---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2005-1083
2005-11-21
---------------------------------------------------------------------
Product : Fedora Core 4
Name : GFS-kernel
Version : 2.6.11.8
Release : 20050601.152643.FC4.19
Summary : GFS-kernel - The Global File System kernel modules
Description :
GFS - The Global File System is a symmetric, shared-disk, cluster file
system.
---------------------------------------------------------------------
Update Information:
Update for latest fc4 kernel (2.6.14-1.1637_FC4)
---------------------------------------------------------------------
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
b42854ca9a097c89dde4769a811f8dc1 SRPMS/GFS-kernel-2.6.11.8-20050601.152643.FC4.19.src.rpm
ed5715e52dd9536ff79a19dcf2c45b79 ppc/GFS-kernel-2.6.11.8-20050601.152643.FC4.19.ppc.rpm
3845018d82bbd50458e3d4a092654417 ppc/GFS-kernheaders-2.6.11.8-20050601.152643.FC4.19.ppc.rpm
94cbf4203de9b39121e3231c94b2e43c ppc/debug/GFS-kernel-debuginfo-2.6.11.8-20050601.152643.FC4.19.ppc.rpm
6623518d918641a2bfbb015103f803c8 x86_64/GFS-kernel-2.6.11.8-20050601.152643.FC4.19.x86_64.rpm
3139e7c5c0d803d0aa552324fbabae42 x86_64/GFS-kernheaders-2.6.11.8-20050601.152643.FC4.19.x86_64.rpm
44b4adfbccf892b671fe8cbfe9a7f03f x86_64/GFS-kernel-smp-2.6.11.8-20050601.152643.FC4.19.x86_64.rpm
c32e85cd50c6903c50b14c2a9d27d6b2 x86_64/debug/GFS-kernel-debuginfo-2.6.11.8-20050601.152643.FC4.19.x86_64.rpm
fd8ca9ca41bcf01907ce025c78b8ece9 i386/GFS-kernel-2.6.11.8-20050601.152643.FC4.19.i586.rpm
ade05aff29161d07c77503a635c0bbeb i386/GFS-kernheaders-2.6.11.8-20050601.152643.FC4.19.i586.rpm
81ace78b7ea11fe80558a94af0a0d431 i386/debug/GFS-kernel-debuginfo-2.6.11.8-20050601.152643.FC4.19.i586.rpm
a37bc750f4c93f49ff3c28ef877cb663 i386/GFS-kernel-2.6.11.8-20050601.152643.FC4.19.i686.rpm
42f3dec9639c84cd8fa1393585238e60 i386/GFS-kernheaders-2.6.11.8-20050601.152643.FC4.19.i686.rpm
ce1d7d60c7d1808c8284c3b1b7e3954b i386/GFS-kernel-smp-2.6.11.8-20050601.152643.FC4.19.i686.rpm
3ec7ced34bfbf374c393af74c6f9a970 i386/debug/GFS-kernel-debuginfo-2.6.11.8-20050601.152643.FC4.19.i686.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2005-1093
2005-11-21
---------------------------------------------------------------------
Product : Fedora Core 4
Name : openswan
Version : 2.4.4
Release : 1.0.FC4.1
Summary : Openswan IPSEC implementation
Description :
Openswan is a free implementation of IPSEC & IKE for Linux. IPSEC is
the Internet Protocol Security and uses strong cryptography to provide
both authentication and encryption services. These services allow you
to build secure tunnels through untrusted networks. Everything passing
through the untrusted net is encrypted by the ipsec gateway machine and
decrypted by the gateway at the other end of the tunnel. The resulting
tunnel is a virtual private network or VPN.
This package contains the daemons and userland tools for setting up
Openswan on a freeswan enabled kernel.
---------------------------------------------------------------------
Update Information:
NISCC has reported two Denial of Service issues in Openswan.
The first involves a specially crafted 3DES packet with an
invalid key length.
The Openswan project has relased version 2.4.4 to fix both
issues.
See http://www.openswan.org/ for details.
---------------------------------------------------------------------
* Mon Nov 21 2005 Harald Hoyer <harald(a)redhat.com> - 2.4.4-1.0.FC4.1
- version 2.4.4
- fixes NISCC Vulnerability Advisory 273756/NISCC/ISAKMP
- fixes NISCC Advisory 3756/NISCC/ISAKMP
* Wed Nov 2 2005 Harald Hoyer <harald(a)redhat.com> - 2.4.2-0.dr5.1
- version 2.4.2dr5
* Tue Oct 25 2005 Harald Hoyer <harald(a)redhat.com> - 2.4.2-0.dr1.1
- version 2.4.2dr1
* Tue Sep 13 2005 Harald Hoyer <harald(a)redhat.com> - 2.4.0-1
- version 2.4.0
* Wed Aug 31 2005 Harald Hoyer <harald(a)redhat.com> - 2.4.0-0.rc4.1
- new version
* Sun Jul 31 2005 Florian La Roche <laroche(a)redhat.com>
- remove sysv startup links to build with current rpm
* Thu May 12 2005 Harald Hoyer <harald(a)redhat.com> - 2.3.1-3
- added openswan-2.3.1-nat_t_aggr.patch
- added openswan-2.3.1-iproute2.patch
- added openswan-2.3.1-cisco.patch
- NAT-T/XAUTH/AGGR-MODE is now possible with a Cisco VPN 3000
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
fe9bc3fa5ef955e12050a4e19fc2b9b6 SRPMS/openswan-2.4.4-1.0.FC4.1.src.rpm
8d46760e08073c0932fff34d4fe8da06 ppc/openswan-2.4.4-1.0.FC4.1.ppc.rpm
acc08c24adbc56dacbaa2f6313216bdd ppc/openswan-doc-2.4.4-1.0.FC4.1.ppc.rpm
57b16a581d23a636785cd592ba84bcdf x86_64/openswan-2.4.4-1.0.FC4.1.x86_64.rpm
e970d54a13742f49fe99862f8b286efe x86_64/openswan-doc-2.4.4-1.0.FC4.1.x86_64.rpm
ccf4eef51f820f89baa9f18a3a3ff15f i386/openswan-2.4.4-1.0.FC4.1.i386.rpm
4f952b746ab8d9bc95cb2e830f1313d2 i386/openswan-doc-2.4.4-1.0.FC4.1.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2005-1092
2005-11-21
---------------------------------------------------------------------
Product : Fedora Core 3
Name : openswan
Version : 2.4.4
Release : 0.FC3.1
Summary : Openswan IPSEC implementation
Description :
Openswan is a free implementation of IPSEC & IKE for Linux. IPSEC is
the Internet Protocol Security and uses strong cryptography to provide
both authentication and encryption services. These services allow you
to build secure tunnels through untrusted networks. Everything passing
through the untrusted net is encrypted by the ipsec gateway machine and
decrypted by the gateway at the other end of the tunnel. The resulting
tunnel is a virtual private network or VPN.
This package contains the daemons and userland tools for setting up
Openswan on a freeswan enabled kernel.
---------------------------------------------------------------------
Update Information:
NISCC has reported two Denial of Service issues in Openswan.
The first involves a specially crafted 3DES packet with an
invalid key length.
The Openswan project has relased version 2.4.4 to fix both
issues.
See http://www.openswan.org/ for details.
---------------------------------------------------------------------
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
79f000a19d216fc95f1bd0f24bd1bf41 SRPMS/openswan-2.4.4-0.FC3.1.src.rpm
6fe24a0ab188b4b0e45d610bfda9b554 x86_64/openswan-2.4.4-0.FC3.1.x86_64.rpm
c1c42f6af380064673bfa648c37349ee x86_64/openswan-doc-2.4.4-0.FC3.1.x86_64.rpm
1dc85100f037b3b18db1a6f0069cad1e i386/openswan-2.4.4-0.FC3.1.i386.rpm
93e5a2376e1373ee40b8ad7960f89dc2 i386/openswan-doc-2.4.4-0.FC3.1.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
Welcome to our issue number 23 of Fedora Weekly News.
http://fedoranews.org/wiki/Fedora_Weekly_News_Issue_23
In this issue, we have following articles:
1 Boston FUDCon 2006
2 New Features Coming in moin 1.5
3 Fedora netdev Kernels
4 First Fedora Ambassadors Meeting
5 Fedora Logo on distrowatch.com
6 New Favicon on fedoraproject.org
7 How to build rpm for kmenu-gnome
8 Building a Simple Calendar Server with Fedora
9 Set up the VNC Server in Fedora
10 Flash Player 7.0.61 Released
11 Firefox 1.5 RC 3 Released
12 Fedora Core 4 Updates
13 Contributing to Fedora Weekly News
14 Editor's Blog
The latest issue can always be found at
http://fedoranews.org/wiki/Fedora_Weekly_News_Latest_Issue
We need more volunteer writers who watch the Fedora community and report
about what is going on. To find out how you can contribute, please visit
http://fedoranews.org/wiki/Contributing_to_Fedora_Weekly_News
See you in next issue of FWN!
--
Thomas Chung
FedoraNEWS.ORG (http://fedoranews.org)
"..where you can free your knowledge for your free community!"
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2005-1077
2005-11-18
---------------------------------------------------------------------
Product : Fedora Core 4
Name : perl
Version : 5.8.6
Release : 16.fc4
Summary : The Perl programming language.
Description :
Perl is a high-level programming language with roots in C, sed, awk
and shell scripting. Perl is good at handling processes and files,
and is especially good at handling text. Perl's hallmarks are
practicality and efficiency. While it is used to do a lot of
different things, Perl's most common applications are system
administration utilities and web programming. A large proportion of
the CGI scripts on the web are written in Perl. You need the perl
package installed on your system so that your system can handle Perl
scripts.
Install this package if you want to program in Perl or enable your
system to handle Perl scripts.
---------------------------------------------------------------------
* Fri Nov 11 2005 Jason Vas Dias <jvdias(a)redhat.com> - 3.5.8.6-16
- fix bug 172587: 'map { print(reverse) } ("")x68' core dump
* Tue Nov 8 2005 Jason Vas Dias <jvdias(a)redhat.com> - 3:5.8.6-16
- fix bug 172739 / upstream bug 36521 - patch 25160
- fix CAN-2004-0976: insecure use of temporary files
* Wed Nov 2 2005 Jason Vas Dias <jvdias(a)redhat.com> - 3:5.8.6-16
- fix bug 171111 / upstream bug 37535: incorrect IOCPARM_LEN
- fix bug 172236 / upstream bug 37582: h2ph not generating C standard headers
- fix bug 172256 / upstream bug 34498: h2ph can't handle #defines in enums
- fix bug 172316: Encode v2.8 panic on invalid UTF-8 input
- fix bug 172336 / upstream bug 37056: backport upstream patch 25084:
prevent realloc recursion on ERANGE errors from nss get* functions
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
d70f372c3402e43304986cf2fdfce7a4 SRPMS/perl-5.8.6-16.fc4.src.rpm
3a63fd96d5378c89138aa848288d8349 ppc/perl-5.8.6-16.fc4.ppc.rpm
0777d7d1f4bd86ec8d46b16e04ea9323 ppc/perl-suidperl-5.8.6-16.fc4.ppc.rpm
968ef29bfd452c37a79761688e8efcc5 ppc/debug/perl-debuginfo-5.8.6-16.fc4.ppc.rpm
1080a28378989dcad02ca51d7f7cdb47 x86_64/perl-5.8.6-16.fc4.x86_64.rpm
2ab3a1b832e06b4ec2aca62ca9d10b61 x86_64/perl-suidperl-5.8.6-16.fc4.x86_64.rpm
52bce66512403007e0a1ee600edc17f7 x86_64/debug/perl-debuginfo-5.8.6-16.fc4.x86_64.rpm
099f53b5e8d58f0c7c18c6eb9fb495f0 i386/perl-5.8.6-16.fc4.i386.rpm
9c45ccf574ddd0bc3367b0b0bf311722 i386/perl-suidperl-5.8.6-16.fc4.i386.rpm
33403773ac61e444a1cb2c977f8a0f9f i386/debug/perl-debuginfo-5.8.6-16.fc4.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2005-1091
2005-11-16
---------------------------------------------------------------------
Product : Fedora Core 3
Name : mc
Version : 4.6.1a
Release : 2.FC3
Summary : User-friendly text console file manager and visual shell.
Description :
Midnight Commander is a visual shell much like a file manager, only
with many more features. It is a text mode application, but it also
includes mouse support. Midnight Commander's best features are its
ability to FTP, view tar and zip files, and to poke into RPMs for
specific files.
---------------------------------------------------------------------
* Wed Nov 16 2005 Jindrich Novy <jnovy(a)redhat.com> 4.6.1a-2.FC3
- update from upstream CVS for the new slang support
- use internal slang-2.0.5 in mc for now
- temporarily drop slang-devel dependency
- don't use gpm to avoid hangs caused by it (#168076, #172921),
console mouse support works even without gpm
- display scrollbars correctly even if UTF-8 locale isn't set (#173014)
- add slang2 support to utf8 patch (Leonard den Ottolander)
- don't try to display UTF8ized characters in hex viewing mode
and display the characters correctly (#173309)
- update %description
* Thu Nov 10 2005 Jindrich Novy <jnovy(a)redhat.com> 4.6.1a-1.FC3
- update to the 4.6.1a branch
- sync utf8, promptfix, 64bit patches
- drop upstreamed gcc4, ftpcrash, find, symcrash, cstrans, searchfix patches
- update userhost patch to let the edited/viewed file name be displayed in
xterm title
- don't display UTF-8 characters as questionmarks in xterm title (#170971)
- add vertical scrollbars to main panels and listboxes
- fix memleak in menu.c caused by UTF-8 patch
- display UTF-8 characters corectly in mcview (#172571)
- fix extensions patch
- convert spec to UTF-8
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
84ec941fcfa034cff6bd3415843ab578 SRPMS/mc-4.6.1a-2.FC3.src.rpm
a8f5ef69d15ea64c070a2ceff15c90ac x86_64/mc-4.6.1a-2.FC3.x86_64.rpm
2d7d1ccb389a3a7d5fe6684b5b3713b2 x86_64/debug/mc-debuginfo-4.6.1a-2.FC3.x86_64.rpm
4845cc609454c0af81ccc9e0e75f1551 i386/mc-4.6.1a-2.FC3.i386.rpm
ff5896d213e8eeaf365242b605236bf8 i386/debug/mc-debuginfo-4.6.1a-2.FC3.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2005-1090
2005-11-16
---------------------------------------------------------------------
Product : Fedora Core 4
Name : mc
Version : 4.6.1a
Release : 0.15.FC4
Summary : User-friendly text console file manager and visual shell.
Description :
Midnight Commander is a visual shell much like a file manager, only
with many more features. It is a text mode application, but it also
includes mouse support. Midnight Commander's best features are its
ability to FTP, view tar and zip files, and to poke into RPMs for
specific files.
---------------------------------------------------------------------
* Wed Nov 16 2005 Jindrich Novy <jnovy(a)redhat.com> 4.6.1a-0.15.FC4
- update from upstream CVS for the new slang support
- use internal slang-2.0.5 in mc for now
- temporarily drop slang-devel dependency
- don't use gpm to avoid hangs caused by it (#168076, #172921),
console mouse support works even without gpm
- display scrollbars correctly even if UTF-8 locale isn't set (#173014)
- add slang2 support to utf8 patch (Leonard den Ottolander)
- don't try to display UTF8ized characters in hex viewing mode
and display the characters correctly (#173309)
- update %description
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
c929f22cf4618821b34a9733b8f68b56 SRPMS/mc-4.6.1a-0.15.FC4.src.rpm
ca5bb814dff537780e34ab5d11f74fae ppc/mc-4.6.1a-0.15.FC4.ppc.rpm
69d0fb6e0074dd90174770fb55ed2053 ppc/debug/mc-debuginfo-4.6.1a-0.15.FC4.ppc.rpm
7742d96e98441060ba6d7514de1787a9 x86_64/mc-4.6.1a-0.15.FC4.x86_64.rpm
42969f7033cea97f679a79baaba53618 x86_64/debug/mc-debuginfo-4.6.1a-0.15.FC4.x86_64.rpm
dda3c9c4196e2ec61846806907e7a51e i386/mc-4.6.1a-0.15.FC4.i386.rpm
ed246ed50687af62530c03c5d401483d i386/debug/mc-debuginfo-4.6.1a-0.15.FC4.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2005-1089
2005-11-16
---------------------------------------------------------------------
Product : Fedora Core 4
Name : shadow-utils
Version : 4.0.12
Release : 6.FC4
Summary : Utilities for managing accounts and shadow password files.
Description :
The shadow-utils package includes the necessary programs for
converting UNIX password files to the shadow password format, plus
programs for managing user and group accounts. The pwconv command
converts passwords to the shadow password format. The pwunconv command
unconverts shadow passwords and generates an npasswd file (a standard
UNIX password file). The pwck command checks the integrity of password
and shadow files. The lastlog command prints out the last login times
for all users. The useradd, userdel, and usermod commands are used for
managing user accounts. The groupadd, groupdel, and groupmod commands
are used for managing group accounts.
---------------------------------------------------------------------
* Wed Nov 16 2005 Peter Vrabec <pvrabec(a)redhat.com> 2:4.0.12-6.FC4
- fix useradd segfaults (#173241)
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
85c018d48653eec39e14589d6905e8e9 SRPMS/shadow-utils-4.0.12-6.FC4.src.rpm
de7466c844e6eb5bb4dad91c68f9ab87 ppc/shadow-utils-4.0.12-6.FC4.ppc.rpm
2a3275d69a09f9b1d69bbc8e0c0059d8 ppc/debug/shadow-utils-debuginfo-4.0.12-6.FC4.ppc.rpm
0731015dfb82e23bff314190356f1375 x86_64/shadow-utils-4.0.12-6.FC4.x86_64.rpm
9bfb7a13d3723781b10988eb43b4ab2c x86_64/debug/shadow-utils-debuginfo-4.0.12-6.FC4.x86_64.rpm
4030241bc59ecb52058fadb296eb17e8 i386/shadow-utils-4.0.12-6.FC4.i386.rpm
4bf302b67d602df3da2afb786b9285c6 i386/debug/shadow-utils-debuginfo-4.0.12-6.FC4.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2005-1088
2005-11-15
---------------------------------------------------------------------
Product : Fedora Core 4
Name : gtk2
Version : 2.6.10
Release : 2.fc4.4
Summary : The GIMP ToolKit (GTK+), a library for creating GUIs for X.
Description :
GTK+ is a multi-platform toolkit for creating graphical user
interfaces. Offering a complete set of widgets, GTK+ is suitable for
projects ranging from small one-off tools to complete application
suites.
---------------------------------------------------------------------
Update Information:
The gtk2 package contains the GIMP ToolKit (GTK+), a library
for creating graphical user interfaces for the X Window System.
A bug was found in the way gtk2 processes XPM images. An
attacker could create a carefully crafted XPM file in such a
way that it could cause an application linked with gtk2 to
execute arbitrary code when the file was opened by a victim.
The Common Vulnerabilities and Exposures project has
assigned the name CVE-2005-3186 to this issue.
Ludwig Nussel discovered an infinite-loop denial of service
bug in the way gtk2 processes XPM images. An attacker could
create a carefully crafted XPM file in such a way that it
could cause an application linked with gtk2 to stop
responding when the file was opened by a victim. The Common
Vulnerabilities and Exposures project has assigned the name
CVE-2005-2975 to this issue.
Users of gtk2 are advised to upgrade to these updated
packages, which contain backported patches and are not
vulnerable to these issues.
---------------------------------------------------------------------
* Mon Oct 31 2005 Matthias Clasen <mclasen(a)redhat.com> - 2.6.10-2.fc4.4
- Prevent an infinite loop in the xpm loader (#171905, CVE-2005-2975)
* Wed Oct 19 2005 Matthias Clasen <mclasen(a)redhat.com> - 2.6.10-2.fc4.2
- Prevent an integer overflow in the xpm loader (#171075, CAN-2005-3186)
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
8b6c8d169a2077aec57fb1551e6b032d SRPMS/gtk2-2.6.10-2.fc4.4.src.rpm
5a1ab1b673c5a2efbdd75e23ad206945 ppc/gtk2-2.6.10-2.fc4.4.ppc.rpm
7880fe183673db71572a166571e5a91d ppc/gtk2-devel-2.6.10-2.fc4.4.ppc.rpm
52958efbd0796646ad0c1ca43a086009 ppc/debug/gtk2-debuginfo-2.6.10-2.fc4.4.ppc.rpm
ef8f41011dc23c3c1432ac81b6965632 ppc/gtk2-2.6.10-2.fc4.4.ppc64.rpm
b1e55459ebf53ad98c7c991c4a771539 x86_64/gtk2-2.6.10-2.fc4.4.x86_64.rpm
eb387f58aabad431bc6ac4e9c377c81f x86_64/gtk2-devel-2.6.10-2.fc4.4.x86_64.rpm
ed1e986aaca3a7d6fe01efaa5227de1e x86_64/debug/gtk2-debuginfo-2.6.10-2.fc4.4.x86_64.rpm
06c4edc69cd8cefc88e0745c9cbad651 x86_64/gtk2-2.6.10-2.fc4.4.i386.rpm
06c4edc69cd8cefc88e0745c9cbad651 i386/gtk2-2.6.10-2.fc4.4.i386.rpm
e9f0a994835b3666c1b85f38121e3251 i386/gtk2-devel-2.6.10-2.fc4.4.i386.rpm
d5ab5b36abd4882a3f0d6081179959d3 i386/debug/gtk2-debuginfo-2.6.10-2.fc4.4.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------