From announce-noreply@rpath.com Wed Aug 13 21:59:59 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7DLxx80026430
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 21:59:59 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7DLxwk1025066
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 17:59:58 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7DLxwOJ015561
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 17:59:58 -0400
Date: Wed, 13 Aug 2008 17:59:58 -0400
Message-Id: <200808132159.m7DLxwOJ015561@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
X-Mailman-Approved-At: Wed, 13 Aug 2008 22:00:58 +0000
Subject: [Sle-announce]  Recommended update for wget
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 13 Aug 2008 21:59:59 -0000

Published: 2008-08-13
Products:
    SLES Delivered by rPath

Updated Versions:
    wget=sle.rpath.com@rpath:sles-10/1.10.2_15.4-2-5

Description:
Fixes timeout for https connections


From announce-noreply@rpath.com Wed Aug 13 22:00:31 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7DM0VGf026438
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 22:00:31 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7DM0USe025210
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:30 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7DM0UnA015624
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:30 -0400
Date: Wed, 13 Aug 2008 18:00:30 -0400
Message-Id: <200808132200.m7DM0UnA015624@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
X-Mailman-Approved-At: Wed, 13 Aug 2008 22:00:58 +0000
Subject: [Sle-announce]  Security update for freetype2,
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 13 Aug 2008 22:00:31 -0000

Published: 2008-08-13
Products:
    SLES Delivered by rPath

Updated Versions:
    freetype2=sle.rpath.com@rpath:sles-10/2.1.10_18.14-1-5

Description:
This update of freetype2 fixes several potential
vulnerabilities reported by iDefense.


From announce-noreply@rpath.com Wed Aug 13 22:00:33 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7DM0X9M026441
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 22:00:33 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7DM0Xq7025223
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:33 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7DM0Xn3015630
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:33 -0400
Date: Wed, 13 Aug 2008 18:00:33 -0400
Message-Id: <200808132200.m7DM0Xn3015630@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
X-Mailman-Approved-At: Wed, 13 Aug 2008 22:00:58 +0000
Subject: [Sle-announce]  Recommended update for mingetty
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 13 Aug 2008 22:00:33 -0000

Published: 2008-08-13
Products:
    SLES Delivered by rPath

Updated Versions:
    mingetty=sle.rpath.com@rpath:sles-10/0.9.6s_88.2-2-5

Description:
On memory mapped files with long file names the mingetty
may die with a SIGSEGV during scanning for /dev/vcsN
devices.


From announce-noreply@rpath.com Wed Aug 13 22:00:34 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7DM0Yk4026444
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 22:00:34 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7DM0Ye7025227
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:34 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7DM0Xsv015635
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:34 -0400
Date: Wed, 13 Aug 2008 18:00:33 -0400
Message-Id: <200808132200.m7DM0Xsv015635@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
X-Mailman-Approved-At: Wed, 13 Aug 2008 22:00:58 +0000
Subject: [Sle-announce]  Security update for Samba
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 13 Aug 2008 22:00:34 -0000

Published: 2008-08-13
Products:
    SLES Delivered by rPath

Updated Versions:
    libsmbclient=sle.rpath.com@rpath:sles-10/3.0.28_0.5-2-5
    cifs-mount=sle.rpath.com@rpath:sles-10/3.0.28_0.5-2-5
    libmsrpc=sle.rpath.com@rpath:sles-10/3.0.28_0.5-2-5
    samba-vscan=sle.rpath.com@rpath:sles-10/3.0.28_0.5-2-5
    samba-pdb=sle.rpath.com@rpath:sles-10/3.0.28_0.5-2-5
    samba-krb-printing=sle.rpath.com@rpath:sles-10/3.0.28_0.5-2-5
    samba-winbind=sle.rpath.com@rpath:sles-10/3.0.28_0.5-2-5
    samba-python=sle.rpath.com@rpath:sles-10/3.0.28_0.5-2-5
    samba-client=sle.rpath.com@rpath:sles-10/3.0.28_0.5-2-5

Description:
Samba has been updated to fix a security problem:

CVE-2008-1105: Secunia research discovered  vulnerability
in Samba, which can be exploited by malicious people to
compromise a vulnerable system.

The vulnerability is caused due to a boundary error within
the "receive_smb_raw()" function in lib/util_sock.c when
parsing SMB packets. This can be exploited to cause a
heap-based buffer overflow via an overly large SMB packet
received in a client context.


From announce-noreply@rpath.com Wed Aug 13 22:00:35 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7DM0ZXL026447
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 22:00:35 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7DM0ZcG025230
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:35 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7DM0Yh7015638
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:34 -0400
Date: Wed, 13 Aug 2008 18:00:34 -0400
Message-Id: <200808132200.m7DM0Yh7015638@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
X-Mailman-Approved-At: Wed, 13 Aug 2008 22:00:58 +0000
Subject: [Sle-announce]  Recommended update for resmgr
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 13 Aug 2008 22:00:35 -0000

Published: 2008-08-13
Products:
    SLES Delivered by rPath

Updated Versions:
    resmgr=sle.rpath.com@rpath:sles-10/0.9.8_SVNr75_18.4-3-5

Description:
resmgr could hang during login if ldap authentication is
used and the network is unavailable. This also affects
local users such as root.


From announce-noreply@rpath.com Wed Aug 13 22:00:36 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7DM0aQU026450
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 22:00:36 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7DM0ZRo025240
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:35 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7DM0ZWr015641
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:35 -0400
Date: Wed, 13 Aug 2008 18:00:35 -0400
Message-Id: <200808132200.m7DM0ZWr015641@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
X-Mailman-Approved-At: Wed, 13 Aug 2008 22:00:58 +0000
Subject: [Sle-announce]  Recommended update for acl
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 13 Aug 2008 22:00:36 -0000

Published: 2008-08-13
Products:
    SLES Delivered by rPath

Updated Versions:
    acl=sle.rpath.com@rpath:sles-10/2.2.41_0.12-1-5

Description:
The acl package was updated to version 2.2.45 to fix
following the bugs:

- Silent failure to recursively set ACLs on directories and
  files when -R is set on setfacl
 - Failure to fully recurse directory structures with
   getfacl -R


From announce-noreply@rpath.com Wed Aug 13 22:00:37 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7DM0bsR026453
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 22:00:37 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7DM0ajM025253
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:36 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7DM0a7U015644
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:36 -0400
Date: Wed, 13 Aug 2008 18:00:36 -0400
Message-Id: <200808132200.m7DM0a7U015644@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
X-Mailman-Approved-At: Wed, 13 Aug 2008 22:00:58 +0000
Subject: [Sle-announce]  Security update for PHP5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 13 Aug 2008 22:00:37 -0000

Published: 2008-08-13
Products:
    SLES Delivered by rPath

Updated Versions:
    php5-dom=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-tokenizer=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-bcmath=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-openssl=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-zlib=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-iconv=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-dbase=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-sqlite=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-ftp=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-pear=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-pdo=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-shmop=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-sysvshm=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-sysvsem=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-sockets=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-ldap=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-pcntl=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-gmp=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-mbstring=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-ctype=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-soap=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-calendar=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-sysvmsg=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-wddx=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-posix=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-bz2=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-ncurses=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-odbc=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-exif=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-gettext=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-fastcgi=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-xmlrpc=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-xmlreader=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5
    php5-dba=sle.rpath.com@rpath:sles-10/5.2.5_9.5-1-5

Description:
This version upgrade php5 to 5.2.6 fixes several security
vulnerabilities.
* Fixed possible stack buffer overflow in the FastCGI SAPI
  identified by Andrei
Nigmatulin.
                          
* Fixed integer overflow in printf() identified by
  Maksymilian
Aciemowicz.
                                           
* Fixed security issue detailed in CVE-2008-0599 identified
  by Ryan
Permeh.
                                      
* Fixed a safe_mode bypass in cURL identified by
  Maksymilian
Arciemowicz.
                                             
* Properly address incomplete multibyte chars inside
  escapeshellcmd() identified by Stefan
Esser.
               
* and many more...


From announce-noreply@rpath.com Wed Aug 13 22:00:38 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7DM0c5X026456
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 22:00:38 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7DM0bYD025261
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:37 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7DM0bnT015649
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:37 -0400
Date: Wed, 13 Aug 2008 18:00:37 -0400
Message-Id: <200808132200.m7DM0bnT015649@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
X-Mailman-Approved-At: Wed, 13 Aug 2008 22:00:58 +0000
Subject: [Sle-announce]  Recommended update for syslogd
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 13 Aug 2008 22:00:38 -0000

Published: 2008-08-13
Products:
    SLES Delivered by rPath

Updated Versions:
    klogd=sle.rpath.com@rpath:sles-10/1.4.1_559.12-2-5

Description:
With coreutils missing in the requirements of syslogd,
syslogd causes an AutoYast build to error and pause.  The
build waits for a system administrator to select: Ignore,
Retry, Abort.


From announce-noreply@rpath.com Wed Aug 13 22:00:39 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7DM0cpG026459
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 22:00:38 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7DM0cu3025277
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:38 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7DM0c0o015654
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:38 -0400
Date: Wed, 13 Aug 2008 18:00:38 -0400
Message-Id: <200808132200.m7DM0c0o015654@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
X-Mailman-Approved-At: Wed, 13 Aug 2008 22:00:58 +0000
Subject: [Sle-announce]  Recommended update for mdadm
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 13 Aug 2008 22:00:39 -0000

Published: 2008-08-13
Products:
    SLES Delivered by rPath

Updated Versions:
    mdadm=sle.rpath.com@rpath:sles-10/2.6_0.17-1-5

Description:
This update fixes hot-adding of large devices (>4TB) to md
arrays.


From announce-noreply@rpath.com Wed Aug 13 22:00:39 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7DM0dwP026462
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 22:00:39 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7DM0dd7025285
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:39 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7DM0dYr015657
	for <sle-announce@lists.rpath.com>; Wed, 13 Aug 2008 18:00:39 -0400
Date: Wed, 13 Aug 2008 18:00:39 -0400
Message-Id: <200808132200.m7DM0dYr015657@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
X-Mailman-Approved-At: Wed, 13 Aug 2008 22:00:58 +0000
Subject: [Sle-announce]  Security update for Linux kernel
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 13 Aug 2008 22:00:40 -0000

Published: 2008-08-13
Products:
    SLES Delivered by rPath

Updated Versions:
    bzip2=sle.rpath.com@rpath:sles-10/1.0.3_17.2-2-5

Description:
Specially crafted files could crash the bzip2-decoder
(CVE-2008-1372).


From announce-noreply@rpath.com Tue Aug 19 01:58:48 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7J1wmiw032000
	for <sle-announce@lists.rpath.com>; Tue, 19 Aug 2008 01:58:48 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7J1wm3j004724
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:48 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7J1wm24019752
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:48 -0400
Date: Mon, 18 Aug 2008 21:58:48 -0400
Message-Id: <200808190158.m7J1wm24019752@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for wget
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 19 Aug 2008 01:58:49 -0000

Published: 2008-08-18
Products:
    SLES Delivered by rPath

Updated Versions:
    wget=sle.rpath.com@rpath:sles-10/1.10.2_15.8-1-1

Description:
Fixes timeout for https connections


From announce-noreply@rpath.com Tue Aug 19 01:58:49 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7J1wneK032003
	for <sle-announce@lists.rpath.com>; Tue, 19 Aug 2008 01:58:49 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7J1wmEM004727
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:48 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7J1wmDR019755
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:48 -0400
Date: Mon, 18 Aug 2008 21:58:48 -0400
Message-Id: <200808190158.m7J1wmDR019755@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for acl
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 19 Aug 2008 01:58:49 -0000

Published: 2008-08-18
Products:
    SLES Delivered by rPath

Updated Versions:
    acl=sle.rpath.com@rpath:sles-10/2.2.41_0.15-1-1

Description:
The acl package was updated to version 2.2.45 to fix
following the bugs:

- Silent failure to recursively set ACLs on directories and
  files when -R is set on setfacl
 - Failure to fully recurse directory structures with
   getfacl -R


From announce-noreply@rpath.com Tue Aug 19 01:58:49 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7J1wn3L032006
	for <sle-announce@lists.rpath.com>; Tue, 19 Aug 2008 01:58:49 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7J1wnhP004734
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:49 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7J1wmWt019759
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:48 -0400
Date: Mon, 18 Aug 2008 21:58:48 -0400
Message-Id: <200808190158.m7J1wmWt019759@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for mdadm
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 19 Aug 2008 01:58:49 -0000

Published: 2008-08-18
Products:
    SLES Delivered by rPath

Updated Versions:
    mdadm=sle.rpath.com@rpath:sles-10/2.6_0.18-1-1

Description:
This update fixes hot-adding of large devices (>4TB) to md
arrays.


From announce-noreply@rpath.com Tue Aug 19 01:58:49 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7J1wneV032009
	for <sle-announce@lists.rpath.com>; Tue, 19 Aug 2008 01:58:49 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7J1wn20004735
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:49 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7J1wn6P019763
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:49 -0400
Date: Mon, 18 Aug 2008 21:58:49 -0400
Message-Id: <200808190158.m7J1wn6P019763@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for mingetty
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 19 Aug 2008 01:58:49 -0000

Published: 2008-08-18
Products:
    SLES Delivered by rPath

Updated Versions:
    mingetty=sle.rpath.com@rpath:sles-10/0.9.6s_88.6-1-1

Description:
On memory mapped files with long file names the mingetty
may die with a SIGSEGV during scanning for /dev/vcsN
devices.


From announce-noreply@rpath.com Tue Aug 19 01:58:50 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7J1wn51032012
	for <sle-announce@lists.rpath.com>; Tue, 19 Aug 2008 01:58:49 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7J1wnRs004742
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:49 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7J1wnf8019766
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:49 -0400
Date: Mon, 18 Aug 2008 21:58:49 -0400
Message-Id: <200808190158.m7J1wnf8019766@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Linux kernel
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 19 Aug 2008 01:58:50 -0000

Published: 2008-08-18
Products:
    SLES Delivered by rPath

Updated Versions:
    bzip2=sle.rpath.com@rpath:sles-10/1.0.3_17.9-1-1

Description:
Specially crafted files could crash the bzip2-decoder
(CVE-2008-1372).


From announce-noreply@rpath.com Tue Aug 19 01:58:50 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7J1woGH032016
	for <sle-announce@lists.rpath.com>; Tue, 19 Aug 2008 01:58:50 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7J1woan004750
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:50 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7J1wnUO019773
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:49 -0400
Date: Mon, 18 Aug 2008 21:58:49 -0400
Message-Id: <200808190158.m7J1wnUO019773@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for syslogd
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 19 Aug 2008 01:58:50 -0000

Published: 2008-08-18
Products:
    SLES Delivered by rPath

Updated Versions:
    klogd=sle.rpath.com@rpath:sles-10/1.4.1_559.17-1-1

Description:
With coreutils missing in the requirements of syslogd,
syslogd causes an AutoYast build to error and pause.  The
build waits for a system administrator to select: Ignore,
Retry, Abort.


From announce-noreply@rpath.com Tue Aug 19 01:58:50 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7J1woZ4032014
	for <sle-announce@lists.rpath.com>; Tue, 19 Aug 2008 01:58:50 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7J1wn2w004743
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:49 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7J1wnqR019770
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:49 -0400
Date: Mon, 18 Aug 2008 21:58:49 -0400
Message-Id: <200808190158.m7J1wnqR019770@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Python
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 19 Aug 2008 01:58:50 -0000

Published: 2008-08-18
Products:
    SLES Delivered by rPath

Updated Versions:
    python=sle.rpath.com@rpath:sles-10/2.4.2_18.22-1-1
    python-xml=sle.rpath.com@rpath:sles-10/2.4.2_18.22-1-1

Description:
This update of python fixes several security
vulnerabilities. (CVE-2008-1679,CVE-2008-1887,
CVE-2008-3143, CVE-2008-3142, CVE-2008-3144, CVE-2008-2315,
CVE-2008-2316) Note: for SLE10 a non-security bug in mmap
was fixed too.


From announce-noreply@rpath.com Tue Aug 19 01:58:51 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7J1wpOb032028
	for <sle-announce@lists.rpath.com>; Tue, 19 Aug 2008 01:58:51 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7J1wpvZ004757
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:51 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7J1woXv019776
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:50 -0400
Date: Mon, 18 Aug 2008 21:58:50 -0400
Message-Id: <200808190158.m7J1woXv019776@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Samba
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 19 Aug 2008 01:58:51 -0000

Published: 2008-08-18
Products:
    SLES Delivered by rPath

Updated Versions:
    samba-client=sle.rpath.com@rpath:sles-10/3.0.28_0.6-1-1
    cifs-mount=sle.rpath.com@rpath:sles-10/3.0.28_0.6-1-1
    samba-pdb=sle.rpath.com@rpath:sles-10/3.0.28_0.6-1-1
    libsmbclient=sle.rpath.com@rpath:sles-10/3.0.28_0.6-1-1
    samba-winbind=sle.rpath.com@rpath:sles-10/3.0.28_0.6-1-1
    samba-python=sle.rpath.com@rpath:sles-10/3.0.28_0.6-1-1
    libmsrpc=sle.rpath.com@rpath:sles-10/3.0.28_0.6-1-1
    samba-krb-printing=sle.rpath.com@rpath:sles-10/3.0.28_0.6-1-1
    samba-vscan=sle.rpath.com@rpath:sles-10/3.0.28_0.6-1-1

Description:
Samba has been updated to fix a security problem:

CVE-2008-1105: Secunia research discovered  vulnerability
in Samba, which can be exploited by malicious people to
compromise a vulnerable system.

The vulnerability is caused due to a boundary error within
the "receive_smb_raw()" function in lib/util_sock.c when
parsing SMB packets. This can be exploited to cause a
heap-based buffer overflow via an overly large SMB packet
received in a client context.


From announce-noreply@rpath.com Tue Aug 19 01:58:52 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7J1wpIT032036
	for <sle-announce@lists.rpath.com>; Tue, 19 Aug 2008 01:58:51 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7J1wpr3004760
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:51 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7J1wpvY019780
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:51 -0400
Date: Mon, 18 Aug 2008 21:58:51 -0400
Message-Id: <200808190158.m7J1wpvY019780@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for resmgr
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 19 Aug 2008 01:58:52 -0000

Published: 2008-08-18
Products:
    SLES Delivered by rPath

Updated Versions:
    resmgr=sle.rpath.com@rpath:sles-10/0.9.8_SVNr75_18.9-1-1

Description:
resmgr could hang during login if ldap authentication is
used and the network is unavailable. This also affects
local users such as root.


From announce-noreply@rpath.com Tue Aug 19 01:58:52 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7J1wqAc032038
	for <sle-announce@lists.rpath.com>; Tue, 19 Aug 2008 01:58:52 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7J1wp4u004771
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:51 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7J1wpUf019783
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:51 -0400
Date: Mon, 18 Aug 2008 21:58:51 -0400
Message-Id: <200808190158.m7J1wpUf019783@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for freetype2,
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 19 Aug 2008 01:58:53 -0000

Published: 2008-08-18
Products:
    SLES Delivered by rPath

Updated Versions:
    freetype2=sle.rpath.com@rpath:sles-10/2.1.10_18.17-1-1

Description:
This update of freetype2 fixes several potential
vulnerabilities reported by iDefense.


From announce-noreply@rpath.com Tue Aug 19 01:58:52 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7J1wqeP032039
	for <sle-announce@lists.rpath.com>; Tue, 19 Aug 2008 01:58:52 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7J1wpqZ004779
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:51 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7J1wpqe019787
	for <sle-announce@lists.rpath.com>; Mon, 18 Aug 2008 21:58:51 -0400
Date: Mon, 18 Aug 2008 21:58:51 -0400
Message-Id: <200808190158.m7J1wpqe019787@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for PHP5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 19 Aug 2008 01:58:53 -0000

Published: 2008-08-18
Products:
    SLES Delivered by rPath

Updated Versions:
    php5-sysvshm=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-gettext=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-posix=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-wddx=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-ldap=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-sysvsem=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-ftp=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-gmp=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-fastcgi=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-sysvmsg=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-calendar=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-soap=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-ctype=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-ncurses=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-shmop=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-sockets=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-exif=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-mbstring=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-dba=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-pear=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-bz2=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-iconv=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-openssl=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-bcmath=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-tokenizer=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-xmlrpc=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-xmlreader=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-zlib=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-sqlite=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-dom=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-dbase=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-pcntl=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-pdo=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1
    php5-odbc=sle.rpath.com@rpath:sles-10/5.2.5_9.6-1-1

Description:
This version upgrade php5 to 5.2.6 fixes several security
vulnerabilities.
* Fixed possible stack buffer overflow in the FastCGI SAPI
  identified by Andrei
Nigmatulin.
                          
* Fixed integer overflow in printf() identified by
  Maksymilian
Aciemowicz.
                                           
* Fixed security issue detailed in CVE-2008-0599 identified
  by Ryan
Permeh.
                                      
* Fixed a safe_mode bypass in cURL identified by
  Maksymilian
Arciemowicz.
                                             
* Properly address incomplete multibyte chars inside
  escapeshellcmd() identified by Stefan
Esser.
               
* and many more...


From announce-noreply@rpath.com Wed Aug 27 15:43:27 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m7RFhRp7016617
	for <sle-announce@lists.rpath.com>; Wed, 27 Aug 2008 15:43:27 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m7RFhQkQ027070
	for <sle-announce@lists.rpath.com>; Wed, 27 Aug 2008 11:43:26 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m7RFhQVO011232
	for <sle-announce@lists.rpath.com>; Wed, 27 Aug 2008 11:43:26 -0400
Date: Wed, 27 Aug 2008 11:43:26 -0400
Message-Id: <200808271543.m7RFhQVO011232@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Perl
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 27 Aug 2008 15:43:27 -0000

Published: 2008-08-27
Products:
    SLES Delivered by rPath

Updated Versions:
    perl=sle.rpath.com@rpath:sles-10/5.8.8_14.10-1-1

Description:
Specially crafted regular expressions could crash perl
(CVE-2008-1927).

Additionally problem in the CGI module was fixed that could
result in an endless loop if uploads were cancelled.


From announce-noreply@rpath.com Thu Sep  4 19:42:21 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m84JgL7l026573
	for <sle-announce@lists.rpath.com>; Thu, 4 Sep 2008 19:42:21 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m84JgKBk009274
	for <sle-announce@lists.rpath.com>; Thu, 4 Sep 2008 15:42:21 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m84JgKs8001001
	for <sle-announce@lists.rpath.com>; Thu, 4 Sep 2008 15:42:20 -0400
Date: Thu, 4 Sep 2008 15:42:20 -0400
Message-Id: <200809041942.m84JgKs8001001@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libxslt
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 04 Sep 2008 19:42:21 -0000

Published: 2008-09-04
Products:
    SLES Delivered by rPath

Updated Versions:
    libxslt=sle.rpath.com@rpath:sles-10/1.1.15_15.11-1-1

Description:
A heap overflow in the RC4 cryptographic routines in
libxslt was fixed which could be used by attackers to
potentially execute code. (CVE-2008-2935)


From announce-noreply@rpath.com Thu Sep  4 19:42:21 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m84JgLtQ026577
	for <sle-announce@lists.rpath.com>; Thu, 4 Sep 2008 19:42:21 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m84JgLMv009278
	for <sle-announce@lists.rpath.com>; Thu, 4 Sep 2008 15:42:21 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m84JgLWr001007
	for <sle-announce@lists.rpath.com>; Thu, 4 Sep 2008 15:42:21 -0400
Date: Thu, 4 Sep 2008 15:42:21 -0400
Message-Id: <200809041942.m84JgLWr001007@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for opensc
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 04 Sep 2008 19:42:22 -0000

Published: 2008-09-04
Products:
    SLES Delivered by rPath

Updated Versions:
    opensc=sle.rpath.com@rpath:sles-10/0.9.6_17.7-1-1

Description:
This update fix a security issues with opensc that occurs
during initializing blank smart cards with Siemens CardOS
M4. It allows to set the PIN of the smart card without
authorization.  (CVE-2008-2235)

NOTE: Already initialized cards are still vulnerable after
this update. Please use the command-line tool pkcs15-tool
with option --test-update and --update when necessary.


From announce-noreply@rpath.com Thu Sep  4 19:42:21 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m84JgL9O026575
	for <sle-announce@lists.rpath.com>; Thu, 4 Sep 2008 19:42:21 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m84JgLs6009277
	for <sle-announce@lists.rpath.com>; Thu, 4 Sep 2008 15:42:21 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m84JgK7L001004
	for <sle-announce@lists.rpath.com>; Thu, 4 Sep 2008 15:42:20 -0400
Date: Thu, 4 Sep 2008 15:42:20 -0400
Message-Id: <200809041942.m84JgK7L001004@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for wireless-tools
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 04 Sep 2008 19:42:22 -0000

Published: 2008-09-04
Products:
    SLES Delivered by rPath

Updated Versions:
    wireless-tools=sle.rpath.com@rpath:sles-10/28pre13_22.19-1-1

Description:
This update fixes connection issues with Intel 2100,2200
and 2915 wireless cards in large WPA-EAP environments.


From announce-noreply@rpath.com Thu Sep  4 19:42:22 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m84JgLjh026582
	for <sle-announce@lists.rpath.com>; Thu, 4 Sep 2008 19:42:21 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m84JgLEK009283
	for <sle-announce@lists.rpath.com>; Thu, 4 Sep 2008 15:42:21 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m84JgLZR001011
	for <sle-announce@lists.rpath.com>; Thu, 4 Sep 2008 15:42:21 -0400
Date: Thu, 4 Sep 2008 15:42:21 -0400
Message-Id: <200809041942.m84JgLZR001011@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for the GCC suite
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 04 Sep 2008 19:42:22 -0000

Published: 2008-09-04
Products:
    SLES Delivered by rPath

Updated Versions:
    gcc-c++=sle.rpath.com@rpath:sles-10/4.1.2_20070115_0.22-1-1
    gcc=sle.rpath.com@rpath:sles-10/4.1.2_20070115_0.22-1-1
    libgcc=sle.rpath.com@rpath:sles-10/4.1.2_20070115_0.22-1-1
    cpp=sle.rpath.com@rpath:sles-10/4.1.2_20070115_0.22-1-1
    libstdc++=sle.rpath.com@rpath:sles-10/4.1.2_20070115_0.22-1-1

Description:
This patch fixes two errors in code generated by the
compiler:
* structure copies sometimes used uninitialized registers,
  bug 354405
* On s390x some xor constructs were compiled into invalid
  instructions, bug 394409 Additionally this patch fixes a
  segfault in libgcc's _Unwind_Resume, bug 376357


From announce-noreply@rpath.com Mon Sep 29 23:37:37 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m8TNbae4010870
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 23:37:36 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m8TNbaai024580
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 19:37:36 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m8TNba1G025963
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 19:37:36 -0400
Date: Mon, 29 Sep 2008 19:37:36 -0400
Message-Id: <200809292337.m8TNba1G025963@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for PHP5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 29 Sep 2008 23:37:37 -0000

Published: 2008-09-29
Products:
    SLES Delivered by rPath

Updated Versions:
    php5-iconv=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-shmop=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-mbstring=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-dom=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-ncurses=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-ctype=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-pear=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-sockets=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-xmlrpc=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-mysql=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-calendar=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-sysvmsg=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-fastcgi=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-sqlite=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-tokenizer=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-exif=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-zlib=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-odbc=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-xmlreader=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-dba=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-pcntl=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-wddx=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-bz2=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-sysvsem=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-ldap=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-dbase=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-gettext=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-openssl=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-gmp=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-posix=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-soap=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-sysvshm=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-ftp=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-pdo=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1
    php5-bcmath=sle.rpath.com@rpath:sles-10/5.2.5_9.9-1-1

Description:
This update fixes some overflows in the gd extension and
the memnstr() function that could crash php or even cause a
buffer overflow (CVE-2008-3658, CVE-2008-3659 and
CVE-2008-3660)


From announce-noreply@rpath.com Mon Sep 29 23:37:37 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m8TNbb1R010873
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 23:37:37 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m8TNbaM4024581
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 19:37:36 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m8TNbaxk025966
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 19:37:36 -0400
Date: Mon, 29 Sep 2008 19:37:36 -0400
Message-Id: <200809292337.m8TNbaxk025966@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libxml2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 29 Sep 2008 23:37:37 -0000

Published: 2008-09-29
Products:
    SLES Delivered by rPath

Updated Versions:
    libxml2=sle.rpath.com@rpath:sles-10/2.6.23_15.11-1-1    libxml2-python=sle.rpath.com@rpath:sles-10/2.6.23_15.9-1-1

Description:
Specially crafted xml files could cause a crash or a heap
based buffer overlow in libxml2 (CVE-2008-3281,
CVE-2008-3529).


From announce-noreply@rpath.com Mon Sep 29 23:37:37 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m8TNbbLq010876
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 23:37:37 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m8TNbaLU024583
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 19:37:37 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m8TNba8F025972
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 19:37:36 -0400
Date: Mon, 29 Sep 2008 19:37:36 -0400
Message-Id: <200809292337.m8TNba8F025972@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for HAL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 29 Sep 2008 23:37:37 -0000

Published: 2008-09-29
Products:
    SLES Delivered by rPath

Updated Versions:
    hal=sle.rpath.com@rpath:sles-10/0.5.6_33.38-1-1

Description:
This patch changes HAL to ignore autofs mountpoints on
handling mounts to prevent long pause in mounting media if
there are a high number of autofs mountpoints in the system.


From announce-noreply@rpath.com Mon Sep 29 23:37:37 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m8TNbb6s010874
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 23:37:37 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m8TNbadd024582
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 19:37:36 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m8TNbasa025969
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 19:37:36 -0400
Date: Mon, 29 Sep 2008 19:37:36 -0400
Message-Id: <200809292337.m8TNbasa025969@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for GnuTLS
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 29 Sep 2008 23:37:38 -0000

Published: 2008-09-29
Products:
    SLES Delivered by rPath

Updated Versions:
    gnutls=sle.rpath.com@rpath:sles-10/1.2.10_13.11-1-1

Description:
Multiple issues have been fixed in gnutls. CVE-2008-1948
(GNUTLS-SA-2008-1-1), CVE-2008-1949 (GNUTLS-SA-2008-1-2)
and CVE-2008-1950 (GNUTLS-SA-2008-1-3) have been assigned
to this issue.


From announce-noreply@rpath.com Mon Sep 29 23:37:37 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m8TNbbTG010881
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 23:37:37 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m8TNbaG3024586
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 19:37:37 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m8TNbaP0025975
	for <sle-announce@lists.rpath.com>; Mon, 29 Sep 2008 19:37:36 -0400
Date: Mon, 29 Sep 2008 19:37:36 -0400
Message-Id: <200809292337.m8TNbaP0025975@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for opensc, opensc-devel
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 29 Sep 2008 23:37:38 -0000

Published: 2008-09-29
Products:
    SLES Delivered by rPath

Updated Versions:
    opensc=sle.rpath.com@rpath:sles-10/0.9.6_17.9-1-1

Description:
This update fixes a security issues with opensc that
occured when initializing blank smart cards with Siemens
CardOS M4. After the initialization anyone could set the
PIN of the smart card without authorization (CVE-2008-2235).

NOTE: Already initialized cards are still vulnerable after
this update. Please use the command-line tool pkcs15-tool
with option
--test-update and --update when necessary.

Please find more information at
http://www.opensc-project.org/security.html

This is the second attempt to fix this problem. The
previous update was unforunately incomplete.


From announce-noreply@rpath.com Fri Oct 10 15:25:58 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m9AFPwi9024173
	for <sle-announce@lists.rpath.com>; Fri, 10 Oct 2008 15:25:58 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m9AFPwQf016553
	for <sle-announce@lists.rpath.com>; Fri, 10 Oct 2008 11:25:58 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m9AFPwcC001429
	for <sle-announce@lists.rpath.com>; Fri, 10 Oct 2008 11:25:58 -0400
Date: Fri, 10 Oct 2008 11:25:58 -0400
Message-Id: <200810101525.m9AFPwcC001429@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for aaa_base
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 10 Oct 2008 15:25:58 -0000

Published: 2008-10-10
Products:
    SLES Delivered by rPath

Updated Versions:
    aaa_base=sle.rpath.com@rpath:sles-10/10_12.47-1-1

Description:
/sbin/get_kernel_version is not only used to identify
kernel images but also to identify versions of kernel dumps
(since the same heuristics works here). Kernel dumps on 32
bit platforms can have more than 4 GiB (due to PAE).
However, the program fails to open the file because it's
compiled without large file support.


From announce-noreply@rpath.com Fri Oct 10 15:25:58 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m9AFPwA6024174
	for <sle-announce@lists.rpath.com>; Fri, 10 Oct 2008 15:25:58 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m9AFPwe5016554
	for <sle-announce@lists.rpath.com>; Fri, 10 Oct 2008 11:25:58 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m9AFPwB2001432
	for <sle-announce@lists.rpath.com>; Fri, 10 Oct 2008 11:25:58 -0400
Date: Fri, 10 Oct 2008 11:25:58 -0400
Message-Id: <200810101525.m9AFPwB2001432@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenSSH
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 10 Oct 2008 15:25:59 -0000

Published: 2008-10-10
Products:
    SLES Delivered by rPath

Updated Versions:
    openssh=sle.rpath.com@rpath:sles-10/4.2p1_18.38.3-1-1

Description:
Due to a faulty signal handler repeated login attempts
could exhaust the maximum allowed connections and prevent
further logins (CVE-2008-4109).

A problem where utmp entries where not deleted when users
logged out was also fixed.


From announce-noreply@rpath.com Thu Oct 23 22:19:12 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m9NMJCvs010142
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 22:19:12 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m9NMJCf1025020
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 18:19:12 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m9NMJBnI011079
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 18:19:11 -0400
Date: Thu, 23 Oct 2008 18:19:11 -0400
Message-Id: <200810232219.m9NMJBnI011079@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for Samba
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 23 Oct 2008 22:19:12 -0000

Published: 2008-10-23
Products:
    SLES Delivered by rPath

Updated Versions:
    libsmbclient=sle.rpath.com@rpath:sles-10/3.0.28_0.8-1-1
    samba-pdb=sle.rpath.com@rpath:sles-10/3.0.28_0.8-1-1
    cifs-mount=sle.rpath.com@rpath:sles-10/3.0.28_0.8-1-1
    samba-client=sle.rpath.com@rpath:sles-10/3.0.28_0.8-1-1
    samba-vscan=sle.rpath.com@rpath:sles-10/3.0.28_0.8-1-1
    samba-krb-printing=sle.rpath.com@rpath:sles-10/3.0.28_0.8-1-1
    samba-python=sle.rpath.com@rpath:sles-10/3.0.28_0.8-1-1
    libmsrpc=sle.rpath.com@rpath:sles-10/3.0.28_0.8-1-1
    samba-winbind=sle.rpath.com@rpath:sles-10/3.0.28_0.8-1-1

Description:
- Fix winbindd crash in an unusual failure mode;
  (bnc#416598).
- Winbindd opens too many processes and connections.
  Backporting from 3.0.3X; (bnc#425811).
- Winbindd loops in child list while cleaning child PID.
  Backporting from 3.0.3X; (bnc#425416).
- Winbindd username resolution fails in trusted domains in
  DSfW; (bnc#391761).
- In DSfW environment rpcclient dumps core when ran with
  ncalrpc option; (bnc#424021).
- "Password last set" timestamp update from admin pw
  change; (bnc#420407).
- Winbindd dumps core when builtin doamin gets overwritten;
  (bnc#251112).
- Winbindd dumps core in race condition in async_request.
  Back porting the fix from 3.0.31; (bnc#416598).
- Winbindd must use idmap-ad backend; (bnc#390771).
- Allow %u parameters for print job username - use advanced
  sub; (bnc#374389).
- Don't overwrite wb-child log names on reload;
  (bnc#382027).
- Allow authentication and memory credential refresh after
  password change from gdm/xdm; [bnc#395578].
- Use machine account and machine password from our domain
  when contacting trusted domains; [bnc#404667].
- Build Samba with debug symbols to get working debuginfo
  packages.
- pam_winbind: Update cached creds during password change;
  [bnc#395578].
- pam_winbind: fix pam_sm_chauthtok for storing modified
  cached creds;  [bnc#395578].
- Don't reset "password last set time" when unlocking an
  autolocked account; [bnc#382111].
- Fix winbind sigterm handling and make init script send
  sighup to all child winbind processes; [bnc#382027].
- Fix bug with winbindd trusted domain child not keeping
  primary domain online status up to date; [bnc#373560].
- Make winbind children reopen logs on SIGHUP; [bnc#382027].
- Prevent winbindd from segfaulting due to corrupted cache
  tdb on flushing caches; [#340332].


From announce-noreply@rpath.com Thu Oct 23 22:19:12 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m9NMJCCM010145
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 22:19:12 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m9NMJC2Y025023
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 18:19:12 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m9NMJC0U011082
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 18:19:12 -0400
Date: Thu, 23 Oct 2008 18:19:12 -0400
Message-Id: <200810232219.m9NMJC0U011082@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for glibc
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 23 Oct 2008 22:19:13 -0000

Published: 2008-10-23
Products:
    SLES Delivered by rPath

Updated Versions:
    glibc=sle.rpath.com@rpath:sles-10/2.4_31.58-1-1
    timezone=sle.rpath.com@rpath:sles-10/2.4_31.58-1-1

Description:
This update includes corrected timezone information (up to
version 2008h). In addition, the following issues were
corrected: 411243: a segmentation fault in strerror_r, when
using setlocale() over different threads.  This was caused
by a race condition due to missing locking. 416838: Missing
error handling in the memory allocator functions leads to
various following errors, including segfaults or data
corruption, in very specific circumstances (e.g. when using
mlockall(), or when allocating too much memory). This is
also bug 422037. 428662: Fix stack pointer corruption
problem for socket() and mcount() on s390 374219: Fix
deadlock condition in the mtrace code 430006: Fix gdb
backtraces across *printf(), *scanf() calls


From announce-noreply@rpath.com Thu Oct 23 22:19:13 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m9NMJDh4010148
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 22:19:13 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m9NMJCne025030
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 18:19:12 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m9NMJC36011085
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 18:19:12 -0400
Date: Thu, 23 Oct 2008 18:19:12 -0400
Message-Id: <200810232219.m9NMJC36011085@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for mkinitrd
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 23 Oct 2008 22:19:13 -0000

Published: 2008-10-23
Products:
    SLES Delivered by rPath

Updated Versions:
    mkinitrd=sle.rpath.com@rpath:sles-10/1.2_106.81-1-1

Description:
Fixup some issues with NFS-root systems:
- Update static IP configuration
- Update DHCP network configuration
- Parse ip= parameter correctly And also fix booting from
  LVM devices


From announce-noreply@rpath.com Thu Oct 23 22:19:13 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m9NMJDN1010151
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 22:19:13 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m9NMJDn8025033
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 18:19:13 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m9NMJCIL011090
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 18:19:12 -0400
Date: Thu, 23 Oct 2008 18:19:12 -0400
Message-Id: <200810232219.m9NMJCIL011090@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for the OpenLDAP client
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 23 Oct 2008 22:19:13 -0000

Published: 2008-10-23
Products:
    SLES Delivered by rPath

Updated Versions:
    openldap2-client=sle.rpath.com@rpath:sles-10/2.3.32_0.30-1-1

Description:
The last security update for openldap2-client introduced a
problem in libldap that could cause LDAP clients to
prematurely truncate search results.


From announce-noreply@rpath.com Thu Oct 23 22:19:13 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id m9NMJDhX010154
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 22:19:13 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id m9NMJDnd025036
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 18:19:13 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id m9NMJDiA011094
	for <sle-announce@lists.rpath.com>; Thu, 23 Oct 2008 18:19:13 -0400
Date: Thu, 23 Oct 2008 18:19:13 -0400
Message-Id: <200810232219.m9NMJDiA011094@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for xntp
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 23 Oct 2008 22:19:14 -0000

Published: 2008-10-23
Products:
    SLES Delivered by rPath

Updated Versions:
    xntp=sle.rpath.com@rpath:sles-10/4.2.4p3_48.7-1-1

Description:
This fixes NTP service display in the Health Monitor in NRM


From announce-noreply@rpath.com Fri Nov  7 19:13:24 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id mA7JDOC1005574
	for <sle-announce@lists.rpath.com>; Fri, 7 Nov 2008 19:13:24 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id mA7JDOQP023737
	for <sle-announce@lists.rpath.com>; Fri, 7 Nov 2008 14:13:24 -0500
Received: from build02.eng.rpath.com (build02.eng.rpath.com [172.16.160.202])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id mA7JDOgv012571
	for <sle-announce@lists.rpath.com>; Fri, 7 Nov 2008 14:13:24 -0500
Date: Fri, 7 Nov 2008 14:13:24 -0500
Message-Id: <200811071913.mA7JDOgv012571@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Apache 2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 07 Nov 2008 19:13:24 -0000

Published: 2008-11-07
Products:
    SLES Delivered by rPath

Updated Versions:
    apache2=sle.rpath.com@rpath:sles-10/2.2.3_16.19-1-1
    apache2-worker=sle.rpath.com@rpath:sles-10/2.2.3_16.19-1-1
    apache2-prefork=sle.rpath.com@rpath:sles-10/2.2.3_16.19-1-1

Description:
Missing sanity checks of FTP URLs allowed cross site
scripting (XSS) attacks via the mod_prody_ftp module
(CVE-2008-2939).

Missing precautions allowed cross site request forgery
(CSRF) via the mod_proxy_balancer interface (CVE-2007-6420)


From announce-noreply@rpath.com Wed Nov 12 22:35:22 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id mACMZMMo021677
	for <sle-announce@lists.rpath.com>; Wed, 12 Nov 2008 22:35:22 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id mACMZMb5008350
	for <sle-announce@lists.rpath.com>; Wed, 12 Nov 2008 17:35:22 -0500
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id mACMZMN6020331
	for <sle-announce@lists.rpath.com>; Wed, 12 Nov 2008 17:35:22 -0500
Date: Wed, 12 Nov 2008 17:35:22 -0500
Message-Id: <200811122235.mACMZMN6020331@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for MySQL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 12 Nov 2008 22:35:22 -0000

Published: 2008-11-12
Products:
    SLES Delivered by rPath

Updated Versions:
    mysql-client=sle.rpath.com@rpath:sles-10/5.0.26_12.22-1-1
    mysql-Max=sle.rpath.com@rpath:sles-10/5.0.26_12.22-1-1
    mysql-shared=sle.rpath.com@rpath:sles-10/5.0.26_12.22-1-1
    mysql=sle.rpath.com@rpath:sles-10/5.0.26_12.22-1-1

Description:
Empty bit-strings in a query could crash the MySQL server
(CVE-2008-3963).

Due to another flaw users could access tables of other
users  (CVE-2008-4097, CVE-2008-4098).


From announce-noreply@rpath.com Tue Nov 18 16:38:48 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id mAIGcm5I015838
	for <sle-announce@lists.rpath.com>; Tue, 18 Nov 2008 16:38:48 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id mAIGclU9010808
	for <sle-announce@lists.rpath.com>; Tue, 18 Nov 2008 11:38:47 -0500
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id mAIGclp8031114
	for <sle-announce@lists.rpath.com>; Tue, 18 Nov 2008 11:38:47 -0500
Date: Tue, 18 Nov 2008 11:38:47 -0500
Message-Id: <200811181638.mAIGclp8031114@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libxml2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 18 Nov 2008 16:38:48 -0000

Published: 2008-11-18
Products:
    SLES Delivered by rPath

Updated Versions:
    libxml2=sle.rpath.com@rpath:sles-10/2.6.23_15.13-1-1

Description:
This update fixes an integer overflow in libxml2 that could
lead to memory corruption and arbitrary code execution.
(CVE-2008-4226) Thanks to: Drew Yao of Apple Product
Security


From announce-noreply@rpath.com Thu Nov 20 03:34:28 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id mAK3YSUD008512
	for <sle-announce@lists.rpath.com>; Thu, 20 Nov 2008 03:34:28 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id mAK3YSra017841
	for <sle-announce@lists.rpath.com>; Wed, 19 Nov 2008 22:34:28 -0500
Received: from localhost.localdomain (enki.rdu.rpath.com [172.16.58.81])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id mAK3YSPD032441;
	Wed, 19 Nov 2008 22:34:28 -0500
Date: Wed, 19 Nov 2008 22:34:28 -0500
Message-Id: <200811200334.mAK3YSPD032441@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for Samba
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 20 Nov 2008 03:34:28 -0000

Published: 2008-11-19
Products:
    SLES Delivered by rPath

Updated Versions:
    samba-python=sle.rpath.com@rpath:sles-10/3.0.32_0.4-1-2
    cifs-mount=sle.rpath.com@rpath:sles-10/3.0.32_0.4-1-2
    libsmbclient=sle.rpath.com@rpath:sles-10/3.0.32_0.4-1-2
    samba-client=sle.rpath.com@rpath:sles-10/3.0.32_0.4-1-2
    samba-vscan=sle.rpath.com@rpath:sles-10/3.0.32_0.4-1-2
    samba-krb-printing=sle.rpath.com@rpath:sles-10/3.0.32_0.4-1-2
    samba-winbind=sle.rpath.com@rpath:sles-10/3.0.32_0.4-1-2
    libmsrpc=sle.rpath.com@rpath:sles-10/3.0.32_0.4-1-2

Description:
This update to 3.0.32 is a collective bugfix update to the
latest maintenance version 3.0.x of samba.org.

This update addresses the following issues:

- Winbindd dumps core when builtin doamin gets overwritten;
  (bnc#251112).
- "Password last set" timestamp update from admin pw
  change; (bnc#420407).
- In DSfW environment rpcclient dumps core when ran with
  ncalrpc option; (bnc#424021).
- Winbindd username resolution fails in trusted domains in
  DSfW; (bnc#391761).
- Winbindd loops in child list while cleaning child PID;
  (bnc#425416).
- Winbindd opens too many processes and connections;
  (bnc#425811).
- Fix winbindd crash in an unusual failure mode;
  (bnc#416598).
- Restart smbfs even with the traditional network setup;
  (bnc#425058);
- Winbindd crash due to double free in request time out
  handler; (bnc#432878).
- Winbindd fails to convert SID's to names in DSFW ADC
  server; (bnc#432652).
- Support for domain, DC and sysvol referrals for Windows
  Vista; (bnc#418638).
- Unable to edit GPO policies in Vista client; (bnc#439815).
- Fix the broken wbinfo -m feature for DSfW; (bnc#443104).

The following documents describe the changes  between the
maintenance releases 3.0.28 and 3.0.32 in detail:

http://www.samba.org/samba/history/samba-3.0.28a.html
http://www.samba.org/samba/history/samba-3.0.29.html
http://www.samba.org/samba/history/samba-3.0.30.html
http://www.samba.org/samba/history/samba-3.0.31.html
http://www.samba.org/samba/history/samba-3.0.32.html


From announce-noreply@rpath.com Fri Nov 21 19:16:33 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id mALJGXfB032761
	for <sle-announce@lists.rpath.com>; Fri, 21 Nov 2008 19:16:33 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id mALJGXC9017277
	for <sle-announce@lists.rpath.com>; Fri, 21 Nov 2008 14:16:33 -0500
Received: from build04.eng.rpath.com (build04.eng.rpath.com [172.16.160.204])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id mALJGXYP006841;
	Fri, 21 Nov 2008 14:16:33 -0500
Date: Fri, 21 Nov 2008 14:16:33 -0500
Message-Id: <200811211916.mALJGXYP006841@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for perl-Bootloader
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 21 Nov 2008 19:16:34 -0000

Published: 2008-11-21
Products:
    SLES Delivered by rPath

Updated Versions:
    perl-Bootloader=sle.rpath.com@rpath:sles-10/0.4.19.13_0.3-1-1

Description:
- Fix fallback for convert unix device to grub device. This
  can avoid problems on system with activated multipath
  (bnc#381386).
- Avoid collecting any hardware information if user want
  skip updating bootloader after kernel upgrade. This
  decrease time needed for kernel upgrade on system with
  thousands of LUNs and skipped bootloader update
  (bnc#425501)


From announce-noreply@rpath.com Wed Dec  3 11:28:04 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id mB3BS4mt023641
	for <sle-announce@lists.rpath.com>; Wed, 3 Dec 2008 11:28:04 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id mB3BS4OI025909
	for <sle-announce@lists.rpath.com>; Wed, 3 Dec 2008 06:28:04 -0500
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id mB3BS3N1023202;
	Wed, 3 Dec 2008 06:28:03 -0500
Date: Wed, 3 Dec 2008 06:28:03 -0500
Message-Id: <200812031128.mB3BS3N1023202@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Samba
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 03 Dec 2008 11:28:04 -0000

Published: 2008-12-03
Products:
    SLES Delivered by rPath

Updated Versions:
    libsmbclient=sle.rpath.com@rpath:sles-10/3.0.32_0.6-1-1
    cifs-mount=sle.rpath.com@rpath:sles-10/3.0.32_0.6-1-1
    libmsrpc=sle.rpath.com@rpath:sles-10/3.0.32_0.6-1-1
    samba-vscan=sle.rpath.com@rpath:sles-10/3.0.32_0.6-1-1
    samba-winbind=sle.rpath.com@rpath:sles-10/3.0.32_0.6-1-1
    samba-client=sle.rpath.com@rpath:sles-10/3.0.32_0.6-1-1
    samba-krb-printing=sle.rpath.com@rpath:sles-10/3.0.32_0.6-1-1
    samba-python=sle.rpath.com@rpath:sles-10/3.0.32_0.6-1-1

Description:
Malicious clients could potentially retrieve arbitrary
memory content from a samba server (CVE-2008-4314).


From announce-noreply@rpath.com Wed Dec  3 19:17:12 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id mB3JHCUF031102
	for <sle-announce@lists.rpath.com>; Wed, 3 Dec 2008 19:17:12 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id mB3JHCaV015474
	for <sle-announce@lists.rpath.com>; Wed, 3 Dec 2008 14:17:12 -0500
Received: from build01.eng.rpath.com (build01.eng.rpath.com [172.16.160.201])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id mB3JHCCG021262;
	Wed, 3 Dec 2008 14:17:12 -0500
Date: Wed, 3 Dec 2008 14:17:12 -0500
Message-Id: <200812031917.mB3JHCCG021262@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for dbus
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 03 Dec 2008 19:17:12 -0000

Published: 2008-12-03
Products:
    SLES Delivered by rPath

Updated Versions:
    dbus-1-glib=sle.rpath.com@rpath:sles-10/0.60_33.20-1-1
    dbus-1=sle.rpath.com@rpath:sles-10/0.60_33.20-1-1

Description:
This update fixes a denial of service bug in dbus.
(CVE-2008-3834)


From announce-noreply@rpath.com Fri Dec  5 11:17:52 2008
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id mB5BHqU9000772
	for <sle-announce@lists.rpath.com>; Fri, 5 Dec 2008 11:17:52 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id mB5BHqrm028198
	for <sle-announce@lists.rpath.com>; Fri, 5 Dec 2008 06:17:52 -0500
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id mB5BHqWQ000497;
	Fri, 5 Dec 2008 06:17:52 -0500
Date: Fri, 5 Dec 2008 06:17:52 -0500
Message-Id: <200812051117.mB5BHqWQ000497@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for util-linux
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 05 Dec 2008 11:17:52 -0000

Published: 2008-12-05
Products:
    SLES Delivered by rPath

Updated Versions:
    util-linux=sle.rpath.com@rpath:sles-10/2.12r_35.30-1-1

Description:
In environments with highly concurrent mount/umount
processes a corruption of /etc/mtab can occur, because
syscall and updating of user space data are two different
steps. This could result in a failure of unmounting of a
filesystem when unmounting by its device name. This patch
enhances the mount/umount programs to do the relevant
operations in one atomic step to avoid these possible
corruption.


From announce-noreply@rpath.com Mon Jan 12 21:48:31 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id n0CLmVhR001329
	for <sle-announce@lists.rpath.com>; Mon, 12 Jan 2009 21:48:31 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n0CLmVV2002151
	for <sle-announce@lists.rpath.com>; Mon, 12 Jan 2009 16:48:31 -0500
Received: from localhost.localdomain (enki.rdu.rpath.com [172.16.58.81])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n0CLmUQV030755;
	Mon, 12 Jan 2009 16:48:30 -0500
Date: Mon, 12 Jan 2009 16:48:30 -0500
Message-Id: <200901122148.n0CLmUQV030755@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for audit
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 12 Jan 2009 21:48:31 -0000

Published: 2009-01-12
Products:
    SLES Delivered by rPath

Updated Versions:
    audit=sle.rpath.com@rpath:sles-10/1.2.9_6.19-1-2

Description:
ausearch does not flush standard output when connected to a
pipe causing data to accumulate in the pipe buffer.  If
ausearch's input is also a pipe where the sender does not
signal end-of-file output may never be flushed.


From announce-noreply@rpath.com Mon Jan 12 21:48:31 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id n0CLmVAn001330
	for <sle-announce@lists.rpath.com>; Mon, 12 Jan 2009 21:48:31 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n0CLmVie002152
	for <sle-announce@lists.rpath.com>; Mon, 12 Jan 2009 16:48:31 -0500
Received: from localhost.localdomain (enki.rdu.rpath.com [172.16.58.81])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n0CLmVAB030757;
	Mon, 12 Jan 2009 16:48:31 -0500
Date: Mon, 12 Jan 2009 16:48:31 -0500
Message-Id: <200901122148.n0CLmVAB030757@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Python
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 12 Jan 2009 21:48:32 -0000

Published: 2009-01-12
Products:
    SLES Delivered by rPath

Updated Versions:
    python-xml=sle.rpath.com@rpath:sles-10/2.4.2_18.25-1-2
    python=sle.rpath.com@rpath:sles-10/2.4.2_18.25-1-2

Description:
Integer Overflows in the python imageop module and in the
expandtabs method potentially allowed attackers to execute
arbitrary code (CVE-2008-4864, CVE-2008-5031)


From announce-noreply@rpath.com Mon Jan 12 21:48:31 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id n0CLmVcB001334
	for <sle-announce@lists.rpath.com>; Mon, 12 Jan 2009 21:48:31 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n0CLmVWo002153
	for <sle-announce@lists.rpath.com>; Mon, 12 Jan 2009 16:48:31 -0500
Received: from localhost.localdomain (enki.rdu.rpath.com [172.16.58.81])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n0CLmVxh030759;
	Mon, 12 Jan 2009 16:48:31 -0500
Date: Mon, 12 Jan 2009 16:48:31 -0500
Message-Id: <200901122148.n0CLmVxh030759@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libxml2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 12 Jan 2009 21:48:32 -0000

Published: 2009-01-12
Products:
    SLES Delivered by rPath

Updated Versions:
    libxml2=sle.rpath.com@rpath:sles-10/2.6.23_15.15-1-2

Description:
libxml2 could run into an endless loop when processing
specially crafted XML files (CVE-2008-4225)


From announce-noreply@rpath.com Mon Jan 12 21:48:32 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id n0CLmVPj001335
	for <sle-announce@lists.rpath.com>; Mon, 12 Jan 2009 21:48:31 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n0CLmV7b002158
	for <sle-announce@lists.rpath.com>; Mon, 12 Jan 2009 16:48:31 -0500
Received: from localhost.localdomain (enki.rdu.rpath.com [172.16.58.81])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n0CLmVwd030761;
	Mon, 12 Jan 2009 16:48:31 -0500
Date: Mon, 12 Jan 2009 16:48:31 -0500
Message-Id: <200901122148.n0CLmVwd030761@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for nfs-utils
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 12 Jan 2009 21:48:32 -0000

Published: 2009-01-12
Products:
    SLES Delivered by rPath

Updated Versions:
    nfs-utils=sle.rpath.com@rpath:sles-10/1.0.7_36.31-1-2

Description:
This update of nfs-utils fixes the handling of the tcp
wrapper ACLs. (CVE-2008-4552)


From announce-noreply@rpath.com Thu Jan 15 17:23:48 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id n0FHNmpm031826
	for <sle-announce@lists.rpath.com>; Thu, 15 Jan 2009 17:23:48 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n0FHNmGa003196
	for <sle-announce@lists.rpath.com>; Thu, 15 Jan 2009 12:23:48 -0500
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n0FHNmT8004611;
	Thu, 15 Jan 2009 12:23:48 -0500
Date: Thu, 15 Jan 2009 12:23:48 -0500
Message-Id: <200901151723.n0FHNmT8004611@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for tcsh
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 15 Jan 2009 17:23:48 -0000

Published: 2009-01-15
Products:
    SLES Delivered by rPath

Updated Versions:
    tcsh=sle.rpath.com@rpath:sles-10/6.14.00_23.13-1-1

Description:
When executing a program inlcuding the full path in tcsh
which has a stalled NFS mount in the same or above
directory tree, the tcsh hangs.


From announce-noreply@rpath.com Sat Jan 17 02:18:58 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by localhost.localdomain (8.13.7/8.13.7) with ESMTP id n0H2Iwcf031487
	for <sle-announce@lists.rpath.com>; Sat, 17 Jan 2009 02:18:58 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n0H2Iw2j002715
	for <sle-announce@lists.rpath.com>; Fri, 16 Jan 2009 21:18:58 -0500
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n0H2IwI8029798;
	Fri, 16 Jan 2009 21:18:58 -0500
Date: Fri, 16 Jan 2009 21:18:58 -0500
Message-Id: <200901170218.n0H2IwI8029798@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for LVM2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Sat, 17 Jan 2009 02:18:58 -0000

Published: 2009-01-16
Products:
    SLES Delivered by rPath

Updated Versions:
    lvm2=sle.rpath.com@rpath:sles-10/2.02.17_7.21-1-1

Description:
LVM2 needs to wait for udev after VGs have been activated.
Also fix the failure of lvm-vg-to-udev-rules.sh when VGs
have more than one LVs.


From announce-noreply@rpath.com Fri Jan 23 12:26:42 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n0NHQgPD007031
	for <sle-announce@lists.rpath.com>; Fri, 23 Jan 2009 17:26:42 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n0NHQgxE003767
	for <sle-announce@lists.rpath.com>; Fri, 23 Jan 2009 12:26:42 -0500
Received: from build02.eng.rpath.com (build02.eng.rpath.com [172.16.160.202])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n0NHQgXo030382;
	Fri, 23 Jan 2009 12:26:42 -0500
Date: Fri, 23 Jan 2009 12:26:42 -0500
Message-Id: <200901231726.n0NHQgXo030382@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for net-snmp
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 23 Jan 2009 17:26:43 -0000

Published: 2009-01-23
Products:
    SLES Delivered by rPath

Updated Versions:
    net-snmp=sle.rpath.com@rpath:sles-10/5.3.0.1_25.28-1-1

Description:
Remote attackers could crash net-snmp via GETBULK-Request
(CVE-2008-4309).

In addition the following non-security issues have been
fixed:

- typo in error message (bnc#439857)
- fix duplicate registration warnings on startup
  (bnc#326957)
- container insert errors reproducable with shared ip
  setups (bnc#396773)
- typo in the snmpd init script to really load all agents
  (bnc#415127)
- logrotate config to restart the snmptrapd aswell
  (bnc#378069)


From announce-noreply@rpath.com Fri Jan 23 12:26:43 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n0NHQh1D007034
	for <sle-announce@lists.rpath.com>; Fri, 23 Jan 2009 17:26:43 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n0NHQgIR003770
	for <sle-announce@lists.rpath.com>; Fri, 23 Jan 2009 12:26:42 -0500
Received: from build02.eng.rpath.com (build02.eng.rpath.com [172.16.160.202])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n0NHQgUv030386;
	Fri, 23 Jan 2009 12:26:42 -0500
Date: Fri, 23 Jan 2009 12:26:42 -0500
Message-Id: <200901231726.n0NHQgUv030386@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for openssl
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 23 Jan 2009 17:26:43 -0000

Published: 2009-01-23
Products:
    SLES Delivered by rPath

Updated Versions:
    openssl=sle.rpath.com@rpath:sles-10/0.9.8a_18.27-1-1

Description:
This update improves the verification of return values.
Prior to this udpate it was possible to bypass the
certification chain checks of openssl. (CVE-2008-5077)


From announce-noreply@rpath.com Tue Jan 27 04:23:00 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n0R9N0oP026364
	for <sle-announce@lists.rpath.com>; Tue, 27 Jan 2009 09:23:00 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n0R9N0fY032010
	for <sle-announce@lists.rpath.com>; Tue, 27 Jan 2009 04:23:00 -0500
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n0R9MxfQ006673;
	Tue, 27 Jan 2009 04:22:59 -0500
Date: Tue, 27 Jan 2009 04:22:59 -0500
Message-Id: <200901270922.n0R9MxfQ006673@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for compat-openssl097g
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 27 Jan 2009 09:23:01 -0000

Published: 2009-01-27
Products:
    SLES Delivered by rPath

Updated Versions:
    compat-openssl097g=sle.rpath.com@rpath:sles-10/0.9.7g_13.13-1-1

Description:
This update improves the verification of return values.
Prior to this update it was possible to bypass the
certification chain checks of openssl. (CVE-2008-5077)


From announce-noreply@rpath.com Wed Jan 28 10:24:23 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n0SFONPx008048
	for <sle-announce@lists.rpath.com>; Wed, 28 Jan 2009 15:24:23 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n0SFONtf027939
	for <sle-announce@lists.rpath.com>; Wed, 28 Jan 2009 10:24:23 -0500
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n0SFONMD009061;
	Wed, 28 Jan 2009 10:24:23 -0500
Date: Wed, 28 Jan 2009 10:24:23 -0500
Message-Id: <200901281524.n0SFONMD009061@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libpng
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 28 Jan 2009 15:24:24 -0000

Published: 2009-01-28
Products:
    SLES Delivered by rPath

Updated Versions:
    libpng=sle.rpath.com@rpath:sles-10/1.2.8_19.18-1-1

Description:
This update of libpng fixes the function
png_check_keyword() that allowed setting arbitrary bytes in
the process memory to 0. (CVE-2008-5907)


From announce-noreply@rpath.com Wed Feb  4 09:32:01 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n14EW1Dv009092
	for <sle-announce@lists.rpath.com>; Wed, 4 Feb 2009 14:32:01 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n14EW1ek019597
	for <sle-announce@lists.rpath.com>; Wed, 4 Feb 2009 09:32:01 -0500
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n14EW04m006026;
	Wed, 4 Feb 2009 09:32:01 -0500
Date: Wed, 4 Feb 2009 09:32:00 -0500
Message-Id: <200902041432.n14EW04m006026@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for Samba
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 04 Feb 2009 14:32:01 -0000

Published: 2009-02-04
Products:
    SLES Delivered by rPath

Updated Versions:
    libmsrpc=sle.rpath.com@rpath:sles-10/3.0.32_0.8-1-1
    libsmbclient=sle.rpath.com@rpath:sles-10/3.0.32_0.8-1-1
    cifs-mount=sle.rpath.com@rpath:sles-10/3.0.32_0.8-1-1
    samba-python=sle.rpath.com@rpath:sles-10/3.0.32_0.8-1-1
    samba-krb-printing=sle.rpath.com@rpath:sles-10/3.0.32_0.8-1-1
    samba-vscan=sle.rpath.com@rpath:sles-10/3.0.32_0.8-1-1
    samba-client=sle.rpath.com@rpath:sles-10/3.0.32_0.8-1-1
    samba-winbind=sle.rpath.com@rpath:sles-10/3.0.32_0.8-1-1

Description:
- Fix nmbstatus dipslay when workgroup parameter is given;
  (bnc#459785).
- Fix Mounting failure when there is white spaces in
  service; (bnc#460793).
- Smbd fails to authenticate user for home directory
  access; (bnc#431826).
- Smbd fails to access share across trusted domains;
  (bnc#448413).


From announce-noreply@rpath.com Wed Feb  4 14:20:07 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n14JK73T009966
	for <sle-announce@lists.rpath.com>; Wed, 4 Feb 2009 19:20:07 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n14JK7c6004333
	for <sle-announce@lists.rpath.com>; Wed, 4 Feb 2009 14:20:07 -0500
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n14JK6bD022688;
	Wed, 4 Feb 2009 14:20:06 -0500
Date: Wed, 4 Feb 2009 14:20:06 -0500
Message-Id: <200902041920.n14JK6bD022688@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for Kerberos
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 04 Feb 2009 19:20:07 -0000

Published: 2009-02-04
Products:
    SLES Delivered by rPath

Updated Versions:
    krb5=sle.rpath.com@rpath:sles-10/1.4.3_19.35-1-1

Description:
This update add a check to krb5_get_cred_from_kdc which
test the initialization status of a principal variable
before it is used.


From announce-noreply@rpath.com Thu Feb  5 14:42:04 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n15Jg4kn015723
	for <sle-announce@lists.rpath.com>; Thu, 5 Feb 2009 19:42:04 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n15Jg4CM020507
	for <sle-announce@lists.rpath.com>; Thu, 5 Feb 2009 14:42:04 -0500
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n15Jg3WV012422;
	Thu, 5 Feb 2009 14:42:03 -0500
Date: Thu, 5 Feb 2009 14:42:03 -0500
Message-Id: <200902051942.n15Jg3WV012422@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for PHP5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 05 Feb 2009 19:42:05 -0000

Published: 2009-02-05
Products:
    SLES Delivered by rPath

Updated Versions:
    php5-calendar=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-exif=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-mbstring=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-zlib=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-gmp=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-tokenizer=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-sysvmsg=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-fastcgi=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-mysql=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-sysvshm=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-pear=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-xmlreader=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-sysvsem=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-ldap=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-pdo=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-sqlite=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-sockets=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-wddx=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-ctype=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-ncurses=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-soap=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-bz2=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-pcntl=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-gettext=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-shmop=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-dom=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-odbc=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-dba=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-xmlrpc=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-bcmath=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-ftp=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-iconv=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-posix=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-openssl=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1
    php5-dbase=sle.rpath.com@rpath:sles-10/5.2.5_9.12-1-1

Description:
This update of php5 fixes a directory traversal bug in
ZipArchive (CVE-2008-5658) and a buffer overflow in the
mstring extension (CVE-2008-5557).


From announce-noreply@rpath.com Fri Feb  6 16:20:58 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n16LKwIk021449
	for <sle-announce@lists.rpath.com>; Fri, 6 Feb 2009 21:20:58 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n16LKvJh012436
	for <sle-announce@lists.rpath.com>; Fri, 6 Feb 2009 16:20:57 -0500
Received: from build04.eng.rpath.com (build04.eng.rpath.com [172.16.160.204])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n16LKvMk013918;
	Fri, 6 Feb 2009 16:20:57 -0500
Date: Fri, 6 Feb 2009 16:20:57 -0500
Message-Id: <200902062120.n16LKvMk013918@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for texinfo
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 06 Feb 2009 21:20:58 -0000

Published: 2009-02-06
Products:
    SLES Delivered by rPath

Updated Versions:
    texinfo=sle.rpath.com@rpath:sles-10/4.8_22.5-1-1
    info=sle.rpath.com@rpath:sles-10/4.8_22.5-1-1

Description:
Specially crafted texinfo files could crash texinfo
utilities like texi2dvi and potentially execute code.
(CVE-2006-4810)


From announce-noreply@rpath.com Thu Feb 12 14:18:43 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n1CJIhc0016592
	for <sle-announce@lists.rpath.com>; Thu, 12 Feb 2009 19:18:43 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n1CJIhYb007042
	for <sle-announce@lists.rpath.com>; Thu, 12 Feb 2009 14:18:43 -0500
Received: from build02.eng.rpath.com (build02.eng.rpath.com [172.16.160.202])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n1CJIhnx011675;
	Thu, 12 Feb 2009 14:18:43 -0500
Date: Thu, 12 Feb 2009 14:18:43 -0500
Message-Id: <200902121918.n1CJIhnx011675@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenSLP
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 12 Feb 2009 19:18:44 -0000

Published: 2009-02-12
Products:
    SLES Delivered by rPath

Updated Versions:
    openslp=sle.rpath.com@rpath:sles-10/1.2.0_22.22-1-1

Description:
OpenSLP prior this update does not correctly check the
return values of OpenSSL functions.


From announce-noreply@rpath.com Fri Feb 13 14:21:32 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n1DJLWZb021910
	for <sle-announce@lists.rpath.com>; Fri, 13 Feb 2009 19:21:32 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n1DJLWoR004510
	for <sle-announce@lists.rpath.com>; Fri, 13 Feb 2009 14:21:32 -0500
Received: from build02.eng.rpath.com (build02.eng.rpath.com [172.16.160.202])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n1DJLWBH004522;
	Fri, 13 Feb 2009 14:21:32 -0500
Date: Fri, 13 Feb 2009 14:21:32 -0500
Message-Id: <200902131921.n1DJLWBH004522@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libxml2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 13 Feb 2009 19:21:33 -0000

Published: 2009-02-13
Products:
    SLES Delivered by rPath

Updated Versions:
    libxml2=sle.rpath.com@rpath:sles-10/2.6.23_15.17-1-1

Description:
A previous security fix for libxml2 caused problems when
processing large xml files. The patch has been reworked so
processing large files works again.


From announce-noreply@rpath.com Mon Feb 16 14:19:41 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n1GJJeuO002997
	for <sle-announce@lists.rpath.com>; Mon, 16 Feb 2009 19:19:40 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n1GJJeWB012374
	for <sle-announce@lists.rpath.com>; Mon, 16 Feb 2009 14:19:40 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n1GJJes2014048;
	Mon, 16 Feb 2009 14:19:40 -0500
Date: Mon, 16 Feb 2009 14:19:40 -0500
Message-Id: <200902161919.n1GJJes2014048@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for nfsidmap
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 16 Feb 2009 19:19:41 -0000

Published: 2009-02-16
Products:
    SLES Delivered by rPath

Updated Versions:
    nfsidmap=sle.rpath.com@rpath:sles-10/0.12_16.20-1-1

Description:
The NFSv4 identity mapper helper daemon hat a problem where
when using very large number of groups for users they
showed as having 'nobody' group membership.


From announce-noreply@rpath.com Fri Feb 20 10:22:19 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n1KFMJud020584
	for <sle-announce@lists.rpath.com>; Fri, 20 Feb 2009 15:22:19 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n1KFMIjY012093
	for <sle-announce@lists.rpath.com>; Fri, 20 Feb 2009 10:22:19 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n1KFMI4L015750;
	Fri, 20 Feb 2009 10:22:18 -0500
Date: Fri, 20 Feb 2009 10:22:18 -0500
Message-Id: <200902201522.n1KFMI4L015750@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for util-linux
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 20 Feb 2009 15:22:19 -0000

Published: 2009-02-20
Products:
    SLES Delivered by rPath

Updated Versions:
    util-linux=sle.rpath.com@rpath:sles-10/2.12r_35.32-1-1

Description:
This patch fixes the following problems:
- Fix problem in sfdisk with partitions greater than 1TB
- Let mount use the canonicalized device name in the system
  call to avoid problems when /proc/mounts symlinked to
  /etc/mtab
- Fix mount locking problem resulting in a deadlock when
  used without -t option and external mount helpers


From announce-noreply@rpath.com Tue Feb 24 09:19:32 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n1OEJWJD006191
	for <sle-announce@lists.rpath.com>; Tue, 24 Feb 2009 14:19:32 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n1OEJWPs017457
	for <sle-announce@lists.rpath.com>; Tue, 24 Feb 2009 09:19:32 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n1OEJWuj016833;
	Tue, 24 Feb 2009 09:19:32 -0500
Date: Tue, 24 Feb 2009 09:19:32 -0500
Message-Id: <200902241419.n1OEJWuj016833@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libpng
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 24 Feb 2009 14:19:32 -0000

Published: 2009-02-24
Products:
    SLES Delivered by rPath

Updated Versions:
    libpng=sle.rpath.com@rpath:sles-10/1.2.8_19.20-1-1

Description:
A allocation mistake in libpng's  pngread.c has been fixed.
CVE-2009-0040 has been assigned to this issue.


From announce-noreply@rpath.com Tue Feb 24 15:18:28 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n1OKISRC007304
	for <sle-announce@lists.rpath.com>; Tue, 24 Feb 2009 20:18:28 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n1OKISWP005106
	for <sle-announce@lists.rpath.com>; Tue, 24 Feb 2009 15:18:28 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n1OKIS5q006243;
	Tue, 24 Feb 2009 15:18:28 -0500
Date: Tue, 24 Feb 2009 15:18:28 -0500
Message-Id: <200902242018.n1OKIS5q006243@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for pam_krb5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 24 Feb 2009 20:18:28 -0000

Published: 2009-02-24
Products:
    SLES Delivered by rPath

Updated Versions:
    pam_krb5=sle.rpath.com@rpath:sles-10/2.2.3_18.9-1-1

Description:
This update fixes the following two issues: 
- pam_sm_chauthtock should return PAM_IGNORE if
  ignore_unknown_principal option is set 
- pam_sm_setcred should assume PAM_ESTABLISH_CRED if no
  flag are passed


From announce-noreply@rpath.com Thu Feb 26 14:21:08 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n1QJL8PM016707
	for <sle-announce@lists.rpath.com>; Thu, 26 Feb 2009 19:21:08 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n1QJL8xd003926
	for <sle-announce@lists.rpath.com>; Thu, 26 Feb 2009 14:21:08 -0500
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n1QJL8Kr015507;
	Thu, 26 Feb 2009 14:21:08 -0500
Date: Thu, 26 Feb 2009 14:21:08 -0500
Message-Id: <200902261921.n1QJL8Kr015507@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libpng
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 26 Feb 2009 19:21:08 -0000

Published: 2009-02-26
Products:
    SLES Delivered by rPath

Updated Versions:
    libpng=sle.rpath.com@rpath:sles-10/1.2.8_19.22-1-1

Description:
A allocation mistake in libpng's pngread.c has been fixed
(CVE-2009-0040). The previous update was using an
incomplete patch so it needed to be reissued.


From announce-noreply@rpath.com Thu Feb 26 15:20:25 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n1QKKPw7016889
	for <sle-announce@lists.rpath.com>; Thu, 26 Feb 2009 20:20:25 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n1QKKPaF009448
	for <sle-announce@lists.rpath.com>; Thu, 26 Feb 2009 15:20:25 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n1QKKOC6019378;
	Thu, 26 Feb 2009 15:20:25 -0500
Date: Thu, 26 Feb 2009 15:20:24 -0500
Message-Id: <200902262020.n1QKKOC6019378@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for aaa_base and nfs-utils
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 26 Feb 2009 20:20:25 -0000

Published: 2009-02-26
Products:
    SLES Delivered by rPath

Updated Versions:
    nfs-utils=sle.rpath.com@rpath:sles-10/1.0.7_36.33-1-1    aaa_base=sle.rpath.com@rpath:sles-10/10_12.50-1-1

Description:
There was a problem with having /usr on it's own partition
and using lvm at the same time which has been fixed now.

mountd was adopted to improve efficiency in the situation
where filesystems are exported to lots of different
netgroups is and some hosts are in many of those netgroups,

A memory leak in handling NFSv4 exports was fixed.

usr/sbin/Check: skip dir if "." or ".." is in MANPATH
(bnc#426646)

boot.crypto: support "noauto" option for LUKS encrypted
volumes  (bnc#462380) set sysctl values for sunrpc in nfs
start script (bnc#431306)

add quoting to xdg-environment.*sh (bnc#463175) Use
/bin/grep in profile.csh (bnc#429336)

update chkconfig manpage (bnc#411221)

use rc_active instead of chkconfig in boot.rootfsck
(bnc#466911)


From announce-noreply@rpath.com Mon Mar  2 13:20:40 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n22IKeYo003000
	for <sle-announce@lists.rpath.com>; Mon, 2 Mar 2009 18:20:40 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n22IKepW010277
	for <sle-announce@lists.rpath.com>; Mon, 2 Mar 2009 13:20:40 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n22IKdLF023532;
	Mon, 2 Mar 2009 13:20:39 -0500
Date: Mon, 2 Mar 2009 13:20:39 -0500
Message-Id: <200903021820.n22IKdLF023532@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for logrotate
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 02 Mar 2009 18:20:40 -0000

Published: 2009-03-02
Products:
    SLES Delivered by rPath

Updated Versions:
    logrotate=sle.rpath.com@rpath:sles-10/3.7.3_13.8-1-1

Description:
The logrotate  command does not support using a variable
"$1" in a config file for substituting the name of log file
being accessed.


From announce-noreply@rpath.com Tue Mar  3 06:19:07 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n23BJ7Cc006459
	for <sle-announce@lists.rpath.com>; Tue, 3 Mar 2009 11:19:07 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n23BJ6jl012443
	for <sle-announce@lists.rpath.com>; Tue, 3 Mar 2009 06:19:06 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n23BJ6Ix007473;
	Tue, 3 Mar 2009 06:19:06 -0500
Date: Tue, 3 Mar 2009 06:19:06 -0500
Message-Id: <200903031119.n23BJ6Ix007473@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for curl
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 03 Mar 2009 11:19:07 -0000

Published: 2009-03-03
Products:
    SLES Delivered by rPath

Updated Versions:
    curl=sle.rpath.com@rpath:sles-10/7.15.1_19.11-1-1

Description:
Arbitrary file access via HTTP-redirect has been fixed in
curl. CVE-2009-0037 has been assigned to this issue.


From announce-noreply@rpath.com Fri Mar  6 11:26:49 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n26GQn8R021615
	for <sle-announce@lists.rpath.com>; Fri, 6 Mar 2009 16:26:49 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n26GQnb3011767
	for <sle-announce@lists.rpath.com>; Fri, 6 Mar 2009 11:26:49 -0500
Received: from build03.eng.rpath.com (build03.eng.rpath.com [172.16.160.203])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n26GQmi5017357;
	Fri, 6 Mar 2009 11:26:48 -0500
Date: Fri, 6 Mar 2009 11:26:48 -0500
Message-Id: <200903061626.n26GQmi5017357@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Apache 2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 06 Mar 2009 16:26:49 -0000

Published: 2009-03-06
Products:
    SLES Delivered by rPath

Updated Versions:
    apache2-worker=sle.rpath.com@rpath:sles-10/2.2.3_16.21-1-1
    apache2=sle.rpath.com@rpath:sles-10/2.2.3_16.21-1-1
    apache2-prefork=sle.rpath.com@rpath:sles-10/2.2.3_16.21-1-1

Description:
A DoS condition in apache2's mod_proxy has been fixed.
CVE-2008-2364 has been assigned to this issue.


From announce-noreply@rpath.com Tue Mar 10 10:29:44 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n2AETiUU006665
	for <sle-announce@lists.rpath.com>; Tue, 10 Mar 2009 14:29:44 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n2AETiYB017406
	for <sle-announce@lists.rpath.com>; Tue, 10 Mar 2009 10:29:44 -0400
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n2AETiVP022188;
	Tue, 10 Mar 2009 10:29:44 -0400
Date: Tue, 10 Mar 2009 10:29:44 -0400
Message-Id: <200903101429.n2AETiVP022188@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for hal
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 10 Mar 2009 14:29:45 -0000

Published: 2009-03-10
Products:
    SLES Delivered by rPath

Updated Versions:
    hal=sle.rpath.com@rpath:sles-10/0.5.6_33.41-1-1

Description:
The dbus package used a too permissive configuration.
Therefore intended access control for some services was not
applied (CVE-2008-4311).

The new configuration denies access by default. Some dbus
services may break due to this setting and need an updated
configuration as well.

Additionally a bug in hal that allowed users to crash the
hal daemon has been fixed.


From announce-noreply@rpath.com Tue Mar 10 15:22:59 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n2AJMxqt007584
	for <sle-announce@lists.rpath.com>; Tue, 10 Mar 2009 19:22:59 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n2AJMxPS030153
	for <sle-announce@lists.rpath.com>; Tue, 10 Mar 2009 15:22:59 -0400
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n2AJMxPW005166;
	Tue, 10 Mar 2009 15:22:59 -0400
Date: Tue, 10 Mar 2009 15:22:59 -0400
Message-Id: <200903101922.n2AJMxPW005166@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for vim
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 10 Mar 2009 19:22:59 -0000

Published: 2009-03-10
Products:
    SLES Delivered by rPath

Updated Versions:
    vim=sle.rpath.com@rpath:sles-10/6.4.6_19.15-1-1

Description:
The VI Improved editor (vim) received bugfixes for some
code execution problems.

CVE-2008-2712: Arbitrary code execution in vim helper
plugins filetype.vim,  zipplugin, xpm.vim, gzip_vim, and
netrw were fix ed. CVE-2008-4101: Arbitrary code execution
when pressing K, ctrl-] or g] depending on the text under
the cursor.


From announce-noreply@rpath.com Tue Mar 17 12:26:36 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n2HGQaF0006460
	for <sle-announce@lists.rpath.com>; Tue, 17 Mar 2009 16:26:36 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n2HGQZAV017048
	for <sle-announce@lists.rpath.com>; Tue, 17 Mar 2009 12:26:36 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n2HGQZjx011390;
	Tue, 17 Mar 2009 12:26:35 -0400
Date: Tue, 17 Mar 2009 12:26:35 -0400
Message-Id: <200903171626.n2HGQZjx011390@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for dbus
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 17 Mar 2009 16:26:36 -0000

Published: 2009-03-17
Products:
    SLES Delivered by rPath

Updated Versions:
    dbus-1-glib=sle.rpath.com@rpath:sles-10/0.60_33.22-1-1
    dbus-1=sle.rpath.com@rpath:sles-10/0.60_33.22-1-1

Description:
The dbus package used a too permissive configuration.
Therefore intended access control for some services was not
applied (CVE-2008-4311).

The new configuration denies access by default. Some dbus
services may break due to this setting and need an updated
configuration as well.


From announce-noreply@rpath.com Thu Mar 26 13:20:05 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n2QHK5MO014263
	for <sle-announce@lists.rpath.com>; Thu, 26 Mar 2009 17:20:05 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n2QHK4MR009667
	for <sle-announce@lists.rpath.com>; Thu, 26 Mar 2009 13:20:04 -0400
Received: from build04.eng.rpath.com (build04.eng.rpath.com [172.16.160.204])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n2QHK3KJ014413;
	Thu, 26 Mar 2009 13:20:03 -0400
Date: Thu, 26 Mar 2009 13:20:03 -0400
Message-Id: <200903261720.n2QHK3KJ014413@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for xntp
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 26 Mar 2009 17:20:05 -0000

Published: 2009-03-26
Products:
    SLES Delivered by rPath

Updated Versions:
    xntp=sle.rpath.com@rpath:sles-10/4.2.4p3_48.10-1-1

Description:
ntp didn't properly check the return value of the openssl
function EVP_VerifyFinal (CVE-2009-0021).

Additionally a problem where ntpd refused to use keys from
/etc/ntp.keys has been fixed.


From announce-noreply@rpath.com Mon Mar 30 19:26:47 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n2UNQkLv001535
	for <sle-announce@lists.rpath.com>; Mon, 30 Mar 2009 23:26:46 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n2UNQkts004707
	for <sle-announce@lists.rpath.com>; Mon, 30 Mar 2009 19:26:46 -0400
Received: from build01.eng.rpath.com (build01.eng.rpath.com [172.16.160.201])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n2UNQjPt023362;
	Mon, 30 Mar 2009 19:26:45 -0400
Date: Mon, 30 Mar 2009 19:26:45 -0400
Message-Id: <200903302326.n2UNQjPt023362@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for mkinitrd
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 30 Mar 2009 23:26:47 -0000

Published: 2009-03-30
Products:
    SLES Delivered by rPath

Updated Versions:
    mkinitrd=sle.rpath.com@rpath:sles-10/1.2_106.83-1-1

Description:
- detect additional parameters of ramdisk at zipl.conf
- Root device not found when using 'LABEL='
- Update manpage to specify the correct inode count
- write a dump of the lvm configuration instead of copying
  lvm.conf if hosttags are in use
- Enable quotas correctly
- find the system root correctly if software RAID is in use


From announce-noreply@rpath.com Wed Apr  1 13:45:29 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n31HjTeC011185
	for <sle-announce@lists.rpath.com>; Wed, 1 Apr 2009 17:45:29 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n31HjTUu029046
	for <sle-announce@lists.rpath.com>; Wed, 1 Apr 2009 13:45:29 -0400
Received: from build02.eng.rpath.com (build02.eng.rpath.com [172.16.160.202])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n31HjSRX010046;
	Wed, 1 Apr 2009 13:45:28 -0400
Date: Wed, 1 Apr 2009 13:45:28 -0400
Message-Id: <200904011745.n31HjSRX010046@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for PHP5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 01 Apr 2009 17:45:30 -0000

Published: 2009-04-01
Products:
    SLES Delivered by rPath

Updated Versions:
    php5-dom=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-xmlrpc=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-dbase=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-exif=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-odbc=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-sockets=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-sqlite=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-mysql=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-pdo=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-gettext=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-ftp=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-sysvshm=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-bcmath=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-zlib=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-iconv=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-ctype=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-shmop=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-mbstring=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-fastcgi=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-ncurses=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-gmp=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-soap=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-dba=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-pcntl=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-xmlreader=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-tokenizer=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-ldap=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-pear=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-wddx=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-openssl=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-calendar=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-sysvmsg=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-bz2=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-posix=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5-sysvsem=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1
    php5=sle.rpath.com@rpath:sles-10/5.2.5_9.14-1-1

Description:
Missing bounds checks of an error in the imageRotate
function of the gd extension potentially allowed attackers
to read portions of memory (CVE-2008-5498).

The mbstring.func_overload in .htaccess was applied to
other virtual hosts on th same machine (CVE-2009-0754).


From announce-noreply@rpath.com Tue Apr  7 08:42:02 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n37Cg2HU003984
	for <sle-announce@lists.rpath.com>; Tue, 7 Apr 2009 12:42:02 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n37Cg1hT023346
	for <sle-announce@lists.rpath.com>; Tue, 7 Apr 2009 08:42:02 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n37Cg0Es001840;
	Tue, 7 Apr 2009 08:42:00 -0400
Date: Tue, 7 Apr 2009 08:42:00 -0400
Message-Id: <200904071242.n37Cg0Es001840@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for glibc
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 07 Apr 2009 12:42:02 -0000

Published: 2009-04-07
Products:
    SLES Delivered by rPath

Updated Versions:
    glibc=sle.rpath.com@rpath:sles-10/2.4_31.61-1-1
    timezone=sle.rpath.com@rpath:sles-10/2.4_31.61-1-1

Description:
Timezone was updated to 2009d:
  * DST changes: Africa/Casablanca, Africa/Tunis,
    Asia/Damascus, America/Argentina/..., America/Havana,
    America/Resolute
  * Historical correction: Europe/Zurich
  * New timezone: America/Argentina/Salta

Also several glibc and nscd bugs were fixed: Fixed SP1->SP2
malloc() performance regression. Fixed munmap race in the
nscd client code. Fixed race condition in setlocale().
Fixed /etc/bindresvport.blacklist parsing. Fixed invalid
assertion in ld.so's realloc().

Fixed 64-bit glibc rpmbuild on ppc64. Added missing
SHM_EXEC #define. Uses the correct instruction during
LD_PROFILE on s390 now.

Made nscd properly report temporary host resolution failure.


From announce-noreply@rpath.com Wed Apr  8 13:22:20 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n38HMKrs009868
	for <sle-announce@lists.rpath.com>; Wed, 8 Apr 2009 17:22:20 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n38HMK9h022622
	for <sle-announce@lists.rpath.com>; Wed, 8 Apr 2009 13:22:20 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n38HMJj5009585;
	Wed, 8 Apr 2009 13:22:19 -0400
Date: Wed, 8 Apr 2009 13:22:19 -0400
Message-Id: <200904081722.n38HMJj5009585@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Kerberos
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 08 Apr 2009 17:22:20 -0000

Published: 2009-04-08
Products:
    SLES Delivered by rPath

Updated Versions:
    krb5=sle.rpath.com@rpath:sles-10/1.4.3_19.41-1-1

Description:
Clients sending negotiation requests with invalid flags
could crash the kerberos server (CVE-2009-0845).

GSS-API clients could crash when reading from an invalid
address space (CVE-2009-0844).

Invalid length checks could crash applications using the
kerberos ASN.1 parser (CVE-2009-0847).

Under certain circumstances the ASN.1 parser could free an
uninitialized pointer which could crash a kerberos server
or even lead to execution of arbitrary code (CVE-2009-0846).


From announce-noreply@rpath.com Wed Apr 15 13:38:13 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n3FHcDU2008432
	for <sle-announce@lists.rpath.com>; Wed, 15 Apr 2009 17:38:13 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n3FHcDXM024176
	for <sle-announce@lists.rpath.com>; Wed, 15 Apr 2009 13:38:13 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n3FHcC3D023133;
	Wed, 15 Apr 2009 13:38:12 -0400
Date: Wed, 15 Apr 2009 13:38:12 -0400
Message-Id: <200904151738.n3FHcC3D023133@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for PostgreSQL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 15 Apr 2009 17:38:13 -0000

Published: 2009-04-15
Products:
    SLES Delivered by rPath

Updated Versions:
    postgresql=sle.rpath.com@rpath:sles-10/8.1.17_0.3-1-1
    postgresql-contrib=sle.rpath.com@rpath:sles-10/8.1.17_0.3-1-1
    postgresql-server=sle.rpath.com@rpath:sles-10/8.1.17_0.3-1-1

Description:
Remote authenticated users could crash the postgresql
server by requesting a conversion with an inappropriate
encoding (CVE-2009-0922).


