CentOS Errata and Security Advisory CESA-2008:0849
ipsec-tools security update for CentOS 3 i386:
https://rhn.redhat.com/errata/RHSA-2008-0849.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
i386:
updates/i386/RPMS/ipsec-tools-0.2.5-0.7.rhel3.5.i386.rpm
source:
updates/SRPMS/ipsec-tools-0.2.5-0.7.rhel3.5.src.rpm
You may update your CentOS-3 i386 installations by running the command:
yum update ipsec-tools
Tru
--
Tru Huynh (mirrors, CentOS-3 i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B
The following errata for CentOS-2 have been built and uploaded to the
centos mirror:
RHSA-2008:0836-02 Moderate: libxml2 security update
Files available:
libxml2-2.4.19-9.ent.i386.rpm
libxml2-devel-2.4.19-9.ent.i386.rpm
libxml2-python-2.4.19-9.ent.i386.rpm
More details are available from the RedHat web site at
https://rhn.redhat.com/errata/rh21as-errata.html
The easy way to make sure you are up to date with all the latest patches
is to run:
# yum update
--
John Newbigin
ITS Senior Analyst / Programmer
Faculty of Information and Communication Technologies
Swinburne University of Technology
Melbourne, Australia
http://www.ict.swin.edu.au/staff/jnewbigin
CentOS Errata and Security Advisory 2008:0839
https://rhn.redhat.com/errata/RHSA-2008-0839.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
s390:
updates/s390/RPMS/postfix-2.2.10-1.2.1.c4.s390.rpm
updates/s390/RPMS/postfix-pflogsumm-2.2.10-1.2.1.c4.s390.rpm
s390x:
updates/s390x/RPMS/postfix-2.2.10-1.2.1.c4.s390x.rpm
updates/s390x/RPMS/postfix-pflogsumm-2.2.10-1.2.1.c4.s390x.rpm
--
Pasi Pirhonen - upi(a)iki.fi - http://pasi.pirhonen.eu/
Top-postings silently ignored
CentOS Errata and Security Advisory 2008:0855
https://rhn.redhat.com/errata/RHSA-2008-0855.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
s390:
updates/s390/RPMS/openssh-3.9p1-11.c4.s390.rpm
updates/s390/RPMS/openssh-askpass-3.9p1-11.c4.s390.rpm
updates/s390/RPMS/openssh-askpass-gnome-3.9p1-11.c4.s390.rpm
updates/s390/RPMS/openssh-clients-3.9p1-11.c4.s390.rpm
updates/s390/RPMS/openssh-server-3.9p1-11.c4.s390.rpm
s390x:
updates/s390x/RPMS/openssh-3.9p1-11.c4.s390x.rpm
updates/s390x/RPMS/openssh-askpass-3.9p1-11.c4.s390x.rpm
updates/s390x/RPMS/openssh-askpass-gnome-3.9p1-11.c4.s390x.rpm
updates/s390x/RPMS/openssh-clients-3.9p1-11.c4.s390x.rpm
updates/s390x/RPMS/openssh-server-3.9p1-11.c4.s390x.rpm
--
Pasi Pirhonen - upi(a)iki.fi - http://pasi.pirhonen.eu/
Top-postings silently ignored
CentOS Errata and Security Advisory 2008:0836
https://rhn.redhat.com/errata/RHSA-2008-0836.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
s390:
updates/s390/RPMS/libxml2-2.6.16-12.2.s390.rpm
updates/s390/RPMS/libxml2-devel-2.6.16-12.2.s390.rpm
updates/s390/RPMS/libxml2-python-2.6.16-12.2.s390.rpm
s390x:
updates/s390x/RPMS/libxml2-2.6.16-12.2.s390x.rpm
updates/s390x/RPMS/libxml2-devel-2.6.16-12.2.s390x.rpm
updates/s390x/RPMS/libxml2-python-2.6.16-12.2.s390x.rpm
--
Pasi Pirhonen - upi(a)iki.fi - http://pasi.pirhonen.eu/
Top-postings silently ignored
CentOS Errata and Security Advisory 2008:0839
https://rhn.redhat.com/errata/RHSA-2008-0839.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
s390:
updates/s390/RPMS/postfix-2.0.16-14.1.RHEL3.s390.rpm
s390x:
updates/s390x/RPMS/postfix-2.0.16-14.1.RHEL3.s390x.rpm
--
Pasi Pirhonen - upi(a)iki.fi - http://pasi.pirhonen.eu/
Top-postings silently ignored
CentOS Errata and Security Advisory 2008:0836
https://rhn.redhat.com/errata/RHSA-2008-0836.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
s390:
updates/s390/RPMS/libxml2-2.5.10-10.s390.rpm
updates/s390/RPMS/libxml2-devel-2.5.10-10.s390.rpm
updates/s390/RPMS/libxml2-python-2.5.10-10.s390.rpm
s390x:
updates/s390x/RPMS/libxml2-2.5.10-10.s390x.rpm
updates/s390x/RPMS/libxml2-devel-2.5.10-10.s390x.rpm
updates/s390x/RPMS/libxml2-python-2.5.10-10.s390x.rpm
--
Pasi Pirhonen - upi(a)iki.fi - http://pasi.pirhonen.eu/
Top-postings silently ignored
CentOS Errata and Security Advisory 2008:0855
https://rhn.redhat.com/errata/RHSA-2008-0855.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
ia64:
updates/ia64/RPMS/openssh-3.9p1-11.c4.ia64.rpm
updates/ia64/RPMS/openssh-askpass-3.9p1-11.c4.ia64.rpm
updates/ia64/RPMS/openssh-askpass-gnome-3.9p1-11.c4.ia64.rpm
updates/ia64/RPMS/openssh-clients-3.9p1-11.c4.ia64.rpm
updates/ia64/RPMS/openssh-server-3.9p1-11.c4.ia64.rpm
--
Pasi Pirhonen - upi(a)iki.fi - http://pasi.pirhonen.eu/
Top-postings silently ignored
CentOS Errata and Security Advisory 2008:0839
https://rhn.redhat.com/errata/RHSA-2008-0839.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
ia64:
updates/ia64/RPMS/postfix-2.2.10-1.2.1.c4.ia64.rpm
updates/ia64/RPMS/postfix-pflogsumm-2.2.10-1.2.1.c4.ia64.rpm
--
Pasi Pirhonen - upi(a)iki.fi - http://pasi.pirhonen.eu/
Top-postings silently ignored
CentOS Errata and Security Advisory 2008:0836
https://rhn.redhat.com/errata/RHSA-2008-0836.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
ia64:
updates/ia64/RPMS/libxml2-2.6.16-12.2.ia64.rpm
updates/ia64/RPMS/libxml2-devel-2.6.16-12.2.ia64.rpm
updates/ia64/RPMS/libxml2-python-2.6.16-12.2.ia64.rpm
--
Pasi Pirhonen - upi(a)iki.fi - http://pasi.pirhonen.eu/
Top-postings silently ignored
CentOS Errata and Security Advisory 2008:0839
https://rhn.redhat.com/errata/RHSA-2008-0839.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
ia64:
updates/ia64/RPMS/postfix-2.0.16-14.1.RHEL3.ia64.rpm
--
Pasi Pirhonen - upi(a)iki.fi - http://pasi.pirhonen.eu/
Top-postings silently ignored
CentOS Errata and Security Advisory 2008:0836
https://rhn.redhat.com/errata/RHSA-2008-0836.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
ia64:
updates/ia64/RPMS/libxml2-2.5.10-10.ia64.rpm
updates/ia64/RPMS/libxml2-devel-2.5.10-10.ia64.rpm
updates/ia64/RPMS/libxml2-python-2.5.10-10.ia64.rpm
--
Pasi Pirhonen - upi(a)iki.fi - http://pasi.pirhonen.eu/
Top-postings silently ignored
Earlier in the day today Red Hat made an announcement [1] that there had been an
intrusion into some of their computer systems last week. In the same
announcement they mention that some of the packages for OpenSSH on RHEL-4 ( i386
and x86_64 ) as well as RHEL-5 ( x86_64 ) were signed by the intruder. In their
announcement they also clarified that they were confident that none of these,
potentially compromised, packages made their way into or through RHN to client
and customer machines. As a security measure a script [3] was made available
along with a semi-detailed description of the issue [2].
We take security issues very seriously, and as soon as we were made aware of the
situation I undertook a complete audit of the entire CentOS4/5 Build and Signing
infrastructure. We can now assure everyone that no compromise has taken place
anywhere within the CentOS Infrastructure. Our entire setup is located behind
multiple firewalls, and only accessible from a very small number of
places, by only a few people. Also included in this audit were all entry points
to the build services, signing machines, primary release machines and
connectivity between all these hosts.
Since OpenSSH is a critical component of any Linux machine, we considered it
essential to audit the last two released package sets (
openssh-4.3p2-26.el5.src.rpm, openssh-4.3p2-26.el5_2.1.src.rpm ). I have just
finished this code audit, and can assure everyone that there is no compromised
code included in either of these packages. A similar check is also being done
for the CentOS-4 sources.
Packages released today, by upstream, ( based on :
openssh-4.3p2-26.el5_2.1.src.rpm, openssh-3.9p1-11.el4_7.src.rpm ) address two
issues. Firstly they contain a fix for
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4752 . And secondly, in
the remote event that someone had indeed got compromised packages via RHN, their
packages would get updated to a known good state. We wanted to get these
packages out right away to address the first issue, and also to cover users
converting non updated RHEL installs to CentOS in the next few weeks/months.
Release of these packages into the mirror.centos.org network does *not* imply
that CentOS users are affected by the intrusion at Red Hat.
Finally, while we feel confident that there is no possibility of this compromise
having been passed onto the CentOS userbase, we still encourage users to verify
their packages independently using whatever resources they might have available.
--
[1]: https://rhn.redhat.com/errata/RHSA-2008-0855.html
[2]: http://www.redhat.com/security/data/openssh-blacklist.html
[3]: https://www.redhat.com/security/data/openssh-blacklist-1.0.sh :Its
important to note that this script *only* checks for packages built within
Red Hat, and will *not* be a reliable source of verification on CentOS since we
rebuild from sources, using no Red Hat binary.
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2008:0855 Critical
Upstream details at : https://rhn.redhat.com/errata/RHSA-2008-0855.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
i386:
d45c32890088d835ce8bc4a569173775 openssh-4.3p2-26.el5_2.1.i386.rpm
7f8194567e7797d834c22090d9c55b69 openssh-askpass-4.3p2-26.el5_2.1.i386.rpm
c145d732591711659b5fe756a4e9a085 openssh-clients-4.3p2-26.el5_2.1.i386.rpm
2b1fdc9b245f2c8cd873ea7f8e3b900c openssh-server-4.3p2-26.el5_2.1.i386.rpm
Source:
278cfb304350f3604fb64ebaee3f1b77 openssh-4.3p2-26.el5_2.1.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2008:0855 Critical
Upstream details at : https://rhn.redhat.com/errata/RHSA-2008-0855.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
x86_64:
161c953e8c1c47c09542020837e9920b openssh-4.3p2-26.el5_2.1.x86_64.rpm
12b02fb6e6d1e8354539cd4cba304803 openssh-askpass-4.3p2-26.el5_2.1.x86_64.rpm
c281a62dc3c21f1225ea309757b755d1 openssh-clients-4.3p2-26.el5_2.1.x86_64.rpm
01b3486f17ecb4adc7c59074525b7fd9 openssh-server-4.3p2-26.el5_2.1.x86_64.rpm
Source:
278cfb304350f3604fb64ebaee3f1b77 openssh-4.3p2-26.el5_2.1.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2008:0818 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2008-0818.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
i386:
12ed57905be0034361f4357f7ebfb580 postfix-2.3.3-2.1.el5_2.i386.rpm
5f45b128714174964caf8b5633d9723f postfix-pflogsumm-2.3.3-2.1.el5_2.i386.rpm
Source:
bf3130ae011fc9d69bcd43a8c29d4811 postfix-2.3.3-2.1.el5_2.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2008:0818 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2008-0818.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
x86_64:
cfcd76e57b844ea28a53de43f9262cb4 postfix-2.3.3-2.1.el5_2.x86_64.rpm
7bebb4b9264b5ceac8c736c75a95155b postfix-pflogsumm-2.3.3-2.1.el5_2.x86_64.rpm
Source:
bf3130ae011fc9d69bcd43a8c29d4811 postfix-2.3.3-2.1.el5_2.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2008:0839 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2008-0839.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
x86_64:
cfcd76e57b844ea28a53de43f9262cb4 postfix-2.3.3-2.1.el5_2.x86_64.rpm
7bebb4b9264b5ceac8c736c75a95155b postfix-pflogsumm-2.3.3-2.1.el5_2.x86_64.rpm
Source:
bf3130ae011fc9d69bcd43a8c29d4811 postfix-2.3.3-2.1.el5_2.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2008:0839 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2008-0839.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
i386:
12ed57905be0034361f4357f7ebfb580 postfix-2.3.3-2.1.el5_2.i386.rpm
5f45b128714174964caf8b5633d9723f postfix-pflogsumm-2.3.3-2.1.el5_2.i386.rpm
Source:
bf3130ae011fc9d69bcd43a8c29d4811 postfix-2.3.3-2.1.el5_2.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory CESA-2008:0839
postfix security update for CentOS 3 x86_64:
https://rhn.redhat.com/errata/RHSA-2008-0839.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
x86_64:
updates/x86_64/RPMS/postfix-2.0.16-14.1.RHEL3.x86_64.rpm
source:
updates/SRPMS/postfix-2.0.16-14.1.RHEL3.src.rpm
You may update your CentOS-3 x86_64 installations by running the command:
yum update postfix
Tru
--
Tru Huynh (mirrors, CentOS-3 i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B
CentOS Errata and Security Advisory CESA-2008:0839
postfix security update for CentOS 3 i386:
https://rhn.redhat.com/errata/RHSA-2008-0839.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
i386:
updates/i386/RPMS/postfix-2.0.16-14.1.RHEL3.i386.rpm
source:
updates/SRPMS/postfix-2.0.16-14.1.RHEL3.src.rpm
You may update your CentOS-3 i386 installations by running the command:
yum update postfix
Tru
--
Tru Huynh (mirrors, CentOS-3 i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B
CentOS Errata and Bugfix Advisory 2008:0824
Upstream details at : https://rhn.redhat.com/errata/RHBA-2008-0824.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
x86_64:
288c7979157a76555734c4dd532803cf strace-4.5.16-1.el5_2.2.x86_64.rpm
Source:
4f46275678d5a11a8d8ceacd3d9c241a strace-4.5.16-1.el5_2.2.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Bugfix Advisory 2008:0824
Upstream details at : https://rhn.redhat.com/errata/RHBA-2008-0824.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
i386:
dba0f8d0a2aca6aca15bd81d63a0b295 strace-4.5.16-1.el5_2.2.i386.rpm
Source:
4f46275678d5a11a8d8ceacd3d9c241a strace-4.5.16-1.el5_2.2.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net