180d11b88c5fa58ad5a0dbf xemacs-21.4.13-8.ent.1.ia64.rpm c3070054bc6a0b31744538b5e007d4ba xemacs-el-21.4.13-8.ent.1.ia64.rpm 9e025747828aab85df935b8549a7785d xemacs-info-21.4.13-8.ent.1.ia64.rpm x86_64: 8b043f8ee239f9ddfc3fd06fea0a2610 xemacs-21.4.13-8.ent.1.x86_64.rpm da4c3c22771c470f641156ae392364b3 xemacs-el-21.4.13-8.ent.1.x86_64.rpm e3eee7414558f7da341a7544fd2de084 xemacs-info-21.4.13-8.ent.1.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: 6366093e19b29b094e694f9c98dd247b xemacs-21.4.13-8.ent.1.src.rpm i386: cf850b6ef4f2d8cb5b135d64d06603e7 xemacs-21.4.13-8.ent.1.i386.rpm 20ce76b7491f4925c6eb50988c1ee6fd xemacs-el-21.4.13-8.ent.1.i386.rpm 30591934bda8c960d6a4a7413a0c99b9 xemacs-info-21.4.13-8.ent.1.i386.rpm ia64: 92b20d9de180d11b88c5fa58ad5a0dbf xemacs-21.4.13-8.ent.1.ia64.rpm c3070054bc6a0b31744538b5e007d4ba xemacs-el-21.4.13-8.ent.1.ia64.rpm 9e025747828aab85df935b8549a7785d xemacs-info-21.4.13-8.ent.1.ia64.rpm x86_64: 8b043f8ee239f9ddfc3fd06fea0a2610 xemacs-21.4.13-8.ent.1.x86_64.rpm da4c3c22771c470f641156ae392364b3 xemacs-el-21.4.13-8.ent.1.x86_64.rpm e3eee7414558f7da341a7544fd2de084 xemacs-info-21.4.13-8.ent.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CAN-2005-0100 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2005 Red Hat, Inc. . The latest XEmacs updates resolve a formatting bug on Fedora Linux, tackling essential vulnerabilities.. XEmacs Security Patch, Red Hat Advisory, String Format Issue, Linux Security Update. . Severity: Critical. LinuxSecurity.comTeam
SUS contains a string format bug that could lead to local privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200409-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: SUS: Local root vulnerability Date: September 14, 2004 Bugs: #63927 ID: 200409-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= SUS contains a string format bug that could lead to local privilege escalation. Background ========= SUS is a utility that allows regular users to be able to execute certain commands as root. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-admin/sus < 2.0.2-r1 > = 2.0.2-r1 Description ========== Leon Juranic found a bug in the logging functionality of SUS that can lead to local privilege escalation. A format string vulnerability exists in the log() function due to an incorrect call to the syslog() function. Impact ===== An attacker with local user privileges can potentially exploit this vulnerability to gain root access. Workaround ========= There is no known workaround at this time. Resolution ========= All SUS users should upgrade to the latest version: # emerge sync # emerge -pv "> =app-admin/sus-2.0.2-r1" # emerge "> =app-admin/sus-2.0.2-r1" References ========= [ 1 ] SUS ChangeLog [ 2 ] BugTraq Advisory Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200409-17 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Updated nss_ldap packages are now available for Red Hat Linux 6.2, 7,7.1, 7.2, and 7.3. These packages fix a string format vulnerability in thepam_ldap module.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated nss_ldap packages fix pam_ldap vulnerability Advisory ID: RHSA-2002:084-22 Issue date: 2002-05-07 Updated on: 2002-06-04 Product: Red Hat Linux Keywords: pam_ldap format string syslog security Cross references: Obsoletes: RHSA-2000:024 CVE Names: CAN-2002-0374 --------------------------------------------------------------------- 1. Topic: Updated nss_ldap packages are now available for Red Hat Linux 6.2, 7, 7.1, 7.2, and 7.3. These packages fix a string format vulnerability in the pam_ldap module. [Update Jun 4, 2002] Replacement packages have been added for Red Hat Linux 6.2. The previous packages could not be installed with the version of RPM that shipped with Red Hat Linux 6.2 2. Relevant releases/architectures: Red Hat Linux 6.2 - alpha, i386, sparc Red Hat Linux 7.0 - alpha, i386 Red Hat Linux 7.1 - alpha, i386, ia64 Red Hat Linux 7.2 - i386, ia64 Red Hat Linux 7.3 - i386 3. Problem description: The pam_ldap module provides authentication for user access to a system by consulting a directory using LDAP. Versions of pam_ldap prior to version 144 include a format string bug in the logging function. The packages included in this erratum update pam_ldap to version 144, fixing this bug. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2002-0374 to this issue. Due to differences in the default behavior of the pam_ldap module when performing account management, the version of authconfig included in Red Rat Linux 7.2 generates incorrect /etc/pam.d/system-auth files for the version of pam_ldap included in this erratum. Thus, an updated version of authconfig for Red Hat Linux 7.2 isincluded in this erratum (versions of authconfig included with Red Hat Linux 7, 7.1, and 7.3 are not affected). Our thanks go to the pam_ldap team at padl.com for bringing this to our attention. A previous revision of this erratum included packages which could not be installed with the version of RPM included with Red Hat Linux 6.2. While they can be installed with versions of RPM which have been released as errata for Red Hat Linux 6.2, this revision includes packages which remove this restriction. Packages for Red Hat Linux 7, 7.1, 7.2, and 7.3 have not been modified. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Linux 6.2: SRPMS: alpha: i386: sparc: Red Hat Linux 7.0: SRPMS: alpha: i386: Red Hat Linux 7.1: SRPMS: alpha: i386: ia64: Red Hat Linux 7.2: SRPMS: i386: ia64: Red Hat Linux 7.3: SRPMS: i386: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 1d947c9c45f55aca6736b3f2999469a5 6.2/en/os/SRPMS/nss_ldap-189-1.6.2.1.src.rpm 4d57f85b69e5c9ec91f25781631722826.2/en/os/alpha/nss_ldap-189-1.6.2.1.alpha.rpm e1b67000a19c392dfa1e8c2db5f269ae 6.2/en/os/i386/nss_ldap-189-1.6.2.1.i386.rpm c9d5b7348ab2281447eda442363ab89e 6.2/en/os/sparc/nss_ldap-189-1.6.2.1.sparc.rpm 1eb57f3965d1c68d7891c8a858573ae1 7.0/en/os/SRPMS/nss_ldap-189-1.7.src.rpm 6f3838a447d9766b782886695df52149 7.0/en/os/alpha/nss_ldap-189-1.7.alpha.rpm 8484f482a1a6816a0c5e1dade2d7fd33 7.0/en/os/i386/nss_ldap-189-1.7.i386.rpm 1eb57f3965d1c68d7891c8a858573ae1 7.1/en/os/SRPMS/nss_ldap-189-1.7.src.rpm 6f3838a447d9766b782886695df52149 7.1/en/os/alpha/nss_ldap-189-1.7.alpha.rpm 8484f482a1a6816a0c5e1dade2d7fd33 7.1/en/os/i386/nss_ldap-189-1.7.i386.rpm 5805176343cfd2b7e033ce8cf8d0706d 7.1/en/os/ia64/nss_ldap-189-1.7.ia64.rpm 7216e533cd6cab1ff4fb46171a585b43 7.2/en/os/SRPMS/authconfig-4.1.19.2-1.src.rpm d977011dc7bbc3eea5b3e01ce7d364d9 7.2/en/os/SRPMS/nss_ldap-189-2.src.rpm 7282baea30503699772dd3e2aa866a11 7.2/en/os/i386/authconfig-4.1.19.2-1.i386.rpm d2b2402e6c59f886556872d6b2bc2f16 7.2/en/os/i386/nss_ldap-189-2.i386.rpm 0c451e5cb1cb7e5a5d7152aa91ee3834 7.2/en/os/ia64/authconfig-4.1.19.2-1.ia64.rpm 7d07126091032adfdae1d2192b9ca264 7.2/en/os/ia64/nss_ldap-189-2.ia64.rpm d977011dc7bbc3eea5b3e01ce7d364d9 7.3/en/os/SRPMS/nss_ldap-189-2.src.rpm d2b2402e6c59f886556872d6b2bc2f16 7.3/en/os/i386/nss_ldap-189-2.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: About You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: https://github.com/PADL CVE -CVE-2002-0374 Copyright(c) 2000, 2001, 2002 Red Hat, Inc. `. Updated nss_ldap packages fix a string format issue in pam_ldap for Red Hat, enhancing system security.. nss_ldap,pam_ldap update,Red Hat advisory,format string issue,Linux security. . Severity: Critical. LinuxSecurity.com Team
There is a format string vulnerability in icecast that can allow a remote user to execute arbitrary code.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: String format vulnerability in icecast Advisory ID: RHSA-2001:004-04 Issue date: 2001-01-23 Updated on: 2001-01-24 Product: Red Hat Powertools Keywords: Cross references: Obsoletes: --------------------------------------------------------------------- 1. Topic: A remote vulnerablity allows execution of arbitrary code. 2. Relevant releases/architectures: Red Hat Powertools 6.0 - alpha, i386, sparc Red Hat Powertools 6.1 - alpha, i386, sparc Red Hat Powertools 6.2 - alpha, i386, sparc Red Hat Powertools 7.0 - alpha, i386 3. Problem description: A string format vulnerability that allows the execution of arbitrary commands exists in all versions of icecast. A patch was posted to Bugtraq to solve the problem and has been incorporated into this update. All usersof icecast should apply this update. 4. Solution: For each RPM for your particular architecture, run: rpm -Fvh [filename] where filename is the name of the RPM. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Powertools 6.0: SRPMS: alpha: i386: sparc: Red Hat Powertools 6.1: SRPMS: alpha: i386: sparc: Red Hat Powertools 6.2: SRPMS: alpha: i386: sparc: Red Hat Powertools 7.0: SRPMS: alpha: i386: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 6e10a41120782afa633229384a3de9f5 6.0/SRPMS/icecast-1.3.8.beta2-2.src.rpm feba1b51874808c6d59eae717adc116d 6.0/alpha/icecast-1.3.8.beta2-2.alpha.rpm 17f5ed6b597b38456faff7e8bd1eb828 6.0/i386/icecast-1.3.8.beta2-2.i386.rpm e8c06fc3348e60a3053e7fad06dedeec 6.0/sparc/icecast-1.3.8.beta2-2.sparc.rpm 6e10a41120782afa633229384a3de9f5 6.1/SRPMS/icecast-1.3.8.beta2-2.src.rpm feba1b51874808c6d59eae717adc116d 6.1/alpha/icecast-1.3.8.beta2-2.alpha.rpm 17f5ed6b597b38456faff7e8bd1eb828 6.1/i386/icecast-1.3.8.beta2-2.i386.rpm e8c06fc3348e60a3053e7fad06dedeec 6.1/sparc/icecast-1.3.8.beta2-2.sparc.rpm 6e10a41120782afa633229384a3de9f5 6.2/SRPMS/icecast-1.3.8.beta2-2.src.rpm feba1b51874808c6d59eae717adc116d 6.2/alpha/icecast-1.3.8.beta2-2.alpha.rpm 17f5ed6b597b38456faff7e8bd1eb828 6.2/i386/icecast-1.3.8.beta2-2.i386.rpm e8c06fc3348e60a3053e7fad06dedeec 6.2/sparc/icecast-1.3.8.beta2-2.sparc.rpm 417343d579a7067720300adc8c99b38d 7.0/SRPMS/icecast-1.3.8.beta2-3.src.rpm b728ad07c46c37221e98d5ee905efb2d 7.0/alpha/icecast-1.3.8.beta2-3.alpha.rpm 9fc78917546ab1bc41fb9951d47bf749 7.0/i386/icecast-1.3.8.beta2-3.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Thanks to |CyRaX| for finding the problem and posting it to Bugtraq. For more information please see Copyright(c) 2000, 2001 Red Hat, Inc. `. The vulnerability in Icecast's string handling presents a potential risk for remote code execution. It is crucial to perform an upgrade at once to mitigate this serious security issue.. Red Hat Powertools, Icecast RCE, String Format Vulnerability. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.