Red Hat Essential and Critical Security Patch Updates
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
Updated tcpdump, libpcap, and arpwatch packages are available for RedHat Linux 6.2 and 7.x. These updates close a buffer overflow when handlingNFS packets.
Updated nss_ldap packages are now available for Red Hat Linux 6.2, 7.0,7.1,7.2, and 7.3. These packages fix a string format vulnerability in thepam_ldap module.
The UW imap daemon contains a buffer overflow which allows a logged in, remote user to execute commands on the server with the user's UID/GID.
Updated fetchmail packages are available for Red Hat Linux 6.2, 7, 7.1,7.2, and 7.3 which close a remotely-exploitable vulnerability in unpatchedversions of fetchmail prior to 5.9.10.
pdated mpg321 packages are available for Red Hat Linux 7.2, which fixa buffer overflow in the network streaming code as well as other bugs.
One component of the XML Extras package in Mozilla 0.9.9 andearlier allows remote attackers to read arbitrary files and listdirectories on a client system.
Updated packages for sharutils are available which fix potential privilegeescalation using the uudecode utility.
Updated perl-Digest-MD5 packages are available which work around a bug inthe utf8 interaction between perl-Digest-MD5 and Perl.
This bug only affects users using the Network Address Translationfeatures of firewalls built with netfilter ("iptables"). Red HatLinux's firewall configuration tools use "ipchains," and thoseconfigurations are not vulnerable to this bug.
Updated mod_python packages have been made available for Red Hat Linux 7.2and 7.3. These updates close a security issue in mod_python which allowsthe publisher handler to use modules which have only been indirectly imported.
The Nautilus file manager in Red Hat Linux 7.2 has a symlink vulnerability.
Updated mod_python packages have been made available for Red Hat Linux 7.2.These updates close a security issue in mod_python which allows thepublisher handler to use modules which have only been indirectly imported.
The default stylesheet used when converting a DocBook document tomultiple HTML files allows an untrusted document to write filesoutside of the current directory.
Updated sudo packages are available which fix a local root exploit.
Updated icecast packages are available which fix a number of security issues.
Updated sudo packages are available which fix a local root exploit.
Updated tcpdump, libpcap, and arpwatch packages are available for RedHat Linux 6.2 and 7.x. These updates close vulnerabilitiespresent in versions of tcpdump up to 3.5.1 and various other bugs.
Updated LogWatch packages are available that fix tmp file race conditionswhich can cause a local user to gain root privileges.
Updated LogWatch packages are available that fix tmp file race conditionswhich can cause a local user to gain root privileges.
Updated PHP packages are available to fix vulnerabilities in the functionsthat parse multipart MIME data, which are used when uploading filesthrough forms.