From announce-noreply@rpath.com Thu Apr 16 13:22:57 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n3GHMv67012802
	for <sle-announce@lists.rpath.com>; Thu, 16 Apr 2009 17:22:57 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n3GHMvXV030994
	for <sle-announce@lists.rpath.com>; Thu, 16 Apr 2009 13:22:57 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n3GHMulN016404;
	Thu, 16 Apr 2009 13:22:56 -0400
Date: Thu, 16 Apr 2009 13:22:56 -0400
Message-Id: <200904161722.n3GHMulN016404@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for udev
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 16 Apr 2009 17:22:57 -0000

Published: 2009-04-16
Products:
    SLES Delivered by rPath

Updated Versions:
    udev=sle.rpath.com@rpath:sles-10/085_30.52-1-1

Description:
This update fixes a local privilege escalation in udev.

CVE-2009-1185: udev did not check the origin of the netlink
messages. A local attacker could fake device create events
and so gain root privileges.

It also fixes three bugs:
- Fixup persistent symlinks for tapes (bnc#446534)
- Fixup broken ATA compability links (bnc#447995)
- Add by-path links for tapes (bnc#478132)


From announce-noreply@rpath.com Wed Apr 22 08:21:15 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n3MCLFRH007841
	for <sle-announce@lists.rpath.com>; Wed, 22 Apr 2009 12:21:15 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n3MCLFem003974
	for <sle-announce@lists.rpath.com>; Wed, 22 Apr 2009 08:21:15 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n3MCLFWG023997;
	Wed, 22 Apr 2009 08:21:15 -0400
Date: Wed, 22 Apr 2009 08:21:15 -0400
Message-Id: <200904221221.n3MCLFWG023997@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for grub
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 22 Apr 2009 12:21:16 -0000

Published: 2009-04-22
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    grub=sle.rpath.com@rpath:sles-10/0.97_16.22.2-1-1

Description:
When a SLES10 SP1 server using xfs for the root filesystem
is updated to SP2 using an online update method (YaST, rug,
etc...), the server dies when attempting to enter grub
stage2. When the same server is updated by booting from an
SP2 CD and choosing to update the installation, no failure
is encountered.


From announce-noreply@rpath.com Wed Apr 22 13:19:04 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n3MHJ4bq008899
	for <sle-announce@lists.rpath.com>; Wed, 22 Apr 2009 17:19:04 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n3MHJ4OP014386
	for <sle-announce@lists.rpath.com>; Wed, 22 Apr 2009 13:19:04 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n3MHJ3CG010440;
	Wed, 22 Apr 2009 13:19:03 -0400
Date: Wed, 22 Apr 2009 13:19:03 -0400
Message-Id: <200904221719.n3MHJ3CG010440@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for udev
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 22 Apr 2009 17:19:05 -0000

Published: 2009-04-22
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    udev=sle.rpath.com@rpath:sles-10/085_30.54-1-1

Description:
This update fixes a local privilege escalation in udev.

CVE-2009-1185: udev did not check the origin of the netlink
messages. A local attacker could fake device create events
and so gain root privileges.

The previous update did not apply the actual patch fixing
this problem, as was reported to us by SGI.

Please reboot the machine after installing the update, or
run: /etc/init.d/boot.udev restart


From announce-noreply@rpath.com Thu Apr 23 13:20:24 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n3NHKOO3013412
	for <sle-announce@lists.rpath.com>; Thu, 23 Apr 2009 17:20:24 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n3NHKO4I026496
	for <sle-announce@lists.rpath.com>; Thu, 23 Apr 2009 13:20:24 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n3NHKNNb000994;
	Thu, 23 Apr 2009 13:20:23 -0400
Date: Thu, 23 Apr 2009 13:20:23 -0400
Message-Id: <200904231720.n3NHKNNb000994@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for GnuTLS
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 23 Apr 2009 17:20:24 -0000

Published: 2009-04-23
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    gnutls=sle.rpath.com@rpath:sles-10/1.2.10_13.15-1-1

Description:
The previous security fix for gnutls (CVE-2008-4989)
introduced a regression in the X.509 validation code for
self-signed certificates. 

This update fixes this problem.


From announce-noreply@rpath.com Mon Apr 27 17:28:54 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n3RLSsL4032036
	for <sle-announce@lists.rpath.com>; Mon, 27 Apr 2009 21:28:54 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n3RLSs9H006891
	for <sle-announce@lists.rpath.com>; Mon, 27 Apr 2009 17:28:54 -0400
Received: from build02.eng.rpath.com (build02.eng.rpath.com [172.16.160.202])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n3RLSsD5018014;
	Mon, 27 Apr 2009 17:28:54 -0400
Date: Mon, 27 Apr 2009 17:28:54 -0400
Message-Id: <200904272128.n3RLSsD5018014@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for cron
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 27 Apr 2009 21:28:54 -0000

Published: 2009-04-27
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    cron=sle.rpath.com@rpath:sles-10/4.1_45.25-1-1

Description:
- #469139: Fix cron daemon not restarting successfully


From announce-noreply@rpath.com Tue Apr 28 09:25:16 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n3SDPGmT002733
	for <sle-announce@lists.rpath.com>; Tue, 28 Apr 2009 13:25:16 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n3SDPFcM031889
	for <sle-announce@lists.rpath.com>; Tue, 28 Apr 2009 09:25:15 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n3SDPF75004985;
	Tue, 28 Apr 2009 09:25:15 -0400
Date: Tue, 28 Apr 2009 09:25:15 -0400
Message-Id: <200904281325.n3SDPF75004985@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for compat-openssl097g
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 28 Apr 2009 13:25:16 -0000

Published: 2009-04-28
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    compat-openssl097g=sle.rpath.com@rpath:sles-10/0.9.7g_13.16-1-1

Description:
This update of openssl fixes the following problems:
- CVE-2009-0590: ASN1_STRING_print_ex() function allows
  remote denial of service
- CVE-2009-0789: denial of service due to malformed ASN.1
  structures


From announce-noreply@rpath.com Tue Apr 28 09:25:16 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n3SDPGbS002734
	for <sle-announce@lists.rpath.com>; Tue, 28 Apr 2009 13:25:16 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n3SDPFFT031890
	for <sle-announce@lists.rpath.com>; Tue, 28 Apr 2009 09:25:15 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n3SDPF8u004987;
	Tue, 28 Apr 2009 09:25:15 -0400
Date: Tue, 28 Apr 2009 09:25:15 -0400
Message-Id: <200904281325.n3SDPF8u004987@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenSSL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 28 Apr 2009 13:25:16 -0000

Published: 2009-04-28
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    openssl=sle.rpath.com@rpath:sles-10/0.9.8a_18.30-1-1

Description:
This update of openssl fixes the following problems:
- CVE-2009-0590: ASN1_STRING_print_ex() function allows
  remote denial of service
- CVE-2009-0789: denial of service due to malformed ASN.1
  structures


From announce-noreply@rpath.com Wed Apr 29 15:20:22 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n3TJKMTZ008210
	for <sle-announce@lists.rpath.com>; Wed, 29 Apr 2009 19:20:22 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n3TJKMuN017522
	for <sle-announce@lists.rpath.com>; Wed, 29 Apr 2009 15:20:22 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n3TJKMoP014649;
	Wed, 29 Apr 2009 15:20:22 -0400
Date: Wed, 29 Apr 2009 15:20:22 -0400
Message-Id: <200904291920.n3TJKMoP014649@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for GPG2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 29 Apr 2009 19:20:23 -0000

Published: 2009-04-29
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    gpg2=sle.rpath.com@rpath:sles-10/1.9.18_17.19-1-1

Description:
gpg-agent modifies SigBlk mask of all processes spawned in
the X session breaking unrelated software started in the
session.


From announce-noreply@rpath.com Thu Apr 30 15:24:13 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n3UJODIV012788
	for <sle-announce@lists.rpath.com>; Thu, 30 Apr 2009 19:24:13 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n3UJODsq003249
	for <sle-announce@lists.rpath.com>; Thu, 30 Apr 2009 15:24:13 -0400
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n3UJOCIi002703;
	Thu, 30 Apr 2009 15:24:13 -0400
Date: Thu, 30 Apr 2009 15:24:12 -0400
Message-Id: <200904301924.n3UJOCIi002703@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenSC
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 30 Apr 2009 19:24:13 -0000

Published: 2009-04-30
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    opensc=sle.rpath.com@rpath:sles-10/0.9.6_17.12-1-1

Description:
Private data objects on smartcards initialized with OpenSC
could be accessed without authentication (CVE-2009-0368).

Only blank cards initialized with OpenSC are affected by
this problem. Affected cards need to be manually fixed,
updating the opensc package alone is not sufficient!

Please carefully read and follow the instructions on the
following web site if you are using PIN protected private
data objects on smart cards other than Oberthur, and you
have initialized those cards using OpenSC:
http://en.opensuse.org/Smart_Cards/Advisories


From announce-noreply@rpath.com Mon May  4 16:26:49 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n44KQnTj031535
	for <sle-announce@lists.rpath.com>; Mon, 4 May 2009 20:26:49 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n44KQm7o023618
	for <sle-announce@lists.rpath.com>; Mon, 4 May 2009 16:26:48 -0400
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n44KQm9w010537;
	Mon, 4 May 2009 16:26:48 -0400
Date: Mon, 4 May 2009 16:26:48 -0400
Message-Id: <200905042026.n44KQm9w010537@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for sysconfig
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 04 May 2009 20:26:49 -0000

Published: 2009-05-04
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    sysconfig=sle.rpath.com@rpath:sles-10/0.50.9_13.52-1-1

Description:
- Fixed overlapping messages in rcnetwork output
  (bnc#406887).
- Fixes for /etc/named.d/forwarders.conf updates in case
  that the file does not exists or it does not already
  contain a 'forwarders {};' block (bnc#134692).
- Fixed ifup-wireless to not set nick by default that
  breaks several drivers (bnc#478513).
- Fixed ifup-wireless to set access point address, but only
  when explicitly requested (bnc#229757, see also
  bnc#329280, bnc#379586, bnc#402438).
- Fixed network scripts to handle dummy interfaces
  (bnc#436857).
- Fixed ipv6 support in ifup-route script and parsing of
  final lines without EOL in ifroute files (bnc#467165).
- Fixed ifdown-autoip to check if info file exists
  (bnc#463266).
- Fixed tunnel setup to skip the getcfg-interface call when
  the config contains IP but no interface setting
  (bnc#476153).
- Added 127.0.0.2/8 address to the loopback interface
  config to avoid problems with ntpd (bnc#355608).
- Fixed ifup-dhcp to retain spaces DHCLIENT_VENDOR_CLASS_ID
  and other dhcpcd option values (bnc#424356).


From announce-noreply@rpath.com Mon May  4 16:26:49 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n44KQnQZ031536
	for <sle-announce@lists.rpath.com>; Mon, 4 May 2009 20:26:49 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n44KQmIG023619
	for <sle-announce@lists.rpath.com>; Mon, 4 May 2009 16:26:48 -0400
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n44KQmaS010539;
	Mon, 4 May 2009 16:26:48 -0400
Date: Mon, 4 May 2009 16:26:48 -0400
Message-Id: <200905042026.n44KQmaS010539@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for freetype2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 04 May 2009 20:26:49 -0000

Published: 2009-05-04
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    freetype2=sle.rpath.com@rpath:sles-10/2.1.10_18.20-1-1

Description:
Freetype was updated to fix some integer overflows that can
be exploited remotely in conjunction with programs like a
web-browser. (CVE-2009-0946) Thanks to Tavis Ormandy who
found the bugs.


From announce-noreply@rpath.com Mon May 18 09:25:10 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n4IDPA3B030225
	for <sle-announce@lists.rpath.com>; Mon, 18 May 2009 13:25:10 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n4IDPAQ8012451
	for <sle-announce@lists.rpath.com>; Mon, 18 May 2009 09:25:10 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n4IDPA79010960;
	Mon, 18 May 2009 09:25:10 -0400
Date: Mon, 18 May 2009 09:25:10 -0400
Message-Id: <200905181325.n4IDPA79010960@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for aaa_base and yast2-vm
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 18 May 2009 13:25:11 -0000

Published: 2009-05-18
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    aaa_base=sle.rpath.com@rpath:sles-10/10_12.53-1-1

Description:
- #488598: chkconfig and insserv fail on init scripts that
  depend on /etc/init.d/boot.clock in Xen domU


From announce-noreply@rpath.com Mon May 18 17:24:54 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n4ILOs10031751
	for <sle-announce@lists.rpath.com>; Mon, 18 May 2009 21:24:54 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n4ILOsoM000573
	for <sle-announce@lists.rpath.com>; Mon, 18 May 2009 17:24:54 -0400
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n4ILOsDk009946;
	Mon, 18 May 2009 17:24:54 -0400
Date: Mon, 18 May 2009 17:24:54 -0400
Message-Id: <200905182124.n4ILOsDk009946@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for xntp
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 18 May 2009 21:24:54 -0000

Published: 2009-05-18
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    xntp=sle.rpath.com@rpath:sles-10/4.2.4p3_48.13.3-1-1

Description:
This update fixes a remote buffer overflow in xntp/ntp
which can be exploited when autokey is enabled to execute
arbitrary code. (CVE-2009-1252) This upfate fixes a buffer
overflow in ntpd that can be triggered by a malicious
server. (CVE-2009-0159)


From announce-noreply@rpath.com Tue May 26 13:34:56 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n4QHYuAV002015
	for <sle-announce@lists.rpath.com>; Tue, 26 May 2009 17:34:56 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n4QHYuRg002417
	for <sle-announce@lists.rpath.com>; Tue, 26 May 2009 13:34:56 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n4QHYtwP027992;
	Tue, 26 May 2009 13:34:55 -0400
Date: Tue, 26 May 2009 13:34:55 -0400
Message-Id: <200905261734.n4QHYtwP027992@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for portmap
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 26 May 2009 17:34:56 -0000

Published: 2009-05-26
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    portmap=sle.rpath.com@rpath:sles-10/5beta_749.18-1-1

Description:
This update corrects portmap daemon being quit by a PIPE
signal when UDP packets with bad checksums are received.
(bnc#481331)


From announce-noreply@rpath.com Tue May 26 13:34:56 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n4QHYu8C002016
	for <sle-announce@lists.rpath.com>; Tue, 26 May 2009 17:34:56 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n4QHYuZ7002418
	for <sle-announce@lists.rpath.com>; Tue, 26 May 2009 13:34:56 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n4QHYupL027994;
	Tue, 26 May 2009 13:34:56 -0400
Date: Tue, 26 May 2009 13:34:56 -0400
Message-Id: <200905261734.n4QHYupL027994@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenSSL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 26 May 2009 17:34:57 -0000

Published: 2009-05-26
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    openssl=sle.rpath.com@rpath:sles-10/0.9.8a_18.32-1-1

Description:
Three remote DoS vulnerabilities have been fixed in
OpenSSL: a DTLS epoch record buffer memory DoS
(CVE-2009-1377), a DTLS fragment handling memory DoS
(CVE-2009-1378) and  a DTLS fragment read after a free DoS
(CVE-2009-1379).


From announce-noreply@rpath.com Wed May 27 15:29:33 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n4RJTXWa007230
	for <sle-announce@lists.rpath.com>; Wed, 27 May 2009 19:29:33 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n4RJTXmS026799
	for <sle-announce@lists.rpath.com>; Wed, 27 May 2009 15:29:33 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n4RJTWev000396;
	Wed, 27 May 2009 15:29:32 -0400
Date: Wed, 27 May 2009 15:29:32 -0400
Message-Id: <200905271929.n4RJTWev000396@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for cyrus-sasl
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 27 May 2009 19:29:33 -0000

Published: 2009-05-27
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    cyrus-sasl-gssapi=sle.rpath.com@rpath:sles-10/2.1.21_18.10.2-1-1
    cyrus-sasl=sle.rpath.com@rpath:sles-10/2.1.21_18.10.2-1-1

Description:
This update of cyrus-sasl improves the output of function
sasl_encode64() by appending a 0 for string termination.
The impact depends on the application that uses
sasl_encode64(). (CVE-2009-0688)


From announce-noreply@rpath.com Thu May 28 11:24:01 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n4SFO1gX011479
	for <sle-announce@lists.rpath.com>; Thu, 28 May 2009 15:24:01 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n4SFO0WW003101
	for <sle-announce@lists.rpath.com>; Thu, 28 May 2009 11:24:00 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n4SFO0WP012323;
	Thu, 28 May 2009 11:24:00 -0400
Date: Thu, 28 May 2009 11:24:00 -0400
Message-Id: <200905281524.n4SFO0WP012323@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for net-snmp
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 28 May 2009 15:24:01 -0000

Published: 2009-05-28
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    net-snmp=sle.rpath.com@rpath:sles-10/5.3.0.1_25.31-1-1

Description:
With this update of net-snmp the handling of TCP wrappers
rules for client authorization was improved, prior to this
update it was possible for remote attackers to bypass
intended access restrictions and execute SNMP queries.
(CVE-2008-6123)  Additionally binding to multiple
interfaces was improved.


From announce-noreply@rpath.com Thu Jun  4 12:25:42 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n54GPgvM012061
	for <sle-announce@lists.rpath.com>; Thu, 4 Jun 2009 16:25:42 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n54GPfDx002803
	for <sle-announce@lists.rpath.com>; Thu, 4 Jun 2009 12:25:41 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n54GPfqJ007998;
	Thu, 4 Jun 2009 12:25:41 -0400
Date: Thu, 4 Jun 2009 12:25:41 -0400
Message-Id: <200906041625.n54GPfqJ007998@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for e2fsprogs
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 04 Jun 2009 16:25:42 -0000

Published: 2009-06-04
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    libcom_err=sle.rpath.com@rpath:sles-10/1.38_25.32-1-1
    e2fsprogs=sle.rpath.com@rpath:sles-10/1.38_25.32-1-1

Description:
This update to e2fsprogs fixes the following bug:
- #393095: e2fsck: potential data corruption bug in journal
  recovery


From announce-noreply@rpath.com Mon Jun  8 23:16:10 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n593GAFZ031264
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 03:16:10 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n593GAHh001880
	for <sle-announce@lists.rpath.com>; Mon, 8 Jun 2009 23:16:10 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n593G9Ft025630;
	Mon, 8 Jun 2009 23:16:09 -0400
Date: Mon, 8 Jun 2009 23:16:09 -0400
Message-Id: <200906090316.n593G9Ft025630@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Optional update for NFS
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 09 Jun 2009 03:16:10 -0000

Published: 2009-06-08
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    nfs-kernel-server=sle.rpath.com@rpath:sles-11/1.1.3_19.1.1-1-1
    nfs-utils=sle.rpath.com@rpath:sles-11/1.1.3_19.1.1-1-1
    nfs-client=sle.rpath.com@rpath:sles-11/1.1.3_19.1.1-1-1

Description:
Add a sysconfig option "NFS_START_SERVICES" to request NFS
services such as gssd or idmap be started at boot time even
though no NFS mounts are listed in /etc/fstab.  This is
useful if something else, such as automount, mounts NFS
filesystems.

Also fix a bug in umount.nfs so that the "mountproto"
option is handled correctly.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=472438
    https://bugzilla.novell.com/show_bug.cgi?id=495993

From announce-noreply@rpath.com Tue Jun  9 12:05:07 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n59G57Lj001096
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 16:05:07 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n59G57L9025446
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 12:05:07 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n59G56sC004440;
	Tue, 9 Jun 2009 12:05:06 -0400
Date: Tue, 9 Jun 2009 12:05:06 -0400
Message-Id: <200906091605.n59G56sC004440@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for bind
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 09 Jun 2009 16:05:07 -0000

Published: 2009-06-09
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    bind-chrootenv=sle.rpath.com@rpath:sles-11/9.5.0P2_20.2.1-1-3
    bind=sle.rpath.com@rpath:sles-11/9.5.0P2_20.2.1-1-3
    bind-utils=sle.rpath.com@rpath:sles-11/9.5.0P2_20.2.1-1-3

Description:
- #488599: bind DNSSEC Lookaside Validation problem
- mount /proc into chroot environment to support multi CPU
  systems (bnc#470828)
- key names with spaces are allowed by genDDNSkey now
  (bnc#459739)
- a missing /etc/named.conf.include could lead to an error
  while "restart" (bnc#455888)
- /etc/named.conf does not include
  /etc/named.d/forwarders.conf by default (bnc#480334)


References:
    https://bugzilla.novell.com/show_bug.cgi?id=488599
    https://bugzilla.novell.com/show_bug.cgi?id=470828
    https://bugzilla.novell.com/show_bug.cgi?id=459739
    https://bugzilla.novell.com/show_bug.cgi?id=455888
    https://bugzilla.novell.com/show_bug.cgi?id=480334

From announce-noreply@rpath.com Tue Jun  9 12:05:07 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n59G572G001097
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 16:05:07 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n59G57gQ025447
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 12:05:07 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n59G5702004442;
	Tue, 9 Jun 2009 12:05:07 -0400
Date: Tue, 9 Jun 2009 12:05:07 -0400
Message-Id: <200906091605.n59G5702004442@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for ntp
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 09 Jun 2009 16:05:07 -0000

Published: 2009-06-09
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    ntp=sle.rpath.com@rpath:sles-11/4.2.4p6_1.17.1-1-3

Description:
This update fixes a remote buffer overflow in xntp/ntp
which can be exploited when autokey is enabled to execute
arbitrary code. (CVE-2009-1252) This upfate fixes a buffer
overflow in ntpd that can be triggered by a malicious
server. (CVE-2009-0159)


References:
    https://bugzilla.novell.com/show_bug.cgi?id=501632
    https://bugzilla.novell.com/show_bug.cgi?id=483897
    https://bugzilla.novell.com/show_bug.cgi?id=482349
    https://bugzilla.novell.com/show_bug.cgi?id=484653
    https://bugzilla.novell.com/show_bug.cgi?id=479341

From announce-noreply@rpath.com Tue Jun  9 12:05:08 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n59G57F7001102
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 16:05:07 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n59G578w025448
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 12:05:07 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n59G57T9004444;
	Tue, 9 Jun 2009 12:05:07 -0400
Date: Tue, 9 Jun 2009 12:05:07 -0400
Message-Id: <200906091605.n59G57T9004444@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenSSL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 09 Jun 2009 16:05:08 -0000

Published: 2009-06-09
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    openssl=sle.rpath.com@rpath:sles-11/0.9.8h_30.13.1-1-3

Description:
Three remote DoS vulnerabilities have been fixed in
OpenSSL: a DTLS epoch record buffer memory DoS
(CVE-2009-1377), a DTLS fragment handling memory DoS
(CVE-2009-1378) and  a DTLS fragment read after a free DoS
(CVE-2009-1379).


References:
    https://bugzilla.novell.com/show_bug.cgi?id=504687

From announce-noreply@rpath.com Tue Jun  9 12:05:08 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n59G58w8001104
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 16:05:08 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n59G57TX025454
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 12:05:07 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n59G57iu004448;
	Tue, 9 Jun 2009 12:05:07 -0400
Date: Tue, 9 Jun 2009 12:05:07 -0400
Message-Id: <200906091605.n59G57iu004448@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for cyrus-sasl
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 09 Jun 2009 16:05:08 -0000

Published: 2009-06-09
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    cyrus-sasl-plain=sle.rpath.com@rpath:sles-11/2.1.22_182.20.1-1-3
    cyrus-sasl-gssapi=sle.rpath.com@rpath:sles-11/2.1.22_182.20.1-1-3
    cyrus-sasl=sle.rpath.com@rpath:sles-11/2.1.22_182.20.1-1-3
    cyrus-sasl-digestmd5=sle.rpath.com@rpath:sles-11/2.1.22_182.20.1-1-3
    cyrus-sasl-crammd5=sle.rpath.com@rpath:sles-11/2.1.22_182.20.1-1-3
    cyrus-sasl-otp=sle.rpath.com@rpath:sles-11/2.1.22_182.20.1-1-3

Description:
This update of cyrus-sasl improves the output of function
sasl_encode64() by appending a 0 for string termination.
The impact depends on the application that uses
sasl_encode64(). (CVE-2009-0688)


References:
    https://bugzilla.novell.com/show_bug.cgi?id=499104

From announce-noreply@rpath.com Tue Jun  9 12:05:08 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n59G57eX001103
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 16:05:07 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n59G57fs025451
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 12:05:07 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n59G57io004446;
	Tue, 9 Jun 2009 12:05:07 -0400
Date: Tue, 9 Jun 2009 12:05:07 -0400
Message-Id: <200906091605.n59G57io004446@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Optional update for NFS
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 09 Jun 2009 16:05:08 -0000

Published: 2009-06-09
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    nfs-kernel-server=sle.rpath.com@rpath:sles-11/1.1.3_19.1.1-1-3
    nfs-client=sle.rpath.com@rpath:sles-11/1.1.3_19.1.1-1-3
    nfs-utils=sle.rpath.com@rpath:sles-11/1.1.3_19.1.1-1-3

Description:
Add a sysconfig option "NFS_START_SERVICES" to request NFS
services such as gssd or idmap be started at boot time even
though no NFS mounts are listed in /etc/fstab.  This is
useful if something else, such as automount, mounts NFS
filesystems.

Also fix a bug in umount.nfs so that the "mountproto"
option is handled correctly.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=472438
    https://bugzilla.novell.com/show_bug.cgi?id=495993

From announce-noreply@rpath.com Tue Jun  9 12:05:09 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n59G58Q9001112
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 16:05:08 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n59G58mj025462
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 12:05:08 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n59G57Bq004452;
	Tue, 9 Jun 2009 12:05:07 -0400
Date: Tue, 9 Jun 2009 12:05:07 -0400
Message-Id: <200906091605.n59G57Bq004452@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for device-mapper and LVM
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 09 Jun 2009 16:05:09 -0000

Published: 2009-06-09
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    lvm2=sle.rpath.com@rpath:sles-11/2.02.39_17.6.2-1-3

Description:
This update fixes the following regression:

- #479104: multipathd daemon fails to add activated paths
  to maps after all-paths down scenario when there are LVs
  configured


References:
    https://bugzilla.novell.com/show_bug.cgi?id=479104

From announce-noreply@rpath.com Tue Jun  9 12:05:08 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n59G58oM001111
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 16:05:08 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n59G58NM025461
	for <sle-announce@lists.rpath.com>; Tue, 9 Jun 2009 12:05:08 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n59G57fT004450;
	Tue, 9 Jun 2009 12:05:07 -0400
Date: Tue, 9 Jun 2009 12:05:07 -0400
Message-Id: <200906091605.n59G57fT004450@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for device-mapper and LVM
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 09 Jun 2009 16:05:09 -0000

Published: 2009-06-09
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    device-mapper=sle.rpath.com@rpath:sles-11/1.02.27_8.7.2-1-3

Description:
This update fixes the following regression:

- #479104: multipathd daemon fails to add activated paths
  to maps after all-paths down scenario when there are LVs
  configured


References:
    https://bugzilla.novell.com/show_bug.cgi?id=479104

From announce-noreply@rpath.com Wed Jun 10 12:25:43 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n5AGPhgV005407
	for <sle-announce@lists.rpath.com>; Wed, 10 Jun 2009 16:25:43 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n5AGPgkC003229
	for <sle-announce@lists.rpath.com>; Wed, 10 Jun 2009 12:25:43 -0400
Received: from build03.eng.rpath.com (build03.eng.rpath.com [172.16.160.203])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n5AGPga2025562;
	Wed, 10 Jun 2009 12:25:42 -0400
Date: Wed, 10 Jun 2009 12:25:42 -0400
Message-Id: <200906101625.n5AGPga2025562@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for dhcpcd
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 10 Jun 2009 16:25:43 -0000

Published: 2009-06-10
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    dhcpcd=sle.rpath.com@rpath:sles-10/1.3.22pl4_223.13-1-1

Description:
dhcpcd sets the link of the device down when the lease
expires. This is fatal, when the device is a bonding
device, because bonding will release all slaves when the
interface is set down. So when this was only a temporary
failure the bonding device with dhcp will never come up
again.


From announce-noreply@rpath.com Mon Jun 15 23:02:19 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n5G32JVs029117
	for <sle-announce@lists.rpath.com>; Tue, 16 Jun 2009 03:02:19 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n5G32JIq009025
	for <sle-announce@lists.rpath.com>; Mon, 15 Jun 2009 23:02:19 -0400
Received: from build03.eng.rpath.com (build03.eng.rpath.com [172.16.160.203])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n5G32J5N019273;
	Mon, 15 Jun 2009 23:02:19 -0400
Date: Mon, 15 Jun 2009 23:02:19 -0400
Message-Id: <200906160302.n5G32J5N019273@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for pango
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 16 Jun 2009 03:02:19 -0000

Published: 2009-06-15
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    pango=sle.rpath.com@rpath:sles-11/1.22.1_3.17.3-1-1

Description:
This update of pango fixes a segfault in libpango that can
be triggered by visiting web-sites. (CVE-2009-1194)


References:
    https://bugzilla.novell.com/show_bug.cgi?id=492773

From announce-noreply@rpath.com Wed Jun 17 16:28:14 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n5HKSEEJ004266
	for <sle-announce@lists.rpath.com>; Wed, 17 Jun 2009 20:28:14 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n5HKSE1L023942
	for <sle-announce@lists.rpath.com>; Wed, 17 Jun 2009 16:28:14 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n5HKSDkc014205;
	Wed, 17 Jun 2009 16:28:13 -0400
Date: Wed, 17 Jun 2009 16:28:13 -0400
Message-Id: <200906172028.n5HKSDkc014205@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenSSL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 17 Jun 2009 20:28:15 -0000

Published: 2009-06-17
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    openssl=sle.rpath.com@rpath:sles-11/0.9.8h_30.14.1-1-1

Description:
OpenSSL DTLS remote DoS in ChangeCipherSpec (CVE-2009-1386)
and in out-of-sequence message handling (CVE-2009-1387)
have been fixed.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=509031

From announce-noreply@rpath.com Wed Jun 17 17:33:55 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n5HLXtER004501
	for <sle-announce@lists.rpath.com>; Wed, 17 Jun 2009 21:33:55 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n5HLXs4T025880
	for <sle-announce@lists.rpath.com>; Wed, 17 Jun 2009 17:33:55 -0400
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n5HLXsxC018536;
	Wed, 17 Jun 2009 17:33:54 -0400
Date: Wed, 17 Jun 2009 17:33:54 -0400
Message-Id: <200906172133.n5HLXsxC018536@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenSSL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 17 Jun 2009 21:33:55 -0000

Published: 2009-06-17
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    openssl=sle.rpath.com@rpath:sles-10/0.9.8a_18.34-1-1

Description:
OpenSSL DTLS remote DoS in ChangeCipherSpec (CVE-2009-1386)
and in out-of-sequence message handling (CVE-2009-1387)
have been fixed.


From announce-noreply@rpath.com Fri Jun 19 15:37:59 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n5JJbx8u012787
	for <sle-announce@lists.rpath.com>; Fri, 19 Jun 2009 19:37:59 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n5JJbxLV001245
	for <sle-announce@lists.rpath.com>; Fri, 19 Jun 2009 15:37:59 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n5JJbxgf020206;
	Fri, 19 Jun 2009 15:37:59 -0400
Date: Fri, 19 Jun 2009 15:37:59 -0400
Message-Id: <200906191937.n5JJbxgf020206@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for Samba
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 19 Jun 2009 19:38:00 -0000

Published: 2009-06-19
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    samba-krb-printing=sle.rpath.com@rpath:sles-10/3.0.32_0.11-1-1
    samba-winbind=sle.rpath.com@rpath:sles-10/3.0.32_0.11-1-1
    samba-client=sle.rpath.com@rpath:sles-10/3.0.32_0.11-1-1
    samba-vscan=sle.rpath.com@rpath:sles-10/3.0.32_0.11-1-1
    libsmbclient=sle.rpath.com@rpath:sles-10/3.0.32_0.11-1-1
    samba-python=sle.rpath.com@rpath:sles-10/3.0.32_0.11-1-1
    cifs-mount=sle.rpath.com@rpath:sles-10/3.0.32_0.11-1-1
    libmsrpc=sle.rpath.com@rpath:sles-10/3.0.32_0.11-1-1

Description:
- Add the NT version included in LDAP filter by Nmbd;
  (bnc#483422). *
- Make libsmbclient work with DFS, backported from 3.3;
  (bnc#475995).
- Backport of the clean event context after fork and krb5
  refresh chain fixes; (bnc#415026).


From announce-noreply@rpath.com Fri Jun 19 17:22:50 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n5JLMoqf013133
	for <sle-announce@lists.rpath.com>; Fri, 19 Jun 2009 21:22:50 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n5JLMoDc004633
	for <sle-announce@lists.rpath.com>; Fri, 19 Jun 2009 17:22:50 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n5JLMn8R026793;
	Fri, 19 Jun 2009 17:22:50 -0400
Date: Fri, 19 Jun 2009 17:22:49 -0400
Message-Id: <200906192122.n5JLMn8R026793@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for sysconfig
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 19 Jun 2009 21:22:50 -0000

Published: 2009-06-19
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    sysconfig=sle.rpath.com@rpath:sles-11/0.71.14_12.2.1-1-1

Description:
- Fixed netconfig regex checks to work with some
  non-English (e.g. Estonian) locales and to allow spaces
  in lease file (bnc#488257).
- Applied fix for the obsolete hwup utility to work with
  ccwgroup (qeth,lcs,ctc) devices on s390x (bnc#483774).
- Fixed overlapping messages in rcnetwork output
  (bnc#406887). 
- Fixed ifup-wireless to not set nick by default that
  breaks several drivers (bnc#478513).
- Fixed ifup-wireless to set ap to 'off' instead to 'any'
  for the madwifi driver that does not support 'any'
  (bnc#402438).
- Fixed network scripts to handle dummy interfaces
  (bnc#436857).
- Fixed ifroute script parsing of final lines without EOL
  in ifroute files (bnc#467165).


References:
    https://bugzilla.novell.com/show_bug.cgi?id=436857
    https://bugzilla.novell.com/show_bug.cgi?id=488257
    https://bugzilla.novell.com/show_bug.cgi?id=483774
    https://bugzilla.novell.com/show_bug.cgi?id=406887
    https://bugzilla.novell.com/show_bug.cgi?id=478513
    https://bugzilla.novell.com/show_bug.cgi?id=402438
    https://bugzilla.novell.com/show_bug.cgi?id=467165

From announce-noreply@rpath.com Tue Jun 23 12:36:39 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n5NGadfc029258
	for <sle-announce@lists.rpath.com>; Tue, 23 Jun 2009 16:36:39 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n5NGadGx020017
	for <sle-announce@lists.rpath.com>; Tue, 23 Jun 2009 12:36:39 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.13.6/8.13.4) with ESMTP id n5NGadfX010990;
	Tue, 23 Jun 2009 12:36:39 -0400
Date: Tue, 23 Jun 2009 12:36:39 -0400
Message-Id: <200906231636.n5NGadfX010990@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Perl
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 23 Jun 2009 16:36:40 -0000

Published: 2009-06-23
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    perl=sle.rpath.com@rpath:sles-11/5.10.0_64.43.1-1-1
    perl-base=sle.rpath.com@rpath:sles-11/5.10.0_64.43.1-1-1

Description:
A Buffer overflow in perl, in the base Compress::Raw::Zlib
perl module has been fixed. (CVE-2009-1391)

Additionaly three non security bugs were fixed.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=511241
    https://bugzilla.novell.com/show_bug.cgi?id=489114
    https://bugzilla.novell.com/show_bug.cgi?id=498425
    https://bugzilla.novell.com/show_bug.cgi?id=493978

From announce-noreply@rpath.com Mon Jul  6 16:59:49 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n66KxmwB022950
	for <sle-announce@lists.rpath.com>; Mon, 6 Jul 2009 20:59:48 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n66Kxm2a001145
	for <sle-announce@lists.rpath.com>; Mon, 6 Jul 2009 16:59:48 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n66KwkE4011492;
	Mon, 6 Jul 2009 16:58:47 -0400
Date: Mon, 6 Jul 2009 16:58:46 -0400
Message-Id: <200907062058.n66KwkE4011492@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for PHP5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 06 Jul 2009 20:59:49 -0000

Published: 2009-07-06
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    php5-pcntl=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-soap=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-calendar=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-gmp=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-sysvmsg=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-dba=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-sockets=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-iconv=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-gettext=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-bcmath=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-ftp=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-exif=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-pear=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-fastcgi=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-tokenizer=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-mbstring=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-sysvsem=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-ncurses=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-openssl=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-mysql=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-wddx=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-posix=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-pdo=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-zlib=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-xmlreader=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-xmlrpc=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-ldap=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-dbase=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-sqlite=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-bz2=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-shmop=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-ctype=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-dom=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-odbc=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1
    php5-sysvshm=sle.rpath.com@rpath:sles-10/5.2.5_9.18-1-1

Description:
This update fixes the JSON parser (CVE-2009-1271) and the
zip packer code (CVE-2009-1272) in php5. Both bugs can lead
to a remote denial of service attack.


From announce-noreply@rpath.com Wed Jul  8 15:25:29 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n68JPTqc031607
	for <sle-announce@lists.rpath.com>; Wed, 8 Jul 2009 19:25:29 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n68JPTQQ004589
	for <sle-announce@lists.rpath.com>; Wed, 8 Jul 2009 15:25:29 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n68JODm8016916;
	Wed, 8 Jul 2009 15:24:13 -0400
Date: Wed, 8 Jul 2009 15:24:13 -0400
Message-Id: <200907081924.n68JODm8016916@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for Xorg
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 08 Jul 2009 19:25:29 -0000

Published: 2009-07-08
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    xorg-x11-libxcb=sle.rpath.com@rpath:sles-11/7.4_1.16.1-1-1

Description:
This updates xorg-x11-libxcb with stability and performance
fixes for various XCB applications, most noteably Mozilla
Firefox.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=423740
    https://bugzilla.novell.com/show_bug.cgi?id=510862

From announce-noreply@rpath.com Mon Jul 13 14:58:11 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6DIwBY8021706
	for <sle-announce@lists.rpath.com>; Mon, 13 Jul 2009 18:58:11 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6DIwB7Y024464
	for <sle-announce@lists.rpath.com>; Mon, 13 Jul 2009 14:58:11 -0400
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6DIuHOa012471;
	Mon, 13 Jul 2009 14:56:17 -0400
Date: Mon, 13 Jul 2009 14:56:17 -0400
Message-Id: <200907131856.n6DIuHOa012471@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Samba
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 13 Jul 2009 18:58:11 -0000

Published: 2009-07-13
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    libwbclient0=sle.rpath.com@rpath:sles-11/3.2.7_11.7.1-1-1
    samba=sle.rpath.com@rpath:sles-11/3.2.7_11.7.1-1-1
    libtalloc1=sle.rpath.com@rpath:sles-11/3.2.7_11.7.1-1-1
    libsmbsharemodes0=sle.rpath.com@rpath:sles-11/3.2.7_11.7.1-1-1
    libnetapi0=sle.rpath.com@rpath:sles-11/3.2.7_11.7.1-1-1
    libsmbclient0=sle.rpath.com@rpath:sles-11/3.2.7_11.7.1-1-1
    samba-client=sle.rpath.com@rpath:sles-11/3.2.7_11.7.1-1-1
    ldapsmb=sle.rpath.com@rpath:sles-11/3.2.7_11.7.1-1-1
    samba-krb-printing=sle.rpath.com@rpath:sles-11/3.2.7_11.7.1-1-1
    samba-winbind=sle.rpath.com@rpath:sles-11/3.2.7_11.7.1-1-1
    libtdb1=sle.rpath.com@rpath:sles-11/3.2.7_11.7.1-1-1
    cifs-mount=sle.rpath.com@rpath:sles-11/3.2.7_11.7.1-1-1

Description:
Fixed a format string vulnerability in smbclient
(CVE-2009-1886) and a ACL bypass vulnerability in samba
(CVE-2009-1888).


References:
    https://bugzilla.novell.com/show_bug.cgi?id=515479
    https://bugzilla.novell.com/show_bug.cgi?id=513360

From announce-noreply@rpath.com Mon Jul 13 15:44:17 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6DJiHBP021873
	for <sle-announce@lists.rpath.com>; Mon, 13 Jul 2009 19:44:17 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6DJiHvn025991
	for <sle-announce@lists.rpath.com>; Mon, 13 Jul 2009 15:44:17 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6DJgNtf015501;
	Mon, 13 Jul 2009 15:42:23 -0400
Date: Mon, 13 Jul 2009 15:42:23 -0400
Message-Id: <200907131942.n6DJgNtf015501@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Samba
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 13 Jul 2009 19:44:18 -0000

Published: 2009-07-13
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    samba-python=sle.rpath.com@rpath:sles-10/3.0.32_0.14-1-1
    samba-vscan=sle.rpath.com@rpath:sles-10/3.0.32_0.14-1-1
    libsmbclient=sle.rpath.com@rpath:sles-10/3.0.32_0.14-1-1
    samba-client=sle.rpath.com@rpath:sles-10/3.0.32_0.14-1-1
    samba-winbind=sle.rpath.com@rpath:sles-10/3.0.32_0.14-1-1
    samba-krb-printing=sle.rpath.com@rpath:sles-10/3.0.32_0.14-1-1
    libmsrpc=sle.rpath.com@rpath:sles-10/3.0.32_0.14-1-1
    cifs-mount=sle.rpath.com@rpath:sles-10/3.0.32_0.14-1-1

Description:
Fixed a format string vulnerability in smbclient
(CVE-2009-1886) and a ACL bypass vulnerability  in samba
(CVE-2009-1888).

Also a printing issue in KRB5 setups was fixed.


From announce-noreply@rpath.com Tue Jul 14 09:31:39 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6EDVdcQ025220
	for <sle-announce@lists.rpath.com>; Tue, 14 Jul 2009 13:31:39 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6EDVcET032039
	for <sle-announce@lists.rpath.com>; Tue, 14 Jul 2009 09:31:39 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6EDVWnZ017227;
	Tue, 14 Jul 2009 09:31:32 -0400
Date: Tue, 14 Jul 2009 09:31:32 -0400
Message-Id: <200907141331.n6EDVWnZ017227@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libpng
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 14 Jul 2009 13:31:39 -0000

Published: 2009-07-14
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    libpng=sle.rpath.com@rpath:sles-10/1.2.8_19.25-1-1

Description:
This update of libpng improves the parsing of 1-bit
interlaced images. This bug could be abused to use
"out-of-bounds pixels" to read memory. (CVE-2009-2042)


From announce-noreply@rpath.com Tue Jul 14 10:27:32 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6EERWoB025388
	for <sle-announce@lists.rpath.com>; Tue, 14 Jul 2009 14:27:32 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6EERVsg002534
	for <sle-announce@lists.rpath.com>; Tue, 14 Jul 2009 10:27:31 -0400
Received: from build01.eng.rpath.com (build01.eng.rpath.com [172.16.160.201])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6EERPhc021808;
	Tue, 14 Jul 2009 10:27:26 -0400
Date: Tue, 14 Jul 2009 10:27:25 -0400
Message-Id: <200907141427.n6EERPhc021808@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libpng
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 14 Jul 2009 14:27:32 -0000

Published: 2009-07-14
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    libpng12-0=sle.rpath.com@rpath:sles-11/1.2.31_5.12.1-1-1

Description:
This update of libpng improves the parsing of 1-bit
interlaced images. This bug could be abused to use
"out-of-bounds pixels" to read memory. (CVE-2009-2042)


References:
    https://bugzilla.novell.com/show_bug.cgi?id=514727

From announce-noreply@rpath.com Wed Jul 15 11:31:50 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6FFVool030081
	for <sle-announce@lists.rpath.com>; Wed, 15 Jul 2009 15:31:50 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6FFVnqP031661
	for <sle-announce@lists.rpath.com>; Wed, 15 Jul 2009 11:31:49 -0400
Received: from build01.eng.rpath.com (build01.eng.rpath.com [172.16.160.201])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6FFVZuK028555;
	Wed, 15 Jul 2009 11:31:35 -0400
Date: Wed, 15 Jul 2009 11:31:35 -0400
Message-Id: <200907151531.n6FFVZuK028555@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for dhcp-client
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 15 Jul 2009 15:31:50 -0000

Published: 2009-07-15
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    dhcp-client=sle.rpath.com@rpath:sles-11/3.1.1_7.13.1-1-1
    dhcp-relay=sle.rpath.com@rpath:sles-11/3.1.1_7.13.1-1-1
    dhcp-server=sle.rpath.com@rpath:sles-11/3.1.1_7.13.1-1-1
    dhcp=sle.rpath.com@rpath:sles-11/3.1.1_7.13.1-1-1

Description:
The DHCP client (dhclient) could be crashed by a malicious
DHCP server sending a overlong subnet field. (CVE-2009-0692)

In some circumstances code execution might be possible, but
might be caught by the buffer overflow checking in newer
distributions. (SLES 10 and 11).


References:
    https://bugzilla.novell.com/show_bug.cgi?id=515599

From announce-noreply@rpath.com Wed Jul 15 15:31:36 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6FJVamK030809
	for <sle-announce@lists.rpath.com>; Wed, 15 Jul 2009 19:31:36 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6FJVaH7009648
	for <sle-announce@lists.rpath.com>; Wed, 15 Jul 2009 15:31:36 -0400
Received: from build02.eng.rpath.com (build02.eng.rpath.com [172.16.160.202])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6FJVLUs014534;
	Wed, 15 Jul 2009 15:31:21 -0400
Date: Wed, 15 Jul 2009 15:31:21 -0400
Message-Id: <200907151931.n6FJVLUs014534@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libapr-util1
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 15 Jul 2009 19:31:37 -0000

Published: 2009-07-15
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    libapr-util1=sle.rpath.com@rpath:sles-11/1.3.4_12.19.1-1-1

Description:
This update of libapr-util1 fixes a memory consumption bug
in the XML parser that can cause a remote denial-of-service
vulnerability in applications using APR (WebDAV for
example) (CVE-2009-1955). Additionally a one byte buffer
overflow in function apr_brigade_vprintf() (CVE-2009-1956)
and buffer underflow in function apr_strmatch_precompile()
(CVE-2009-0023) was fixed too. Depending on the application
using this function it can lead to remote denial of service
or information leakage.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=509825

From announce-noreply@rpath.com Wed Jul 15 15:31:37 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6FJVb2H030812
	for <sle-announce@lists.rpath.com>; Wed, 15 Jul 2009 19:31:37 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6FJVaRv009649
	for <sle-announce@lists.rpath.com>; Wed, 15 Jul 2009 15:31:36 -0400
Received: from build02.eng.rpath.com (build02.eng.rpath.com [172.16.160.202])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6FJVLQI014536;
	Wed, 15 Jul 2009 15:31:21 -0400
Date: Wed, 15 Jul 2009 15:31:21 -0400
Message-Id: <200907151931.n6FJVLQI014536@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for expect
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 15 Jul 2009 19:31:37 -0000

Published: 2009-07-15
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    expect=sle.rpath.com@rpath:sles-11/5.44.1.11_1.241.1-1-1

Description:
When using expect's builtin "stty" command, a string buffer
is used internally that in some cases is one character too
small to hold the whole string.  This causes fortify to
report a buffer overflow and terminate the process. This
update corrects the buffer sizing.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=501291

From announce-noreply@rpath.com Thu Jul 16 05:35:55 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6G9ZtIb001094
	for <sle-announce@lists.rpath.com>; Thu, 16 Jul 2009 09:35:55 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6G9ZtVW009158
	for <sle-announce@lists.rpath.com>; Thu, 16 Jul 2009 05:35:55 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6G9Za5s003280;
	Thu, 16 Jul 2009 05:35:36 -0400
Date: Thu, 16 Jul 2009 05:35:36 -0400
Message-Id: <200907160935.n6G9Za5s003280@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libapr-util1
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 16 Jul 2009 09:35:56 -0000

Published: 2009-07-16
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    libapr-util1=sle.rpath.com@rpath:sles-10/1.2.2_13.7-1-1

Description:
This update of libapr-util1 fixes a memory consumption bug
in the XML parser that can cause a remote denial-of-service
vulnerability in applications using APR (WebDAV for
example) (CVE-2009-1955). Additionally a one byte buffer
overflow in function apr_brigade_vprintf() (CVE-2009-1956)
and buffer underflow in function apr_strmatch_precompile()
(CVE-2009-0023) was fixed too. Depending on the application
using this function it can lead to remote denial of service
or information leakage.


From announce-noreply@rpath.com Thu Jul 16 15:29:32 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6GJTWkG003027
	for <sle-announce@lists.rpath.com>; Thu, 16 Jul 2009 19:29:32 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6GJTWPW001408
	for <sle-announce@lists.rpath.com>; Thu, 16 Jul 2009 15:29:32 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6GJT9Vj011132;
	Thu, 16 Jul 2009 15:29:10 -0400
Date: Thu, 16 Jul 2009 15:29:09 -0400
Message-Id: <200907161929.n6GJT9Vj011132@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for bash
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 16 Jul 2009 19:29:32 -0000

Published: 2009-07-16
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    libreadline5=sle.rpath.com@rpath:sles-11/3.2_147.4.1-1-1
    bash=sle.rpath.com@rpath:sles-11/3.2_147.4.1-1-1

Description:
bash: The bash had a memory leak in its builtin read. This
bug is fixed by this update.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=510288
    https://bugzilla.novell.com/show_bug.cgi?id=476844

From announce-noreply@rpath.com Thu Jul 16 15:35:38 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6GJZbdE003052
	for <sle-announce@lists.rpath.com>; Thu, 16 Jul 2009 19:35:37 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6GJZbI1001651
	for <sle-announce@lists.rpath.com>; Thu, 16 Jul 2009 15:35:37 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6GJZFfT011610;
	Thu, 16 Jul 2009 15:35:15 -0400
Date: Thu, 16 Jul 2009 15:35:15 -0400
Message-Id: <200907161935.n6GJZFfT011610@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for bash
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 16 Jul 2009 19:35:38 -0000

Published: 2009-07-16
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    bash=sle.rpath.com@rpath:sles-10/3.1_24.23.2-1-1
    readline=sle.rpath.com@rpath:sles-10/3.1_24.23.2-1-1

Description:
bash: The bash had a memory leak in its builtin read. This
bug is fixed by this update.


From announce-noreply@rpath.com Tue Jul 21 16:11:53 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6LKBreD026353
	for <sle-announce@lists.rpath.com>; Tue, 21 Jul 2009 20:11:53 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6LKBr9c005938
	for <sle-announce@lists.rpath.com>; Tue, 21 Jul 2009 16:11:53 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6LKAnAh029449;
	Tue, 21 Jul 2009 16:10:50 -0400
Date: Tue, 21 Jul 2009 16:10:49 -0400
Message-Id: <200907212010.n6LKAnAh029449@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for PHP5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 21 Jul 2009 20:11:53 -0000

Published: 2009-07-21
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    php5-ncurses=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-xmlrpc=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-bz2=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-xmlreader=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-exif=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-xsl=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    apache2-mod_php5=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-pgsql=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-iconv=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-suhosin=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-shmop=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-tokenizer=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-gettext=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-mysql=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-pdo=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-gd=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-snmp=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-ldap=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-readline=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-curl=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-gmp=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-posix=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-ctype=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-xmlwriter=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-dbase=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-mcrypt=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-dom=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-pear=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-pspell=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-fastcgi=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-bcmath=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-openssl=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-ftp=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-json=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-sockets=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-zip=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-sysvsem=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-sqlite=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-zlib=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-odbc=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-sysvshm=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-tidy=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-calendar=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-sysvmsg=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-pcntl=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-dba=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-hash=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-mbstring=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-soap=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1
    php5-wddx=sle.rpath.com@rpath:sles-11/5.2.6_50.20.1-1-1

Description:
The  json_decode fails to work correctly after last
security update, this update fixes this problem.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=521033

From announce-noreply@rpath.com Wed Jul 22 12:57:53 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6MGvrL5030393
	for <sle-announce@lists.rpath.com>; Wed, 22 Jul 2009 16:57:53 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6MGvrop020889
	for <sle-announce@lists.rpath.com>; Wed, 22 Jul 2009 12:57:53 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6MGukmI012854;
	Wed, 22 Jul 2009 12:56:46 -0400
Date: Wed, 22 Jul 2009 12:56:46 -0400
Message-Id: <200907221656.n6MGukmI012854@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for PHP5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 22 Jul 2009 16:57:54 -0000

Published: 2009-07-22
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    php5-fastcgi=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-dbase=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-dba=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-dom=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-shmop=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-iconv=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-exif=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-sysvsem=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-calendar=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-sysvshm=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-ftp=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-sqlite=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-pdo=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-openssl=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-sockets=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-wddx=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-ctype=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-ncurses=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-soap=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-pcntl=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-sysvmsg=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-zlib=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-odbc=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-gmp=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-gettext=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-mbstring=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-xmlrpc=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-ldap=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-pear=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-bz2=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-mysql=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-tokenizer=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-posix=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-bcmath=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1
    php5-xmlreader=sle.rpath.com@rpath:sles-10/5.2.5_9.20-1-1

Description:
The  json_decode fails to work correctly after last
security update, this update fixes this problem.


From announce-noreply@rpath.com Wed Jul 29 22:35:13 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6U2ZDRZ032486
	for <sle-announce@lists.rpath.com>; Thu, 30 Jul 2009 02:35:13 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6U2ZDwv025437
	for <sle-announce@lists.rpath.com>; Wed, 29 Jul 2009 22:35:13 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6U2XA8s023467;
	Wed, 29 Jul 2009 22:33:10 -0400
Date: Wed, 29 Jul 2009 22:33:10 -0400
Message-Id: <200907300233.n6U2XA8s023467@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for util-linux
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 30 Jul 2009 02:35:13 -0000

Published: 2009-07-29
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    util-linux=sle.rpath.com@rpath:sles-10/2.12r_35.35.2-1-1

Description:
util-linux: Problems with "mount" fixed by this update.
These two bugs were fixed: Bug 494809 - failed to umount
"/" during reboot or shutdown after installation of
util-linux Bug 491140 - mount ignores "proto=" for "nfs"


From announce-noreply@rpath.com Thu Jul 30 13:10:10 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6UHAARK003178
	for <sle-announce@lists.rpath.com>; Thu, 30 Jul 2009 17:10:10 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6UHAAe0028328
	for <sle-announce@lists.rpath.com>; Thu, 30 Jul 2009 13:10:10 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6UH82Dm017765;
	Thu, 30 Jul 2009 13:08:03 -0400
Date: Thu, 30 Jul 2009 13:08:02 -0400
Message-Id: <200907301708.n6UH82Dm017765@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for bind
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 30 Jul 2009 17:10:10 -0000

Published: 2009-07-30
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    bind-utils=sle.rpath.com@rpath:sles-11/9.5.0P2_20.3.1-1-1
    bind=sle.rpath.com@rpath:sles-11/9.5.0P2_20.3.1-1-1
    bind-chrootenv=sle.rpath.com@rpath:sles-11/9.5.0P2_20.3.1-1-1

Description:
- #488599: bind DNSSEC Lookaside Validation problem
- mount /proc into chroot environment to support multi CPU
  systems (bnc#470828)
- key names with spaces are allowed by genDDNSkey now
  (bnc#459739)
- a missing /etc/named.conf.include could lead to an error
  while "restart" (bnc#455888)
- /etc/named.conf does not include
  /etc/named.d/forwarders.conf by default (bnc#480334)


References:
    https://bugzilla.novell.com/show_bug.cgi?id=488599
    https://bugzilla.novell.com/show_bug.cgi?id=470828
    https://bugzilla.novell.com/show_bug.cgi?id=459739
    https://bugzilla.novell.com/show_bug.cgi?id=455888
    https://bugzilla.novell.com/show_bug.cgi?id=480334

From announce-noreply@rpath.com Thu Jul 30 16:10:57 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n6UKAvPB004712
	for <sle-announce@lists.rpath.com>; Thu, 30 Jul 2009 20:10:57 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n6UKAvK3006267
	for <sle-announce@lists.rpath.com>; Thu, 30 Jul 2009 16:10:57 -0400
Received: from build01.eng.rpath.com (build01.eng.rpath.com [172.16.160.201])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n6UK8mme029794;
	Thu, 30 Jul 2009 16:08:49 -0400
Date: Thu, 30 Jul 2009 16:08:49 -0400
Message-Id: <200907302008.n6UK8mme029794@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for bind
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 30 Jul 2009 20:10:58 -0000

Published: 2009-07-30
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    bind-chrootenv=sle.rpath.com@rpath:sles-10/9.3.4_1.29-1-1
    bind=sle.rpath.com@rpath:sles-10/9.3.4_1.29-1-1
    bind-utils=sle.rpath.com@rpath:sles-10/9.3.4_1.29-1-1

Description:
Specially crafted ddns update packets could trigger an
exception in bind causing it to exit. The attack works if
BIND is master for a zone even if ddns is not configured
(CVE-2009-0696).


From announce-noreply@rpath.com Thu Aug  6 11:05:40 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n76F5ev0005144
	for <sle-announce@lists.rpath.com>; Thu, 6 Aug 2009 15:05:40 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n76F5exJ026398
	for <sle-announce@lists.rpath.com>; Thu, 6 Aug 2009 11:05:40 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n76F2eiT027661;
	Thu, 6 Aug 2009 11:02:40 -0400
Date: Thu, 6 Aug 2009 11:02:40 -0400
Message-Id: <200908061502.n76F2eiT027661@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for LVM2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 06 Aug 2009 15:05:40 -0000

Published: 2009-08-06
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    lvm2=sle.rpath.com@rpath:sles-11/2.02.39_18.8.1-1-1

Description:
Fix mkinitrd hang during installing new kernel (bnc#510058)
when using LVM2.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=510058

From announce-noreply@rpath.com Tue Aug 11 10:47:03 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n7BEl3bQ029329
	for <sle-announce@lists.rpath.com>; Tue, 11 Aug 2009 14:47:03 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n7BEl3tA013322
	for <sle-announce@lists.rpath.com>; Tue, 11 Aug 2009 10:47:03 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n7BEhPOs031659;
	Tue, 11 Aug 2009 10:43:25 -0400
Date: Tue, 11 Aug 2009 10:43:25 -0400
Message-Id: <200908111443.n7BEhPOs031659@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libxml2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 11 Aug 2009 14:47:03 -0000

Published: 2009-08-11
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    libxml2=sle.rpath.com@rpath:sles-10/2.6.23_15.20-1-1

Description:
This update of libxml2 does not use pointers after they
were freed anymore. (CVE-2009-2416)


From announce-noreply@rpath.com Thu Aug 13 11:24:39 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n7DFOdri006173
	for <sle-announce@lists.rpath.com>; Thu, 13 Aug 2009 15:24:39 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n7DFOd2T013983
	for <sle-announce@lists.rpath.com>; Thu, 13 Aug 2009 11:24:39 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n7DFKkj3010288;
	Thu, 13 Aug 2009 11:20:46 -0400
Date: Thu, 13 Aug 2009 11:20:46 -0400
Message-Id: <200908131520.n7DFKkj3010288@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for wget
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 13 Aug 2009 15:24:39 -0000

Published: 2009-08-13
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    wget=sle.rpath.com@rpath:sles-11/1.11.4_1.15.1-1-1

Description:
This update wget improves the handling of the  0-character
in the subject name of a SSL certificate.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=528298

From announce-noreply@rpath.com Thu Aug 13 12:26:26 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n7DGQQ7P006378
	for <sle-announce@lists.rpath.com>; Thu, 13 Aug 2009 16:26:26 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n7DGQPs0016196
	for <sle-announce@lists.rpath.com>; Thu, 13 Aug 2009 12:26:25 -0400
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n7DGMWFd014415;
	Thu, 13 Aug 2009 12:22:32 -0400
Date: Thu, 13 Aug 2009 12:22:32 -0400
Message-Id: <200908131622.n7DGMWFd014415@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for wget
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 13 Aug 2009 16:26:26 -0000

Published: 2009-08-13
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    wget=sle.rpath.com@rpath:sles-10/1.10.2_15.11-1-1

Description:
This update wget improves the handling of the  0-character
in the subject name of a SSL certificate.


From announce-noreply@rpath.com Mon Aug 17 07:29:41 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n7HBTfRb023714
	for <sle-announce@lists.rpath.com>; Mon, 17 Aug 2009 11:29:41 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n7HBTet6019972
	for <sle-announce@lists.rpath.com>; Mon, 17 Aug 2009 07:29:40 -0400
Received: from build02.eng.rpath.com (build02.eng.rpath.com [172.16.160.202])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n7HBPIcb014156;
	Mon, 17 Aug 2009 07:25:18 -0400
Date: Mon, 17 Aug 2009 07:25:18 -0400
Message-Id: <200908171125.n7HBPIcb014156@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for curl
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 17 Aug 2009 11:29:41 -0000

Published: 2009-08-17
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    curl=sle.rpath.com@rpath:sles-11/7.19.0_11.22.1-1-1

Description:
This update of libcurl2 fixes the 0-character handling in
the subject name of a SSL certificate. This bug could be
used to execute an undetected man-in-the-middle-attack.
(CVE-2009-2417)


References:
    https://bugzilla.novell.com/show_bug.cgi?id=527990

From announce-noreply@rpath.com Mon Aug 17 14:38:20 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n7HIcJHh025155
	for <sle-announce@lists.rpath.com>; Mon, 17 Aug 2009 18:38:19 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n7HIcJK7001613
	for <sle-announce@lists.rpath.com>; Mon, 17 Aug 2009 14:38:19 -0400
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n7HIXtHx008098;
	Mon, 17 Aug 2009 14:33:56 -0400
Date: Mon, 17 Aug 2009 14:33:55 -0400
Message-Id: <200908171833.n7HIXtHx008098@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for curl
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 17 Aug 2009 18:38:20 -0000

Published: 2009-08-17
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    curl=sle.rpath.com@rpath:sles-10/7.15.1_19.14.2-1-1

Description:
This update of libcurl2 fixes the 0-character handling in
the subject name of a SSL certificate. This bug could be
used to execute an undetected man-in-the-middle-attack.
(CVE-2009-2417)


From announce-noreply@rpath.com Mon Aug 17 14:38:20 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n7HIcKIu025158
	for <sle-announce@lists.rpath.com>; Mon, 17 Aug 2009 18:38:20 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n7HIcJgc001614
	for <sle-announce@lists.rpath.com>; Mon, 17 Aug 2009 14:38:19 -0400
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n7HIXuj5008100;
	Mon, 17 Aug 2009 14:33:56 -0400
Date: Mon, 17 Aug 2009 14:33:56 -0400
Message-Id: <200908171833.n7HIXuj5008100@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for file
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 17 Aug 2009 18:38:20 -0000

Published: 2009-08-17
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    file=sle.rpath.com@rpath:sles-10/4.21_47.4.2-1-1

Description:
Some PDFs will not be determine by the file command of file
4.16 caused by to many false positives within the magic
formats. The newer file command of file 4.21 can handle
this more reliable.


From announce-noreply@rpath.com Wed Aug 19 08:24:50 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n7JCOohw000992
	for <sle-announce@lists.rpath.com>; Wed, 19 Aug 2009 12:24:50 GMT
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n7JCOo9O012364
	for <sle-announce@lists.rpath.com>; Wed, 19 Aug 2009 08:24:50 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n7JCOnEO014808;
	Wed, 19 Aug 2009 08:24:50 -0400
Date: Wed, 19 Aug 2009 08:24:49 -0400
Message-Id: <200908191224.n7JCOnEO014808@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libtiff
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 19 Aug 2009 12:24:51 -0000

Published: 2009-08-19
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    tiff=sle.rpath.com@rpath:sles-11/3.8.2_141.8.1-1-1

Description:
This update of the tiff package fixes various integer
overflows in the tools. (CVE-2009-2347)


References:
    https://bugzilla.novell.com/show_bug.cgi?id=519796

From announce-noreply@rpath.com Tue Aug 25 14:36:26 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n7PIaPj8009586
	for <sle-announce@lists.rpath.com>; Tue, 25 Aug 2009 14:36:25 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n7PIaPFh006920
	for <sle-announce@lists.rpath.com>; Tue, 25 Aug 2009 14:36:25 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n7PIaPrk009473;
	Tue, 25 Aug 2009 14:36:25 -0400
Date: Tue, 25 Aug 2009 14:36:25 -0400
Message-Id: <200908251836.n7PIaPrk009473@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for MySQL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 25 Aug 2009 18:36:26 -0000

Published: 2009-08-25
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    mysql-client=sle.rpath.com@rpath:sles-10/5.0.26_12.24.2-1-1
    mysql=sle.rpath.com@rpath:sles-10/5.0.26_12.24.2-1-1
    mysql-Max=sle.rpath.com@rpath:sles-10/5.0.26_12.24.2-1-1
    mysql-shared=sle.rpath.com@rpath:sles-10/5.0.26_12.24.2-1-1

Description:
- the COM_CREATE_DB and COM_DROP_DB suffered from format
  string vulnerabilities (CVE-2009-2446)

- the command line client was prone to cross-site scripting
  (XSS) attacks (CVE-2008-4456)

Additionally a problem that sometimes prevented slave hosts
from reconnecting to the master server has been fixed.


From announce-noreply@rpath.com Wed Aug 26 09:29:33 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n7QDTXj2012999
	for <sle-announce@lists.rpath.com>; Wed, 26 Aug 2009 09:29:33 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n7QDTXD2008546
	for <sle-announce@lists.rpath.com>; Wed, 26 Aug 2009 09:29:33 -0400
Received: from build02.eng.rpath.com (build02.eng.rpath.com [172.16.160.202])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n7QDTWk9008857;
	Wed, 26 Aug 2009 09:29:32 -0400
Date: Wed, 26 Aug 2009 09:29:32 -0400
Message-Id: <200908261329.n7QDTWk9008857@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for glib2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 26 Aug 2009 13:29:33 -0000

Published: 2009-08-26
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    libglib-2_0-0=sle.rpath.com@rpath:sles-11/2.18.2_7.8.1-1-1
    libgmodule-2_0-0=sle.rpath.com@rpath:sles-11/2.18.2_7.8.1-1-1
    libgio-2_0-0=sle.rpath.com@rpath:sles-11/2.18.2_7.8.1-1-1
    glib2=sle.rpath.com@rpath:sles-11/2.18.2_7.8.1-1-1
    glib2-lang=sle.rpath.com@rpath:sles-11/2.18.2_7.8.1-1-1
    libgobject-2_0-0=sle.rpath.com@rpath:sles-11/2.18.2_7.8.1-1-1
    libgthread-2_0-0=sle.rpath.com@rpath:sles-11/2.18.2_7.8.1-1-1

Description:
Large strings could lead to a heap overflow in the base64
encoding and decoding functions. Attackers could
potentially exploit that to execute arbitrary code
(CVE-2008-4316).


References:
    https://bugzilla.novell.com/show_bug.cgi?id=449927

From announce-noreply@rpath.com Wed Aug 26 17:29:00 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n7QLT04j014541
	for <sle-announce@lists.rpath.com>; Wed, 26 Aug 2009 17:29:00 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n7QLT0fg027020
	for <sle-announce@lists.rpath.com>; Wed, 26 Aug 2009 17:29:00 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n7QLT00m007542;
	Wed, 26 Aug 2009 17:29:00 -0400
Date: Wed, 26 Aug 2009 17:29:00 -0400
Message-Id: <200908262129.n7QLT00m007542@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for mkinitrd
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 26 Aug 2009 21:29:01 -0000

Published: 2009-08-26
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    mkinitrd=sle.rpath.com@rpath:sles-10/1.2_106.86.3-1-1

Description:
check for iSCSI if root is found by LABEL (bnc#508105)
Include MPIO only if it is needed (bnc#414267) Return 1 if
bogus arguments for -k or -i are given (bnc#499950) Fix
boot from iSCSI (bnc#518355) Use correct multipath bindings
file (bnc#500785) Support large minor numbers (bnc#503242)


From announce-noreply@rpath.com Fri Aug 28 23:21:35 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n7T3LZ05024841
	for <sle-announce@lists.rpath.com>; Fri, 28 Aug 2009 23:21:35 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n7T3LZZS032468
	for <sle-announce@lists.rpath.com>; Fri, 28 Aug 2009 23:21:35 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n7T3LYiR030724;
	Fri, 28 Aug 2009 23:21:34 -0400
Date: Fri, 28 Aug 2009 23:21:34 -0400
Message-Id: <200908290321.n7T3LYiR030724@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for CVS
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Sat, 29 Aug 2009 03:21:35 -0000

Published: 2009-08-28
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    cvs=sle.rpath.com@rpath:sles-10/1.12.12_19.4.2-1-1

Description:
- #491633: cvs causing segfault


From announce-noreply@rpath.com Sun Sep 20 20:30:45 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n8L0Ujeu000871
	for <sle-announce@lists.rpath.com>; Sun, 20 Sep 2009 20:30:45 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n8L0UjdV030683
	for <sle-announce@lists.rpath.com>; Sun, 20 Sep 2009 20:30:45 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n8L0UiBj003128;
	Sun, 20 Sep 2009 20:30:44 -0400
Date: Sun, 20 Sep 2009 20:30:44 -0400
Message-Id: <200909210030.n8L0UiBj003128@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for GnuTLS
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 21 Sep 2009 00:30:46 -0000

Published: 2009-09-20
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    gnutls=sle.rpath.com@rpath:sles-11/2.4.1_24.19.1-1-1

Description:
This update of gnutls improves the verification of the
domain/subject names in a SSL certificate. CVE-2009-2730
has been assigned to this issue.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=528372

From announce-noreply@rpath.com Mon Sep 21 09:21:10 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n8LDLAdf003181
	for <sle-announce@lists.rpath.com>; Mon, 21 Sep 2009 09:21:10 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n8LDLA47023433
	for <sle-announce@lists.rpath.com>; Mon, 21 Sep 2009 09:21:10 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n8LDL9Lp014926;
	Mon, 21 Sep 2009 09:21:10 -0400
Date: Mon, 21 Sep 2009 09:21:09 -0400
Message-Id: <200909211321.n8LDL9Lp014926@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenLDAP2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 21 Sep 2009 13:21:10 -0000

Published: 2009-09-21
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    openldap2-client=sle.rpath.com@rpath:sles-11/2.4.12_7.18.1-2-1
    libldap-2_4-2=sle.rpath.com@rpath:sles-11/2.4.12_7.18.1-2-1

Description:
This update of openldap2 makes SSL certificate verification
more robust against uses of the special character \0 in the
subjects name. (CVE-2009-2408)


References:
    https://bugzilla.novell.com/show_bug.cgi?id=537143

From announce-noreply@rpath.com Mon Sep 21 18:21:40 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n8LMLeXX004999
	for <sle-announce@lists.rpath.com>; Mon, 21 Sep 2009 18:21:40 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n8LMLe3Z009903
	for <sle-announce@lists.rpath.com>; Mon, 21 Sep 2009 18:21:40 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n8LMLeWZ016402;
	Mon, 21 Sep 2009 18:21:40 -0400
Date: Mon, 21 Sep 2009 18:21:40 -0400
Message-Id: <200909212221.n8LMLeWZ016402@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenLDAP2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 21 Sep 2009 22:21:40 -0000

Published: 2009-09-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    openldap2-client=sle.rpath.com@rpath:sles-10/2.3.32_0.33.2-1-1

Description:
This update of openldap2 makes SSL certificate verification
more robust against uses of the special character \0 in the
subjects name. (CVE-2009-2408)


From announce-noreply@rpath.com Mon Sep 28 12:46:38 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n8SGkcVY002034
	for <sle-announce@lists.rpath.com>; Mon, 28 Sep 2009 12:46:38 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n8SGkc4R014608
	for <sle-announce@lists.rpath.com>; Mon, 28 Sep 2009 12:46:38 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n8SGkbjH028420;
	Mon, 28 Sep 2009 12:46:37 -0400
Date: Mon, 28 Sep 2009 12:46:37 -0400
Message-Id: <200909281646.n8SGkbjH028420@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for PostgreSQL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 28 Sep 2009 16:46:39 -0000

Published: 2009-09-28
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    postgresql-server=sle.rpath.com@rpath:sles-11/8.3.8_0.1.1-1-1
    postgresql=sle.rpath.com@rpath:sles-11/8.3.8_0.1.1-1-1
    postgresql-contrib=sle.rpath.com@rpath:sles-11/8.3.8_0.1.1-1-1

Description:
Multiple security vulnerabilities have been fixed in
PostgrSQL
- CVE-2009-3229: allows remote authenticated users to cause
  a denial of service
- CVE-2009-3230: allows remote authenticated users to gain
  higher privileges
- CVE-2009-3231: when using LDAP authentication with
  anonymous binds, allows remote attackers to bypass
  authentication via an empty password


References:
    https://bugzilla.novell.com/show_bug.cgi?id=537706

From announce-noreply@rpath.com Wed Sep 30 14:09:57 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n8UI9uLx011158
	for <sle-announce@lists.rpath.com>; Wed, 30 Sep 2009 14:09:56 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n8UI9uX8004435
	for <sle-announce@lists.rpath.com>; Wed, 30 Sep 2009 14:09:56 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n8UI9uvM031975;
	Wed, 30 Sep 2009 14:09:56 -0400
Date: Wed, 30 Sep 2009 14:09:56 -0400
Message-Id: <200909301809.n8UI9uvM031975@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for glibc
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 30 Sep 2009 18:09:57 -0000

Published: 2009-09-30
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    glibc-profile=sle.rpath.com@rpath:sles-11/2.9_13.3.1-2-1
    glibc=sle.rpath.com@rpath:sles-11/2.9_13.3.1-2-1
    nscd=sle.rpath.com@rpath:sles-11/2.9_13.3.1-2-1

Description:
- Fix nscd handling of zero negative timeout for some
  databases; this would create various database
  inconsistencies and triggered major locking problems
- Replace the nscd mem-in-flight handling with simpler
  bookkeeping; this fixes various crashes during database
  garbage collection
- Fix invalid pointer handling in some nscd assertions and
  the code to send data to the client; this fixes nscd
  crashing with various assertion failures during request
  handling

- Fix SHA256, SHA512 crypt() support (it was not accessible
  due to the Blowfish support patch)
- Fix few race conditions in the malloc() allocator
- Raise utmp locking timeout from 1s to 30s to ensure
  logins get recorded even on systems under extreme load
- Add SHM_EXEC flag to <bits/shm.h>


References:
    https://bugzilla.novell.com/show_bug.cgi?id=529495
    https://bugzilla.novell.com/show_bug.cgi?id=508081
    https://bugzilla.novell.com/show_bug.cgi?id=523154
    https://bugzilla.novell.com/show_bug.cgi?id=523170
    https://bugzilla.novell.com/show_bug.cgi?id=505215
    https://bugzilla.novell.com/show_bug.cgi?id=474021
    https://bugzilla.novell.com/show_bug.cgi?id=486631
    https://bugzilla.novell.com/show_bug.cgi?id=513617

From announce-noreply@rpath.com Thu Oct  1 15:25:24 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n91JPNIe017083
	for <sle-announce@lists.rpath.com>; Thu, 1 Oct 2009 15:25:23 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n91JPNj5018359
	for <sle-announce@lists.rpath.com>; Thu, 1 Oct 2009 15:25:23 -0400
Received: from build02.eng.rpath.com (build02.eng.rpath.com [172.16.160.202])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n91JPNK8020512;
	Thu, 1 Oct 2009 15:25:23 -0400
Date: Thu, 1 Oct 2009 15:25:23 -0400
Message-Id: <200910011925.n91JPNK8020512@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for lvm2 and mkinitrd
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 01 Oct 2009 19:25:24 -0000

Published: 2009-10-01
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    mkinitrd=sle.rpath.com@rpath:sles-10/1.2_106.86.5-1-1    lvm2=sle.rpath.com@rpath:sles-10/2.02.17_7.24.2-1-1

Description:


From announce-noreply@rpath.com Fri Oct  9 15:55:15 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n99JtF2J019657
	for <sle-announce@lists.rpath.com>; Fri, 9 Oct 2009 15:55:15 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n99JtFVu013980
	for <sle-announce@lists.rpath.com>; Fri, 9 Oct 2009 15:55:15 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n99JtFWE013955;
	Fri, 9 Oct 2009 15:55:15 -0400
Date: Fri, 9 Oct 2009 15:55:15 -0400
Message-Id: <200910091955.n99JtFWE013955@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for sysconfig
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 09 Oct 2009 19:55:16 -0000

Published: 2009-10-09
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    sysconfig=sle.rpath.com@rpath:sles-11/0.71.14_12.5.1-1-1

Description:
The following bugs are fixed by this update: Bug 542230:
Fixed typo in ifstatus causing to return bad code. Bug
537052: Blacklisted mISDN modules in
/etc/modprobe.d/50-blacklist.conf Bug 541035: Fixed to just
reload bind instead of try-restart in netconfig to avoid
failures in another services. Bug 515629: Fixed waiting for
successful connection in NetworkManager in the
/etc/init.d/network script by removing nm-online's --exit
option, that caused to exit immediately instead of waiting
up to NM_ONLINE_TIMEOUT seconds, because the NetworkManager
has  been started just now and not ready yet. Bug 522225:
Marked tap interfaces as supported in rcnetwork localfs
flow, to start a bridge with tap port in localfs flow. Bug
524691: Fixed dhclient6 variable typos in ifup-dhcp. Bug
528759: Fixed spec file to remove the
HOTPLUG_CHECK_FILESYSTEMS and HOTPLUG_MOUNT_FSTAB variables
from /etc/sysconfig/storage instead of removing of the
complete file. Bug 524695: Added additional dhcp client
specific start options variables DHCPCD-, DHCLIENT- and
DHCP6C_USER_OPTIONS, enabling the user to set custom
options in special cases (e.g. for TAHI tests). Bug 509495:
Fixed udev 81-mount.rules to allow md devices on iscsi to
automount.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=509495
    https://bugzilla.novell.com/show_bug.cgi?id=515629
    https://bugzilla.novell.com/show_bug.cgi?id=522225
    https://bugzilla.novell.com/show_bug.cgi?id=524691
    https://bugzilla.novell.com/show_bug.cgi?id=524695
    https://bugzilla.novell.com/show_bug.cgi?id=528759
    https://bugzilla.novell.com/show_bug.cgi?id=541035
    https://bugzilla.novell.com/show_bug.cgi?id=542230
    https://bugzilla.novell.com/show_bug.cgi?id=537052

From announce-noreply@rpath.com Wed Oct 14 22:26:14 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n9F2QDql009397
	for <sle-announce@lists.rpath.com>; Wed, 14 Oct 2009 22:26:13 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n9F2QDH8017580
	for <sle-announce@lists.rpath.com>; Wed, 14 Oct 2009 22:26:13 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n9F2QDAw003321;
	Wed, 14 Oct 2009 22:26:13 -0400
Date: Wed, 14 Oct 2009 22:26:13 -0400
Message-Id: <200910150226.n9F2QDAw003321@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for mdadm
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 15 Oct 2009 02:26:14 -0000

Published: 2009-10-14
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    mdadm=sle.rpath.com@rpath:sles-11/3.0_18.2.1-1-1

Description:
The mdadm tool was fixed to read raid metatada on devices
with 4096 sector size, such as dasd.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=466172

From announce-noreply@rpath.com Thu Oct 15 14:23:33 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n9FINXkD012492
	for <sle-announce@lists.rpath.com>; Thu, 15 Oct 2009 14:23:33 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n9FINXLc008730
	for <sle-announce@lists.rpath.com>; Thu, 15 Oct 2009 14:23:33 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n9FINXnv023324;
	Thu, 15 Oct 2009 14:23:33 -0400
Date: Thu, 15 Oct 2009 14:23:33 -0400
Message-Id: <200910151823.n9FINXnv023324@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for libusb
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 15 Oct 2009 18:23:33 -0000

Published: 2009-10-15
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    libusb-0_1-4=sle.rpath.com@rpath:sles-11/0.1.12_139.1.1-1-1
    libusb=sle.rpath.com@rpath:sles-11/0.1.12_139.1.1-1-1
    libusbpp-0_1-4=sle.rpath.com@rpath:sles-11/0.1.12_139.1.1-1-1

Description:
libusb: Instead of using standard library dependencies,
several third party packages depend on symbol "libusb". But
the libusb package was split according to shared library
packaging policy. "libusb" does not exist any more, and
installation of these third party packages fail. This
update just adds the needed symbol.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=519311

From announce-noreply@rpath.com Fri Oct 16 10:53:10 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n9GErAiw016160
	for <sle-announce@lists.rpath.com>; Fri, 16 Oct 2009 10:53:10 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n9GEr9p8006529
	for <sle-announce@lists.rpath.com>; Fri, 16 Oct 2009 10:53:10 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n9GEr9Vv025680;
	Fri, 16 Oct 2009 10:53:09 -0400
Date: Fri, 16 Oct 2009 10:53:09 -0400
Message-Id: <200910161453.n9GEr9Vv025680@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for PHP5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 16 Oct 2009 14:53:10 -0000

Published: 2009-10-16
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    apache2-mod_php5=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-readline=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-tidy=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-sysvshm=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-iconv=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-snmp=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-json=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-pear=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-posix=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-pspell=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-wddx=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-gmp=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-suhosin=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-bcmath=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-sysvmsg=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-calendar=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-sockets=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-ncurses=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-ftp=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-mysql=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-bz2=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-soap=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-pdo=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-mbstring=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-fastcgi=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-sysvsem=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-zip=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-pgsql=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-tokenizer=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-xmlwriter=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-ctype=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-xsl=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-gd=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-exif=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-sqlite=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-dba=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-xmlreader=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-hash=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-xmlrpc=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-mcrypt=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-dbase=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-ldap=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-shmop=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-openssl=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-gettext=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-curl=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-dom=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-pcntl=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-zlib=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1
    php5-odbc=sle.rpath.com@rpath:sles-11/5.2.6_50.23.1-1-1

Description:
Multiple issues have been fixed in php5:
- php_openssl_apply_verification_policy() fails to verify
  certificate (CVE-2009-3291)
- "missing sainity checks around exif" (CVE-2009-3292)
- unspecified vulnerability in the imagecolortransparent()
  (CVE-2009-3293)
- denial of service in exif module (CVE-2009-2687)
  Additionally we fixed:
- xmlparse was broken
- read_exif_data() only returns the first letter of UTF-16
  strings


References:
    https://bugzilla.novell.com/show_bug.cgi?id=540242

From announce-noreply@rpath.com Mon Oct 19 14:36:30 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n9JIaUrQ029558
	for <sle-announce@lists.rpath.com>; Mon, 19 Oct 2009 14:36:30 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n9JIaUuH007209
	for <sle-announce@lists.rpath.com>; Mon, 19 Oct 2009 14:36:30 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n9JIaU66015098;
	Mon, 19 Oct 2009 14:36:30 -0400
Date: Mon, 19 Oct 2009 14:36:30 -0400
Message-Id: <200910191836.n9JIaU66015098@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for PHP5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 19 Oct 2009 18:36:31 -0000

Published: 2009-10-19
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    php5-pcntl=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-sysvmsg=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-calendar=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-exif=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-iconv=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-dom=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-pdo=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-mysql=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-gettext=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-bz2=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-xmlrpc=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-bcmath=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-ftp=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-tokenizer=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-openssl=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-sockets=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-ctype=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-sqlite=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-mbstring=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-zlib=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-fastcgi=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-soap=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-pear=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-dba=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-dbase=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-xmlreader=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-wddx=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-sysvsem=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-ldap=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-shmop=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-odbc=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-gmp=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-posix=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-sysvshm=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1
    php5-ncurses=sle.rpath.com@rpath:sles-10/5.2.5_9.22-1-1

Description:
Multiple issues have been fixed in php5:
- php_openssl_apply_verification_policy() fails to verify
  certificate (CVE-2009-3291)
- "missing sainity checks around exif" (CVE-2009-3292)
- unspecified vulnerability in the imagecolortransparent()
  (CVE-2009-3293)
- denial of service in exif module (CVE-2009-2687)
  Additionally we fixed:
- xmlparse was broken
- read_exif_data() only returns the first letter of UTF-16
  strings


From announce-noreply@rpath.com Thu Oct 22 16:37:20 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n9MKbKfV010878
	for <sle-announce@lists.rpath.com>; Thu, 22 Oct 2009 16:37:20 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n9MKbJGd015771
	for <sle-announce@lists.rpath.com>; Thu, 22 Oct 2009 16:37:19 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n9MKbJHL032191;
	Thu, 22 Oct 2009 16:37:19 -0400
Date: Thu, 22 Oct 2009 16:37:19 -0400
Message-Id: <200910222037.n9MKbJHL032191@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Samba
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 22 Oct 2009 20:37:20 -0000

Published: 2009-10-22
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    samba-krb-printing=sle.rpath.com@rpath:sles-11/3.2.7_11.8.2-1-1
    ldapsmb=sle.rpath.com@rpath:sles-11/3.2.7_11.8.2-1-1
    libtdb1=sle.rpath.com@rpath:sles-11/3.2.7_11.8.2-1-1
    samba=sle.rpath.com@rpath:sles-11/3.2.7_11.8.2-1-1
    libtalloc1=sle.rpath.com@rpath:sles-11/3.2.7_11.8.2-1-1
    samba-client=sle.rpath.com@rpath:sles-11/3.2.7_11.8.2-1-1
    libsmbsharemodes0=sle.rpath.com@rpath:sles-11/3.2.7_11.8.2-1-1
    libnetapi0=sle.rpath.com@rpath:sles-11/3.2.7_11.8.2-1-1
    libsmbclient0=sle.rpath.com@rpath:sles-11/3.2.7_11.8.2-1-1
    libwbclient0=sle.rpath.com@rpath:sles-11/3.2.7_11.8.2-1-1
    cifs-mount=sle.rpath.com@rpath:sles-11/3.2.7_11.8.2-1-1
    samba-winbind=sle.rpath.com@rpath:sles-11/3.2.7_11.8.2-1-1

Description:
samba's make_connection_snum() handles certain input
incorrectly, which may lead to disclosure of the root
directory. CVE-2009-2813 has been assigned to this issue.
Additionally an information disclosure vulnerability in
mount.cifs has been fixed (CVE-2009-2948) as well as a DoS
condition (CVE-2009-2906).


References:
    https://bugzilla.novell.com/show_bug.cgi?id=539517

From announce-noreply@rpath.com Thu Oct 22 16:37:20 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n9MKbKTM010879
	for <sle-announce@lists.rpath.com>; Thu, 22 Oct 2009 16:37:20 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n9MKbJ8Z015772
	for <sle-announce@lists.rpath.com>; Thu, 22 Oct 2009 16:37:19 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n9MKbJ5a032194;
	Thu, 22 Oct 2009 16:37:19 -0400
Date: Thu, 22 Oct 2009 16:37:19 -0400
Message-Id: <200910222037.n9MKbJ5a032194@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libapr-util1
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 22 Oct 2009 20:37:20 -0000

Published: 2009-10-22
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    libapr-util1=sle.rpath.com@rpath:sles-11/1.3.4_12.20.2-1-1

Description:
This update of libapr-util1 fixes a memory consumption bug
in the XML parser that can cause a remote denial-of-service
vulnerability in applications using APR (WebDAV for
example) (CVE-2009-1955). Additionally a one byte buffer
overflow in function apr_brigade_vprintf() (CVE-2009-1956)
and buffer underflow in function apr_strmatch_precompile()
(CVE-2009-0023) was fixed too. Depending on the application
using this function it can lead to remote denial of service
or information leakage.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=509825

From announce-noreply@rpath.com Thu Oct 22 16:37:20 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n9MKbKbX010883
	for <sle-announce@lists.rpath.com>; Thu, 22 Oct 2009 16:37:20 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n9MKbKD5015773
	for <sle-announce@lists.rpath.com>; Thu, 22 Oct 2009 16:37:20 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n9MKbJfM032197;
	Thu, 22 Oct 2009 16:37:19 -0400
Date: Thu, 22 Oct 2009 16:37:19 -0400
Message-Id: <200910222037.n9MKbJfM032197@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libapr
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 22 Oct 2009 20:37:20 -0000

Published: 2009-10-22
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    libapr1=sle.rpath.com@rpath:sles-11/1.3.3_11.16.1-1-1

Description:
This update of libapr-util1 and libapr1 fixes multiple
integer overflows that could probably be used to execute
arbitrary code remotely. (CVE-2009-2412)


References:
    https://bugzilla.novell.com/show_bug.cgi?id=529591

From announce-noreply@rpath.com Thu Oct 22 20:37:51 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n9N0bpjc011717
	for <sle-announce@lists.rpath.com>; Thu, 22 Oct 2009 20:37:51 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n9N0bos9020741
	for <sle-announce@lists.rpath.com>; Thu, 22 Oct 2009 20:37:50 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n9N0boYu010599;
	Thu, 22 Oct 2009 20:37:50 -0400
Date: Thu, 22 Oct 2009 20:37:50 -0400
Message-Id: <200910230037.n9N0boYu010599@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Samba
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 23 Oct 2009 00:37:51 -0000

Published: 2009-10-22
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    samba-vscan=sle.rpath.com@rpath:sles-10/3.0.32_0.16-1-1
    samba-krb-printing=sle.rpath.com@rpath:sles-10/3.0.32_0.16-1-1
    samba-python=sle.rpath.com@rpath:sles-10/3.0.32_0.16-1-1
    libmsrpc=sle.rpath.com@rpath:sles-10/3.0.32_0.16-1-1
    cifs-mount=sle.rpath.com@rpath:sles-10/3.0.32_0.16-1-1
    samba-winbind=sle.rpath.com@rpath:sles-10/3.0.32_0.16-1-1
    samba-client=sle.rpath.com@rpath:sles-10/3.0.32_0.16-1-1
    libsmbclient=sle.rpath.com@rpath:sles-10/3.0.32_0.16-1-1

Description:
samba's make_connection_snum() handles certain input
incorrectly, which may lead to disclosure of the root
directory. CVE-2009-2813 has been assigned to this issue.
Additionally an information disclosure vulnerability in
mount.cifs has been fixed (CVE-2009-2948) as well as a DoS
condition (CVE-2009-2906).


From announce-noreply@rpath.com Thu Oct 22 20:37:51 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n9N0bpvV011718
	for <sle-announce@lists.rpath.com>; Thu, 22 Oct 2009 20:37:51 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n9N0bo56020742
	for <sle-announce@lists.rpath.com>; Thu, 22 Oct 2009 20:37:51 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n9N0boZT010601;
	Thu, 22 Oct 2009 20:37:50 -0400
Date: Thu, 22 Oct 2009 20:37:50 -0400
Message-Id: <200910230037.n9N0boZT010601@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libapr
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 23 Oct 2009 00:37:51 -0000

Published: 2009-10-22
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    libapr1=sle.rpath.com@rpath:sles-10/1.2.2_13.8.2-1-1    libapr-util1=sle.rpath.com@rpath:sles-10/1.2.2_13.10.1-1-1

Description:
This update of libapr-util1 and libapr1 fixes multiple
integer overflows that could probably be used to execute
arbitrary code remotely. (CVE-2009-2412)


From announce-noreply@rpath.com Fri Oct 23 16:33:44 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n9NKXiv3015405
	for <sle-announce@lists.rpath.com>; Fri, 23 Oct 2009 16:33:44 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n9NKXi29017824
	for <sle-announce@lists.rpath.com>; Fri, 23 Oct 2009 16:33:44 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n9NKXh2u008157;
	Fri, 23 Oct 2009 16:33:43 -0400
Date: Fri, 23 Oct 2009 16:33:43 -0400
Message-Id: <200910232033.n9NKXh2u008157@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Apache 2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 23 Oct 2009 20:33:44 -0000

Published: 2009-10-23
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    apache2-utils=sle.rpath.com@rpath:sles-11/2.2.10_2.21.1-1-1
    apache2-example-pages=sle.rpath.com@rpath:sles-11/2.2.10_2.21.1-1-1
    apache2-worker=sle.rpath.com@rpath:sles-11/2.2.10_2.21.1-1-1
    apache2-prefork=sle.rpath.com@rpath:sles-11/2.2.10_2.21.1-1-1
    apache2=sle.rpath.com@rpath:sles-11/2.2.10_2.21.1-1-1

Description:
This update of the Apache webserver fixes various security
issues:
- the option IncludesNOEXEC could be bypassed via .htaccess
  (CVE-2009-1195) 
- mod_proxy could run into an infinite loop when used as
  reverse  proxy (CVE-2009-1890) 
- mod_deflate continued to compress large files even after
  a network connection was closed, causing mod_deflate to
  consume large amounts of CPU (CVE-2009-1891)
- The ap_proxy_ftp_handler function in
  modules/proxy/proxy_ftp.c in the mod_proxy_ftp module
  allows remote FTP servers to cause a denial of service
  (NULL pointer dereference and child process crash) via a
  malformed reply to an EPSV command. (CVE-2009-3094)
- access restriction bypass in mod_proxy_ftp module
  (CVE-2009-3095)


References:
    https://bugzilla.novell.com/show_bug.cgi?id=521906
    https://bugzilla.novell.com/show_bug.cgi?id=513080
    https://bugzilla.novell.com/show_bug.cgi?id=512583
    https://bugzilla.novell.com/show_bug.cgi?id=539571
    https://bugzilla.novell.com/show_bug.cgi?id=519194
    https://bugzilla.novell.com/show_bug.cgi?id=538322

From announce-noreply@rpath.com Fri Oct 23 18:34:34 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n9NMYY2O015756
	for <sle-announce@lists.rpath.com>; Fri, 23 Oct 2009 18:34:34 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n9NMYXp9020476
	for <sle-announce@lists.rpath.com>; Fri, 23 Oct 2009 18:34:34 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n9NMYX31013376;
	Fri, 23 Oct 2009 18:34:33 -0400
Date: Fri, 23 Oct 2009 18:34:33 -0400
Message-Id: <200910232234.n9NMYX31013376@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Apache 2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 23 Oct 2009 22:34:34 -0000

Published: 2009-10-23
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    apache2-worker=sle.rpath.com@rpath:sles-10/2.2.3_16.25.4-1-1
    apache2-prefork=sle.rpath.com@rpath:sles-10/2.2.3_16.25.4-1-1
    apache2=sle.rpath.com@rpath:sles-10/2.2.3_16.25.4-1-1

Description:
This update of the Apache webserver fixes various security
issues:
- the option IncludesNOEXEC could be bypassed via .htaccess
  (CVE-2009-1195) 
- mod_proxy could run into an infinite loop when used as
  reverse  proxy (CVE-2009-1890) 
- mod_deflate continued to compress large files even after
  a network connection was closed, causing mod_deflate to
  consume large amounts of CPU (CVE-2009-1891)
- The ap_proxy_ftp_handler function in
  modules/proxy/proxy_ftp.c in the mod_proxy_ftp module
  allows remote FTP servers to cause a denial of service
  (NULL pointer dereference and child process crash) via a
  malformed reply to an EPSV command. (CVE-2009-3094)
- access restriction bypass in mod_proxy_ftp module
  (CVE-2009-3095)

Also a incompatibility between mod_cache and mod_rewrite
was fixed.


From announce-noreply@rpath.com Mon Oct 26 10:27:34 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n9QERYR0027167
	for <sle-announce@lists.rpath.com>; Mon, 26 Oct 2009 10:27:34 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n9QERY3T030899
	for <sle-announce@lists.rpath.com>; Mon, 26 Oct 2009 10:27:34 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n9QERXRR020586;
	Mon, 26 Oct 2009 10:27:33 -0400
Date: Mon, 26 Oct 2009 10:27:33 -0400
Message-Id: <200910261427.n9QERXRR020586@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for udev
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 26 Oct 2009 14:27:35 -0000

Published: 2009-10-26
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    libvolume_id1=sle.rpath.com@rpath:sles-11/128_13.3.1-1-1
    udev=sle.rpath.com@rpath:sles-11/128_13.3.1-1-1

Description:
This update fixes a local privilege escalation in udev.

CVE-2009-1185: udev did not check the origin of the netlink
messages. A local attacker could fake device create events
and so gain root privileges.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=493158

From announce-noreply@rpath.com Wed Oct 28 11:35:54 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n9SFZsnQ003526
	for <sle-announce@lists.rpath.com>; Wed, 28 Oct 2009 11:35:54 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n9SFZsp9001801
	for <sle-announce@lists.rpath.com>; Wed, 28 Oct 2009 11:35:54 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n9SFZsbG011634;
	Wed, 28 Oct 2009 11:35:54 -0400
Date: Wed, 28 Oct 2009 11:35:54 -0400
Message-Id: <200910281535.n9SFZsbG011634@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for neon
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 28 Oct 2009 15:35:55 -0000

Published: 2009-10-28
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    neon=sle.rpath.com@rpath:sles-10/0.24.7_20.8.1-1-1

Description:
neon did not properly handle embedded NUL characters in
X.509 certificates when comparing host names. Attackers
could exploit that to spoof SSL servers (CVE-2009-2408).

Specially crafted XML documents that contain a large number
of nested entity references could cause neon to consume
large amounts of CPU and memory (CVE-2009-2473).


From announce-noreply@rpath.com Wed Oct 28 14:29:33 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	n9SITXxX004008
	for <sle-announce@lists.rpath.com>; Wed, 28 Oct 2009 14:29:33 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id n9SITWUg005817
	for <sle-announce@lists.rpath.com>; Wed, 28 Oct 2009 14:29:32 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id n9SITWbX021227;
	Wed, 28 Oct 2009 14:29:32 -0400
Date: Wed, 28 Oct 2009 14:29:32 -0400
Message-Id: <200910281829.n9SITWbX021227@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libneon
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 28 Oct 2009 18:29:33 -0000

Published: 2009-10-28
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    neon=sle.rpath.com@rpath:sles-11/0.28.3_2.12.1-2-1

Description:
neon did not properly handle embedded NUL characters in
X.509 certificates when comparing host names. Attackers
could exploit that to spoof SSL servers (CVE-2009-2408).

Specially crafted XML documents that contain a large number
of nested entity references could cause neon to consume
large amounts of CPU and memory (CVE-2009-2473).


References:
    https://bugzilla.novell.com/show_bug.cgi?id=528370
    https://bugzilla.novell.com/show_bug.cgi?id=532345

From announce-noreply@rpath.com Mon Nov  2 19:33:04 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nA30X4jI028397
	for <sle-announce@lists.rpath.com>; Mon, 2 Nov 2009 19:33:04 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nA30X4Wq027488
	for <sle-announce@lists.rpath.com>; Mon, 2 Nov 2009 19:33:04 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nA30X3ER027206;
	Mon, 2 Nov 2009 19:33:03 -0500
Date: Mon, 2 Nov 2009 19:33:03 -0500
Message-Id: <200911030033.nA30X3ER027206@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for timezone
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 03 Nov 2009 00:33:04 -0000

Published: 2009-11-02
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    timezone=sle.rpath.com@rpath:sles-11/2009p_0.1.1-1-1

Description:
- update data to 2009p:
  * DST changes: Asia/Karachi, Asia/Dhaka, America/Argentina


References:
    https://bugzilla.novell.com/show_bug.cgi?id=548413

From announce-noreply@rpath.com Tue Nov  3 16:38:06 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nA3Lc5iv032387
	for <sle-announce@lists.rpath.com>; Tue, 3 Nov 2009 16:38:05 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nA3Lc5pX023567
	for <sle-announce@lists.rpath.com>; Tue, 3 Nov 2009 16:38:05 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nA3Lc4Ax027840;
	Tue, 3 Nov 2009 16:38:04 -0500
Date: Tue, 3 Nov 2009 16:38:04 -0500
Message-Id: <200911032138.nA3Lc4Ax027840@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for HAL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 03 Nov 2009 21:38:06 -0000

Published: 2009-11-03
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    hal=sle.rpath.com@rpath:sles-11/0.5.12_23.18.1-1-1

Description:
This HAL Update provides better support for many mobile
devices.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=474079
    https://bugzilla.novell.com/show_bug.cgi?id=479262
    https://bugzilla.novell.com/show_bug.cgi?id=474065
    https://bugzilla.novell.com/show_bug.cgi?id=471514
    https://bugzilla.novell.com/show_bug.cgi?id=525959
    https://bugzilla.novell.com/show_bug.cgi?id=531435
    https://bugzilla.novell.com/show_bug.cgi?id=502907
    https://bugzilla.novell.com/show_bug.cgi?id=488035
    https://bugzilla.novell.com/show_bug.cgi?id=491802

From announce-noreply@rpath.com Mon Nov  9 14:55:40 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nA9JteFe025145
	for <sle-announce@lists.rpath.com>; Mon, 9 Nov 2009 14:55:40 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nA9JtdQe014154
	for <sle-announce@lists.rpath.com>; Mon, 9 Nov 2009 14:55:40 -0500
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nA9JtdA7032002;
	Mon, 9 Nov 2009 14:55:39 -0500
Date: Mon, 9 Nov 2009 14:55:39 -0500
Message-Id: <200911091955.nA9JtdA7032002@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for glibc and timezone
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 09 Nov 2009 19:55:40 -0000

Published: 2009-11-09
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    glibc=sle.rpath.com@rpath:sles-10/2.4_31.63.3-1-1
    timezone=sle.rpath.com@rpath:sles-10/2.4_31.63.3-1-1

Description:
- Add support for multiple group records for a single group
  when using nss_compat
- Fix localtime() never refreshing its timezone information
- Mitigate a dlopen() race condition
- Fix potential buffer overrun in memcpy() code on ppc
- Fix get*() calls routed through nscd returning bogus
  ENOENT in some conditions
- Raise utmp locking timeout from 1s to 30s to ensure
  logins get recorded even on heavily loaded systems
- setgroup() error in paranoia mode is not fatal for nscd
  anymore; setres*id() is used instead of set*id() in nscd
  paranoia mode so that nscd restarts with correct
  priviledges
- update data to 2009p:
  * DST changes: Africa/Cairo, Indian/Mauritius,
    Asia/Dhaka, Asia/Karachi, Asia/Gaza, Pacific/Apia,
    America/Argentina


From announce-noreply@rpath.com Wed Nov 11 20:44:24 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nAC1iOj6002987
	for <sle-announce@lists.rpath.com>; Wed, 11 Nov 2009 20:44:24 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nAC1iOuv012613
	for <sle-announce@lists.rpath.com>; Wed, 11 Nov 2009 20:44:24 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nAC1iN3g030494;
	Wed, 11 Nov 2009 20:44:23 -0500
Date: Wed, 11 Nov 2009 20:44:23 -0500
Message-Id: <200911120144.nAC1iN3g030494@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for CUPS
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 12 Nov 2009 01:44:24 -0000

Published: 2009-11-11
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    cups-client=sle.rpath.com@rpath:sles-11/1.3.9_8.20.1-1-1
    cups=sle.rpath.com@rpath:sles-11/1.3.9_8.20.1-1-1

Description:
The cups web interface was prone to Cross-Site   Scripting
(XSS) problems (CVE-2009-2820).


References:
    https://bugzilla.novell.com/show_bug.cgi?id=548317

From announce-noreply@rpath.com Mon Nov 16 07:32:40 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nAGCWdb1023070
	for <sle-announce@lists.rpath.com>; Mon, 16 Nov 2009 07:32:39 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nAGCWdtk031303
	for <sle-announce@lists.rpath.com>; Mon, 16 Nov 2009 07:32:39 -0500
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nAGCWdGC008358;
	Mon, 16 Nov 2009 07:32:39 -0500
Date: Mon, 16 Nov 2009 07:32:39 -0500
Message-Id: <200911161232.nAGCWdGC008358@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libopenssl
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 16 Nov 2009 12:32:40 -0000

Published: 2009-11-16
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    openssl=sle.rpath.com@rpath:sles-11/0.9.8h_30.15.1-1-1

Description:
The TLS/SSLv3 protocol as implemented in openssl prior to
this update was not able to associate data to a
renegotiated connection. This allowed man-in-the-middle
attackers to inject HTTP requests in a HTTPS session
without being noticed. For example Apache's mod_ssl was
vulnerable to this kind of attack because it uses openssl.
Please note that renegotiation will be disabled by this
update and may cause problems in some cases.
(CVE-2009-3555: CVSS v2 Base Score: 6.4)


References:
    https://bugzilla.novell.com/show_bug.cgi?id=553641

From announce-noreply@rpath.com Mon Nov 16 08:24:14 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nAGDOE0e023212
	for <sle-announce@lists.rpath.com>; Mon, 16 Nov 2009 08:24:14 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nAGDOEjm032208
	for <sle-announce@lists.rpath.com>; Mon, 16 Nov 2009 08:24:14 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nAGDOEb0011097;
	Mon, 16 Nov 2009 08:24:14 -0500
Date: Mon, 16 Nov 2009 08:24:14 -0500
Message-Id: <200911161324.nAGDOEb0011097@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenSSL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 16 Nov 2009 13:24:15 -0000

Published: 2009-11-16
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    openssl=sle.rpath.com@rpath:sles-10/0.9.8a_18.39.1-1-1

Description:
The TLS/SSLv3 protocol as implemented in openssl prior to
this update was not able to associate data to a
renegotiated connection. This allowed man-in-the-middle
attackers to inject HTTP requests in a HTTPS session
without being noticed. For example Apache's mod_ssl was
vulnerable to this kind of attack because it uses openssl.
Please note that renegotiation will be disabled by this
update and may cause problems in some cases.
(CVE-2009-3555: CVSS v2 Base Score: 6.4)


From announce-noreply@rpath.com Mon Nov 16 17:24:26 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nAGMOQi4024813
	for <sle-announce@lists.rpath.com>; Mon, 16 Nov 2009 17:24:26 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nAGMOQl2010741
	for <sle-announce@lists.rpath.com>; Mon, 16 Nov 2009 17:24:26 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nAGMOPt3008750;
	Mon, 16 Nov 2009 17:24:25 -0500
Date: Mon, 16 Nov 2009 17:24:25 -0500
Message-Id: <200911162224.nAGMOPt3008750@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenSSL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 16 Nov 2009 22:24:26 -0000

Published: 2009-11-16
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    compat-openssl097g=sle.rpath.com@rpath:sles-10/0.9.7g_13.19.1-1-1

Description:
The TLS/SSLv3 protocol as implemented in openssl prior to
this update was not able to associate data to a
renegotiated connection. This allowed man-in-the-middle
attackers to inject HTTP requests in a HTTPS session
without being noticed. For example Apache's mod_ssl was
vulnerable to this kind of attack because it uses openssl.
Please note that renegotiation will be disabled by this
update and may cause problems in some cases.
(CVE-2009-3555: CVSS v2 Base Score: 6.4)


From announce-noreply@rpath.com Fri Nov 20 14:28:39 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nAKJSdxT009377
	for <sle-announce@lists.rpath.com>; Fri, 20 Nov 2009 14:28:39 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nAKJSc80018076
	for <sle-announce@lists.rpath.com>; Fri, 20 Nov 2009 14:28:38 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nAKJScNr006203;
	Fri, 20 Nov 2009 14:28:38 -0500
Date: Fri, 20 Nov 2009 14:28:38 -0500
Message-Id: <200911201928.nAKJScNr006203@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for expat
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 20 Nov 2009 19:28:39 -0000

Published: 2009-11-20
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    expat=sle.rpath.com@rpath:sles-10/2.0.0_13.7.1-1-1

Description:
Specially crafted XML documents could make expat run into
an enless loop, therefore locking up applications using
expat (CVE-2009-3720).


From announce-noreply@rpath.com Tue Nov 24 11:41:20 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nAOGfKmQ025472
	for <sle-announce@lists.rpath.com>; Tue, 24 Nov 2009 11:41:20 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nAOGfJss016831
	for <sle-announce@lists.rpath.com>; Tue, 24 Nov 2009 11:41:19 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nAOGfJQH023518;
	Tue, 24 Nov 2009 11:41:19 -0500
Date: Tue, 24 Nov 2009 11:41:19 -0500
Message-Id: <200911241641.nAOGfJQH023518@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for freetype2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 24 Nov 2009 16:41:20 -0000

Published: 2009-11-24
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    freetype2=sle.rpath.com@rpath:sles-11/2.3.7_25.10.1-2-1

Description:
Some pdf-documents can cause an arithmetic exception in
freetype2. This bug is fixed by this update.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=508139

From announce-noreply@rpath.com Mon Nov 30 07:29:10 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nAUCT9QQ017398
	for <sle-announce@lists.rpath.com>; Mon, 30 Nov 2009 07:29:09 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nAUCT9II021896
	for <sle-announce@lists.rpath.com>; Mon, 30 Nov 2009 07:29:09 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nAUCT9M6005659;
	Mon, 30 Nov 2009 07:29:09 -0500
Date: Mon, 30 Nov 2009 07:29:09 -0500
Message-Id: <200911301229.nAUCT9M6005659@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for perl-Bootloader
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 30 Nov 2009 12:29:10 -0000

Published: 2009-11-30
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    perl-Bootloader=sle.rpath.com@rpath:sles-11/0.4.89.1_0.2.1-1-1

Description:
This update includes the following bug fixes:
- Fix installing lilo even if partition table is
  inconsistent.
- Fix device with # in grub bootloader.
- Fix image section without root for s390.
- Fix timeout conversion for lilo bootloader.
- Fix removing color key in global section for grub.
- Improve partition fallback, if device cannot be
  recognized.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=466427
    https://bugzilla.novell.com/show_bug.cgi?id=481416
    https://bugzilla.novell.com/show_bug.cgi?id=483617
    https://bugzilla.novell.com/show_bug.cgi?id=511186
    https://bugzilla.novell.com/show_bug.cgi?id=511398
    https://bugzilla.novell.com/show_bug.cgi?id=464098
    https://bugzilla.novell.com/show_bug.cgi?id=468792
    https://bugzilla.novell.com/show_bug.cgi?id=466250

From announce-noreply@rpath.com Mon Nov 30 14:35:01 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nAUJZ14g018610
	for <sle-announce@lists.rpath.com>; Mon, 30 Nov 2009 14:35:01 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nAUJYw7A032010
	for <sle-announce@lists.rpath.com>; Mon, 30 Nov 2009 14:34:58 -0500
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nAUJYwbR028659;
	Mon, 30 Nov 2009 14:34:58 -0500
Date: Mon, 30 Nov 2009 14:34:58 -0500
Message-Id: <200911301934.nAUJYwbR028659@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for bind
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 30 Nov 2009 19:35:01 -0000

Published: 2009-11-30
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    bind-utils=sle.rpath.com@rpath:sles-11/9.5.0P2_20.4.1-1-1
    bind-chrootenv=sle.rpath.com@rpath:sles-11/9.5.0P2_20.4.1-1-1
    bind=sle.rpath.com@rpath:sles-11/9.5.0P2_20.4.1-1-1

Description:
The bind DNS server was updated to close a possible cache
poisoning vulnerability which allowed to bypass DNSSEC.
CVE-2009-4022: CVSS v2 Base Score: 2.6


References:
    https://bugzilla.novell.com/show_bug.cgi?id=558260

From announce-noreply@rpath.com Tue Dec  1 19:35:16 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nB20ZGf9024983
	for <sle-announce@lists.rpath.com>; Tue, 1 Dec 2009 19:35:16 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nB20ZFrd004509
	for <sle-announce@lists.rpath.com>; Tue, 1 Dec 2009 19:35:15 -0500
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nB20ZF31016027;
	Tue, 1 Dec 2009 19:35:15 -0500
Date: Tue, 1 Dec 2009 19:35:15 -0500
Message-Id: <200912020035.nB20ZF31016027@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for e2fsprogs
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 02 Dec 2009 00:35:16 -0000

Published: 2009-12-01
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    libcom_err2=sle.rpath.com@rpath:sles-11/1.41.1_13.11.1-1-1
    e2fsprogs=sle.rpath.com@rpath:sles-11/1.41.1_13.11.1-1-1
    libblkid1=sle.rpath.com@rpath:sles-11/1.41.1_13.11.1-1-1
    uuid-runtime=sle.rpath.com@rpath:sles-11/1.41.1_13.11.1-1-1
    libext2fs2=sle.rpath.com@rpath:sles-11/1.41.1_13.11.1-1-1
    libuuid1=sle.rpath.com@rpath:sles-11/1.41.1_13.11.1-1-1

Description:
e2fsprogs: fsck during boot up fails with the error message
"too many open files". This bug is fixed by this update.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=503008

From announce-noreply@rpath.com Tue Dec  1 19:35:16 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nB20ZG3b024984
	for <sle-announce@lists.rpath.com>; Tue, 1 Dec 2009 19:35:16 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nB20ZFC0004510
	for <sle-announce@lists.rpath.com>; Tue, 1 Dec 2009 19:35:15 -0500
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nB20ZFAS016029;
	Tue, 1 Dec 2009 19:35:15 -0500
Date: Tue, 1 Dec 2009 19:35:15 -0500
Message-Id: <200912020035.nB20ZFAS016029@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for module-init-tools
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 02 Dec 2009 00:35:16 -0000

Published: 2009-12-01
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    module-init-tools=sle.rpath.com@rpath:sles-11/3.4_70.7.1-1-1

Description:
This update fixes two bugs that could result in missing
weak-modules symlinks after installing or updating kernel
module packages. A minor bug that caused useless output
when installing from the commandline was also fixed.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=491937
    https://bugzilla.novell.com/show_bug.cgi?id=485914
    https://bugzilla.novell.com/show_bug.cgi?id=527312
    https://bugzilla.novell.com/show_bug.cgi?id=546797

From announce-noreply@rpath.com Fri Dec 11 11:28:06 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nBBGS6Jc002610
	for <sle-announce@lists.rpath.com>; Fri, 11 Dec 2009 11:28:06 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nBBGS66P004412
	for <sle-announce@lists.rpath.com>; Fri, 11 Dec 2009 11:28:06 -0500
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nBBGS6AG032118;
	Fri, 11 Dec 2009 11:28:06 -0500
Date: Fri, 11 Dec 2009 11:28:06 -0500
Message-Id: <200912111628.nBBGS6AG032118@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for expat
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 11 Dec 2009 16:28:07 -0000

Published: 2009-12-11
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    expat=sle.rpath.com@rpath:sles-11/2.0.1_88.23.1-1-1

Description:
Specially crafted XML documents could make expat run into
an enless loop, therefore locking up applications using
expat (CVE-2009-3720).


References:
    https://bugzilla.novell.com/show_bug.cgi?id=550664

From announce-noreply@rpath.com Fri Dec 11 12:27:22 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nBBHRMFr002777
	for <sle-announce@lists.rpath.com>; Fri, 11 Dec 2009 12:27:22 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nBBHRMdO005484
	for <sle-announce@lists.rpath.com>; Fri, 11 Dec 2009 12:27:22 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nBBHRMec002851;
	Fri, 11 Dec 2009 12:27:22 -0500
Date: Fri, 11 Dec 2009 12:27:22 -0500
Message-Id: <200912111727.nBBHRMec002851@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for expat
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 11 Dec 2009 17:27:23 -0000

Published: 2009-12-11
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    expat=sle.rpath.com@rpath:sles-10/2.0.0_13.7.3-1-1

Description:
Specially crafted XML files could crash applications that
use expat to parse such files (CVE-2009-3560).


From announce-noreply@rpath.com Wed Dec 16 19:37:15 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nBH0bFs8032762
	for <sle-announce@lists.rpath.com>; Wed, 16 Dec 2009 19:37:15 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nBH0bEf2006598
	for <sle-announce@lists.rpath.com>; Wed, 16 Dec 2009 19:37:14 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nBH0bEjO022116;
	Wed, 16 Dec 2009 19:37:14 -0500
Date: Wed, 16 Dec 2009 19:37:14 -0500
Message-Id: <200912170037.nBH0bEjO022116@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for device-mapper
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 17 Dec 2009 00:37:15 -0000

Published: 2009-12-16
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    device-mapper=sle.rpath.com@rpath:sles-11/1.02.27_8.9.1-1-1

Description:
This update corrects an out of memory access in pvscan and
vgscan that can cause crashes (bnc#550363).


References:
    https://bugzilla.novell.com/show_bug.cgi?id=550363

From announce-noreply@rpath.com Wed Dec 16 19:37:15 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nBH0bFmW032764
	for <sle-announce@lists.rpath.com>; Wed, 16 Dec 2009 19:37:15 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nBH0bE7v006600
	for <sle-announce@lists.rpath.com>; Wed, 16 Dec 2009 19:37:15 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nBH0bEGe022120;
	Wed, 16 Dec 2009 19:37:14 -0500
Date: Wed, 16 Dec 2009 19:37:14 -0500
Message-Id: <200912170037.nBH0bEGe022120@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for OpenSLP
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 17 Dec 2009 00:37:16 -0000

Published: 2009-12-16
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    openslp=sle.rpath.com@rpath:sles-11/1.2.0_172.6.1-1-1
    openslp-server=sle.rpath.com@rpath:sles-11/1.2.0_172.6.1-1-1

Description:
libslp may use only a subset of the known DAs due to a bug
in the DAAdvert handling for non-openslp servers.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=533432

From announce-noreply@rpath.com Wed Dec 16 19:37:15 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nBH0bFJ0032763
	for <sle-announce@lists.rpath.com>; Wed, 16 Dec 2009 19:37:15 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nBH0bEkK006599
	for <sle-announce@lists.rpath.com>; Wed, 16 Dec 2009 19:37:15 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nBH0bEBF022118;
	Wed, 16 Dec 2009 19:37:14 -0500
Date: Wed, 16 Dec 2009 19:37:14 -0500
Message-Id: <200912170037.nBH0bEBF022118@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for sysvinit
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 17 Dec 2009 00:37:16 -0000

Published: 2009-12-16
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    sysvinit=sle.rpath.com@rpath:sles-11/2.86_195.13.1-1-1

Description:
This update is a collective bugfix update for sysvinit:

- Fixes a segmentation fault in checkproc due to a race in
  reading the /proc file system.
- Add option to startproc to wait for process termination
  before returning
- Support for properly restarted lighttpd process


References:
    https://bugzilla.novell.com/show_bug.cgi?id=542717
    https://bugzilla.novell.com/show_bug.cgi?id=482096
    https://bugzilla.novell.com/show_bug.cgi?id=489473
    https://bugzilla.novell.com/show_bug.cgi?id=559534

From announce-noreply@rpath.com Wed Dec 16 20:32:14 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nBH1WDF4000564
	for <sle-announce@lists.rpath.com>; Wed, 16 Dec 2009 20:32:13 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nBH1WDTZ007773
	for <sle-announce@lists.rpath.com>; Wed, 16 Dec 2009 20:32:13 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nBH1WDt4024586;
	Wed, 16 Dec 2009 20:32:13 -0500
Date: Wed, 16 Dec 2009 20:32:13 -0500
Message-Id: <200912170132.nBH1WDt4024586@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for OpenSLP
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 17 Dec 2009 01:32:14 -0000

Published: 2009-12-16
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    openslp=sle.rpath.com@rpath:sles-10/1.2.0_22.26.1-1-1

Description:
libslp may use only a subset of the known DAs due to a bug
in the DAAdvert handling for non-openslp servers.


