Red Hat Essential and Critical Security Patch Updates
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
The XEmacs package as shipped with Red Hat PowerTools 6.2 has a securityproblem with gnuserv and gnuclient, due to a buffer overflow and weaksecurity.
The inetd server as shipped with Red Hat Linux 6.2 fails to close socketsfor internal services properly.
New micq packages are available which fix a buffer overflow vulnerability.
This update fixes several general problems with php3 and 4, along with some security holes in versions 4.0 through 4.0.4 of php.
There is a format string vulnerability in icecast that can allow a remote user to execute arbitrary code.
The MySQL database that shipped with Red Hat Linux 7 and the updates for ithave been reported by the MySQL authors to have security problems.
Because of a typo in glibc source RESOLV_HOST_CONF and RES_OPTIONS variables were not removed from environment for SUID/SGID programs.
This errata changes the default directory used forPID files to /var/run.
The MySQL packages shipped in Red Hat Linux 7 and as updates had bugs whichcaused the DB engine to return bad results or crash.
An issue involves incorrect protection of a data updating method on Imageand File objects has been fixed.
Bad TCP packets (e.g. a SYN packet with kind=3, len=0) over aPPP-over-Ethernet link could lock up rp-pppoe.
Updated gnupg packages are now available for Red Hat Linux 6.x and 7.
By using a carefully crafted database, a local user could overwrite some of slocate's internal structures, leading to a local group slocate compromise.
Stunnel version 3.8 (and earlier) contained a format-stringvulnerability. Version 3.9 closes this vulnerability.
A new Zope-Hotfix package is availble which fixes issues with computationof local roles.
New BitchX packages are available which fix the problem with processingmalformed DNS answers.
Vulnerability in legacy names allows calling those contructors without thecorrect permissions.