Red Hat 9062 Published by

The following updates has been released for Red Hat Enterprise Linux: [RHSA-2011:1325-01] Moderate: evolution28-pango security update, [RHSA-2011:1327-01] Moderate: frysk security update, [RHSA-2011:1326-01] Moderate: pango security update, [RHSA-2011:1323-01] Moderate: qt security update, and [RHSA-2011:1324-01] Moderate: qt4 security update



[RHSA-2011:1325-01] Moderate: evolution28-pango security update
=====================================================================
Red Hat Security Advisory

Synopsis: Moderate: evolution28-pango security update
Advisory ID: RHSA-2011:1325-01
Product: Red Hat Enterprise Linux
Advisory URL: https://rhn.redhat.com/errata/RHSA-2011-1325.html
Issue date: 2011-09-21
CVE Names: CVE-2011-3193
=====================================================================

1. Summary:

Updated evolution28-pango packages that fix one security issue are now
available for Red Hat Enterprise Linux 4.

The Red Hat Security Response Team has rated this update as having moderate
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Description:

Pango is a library used for the layout and rendering of internationalized
text.

A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping
engine used in Pango. If a user loaded a specially-crafted font file with
an application that uses Pango, it could cause the application to crash or,
possibly, execute arbitrary code with the privileges of the user running
the application. (CVE-2011-3193)

Users of evolution28-pango are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue. After
installing this update, you must restart your system or restart the X
server for the update to take effect.

4. Solution:

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259

5. Bugs fixed (http://bugzilla.redhat.com/):

733118 - CVE-2011-3193 qt/harfbuzz buffer overflow

6. Package List:

Red Hat Enterprise Linux AS version 4:

Source:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/evolution28-pango-1.14.9-13.el4_11.src.rpm

i386:
evolution28-pango-1.14.9-13.el4_11.i386.rpm
evolution28-pango-debuginfo-1.14.9-13.el4_11.i386.rpm
evolution28-pango-devel-1.14.9-13.el4_11.i386.rpm

ia64:
evolution28-pango-1.14.9-13.el4_11.ia64.rpm
evolution28-pango-debuginfo-1.14.9-13.el4_11.ia64.rpm
evolution28-pango-devel-1.14.9-13.el4_11.ia64.rpm

ppc:
evolution28-pango-1.14.9-13.el4_11.ppc.rpm
evolution28-pango-debuginfo-1.14.9-13.el4_11.ppc.rpm
evolution28-pango-devel-1.14.9-13.el4_11.ppc.rpm

s390:
evolution28-pango-1.14.9-13.el4_11.s390.rpm
evolution28-pango-debuginfo-1.14.9-13.el4_11.s390.rpm
evolution28-pango-devel-1.14.9-13.el4_11.s390.rpm

s390x:
evolution28-pango-1.14.9-13.el4_11.s390x.rpm
evolution28-pango-debuginfo-1.14.9-13.el4_11.s390x.rpm
evolution28-pango-devel-1.14.9-13.el4_11.s390x.rpm

x86_64:
evolution28-pango-1.14.9-13.el4_11.x86_64.rpm
evolution28-pango-debuginfo-1.14.9-13.el4_11.x86_64.rpm
evolution28-pango-devel-1.14.9-13.el4_11.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

Source:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/evolution28-pango-1.14.9-13.el4_11.src.rpm

i386:
evolution28-pango-1.14.9-13.el4_11.i386.rpm
evolution28-pango-debuginfo-1.14.9-13.el4_11.i386.rpm
evolution28-pango-devel-1.14.9-13.el4_11.i386.rpm

x86_64:
evolution28-pango-1.14.9-13.el4_11.x86_64.rpm
evolution28-pango-debuginfo-1.14.9-13.el4_11.x86_64.rpm
evolution28-pango-devel-1.14.9-13.el4_11.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

Source:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/evolution28-pango-1.14.9-13.el4_11.src.rpm

i386:
evolution28-pango-1.14.9-13.el4_11.i386.rpm
evolution28-pango-debuginfo-1.14.9-13.el4_11.i386.rpm
evolution28-pango-devel-1.14.9-13.el4_11.i386.rpm

ia64:
evolution28-pango-1.14.9-13.el4_11.ia64.rpm
evolution28-pango-debuginfo-1.14.9-13.el4_11.ia64.rpm
evolution28-pango-devel-1.14.9-13.el4_11.ia64.rpm

x86_64:
evolution28-pango-1.14.9-13.el4_11.x86_64.rpm
evolution28-pango-debuginfo-1.14.9-13.el4_11.x86_64.rpm
evolution28-pango-devel-1.14.9-13.el4_11.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

