RHSA-2009:1140-02 Moderate: ruby security update  

Posted by Daniela Mehler

"-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
Red Hat Security Advisory

Synopsis: Moderate: ruby security update
Advisory ID: RHSA-2009:1140-02
Product: Red Hat Enterprise Linux
Advisory URL: https://rhn.redhat.com/errata/RHSA-2009-1140.html
Issue date: 2009-07-02
CVE Names: CVE-2007-1558 CVE-2009-0642 CVE-2009-1904
=====================================================================

1. Summary:

Updated ruby packages that fix multiple security issues are now available
for Red Hat Enterprise Linux 4 and 5.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64
RHEL Desktop Workstation (v. 5 client) - i386, x86_64
Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64

3. Description:

Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

A flaw was found in the way the Ruby POP module processed certain APOP
authentication requests. By sending certain responses when the Ruby APOP
module attempted to authenticate using APOP against a POP server, a remote
attacker could, potentially, acquire certain portions of a user's
authentication credentials. (CVE-2007-1558)

It was discovered that Ruby did not properly check the return value when
verifying X.509 certificates. This could, potentially, allow a remote
attacker to present an invalid X.509 certificate, and have Ruby treat it as
valid. (CVE-2009-0642)

A flaw was found in the way Ruby converted BigDecimal objects to Float
numbers. If an attacker were able to provide certain input for the
BigDecimal object converter, they could crash an application using this
class. (CVE-2009-1904)

All Ruby users should upgrade to these updated packages, which contain
backported patches to resolve these issues.

4. Solution:

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

5. Bugs fixed (http://bugzilla.redhat.com/):

241191 - CVE-2007-1558 fetchmail/mutt/evolution/...: APOP password disclosure vulnerability
486183 - CVE-2009-0642 ruby: Incorrect checks for validity of X.509 certificates
504958 - CVE-2009-1904 ruby: DoS vulnerability in BigDecimal

6. Package List:

Red Hat Enterprise Linux AS version 4:

Source:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/ruby-1.8.1-7.el4_8.3.src.rpm

i386:
irb-1.8.1-7.el4_8.3.i386.rpm
ruby-1.8.1-7.el4_8.3.i386.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.i386.rpm
ruby-devel-1.8.1-7.el4_8.3.i386.rpm
ruby-docs-1.8.1-7.el4_8.3.i386.rpm
ruby-libs-1.8.1-7.el4_8.3.i386.rpm
ruby-mode-1.8.1-7.el4_8.3.i386.rpm
ruby-tcltk-1.8.1-7.el4_8.3.i386.rpm

ia64:
irb-1.8.1-7.el4_8.3.ia64.rpm
ruby-1.8.1-7.el4_8.3.ia64.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.i386.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.ia64.rpm
ruby-devel-1.8.1-7.el4_8.3.ia64.rpm
ruby-docs-1.8.1-7.el4_8.3.ia64.rpm
ruby-libs-1.8.1-7.el4_8.3.i386.rpm
ruby-libs-1.8.1-7.el4_8.3.ia64.rpm
ruby-mode-1.8.1-7.el4_8.3.ia64.rpm
ruby-tcltk-1.8.1-7.el4_8.3.ia64.rpm

ppc:
irb-1.8.1-7.el4_8.3.ppc.rpm
ruby-1.8.1-7.el4_8.3.ppc.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.ppc.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.ppc64.rpm
ruby-devel-1.8.1-7.el4_8.3.ppc.rpm
ruby-docs-1.8.1-7.el4_8.3.ppc.rpm
ruby-libs-1.8.1-7.el4_8.3.ppc.rpm
ruby-libs-1.8.1-7.el4_8.3.ppc64.rpm
ruby-mode-1.8.1-7.el4_8.3.ppc.rpm
ruby-tcltk-1.8.1-7.el4_8.3.ppc.rpm

s390:
irb-1.8.1-7.el4_8.3.s390.rpm
ruby-1.8.1-7.el4_8.3.s390.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.s390.rpm
ruby-devel-1.8.1-7.el4_8.3.s390.rpm
ruby-docs-1.8.1-7.el4_8.3.s390.rpm
ruby-libs-1.8.1-7.el4_8.3.s390.rpm
ruby-mode-1.8.1-7.el4_8.3.s390.rpm
ruby-tcltk-1.8.1-7.el4_8.3.s390.rpm

s390x:
irb-1.8.1-7.el4_8.3.s390x.rpm
ruby-1.8.1-7.el4_8.3.s390x.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.s390.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.s390x.rpm
ruby-devel-1.8.1-7.el4_8.3.s390x.rpm
ruby-docs-1.8.1-7.el4_8.3.s390x.rpm
ruby-libs-1.8.1-7.el4_8.3.s390.rpm
ruby-libs-1.8.1-7.el4_8.3.s390x.rpm
ruby-mode-1.8.1-7.el4_8.3.s390x.rpm
ruby-tcltk-1.8.1-7.el4_8.3.s390x.rpm

x86_64:
irb-1.8.1-7.el4_8.3.x86_64.rpm
ruby-1.8.1-7.el4_8.3.x86_64.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.i386.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.x86_64.rpm
ruby-devel-1.8.1-7.el4_8.3.x86_64.rpm
ruby-docs-1.8.1-7.el4_8.3.x86_64.rpm
ruby-libs-1.8.1-7.el4_8.3.i386.rpm
ruby-libs-1.8.1-7.el4_8.3.x86_64.rpm
ruby-mode-1.8.1-7.el4_8.3.x86_64.rpm
ruby-tcltk-1.8.1-7.el4_8.3.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

Source:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/ruby-1.8.1-7.el4_8.3.src.rpm

i386:
irb-1.8.1-7.el4_8.3.i386.rpm
ruby-1.8.1-7.el4_8.3.i386.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.i386.rpm
ruby-devel-1.8.1-7.el4_8.3.i386.rpm
ruby-docs-1.8.1-7.el4_8.3.i386.rpm
ruby-libs-1.8.1-7.el4_8.3.i386.rpm
ruby-mode-1.8.1-7.el4_8.3.i386.rpm
ruby-tcltk-1.8.1-7.el4_8.3.i386.rpm

x86_64:
irb-1.8.1-7.el4_8.3.x86_64.rpm
ruby-1.8.1-7.el4_8.3.x86_64.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.i386.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.x86_64.rpm
ruby-devel-1.8.1-7.el4_8.3.x86_64.rpm
ruby-docs-1.8.1-7.el4_8.3.x86_64.rpm
ruby-libs-1.8.1-7.el4_8.3.i386.rpm
ruby-libs-1.8.1-7.el4_8.3.x86_64.rpm
ruby-mode-1.8.1-7.el4_8.3.x86_64.rpm
ruby-tcltk-1.8.1-7.el4_8.3.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

Source:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/ruby-1.8.1-7.el4_8.3.src.rpm

i386:
irb-1.8.1-7.el4_8.3.i386.rpm
ruby-1.8.1-7.el4_8.3.i386.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.i386.rpm
ruby-devel-1.8.1-7.el4_8.3.i386.rpm
ruby-docs-1.8.1-7.el4_8.3.i386.rpm
ruby-libs-1.8.1-7.el4_8.3.i386.rpm
ruby-mode-1.8.1-7.el4_8.3.i386.rpm
ruby-tcltk-1.8.1-7.el4_8.3.i386.rpm

ia64:
irb-1.8.1-7.el4_8.3.ia64.rpm
ruby-1.8.1-7.el4_8.3.ia64.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.i386.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.ia64.rpm
ruby-devel-1.8.1-7.el4_8.3.ia64.rpm
ruby-docs-1.8.1-7.el4_8.3.ia64.rpm
ruby-libs-1.8.1-7.el4_8.3.i386.rpm
ruby-libs-1.8.1-7.el4_8.3.ia64.rpm
ruby-mode-1.8.1-7.el4_8.3.ia64.rpm
ruby-tcltk-1.8.1-7.el4_8.3.ia64.rpm

x86_64:
irb-1.8.1-7.el4_8.3.x86_64.rpm
ruby-1.8.1-7.el4_8.3.x86_64.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.i386.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.x86_64.rpm
ruby-devel-1.8.1-7.el4_8.3.x86_64.rpm
ruby-docs-1.8.1-7.el4_8.3.x86_64.rpm
ruby-libs-1.8.1-7.el4_8.3.i386.rpm
ruby-libs-1.8.1-7.el4_8.3.x86_64.rpm
ruby-mode-1.8.1-7.el4_8.3.x86_64.rpm
ruby-tcltk-1.8.1-7.el4_8.3.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

