[El-errata] ELSA-2014-1606 Moderate: Oracle Linux 6 file security and bug fix update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Thu Oct 16 09:35:23 PDT 2014


Oracle Linux Security Advisory ELSA-2014-1606

https://rhn.redhat.com/errata/RHSA-2014-1606.html

The following updated rpms for Oracle Linux 6 have been uploaded to the 
Unbreakable Linux Network:

i386:
file-5.04-21.el6.i686.rpm
file-devel-5.04-21.el6.i686.rpm
file-libs-5.04-21.el6.i686.rpm
file-static-5.04-21.el6.i686.rpm
python-magic-5.04-21.el6.i686.rpm

x86_64:
file-5.04-21.el6.x86_64.rpm
file-devel-5.04-21.el6.i686.rpm
file-devel-5.04-21.el6.x86_64.rpm
file-libs-5.04-21.el6.i686.rpm
file-libs-5.04-21.el6.x86_64.rpm
file-static-5.04-21.el6.x86_64.rpm
python-magic-5.04-21.el6.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/file-5.04-21.el6.src.rpm



Description of changes:

[5.04-21]
- fix typographical error in changelog

[5.04-20]
- fix #1037279 - better patch for the bug from previous release

[5.04-19]
- fix #1037279 - display "from" field on 32bit ppc core

[5.04-18]
- fix #664513 - trim white-spaces during ISO9660 detection

[5.04-17]
- fix CVE-2014-3479 (cdf_check_stream_offset boundary check)
- fix CVE-2014-3480 (cdf_count_chain insufficient boundary check)
- fix CVE-2014-0237 (cdf_unpack_summary_info() excessive looping DoS)
- fix CVE-2014-0238 (CDF property info parsing nelements infinite loop)
- fix CVE-2014-2270 (out-of-bounds access in search rules with offsets)
- fix CVE-2014-1943 (unrestricted recursion in handling of indirect type 
rules)
- fix CVE-2012-1571 (out of bounds read in CDF parser)

[5.04-16]
- fix #873997 - improve Minix detection pattern to fix false positives
- fix #884396 - improve PBM pattern to fix misdetection with x86 boot sector
- fix #980941 - improve Bio-Rad pattern to fix false positives
- fix #849621 - tweak strength of XML, Latex and Python patterns to execute
   them in the proper order
- fix #1067771 - detect qcow version 3 images
- fix #1064463 - treat RRDTool files as binary files





More information about the El-errata mailing list