LWN.net Logo

Trustix Secure Linux

From:  Trustix Security Advisor <tsl-AT-trustix.org>
To:  tsl-announce-AT-lists.trustix.org
Subject:  TSL-2004-0023 - multi
Date:  Fri, 30 Apr 2004 10:55:49 +0200

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Trustix Secure Linux Bugfix Advisory #2004-0023

Package name:      apache, cyrus-imapd, fcron, libpcap, squid
Summary:           Package bugs
Date:              2004-04-29
Affected versions: Trustix Secure Linux 2.1
                   Trustix Secure Enterprise Linux 2

- --------------------------------------------------------------------------
Package description:
  Apache:
  Apache is a full featured web server that is freely available, and also
  happens to be the most widely used.

  Cyrus-imapd:
  The Cyrus IMAP server is a scaleable enterprise mail system
  designed for use from small to large enterprise environments using
  standards-based technologies.

  Fcron:
  Fcron is a scheduler. It aims at replacing Vixie Cron, so it implements most
  of its functionalities.

  Libpcap:
  Libpcap provides a portable framework for low-level network
  monitoring.  Libpcap can provide network statistics collection,
  security monitoring and network debugging.  Since almost every system
  vendor provides a different interface for packet capture, the libpcap
  authors created this system-independent API to ease in porting and to
  alleviate the need for several system-dependent packet capture modules
  in each application.

  Squid:
  Squid is a high-performance proxy caching server for Web clients,
  supporting FTP, gopher, and HTTP data objects. Unlike traditional
  caching software, Squid handles all requests in a single,
  non-blocking, I/O-driven process. Squid keeps meta data and especially
  hot objects cached in RAM, caches DNS lookups, supports non-blocking
  DNS lookups, and implements negative caching of failed requests.

Problem description:
  Apache:
  The Apache packages in TSL 2.1 and TSEL 2 are missing a number of modules
  due to a typo in the spec file.

  Cyrus-imapd:
  Use of deprecated program in cron job lead to warning messages.

  Fcron:
  Incorrect path in %post breaking first time installations.

  libpcap:
  The package did not contain the shared libraries.

  Squid:
  The smb_auth module was build with wrong SAMBAPREFIX making it unusable.

Action:
  We recommend that all systems with this package installed be upgraded.
  Please note that if you do not need the functionality provided by this
  package, you may want to remove it from your system.


Location:
  All Trustix Secure Linux updates are available from
  <URI:http://http.trustix.org/pub/trustix/updates/>
  <URI:ftp://ftp.trustix.org/pub/trustix/updates/>


About Trustix Secure Linux:
  Trustix Secure Linux is a small Linux distribution for servers. With focus
  on security and stability, the system is painlessly kept safe and up to
  date from day one using swup, the automated software updater.


Automatic updates:
  Users of the SWUP tool can enjoy having updates automatically
  installed using 'swup --upgrade'.


Public testing:
  Most updates for Trustix Secure Linux are made available for public
  testing some time before release.
  If you want to contribute by testing the various packages in the
  testing tree, please feel free to share your findings on the
  tsl-discuss mailinglist.
  The testing tree is located at
  <URI:http://tsldev.trustix.org/horizon/>

  You may also use swup for public testing of updates:
  
  site {
      class = 0
      location = "http://tsldev.trustix.org/horizon/rdfs/latest.rdf"
      regexp = ".*"
  }
  

Questions?
  Check out our mailing lists:
  <URI:http://www.trustix.org/support/>


Verification:
  This advisory along with all Trustix packages are signed with the
  TSL sign key.
  This key is available from:
  <URI:http://www.trustix.org/TSL-SIGN-KEY>

  The advisory itself is available from the errata pages at
  <URI:http://www.trustix.org/errata/trustix-2.1/>
  or directly at
  <URI:http://www.trustix.org/errata/misc/2004/TSL-2004-0023-multi.asc.txt>


MD5sums of the packages:
- --------------------------------------------------------------------------
6d7575a70deacc79a4c38de8d1599d0a  TSEL-2/apache-2.0.49-6tr.i586.rpm
d356ba976e0f3f8b0e98e17134e3071f  TSEL-2/apache-dbm-2.0.49-6tr.i586.rpm
2cca3e30aeef72e2660fe852339ae8d5  TSEL-2/apache-devel-2.0.49-6tr.i586.rpm
1eff6311ee8eed0ec372f88b31722d74  TSEL-2/apache-manual-2.0.49-6tr.i586.rpm
3110539ffb07ba311bb14e5ff44df59e  TSEL-2/cyrus-imapd-2.2.3-2tr.i586.rpm
ce3f323431dd70b9b62f0b4e253ad0b2  TSEL-2/cyrus-imapd-devel-2.2.3-2tr.i586.rpm
0a18552ecfa98c41827c910b630388f1  TSEL-2/fcron-2.9.4-8tr.i586.rpm
c206671508dc33b0fb34f27fbbcbc0eb  TSEL-2/libpcap-0.8.2-4tr.i586.rpm
ba8f90f7d37965ed8d86cf5737349ba4  TSEL-2/squid-2.5.STABLE5-4tr.i586.rpm
cb75265f23349a538fedb2b99f66b611  2.1/rpms/apache-2.0.49-6tr.i586.rpm
1ebe817bf2fa3aaa579836a45c66b655  2.1/rpms/apache-dbm-2.0.49-6tr.i586.rpm
01c51b091305c273e7f1ecc8e3248ab0  2.1/rpms/apache-devel-2.0.49-6tr.i586.rpm
919997a0c15eef15433091a9bf028917  2.1/rpms/apache-manual-2.0.49-6tr.i586.rpm
10f607ba4c5a9ff86d5233d41c8e6b59  2.1/rpms/cyrus-imapd-2.2.3-2tr.i586.rpm
1cb8a472e86d9d07a606c08936c7b2f2  2.1/rpms/cyrus-imapd-devel-2.2.3-2tr.i586.rpm
77c510a0cf24c4bc2807dc0458507e0f  2.1/rpms/fcron-2.9.4-8tr.i586.rpm
62645c045a78b8649da84c2d1c65bed7  2.1/rpms/libpcap-0.8.2-4tr.i586.rpm
8c1afb76a8fe2c25d24f0b44e565a8f8  2.1/rpms/squid-2.5.STABLE5-4tr.i586.rpm
- --------------------------------------------------------------------------


Trustix Security Team

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQFAkgcvi8CEzsK9IksRAjArAKCM1csiaTLN+1ys3bEiLwt3pS8XqgCgnBMO
LAd+Gq3RJFwSBumb0ygyt0E=
=rt+P
-----END PGP SIGNATURE-----
_______________________________________________
tsl-announce mailing list
tsl-announce@lists.trustix.org
http://lists.trustix.org/mailman/listinfo/tsl-announce


(Log in to post comments)

Copyright © 2004, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds