Red Hat Essential and Critical Security Patch Updates
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
An updated gaim package that fixes several security issues is now available.
An updated mod_ssl package for Apache that fixes a format stringvulnerability is now available.
An updated rsync package that fixes a path sanitizing bug is now available.
Updated krb5 packages that improve client responsiveness and fix severalsecurity issues are now available for Red Hat Enterprise Linux 3.
Updated Kerberos (krb5) packages that correct double-free and ASN.1parsing bugs are now available for Red Hat Enterprise Linux.
An updated Adobe Acrobat Reader package that fixes multiple security issuesis now available.
Updated qt packages that fix security issues in several of the imagedecoders are now available.
A bug in the SoundBlaster 16 code which did not properly handle certain sample sizes has been fixed. This flaw could be used by local users to crash a system.
Netscape Navigator and Netscape Communicator have been removed from the RedHat Enterprise Linux 2.1 CD-ROM distribution as part of Update 5. Thesepackages were based on Netscape 4.8, which is known to be vulnerable torecent critical security issues, such as CAN-2004-0597, CAN-2004-0598, andCAN-2004-0599.
Temporary files were being created without taking adequate precautions, and therefore a local user could potentially overwrite files with the privileges of the user running emacs.
Updated Itanium kernel packages that fix a number of security issues are now available.
If he pam_wheel module was used with the "trust" option enabled, but without the "use_uid" option, any local user could use PAM to gain access to a superuser account without supplying a password.
Updated Ethereal packages that fix various security vulnerabilities are now available.
Updated mozilla packages based on version 1.4.3 that fix a number of security issues for Red Hat Enterprise Linux are now available.
Updated glibc packages that fix a security flaw in the resolver as well as dlclose handling are now available.
An attacker who is able to influence a user to open a specially-crafted URI using gnome-vfs could perform actions as that user.
An attacker could create a carefully crafted PNG file in such a way that it would cause an application linked with libpng to execute arbitrary code when the file was opened by a victim.
Updated kernel packages that fix several security issues in Red Hat Enterprise Linux 3 are now available.
Updated kernel packages that fix potential information leaks and a incorrect driver permission for Red Hat Enterprise Linux 2.1 are now available.