strace
235
An updated squirrelmail package that fixes multiple security issues is now available for Red Hat
Enterprise Linux 3, 4, and 5.
This update has been rated as having important security impact by the Red Hat Security Response
Team.
SquirrelMail is a standards-based webmail package written in PHP.
A server-side code injection flaw was found in the SquirrelMail "map_yp_alias" function. If SquirrelMail
was configured to retrieve a user's IMAP server address from a Network Information Service (NIS)
server via the "map_yp_alias" function, an unauthenticated, remote attacker using a specially-
crafted username could use this flaw to execute arbitrary code with the privileges of the web server.
(
CVE-2009-1579
1668
)
Multiple cross-site scripting (XSS) flaws were found in SquirrelMail. An attacker could construct
a carefully crafted URL, which once visited by an unsuspecting user, could cause the user's
web browser to execute malicious script in the context of the visited SquirrelMail web page.
(
CVE-2009-1578
1669
)
It was discovered that SquirrelMail did not properly sanitize Cascading Style Sheets (CSS) directives
used in HTML mail. A remote attacker could send a specially-crafted email that could place mail
content above SquirrelMail's controls, possibly allowing phishing and cross-site scripting attacks.
(
CVE-2009-1581
1670
)
Users of squirrelmail should upgrade to this updated package, which contains backported patches to
correct these issues.
1.211. strace
1.211.1. RHBA-2009:0309: bug fix update
Note
This update has already been released (prior to the GA of this release) as errata
RHBA-2009:0309
1671
An updated strace package that fixes a bug is now available.
The strace program intercepts and records the system calls that are made and the signals that are
received by processes.
This updated strace package fixes a bug which occurred when "strace -f" was used to trace a
multithreaded program. strace selected threads to trace in an inoptimal manner, which could have
caused certain threads to either run more slowly or to perpetually wait. With this update, strace selects
threads to trace in a smarter manner, thus ensuring that no threads are left overlong in a waiting state,
and therefore resolving the issue.
1668
https://www.redhat.com/security/data/cve/CVE-2009-1579.html
1669
https://www.redhat.com/security/data/cve/CVE-2009-1578.html
1670
https://www.redhat.com/security/data/cve/CVE-2009-1581.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...