|
|
Log in / Subscribe / Register

Security

No legacy for Fedora x86-64

April 27, 2005

This article was contributed by Joe 'Zonker' Brockmeier.

As Fedora Core 2 (FC2) is transferred to the Fedora Legacy Project, some users may be surprised to find that the project will be focusing only on the i386 platform, leaving users of FC2 on x86_64 platforms to fend for themselves when it comes to security updates and bugfixes.

For those not familiar with Fedora Legacy, the project provides support for Red Hat 7.3, Red Hat 9, and Fedora Core releases past their "end-of-life." With Fedora Core releases, the project uses a "1-2-3 and out" policy. When Red Hat's Fedora team stops providing support for an FC release, the Fedora Legacy project begins maintaining the release, for two additional releases. Note that the idea behind the Legacy project is not to provide new packages for retired releases, but only to provide security updates and necessary fixes. Users who want the newest software need to look to newer FC releases.

Unlike Fedora Core, the Fedora Legacy project is not directly sponsored by Red Hat, though the group does receive some assistance from Red Hat. We talked to Jesse Keating, Fedora Legacy Project Leader, about the lack of support for FC2 on x86_64, what alternatives users have, and whether the project will be supporting future x86_64 releases.

Keating said that the project lacks the developers to keep up with x86_64 in addition to maintaining i386 versions of FC:

Primarily it is lack of developers/testers for package testing and approval. Starting off with the small set we have, and trying to subset them into x86_64 users is pretty tough. Further reasons include lack of physical resources (build hardware, rack space, bandwidth), build software changes, and publishing changes necessary to handle x86_64.

Indeed, it does seem that the Legacy project is a bit short-staffed. The (volunteer) positions page lists quite a few vacancies.

We also asked Keating how the project was building packages, whether they used a system similar to Debian buildd or something else. Keating said that the project is using a version of mach to build packages, and that they're looking to have a system that can produce i386 and x86_64 packages.

This allows us to build in a fresh chroot each time, and do multiple builds of a package for different RH/FC releases. It works pretty well for what we need it for. In the near future we will look at moving to the new Fedora Extras build system that is currently in development. Our goal is to be able to have one build system we can use to produce both 32bit and 64bit packages. Currently 32bit packages have to be built on a 32bit host and 64bit packages will have to be built on a 64bit host. The main build hardware that Pogo Linux donated to the project is x86_64 capable (dual Opteron) but we're using it in a 32bit mode currently. Given the price of rack space and bandwidth and all things associated we may not be able to afford a second 64bit build system. So we'll probably have to wait until the new build software is complete and re-design/deploy our Legacy build server.

Users who are in no hurry to upgrade to later FC releases can try building the source RPMs on x86_64. Keating invited those users to offer feedback on the packages, and said that users "typically" don't run into issues when trying to compile i386 packages on x86_64.

Keating did say that it's likely that there would be support for x86_64 in the future, given that there are more users for x86_64 with each new FC release. Since the Legacy project is strictly a volunteer operation, the best way to see to it that there is support for x86_64 is for users to get involved with the project.

Comments (3 posted)

New vulnerabilities

Convert-UUlib: buffer overflow

Package(s):Convert-UUlib CVE #(s):
Created:April 26, 2005 Updated:April 27, 2005
Description: A vulnerability has been reported in Convert-UUlib where a malformed parameter can be provided by an attacker allowing a read operation to overflow a buffer. The vendor credits Mark Martinec and Robert Lewis with the discovery.
Alerts:
Gentoo 200504-26 Convert-UUlib 2005-04-26

Comments (none posted)

eGroupWare: XSS and SQL injection vulnerabilities

Package(s):eGroupWare CVE #(s):
Created:April 25, 2005 Updated:April 27, 2005
Description: Multiple SQL injection and cross-site scripting vulnerabilities have been found in several eGroupWare modules. An attacker could possibly use the SQL injection vulnerabilities to gain information from the database. Furthermore the cross-site scripting issues give an attacker the ability to inject and execute malicious script code or to steal cookie based authentication credentials, potentially compromising the victim's browser.
Alerts:
Gentoo 200504-24 egroupware 2005-04-25

Comments (none posted)

kimgio input validation errors

Package(s):kimgio CVE #(s):CAN-2005-1046
Created:April 22, 2005 Updated:July 19, 2005
Description: KDE has issued a security advisory for kimgio. This is found in kdelibs as shipped with KDE 3.2 up to including KDE 3.4. kimgio contains a PCX image file format reader that does not properly perform input validation. A source code audit performed by the KDE security team discovered several vulnerabilities in the PCX and other image file format readers, some of them exploitable to execute arbitrary code.
Alerts:
Ubuntu USN-114-2 kdelibs 2005-05-27
Red Hat RHSA-2005:393-01 kdelibs 2005-05-17
Mandriva MDKSA-2005:085 kdelibs 2005-05-12
Ubuntu USN-114-1 kdelibs 2005-05-03
Fedora FEDORA-2005-350 kdelibs 2005-05-02
Debian DSA-714-1 kdelibs 2005-04-26
Gentoo 200504-22 kimgio 2005-04-22

Comments (none posted)

Kommander untrusted code execution

Package(s):kommander CVE #(s):CAN-2005-0754
Created:April 22, 2005 Updated:May 20, 2005
Description: KDE has issued a security advisory for Kommander. Quanta 3.1.x, KDE 3.2 and new up to including KDE 3.4.0 are vulnerable. Kommander executes without user confirmation data files from possibly untrusted locations. As they contain scripts, the user might accidentally run arbitrary code.
Alerts:
Gentoo 200504-23:02 kdewebdev 2005-04-22
Ubuntu USN-115-1 kdewebdev 2005-05-03
Fedora FEDORA-2005-345 kdewebdev 2005-04-28
Gentoo 200504-23 kdewebdev 2005-04-22

Comments (none posted)

lsh: buffer overflow and more

Package(s):lsh-utils CVE #(s):CAN-2003-0826 CAN-2005-0814
Created:April 27, 2005 Updated:April 27, 2005
Description: The lsh implementation of SSH2 suffers from a number of vulnerabilities, including an exploitable buffer overflow.
Alerts:
Debian DSA-717-1 lsh-utils 2005-04-27

Comments (none posted)

openmosixview: insecure temp file

Package(s):openmosixview CVE #(s):CAN-2005-0894
Created:April 21, 2005 Updated:April 27, 2005
Description: openMosixview and the openMosixcollector daemon can create an insecure temporary file, this can be exploited by a local user to overwrite arbitrary files via symbolic links.
Alerts:
Gentoo 200504-20 openmosixview 2005-04-21

Comments (none posted)

Rootkit Hunter: insecure temporary file creation

Package(s):rkhunter CVE #(s):CAN-2005-1270
Created:April 26, 2005 Updated:April 27, 2005
Description: Sune Kloppenborg Jeppesen and Tavis Ormandy of the Gentoo Linux Security Team have reported that the check_update.sh script and the main rkhunter script insecurely creates several temporary files with predictable filenames.
Alerts:
Gentoo 200504-25 rkhunter 2005-04-26

Comments (none posted)

xine-lib: two heap overflow vulnerabilities

Package(s):xine-lib CVE #(s):CAN-2005-1195
Created:April 26, 2005 Updated:June 2, 2005
Description: Heap overflows have been found in the code handling RealMedia RTSP and Microsoft Media Services streams over TCP (MMST). See Xine Advisory XSA-2004-8 for details.
Alerts:
Mandriva MDKSA-2005:094 xine-lib 2005-05-26
SuSE SUSE-SR:2005:013 xine kimgio 2005-05-18
Ubuntu USN-123-1 xine-lib 2005-05-06
Slackware SSA:2005-121-02 xine 2005-05-02
Gentoo 200504-27 xine-lib 2005-04-26

Comments (none posted)

Page editor: Jonathan Corbet
Next page: Kernel development>>


Copyright © 2005, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds