Chapter 1. Package Updates
6
1.4.2. RHSA-2009:0478: Critical security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:0478
45
Updated acroread packages that fix two security issues are now available for Red Hat Enterprise
Linux 3 Extras, Red Hat Enterprise Linux 4 Extras, and Red Hat Enterprise Linux 5 Supplementary.
This update has been rated as having critical security impact by the Red Hat Security Response
Team.
Adobe Reader allows users to view and print documents in Portable Document Format (PDF).
Two flaws were discovered in Adobe Reader's JavaScript API. A PDF file containing malicious
JavaScript instructions could cause Adobe Reader to crash or, potentially, execute arbitrary code as
the user running Adobe Reader. (
CVE-2009-1492
46
,
CVE-2009-1493
47
)
All Adobe Reader users should install these updated packages. They contain Adobe Reader version
8.1.5, which is not vulnerable to these issues. All running instances of Adobe Reader must be
restarted for the update to take effect.
1.4.3. RHSA-2009:0376: Critical security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:0376
48
Updated acroread packages that fix multiple security issues are now available for Red Hat Enterprise
Linux 3 Extras, Red Hat Enterprise Linux 4 Extras, and Red Hat Enterprise Linux 5 Supplementary.
This update has been rated as having critical security impact by the Red Hat Security Response
Team.
Adobe Reader allows users to view and print documents in Portable Document Format (PDF).
Multiple input validation flaws were discovered in the JBIG2 compressed images decoder used
by Adobe Reader. A malicious PDF file could cause Adobe Reader to crash or, potentially,
execute arbitrary code as the user running Adobe Reader. (
CVE-2009-0193
49
,
CVE-2009-0658
50
,
CVE-2009-0928
51
,
CVE-2009-1061
52
,
CVE-2009-1062
53
)
All Adobe Reader users should install these updated packages. They contain Adobe Reader version
8.1.4, which is not vulnerable to these issues. All running instances of Adobe Reader must be
restarted for the update to take effect.
46
https://www.redhat.com/security/data/cve/CVE-2009-1492.html
47
https://www.redhat.com/security/data/cve/CVE-2009-1493.html
49
https://www.redhat.com/security/data/cve/CVE-2009-0193.html
50
https://www.redhat.com/security/data/cve/CVE-2009-0658.html
51
https://www.redhat.com/security/data/cve/CVE-2009-0928.html
52
https://www.redhat.com/security/data/cve/CVE-2009-1061.html
53
https://www.redhat.com/security/data/cve/CVE-2009-1062.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...