• Home
  • Et Cetera

Infosecurity.US

Oracle Releases Multiple EL Patches, SELinux, XPDF, Et Cetera

By Marc Handelman on October 17th, 2009

Oracle Toys With The Penguin

Oracle Corporation (NasdaqGS: ORCL) has released the Redwood Shores, CA based company’s latest Enterprise Linux  patches; of particular interest to us is the SELinux Policy Bug Fix Updates. The updates to Oracle’s Enterprise Linux operating system are available via the company’s Unbreakable Linux Network (ULN) site. Oracle Enterprise Linux is a variant of RED HAT, INC.’s (NYSE: RHT)  Red Hat Enterprise Linux OS. Additional information inclusive of release notes and linkage may be accessed after the jump.

Enterprise Linux Bug Fix Advisory ELBA-2009-1515

https://rhn.redhat.com/errata/RHBA-2009-1515.html

The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network:

i386:device-mapper-multipath-0.4.7.30.el5_4.2.i386.rpm
kpartx-0.4.7-30.el5_4.2.i386.rpm

x86_64:
device-mapper-multipath-0.4.7-30.el5_4.2.x86_64.rpm
kpartx-0.4.7-30.el5_4.2.x86_64.rpm

ia64:
device-mapper-multipath-0.4.7-30.el5_4.2.ia64.rpm
kpartx-0.4.7-30.el5_4.2.ia64.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/device-mapper-multipath-0.4.7-30.el5_4.2.src.rpm

Description of changes:

[0.4.7-30.el5_4.1]
- Added kpartx-fix-large-minor-devices.patch
- Resolves: bz #528132

[0.4.7-30.el5_4.1]
- Added 515171_new_hardware.patch
- Resolves: bz #523392

—

Enterprise Linux Bug Fix Advisory ELBA-2009-1495

https://rhn.redhat.com/errata/RHBA-2009-1495.html

The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network:

i386:selinux-policy-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-devel-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-minimum-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-mls-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-strict-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-targeted-2.4.6-255.el5_4.1.noarch.rpm

x86_64:
selinux-policy-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-devel-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-minimum-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-mls-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-strict-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-targeted-2.4.6-255.el5_4.1.noarch.rpm

ia64:
selinux-policy-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-devel-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-minimum-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-mls-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-strict-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-targeted-2.4.6-255.el5_4.1.noarch.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/selinux-policy-2.4.6-255.el5_4.1.src.rpm

Description of changes:

[2.4.6-255.el5_4.1]
- Allow cyrus to stream connect to snmp
Resolves: bz523927

—
Enterprise Linux Bug Fix Advisory ELBA-2009-1494

https://rhn.redhat.com/errata/RHBA-2009-1494.html

The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network:

i386:tcsh-6.14-14.el5_4.2.i386.rpm
x86_64:tcsh-6.14-14.el5_4.2.x86_64.rpm
ia64:tcsh-6.14-14.el5_4.2.ia64.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/tcsh-6.14-14.el5_4.2.src.rpm

Description of changes:

[6.14-14.2]
- Fix broken globbing error reporting

[6.14-14.1]
- Fix tcsh globbing causing bad automount
Resolves: #526459

—
Oracle VM Security Advisory OVMSA-2009-0023

The following updated rpms for Oracle VM 2.1 have been uploaded to the Unbreakable Linux Network:

i386:
kernel-BOOT-devel-2.6.18-8.1.15.6.2.el5.i686.rpm
kernel-BOOT-2.6.18-8.1.15.6.2.el5.i686.rpm
kernel-kdump-2.6.18-8.1.15.6.2.el5.i686.rpm
kernel-kdump-devel-2.6.18-8.1.15.6.2.el5.i686.rpm
kernel-ovs-2.6.18-8.1.15.6.2.el5.i686.rpm
kernel-ovs-devel-2.6.18-8.1.15.6.2.el5.i686.rpm

SRPMS:
http://oss.oracle.com/oraclevm/server/SRPMS-updates/kernel-2.6.18-8.1.15.6.2.el5.src.rpm

Description of changes:
[2.6.18-8.1.15.6.2.el5]
- backport for online resize of blockdev [orabug 8585251] [rh bugz 444964]
- CVE-2009-2692 - [net] make sock_sendpage use kernel_sendpage (Jiri Pirko ) [517445 516955]
- CVE-2009-2698 - [net] prevent null pointer dereference in udp_sendmsg (Vitaly Mayatskikh) [518047 518043]

[2.6.18-8.1.15.6.1.el5]
- Updated cciss module to 3.6.20 (wiekus.beukes@oracle.com)
- update bnx2x 1.48.107 (kurt.hackel@oracle.com)
- update bnx2 1.8.8b (kurt.hackel@oracle.com)

[2.6.18-8.1.15.5.3.el5]
- update bfa to 1.1.0.9-0 [bugz 9518]

[2.6.18-8.1.15.5.2.el5]
- Fix dom0 crash in loopback_start_xmit+0x107/0x2BD (tina.yang@oracle.com) [bug 7634343]

—
Enterprise Linux Bug Fix Advisory ELBA-2009-1514

https://rhn.redhat.com/errata/RHBA-2009-1514.html

The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network:

i386:
xen-libs-3.0.3-94.el5_4.2.i386.rpm
xen-3.0.3-94.el5_4.2.i386.rpm
xen-devel-3.0.3-94.el5_4.2.i386.rpm

x86_64:
xen-libs-3.0.3-94.el5_4.2.i386.rpm
xen-libs-3.0.3-94.el5_4.2.x86_64.rpm
xen-3.0.3-94.el5_4.2.x86_64.rpm
xen-devel-3.0.3-94.el5_4.2.i386.rpm
xen-devel-3.0.3-94.el5_4.2.x86_64.rpm

ia64:
xen-libs-3.0.3-94.el5_4.2.ia64.rpm
xen-3.0.3-94.el5_4.2.ia64.rpm
xen-devel-3.0.3-94.el5_4.2.ia64.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/xen-3.0.3-94.el5_4.2.src.rpm

Description of changes:

[3.0.3-94.el5_4.2]
- Fix memory leaks in lib{xc, xenstore} python bindings (rhbz 528163)

—
Enterprise Linux Bug Fix Advisory ELBA-2009-1510

https://rhn.redhat.com/errata/RHBA-2009-1510.html

The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network:

i386:
rgmanager-2.0.52-1.0.1.el5_4.1.i386.rpm
x86_64:rgmanager-2.0.52-1.0.1.el5_4.1.x86_64.rpm

ia64:rgmanager-2.0.52-1.0.1.el5_4.1.ia64.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/rgmanager-2.0.52-1.0.1.el5_4.1.src.rpm

Description of changes:

[2.0.52-1.0.1.el5_4.1]
- Update summary and description in specfile to be vendor neutral

[2.0.52-1.el5_4.1]
- Fix missing path support in vm.sh
- Resolves: rhbz#524213 (519786)

—
Enterprise Linux Security Advisory ELSA-2009-1513

https://rhn.redhat.com/errata/RHSA-2009-1513.html

The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network:

i386:
cups-1.3.7-11.el5_4.3.i386.rpm
cups-devel-1.3.7-11.el5_4.3.i386.rpm
cups-libs-1.3.7-11.el5_4.3.i386.rpm
cups-lpd-1.3.7-11.el5_4.3.i386.rpm

x86_64:
cups-1.3.7-11.el5_4.3.x86_64.rpm
cups-devel-1.3.7-11.el5_4.3.i386.rpm
cups-devel-1.3.7-11.el5_4.3.x86_64.rpm
cups-libs-1.3.7-11.el5_4.3.i386.rpm
cups-libs-1.3.7-11.el5_4.3.x86_64.rpm
cups-lpd-1.3.7-11.el5_4.3.x86_64.rpm

ia64:
cups-1.3.7-11.el5_4.3.ia64.rpm
cups-devel-1.3.7-11.el5_4.3.ia64.rpm
cups-libs-1.3.7-11.el5_4.3.i386.rpm
cups-libs-1.3.7-11.el5_4.3.ia64.rpm
cups-lpd-1.3.7-11.el5_4.3.ia64.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/cups-1.3.7-11.el5_4.3.src.rpm

Description of changes:

[1:1.3.7-11:.3]
- Include NULL pointer check in ObjectStream::getObject.  Part of the
fix for CVE-2009-3608 (bug #526637).

[1:1.3.7-11:.2]
- Applied patch to fix CVE-2009-3608 (bug #526637) and
CVE-2009-3609 (bug #526893).

—
Enterprise Linux Security Advisory ELSA-2009-1504

https://rhn.redhat.com/errata/RHSA-2009-1504.html

The following updated rpms for Enterprise Linux 5 have been uploaded tothe Unbreakable Linux Network:

i386:poppler-0.5.4-4.4.el5_4.11.

—
Enterprise Linux Bug Fix Advisory ELBA-2009-1511

https://rhn.redhat.com/errata/RHBA-2009-1511.html

The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network:

i386:coreutils-5.97-23.el5_4.1.i386.rpm

x86_64:coreutils-5.97-23.el5_4.1.x86_64.rpm

ia64:coreutils-5.97-23.el5_4.1.ia64.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/coreutils-5.97-23.el5_4.1.src.rpm

Description of changes:

[5.97-23.1]
[as regular user]
cause “Permission denied” (#520630, introduced by fix for
rhbz #497830)

—
Enterprise Linux Security Advisory ELSA-2009-1500

https://rhn.redhat.com/errata/RHSA-2009-1500.html

The following updated rpms for Enterprise Linux 3 have been uploaded to the Unbreakable Linux Network:

i386:xpdf-2.02-17.el3.i386.rpm
x86_64:xpdf-2.02-17.el3.x86_64.rpm

SRPMS:
http://oss.oracle.com/el3/SRPMS-updates/xpdf-2.02-17.el3.src.rpm

Description of changes:

[2.02-17.el3]
- Resolves: #527470, CVE-2009-0791

[2.02-16.el3]
- Resolves: #527470, CVE-2009-0791

[2.02-15.el3]
- Resolves: #527470, CVE-2009-0791

—
Enterprise Linux Security Advisory ELSA-2009-1503

https://rhn.redhat.com/errata/RHSA-2009-1503.html

The following updated rpms for Enterprise Linux 4 have been uploaded to the Unbreakable Linux Network:

i386:gpdf-2.8.2-7.7.2.el4_8.5.i386.rpm

x86_64:gpdf-2.8.2-7.7.2.el4_8.5.x86_64.rpm

ia64:gpdf-2.8.2-7.7.2.el4_8.5.ia64.rpm

SRPMS:
http://oss.oracle.com/el4/SRPMS-updates/gpdf-2.8.2-7.7.2.el4_8.5.src.rpm

Description of changes:

[2.8.2-7.7.2.el4_8.5]
- Fixes various flaws addressed in bugs #491840 (CVE-2009-0791),
- Resolves: #527413

—
Enterprise Linux Security Advisory ELSA-2009-1501

https://rhn.redhat.com/errata/RHSA-2009-1501.html

The following updated rpms for Enterprise Linux 4 have been uploaded tothe Unbreakable Linux Network:

i386:xpdf-3.00-22.el4_8.1.i386.rpm
x86_64:xpdf-3.00-22.el4_8.1.x86_64.rpm
ia64:xpdf-3.00-22.el4_8.1.ia64.rpm

SRPMS:
http://oss.oracle.com/el4/SRPMS-updates/xpdf-3.00-22.el4_8.1.src.rpm

Description of changes:

[3.00-22.1]
- Resolves: #527468, CVE-2009-0791

[3.00-22.el4]
- CVE-2009-0791

[3.00-21.el4]
- CVE-2009-0791

Enterprise Linux Security Advisory ELSA-2009-1512

https://rhn.redhat.com/errata/RHSA-2009-1512.html

The following updated rpms for Enterprise Linux 4 have been uploaded to the Unbreakable Linux Network:

i386:
kdegraphics-3.3.1-15.el4_8.2.i386.rpm
kdegraphics-devel-3.3.1-15.el4_8.2.i386.rpm

x86_64:
kdegraphics-3.3.1-15.el4_8.2.x86_64.rpm
kdegraphics-devel-3.3.1-15.el4_8.2.x86_64.rpm

ia64:
kdegraphics-3.3.1-15.el4_8.2.ia64.rpm
kdegraphics-devel-3.3.1-15.el4_8.2.ia64.rpm

SRPMS:
http://oss.oracle.com/el4/SRPMS-updates/kdegraphics-3.3.1-15.el4_8.2.src.rpm

Description of changes:

[3.3.1-15.2]
- Add missing NULL check to CVE-2009-3608 patch

[3.3.1-15.1]
- CVE-2009-0791

Categories: LINUX, Linux Security, Oracle Enterprise Linux, Oracle Linux, Redhat Enterprise Linux
Tags: Features, Oracle Corporation, Oracle Enterprise Linux, Red Hat, Red Hat Enterprise Linux, Unbreakable Linux Network

Comments are closed.

