White Box 64 Published by Philipp Esselbach 0

Updated libpng packages are available for White Box Enterprise Linux 3.0

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated libpng packages fix security issues
Advisory ID: WBSA-2004:402-01
Issue date: 08-19-2004
Updated on: 08-19-2004
Product: White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords:
Cross references:
Obsoletes: WBSA-2004:249
CVE Names: CAN-2002-1363 CAN-2004-0597 CAN-2004-0598 CAN-2004-0
-----------------------------------------------------------------------

Another catchup announcement.

Updated libpng packages that fix several issues are now available.

More information is available in Red Hat, Inc's original advisory available on their site at:

http://www.redhat.com/archives/enterprise-watch-list/2004-August/msg00002.html

To install this new package on your White Box Enterprise Linux system use the Up2Date Network or Yum.

Note: Be sure to change the default Up2Date or Yum server from the initial location to prevent undue load to the whiteboxlinux.org server, which doesn't have a lot of outbound bandwidth. The config files already have entries for mirror sites commented out.

Up2Date's configuration file is at /etc/sysconfig/rhn/sources

Yum's configuration is in /etc/yum.conf

White Box 64 Published by Philipp Esselbach 0

An updated ipsec-tools package is available for White Box Enterprise Linux 3.0

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated ipsec-tools package
Advisory ID: WBSA-2004:308-01
Issue date: 08-19-2004
Updated on: 08-19-2004
Product: White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords: IKE racoon X.509
Cross references:
Obsoletes: RHSA-2004:165
CVE Names: CAN-2004-0607
-----------------------------------------------------------------------

Another catchup announcement.

An updated ipsec-tools package that fixes verification of X.509 certificates in racoon is now available.

More information is available in Red Hat, Inc's original advisory available on their site at:

http://www.redhat.com/archives/enterprise-watch-list/2004-July/msg00008.html

To install this new package on your White Box Enterprise Linux system use the Up2Date Network or Yum.

White Box 64 Published by Philipp Esselbach 0

Updated samba packages are available for White Box Enterprise Linux 3.0

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated samba packages fix vulnerabilities
Advisory ID: WBSA-2004:259-01
Issue date: 08-19-2004
Updated on: 08-19-2004
Product: White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords: smb
Cross references:
Obsoletes:
CVE Names: CAN-2004-0600 CAN-2004-0686
-----------------------------------------------------------------------

Another catchup announcement.

Updated samba packages that fix buffer overflows, as well as other various bugs, are now available.

More information is available in Red Hat, Inc's original advisory available on their site at:

http://www.redhat.com/archives/enterprise-watch-list/2004-July/msg00005.html

To install this new package on your White Box Enterprise Linux system use the Up2Date Network or Yum.

White Box 64 Published by Philipp Esselbach 0

GNOME VFS updates are available for White Box Enterprise Linux 3.0

-----------------------------------------------------------------------
Security Advisory

Synopsis: GNOME VFS updates address extfs vulnerability
Advisory ID: WBSA-2004:373-01
Issue date: 08-19-2004
Updated on: 08-19-2004
Product: White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords: gnome-vfs gnome-vfs2 extfs
Cross references:
Obsoletes:
CVE Names: CAN-2004-0494
-----------------------------------------------------------------------

Another catchup announcement.

Updated GNOME VFS packages that remove potential extfs-related vulnerabilities are now available.

More information is available in Red Hat, Inc's original advisory available on their site at:

http://www.redhat.com/archives/enterprise-watch-list/2004-August/msg00003.html

To install this new package on your White Box Enterprise Linux system use the Up2Date Network or Yum.

White Box 64 Published by Philipp Esselbach 0

Updated kernel packages are available for White Box Enterprise Linux 3.0

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated kernel packages fix security vulnerabilities
Advisory ID: WBSA-2004:413-01
Issue date: 08-19-2004
Updated on: 08-19-2004
Product: White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords: kernel security errata
Cross references:
Obsoletes: WBSA-2004:360
CVE Names: CAN-2004-0178 CAN-2004-0415 CAN-2004-0447 CAN-2004-0535 CAN-2004-0587
-----------------------------------------------------------------------

Another catchup announcement.

Updated kernel packages that fix several security issues are now available.

More information is available in Red Hat, Inc's original advisory available on their site at:

http://www.redhat.com/archives/enterprise-watch-list/2004-August/msg00001.html

To install this new package on your White Box Enterprise Linux system use the Up2Date Network or Yum.

