• Home
  • Et Cetera

Infosecurity.US

Oracle Releases Multiple EL Patches, SELinux, XPDF, Et Cetera

By Marc Handelman on October 17th, 2009

Oracle Toys With The Penguin

Oracle Corporation (NasdaqGS: ORCL) has released the Redwood Shores, CA based company’s latest Enterprise Linux  patches; of particular interest to us is the SELinux Policy Bug Fix Updates. The updates to Oracle’s Enterprise Linux operating system are available via the company’s Unbreakable Linux Network (ULN) site. Oracle Enterprise Linux is a variant of RED HAT, INC.’s (NYSE: RHT)  Red Hat Enterprise Linux OS. Additional information inclusive of release notes and linkage may be accessed after the jump.

Enterprise Linux Bug Fix Advisory ELBA-2009-1515

https://rhn.redhat.com/errata/RHBA-2009-1515.html

The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network:

i386:device-mapper-multipath-0.4.7.30.el5_4.2.i386.rpm
kpartx-0.4.7-30.el5_4.2.i386.rpm

x86_64:
device-mapper-multipath-0.4.7-30.el5_4.2.x86_64.rpm
kpartx-0.4.7-30.el5_4.2.x86_64.rpm

ia64:
device-mapper-multipath-0.4.7-30.el5_4.2.ia64.rpm
kpartx-0.4.7-30.el5_4.2.ia64.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/device-mapper-multipath-0.4.7-30.el5_4.2.src.rpm

Description of changes:

[0.4.7-30.el5_4.1]
- Added kpartx-fix-large-minor-devices.patch
- Resolves: bz #528132

[0.4.7-30.el5_4.1]
- Added 515171_new_hardware.patch
- Resolves: bz #523392

—

Enterprise Linux Bug Fix Advisory ELBA-2009-1495

https://rhn.redhat.com/errata/RHBA-2009-1495.html

The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network:

i386:selinux-policy-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-devel-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-minimum-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-mls-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-strict-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-targeted-2.4.6-255.el5_4.1.noarch.rpm

x86_64:
selinux-policy-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-devel-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-minimum-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-mls-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-strict-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-targeted-2.4.6-255.el5_4.1.noarch.rpm

ia64:
selinux-policy-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-devel-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-minimum-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-mls-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-strict-2.4.6-255.el5_4.1.noarch.rpm
selinux-policy-targeted-2.4.6-255.el5_4.1.noarch.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/selinux-policy-2.4.6-255.el5_4.1.src.rpm

Description of changes:

[2.4.6-255.el5_4.1]
- Allow cyrus to stream connect to snmp
Resolves: bz523927

—
Enterprise Linux Bug Fix Advisory ELBA-2009-1494

https://rhn.redhat.com/errata/RHBA-2009-1494.html

The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network:

i386:tcsh-6.14-14.el5_4.2.i386.rpm
x86_64:tcsh-6.14-14.el5_4.2.x86_64.rpm
ia64:tcsh-6.14-14.el5_4.2.ia64.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/tcsh-6.14-14.el5_4.2.src.rpm

Description of changes:

[6.14-14.2]
- Fix broken globbing error reporting

[6.14-14.1]
- Fix tcsh globbing causing bad automount
Resolves: #526459

—
Oracle VM Security Advisory OVMSA-2009-0023

The following updated rpms for Oracle VM 2.1 have been uploaded to the Unbreakable Linux Network:

i386:
kernel-BOOT-devel-2.6.18-8.1.15.6.2.el5.i686.rpm
kernel-BOOT-2.6.18-8.1.15.6.2.el5.i686.rpm
kernel-kdump-2.6.18-8.1.15.6.2.el5.i686.rpm
kernel-kdump-devel-2.6.18-8.1.15.6.2.el5.i686.rpm
kernel-ovs-2.6.18-8.1.15.6.2.el5.i686.rpm
kernel-ovs-devel-2.6.18-8.1.15.6.2.el5.i686.rpm

SRPMS:
http://oss.oracle.com/oraclevm/server/SRPMS-updates/kernel-2.6.18-8.1.15.6.2.el5.src.rpm

Description of changes:
[2.6.18-8.1.15.6.2.el5]
- backport for online resize of blockdev [orabug 8585251] [rh bugz 444964]
- CVE-2009-2692 - [net] make sock_sendpage use kernel_sendpage (Jiri Pirko ) [517445 516955]
- CVE-2009-2698 - [net] prevent null pointer dereference in udp_sendmsg (Vitaly Mayatskikh) [518047 518043]

[2.6.18-8.1.15.6.1.el5]
- Updated cciss module to 3.6.20 (wiekus.beukes@oracle.com)
- update bnx2x 1.48.107 (kurt.hackel@oracle.com)
- update bnx2 1.8.8b (kurt.hackel@oracle.com)

[2.6.18-8.1.15.5.3.el5]
- update bfa to 1.1.0.9-0 [bugz 9518]

[2.6.18-8.1.15.5.2.el5]
- Fix dom0 crash in loopback_start_xmit+0x107/0x2BD (tina.yang@oracle.com) [bug 7634343]

—
Enterprise Linux Bug Fix Advisory ELBA-2009-1514

https://rhn.redhat.com/errata/RHBA-2009-1514.html

The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network:

i386:
xen-libs-3.0.3-94.el5_4.2.i386.rpm
xen-3.0.3-94.el5_4.2.i386.rpm
xen-devel-3.0.3-94.el5_4.2.i386.rpm

x86_64:
xen-libs-3.0.3-94.el5_4.2.i386.rpm
xen-libs-3.0.3-94.el5_4.2.x86_64.rpm
xen-3.0.3-94.el5_4.2.x86_64.rpm
xen-devel-3.0.3-94.el5_4.2.i386.rpm
xen-devel-3.0.3-94.el5_4.2.x86_64.rpm

ia64:
xen-libs-3.0.3-94.el5_4.2.ia64.rpm
xen-3.0.3-94.el5_4.2.ia64.rpm
xen-devel-3.0.3-94.el5_4.2.ia64.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/xen-3.0.3-94.el5_4.2.src.rpm

Description of changes:

[3.0.3-94.el5_4.2]
- Fix memory leaks in lib{xc, xenstore} python bindings (rhbz 528163)

—
Enterprise Linux Bug Fix Advisory ELBA-2009-1510

https://rhn.redhat.com/errata/RHBA-2009-1510.html

The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network:

i386:
rgmanager-2.0.52-1.0.1.el5_4.1.i386.rpm
x86_64:rgmanager-2.0.52-1.0.1.el5_4.1.x86_64.rpm

ia64:rgmanager-2.0.52-1.0.1.el5_4.1.ia64.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/rgmanager-2.0.52-1.0.1.el5_4.1.src.rpm

Description of changes:

[2.0.52-1.0.1.el5_4.1]
- Update summary and description in specfile to be vendor neutral

[2.0.52-1.el5_4.1]
- Fix missing path support in vm.sh
- Resolves: rhbz#524213 (519786)

—
Enterprise Linux Security Advisory ELSA-2009-1513

https://rhn.redhat.com/errata/RHSA-2009-1513.html

The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network:

i386:
cups-1.3.7-11.el5_4.3.i386.rpm
cups-devel-1.3.7-11.el5_4.3.i386.rpm
cups-libs-1.3.7-11.el5_4.3.i386.rpm
cups-lpd-1.3.7-11.el5_4.3.i386.rpm

x86_64:
cups-1.3.7-11.el5_4.3.x86_64.rpm
cups-devel-1.3.7-11.el5_4.3.i386.rpm
cups-devel-1.3.7-11.el5_4.3.x86_64.rpm
cups-libs-1.3.7-11.el5_4.3.i386.rpm
cups-libs-1.3.7-11.el5_4.3.x86_64.rpm
cups-lpd-1.3.7-11.el5_4.3.x86_64.rpm

ia64:
cups-1.3.7-11.el5_4.3.ia64.rpm
cups-devel-1.3.7-11.el5_4.3.ia64.rpm
cups-libs-1.3.7-11.el5_4.3.i386.rpm
cups-libs-1.3.7-11.el5_4.3.ia64.rpm
cups-lpd-1.3.7-11.el5_4.3.ia64.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/cups-1.3.7-11.el5_4.3.src.rpm

Description of changes:

[1:1.3.7-11:.3]
- Include NULL pointer check in ObjectStream::getObject.  Part of the
fix for CVE-2009-3608 (bug #526637).

[1:1.3.7-11:.2]
- Applied patch to fix CVE-2009-3608 (bug #526637) and
CVE-2009-3609 (bug #526893).

—
Enterprise Linux Security Advisory ELSA-2009-1504

https://rhn.redhat.com/errata/RHSA-2009-1504.html

The following updated rpms for Enterprise Linux 5 have been uploaded tothe Unbreakable Linux Network:

i386:poppler-0.5.4-4.4.el5_4.11.

—
Enterprise Linux Bug Fix Advisory ELBA-2009-1511

https://rhn.redhat.com/errata/RHBA-2009-1511.html

The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network:

i386:coreutils-5.97-23.el5_4.1.i386.rpm

x86_64:coreutils-5.97-23.el5_4.1.x86_64.rpm

ia64:coreutils-5.97-23.el5_4.1.ia64.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/coreutils-5.97-23.el5_4.1.src.rpm

Description of changes:

[5.97-23.1]
[as regular user]
cause “Permission denied” (#520630, introduced by fix for
rhbz #497830)

—
Enterprise Linux Security Advisory ELSA-2009-1500

https://rhn.redhat.com/errata/RHSA-2009-1500.html

The following updated rpms for Enterprise Linux 3 have been uploaded to the Unbreakable Linux Network:

i386:xpdf-2.02-17.el3.i386.rpm
x86_64:xpdf-2.02-17.el3.x86_64.rpm

SRPMS:
http://oss.oracle.com/el3/SRPMS-updates/xpdf-2.02-17.el3.src.rpm

Description of changes:

[2.02-17.el3]
- Resolves: #527470, CVE-2009-0791

[2.02-16.el3]
- Resolves: #527470, CVE-2009-0791

[2.02-15.el3]
- Resolves: #527470, CVE-2009-0791

—
Enterprise Linux Security Advisory ELSA-2009-1503

https://rhn.redhat.com/errata/RHSA-2009-1503.html

The following updated rpms for Enterprise Linux 4 have been uploaded to the Unbreakable Linux Network:

i386:gpdf-2.8.2-7.7.2.el4_8.5.i386.rpm

x86_64:gpdf-2.8.2-7.7.2.el4_8.5.x86_64.rpm

ia64:gpdf-2.8.2-7.7.2.el4_8.5.ia64.rpm

SRPMS:
http://oss.oracle.com/el4/SRPMS-updates/gpdf-2.8.2-7.7.2.el4_8.5.src.rpm

Description of changes:

[2.8.2-7.7.2.el4_8.5]
- Fixes various flaws addressed in bugs #491840 (CVE-2009-0791),
- Resolves: #527413

—
Enterprise Linux Security Advisory ELSA-2009-1501

https://rhn.redhat.com/errata/RHSA-2009-1501.html

The following updated rpms for Enterprise Linux 4 have been uploaded tothe Unbreakable Linux Network:

i386:xpdf-3.00-22.el4_8.1.i386.rpm
x86_64:xpdf-3.00-22.el4_8.1.x86_64.rpm
ia64:xpdf-3.00-22.el4_8.1.ia64.rpm

SRPMS:
http://oss.oracle.com/el4/SRPMS-updates/xpdf-3.00-22.el4_8.1.src.rpm

Description of changes:

[3.00-22.1]
- Resolves: #527468, CVE-2009-0791

[3.00-22.el4]
- CVE-2009-0791

[3.00-21.el4]
- CVE-2009-0791

Enterprise Linux Security Advisory ELSA-2009-1512

https://rhn.redhat.com/errata/RHSA-2009-1512.html

The following updated rpms for Enterprise Linux 4 have been uploaded to the Unbreakable Linux Network:

i386:
kdegraphics-3.3.1-15.el4_8.2.i386.rpm
kdegraphics-devel-3.3.1-15.el4_8.2.i386.rpm

x86_64:
kdegraphics-3.3.1-15.el4_8.2.x86_64.rpm
kdegraphics-devel-3.3.1-15.el4_8.2.x86_64.rpm

ia64:
kdegraphics-3.3.1-15.el4_8.2.ia64.rpm
kdegraphics-devel-3.3.1-15.el4_8.2.ia64.rpm

SRPMS:
http://oss.oracle.com/el4/SRPMS-updates/kdegraphics-3.3.1-15.el4_8.2.src.rpm

Description of changes:

[3.3.1-15.2]
- Add missing NULL check to CVE-2009-3608 patch

[3.3.1-15.1]
- CVE-2009-0791

Categories: LINUX, Linux Security, Oracle Enterprise Linux, Oracle Linux, Redhat Enterprise Linux
Tags: Features, Oracle Corporation, Oracle Enterprise Linux, Red Hat, Red Hat Enterprise Linux, Unbreakable Linux Network

Related Headlines

    Related posts:

    1. Oracle Releases Multiple Linux Updates, elinks, xen and openais revved
    2. Oracle Patches Enterprise Linux, Fixes for UP2DATE, OCFS2
    3. Oracle Releases Multiple Enterprise Linux Updates, Let The Patching Begin…
    4. Oracle Wakes Sleeping Penguin, Enterprise Linux Updated
    5. Oracle Enterprise Linux Critical Security Updates: Mozilla Firefox and Seamonkey, etc

Comments are closed.

« Wilkinson: Education XKCD: Nowhere »
  • Latest
  • Random
  • Bookmarks
  • Archives
  • Steve Benson: Persian Lights…
  • New, Pernicious BotNet Emerges
  • VMWare Announces ESX Console Security Update
  • Nick Anderson: Egg
  • Doppelgänger Infinitus
  • Robert Ariall: Iran For Cover
  • Data Leakage Wednesdays: Old Printer Vector
  • XKCD: Exoplanets
  • Apple Releases Magic Footpad, Raises Ante On Bipedal Computer Controls
  • Science Tuesday: Asteroidal Discoveries Mapped, 01980 – 02010
  • Inspector General: IRS Systems Found Insecure – Again
  • Twitter Scam Redux – The Shortening
  • Apple Releases iOS Updates, Multiple Vulnerabilitie Mitigated
  • New York Pedestrians
  • Stein: Health-Care Reform
  • Postfix Vulnerability Announced: Linux Specific Local DoS
  • SCADA Cyber Security Workshop Call for Speakers
  • GNUCITIZEN Announces New, Online Security System
  • Survey Says: 35% Of Oracle DBAs Monitor Systems. Better Than 0% I Suppose…
  • Botnet Takedown, FastFlux Flumoxed
  • Apple
  • BSD
  • Closson
  • Darknet
  • Debian
  • Finnigan
  • ha.ckers
  • Hoff
  • Insecure
  • Krebs
  • Layer8
  • MSRC
  • Network Security Blog
  • NSA SEL
  • openSUSE
  • RedHat
  • SANS
  • Schneier
  • Security Eunoia
  • Securosis
  • Shimel
  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
Subscribe

Featured Blog - Blogs.com SANS Security Reading Room KnotOriginal: fine art to hang on your body and walls Member - Security Bloggers Network

Dilbert

KnotOriginal

Featured Video

QOTD

RSS Security Bloggers Network

  • Two Wheel EV Recumbant: Zerotracer 2010/09/02 Davi Ottenheimer
  • Ben Franklin’s Endpoint Security Advice 2010/09/02 Jeff Hughes
  • Configuring Conditional SSH Connections 2010/09/02 Xavier
  • Truecrypt and USB drives 2010/09/02 always peace
  • LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs 2010/09/02 Andrew Hay
  • Safe Web Surfing Rule # 1: READ the URL 2010/09/02 Tom Kelchner
  • Heartland Set To Pay Discover $5M For 2008 Data Breach 2010/09/02 spinman
  • User’s Opinions on Malware Infections 2010/09/02 spinman
  • Acunetix Web Vulnerability Scanner 7 Released 2010/09/02 spinman
  • LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs 2010/09/02 Anton Chuvakin

RSS Cryptography

  • Monitor: Schrodinger's cat and mouse 2010/09/02
  • How to configure a Junos security device 2010/09/02
  • Net Effect: Hay-what? 2010/09/02
  • The Art of Proof 2010/09/02
  • Quantum crypto cracked, researchers say 2010/09/01

RSS SANS ISC

  • Microsoft EMETv2 released, (Thu, Sep 2nd) 2010/09/02
  • SDF, please!, (Thu, Sep 2nd) 2010/09/02
  • Month of Undisclosed 0-day Bugs, (Wed, Sep 1st) 2010/09/01
  • Microsoft issues updates to sysinternals ProcDump and Process Monitor: http://blogs.technet.com/b/sysinternals/archive/2010/08/30/updates-procdump-process-monitor-and-a-new-mark-s-blog-post.aspx, (Wed, Sep 1st) 2010/09/01
  • VMWARE releases 2 security advisories for ESX Service Console: http://lists.vmware.com/pipermail/security-announce/2010/000103.html and http://lists.vmware.com/pipermail/security-announce/2010/000104.html, (Wed, Sep 1st) 2010/09/01

RSS Oracle

  • Going to Oracle OpenWorld 2010? 2010/09/02
  • Automatic Time Zone support in Application Express 4.0 2010/09/02
  • EBS, Collaborate, Security, BPEL, OWB, Blog of Note, Hyperion, EPM, Burnout, WiFi 2010/09/02
  • Details of Tuxedo sessions at OOW 2010/09/02
  • JavaOne Preview on TechCast Live! (Tues., Sept. 7, 10am PT) 2010/09/02
  • links for 2010-09-02 2010/09/02
  • Join us for a Bersin & Associates Webcast - "Evolution of ERPs: Driving Business Value through Integrated Talent Management" 2010/09/02

RSS MySQL

  • Join MySQL at OSCON 2010/07/02
  • TechCast Live: Jono Bacon and Luke Kowalski on MySQL Community 2010/05/21
  • What's New in the MySQL Enterprise Spring 2010 Release? - Interview with Mark Matthews and Andy Bang 2010/05/17
  • Introduction to MySQL 5.5 2010/04/13
  • Why Should I Check Out a MySQL-Based Column Database ? 2010/02/12
  • A deep look at MySQL 5.5 partitioning enhancements 2009/12/24
  • Sun "Tech Days" Conference World Tour Kicks Off in Brazil 2009/12/07

RSS Linux

  • A Guide to Today's Top 10 Linux Distributions - NetworkWorld.com 2010/09/02
  • Embedded Linux Conference videos available - LWN.net 2010/09/02
  • Net Applications' iOS vs Linux Report Confuses Me - Muktware (blog) 2010/09/02
  • Cloudlinux Named Editor's Choice By Web Host Magazine & Buyer's Guide - PR Urgent 2010/09/02
  • Samsung's 3D TV remote let's you take the screen with you - Geek.com 2010/09/02

RSS MAC OSX

  • Samsung Reveals Half-Pint iPad, The Galaxy Tab 2010/09/02 Eli Milchman
  • Daily Deals: New nano, touch and Apple TV 2010/09/02 Ed Sutherland
  • iPhone 4 Coffee Table Gets You Better Reception Than iPod Table? 2010/09/02 Nicole Martinelli
  • Walkman Outsells iPods in Japan, Can Wristwatch Nano Change That? 2010/09/02 Nicole Martinelli
  • Amazon: Buy – Don’t Rent – 99-Cent Fox, ABC TV Episodes 2010/09/02 Ed Sutherland
  • Analyst: New Apple TV Rival for Cable’s Video-on-Demand 2010/09/02 Ed Sutherland
  • iTunes Ping And Facebook: What’s Going On? 2010/09/02 Giles Turnbull

RSS Microsoft

  • Update on Security Advisory 2269637 2010/08/31 MSRCTEAM
  • Microsoft Security Advisory 2269637 Released 2010/08/22 MSRCTEAM
  • August 2010 Webcast and QA 2010/08/12 MSRCTEAM
  • Update on the publicly disclosed Win32k.sys EoP Vulnerability 2010/08/10 MSRCTEAM
  • August 2010 Security Bulletin Release 2010/08/10 MSRCTEAM
  • August 2010 Bulletin Release Advance Notification 2010/08/05 MSRCTEAM
  • August 2010 Out-of-Band Security Release Webcast Q&A 2010/08/03 MSRCTEAM

RSS Network

  • How to get started with a blade system 2010/09/02
  • Opsview Community Edition review 2010/09/02
  • Cacti review 2010/09/02
  • Brocade adds 100G Ethernet to switch and router line 2010/09/02
  • Is Cisco making a play for Skype? 2010/08/31
  • Skype launches Skype Connect enterprise voice calling 2010/08/31
  • Sonos ZonePlayer S5 review 2010/08/25

Daily Posts

September 2010
S M T W T F S
« Aug    
 1234
567891011
12131415161718
19202122232425
2627282930  
Creative Commons License
The Infosecurity.US Blog is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

Find the best blogs at Blogs.com.

Creative Commons Attribution-Share Alike 3.0 U.S. License ©2010 Infosecurity.US

Subscribe