« Wilkinson: Education XKCD: Nowhere »
  • Latest
  • Random
  • Bookmarks
  • Archives
  • Lisa Benson: Jobs
  • Final Apache HTTP Server 1.3 Series Release
  • Sherffius: The Moon
  • NSA To Aid Google In Chinese State Sponsored Intrusion Investigation
  • Oracle Patches Critical WebLogic Flaw
  • Lisa Benson: Beanstalk
  • USB Electronic Key Impressioner – Open Sesame
  • Sherffius: Bacterial-Laden
  • Firefox Malware Extensions Discovered
  • Holbert: Trillion Dollar Stuck Pedal
  • Sunday’s INFOSEC MustRead: InfosecWriters.com
  • XKCD: Abstraction
  • Bonehead Information Technology Practices
  • XKCD: Form
  • Microsoft Fails To Patch SQL Server Password Exploit, What’s New…
  • Dilbert: Dogbert The CEO
  • Dilbert: Marketing
  • Wondermark: Be Honest
  • Wilkinson: Jihadist Cartoon Academy
  • Sunshine State Loses Quarter Million Social Security Numbers
  • Apple
  • BSD
  • Closson
  • Darknet
  • Debian
  • Finnigan
  • ha.ckers
  • Hoff
  • Insecure
  • Krebs
  • Layer8
  • MSRC
  • Network Security Blog
  • NSA SEL
  • openSUSE
  • RedHat
  • SANS
  • Schneier
  • Security Eunoia
  • Securosis
  • Shimel
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
Subscribe

Featured Blog - Blogs.com SANS Security Reading Room KnotOriginal: fine art to hang on your body and walls Member - Security Bloggers Network

Dilbert

Sponsored Links

KnotOriginal

Featured Video

RSS Cryptography

  • Microscope-wielding boffins crack cordless phone crypto 2010/02/08
  • Making packet processing more efficient with network-optimized multicore designs: Part 2 2010/02/08
  • New Attack on Threefish 2010/02/07
  • So I deleted it without reading it. 2010/02/06
  • Kaspersky: Google hack takes spotlight from Russia 2010/02/05
  • IP Cores, Inc. Announces an Update of its Elliptic Curve Crypto Accelerator 2010/02/05
  • SMIC, SSHIC deliver smart card IC using 0.162 m EEPROM 2010/02/04
  • Revere Security Appoints Co-Inventor of Public-Key Cryptography... 2010/02/03
  • Data defenders: Researchers try to ward off increasingly sophisticated cyber attacks 2010/02/02
  • IP Cores Selects Phoenix Technologies for Israel 2010/02/02

RSS Security Bloggers Network

  • My Blackhat DC Paper, Slides, and Video are available 2010/02/08 IBM Internet Security Systems Frequency X Blog
  • Is Your BlackBerry Spying On You? 2010/02/08 spinman
  • The 800-lb Dragon’s APTitude 2010/02/08 Bill Wildprett
  • Wrapping insecure web apps with Apache 2010/02/08 Asmodian X
  • Oracle Patches Critical WebLogic Flaw 2010/02/08 Marc Handelman
  • Lisa Benson: Beanstalk 2010/02/08 Marc Handelman
  • Week 5 in Review 2010/02/08 glenn
  • Google Street View Car Gets GPSed by F.A.T. Pranksters 2010/02/08 Devin McDonald

RSS SANS ISC

  • Oracle has an unscheduled security alert and patch for CVE-2010-0073. The issue affects WebLogic Server and is remotely exploitable. Details and patch are here http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0073.html, (Tue, Feb 9th) 2010/02/09
  • When is a 0day not a 0day? Samba symlink bad default config, (Tue, Feb 9th) 2010/02/09
  • When is a 0day not a 0day? Fake OpenSSh exploit, again. , (Mon, Feb 8th) 2010/02/08
  • Mandiant Mtrends Report, (Sun, Feb 7th) 2010/02/07
  • LANDesk Management Gateway Vulnerability, (Sat, Feb 6th) 2010/02/06
  • tweaked ISC layout. Please submit screen shot and browser details if things don't look right., (Sat, Feb 6th) 2010/02/06
  • Oracle WebLogic Server Security Alert, (Sat, Feb 6th) 2010/02/06
  • New version of Andreas Schuster's Evtx Parser released http://computer.forensikblog.de/en/2010/02/evtx_parser_1_0_2.html, (Sat, Feb 6th) 2010/02/06
  • Memory Analysis - time to move beyond XP, (Fri, Feb 5th) 2010/02/06

RSS Oracle

  • Oracle to Acquire AmberPoint 2010/02/09
  • Bookmarkable page with parameters 2010/02/09
  • 32-bit to 64-bit database migration tips: OLAP upgrade 2010/02/08
  • ADF Coding Ninja 2010/02/08
  • Case Study: Swedish Rail Operator SJ Increases Revenue and Customer Satisfaction Using CRM 2010/02/08
  • Random Things: Volume #13 2010/02/08
  • v-Commerce? 2010/02/08

RSS MySQL

  • A deep look at MySQL 5.5 partitioning enhancements 2009/12/24
  • Sun "Tech Days" Conference World Tour Kicks Off in Brazil 2009/12/07
  • Tino Rachui: Using MySQL Cluster in Sun's Virtual Desktop Infrastructure 2009/11/10
  • MySQL Database Analytics with InfiniDB from Calpont – Part 2 2009/10/28
  • MySQL Database Analytics with InfiniDB from Calpont – Part 1 2009/10/27
  • What's New in the MySQL Enterprise Fall 2009 Release? - Interview with Mark Matthews and Andy Bang 2009/09/08
  • Introducing the MySQL Librarian 2009/07/14

RSS Linux

  • Oracle Drops Sun's Commitment To Accessibility - Slashdot 2010/02/09
  • LinuxCon Puts Out Call for Papers Ahead of Summer Event - OStatic (blog) 2010/02/09
  • How To Reverse Engineer A Motherboard BIOS - Benchmark Reviews 2010/02/09
  • Oracle Patches Dangerous WebLogic Server Flaw - eWeek 2010/02/09
  • Unix ENGINEER - TRADING - SYDNEY CBD! - Australian Techworld 2010/02/09

RSS MAC OSX

  • Anti-DRM Protest Against The iPad Grows 2010/02/08 Eli Milchman
  • Amazon to Hike Ebook Pricing as iPad Ships 2010/02/08 Ed Sutherland
  • Daily Deals: iPhone Acces. Bundle, External Superdrive, App Store Freebies 2010/02/08 Ed Sutherland
  • Mock Up Your iPad Ideas With IA’s Omnigraffle Template 2010/02/08 Giles Turnbull
  • The inevitable DIY iPad papercraft mockup 2010/02/08 John Brownlee
  • Apple to app devs: don’t use Core Location “primarily” for advertising 2010/02/08 John Brownlee
  • Report: Carriers to Subsidized iPads for 2-Year 3G Contracts 2010/02/08 Ed Sutherland

RSS Microsoft

  • February 2010 Bulletin Release Advance Notification 2010/02/04 MSRCTEAM
  • Security Advisory 980088 Released 2010/02/03 MSRCTEAM
  • January 2010 Out-of-Band Security Bulletin Webcast 2010/01/22 MSRCTEAM
  • Bulletin MS10-002 Released 2010/01/21 MSRCTEAM
  • Security Advisory 979682 Released 2010/01/21 MSRCTEAM
  • Advance Notification for Out-of-Band Bulletin Release 2010/01/20 MSRCTEAM
  • Security Advisory 979352 – Going out of Band 2010/01/19 MSRCTEAM

RSS Network

  • Europe lagging behind on fibre broadband adoption 2010/02/08
  • LG NAS N4B1 review 2010/02/08
  • VoIP patent under review by Patent Office 2010/02/08
  • YouTube now supports IPv6 2010/02/08
  • Where do web giants stand on IPv6? 2010/02/05
  • Intel details vPro for Core i5, i7 processors 2010/02/05
  • Microsoft IE still popular, researcher says 2010/02/05

Daily Posts

February 2010
S M T W T F S
« Jan    
 123456
78910111213
14151617181920
21222324252627
28  
Creative Commons License
The Infosecurity.US Blog is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

Find the best blogs at Blogs.com.

Creative Commons Attribution-Share Alike 3.0 U.S. License ©2010 Infosecurity.US

Subscribe