Chapter 1. Package Updates
36
* the CUPS PDF input filter is no longer a separate PDF handling implementation, and instead uses
the pdftops program from the poppler-utils package directly. (
BZ#527429
249
)
* adding or modifying many queues could cause the scheduler to leak large amounts of memory.
(
BZ#540646
250
)
All cups users should upgrade to these updated packages, which resolve these issues.
1.30. curl
1.30.1. RHSA-2010:0273: Moderate security, bug fix and
enhancement update
Updated curl packages that fix one security issue, various bugs, and add enhancements are now
available for Red Hat Enterprise Linux 5.
The Red Hat Security Response Team has rated this update as having moderate security impact. A
Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is
available from the CVE link in the References section.
cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and DICT servers, using any of the
supported protocols. cURL is designed to work without user interaction or any kind of interactivity.
Wesley Miaw discovered that when deflate compression was used, libcurl could call the registered
write callback function with data exceeding the documented limit. A malicious server could use this
flaw to crash an application using libcurl or, potentially, execute arbitrary code. Note: This issue only
affected applications using libcurl that rely on the documented data size limit, and that copy the data to
the insufficiently sized buffer. (
CVE-2010-0734
251
)
This update also fixes the following bugs:
* when using curl to upload a file, if the connection was broken or reset by the server during the
transfer, curl immediately started using 100% CPU and failed to acknowledge that the transfer had
failed. With this update, curl displays an appropriate error message and exits when an upload fails
mid-transfer due to a broken or reset connection. (
BZ#479967
252
)
* libcurl experienced a segmentation fault when attempting to reuse a connection after performing
GSS-negotiate authentication, which in turn caused the curl program to crash. This update fixes this
bug so that reused connections are able to be successfully established even after GSS-negotiate
authentication has been performed. (
BZ#517199
253
)
As well, this update adds the following enhancements:
* curl now supports loading Certificate Revocation Lists (CRLs) from a Privacy Enhanced Mail (PEM)
file. When curl attempts to access sites that have had their certificate revoked in a CRL, curl refuses
access to those sites. (
BZ#532069
254
)
249
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=527429
250
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=540646
251
https://www.redhat.com/security/data/cve/CVE-2010-0734.html
252
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=479967
253
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=517199
254
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=532069
Summary of Contents for ENTERPRISE LINUX 5.5 - S 2010
Page 10: ...x ...
Page 308: ...298 ...
Page 310: ...300 ...
Page 468: ...458 ...
Page 470: ...460 ...