CentOS Errata and Security Advisory 2008:0287 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2008-0287.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
x86_64:
0e230c50577aed26926e50d594cca5b2 libxslt-1.1.17-2.el5_1.1.i386.rpm
3181699a50ac93f301c4673c0ef7d59d libxslt-1.1.17-2.el5_1.1.x86_64.rpm
047f647bc2cfe8072435c70037a4ed6c libxslt-devel-1.1.17-2.el5_1.1.i386.rpm
a5e1db39df2bb5bcc68fb44054fb6b7f libxslt-devel-1.1.17-2.el5_1.1.x86_64.rpm
6cc5827917f8924c05d88e63a7e34c86 libxslt-python-1.1.17-2.el5_1.1.x86_64.rpm
Source:
ef97c07be7897cf9346239cb60557173 libxslt-1.1.17-2.el5_1.1.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory CESA-2008:0287
libxslt security update for CentOS 3 x86_64:
https://rhn.redhat.com/errata/RHSA-2008-0287.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
x86_64:
updates/x86_64/RPMS/libxslt-1.0.33-6.i386.rpm
updates/x86_64/RPMS/libxslt-1.0.33-6.x86_64.rpm
updates/x86_64/RPMS/libxslt-devel-1.0.33-6.x86_64.rpm
addons/x86_64/RPMS/libxslt-python-1.0.33-6.x86_64.rpm
source:
updates/SRPMS/libxslt-1.0.33-6.src.rpm
You may update your CentOS-3 x86_64 installations by running the command:
yum update libxslt
Tru
--
Tru Huynh (mirrors, CentOS-3 i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B
CentOS Errata and Security Advisory CESA-2008:0287
libxslt security update for CentOS 3 i386:
https://rhn.redhat.com/errata/RHSA-2008-0287.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
i386:
updates/i386/RPMS/libxslt-1.0.33-6.i386.rpm
updates/i386/RPMS/libxslt-devel-1.0.33-6.i386.rpm
addons/i386/RPMS/libxslt-python-1.0.33-6.i386.rpm
source:
updates/SRPMS/libxslt-1.0.33-6.src.rpm
You may update your CentOS-3 i386 installations by running the command:
yum update libxslt
Tru
--
Tru Huynh (mirrors, CentOS-3 i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B
CentOS Errata and Bugfix Advisory 2008:0280
Upstream details at : https://rhn.redhat.com/errata/RHBA-2008-0280.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
i386:
fe1476d70e4b6587e5b400aa87d98e33 xen-3.0.3-41.el5_1.6.i386.rpm
d816b1d9bcd821873c2795fc5653a50d xen-devel-3.0.3-41.el5_1.6.i386.rpm
446c29eeb926276cee3958194e888edb xen-libs-3.0.3-41.el5_1.6.i386.rpm
Source:
16062424fe0d1d8f0e60d69c6a1e82ad xen-3.0.3-41.el5_1.6.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Bugfix Advisory 2008:0280
Upstream details at : https://rhn.redhat.com/errata/RHBA-2008-0280.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
x86_64:
00aac74a24738e20b60422d7f6095c20 xen-3.0.3-41.el5_1.6.x86_64.rpm
550be917a166ef10df70d94347ad4a4c xen-devel-3.0.3-41.el5_1.6.i386.rpm
d11145a16d9781dc33d5368c2e76e317 xen-devel-3.0.3-41.el5_1.6.x86_64.rpm
34a5389dbc59e7feefcd0c1bda13ba79 xen-libs-3.0.3-41.el5_1.6.i386.rpm
f9623d0a717a6d1f7fd3d391432d04d7 xen-libs-3.0.3-41.el5_1.6.x86_64.rpm
Source:
16062424fe0d1d8f0e60d69c6a1e82ad xen-3.0.3-41.el5_1.6.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2008:0270 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2008-0270.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
x86_64:
78cf5b45956016f3bd4200f4ab68e51b libvorbis-1.1.2-3.el5_1.2.i386.rpm
199d2dadd24c01fa42c0ee842b924b6f libvorbis-1.1.2-3.el5_1.2.x86_64.rpm
65dc9e0a84a6d88dff25e80f1b64d2c4 libvorbis-devel-1.1.2-3.el5_1.2.i386.rpm
7e732e8fb57ca2978cb1dd5d5ee61295 libvorbis-devel-1.1.2-3.el5_1.2.x86_64.rpm
Source:
d63e5567c1dd8a2ee1624799505c3c2b libvorbis-1.1.2-3.el5_1.2.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2008:0270 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2008-0270.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
i386:
1f3bee2fa8673179621849948da4bb8b libvorbis-1.1.2-3.el5_1.2.i386.rpm
78bd9e7a4be68f85f06fc314800d4eed libvorbis-devel-1.1.2-3.el5_1.2.i386.rpm
Source:
d63e5567c1dd8a2ee1624799505c3c2b libvorbis-1.1.2-3.el5_1.2.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Bugfix Advisory 2008:0219
Upstream details at : https://rhn.redhat.com/errata/RHBA-2008-0219.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
x86_64:
6848614cc3bdb00abf10b5de1570098b device-mapper-multipath-0.4.7-12.el5_1.4.x86_64.rpm
5937c6cdf355f631c930961278748573 kpartx-0.4.7-12.el5_1.4.x86_64.rpm
Source:
ad4f7bc83160d9902ba03b2467d06558 device-mapper-multipath-0.4.7-12.el5_1.4.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Bugfix Advisory 2008:0219
Upstream details at : https://rhn.redhat.com/errata/RHBA-2008-0219.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
i386:
595507777df9907e6a514156a1a39e91 device-mapper-multipath-0.4.7-12.el5_1.4.i386.rpm
