This update fixes incorrect message output under certain locales in new mail notification, changing resource limits and listing possible completions.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-173 2005-02-26 ---------------------------------------------------------------------Product : Fedora Core 3 Name : tcsh Version : 6.13 Release : 10.FC3.1 Summary : An enhanced version of csh, the C shell. Description : Tcsh is an enhanced but completely compatible version of csh, the C shell. Tcsh is a command language interpreter which can be used both as an interactive login shell and as a shell script command processor. Tcsh includes a command line editor, programmable word completion, spelling correction, a history mechanism, job control and a C language like syntax. ---------------------------------------------------------------------Update Information: This update fixes incorrect message output under certain locales in new mail notification, changing resource limits and listing possible completions. ---------------------------------------------------------------------* Fri Feb 25 2005 Miloslav Trmac - 6.13-10.FC3.1 - Build for FC 3 * Sun Jan 30 2005 Miloslav Trmac - 6.13-11 - Fix the previous patch, handle a missed case (#146330) * Sat Jan 15 2005 Miloslav Trmac - 6.13-10 - Avoid reusing iconv_catgets' static buffer (#145177, #145195) ---------------------------------------------------------------------This update can be downloaded from: 489a2b6bac1846e74566ef3c6595e566 SRPMS/tcsh-6.13-10.FC3.1.src.rpm 70248277a4b780e91d8879007887fa15 x86_64/tcsh-6.13-10.FC3.1.x86_64.rpm aad36807a3257b66b8ccad743fa6d795 x86_64/debug/tcsh-debuginfo-6.13-10.FC3.1.x86_64.rpm 6b96805774ff226c013308f15e37d13f i386/tcsh-6.13-10.FC3.1.i386.rpm cc227e1e067ed342c245b323202ac18c i386/debug/tcsh-debuginfo-6.13-10.FC3.1.i386.rpm This update can alsobe installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Versions 6.09 and below of tcsh are vulnerable to a symbolic link attack.. ` --------------------------------------------------------------------- Red Hat, Inc. Security Advisory Synopsis: Updated tcsh packages are now available for Red Hat Linux. Advisory ID: RHSA-2000:121-04 Issue date: 2000-11-30 Updated on: 2000-12-01 Product: Red Hat Linux Keywords: tcsh symlink vulnerability Cross references: N/A --------------------------------------------------------------------- 1. Topic: Updated tcsh packages are now available for Red Hat Linux 5.2, 6.x, and 7. 2. Relevant releases/architectures: Red Hat Linux 5.2 - i386, alpha, sparc Red Hat Linux 6.0 - i386, alpha, sparc Red Hat Linux 6.1 - i386, alpha, sparc Red Hat Linux 6.2 - i386, alpha, sparc Red Hat Linux 6.2EE - i386, alpha, sparc Red Hat Linux 7.0 - i386, alpha Red Hat Linux 7.0J - i386, alpha 3. Problem description: Versions 6.09 and below of tcsh are vulnerable to a symbolic link attack. This attack can be used to cause users to destroy the contents of any file to which they have write access. 4. Solution: For each RPM for your particular architecture, run: rpm -Fvh [filename] where filename is the name of the RPM. 5. Bug IDs fixed ( for more info): 20679 - tcsh '
Proton reported on bugtraq that tcsh did not handle in-here documentscorrectly. The version of tcsh that is distributed with Debian GNU/Linux2.2r0 also suffered from this problem. . - ------------------------------------------------------------------------Debian Security Advisory
Get the latest Linux and open source security news straight to your inbox.