---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-277
2004-08-31
---------------------------------------------------------------------
Product : Fedora Core 2
Name : krb5
Version : 1.3.4
Release : 6
Summary : The Kerberos network authentication system.
Description :
Kerberos V5 is a trusted-third-party network authentication system,
which can improve your network's security by eliminating the insecure
practice of cleartext passwords.
---------------------------------------------------------------------
Update Information:
Kerberos is a networked authentication system which uses a trusted
third party (a KDC) to authenticate clients and servers to each
other.
Several double-free bugs were found in the Kerberos 5 KDC and
libraries. A remote attacker could potentially exploit these flaws to
execute arbitrary code. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the names CAN-2004-0642 and
CAN-2004-0643 to these issues.
A double-free bug was also found in the krb524 server
(CAN-2004-0772), however this issue does not affect Fedora Core.
An infinite loop bug was found in the Kerberos 5 ASN.1 decoder
library. A remote attacker may be able to trigger this flaw and cause
a denial of service. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0644 to this issue.
---------------------------------------------------------------------
* Tue Aug 24 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.4-6
- rebuild
* Tue Aug 24 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.4-5
- incorporate revised fixes from Tom Yu for CAN-2004-0642, CAN-2004-0644,
CAN-2004-0772
* Mon Aug 23 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.4-4
- rebuild
* Mon Aug 23 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.4-3
- incorporate fixes from Tom Yu for CAN-2004-0642, CAN-2004-0772
(MITKRB5-SA-2004-002, #130732)
- incorporate fixes from Tom Yu for CAN-2004-0644 (MITKRB5-SA-2004-003, #130732)
* Tue Jul 27 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.4-2
- fix indexing error in server sorting patch (#127336)
* Tue Jun 15 2004 Elliot Lee <sopwith(a)redhat.com>
- rebuilt
* Mon Jun 14 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.4-0.1
- update to 1.3.4 final
* Mon Jun 07 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.4-0
- update to 1.3.4 beta1
- remove MITKRB5-SA-2004-001, included in 1.3.4
* Mon Jun 07 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.3-8
- rebuild
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
2b26718a3e533f32a1e98b401a2e21d4 SRPMS/krb5-1.3.4-6.src.rpm
beebe2125e840d9cb4546465b9833d66 x86_64/krb5-devel-1.3.4-6.x86_64.rpm
e00056df9058bed4b00684d2a64ffbe6 x86_64/krb5-libs-1.3.4-6.x86_64.rpm
abe8cf2e80236fb5a6adfa62c6e13240 x86_64/krb5-server-1.3.4-6.x86_64.rpm
11fdd50862bc0379fbfb3d804e59143b x86_64/krb5-workstation-1.3.4-6.x86_64.rpm
a6abcfdeb10910b7b814391c720d2ae7 x86_64/debug/krb5-debuginfo-1.3.4-6.x86_64.rpm
1d720b00203ce00d4c75e3926ee618e4 x86_64/krb5-libs-1.3.4-6.i386.rpm
16d556d502f9d34729bcb166ec209ea8 i386/krb5-devel-1.3.4-6.i386.rpm
1d720b00203ce00d4c75e3926ee618e4 i386/krb5-libs-1.3.4-6.i386.rpm
4534128db2230d8e8f0b76a591e7f7a6 i386/krb5-server-1.3.4-6.i386.rpm
c8f55dbadff7333fdb49b8f39173135b i386/krb5-workstation-1.3.4-6.i386.rpm
0092eed09687bf677aa0ed0c3980ec98 i386/debug/krb5-debuginfo-1.3.4-6.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-276
2004-08-31
---------------------------------------------------------------------
Product : Fedora Core 1
Name : krb5
Version : 1.3.4
Release : 5
Summary : The Kerberos network authentication system.
Description :
Kerberos V5 is a trusted-third-party network authentication system,
which can improve your network's security by eliminating the insecure
practice of cleartext passwords.
---------------------------------------------------------------------
Update Information:
Kerberos is a networked authentication system which uses a trusted
third party (a KDC) to authenticate clients and servers to each
other.
Several double-free bugs were found in the Kerberos 5 KDC and
libraries. A remote attacker could potentially exploit these flaws to
execute arbitrary code. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the names CAN-2004-0642 and
CAN-2004-0643 to these issues.
A double-free bug was also found in the krb524 server
(CAN-2004-0772), however this issue does not affect Fedora Core.
An infinite loop bug was found in the Kerberos 5 ASN.1 decoder
library. A remote attacker may be able to trigger this flaw and cause
a denial of service. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0644 to this issue.
---------------------------------------------------------------------
* Tue Aug 24 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.4-5
- incorporate revised fixes from Tom Yu for CAN-2004-0642, CAN-2004-0644,
CAN-2004-0772
* Mon Aug 23 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.4-4
- rebuild
* Mon Aug 23 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.4-3
- incorporate fixes from Tom Yu for CAN-2004-0642, CAN-2004-0772
(MITKRB5-SA-2004-002, #130732)
- incorporate fixes from Tom Yu for CAN-2004-0644 (MITKRB5-SA-2004-003, #130732)
* Tue Jul 27 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.4-2
- fix indexing error in server sorting patch (#127336)
* Tue Jun 15 2004 Elliot Lee <sopwith(a)redhat.com>
- rebuilt
* Mon Jun 14 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.4-0.1
- update to 1.3.4 final
* Mon Jun 07 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.4-0
- update to 1.3.4 beta1
- remove MITKRB5-SA-2004-001, included in 1.3.4
* Mon Jun 07 2004 Nalin Dahyabhai <nalin(a)redhat.com> 1.3.3-8
- rebuild
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
215744598787e8555852a42346523ff0 SRPMS/krb5-1.3.4-5.src.rpm
0bdb0a2c01e7682ac61009e86eb79c92 x86_64/krb5-devel-1.3.4-5.x86_64.rpm
575fa819175d43d6835867acb616da45 x86_64/krb5-libs-1.3.4-5.x86_64.rpm
2417f376a3f96de6514432efd70ba550 x86_64/krb5-server-1.3.4-5.x86_64.rpm
f79c01f71dd81127946c5e951ee3fa70 x86_64/krb5-workstation-1.3.4-5.x86_64.rpm
43fd30f8236c8a05edc726d7a9a318c9 x86_64/debug/krb5-debuginfo-1.3.4-5.x86_64.rpm
90924e3b1aa64f7e0780613e49d97a77 x86_64/krb5-libs-1.3.4-5.i386.rpm
201f89557be28e3cbcf6c7e2d23187d0 i386/krb5-devel-1.3.4-5.i386.rpm
90924e3b1aa64f7e0780613e49d97a77 i386/krb5-libs-1.3.4-5.i386.rpm
0ea73ac3eeb55350d9ae5b2bcdf33059 i386/krb5-server-1.3.4-5.i386.rpm
69ecbbe96b6b900c0a8b5f5d76fffbab i386/krb5-workstation-1.3.4-5.i386.rpm
dfb27688cf0416cb9c051e9df0bbe5ab i386/debug/krb5-debuginfo-1.3.4-5.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-279
2004-08-26
---------------------------------------------------------------------
Product : Fedora Core 2
Name : gaim
Version : 0.82
Release : 0.FC2
Summary : A Gtk+ based multiprotocol instant messaging client
Description :
Gaim allows you to talk to anyone using a variety of messaging
protocols, including AIM (Oscar and TOC), ICQ, IRC, Yahoo!,
MSN Messenger, Jabber, Gadu-Gadu, Napster, and Zephyr. These
protocols are implemented using a modular, easy to use design.
To use a protocol, just add an account using the account editor.
Gaim supports many common features of other clients, as well as many
unique features, such as perl scripting and C plugins.
Gaim is NOT affiliated with or endorsed by America Online, Inc.,
Microsoft Corporation, or Yahoo! Inc. or other messaging service
providers.
---------------------------------------------------------------------
Update Information:
0.82 update contains many bug and security improvements.
---------------------------------------------------------------------
* Wed Aug 25 2004 Warren Togami <wtogami(a)redhat.com> 0.82-0.FC2
- FC2 update
* Wed Aug 25 2004 Warren Togami <wtogami(a)redhat.com> 0.82-1
- Update to 0.82 resolves several security issues and bugs
CAN-2004-0500, CAN-2004-0754, CAN-2004-0784, CAN-2004-0785
More details at http://gaim.sourceforge.net/security/
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
b541c49b833569299e0493ee217cfbdf SRPMS/gaim-0.82-0.FC2.src.rpm
195b5fd6dc6b57b5efa7a0cb48ee784a x86_64/gaim-0.82-0.FC2.x86_64.rpm
54b376b2755796b1e3e98445db402f7b
x86_64/debug/gaim-debuginfo-0.82-0.FC2.x86_64.rpm
424761cc496a309f0a11714bf49d15f3 i386/gaim-0.82-0.FC2.i386.rpm
8eea8d251a8aa321a46668f05f6df10a
i386/debug/gaim-debuginfo-0.82-0.FC2.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-278
2004-08-26
---------------------------------------------------------------------
Product : Fedora Core 1
Name : gaim
Version : 0.82
Release : 0.FC1
Summary : A Gtk+ based multiprotocol instant messaging client
Description :
Gaim allows you to talk to anyone using a variety of messaging
protocols, including AIM (Oscar and TOC), ICQ, IRC, Yahoo!,
MSN Messenger, Jabber, Gadu-Gadu, Napster, and Zephyr. These
protocols are implemented using a modular, easy to use design.
To use a protocol, just add an account using the account editor.
Gaim supports many common features of other clients, as well as many
unique features, such as perl scripting and C plugins.
Gaim is NOT affiliated with or endorsed by America Online, Inc.,
Microsoft Corporation, or Yahoo! Inc. or other messaging service
providers.
---------------------------------------------------------------------
Update Information:
0.82 update contains many bug and security improvements.
---------------------------------------------------------------------
* Wed Aug 25 2004 Warren Togami <wtogami(a)redhat.com> 0.82-0.FC1
- FC1 update
* Wed Aug 25 2004 Warren Togami <wtogami(a)redhat.com> 0.82-1
- Update to 0.82 resolves several security issues and bugs
CAN-2004-0500, CAN-2004-0754, CAN-2004-0784, CAN-2004-0785
More details at http://gaim.sourceforge.net/security/
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
174ca09c008c59371289bb66e4e2632b SRPMS/gaim-0.82-0.FC1.src.rpm
9226eca202c3f8e40ca8dc0765b6a3f9 x86_64/gaim-0.82-0.FC1.x86_64.rpm
e23da9cd2592709a6c392c50deca5124
x86_64/debug/gaim-debuginfo-0.82-0.FC1.x86_64.rpm
d1a69928d1cf56234af3d507c328f826 i386/gaim-0.82-0.FC1.i386.rpm
c3d68d0bd2913e436621bf5a59dbdc34
i386/debug/gaim-debuginfo-0.82-0.FC1.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
Subject: Fedora Core 2 Update: qt-3.3.3-0.1
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-271
2004-08-23
---------------------------------------------------------------------
Product : Fedora Core 2
Name : qt
Version : 3.3.3
Release : 0.1
Summary : The shared library for the Qt GUI toolkit.
Description :
Qt is a GUI software toolkit which simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications
for the X Window System.
Qt is written in C++ and is fully object-oriented.
This package contains the shared library needed to run qt
applications, as well as the README files for qt.
---------------------------------------------------------------------
Update Information:
During a security audit, Chris Evans discovered a heap overflow in the BMP
image decoder in Qt versions prior to 3.3.3. An attacker could create a
carefully crafted BMP file in such a way that it would cause an application
linked with Qt to crash or possibly execute arbitrary code when the file
was opened by a victim. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0691 to this issue.
Additionally, various flaws were discovered in the GIF, XPM, and JPEG
decoders in Qt versions prior to 3.3.3. An attacker could create carefully
crafted image files in such a way that it could cause an application linked
against Qt to crash when the file was opened by a victim. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0692 and CAN-2004-0693 to these issues.
Users of Qt should update to these updated packages which contain
backported patches and are not vulnerable to these issues.
---------------------------------------------------------------------
* Thu Aug 19 2004 Than Ngo <than(a)redhat.com> 1:3.3.3-0.1
- update to 3.3.3, fix image buffer overflows
* Thu Jul 29 2004 Than Ngo <than(a)redhat.com> 1:3.3.2-2.1
- fix overflow vulnerability, thanks to trolltech
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
d7d133c9fb84ec203b4a96451397777c SRPMS/qt-3.3.3-0.1.src.rpm
3069582d6fc4e3472a9b578b9031b613 x86_64/qt-3.3.3-0.1.x86_64.rpm
f827f011c8284069da86aa977399e16a x86_64/qt-devel-3.3.3-0.1.x86_64.rpm
a98f9ad7b50bd5757f4d70cfe4e6b43d x86_64/qt-ODBC-3.3.3-0.1.x86_64.rpm
8d9305bbd849ad85033830adf8ce69d8 x86_64/qt-MySQL-3.3.3-0.1.x86_64.rpm
17eee4ff21a9afeab3af2e711fa350df x86_64/qt-PostgreSQL-3.3.3-0.1.x86_64.rpm
c62a0d58db076e8aae868959410240fa x86_64/qt-designer-3.3.3-0.1.x86_64.rpm
db3d362f1ccdc2643b0dad1494d3dae2
x86_64/debug/qt-debuginfo-3.3.3-0.1.x86_64.rpm
64f43afd922842ea5847d2549e989ffa i386/qt-3.3.3-0.1.i386.rpm
88f2edc217d4d6ef27974756aac2d590 i386/qt-devel-3.3.3-0.1.i386.rpm
0688e0872934c4dc365f496953e9b5cc i386/qt-ODBC-3.3.3-0.1.i386.rpm
c0208bd84c45a11a2a90e738cd3f4232 i386/qt-MySQL-3.3.3-0.1.i386.rpm
7e6fa694913d8f03d88ba49dfbedf8e8 i386/qt-PostgreSQL-3.3.3-0.1.i386.rpm
67cfecbeb2b1528a1224daca29a4fd6c i386/qt-designer-3.3.3-0.1.i386.rpm
822a56de23158db0bfe1979ba064420a i386/debug/qt-debuginfo-3.3.3-0.1.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
Subject: Fedora Core 1 Update: qt-3.1.2-14.2
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-270
2004-08-23
---------------------------------------------------------------------
Product : Fedora Core 1
Name : qt
Version : 3.1.2
Release : 14.2
Summary : The shared library for the Qt GUI toolkit.
Description :
Qt is a GUI software toolkit which simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications
for the X Window System.
Qt is written in C++ and is fully object-oriented.
This package contains the shared library needed to run qt
applications, as well as the README files for qt.
---------------------------------------------------------------------
Update Information:
During a security audit, Chris Evans discovered a heap overflow in the BMP
image decoder in Qt versions prior to 3.3.3. An attacker could create a
carefully crafted BMP file in such a way that it would cause an application
linked with Qt to crash or possibly execute arbitrary code when the file
was opened by a victim. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0691 to this issue.
Additionally, various flaws were discovered in the GIF, XPM, and JPEG
decoders in Qt versions prior to 3.3.3. An attacker could create carefully
crafted image files in such a way that it could cause an application linked
against Qt to crash when the file was opened by a victim. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0692 and CAN-2004-0693 to these issues.
Users of Qt should update to these updated packages which contain
backported patches and are not vulnerable to these issues.
---------------------------------------------------------------------
* Thu Aug 19 2004 Than Ngo <than(a)redhat.com> 1:3.1.2-14.2
- fix image buffer overflows
* Thu Jul 29 2004 Than Ngo <than(a)redhat.com> 1:3.1.2-14.1
- fix overflow vulnerability, thanks to trolltech
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
c763ada78b47f3bc72a06e26b929c8c4 SRPMS/qt-3.1.2-14.2.src.rpm
f86739a73579c5b6b698a873b4446d22 x86_64/qt-3.1.2-14.2.x86_64.rpm
6110ba73b9bbce08df7f8529d8185a51 x86_64/qt-devel-3.1.2-14.2.x86_64.rpm
86aad3b91aef11b01da1c816cccaffbe x86_64/qt-ODBC-3.1.2-14.2.x86_64.rpm
fb94f45a83cabdfb45751fd293be2ccc x86_64/qt-MySQL-3.1.2-14.2.x86_64.rpm
d4077aa9c95b065b89512e8937d3895d x86_64/qt-PostgreSQL-3.1.2-14.2.x86_64.rpm
2dce1a5d23a9f763f34b0f180cf5d5a1 x86_64/qt-designer-3.1.2-14.2.x86_64.rpm
b34a6cc0e2af6a58241bdb9e25618919
x86_64/debug/qt-debuginfo-3.1.2-14.2.x86_64.rpm
aca527b50ab8b71bbb7e4a6e93278173 i386/qt-3.1.2-14.2.i386.rpm
d800a0e0f24c5c748c0e6d4d0cbc766d i386/qt-devel-3.1.2-14.2.i386.rpm
8dc18024573a730fd625a54c4283be63 i386/qt-ODBC-3.1.2-14.2.i386.rpm
62785195ce484b82c388c3bc38992895 i386/qt-MySQL-3.1.2-14.2.i386.rpm
586469add7922ac224dcdc24819ce284 i386/qt-PostgreSQL-3.1.2-14.2.i386.rpm
263b2d0b195ab4869be6f4074df1c728 i386/qt-designer-3.1.2-14.2.i386.rpm
fb8ebc4323f3d36032d757a365a9bbbc
i386/debug/qt-debuginfo-3.1.2-14.2.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-267
2004-08-20
---------------------------------------------------------------------
Product : Fedora Core 2
Name : kernel
Version : 2.6.8
Release : 1.521
Summary : The Linux kernel (the core of the Linux operating system)
Description :
The kernel package contains the Linux kernel (vmlinuz), the core of any
Linux operating system. The kernel handles the basic functions
of the operating system: memory allocation, process allocation, device
input and output, etc.
---------------------------------------------------------------------
Update Information:
This update kernel updates the Fedora Core 2 kernel to version 2.6.8.
Included in this new upstream kernel are several fixes on the networking
front, including traffic shaping and window scaling fixes.
Note: This kernel includes several Execshield cleanups and changes, and as a
result programs that make certain restrictive assumptions about the virtual
address space (such as Wine) need a different workaround than before.
The applications can get the old (legacy) VA layout via the
setarch -L <application>
option when a recent enough serarch application is in use, in addition there
now is a global switch to go to the legacy VA layout:
echo 1 > /proc/sys/vm/legacy_va_layout
---------------------------------------------------------------------
* Sat Aug 14 2004 Arjan van de Ven <arjanv(a)redhat.com>
- 2.6.8-rc4-bk3
- split execshield up some more
* Sat Aug 14 2004 Dave Jones <davej(a)redhat.com>
- Update SCSI whitelist again with some more card readers.
