LWN.net Logo

Fedora alert FEDORA-2011-14727 (hardlink)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 16 Update: hardlink-1.0-12.fc16
Date:  Wed, 23 Nov 2011 23:27:58 +0000
Message-ID:  <20111123232800.4FC24214E6@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2011-14727 2011-10-22 00:07:21 -------------------------------------------------------------------------------- Name : hardlink Product : Fedora 16 Version : 1.0 Release : 12.fc16 URL : http://pkgs.fedoraproject.org/gitweb/?p=hardlink.git Summary : Create a tree of hardlinks Description : hardlink is used to create a tree of hard links. It's used by kernel installation to dramatically reduce the amount of diskspace used by each kernel package installed. -------------------------------------------------------------------------------- Update Information: fix possible buffer overflows, integer overflows (CVE-2011-3630 CVE-2011-3631 CVE-2011-3632) -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 21 2011 Jindrich Novy <jnovy@redhat.com> - 1:1.0-12 - fix possible buffer overflows, integer overflows (CVE-2011-3630 CVE-2011-3631 CVE-2011-3632) - update man page -------------------------------------------------------------------------------- References: [ 1 ] Bug #746709 - CVE-2011-3630 hardlink: Multiple stack-based buffer overflows when run on a tree with deeply nested directories https://bugzilla.redhat.com/show_bug.cgi?id=746709 [ 2 ] Bug #746710 - CVE-2011-3631 hardlink: Multiple integer overflows, when adding string lengths https://bugzilla.redhat.com/show_bug.cgi?id=746710 [ 3 ] Bug #746713 - CVE-2011-3632 hardlink: Prone to symlink attacks https://bugzilla.redhat.com/show_bug.cgi?id=746713 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update hardlink' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds