<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Red Hat Enterprise Linux WS (v. 3 for x86)</title>
<link>http://rhn.redhat.com/</link>
<description></description>
<language>en</language>
<pubDate>57</pubDate>

<item>
<title>vixie-cron bug fix</title>
<link>https://rhn.redhat.com/errata/RHBA-2007-1001.html</link>
<description>&lt;a href="https://rhn.redhat.com/errata/RHBA-2007-1001.html"&gt;RHBA-2007:1001&lt;/a&gt;&lt;br&gt;&lt;br&gt;The vixie-cron package contains the Vixie version of cron. Cron is a&lt;br&gt;standard UNIX daemon that runs specified programs at scheduled times. Vixie&lt;br&gt;cron adds better security and more powerful configuration options to the&lt;br&gt;standard version of cron.&lt;br&gt;&lt;br&gt;vixie-cron failed to acknowledge changes to symbolic links that pointed to&lt;br&gt;crontab files. In these updated packages symbolic links can be used for&lt;br&gt;cron jobs, even if the symbolic link is changed or deleted.&lt;br&gt;&lt;br&gt;Users of vixie-cron are advised to upgrade to these updated packages, which&lt;br&gt;resolve this issue.
&lt;br&gt;
	Bugzillas (&lt;a href="http://bugzilla.redhat.com/bugzilla"&gt;bugzilla.redhat.com&lt;/a&gt;):
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=253391" title="Cron does not detect changed symlink" &gt;253391&lt;/a&gt;
</description>
<pubDate>Mon, 19 Nov 2007 00:00:00 -0500</pubDate>
</item>

<item>
<title>Moderate: net-snmp security update</title>
<link>https://rhn.redhat.com/errata/RHSA-2007-1045.html</link>
<description>&lt;a href="https://rhn.redhat.com/errata/RHSA-2007-1045.html"&gt;RHSA-2007:1045&lt;/a&gt;&lt;br&gt;&lt;br&gt;Simple Network Management Protocol (SNMP) is a protocol used for network&lt;br&gt;management.&lt;br&gt;&lt;br&gt;A flaw was discovered in the way net-snmp handled certain requests. A&lt;br&gt;remote attacker who can connect to the snmpd UDP port (161 by default)&lt;br&gt;could send a malicious packet causing snmpd to crash, resulting in a&lt;br&gt;denial of service. (CVE-2007-5846)&lt;br&gt;&lt;br&gt;All users of net-snmp are advised to upgrade to these updated packages,&lt;br&gt;which contain a backported patch to resolve this issue.
&lt;br&gt;
	CVEs (&lt;a href="http://cve.mitre.org"&gt;cve.mitre.org&lt;/a&gt;):&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5846"&gt;CVE-2007-5846&lt;/a&gt;
&lt;br&gt;
	Bugzillas (&lt;a href="http://bugzilla.redhat.com/bugzilla"&gt;bugzilla.redhat.com&lt;/a&gt;):
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=363631" title="CVE-2007-5846 net-snmp remote DoS via udp packet" &gt;363631&lt;/a&gt;
</description>
<pubDate>Thu, 15 Nov 2007 00:00:00 -0500</pubDate>
</item>

<item>
<title>Moderate: util-linux security update</title>
<link>https://rhn.redhat.com/errata/RHSA-2007-0969.html</link>
<description>&lt;a href="https://rhn.redhat.com/errata/RHSA-2007-0969.html"&gt;RHSA-2007:0969&lt;/a&gt;&lt;br&gt;&lt;br&gt;The util-linux package contains a large variety of low-level system&lt;br&gt;utilities that are necessary for a Linux system to function. &lt;br&gt;&lt;br&gt;A flaw was discovered in the way that the mount and umount utilities&lt;br&gt;used the setuid and setgid functions, which could lead to privileges being&lt;br&gt;dropped improperly.  A local user could use this flaw to run mount helper&lt;br&gt;applications such as, mount.nfs, with additional privileges (CVE-2007-5191).&lt;br&gt;&lt;br&gt;Users are advised to update to these erratum packages which contain a&lt;br&gt;backported patch to correct this issue.
&lt;br&gt;
	CVEs (&lt;a href="http://cve.mitre.org"&gt;cve.mitre.org&lt;/a&gt;):&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5191"&gt;CVE-2007-5191&lt;/a&gt;
&lt;br&gt;
	Bugzillas (&lt;a href="http://bugzilla.redhat.com/bugzilla"&gt;bugzilla.redhat.com&lt;/a&gt;):
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=320041" title="CVE-2007-5191 util-linux (u)mount doesn't drop privileges properly when calling helpers" &gt;320041&lt;/a&gt;
</description>
<pubDate>Thu, 15 Nov 2007 00:00:00 -0500</pubDate>
</item>

<item>
<title>Critical: samba security update</title>
<link>https://rhn.redhat.com/errata/RHSA-2007-1013.html</link>
<description>&lt;a href="https://rhn.redhat.com/errata/RHSA-2007-1013.html"&gt;RHSA-2007:1013&lt;/a&gt;&lt;br&gt;&lt;br&gt;Samba is a suite of programs used by machines to share files, printers, and&lt;br&gt;other information.&lt;br&gt;&lt;br&gt;A buffer overflow flaw was found in the way Samba creates NetBIOS replies.&lt;br&gt;If a Samba server is configured to run as a WINS server, a remote&lt;br&gt;unauthenticated user could cause the Samba server to crash or execute&lt;br&gt;arbitrary code. (CVE-2007-5398)&lt;br&gt;&lt;br&gt;A heap-based buffer overflow flaw was found in the way Samba authenticates&lt;br&gt;users. A remote unauthenticated user could trigger this flaw to cause the&lt;br&gt;Samba server to crash. Careful analysis of this flaw has determined that&lt;br&gt;arbitrary code execution is not possible, and under most circumstances will&lt;br&gt;not result in a crash of the Samba server. (CVE-2007-4572)&lt;br&gt;&lt;br&gt;Red Hat would like to thank Alin Rad Pop of Secunia Research, and the Samba&lt;br&gt;developers for responsibly disclosing these issues.&lt;br&gt;&lt;br&gt;Users of Samba are advised to ugprade to these updated packages, which&lt;br&gt;contain backported patches to resolve these issues.
&lt;br&gt;
	CVEs (&lt;a href="http://cve.mitre.org"&gt;cve.mitre.org&lt;/a&gt;):&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4572"&gt;CVE-2007-4572&lt;/a&gt;
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5398"&gt;CVE-2007-5398&lt;/a&gt;
&lt;br&gt;
	Bugzillas (&lt;a href="http://bugzilla.redhat.com/bugzilla"&gt;bugzilla.redhat.com&lt;/a&gt;):
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=358831" title="CVE-2007-5398 Samba "reply_netbios_packet()" Buffer Overflow Vulnerability" &gt;358831&lt;/a&gt;
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=294631" title="CVE-2007-4572 samba buffer overflow" &gt;294631&lt;/a&gt;
</description>
<pubDate>Thu, 15 Nov 2007 00:00:00 -0500</pubDate>
</item>

<item>
<title>Important: xpdf security update</title>
<link>https://rhn.redhat.com/errata/RHSA-2007-1030.html</link>
<description>&lt;a href="https://rhn.redhat.com/errata/RHSA-2007-1030.html"&gt;RHSA-2007:1030&lt;/a&gt;&lt;br&gt;&lt;br&gt;Xpdf is an X Window System-based viewer for Portable Document Format (PDF)&lt;br&gt;files.&lt;br&gt;&lt;br&gt;Alin Rad Pop discovered several flaws in the handling of PDF files. An&lt;br&gt;attacker could create a malicious PDF file that would cause Xpdf to crash,&lt;br&gt;or potentially execute arbitrary code when opened.  &lt;br&gt;(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)&lt;br&gt;&lt;br&gt;A flaw was found in the t1lib library, used in the handling of Type 1&lt;br&gt;fonts. An attacker could create a malicious file that would cause Xpdf to&lt;br&gt;crash, or potentially execute arbitrary code when opened. (CVE-2007-4033)&lt;br&gt;&lt;br&gt;Users are advised to upgrade to these updated packages, which contain&lt;br&gt;backported patches to resolve these issues.
&lt;br&gt;
	CVEs (&lt;a href="http://cve.mitre.org"&gt;cve.mitre.org&lt;/a&gt;):&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4033"&gt;CVE-2007-4033&lt;/a&gt;
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4352"&gt;CVE-2007-4352&lt;/a&gt;
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5392"&gt;CVE-2007-5392&lt;/a&gt;
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5393"&gt;CVE-2007-5393&lt;/a&gt;
&lt;br&gt;
	Bugzillas (&lt;a href="http://bugzilla.redhat.com/bugzilla"&gt;bugzilla.redhat.com&lt;/a&gt;):
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=345111" title="CVE-2007-5392 xpdf buffer overflow in DCTStream::reset()" &gt;345111&lt;/a&gt;
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=345121" title="CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()" &gt;345121&lt;/a&gt;
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=345101" title="CVE-2007-4352 xpdf memory corruption in DCTStream::readProgressiveDataUnit()" &gt;345101&lt;/a&gt;
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=352271" title="CVE-2007-4033 t1lib font filename string overflow" &gt;352271&lt;/a&gt;
</description>
<pubDate>Wed, 07 Nov 2007 00:00:00 -0500</pubDate>
</item>

<item>
<title>Important: tetex security update</title>
<link>https://rhn.redhat.com/errata/RHSA-2007-1028.html</link>
<description>&lt;a href="https://rhn.redhat.com/errata/RHSA-2007-1028.html"&gt;RHSA-2007:1028&lt;/a&gt;&lt;br&gt;&lt;br&gt;TeTeX is an implementation of TeX. TeX takes a text file and a set of&lt;br&gt;formatting commands as input, and creates a typesetter-independent DeVice&lt;br&gt;Independent (dvi) file as output.&lt;br&gt;&lt;br&gt;Alin Rad Pop discovered a flaw in the handling of PDF files. An attacker&lt;br&gt;could create a malicious PDF file that would cause TeTeX to crash, or&lt;br&gt;potentially execute arbitrary code when opened. (CVE-2007-5393)&lt;br&gt;&lt;br&gt;Users are advised to upgrade to these updated packages, which contain&lt;br&gt;backported patches to resolve these issues.
&lt;br&gt;
	CVEs (&lt;a href="http://cve.mitre.org"&gt;cve.mitre.org&lt;/a&gt;):&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5393"&gt;CVE-2007-5393&lt;/a&gt;
&lt;br&gt;
	Bugzillas (&lt;a href="http://bugzilla.redhat.com/bugzilla"&gt;bugzilla.redhat.com&lt;/a&gt;):
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=345121" title="CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()" &gt;345121&lt;/a&gt;
</description>
<pubDate>Wed, 07 Nov 2007 00:00:00 -0500</pubDate>
</item>

<item>
<title>Important: cups security update</title>
<link>https://rhn.redhat.com/errata/RHSA-2007-1023.html</link>
<description>&lt;a href="https://rhn.redhat.com/errata/RHSA-2007-1023.html"&gt;RHSA-2007:1023&lt;/a&gt;&lt;br&gt;&lt;br&gt;The Common UNIX Printing System (CUPS) provides a portable printing layer&lt;br&gt;for UNIX(R) operating systems.&lt;br&gt;&lt;br&gt;Alin Rad Pop discovered a flaw in the handling of PDF files. An attacker&lt;br&gt;could create a malicious PDF file that would cause CUPS to crash or&lt;br&gt;potentially execute arbitrary code when printed. (CVE-2007-5393)&lt;br&gt;&lt;br&gt;Alin Rad Pop discovered a flaw in in the way CUPS handles certain IPP tags.&lt;br&gt;A remote attacker who is able to connect to the IPP TCP port could send a&lt;br&gt;malicious request causing the CUPS daemon to crash. (CVE-2007-4351)&lt;br&gt;&lt;br&gt;A flaw was found in the way CUPS handled SSL negotiation. A remote attacker&lt;br&gt;capable of connecting to the CUPS daemon could cause CUPS to crash.&lt;br&gt;(CVE-2007-4045)&lt;br&gt;&lt;br&gt;All CUPS users are advised to upgrade to these updated packages, which&lt;br&gt;contain backported patches to resolve these issues.
&lt;br&gt;
	CVEs (&lt;a href="http://cve.mitre.org"&gt;cve.mitre.org&lt;/a&gt;):&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4045"&gt;CVE-2007-4045&lt;/a&gt;
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4351"&gt;CVE-2007-4351&lt;/a&gt;
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5393"&gt;CVE-2007-5393&lt;/a&gt;
&lt;br&gt;
	Bugzillas (&lt;a href="http://bugzilla.redhat.com/bugzilla"&gt;bugzilla.redhat.com&lt;/a&gt;):
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=345121" title="CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()" &gt;345121&lt;/a&gt;
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=250161" title="CVE-2007-4045 Incomplete fix for CVE-2007-0720 CUPS denial of service" &gt;250161&lt;/a&gt;
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=345091" title="CVE-2007-4351 cups boundary error" &gt;345091&lt;/a&gt;
</description>
<pubDate>Wed, 07 Nov 2007 00:00:00 -0500</pubDate>
</item>

