[Previo por Fecha] [Siguiente por Fecha] [Previo por Hilo] [Siguiente por Hilo]
[Hilos de Discusión] [Fecha] [Tema] [Autor]------- Start of forwarded message ------- Return-Path: <redhat-announce-list-request en redhat com> Resent-Cc: recipient list not shown: ; MBOX-Line: From redhat-announce-list-request en redhat com Mon Jan 19 22:39:53 1998 Date: Mon, 19 Jan 1998 22:39:46 -0500 (EST) From: Erik Troan <ewt en redhat com> Reply-To: redhat-list en redhat com To: redhat-announce-list en redhat com Subject: SECURITY: new MH release now available Approved: ewt en redhat com MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Resent-From: redhat-announce-list en redhat com X-Mailing-List: <redhat-announce-list en redhat com> archive/latest/722 X-Loop: redhat-announce-list en redhat com Precedence: list Resent-Sender: redhat-announce-list-request en redhat com X-URL: http://www.redhat.com - -----BEGIN PGP SIGNED MESSAGE----- Buffer overflows have been found in inc and msgchk as included with the mh package in all versions of Red Hat. These overflows allow all users to gain root access to systems with them installed. If you do not need the mh package, the easiest fix for this problem is to 'rpm -e mh'. If you do need it, fixes are available for users of Red Hat 5.0 and Red Hat 4.x. As always, these packages have been signed with the Red Hat PGP key. Thanks to Cesar Tascon Alvarez for finding this problem. Erik Red Hat 5.0 - - ------------- i386: rpm -Uvh ftp://ftp.redhat.com/updates/5.0/i386/mh-6.8.4-5.i386.rpm alpha: rpm -Uvh ftp://ftp.redhat.com/updates/5.0/alpha/mh-6.8.4-5.alpha.rpm Red Hat 4.2 - - ------------- i386: rpm -Uvh ftp://ftp.redhat.com/updates/4.2/i386/mh-6.8.3-14.i386.rpm alpha: rpm -Uvh ftp://ftp.redhat.com/updates/4.2/alpha/mh-6.8.3-14.alpha.rpm SPARC: rpm -Uvh ftp://ftp.redhat.com/updates/4.2/sparc/mh-6.8.3-14.sparc.rpm - -----BEGIN PGP SIGNATURE----- Version: 2.6.2 iQCVAwUBNMQciKUg6PHLopv5AQHZKgP+Om0DnXMPydmdQIKh8+fQibI+Ftyw3QcR vXVqmEzeDfJFu6mLnwWBd+oVctdHnHTYbW4SjAqaWMw4XUEVome6YRwejVhfoYA4 WKN1sEFRHSSJi+sDLm8nQqObynx1pzMS+jbr6Lbx3NE8HyfZIAFPHEPqZG9dctxa ru8ym2Y9koU= =jwCH - -----END PGP SIGNATURE----- - -- To unsubscribe: mail -s unsubscribe redhat-announce-list-request en redhat com < /dev/null ------- End of forwarded message -------