6dbc1f26ff888504fdc312c5d0cfd72d kpartx-0.4.7-12.el5_1.4.i386.rpm
Source:
ad4f7bc83160d9902ba03b2467d06558 device-mapper-multipath-0.4.7-12.el5_1.4.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Bugfix Advisory 2008:0258
Upstream details at : https://rhn.redhat.com/errata/RHBA-2008-0258.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
i386:
97f048f9e25b96598e6666ce8ade3f79 mcstrans-0.2.7-1.el5.i386.rpm
Source:
c4d891a0a78fa4b39e186671862bf38e mcstrans-0.2.7-1.el5.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Bugfix Advisory 2008:0258
Upstream details at : https://rhn.redhat.com/errata/RHBA-2008-0258.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
x86_64:
6fe63939ed264c22999fb31a32824c29 mcstrans-0.2.7-1.el5.x86_64.rpm
Source:
c4d891a0a78fa4b39e186671862bf38e mcstrans-0.2.7-1.el5.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2008:0270
https://rhn.redhat.com/errata/RHSA-2008-0270.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
s390:
updates/s390/RPMS/libvorbis-1.1.0-3.c4.1.s390.rpm
updates/s390/RPMS/libvorbis-devel-1.1.0-3.c4.1.s390.rpm
s390x:
updates/s390x/RPMS/libvorbis-1.1.0-3.c4.1.s390x.rpm
updates/s390x/RPMS/libvorbis-devel-1.1.0-3.c4.1.s390x.rpm
--
Pasi Pirhonen - upi(a)iki.fi - http://pasi.pirhonen.eu/
Top-postings silently ignored
CentOS Errata and Security Advisory 2008:0270
https://rhn.redhat.com/errata/RHSA-2008-0270.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
ia64:
updates/ia64/RPMS/libvorbis-1.1.0-3.c4.1.ia64.rpm
updates/ia64/RPMS/libvorbis-devel-1.1.0-3.c4.1.ia64.rpm
--
Pasi Pirhonen - upi(a)iki.fi - http://pasi.pirhonen.eu/
Top-postings silently ignored
CentOS Errata and Security Advisory 2008:0270
https://rhn.redhat.com/errata/RHSA-2008-0270.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
s390:
updates/s390/RPMS/libvorbis-1.0-10.el3.s390.rpm
updates/s390/RPMS/libvorbis-devel-1.0-10.el3.s390.rpm
s390x:
updates/s390x/RPMS/libvorbis-1.0-10.el3.s390x.rpm
updates/s390x/RPMS/libvorbis-devel-1.0-10.el3.s390x.rpm
--
Pasi Pirhonen - upi(a)iki.fi - http://pasi.pirhonen.eu/
Top-postings silently ignored
CentOS Errata and Security Advisory 2008:0270
https://rhn.redhat.com/errata/RHSA-2008-0270.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
ia64:
updates/ia64/RPMS/libvorbis-1.0-10.el3.ia64.rpm
updates/ia64/RPMS/libvorbis-devel-1.0-10.el3.ia64.rpm
--
Pasi Pirhonen - upi(a)iki.fi - http://pasi.pirhonen.eu/
Top-postings silently ignored
The following errata for CentOS-2 have been built and uploaded to the
centos mirror:
RHSA-2008:0271-01 Important: libvorbis security update
Files available:
libvorbis-1.0rc2-9.el2.i386.rpm
libvorbis-devel-1.0rc2-9.el2.i386.rpm
More details are available from the RedHat web site at
https://rhn.redhat.com/errata/rh21as-errata.html
The easy way to make sure you are up to date with all the latest patches
is to run:
# yum update
--
John Newbigin
ITS Senior Analyst / Programmer
Faculty of Information and Communication Technologies
Swinburne University of Technology
Melbourne, Australia
http://www.ict.swin.edu.au/staff/jnewbigin
CentOS Errata and Security Advisory 2008:0194 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2008-0194.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
x86_64:
c7f5f0b8fc0ded6a071c537ab490edff xen-3.0.3-41.el5_1.5.x86_64.rpm
af6fb05cfebd799f9071cc3e83f561c1 xen-devel-3.0.3-41.el5_1.5.i386.rpm
3b697c6fdc46dbd2e939da6a334c9220 xen-devel-3.0.3-41.el5_1.5.x86_64.rpm
bc77d399eb72833ed5ca4dcfffe599e0 xen-libs-3.0.3-41.el5_1.5.i386.rpm
9662e7449f8a764cc022f6110a8def5a xen-libs-3.0.3-41.el5_1.5.x86_64.rpm
Source:
32a42dbc51a00c12719ae6c5405439b1 xen-3.0.3-41.el5_1.5.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2008:0194 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2008-0194.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
i386:
895491c081517cb49e65fdcc73b11291 xen-3.0.3-41.el5_1.5.i386.rpm
fca59354c0adf82110f6b647681aea80 xen-devel-3.0.3-41.el5_1.5.i386.rpm
574f651c259c429ceddc4b8ef2d8eb95 xen-libs-3.0.3-41.el5_1.5.i386.rpm
Source:
32a42dbc51a00c12719ae6c5405439b1 xen-3.0.3-41.el5_1.5.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos(a)irc.freenode.net
A severe vulnerability was found in the random number generator (RNG)
of the Debian OpenSSL package, starting with version 0.9.8c-1 (and
similar packages in derived distributions such as Ubuntu). While this
bug is not present in the OpenSSL packages provided by CentOS, it may
still affect CentOS users.
