---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-077
2004-02-26
---------------------------------------------------------------------
Name : xchat
Version : 2.0.7
Release : 1.FC1.0
Summary : A popular and easy to use graphical IRC (chat) client
Description :
X-Chat is an easy to use graphical IRC chat client for the X Window
System.
---------------------------------------------------------------------
Update Information:
New xchat 2.0.7 packages are available for Fedora Core 1 as an
enhancement update. Additionally, the x86_64 packages fix
64 bit related bugs which affect the AMD64 platform, and possibly
other 64 bit variants.
---------------------------------------------------------------------
* Tue Feb 17 2004 Mike A. Harris <mharris(a)redhat.com> 1:2.0.7-1.FC1.0
- Rebuild xchat 2.0.7-3 as 2.0.7-1.FC1.0 for release as an enhancement erratum
for Fedora Core 1. Also fixes AMD64 64bit issues reported in bug (#114237)
* Fri Feb 13 2004 Elliot Lee <sopwith(a)redhat.com> 1:2.0.7-3
- rebuilt
* Mon Jan 26 2004 Jeremy Katz <katzj(a)redhat.com> 1:2.0.7-2
- rebuild for new perl version
* Sat Jan 10 2004 Mike A. Harris <mharris(a)redhat.com> 1:2.0.7-1
- Updated to xchat 2.0.7
- Removed already integrated patches, including: xc204-fixperlui.diff,
xchat-2.0.4-screen-position-fix.patch, xchat-2.0.4-exec-shield-GNU-stack.patch
- Added a new rpm macro require_autoconf, which is disabled (0) by default, as
it seems no longer necessary to run autoconf prior to ./configure, so we no
longer need to BuildRequire autoconf 2.54 either.
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
c43863517cc4c67dc3fa78ae1c502e1d SRPMS/xchat-2.0.7-1.FC1.0.src.rpm
f0308ff2083331b70f7c775ddb84d4f4 i386/xchat-2.0.7-1.FC1.0.i386.rpm
0784e8115da0763fdb2210e132ebe27f i386/debug/xchat-debuginfo-2.0.7-1.FC1.0.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-087
2004-02-25
---------------------------------------------------------------------
Name : libxml2
Version : 2.6.6
Release : 3
Summary : Library providing XML and HTML support
Description :
This library allows to manipulate XML files. It includes support
to read, modify and write XML and HTML files. There is DTDs support
this includes parsing and validation even with complex DtDs, either
at parse time or later once the document has been modified. The output
can be a simple SAX stream or and in-memory DOM like representations.
In this case one can use the built-in XPath and XPointer implementation
to select subnodes or ranges. A flexible Input/Output mechanism is
available, with existing HTTP and FTP modules and combined to an
URI library.
---------------------------------------------------------------------
Update Information:
Updated libxml2 packages are available to fix an overflow when parsing
the URI for remote resources.
---------------------------------------------------------------------
* Thu Feb 12 2004 Daniel Veillard <veillard(a)redhat.com>
- upstream release 2.6.6 see http://xmlsoft.org/news.html
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
c46c9ba42ba7d27bfcf48899119a1d40 SRPMS/libxml2-2.6.6-3.src.rpm
d7a9dec974250e425d6052e0f648b6c5 i386/libxml2-2.6.6-3.i386.rpm
0758aa446c1a43d18bc016df35288806 i386/libxml2-devel-2.6.6-3.i386.rpm
07843af17c126497f4baa8d279c7d920 i386/libxml2-python-2.6.6-3.i386.rpm
ae7105805216615e6460c60be9c679da i386/debug/libxml2-debuginfo-2.6.6-3.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
Daniel
--
Daniel Veillard | Red Hat Network https://rhn.redhat.com/
veillard(a)redhat.com | libxml GNOME XML XSLT toolkit http://xmlsoft.org/http://veillard.com/ | Rpmfind RPM search engine http://rpmfind.net/
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-072
2004-02-23
---------------------------------------------------------------------
Name : spamassassin
Version : 2.63
Release : 0.2
Summary : Spam filter for email which can be invoked from mail
delivery agents.
Description :
SpamAssassin provides you with a way to reduce if not completely eliminate
Unsolicited Commercial Email (SPAM) from your incoming email. It can
be invoked by a MDA such as sendmail or postfix, or can be called from
a procmail script, .forward file, etc. It uses a genetic-algorithm
evolved scoring system to identify messages which look spammy, then
adds headers to the message so they can be filtered by the user's mail
reading software. This distribution includes the spamd/spamc components
which create a server that considerably speeds processing of mail.