Source:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/ruby-1.8.1-7.el4_8.3.src.rpm

i386:
irb-1.8.1-7.el4_8.3.i386.rpm
ruby-1.8.1-7.el4_8.3.i386.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.i386.rpm
ruby-devel-1.8.1-7.el4_8.3.i386.rpm
ruby-docs-1.8.1-7.el4_8.3.i386.rpm
ruby-libs-1.8.1-7.el4_8.3.i386.rpm
ruby-mode-1.8.1-7.el4_8.3.i386.rpm
ruby-tcltk-1.8.1-7.el4_8.3.i386.rpm

ia64:
irb-1.8.1-7.el4_8.3.ia64.rpm
ruby-1.8.1-7.el4_8.3.ia64.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.i386.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.ia64.rpm
ruby-devel-1.8.1-7.el4_8.3.ia64.rpm
ruby-docs-1.8.1-7.el4_8.3.ia64.rpm
ruby-libs-1.8.1-7.el4_8.3.i386.rpm
ruby-libs-1.8.1-7.el4_8.3.ia64.rpm
ruby-mode-1.8.1-7.el4_8.3.ia64.rpm
ruby-tcltk-1.8.1-7.el4_8.3.ia64.rpm

x86_64:
irb-1.8.1-7.el4_8.3.x86_64.rpm
ruby-1.8.1-7.el4_8.3.x86_64.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.i386.rpm
ruby-debuginfo-1.8.1-7.el4_8.3.x86_64.rpm
ruby-devel-1.8.1-7.el4_8.3.x86_64.rpm
ruby-docs-1.8.1-7.el4_8.3.x86_64.rpm
ruby-libs-1.8.1-7.el4_8.3.i386.rpm
ruby-libs-1.8.1-7.el4_8.3.x86_64.rpm
ruby-mode-1.8.1-7.el4_8.3.x86_64.rpm
ruby-tcltk-1.8.1-7.el4_8.3.x86_64.rpm

Red Hat Enterprise Linux Desktop (v. 5 client):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/ruby-1.8.5-5.el5_3.7.src.rpm

i386:
ruby-1.8.5-5.el5_3.7.i386.rpm
ruby-debuginfo-1.8.5-5.el5_3.7.i386.rpm
ruby-docs-1.8.5-5.el5_3.7.i386.rpm
ruby-irb-1.8.5-5.el5_3.7.i386.rpm
ruby-libs-1.8.5-5.el5_3.7.i386.rpm
ruby-rdoc-1.8.5-5.el5_3.7.i386.rpm
ruby-ri-1.8.5-5.el5_3.7.i386.rpm
ruby-tcltk-1.8.5-5.el5_3.7.i386.rpm

x86_64:
ruby-1.8.5-5.el5_3.7.x86_64.rpm
ruby-debuginfo-1.8.5-5.el5_3.7.i386.rpm
ruby-debuginfo-1.8.5-5.el5_3.7.x86_64.rpm
ruby-docs-1.8.5-5.el5_3.7.x86_64.rpm
ruby-irb-1.8.5-5.el5_3.7.x86_64.rpm
ruby-libs-1.8.5-5.el5_3.7.i386.rpm
ruby-libs-1.8.5-5.el5_3.7.x86_64.rpm
ruby-rdoc-1.8.5-5.el5_3.7.x86_64.rpm
ruby-ri-1.8.5-5.el5_3.7.x86_64.rpm
ruby-tcltk-1.8.5-5.el5_3.7.x86_64.rpm

RHEL Desktop Workstation (v. 5 client):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/ruby-1.8.5-5.el5_3.7.src.rpm

i386:
ruby-debuginfo-1.8.5-5.el5_3.7.i386.rpm
ruby-devel-1.8.5-5.el5_3.7.i386.rpm
ruby-mode-1.8.5-5.el5_3.7.i386.rpm

x86_64:
ruby-debuginfo-1.8.5-5.el5_3.7.i386.rpm
ruby-debuginfo-1.8.5-5.el5_3.7.x86_64.rpm
ruby-devel-1.8.5-5.el5_3.7.i386.rpm
ruby-devel-1.8.5-5.el5_3.7.x86_64.rpm
ruby-mode-1.8.5-5.el5_3.7.x86_64.rpm

Red Hat Enterprise Linux (v. 5 server):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Server/en/os/SRPMS/ruby-1.8.5-5.el5_3.7.src.rpm

i386:
ruby-1.8.5-5.el5_3.7.i386.rpm
ruby-debuginfo-1.8.5-5.el5_3.7.i386.rpm
ruby-devel-1.8.5-5.el5_3.7.i386.rpm
ruby-docs-1.8.5-5.el5_3.7.i386.rpm
ruby-irb-1.8.5-5.el5_3.7.i386.rpm
ruby-libs-1.8.5-5.el5_3.7.i386.rpm
ruby-mode-1.8.5-5.el5_3.7.i386.rpm
ruby-rdoc-1.8.5-5.el5_3.7.i386.rpm
ruby-ri-1.8.5-5.el5_3.7.i386.rpm
ruby-tcltk-1.8.5-5.el5_3.7.i386.rpm

ia64:
ruby-1.8.5-5.el5_3.7.ia64.rpm
ruby-debuginfo-1.8.5-5.el5_3.7.ia64.rpm
ruby-devel-1.8.5-5.el5_3.7.ia64.rpm
ruby-docs-1.8.5-5.el5_3.7.ia64.rpm
ruby-irb-1.8.5-5.el5_3.7.ia64.rpm
ruby-libs-1.8.5-5.el5_3.7.ia64.rpm
ruby-mode-1.8.5-5.el5_3.7.ia64.rpm
ruby-rdoc-1.8.5-5.el5_3.7.ia64.rpm
ruby-ri-1.8.5-5.el5_3.7.ia64.rpm
ruby-tcltk-1.8.5-5.el5_3.7.ia64.rpm

ppc:
ruby-1.8.5-5.el5_3.7.ppc.rpm
ruby-debuginfo-1.8.5-5.el5_3.7.ppc.rpm
ruby-debuginfo-1.8.5-5.el5_3.7.ppc64.rpm
ruby-devel-1.8.5-5.el5_3.7.ppc.rpm
ruby-devel-1.8.5-5.el5_3.7.ppc64.rpm
ruby-docs-1.8.5-5.el5_3.7.ppc.rpm
ruby-irb-1.8.5-5.el5_3.7.ppc.rpm
ruby-libs-1.8.5-5.el5_3.7.ppc.rpm
ruby-libs-1.8.5-5.el5_3.7.ppc64.rpm
ruby-mode-1.8.5-5.el5_3.7.ppc.rpm
ruby-rdoc-1.8.5-5.el5_3.7.ppc.rpm
ruby-ri-1.8.5-5.el5_3.7.ppc.rpm
ruby-tcltk-1.8.5-5.el5_3.7.ppc.rpm

s390x:
ruby-1.8.5-5.el5_3.7.s390x.rpm
ruby-debuginfo-1.8.5-5.el5_3.7.s390.rpm
ruby-debuginfo-1.8.5-5.el5_3.7.s390x.rpm
ruby-devel-1.8.5-5.el5_3.7.s390.rpm
ruby-devel-1.8.5-5.el5_3.7.s390x.rpm
ruby-docs-1.8.5-5.el5_3.7.s390x.rpm
ruby-irb-1.8.5-5.el5_3.7.s390x.rpm
ruby-libs-1.8.5-5.el5_3.7.s390.rpm
ruby-libs-1.8.5-5.el5_3.7.s390x.rpm
ruby-mode-1.8.5-5.el5_3.7.s390x.rpm
ruby-rdoc-1.8.5-5.el5_3.7.s390x.rpm
ruby-ri-1.8.5-5.el5_3.7.s390x.rpm
ruby-tcltk-1.8.5-5.el5_3.7.s390x.rpm

x86_64:
ruby-1.8.5-5.el5_3.7.x86_64.rpm
ruby-debuginfo-1.8.5-5.el5_3.7.i386.rpm
ruby-debuginfo-1.8.5-5.el5_3.7.x86_64.rpm
ruby-devel-1.8.5-5.el5_3.7.i386.rpm
ruby-devel-1.8.5-5.el5_3.7.x86_64.rpm
ruby-docs-1.8.5-5.el5_3.7.x86_64.rpm
ruby-irb-1.8.5-5.el5_3.7.x86_64.rpm
ruby-libs-1.8.5-5.el5_3.7.i386.rpm
ruby-libs-1.8.5-5.el5_3.7.x86_64.rpm
ruby-mode-1.8.5-5.el5_3.7.x86_64.rpm
ruby-rdoc-1.8.5-5.el5_3.7.x86_64.rpm
ruby-ri-1.8.5-5.el5_3.7.x86_64.rpm
ruby-tcltk-1.8.5-5.el5_3.7.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1558
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0642
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1904
http://www.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is . More contact
details at https://www.redhat.com/security/team/contact/

Copyright 2009 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFKTOjZXlSAg2UNWIIRApmfAJ4hL3LESrhpOWPHSuPPP0hHf04l/ACeP6Qk
xADthyb9rgzWXxu9Q39Sl/M=
=9kgV
-----END PGP SIGNATURE-----
"

RHSA-2009:1138-01 Important: openswan security update  

Posted by Daniela Mehler

"-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
Red Hat Security Advisory

Synopsis: Important: openswan security update
Advisory ID: RHSA-2009:1138-01
Product: Red Hat Enterprise Linux
Advisory URL: https://rhn.redhat.com/errata/RHSA-2009-1138.html
Issue date: 2009-07-02
CVE Names: CVE-2009-2185
=====================================================================

1. Summary:

Updated openswan packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 5.

This update has been rated as having important security impact by the Red
Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64
Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64

3. Description:

Openswan is a free implementation of Internet Protocol Security (IPsec)
and Internet Key Exchange (IKE). IPsec uses strong cryptography to provide
both authentication and encryption services. These services allow you to
build secure tunnels through untrusted networks. Everything passing through
the untrusted network is encrypted by the IPsec gateway machine, and
decrypted by the gateway at the other end of the tunnel. The resulting
tunnel is a virtual private network (VPN).

Multiple insufficient input validation flaws were found in the way
Openswan's pluto IKE daemon processed some fields of X.509 certificates. A
remote attacker could provide a specially-crafted X.509 certificate that
would crash the pluto daemon. (CVE-2009-2185)

All users of openswan are advised to upgrade to these updated packages,
which contain a backported patch to correct these issues. After installing
this update, the ipsec service will be restarted automatically.

4. Solution:

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

5. Bugs fixed (http://bugzilla.redhat.com/):

507362 - CVE-2009-2185 Openswan ASN.1 parser vulnerability

6. Package List:

Red Hat Enterprise Linux Desktop (v. 5 client):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/openswan-2.6.14-1.el5_3.3.src.rpm

i386:
openswan-2.6.14-1.el5_3.3.i386.rpm
openswan-debuginfo-2.6.14-1.el5_3.3.i386.rpm
openswan-doc-2.6.14-1.el5_3.3.i386.rpm

x86_64:
openswan-2.6.14-1.el5_3.3.x86_64.rpm
openswan-debuginfo-2.6.14-1.el5_3.3.x86_64.rpm
openswan-doc-2.6.14-1.el5_3.3.x86_64.rpm

Red Hat Enterprise Linux (v. 5 server):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Server/en/os/SRPMS/openswan-2.6.14-1.el5_3.3.src.rpm

i386:
openswan-2.6.14-1.el5_3.3.i386.rpm
openswan-debuginfo-2.6.14-1.el5_3.3.i386.rpm
openswan-doc-2.6.14-1.el5_3.3.i386.rpm

ia64:
openswan-2.6.14-1.el5_3.3.ia64.rpm
openswan-debuginfo-2.6.14-1.el5_3.3.ia64.rpm
openswan-doc-2.6.14-1.el5_3.3.ia64.rpm

ppc:
openswan-2.6.14-1.el5_3.3.ppc.rpm
openswan-debuginfo-2.6.14-1.el5_3.3.ppc.rpm
openswan-doc-2.6.14-1.el5_3.3.ppc.rpm

s390x:
openswan-2.6.14-1.el5_3.3.s390x.rpm
openswan-debuginfo-2.6.14-1.el5_3.3.s390x.rpm
openswan-doc-2.6.14-1.el5_3.3.s390x.rpm

x86_64:
openswan-2.6.14-1.el5_3.3.x86_64.rpm
openswan-debuginfo-2.6.14-1.el5_3.3.x86_64.rpm
openswan-doc-2.6.14-1.el5_3.3.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2185
http://www.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is . More contact
details at https://www.redhat.com/security/team/contact/

Copyright 2009 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFKTNFnXlSAg2UNWIIRAugsAJ4yaxSTRGdgKqPWiqhYXrOwugw5lACfblkL
8Sb2/1P4b1TJZXDNJGwb76I=
=8sMZ
-----END PGP SIGNATURE-----
"

USN-797-1: tiff vulnerability  

Posted by Daniela Mehler

"Ubuntu Security Notice USN-797-1 July 06, 2009
tiff vulnerability
CVE-2009-2285
==========================
==========================
=========

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
libtiff4 3.7.4-1ubuntu3.4

Ubuntu 8.04 LTS:
libtiff4 3.8.2-7ubuntu3.2

Ubuntu 8.10:
libtiff4 3.8.2-11ubuntu0.8.10.1

Ubuntu 9.04:
libtiff4 3.8.2-11ubuntu0.9.04.1

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

It was discovered that the TIFF library did not correctly handle certain
malformed TIFF images. If a user or automated system were tricked into
processing a malicious image, a remote attacker could cause an application
linked against libtiff to crash, leading to a denial of service.


Updated packages for Ubuntu 6.06 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/tiff_3.7.4-1ubuntu3.=
4.diff.gz
Size/MD5: 19878 69684a7a9c033fb40c755d2bb4dffaa2
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/tiff_3.7.4-1ubuntu3.=
4.dsc
Size/MD5: 764 2a6cbe50d507d9c402ad4e92fa1a66b8
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/tiff_3.7.4.orig.tar.=
gz
Size/MD5: 1280113 02cf5c3820bda83b35bb35b45ae27005

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.7.4-=
1ubuntu3.4_amd64.deb
Size/MD5: 220708 159dcfd51cf69df380ea71620b922f04
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.7.4-1=
ubuntu3.4_amd64.deb
Size/MD5: 282354 541c2a6b0fe97743b984dd97c20395fd
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.7.4-1ubun=
tu3.4_amd64.deb
Size/MD5: 475612 4cb99e064c4547553f0edb081c529809
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.7.4-1=
ubuntu3.4_amd64.deb
Size/MD5: 44662 4f662fbcf9fa548ab4f8b8754306c69b
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_3=
.7.4-1ubuntu3.4_amd64.deb
Size/MD5: 49846 953651334379bbaca92baf34950e2405

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.7.4-=
1ubuntu3.4_i386.deb
Size/MD5: 205896 f5ca6a96e1d3dedb3daea18094d65ac3
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.7.4-1=
ubuntu3.4_i386.deb
Size/MD5: 258978 6f612fbbf5ef115b4dcce981dcacf46f
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.7.4-1ubun=
tu3.4_i386.deb
Size/MD5: 461822 ccb6e0322690b9e0f4064ee72813bd1f
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.7.4-1=
ubuntu3.4_i386.deb
Size/MD5: 44646 fedd7054ff09c4a761f0bf052adc9dbb
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_3=
.7.4-1ubuntu3.4_i386.deb
Size/MD5: 49176 4b422744db9046b2e6c24e2eeb8d0863

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.7.4-=
1ubuntu3.4_powerpc.deb
Size/MD5: 239714 2c126df7fad173e8e8facfbfe70d96bf
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.7.4-1=
ubuntu3.4_powerpc.deb
Size/MD5: 288002 38a94eccdd4d769d5c833a4c18861a66
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.7.4-1ubun=
tu3.4_powerpc.deb
Size/MD5: 475924 aae7d86246008c63a0ef95a08b5f4eb2
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.7.4-1=
ubuntu3.4_powerpc.deb
Size/MD5: 46874 da98b514589753068801921dc68ceae6
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_3=
.7.4-1ubuntu3.4_powerpc.deb
Size/MD5: 51514 80ac11ceaaffc8f848967b0811b7f5e2

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.7.4-=
1ubuntu3.4_sparc.deb
Size/MD5: 208520 4abc2ee74c41ba87917b975a7cb758ed
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.7.4-1=
ubuntu3.4_sparc.deb
Size/MD5: 269972 3cdfd7084bf54d17643e2f00793fb3a5
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.7.4-1ubun=
tu3.4_sparc.deb
Size/MD5: 466632 b2c1bfb026aac831ced2ce4dafebf860
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.7.4-1=
ubuntu3.4_sparc.deb
Size/MD5: 44594 f97d5668dd1b3deeb9992be92e1ffc7f
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_3=
.7.4-1ubuntu3.4_sparc.deb
Size/MD5: 49728 c4ce31f33d03dc294f40ada0bc955887

Updated packages for Ubuntu 8.04 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/tiff_3.8.2-7ubuntu3.=
2.diff.gz
Size/MD5: 18378 450fcf81a838b9c67637987a2b39088b
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/tiff_3.8.2-7ubuntu3.=
2.dsc
Size/MD5: 860 92cf9f6d3136c5b6fb52e4d123c0fdd5
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/tiff_3.8.2.orig.tar.=
gz
Size/MD5: 1333780 e6ec4ab957ef49d5aabc38b7a376910b

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.8.2-=
7ubuntu3.2_amd64.deb
Size/MD5: 186242 28dff44adbabe76ab7e85ff2da365f9d
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.8.2-7=
ubuntu3.2_amd64.deb
Size/MD5: 570796 315cdea73e2f4c28c891848d7e7e4fc0
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.8.2-7ubun=
tu3.2_amd64.deb
Size/MD5: 130702 854535fab48a5f2a37a9256f61a38ab5
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.8.2-7=
ubuntu3.2_amd64.deb
Size/MD5: 5064 4097c51386aaaafbfeae9eabaeb997c9
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_3=
.8.2-7ubuntu3.2_amd64.deb
Size/MD5: 10494 49c45bed31e28bcd9d5e706f1c8db3cc

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.8.2-=
7ubuntu3.2_i386.deb
Size/MD5: 175048 01226d438f325312684575560d86d93b
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.8.2-7=
ubuntu3.2_i386.deb
Size/MD5: 552280 36c3a1e37d12f1992346a057e4dab075
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.8.2-7ubun=
tu3.2_i386.deb
Size/MD5: 122400 44cb0efa99a513084835be466da2cb7d
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.8.2-7=
ubuntu3.2_i386.deb
Size/MD5: 5048 db565d6e40fa1b15e6ff9b87a599c0d7
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_3=
.8.2-7ubuntu3.2_i386.deb
Size/MD5: 9942 c7f799a523da81cee7c90ade65be2ccd

