[El-errata] ELSA-2011-0486 Moderate: Oracle Linux 5 xmlsec1 security and bug fix update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Wed May 4 21:56:59 PDT 2011


Oracle Linux Security Advisory ELSA-2011-0486

https://rhn.redhat.com/errata/RHSA-2011-0486.html

The following updated rpms for Oracle Linux 5 have been uploaded to the 
Unbreakable Linux Network:

i386:
xmlsec1-1.2.9-8.1.2.i386.rpm
xmlsec1-devel-1.2.9-8.1.2.i386.rpm
xmlsec1-gnutls-1.2.9-8.1.2.i386.rpm
xmlsec1-gnutls-devel-1.2.9-8.1.2.i386.rpm
xmlsec1-nss-1.2.9-8.1.2.i386.rpm
xmlsec1-nss-devel-1.2.9-8.1.2.i386.rpm
xmlsec1-openssl-1.2.9-8.1.2.i386.rpm
xmlsec1-openssl-devel-1.2.9-8.1.2.i386.rpm

x86_64:
xmlsec1-1.2.9-8.1.2.i386.rpm
xmlsec1-1.2.9-8.1.2.x86_64.rpm
xmlsec1-devel-1.2.9-8.1.2.i386.rpm
xmlsec1-devel-1.2.9-8.1.2.x86_64.rpm
xmlsec1-gnutls-1.2.9-8.1.2.i386.rpm
xmlsec1-gnutls-1.2.9-8.1.2.x86_64.rpm
xmlsec1-gnutls-devel-1.2.9-8.1.2.i386.rpm
xmlsec1-gnutls-devel-1.2.9-8.1.2.x86_64.rpm
xmlsec1-nss-1.2.9-8.1.2.i386.rpm
xmlsec1-nss-1.2.9-8.1.2.x86_64.rpm
xmlsec1-nss-devel-1.2.9-8.1.2.i386.rpm
xmlsec1-nss-devel-1.2.9-8.1.2.x86_64.rpm
xmlsec1-openssl-1.2.9-8.1.2.i386.rpm
xmlsec1-openssl-1.2.9-8.1.2.x86_64.rpm
xmlsec1-openssl-devel-1.2.9-8.1.2.i386.rpm
xmlsec1-openssl-devel-1.2.9-8.1.2.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol5/SRPMS-updates/xmlsec1-1.2.9-8.1.2.src.rpm


Description of changes:


[1.2.9-8.1.2]
- disable xslt i/o support in library, tools and examples, CVE-2011-1425
- Resolves: rhbz#694124
- limit the paths used for searching the security library loaded dynamically






More information about the El-errata mailing list