Chapter 1. Package Updates
212
* executing the semanage command with the translation option caused denials and undesired mode
changes to the setrans.conf file. This update removes the translation functionality from the semanage
command. (
BZ#460970
1705
)
* the semanage command allowed an invalid network port number to be passed to it. This update
adds proper verification of the port number option to semanage. Any invalid port number is now
rejected. (
BZ#505521
1706
)
* the use of the #!/usr/bin/env python option at the top of python scripts is being phased out, in favour
of the #!/usr/bin/python option. There was one instance of the former option in a policycoreutils python
script. This fix replaces this line with the latter option in this file. (
BZ#521298
1707
)
* the semanage command did not support the node option being passed to it and resulted in an error
when it was used. This fix adds the node option to the semanage command. This option allows you to
list, add and modify nodes in SELinux policy. (
BZ#527487
1708
)
Users of policycoreutils are advised to upgrade to these updated packages, which resolve these
issues.
1.163. poppler
1.163.1. RHSA-2009:1504: Important security and bug fix update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:1504
1709
Updated poppler packages that fix multiple security issues and a bug are now available for Red Hat
Enterprise Linux 5.
This update has been rated as having important security impact by the Red Hat Security Response
Team.
Poppler is a Portable Document Format (PDF) rendering library, used by applications such as Evince.
Multiple integer overflow flaws were found in poppler. An attacker could create a malicious PDF file
that would cause applications that use poppler (such as Evince) to crash or, potentially, execute
arbitrary code when opened. (
CVE-2009-3603
1710
,
CVE-2009-3608
1711
,
CVE-2009-3609
1712
)
Red Hat would like to thank Chris Rohlf for reporting the
CVE-2009-3608
1713
issue.
1705
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=460970
1706
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=505521
1707
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=521298
1708
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=527487
1710
https://www.redhat.com/security/data/cve/CVE-2009-3603.html
1711
https://www.redhat.com/security/data/cve/CVE-2009-3608.html
1712
https://www.redhat.com/security/data/cve/CVE-2009-3609.html
1713
https://www.redhat.com/security/data/cve/CVE-2009-3608.html
Содержание ENTERPRISE LINUX 5.5 - S 2010
Страница 10: ...x ...
Страница 308: ...298 ...
Страница 310: ...300 ...
Страница 468: ...458 ...
Страница 470: ...460 ...