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/main/t/tiff/libtiff-tools_3.8.2-7ubuntu3.2=
_lpia.deb
Size/MD5: 177116 df191c9d5e2f48103589d92a59b902d1
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4-dev_3.8.2-7ubuntu3.2_=
lpia.deb
Size/MD5: 554842 2d10224badec0434fbb9d21d432df89d
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4_3.8.2-7ubuntu3.2_lpia=
.deb
Size/MD5: 123556 534d8b03274794d0563a3b48001143c7
http://ports.ubuntu.com/pool/main/t/tiff/libtiffxx0c2_3.8.2-7ubuntu3.2_=
lpia.deb
Size/MD5: 4920 264e617e42f1c8972cb1b2bb18a91574
http://ports.ubuntu.com/pool/universe/t/tiff/libtiff-opengl_3.8.2-7ubun=
tu3.2_lpia.deb
Size/MD5: 9976 e5940f1dbb7d090a4e5d47cca0daeca2

powerpc architecture (Apple Macintosh G3/G4/G5):

http://ports.ubuntu.com/pool/main/t/tiff/libtiff-tools_3.8.2-7ubuntu3.2=
_powerpc.deb
Size/MD5: 223238 2385fe8b199cce7295eaea9282cacf24
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4-dev_3.8.2-7ubuntu3.2_=
powerpc.deb
Size/MD5: 576794 51814c281f84fe2e0650d3f8e029ac4a
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4_3.8.2-7ubuntu3.2_powe=
rpc.deb
Size/MD5: 134016 3df0fd7a4ad96106e2f5143f1645b102
http://ports.ubuntu.com/pool/main/t/tiff/libtiffxx0c2_3.8.2-7ubuntu3.2_=
powerpc.deb
Size/MD5: 7514 5963503e765f0fe71ffa80fbc60c162f
http://ports.ubuntu.com/pool/universe/t/tiff/libtiff-opengl_3.8.2-7ubun=
tu3.2_powerpc.deb
Size/MD5: 13286 3f3851bf7186b2d4450d35beeec0bb4d

sparc architecture (Sun SPARC/UltraSPARC):

http://ports.ubuntu.com/pool/main/t/tiff/libtiff-tools_3.8.2-7ubuntu3.2=
_sparc.deb
Size/MD5: 178640 086f9b0f2e83f879e323fd924f8a89f2
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4-dev_3.8.2-7ubuntu3.2_=
sparc.deb
Size/MD5: 558202 b334310f53743de237845e24fcd911ec
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4_3.8.2-7ubuntu3.2_spar=
c.deb
Size/MD5: 122160 95fd3e3346b8dce74e274239d00c018b
http://ports.ubuntu.com/pool/main/t/tiff/libtiffxx0c2_3.8.2-7ubuntu3.2_=
sparc.deb
Size/MD5: 4800 4a09138aa5f408d8fe49057f90cd0df1
http://ports.ubuntu.com/pool/universe/t/tiff/libtiff-opengl_3.8.2-7ubun=
tu3.2_sparc.deb
Size/MD5: 10710 18641ce46b309baeb923165dd8e03158

Updated packages for Ubuntu 8.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/tiff_3.8.2-11ubuntu0=
.8.10.1.diff.gz
Size/MD5: 37962 6c0956eecb7503bdb31a1bd4299efe47
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/tiff_3.8.2-11ubuntu0=
.8.10.1.dsc
Size/MD5: 1328 7548341cdd1a4a9bae7c793b6f677233
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/tiff_3.8.2.orig.tar.=
gz
Size/MD5: 1333780 e6ec4ab957ef49d5aabc38b7a376910b

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-doc_3.8.2-11=
ubuntu0.8.10.1_all.deb
Size/MD5: 334688 eff9827309f80a957196e9cd4da695d8

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.8.2-1=
1ubuntu0.8.10.1_amd64.deb
Size/MD5: 250518 61fe3d4dd8def51dbd2b5d9b4159a9bc
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.8.2-11ubu=
ntu0.8.10.1_amd64.deb
Size/MD5: 134084 c2adab0fb711634f47e695f3dd7447f8
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.8.2-1=
1ubuntu0.8.10.1_amd64.deb
Size/MD5: 6286 4b2563a3b767209061646fa6ae9ac85b
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_3=
.8.2-11ubuntu0.8.10.1_amd64.deb
Size/MD5: 11898 81a456c5d470799230c6a44f9cc8f9b9
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-tools_3.=
8.2-11ubuntu0.8.10.1_amd64.deb
Size/MD5: 191424 82a9fa8eb070e32116b0d8ecd5a22e0d

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.8.2-1=
1ubuntu0.8.10.1_i386.deb
Size/MD5: 233298 a01eb038a2ccbef8b6603525bc3f2f75
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.8.2-11ubu=
ntu0.8.10.1_i386.deb
Size/MD5: 125878 4eda3acf59c21aba5e1cc89e96bfa8cc
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.8.2-1=
1ubuntu0.8.10.1_i386.deb
Size/MD5: 6272 a6ec88be551d729364d27af4863e1b11
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_3=
.8.2-11ubuntu0.8.10.1_i386.deb
Size/MD5: 11236 359d02f2dcdad53dcf72d0619aff697b
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-tools_3.=
8.2-11ubuntu0.8.10.1_i386.deb
Size/MD5: 176054 42b7f0efbbc73b45d6e69053ebf33671

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/main/t/tiff/libtiff4-dev_3.8.2-11ubuntu0.8=
.10.1_lpia.deb
Size/MD5: 235774 ca05ad7d9e13ada710db91e738800eab
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4_3.8.2-11ubuntu0.8.10.=
1_lpia.deb
Size/MD5: 127584 cf7c86c00c4a0e05cac37039288965f0
http://ports.ubuntu.com/pool/main/t/tiff/libtiffxx0c2_3.8.2-11ubuntu0.8=
.10.1_lpia.deb
Size/MD5: 6132 a865f92bff1a6c22b927ee8af097c433
http://ports.ubuntu.com/pool/universe/t/tiff/libtiff-opengl_3.8.2-11ubu=
ntu0.8.10.1_lpia.deb
Size/MD5: 11282 733acc73b8be40399063ff28128525f5
http://ports.ubuntu.com/pool/universe/t/tiff/libtiff-tools_3.8.2-11ubun=
tu0.8.10.1_lpia.deb
Size/MD5: 178278 523c412323f658d260ae6a4d2ff40966

powerpc architecture (Apple Macintosh G3/G4/G5):

http://ports.ubuntu.com/pool/main/t/tiff/libtiff4-dev_3.8.2-11ubuntu0.8=
.10.1_powerpc.deb
Size/MD5: 256510 d4b027ddeb929f3589956ba496cffba0
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4_3.8.2-11ubuntu0.8.10.=
1_powerpc.deb
Size/MD5: 137148 e32d2bdd0d4a7cc71eec5e7daed52aa9
http://ports.ubuntu.com/pool/main/t/tiff/libtiffxx0c2_3.8.2-11ubuntu0.8=
.10.1_powerpc.deb
Size/MD5: 8724 cc701a74b724ca482b21a3dc321949c3
http://ports.ubuntu.com/pool/universe/t/tiff/libtiff-opengl_3.8.2-11ubu=
ntu0.8.10.1_powerpc.deb
Size/MD5: 14234 cbff4f6e6faddfde029ff78ec9c48afb
http://ports.ubuntu.com/pool/universe/t/tiff/libtiff-tools_3.8.2-11ubun=
tu0.8.10.1_powerpc.deb
Size/MD5: 221040 f917935a1761ef9848e8c7c10e0ef06b

sparc architecture (Sun SPARC/UltraSPARC):

http://ports.ubuntu.com/pool/main/t/tiff/libtiff4-dev_3.8.2-11ubuntu0.8=
.10.1_sparc.deb
Size/MD5: 237666 5d6d33cc67ef0d14bd626ccb4dd9bcb6
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4_3.8.2-11ubuntu0.8.10.=
1_sparc.deb
Size/MD5: 123990 190cefef6ceb37c906aecaf1bf59b876
http://ports.ubuntu.com/pool/main/t/tiff/libtiffxx0c2_3.8.2-11ubuntu0.8=
.10.1_sparc.deb
Size/MD5: 6006 6ec8001760781f1af9d8592866ff82fe
http://ports.ubuntu.com/pool/universe/t/tiff/libtiff-opengl_3.8.2-11ubu=
ntu0.8.10.1_sparc.deb
Size/MD5: 12046 a2b4639c81cb79b31b0646657205fa35
http://ports.ubuntu.com/pool/universe/t/tiff/libtiff-tools_3.8.2-11ubun=
tu0.8.10.1_sparc.deb
Size/MD5: 183412 8ff9e8d6a32d80872131327e5203796c

Updated packages for Ubuntu 9.04:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/tiff_3.8.2-11ubuntu0=
.9.04.1.diff.gz
Size/MD5: 37962 438146f23bcd7888fcc66c7b9d78098b
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/tiff_3.8.2-11ubuntu0=
.9.04.1.dsc
Size/MD5: 1328 9ec573172e0fde174b56d0a3956ee35b
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/tiff_3.8.2.orig.tar.=
gz
Size/MD5: 1333780 e6ec4ab957ef49d5aabc38b7a376910b

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-doc_3.8.2-11=
ubuntu0.9.04.1_all.deb
Size/MD5: 334670 fa4a10e51620299585fa1642196f2887

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.8.2-=
11ubuntu0.9.04.1_amd64.deb
Size/MD5: 191466 a61b82a3393f44e40cd2cc0f640eb6c6
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.8.2-1=
1ubuntu0.9.04.1_amd64.deb
Size/MD5: 250604 cd4538b261cc9003e7c131adda8b51ca
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.8.2-11ubu=
ntu0.9.04.1_amd64.deb
Size/MD5: 134104 38fa2282b5e992c72a4ac79e0ece52b0
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.8.2-1=
1ubuntu0.9.04.1_amd64.deb
Size/MD5: 6286 401262f1a09831f0130f0db2872c97f6
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_3=
.8.2-11ubuntu0.9.04.1_amd64.deb
Size/MD5: 11898 bdf96619188143fe417e8fa3bc5f780d

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.8.2-=
11ubuntu0.9.04.1_i386.deb
Size/MD5: 176050 aa334ea8a28d5274741368d08b0f795d
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.8.2-1=
1ubuntu0.9.04.1_i386.deb
Size/MD5: 233334 2f3bfd25e51a9cca95f4c58646318d29
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.8.2-11ubu=
ntu0.9.04.1_i386.deb
Size/MD5: 125970 3ceceb06c0b6b94fa508e008f19408b7
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.8.2-1=
1ubuntu0.9.04.1_i386.deb
Size/MD5: 6272 35faf1e62dc2e57509ef98116b4c7cfb
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_3=
.8.2-11ubuntu0.9.04.1_i386.deb
Size/MD5: 11228 0abf911853cdb7cd1020f5c43782ab92

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/main/t/tiff/libtiff-tools_3.8.2-11ubuntu0.=
9.04.1_lpia.deb
Size/MD5: 178280 db957830b08ec26fc211e78674f175c7
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4-dev_3.8.2-11ubuntu0.9=
.04.1_lpia.deb
Size/MD5: 235772 146d7fbd61e3885873c2d884c3f289be
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4_3.8.2-11ubuntu0.9.04.=
1_lpia.deb
Size/MD5: 127566 bec17756ac7d7c5c94fb4823b297b6df
http://ports.ubuntu.com/pool/main/t/tiff/libtiffxx0c2_3.8.2-11ubuntu0.9=
.04.1_lpia.deb
Size/MD5: 6126 36ebd0a2f1faaa2d67cdc9687377047b
http://ports.ubuntu.com/pool/universe/t/tiff/libtiff-opengl_3.8.2-11ubu=
ntu0.9.04.1_lpia.deb
Size/MD5: 11276 efd0a2c2218bfbcd1a9211d85945fa43

powerpc architecture (Apple Macintosh G3/G4/G5):

http://ports.ubuntu.com/pool/main/t/tiff/libtiff-tools_3.8.2-11ubuntu0.=
9.04.1_powerpc.deb
Size/MD5: 221080 3ba1c50579c20918faaef6191ed041eb
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4-dev_3.8.2-11ubuntu0.9=
.04.1_powerpc.deb
Size/MD5: 256338 eeb0f7815019f42674e3ed5fdfc72036
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4_3.8.2-11ubuntu0.9.04.=
1_powerpc.deb
Size/MD5: 136980 638fb9b42c406d00b1510a926b5ed3ba
http://ports.ubuntu.com/pool/main/t/tiff/libtiffxx0c2_3.8.2-11ubuntu0.9=
.04.1_powerpc.deb
Size/MD5: 8726 50665d1f710dba6dc2742e2bb57acf02
http://ports.ubuntu.com/pool/universe/t/tiff/libtiff-opengl_3.8.2-11ubu=
ntu0.9.04.1_powerpc.deb
Size/MD5: 14228 3f0ee5ed9b9d24b19ec162f1c71127ce

sparc architecture (Sun SPARC/UltraSPARC):

http://ports.ubuntu.com/pool/main/t/tiff/libtiff-tools_3.8.2-11ubuntu0.=
9.04.1_sparc.deb
Size/MD5: 183404 2852bdbf720008437395f7821c827fd4
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4-dev_3.8.2-11ubuntu0.9=
.04.1_sparc.deb
Size/MD5: 237662 9da18282c48f96aabf98965c0717d9b2
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4_3.8.2-11ubuntu0.9.04.=
1_sparc.deb
Size/MD5: 123884 1600707f7478f01789738311510f598a
http://ports.ubuntu.com/pool/main/t/tiff/libtiffxx0c2_3.8.2-11ubuntu0.9=
.04.1_sparc.deb
Size/MD5: 5970 15efadc4f18985aa1fadc50bec55d099
http://ports.ubuntu.com/pool/universe/t/tiff/libtiff-opengl_3.8.2-11ubu=
ntu0.9.04.1_sparc.deb
Size/MD5: 12018 1475302ae62826aced512ca859a2c237



--=-QZuUXxiqrnN+elNkh4mZ
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEABECAAYFAkpSQsUACgkQLMAs/0C4zNoE4gCbBCExnygkDVYOdy8ngopkJIFo
6XgAn3Bl9fWGA0jZFc54iLHd2p+r5gFh
=kBnL
-----END PGP SIGNATURE-----
"

GLSA 200907-03 APR Utility Library: Multiple vulnerabilities  

Posted by Daniela Mehler

"Gentoo Linux Security Advisory GLSA 200907-03
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Normal
Title: APR Utility Library: Multiple vulnerabilities
Date: July 04, 2009
Bugs: #268643, #272260, #274193
ID: 200907-03

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities in the Apache Portable Runtime Utility Library
might enable remote attackers to cause a Denial of Service or disclose
sensitive information.

Background
==========

The Apache Portable Runtime Utility Library (aka apr-util) provides an
interface to functionality such as XML parsing, string matching and
databases connections.

Affected packages
=================

-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 dev-libs/apr-util < 1.3.7 > = 1.3.7

Description
===========

Multiple vulnerabilities have been discovered in the APR Utility
Library:

* Matthew Palmer reported a heap-based buffer underflow while
compiling search patterns in the apr_strmatch_precompile() function
in strmatch/apr_strmatch.c (CVE-2009-0023).

* kcope reported that the expat XML parser in xml/apr_xml.c does not
limit the amount of XML entities expanded recursively
(CVE-2009-1955).

* C. Michael Pilato reported an off-by-one error in the
apr_brigade_vprintf() function in buckets/apr_brigade.c
(CVE-2009-1956).

Impact
======

A remote attacker could exploit these vulnerabilities to cause a Denial
of Service (crash or memory exhaustion) via an Apache HTTP server
running mod_dav or mod_dav_svn, or using several configuration files.
Additionally, a remote attacker could disclose sensitive information or
cause a Denial of Service by sending a specially crafted input. NOTE:
Only big-endian architectures such as PPC and HPPA are affected by the
latter flaw.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Apache Portable Runtime Utility Library users should upgrade to the
latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-libs/apr-util-1.3.7"

References
==========

[ 1 ] CVE-2009-0023
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0023
[ 2 ] CVE-2009-1955
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1955
[ 3 ] CVE-2009-1956
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1956

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200907-03.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2009 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5
"

RHSA-2009:1139-01 Moderate: pidgin security and bug fix update  

Posted by Daniela Mehler

"-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
Red Hat Security Advisory

Synopsis: Moderate: pidgin security and bug fix update
Advisory ID: RHSA-2009:1139-01
Product: Red Hat Enterprise Linux
Advisory URL: https://rhn.redhat.com/errata/RHSA-2009-1139.html
Issue date: 2009-07-02
CVE Names: CVE-2009-1889
=====================================================================

1. Summary:

Updated pidgin packages that fix one security issue and one bug are now
available for Red Hat Enterprise Linux 4 and 5.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64
RHEL Desktop Workstation (v. 5 client) - i386, x86_64
RHEL Optional Productivity Applications (v. 5 server) - i386, x86_64

3. Description:

Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously. The AOL
Open System for CommunicAtion in Realtime (OSCAR) protocol is used by the
AOL ICQ and AIM instant messaging systems.

A denial of service flaw was found in the Pidgin OSCAR protocol
implementation. If a remote ICQ user sent a web message to a local Pidgin
user using this protocol, it would cause excessive memory usage, leading to
a denial of service (Pidgin crash). (CVE-2009-1889)

These updated packages also fix the following bug:

* the Yahoo! Messenger Protocol changed, making it incompatible (and
unusable) with Pidgin versions prior to 2.5.7. This update provides Pidgin
2.5.8, which implements version 16 of the Yahoo! Messenger Protocol, which
resolves this issue.

Note: These packages upgrade Pidgin to version 2.5.8. Refer to the Pidgin
release notes for a full list of changes:
http://developer.pidgin.im/wiki/ChangeLog

All Pidgin users should upgrade to these updated packages, which correct
these issues. Pidgin must be restarted for this update to take effect.

4. Solution:

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

5. Bugs fixed (http://bugzilla.redhat.com/):

508271 - pidgin Yahoo protocol 16 [rhel-4.8.z]
508272 - pidgin Yahoo protocol 16 [rhel-5.3.z]
508738 - CVE-2009-1889 pidgin: DoS via specially-crafted ICQWebMessage

6. Package List:

Red Hat Enterprise Linux AS version 4:

