Red Hat Essential and Critical Security Patch Updates
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
Updated secureweb packages are now available for Red Hat Secure Web Server3.2. These updates address possible vulnerabilities in how the MM libraryopens temporary files.
Updated gaim packages are now available for Red Hat Linux 7.1, 7.2, and7.3. These updates fix a buffer overflow in the Jabber plug-in module.
Updated gaim packages are now available for Red Hat Powertools 7.These updates fix a buffer overflow in the Jabber plug-in module.
A locally exploitable vulnerability is present in the util-linux packageshipped with Red Hat Linux
Updated glibc packages are available to fix two vulnerabilities in theresolver functions. A buffer overflow vulnerability has been found in the way the glibc resolver handles the resolution of network names and addresses via DNS
Updated mod_ssl packages are now available for Red Hat Linux 7, 7.1, 7.2,and 7.3. These updates incorporate a fix for an incorrect bounds check inversions of mod_ssl up to and including version 2.8.9.
A problem was found in the code used by Squid to handle compressed DNSreplies where a malicious DNS server could cause Squid to crash. This bugis fixed in the 2.4.STABLE6 release of Squid.
Updated mailman packages are now available for Red Hat Secure Web Server3.2 (U.S.). These updates resolve a cross-site scripting vulnerabilitypresent in versions of Mailman prior to 2.0.11.
Updated openssh packages are now available for Red Hat Linux 7, 7.1, 7.2,and 7.3. These updates fix an input validation error in OpenSSH.
The Apache Web server contains a security vulnerability which can be usedto launch a denial of service attack, or in some cases, allow remote codeexecution.
The Apache Web server contains a security vulnerability which can be usedto launch a denial of service attack, or in some cases, allow remote codeexecution.
The Apache Web server contains a security vulnerability which can be usedto launch a denial of service attack, or in some cases, allow remote codeexecution.
Updated mailman packages are now available for Red Hat Linux 7.2 and 7.3. These updates resolve a cross-site scripting vulnerability present inversions of Mailman prior to 2.0.11.
The LPRng print spooler, as shipped in Red Hat Linux 7.x, accepts allremote print jobs by default.
Updated mailman packages are now available for Red Hat Power Tools 7 and7.1. These updates resolve a cross-site scripting vulnerability present inversions of Mailman prior to 2.0.1
Updated ethereal packages are available which fix several security problems.
Version 9 of the bind name prior to version 9.2.1 contain a denial ofservice vulnerability.
Updated packages are available for GNU Ghostscript which fix avulnerability found during Postscript interpretation.
A security issue in XChat allows a malicious server to execute arbitrarycommands.
Updated nss_ldap packages are now available for Red Hat Linux 6.2, 7,7.1, 7.2, and 7.3. These packages fix a string format vulnerability in thepam_ldap module.