[El-errata] ELSA-2012-0451 Important: Oracle Linux 4 rpm security update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Tue Apr 17 10:17:14 PDT 2012
Oracle Linux Security Advisory ELSA-2012-0451
https://rhn.redhat.com/errata/RHSA-2012-0451.html
The following updated rpms for Oracle Linux 4 have been uploaded to the
Unbreakable Linux Network:
i386:
popt-1.9.1-36_nonptl.el4.i386.rpm
rpm-4.3.3-36_nonptl.el4.i386.rpm
rpm-build-4.3.3-36_nonptl.el4.i386.rpm
rpm-devel-4.3.3-36_nonptl.el4.i386.rpm
rpm-libs-4.3.3-36_nonptl.el4.i386.rpm
rpm-python-4.3.3-36_nonptl.el4.i386.rpm
x86_64:
popt-1.9.1-36_nonptl.el4.i386.rpm
popt-1.9.1-36_nonptl.el4.x86_64.rpm
rpm-4.3.3-36_nonptl.el4.x86_64.rpm
rpm-build-4.3.3-36_nonptl.el4.x86_64.rpm
rpm-devel-4.3.3-36_nonptl.el4.x86_64.rpm
rpm-libs-4.3.3-36_nonptl.el4.i386.rpm
rpm-libs-4.3.3-36_nonptl.el4.x86_64.rpm
rpm-python-4.3.3-36_nonptl.el4.x86_64.rpm
ia64:
popt-1.9.1-36_nonptl.el4.i386.rpm
popt-1.9.1-36_nonptl.el4.ia64.rpm
rpm-4.3.3-36_nonptl.el4.ia64.rpm
rpm-build-4.3.3-36_nonptl.el4.ia64.rpm
rpm-devel-4.3.3-36_nonptl.el4.ia64.rpm
rpm-libs-4.3.3-36_nonptl.el4.i386.rpm
rpm-libs-4.3.3-36_nonptl.el4.ia64.rpm
rpm-python-4.3.3-36_nonptl.el4.ia64.rpm
SRPMS:
http://oss.oracle.com/el4/SRPMS-updates/rpm-4.3.3-36_nonptl.el4.src.rpm
Description of changes:
[4.3.3-36_nonptl]
- Proper region tag validation on package/header read (CVE-2012-0060)
- Double-check region size against header size (CVE-2012-0061)
- Validate negated offsets too in headerVerifyInfo() (CVE-2012-0815)
More information about the El-errata
mailing list