LWN.net Logo

TSL-2004-0064 - multi

From:  Trustix Security Advisor <tsl-AT-trustix.org>
To:  tsl-announce-AT-lists.trustix.org
Subject:  TSL-2004-0064 - multi
Date:  Thu, 9 Dec 2004 15:58:14 +0100

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Trustix Secure Linux Advisory #2004-0064

Package name:      amavisd-new, anaconda, apache, courier-imap, gzip,
                   hwdata, kernel, mkinitrd, perl-uri, perl-uri, postgresql
                   procmail, python, razor-agents, sqlgrey, swup
Summary:           Package bugfixes
Date:              2004-12-09
Affected versions: Trustix Secure Linux 2.2

- --------------------------------------------------------------------------
Package description:
  amavisd-new
  AMaViS is a script that interfaces a mail transport agent (MTA) with
  one or more virus scanners.
  
  anaconda
  The anaconda package contains portions of the Trustix Secure Linux
  installation program which can then be run by the user for
  reconfiguration and advanced installation options.
  Based on Red Hat anaconda 7.2 and 7.3
  
  apache
  Apache is a full featured web server that is freely available, and also
  happens to be the most widely used.
  
  courier-imap
  Courier-IMAP is an IMAP server for Maildir mailboxes.  This package contains
  the standalone version of the IMAP server that's included in the Courier
  mail server package.  This package is a standalone version for use with
  other mail servers.
  
  gzip
  The gzip package contains the popular GNU gzip data compression
  program.  Gzipped files have a .gz extension.
  
  hwdata
  hwdata contains various hardware identification and configuration data,
  such as the pci.ids database, the XFree86 Cards and MonitorsDb databases.
  
  kernel
  The kernel package contains the Linux kernel (vmlinuz), the core of your
  Trustix Secure Linux operating system.  The kernel handles the basic
  functions of the operating system:  memory allocation, process allocation,
  device input and output, etc.
  
  mkinitrd
  Mkinitrd creates filesystem images for use as initial ramdisk (initrd)
  images.  These ramdisk images are often used to preload the block
  device modules (SCSI or RAID) needed to access the root filesystem.
  
  perl-uri
  This module implements the URI class. Objects of this class represent
  "Uniform Resource Identifier references" as specified in RFC 2396 (and
  updated by RFC 2732).
  
  postgresql
  PostgreSQL is an advanced Object-Relational database management system
  (DBMS) that supports almost all SQL constructs (including
  transactions, subselects and user-defined types and functions).
  
  procmail
  The procmail program is a powerful mail filter.
  Procmail is also the basis for the SmartList mailing list processor.
  
  python
  Python is an interpreted, interactive, object-oriented programming
  language often compared to Tcl, Perl, Scheme or Java. Python includes
  modules, classes, exceptions, very high level dynamic data types and
  dynamic typing. Python supports interfaces to many system calls and
  libraries.
  
  razor-agents
  Vipul's Razor is a distributed, collaborative, spam detection and
  filtering network. Razor establishes a distributed and constantly
  updating catalogue of spam in propagation. This catalogue is used
  by clients to filter out known spam.  Prior to manual processing or
  transport-level reception, Razor Filtering Agents (end-users and MTAs)
  check their incoming mail against a Catalogue Server and filter out
  or deny transport in case of a signature match. Catalogued spam, once
  identified and reported by a Reporting Agent, can be blocked out by the
  rest of the Filtering Agents on the network.
  
  sqlgrey
  SQLgrey is a Postfix grey-listing policy service with auto-white-listing
  written in Perl with SQL database as storage backend.
  Greylisting stops 50 to 90 % junk mails (spam and virus) before they
  reach your Postfix server (saves BW, user time and CPU time).
  
  swup
  SWUP - SoftWare UPdater is an extension for existing software packaging
  systems to facilitate automatic and secure update and install. SWUP
  handles dependencies between software packages, and is able to fetch
  additional required software when installing or upgrading.
  

Problem description:
  amavisd-new
  - Now even prereq what we need.
  
  anaconda
  - See if we get a more complete list of network drivers for pxe
  
  apache
  - Changed suexec path to /home/httpd
  
  courier-imap
  - Fix typo in imap initscript.
  
  gzip
  - Fix man page bug BugZilla Id: 17
  
  hwdata
  - Try to add ata_piix
  
  kernel
  - Try to add ata_piix
  
  mkinitrd
  - ata_piix depends on libata
  
  perl-uri
  - Adopted into main.
  
  postgresql
  - Now even do echo in stop() in initscript.
  
  procmail
  - Remove too agressive patches that breaks certain setups.
  
  python
  - Modules require expat-libs.
  
  razor-agents
  - New upstream.
  
  sqlgrey
  - The postun script contained scripts from the package so it should be
    preun instead.
  
  swup
  - Bugfix: swup: don't die if picked provider is excluded
  - Bugfix: swup: skip transaction if picked provider is excluded.
  - Bugfix: swup: don't loop when arguments to --upgrade is given.
  

Action:
  We recommend that all systems with this package installed be upgraded.
  Please note that if you do not need the functionality provided by this
  package, you may want to remove it from your system.


Location:
  All Trustix Secure Linux updates are available from
  <URI:http://http.trustix.org/pub/trustix/updates/>>
  <URI:ftp://ftp.trustix.org/pub/trustix/updates/>>


About Trustix Secure Linux:
  Trustix Secure Linux is a small Linux distribution for servers. With focus
  on security and stability, the system is painlessly kept safe and up to
  date from day one using swup, the automated software updater.


Automatic updates:
  Users of the SWUP tool can enjoy having updates automatically
  installed using 'swup --upgrade'.


Questions?
  Check out our mailing lists:
  <URI:http://www.trustix.org/support/>>


Verification:
  This advisory along with all Trustix packages are signed with the
  TSL sign key.
  This key is available from:
  <URI:http://www.trustix.org/TSL-SIGN-KEY>>

  The advisory itself is available from the errata pages at
  <URI:http://www.trustix.org/errata/trustix-2.2/>>
  or directly at
  <URI:http://www.trustix.org/errata/2004/0064/>>


MD5sums of the packages:
- --------------------------------------------------------------------------
168ebc47ddcf3d850e211a139d323f3b  2.2/rpms/amavisd-new-2.2.0-7tr.i586.rpm
9ec520a5eea182f1ead5bbdf64a7b5d9
2.2/rpms/amavisd-new-config-2.2.0-7tr.i586.rpm
bfb4b8ad5c68ba5922a6031a88dc2e75  2.2/rpms/anaconda-7.2.4-7tr.i586.rpm
2326b6ef558caa936fdc4ca72fbd31a5  2.2/rpms/anaconda-runtime-7.2.4-7tr.i586.rpm
ca6472082ab9b7d577ec18ee31b4ed3d  2.2/rpms/apache-2.0.52-7tr.i586.rpm
a1fe38334bb7fffee059bd20553ed3bb  2.2/rpms/apache-dbm-2.0.52-7tr.i586.rpm
683afad8fde3334a896f2e6868f7a481  2.2/rpms/apache-devel-2.0.52-7tr.i586.rpm
3115add61a6fb1cb907857d0599dba02  2.2/rpms/apache-html-2.0.52-7tr.i586.rpm
191936736ddadc4fd1efc741cfb52a11  2.2/rpms/apache-manual-2.0.52-7tr.i586.rpm
a4e45ff5b21ef7b240e6a0e695f6e430  2.2/rpms/courier-imap-3.0.8-8tr.i586.rpm
27907d19e17feb08c669b77d61639adc
2.2/rpms/courier-imap-ldap-3.0.8-8tr.i586.rpm
4bddcdf32fc974c4883c9d4b9371c4de
2.2/rpms/courier-imap-mysql-3.0.8-8tr.i586.rpm
386c427aee211be74a03f0fb7de14482
2.2/rpms/courier-imap-pgsql-3.0.8-8tr.i586.rpm
c8aa840955aa509464f5b3d179a64a7b  2.2/rpms/hwdata-0.44-19tr.i586.rpm
2efa23e7acd8300a2f85c65cfd2f6eaf  2.2/rpms/hwdata-devel-0.44-19tr.i586.rpm
9c4587dd536472e3e84b1cef49572672  2.2/rpms/kernel-2.4.28-6tr.i586.rpm
c823e2b7b074618ec3714f527dfa13b0  2.2/rpms/kernel-BOOT-2.4.28-6tr.i586.rpm
2e54af31537a5c11d7bcc1f895191159  2.2/rpms/kernel-doc-2.4.28-6tr.i586.rpm
73ede2ee95ba4077161db98a023e53da  2.2/rpms/kernel-smp-2.4.28-6tr.i586.rpm
e40a1e2276d5381f039b8c6e2315edb5  2.2/rpms/kernel-source-2.4.28-6tr.i586.rpm
76811db15ee3740e67fbd27716e7346c  2.2/rpms/kernel-utils-2.4.28-6tr.i586.rpm
2ecd6a9928526b92ac05e07df9e794dd  2.2/rpms/mkinitrd-3.4.43-12tr.i586.rpm
5eb2141539db3ece0c13768353c3e283  2.2/rpms/perl-uri-1.34-4tr.i586.rpm
445a01c2db78a20e9e4b0c2c850e2dee
2.2/rpms/postgresql-8.0.0-0.beta5.2tr.i586.rpm
13b85909ef3727bab6c5b392732c94af
2.2/rpms/postgresql-contrib-8.0.0-0.beta5.2tr.
i586.rpm
8c0ba6659298b250d05913b0d9d32a83
2.2/rpms/postgresql-devel-8.0.0-0.beta5.2tr.i5
86.rpm
21a66b5aaf7ea56474b8b6d764edb82b
2.2/rpms/postgresql-docs-8.0.0-0.beta5.2tr.i58
6.rpm
1954f1798925fa30d5b0548ba2b997df
2.2/rpms/postgresql-libs-8.0.0-0.beta5.2tr.i58
6.rpm
802ded1797312d847aa4f11622277341
2.2/rpms/postgresql-plperl-8.0.0-0.beta5.2tr.i
586.rpm
984698b057aeb20b8f2ceb16f8b2a7a4
2.2/rpms/postgresql-python-8.0.0-0.beta5.2tr.i
586.rpm
a2508636464dcfa4fcb0e70427d6f48c
2.2/rpms/postgresql-server-8.0.0-0.beta5.2tr.i
586.rpm
1c0f723293d8541ff3afa429a02ac1df
2.2/rpms/postgresql-test-8.0.0-0.beta5.2tr.i58
6.rpm
68ab75fa2663766630a110adbe011399  2.2/rpms/procmail-3.22-10tr.i586.rpm
926227da03735ea30ecfddc522f253e3  2.2/rpms/python-2.2.3-14tr.i586.rpm
4df951f142dc8e5174b0588dac2bb4a6  2.2/rpms/python-dbm-2.2.3-14tr.i586.rpm
fbdba75dab181b5bb7f21cf915abc8f1  2.2/rpms/python-devel-2.2.3-14tr.i586.rpm
b8ef5beefeccc796602c2e13b64a3281  2.2/rpms/python-docs-2.2.3-14tr.i586.rpm
a863f3bb9cdd53e0677e60d0859fbaa3  2.2/rpms/python-gdbm-2.2.3-14tr.i586.rpm
ee33584d109dc59b61a23a7e12b1eb1a  2.2/rpms/python-modules-2.2.3-14tr.i586.rpm
c742c2613c942476da0f062403e81800  2.2/rpms/razor-agents-2.67-1tr.i586.rpm
fe52556f7a7401afe60467f7e4133d88  2.2/rpms/sqlgrey-1.2.0-2tr.i586.rpm
9ade58a14e743314cf627e859ed74eb4  2.2/rpms/swup-2.6.15-1tr.i586.rpm
377d691ddf9954066c9c555a7b1fd7a7  2.2/rpms/swup-conf-2.6.15-1tr.i586.rpm
71d67d1ec3a0175cb3f82804cd80d0c0  2.2/rpms/swup-cron-2.6.15-1tr.i586.rpm
32782fb6ea7fd29332eb70ac91ff67a5  2.2/rpms/swup-libs-2.6.15-1tr.i586.rpm
8b8ccefc170793791f12218c0397344c  2.2/rpms/swup-rdfgen-2.6.15-1tr.i586.rpm
- --------------------------------------------------------------------------


Trustix Security Team

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQFBuGeyi8CEzsK9IksRAuSiAKCDdJFfqfKVgsPHxyXsKlLbL+iuXACgiGIL
rWzzcq8UqTxCeWwzLuKwWPM=
=3WFL
-----END PGP SIGNATURE-----
_______________________________________________
tsl-announce mailing list
tsl-announce@lists.trustix.org
http://lists.trustix.org/mailman/listinfo/tsl-announce


(Log in to post comments)

Copyright © 2004, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds