openssl-doc.rpm Security update: This update fixes a number of vulnerabilities in the openssl package, known as ASN.1 parsing vulnerabilities (CAN-2003-0545, CAN-2003-0543, CAN-2003-0544) that allow for a remote denial of service (DoS) or possibly the execution of arbitrary code. You should reboot your system after applying this update. xf86tools.rpm This update ensures that the 'precompiled kernel interfaces' are provided for the new nvidia installer after future SuSE kernel updates, thereby rendering the kernel sources unnecessary for using the nvidia installer. lsh.rpm Security update: A remotely exploitable buffer overflow exists in LSH, a free SSH implementation. Remote attackers may execute arbitrary code as root. liboop.rpm Security update: A remotely exploitable buffer overflow exists in LSH, a free SSH implementation. Remote attackers may execute arbitrary code as root. lsh-devel.rpm Security update: A remotely exploitable buffer overflow exists in LSH, a free SSH implementation. Remote attackers may execute arbitrary code as root. sysconfig.rpm This update fixes the faulty behaviour of wireless LAN support of SuSE Linux 9.0 installations which were updated from SuSE Linux 8.2. cron.rpm Fix to set correct nice level for scripts executed by cron jpilot-Backup.rpm Compiled with GTK1 support, to fix problems with locales. jpilot.rpm Compiled with GTK1 support, to fix problems with locales. jpilot-devel.rpm Compiled with GTK1 support, to fix problems with locales. openssh-askpass.rpm This update re-enables PAM support after it had been disabled in the last update. bluez-bluefw.rpm This update removes a bug in the hotplug script. tsclient.rpm Recommended Update: Fixed some problems with missing banner for special languages. yast2-storage.rpm fix handling of encrypted loop fs with "noauto" fstab option cipe.rpm This update corrects the faultily listed known network interface names in the init script. kdebase3-ksysguardd.rpm Fix behaviour of kwin with maximised windows without border (full screen) AMD64 only: Support for 32bit Netscape plugins in Konqueror kdebase3-nsplugin.rpm Fix behaviour of kwin with maximised windows without border (full screen) AMD64 only: Support for 32bit Netscape plugins in Konqueror kdebase3-extra.rpm Fix behaviour of kwin with maximised windows without border (full screen) AMD64 only: Support for 32bit Netscape plugins in Konqueror kdebase3-kdm.rpm Fix behaviour of kwin with maximised windows without border (full screen) AMD64 only: Support for 32bit Netscape plugins in Konqueror kdebase3-samba.rpm Fix behaviour of kwin with maximised windows without border (full screen) AMD64 only: Support for 32bit Netscape plugins in Konqueror gnucash.rpm Graphs and diagrams work again in gnucash. Update to latest stable version. kbd.rpm Due to a wrong path, kbdrate was not called in the initscript, thus not setting the typematic rate and delay as it should. libnids.rpm Security Fix for probably remote exploitable buffer overflow in TCP stream reassembly code. thttpd.rpm Security fix for remote exploitable buffer overflow and virtual hosting information leak. yast2-packagemanager-devel.rpm Improved load-balancing for YOU mirrors. koffice.rpm Fixes a segfault in kword on closing the file dialog. saint.rpm Recomended Update: Fixed a problem with package build that prevented proper function. coreutils.rpm Security Fix for denial-of-service attack by abusing the -w option of `ls'. perl-Qt.rpm Fixed undefined symbol in Qt.so loadable perl module. capi4hylafax.rpm Security update: This update fixes some format string errors in the hylafax package that may allow an attacker to gain root privileges. sysconfig.rpm This update fixes the faulty behaviour of wireless LAN support of SuSE Linux 9.0 installations which were updated from SuSE Linux 8.2. Further on it fixes a problem with some 54MBit wireless LAN cards when WEP encryption is being used. gdm2.rpm Security Update: This patch disables two denial-of-service attacks by exploiting two different mechanisms in GDM. The Common Vulnerabilities and Exposures project has assigned these exploits as CAN-2003-0793 and CAN-2003-0794. ircd.rpm Security update: This update for the ircd daemon fixes a buffer overflow bug that allows the IRC server to be crashed by a locally connected user. pinentry.rpm Recommended Update: This update fixes sometimes occuring "Out of memory" errors. suselinux-userguide_de.rpm Adjust missing pictures; thanks to Thomas Schraitle, reported by Christoph Thiel [# 32850]. suselinux-userguide_de-pdf.rpm Adjust missing pictures; thanks to Thomas Schraitle, reported by Christoph Thiel [# 32850]. suselinux-userguide_en.rpm Adjust missing pictures; thanks to Thomas Schraitle, reported by Christoph Thiel [# 32850]. Also translate two paragraphs. suselinux-userguide_en-pdf.rpm Adjust missing pictures; thanks to Thomas Schraitle, reported by Christoph Thiel [# 32850]. Also translate two paragraphs. kernel-source-um.rpm This kernel update fixes various problems found since the 9.0 release. - Various ACPI fixes (T40, SCI table, IRQ floods) - Locking problem with ide_scsi_abort - Error handling in cdrom river fixed - Various IPv6 fixes - Racy last merge disabled (deadlocks on SMP machines) - Various NFS corner cases (ACLs, TCP, locks, silly_delete) - Patches to avoid stack overflow - kmod UID / signal and exit_mmap update - Fix memory leak in LVM - Fix /proc read memory corruption - Fix races in ISDN network device removal - reiserfs corruption when cleaning up lost files after crash - VIA KT400/600 support (don't use AGPv3) - ALSA update, fixing problems with OSS emulation oopsing host-k_um.rpm This kernel update fixes various problems found since the 9.0 release. - Various ACPI fixes (T40, SCI table, IRQ floods) - Locking problem with ide_scsi_abort - Error handling in cdrom river fixed - Various IPv6 fixes - Racy last merge disabled (deadlocks on SMP machines) - Various NFS corner cases (ACLs, TCP, locks, silly_delete) - Patches to avoid stack overflow - kmod UID / signal and exit_mmap update - Fix memory leak in LVM - Fix /proc read memory corruption - Fix races in ISDN network device removal - reiserfs corruption when cleaning up lost files after crash - VIA KT400/600 support (don't use AGPv3) - ALSA update, fixing problems with OSS emulation oopsing xscreensaver.rpm Security Fix for local vulnerability concerning the creation and usage of temporary files as well as fix for crash while verifying the user-password. ganglia-monitor-core-devel.rpm Security Fix for remote denial-of-service attack. ganglia-webfrontend.rpm Security Fix for remote denial-of-service attack. ganglia-monitor-core.rpm Security Fix for remote denial-of-service attack. apache-example-pages.rpm Security update: This update fixes a vulnerability in the apache package, known as Local configuration regular expression overflow (CAN-2003-0542), which could allow a remote attacker the execution of arbitrary code. When configuring a regular expression with more than 9 captures, buffer overflows in mod_alias and mod_rewrite were possible. apache-doc.rpm Security update: This update fixes a vulnerability in the apache package, known as Local configuration regular expression overflow (CAN-2003-0542), which could allow a remote attacker the execution of arbitrary code. When configuring a regular expression with more than 9 captures, buffer overflows in mod_alias and mod_rewrite were possible. bastille.rpm This update adds the missing symbolic link that permits bastille to work on SUSE LINUX 9.0. unace.rpm Security Fix for buffer overflow with long file-names. screen.rpm Security fix for possibly remote privilege escalation in screen. lftp.rpm Security Fix: This update fix' a remote exploitable buffer overflow while using HTTP/HTTPS. freeradius-devel.rpm Security Fix for remote denial-of-dervice attack by sending a malformated "tunnel password" package that results in a faulty memory allocation. irssi.rpm Security Fix: This update fixes a remote denial-of-service attack against irssi irc client. memprof.rpm Bugfix: libmemintercept.so, required for running memprof, was missing from the package. fontconfig.rpm The default for subpixel hinting is set to "none" in these updated fontconfig packages. If you switch off subpixel hinting in the KDE control centre, KDE removes all rules concerning subpixel hinting from ~/.fonts.conf, but the global default may still be to use subpixel hinting on some TFT displays. Making the global default "none" means you can really switch it off in the KDE control centre. fontconfig-devel.rpm The default for subpixel hinting is set to "none" in these updated fontconfig packages. If you switch off subpixel hinting in the KDE control centre, KDE removes all rules concerning subpixel hinting from ~/.fonts.conf, but the global default may still be to use subpixel hinting on some TFT displays. Making the global default "none" means you can really switch it off in the KDE control centre. cdrecord.rpm This update fixes a problem that prevented cdrecord from working on a machine running the Linux 2.6 kernel. Installations running the 2.4 kernel are unaffected. tcpd.rpm This fix corrects invalid warning about "host name mismatch". inn.rpm Security-Fix INN handles certain control messages in an insecure way. This may allow remote attackers to execute arbitrary commands. INN 2.3.x is not affected. mpg321.rpm Security Fix: A format-bug in mpg321 can be exploited (even remotly by HTTP streaming) to execute code with the permissions of the user running mpg321 on special MP3 files. popper.rpm This update fixes unsecure temp file handling. kdepim3.rpm It was possible to use a buffer overflow via a special crafted vcard file to run code during generating previews. By default it was only possible on local filesystems, but the user can enable this also for remote file systems. gnome-filesystem.rpm Security Fix: This update fixes the insecure handling of temporary files. cvsup.rpm Security Fix: Removed public-writable directories from shared library search path. 3ddiag.rpm Security Fix: Some scripts of 3Ddiag handle local temporary files in an insecure manner which may lead to local privilege escalation. nmap.rpm Security Fix: nmap does not run as root due to bad interaction between kernel and user-space for pre calculated IP checksum. Thanks to Dirk Mueller for debugging. whois.rpm Fixed 64-bit archs problem, which caused problem with some IPs? apache-contrib.rpm Security Fix: This update fixes several buffer overflow that are propably exploitable remotely and insecure file handling in the Apache module mod_gzip. Additionally a failure in mod_auth_shadow was fixed that caused the ignorance of account expiration dates. ucdsnmp.rpm Activated support for dynamic loading of modules. mutt.rpm This update fixes a buffer overflow that can be triggered by incoming messages yast2-bootloader.rpm A new cd-rom/-writer or dvd-rom wasn't setup properly by yast2 cd-rom, due to a namespace conflict. This conflict is solved in this update. XFree86.rpm Security Fix: A buffer overflow in the X server can be triggered by using a malformed fonts.alias file. This bug can be used to gain local root privilege. python-numeric.rpm Threading-support has been activated for python-gtk. Due new dependency python-numeric is also included in this update. python-gtk.rpm Threading-support has been activated for python-gtk. Due new dependency python-numeric is also included in this update. dosfstools.rpm Bugfix for bad detection of empty FAT entries because of signed and unsigned comparsion. quagga.rpm Fixed installation bug. gnome-session.rpm Security Fix: This updates solves a problem with the initialisation of the LD_LIBRARY_PATH while starting GNOME by using /usr/X11R6/bin/gnome. This bug can lead to local privilege escalation. pwlib.rpm Security Fix: This update addresses several security vulnerabilities that may be exploited remotely via applications that link with pwlib, like GnomeMeeting or alike. emil.rpm Security Fix: The emil mail filter conatins buffer overflows and format-string bugs that can be exploited remotely if emil is used in conjunction with procmail, sendmail and alike. (CAN-2004-0152, CAN-2004-0153) openssh.rpm The scp client accidental allowed special characters in filenames to be given by the server. This allowed evil servers to create files outside the working directory under the privilege of the user running the scp client. This bug has been fixed. sysstat.rpm Security Fix: This update close two cases of insecure temporary file handling in the isag code. uudeview.rpm Security Fix: This update fixes the insecure handling of temporary files in uudeview. kphone.rpm fixes a possible denial-of-service attack in sip client code. gtk2-engines.rpm The package gtk-engines missed a check for a pointer which caused certain gtk-themes to crash. See http://bugzilla.gnome.org/show_bug.cgi?id=112066 for more information. metamail.rpm Security Fix: This update fixes two buffer overflows and two format string bugs that can be exploited remotely in conjunction with other tools to gain access to a system with the privileges of the user running metamail. monit.rpm There exists security vulnerabilites in the monit HTTP interface, which could allow an attacker in the worst case to gain root access to the system. This issue only affects monit if monit is started with http server support. See http://www.tildeslash.com/monit/secadv_20040305.txt for details. leafnode.rpm Security Fix: This update of leafnode fixes potential security vulnerabilities (denial-of-service attack triggered locally). canna.rpm This update fixes the unsecure handling of temporary files in the start script /etc/init.d/canna xine-ui.rpm Security Fix: This update fixes two vulnerabilities that allow remote attackers to write arbitrary data to files either by opening a malicious MRL or by opening a malicious playlist. yast2-packagemanager.rpm Security update: This update package for the yast2-packagemanager, the central component for YOU (Yast Online Update), fixes a local vulnerability caused by insecure file handling when YOU is called as non-root (checking mode). xchat.rpm This update fixes a buffer overflow present when using a SOCKS5 proxy with xchat. epiphany.rpm This patch updates the GNOME programs Epiphany and Galeon to version 1.0.2 and 1.3.14a, to stay compatible with the recent Mozilla update to version 1.4.1. galeon.rpm This patch updates the GNOME programs Epiphany and Galeon to version 1.0.2 and 1.3.14a, to stay compatible with the recent Mozilla update to version 1.4.1. utempter.rpm Security Fix: This updates addresses a possible symlink attack while using tty device files. This bug may lead to a local root compromise. rarpd.rpm Fixes wrong server address in the response paket. mpich.rpm Removed unnecessary setuid bit. apache-devel.rpm This apache update solves the following security problems: - mod_digest, verify nonce (CAN-2003-0987) - escape suspicious chars before logging them (CAN-2003-0020) - starvation issue on listening sockets (CAN-2004-0174) - buffer overflow in mod_ssl (ssl_util_uuencode(), #40791) raidtools.rpm Fixed a bug in mkraid where mkraid falsely claimed an array to be already active. subversion-server.rpm Potential Denial of Service and Heap Overflow issue related to the parsing of strings in the 'svn://' family of access protocols. Only sites running 'svnserve' are affected. subversion-devel.rpm Potential Denial of Service and Heap Overflow issue related to the parsing of strings in the 'svn://' family of access protocols. Only sites running 'svnserve' are affected. subversion.rpm Potential Denial of Service and Heap Overflow issue related to the parsing of strings in the 'svn://' family of access protocols. Only sites running 'svnserve' are affected. sitecopy.rpm The sitecopy package includes a vulnerable version of the neon library. (CAN-2004-0179, CAN-2004-0398) xsitecopy.rpm The sitecopy package includes a vulnerable version of the neon library. (CAN-2004-0179, CAN-2004-0398) less.rpm This update fixes a possible symlink attack in lessopen.sh. The attack can be executed by local users to overwrite arbitray files with the privileges of the user running less. psqlODBC.rpm A buffer overflow in psqlODBC could be exploited to crash the application using it. E.g. a PHP script that uses ODBC to access a PostgreSQL database can be utilized to crash the surrounding Apache webserver. Other parts of PostgreSQL are not affected. tripwire.rpm fixes segfault on start of binary. (has been recompiled with more recent binutils) freeswan.rpm A bug in the certificate chain authentication code could allow an attacker to authenticate any host against a FreeS/WAN server by presenting specially crafted certificates wrapped in a PKCS#7 file. dhcp-server.rpm This update adds a fix from 3.0.1rc14 to the dynamical DNS code that restricts the total length of DDNS domain names with client provided hostnames to 255 characters, to avoid possible security problems. These problems may be exploitable by remote users to execute arbitrary code. Only DHCP servers configured for dynamical DNS are affected. cadaver.rpm This update fixes several vulnerabilities in the included neon library. (CAN-2004-0179, CAN-2004-0398) kopete.rpm Fixes an security issue in the winpopup protocol. It was possible to overwrite files via a symlink attack. wv.rpm This update resolves the insecure handling of temporary files. gnats.rpm A format string bug in gnats has been removed that possibly allows remote command execution. pure-ftpd.rpm This update fixes a possible DoS attack because of a bug in the accept_client function handling the setup of new connections. neon.rpm Security update for adding missing filtering of control characters. neon-devel.rpm Security update for adding missing filtering of control characters. pavuk.rpm This update fixes several buffer overflows in pavuk's digest authentication support. Thanks to Matthew Murphy for reporting this issue to us. sox.rpm Buffer overflows in the 'sox' and 'play' have been fixed that could be exploited by playing specially crafted .wav files. (CAN-2004-0557) lha.rpm The source code of lha was reviewed to find possible security vulnerabilities. As a result several possible buffer overflows were fixed that can be exploited by providing a special archive to lha. aspell.rpm A bug in the aspell utility word-list-compress can allow an attacker to execute arbitrary code. aspell-devel.rpm A bug in the aspell utility word-list-compress can allow an attacker to execute arbitrary code. arts-devel.rpm This update removes an inconsistency in the comparsion of credentials while creating temporary files. This flaw can be exploited locally in conjunction with setuid Arts applications. (very unlikely) arts.rpm This update removes an inconsistency in the comparsion of credentials while creating temporary files. This flaw can be exploited locally in conjunction with setuid Arts applications. (very unlikely) kdebase3-devel.rpm This update resolves various security vulnerabilities: - unsecure handling of temporary files. (CAN-2004-0689) Thanks to Andrew Tuitt. - unsecure tempfile handling in dcopserver (CAN-2004-0690) - modification of content in unrelated browser windows (CAN-2004-0721) kdelibs3-devel.rpm This update resolves various security vulnerabilities: - unsecure handling of temporary files. (CAN-2004-0689) Thanks to Andrew Tuitt. - unsecure tempfile handling in dcopserver (CAN-2004-0690) - modification of content in unrelated browser windows (CAN-2004-0721) rsync.rpm This update fixes a path-sanitizing bug in rsync, which affects running rsync in daemon mode with chroot disabled. rrdtool.rpm This update fixes security problems with the included libpng. libpng-devel.rpm This update adds a missing patch to secure writing of images. The exploitation probobility is very low. libpng.rpm This update adds a missing patch to secure writing of images. The exploitation probobility is very low. qt3.rpm Security Update: This updates resolves several buffer overflow bugs in the QT library. These overflows exist in the image handling code for various image formats and can be exploited by attackers to crash or probably execute code by providing malformated image files to QT-based applications. (CAN-2004-0691, CAN-2004-0692, CAN-2004-0693) qt3-non-mt.rpm Security Update: This updates resolves several buffer overflow bugs in the QT library. These overflows exist in the image handling code for various image formats and can be exploited by attackers to crash or probably execute code by providing malformated image files to QT-based applications. (CAN-2004-0691, CAN-2004-0692, CAN-2004-0693) qt3-static.rpm Security Update: This updates resolves several buffer overflow bugs in the QT library. These overflows exist in the image handling code for various image formats and can be exploited by attackers to crash or probably execute code by providing malformated image files to QT-based applications. (CAN-2004-0691, CAN-2004-0692, CAN-2004-0693) mkinitrd.rpm Fix kernel command line parsing in mkinitrd so that vga=0xXXX is again recognized correctly. The last update of mkinitrd was broken, the boot splash screen would not be displayed. spamassassin.rpm Security Update: This update fixes a denial-of-service condition in SpamAssassin. This previous update was missing one sub package of SpamAssassin. perl-spamassassin.rpm Security Update: This update fixes a denial-of-service condition in SpamAssassin. This previous update was missing one sub package of SpamAssassin. libnetpbm.rpm Security-Fix: Some tools of the netpbm suite create files in an insecure manner that can lead to local privilege escalation. This is a reissue of earlier security updates for netpbm, since they were missing a subpackage. a2ps.rpm Security Update: This update fix' the handling of filename that include shell meta-characters. Without this patch it was possible to execute shell commands via a2ps by providing a filename that includes meta-characters as an argument. nessus-core.rpm nessus-adduser created temporary files in $TMPDIR in an insecure way. This has been fixed by creating an additional temporary directory first. mod_dav.rpm A vulnerability in the WebDAV module has been fixed. A remote attacker could crash a server process, leading to a Denial of Service scenario. Only installations configured for WebDAV access were affected. See http://nagoya.apache.org/bugzilla/show_bug.cgi?id=31183. CAN-2004-0809 has been assigned to this issue. zinf.rpm A buffer overflow in the playlist handling of zinf discovered by Luigi Auriemma has been fixed. openmotif-devel.rpm This update fixes following security problems in OpenMotif: CAN-2004-0687: Several stack overflows in the libXPM image handling library contained within OpenMotif were fixed. CAN-2004-0688: Several integer overflow problems in the libXPM image handling library contained within OpenMotif were fixed. openmotif-demo.rpm This update fixes following security problems in OpenMotif: CAN-2004-0687: Several stack overflows in the libXPM image handling library contained within OpenMotif were fixed. CAN-2004-0688: Several integer overflow problems in the libXPM image handling library contained within OpenMotif were fixed. openmotif-libs.rpm This update fixes following security problems in OpenMotif: CAN-2004-0687: Several stack overflows in the libXPM image handling library contained within OpenMotif were fixed. CAN-2004-0688: Several integer overflow problems in the libXPM image handling library contained within OpenMotif were fixed. openmotif.rpm This update fixes following security problems in OpenMotif: CAN-2004-0687: Several stack overflows in the libXPM image handling library contained within OpenMotif were fixed. CAN-2004-0688: Several integer overflow problems in the libXPM image handling library contained within OpenMotif were fixed. aaa_base.rpm This updates fixes several /tmp file removal race problems in aaa_base: - The suse.de-clean-vi was not race free and could be used by a local attacker to remove any file on the system. - The safe-rm script used for safe /tmp file removal could be tricked by a local attacker with a symlink attack to remove any file in the filesystem due to a very narrow race in bash directory handling. - The initial tmp file cleaning script could be tricked by a local attacker to delete any file on the system with the agent substring "agent" in its name. Thanks to Stefan Nordhausen for reporting this problems to us! man.rpm Use safe-rm to avoid link attacks on clearing temporary files. cyrus-sasl-devel.rpm A security problem has been found in the Cyrus SASL authentification libraries that could lead to a local attacker gaining root access. Affected applications are not included in the SUSE default installation, but third party apps might be affected. The issue has been given the Mitre CVE Id CAN-2004-0884. ez-ipupdate.rpm This update fixes a remotely exploitable format string bug. This bug can be exploited if ez-ipupdate runs in daemon-mode or not, and even in quiet-mode. Thanks to Ulf Harnhammar. xzgv.rpm Like its predecessor gv the picture viewer xzgv contains numerous integer multiplication overflows which can be exploited by tricking a user to view specially crafted images with xzgv. The resulting buffer overflow can be abused to run malicious code with the user id of the user who runs xzgv. This update closes the vulnerability. sharutils.rpm Several buffer overflows in the shar program were found. Also some shell quoting problems where identified and fixed by Andreas Schwab. smalltalk.rpm This update fixes vulnerable libxpm code included in smalltalk. These bugs can be exploited whenever malformated XPM images are processed. Very unlikely. acpid.rpm This update removes the possibility for a local DoS attack. tftp.rpm This update fixes some buffer overflows in the tftp client code that handles DNS name lookups. Eploitation can be done using a malicious DNS server and will result in a remote code execution. perl-MIME-tools.rpm A bug when parsing empty MIME boundaries was fixed that allowed a mail virus to slip through virus scanners undetected. resmgr.rpm This update of resmgr improves the stability of determining terminal names. gd.rpm The graphics library GD used by several applications is vulnerable to arithmetic failures that may lead to buffer overflows afterwards. The bug can be exploited remotely by tricking a user or network application to open a malformated PNG image. A successful exploitation results in arbitrary code execution. gd-devel.rpm The graphics library GD used by several applications is vulnerable to arithmetic failures that may lead to buffer overflows afterwards. The bug can be exploited remotely by tricking a user or network application to open a malformated PNG image. A successful exploitation results in arbitrary code execution. iptables.rpm Due to an uninitialized variable in iptables and ip6tables additional kernel modules may not get loaded which may result in rules not beeing implemented. (CAN-2004-0986) perl-Archive-Zip.rpm Mail virus scanners like amavis use perl-Archive-Zip to scan ZIP archives. A bug in the handling of files with manipulated size entires has been fixed that could leave malicious code in such files undetected. xmlstarlet.rpm xmlstarlet is linked statically against libxml2 and thus it inherited buffer overflows from the library. This update fixes several buffer overflows that can occur while processing FTP and HTTP URLs as well as in DNS name handling code. These bugs can be exploited remotely to execute arbitrary code. unarj.rpm A directory traversal bug was spotted in the unarj program, which could allow a handcrafted archive to overwrite files outside of the current directory. (CAN-2004-0947) Additionaly Ludwig Nussel of SUSE Security audited unarj and found several buffer overflows which are also fixed by this update. imlib.rpm This upgrade fixes several integer overflow in the image loaders contained in imlib, which could lead to a remote attacker gaining local access by (for instance) a handcrafted XPM files. imlib-config.rpm This upgrade fixes several integer overflow in the image loaders contained in imlib, which could lead to a remote attacker gaining local access by (for instance) a handcrafted XPM files. imlib-devel.rpm This upgrade fixes several integer overflow in the image loaders contained in imlib, which could lead to a remote attacker gaining local access by (for instance) a handcrafted XPM files. zip.rpm When zip performs recursive folder compression, it does not check for the length of resulting path. If the path is too long, a buffer overflow occurs leading to stack corruption and segmentation fault. file.rpm This security update fixes a possible buffer overflow when parsing ELF based binaries. nfs-utils.rpm statd did not ignore the "SIGPIPE" signal which caused it to shutdown if a misconfigured or malicious peer terminated the TCP connection prematurely. This problem has been fixed. samba-vscan.rpm This update of the samba server fixes several integer overflows that can be exploited to overflow heap memory. An attacker can use this bugs to execute arbitrary code remotely. (CAN-2004-1154) iproute2.rpm iproute2 did not validate whether messages sent via the kernel netlink interface originate from root which allowed local users to cause a Denial of Service condition. This bug has been fixed. (CAN-2003-0856) namazu.rpm This update fixes a cross site scripting vulnerability of namazu. namazu-devel.rpm This update fixes a cross site scripting vulnerability of namazu. subversion-viewcvs.rpm An issue allowing a Cross-site scripting (XSS) attack has been fixed. URLs shown in the error page by ViewCVS were not properly quoted. CAN-2004-1062 has been assigned to this issue. libxml-devel.rpm This update adds missing patches for a buffer overflow in URL parsing code (CAN-2004-0989) and a buffer overflow while handling DNS responses (CAN-2004-0110). This bugs can be exploited remotely to execute arbitrary code. libxml.rpm This update adds missing patches for a buffer overflow in URL parsing code (CAN-2004-0989) and a buffer overflow while handling DNS responses (CAN-2004-0110). This bugs can be exploited remotely to execute arbitrary code. libxml2-devel.rpm This update fixes a buffer overflow in the DNS handling code (CAN-2004-0110). This bug can be exploited remotely via a DNS server under the control of the attacker. libxml2-python.rpm This update fixes a buffer overflow in the DNS handling code (CAN-2004-0110). This bug can be exploited remotely via a DNS server under the control of the attacker. libxml2.rpm This update fixes a buffer overflow in the DNS handling code (CAN-2004-0110). This bug can be exploited remotely via a DNS server under the control of the attacker. kdegraphics3-fax.rpm kfax contains an outdated copy of libtiff which is vulnerable against buffer overflows. This update removes this copy and uses the fixed system wide library. imlib2-filters.rpm This fixes several integer and buffer overflows in the BMP and XPM loaders of imlib2 which were already fixed for imlib, referenced there under the CVE ID CAN-2004-1026. imlib2-loaders.rpm This fixes several integer and buffer overflows in the BMP and XPM loaders of imlib2 which were already fixed for imlib, referenced there under the CVE ID CAN-2004-1026. imlib2-devel.rpm This fixes several integer and buffer overflows in the BMP and XPM loaders of imlib2 which were already fixed for imlib, referenced there under the CVE ID CAN-2004-1026. imlib2.rpm This fixes several integer and buffer overflows in the BMP and XPM loaders of imlib2 which were already fixed for imlib, referenced there under the CVE ID CAN-2004-1026. exim.rpm A buffer overflow in the host_aton function allowed a local attacker to gain privileges of the mail system. This bug has been fixed (CAN-2005-0021). Additionally a buffer overflow in the auth_spa_server function has been fixed (CAN-2005-0022). Exim is compiled without SPA support but the patch is included in the source code nevertheless. mpg123.rpm This update fixes a possible buffer overflow in mpg123 that could be exploited by specially crafted mp2 or mp3 files (CAN-2004-0991). Additionally the patch for the buffer overflow in the HTTP code was replaced with a better one (CAN-2004-0982). kdebase3.rpm A malicious website could abuse Konqueror to load its own content into a window or tab that was opened by a trusted website or it could trick a trusted website into loading content into an existing window or tab. Passwords in smb:/ URLs are not visible to the user anymore. (CAN-2004-1158) ncpfs-devel.rpm This update fixes the following security issues: - a buffer overflow in ncplogin and ncpmap. Both applications are installed setuid-root on SuSE Linux, but only users of group 'trusted' are allowed to execute the binaries. If successfully exploited this vulnerabilities could be used to gain local root access. - missing file permisions checks for ~/.nwclient (CAN-2005-0013) - a buffer overflow in ncplogin (CAN-2005-0014) ncpfs.rpm This update fixes the following security issues: - a buffer overflow in ncplogin and ncpmap. Both applications are installed setuid-root on SuSE Linux, but only users of group 'trusted' are allowed to execute the binaries. If successfully exploited this vulnerabilities could be used to gain local root access. - missing file permisions checks for ~/.nwclient (CAN-2005-0013) - a buffer overflow in ncplogin (CAN-2005-0014) hylafax.rpm A bug in the authentication code of hfaxd has been fixed that allowed attackers to gain unauthorized access to the fax system by guessing the content of the hosts.hfaxd file. Please note that entries in hosts.hfaxd that are of the form 192.168.0 username:uid:pass:adminpass user@host will no longer work after this update. Such entries should be changed into 192.168.0.[0-9]+ username@:uid:pass:adminpass user@host If possible delimiters for the regular expressions should be used: @192.168.0.[0-9]+$ ^username@:uid:pass:adminpass ^user@host$ libsmbclient-devel.rpm Fix order of evaluation in the bitmap code. This might lead to segfaulting Samba daemons smbd and winbind. samba-client.rpm Fix order of evaluation in the bitmap code. This might lead to segfaulting Samba daemons smbd and winbind. samba.rpm Fix order of evaluation in the bitmap code. This might lead to segfaulting Samba daemons smbd and winbind. libsmbclient.rpm Fix order of evaluation in the bitmap code. This might lead to segfaulting Samba daemons smbd and winbind. mc.rpm Various security bugs ranging from denial of service conditions to command execution have been fixed. (CAN-2004-1004, CAN-2004-1005, CAN-2004-1176) htdig.rpm Security Update: This update fixes a Cross-Site-Scripting vulnerability that can be exploited remotely. (CAN-2005-0085) evolution.rpm Security Update: This update fixes an interger-overflow in a helper application used by evolution. This bug can be exploited locally in conjunction with a malicious POP server to gain higher privileges. (CAN-2005-0102) evolution-devel.rpm Security Update: This update fixes an interger-overflow in a helper application used by evolution. This bug can be exploited locally in conjunction with a malicious POP server to gain higher privileges. (CAN-2005-0102) perl-DBI.rpm Security Update: This update fixes insecure temp. file handling. (CAN-2005-0077) konversation.rpm This update fixes three vulnerabilities which allow remote command execution, information leakage, and unallowed IRC client command execution. postgresql-python.rpm This update fixes the possibility for unprivileged users to load and execute arbitray code from shared libraries via the LOAD SQL statement in the database backend. enscript.rpm Unsanitised input can caues the execution of arbitrary commands via EPSF pipe support. This has been disabled, also upstream (CAN-2004-1184). Due to missing sanitising of filenames it is possible that a specially crafted filename can cause arbitrary commands to be executed (CAN-2004-1185). Multiple buffer overflows can cause the program to crash (CAN-2004-1186). gftp.rpm Improper handling of filenames containing slashes allowed a malicious ftp server to overwrite files in the system if the user used gftp. This bug has been fixed. python.rpm This update fixes a bug in the SimpleXMLRPCServer which affects any programs which allows remote untrusted users to do unrestricted traversal. The vulnerability can be used to access and change internal functions. (CAN-2005-0089) openldap2-back-monitor.rpm Security Update: This updates fixes a remote exploitable denial-of-service conditions in slapd the LDAP server daemon. It is possible to crash the daemon by providing special search strings. openldap2-back-perl.rpm Security Update: This updates fixes a remote exploitable denial-of-service conditions in slapd the LDAP server daemon. It is possible to crash the daemon by providing special search strings. openldap2-back-ldap.rpm Security Update: This updates fixes a remote exploitable denial-of-service conditions in slapd the LDAP server daemon. It is possible to crash the daemon by providing special search strings. openldap2-back-meta.rpm Security Update: This updates fixes a remote exploitable denial-of-service conditions in slapd the LDAP server daemon. It is possible to crash the daemon by providing special search strings. openldap2.rpm Security Update: This updates fixes a remote exploitable denial-of-service conditions in slapd the LDAP server daemon. It is possible to crash the daemon by providing special search strings. emacs.rpm Format string bugs fixed in helper application movemail which could be used to execute arbitrary code. xemacs.rpm Format string bugs fixed in helper application movemail which could be used to execute arbitrary code. cyrus-imapd.rpm This update fixes several one-byte buffer overruns in the imap annote extension as well as in cached header handling which can be run by an authenticated user. Additionally bounds checking in fetchnews was improved to avoid exploitation by a peer news admin. Please note that one-byte buffer overflows can not be exploited to execute arbitrary commands by manipulating the saved registers on the stack if the compiler used (gcc >= 3) aligns the stack space. Nevertheless the code behaviour may be manipulated by overwriting local variables. The result is not known but ranges between a denial-of-service condition and privilege escalation. apache2-mod_python.rpm This update fixes an infomation leak in mod_python when using the publisher handle. Due to the bug it is possible to get access to published objects remotely without permission (CAN-2005-0088). imap.rpm This Update fixes a logical error in the challenge response auhentication mechanism CRAM-MD5. Due to this mistake a remote attacker can gain access to the IMAP server as arbitrary user. (CAN-2005-0198) cyrus-sasl.rpm This update fixes a buffer overflow in the digestmda5 code. (CAN-2005-0373) gpg.rpm The OpenPGP protocol was vulnerable to a timing-attack to gain plaintext from ciphertext. The timing difference appears as side effect of the so called quick scan and is only exploitable on systems that accept an arbitrary amount of ciphertext for automatic decryption. mod_python.rpm This update fixes an infomation leak in mod_python when using the publisher handle. Due to the bug it is possible to get access to published objects remotely without permission (CAN-2005-0088). squirrelmail-plugins.rpm This update fixes a command injection vulnerability in squirrelmail's S/MIME plugin which could be exploited remotely to execute arbitrary commands with the privileges of the web-server. (CAN-2005-0239) ImageMagick.rpm This update fixes several security issues: - A format string vulnerability in the display program. (CAN-2005-0397) - A buffer overflow in the SGI image decoder routines. - A buffer overflow in the TIFF image decoder routines. - A denial of service attack (crash) in the TIFF decoder. - A denial of service attack (crash) in the PSD decoder. perl-PerlMagick.rpm This update fixes several security issues: - A format string vulnerability in the display program. (CAN-2005-0397) - A buffer overflow in the SGI image decoder routines. - A buffer overflow in the TIFF image decoder routines. - A denial of service attack (crash) in the TIFF decoder. - A denial of service attack (crash) in the PSD decoder. ImageMagick-devel.rpm This update fixes several security issues: - A format string vulnerability in the display program. (CAN-2005-0397) - A buffer overflow in the SGI image decoder routines. - A buffer overflow in the TIFF image decoder routines. - A denial of service attack (crash) in the TIFF decoder. - A denial of service attack (crash) in the PSD decoder. ImageMagick-Magick++.rpm This update fixes several security issues: - A format string vulnerability in the display program. (CAN-2005-0397) - A buffer overflow in the SGI image decoder routines. - A buffer overflow in the TIFF image decoder routines. - A denial of service attack (crash) in the TIFF decoder. - A denial of service attack (crash) in the PSD decoder. tetex.rpm By placing a symlink in /var/cache/fonts a user could find out which files exist in directories not accessible for him. Indexing /var/cache/fonts is now done as user nobody instead of root to prevent this. XFree86-libs.rpm This update fixes a buffer overflow in some for loops that can be triggered while processing XPM image file data. This bug might be exploitable from remote to execute arbitrary code. (CAN-2005-0605) grip.rpm Insufficient checks when processing CDDB queries could lead to buffer- and integeroverflows. Those bugs have been fixed (CAN-2005-0706). libexif.rpm This update fixes a small buffer overflow in the libexif image processing library which could lead to a denial of service or potential remote code execution attack when sending handcrafted JPG files. This is tracked by the Mitre CVE ID CAN-2005-0664. wget.rpm This security update fixes security problems with wget. - HTTP redirect statements could be used to do a directory traversal and write to files outside of the current directory. - HTTP redirect statements could be used to overwrite dot (".") files potentially overwriting users .bashrc or similar files. This update replaces dangerous directories and filenames by replacing the dot (".") with an underscore ("_"). The SUSE Linux 9.3 update also fixes the incorrectly encoded german translations. gnome-vfs2.rpm This update fixes the following security problems: - The VFS scripts contained in GNOME are vulnerable to attacks on temporary files as well as command execution via shell meta-characters. These bugs can be exploited by accessing a malformated archive file (CAN-2004-0494, SUSE LINUX <= 9.2). - Insufficient checks when processing CDDB queries could lead to buffer and integer overflows (CAN-2005-0706). gnome-vfs2-doc.rpm This update fixes the following security problems: - The VFS scripts contained in GNOME are vulnerable to attacks on temporary files as well as command execution via shell meta-characters. These bugs can be exploited by accessing a malformated archive file (CAN-2004-0494, SUSE LINUX <= 9.2). - Insufficient checks when processing CDDB queries could lead to buffer and integer overflows (CAN-2005-0706). heimdal-lib.rpm This update fixes several vulnerabilities in the telnet client. CAN-2005-0469: A buffer overflow in the LINEMODE suboption command SLC can be exploited by a malicious server to execute arbitrary code on the client site with the privileges of the user running telnet. CAN-2005-0468: Another buffer overflow can be exploited remotely via a malicious server by sending environment variables to the client. The result of this bug is arbitrary code execution too. Note that this bug can also be exploited by clicking on a URL link that uses telnet:// as protocol and points to a server controlled by an attacker. heimdal-devel.rpm This update fixes several vulnerabilities in the telnet client. CAN-2005-0469: A buffer overflow in the LINEMODE suboption command SLC can be exploited by a malicious server to execute arbitrary code on the client site with the privileges of the user running telnet. CAN-2005-0468: Another buffer overflow can be exploited remotely via a malicious server by sending environment variables to the client. The result of this bug is arbitrary code execution too. Note that this bug can also be exploited by clicking on a URL link that uses telnet:// as protocol and points to a server controlled by an attacker. cvs.rpm This update fixes some exploitable buffer overflows which could lead to a remote code execution attack. OpenOffice_org-sk.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-sv.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-zh-CN.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-zh-TW.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-pl.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-el.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-fr.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-ko.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-ja.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-cs.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-da.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-en-help.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-pt.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-en.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-tr.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-hu.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-es.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-ru.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-it.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-de.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-nl.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. OpenOffice_org-ar.rpm This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice. This is tracked by the Mitre CVE ID CAN-2005-0941. gnome-vfs.rpm This update fixes the following security problems: - The VFS scripts contained in GNOME are vulnerable to attacks on temporary files as well as command execution via shell meta-characters. These bugs can be exploited by accessing a malformated archive file (CAN-2004-0494, SUSE LINUX <= 9.2). - Insufficient checks when processing CDDB queries could lead to buffer and integer overflows (CAN-2005-0706). kdelibs3.rpm Multiple security bugs in various image decoders that could lead to crashes or code execution have been fixed (CAN-2005-1046). xv.rpm This update fixes several security problems: - a buffer overflow in the BMP decoder (CAN-2004-1725) - integer overflows in the Iris, PCX and PM decoders (CAN-2004-1726) - format string bugs in filename handling (CAN-2005-0665) - buffer overflows in the PDS decoder - format string bugs in the TIFF and PDS decoders - handling of shell meta-characters in filenames libtiff.rpm This update fixes a buffer overflow in the BitsPerSample() function. tiff.rpm This update fixes a buffer overflow in the BitsPerSample() function. qpopper.rpm Qpopper was handling user files while running as root. Qpopper could also be tricked into overwriting system files. CAN 2005-1151 and CAN 2005-1152 have been assigned to these issues. perl-Convert-UUlib.rpm This update fixes a buffer overflow that could allow an attacker to execute arbitrary code (CAN-2005-1349). freeradius.rpm The FreeRADIUS SQL support is prone to a SQL command injection (CAN-2005-1455) and to a buffer overflow (CAN-2005-1454). The buffer overflow might be exploitable remotely to execute arbitrary code. bzip2.rpm bzip2 could crash or run into an enless loop when decompressing certain specially crafted archives. This problem has been fixed. (CAN-2005-1260) telnet.rpm The telnet client protocol can be abused by a malicious server to read the environment of the client site. The information can be used as preparation for further attacks. This bug can also be exploited by using the telnet:// URL on a web-site and letting the web-browser fork a telnet client. This bug was reported by iDEFENSE [IDEF0865]. Note that this patch changes the behaviour of the telnet client regarding the rule of exported environment variables. Please consult the man page for further details. gedit2.rpm Gedit had a format string bug in the filename handling, potentially allowing an attacker to execute arbitrary code. This bug has been fixed (CAN-2005-1686). postgresql-test.rpm This update fixes the following security issues: - load arbitrary shared libraries and execute code via the LOAD extension (CAN-2005-0227) - bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command (CAN-2005-0244) - a heap based buffer overflow (CAN-2005-0245) - denial of service through intagg contrib module (CAN-2005-0246) - execute arbitrary code due to bugs in several SQL commands (CAN-2005-0247, CAN-2005-1409, CAN-2005-1410) This update also fixes the following non-security issues: - A race condition that allowed a transaction to be seen as committed for some purposes (eg SELECT FOR UPDATE) slightly sooner than for other purposes postgresql.rpm This update fixes the following security issues: - load arbitrary shared libraries and execute code via the LOAD extension (CAN-2005-0227) - bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command (CAN-2005-0244) - a heap based buffer overflow (CAN-2005-0245) - denial of service through intagg contrib module (CAN-2005-0246) - execute arbitrary code due to bugs in several SQL commands (CAN-2005-0247, CAN-2005-1409, CAN-2005-1410) This update also fixes the following non-security issues: - A race condition that allowed a transaction to be seen as committed for some purposes (eg SELECT FOR UPDATE) slightly sooner than for other purposes postgresql-docs.rpm This update fixes the following security issues: - load arbitrary shared libraries and execute code via the LOAD extension (CAN-2005-0227) - bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command (CAN-2005-0244) - a heap based buffer overflow (CAN-2005-0245) - denial of service through intagg contrib module (CAN-2005-0246) - execute arbitrary code due to bugs in several SQL commands (CAN-2005-0247, CAN-2005-1409, CAN-2005-1410) This update also fixes the following non-security issues: - A race condition that allowed a transaction to be seen as committed for some purposes (eg SELECT FOR UPDATE) slightly sooner than for other purposes postgresql-pl.rpm This update fixes the following security issues: - load arbitrary shared libraries and execute code via the LOAD extension (CAN-2005-0227) - bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command (CAN-2005-0244) - a heap based buffer overflow (CAN-2005-0245) - denial of service through intagg contrib module (CAN-2005-0246) - execute arbitrary code due to bugs in several SQL commands (CAN-2005-0247, CAN-2005-1409, CAN-2005-1410) This update also fixes the following non-security issues: - A race condition that allowed a transaction to be seen as committed for some purposes (eg SELECT FOR UPDATE) slightly sooner than for other purposes postgresql-server.rpm This update fixes the following security issues: - load arbitrary shared libraries and execute code via the LOAD extension (CAN-2005-0227) - bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command (CAN-2005-0244) - a heap based buffer overflow (CAN-2005-0245) - denial of service through intagg contrib module (CAN-2005-0246) - execute arbitrary code due to bugs in several SQL commands (CAN-2005-0247, CAN-2005-1409, CAN-2005-1410) This update also fixes the following non-security issues: - A race condition that allowed a transaction to be seen as committed for some purposes (eg SELECT FOR UPDATE) slightly sooner than for other purposes postgresql-libs.rpm This update fixes the following security issues: - load arbitrary shared libraries and execute code via the LOAD extension (CAN-2005-0227) - bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command (CAN-2005-0244) - a heap based buffer overflow (CAN-2005-0245) - denial of service through intagg contrib module (CAN-2005-0246) - execute arbitrary code due to bugs in several SQL commands (CAN-2005-0247, CAN-2005-1409, CAN-2005-1410) This update also fixes the following non-security issues: - A race condition that allowed a transaction to be seen as committed for some purposes (eg SELECT FOR UPDATE) slightly sooner than for other purposes postgresql-contrib.rpm This update fixes the following security issues: - load arbitrary shared libraries and execute code via the LOAD extension (CAN-2005-0227) - bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command (CAN-2005-0244) - a heap based buffer overflow (CAN-2005-0245) - denial of service through intagg contrib module (CAN-2005-0246) - execute arbitrary code due to bugs in several SQL commands (CAN-2005-0247, CAN-2005-1409, CAN-2005-1410) This update also fixes the following non-security issues: - A race condition that allowed a transaction to be seen as committed for some purposes (eg SELECT FOR UPDATE) slightly sooner than for other purposes postgresql-devel.rpm This update fixes the following security issues: - load arbitrary shared libraries and execute code via the LOAD extension (CAN-2005-0227) - bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command (CAN-2005-0244) - a heap based buffer overflow (CAN-2005-0245) - denial of service through intagg contrib module (CAN-2005-0246) - execute arbitrary code due to bugs in several SQL commands (CAN-2005-0247, CAN-2005-1409, CAN-2005-1410) This update also fixes the following non-security issues: - A race condition that allowed a transaction to be seen as committed for some purposes (eg SELECT FOR UPDATE) slightly sooner than for other purposes quanta.rpm Kommander executed scripts also from untrusted sources without further checks. This has been disabled now. razor-agents.rpm Varioius security bugs were fixed in upstream code. This bug led to remote denial-of-service conditions due to processing malformed messages and possible stepping into infinite loops. sudo.rpm Sudo is vulnerable to a race-condition regarding command aliases like ALL that do not include a path-name. An attacker can use this bug to execute arbitrary commands. (CAN-2005-1993) tcpdump.rpm This update fixes a bug that could make tcpdump run into an infinite loop when analyzing certain specially crafted packets. This bug is considered security relevant as tcpdump is often used to analyze security relevant network traffic (CAN-2005-1279). perl-Net-Server.rpm A format string problem was found in the logging routines of the perl-Net-Server perl module collection. This could lead to a remote attacker being able to crash a server using the perl-Net-Server module. This is tracked by the Mitre CVE ID CAN-2005-1127. heimdal.rpm A buffer overflow has been fixed in the kerberos telnetd daemon which could lead to a remote user executing code as root by overflowing a buffer. dhcpcd.rpm This update fixes a denial-of-service bug that can be triggered remotely by sending a malformed package to crash the client. ruby.rpm This update fixes the following security issue: A bug in the XML-RPC library allowed remote attackers to execute arbitrary code (CAN-2005-1992). apache2-doc.rpm This update fixes the following security issues: - Requests containing both Transfer-Encoding and Content-Length allowed to perform so called "HTTP Request Smuggling" attacks (CAN-2005-2088). - An off-by-one overflow whilst printing CRL information at "LogLevel debug" which could be triggered by malicious CRLs (CAN-2005-1268). apache2-example-pages.rpm This update fixes the following security issues: - Requests containing both Transfer-Encoding and Content-Length allowed to perform so called "HTTP Request Smuggling" attacks (CAN-2005-2088). - An off-by-one overflow whilst printing CRL information at "LogLevel debug" which could be triggered by malicious CRLs (CAN-2005-1268). fetchmail.rpm This update fixes the following security issue: A buffer overflow allowed a malicious POP3 server to crash fetchmail and execute arbitrary code (CAN-2005-2335). pam_krb5.rpm This update fixes two security-related bugs in pam_krb5. The first bug is the use of the wrong UID to change the file-permissions on the ticket file which causes Kerberos to stop working correctly. The second bug can make the PAM module crash due to a uninitialized variable. apache.rpm This update fixes the following security issues: - Requests containing both Transfer-Encoding and Content-Length allowed to perform so called "HTTP Request Smuggling" attacks (CAN-2005-2088). - A buffer overflow in htpasswd mod_ssl.rpm This update fixes the following security issues: - Requests containing both Transfer-Encoding and Content-Length allowed to perform so called "HTTP Request Smuggling" attacks (CAN-2005-2088). - A buffer overflow in htpasswd squirrelmail.rpm This update fixes even more cross site scripting (XSS) bugs in squirrelmail (CAN-2004-0519). acroread.rpm Buffer overflow in a "core application plug-in" for the Adobe Reader allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors. This is tracked by the Mitre CVE ID CAN-2005-2470. pcre-devel.rpm A vulnerability was found in the PCRE regular expression handling library which allows an attacker to crash or overflow a buffer in the program by specifying a special regular expression. This is tracked by the Mitre CVE ID CAN-2005-2491. pcre.rpm A vulnerability was found in the PCRE regular expression handling library which allows an attacker to crash or overflow a buffer in the program by specifying a special regular expression. This is tracked by the Mitre CVE ID CAN-2005-2491. kismet.rpm This update fixes two bugs in kismet (CAN-2005-2626, CAN-2005-2627) that could probably be exploited to execute commands remotely. openvpn.rpm This update fixes the following security issue: With disabled TLS authentication a malicious client could close OpenVPN connections of other clients (CAN-2005-2531). gaim.rpm This update fixes a problem with an earlier GAIM security update which broke the AIM protocol. pam_ldap.rpm This update adds a missing feature to the TLS support. Previously it was possible that a password was sent in cleartext over the network even with TLS support when the connection was redirected to a slave LDAP server. This is fixed now. (CAN-2005-2069) openldap2-client.rpm This update adds a missing feature to the TLS support. Previously it was possible that a password was sent in cleartext over the network even with TLS support when the connection was redirected to a slave LDAP server. This is fixed now. (CAN-2005-2069) openldap2-devel.rpm This update adds a missing feature to the TLS support. Previously it was possible that a password was sent in cleartext over the network even with TLS support when the connection was redirected to a slave LDAP server. This is fixed now. (CAN-2005-2069) libapr0.rpm This update of apache2 fixes an integer overflow in the PCRE quantifier parsing which can be triggered by a local user through use of a carefully-crafted regex in an .htaccess file. (CAN-2005-2491). Additionally a memory consumption bug in byterange handling (CAN-2005-2728) and a bug in mod_ssl which allows to bypass the client-certificate authentication in a vhost context (CAN-2005-2700). apache2-devel.rpm This update of apache2 fixes an integer overflow in the PCRE quantifier parsing which can be triggered by a local user through use of a carefully-crafted regex in an .htaccess file. (CAN-2005-2491). Additionally a memory consumption bug in byterange handling (CAN-2005-2728) and a bug in mod_ssl which allows to bypass the client-certificate authentication in a vhost context (CAN-2005-2700). apache2.rpm This update of apache2 fixes an integer overflow in the PCRE quantifier parsing which can be triggered by a local user through use of a carefully-crafted regex in an .htaccess file. (CAN-2005-2491). Additionally a memory consumption bug in byterange handling (CAN-2005-2728) and a bug in mod_ssl which allows to bypass the client-certificate authentication in a vhost context (CAN-2005-2700). apache2-leader.rpm This update of apache2 fixes an integer overflow in the PCRE quantifier parsing which can be triggered by a local user through use of a carefully-crafted regex in an .htaccess file. (CAN-2005-2491). Additionally a memory consumption bug in byterange handling (CAN-2005-2728) and a bug in mod_ssl which allows to bypass the client-certificate authentication in a vhost context (CAN-2005-2700). apache2-prefork.rpm This update of apache2 fixes an integer overflow in the PCRE quantifier parsing which can be triggered by a local user through use of a carefully-crafted regex in an .htaccess file. (CAN-2005-2491). Additionally a memory consumption bug in byterange handling (CAN-2005-2728) and a bug in mod_ssl which allows to bypass the client-certificate authentication in a vhost context (CAN-2005-2700). apache2-metuxmpm.rpm This update of apache2 fixes an integer overflow in the PCRE quantifier parsing which can be triggered by a local user through use of a carefully-crafted regex in an .htaccess file. (CAN-2005-2491). Additionally a memory consumption bug in byterange handling (CAN-2005-2728) and a bug in mod_ssl which allows to bypass the client-certificate authentication in a vhost context (CAN-2005-2700). mysql.rpm This update fixes a stack-based buffer overflow in MySQL's init_syms function that can be exploited by authenticated users with the privilege to create user-defined functions. (CAN-2005-2558) mysql-devel.rpm This update fixes a stack-based buffer overflow in MySQL's init_syms function that can be exploited by authenticated users with the privilege to create user-defined functions. (CAN-2005-2558) mysql-Max.rpm This update fixes a stack-based buffer overflow in MySQL's init_syms function that can be exploited by authenticated users with the privilege to create user-defined functions. (CAN-2005-2558) util-linux.rpm The remount option of umount allowed local users to clear certain security relevant flags such as the nosuid flag. XFree86-server.rpm This update fixes an integer overflow in the pixmap handling (CAN-2005-2495). An attacker may be able to exploit this bug to execute code remotely. arc.rpm This updates fixes two bugs. Eric Romang discovered that the ARC archive program under Unix creates a temporary file with insecure permissions which may lead to an attacker stealing sensitive information (CAN-2005-2945). Joey Schulze discovered that the temporary file was created in an insecure fashion as well, leaving it open to a classic symlink attack (CAN-2005-2992). mozilla-calendar.rpm This update includes all security fixes from Mozilla 1.7.12: - CAN-2005-2701: Heap overrun in XBM image processing - CAN-2005-2702: Crash on "zero-width non-joiner" sequence - CAN-2005-2703: XMLHttpRequest header spoofing - CAN-2005-2704: Object spoofing using XBL - CAN-2005-2705: JavaScript integer overflow - CAN-2005-2706: Privilege escalation using about: scheme - CAN-2005-2707: Chrome window spoofing mozilla-irc.rpm This update includes all security fixes from Mozilla 1.7.12: - CAN-2005-2701: Heap overrun in XBM image processing - CAN-2005-2702: Crash on "zero-width non-joiner" sequence - CAN-2005-2703: XMLHttpRequest header spoofing - CAN-2005-2704: Object spoofing using XBL - CAN-2005-2705: JavaScript integer overflow - CAN-2005-2706: Privilege escalation using about: scheme - CAN-2005-2707: Chrome window spoofing mozilla.rpm This update includes all security fixes from Mozilla 1.7.12: - CAN-2005-2701: Heap overrun in XBM image processing - CAN-2005-2702: Crash on "zero-width non-joiner" sequence - CAN-2005-2703: XMLHttpRequest header spoofing - CAN-2005-2704: Object spoofing using XBL - CAN-2005-2705: JavaScript integer overflow - CAN-2005-2706: Privilege escalation using about: scheme - CAN-2005-2707: Chrome window spoofing mozilla-cs.rpm This update includes all security fixes from Mozilla 1.7.12: - CAN-2005-2701: Heap overrun in XBM image processing - CAN-2005-2702: Crash on "zero-width non-joiner" sequence - CAN-2005-2703: XMLHttpRequest header spoofing - CAN-2005-2704: Object spoofing using XBL - CAN-2005-2705: JavaScript integer overflow - CAN-2005-2706: Privilege escalation using about: scheme - CAN-2005-2707: Chrome window spoofing mozilla-dom-inspector.rpm This update includes all security fixes from Mozilla 1.7.12: - CAN-2005-2701: Heap overrun in XBM image processing - CAN-2005-2702: Crash on "zero-width non-joiner" sequence - CAN-2005-2703: XMLHttpRequest header spoofing - CAN-2005-2704: Object spoofing using XBL - CAN-2005-2705: JavaScript integer overflow - CAN-2005-2706: Privilege escalation using about: scheme - CAN-2005-2707: Chrome window spoofing mozilla-hu.rpm This update includes all security fixes from Mozilla 1.7.12: - CAN-2005-2701: Heap overrun in XBM image processing - CAN-2005-2702: Crash on "zero-width non-joiner" sequence - CAN-2005-2703: XMLHttpRequest header spoofing - CAN-2005-2704: Object spoofing using XBL - CAN-2005-2705: JavaScript integer overflow - CAN-2005-2706: Privilege escalation using about: scheme - CAN-2005-2707: Chrome window spoofing mozilla-venkman.rpm This update includes all security fixes from Mozilla 1.7.12: - CAN-2005-2701: Heap overrun in XBM image processing - CAN-2005-2702: Crash on "zero-width non-joiner" sequence - CAN-2005-2703: XMLHttpRequest header spoofing - CAN-2005-2704: Object spoofing using XBL - CAN-2005-2705: JavaScript integer overflow - CAN-2005-2706: Privilege escalation using about: scheme - CAN-2005-2707: Chrome window spoofing mozilla-devel.rpm This update includes all security fixes from Mozilla 1.7.12: - CAN-2005-2701: Heap overrun in XBM image processing - CAN-2005-2702: Crash on "zero-width non-joiner" sequence - CAN-2005-2703: XMLHttpRequest header spoofing - CAN-2005-2704: Object spoofing using XBL - CAN-2005-2705: JavaScript integer overflow - CAN-2005-2706: Privilege escalation using about: scheme - CAN-2005-2707: Chrome window spoofing mozilla-spellchecker.rpm This update includes all security fixes from Mozilla 1.7.12: - CAN-2005-2701: Heap overrun in XBM image processing - CAN-2005-2702: Crash on "zero-width non-joiner" sequence - CAN-2005-2703: XMLHttpRequest header spoofing - CAN-2005-2704: Object spoofing using XBL - CAN-2005-2705: JavaScript integer overflow - CAN-2005-2706: Privilege escalation using about: scheme - CAN-2005-2707: Chrome window spoofing mozilla-deat.rpm This update includes all security fixes from Mozilla 1.7.12: - CAN-2005-2701: Heap overrun in XBM image processing - CAN-2005-2702: Crash on "zero-width non-joiner" sequence - CAN-2005-2703: XMLHttpRequest header spoofing - CAN-2005-2704: Object spoofing using XBL - CAN-2005-2705: JavaScript integer overflow - CAN-2005-2706: Privilege escalation using about: scheme - CAN-2005-2707: Chrome window spoofing MozillaFirebird.rpm This Mozilla Firefox security update fixes problems before version 1.0.7. The IDN support (disabled by previous update) was reenabled. These problems include: - CAN-2005-2701: Heap overrun in XBM image processing - CAN-2005-2702: Crash on "zero-width non-joiner" sequence - CAN-2005-2703: XMLHttpRequest header spoofing - CAN-2005-2704: Object spoofing using XBL - CAN-2005-2705: JavaScript integer overflow - CAN-2005-2706: Privilege escalation using about: scheme - CAN-2005-2707: Chrome window spoofing problem. XFree86-Xvnc.rpm This update fixes an integer overflow in the pixmap handling (CAN-2005-2495). An attacker may be able to exploit this bug to execute code remotely. liby2util.rpm Rene "l00m" Fischer found two problem in the handling of package repositories. - The remote repositories were copied with permissions and ownerships intact. If the remote repository was owned by a user or had problematic permissions, these ownership and permissions were copied over to the system. If these included world writeable permissions local users could overwrite package meta files. This problem is not present when installing from CD or a correctly set up network source. - The YaST package handling had a bufferoverflow which could be used by attackers having access to the meta data (for instance due to above permission problem) to potentially execute code. These problems have been fixed with this update. liby2util-devel.rpm Rene "l00m" Fischer found two problem in the handling of package repositories. - The remote repositories were copied with permissions and ownerships intact. If the remote repository was owned by a user or had problematic permissions, these ownership and permissions were copied over to the system. If these included world writeable permissions local users could overwrite package meta files. This problem is not present when installing from CD or a correctly set up network source. - The YaST package handling had a bufferoverflow which could be used by attackers having access to the meta data (for instance due to above permission problem) to potentially execute code. These problems have been fixed with this update. texinfo.rpm This update improves the handling of temporary files. Previous versions can be exploited by local users to overwrite arbitrary files. (CAN-2005-3011) cfengine.rpm This update of cfengine improves the handling of temporary files. This bug can be exploited locally and probably be used to escalate privileges. (CAN-2005-2960) abiword2.rpm This update of abiword fixes several buffer overflows that can be triggered by parsing malformated RTF documents (CAN-2005-2964). Thanks to Chris Evans. xine-lib.rpm When you use xine or gxine to play a CD, the programs will connect to a CDDB server to retrieve the record's artist/band and title as well as the song titles. The programs write this information to a cache file, and the code in xine-lib that performs this action suffers from a format string security bug, allowing remote execution of arbitrary code. This patch fixes this problem. (CAN-2005-2967) imap-lib.rpm The client part of the University of Washington IMAP implementation is prone to a buffer overflow while parsing mailbox names. This bug can probably be exploited by a remote attacker to execute arbitrary code with the privileges of the user running the affected mail client. (CAN-2005-2933) mailsync.rpm The client part of the University of Washington IMAP implementation is prone to a buffer overflow while parsing mailbox names. This bug can probably be exploited by a remote attacker to execute arbitrary code with the privileges of the user running the affected mail client. (CAN-2005-2933) imap-devel.rpm The client part of the University of Washington IMAP implementation is prone to a buffer overflow while parsing mailbox names. This bug can probably be exploited by a remote attacker to execute arbitrary code with the privileges of the user running the affected mail client. (CAN-2005-2933) openssl-devel.rpm This update fixes a protocol downgrading attack in openssl which allows a man-in-the-middle attacker to force the usage of SSLv2. This happens due to the work-around code of SSL_OP_MSIE_SSLV2_RSA_PADDING which is included in SSL_OP_ALL. (CAN-2005-2969) openssl.rpm This update fixes a protocol downgrading attack in openssl which allows a man-in-the-middle attacker to force the usage of SSLv2. This happens due to the work-around code of SSL_OP_MSIE_SSLV2_RSA_PADDING which is included in SSL_OP_ALL. (CAN-2005-2969) xli.rpm This update fixes several buffer overflows in xli which can be exploited by malformated image file to execute arbitrary code. (CAN-2005-3178) permissions.rpm It is technically impossible to change permissions files in of world writeable directories that don't have the sticky bit set in a secure way. This update therefore removes /var/lib/xmcd/discog from /etc/permissions*. Furthermore permissions handling of files below /var/games is removed. To be able to change permissions of directories in world writeable directories in a secure way a slash must be appended to the path in the /etc/permssions* file. This update corrects missing slashes amongst others for /usr/src/packages/*. xmcd.rpm It is technically impossible to change permissions files in of world writeable directories that don't have the sticky bit set in a secure way. This update therefore removes /var/lib/xmcd/discog from /etc/permissions*. Furthermore permissions handling of files below /var/games is removed. To be able to change permissions of directories in world writeable directories in a secure way a slash must be appended to the path in the /etc/permssions* file. This update corrects missing slashes amongst others for /usr/src/packages/*. lynx.rpm This update fixes a buffer overflow in function HTrjis() that occurs while processing NNTP headers. An attacker can exploit this remotely by persuading the victim user to connect to a NNTP server which includes a malformated article to execute arbitrary code. (CAN-2005-3120) ethereal.rpm This update upgrades ethereal to version 0.10.13 to fix several security related bugs ranging from crashes to arbitrary code execution. (CVE-2005-3241, CVE-2005-3242, CVE-2005-3243, CVE-2005-3244, CVE-2005-3245, CVE-2005-3246, CVE-2005-3247, CVE-2005-3248, CVE-2005-3249, CVE-2005-3184, CVE-2005-3313) shadow.rpm Thomas Gerisch reported a local privilege escalation in the 'chfn' program caused by insufficient argument checking. This problem allows a local attacker to easily gain root privileges. libungif.rpm This update fixes the following security issues: - specially crafted GIF files could crash applications (CVE-2005-2974). - specially crafted GIF files could overwrite memory which potentially allowed to execute arbitrary code (CVE-2005-3350). snort.rpm A buffer overflow in snort's Back Orifice preprocessor code will be fixed by this update. This bug can be exploited by remote attackers to execute arbitrary code with the privileges of the snort daemon. (CVE-2005-3252) gpsdrive.rpm This update fixes the following security problem: A format string bug in friendsd2 allowed an attacker to execute arbitrary code (CVE-2005-3523). flash-player.rpm This update upgrades flash-player to version 7.0.25 to fix a buffer overflow (CAN-2005-2628). libgda.rpm This update fixes the following security problem: libgda contained two format string bugs in logging routines. Those bugs could potentially indirectly lead to arbitrary code execution via applications that link against libgda and supply data to libgda (CAN-2005-2958). libgda-devel.rpm This update fixes the following security problem: libgda contained two format string bugs in logging routines. Those bugs could potentially indirectly lead to arbitrary code execution via applications that link against libgda and supply data to libgda (CAN-2005-2958). gtk2.rpm This update fixes the following security problem: a heap overflow in the XPM reader allowed attackers to execute arbitrary code via specially crafted XPM images (CVE-2005-3186, CVE-2005-2976). gtk2-devel.rpm This update fixes the following security problem: a heap overflow in the XPM reader allowed attackers to execute arbitrary code via specially crafted XPM images (CVE-2005-3186, CVE-2005-2976). gdk-pixbuf-devel.rpm This update fixes the following security problem: a heap overflow in the XPM reader allowed attackers to execute arbitrary code via specially crafted XPM images (CVE-2005-3186, CVE-2005-2975, CVE-2005-2976). gdk-pixbuf.rpm This update fixes the following security problem: a heap overflow in the XPM reader allowed attackers to execute arbitrary code via specially crafted XPM images (CVE-2005-3186, CVE-2005-2975, CVE-2005-2976). sylpheed.rpm This update fixes a buffer overflow when importing LDIF, mutt and pine addressbooks (CVE-2005-3354). mozilla-mail.rpm This update fixes the following security problem: Upon sending an encrypted mail enigmail could accidently encrypt it for the wrong recipient (CVE-2005-3256). squid.rpm This update of squid fixes some bugs that lead to crashes. This bugs were introduced by a previous security-update (SUSE-SA:2005:053). Please note that this is a version upgrade so you should do the following steps: - delete the old cache - adapt the configuration file to new options - "clientProcessHit: Vary object loop!" message can be ignored apache2-worker.rpm This update fixes a memory leak in apache2-worker that allowed attackers to exhaust all available memory (CVE-2005-2970). opera.rpm This update fixes the following security problem: insufficient quoting of shell meta characters in the opera start script allowed to execute arbitrary commands if URLs with such characters were passed to the script (CVE-2005-3750). This updates fixes the previous broken Opera 8.51 update. netpbm.rpm This update fixes a buffer overflow in the RGBA-palette code. This bug can be abused to trigger a denial-or-service attack by feeding untrusted data to "pnmtopng -alpha" (maybe via a remote service like a CGI, MUA, etc.). The execution of arbitrary code is theoretically possible but very unlikely. Another possible buffer overflow that can occur while handling a textline was fixed too. otrs.rpm This patch updates OTRS to the current stable release of the particular major OTRS version shipped with SuSE Linux. The update is required to solve the following issues: CVE-2005-3893 Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action. CVE-2005-3894 Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the QueueID parameter and (2) Action parameters. CVE-2005-3895 Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, when AttachmentDownloadType is set to inline, renders text/html e-mail attachments as HTML in the browser when the queue moderator attempts to download the attachment, which allows remote attackers to execute arbitrary web script or HTML. NOTE: this particular issue is referred to as XSS by some sources. k_smp4G.rpm This kernel update contains several security fixes and some bugfixes, listed below: Security fixes: - CVE-2005-3783: A check in ptrace(2) handling that finds out if a process is attaching to itself was incorrect and could be used by a local attacker to crash the machine. - CVE-2005-3044: Missing sockfd_put() calls in routing_ioctl() leaked file handles which in turn could exhaust system memory. - CVE-2005-2490: A stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 and 2.4 allowed local users execute arbitrary code by calling sendmsg and modifying the message contents in another thread. - CVE-2005-3806: A bug in IPv6 flowlabel handling code could be used by a local attacker to free non-allocated memory and in turn corrupt kernel memory and likely crash the machine. - CVE-2005-3275: The NAT code in Linux kernel incorrectly declares a variable to be static, which allows remote attackers to cause a denial of service (memory corruption) by causing two packets for the same protocol to be NATed at the same time. - CVE-2005-2457: A problem in decompression of files on "zisofs" filesystem was fixed. - CVE-2005-2458: A potential buffer overflow in the zlib decompression handling in the kernel was fixed. - CVE-2005-2459: Some return codes in zlib decoding were fixed which could have led to an attacker crashing the kernel. Non security bugfixes: - Fixed a race on the count of unused dcache entries. - Fixed the "treason uncloaked" kernel messages that were caused by a stale pred_flags variable when the TCP snd_wnd changes. - Allow filesystems to return NFSERR_JUKEBOX to the server by returning -ETIMEDOUT. - Documented SCSI device scanning parameters. - Added an NFS ACL fix for Solaris VxFS compatibility. - Fixed an incorrect error return in ip_conntrack_expect_related. - Add EMC Invista to SCSI LUN blacklist. - A USB problem with the OHCI chipset was fixed. - When coredumping, the %fs and %gs register are now stored correctly. - The TSC (timestampcount) register is now used as monotonic source for the hangcheck timer. kernel-source.rpm This kernel update contains several security fixes and some bugfixes, listed below: Security fixes: - CVE-2005-3783: A check in ptrace(2) handling that finds out if a process is attaching to itself was incorrect and could be used by a local attacker to crash the machine. - CVE-2005-3044: Missing sockfd_put() calls in routing_ioctl() leaked file handles which in turn could exhaust system memory. - CVE-2005-2490: A stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 and 2.4 allowed local users execute arbitrary code by calling sendmsg and modifying the message contents in another thread. - CVE-2005-3806: A bug in IPv6 flowlabel handling code could be used by a local attacker to free non-allocated memory and in turn corrupt kernel memory and likely crash the machine. - CVE-2005-3275: The NAT code in Linux kernel incorrectly declares a variable to be static, which allows remote attackers to cause a denial of service (memory corruption) by causing two packets for the same protocol to be NATed at the same time. - CVE-2005-2457: A problem in decompression of files on "zisofs" filesystem was fixed. - CVE-2005-2458: A potential buffer overflow in the zlib decompression handling in the kernel was fixed. - CVE-2005-2459: Some return codes in zlib decoding were fixed which could have led to an attacker crashing the kernel. Non security bugfixes: - Fixed a race on the count of unused dcache entries. - Fixed the "treason uncloaked" kernel messages that were caused by a stale pred_flags variable when the TCP snd_wnd changes. - Allow filesystems to return NFSERR_JUKEBOX to the server by returning -ETIMEDOUT. - Documented SCSI device scanning parameters. - Added an NFS ACL fix for Solaris VxFS compatibility. - Fixed an incorrect error return in ip_conntrack_expect_related. - Add EMC Invista to SCSI LUN blacklist. - A USB problem with the OHCI chipset was fixed. - When coredumping, the %fs and %gs register are now stored correctly. - The TSC (timestampcount) register is now used as monotonic source for the hangcheck timer. ltmodem.rpm This kernel update contains several security fixes and some bugfixes, listed below: Security fixes: - CVE-2005-3783: A check in ptrace(2) handling that finds out if a process is attaching to itself was incorrect and could be used by a local attacker to crash the machine. - CVE-2005-3044: Missing sockfd_put() calls in routing_ioctl() leaked file handles which in turn could exhaust system memory. - CVE-2005-2490: A stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 and 2.4 allowed local users execute arbitrary code by calling sendmsg and modifying the message contents in another thread. - CVE-2005-3806: A bug in IPv6 flowlabel handling code could be used by a local attacker to free non-allocated memory and in turn corrupt kernel memory and likely crash the machine. - CVE-2005-3275: The NAT code in Linux kernel incorrectly declares a variable to be static, which allows remote attackers to cause a denial of service (memory corruption) by causing two packets for the same protocol to be NATed at the same time. - CVE-2005-2457: A problem in decompression of files on "zisofs" filesystem was fixed. - CVE-2005-2458: A potential buffer overflow in the zlib decompression handling in the kernel was fixed. - CVE-2005-2459: Some return codes in zlib decoding were fixed which could have led to an attacker crashing the kernel. Non security bugfixes: - Fixed a race on the count of unused dcache entries. - Fixed the "treason uncloaked" kernel messages that were caused by a stale pred_flags variable when the TCP snd_wnd changes. - Allow filesystems to return NFSERR_JUKEBOX to the server by returning -ETIMEDOUT. - Documented SCSI device scanning parameters. - Added an NFS ACL fix for Solaris VxFS compatibility. - Fixed an incorrect error return in ip_conntrack_expect_related. - Add EMC Invista to SCSI LUN blacklist. - A USB problem with the OHCI chipset was fixed. - When coredumping, the %fs and %gs register are now stored correctly. - The TSC (timestampcount) register is now used as monotonic source for the hangcheck timer. Intel-536ep.rpm This kernel update contains several security fixes and some bugfixes, listed below: Security fixes: - CVE-2005-3783: A check in ptrace(2) handling that finds out if a process is attaching to itself was incorrect and could be used by a local attacker to crash the machine. - CVE-2005-3044: Missing sockfd_put() calls in routing_ioctl() leaked file handles which in turn could exhaust system memory. - CVE-2005-2490: A stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 and 2.4 allowed local users execute arbitrary code by calling sendmsg and modifying the message contents in another thread. - CVE-2005-3806: A bug in IPv6 flowlabel handling code could be used by a local attacker to free non-allocated memory and in turn corrupt kernel memory and likely crash the machine. - CVE-2005-3275: The NAT code in Linux kernel incorrectly declares a variable to be static, which allows remote attackers to cause a denial of service (memory corruption) by causing two packets for the same protocol to be NATed at the same time. - CVE-2005-2457: A problem in decompression of files on "zisofs" filesystem was fixed. - CVE-2005-2458: A potential buffer overflow in the zlib decompression handling in the kernel was fixed. - CVE-2005-2459: Some return codes in zlib decoding were fixed which could have led to an attacker crashing the kernel. Non security bugfixes: - Fixed a race on the count of unused dcache entries. - Fixed the "treason uncloaked" kernel messages that were caused by a stale pred_flags variable when the TCP snd_wnd changes. - Allow filesystems to return NFSERR_JUKEBOX to the server by returning -ETIMEDOUT. - Documented SCSI device scanning parameters. - Added an NFS ACL fix for Solaris VxFS compatibility. - Fixed an incorrect error return in ip_conntrack_expect_related. - Add EMC Invista to SCSI LUN blacklist. - A USB problem with the OHCI chipset was fixed. - When coredumping, the %fs and %gs register are now stored correctly. - The TSC (timestampcount) register is now used as monotonic source for the hangcheck timer. k_smp.rpm This kernel update contains several security fixes and some bugfixes, listed below: Security fixes: - CVE-2005-3783: A check in ptrace(2) handling that finds out if a process is attaching to itself was incorrect and could be used by a local attacker to crash the machine. - CVE-2005-3044: Missing sockfd_put() calls in routing_ioctl() leaked file handles which in turn could exhaust system memory. - CVE-2005-2490: A stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 and 2.4 allowed local users execute arbitrary code by calling sendmsg and modifying the message contents in another thread. - CVE-2005-3806: A bug in IPv6 flowlabel handling code could be used by a local attacker to free non-allocated memory and in turn corrupt kernel memory and likely crash the machine. - CVE-2005-3275: The NAT code in Linux kernel incorrectly declares a variable to be static, which allows remote attackers to cause a denial of service (memory corruption) by causing two packets for the same protocol to be NATed at the same time. - CVE-2005-2457: A problem in decompression of files on "zisofs" filesystem was fixed. - CVE-2005-2458: A potential buffer overflow in the zlib decompression handling in the kernel was fixed. - CVE-2005-2459: Some return codes in zlib decoding were fixed which could have led to an attacker crashing the kernel. Non security bugfixes: - Fixed a race on the count of unused dcache entries. - Fixed the "treason uncloaked" kernel messages that were caused by a stale pred_flags variable when the TCP snd_wnd changes. - Allow filesystems to return NFSERR_JUKEBOX to the server by returning -ETIMEDOUT. - Documented SCSI device scanning parameters. - Added an NFS ACL fix for Solaris VxFS compatibility. - Fixed an incorrect error return in ip_conntrack_expect_related. - Add EMC Invista to SCSI LUN blacklist. - A USB problem with the OHCI chipset was fixed. - When coredumping, the %fs and %gs register are now stored correctly. - The TSC (timestampcount) register is now used as monotonic source for the hangcheck timer. k_athlon.rpm This kernel update contains several security fixes and some bugfixes, listed below: Security fixes: - CVE-2005-3783: A check in ptrace(2) handling that finds out if a process is attaching to itself was incorrect and could be used by a local attacker to crash the machine. - CVE-2005-3044: Missing sockfd_put() calls in routing_ioctl() leaked file handles which in turn could exhaust system memory. - CVE-2005-2490: A stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 and 2.4 allowed local users execute arbitrary code by calling sendmsg and modifying the message contents in another thread. - CVE-2005-3806: A bug in IPv6 flowlabel handling code could be used by a local attacker to free non-allocated memory and in turn corrupt kernel memory and likely crash the machine. - CVE-2005-3275: The NAT code in Linux kernel incorrectly declares a variable to be static, which allows remote attackers to cause a denial of service (memory corruption) by causing two packets for the same protocol to be NATed at the same time. - CVE-2005-2457: A problem in decompression of files on "zisofs" filesystem was fixed. - CVE-2005-2458: A potential buffer overflow in the zlib decompression handling in the kernel was fixed. - CVE-2005-2459: Some return codes in zlib decoding were fixed which could have led to an attacker crashing the kernel. Non security bugfixes: - Fixed a race on the count of unused dcache entries. - Fixed the "treason uncloaked" kernel messages that were caused by a stale pred_flags variable when the TCP snd_wnd changes. - Allow filesystems to return NFSERR_JUKEBOX to the server by returning -ETIMEDOUT. - Documented SCSI device scanning parameters. - Added an NFS ACL fix for Solaris VxFS compatibility. - Fixed