<item>
<title>Important: perl security update</title>
<link>https://rhn.redhat.com/errata/RHSA-2007-0966.html</link>
<description>&lt;a href="https://rhn.redhat.com/errata/RHSA-2007-0966.html"&gt;RHSA-2007:0966&lt;/a&gt;&lt;br&gt;&lt;br&gt;Perl is a high-level programming language commonly used for system&lt;br&gt;administration utilities and Web programming.&lt;br&gt;&lt;br&gt;A flaw was found in Perl's regular expression engine. Specially crafted&lt;br&gt;input to a regular expression can cause Perl to improperly allocate memory,&lt;br&gt;possibly resulting in arbitrary code running with the permissions of the&lt;br&gt;user running Perl. (CVE-2007-5116)&lt;br&gt;&lt;br&gt;Users of Perl are advised to upgrade to these updated packages, which&lt;br&gt;contain a backported patch to resolve this issue.&lt;br&gt;&lt;br&gt;Red Hat would like to thank Tavis Ormandy and Will Drewry for properly&lt;br&gt;disclosing this issue.
&lt;br&gt;
	CVEs (&lt;a href="http://cve.mitre.org"&gt;cve.mitre.org&lt;/a&gt;):&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5116"&gt;CVE-2007-5116&lt;/a&gt;
&lt;br&gt;
	Bugzillas (&lt;a href="http://bugzilla.redhat.com/bugzilla"&gt;bugzilla.redhat.com&lt;/a&gt;):
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=323571" title="CVE-2007-5116 perl regular expression UTF parsing errors" &gt;323571&lt;/a&gt;
</description>
<pubDate>Mon, 05 Nov 2007 00:00:00 -0500</pubDate>
</item>

<item>
<title>Moderate: libpng security update</title>
<link>https://rhn.redhat.com/errata/RHSA-2007-0992.html</link>
<description>&lt;a href="https://rhn.redhat.com/errata/RHSA-2007-0992.html"&gt;RHSA-2007:0992&lt;/a&gt;&lt;br&gt;&lt;br&gt;The libpng package contains a library of functions for creating and&lt;br&gt;manipulating PNG (Portable Network Graphics) image format files.&lt;br&gt;&lt;br&gt;Several flaws were discovered in the way libpng handled various PNG image&lt;br&gt;chunks.  An attacker could create a carefully crafted PNG image file in&lt;br&gt;such a way that it could cause an application linked with libpng to crash&lt;br&gt;when the file was manipulated. (CVE-2007-5269)&lt;br&gt;&lt;br&gt;Users should update to these updated packages which contain a backported&lt;br&gt;patch to correct these issues.
&lt;br&gt;
	CVEs (&lt;a href="http://cve.mitre.org"&gt;cve.mitre.org&lt;/a&gt;):&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5269"&gt;CVE-2007-5269&lt;/a&gt;
&lt;br&gt;
	Bugzillas (&lt;a href="http://bugzilla.redhat.com/bugzilla"&gt;bugzilla.redhat.com&lt;/a&gt;):
&lt;a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=324771" title="CVE-2007-5269 libpng DoS via multiple out-of-bounds reads" &gt;324771&lt;/a&gt;
</description>
<pubDate>Tue, 23 Oct 2007 00:00:00 -0500</pubDate>
</item>

</channel>
</rss>