Updated firefox packages that fix several security bugs are now available Fedora Core 6. This update has been rated as having critical security impact by the Fedora Security Response Team. Mozilla Firefox is an open source Web browser. Several flaws were found in the way Firefox processed certain malformed JavaScript code. A web page containing malicious JavaScript code could cause Firefox to crash or potentially execute arbitrary code as the user running Firefox. . ---------------------------------------------------------------------Fedora Update Notification FEDORA-2007-549 2007-05-31 ---------------------------------------------------------------------Product : Fedora Core 6 Name : yelp Version : 2.16.0 Release : 13.fc6 Summary : A system documentation reader from the Gnome project Description : Yelp is the Gnome 2 help/documentation browser. It is designed to help you browse all the documentation on your system in one central tool. ---------------------------------------------------------------------Update Information: Updated firefox packages that fix several security bugs are now available Fedora Core 6. This update has been rated as having critical security impact by the Fedora Security Response Team. Mozilla Firefox is an open source Web browser. Several flaws were found in the way Firefox processed certain malformed JavaScript code. A web page containing malicious JavaScript code could cause Firefox to crash or potentially execute arbitrary code as the user running Firefox. (CVE-2007-2867, CVE-2007-2868) A flaw was found in the way Firefox handled certain FTP PASV commands. A malicious FTP server could use this flaw to perform a rudimentary port-scan of machines behind a user's firewall. (CVE-2007-1562) Several denial of service flaws were found in the way Firefox handled certain form and cookie data. A malicious web site that is able to set arbitrary form and cookie data could prevent Firefox from functioningproperly. (CVE-2007-1362, CVE-2007-2869) A flaw was found in the way Firefox handled the addEventListener JavaScript method. A malicious web site could use this method to access or modify sensitive data from another web site. (CVE-2007-2870) A flaw was found in the way Firefox displayed certain web content. A malicious web page could generate content that would overlay user interface elements such as the hostname and security indicators, tricking users into thinking they are visiting a different site. (CVE-2007-2871) Users of Firefox are advised to upgrade to these erratum packages, which contain Firefox version 1.5.0.12 that corrects these issues. ---------------------------------------------------------------------* Wed May 30 2007 Christopher Aillon - 2.16.0-13 - Rebuild against newer gecko ---------------------------------------------------------------------This update can be downloaded from: f180b68f4c5970753df93402214121a63f429aeb SRPMS/yelp-2.16.0-13.fc6.src.rpm f180b68f4c5970753df93402214121a63f429aeb noarch/yelp-2.16.0-13.fc6.src.rpm 51a2f81c7e8e0ec06934f37bfc87d11640b77ead ppc/debug/yelp-debuginfo-2.16.0-13.fc6.ppc.rpm 1779f3eb0565252531055330a3954b22016b202d ppc/yelp-2.16.0-13.fc6.ppc.rpm 59d1165fe5704217a8965c7b863b9a3933d03c53 x86_64/debug/yelp-debuginfo-2.16.0-13.fc6.x86_64.rpm 8c54a35cdabaae9ba415c5a588daf94cc54f1050 x86_64/yelp-2.16.0-13.fc6.x86_64.rpm adfc02cecf94414ff1219855e878a753bcdef44f i386/debug/yelp-debuginfo-2.16.0-13.fc6.i386.rpm 690097b89973a5e2221c1911a66c9583c7e25b78 i386/yelp-2.16.0-13.fc6.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailinglist
Updated glibc packages that address several bugs are now available. This update has been rated as having low security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Low: glibc security update Advisory ID: RHSA-2005:261-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:261.html Issue date: 2005-04-28 Updated on: 2005-04-28 Product: Red Hat Enterprise Linux Keywords: glibc LD_DEBUG catchsegv glibcbug CVE Names: CAN-2004-0968 CAN-2004-1382 CAN-2004-1453 - ---------------------------------------------------------------------1. Summary: Updated glibc packages that address several bugs are now available. This update has been rated as having low security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 3. Problem description: The GNU libc packages (known as glibc) contain the standard C libraries used by applications. Flaws in the catchsegv and glibcbug scripts were discovered. A local user could utilize these flaws to overwrite files via a symlink attack on temporary files. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0968 and CAN-2004-1382 to these issues. It was discovered that the use of LD_DEBUG and LD_SHOW_AUXV were not restricted for a setuid program. A local user could utilize this flaw to gain information, such as the list of symbols used by the program. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1453 to this issue. This erratum also addresses the following bugs in the GNU C Library: - - Now avoids calling sigaction(SIGPIPE, ...) in syslog implementation - - Fixed poll on Itanium - - Now allows setenv/putenv in shared library constructors Users of glibc are advised to upgrade to these erratum packages that remove the unecessary glibcbug script and contain backported patches to correct these other issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 140068 - [RHAS2.1] CAN-2004-0968 temporary file vulnerabilities in catchsegv script 140487 - [RHAS2.1] Bad declaration of __syscall_poll can cause bogus values for timeout to be passed to the kernel 148814 - CAN-2004-1453 Information leak with LD_DEBUG 148800 - CAN-2004-1382 insecure temporary file usage 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 86c397f7614278f57b9b814d6adedace glibc-2.2.4-32.20.src.rpm i386: 5b601e85eba293c52d9fe15d8e766a12 glibc-2.2.4-32.20.i386.rpm e1c21533e3d86da39390e93d4b93060e glibc-2.2.4-32.20.i686.rpm b7eda3e6a3b7f24813415c692bde5cff glibc-common-2.2.4-32.20.i386.rpm 0b39ef1f661609a0346675b1877a6288 glibc-devel-2.2.4-32.20.i386.rpm 88ed7d4adfcf4627478367a253a65989 glibc-profile-2.2.4-32.20.i386.rpm b3d6d4389676fc0652277f490d47dfec nscd-2.2.4-32.20.i386.rpm ia64: 158103afa78aec998e3db120d245cd37 glibc-2.2.4-32.20.ia64.rpm 321c25cf3605db040fef49a79c443618 glibc-common-2.2.4-32.20.ia64.rpm a5eb76dc9b8dbcf8cfd6938d1a957977 glibc-devel-2.2.4-32.20.ia64.rpm b24148c15938f32f7a5f7df0773eb092 glibc-profile-2.2.4-32.20.ia64.rpm 925478d53517e5cd62762f608b4e26f8 nscd-2.2.4-32.20.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 86c397f7614278f57b9b814d6adedace glibc-2.2.4-32.20.src.rpm ia64: 158103afa78aec998e3db120d245cd37 glibc-2.2.4-32.20.ia64.rpm 321c25cf3605db040fef49a79c443618 glibc-common-2.2.4-32.20.ia64.rpm a5eb76dc9b8dbcf8cfd6938d1a957977 glibc-devel-2.2.4-32.20.ia64.rpm b24148c15938f32f7a5f7df0773eb092 glibc-profile-2.2.4-32.20.ia64.rpm 925478d53517e5cd62762f608b4e26f8 nscd-2.2.4-32.20.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: 86c397f7614278f57b9b814d6adedace glibc-2.2.4-32.20.src.rpm i386: 5b601e85eba293c52d9fe15d8e766a12 glibc-2.2.4-32.20.i386.rpm e1c21533e3d86da39390e93d4b93060e glibc-2.2.4-32.20.i686.rpm b7eda3e6a3b7f24813415c692bde5cff glibc-common-2.2.4-32.20.i386.rpm 0b39ef1f661609a0346675b1877a6288 glibc-devel-2.2.4-32.20.i386.rpm 88ed7d4adfcf4627478367a253a65989 glibc-profile-2.2.4-32.20.i386.rpm b3d6d4389676fc0652277f490d47dfec nscd-2.2.4-32.20.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 86c397f7614278f57b9b814d6adedace glibc-2.2.4-32.20.src.rpm i386: 5b601e85eba293c52d9fe15d8e766a12 glibc-2.2.4-32.20.i386.rpm e1c21533e3d86da39390e93d4b93060e glibc-2.2.4-32.20.i686.rpm b7eda3e6a3b7f24813415c692bde5cff glibc-common-2.2.4-32.20.i386.rpm 0b39ef1f661609a0346675b1877a6288 glibc-devel-2.2.4-32.20.i386.rpm 88ed7d4adfcf4627478367a253a65989 glibc-profile-2.2.4-32.20.i386.rpm b3d6d4389676fc0652277f490d47dfec nscd-2.2.4-32.20.i386.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-CAN-2004-0968 https://www.cve.org/CVERecord?id=CVE-CAN-2004-1382 https://www.cve.org/CVERecord?id=CVE-CAN-2004-1453 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact Copyright 2005 Red Hat, Inc. . Oracle introduces a minor patch for OpenSSL, fixing various vulnerabilities and enhancing local user permissions to mitigate potential exploitation threats.. glibc Update, Red Hat Enterprise, Security Advisory, Low Severity Bugs, System Exploits. . Severity: Low. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.