an incorrect error return in ip_conntrack_expect_related. - Add EMC Invista to SCSI LUN blacklist. - A USB problem with the OHCI chipset was fixed. - When coredumping, the %fs and %gs register are now stored correctly. - The TSC (timestampcount) register is now used as monotonic source for the hangcheck timer. k_deflt.rpm This kernel update contains several security fixes and some bugfixes, listed below: Security fixes: - CVE-2005-3783: A check in ptrace(2) handling that finds out if a process is attaching to itself was incorrect and could be used by a local attacker to crash the machine. - CVE-2005-3044: Missing sockfd_put() calls in routing_ioctl() leaked file handles which in turn could exhaust system memory. - CVE-2005-2490: A stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 and 2.4 allowed local users execute arbitrary code by calling sendmsg and modifying the message contents in another thread. - CVE-2005-3806: A bug in IPv6 flowlabel handling code could be used by a local attacker to free non-allocated memory and in turn corrupt kernel memory and likely crash the machine. - CVE-2005-3275: The NAT code in Linux kernel incorrectly declares a variable to be static, which allows remote attackers to cause a denial of service (memory corruption) by causing two packets for the same protocol to be NATed at the same time. - CVE-2005-2457: A problem in decompression of files on "zisofs" filesystem was fixed. - CVE-2005-2458: A potential buffer overflow in the zlib decompression handling in the kernel was fixed. - CVE-2005-2459: Some return codes in zlib decoding were fixed which could have led to an attacker crashing the kernel. Non security bugfixes: - Fixed a race on the count of unused dcache entries. - Fixed the "treason uncloaked" kernel messages that were caused by a stale pred_flags variable when the TCP snd_wnd changes. - Allow filesystems to return NFSERR_JUKEBOX to the server by returning -ETIMEDOUT. - Documented SCSI device scanning parameters. - Added an NFS ACL fix for Solaris VxFS compatibility. - Fixed an incorrect error return in ip_conntrack_expect_related. - Add EMC Invista to SCSI LUN blacklist. - A USB problem with the OHCI chipset was fixed. - When coredumping, the %fs and %gs register are now stored correctly. - The TSC (timestampcount) register is now used as monotonic source for the hangcheck timer. k_um.rpm This kernel update contains several security fixes and some bugfixes, listed below: Security fixes: - CVE-2005-3783: A check in ptrace(2) handling that finds out if a process is attaching to itself was incorrect and could be used by a local attacker to crash the machine. - CVE-2005-3044: Missing sockfd_put() calls in routing_ioctl() leaked file handles which in turn could exhaust system memory. - CVE-2005-2490: A stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 and 2.4 allowed local users execute arbitrary code by calling sendmsg and modifying the message contents in another thread. - CVE-2005-3806: A bug in IPv6 flowlabel handling code could be used by a local attacker to free non-allocated memory and in turn corrupt kernel memory and likely crash the machine. - CVE-2005-3275: The NAT code in Linux kernel incorrectly declares a variable to be static, which allows remote attackers to cause a denial of service (memory corruption) by causing two packets for the same protocol to be NATed at the same time. - CVE-2005-2457: A problem in decompression of files on "zisofs" filesystem was fixed. - CVE-2005-2458: A potential buffer overflow in the zlib decompression handling in the kernel was fixed. - CVE-2005-2459: Some return codes in zlib decoding were fixed which could have led to an attacker crashing the kernel. Non security bugfixes: - Fixed a race on the count of unused dcache entries. - Fixed the "treason uncloaked" kernel messages that were caused by a stale pred_flags variable when the TCP snd_wnd changes. - Allow filesystems to return NFSERR_JUKEBOX to the server by returning -ETIMEDOUT. - Documented SCSI device scanning parameters. - Added an NFS ACL fix for Solaris VxFS compatibility. - Fixed an incorrect error return in ip_conntrack_expect_related. - Add EMC Invista to SCSI LUN blacklist. - A USB problem with the OHCI chipset was fixed. - When coredumping, the %fs and %gs register are now stored correctly. - The TSC (timestampcount) register is now used as monotonic source for the hangcheck timer. Intel-v92ham.rpm This kernel update contains several security fixes and some bugfixes, listed below: Security fixes: - CVE-2005-3783: A check in ptrace(2) handling that finds out if a process is attaching to itself was incorrect and could be used by a local attacker to crash the machine. - CVE-2005-3044: Missing sockfd_put() calls in routing_ioctl() leaked file handles which in turn could exhaust system memory. - CVE-2005-2490: A stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 and 2.4 allowed local users execute arbitrary code by calling sendmsg and modifying the message contents in another thread. - CVE-2005-3806: A bug in IPv6 flowlabel handling code could be used by a local attacker to free non-allocated memory and in turn corrupt kernel memory and likely crash the machine. - CVE-2005-3275: The NAT code in Linux kernel incorrectly declares a variable to be static, which allows remote attackers to cause a denial of service (memory corruption) by causing two packets for the same protocol to be NATed at the same time. - CVE-2005-2457: A problem in decompression of files on "zisofs" filesystem was fixed. - CVE-2005-2458: A potential buffer overflow in the zlib decompression handling in the kernel was fixed. - CVE-2005-2459: Some return codes in zlib decoding were fixed which could have led to an attacker crashing the kernel. Non security bugfixes: - Fixed a race on the count of unused dcache entries. - Fixed the "treason uncloaked" kernel messages that were caused by a stale pred_flags variable when the TCP snd_wnd changes. - Allow filesystems to return NFSERR_JUKEBOX to the server by returning -ETIMEDOUT. - Documented SCSI device scanning parameters. - Added an NFS ACL fix for Solaris VxFS compatibility. - Fixed an incorrect error return in ip_conntrack_expect_related. - Add EMC Invista to SCSI LUN blacklist. - A USB problem with the OHCI chipset was fixed. - When coredumping, the %fs and %gs register are now stored correctly. - The TSC (timestampcount) register is now used as monotonic source for the hangcheck timer. mod_php4-core.rpm This update fixes crashes with mod_rewrite caused by the previous security update. This update fixes the following security issues: - Bugs in the exif code could lead to a crash (CVE-2005-3353) - A bug in parse_str() could lead to activation of register_globals (CVE-2005-3389) - File uploads could overwrite $GLOBALS (CVE-2005-3390) - Missing safe_mode checks in image processing and cURL functions (CVE-2005-3391) - Information leakage via the virtual() function (CVE-2005-3392) - Bugs in the mb_send_mail() function allowed to inject arbitrary addresses into the 'To' header (CVE-2005-3883) mod_php4-devel.rpm This update fixes crashes with mod_rewrite caused by the previous security update. This update fixes the following security issues: - Bugs in the exif code could lead to a crash (CVE-2005-3353) - A bug in parse_str() could lead to activation of register_globals (CVE-2005-3389) - File uploads could overwrite $GLOBALS (CVE-2005-3390) - Missing safe_mode checks in image processing and cURL functions (CVE-2005-3391) - Information leakage via the virtual() function (CVE-2005-3392) - Bugs in the mb_send_mail() function allowed to inject arbitrary addresses into the 'To' header (CVE-2005-3883) mod_php4-servlet.rpm This update fixes crashes with mod_rewrite caused by the previous security update. This update fixes the following security issues: - Bugs in the exif code could lead to a crash (CVE-2005-3353) - A bug in parse_str() could lead to activation of register_globals (CVE-2005-3389) - File uploads could overwrite $GLOBALS (CVE-2005-3390) - Missing safe_mode checks in image processing and cURL functions (CVE-2005-3391) - Information leakage via the virtual() function (CVE-2005-3392) - Bugs in the mb_send_mail() function allowed to inject arbitrary addresses into the 'To' header (CVE-2005-3883) apache2-mod_php4.rpm This update fixes crashes with mod_rewrite caused by the previous security update. This update fixes the following security issues: - Bugs in the exif code could lead to a crash (CVE-2005-3353) - A bug in parse_str() could lead to activation of register_globals (CVE-2005-3389) - File uploads could overwrite $GLOBALS (CVE-2005-3390) - Missing safe_mode checks in image processing and cURL functions (CVE-2005-3391) - Information leakage via the virtual() function (CVE-2005-3392) - Bugs in the mb_send_mail() function allowed to inject arbitrary addresses into the 'To' header (CVE-2005-3883) mod_php4.rpm This update fixes crashes with mod_rewrite caused by the previous security update. This update fixes the following security issues: - Bugs in the exif code could lead to a crash (CVE-2005-3353) - A bug in parse_str() could lead to activation of register_globals (CVE-2005-3389) - File uploads could overwrite $GLOBALS (CVE-2005-3390) - Missing safe_mode checks in image processing and cURL functions (CVE-2005-3391) - Information leakage via the virtual() function (CVE-2005-3392) - Bugs in the mb_send_mail() function allowed to inject arbitrary addresses into the 'To' header (CVE-2005-3883) mod_php4-aolserver.rpm This update fixes crashes with mod_rewrite caused by the previous security update. This update fixes the following security issues: - Bugs in the exif code could lead to a crash (CVE-2005-3353) - A bug in parse_str() could lead to activation of register_globals (CVE-2005-3389) - File uploads could overwrite $GLOBALS (CVE-2005-3390) - Missing safe_mode checks in image processing and cURL functions (CVE-2005-3391) - Information leakage via the virtual() function (CVE-2005-3392) - Bugs in the mb_send_mail() function allowed to inject arbitrary addresses into the 'To' header (CVE-2005-3883) perl.rpm An integer overflow in the format string functionality in Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap (CVE-2005-3962). This requires the attacker to be able to supply formatstrings to the application, which unfortunately is true for some web applications. horde.rpm This update fixes the following security problem: Bugs in error messages allowed cross-site scripting (CVE-2005-3570). java2-jre.rpm Unspecified vulnerabilities within the JRE allow attackers to execute arbitrary code outside the sandbox. The IDs CVE-2005-3904, CVE-2005-3905 and CVE-2005-3906 have been assigned to this issue. java2.rpm Unspecified vulnerabilities within the JRE allow attackers to execute arbitrary code outside the sandbox. The IDs CVE-2005-3904, CVE-2005-3905 and CVE-2005-3906 have been assigned to this issue. mailman.rpm This update fixes the following security problem: a bug when decoding UTF-8 could crash mailman (CAN-2004-1177). Additionally the dependency on python-xml that was introduced by the previous update has been removed again. koffice-wordprocessing.rpm This update fixes the following security problem: Integer overflows in the contained xpdf code potentially allowed to execute arbitrary code via specially crafted PDF files (CVE-2005-3191, CVE-2005-3192, CVE-2005-3193). xpdf.rpm This update fixes the following security problem: Integer overflows in the contained xpdf code potentially allowed to execute arbitrary code via specially crafted PDF files (CVE-2005-3191, CVE-2005-3192, CVE-2005-3193). pdftohtml.rpm Integer overflows in the contained xpdf code potentially allowed to execute arbitrary code via specially crafted PDF files (CVE-2005-3191, CVE-2005-3192). cups-client.rpm Integer overflows in pdftops (contains xpdf code) potentially allowed to execute arbitrary code via specially crafted PDF files (CVE-2005-3191, CVE-2005-3192). cups-devel.rpm Integer overflows in pdftops (contains xpdf code) potentially allowed to execute arbitrary code via specially crafted PDF files (CVE-2005-3191, CVE-2005-3192). cups.rpm Integer overflows in pdftops (contains xpdf code) potentially allowed to execute arbitrary code via specially crafted PDF files (CVE-2005-3191, CVE-2005-3192). foomatic-filters.rpm Integer overflows in pdftops (contains xpdf code) potentially allowed to execute arbitrary code via specially crafted PDF files (CVE-2005-3191, CVE-2005-3192). cups-libs.rpm Integer overflows in pdftops (contains xpdf code) potentially allowed to execute arbitrary code via specially crafted PDF files (CVE-2005-3191, CVE-2005-3192). procmail.rpm Fix the biff/comsat notification behaviour of procmail introduced with the last change for avoiding truncated folder if reached quota.