tar
261
SystemTap scripts could crash the system. This update adds mutual exclusions to both shutdown
and startup codes, thereby preventing a possible crash. (
BZ#521610
2081
)
• The
literal_addr_to_sym_addr()
function did not correctly compute for marker addresses.
As such, markers became inaccessible after running
prelink
; this prevented scripts that used
markers from compiling. This release fixes the
literal_addr_to_sym_addr()
, ensuring that
marker addresses are accessible after running
prelink
. (
BZ#564445
2082
)
• Updates to GCC changed the format of variable locations it provided during compile time. However,
the code used by SystemTap to process variable locations (in
loc2c.c
) was not updated
accordingly to understand this new format. This could prevent some variables from initializing
properly. With this release, the
loc2c.c
file is updated to correctly process the new format used by
GCC for variable locations. (
BZ#536807
2083
)
SystemTap users are advised to apply this update.
1.202. tar
1.202.1. RHSA-2010:0141: Moderate security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2010:0141
2084
An updated tar package that fixes two security issues is now available for Red Hat Enterprise Linux 4
and 5.
This update has been rated as having moderate security impact by the Red Hat Security Response
Team.
The GNU tar program saves many files together in one archive and can restore individual files (or all
of the files) from that archive.
A heap-based buffer overflow flaw was found in the way tar expanded archive files. If a user were
tricked into expanding a specially-crafted archive, it could cause the tar executable to crash or execute
arbitrary code with the privileges of the user running tar. (
CVE-2010-0624
2085
)
Red Hat would like to thank Jakob Lell for responsibly reporting the
CVE-2010-0624
2086
issue.
A denial of service flaw was found in the way tar expanded archive files. If a user expanded a
specially-crafted archive, it could cause the tar executable to crash. (
CVE-2007-4476
2087
)
Users of tar are advised to upgrade to this updated package, which contains backported patches to
correct these issues.
1.202.2. RHBA-2010:0224: bug fix and enhancement update
An updated tar package that fixes several bugs and adds various enhancements is now available.
2085
https://www.redhat.com/security/data/cve/CVE-2010-0624.html
2086
https://www.redhat.com/security/data/cve/CVE-2010-0624.html
2087
https://www.redhat.com/security/data/cve/CVE-2007-4476.html
Содержание ENTERPRISE LINUX 5.5 - S 2010
Страница 10: ...x ...
Страница 308: ...298 ...
Страница 310: ...300 ...
Страница 468: ...458 ...
Страница 470: ...460 ...