Fixlet Site - PatchesforSUSELinuxEnterprise Current Version: 53 Published: Tue, 17 Jul 2007 00:45:20 GMT *************************************************************** Title: PATCH-11559 - Security update for Apache2 - SLES9 Severity: Fixlet ID: 1155901 Fixlet Link: http://support.novell.com/techcenter/psdb/26c3e83f9771093dfc1fecccbe79c9fe.html Fixlet Description: The new version of Apache2 is now available. Please see patch page for more detailed information. *************************************************************** Title: PATCH-11567 - Security update for Java 2 - SLES9 Severity: Fixlet ID: 1156701 Fixlet Link: http://support.novell.com/techcenter/psdb/90864743019d987b918e58f9bba908b8.html Fixlet Description: SUN Java was upgraded to 1.3.1_20 for SLES 8, and 1.4.2_15 for SUSE Linux Enterprise Desktop 1 and SLES 9. Please see patch page for more detailed information. *************************************************************** Title: PATCH-11570 - Security update for IBMJava2 SDK and IBMJava2 JRE - SLES9 Severity: Fixlet ID: 1157001 Fixlet Link: http://support.novell.com/techcenter/psdb/3012728a973846dec5946ec81fd01aca.html Fixlet Description: The IBM Java JRE/SDK has been brought to release 1.4.2 SR8 (SLES9) and 1.3.1 SR10-1 (SLES8), containing several bugfixes, including following security fixes: CVE-2007-0243: A buffer overflow vulnerability in the Java(TM) Runtime Environment may allow an untrusted applet to elevate its privileges. For example, an applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet. CVE-2006-6737/CVE-2006-6736: Two vulnerabilities in the Java Runtime Environment may independently allow an untrusted applet to access data in other applets. CVE-2006-6745: Two vulnerabilities in the Java(TM) Runtime Environment with serialization may independently allow an untrusted applet or application to elevate its privileges. Install this update. Please see patch page for more detailed information. *************************************************************** Title: PATCH-B7062801 - Security update for OpenOffice_org - SLED10 Severity: Fixlet ID: 706280101 Fixlet Link: http://support.novell.com/techcenter/psdb/d79c3af9a7a1e5ce0c949b94c3420e14.html Fixlet Description: This update of OpenOffice_org fixes a heap-overflow in the RTF parser and additional non-security bugs. Please see patch page for more detailed information. *************************************************************** Title: PATCH-B7062801 - Dependencies Needed - SLED10 Severity: Fixlet ID: 706280103 Fixlet Link: http://support.novell.com/techcenter/psdb/d79c3af9a7a1e5ce0c949b94c3420e14.html Fixlet Description: This update of OpenOffice_org fixes a heap-overflow in the RTF parser and additional non-security bugs. However, this update requires that the package "xalan-j2" be installed and at least version "2.6.0-21.4.1" as well as the package "xerces-j2" be installed and at least version "2.7.1-16.4.1". Also, the package "xml-commons-apis" will need to be installed and at least version "1.3.02-16". Additionally, the package "OpenOffice_org-nld" will need to be removed, if it is currently installed. *************************************************************** Title: PATCH-B7070601 - Security update for cron - SLED10/SLES10 Severity: Fixlet ID: 707060101 Fixlet Link: http://support.novell.com/techcenter/psdb/9acb48d1dc03ba4123a90374822692ac.html Fixlet Description: An updated cron package that fixes an issue is now available. Please see patch page for more detailed information. *************************************************************** Title: PATCH-B7070602 - Security update for evolution-data-server - SLED10/SLES10 Severity: Fixlet ID: 707060201 Fixlet Link: http://support.novell.com/techcenter/psdb/05f2191a0a3c694e34ebe389d55eb5ab.html Fixlet Description: Updated evolution-data-server packages that fix a bug are now available. Please see patch page for more detailed information. *************************************************************** Title: PATCH-B7071001 - Security update for mutt - SLED10/SLES10 Severity: Fixlet ID: 707100101 Fixlet Link: http://support.novell.com/techcenter/psdb/4ab149bab93f9785bf46bd10d78c8431.html Fixlet Description: This update of mutt fixes a vulnerability in the APOP implementation that allows an active attacker to guess three bytes of the password. Please see patch page for more detailed information. *************************************************************** Title: PATCH-B7071002 - Security update for PHP5 - SLES10 Severity: Fixlet ID: 707100201 Fixlet Link: http://support.novell.com/techcenter/psdb/d7e991611687640b021d8eb8774f15e7.html Fixlet Description: Several issues have been fixed in the updated PHP5 pacakges. Please see patch page for more detailed information. *************************************************************** Title: PATCH-B7071003 - Security update for Java - SLES10 Severity: Fixlet ID: 707100301 Fixlet Link: http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html Fixlet Description: The Sun JAVA JDK 1.4.2 was upgraded to release 15 to fix various bugs, including the security bugs.Please see patch page for more detailed information. *************************************************************** Title: PATCH-B7071003 - Security update for Java - SLED10 Severity: Fixlet ID: 707100302 Fixlet Link: http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html Fixlet Description: The Sun JAVA JDK 1.4.2 was upgraded to release 15 to fix various bugs, including the security bugs.Please see patch page for more detailed information. *************************************************************** Title: PATCH-B7071101 - Security update for IBM Java - SLES10 Severity: Fixlet ID: 707110101 Fixlet Link: http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html Fixlet Description: The IBM Java JRE/SDK has been brought to release 1.4.2 SR 8 containing several bug fixes and three security fixes. Please see patch page for more detailed information. *************************************************************** Title: PATCH-B7071201 - Security update for avahi - SLED10 Severity: Fixlet ID: 707120101 Fixlet Link: http://support.novell.com/techcenter/psdb/ec1f5cd50770f10937939eb5228ef181.html Fixlet Description: Local attackers could send empty TXT data via D-BUS, causing the avahi daemon to exit. Please see patch page for more detailed information.