Tuesday, September 11, 2012

[CentOS-announce] CEBA-2012:1251 CentOS 6 kdelibs FASTTRACK Update

CentOS Errata and Bugfix Advisory 2012:1251

Upstream details at : https://rhn.redhat.com/errata/RHBA-2012-1251.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )


i386:
50f7ba08e4d506cd0c8855668c11ce093ea030c6c3e5836d5fa8bb6ea865a6cf kdelibs-4.3.4-17.el6.i686.rpm
64a2f5d78099eae5e3941faea048fbe45ee55138ea8c9fd08dee9f66c1e335e4 kdelibs-apidocs-4.3.4-17.el6.noarch.rpm
a0860a5f4c2a73c162ad637d3dd4e4d9bd95316a34b6fbf44271be6fb5bf6eea kdelibs-common-4.3.4-17.el6.i686.rpm
49d902676386bde2f735bf6af1a5592b3a75cb4584fbf7532f9468ddd4658545 kdelibs-devel-4.3.4-17.el6.i686.rpm

x86_64:
50f7ba08e4d506cd0c8855668c11ce093ea030c6c3e5836d5fa8bb6ea865a6cf kdelibs-4.3.4-17.el6.i686.rpm
42dff05ce579806349a75b3d9c8ef7ef7a3f9b2c2c569241579cb1055e4a57d1 kdelibs-4.3.4-17.el6.x86_64.rpm
f239b8a426a6e3ede5a2044d532310bffa4a4ce3acf58ed9347c24559599abc0 kdelibs-apidocs-4.3.4-17.el6.noarch.rpm
497e01397275227241ceef5889144481e32d3e1b87fa8c1731844fe12df4b258 kdelibs-common-4.3.4-17.el6.x86_64.rpm
49d902676386bde2f735bf6af1a5592b3a75cb4584fbf7532f9468ddd4658545 kdelibs-devel-4.3.4-17.el6.i686.rpm
4dad7209aa712781c9492dfbc00a0289f023626c7984502cda93a4d8d18b4e68 kdelibs-devel-4.3.4-17.el6.x86_64.rpm

Source:
29869bfd8c0d64aa70031ffb75193a8d555e681cbea434e5f18fbe30c24d2981 kdelibs-4.3.4-17.el6.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CEBA-2012:1244 CentOS 6 kdelibs3 FASTTRACK Update

CentOS Errata and Bugfix Advisory 2012:1244

Upstream details at : https://rhn.redhat.com/errata/RHBA-2012-1244.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )


i386:
303db08ca10b8b96ef36f8bdddfe748644700434e703bc938bb1f356a2a4c2c7 kdelibs3-3.5.10-25.el6.i686.rpm
3edfffecd4c349c67b490940a5c2ae7e5f465311945ae466ee1c281d4feb36df kdelibs3-apidocs-3.5.10-25.el6.noarch.rpm
d821d284248379c46ec8c6d9166962e645a43732d75d68f5b511eadf47470d42 kdelibs3-devel-3.5.10-25.el6.i686.rpm

x86_64:
303db08ca10b8b96ef36f8bdddfe748644700434e703bc938bb1f356a2a4c2c7 kdelibs3-3.5.10-25.el6.i686.rpm
6f14e56618d32a0775bd4599b5013b2e535e8207493ba1e7c7d2e3fbb2e67753 kdelibs3-3.5.10-25.el6.x86_64.rpm
89a11cc6c161e5561cff9dd4f229844b548b3783399d9e9dff215fa5e8eb21f5 kdelibs3-apidocs-3.5.10-25.el6.noarch.rpm
d821d284248379c46ec8c6d9166962e645a43732d75d68f5b511eadf47470d42 kdelibs3-devel-3.5.10-25.el6.i686.rpm
ea88e0c77781808e82fc045ab18a78da7f249cec42c31d8c16d076b0ef35ba60 kdelibs3-devel-3.5.10-25.el6.x86_64.rpm

Source:
d4c1f483dfb1d0791b6ce8d725a32aaf4d81eb40c8ffc4aa4209d73edc22ab0c kdelibs3-3.5.10-25.el6.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CEBA-2012:1250 CentOS 6 python Update

CentOS Errata and Bugfix Advisory 2012:1250

Upstream details at : https://rhn.redhat.com/errata/RHBA-2012-1250.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )


i386:
544006ad24605e1fbaffff259ce453ebf61cabd7f988b36f2a503eec794420ad python-2.6.6-29.el6_3.3.i686.rpm
50a7c587f52185a6a9da846dcf45707faf3ca8447bb15974f6db5e310f16d60b python-devel-2.6.6-29.el6_3.3.i686.rpm
606f91033a3f70f9525832b9e350bc9916e44a44cb50b52b9280615fec9aa2d0 python-libs-2.6.6-29.el6_3.3.i686.rpm
30f96db8b8385fd4e1bd68a5abecfa28ac695570d530f18899ab7375d95c59bb python-test-2.6.6-29.el6_3.3.i686.rpm
f59751222914afc8170e2342cb7a03cc663dccdd2f4585887c2f662a8473f6e9 python-tools-2.6.6-29.el6_3.3.i686.rpm
65983b5a23c13a875f957e4b9e79a3b1ca6b48510da61dc30a0499061eaf6797 tkinter-2.6.6-29.el6_3.3.i686.rpm

x86_64:
544006ad24605e1fbaffff259ce453ebf61cabd7f988b36f2a503eec794420ad python-2.6.6-29.el6_3.3.i686.rpm
eeafe11c3ff2d84e997ec16410d697ed2fa0d788cc92e96ead5a8687d64c943a python-2.6.6-29.el6_3.3.x86_64.rpm
50a7c587f52185a6a9da846dcf45707faf3ca8447bb15974f6db5e310f16d60b python-devel-2.6.6-29.el6_3.3.i686.rpm
58696d0e9051a55fab100bf21e438970aa5141ba75ca6aab455c21e2e3a7de6b python-devel-2.6.6-29.el6_3.3.x86_64.rpm
606f91033a3f70f9525832b9e350bc9916e44a44cb50b52b9280615fec9aa2d0 python-libs-2.6.6-29.el6_3.3.i686.rpm
ff192b77afbc9a2e8beb752dcecd9407a53dedfbd766918a7dad2a5a0ae78073 python-libs-2.6.6-29.el6_3.3.x86_64.rpm
8fbb34b91d5fecfb03d9bf0291e4af2b991c0930a5ba21e4a8b342522e4c7bda python-test-2.6.6-29.el6_3.3.x86_64.rpm
8f18541159a5ef4b7012ff565772807f2fd6f757a7991b2adb7f89faac325fb3 python-tools-2.6.6-29.el6_3.3.x86_64.rpm
21eddd0c50398bb726597f38f3787dc00d4be423ba0811563c99acda9b7df63b tkinter-2.6.6-29.el6_3.3.x86_64.rpm

Source:
c41fa561f9ce92e0913efc0e8ccbd98e66e670ae23768f5b7a77bd3d5f3f4f29 python-2.6.6-29.el6_3.3.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CEBA-2012:1252 CentOS 6 selinux-policy Update

CentOS Errata and Bugfix Advisory 2012:1252

Upstream details at : https://rhn.redhat.com/errata/RHBA-2012-1252.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )


i386:
85b887e7f57f1cc2ae3b83f3a4e9b2115b4f13edd6da976fe97637471d877c8e selinux-policy-3.7.19-155.el6_3.4.noarch.rpm
986ffcaa9974d96360fac643545e19f2a0b0af8b2be53c847e1ca3a49d6c62f1 selinux-policy-doc-3.7.19-155.el6_3.4.noarch.rpm
8674cea7e8c9575f72d8b2d9f7958d328b9003933db2416ef831f6dd02bac672 selinux-policy-minimum-3.7.19-155.el6_3.4.noarch.rpm
59c93c1c982b5ef6205761a4b6491d0b207644d8eac9763e9ae8ef38b5948ed0 selinux-policy-mls-3.7.19-155.el6_3.4.noarch.rpm
18d7b133d56ac9e86fc8af7c4212be68aeb3f522a8a7762c79f2640652427213 selinux-policy-targeted-3.7.19-155.el6_3.4.noarch.rpm

x86_64:
8e8e040252e385f59918312dc57800b647e7fd3aad3bfad939bff9d77a0ba0a1 selinux-policy-3.7.19-155.el6_3.4.noarch.rpm
e5bcd4635a4a25b75a143bfec84ddf1b5004989669ecaab700d302611f280a1e selinux-policy-doc-3.7.19-155.el6_3.4.noarch.rpm
96aae592ba052f7c53c6d33c3b36c4f99b09b4e58abe3d0bd95c4a4b7fb55db1 selinux-policy-minimum-3.7.19-155.el6_3.4.noarch.rpm
fc4d19d1e5f0d21fa8a5aa59c46b5615290ffd116c164d00149a2b5cdaec6331 selinux-policy-mls-3.7.19-155.el6_3.4.noarch.rpm
0486b695c2aef13462680512917c59e57f39b71a5507859bf5f1374ac8f5e714 selinux-policy-targeted-3.7.19-155.el6_3.4.noarch.rpm

Source:
7a1a75ddc8b3978d5118eba26cada7a90029c30926e7e77d205104752c341b16 selinux-policy-3.7.19-155.el6_3.4.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CEBA-2012:1249 CentOS 5 ipsec-tools Update

CentOS Errata and Bugfix Advisory 2012:1249

Upstream details at : https://rhn.redhat.com/errata/RHBA-2012-1249.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
a221822c45245f3a67b7f1af2252f90b7592b1df582041b87d7a726e9a59d91b ipsec-tools-0.6.5-14.el5_8.5.i386.rpm

x86_64:
4a5651b99036724dbbd58c58f3f1c5ee3e637a36059498cc52c6f1e87d1ffca8 ipsec-tools-0.6.5-14.el5_8.5.x86_64.rpm

Source:
28b390a101923f5f7ae08b28f64ffb75e3bd41de8a78320769e47aa884509f30 ipsec-tools-0.6.5-14.el5_8.5.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

Monday, September 10, 2012

[USN-1563-1] Linux kernel (Oneiric backport) vulnerability

========================================================================
Ubuntu Security Notice USN-1563-1
September 10, 2012

linux-lts-backport-oneiric vulnerability
========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

The system could be made to crash under certain conditions.

Software Description:
- linux-lts-backport-oneiric: Linux kernel backport from Oneiric

Details:

A flaw was found in the Linux kernel's Reliable Datagram Sockets (RDS)
protocol implementation. A local, unprivileged user could use this flaw to
cause a denial of service.

[USN-1562-1] Linux kernel (Natty backport) vulnerability

========================================================================
Ubuntu Security Notice USN-1562-1
September 10, 2012

linux-lts-backport-natty vulnerability
========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

The system could be made to crash under certain conditions.

Software Description:
- linux-lts-backport-natty: Linux kernel backport from Natty

Details:

Some errors where discovered in the Linux kernel's UDF file system, which
is used to mount some CD-ROMs and DVDs. An unprivileged local user could
use these flaws to crash the system.

[USN-1527-2] XML-RPC for C and C++ vulnerabilities

========================================================================
Ubuntu Security Notice USN-1527-2
September 10, 2012

xmlrpc-c vulnerabilities
========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS

Summary:

XML-RPC for C and C++ could be made to cause a denial of service by consuming
excessive CPU and memory resources.

Software Description:
- xmlrpc-c: Lightweight RPC library based on XML and HTTP

Details:

USN-1527-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for XML-RPC for C and C++. Both issues described in the
original advisory affected XML-RPC for C and C++ in Ubuntu 10.04 LTS, 11.04,
11.10 and 12.04 LTS.

[CentOS-announce] CEBA-2012:1247 CentOS 6 libdvdread FASTTRACK Update

CentOS Errata and Bugfix Advisory 2012:1247

Upstream details at : https://rhn.redhat.com/errata/RHBA-2012-1247.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )


i386:
cc0abd3827fc4a7b9be2c4d51eab07dbe8e45cc704f7614d5ba24500c54ecfaf libdvdread-4.1.4-0.3.svn1183.el6.i686.rpm
7980ee5a7ba4fa480fb94be15c5772bf02292ed0dcd759fdd38826949fdf52a2 libdvdread-devel-4.1.4-0.3.svn1183.el6.i686.rpm

x86_64:
cc0abd3827fc4a7b9be2c4d51eab07dbe8e45cc704f7614d5ba24500c54ecfaf libdvdread-4.1.4-0.3.svn1183.el6.i686.rpm
4dfd44b3d382d9b9870a45370b11cb499abb0ab0c8ff47a704c8380fe3dcdf49 libdvdread-4.1.4-0.3.svn1183.el6.x86_64.rpm
7980ee5a7ba4fa480fb94be15c5772bf02292ed0dcd759fdd38826949fdf52a2 libdvdread-devel-4.1.4-0.3.svn1183.el6.i686.rpm
853a1c33722a417489460d4d4a3135cd491f108b24bc7f207be2a8099e4a4a8e libdvdread-devel-4.1.4-0.3.svn1183.el6.x86_64.rpm

Source:
12315446d73198c35d8cc58284dc3c7ff982fb2ae3f891f38413eab897395c9e libdvdread-4.1.4-0.3.svn1183.el6.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net

[USN-1561-1] ubiquity-slideshow-ubuntu vulnerability

========================================================================
Ubuntu Security Notice USN-1561-1
September 10, 2012

ubiquity-slideshow-ubuntu vulnerability
========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

ubiquity-slideshow-ubuntu would allow unintended access to files over the
network during system installation.

Software Description:
- ubiquity-slideshow-ubuntu: Ubiquity slideshow for Ubuntu

Details:

Paul Mutton discovered that ubiquity-slideshow-ubuntu incorrectly handled
the Twitter feed displayed during system installation. A remote attacker
could use this flaw to inject code into the Twitter feed and read arbitrary
files off the filesystem during system installation. This flaw has been
resolved in the Ubuntu 12.04.1 LTS installation images by disabling the
Twitter feed.

[USN-1559-1] GIMP vulnerabilities

========================================================================
Ubuntu Security Notice USN-1559-1
September 10, 2012

gimp vulnerabilities
========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS

Summary:

GIMP could be made to crash or run programs as your login if it opened a
specially crafted file.

Software Description:
- gimp: The GNU Image Manipulation Program

Details:

Joseph Sheridan discovered that GIMP incorrectly handled certain malformed
headers in FIT files. If a user were tricked into opening a specially
crafted FIT image file, an attacker could cause GIMP to crash.
(CVE-2012-3236)

Murray McAllister discovered that GIMP incorrectly handled malformed KiSS
palette files. If a user were tricked into opening a specially crafted KiSS
palette file, an attacker could cause GIMP to crash, or possibly execute
arbitrary code with the user's privileges. (CVE-2012-3403)

Matthias Weckbecker discovered that GIMP incorrectly handled malformed GIF
image files. If a user were tricked into opening a specially crafted GIF
image file, an attacker could cause GIMP to crash, or possibly execute
arbitrary code with the user's privileges. (CVE-2012-3481)

[USN-1560-1] Django vulnerabilities

========================================================================
Ubuntu Security Notice USN-1560-1
September 10, 2012

python-django vulnerabilities
========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS

Summary:

Applications using Django could be made to crash or expose sensitive
information.

Software Description:
- python-django: High-level Python web development framework

Details:

It was discovered that Django incorrectly validated the scheme of a
redirect target. If a user were tricked into opening a specially crafted
URL, an attacker could possibly exploit this to conduct cross-site
scripting (XSS) attacks. (CVE-2012-3442)

It was discovered that Django incorrectly handled validating certain
images. A remote attacker could use this flaw to cause the server to
consume memory, leading to a denial of service. (CVE-2012-3443)

Jeroen Dekkers discovered that Django incorrectly handled certain image
dimensions. A remote attacker could use this flaw to cause the server to
consume resources, leading to a denial of service. (CVE-2012-3444)