To enable spamassassin, if you are receiving mail locally, simply add
this line to your ~/.procmailrc:
INCLUDERC=/etc/mail/spamassassin/spamassassin-default.rc
To filter spam for all users, add that line to /etc/procmailrc
(creating if necessary).
---------------------------------------------------------------------
Update Information:
This update from spamassassin-2.60 to 2.63 in FC1 should fix many
bugs and improve spam detection capability. See the release notes
at http://www.spamassassin.org for more information.
This release also enables spamc/spamd optional OpenSSL support.
---------------------------------------------------------------------
* Wed Feb 11 2004 Warren Togami <wtogami(a)redhat.com> 2.63-0.2
- rename for FC1
* Wed Feb 11 2004 Warren Togami <wtogami(a)redhat.com> 2.63-6
- require sitelib instead
* Wed Jan 21 2004 Warren Togami <wtogami(a)redhat.com> 2.63-3
- krb5-backcompat.patch so older krb5-devel does not fail
* Wed Jan 21 2004 Warren Togami <wtogami(a)redhat.com> 2.63-2
- upgrade to 2.63
* Mon Jan 19 2004 Warren Togami <wtogami(a)redhat.com> 2.62-3
- Ville Skyttä's fixes from #113596 including:
- Fix buildroot traces
- enable openssl
- Trailing slash to DESTDIR (bug 90202 comment 14).
- export optflags so they're honored, affects spamc only.
* Mon Jan 19 2004 Warren Togami <wtogami(a)redhat.com> 2.62-2
- upgrade to 2.62
- Prereq -> Requires, former is deprecated
- Require current version of perl
- Remove urban myth clean test
- TODO: Get rid of prefix
* Wed Dec 31 2003 Dan Walsh <dwalsh(a)redhat.com> 2.61-2
- Change sysconfdir to not use full path
* Tue Dec 09 2003 Chip Turner <cturner(a)redhat.com> 2.61-1
- upgrade to 2.61
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
c3e019d39524e4285c3676c1922eef1c SRPMS/spamassassin-2.63-0.2.src.rpm
8dacc52f924e5662adf11305cff01609 i386/spamassassin-2.63-0.2.i386.rpm
c38478ee0ac1b032e0a5a8cbdbcaecfe
i386/debug/spamassassin-debuginfo-2.63-0.2.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-073
2004-02-23
---------------------------------------------------------------------
Name : kernel-pcmcia-cs
Version : 3.1.31
Release : 16
Summary : The daemon for using PCMCIA adapters.
Description :
Many laptop machines (and some non-laptops) support PCMCIA cards for
expansion. Also known as "credit card adapters," PCMCIA cards are
small cards for everything from SCSI support to modems. PCMCIA cards
are hot swappable (i.e., they can be exchanged without rebooting the
system) and quite convenient to use. The kernel-pcmcia-cs package
contains a set of loadable kernel modules that implement an
applications program interface, a set of client drivers for specific
cards and a card manager daemon that can respond to card insertion and
removal events by loading and unloading drivers on demand. The daemon
also supports hot swapping, so that the cards can be safely inserted
and ejected at any time.
---------------------------------------------------------------------
Update Information:
This update is mainly a rebuild for x86_64 support Other changes include a
change to the initscript to load modules without the .o suffix.
---------------------------------------------------------------------
* Wed Feb 11 2004 Bill Nottingham <notting(a)redhat.com> 3.1.31-16
- build for x86_64 (#115104)
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
e14f725cadb1bfb910480432d806ba3d SRPMS/kernel-pcmcia-cs-3.1.31-16.src.rpm
2fa4602be997f5588e4fca67b6c34155 i386/kernel-pcmcia-cs-3.1.31-16.i386.rpm
26c01c3b05c5ec670e5bdfb5aaf595bf i386/debug/kernel-pcmcia-cs-debuginfo-3.1.31-16.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-082
2004-02-23
---------------------------------------------------------------------
Name : hwdata
Version : 0.103.1
Release : 1
Summary : Hardware identification and configuration data
Description :
hwdata contains various hardware identification and configuration data,
such as the pci.ids database, the XFree86 Cards and MonitorsDb databases.
---------------------------------------------------------------------
Update Information:
This update updates the MonitorsDB monitor listing and the pci.ids file
of PCI device descriptions, and updates a couple of pcitable entries for
cards that don't have modules.pcimap entries, such as the 3com 3c940.
---------------------------------------------------------------------
* Mon Feb 23 2004 Bill Nottingham <notting(a)redhat.com> 0.103.1-1
- update 3c940 mapping
* Mon Jan 19 2004 Brent Fox <bfox(a)redhat.com> 0.103-1
- fix tab spacing
* Fri Jan 16 2004 Brent Fox <bfox(a)redhat.com> 0.102-1
- added an entry for ATI Radeon 9200SE (bug #111306)
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
f0e415b4e1729d7c599f0f9df53d0e9a SRPMS/hwdata-0.103.1-1.src.rpm
067aa285df0eb333873a9b7316ab5e10 i386/hwdata-0.103.1-1.noarch.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Security Update Notification
FEDORA-2004-080
2004-02-18
---------------------------------------------------------------------
Name : kernel
Version : 2.4.22
Release : 1.2174.nptl
Summary : The Linux kernel (the core of the Linux operating system)
Description :
The kernel package contains the Linux kernel (vmlinuz), the core of your
Fedora Core Linux operating system. The kernel handles the basic functions
of the operating system: memory allocation, process allocation, device
input and output, etc.
The previous security errata (2.4.22-1.2173) unfortunatly contained a bug
which made some systems unbootable, due to breakage in the aacraid scsi
driver. This update contains no further changes vs 2173.
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
0e7e280c49392ab8c969a14a1bc53019 SRPMS/kernel-2.4.22-1.2174.nptl.src.rpm
4f743a2f8bd11a71456ffe7ea63e73fe i386/kernel-source-2.4.22-1.2174.nptl.i386.rpm
06263a61c6dd484cd660c302e6f0661c i386/kernel-doc-2.4.22-1.2174.nptl.i386.rpm
1a28c697f78a861e9a0a1316ad3a7380 i386/kernel-BOOT-2.4.22-1.2174.nptl.i386.rpm
985607d76a121d278d89b393b6e8b2be i386/debug/kernel-debuginfo-2.4.22-1.2174.nptl.i386.rpm
5f8f02bcb9707d5c7a7478a2873a990c i386/kernel-2.4.22-1.2174.nptl.i586.rpm
6fdf2932cd587ab5f08b213b3b99c9e0 i386/debug/kernel-debuginfo-2.4.22-1.2174.nptl.i586.rpm
1ced9ea530a02046be2df687e3f11949 i386/kernel-2.4.22-1.2174.nptl.i686.rpm
55462d3b48efee106a11ecc22e36b0b7 i386/kernel-smp-2.4.22-1.2174.nptl.i686.rpm
b2b51f50ae8a02f8c58d6f723685111a i386/debug/kernel-debuginfo-2.4.22-1.2174.nptl.i686.rpm
17b30206c55ed2ea3040b37758d6062a i386/kernel-2.4.22-1.2174.nptl.athlon.rpm
ad10047a5765aab12955c2332c4012ac i386/kernel-smp-2.4.22-1.2174.nptl.athlon.rpm
4f435ef1c7c27f6e66a04895eb721baa i386/debug/kernel-debuginfo-2.4.22-1.2174.nptl.athlon.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
Another issue of the Fedora News Updates has been released and is
available at:
http://fedoranews.org/colin/fnu/issue6.shtml
The current issue is always linked to
http://fedoranews.org/colin/fnu/current.shtml
In this issue we cover the launching of Fedora Core 2 test1, a new
online-based forum, as well as tips on dealing with FC2 test1. Rolling
your own Fedora-based ISOs, why Linux uses all its available resources,
and lots of software pointers in this issue.
--
Colin Charles, byte(a)aeon.com.my
http://www.bytebot.net/http://fedoranews.org/colin/fnu/ - Fedora News Updates
---------------------------------------------------------------------
Fedora Security Update Notification
FEDORA-2004-079
2004-02-18
---------------------------------------------------------------------
Name : kernel
Version : 2.4.22
Release : 1.2173.nptl
Summary : The Linux kernel (the core of the Linux operating system)
Description :
The kernel package contains the Linux kernel (vmlinuz), the core of your
Fedora Core Linux operating system. The kernel handles the basic functions
of the operating system: memory allocation, process allocation, device
input and output, etc.
Paul Starzetz discovered a flaw in return value checking in mremap() in the
Linux kernel versions 2.4.24 and previous that may allow a local attacker
to gain root privileges. No exploit is currently available; however this
issue is exploitable. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0077 to this issue.
Arjan van de Ven discovered a flaw in ncp_lookup() in ncpfs that could
allow local privilege escalation. ncpfs is only used to allow a system to
mount volumes of NetWare servers or print to NetWare printers. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0010 to this issue.
All users are advised to upgrade to these errata packages, which contain
backported security patches that correct these issues.
Red Hat would like to thank Paul Starzetz from ISEC for reporting the issue
CAN-2004-0077.
---------------------------------------------------------------------
* Wed Feb 18 2004 Dave Jones <davej(a)redhat.com>
- Fix security problem in gamma DRI driver.
* Tue Feb 17 2004 Dave Jones <davej(a)redhat.com>
- Fix leak in SSTFB driver.
* Sat Feb 14 2004 Dave Jones <davej(a)redhat.com>
- aacraid fix for #92129
* Fri Feb 13 2004 Dave Jones <davej(a)redhat.com>
- Fix building of vt8231.o
* Thu Feb 05 2004 Dave Jones <davej(a)redhat.com>
- Check do_mremap return values (CAN-2004-0077)
* Mon Feb 02 2004 Dave Jones <davej(a)redhat.com>
- Disable stack overflow checking.
- More bits from 2.4.25pre
- Fix ipt_conntrack/ipt_state module refcounting.
- Zero last byte of mount option page
- AMD64 update
- Fix deep stack usage in ncpfs (CAN-2004-0010)
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
be83c63da2ef761aeb7e8696879be360 SRPMS/kernel-2.4.22-1.2173.nptl.src.rpm
78db0934086e959ad1bff965bcc2a188 i386/kernel-source-2.4.22-1.2173.nptl.i386.rpm
64a824908fb9851768f2bdd0911b5f65 i386/kernel-doc-2.4.22-1.2173.nptl.i386.rpm
f8136a330f1bdad42b5c08c5cfaa7464 i386/kernel-BOOT-2.4.22-1.2173.nptl.i386.rpm
50991b3c9e6a7ab6b16d884e032ad391 i386/debug/kernel-debuginfo-2.4.22-1.2173.nptl.i386.rpm
731de10afe170d5ebd33c199690c947c i386/kernel-2.4.22-1.2173.nptl.i586.rpm
7a676c2c3c5b899f9de46245e553dded i386/debug/kernel-debuginfo-2.4.22-1.2173.nptl.i586.rpm
c3571e87235b5717205f752a2981e044 i386/kernel-2.4.22-1.2173.nptl.i686.rpm
cebf23c3578adc7bfce4c39902111fd0 i386/kernel-smp-2.4.22-1.2173.nptl.i686.rpm
1eb059360ae74ba8116baa67835bce90 i386/debug/kernel-debuginfo-2.4.22-1.2173.nptl.i686.rpm
c41be8c7cde8cbfab3630a03d4251bb2 i386/kernel-2.4.22-1.2173.nptl.athlon.rpm
958c124d969d6804bd81011924d063e2 i386/kernel-smp-2.4.22-1.2173.nptl.athlon.rpm
cc3b30df501a44e64c1405b6928c04f7 i386/debug/kernel-debuginfo-2.4.22-1.2173.nptl.athlon.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
Updated Samba packages that fix a potential unathorized access problem
are now avaliable.
Under some circumstances, Samba 3.0.0 and 3.0.1 could overwrite the
password field of a disabled account with uninitialized memory. If an
attacker could know what will be in that memory, he could gain access
to the disabled acocunt.
If you use Samba, you should consider upgrading to these new packages.
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-074
2004-02-16
---------------------------------------------------------------------
Name : samba
Version : 3.0.2
Release : 7.FC1
Summary : The Samba SMB server.
Description :
Samba is the protocol by which a lot of PC-related machines share
files, printers, and other information (such as lists of available
files and printers). The Windows NT, OS/2, and Linux operating systems
support this natively, and add-on packages can enable the same thing
for DOS, Windows, VMS, UNIX of all kinds, MVS, and more. This package
provides an SMB server that can be used to provide network services to
SMB (sometimes called "Lan Manager") clients. Samba uses NetBIOS over
TCP/IP (NetBT) protocols and does NOT need the NetBEUI (Microsoft Raw
NetBIOS frame) protocol.
---------------------------------------------------------------------
Update Information:
---------------------------------------------------------------------
* Thu Feb 12 2004 Jay Fenlason <fenlason(a)redhat.com> 3.0.2-7.FC1
- Fix the ownership on /usr/lib/samba and /usr/lib/samba/charset
* Mon Feb 09 2004 Jay Fenlason <fenlason(a)redhat.com> 3.0.2-5.FC1
- Merge from HEAD to build 3.0.2 for Fedora Core 1 erratum.
- New upstream version: 3.0.2 final includes security fix for #114995
(CAN-2004-0082)
- Edit postun script for the -common package to restart winbind when
appropriate. Fixes bugzilla #114051.
* Mon Feb 02 2004 Jay Fenlason <fenlason(a)redhat.com> 3.0.2-3rc2
- add %dir entries for /usr/lib/samba and /usr/lib/samba/charset
- Upgrade to new upstream version
- build mount.cifs for the new cifs filesystem in the 2.6 kernel.
* Mon Jan 19 2004 Jay Fenlason <fenlason(a)redhat.com> 3.0.2-1rc1
- Upgrade to new upstream version
* Wed Dec 17 2003 Felipe Alfaro Solana <felipe_alfaro(a)linuxmail.org> 3.0.1-1
- Update to 3.0.1
- Removed testparm patch as it's already merged
- Removed Samba.7* man pages
- Fixed .buildroot patch
- Fixed .pie patch
- Added new /usr/bin/tdbdump file
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
2ee8ced2420caee182cc7e7bd24bc578 SRPMS/samba-3.0.2-7.FC1.src.rpm
f07e98858197c4c0f8d87823f07d2e18 i386/samba-3.0.2-7.FC1.i386.rpm
5db069ff37ce550bf10bd555d52df2da i386/samba-client-3.0.2-7.FC1.i386.rpm
fa703cf8f43b965faebdb3ecdd7e438e i386/samba-common-3.0.2-7.FC1.i386.rpm
5823c93c369ca7e6083b386bb48bf81a i386/debug/samba-debuginfo-3.0.2-7.FC1.i386.rpm
e4ceab8f113b7fcbd460271ab72dea95 i386/samba-swat-3.0.2-7.FC1.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-076
2004-02-16
---------------------------------------------------------------------
Name : freeradius
Version : 0.9.3
Release : 1.1
Summary : High-performance and highly configurable free RADIUS server.
Description :
The FreeRADIUS Server Project is a high performance and highly configurable
GPL'd free RADIUS server. The server is similar in some respects to
Livingston's 2.0 server. While FreeRADIUS started as a variant of the
Cistron RADIUS server, they don't share a lot in common any more. It now has
many more features than Cistron or Livingston, and is much more configurable.
FreeRADIUS is an Internet authentication daemon, which implements the RADIUS
protocol, as defined in RFC 2865 (and others). It allows Network Access
Servers (NAS boxes) to perform authentication for dial-up users. There are
also RADIUS clients available for Web servers, firewalls, Unix logins, and
more. Using RADIUS allows authentication and authorization for a network to
be centralized, and minimizes the amount of re-configuration which has to be
done when adding or deleting new users.
---------------------------------------------------------------------
This version corrects a flaw in 0.9.2 (and all earlier versions of the
server) which may allow an attacker to DoS the server.
The bug does not look to be easily exploitable, as it overwrites the heap
(not the stack), and any exploit code must be in the form of a valid RADIUS
packet.
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
45682e5adaf0d649c3f4c30a4b7cb1af SRPMS/freeradius-0.9.3-1.1.src.rpm
9642e1db1cf8955d4fc24040b73f3506 i386/freeradius-0.9.3-1.1.i386.rpm
55d0a73f2a1da031d8b3ad0775fb2512 i386/debug/freeradius-debuginfo-0.9.3-1.1.i386.rpm
421c75806a8e7e296c95ac831bccbb9d i386/freeradius-mysql-0.9.3-1.1.i386.rpm
4c5f4346bbb56bb2c09fe31183c0af6a i386/freeradius-postgresql-0.9.3-1.1.i386.rpm
7eed2b5cd2bbea4ec1064be038584caf i386/freeradius-unixODBC-0.9.3-1.1.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------