[El-errata] ELSA-2012-0451 Important: Oracle Linux 5 rpm security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Tue Apr 3 22:46:38 PDT 2012


Oracle Linux Security Advisory ELSA-2012-0451

https://rhn.redhat.com/errata/RHSA-2012-0451.html

The following updated rpms for Oracle Linux 5 have been uploaded to the 
Unbreakable Linux Network:

i386:
popt-1.10.2.3-28.0.1.el5_8.i386.rpm
rpm-4.4.2.3-28.0.1.el5_8.i386.rpm
rpm-apidocs-4.4.2.3-28.0.1.el5_8.i386.rpm
rpm-build-4.4.2.3-28.0.1.el5_8.i386.rpm
rpm-devel-4.4.2.3-28.0.1.el5_8.i386.rpm
rpm-libs-4.4.2.3-28.0.1.el5_8.i386.rpm
rpm-python-4.4.2.3-28.0.1.el5_8.i386.rpm

x86_64:
popt-1.10.2.3-28.0.1.el5_8.i386.rpm
popt-1.10.2.3-28.0.1.el5_8.x86_64.rpm
rpm-4.4.2.3-28.0.1.el5_8.x86_64.rpm
rpm-apidocs-4.4.2.3-28.0.1.el5_8.x86_64.rpm
rpm-build-4.4.2.3-28.0.1.el5_8.x86_64.rpm
rpm-devel-4.4.2.3-28.0.1.el5_8.i386.rpm
rpm-devel-4.4.2.3-28.0.1.el5_8.x86_64.rpm
rpm-libs-4.4.2.3-28.0.1.el5_8.i386.rpm
rpm-libs-4.4.2.3-28.0.1.el5_8.x86_64.rpm
rpm-python-4.4.2.3-28.0.1.el5_8.x86_64.rpm

ia64:
popt-1.10.2.3-28.0.1.el5_8.ia64.rpm
rpm-4.4.2.3-28.0.1.el5_8.ia64.rpm
rpm-apidocs-4.4.2.3-28.0.1.el5_8.ia64.rpm
rpm-build-4.4.2.3-28.0.1.el5_8.ia64.rpm
rpm-devel-4.4.2.3-28.0.1.el5_8.ia64.rpm
rpm-libs-4.4.2.3-28.0.1.el5_8.ia64.rpm
rpm-python-4.4.2.3-28.0.1.el5_8.ia64.rpm


SRPMS:
http://oss.oracle.com/ol5/SRPMS-updates/rpm-4.4.2.3-28.0.1.el5_8.src.rpm


Description of changes:

[4.4.2.3-28.0.1.el5_8]
- Add missing files in /usr/share/doc/

[4.4.2.3-28]
- Proper region tag validation on package/header read (CVE-2012-0060)
- Double-check region size against header size (CVE-2012-0061)
- Validate negated offsets too in headerVerifyInfo() (CVE-2012-0815)





More information about the El-errata mailing list