* Tue Aug 10 2004 Arjan van de Ven <arjanv(a)redhat.com>
- 2.6.8-rc3-bk3
* Thu Aug 05 2004 Arjan van de Ven <arjanv(a)redhat.com>
- Add the flex-mmap bits for s390/s390x (Pete Zaitcev)
- Add flex-mmap for x86-64 32 bit emulation
- 2.6.8-rc3
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
c6a6b494059f01e20f69be28e35d7c34 SRPMS/kernel-2.6.8-1.521.src.rpm
c8414cca0d78754981e7f22e98dc3378 x86_64/kernel-2.6.8-1.521.x86_64.rpm
183e619084d567f95730f29c60974c7a x86_64/kernel-smp-2.6.8-1.521.x86_64.rpm
c9af2d7eaf18b507919a666ce31c083e x86_64/debug/kernel-debuginfo-2.6.8-1.521.x86_64.rpm
1249d155d13f218a29a9630fca462b26 x86_64/kernel-sourcecode-2.6.8-1.521.noarch.rpm
64d38986eb380f5a126435750bdb6143 x86_64/kernel-doc-2.6.8-1.521.noarch.rpm
5a4cb0bdd3d1f9a477c40d8c94810c08 i386/kernel-2.6.8-1.521.i586.rpm
a5f6c23c132494c058b65c400e0e8f7a i386/kernel-smp-2.6.8-1.521.i586.rpm
f2c200606b2ebbea9cfdbed8165486ab i386/debug/kernel-debuginfo-2.6.8-1.521.i586.rpm
0cc396210fec597d6440541a3bde5295 i386/kernel-2.6.8-1.521.i686.rpm
51155f6069b4d2b9831697e25ceb1fb3 i386/kernel-smp-2.6.8-1.521.i686.rpm
01d3bdeb3f225098af29be2c1a512ef8 i386/debug/kernel-debuginfo-2.6.8-1.521.i686.rpm
1249d155d13f218a29a9630fca462b26 i386/kernel-sourcecode-2.6.8-1.521.noarch.rpm
64d38986eb380f5a126435750bdb6143 i386/kernel-doc-2.6.8-1.521.noarch.rpm
This update can also be installed with yum or the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-269
2004-08-19
---------------------------------------------------------------------
Product : Fedora Core 2
Name : rsync
Version : 2.6.2
Release : 1.fc2.0
Summary : A program for synchronizing files over a network.
Description :
Rsync uses a reliable algorithm to bring remote and host files into
sync very quickly. Rsync is fast because it just sends the differences
in the files over the network instead of sending the complete
files. Rsync is often used as a very powerful mirroring process or
just as a more capable replacement for the rcp command. A technical
report which describes the rsync algorithm is included in this
package.
---------------------------------------------------------------------
Update Information:
This update backports a security fix to a path-sanitizing flaw that
affects rsync when it is used in daemon mode without also using
chroot.
For more information see http://samba.org/rsync/#security_aug04
---------------------------------------------------------------------
* Thu Aug 19 2004 Jay Fenlason <fenlason(a)redhat.com> 2.6.2-1.fc2.0
- Backport fix for CAN-2004-0792
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
d6ae9d1c6e5d18903911e1fdedd55a03 SRPMS/rsync-2.6.2-1.fc2.0.src.rpm
f03bc05659c874cb39d4bab606dfaabf x86_64/rsync-2.6.2-1.fc2.0.x86_64.rpm
97f2ed68e7b3f7e0c5888b0aa8cd2088 x86_64/debug/rsync-debuginfo-2.6.2-1.fc2.0.x86_64.rpm
1dd097feb524de781f6ae9ecf74bcc3d i386/rsync-2.6.2-1.fc2.0.i386.rpm
38590683c5bca0a599fbc70a971c6b7e i386/debug/rsync-debuginfo-2.6.2-1.fc2.0.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
Subject: Fedora Core 1 Update: rsync-2.5.7-5.fc1.1
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-268
2004-08-19
---------------------------------------------------------------------
Product : Fedora Core 1
Name : rsync
Version : 2.5.7
Release : 5.fc1.1
Summary : A program for synchronizing files over a network.
