Fixlet Site - PatchesforSUSELinuxEnterprise Current Version: 51 Published: Sat, 16 Jun 2007 00:23:16 GMT *************************************************************** Title: PATCH-11528 - Security update for jakarta-tomcat - SLES9 Severity: Fixlet ID: 1152801 Fixlet Link: http://support.novell.com/techcenter/psdb/63490b4245c63cb9b560c819f48e0d9d.html Fixlet Description: Certain characters of the URL were not properly filtered. This allowed directory reverse traversal attacks to access the web-root of tomcat. Please see patch page for more detailed information. *************************************************************** Title: PATCH-11530 - Security update for file - SLES9 Severity: Fixlet ID: 1153001 Fixlet Link: http://support.novell.com/techcenter/psdb/40f3a050df9659ee95c994d2fde2b2b0.html Fixlet Description: This update fixes an integer overflow in function file_printf() of file. This bug can be used to execute arbitrary code. Please see patch page for more detailed information. *************************************************************** Title: PATCH-11531 - Security update for Python - SLES9 Severity: Fixlet ID: 1153101 Fixlet Link: http://support.novell.com/techcenter/psdb/74ea95d7621db0dbcf832e3be84300de.html Fixlet Description: This update fixes an off-by-one error in the PyLocale_strxfrm() function which can lead to a memory leak. Please see patch page for more detailed information. *************************************************************** Title: PATCH-11532 - Security update for libpng - SLES9 Severity: Fixlet ID: 1153201 Fixlet Link: http://support.novell.com/techcenter/psdb/46bf07db17204012a69d1c67caf92ee4.html Fixlet Description: Applications using libpng can crash if libpng is ask to process a grayscale image with a malformed (bad CRC) tRNS chunk. Please see patch page for more detailed information. *************************************************************** Title: PATCH-11543 - Security update for clamav - SLES9 Severity: Fixlet ID: 1154301 Fixlet Link: http://support.novell.com/techcenter/psdb/5a3e85703885a03d41664f02c24200e0.html Fixlet Description: This update of ClamAV fixes several security bugs. wrong calculation of buffer-enduse strict permissions for temporary filesheap corruption causing denial-of-service with corrupted rar archivedetect block list loop Please see patch page for more detailed information. *************************************************************** Title: PATCH-B7053001 - Security update for kdebase3 - SLED10/SLES10 Severity: Fixlet ID: 705300101 Fixlet Link: http://support.novell.com/techcenter/psdb/1e90556f8507df445afbf3c829591431.html Fixlet Description: A problem with the interaction between the Flash Player and the Konqueror web browser was fixed. The problem could lead to keypresses leaking to the applet instead of the browser. Please see patch page for more detailed information.