Fixlet Site - PatchesforRedHatEnterpriseLinux Current Version: 177 Published: Thu, 15 Feb 2007 23:20:38 GMT *************************************************************** Title: RHSA-2007:0001 - Openoffice.Org Security Update - Red Hat Enterprise 3.0 (i386) Severity: Important Fixlet ID: 200700102 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0001.html Fixlet Description: Updated openoffice. org packages that fix several integer overflow bugs are now available. All users of OpenOffice. org are advised to upgrade to these updated packages, which contain a backported fix for this issue. *************************************************************** Title: RHSA-2007:0001 - Openoffice.Org Security Update - Red Hat Enterprise 4.0 (i386) Severity: Important Fixlet ID: 200700104 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0001.html Fixlet Description: Updated openoffice. org packages that fix several integer overflow bugs are now available. All users of OpenOffice. org are advised to upgrade to these updated packages, which contain a backported fix for this issue. *************************************************************** Title: RHSA-2007:0001 - Dependencies Needed - Red Hat Enterprise 3.0 (i386) Severity: Important Fixlet ID: 200700106 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0001.html Fixlet Description: Updated openoffice. org packages that fix several integer overflow bugs are now available. However, this security update requires at least version "0.5-1" of the i386 package "startup-notification" and at least version "1.1.2-35.2.0.EL3" of the i386 package "redhat-artwork." You must install or upgrade these packages in order for this security update to become relevant. *************************************************************** Title: RHSA-2007:0002 - Xfree86 Security Update - Red Hat Enterprise 3.0 (x86_64) Severity: Important Fixlet ID: 200700202 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0002.html Fixlet Description: Updated XFree86 packages that fix a denial of service security issue have been released. Please see patch page for more detailed information. *************************************************************** Title: RHSA-2007:0003 - Xorg-X11 Security Update - Red Hat Enterprise 4.0 (x86_64) Severity: Important Fixlet ID: 200700302 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0003.html Fixlet Description: Updated X. org packages that fix a security issue are now available for Red Hat Enterprise Linux 4. Users of X. org should upgrade to these updated packages, which contain a backported patch and is not vulnerable to this issue. *************************************************************** Title: RHSA-2007:0008 - Dbus Security Update - Red Hat Enterprise 4.0 (x86_64) Severity: Moderate Fixlet ID: 200700802 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0008.html Fixlet Description: Updated dbus packages that fix a security issue are now available for Red Hat Enterprise Linux 4. This update has been rated as having moderate security impact by the Red Hat Security Response Team. D-BUS is a system for sending messages between applications. It is used both for the systemwide message bus service, and as a per-user-login-session messaging facility. Kimmo Hamalainen discovered a flaw in the way D-BUS processes certain messages. It is possible for a local unprivileged D-BUS process to disrupt the ability of another D-BUS process to receive messages. (CVE-2006-6107) Users of dbus are advised to upgrade to these updated packages, which contain backported patches to correct this issue. *************************************************************** Title: RHSA-2007:0008 - Dependencies Needed - Red Hat Enterprise 4.0 (x86_64) Severity: Moderate Fixlet ID: 200700804 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0008.html Fixlet Description: Updated dbus packages that fix a security issue are now available for Red Hat Enterprise Linux 4. However, this security update requires the package "audit-libs" of i386 and x86_64 architecture to be at least version "1.0.3-6.EL4". You must update or install this package in order for this security update to become relevant. *************************************************************** Title: RHSA-2007:0011 - Libgsf Security Update - Red Hat Enterprise 3.0 (x86_64) Severity: Moderate Fixlet ID: 200701102 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0011.html Fixlet Description: Updated libgsf packages that fix a buffer overflow flaw are now available. Users of GNOME Structured File Library should upgrade to these updated packages, which contain a backported patch that resolves this issue. *************************************************************** Title: RHSA-2007:0011 - Libgsf Security Update - Red Hat Enterprise 4.0 (x86_64) Severity: Moderate Fixlet ID: 200701104 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0011.html Fixlet Description: Updated libgsf packages that fix a buffer overflow flaw are now available. Users of GNOME Structured File Library should upgrade to these updated packages, which contain a backported patch that resolves this issue. *************************************************************** Title: RHSA-2007:0014 - Kernel Security Update - Red Hat Enterprise 4.0 (x86_64) Severity: Important Fixlet ID: 200701402 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0014.html Fixlet Description: Updated kernel packages that fix several security issues in the Red Hat Enterprise Linux 4 kernel are now available. *************************************************************** Title: RHSA-2007:0014 - Dependencies Needed - Red Hat Enterprise 4.0 (x86_64) Severity: Important Fixlet ID: 200701403 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0014.html Fixlet Description: Updated kernel packages that fix a number of issues are now available. However, this security update requires the package "mkinitrd" to be at least version "4.2.1.6-1". You must update or install this package in order for this security update to become relevant. *************************************************************** Title: RHSA-2007:0017 - Adobe Acrobat Reader Security Update - Red Hat Enterprise 4.0 (i386) Severity: Critical Fixlet ID: 200701702 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0017.html Fixlet Description: Updated acroread packages that fix several security issues are now available for Red Hat Enterprise Linux 4. All users of Acrobat Reader are advised to upgrade to these updated packages, which contain Acrobat Reader version 7.0.9 and are not vulnerable to these issues. *************************************************************** Title: RHSA-2007:0018 - Fetchmail Security Update - Red Hat Enterprise 3.0 (x86_64) Severity: Moderate Fixlet ID: 200701802 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0018.html Fixlet Description: Updated fetchmail packages that fix two security issues, rated moderate, are now available. Please see patch page for detailed information. *************************************************************** Title: RHSA-2007:0018 - Fetchmail Security Update - Red Hat Enterprise 4.0 (x86_64) Severity: Moderate Fixlet ID: 200701804 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0018.html Fixlet Description: An updated fetchmail package that fixes two security issues is now available. Users of Fetchmail should update to this package, which contain backported patches to correct these issues. *************************************************************** Title: RHSA-2007:0019 - Gtk2 Security Update - Red Hat Enterprise 4.0 (x86_64) Severity: Moderate Fixlet ID: 200701902 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0019.html Fixlet Description: Updated gtk2 packages that fix a security issue are now available. A bug was found in the way the gtk2 GdkPixbufLoader() function processed invalid input. Applications linked against gtk2 could crash if they loaded a malformed image file. Please see patch page for more detailed information. *************************************************************** Title: RHSA-2007:0021 - Adobe Acrobat Reader Security Update - Red Hat Enterprise 3.0 (i386) Severity: Critical Fixlet ID: 200702102 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0021.html Fixlet Description: Several security issues have been addressed with these updated packages. Please see patch page for detailed information. *************************************************************** Title: RHSA-2007:0022 - Squirrelmail Security Update - Red Hat Enterprise 3.0 (noarch) Severity: Moderate Fixlet ID: 200702202 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0022.html Fixlet Description: A new squirrelmail package that fixes security issues is now available for Red Hat Enterprise Linux 3 and 4. Please see patch page for detailed information. *************************************************************** Title: RHSA-2007:0022 - Squirrelmail Security Update - Red Hat Enterprise 4.0 (noarch) Severity: Moderate Fixlet ID: 200702204 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0022.html Fixlet Description: A new squirrelmail package that fixes security issues is now available for Red Hat Enterprise Linux 3 and 4. Users of SquirrelMail should upgrade to this erratum package, which contains a backported patch to correct these issues. Notes: - After installing this update, users are advised to restart their httpd service to ensure that the updated version functions correctly. - config. php should NOT be modified, please modify config_local. php instead. - *************************************************************** Title: RHSA-2007:0022 - Dependancies Needed- Red Hat Enterprise 3.0 (noarch) Severity: Moderate Fixlet ID: 200702205 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0022.html Fixlet Description: Updated squirrelmail package that fixes a number of issues is now available. However, this security update requires the package "php" be at least version "4.3.2-37". You must update or install this package in order for this security update to become relevant. *************************************************************** Title: RHSA-2007:0022 - Dependancies Needed- Red Hat Enterprise 4.0 (noarch) Severity: Moderate Fixlet ID: 200702206 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0022.html Fixlet Description: An updated squirrelmail package that fixes a number of issues is now available. However, this security update requires the x86_64 package "php" be at least version "4.3.9-3.1". You must update or install this package in order for this security update to become relevant. *************************************************************** Title: RHSA-2007:0044 - Bind Security Update - Red Hat Enterprise 3.0 (x86_64) Severity: Moderate Fixlet ID: 200704402 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0044.html Fixlet Description: Updated bind packages that fix a security issue and a bug are now available. Users of BIND are advised to upgrade to these updated packages, which contain backported patches to correct these issues. *************************************************************** Title: RHSA-2007:0044 - Bind Security Update - Red Hat Enterprise 4.0 (x86_64) Severity: Moderate Fixlet ID: 200704404 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0044.html Fixlet Description: Updated bind packages that fix a security issue and a bug are now available. Please see patch page for more detailed information. *************************************************************** Title: RHSA-2007:0044 - Dependencies Needed - Red Hat Enterprise 3.0 (x86_64) Severity: Moderate Fixlet ID: 200704405 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0044.html Fixlet Description: Updated bind packages that fix a security issue and a bug are now available. However, this security update requires at least version "9.2.4-EL3_10" of packages "bind", "bind-libs" and "bind-utils" if they present. You must install or upgrade these packages in order for this security update to become relevant. *************************************************************** Title: RHSA-2007:0062 - Java-1.4.2-Ibm Security Update - Red Hat Enterprise 3.0 (x86_64) Severity: Critical Fixlet ID: 200706202 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0062.html Fixlet Description: Updated java-1.4.2-ibm packages to correct several security issues are now available for Red Hat Enterprise Linux 3 and 4 Extras. All users of java-1.4.2-ibm should upgrade to these updated packages, which contain IBM's 1.4.2 SR7 Java release which resolves these issues. *************************************************************** Title: RHSA-2007:0062 - Java-1.4.2-Ibm Security Update - Red Hat Enterprise 4.0 (x86_64) Severity: Critical Fixlet ID: 200706204 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0062.html Fixlet Description: Updated java-1.4.2-ibm packages that correct several security issues are now available for Red Hat Enterprise Linux 3 and 4 Extras. An untrusted applet could use these vulnerabilities to access data from other applets. Serialization flaws were discovered in the Java Runtime Environment. An untrusted applet or application could use these flaws to elevate its privileges. Please see patch page for more detailed information. *************************************************************** Title: RHSA-2007:0064 - PostgreSQL Security Update - Red Hat Enterprise 3.0 (x86_64) Severity: Moderate Fixlet ID: 200706402 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0064.html Fixlet Description: Updated postgresql packages that fix two security issues are now available for Red Hat Enterprise Linux 3. Users of PostgreSQL should upgrade to these updated packages containing PostgreSQL version 7.4.16 or 7.3.18, which correct these issues. *************************************************************** Title: RHSA-2007:0064 - PostgreSQL Security Update - Red Hat Enterprise 4.0 (x86_64) Severity: Moderate Fixlet ID: 200706404 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0064.html Fixlet Description: Updated postgresql packages that fix two security issues are now available for Red Hat Enterprise Linux 3 and 4. A flaw was found in the way the PostgreSQL server handles certain SQL-language functions that would allow an authenticated user could execute a sequence of commands which could crash the PostgreSQL server or possibly read from arbitrary memory locations. Please see patch page for more detailed information. *************************************************************** Title: RHSA-2007:0073 - Java-1.5.0-Ibm Security Update - Red Hat Enterprise 4.0 (x86_64) Severity: Critical Fixlet ID: 200707302 Fixlet Link: https://rhn.redhat.com/errata/RHSA-2007-0073.html Fixlet Description: Java-1.5.0-ibm packages that correct several security issues are available for Red Hat Enterprise Linux 4 Extras. Vulnerabilities were discovered in the Java Runtime Environment. An untrusted applet could use these vulnerabilities to access data from other applets. Please see patch page for more detailed information.