LWN.net Logo

Trustix Secure Linux TSL-2004-0067

From:  Trustix Security Advisor <tsl-AT-trustix.org>
To:  tsl-announce-AT-lists.trustix.org
Subject:  TSL-2004-0067 - multi
Date:  Mon, 20 Dec 2004 11:32:37 +0100

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Trustix Secure Linux Advisory #2004-0067

Package name:      anaconda, mailcap, mkinitrd, vim, postgresql, ntp, sqlgrey
                   db4, rsync, postgresql
Summary:           Package bugfixes
Date:              2004-12-17
Affected versions: Trustix Secure Linux 2.1
                   Trustix Secure Linux 2.2
                   Trustix Operating System - Enterprise Server 2

- --------------------------------------------------------------------------
Package description:
  anaconda:
  The anaconda package contains portions of the Trustix Secure Linux
  installation program which can then be run by the user for
  reconfiguration and advanced installation options.
  Based on Red Hat anaconda 7.2 and 7.3
  
  db4:
  The Berkeley Database (Berkeley DB) is a programmatic toolkit that
  provides embedded database support for both traditional and
  client/server applications. The Berkeley DB includes B+tree, Extended
  Linear Hashing, Fixed and Variable-length record access methods,
  transactions, locking, logging, shared memory caching, and database
  recovery. The Berkeley DB supports C, C++, Java, and Perl APIs. It is
  used by many applications, including Python and Perl, so this should
  be installed on all systems.
  
  mailcap:
  The mailcap file is used by the metamail program.  Metamail reads the
  mailcap file to determine how it should display non-text or multimedia
  material.  Basically, mailcap associates a particular type of file
  with a particular program that a mail agent or other program can call
  in order to handle the file.
  
  mkinitrd:
  Mkinitrd creates filesystem images for use as initial ramdisk (initrd)
  images.  These ramdisk images are often used to preload the block
  device modules (SCSI or RAID) needed to access the root filesystem.
  
  ntp:
  The Network Time Protocol (NTP) is used to synchronize a computer's
  time with another reference time source. The ntp package contains
  utilities and daemons that will synchronize your computer's time to
  Coordinated Universal Time (UTC) via the NTP protocol and NTP servers.
  The ntp package includes ntpdate (a program for retrieving the date
  and time from remote machines via a network) and ntpd (a daemon which
  continuously adjusts system time).
  
  postgresql:
  PostgreSQL is an advanced Object-Relational database management system
  (DBMS) that supports almost all SQL constructs (including
  transactions, subselects and user-defined types and functions). The
  postgresql package includes the client programs and libraries that
  you'll need to access a PostgreSQL DBMS server.  These PostgreSQL
  client programs are programs that directly manipulate the internal
  structure of PostgreSQL databases on a PostgreSQL server. These client
  programs can be located on the same machine with the PostgreSQL
  server, or may be on a remote machine which accesses a PostgreSQL
  server over a network connection. This package contains the docs
  in HTML for the whole package, as well as command-line utilities for
  managing PostgreSQL databases on a PostgreSQL server.
  
  rsync:
  Rsync uses a quick and reliable algorithm to very quickly bring
  remote and host files into sync.  Rsync is fast because it just
  sends the differences in the files over the network (instead of
  sending the complete files). Rsync is often used as a very powerful
  mirroring process or just as a more capable replacement for the
  rcp command.  A technical report which describes the rsync algorithm
  is included in this package.
  
  sqlgrey:
  SQLgrey is a Postfix grey-listing policy service with auto-white-listing
  written in Perl with SQL database as storage backend.
  Greylisting stops 50 to 90 % junk mails (spam and virus) before they
  reach your Postfix server (saves BW, user time and CPU time).
  
  vim:
  VIM (VIsual editor iMproved) is an updated and improved version of the vi
  editor.  Vi was the first real screen-based editor for UNIX, and is still
  very popular.  VIM improves on vi by adding new features: multiple windows,
  multi-level undo, block highlighting and more.
  

Problem description:
  anaconda:
  The previous attempt to get PXE booting working with more network cards
  turned out not to work.  This update fixes that.

  db4:
  Applied the latest patch from Sleepycat with the hopes that it makes
  the sleep under high load as reported go away.

  mailcap:
  Fix incorrect entries.

  mkinitrd:
  Now use the old, static insmod.  This should make certain SATA controllers
  work.

  ntp:
  authenticate is not a valid configuration statement.  Removed.

  postgresql:
  In TSL 2.2, this is an upgrade to 8.0.0 RC 1.

  In TSL 2.1, this is a fix to make stop() in initscript actually say
  that it is stopping.

  rsync:
  Add missing initscript.

  sqlgrey:
  Now be more robust against odd characthers.

  vim:
  Fix modelines.


Action:
  We recommend that all systems with this package installed be upgraded.
  Please note that if you do not need the functionality provided by this
  package, you may want to remove it from your system.


Location:
  All Trustix Secure Linux updates are available from
  <URI:http://http.trustix.org/pub/trustix/updates/>>
  <URI:ftp://ftp.trustix.org/pub/trustix/updates/>>


About Trustix Secure Linux:
  Trustix Secure Linux is a small Linux distribution for servers. With focus
  on security and stability, the system is painlessly kept safe and up to
  date from day one using swup, the automated software updater.


Automatic updates:
  Users of the SWUP tool can enjoy having updates automatically
  installed using 'swup --upgrade'.


Questions?
  Check out our mailing lists:
  <URI:http://www.trustix.org/support/>>


Verification:
  This advisory along with all Trustix packages are signed with the
  TSL sign key.
  This key is available from:
  <URI:http://www.trustix.org/TSL-SIGN-KEY>>

  The advisory itself is available from the errata pages at
  <URI:http://www.trustix.org/errata/trustix-2.1/>> and
  <URI:http://www.trustix.org/errata/trustix-2.2/>>
  or directly at
  <URI:http://www.trustix.org/errata/2004/0067/>>


MD5sums of the packages:
- --------------------------------------------------------------------------
d93c7c1521cdd15cea6331139b4619a4  2.2/rpms/anaconda-7.2.4-8tr.i586.rpm
5399ab260fde48c26e2897f63361dcfb  2.2/rpms/anaconda-runtime-7.2.4-8tr.i586.rpm
132c74fed58bee923dc64f04576b339e  2.2/rpms/db4-4.1.25-7tr.i586.rpm
f86422f147dabcecd29db68e448a137a  2.2/rpms/db4-devel-4.1.25-7tr.i586.rpm
436134a86620b23dc074950ac7e65d3e  2.2/rpms/db4-utils-4.1.25-7tr.i586.rpm
73739e9e68bca5147387fbc0191bf976  2.2/rpms/mailcap-2.1.15-2tr.i586.rpm
b2eb3f2fa5b8fb72b5fadb5962615ff0  2.2/rpms/mkinitrd-3.4.43-13tr.i586.rpm
05c1474c229a82cc732e4f88940d662d  2.2/rpms/ntp-4.2.0-12tr.i586.rpm
514c7bc7c56e0bdef590ab33281c67ac  2.2/rpms/postgresql-8.0.0-0.rc1.2tr.i586.rpm
afba31e5087310fede7d47be97f39731
2.2/rpms/postgresql-contrib-8.0.0-0.rc1.2tr.i586.rpm
aad43f99e9f27c9213457d970d8f9be2
2.2/rpms/postgresql-devel-8.0.0-0.rc1.2tr.i586.rpm
a856655ddd61c66885b9311941a8fa2c
2.2/rpms/postgresql-docs-8.0.0-0.rc1.2tr.i586.rpm
d43baa3944c5ea8b6ce66082a7a6ead0
2.2/rpms/postgresql-libs-8.0.0-0.rc1.2tr.i586.rpm
4b400591f7ff7d14f80c886897327bbf
2.2/rpms/postgresql-plperl-8.0.0-0.rc1.2tr.i586.rpm
8812c35fc75551e6a1554a8e9a55a3ac
2.2/rpms/postgresql-python-8.0.0-0.rc1.2tr.i586.rpm
5271f876de54e751db1e0fb77c50e158
2.2/rpms/postgresql-server-8.0.0-0.rc1.2tr.i586.rpm
754e28a18ef58678210bffe743752c93
2.2/rpms/postgresql-test-8.0.0-0.rc1.2tr.i586.rpm
12149899aaa06916ffdce8c8e7c21661  2.2/rpms/sqlgrey-1.4.0-4tr.i586.rpm
4e3bfab9068fda5c517a198f418ca7b4  2.2/rpms/vim-6.3.045-1tr.i586.rpm
b123d4e89a715d3d39b23276c1006b5a  2.2/rpms/vim-doc-6.3.045-1tr.i586.rpm
75067e6de902fc9ab68bd43eb4ea2605  2.2/rpms/vim-syntax-6.3.045-1tr.i586.rpm
b63f218964b1fb33e84fd3e6498a0310  2.2/rpms/vim-tools-6.3.045-1tr.i586.rpm

108cafbd815602a49524681142148b77  2.1/rpms/postgresql-7.4.6-3tr.i586.rpm
0e1541beb3d94a0c55dc952b9cb88b7b
2.1/rpms/postgresql-contrib-7.4.6-3tr.i586.rpm3131ff6952e39e394a5373937f742c5f
2.1/rpms/postgresql-devel-7.4.6-3tr.i586.rpm
30544e93f10f296f18c17846c006aad8  2.1/rpms/postgresql-docs-7.4.6-3tr.i586.rpm
3a44d01787a29de30a65ca875ea353eb  2.1/rpms/postgresql-libs-7.4.6-3tr.i586.rpm
15acb7ad932022242e54ee4643170e01
2.1/rpms/postgresql-plperl-7.4.6-3tr.i586.rpm
878a4176ddf618d954dc06abc8091740
2.1/rpms/postgresql-python-7.4.6-3tr.i586.rpm
1a7a83ea21a59382fd76673a77f6d696
2.1/rpms/postgresql-server-7.4.6-3tr.i586.rpm
9cbf726dfcb43c02ba38a33c17eed844  2.1/rpms/postgresql-test-7.4.6-3tr.i586.rpm
b6a182817f95157d97eb9319379d8db4  2.1/rpms/rsync-2.6.2-3tr.i586.rpm
e710a0fb98fb74f77591e122e9118221  2.1/rpms/rsync-server-2.6.2-3tr.i586.rpm
- --------------------------------------------------------------------------


Trustix Security Team

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQFBxpCri8CEzsK9IksRAgBtAJ0XF8id+1xo8NtThjCQrM9hiTY+vwCaA01G
a37lzV55pWoWVvwcxEA2lDI=
=psf+
-----END PGP SIGNATURE-----
_______________________________________________
tsl-announce mailing list
tsl-announce@lists.trustix.org
http://lists.trustix.org/mailman/listinfo/tsl-announce


(Log in to post comments)

Copyright © 2004, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds