[Previo por Fecha] [Siguiente por Fecha] [Previo por Hilo] [Siguiente por Hilo]

[Hilos de Discusión] [Fecha] [Tema] [Autor]

[ewt en redhat com: SECURITY: new MH release now available]



------- Start of forwarded message -------
Return-Path: <redhat-announce-list-request en redhat com>
Resent-Cc: recipient list not shown: ;
MBOX-Line: From redhat-announce-list-request en redhat com  Mon Jan 19 22:39:53 1998
Date: Mon, 19 Jan 1998 22:39:46 -0500 (EST)
From: Erik Troan <ewt en redhat com>
Reply-To: redhat-list en redhat com
To: redhat-announce-list en redhat com
Subject: SECURITY: new MH release now available
Approved: ewt en redhat com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Resent-From: redhat-announce-list en redhat com
X-Mailing-List: <redhat-announce-list en redhat com> archive/latest/722
X-Loop: redhat-announce-list en redhat com
Precedence: list
Resent-Sender: redhat-announce-list-request en redhat com
X-URL: http://www.redhat.com

- -----BEGIN PGP SIGNED MESSAGE-----


Buffer overflows have been found in inc and msgchk as included with the
mh package in all versions of Red Hat. These overflows allow all users
to gain root access to systems with them installed.

If you do not need the mh package, the easiest fix for this problem is
to 'rpm -e mh'. If you do need it, fixes are available for users of Red
Hat 5.0 and Red Hat 4.x. As always, these packages have been signed with
the Red Hat PGP key.

Thanks to Cesar Tascon Alvarez for finding this problem.

Erik

Red Hat 5.0
- - -------------

i386:
rpm -Uvh ftp://ftp.redhat.com/updates/5.0/i386/mh-6.8.4-5.i386.rpm

alpha:
rpm -Uvh ftp://ftp.redhat.com/updates/5.0/alpha/mh-6.8.4-5.alpha.rpm

Red Hat 4.2
- - -------------

i386:
rpm -Uvh ftp://ftp.redhat.com/updates/4.2/i386/mh-6.8.3-14.i386.rpm

alpha:
rpm -Uvh ftp://ftp.redhat.com/updates/4.2/alpha/mh-6.8.3-14.alpha.rpm

SPARC:
rpm -Uvh ftp://ftp.redhat.com/updates/4.2/sparc/mh-6.8.3-14.sparc.rpm


- -----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBNMQciKUg6PHLopv5AQHZKgP+Om0DnXMPydmdQIKh8+fQibI+Ftyw3QcR
vXVqmEzeDfJFu6mLnwWBd+oVctdHnHTYbW4SjAqaWMw4XUEVome6YRwejVhfoYA4
WKN1sEFRHSSJi+sDLm8nQqObynx1pzMS+jbr6Lbx3NE8HyfZIAFPHEPqZG9dctxa
ru8ym2Y9koU=
=jwCH
- -----END PGP SIGNATURE-----

- -- 
To unsubscribe:
mail -s unsubscribe redhat-announce-list-request en redhat com < /dev/null
------- End of forwarded message -------



[Hilos de Discusión] [Fecha] [Tema] [Autor]