Description :
Rsync uses a reliable algorithm to bring remote and host files into
sync very quickly. Rsync is fast because it just sends the differences
in the files over the network instead of sending the complete
files. Rsync is often used as a very powerful mirroring process or
just as a more capable replacement for the rcp command. A technical
report which describes the rsync algorithm is included in this
package.
---------------------------------------------------------------------
Update Information:
This update backports a security fix to a path-sanitizing flaw that
affects rsync when it is used in daemon mode without also using
chroot.
For more information see http://samba.org/rsync/#security_aug04
---------------------------------------------------------------------
* Thu Aug 19 2004 Jay Fenlason <fenlason(a)redhat.com> 2.5.7-5.fc1.1
- Backport fix for CAN-2004-0792
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
01fb9ef513ef0d484efb1bd66e91ad69 SRPMS/rsync-2.5.7-5.fc1.1.src.rpm
dd13aba3dc99efc30ecaa0eeb49f242e x86_64/rsync-2.5.7-5.fc1.1.x86_64.rpm
d8963193e902465e632e0ed993e92f82 x86_64/debug/rsync-debuginfo-2.5.7-5.fc1.1.x86_64.rpm
bab0cb276f77596a6b9520401298764f i386/rsync-2.5.7-5.fc1.1.i386.rpm
094fa40ae453fddd43edce9fd10a054b i386/debug/rsync-debuginfo-2.5.7-5.fc1.1.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-263
2004-08-17
---------------------------------------------------------------------
Product : Fedora Core 1
Name : ghostscript
Version : 7.07
Release : 15.4
Summary : A PostScript(TM) interpreter and renderer.
Description :
Ghostscript is a set of software that provides a PostScript(TM)
interpreter, a set of C procedures (the Ghostscript library, which
implements the graphics capabilities in the PostScript language) and
an interpreter for Portable Document Format (PDF) files. Ghostscript
translates PostScript code into many common, bitmapped formats, like
those understood by your printer or screen. Ghostscript is normally
used to display PostScript files and to print PostScript files to
non-PostScript printers.
If you need to display PostScript files or print them to
non-PostScript printers, you should install ghostscript. If you
install ghostscript, you also need to install the ghostscript-fonts
package.
---------------------------------------------------------------------
Update Information:
This update provides shared libraries. This update has been re-made
because the hpijs packages had the wrong release number (thanks go to
Michal Jaegermann for spotting it).
---------------------------------------------------------------------
* Tue Aug 17 2004 Tim Waugh <twaugh(a)redhat.com> 7.07-15.4
- Rebuilt.
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
af6800ae4b7d62de9da6b8b097a60afe SRPMS/ghostscript-7.07-15.4.src.rpm
8ac5ad03c698fad9b3f51c91635226dd x86_64/ghostscript-7.07-15.4.x86_64.rpm
fd69a278493faeadb964c07e4deb4592 x86_64/ghostscript-devel-7.07-15.4.x86_64.rpm
898f548a2e241d1ca35b0a3bb9ae1d8e x86_64/ghostscript-gtk-7.07-15.4.x86_64.rpm
3eccb9c1bb3f7407807eaa46b4ee0eb6 x86_64/hpijs-1.5-4.4.x86_64.rpm
d55d96fe8db75ff0b24c1b56e2ef6557 x86_64/debug/ghostscript-debuginfo-7.07-15.4.x86_64.rpm
1215ffdcf9ec03ff446d87834a66add0 i386/ghostscript-7.07-15.4.i386.rpm
af1cc5c2097d5b01600d6698ff56e455 i386/ghostscript-devel-7.07-15.4.i386.rpm
c80122af1092cee0f27a3b453a2d69c6 i386/ghostscript-gtk-7.07-15.4.i386.rpm
76131bc868493af319c6dc5616b122c3 i386/hpijs-1.5-4.4.i386.rpm
d6290072265b2b606b41b10aceb130fd i386/debug/ghostscript-debuginfo-7.07-15.4.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------