TSL-2005-0019 - multi
[Posted May 11, 2005 by ris]
| From: |
| Trustix Security Advisor <tsl-AT-trustix.org> |
| To: |
| tsl-announce-AT-lists.trustix.org |
| Subject: |
| TSL-2005-0019 - multi |
| Date: |
| Fri, 6 May 2005 18:36:19 +0200 |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- --------------------------------------------------------------------------
Trustix Secure Linux Bugfix Advisory #2005-0019
Package name: bind bittorrent bzip2 clamav hwdata ppp spamassassin
Summary: Various packaging fixes
Date: 2005-05-06
Affected versions: Trustix Secure Linux 2.1
Trustix Secure Linux 2.2
Trustix Operating System - Enterprise Server 2
- --------------------------------------------------------------------------
Package description:
bind:
BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. BIND includes a DNS server (named),
which resolves host names to IP addresses, and a resolver library
(routines for applications to use when interfacing with DNS). A DNS
server allows clients to name resources or objects and share the
information with other network machines. The named DNS server can be
used on workstations as a caching name server, but is generally only
needed on one machine for an entire network.
bittorrent:
BitTorrent gives you the same freedom to publish previously enjoyed by
only a select few with special equipment and lots of money.
You have something terrific to publish -- a large music or video file,
software, a game or anything else that many people would like to have.
But the more popular your file becomes, the more you are punished by
soaring bandwidth costs. If your file becomes phenomenally successful
and a flash crowd of hundreds or thousands try to get it at once, your
server simply crashes and no one gets it. There is a solution to this
vicious cycle. BitTorrent, the result of over two years of intensive
development, is a simple and free software product that addresses all
of these problems.
bzip2:
Bzip2 is a freely available, patent-free, high quality data compressor.
Bzip2 compresses files to within 10 to 15 percent of the capabilities
of the best techniques available. However, bzip2 has the added benefit
of being approximately two times faster at compression and six times
faster at decompression than those techniques. Bzip2 is not the
fastest compression utility, but it does strike a balance between speed
and compression capability.
clamav:
Clam AntiVirus is a GPL anti-virus toolkit for UNIX. The main purpose of
this software is the integration with mail servers (attachment scanning).
The package provides a flexible and scalable multi-threaded daemon,
a command line scanner, and a tool for automatic updating via Internet.
The programs are based on a shared library distributed with package,
which you can use with your own software.
Most importantly, the virus database is kept up to date .
hwdata:
hwdata contains various hardware identification and configuration data,
such as the pci.ids database, the XFree86 Cards and MonitorsDb databases.
ppp:
The ppp package contains the PPP (Point-to-Point Protocol) daemon
and documentation for PPP support. The PPP protocol provides a
method for transmitting datagrams over serial point-to-point links.
spamassassin:
SpamAssassin provides you with a way to reduce, if not completely
eliminate, Unsolicited Bulk Email (or "spam") from your incoming email.
It can be invoked by a MDA such as sendmail or postfix, or can be called
from a procmail script, .forward file, etc. It uses a
genetic-algorithm-evolved scoring system to identify messages which look
spammy, then adds headers to the message so they can be filtered by the
user's mail reading software. This distribution includes the
spamd/spamc components which considerably speeds processing of mail.
Problem description:
bind:
- Fix File Conflicts Issue, Bug #556
bittorrent:
- Use %doc as opposed to /usr/share/doc in filelist. Bug #606.
bzip2:
- New upstream.
clamav:
- New Upstream,improves detection of JPEG (MS04-028) based exploits,
introduces support for TNEF files and new detection mechanisms.
Various bugfixes (including problems with scanning of digest mail
files) and improvements have been made.
hwdata:
- Less spaces in pcitables.
ppp:
- Fixed wrong plugins directory, Bug #562
spamassassin:
- New Upstream, fixes possible memory bloat from large AutoWhitelist
db files. It fixes a bug where user defined rules scores became ignored.
Action:
We recommend that all systems with this package installed be upgraded.
Please note that if you do not need the functionality provided by this
package, you may want to remove it from your system.
Location:
All Trustix Secure Linux updates are available from
<URI:http://http.trustix.org/pub/trustix/updates/>>
<URI:ftp://ftp.trustix.org/pub/trustix/updates/>>
About Trustix Secure Linux:
Trustix Secure Linux is a small Linux distribution for servers. With focus
on security and stability, the system is painlessly kept safe and up to
date from day one using swup, the automated software updater.
Automatic updates:
Users of the SWUP tool can enjoy having updates automatically
installed using 'swup --upgrade'.
Questions?
Check out our mailing lists:
<URI:http://www.trustix.org/support/>>
Verification:
This advisory along with all Trustix packages are signed with the
TSL sign key.
This key is available from:
<URI:http://www.trustix.org/TSL-SIGN-KEY>>
The advisory itself is available from the errata pages at
<URI:http://www.trustix.org/errata/trustix-2.1/>> and
<URI:http://www.trustix.org/errata/trustix-2.2/>>
or directly at
<URI:http://www.trustix.org/errata/2005/0019/>>
MD5sums of the packages:
- --------------------------------------------------------------------------
67bdf09bcb2d2a991b22864a8c3a9e55 2.2/rpms/bind-9.3.1-2tr.i586.rpm
03ceacfe2232dda4ead8e5392e887edb 2.2/rpms/bind-devel-9.3.1-2tr.i586.rpm
7c4e50231a08f5b538351e2c5065dd2f 2.2/rpms/bind-libs-9.3.1-2tr.i586.rpm
e4d8f10b3fcf0dec431d0261b22dc723 2.2/rpms/bind-light-9.3.1-2tr.i586.rpm
dcff11d97ec4455cd80ef36c8ca6a505 2.2/rpms/bind-light-devel-9.3.1-2tr.i586.rpm
5bffca004d23844da2e7fc3779f1fe6e 2.2/rpms/bind-utils-9.3.1-2tr.i586.rpm
16e3a28141208dabf76585bd1d314bc8 2.2/rpms/bittorrent-4.0.1-4tr.i586.rpm
4e9b814827d1397ed22d48a9039712d5 2.2/rpms/bzip2-1.0.3-1tr.i586.rpm
f06ad123182ad54a4231fb38fa0ca804 2.2/rpms/bzip2-devel-1.0.3-1tr.i586.rpm
af8e430c3205890d6f08aa9773094adc 2.2/rpms/bzip2-libs-1.0.3-1tr.i586.rpm
af75e88aa99df1a7e5a8d2bfe3f538fc 2.2/rpms/clamav-0.84-1tr.i586.rpm
8fb9463b61d784bb6fa89db8c3d303d1 2.2/rpms/clamav-devel-0.84-1tr.i586.rpm
f66ccbe72e69c63915f93a843b09a6ef 2.2/rpms/hwdata-0.44-23tr.i586.rpm
5717373f55c1690035a825fbfa66872d 2.2/rpms/hwdata-devel-0.44-23tr.i586.rpm
83af54c5ff540aa054e05d8136c4f4de
2.2/rpms/perl-mail-spamassassin-3.0.3-1tr.i586.rpm
81f7fc36bbc8908187cac1d464f68bdf 2.2/rpms/ppp-2.4.3-4tr.i586.rpm
bde9c60f0c98eccad79261d0985022fd 2.2/rpms/spamassassin-3.0.3-1tr.i586.rpm
707f3e8138e26e08acbdbf3be5bb9113
2.2/rpms/spamassassin-tools-3.0.3-1tr.i586.rpm
7bbc84db817fadb2773393f79e5c8d12 2.1/rpms/bind-9.2.3-7tr.i586.rpm
e74402c46df9d07e3a637a9c96072dcf 2.1/rpms/bind-devel-9.2.3-7tr.i586.rpm
83db3dfe7a914c8adb9e6e045b9cd01f 2.1/rpms/bind-libs-9.2.3-7tr.i586.rpm
f33a67c47ee3ea32dc4ea3a59d1741f1 2.1/rpms/bind-light-9.2.3-7tr.i586.rpm
b4adb58a80cd20574c7648a5452adcbd 2.1/rpms/bind-light-devel-9.2.3-7tr.i586.rpm
18996c25f8dc1a8bb9e5faa8e66f8cbd 2.1/rpms/bind-utils-9.2.3-7tr.i586.rpm
c38b82d3a79a19dcdee05576f167fd26 2.1/rpms/bzip2-1.0.3-1tr.i586.rpm
29b14ca650b932fe2730d19616ef735c 2.1/rpms/bzip2-devel-1.0.3-1tr.i586.rpm
deaf4475208668ae71d5a58805152185 2.1/rpms/bzip2-libs-1.0.3-1tr.i586.rpm
81e14585f7a740d761d853f8bacf83be 2.1/rpms/hwdata-0.44-17tr.i586.rpm
e40eafbaf1a2242d01c855f307308eb1 2.1/rpms/hwdata-devel-0.44-17tr.i586.rpm
e9632c64cd312a01764dbfa8a06b8432 2.1/rpms/ppp-2.4.1-12tr.i586.rpm
- --------------------------------------------------------------------------
Trustix Security Team
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)
iD8DBQFCe5uki8CEzsK9IksRAmVrAJ9jKHPS4WBAqhXPi3yC2HMfwu07cACeNmcR
JdFkYeh9gNQJYLrpnB9hak0=
=3s8z
-----END PGP SIGNATURE-----
_______________________________________________
tsl-announce mailing list
tsl-announce@lists.trustix.org
http://lists.trustix.org/mailman/listinfo/tsl-announce
(
Log in to post comments)