Chapter 1. Package Updates
152
The updated libsepol packages address the following issues:
• the RPM package information specified that libsepol was provided under a GPL license. This
contradicted the source RPM change log, which specified that libsepol was provided under a LGPL
licence. The correct licence type (LGPL) is now specified in the libsepol package information.
(
BZ#488802
1149
)
• dontaudit messages could not be disabled, which made it difficult for customers building their own
security policies to identify which policies were being denied. This updated package includes the
"sepol_set_disable_dontaudit" function, which allows dontaudit messages to be disabled.
All users of libsepol are advised to upgrade to these updated packages, which resolve these issues.
1.123. libsoup
1.123.1. RHSA-2009:0344: Moderate security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:0344
1150
Updated libsoup and evolution28-libsoup packages that fix a security issue are now available for Red
Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red Hat Security Response
Team.
libsoup is an HTTP client/library implementation for GNOME written in C. It was originally part of a
SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP
parts have now been split into separate packages.
An integer overflow flaw which caused a heap-based buffer overflow was discovered in libsoup's
Base64 encoding routine. An attacker could use this flaw to crash, or, possibly, execute arbitrary code.
This arbitrary code would execute with the privileges of the application using libsoup's Base64 routine
to encode large, untrusted inputs. (
CVE-2009-0585
1151
)
All users of libsoup and evolution28-libsoup should upgrade to these updated packages, which contain
a backported patch to resolve this issue. All running applications using the affected library function
(such as Evolution configured to connect to the GroupWise back-end) must be restarted for the update
to take effect.
1.124. libspe2
1.124.1. RHBA-2009:1263: bug fix and enhancement update
An updated libspe2 package (re-based to upstream version 2.3.0-135) is now available.
1151
https://www.redhat.com/security/data/cve/CVE-2009-0585.html
Содержание ENTERPRISE 5.4 RELEASE NOTES
Страница 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Страница 18: ...xviii ...
Страница 306: ...288 ...
Страница 464: ...446 ...
Страница 466: ...448 ...