---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-057
2004-01-31
---------------------------------------------------------------------
Name : rdesktop
Version : 1.3.0
Release : 2
Summary : X client for remote desktop into Windows Terminal Server
Description :
rdesktop is an open source client for Windows NT Terminal Server and
Windows 2000 Terminal Services, capable of natively speaking Remote
Desktop Protocol (RDP) in order to present the user's NT
desktop. Unlike Citrix ICA, no server extensions are required.
---------------------------------------------------------------------
Update Information:
http://sourceforge.net/mailarchive/forum.php?thread_id=3371793&forum_id=8866
Upstream project's complete changelog for the new 1.3.0 version is here.
rdesktop-1.3.0 is a major feature upgrade which adds much capability
including:
* RDP5
* 15, 16 and 24 bit color depths
* Basic clipboard redirection
* Sound
* IPv6
* Some bug fixes
---------------------------------------------------------------------
* Thu Jan 15 2004 Warren Togami <wtogami(a)redhat.com> 1.3.0-2
- upgrade to 1.3.0
- improve summary
- BuildPrereq -> BuildRequires, the former is deprecated
- Remove doc files that no longer exist
- Add missing XFree86-devel
- There was no -1. Nothing to see here. Move along.
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
6ca88a1385b8d47b36033a8feca55edd SRPMS/rdesktop-1.3.0-2.src.rpm
636cfabd07c69e6522e7022f046b606d i386/rdesktop-1.3.0-2.i386.rpm
55a16923f7b10aea74dda9a27b2c7e7b
i386/debug/rdesktop-debuginfo-1.3.0-2.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
Another issue of the Fedora News Updates has been released and is
available at:
http://fedoranews.org/colin/fnu/week4.shtml
The current issue is always linked to
http://fedoranews.org/colin/fnu/current.shtml
In this issue, we cover The Fedora Project getting a new leader, the
current on-going Bug Day, some new changes with Fedora Core 2 and
introduce some applications. We also cover the LWCE Fedora BOF session.
--
Colin Charles, byte(a)aeon.com.my
http://www.bytebot.net/
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-059
2004-01-26
---------------------------------------------------------------------
Name : slocate
Version : 2.7
Release : 4
Summary : Finds files on a system via a central database.
Description :
Slocate is a security-enhanced version of locate. Just like locate,
slocate searches through a central database (which is updated nightly)
for files which match a given pattern. Slocate allows you to quickly
find files anywhere on your system.
---------------------------------------------------------------------
Update Information:
Patrik Hornik discovered a vulnerability in Slocate versions up to and
including 2.7 where a carefully crafted database could overflow a
heap-based buffer. A local user could exploit this vulnerability to gain
"slocate" group privileges and then read the entire slocate database. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2003-0848 to this issue.
Users of Slocate should upgrade to these packages which contain a
patch from Kevin Lindsay which causes slocate to drop privileges before
reading a user-supplied database.
---------------------------------------------------------------------
* Wed Jan 21 2004 Mark Cox <mjc(a)redhat.com>
- drop privs for non slocate gid databases (CAN-2003-0848)
- update to 2.7
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
01bf7fd37e5eeb0f4ec4bdc09a4f236e SRPMS/slocate-2.7-4.src.rpm
ecec8659907bbbe65297b634d930b9ae i386/slocate-2.7-4.i386.rpm
33661442e2657b361a64acac29e0cea8 i386/debug/slocate-debuginfo-2.7-4.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
Another issue of the Fedora News Updates has been released and is
available at:
http://fedoranews.org/colin/fnu/week3.shtml
The current issue is always linked to
http://fedoranews.org/colin/fnu/current.shtml
In this issue, there's news ranging from the Fedora People blog site, as
well as the most important up2date error fixes (which really gets solved
when you use a mirror!). There's more about the kernel, and an update
with regards to OpenOffice.org from Dan Williams.
--
Colin Charles, byte(a)aeon.com.my
http://www.bytebot.net/
My announcements aren't as fun to read as Bill Nottingham's, but
hopefully the content makes up a bit for the (lack of) style.
A test release of Fedora Core 1 for AMD64 is now available at
ftp://download.fedora.redhat.com/pub/fedora/linux/core/test/0.96/x86_64/
and at distinguised mirror sites near you. Like the original x86
architecture release, the AMD64 architecture has three binary ISO images
and three source ISO images. This is a single (we hope and intend)
test release specifically to check hardware support; the package set is
the same versions as an updated Fedora Core 1 for x86 system will have.
Please file bugs via Bugzilla, at http://bugzilla.redhat.com/bugzilla/
(Product "Fedora Core", Version "test1", Architecture "x86_64" so that
they are noticed and appropriately classified. Hardware support bugs
should generally be filed against the <tt>kernel</tt> component, unless
they are specifically about kudzu or anaconda. Discuss this test release
on fedora-test-list.
We are hoping to make minimal changes before making the final release
available, soon.
Many mirrors are in sync already, many more are still syncing.
michaelkjohnson
"He that composes himself is wiser than he that composes a book."
Linux Application Development -- Ben Franklin
http://people.redhat.com/johnsonm/lad/
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2003-048
2004-01-13
---------------------------------------------------------------------
Name : kernel
Version : 2.4.22
Release : 1.2149.nptl
Summary : The Linux kernel (the core of the Linux operating system)
Description :
The kernel package contains the Linux kernel (vmlinuz), the core of your
Fedora Core Linux operating system. The kernel handles the basic functions
of the operating system: memory allocation, process allocation, device
input and output, etc.
---------------------------------------------------------------------
* Wed Jan 07 2004 Dave Jones <davej(a)redhat.com>
- Merge several EXT2/3 fixes from 2.4.25pre
- EXT2/3 fixes.
- Reclaim pages in truncate
- 2.6 EA symlink compatibility
- forward-compatibility: online resizing
- Allow filesystems with expanded inodes to be mounted
- Handle j_commit_interval == 0
- IDE timeout race fix
- Merge some 2.4.23pre patches that were missed.
- Make root a special case for per-user process limits.
- out_of_memory() locking
- Drop module count if lockd reclaimer thread failed to start
- Fix potential fsync() race condition
- s/Red Hat/Fedora/ in specfile (#112992)
- Add PCI ident for new Intel e1000 card. (#105046)
- Actually wire up 3c59x ethtool ioctl.
- Fix up numeric sysctls to match mainline.
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
0528ff2ef4b077e34a6e9f0bdc4c4c43 SRPMS/kernel-2.4.22-1.2149.nptl.src.rpm
cf2da4c300650d6a68aeb3141e8de93e i386/kernel-source-2.4.22-1.2149.nptl.i386.rpm
b6ffe91b11cb64af23f08de19c965677 i386/kernel-doc-2.4.22-1.2149.nptl.i386.rpm
37bdb02f23cd936fc6a68c8b2f176275 i386/kernel-BOOT-2.4.22-1.2149.nptl.i386.rpm
fe89710f267b238c9e5fcdf3d2658383 i386/debug/kernel-debuginfo-2.4.22-1.2149.nptl.i386.rpm
68de6d015862dfc63d40b68a8fa1affa i386/kernel-2.4.22-1.2149.nptl.i586.rpm
9714ae57c042a42400336c06ae07f2c3 i386/debug/kernel-debuginfo-2.4.22-1.2149.nptl.i586.rpm
ccc831fbb9ffa04ed7504f058411febc i386/kernel-2.4.22-1.2149.nptl.i686.rpm
257145cc01f1ea38fbcf22304b93d566 i386/kernel-smp-2.4.22-1.2149.nptl.i686.rpm
baff2d70eb4e24b626511b9f3feacccd i386/debug/kernel-debuginfo-2.4.22-1.2149.nptl.i686.rpm
70b1314d932ff4283cab39a289b7aedc i386/kernel-2.4.22-1.2149.nptl.athlon.rpm
af27b81477979c6ff42a9e1475adaf3b i386/kernel-smp-2.4.22-1.2149.nptl.athlon.rpm
307fb0efbbc54a55e3d0c2a4b134c691 i386/debug/kernel-debuginfo-2.4.22-1.2149.nptl.athlon.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2003-045
2004-01-12
---------------------------------------------------------------------
Name : glibc
Version : 2.3.2
Release : 101.4
Summary : The GNU libc libraries.
Description :
The glibc package contains standard libraries which are used by
multiple programs on the system. In order to save disk space and
memory, as well as to make upgrading easier, common system code is
kept in one place and shared between programs. This particular package
contains the most important sets of shared libraries: the standard C
library and the standard math library. Without these two libraries, a
Linux system will not function.
---------------------------------------------------------------------
Update Information:
This glibc update fixes lots of bugs in the regular expression
matcher and speeds it up. It fixes a couple of other bugs as well.
---------------------------------------------------------------------
* Tue Jan 06 2004 Jakub Jelinek <jakub(a)redhat.com> 2.3.2-101.4
- some further regex speedups
- fix re.translate handling in regex (#112869)
- change regfree to match old regex behaviour (what is freed
and clearing of freed pointers)
* Tue Dec 30 2003 Jakub Jelinek <jakub(a)redhat.com> 2.3.2-101.3
- fix pmap_set fd and memory leak (#112726)
- fix backreference handling in regex
* Tue Dec 30 2003 Jakub Jelinek <jakub(a)redhat.com> 2.3.2-101.2
- fix to make pthread_setcancelstate (PTHREAD_CANCEL_DISABLE, )
really disable cancellation (#112512)
- lots of regex fixes and speedups (#110401)
- fix nextafter*/nexttoward*
- handle 6th syscall(3) argument on AMD64
- handle memalign/posix_memalign in mtrace
- fix linuxthreads memory leak (#112208)
- remove throw () from cancellation points in linuxthreads (#112602)
- fix NPTL unregister_atfork
- fix unwinding through alternate signal stacks
- fix atan2
- fix pshared condvars in NPTL
- fix pthread_attr_destroy for attributes created with
pthread_attr_init(a)GLIBC_2.0
- add BuildPrereq texinfo (#110252)
- fix ceill/floorl on AMD64
- work around IA64 gas bug with unwind info and .align
- fix NPTL configure
- allow dlopen after fork () in threaded programs
- compute IA-64 default thread stack size correctly
- fix thread stacks with ulimit -s not a multiple of a page size
- randomize PIE shared libraries, honor LD_USE_LOAD_BIAS env variable
- fix execstack handling on kernels without exec-shield
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
8691ff42e5e40639efe255978ceede12 SRPMS/glibc-2.3.2-101.4.src.rpm
435668fdcb571bbb198f611c612343f4 i386/glibc-2.3.2-101.4.i386.rpm
dc6df4a2dd5ceb99abc1cdd86b0942d7 i386/glibc-devel-2.3.2-101.4.i386.rpm
732b23e9774f89bc843fc6bf15c373b7 i386/glibc-headers-2.3.2-101.4.i386.rpm
e8f0b913a4fcc7e00a9a9b7dc8f30f83 i386/glibc-profile-2.3.2-101.4.i386.rpm
3b766065c659937bef08187340c6575e i386/glibc-common-2.3.2-101.4.i386.rpm
ad87113eb994e0cc6ac4b686dafcd54a i386/nscd-2.3.2-101.4.i386.rpm
69bb62e474314b3c6ab74a52d784c93e i386/glibc-debug-2.3.2-101.4.i386.rpm
04e50621c21974cf724f85d3b0134c8a i386/glibc-utils-2.3.2-101.4.i386.rpm
cd2781341edc7922999286d6ab4cd520 i386/debug/glibc-debuginfo-2.3.2-101.4.i386.rpm
1536c86890e7853be071d5096021935e i386/debug/glibc-debuginfo-common-2.3.2-101.4.i386.rpm
7eeb7de975cfc94a1cb42e9cbda946f6 i386/glibc-2.3.2-101.4.i686.rpm
a14c5100db056132a45f47511b5224b7 i386/nptl-devel-2.3.2-101.4.i686.rpm
f397cf2e092bf985bee6d4dc134bddc0 i386/debug/glibc-debuginfo-2.3.2-101.4.i686.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2003-005
2004-01-08
---------------------------------------------------------------------
Name : php
Version : 4.3.4
Release : 1.1
Summary : The PHP HTML-embedded scripting language. (PHP: Hypertext Preprocessor)
Description :
PHP is an HTML-embedded scripting language. PHP attempts to make it
easy for developers to write dynamically generated webpages. PHP also
offers built-in database integration for several commercial and
non-commercial database management systems, so writing a
database-enabled webpage with PHP is fairly simple. The most common
use of PHP coding is probably as a replacement for CGI scripts. The
mod_php module enables the Apache Web server to understand and process
the embedded PHP language in Web pages.
---------------------------------------------------------------------
Update Information:
This update includes the latest stable release of PHP 4 with a
large number of bug fixes since the previous 4.3.3 release.
---------------------------------------------------------------------
* Mon Nov 10 2003 Joe Orton <jorton(a)redhat.com> 4.3.4-1.1
- rebuild for FC1 updates
* Mon Nov 10 2003 Joe Orton <jorton(a)redhat.com> 4.3.4-1
- update to 4.3.4
- include all licence files
- libxmlrpc fixes
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
871c235ab0c0d565a539acbe93af93c7 SRPMS/php-4.3.4-1.1.src.rpm
2856765b46f5b9110c9791143703419d i386/php-4.3.4-1.1.i386.rpm
c8c1e340f9fefa9c689d7611d9ce7ac3 i386/php-devel-4.3.4-1.1.i386.rpm
16202fd128f5d2f2e4c4d143426e7c28 i386/php-imap-4.3.4-1.1.i386.rpm
d2aa01fc26de25258397d6454c0ea28c i386/php-ldap-4.3.4-1.1.i386.rpm
b6a6506d70b2c4a400e7bf94019c6998 i386/php-mysql-4.3.4-1.1.i386.rpm
f46e141c77e2a045dd022ea480a2edea i386/php-pgsql-4.3.4-1.1.i386.rpm
3968c5f541e8808fc7f1e3f0a3b5894d i386/php-odbc-4.3.4-1.1.i386.rpm
60e343db8475e0186500eb872f57f45b i386/php-snmp-4.3.4-1.1.i386.rpm
05ec9feeeaeffaecb09fe4dfcc905426 i386/php-domxml-4.3.4-1.1.i386.rpm
9bd9cf0bb88f2ee6bb08f85a3dd377e7 i386/php-xmlrpc-4.3.4-1.1.i386.rpm
4de1cf6a0627b893331184e453347b49 i386/debug/php-debuginfo-4.3.4-1.1.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2003-004
2004-01-08
---------------------------------------------------------------------
Name : httpd
Version : 2.0.48
Release : 1.2
Summary : Apache HTTP Server
Description :
Apache is a powerful, full-featured, efficient, and freely-available
Web server. Apache is also the most popular Web server on the
Internet.
---------------------------------------------------------------------
Update Information:
This update includes the latest stable release of Apache httpd 2.0,
including a fix for the security issue CVE CAN-2003-0542, a buffer
overflow in the parsing of configuration files.
---------------------------------------------------------------------
* Wed Nov 19 2003 Joe Orton <jorton(a)redhat.com> 2.0.48-1.2
- bug fix for #110184
* Tue Oct 28 2003 Joe Orton <jorton(a)redhat.com> 2.0.48-1.1
- update to 2.0.48 (#108608, thanks to Robert Scheck)
- includes security fix for CVE CAN-2003-0542
- reinstate mpm_common.h (#108080)
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
7b5332edf474a11279d7fadf6563bead SRPMS/httpd-2.0.48-1.2.src.rpm
e4c3bcac083c65d2cfd66c0c3d12067e i386/httpd-2.0.48-1.2.i386.rpm
7f5a0de17d10130f223cf6fbc82d087a i386/httpd-devel-2.0.48-1.2.i386.rpm
a78cef392b7deb61ec6574cc20803067 i386/httpd-manual-2.0.48-1.2.i386.rpm
0fbe28cb1c820df6c619a7ed897e8c77 i386/mod_ssl-2.0.48-1.2.i386.rpm
1adf236f2b50ca7a533e2d77a1585cd7 i386/debug/httpd-debuginfo-2.0.48-1.2.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Security Update Notification
FEDORA-2003-047
2004-01-07
---------------------------------------------------------------------
Name : kernel
Version : 2.4.22
Release : 1.2140.nptl
Summary : The Linux kernel (the core of the Linux operating system)
Description :
The kernel package contains the Linux kernel (vmlinuz), the core of your
Red Hat Linux operating system. The kernel handles the basic functions
of the operating system: memory allocation, process allocation, device
input and output, etc.
---------------------------------------------------------------------
Various RTC drivers had the potential to leak small amounts of kernel
memory to userspace through IOCTL's.
The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-0984 to this issue.
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
69a643e061b0e3a56d07eccf8b142b26 SRPMS/kernel-2.4.22-1.2140.nptl.src.rpm
ff15774cedef09fbfe59c25ece1f6ed2 i386/kernel-source-2.4.22-1.2140.nptl.i386.rpm
9eba879575a930ee4c3ed392cd57ab6b i386/kernel-doc-2.4.22-1.2140.nptl.i386.rpm
3a8bccb684dd6dfcea88f5dce35cdab0 i386/kernel-BOOT-2.4.22-1.2140.nptl.i386.rpm
567c39348a31b964187354a71f2e5a5e i386/debug/kernel-debuginfo-2.4.22-1.2140.nptl.i386.rpm
9a99f90d73034bc06bc75b1f8ca5939c i386/kernel-2.4.22-1.2140.nptl.i586.rpm
0043651e9f2a8781d86a48fc416008b7 i386/debug/kernel-debuginfo-2.4.22-1.2140.nptl.i586.rpm
2058a8d4276508f91c5d8e91b5552fec i386/kernel-2.4.22-1.2140.nptl.i686.rpm
de785e229eb62997287c9ba3c4d35164 i386/kernel-smp-2.4.22-1.2140.nptl.i686.rpm
cb85e72a2437356068cb5f498b4199c5 i386/debug/kernel-debuginfo-2.4.22-1.2140.nptl.i686.rpm
86056e2e9770d38a8dc99ca01f8e1881 i386/kernel-2.4.22-1.2140.nptl.athlon.rpm
e58efa41da0cbd119ade33bf39c3763c i386/kernel-smp-2.4.22-1.2140.nptl.athlon.rpm
ceeb465c728f5ed0e2656d943eba42ff i386/debug/kernel-debuginfo-2.4.22-1.2140.nptl.athlon.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0984