Chapter 1. Package Updates
38
Updated cyrus-sasl packages that resolve an issue are now available.
The cyrus-sasl packages contain the Cyrus implementation of SASL. SASL is the Simple
Authentication and Security Layer, a method for adding authentication support to connection-based
protocols.
These updated cyrus-sasl packages fix the following bug:
* multithreaded programs which used the Cyrus SASL libraries could have become unresponsive after
attempting to perform authentication routines. This was caused by a failure to release a mutex lock on
a data structure in the Cyrus SASL code, which resulted in a race condition, thus causing the program
using the library to hang. This race condition has been fixed so that it is thread-safe in this update.
(
BZ#568084
261
)
All users of cyrus-sasl are advised to upgrade to these updated packages, which resolve this issue.
1.33. dbus
1.33.1. RHSA-2010:0018: Moderate security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2010:0018
262
Updated dbus packages that fix a security issue are now available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red Hat Security Response
Team.
D-Bus is a system for sending messages between applications. It is used for the system-wide
message bus service and as a per-user-login-session messaging facility.
It was discovered that the Red Hat Security Advisory RHSA-2009:0008 did not correctly fix the denial
of service flaw in the system for sending messages between applications. A local user could use this
flaw to send a message with a malformed signature to the bus, causing the bus (and, consequently,
any process using libdbus to receive messages) to abort. (
CVE-2009-1189
263
)
Note: Users running any application providing services over the system message bus are advised to
test this update carefully before deploying it in production environments.
All users are advised to upgrade to these updated packages, which contain a backported patch to
correct this issue. For the update to take effect, all running instances of dbus-daemon and all running
applications using the libdbus library must be restarted, or the system rebooted.
1.33.2. RHBA-2010:0236: bug fix update
Updated dbus packages that fix a multilib conflict that could cause installation failure on 64-bit
architectures are now available.
261
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=568084
263
https://www.redhat.com/security/data/cve/CVE-2009-1189.html
Summary of Contents for ENTERPRISE LINUX 5.5 - S 2010
Page 10: ...x ...
Page 308: ...298 ...
Page 310: ...300 ...
Page 468: ...458 ...
Page 470: ...460 ...