The bug barred the OpenSSL random number generator from gaining enough
entropy required for generating unpredicatable keys. In fact it
appearss that the only source for entropy was the process ID of the
process generating a key, which is chosen from a very small range and
is predictable. As such, all keys generated using the Debian OpenSSL
library should be considered compromized. Programs that use OpenSSL
include OpenSSH and OpenVPN. Note that GnuPG and GNU TLS do not use
OpenSSL, so they are not affected.
This vulnerability can affect CentOS machines through the use of keys
that were generated with the OpenSSL package from Debian. For
instance, if a user uses OpenSSH public key authentication to log on
to a CentOS server, and this user generated the key pair with a
vulnerable OpenSSL library, the server is at heavy risk because the
key can be reproduced easily.
Additionally, all (good) DSA keys that were ever used on a vulnerable
Debian machine for signing or authentication should also be considered
compromized due to a known attack on DSA keys.
As a result of this bug, everyone should audit *every* key or
cerficicate that was generated with OpenSSL, to trace its origin and
make sure that it was not generated with a vulnerable Debian OpenSSL
package. Or in the case of DSA keys care should be taken that they
were not generated or used on a system with a vulnerable OpenSSL
package. Keys that are potentially compromised should be replaced with
strong keys.
The Debian Wiki[2] has a preliminary list of affected application. A
tool to detect potentially weak keys is also provided, but it contains
an incomplete list of affected keys and can give false positives.
The Metasploit project provides a full list of weak keys in various
configurations[3].
Questions on how this may affect CentOS users should be directed to
the CentOS users list. List subscription information is available
from:
http://lists.centos.org/mailman/listinfo/centos
With kind regards,
The CentOS Team
[1] http://www.debian.org/security/2008/dsa-1571
[2] http://wiki.debian.org/SSLkeys
[3] http://metasploit.com/users/hdm/tools/debian-openssl/
CentOS Errata and Security Advisory 2008:0270 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2008-0270.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
i386:
libvorbis-1.1.0-3.el4_6.1.i386.rpm
libvorbis-devel-1.1.0-3.el4_6.1.i386.rpm
src:
libvorbis-1.1.0-3.el4_6.1.src.rpm
CentOS Errata and Security Advisory 2008:0270 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2008-0270.html
The following updated files have been uploaded and are currently
syncing to the mirrors:
x86_64:
libvorbis-1.1.0-3.el4_6.1.i386.rpm
libvorbis-1.1.0-3.el4_6.1.x86_64.rpm
libvorbis-devel-1.1.0-3.el4_6.1.x86_64.rpm
src:
libvorbis-1.1.0-3.el4_6.1.src.rpm
CentOS Errata and Security Advisory CESA-2008:0270
libvorbis security update for CentOS 3 x86_64:
https://rhn.redhat.com/errata/RHSA-2008-0270.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
x86_64:
updates/x86_64/RPMS/libvorbis-1.0-10.el3.i386.rpm
updates/x86_64/RPMS/libvorbis-1.0-10.el3.x86_64.rpm
updates/x86_64/RPMS/libvorbis-devel-1.0-10.el3.x86_64.rpm
source:
updates/SRPMS/libvorbis-1.0-10.el3.src.rpm
You may update your CentOS-3 x86_64 installations by running the command:
yum update libvorbis\*
Tru
--
Tru Huynh (mirrors, CentOS-3 i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B
CentOS Errata and Security Advisory CESA-2008:0270
libvorbis security update for CentOS 3 i386:
https://rhn.redhat.com/errata/RHSA-2008-0270.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
i386:
updates/i386/RPMS/libvorbis-1.0-10.el3.i386.rpm
updates/i386/RPMS/libvorbis-devel-1.0-10.el3.i386.rpm
source:
updates/SRPMS/libvorbis-1.0-10.el3.src.rpm
You may update your CentOS-3 i386 installations by running the command:
yum update libvorbis\*
Tru
--
Tru Huynh (mirrors, CentOS-3 i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B