Fedora Essential and Critical Security Patch Updates - Page 885
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
This update fixes some minor bugs discovered after the final freeze date.
Due to debugging code left accidently in the FC3 udev package, SIGCHLD signals are blocked in udev, which prevents getting the proper exit status in udev.rules. This means no cdrom symlinks are created and pam_console does not apply desktop user ownerships to any cdrom devices.
A buffer overflow has been found in zip which will lead to a buffer overflow when a user try to create a zip archive which contains very long filenames.
A buffer overflow has been found in zip which will lead to a buffer overflow when a user try to create a zip archive which contains very long filenames.
This new release of wget adds support for large files >2Gb, p.e. DVD ISOs.
system-config-users is a graphical utility for administrating users and groups. It depends on the libuser library.
This update fixes bug #137499 where some DocBook transformations broke following the latest security release of libxml2-2.6.15-2 . It brings back libxslt in sync with the installed version of libxml2.
Update to gpdf 2.8.0, which fixes the CAN-2004-0888 security issue.
A problem with PDF handling was discovered by Chris Evans, and has been fixed. The Common Vulnerabilities and Exposures project (https://www.mitre.org) has assigned the name CAN-2004-0888 to this issue.
The FreeRADIUS Server Project is a high performance and highly configurable GPL'd free RADIUS server. The server is similar in some respects to Livingston's 2.0 server.
Multiple buffer overflow bugs have been found libxml2 versions prior to 2.6.14. If an attacker can trick a user into passing a specially crafted FTP URL or FTP proxy URL to libxml2, it could be possible to execute arbitrary code.
The md5sums of the glib2-2.4.7-1.1 and gtk2-2.4.13-2.1 updates don't match the ones in the announcements I sent out.
A problem with PDF handling was discovered by Chris Evans, and has been fixed. The Common Vulnerabilities and Exposures project (https://www.mitre.org) has assigned the name CAN-2004-0888 to this issue.
Chris Evans and others discovered a number of integer overflow bugs that affected all versions of xpdf. An attacker could construct a carefully crafted PDF file that could cause xpdf to crash or possibly execute arbitrary code when opened.
Previous tzdata-2004e-1.fc2 announcement from 2004-10-12 had wrong md5sums (before signing).
This update is equivalent to the Fedora Core 3 version of OpenOffice.org. The changes since the previous version of OpenOffice.org in Fedora Core 2 are too numerous to list here, but there are quite a few notable improvements.
GTK+ 2.4.13 contains many bug fixes, with an emphasis on making the new file chooser work better.
A brown paper bag release -- I missed that 1bpp and 24bpp are also valid for BMP.
A security fix [CAN-2004-0755]. ruby-1.8.1-cgi_session_perms.patch: sets the permission of the session data file to 0600. (#130063)