Source:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/evolution28-pango-1.14.9-13.el4_11.src.rpm

i386:
evolution28-pango-1.14.9-13.el4_11.i386.rpm
evolution28-pango-debuginfo-1.14.9-13.el4_11.i386.rpm
evolution28-pango-devel-1.14.9-13.el4_11.i386.rpm

ia64:
evolution28-pango-1.14.9-13.el4_11.ia64.rpm
evolution28-pango-debuginfo-1.14.9-13.el4_11.ia64.rpm
evolution28-pango-devel-1.14.9-13.el4_11.ia64.rpm

x86_64:
evolution28-pango-1.14.9-13.el4_11.x86_64.rpm
evolution28-pango-debuginfo-1.14.9-13.el4_11.x86_64.rpm
evolution28-pango-devel-1.14.9-13.el4_11.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/#package

7. References:

https://www.redhat.com/security/data/cve/CVE-2011-3193.html
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2011 Red Hat, Inc.
[RHSA-2011:1327-01] Moderate: frysk security update
=====================================================================
Red Hat Security Advisory

Synopsis: Moderate: frysk security update
Advisory ID: RHSA-2011:1327-01
Product: Red Hat Enterprise Linux
Advisory URL: https://rhn.redhat.com/errata/RHSA-2011-1327.html
Issue date: 2011-09-21
CVE Names: CVE-2011-3193
=====================================================================

1. Summary:

An updated frysk package that fixes one security issue is now available for
Red Hat Enterprise Linux 4.

The Red Hat Security Response Team has rated this update as having moderate
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, x86_64
Red Hat Enterprise Linux WS version 4 - i386, x86_64

3. Description:

frysk is an execution-analysis technology implemented using native Java and
C++. It provides developers and system administrators with the ability to
examine and analyze multi-host, multi-process, and multithreaded systems
while they are running. frysk is released as a Technology Preview for Red
Hat Enterprise Linux 4.

A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping
engine used in the embedded Pango library. If a frysk application were used
to debug or trace a process that uses HarfBuzz while it loaded a
specially-crafted font file, it could cause the application to crash or,
possibly, execute arbitrary code with the privileges of the user running
the application. (CVE-2011-3193)

Users of frysk are advised to upgrade to this updated package, which
contains a backported patch to correct this issue. All running frysk
applications must be restarted for this update to take effect.

4. Solution:

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259

5. Bugs fixed (http://bugzilla.redhat.com/):

733118 - CVE-2011-3193 qt/harfbuzz buffer overflow

6. Package List:

Red Hat Enterprise Linux AS version 4:

Source:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/frysk-0.0.1.2007.08.03-8.el4.src.rpm

i386:
frysk-0.0.1.2007.08.03-8.el4.i386.rpm
frysk-debuginfo-0.0.1.2007.08.03-8.el4.i386.rpm

x86_64:
frysk-0.0.1.2007.08.03-8.el4.x86_64.rpm
frysk-debuginfo-0.0.1.2007.08.03-8.el4.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

Source:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/frysk-0.0.1.2007.08.03-8.el4.src.rpm

i386:
frysk-0.0.1.2007.08.03-8.el4.i386.rpm
frysk-debuginfo-0.0.1.2007.08.03-8.el4.i386.rpm

x86_64:
frysk-0.0.1.2007.08.03-8.el4.x86_64.rpm
frysk-debuginfo-0.0.1.2007.08.03-8.el4.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

Source:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/frysk-0.0.1.2007.08.03-8.el4.src.rpm

i386:
frysk-0.0.1.2007.08.03-8.el4.i386.rpm
frysk-debuginfo-0.0.1.2007.08.03-8.el4.i386.rpm

x86_64:
frysk-0.0.1.2007.08.03-8.el4.x86_64.rpm
frysk-debuginfo-0.0.1.2007.08.03-8.el4.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

Source:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/frysk-0.0.1.2007.08.03-8.el4.src.rpm

i386:
frysk-0.0.1.2007.08.03-8.el4.i386.rpm
frysk-debuginfo-0.0.1.2007.08.03-8.el4.i386.rpm

x86_64:
frysk-0.0.1.2007.08.03-8.el4.x86_64.rpm
frysk-debuginfo-0.0.1.2007.08.03-8.el4.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/#package

7. References:

https://www.redhat.com/security/data/cve/CVE-2011-3193.html
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/support/offerings/techpreview/

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2011 Red Hat, Inc.
[RHSA-2011:1326-01] Moderate: pango security update
=====================================================================
Red Hat Security Advisory

Synopsis: Moderate: pango security update
Advisory ID: RHSA-2011:1326-01
Product: Red Hat Enterprise Linux
Advisory URL: https://rhn.redhat.com/errata/RHSA-2011-1326.html
Issue date: 2011-09-21
CVE Names: CVE-2011-3193
=====================================================================

1. Summary:

Updated pango packages that fix one security issue are now available for
Red Hat Enterprise Linux 5.

The Red Hat Security Response Team has rated this update as having moderate
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.

2. Relevant releases/architectures:

RHEL Desktop Workstation (v. 5 client) - i386, x86_64
Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64
Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64

3. Description:

Pango is a library used for the layout and rendering of internationalized
text.

A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping
engine used in Pango. If a user loaded a specially-crafted font file with
an application that uses Pango, it could cause the application to crash or,
possibly, execute arbitrary code with the privileges of the user running
the application. (CVE-2011-3193)

Users of pango are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, you must restart your system or restart the X server for the update
to take effect.

4. Solution:

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259

5. Bugs fixed (http://bugzilla.redhat.com/):

733118 - CVE-2011-3193 qt/harfbuzz buffer overflow

6. Package List:

Red Hat Enterprise Linux Desktop (v. 5 client):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/pango-1.14.9-8.el5_7.3.src.rpm

i386:
pango-1.14.9-8.el5_7.3.i386.rpm
pango-debuginfo-1.14.9-8.el5_7.3.i386.rpm

x86_64:
pango-1.14.9-8.el5_7.3.i386.rpm
pango-1.14.9-8.el5_7.3.x86_64.rpm
pango-debuginfo-1.14.9-8.el5_7.3.i386.rpm
pango-debuginfo-1.14.9-8.el5_7.3.x86_64.rpm

RHEL Desktop Workstation (v. 5 client):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/pango-1.14.9-8.el5_7.3.src.rpm

i386:
pango-debuginfo-1.14.9-8.el5_7.3.i386.rpm
pango-devel-1.14.9-8.el5_7.3.i386.rpm

x86_64:
pango-debuginfo-1.14.9-8.el5_7.3.i386.rpm
pango-debuginfo-1.14.9-8.el5_7.3.x86_64.rpm
pango-devel-1.14.9-8.el5_7.3.i386.rpm
pango-devel-1.14.9-8.el5_7.3.x86_64.rpm

Red Hat Enterprise Linux (v. 5 server):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Server/en/os/SRPMS/pango-1.14.9-8.el5_7.3.src.rpm

i386:
pango-1.14.9-8.el5_7.3.i386.rpm
pango-debuginfo-1.14.9-8.el5_7.3.i386.rpm
pango-devel-1.14.9-8.el5_7.3.i386.rpm

ia64:
pango-1.14.9-8.el5_7.3.i386.rpm
pango-1.14.9-8.el5_7.3.ia64.rpm
pango-debuginfo-1.14.9-8.el5_7.3.i386.rpm
pango-debuginfo-1.14.9-8.el5_7.3.ia64.rpm
pango-devel-1.14.9-8.el5_7.3.ia64.rpm

ppc:
pango-1.14.9-8.el5_7.3.ppc.rpm
pango-1.14.9-8.el5_7.3.ppc64.rpm
pango-debuginfo-1.14.9-8.el5_7.3.ppc.rpm
pango-debuginfo-1.14.9-8.el5_7.3.ppc64.rpm
pango-devel-1.14.9-8.el5_7.3.ppc.rpm
pango-devel-1.14.9-8.el5_7.3.ppc64.rpm

s390x:
pango-1.14.9-8.el5_7.3.s390.rpm
pango-1.14.9-8.el5_7.3.s390x.rpm
pango-debuginfo-1.14.9-8.el5_7.3.s390.rpm
pango-debuginfo-1.14.9-8.el5_7.3.s390x.rpm
pango-devel-1.14.9-8.el5_7.3.s390.rpm
pango-devel-1.14.9-8.el5_7.3.s390x.rpm

x86_64:
pango-1.14.9-8.el5_7.3.i386.rpm
pango-1.14.9-8.el5_7.3.x86_64.rpm
pango-debuginfo-1.14.9-8.el5_7.3.i386.rpm
pango-debuginfo-1.14.9-8.el5_7.3.x86_64.rpm
pango-devel-1.14.9-8.el5_7.3.i386.rpm
pango-devel-1.14.9-8.el5_7.3.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/#package

7. References:

https://www.redhat.com/security/data/cve/CVE-2011-3193.html
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2011 Red Hat, Inc.
[RHSA-2011:1323-01] Moderate: qt security update
=====================================================================
Red Hat Security Advisory

Synopsis: Moderate: qt security update
Advisory ID: RHSA-2011:1323-01
Product: Red Hat Enterprise Linux
Advisory URL: https://rhn.redhat.com/errata/RHSA-2011-1323.html
Issue date: 2011-09-21
CVE Names: CVE-2011-3193 CVE-2011-3194
=====================================================================

1. Summary:

Updated qt packages that fix two security issues are now available for Red
Hat Enterprise Linux 6.

The Red Hat Security Response Team has rated this update as having moderate
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64
Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, noarch, x86_64
Red Hat Enterprise Linux HPC Node (v. 6) - x86_64
Red Hat Enterprise Linux HPC Node Optional (v. 6) - noarch, x86_64
Red Hat Enterprise Linux Server (v. 6) - i386, noarch, ppc64, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 6) - i386, noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64

3. Description:

Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System. HarfBuzz is an OpenType text shaping engine.

A buffer overflow flaw was found in the harfbuzz module in Qt. If a user
loaded a specially-crafted font file with an application linked against Qt,
it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2011-3193)

A buffer overflow flaw was found in the way Qt handled certain gray-scale
image files. If a user loaded a specially-crafted gray-scale image file
with an application linked against Qt, it could cause the application to
crash or, possibly, execute arbitrary code with the privileges of the user
running the application. (CVE-2011-3194)

Users of Qt should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications linked
against Qt libraries must be restarted for this update to take effect.

4. Solution:

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259

5. Bugs fixed (http://bugzilla.redhat.com/):

733118 - CVE-2011-3193 qt/harfbuzz buffer overflow
733119 - CVE-2011-3194 qt buffer overflow in greyscale images

6. Package List:

Red Hat Enterprise Linux Desktop (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Client/en/os/SRPMS/qt-4.6.2-17.el6_1.1.src.rpm

i386:
phonon-backend-gstreamer-4.6.2-17.el6_1.1.i686.rpm
qt-4.6.2-17.el6_1.1.i686.rpm
qt-debuginfo-4.6.2-17.el6_1.1.i686.rpm
qt-mysql-4.6.2-17.el6_1.1.i686.rpm
qt-odbc-4.6.2-17.el6_1.1.i686.rpm
qt-postgresql-4.6.2-17.el6_1.1.i686.rpm
qt-sqlite-4.6.2-17.el6_1.1.i686.rpm
qt-x11-4.6.2-17.el6_1.1.i686.rpm

x86_64:
phonon-backend-gstreamer-4.6.2-17.el6_1.1.i686.rpm
phonon-backend-gstreamer-4.6.2-17.el6_1.1.x86_64.rpm
qt-4.6.2-17.el6_1.1.i686.rpm
qt-4.6.2-17.el6_1.1.x86_64.rpm
qt-debuginfo-4.6.2-17.el6_1.1.i686.rpm
qt-debuginfo-4.6.2-17.el6_1.1.x86_64.rpm
qt-mysql-4.6.2-17.el6_1.1.i686.rpm
qt-mysql-4.6.2-17.el6_1.1.x86_64.rpm
qt-odbc-4.6.2-17.el6_1.1.i686.rpm
qt-odbc-4.6.2-17.el6_1.1.x86_64.rpm
qt-postgresql-4.6.2-17.el6_1.1.i686.rpm
qt-postgresql-4.6.2-17.el6_1.1.x86_64.rpm
qt-sqlite-4.6.2-17.el6_1.1.i686.rpm
qt-sqlite-4.6.2-17.el6_1.1.x86_64.rpm
qt-x11-4.6.2-17.el6_1.1.i686.rpm
qt-x11-4.6.2-17.el6_1.1.x86_64.rpm

Red Hat Enterprise Linux Desktop Optional (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Client/en/os/SRPMS/qt-4.6.2-17.el6_1.1.src.rpm

i386:
qt-debuginfo-4.6.2-17.el6_1.1.i686.rpm
qt-demos-4.6.2-17.el6_1.1.i686.rpm
qt-devel-4.6.2-17.el6_1.1.i686.rpm
qt-examples-4.6.2-17.el6_1.1.i686.rpm

noarch:
qt-doc-4.6.2-17.el6_1.1.noarch.rpm

x86_64:
qt-debuginfo-4.6.2-17.el6_1.1.i686.rpm
qt-debuginfo-4.6.2-17.el6_1.1.x86_64.rpm
qt-demos-4.6.2-17.el6_1.1.x86_64.rpm
qt-devel-4.6.2-17.el6_1.1.i686.rpm
qt-devel-4.6.2-17.el6_1.1.x86_64.rpm
qt-examples-4.6.2-17.el6_1.1.x86_64.rpm

Red Hat Enterprise Linux HPC Node (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6ComputeNode/en/os/SRPMS/qt-4.6.2-17.el6_1.1.src.rpm

x86_64:
phonon-backend-gstreamer-4.6.2-17.el6_1.1.x86_64.rpm
qt-4.6.2-17.el6_1.1.x86_64.rpm
qt-debuginfo-4.6.2-17.el6_1.1.x86_64.rpm
qt-sqlite-4.6.2-17.el6_1.1.x86_64.rpm
qt-x11-4.6.2-17.el6_1.1.x86_64.rpm

Red Hat Enterprise Linux HPC Node Optional (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6ComputeNode/en/os/SRPMS/qt-4.6.2-17.el6_1.1.src.rpm

noarch:
qt-doc-4.6.2-17.el6_1.1.noarch.rpm

x86_64:
phonon-backend-gstreamer-4.6.2-17.el6_1.1.i686.rpm
qt-4.6.2-17.el6_1.1.i686.rpm
qt-debuginfo-4.6.2-17.el6_1.1.i686.rpm
qt-debuginfo-4.6.2-17.el6_1.1.x86_64.rpm
qt-demos-4.6.2-17.el6_1.1.x86_64.rpm
qt-devel-4.6.2-17.el6_1.1.i686.rpm
qt-devel-4.6.2-17.el6_1.1.x86_64.rpm
qt-examples-4.6.2-17.el6_1.1.x86_64.rpm
qt-mysql-4.6.2-17.el6_1.1.i686.rpm
qt-mysql-4.6.2-17.el6_1.1.x86_64.rpm
qt-odbc-4.6.2-17.el6_1.1.i686.rpm
qt-odbc-4.6.2-17.el6_1.1.x86_64.rpm
qt-postgresql-4.6.2-17.el6_1.1.i686.rpm
qt-postgresql-4.6.2-17.el6_1.1.x86_64.rpm
qt-sqlite-4.6.2-17.el6_1.1.i686.rpm
qt-x11-4.6.2-17.el6_1.1.i686.rpm

Red Hat Enterprise Linux Server (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Server/en/os/SRPMS/qt-4.6.2-17.el6_1.1.src.rpm

i386:
phonon-backend-gstreamer-4.6.2-17.el6_1.1.i686.rpm
qt-4.6.2-17.el6_1.1.i686.rpm
qt-debuginfo-4.6.2-17.el6_1.1.i686.rpm
qt-devel-4.6.2-17.el6_1.1.i686.rpm
qt-mysql-4.6.2-17.el6_1.1.i686.rpm
qt-odbc-4.6.2-17.el6_1.1.i686.rpm
qt-postgresql-4.6.2-17.el6_1.1.i686.rpm
qt-sqlite-4.6.2-17.el6_1.1.i686.rpm
qt-x11-4.6.2-17.el6_1.1.i686.rpm

noarch:
qt-doc-4.6.2-17.el6_1.1.noarch.rpm

ppc64:
phonon-backend-gstreamer-4.6.2-17.el6_1.1.ppc.rpm
phonon-backend-gstreamer-4.6.2-17.el6_1.1.ppc64.rpm
qt-4.6.2-17.el6_1.1.ppc.rpm
qt-4.6.2-17.el6_1.1.ppc64.rpm
qt-debuginfo-4.6.2-17.el6_1.1.ppc.rpm
qt-debuginfo-4.6.2-17.el6_1.1.ppc64.rpm
qt-devel-4.6.2-17.el6_1.1.ppc.rpm
qt-devel-4.6.2-17.el6_1.1.ppc64.rpm
qt-mysql-4.6.2-17.el6_1.1.ppc.rpm
qt-mysql-4.6.2-17.el6_1.1.ppc64.rpm
qt-odbc-4.6.2-17.el6_1.1.ppc.rpm
qt-odbc-4.6.2-17.el6_1.1.ppc64.rpm
qt-postgresql-4.6.2-17.el6_1.1.ppc.rpm
qt-postgresql-4.6.2-17.el6_1.1.ppc64.rpm
qt-sqlite-4.6.2-17.el6_1.1.ppc.rpm
qt-sqlite-4.6.2-17.el6_1.1.ppc64.rpm
qt-x11-4.6.2-17.el6_1.1.ppc.rpm
qt-x11-4.6.2-17.el6_1.1.ppc64.rpm

s390x:
phonon-backend-gstreamer-4.6.2-17.el6_1.1.s390.rpm
phonon-backend-gstreamer-4.6.2-17.el6_1.1.s390x.rpm
qt-4.6.2-17.el6_1.1.s390.rpm
qt-4.6.2-17.el6_1.1.s390x.rpm
qt-debuginfo-4.6.2-17.el6_1.1.s390.rpm
qt-debuginfo-4.6.2-17.el6_1.1.s390x.rpm
qt-devel-4.6.2-17.el6_1.1.s390.rpm
qt-devel-4.6.2-17.el6_1.1.s390x.rpm
qt-mysql-4.6.2-17.el6_1.1.s390.rpm
qt-mysql-4.6.2-17.el6_1.1.s390x.rpm
qt-odbc-4.6.2-17.el6_1.1.s390.rpm
qt-odbc-4.6.2-17.el6_1.1.s390x.rpm
qt-postgresql-4.6.2-17.el6_1.1.s390.rpm
qt-postgresql-4.6.2-17.el6_1.1.s390x.rpm
qt-sqlite-4.6.2-17.el6_1.1.s390.rpm
qt-sqlite-4.6.2-17.el6_1.1.s390x.rpm
qt-x11-4.6.2-17.el6_1.1.s390.rpm
qt-x11-4.6.2-17.el6_1.1.s390x.rpm

x86_64:
phonon-backend-gstreamer-4.6.2-17.el6_1.1.i686.rpm
phonon-backend-gstreamer-4.6.2-17.el6_1.1.x86_64.rpm
qt-4.6.2-17.el6_1.1.i686.rpm
qt-4.6.2-17.el6_1.1.x86_64.rpm
qt-debuginfo-4.6.2-17.el6_1.1.i686.rpm
qt-debuginfo-4.6.2-17.el6_1.1.x86_64.rpm
qt-devel-4.6.2-17.el6_1.1.i686.rpm
qt-devel-4.6.2-17.el6_1.1.x86_64.rpm
qt-mysql-4.6.2-17.el6_1.1.i686.rpm
qt-mysql-4.6.2-17.el6_1.1.x86_64.rpm
qt-odbc-4.6.2-17.el6_1.1.i686.rpm
qt-odbc-4.6.2-17.el6_1.1.x86_64.rpm
qt-postgresql-4.6.2-17.el6_1.1.i686.rpm
qt-postgresql-4.6.2-17.el6_1.1.x86_64.rpm
qt-sqlite-4.6.2-17.el6_1.1.i686.rpm
qt-sqlite-4.6.2-17.el6_1.1.x86_64.rpm
qt-x11-4.6.2-17.el6_1.1.i686.rpm
qt-x11-4.6.2-17.el6_1.1.x86_64.rpm

Red Hat Enterprise Linux Server Optional (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Server/en/os/SRPMS/qt-4.6.2-17.el6_1.1.src.rpm

i386:
qt-debuginfo-4.6.2-17.el6_1.1.i686.rpm
qt-demos-4.6.2-17.el6_1.1.i686.rpm
qt-examples-4.6.2-17.el6_1.1.i686.rpm

ppc64:
qt-debuginfo-4.6.2-17.el6_1.1.ppc64.rpm
qt-demos-4.6.2-17.el6_1.1.ppc64.rpm
qt-examples-4.6.2-17.el6_1.1.ppc64.rpm

s390x:
qt-debuginfo-4.6.2-17.el6_1.1.s390x.rpm
qt-demos-4.6.2-17.el6_1.1.s390x.rpm
qt-examples-4.6.2-17.el6_1.1.s390x.rpm

x86_64:
qt-debuginfo-4.6.2-17.el6_1.1.x86_64.rpm
qt-demos-4.6.2-17.el6_1.1.x86_64.rpm
qt-examples-4.6.2-17.el6_1.1.x86_64.rpm

Red Hat Enterprise Linux Workstation (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Workstation/en/os/SRPMS/qt-4.6.2-17.el6_1.1.src.rpm

i386:
phonon-backend-gstreamer-4.6.2-17.el6_1.1.i686.rpm
qt-4.6.2-17.el6_1.1.i686.rpm
qt-debuginfo-4.6.2-17.el6_1.1.i686.rpm
qt-devel-4.6.2-17.el6_1.1.i686.rpm
qt-mysql-4.6.2-17.el6_1.1.i686.rpm
qt-odbc-4.6.2-17.el6_1.1.i686.rpm
qt-postgresql-4.6.2-17.el6_1.1.i686.rpm
qt-sqlite-4.6.2-17.el6_1.1.i686.rpm
qt-x11-4.6.2-17.el6_1.1.i686.rpm

noarch:
qt-doc-4.6.2-17.el6_1.1.noarch.rpm

x86_64:
phonon-backend-gstreamer-4.6.2-17.el6_1.1.i686.rpm
phonon-backend-gstreamer-4.6.2-17.el6_1.1.x86_64.rpm
qt-4.6.2-17.el6_1.1.i686.rpm
qt-4.6.2-17.el6_1.1.x86_64.rpm
qt-debuginfo-4.6.2-17.el6_1.1.i686.rpm
qt-debuginfo-4.6.2-17.el6_1.1.x86_64.rpm
qt-devel-4.6.2-17.el6_1.1.i686.rpm
qt-devel-4.6.2-17.el6_1.1.x86_64.rpm
qt-mysql-4.6.2-17.el6_1.1.i686.rpm
qt-mysql-4.6.2-17.el6_1.1.x86_64.rpm
qt-odbc-4.6.2-17.el6_1.1.i686.rpm
qt-odbc-4.6.2-17.el6_1.1.x86_64.rpm
qt-postgresql-4.6.2-17.el6_1.1.i686.rpm
qt-postgresql-4.6.2-17.el6_1.1.x86_64.rpm
qt-sqlite-4.6.2-17.el6_1.1.i686.rpm
qt-sqlite-4.6.2-17.el6_1.1.x86_64.rpm
qt-x11-4.6.2-17.el6_1.1.i686.rpm
qt-x11-4.6.2-17.el6_1.1.x86_64.rpm

Red Hat Enterprise Linux Workstation Optional (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Workstation/en/os/SRPMS/qt-4.6.2-17.el6_1.1.src.rpm

i386:
qt-debuginfo-4.6.2-17.el6_1.1.i686.rpm
qt-demos-4.6.2-17.el6_1.1.i686.rpm
qt-examples-4.6.2-17.el6_1.1.i686.rpm

x86_64:
qt-debuginfo-4.6.2-17.el6_1.1.x86_64.rpm
qt-demos-4.6.2-17.el6_1.1.x86_64.rpm
qt-examples-4.6.2-17.el6_1.1.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/#package

7. References:

https://www.redhat.com/security/data/cve/CVE-2011-3193.html
https://www.redhat.com/security/data/cve/CVE-2011-3194.html
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2011 Red Hat, Inc.
[RHSA-2011:1324-01] Moderate: qt4 security update
=====================================================================
Red Hat Security Advisory

Synopsis: Moderate: qt4 security update
Advisory ID: RHSA-2011:1324-01
Product: Red Hat Enterprise Linux
Advisory URL: https://rhn.redhat.com/errata/RHSA-2011-1324.html
Issue date: 2011-09-21
CVE Names: CVE-2007-0242 CVE-2011-3193
=====================================================================

1. Summary:

Updated qt4 packages that fix two security issues are now available for Red
Hat Enterprise Linux 5.

The Red Hat Security Response Team has rated this update as having moderate
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.

2. Relevant releases/architectures:

RHEL Desktop Workstation (v. 5 client) - i386, x86_64
Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64
Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64

3. Description:

Qt 4 is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System. HarfBuzz is an OpenType text shaping engine.

A flaw in the way Qt 4 expanded certain UTF-8 characters could be used to
prevent a Qt 4 based application from properly sanitizing user input.
Depending on the application, this could allow an attacker to perform
directory traversal, or for web applications, a cross-site scripting (XSS)
attack. (CVE-2007-0242)

A buffer overflow flaw was found in the harfbuzz module in Qt 4. If a user
loaded a specially-crafted font file with an application linked against Qt
4, it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2011-3193)

Users of Qt 4 should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications linked
against Qt 4 libraries must be restarted for this update to take effect.

4. Solution:

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259

5. Bugs fixed (http://bugzilla.redhat.com/):

234633 - CVE-2007-0242 QT UTF8 improper character expansion
733118 - CVE-2011-3193 qt/harfbuzz buffer overflow

6. Package List:

Red Hat Enterprise Linux Desktop (v. 5 client):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/qt4-4.2.1-1.el5_7.1.src.rpm

i386:
qt4-4.2.1-1.el5_7.1.i386.rpm
qt4-debuginfo-4.2.1-1.el5_7.1.i386.rpm
qt4-doc-4.2.1-1.el5_7.1.i386.rpm
qt4-mysql-4.2.1-1.el5_7.1.i386.rpm
qt4-odbc-4.2.1-1.el5_7.1.i386.rpm
qt4-postgresql-4.2.1-1.el5_7.1.i386.rpm
qt4-sqlite-4.2.1-1.el5_7.1.i386.rpm

x86_64:
qt4-4.2.1-1.el5_7.1.i386.rpm
qt4-4.2.1-1.el5_7.1.x86_64.rpm
qt4-debuginfo-4.2.1-1.el5_7.1.i386.rpm
qt4-debuginfo-4.2.1-1.el5_7.1.x86_64.rpm
qt4-doc-4.2.1-1.el5_7.1.x86_64.rpm
qt4-mysql-4.2.1-1.el5_7.1.x86_64.rpm
qt4-odbc-4.2.1-1.el5_7.1.x86_64.rpm
qt4-postgresql-4.2.1-1.el5_7.1.x86_64.rpm
qt4-sqlite-4.2.1-1.el5_7.1.x86_64.rpm

RHEL Desktop Workstation (v. 5 client):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/qt4-4.2.1-1.el5_7.1.src.rpm

i386:
qt4-debuginfo-4.2.1-1.el5_7.1.i386.rpm
qt4-devel-4.2.1-1.el5_7.1.i386.rpm

x86_64:
qt4-debuginfo-4.2.1-1.el5_7.1.i386.rpm
qt4-debuginfo-4.2.1-1.el5_7.1.x86_64.rpm
qt4-devel-4.2.1-1.el5_7.1.i386.rpm
qt4-devel-4.2.1-1.el5_7.1.x86_64.rpm

Red Hat Enterprise Linux (v. 5 server):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Server/en/os/SRPMS/qt4-4.2.1-1.el5_7.1.src.rpm

i386:
qt4-4.2.1-1.el5_7.1.i386.rpm
qt4-debuginfo-4.2.1-1.el5_7.1.i386.rpm
qt4-devel-4.2.1-1.el5_7.1.i386.rpm
qt4-doc-4.2.1-1.el5_7.1.i386.rpm
qt4-mysql-4.2.1-1.el5_7.1.i386.rpm
qt4-odbc-4.2.1-1.el5_7.1.i386.rpm
qt4-postgresql-4.2.1-1.el5_7.1.i386.rpm
qt4-sqlite-4.2.1-1.el5_7.1.i386.rpm

ia64:
qt4-4.2.1-1.el5_7.1.ia64.rpm
qt4-debuginfo-4.2.1-1.el5_7.1.ia64.rpm
qt4-devel-4.2.1-1.el5_7.1.ia64.rpm
qt4-doc-4.2.1-1.el5_7.1.ia64.rpm
qt4-mysql-4.2.1-1.el5_7.1.ia64.rpm
qt4-odbc-4.2.1-1.el5_7.1.ia64.rpm
qt4-postgresql-4.2.1-1.el5_7.1.ia64.rpm
qt4-sqlite-4.2.1-1.el5_7.1.ia64.rpm

ppc:
qt4-4.2.1-1.el5_7.1.ppc.rpm
qt4-4.2.1-1.el5_7.1.ppc64.rpm
qt4-debuginfo-4.2.1-1.el5_7.1.ppc.rpm
qt4-debuginfo-4.2.1-1.el5_7.1.ppc64.rpm
qt4-devel-4.2.1-1.el5_7.1.ppc.rpm
qt4-devel-4.2.1-1.el5_7.1.ppc64.rpm
qt4-doc-4.2.1-1.el5_7.1.ppc.rpm
qt4-mysql-4.2.1-1.el5_7.1.ppc.rpm
qt4-odbc-4.2.1-1.el5_7.1.ppc.rpm
qt4-postgresql-4.2.1-1.el5_7.1.ppc.rpm
qt4-sqlite-4.2.1-1.el5_7.1.ppc.rpm

s390x:
qt4-4.2.1-1.el5_7.1.s390.rpm
qt4-4.2.1-1.el5_7.1.s390x.rpm
qt4-debuginfo-4.2.1-1.el5_7.1.s390.rpm
qt4-debuginfo-4.2.1-1.el5_7.1.s390x.rpm
qt4-devel-4.2.1-1.el5_7.1.s390.rpm
qt4-devel-4.2.1-1.el5_7.1.s390x.rpm
qt4-doc-4.2.1-1.el5_7.1.s390x.rpm
qt4-mysql-4.2.1-1.el5_7.1.s390x.rpm
qt4-odbc-4.2.1-1.el5_7.1.s390x.rpm
qt4-postgresql-4.2.1-1.el5_7.1.s390x.rpm
qt4-sqlite-4.2.1-1.el5_7.1.s390x.rpm

x86_64:
qt4-4.2.1-1.el5_7.1.i386.rpm
qt4-4.2.1-1.el5_7.1.x86_64.rpm
qt4-debuginfo-4.2.1-1.el5_7.1.i386.rpm
qt4-debuginfo-4.2.1-1.el5_7.1.x86_64.rpm
qt4-devel-4.2.1-1.el5_7.1.i386.rpm
qt4-devel-4.2.1-1.el5_7.1.x86_64.rpm
qt4-doc-4.2.1-1.el5_7.1.x86_64.rpm
qt4-mysql-4.2.1-1.el5_7.1.x86_64.rpm
qt4-odbc-4.2.1-1.el5_7.1.x86_64.rpm
qt4-postgresql-4.2.1-1.el5_7.1.x86_64.rpm
qt4-sqlite-4.2.1-1.el5_7.1.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/#package

7. References:

https://www.redhat.com/security/data/cve/CVE-2007-0242.html
https://www.redhat.com/security/data/cve/CVE-2011-3193.html
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2011 Red Hat, Inc.