White Box 64 Published by Philipp Esselbach 0

Updated PHP packages are available for White Box Enterprise Linux 3.0

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated php packages fix security issues
Advisory ID: WBSA-2004:392-01
Issue date: 08-19-2004
Updated on: 08-19-2004
Product: White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords:
Cross references: WBSA-2004:342
Obsoletes:
CVE Names: CAN-2004-0594 CAN-2004-0595
-----------------------------------------------------------------------

Catching up the announcments. This one posted to the primary mirror on July 22nd so if you have been running up2date regularly you already have it.

Updated php packages that fix various security issues are now available.

More information is available in Red Hat, Inc's original advisory available on their site at:

http://www.redhat.com/archives/enterprise-watch-list/2004-July/msg00004.html

To install this new package on your White Box Enterprise Linux system use the Up2Date Network or Yum.

White Box 64 Published by Philipp Esselbach 0

John Morris has posted an update on the latest White Box Enterprise Linux updates:

I'm about to be leaving town for a week and have been trying to catch up on the flood of errata that has dropped in the last two days. I know I haven't been posting the notices for the last couple of weeks, I'll catch up on all of them when I get back. Instead of catching up on back annoucements today though, I have new packages for your updating pleasure.

The updates tree should now be current with the following exceptions:

White Box 64 Published by Philipp Esselbach 0

Updtaed kernel packages are available for White Box Enterprise Linux 3.0

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated kernel packages fix security vulnerabilities
Advisory ID: [WBSA-2004:360-01]
Issue date: 2004-07-07
Updated on: 2004-07-07
Product: White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords: kernel security errata
Cross references:
Obsoletes: WBSA-2004:255
CVE Names: CAN-2004-0497
-----------------------------------------------------------------------

Updated kernel packages that fix a security vulnerability affecting the kernel nfs server for Red Hat Enterprise Linux 3 are now available.

More information is available in Red Hat, Inc's original advisory available on their site at:

http://www.redhat.com/archives/enterprise-watch-list/2004-July/msg00000.html

To install this new package on your White Box Enterprise Linux system use the Up2Date Network or Yum.

White Box 64 Published by Philipp Esselbach 0

Updated kernel packages are available for White Box Enterprise Linux

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated kernel packages fix security vulnerabilities
Advisory ID: WBSA-2004:255-01
Issue date: 2004-06-21
Updated on: 2004-06-21
Product: White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords:
Cross references:
Obsoletes: WBSA-2004:188
CVE Names: CAN-2004-0427 CAN-2004-0495 CAN-2004-0554
-----------------------------------------------------------------------

Updated kernel packages for Red Hat Enterprise Linux 3 that fix security vulnerabilities are now available.

More information is available in Red Hat, Inc's original advisory available on their site at:

http://www.redhat.com/archives/enterprise-watch-list/2004-June/msg00007.html

To install this new package on your White Box Enterprise Linux system use the Up2Date Network or Yum.

White Box 64 Published by Philipp Esselbach 0

An updated SquirrelMail package is available for White Box Enterprise Linux

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated SquirrelMail package fixes multiple vulnerabilities
Advisory ID: WBSA-2004:240-01
Issue date: 2004-06-21
Updated on: 2004-06-21
Product: White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords: cross-site scripting XSS sql injection
Cross references:
Obsoletes:
CVE Names: CAN-2004-0519 CAN-2004-0520 CAN-2004-0521
-----------------------------------------------------------------------

An updated SquirrelMail package that fixes several security vulnerabilities is now available.

More information is available in Red Hat, Inc's original advisory available on their site at:

http://www.redhat.com/archives/enterprise-watch-list/2004-June/msg00004.html

To install this new package on your White Box Enterprise Linux system use the Up2Date Network or Yum.

White Box 64 Published by Philipp Esselbach 0

Updated libpng packages are available for White Box Enterprise Linux

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated libpng packages fix security issue
Advisory ID: WBSA-2004:249-01
Issue date: 2004-06-21
Updated on: 2004-06-21
Product: White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords:
Cross references:
Obsoletes:
CVE Names: CAN-2002-1363
-----------------------------------------------------------------------

Updated libpng packages that fix a possible buffer overflow are now available.

More information is available in Red Hat, Inc's original advisory available on their site at:

http://www.redhat.com/archives/enterprise-watch-list/2004-June/msg00008.html

To install this new package on your White Box Enterprise Linux system use the Up2Date Network or Yum.

White Box 64 Published by Philipp Esselbach 0

An update utempter package is available for White Box Enterprise Linux 3.0

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated utempter package fixes vulnerability
Advisory ID: [WBSA-2004:174-01]
Issue date: 2004-06-10
Updated on: 2004-06-10
Product: White Box Enterprise Linux 3.0 (i386)
Keywords:
Cross references:
Obsoletes:
CVE Names: CAN-2004-0233
-----------------------------------------------------------------------

Note: This one went to the mirrors on May 31.

An updated utempter package that fixes a potential symlink vulnerability is now available.

White Box 64 Published by Philipp Esselbach 0

An updated cvs package has been released for White Box Enterprise Linux 3.0

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated cvs package fixes security issues
Advisory ID: [WBSA-2004:233-01]
Issue date: 2004-06-09
Updated on: 2004-06-10
Product: White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords:
Cross references:
Obsoletes: WBSA-2004:190
CVE Names: CAN-2004-0414 CAN-2004-0416 CAN-2004-0417 CAN-2004-041
-----------------------------------------------------------------------

An updated cvs package that fixes several server vulnerabilities, which could be exploited by a malicious client, is now available.

White Box 64 Published by Philipp Esselbach 0

An updated squid package is available for White Box Enterpirse Linux 3.0

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated squid package fixes security vulnerability
Advisory ID: [WBSA-2004:242-01]
Issue date: 2004-06-09
Updated on: 2004-06-10
Product: White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords:
Cross references:
Obsoletes: WBSA-2004:133
CVE Names: CAN-2004-0541
-----------------------------------------------------------------------

An updated squid package that fixes a security vulnerability in the NTLM authentication helper is now available.

White Box 64 Published by Philipp Esselbach 0

Updated Ethereal packages are available for White Box Enterprise Linux 3.0

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated Ethereal packages fix security issues
Advisory ID: [WBSA-2004:234-01]
Issue date: 2004-06-09
Updated on: 2004-06-10
Product: White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords:
Cross references:
Obsoletes: WBSA-2004:136
CVE Names: CAN-2004-0504 CAN-2004-0505 CAN-2004-0506
-----------------------------------------------------------------------

Updated Ethereal packages that fix various security vulnerabilities are now available.

White Box 64 Published by Philipp Esselbach 0

Updated krb5 packages are available for White Box Enterprise Linux 3.0

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated krb5 packages available
Advisory ID: [WBSA-2004:236-01]
Issue date: 2004-06-09
Updated on: 2004-06-10
Product: White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords: krb5 auth_to_local MITKRB5-SA-2004-001
Cross references:
Obsoletes: WBBA-2004:208
CVE Names: CAN-2004-0523
-----------------------------------------------------------------------

Updated Kerberos 5 (krb5) packages which correct buffer overflows in the krb5_aname_to_localname function are now available.

White Box 64 Published by Philipp Esselbach 0

Updated tcpdump packages are available for White Box Enterprise Linux 3.0

-----------------------------------------------------------------------
Security Advisory

Synopsis: Updated tcpdump packages fix various vulnerabilities
Advisory ID: [WBSA-2004:219-01]
Issue date: 2004-06-10
Updated on: 2004-06-10
Product: White Box Enterprise Linux 3.0 (i386)
Keywords: tcpdump buffer overflow libpcap arpwatch
Cross references:
Obsoletes: WBSA-2004:008-09
CVE Names: CAN-2004-0183 CAN-2004-0184
-----------------------------------------------------------------------

Note: This one slipped through the cracks. It was originally issued by RH on 2004-05-26.

Updated tcpdump, libpcap, and arpwatch packages fix vulnerabilities in ISAKMP parsing.

White Box 64 Published by Philipp Esselbach 0

An updated LHA package has been released for White Box Enterprise Linux 3.0

-----------------------------------------------------------------------
Security Advisory

Synopsis: An updated LHA package fixes security vulnerabilities
Advisory ID: [WBSA-2004:178-01]
Issue date: 2004-06-10
Updated on: 2004-06-10
Product: White Box Enterprise Linux 3.0 (i386)
Keywords:
Cross references:
Obsoletes:
CVE Names: CAN-2004-0234 CAN-2004-0235
-----------------------------------------------------------------------

Note: This one went to the mirrors on May 31.

An updated LHA package that fixes several security vulnerabilities is now available.