Source:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/pidgin-2.5.8-1.el4.src.rpm

i386:
finch-2.5.8-1.el4.i386.rpm
finch-devel-2.5.8-1.el4.i386.rpm
libpurple-2.5.8-1.el4.i386.rpm
libpurple-devel-2.5.8-1.el4.i386.rpm
libpurple-perl-2.5.8-1.el4.i386.rpm
libpurple-tcl-2.5.8-1.el4.i386.rpm
pidgin-2.5.8-1.el4.i386.rpm
pidgin-debuginfo-2.5.8-1.el4.i386.rpm
pidgin-devel-2.5.8-1.el4.i386.rpm
pidgin-perl-2.5.8-1.el4.i386.rpm

ia64:
finch-2.5.8-1.el4.ia64.rpm
finch-devel-2.5.8-1.el4.ia64.rpm
libpurple-2.5.8-1.el4.ia64.rpm
libpurple-devel-2.5.8-1.el4.ia64.rpm
libpurple-perl-2.5.8-1.el4.ia64.rpm
libpurple-tcl-2.5.8-1.el4.ia64.rpm
pidgin-2.5.8-1.el4.ia64.rpm
pidgin-debuginfo-2.5.8-1.el4.ia64.rpm
pidgin-devel-2.5.8-1.el4.ia64.rpm
pidgin-perl-2.5.8-1.el4.ia64.rpm

ppc:
finch-2.5.8-1.el4.ppc.rpm
finch-devel-2.5.8-1.el4.ppc.rpm
libpurple-2.5.8-1.el4.ppc.rpm
libpurple-devel-2.5.8-1.el4.ppc.rpm
libpurple-perl-2.5.8-1.el4.ppc.rpm
libpurple-tcl-2.5.8-1.el4.ppc.rpm
pidgin-2.5.8-1.el4.ppc.rpm
pidgin-debuginfo-2.5.8-1.el4.ppc.rpm
pidgin-devel-2.5.8-1.el4.ppc.rpm
pidgin-perl-2.5.8-1.el4.ppc.rpm

x86_64:
finch-2.5.8-1.el4.x86_64.rpm
finch-devel-2.5.8-1.el4.x86_64.rpm
libpurple-2.5.8-1.el4.x86_64.rpm
libpurple-devel-2.5.8-1.el4.x86_64.rpm
libpurple-perl-2.5.8-1.el4.x86_64.rpm
libpurple-tcl-2.5.8-1.el4.x86_64.rpm
pidgin-2.5.8-1.el4.x86_64.rpm
pidgin-debuginfo-2.5.8-1.el4.x86_64.rpm
pidgin-devel-2.5.8-1.el4.x86_64.rpm
pidgin-perl-2.5.8-1.el4.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

Source:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/pidgin-2.5.8-1.el4.src.rpm

i386:
finch-2.5.8-1.el4.i386.rpm
finch-devel-2.5.8-1.el4.i386.rpm
libpurple-2.5.8-1.el4.i386.rpm
libpurple-devel-2.5.8-1.el4.i386.rpm
libpurple-perl-2.5.8-1.el4.i386.rpm
libpurple-tcl-2.5.8-1.el4.i386.rpm
pidgin-2.5.8-1.el4.i386.rpm
pidgin-debuginfo-2.5.8-1.el4.i386.rpm
pidgin-devel-2.5.8-1.el4.i386.rpm
pidgin-perl-2.5.8-1.el4.i386.rpm

x86_64:
finch-2.5.8-1.el4.x86_64.rpm
finch-devel-2.5.8-1.el4.x86_64.rpm
libpurple-2.5.8-1.el4.x86_64.rpm
libpurple-devel-2.5.8-1.el4.x86_64.rpm
libpurple-perl-2.5.8-1.el4.x86_64.rpm
libpurple-tcl-2.5.8-1.el4.x86_64.rpm
pidgin-2.5.8-1.el4.x86_64.rpm
pidgin-debuginfo-2.5.8-1.el4.x86_64.rpm
pidgin-devel-2.5.8-1.el4.x86_64.rpm
pidgin-perl-2.5.8-1.el4.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

Source:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/pidgin-2.5.8-1.el4.src.rpm

i386:
finch-2.5.8-1.el4.i386.rpm
finch-devel-2.5.8-1.el4.i386.rpm
libpurple-2.5.8-1.el4.i386.rpm
libpurple-devel-2.5.8-1.el4.i386.rpm
libpurple-perl-2.5.8-1.el4.i386.rpm
libpurple-tcl-2.5.8-1.el4.i386.rpm
pidgin-2.5.8-1.el4.i386.rpm
pidgin-debuginfo-2.5.8-1.el4.i386.rpm
pidgin-devel-2.5.8-1.el4.i386.rpm
pidgin-perl-2.5.8-1.el4.i386.rpm

ia64:
finch-2.5.8-1.el4.ia64.rpm
finch-devel-2.5.8-1.el4.ia64.rpm
libpurple-2.5.8-1.el4.ia64.rpm
libpurple-devel-2.5.8-1.el4.ia64.rpm
libpurple-perl-2.5.8-1.el4.ia64.rpm
libpurple-tcl-2.5.8-1.el4.ia64.rpm
pidgin-2.5.8-1.el4.ia64.rpm
pidgin-debuginfo-2.5.8-1.el4.ia64.rpm
pidgin-devel-2.5.8-1.el4.ia64.rpm
pidgin-perl-2.5.8-1.el4.ia64.rpm

x86_64:
finch-2.5.8-1.el4.x86_64.rpm
finch-devel-2.5.8-1.el4.x86_64.rpm
libpurple-2.5.8-1.el4.x86_64.rpm
libpurple-devel-2.5.8-1.el4.x86_64.rpm
libpurple-perl-2.5.8-1.el4.x86_64.rpm
libpurple-tcl-2.5.8-1.el4.x86_64.rpm
pidgin-2.5.8-1.el4.x86_64.rpm
pidgin-debuginfo-2.5.8-1.el4.x86_64.rpm
pidgin-devel-2.5.8-1.el4.x86_64.rpm
pidgin-perl-2.5.8-1.el4.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

Source:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/pidgin-2.5.8-1.el4.src.rpm

i386:
finch-2.5.8-1.el4.i386.rpm
finch-devel-2.5.8-1.el4.i386.rpm
libpurple-2.5.8-1.el4.i386.rpm
libpurple-devel-2.5.8-1.el4.i386.rpm
libpurple-perl-2.5.8-1.el4.i386.rpm
libpurple-tcl-2.5.8-1.el4.i386.rpm
pidgin-2.5.8-1.el4.i386.rpm
pidgin-debuginfo-2.5.8-1.el4.i386.rpm
pidgin-devel-2.5.8-1.el4.i386.rpm
pidgin-perl-2.5.8-1.el4.i386.rpm

ia64:
finch-2.5.8-1.el4.ia64.rpm
finch-devel-2.5.8-1.el4.ia64.rpm
libpurple-2.5.8-1.el4.ia64.rpm
libpurple-devel-2.5.8-1.el4.ia64.rpm
libpurple-perl-2.5.8-1.el4.ia64.rpm
libpurple-tcl-2.5.8-1.el4.ia64.rpm
pidgin-2.5.8-1.el4.ia64.rpm
pidgin-debuginfo-2.5.8-1.el4.ia64.rpm
pidgin-devel-2.5.8-1.el4.ia64.rpm
pidgin-perl-2.5.8-1.el4.ia64.rpm

x86_64:
finch-2.5.8-1.el4.x86_64.rpm
finch-devel-2.5.8-1.el4.x86_64.rpm
libpurple-2.5.8-1.el4.x86_64.rpm
libpurple-devel-2.5.8-1.el4.x86_64.rpm
libpurple-perl-2.5.8-1.el4.x86_64.rpm
libpurple-tcl-2.5.8-1.el4.x86_64.rpm
pidgin-2.5.8-1.el4.x86_64.rpm
pidgin-debuginfo-2.5.8-1.el4.x86_64.rpm
pidgin-devel-2.5.8-1.el4.x86_64.rpm
pidgin-perl-2.5.8-1.el4.x86_64.rpm

Red Hat Enterprise Linux Desktop (v. 5 client):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/pidgin-2.5.8-1.el5.src.rpm

i386:
finch-2.5.8-1.el5.i386.rpm
libpurple-2.5.8-1.el5.i386.rpm
libpurple-perl-2.5.8-1.el5.i386.rpm
libpurple-tcl-2.5.8-1.el5.i386.rpm
pidgin-2.5.8-1.el5.i386.rpm
pidgin-debuginfo-2.5.8-1.el5.i386.rpm
pidgin-perl-2.5.8-1.el5.i386.rpm

x86_64:
finch-2.5.8-1.el5.i386.rpm
finch-2.5.8-1.el5.x86_64.rpm
libpurple-2.5.8-1.el5.i386.rpm
libpurple-2.5.8-1.el5.x86_64.rpm
libpurple-perl-2.5.8-1.el5.x86_64.rpm
libpurple-tcl-2.5.8-1.el5.x86_64.rpm
pidgin-2.5.8-1.el5.i386.rpm
pidgin-2.5.8-1.el5.x86_64.rpm
pidgin-debuginfo-2.5.8-1.el5.i386.rpm
pidgin-debuginfo-2.5.8-1.el5.x86_64.rpm
pidgin-perl-2.5.8-1.el5.x86_64.rpm

RHEL Desktop Workstation (v. 5 client):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/pidgin-2.5.8-1.el5.src.rpm

i386:
finch-devel-2.5.8-1.el5.i386.rpm
libpurple-devel-2.5.8-1.el5.i386.rpm
pidgin-debuginfo-2.5.8-1.el5.i386.rpm
pidgin-devel-2.5.8-1.el5.i386.rpm

x86_64:
finch-devel-2.5.8-1.el5.i386.rpm
finch-devel-2.5.8-1.el5.x86_64.rpm
libpurple-devel-2.5.8-1.el5.i386.rpm
libpurple-devel-2.5.8-1.el5.x86_64.rpm
pidgin-debuginfo-2.5.8-1.el5.i386.rpm
pidgin-debuginfo-2.5.8-1.el5.x86_64.rpm
pidgin-devel-2.5.8-1.el5.i386.rpm
pidgin-devel-2.5.8-1.el5.x86_64.rpm

RHEL Optional Productivity Applications (v. 5 server):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Server/en/os/SRPMS/pidgin-2.5.8-1.el5.src.rpm

i386:
finch-2.5.8-1.el5.i386.rpm
finch-devel-2.5.8-1.el5.i386.rpm
libpurple-2.5.8-1.el5.i386.rpm
libpurple-devel-2.5.8-1.el5.i386.rpm
libpurple-perl-2.5.8-1.el5.i386.rpm
libpurple-tcl-2.5.8-1.el5.i386.rpm
pidgin-2.5.8-1.el5.i386.rpm
pidgin-debuginfo-2.5.8-1.el5.i386.rpm
pidgin-devel-2.5.8-1.el5.i386.rpm
pidgin-perl-2.5.8-1.el5.i386.rpm

x86_64:
finch-2.5.8-1.el5.i386.rpm
finch-2.5.8-1.el5.x86_64.rpm
finch-devel-2.5.8-1.el5.i386.rpm
finch-devel-2.5.8-1.el5.x86_64.rpm
libpurple-2.5.8-1.el5.i386.rpm
libpurple-2.5.8-1.el5.x86_64.rpm
libpurple-devel-2.5.8-1.el5.i386.rpm
libpurple-devel-2.5.8-1.el5.x86_64.rpm
libpurple-perl-2.5.8-1.el5.x86_64.rpm
libpurple-tcl-2.5.8-1.el5.x86_64.rpm
pidgin-2.5.8-1.el5.i386.rpm
pidgin-2.5.8-1.el5.x86_64.rpm
pidgin-debuginfo-2.5.8-1.el5.i386.rpm
pidgin-debuginfo-2.5.8-1.el5.x86_64.rpm
pidgin-devel-2.5.8-1.el5.i386.rpm
pidgin-devel-2.5.8-1.el5.x86_64.rpm
pidgin-perl-2.5.8-1.el5.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1889
http://www.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is . More contact
details at https://www.redhat.com/security/team/contact/

Copyright 2009 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFKTNF/XlSAg2UNWIIRAr8lAKCr/4odojtnNTEP/gqW9lDWfQjv5wCgkjsb
3ibMWjOdc4L9r3p2PHAGfFA=
=WHwQ
-----END PGP SIGNATURE-----
"

DSA 1826-1: New eggdrop packages fix several vulnerabilities  

Posted by Daniela Mehler

"-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
Debian Security Advisory DSA-1826-1 security@debian.org
http://www.debian.org/security/ Steffen Joeris
July 04, 2009 http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package : eggdrop
Vulnerability : several
Problem type : remote
Debian-specific: no
CVE Id(s) : CVE-2007-2807 CVE-2009-1789
Debian Bugs : 427157 528778

Several vulnerabilities have been discovered in eggdrop, an advanced IRC
robot. The Common Vulnerabilities and Exposures project identifies the
following problems:

CVE-2007-2807

It was discovered that eggdrop is vulnerable to a buffer overflow, which
could result in a remote user executing arbitrary code. The previous DSA
(DSA-1448-1) did not fix the issue correctly.

CVE-2009-1789

It was discovered that eggdrop is vulnerable to a denial of service
attack, that allows remote attackers to cause a crash via a crafted
PRIVMSG.

For the stable distribution (lenny), these problems have been fixed in
version 1.6.19-1.1+lenny1.

For the old stable distribution (etch), these problems have been fixed in
version 1.6.18-1etch2.

For the unstable distribution (sid), this problem has been fixed in
version 1.6.19-1.2


We recommend that you upgrade your eggdrop package.


Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 4.0 alias etch
- -------------------------------

Debian (oldstable)
- ------------------

Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives:

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.18-1etch2.dsc
Size/MD5 checksum: 650 594b4749b9ec89f7d369643895710ad8
http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.18-1etch2.diff.gz
Size/MD5 checksum: 8016 1a18e0a558c7de704c220e6ed0f14bff
http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.18.orig.tar.gz
Size/MD5 checksum: 1025608 c2734a51926bdf0380d8bb53f5a7b2ee

Architecture independent packages:

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop-data_1.6.18-1etch2_all.deb
Size/MD5 checksum: 413124 5f8afe289ebefcc7921fc1a9189c7efd

alpha architecture (DEC Alpha)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.18-1etch2_alpha.deb
Size/MD5 checksum: 597062 c79a36069bad2181b84fc8d49b944b16

amd64 architecture (AMD x86_64 (AMD64))

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.18-1etch2_amd64.deb
Size/MD5 checksum: 537512 9c3244b387ee9ceddb1dda220247a4f1

arm architecture (ARM)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.18-1etch2_arm.deb
Size/MD5 checksum: 498890 055e953dcb486f625a15459dc55aab19

hppa architecture (HP PA RISC)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.18-1etch2_hppa.deb
Size/MD5 checksum: 600144 ac69ebc0c01053cd4cbd35eba71546a8

i386 architecture (Intel ia32)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.18-1etch2_i386.deb
Size/MD5 checksum: 475340 945bb805188e10c0ce96e0b5d2295deb

ia64 architecture (Intel ia64)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.18-1etch2_ia64.deb
Size/MD5 checksum: 755532 724ae130ed456eb5d5a229fa9a9c1669

mips architecture (MIPS (Big Endian))

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.18-1etch2_mips.deb
Size/MD5 checksum: 533850 60232404dbc3aab7be1bbd44f9727cf7

mipsel architecture (MIPS (Little Endian))

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.18-1etch2_mipsel.deb
Size/MD5 checksum: 537320 40f9df7e42a932ea8c0c91d9c778505d

powerpc architecture (PowerPC)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.18-1etch2_powerpc.deb
Size/MD5 checksum: 522414 27b819f07a51ef3027bf89e77afbfeea

s390 architecture (IBM S/390)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.18-1etch2_s390.deb
Size/MD5 checksum: 530102 32d0911a7a50d9de96313ec56d707c09

sparc architecture (Sun SPARC/UltraSPARC)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.18-1etch2_sparc.deb
Size/MD5 checksum: 490614 8985bad87328abe986ccd99d5d4a106f


Debian GNU/Linux 5.0 alias lenny
- --------------------------------

Debian (stable)
- ---------------

Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives:

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19-1.1+lenny1.dsc
Size/MD5 checksum: 1083 0fbb3a99c0027705fd9459ff03fce710
http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19.orig.tar.gz
Size/MD5 checksum: 1033152 4d89a901e95f0f9937f4ffac783d55d8
http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19-1.1+lenny1.diff.gz
Size/MD5 checksum: 17603 73742e8b01487405d815296f5fb91a58

Architecture independent packages:

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop-data_1.6.19-1.1+lenny1_all.deb
Size/MD5 checksum: 412066 7e5a850e026fe53cfade4e6dd43948af

alpha architecture (DEC Alpha)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19-1.1+lenny1_alpha.deb
Size/MD5 checksum: 593730 d791d84436f4ba40ac542afdb5181588

amd64 architecture (AMD x86_64 (AMD64))

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19-1.1+lenny1_amd64.deb
Size/MD5 checksum: 545870 0bba74f2562866bb282d5ac9c575d042

arm architecture (ARM)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19-1.1+lenny1_arm.deb
Size/MD5 checksum: 507040 86269695984245a98e23a2ec3c48259d

armel architecture (ARM EABI)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19-1.1+lenny1_armel.deb
Size/MD5 checksum: 523006 14ec7c7ea8de55c77a554c2b8871231a

hppa architecture (HP PA RISC)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19-1.1+lenny1_hppa.deb
Size/MD5 checksum: 591212 9f79dac9962932605a4dc331f201736d

i386 architecture (Intel ia32)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19-1.1+lenny1_i386.deb
Size/MD5 checksum: 468618 1231dad4cd3f847298efd9c453ec7a67

ia64 architecture (Intel ia64)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19-1.1+lenny1_ia64.deb
Size/MD5 checksum: 750226 a24c908ebc0e6ee68f5d07778527b767

mips architecture (MIPS (Big Endian))

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19-1.1+lenny1_mips.deb
Size/MD5 checksum: 523760 a62db58be23b5a3b2d568344f1d7503d

mipsel architecture (MIPS (Little Endian))

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19-1.1+lenny1_mipsel.deb
Size/MD5 checksum: 526202 431f1302ef1539336b57887e58317aa5

powerpc architecture (PowerPC)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19-1.1+lenny1_powerpc.deb
Size/MD5 checksum: 532980 435c9a597ba6a84b2f7fb655fbd06d2b

s390 architecture (IBM S/390)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19-1.1+lenny1_s390.deb
Size/MD5 checksum: 527910 4b95f23c5e1cd5120d5bfaf0fc4e420f

sparc architecture (Sun SPARC/UltraSPARC)

http://security.debian.org/pool/updates/main/e/eggdrop/eggdrop_1.6.19-1.1+lenny1_sparc.deb
Size/MD5 checksum: 479812 cabbfb068f710ecba8715a89815fe252


These files will probably be moved into the stable distribution on
its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show ' and http://packages.debian.org/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkpOw2wACgkQ62zWxYk/rQe2VACeKGzfpUAXZEfTvVPOmQqRW9Z5
/5oAnA+PZjuAarXURzc923k2zul0vzag
=R3e5
-----END PGP SIGNATURE-----
"

USN-795-1: Nagios vulnerability  

Posted by Daniela Mehler

"Ubuntu Security Notice USN-795-1 July 02, 2009
nagios2, nagios3 vulnerability
CVE-2009-2288
==========================
==========================
=========

A security issue affects the following Ubuntu releases:

Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.04 LTS:
nagios2 2.11-1ubuntu1.5

Ubuntu 8.10:
nagios3 3.0.2-1ubuntu1.2

Ubuntu 9.04:
nagios3 3.0.6-2ubuntu1.1

After a standard system upgrade you need to restart Nagios to effect
the necessary changes.

Details follow:

It was discovered that Nagios did not properly parse certain commands
submitted using the WAP web interface. An authenticated user could exploit
this flaw and execute arbitrary programs on the server.


Updated packages for Ubuntu 8.04 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/universe/n/nagios2/nagios2_2.11-=
1ubuntu1.5.diff.gz
Size/MD5: 38279 5ac25c4aebdf965b305601c175702762
http://security.ubuntu.com/ubuntu/pool/universe/n/nagios2/nagios2_2.11-=
1ubuntu1.5.dsc
Size/MD5: 1174 550ace4cab74733c7ba58d996105fe41
http://security.ubuntu.com/ubuntu/pool/universe/n/nagios2/nagios2_2.11.=
orig.tar.gz
Size/MD5: 1741962 058c1f4829de748b42da1b584cccc941

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/universe/n/nagios2/nagios2-commo=
n_2.11-1ubuntu1.5_all.deb
Size/MD5: 61606 7c7cdbb7a541a7dc2e6cbe6b0a1e4a1c
http://security.ubuntu.com/ubuntu/pool/universe/n/nagios2/nagios2-doc_2=
.11-1ubuntu1.5_all.deb
Size/MD5: 1135074 434928fdccc05df77e7c1b55c0944f7d

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/universe/n/nagios2/nagios2-dbg_2=
.11-1ubuntu1.5_amd64.deb
Size/MD5: 1641482 c196a73f534801375beae196a695e2a3
http://security.ubuntu.com/ubuntu/pool/universe/n/nagios2/nagios2_2.11-=
1ubuntu1.5_amd64.deb
Size/MD5: 1106466 1f9ee59209d23fec44c8caef64d73603

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/universe/n/nagios2/nagios2-dbg_2=
.11-1ubuntu1.5_i386.deb
Size/MD5: 1553278 8cfc9a73ee6b53cb92ef16ceace75c81
http://security.ubuntu.com/ubuntu/pool/universe/n/nagios2/nagios2_2.11-=
1ubuntu1.5_i386.deb
Size/MD5: 987476 fb77a60168243e0e9b2ce41fb6b6d952

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/universe/n/nagios2/nagios2-dbg_2.11-1ubunt=
u1.5_lpia.deb
Size/MD5: 1587648 895c0d78b5911808b2eb41180ec14f02
http://ports.ubuntu.com/pool/universe/n/nagios2/nagios2_2.11-1ubuntu1.5=
_lpia.deb
Size/MD5: 999380 8d58ae28c5486ca49bea608504b626f0

powerpc architecture (Apple Macintosh G3/G4/G5):

http://ports.ubuntu.com/pool/universe/n/nagios2/nagios2-dbg_2.11-1ubunt=
u1.5_powerpc.deb
Size/MD5: 1610524 c7c0f2c4ba63f63501215495753ff780
http://ports.ubuntu.com/pool/universe/n/nagios2/nagios2_2.11-1ubuntu1.5=
_powerpc.deb
Size/MD5: 1109852 db249ea38d72b5da364d0a72e980e496

sparc architecture (Sun SPARC/UltraSPARC):

http://ports.ubuntu.com/pool/universe/n/nagios2/nagios2-dbg_2.11-1ubunt=
u1.5_sparc.deb
Size/MD5: 1449090 5a55e6d14881d445b8f61bbb34ce0b5a
http://ports.ubuntu.com/pool/universe/n/nagios2/nagios2_2.11-1ubuntu1.5=
_sparc.deb
Size/MD5: 989830 c0755ea4ad906f8a390696f5b22e70b5

Updated packages for Ubuntu 8.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2-1ub=
untu1.2.diff.gz
Size/MD5: 38837 9d114719a76218b8a5091e0366cb7021
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2-1ub=
untu1.2.dsc
Size/MD5: 1644 dd4d8f5b405b7172784b948063b3edc6
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2.ori=
g.tar.gz
Size/MD5: 2759331 008d71aac08660bc007f7130ea82ab80

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-common_3.=
0.2-1ubuntu1.2_all.deb
Size/MD5: 72322 fe1bd2d9b7b4445431c26812b1f31882
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-doc_3.0.2=
-1ubuntu1.2_all.deb
Size/MD5: 2063342 b1f7b496156df603ba106ce0ef5586ef

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-dbg_3.0.2=
-1ubuntu1.2_amd64.deb
Size/MD5: 2660548 9bb9cc6116a2339f5576571d0743c836
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2-1ub=
untu1.2_amd64.deb
Size/MD5: 1538942 745dadf430d6d524ce2a03f4a5862a07

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-dbg_3.0.2=
-1ubuntu1.2_i386.deb
Size/MD5: 2429640 607d3061e30c10cd6e1e35d2fd6360df
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2-1ub=
untu1.2_i386.deb
Size/MD5: 1387634 5ceaf6ffdc011083ad34eb3d8dbfb136

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/main/n/nagios3/nagios3-dbg_3.0.2-1ubuntu1.=
2_lpia.deb
Size/MD5: 2480154 a6da42b7b34b6cd061194b3af2220085
http://ports.ubuntu.com/pool/main/n/nagios3/nagios3_3.0.2-1ubuntu1.2_lp=
ia.deb
Size/MD5: 1376700 2ea3ee9bca2ae629740dfce4487698d5

powerpc architecture (Apple Macintosh G3/G4/G5):

http://ports.ubuntu.com/pool/main/n/nagios3/nagios3-dbg_3.0.2-1ubuntu1.=
2_powerpc.deb
Size/MD5: 2631370 5f68ac3f75cc8761b84213ea5c11adf3
http://ports.ubuntu.com/pool/main/n/nagios3/nagios3_3.0.2-1ubuntu1.2_po=
werpc.deb
Size/MD5: 1525420 917f29e0d8b82bdb86887af4806ef5f1

sparc architecture (Sun SPARC/UltraSPARC):

http://ports.ubuntu.com/pool/main/n/nagios3/nagios3-dbg_3.0.2-1ubuntu1.=
2_sparc.deb
Size/MD5: 2327596 13a0e4f497814b337fde9e12c49ad043
http://ports.ubuntu.com/pool/main/n/nagios3/nagios3_3.0.2-1ubuntu1.2_sp=
arc.deb
Size/MD5: 1380100 4e25adcec75a84c620a9fb7e18b75702

Updated packages for Ubuntu 9.04:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.6-2ub=
untu1.1.diff.gz
Size/MD5: 38327 dc34106fff458be3756e32a243493aeb
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.6-2ub=
untu1.1.dsc
Size/MD5: 1644 040f8f07b7412fcef4d0524940d279f2
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.6.ori=
g.tar.gz
Size/MD5: 2735504 900e3f4164f4b2a18485420eeaefe812

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-common_3.=
0.6-2ubuntu1.1_all.deb
Size/MD5: 75416 a033c3d7df46e468829ca115bb972a38
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-doc_3.0.6=
-2ubuntu1.1_all.deb
Size/MD5: 2034048 d67fb713664aaba43e5c61f73d8ccc49

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-dbg_3.0.6=
-2ubuntu1.1_amd64.deb
Size/MD5: 2700484 75291229645109a5e7b91b6f4424258c
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.6-2ub=
untu1.1_amd64.deb
Size/MD5: 1545190 3c62bce19c004bc1806fb0f67571a4f1

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-dbg_3.0.6=
-2ubuntu1.1_i386.deb
Size/MD5: 2475634 8469b5914727459b29c59499fc8e7dae
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.6-2ub=
untu1.1_i386.deb
Size/MD5: 1393028 9c999ffd347ee3ae7f67276877ec60fe

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/main/n/nagios3/nagios3-dbg_3.0.6-2ubuntu1.=
1_lpia.deb
Size/MD5: 2518790 6bb2db3e55bbac932c61337bd747607c
http://ports.ubuntu.com/pool/main/n/nagios3/nagios3_3.0.6-2ubuntu1.1_lp=
ia.deb
Size/MD5: 1381592 8ddf7128ad7e373dd83f5c322961660a

powerpc architecture (Apple Macintosh G3/G4/G5):

http://ports.ubuntu.com/pool/main/n/nagios3/nagios3-dbg_3.0.6-2ubuntu1.=
1_powerpc.deb
Size/MD5: 2677292 7c7a08f106cda4312bb4ca5a78f574d9
http://ports.ubuntu.com/pool/main/n/nagios3/nagios3_3.0.6-2ubuntu1.1_po=
werpc.deb
Size/MD5: 1531258 bb4c09f548d08b0f23b48f6de1ac1602

sparc architecture (Sun SPARC/UltraSPARC):

http://ports.ubuntu.com/pool/main/n/nagios3/nagios3-dbg_3.0.6-2ubuntu1.=
1_sparc.deb
Size/MD5: 2367924 6d548fa4e1b0845eb83713fd95179811
http://ports.ubuntu.com/pool/main/n/nagios3/nagios3_3.0.6-2ubuntu1.1_sp=
arc.deb
Size/MD5: 1384926 ee9e8973823c241fe7b9d5611476b887



--=-a7lsibacS7tz9Olr2Tyj
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEABECAAYFAkpM/G8ACgkQLMAs/0C4zNofIgCgr57cLSZSjgONq5l3II6w5iyF
AqoAoKHwXqHtFglut4hHwcgQ5OvfdMYs
=zbiq
-----END PGP SIGNATURE-----
"