[SECURITY] Fedora 10 Update: psi-0.12.1-1.fc10

Filed Under (Security) by Darrin on 05-03-2009

Tagged Under : ,

------------------------------
————————————————–
Fedora Update Notification
FEDORA-2009-2285
2009-03-04 15:50:58
——————————————————————————–

Name        : psi
Product     : Fedora 10
Version     : 0.12.1
Release     : 1.fc10
URL         : http://psi-im.org
Summary     : Jabber client based on Qt
Description :
Psi is the premiere Instant Messaging application designed for Microsoft
Windows, Apple Mac OS X and GNU/Linux. Built upon an open protocol named
Jabber, Psi is a fast and lightweight messaging client that utilises the best
in open source technologies. Psi contains all the features necessary to chat,
with no bloated extras that slow your computer down. The Jabber protocol
provides gateways to other protocols as AIM, ICQ, MSN and Yahoo!.
If you want SSL support, install the qca-tls package.

——————————————————————————–
Update Information:

This is a bugfix-only update to version 0.12.1    New in 0.12.1   – Bugfix for
DOS vulnerability in the file transfer code.     Thanks to Jesus Olmos
(jolmos@isecauditors.com)
——————————————————————————–
ChangeLog:

* Tue Mar  3 2009 Sven Lankes <sven@lank.es> 0.12.1-1
- version 0.12.1
——————————————————————————–
References:

[ 1 ] Bug #488299 – CVE-2008-6393 psi: remote DoS vulnerability [F10]
https://bugzilla.redhat.com/show_bug.cgi?id=488299
——————————————————————————–

This update can be installed with the “yum” update program.  Use
su -c ‘yum update psi’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
——————————————————————————–

_______________________________________________
Fedora-package-announce mailing list
Fedora-package-announce@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-package-announce

Bookmark and Share

[SECURITY] Fedora 9 Update: psi-0.12.1-1.fc9

Filed Under (Security) by Darrin on 05-03-2009

Tagged Under : ,

------------------------------
————————————————–
Fedora Update Notification
FEDORA-2009-2295
2009-03-04 15:51:08
——————————————————————————–

Name        : psi
Product     : Fedora 9
Version     : 0.12.1
Release     : 1.fc9
URL         : http://psi-im.org
Summary     : Jabber client based on Qt
Description :
Psi is the premiere Instant Messaging application designed for Microsoft
Windows, Apple Mac OS X and GNU/Linux. Built upon an open protocol named
Jabber, Psi is a fast and lightweight messaging client that utilises the best
in open source technologies. Psi contains all the features necessary to chat,
with no bloated extras that slow your computer down. The Jabber protocol
provides gateways to other protocols as AIM, ICQ, MSN and Yahoo!.
If you want SSL support, install the qca-tls package.

——————————————————————————–
Update Information:

This is a security-bugfix-only update to version 0.12.1 fixing a DOS
vulnerability.    New in 0.12.1   – Bugfix for DOS vulnerability in the file
transfer code.     Thanks to Jesus Olmos (jolmos@isecauditors.com)
——————————————————————————–
ChangeLog:

* Tue Mar  3 2009 Sven Lankes <sven@lank.es> 0.12.1-1
- version 0.12.1
* Wed Aug 13 2008 Aurelien Bompard <abompard@fedoraproject.org> 0.12-1
- version 0.12
* Wed May 21 2008 Tom “spot” Callaway <tcallawa@redhat.com> 0.11-5
- fix license tag
——————————————————————————–
References:

[ 1 ] Bug #488301 – CVE-2008-6393 psi: remote DoS vulnerability [F9]
https://bugzilla.redhat.com/show_bug.cgi?id=488301
——————————————————————————–

This update can be installed with the “yum” update program.  Use
su -c ‘yum update psi’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
——————————————————————————–

_______________________________________________
Fedora-package-announce mailing list
Fedora-package-announce@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-package-announce

Bookmark and Share

[SECURITY] Fedora 10 Update: mediawiki-1.14.0-45.fc10

Filed Under (Security) by Darrin on 03-03-2009

Tagged Under : ,

------------------------------
————————————————–
Fedora Update Notification
FEDORA-2009-2231
2009-03-02 16:38:05
——————————————————————————–

Name        : mediawiki
Product     : Fedora 10
Version     : 1.14.0
Release     : 45.fc10
URL         : http://www.mediawiki.org/
Summary     : A wiki engine
Description :
MediaWiki is the software used for Wikipedia and the other Wikimedia
Foundation websites. Compared to other wikis, it has an excellent
range of features and support for high-traffic websites using multiple
servers

This package supports wiki farms. Copy /var/www/wiki over to the
desired wiki location and configure it through the web
interface. Remember to remove the config dir after completing the
configuration.

——————————————————————————–
Update Information:

This update fixes the XSS vulnerabilities in 1.13.3 and splits the package into
a non-math and a full package to allow for smaller installs where embedded math
is not required.
——————————————————————————–
ChangeLog:

* Sat Feb 28 2009 Axel Thimm <Axel.Thimm@ATrpms.net> – 1.14.0-45
- Update to 1.14.0.
* Sun Feb 22 2009 Axel Thimm <Axel.Thimm@ATrpms.net> – 1.13.4-44
- Split package up, so some users can decide to not install math
support (results in smaller installs), see RH bug #485447.
* Wed Feb 18 2009 Axel Thimm <Axel.Thimm@ATrpms.net> – 1.13.4-43
- Update to 1.13.4, closes RH bug #485728.
* Tue Dec 23 2008 Axel Thimm <Axel.Thimm@ATrpms.net> – 1.13.3-42
- Update to 1.13.3, closes RH bug #476621 (CVE-2008-5249,
CVE-2008-5250, CVE-2008-5252 and CVE-2008-5687, CVE-2008-5688)
——————————————————————————–
References:

[ 1 ] Bug #487489 – CVE-2009-0737 mediawiki: multiple XSS issues in the installer
https://bugzilla.redhat.com/show_bug.cgi?id=487489
——————————————————————————–

This update can be installed with the “yum” update program.  Use
su -c ‘yum update mediawiki’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
——————————————————————————–

_______________________________________________
Fedora-package-announce mailing list
Fedora-package-announce@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-package-announce

Bookmark and Share

[SECURITY] Fedora 9 Update: mediawiki-1.14.0-45.fc9

Filed Under (Security) by Darrin on 03-03-2009

Tagged Under : ,

------------------------------
————————————————–
Fedora Update Notification
FEDORA-2009-2237
2009-03-02 16:38:10
——————————————————————————–

Name        : mediawiki
Product     : Fedora 9
Version     : 1.14.0
Release     : 45.fc9
URL         : http://www.mediawiki.org/
Summary     : A wiki engine
Description :
MediaWiki is the software used for Wikipedia and the other Wikimedia
Foundation websites. Compared to other wikis, it has an excellent
range of features and support for high-traffic websites using multiple
servers

This package supports wiki farms. Copy /var/www/wiki over to the
desired wiki location and configure it through the web
interface. Remember to remove the config dir after completing the
configuration.

——————————————————————————–
Update Information:

This update fixes the XSS vulnerabilities in 1.13.3 and splits the package into
a non-math and a full package to allow for smaller installs where embedded math
is not required.
——————————————————————————–
ChangeLog:

* Sat Feb 28 2009 Axel Thimm <Axel.Thimm@ATrpms.net> – 1.14.0-45
- Update to 1.14.0.
* Sun Feb 22 2009 Axel Thimm <Axel.Thimm@ATrpms.net> – 1.13.4-44
- Split package up, so some users can decide to not install math
support (results in smaller installs), see RH bug #485447.
* Wed Feb 18 2009 Axel Thimm <Axel.Thimm@ATrpms.net> – 1.13.4-43
- Update to 1.13.4, closes RH bug #485728.
* Tue Dec 23 2008 Axel Thimm <Axel.Thimm@ATrpms.net> – 1.13.3-42
- Update to 1.13.3, closes RH bug #476621 (CVE-2008-5249,
CVE-2008-5250, CVE-2008-5252 and CVE-2008-5687, CVE-2008-5688)
* Sun Oct  5 2008 Axel Thimm <Axel.Thimm@ATrpms.net> – 1.13.2-41
- Update to 1.13.2.
* Sun Aug 24 2008 Axel Thimm <Axel.Thimm@ATrpms.net> – 1.13.0-40
- Use consistently Patch0 and %patch0.
* Sat Aug 16 2008 Axel Thimm <Axel.Thimm@ATrpms.net> – 1.13.0-39
- Update to 1.13.0.
* Wed May 21 2008 Tom “spot” Callaway <tcallawa@redhat.com> 1.10.4-40
- fix license tag
——————————————————————————–
References:

[ 1 ] Bug #487489 – CVE-2009-0737 mediawiki: multiple XSS issues in the installer
https://bugzilla.redhat.com/show_bug.cgi?id=487489
——————————————————————————–

This update can be installed with the “yum” update program.  Use
su -c ‘yum update mediawiki’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
——————————————————————————–

_______________________________________________
Fedora-package-announce mailing list
Fedora-package-announce@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-package-announce

Bookmark and Share

[SECURITY] Fedora 10 Update: net-snmp-5.4.2.1-3.fc10

Filed Under (Security) by Darrin on 18-02-2009

Tagged Under : ,

------------------------------
————————————————–
Fedora Update Notification
FEDORA-2009-1769
2009-02-17 14:51:02
——————————————————————————–

Name        : net-snmp
Product     : Fedora 10
Version     : 5.4.2.1
Release     : 3.fc10
URL         : http://net-snmp.sourceforge.net/
Summary     : A collection of SNMP protocol tools and libraries
Description :
SNMP (Simple Network Management Protocol) is a protocol used for
network management. The NET-SNMP project includes various SNMP tools:
an extensible agent, an SNMP library, tools for requesting or setting
information from SNMP agents, tools for generating and handling SNMP
traps, a version of the netstat command which uses SNMP, and a Tk/Perl
mib browser. This package contains the snmpd and snmptrapd daemons,
documentation, etc.

You will probably also want to install the net-snmp-utils package,
which contains NET-SNMP utilities.

Building option:
–without tcp_wrappers : disable tcp_wrappers support

——————————————————————————–
ChangeLog:

* Mon Feb 16 2009 Jan Safranek <jsafranek@redhat.com> 5.4.2.1-3
- fix tcp_wrappers integration (CVE-2008-6123)
* Mon Dec  1 2008 Jan Safranek <jsafranek@redhat.com> 5.4.2.1-2
- rebuild for fixed rpm (#473420)
* Mon Nov  3 2008 Jan Safranek <jsafranek@redhat.com> 5.4.2.1-1
- explicitly require the right version and release of net-snmp and
net-snmp-libs
- update to net-snmp-5.4.2.1 to fix CVE-2008-4309
——————————————————————————–
References:

[ 1 ] Bug #485211 – CVE-2008-6123 net-snmp: snmp queries allowed from each remote host regardless of /etc/hosts.allow configuration (host sensitive information disclosure)
https://bugzilla.redhat.com/show_bug.cgi?id=485211
——————————————————————————–

This update can be installed with the “yum” update program.  Use
su -c ‘yum update net-snmp’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
——————————————————————————–

_______________________________________________
Fedora-package-announce mailing list
Fedora-package-announce@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-package-announce

Bookmark and Share