From announce-noreply@rpath.com Thu Dec 17 11:28:37 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nBHGSbtS004867
	for <sle-announce@lists.rpath.com>; Thu, 17 Dec 2009 11:28:37 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nBHGSbsQ032271
	for <sle-announce@lists.rpath.com>; Thu, 17 Dec 2009 11:28:37 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nBHGSbkg007633;
	Thu, 17 Dec 2009 11:28:37 -0500
Date: Thu, 17 Dec 2009 11:28:37 -0500
Message-Id: <200912171628.nBHGSbkg007633@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for device-mapper
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 17 Dec 2009 16:28:37 -0000

Published: 2009-12-17
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    device-mapper=sle.rpath.com@rpath:sles-10/1.02.13_6.17.1-1-1

Description:
This update corrects an out of memory access in pvscan and
vgscan that can cause crashes (bnc#550363).


From announce-noreply@rpath.com Thu Dec 17 14:50:08 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nBHJo8Wk005981
	for <sle-announce@lists.rpath.com>; Thu, 17 Dec 2009 14:50:08 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nBHJo8LB006492
	for <sle-announce@lists.rpath.com>; Thu, 17 Dec 2009 14:50:08 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nBHJo8B0019855;
	Thu, 17 Dec 2009 14:50:08 -0500
Date: Thu, 17 Dec 2009 14:50:08 -0500
Message-Id: <200912171950.nBHJo8B0019855@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for PHP5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 17 Dec 2009 19:50:08 -0000

Published: 2009-12-17
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    php5-sysvmsg=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-calendar=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-bz2=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-ctype=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-wddx=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-xmlrpc=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-curl=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-openssl=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-hash=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-sqlite=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-mbstring=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-bcmath=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-readline=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-tidy=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-sysvsem=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-fastcgi=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-dba=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-gmp=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-xmlwriter=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-ncurses=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-zip=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-posix=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-ftp=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-odbc=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-suhosin=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-pcntl=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-soap=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-zlib=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-pspell=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-mysql=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-tokenizer=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-sysvshm=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-pear=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-pgsql=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-sockets=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-snmp=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-json=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-ldap=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-pdo=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-iconv=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    apache2-mod_php5=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-mcrypt=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-dbase=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-exif=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-shmop=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-dom=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-gettext=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-xmlreader=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-gd=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1
    php5-xsl=sle.rpath.com@rpath:sles-11/5.2.6_50.23.15-1-1

Description:
Multiple issues have been fixed in php5:
- php_openssl_apply_verification_policy() fails to verify
  certificate (CVE-2009-3291)
- "missing sainity checks around exif" (CVE-2009-3292)
- unspecified vulnerability in the imagecolortransparent()
  (CVE-2009-3293)
- denial of service in exif module (CVE-2009-2687)
  Additionally we fixed:
- xmlparse was broken
- read_exif_data() only returns the first letter of UTF-16
  strings


References:
    https://bugzilla.novell.com/show_bug.cgi?id=540242

From announce-noreply@rpath.com Fri Dec 18 22:27:40 2009
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	nBJ3ReI9014067
	for <sle-announce@lists.rpath.com>; Fri, 18 Dec 2009 22:27:40 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id nBJ3ReXU026260
	for <sle-announce@lists.rpath.com>; Fri, 18 Dec 2009 22:27:40 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id nBJ3RdVQ005895;
	Fri, 18 Dec 2009 22:27:39 -0500
Date: Fri, 18 Dec 2009 22:27:39 -0500
Message-Id: <200912190327.nBJ3RdVQ005895@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for xntp
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Sat, 19 Dec 2009 03:27:40 -0000

Published: 2009-12-18
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    xntp=sle.rpath.com@rpath:sles-10/4.2.4p3_48.13.5-1-1

Description:
By sending specially crafted NTP packets attackers could
make ntpd flood it's log file with error messages or even
run into an endless loop (CVE-2009-3563).


From announce-noreply@rpath.com Mon Jan  4 14:25:21 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o04JPKuO006966
	for <sle-announce@lists.rpath.com>; Mon, 4 Jan 2010 14:25:20 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o04JPKCY027886
	for <sle-announce@lists.rpath.com>; Mon, 4 Jan 2010 14:25:20 -0500
Received: from build05.eng.rpath.com (build05.eng.rpath.com [172.16.160.205])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o04JPKMX003262;
	Mon, 4 Jan 2010 14:25:20 -0500
Date: Mon, 4 Jan 2010 14:25:20 -0500
Message-Id: <201001041925.o04JPKMX003262@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libtool
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 04 Jan 2010 19:25:21 -0000

Published: 2010-01-04
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    libtool=sle.rpath.com@rpath:sles-10/1.5.22_13.16.1-1-1

Description:
libtool: libltdl may load modules from the current working
directory. CVE-2009-3736 has been assigned to this issue.


From announce-noreply@rpath.com Tue Jan  5 11:23:04 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o05GN4Jk011605
	for <sle-announce@lists.rpath.com>; Tue, 5 Jan 2010 11:23:04 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o05GN41o026670
	for <sle-announce@lists.rpath.com>; Tue, 5 Jan 2010 11:23:04 -0500
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o05GN3Lg029416;
	Tue, 5 Jan 2010 11:23:03 -0500
Date: Tue, 5 Jan 2010 11:23:03 -0500
Message-Id: <201001051623.o05GN3Lg029416@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for libtool
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 05 Jan 2010 16:23:04 -0000

Published: 2010-01-05
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    libtool=sle.rpath.com@rpath:sles-11/2.2.6_2.131.1-1-1
    libltdl7=sle.rpath.com@rpath:sles-11/2.2.6_2.131.1-1-1

Description:
libtool: libltdl may load modules from the current working
directory. CVE-2009-3736 has been assigned to this issue.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=556122

From announce-noreply@rpath.com Fri Jan  8 07:27:44 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o08CRiXT026813
	for <sle-announce@lists.rpath.com>; Fri, 8 Jan 2010 07:27:44 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o08CRip7002860
	for <sle-announce@lists.rpath.com>; Fri, 8 Jan 2010 07:27:44 -0500
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o08CRi8A029565;
	Fri, 8 Jan 2010 07:27:44 -0500
Date: Fri, 8 Jan 2010 07:27:44 -0500
Message-Id: <201001081227.o08CRi8A029565@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for NFS
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 08 Jan 2010 12:27:45 -0000

Published: 2010-01-08
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    nfs-client=sle.rpath.com@rpath:sles-11/1.1.3_19.2.1-1-1
    nfs-utils=sle.rpath.com@rpath:sles-11/1.1.3_19.2.1-1-1
    nfs-kernel-server=sle.rpath.com@rpath:sles-11/1.1.3_19.2.1-1-1

Description:
Collective nfs-utils update, containing the following fixes:

Fix bug where "exportfs -r" can sometimes unexport
filesystems incorrectly. Fix bug which stopped sm-notify
from working properly. Make sure nfs setting in
/etc/sysctl.conf are always put into effect.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=474328
    https://bugzilla.novell.com/show_bug.cgi?id=520311
    https://bugzilla.novell.com/show_bug.cgi?id=508319

From announce-noreply@rpath.com Fri Jan  8 18:28:14 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o08NSECs029121
	for <sle-announce@lists.rpath.com>; Fri, 8 Jan 2010 18:28:14 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o08NSEGV017863
	for <sle-announce@lists.rpath.com>; Fri, 8 Jan 2010 18:28:14 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o08NSDFq029243;
	Fri, 8 Jan 2010 18:28:13 -0500
Date: Fri, 8 Jan 2010 18:28:13 -0500
Message-Id: <201001082328.o08NSDFq029243@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for nfs-utils
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 08 Jan 2010 23:28:14 -0000

Published: 2010-01-08
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    nfs-utils=sle.rpath.com@rpath:sles-10/1.0.7_36.36.2-1-1

Description:
Collective nfs-utils update:
- Fix bug where "exportfs -r" can sometimes unexport
  filesystems incorrectly.
- Fix bug in idmapd where a SIGHUP is not sufficient for it
  to reread it's configuration.


From announce-noreply@rpath.com Fri Jan  8 18:28:14 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o08NSEft029122
	for <sle-announce@lists.rpath.com>; Fri, 8 Jan 2010 18:28:14 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o08NSEMl017862
	for <sle-announce@lists.rpath.com>; Fri, 8 Jan 2010 18:28:14 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o08NSDKi029241;
	Fri, 8 Jan 2010 18:28:13 -0500
Date: Fri, 8 Jan 2010 18:28:13 -0500
Message-Id: <201001082328.o08NSDKi029241@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for parted
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 08 Jan 2010 23:28:15 -0000

Published: 2010-01-08
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    parted=sle.rpath.com@rpath:sles-10/1.6.25.1_15.22.2-1-1

Description:
Race condition in parted might cause /proc/partitions being
outdated after modification of partition table. Mismatches
between partition layouts "on disk" and "in kernel data"
can lead to data loss. Also fixes bogus error messages when
partprobe is used on disk with dvh partition table and
improper data conversion in parted that could cause several
kinds of errors on 64bit machines.


From announce-noreply@rpath.com Tue Jan 12 10:39:07 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o0CFd6go017377
	for <sle-announce@lists.rpath.com>; Tue, 12 Jan 2010 10:39:06 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o0CFd6vO017236
	for <sle-announce@lists.rpath.com>; Tue, 12 Jan 2010 10:39:06 -0500
Received: from build09.eng.rpath.com (build09.eng.rpath.com [172.16.160.209])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o0CFd6Mi013068;
	Tue, 12 Jan 2010 10:39:06 -0500
Date: Tue, 12 Jan 2010 10:39:06 -0500
Message-Id: <201001121539.o0CFd6Mi013068@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for ntp
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 12 Jan 2010 15:39:07 -0000

Published: 2010-01-12
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    ntp=sle.rpath.com@rpath:sles-11/4.2.4p6_1.18.1-1-1

Description:
By sending specially crafted NTP packets attackers could
make ntpd flood it's log file with error messages or even
run into an endless loop (CVE-2009-3563).


References:
    https://bugzilla.novell.com/show_bug.cgi?id=550316
    https://bugzilla.novell.com/show_bug.cgi?id=517222
    https://bugzilla.novell.com/show_bug.cgi?id=515629

From announce-noreply@rpath.com Tue Jan 12 16:32:31 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o0CLWVIu018878
	for <sle-announce@lists.rpath.com>; Tue, 12 Jan 2010 16:32:31 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o0CLWUCx028537
	for <sle-announce@lists.rpath.com>; Tue, 12 Jan 2010 16:32:30 -0500
Received: from build10.eng.rpath.com (build10.eng.rpath.com [172.16.160.210])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o0CLWUMk000312;
	Tue, 12 Jan 2010 16:32:30 -0500
Date: Tue, 12 Jan 2010 16:32:30 -0500
Message-Id: <201001122132.o0CLWUMk000312@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce] Recommended update for glibc and Java timezone data
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 12 Jan 2010 21:32:31 -0000

Published: 2010-01-12
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    timezone=sle.rpath.com@rpath:sles-11/2009u_0.1.1-1-1

Description:
update tzdata to version 2009u:
  * DST changes: Asia/Damascus, Asia/Dhaka, Pacific/Fiji
  * GMT offset changes: some bases in Antartica
  * New zones: Asia/Novokuznetsk
  * Historical changes: Asia/Hong_Kong


References:
    https://bugzilla.novell.com/show_bug.cgi?id=558411

From announce-noreply@rpath.com Wed Jan 13 18:34:53 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o0DNYr5l024865
	for <sle-announce@lists.rpath.com>; Wed, 13 Jan 2010 18:34:53 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o0DNYrmb006024
	for <sle-announce@lists.rpath.com>; Wed, 13 Jan 2010 18:34:53 -0500
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o0DNYqxJ009667;
	Wed, 13 Jan 2010 18:34:53 -0500
Date: Wed, 13 Jan 2010 18:34:52 -0500
Message-Id: <201001132334.o0DNYqxJ009667@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for timezone
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 13 Jan 2010 23:34:53 -0000

Published: 2010-01-13
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    timezone=sle.rpath.com@rpath:sles-10/2.4_31.63.5-1-1
    glibc=sle.rpath.com@rpath:sles-10/2.4_31.63.5-1-1

Description:
update tzdata to version 2009u:
  * DST changes: Asia/Damascus, Asia/Dhaka, Pacific/Fiji
  * GMT offset changes: some bases in Antartica
  * New zones: Asia/Novokuznetsk
  * Historical changes: Asia/Hong_Kong


From announce-noreply@rpath.com Thu Jan 14 10:27:15 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o0EFRFVX028836
	for <sle-announce@lists.rpath.com>; Thu, 14 Jan 2010 10:27:15 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o0EFRFTH028623
	for <sle-announce@lists.rpath.com>; Thu, 14 Jan 2010 10:27:15 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o0EFRFcq019867;
	Thu, 14 Jan 2010 10:27:15 -0500
Date: Thu, 14 Jan 2010 10:27:15 -0500
Message-Id: <201001141527.o0EFRFcq019867@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for expat
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 14 Jan 2010 15:27:15 -0000

Published: 2010-01-14
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    expat=sle.rpath.com@rpath:sles-11/2.0.1_88.26.1-1-1

Description:
The previous expat security update (CVE-2009-3560) caused
parse errors with some xml documents.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=566434

From announce-noreply@rpath.com Thu Jan 14 10:35:57 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o0EFZvLd028888
	for <sle-announce@lists.rpath.com>; Thu, 14 Jan 2010 10:35:57 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o0EFZvrU028864
	for <sle-announce@lists.rpath.com>; Thu, 14 Jan 2010 10:35:57 -0500
Received: from build10.eng.rpath.com (build10.eng.rpath.com [172.16.160.210])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o0EFZvDP020351;
	Thu, 14 Jan 2010 10:35:57 -0500
Date: Thu, 14 Jan 2010 10:35:57 -0500
Message-Id: <201001141535.o0EFZvDP020351@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for expat
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Thu, 14 Jan 2010 15:35:57 -0000

Published: 2010-01-14
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    expat=sle.rpath.com@rpath:sles-10/2.0.0_13.7.5-1-1

Description:
The previous expat security update (CVE-2009-3560) caused
parse errors with some xml documents.


From announce-noreply@rpath.com Mon Jan 18 12:47:19 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o0IHlJeW018730
	for <sle-announce@lists.rpath.com>; Mon, 18 Jan 2010 12:47:19 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o0IHlIRL017093
	for <sle-announce@lists.rpath.com>; Mon, 18 Jan 2010 12:47:18 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o0IHlIEG027235;
	Mon, 18 Jan 2010 12:47:18 -0500
Date: Mon, 18 Jan 2010 12:47:18 -0500
Message-Id: <201001181747.o0IHlIEG027235@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for PostgreSQL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 18 Jan 2010 17:47:19 -0000

Published: 2010-01-18
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    postgresql-server=sle.rpath.com@rpath:sles-11/8.3.9_0.1.1-1-1
    postgresql=sle.rpath.com@rpath:sles-11/8.3.9_0.1.1-1-1
    postgresql-contrib=sle.rpath.com@rpath:sles-11/8.3.9_0.1.1-1-1

Description:

The following bugs have been fixed:



 An unprivileged, authenticated PostgreSQL user could create a table
which references functions with malicious content. Maintenance
operations carried out be the database superuser could execute such
functions (CVE-2009-4136).

 Embedded null bytes in the common name of SSL certificates could
bypass certificate hostname checks (CVE-2009-4034).




PostgreSQL was updated to the next upstream patchlevel update which also includes several bugfixes. See the package changelog for details.




References:
    https://bugzilla.novell.com/show_bug.cgi?id=564360
    https://bugzilla.novell.com/show_bug.cgi?id=564710
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4136
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4034

From announce-noreply@rpath.com Mon Jan 18 13:31:01 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o0IIV1j5019058
	for <sle-announce@lists.rpath.com>; Mon, 18 Jan 2010 13:31:01 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o0IIV136018733
	for <sle-announce@lists.rpath.com>; Mon, 18 Jan 2010 13:31:01 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o0IIV0tW029800;
	Mon, 18 Jan 2010 13:31:00 -0500
Date: Mon, 18 Jan 2010 13:31:00 -0500
Message-Id: <201001181831.o0IIV0tW029800@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for PostgreSQL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 18 Jan 2010 18:31:02 -0000

Published: 2010-01-18
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    postgresql=sle.rpath.com@rpath:sles-10/8.1.19_0.4.1-1-1
    postgresql-server=sle.rpath.com@rpath:sles-10/8.1.19_0.4.1-1-1
    postgresql-contrib=sle.rpath.com@rpath:sles-10/8.1.19_0.4.1-1-1

Description:

The following bugs have been fixed:



 An unprivileged, authenticated PostgreSQL user could create a table
which references functions with malicious content. Maintenance
operations carried out be the database superuser could execute such
functions (CVE-2009-4136).

 Embedded null bytes in the common name of SSL certificates could
bypass certificate hostname checks (CVE-2009-4034).




PostgreSQL was updated to the next upstream patchlevel update which also includes several bugfixes. See the package changelog for details.




From announce-noreply@rpath.com Tue Jan 19 10:35:13 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o0JFZDZR023646
	for <sle-announce@lists.rpath.com>; Tue, 19 Jan 2010 10:35:13 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o0JFZDB8014919
	for <sle-announce@lists.rpath.com>; Tue, 19 Jan 2010 10:35:13 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o0JFZDGU021377;
	Tue, 19 Jan 2010 10:35:13 -0500
Date: Tue, 19 Jan 2010 10:35:13 -0500
Message-Id: <201001191535.o0JFZDGU021377@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Kerberos 5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 19 Jan 2010 15:35:14 -0000

Published: 2010-01-19
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    krb5=sle.rpath.com@rpath:sles-10/1.4.3_19.43.2-1-1

Description:
Specially crafted AES and RC4 packets could allow unauthenticated
remote attackers to trigger an integer overflow leads to heap memory
corruption (CVE-2009-4212). This has been fixed.


From announce-noreply@rpath.com Fri Jan 22 13:35:27 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o0MIZR1X009484
	for <sle-announce@lists.rpath.com>; Fri, 22 Jan 2010 13:35:27 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o0MIZR1k004237
	for <sle-announce@lists.rpath.com>; Fri, 22 Jan 2010 13:35:27 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o0MIZQM4013662;
	Fri, 22 Jan 2010 13:35:26 -0500
Date: Fri, 22 Jan 2010 13:35:26 -0500
Message-Id: <201001221835.o0MIZQM4013662@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for device-mapper
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 22 Jan 2010 18:35:28 -0000

Published: 2010-01-22
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    device-mapper=sle.rpath.com@rpath:sles-11/1.02.27_8.12.1-1-1

Description:

The following bug has been fixed:



 #557775: device-mapper fails when running pvmove




References:
    https://bugzilla.novell.com/show_bug.cgi?id=557775

From announce-noreply@rpath.com Fri Jan 22 13:35:27 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o0MIZRYO009485
	for <sle-announce@lists.rpath.com>; Fri, 22 Jan 2010 13:35:27 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o0MIZR3e004238
	for <sle-announce@lists.rpath.com>; Fri, 22 Jan 2010 13:35:27 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o0MIZRbH013664;
	Fri, 22 Jan 2010 13:35:27 -0500
Date: Fri, 22 Jan 2010 13:35:27 -0500
Message-Id: <201001221835.o0MIZRbH013664@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenSSL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 22 Jan 2010 18:35:28 -0000

Published: 2010-01-22
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    openssl=sle.rpath.com@rpath:sles-11/0.9.8h_30.18.1-1-1

Description:
Incorrect use of an OpenSSL cleanup function can lead to memory
leaks in applications. For example an SSL enabled web server such as
Apache that uses PHP, curl and OpenSSL leaks memory if a SIGHUP
signal was sent to Apache. The OpenSSL cleanup function was made
more robust to avoid memory leaks (CVE-2009-4355).


References:
    https://bugzilla.novell.com/show_bug.cgi?id=566238
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4355

From announce-noreply@rpath.com Fri Jan 22 14:40:45 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o0MJeiTI009762
	for <sle-announce@lists.rpath.com>; Fri, 22 Jan 2010 14:40:45 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o0MJei7g007924
	for <sle-announce@lists.rpath.com>; Fri, 22 Jan 2010 14:40:44 -0500
Received: from build09.eng.rpath.com (build09.eng.rpath.com [172.16.160.209])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o0MJei6C017894;
	Fri, 22 Jan 2010 14:40:44 -0500
Date: Fri, 22 Jan 2010 14:40:44 -0500
Message-Id: <201001221940.o0MJei6C017894@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenSSL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 22 Jan 2010 19:40:45 -0000

Published: 2010-01-22
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    openssl=sle.rpath.com@rpath:sles-10/0.9.8a_18.39.3-1-1

Description:
Incorrect use of an OpenSSL cleanup function can lead to memory
leaks in applications. For example an SSL enabled web server such as
Apache that uses PHP, curl and OpenSSL leaks memory if a SIGHUP
signal was sent to Apache. The OpenSSL cleanup function was made
more robust to avoid memory leaks (CVE-2009-4355).


From announce-noreply@rpath.com Mon Jan 25 10:33:25 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o0PFXPPd025918
	for <sle-announce@lists.rpath.com>; Mon, 25 Jan 2010 10:33:25 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o0PFXPMb016168
	for <sle-announce@lists.rpath.com>; Mon, 25 Jan 2010 10:33:25 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o0PFXP8S001934;
	Mon, 25 Jan 2010 10:33:25 -0500
Date: Mon, 25 Jan 2010 10:33:25 -0500
Message-Id: <201001251533.o0PFXP8S001934@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for bind
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 25 Jan 2010 15:33:25 -0000

Published: 2010-01-25
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    bind=sle.rpath.com@rpath:sles-11/9.5.0P2_20.7.1-1-1
    bind-chrootenv=sle.rpath.com@rpath:sles-11/9.5.0P2_20.7.1-1-1
    bind-utils=sle.rpath.com@rpath:sles-11/9.5.0P2_20.7.1-1-1

Description:
When bind is configured for DNSSEC it could incorrectly cache NXDOMAIN responses (CVE-2010-0097). Moreover, the fix for CVE-2009-4022 was incomplete. Despite the previous fix CNAME and DNAME responses could be incorrectly cached (CVE-2010-0290). All these bugs have been fixed.



References:
    https://bugzilla.novell.com/show_bug.cgi?id=570912
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0097
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0290

From announce-noreply@rpath.com Mon Jan 25 13:22:09 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o0PIM84h026531
	for <sle-announce@lists.rpath.com>; Mon, 25 Jan 2010 13:22:08 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o0PIM8II021112
	for <sle-announce@lists.rpath.com>; Mon, 25 Jan 2010 13:22:08 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o0PIM8HI010266;
	Mon, 25 Jan 2010 13:22:08 -0500
Date: Mon, 25 Jan 2010 13:22:08 -0500
Message-Id: <201001251822.o0PIM8HI010266@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for gzip
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 25 Jan 2010 18:22:09 -0000

Published: 2010-01-25
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    gzip=sle.rpath.com@rpath:sles-11/1.3.12_69.19.1-1-1

Description:

The following bugs have been fixed:



 Specially crafted gzip archives could lead to gzip allocating a too small huffman table. Attackers could exploit that to crash gzip (CVE-2009-2624).

Specially crafted gzip archives could trigger integer overflows. Attackers could exploit that to crash gzip or potentially execute arbitrary code (CVE-2010-0001). Only 64bit architectures are affected by this flaw.




References:
    https://bugzilla.novell.com/show_bug.cgi?id=570331
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2624
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0001

From announce-noreply@rpath.com Mon Jan 25 14:34:23 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o0PJYN04026837
	for <sle-announce@lists.rpath.com>; Mon, 25 Jan 2010 14:34:23 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o0PJYNgc023058
	for <sle-announce@lists.rpath.com>; Mon, 25 Jan 2010 14:34:23 -0500
Received: from build09.eng.rpath.com (build09.eng.rpath.com [172.16.160.209])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o0PJYN55013711;
	Mon, 25 Jan 2010 14:34:23 -0500
Date: Mon, 25 Jan 2010 14:34:23 -0500
Message-Id: <201001251934.o0PJYN55013711@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for gzip
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 25 Jan 2010 19:34:24 -0000

Published: 2010-01-25
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    gzip=sle.rpath.com@rpath:sles-10/1.3.5_159.10.1-1-1

Description:

The following bug has been fixed:



 Specially crafted gzip archives could trigger integer overflows. Attackers could exploit that to crash gzip or potentially execute arbitrary code (CVE-2010-0001). Only 64bit architectures are affected by this flaw.




From announce-noreply@rpath.com Mon Feb  1 13:38:40 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o11Ice0D006090
	for <sle-announce@lists.rpath.com>; Mon, 1 Feb 2010 13:38:40 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o11Icdvw002988
	for <sle-announce@lists.rpath.com>; Mon, 1 Feb 2010 13:38:39 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o11IcdJL019382;
	Mon, 1 Feb 2010 13:38:39 -0500
Date: Mon, 1 Feb 2010 13:38:39 -0500
Message-Id: <201002011838.o11IcdJL019382@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for dhcpcd
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 01 Feb 2010 18:38:40 -0000

Published: 2010-02-01
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    dhcpcd=sle.rpath.com@rpath:sles-11/3.2.3_44.10.1-1-1

Description:

This updates fixed to the sysconfig and dhcpcd packages, that have to be
installed together, because sysconfig requires synchronization changes
provided by the dhcpcd package.



The sysconfig package provides following fixes:



 The udevmountd rule provided in sysconfig was updated to prevent
udevmountd from mounting encrypted volumes in the background while boot.crypto
tries to do the same in the foreground (bnc#568577). 
 Fix to allow ifup tap when it already exists, e.g. created by kvm
(bnc#557864). 
 Synchronized ifup-dhcp and dhcpcd configuration steps to report status
after dhcpcd really finished all its steps (bnc#518219). 
 Improved detection if a dhcp client is running, causing ifup-dhcp and the
network script to report false  failures, when the client forks at the moment
of the check (bnc#562030 and others). 
 Avoid error message, when pcmcia device does not provide its vendor/name
info via sysfs device/prod_id files  (bnc#551640). 
 Fixed to not set WIRELESS_AP at all for wl driver (bnc#555774).
 Fixed typo in convert_persistent_name_rules script causing to generate
persistent name rules on update, not matching the MAC address (bnc#546575). 



The dhcpcd package provides following fixes:



 dhcpcd was not using gateway component of dhcp option 121 (classless
routes) in host routes (bnc#565030) 
 dhcpcd was setting bad routes when the gateway address were not in our
network (bnc#569972) 
 correctly remove the domain name part from hostname when -HHH option is
set as used in sysconfig (bnc#556613) 
 call dhcpcd script (/etc/sysconfig/network/scripts/dhcpcd-hook) once
again with "complete" when all configuration is done and hostname is set, to
allow ifup-dhcp to synchronize using it and report correct status (bnc#518219) 
 dhcp client swamps network with dhcp requests although the ip address is
already obtained (bnc#552916) 
 dhcpcd does not honor -p / --persistent option breaking nfs/iscsi root
systems (bnc#551376) 
 dhcpcd-3.x does not provide DHCPGIADDR and DHCPSIADDR info file as
dhcpcd-1.x did and breaks initrd nfs scripts (bnc#558744) 
 dhcpcd -T eth0 always returned error code 1 (bnc#551350), fixed implicit
pwrite(2) 




References:
    https://bugzilla.novell.com/show_bug.cgi?id=518219
    https://bugzilla.novell.com/show_bug.cgi?id=546575
    https://bugzilla.novell.com/show_bug.cgi?id=551350
    https://bugzilla.novell.com/show_bug.cgi?id=551376
    https://bugzilla.novell.com/show_bug.cgi?id=551640
    https://bugzilla.novell.com/show_bug.cgi?id=552916
    https://bugzilla.novell.com/show_bug.cgi?id=555774
    https://bugzilla.novell.com/show_bug.cgi?id=556613
    https://bugzilla.novell.com/show_bug.cgi?id=557864
    https://bugzilla.novell.com/show_bug.cgi?id=558744
    https://bugzilla.novell.com/show_bug.cgi?id=562030
    https://bugzilla.novell.com/show_bug.cgi?id=565030
    https://bugzilla.novell.com/show_bug.cgi?id=568577
    https://bugzilla.novell.com/show_bug.cgi?id=569972

From announce-noreply@rpath.com Mon Feb  1 13:38:40 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o11IceVP006091
	for <sle-announce@lists.rpath.com>; Mon, 1 Feb 2010 13:38:40 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o11IcdaK002989
	for <sle-announce@lists.rpath.com>; Mon, 1 Feb 2010 13:38:40 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o11Icd2d019384;
	Mon, 1 Feb 2010 13:38:39 -0500
Date: Mon, 1 Feb 2010 13:38:39 -0500
Message-Id: <201002011838.o11Icd2d019384@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for dhcpcd
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 01 Feb 2010 18:38:40 -0000

Published: 2010-02-01
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    sysconfig=sle.rpath.com@rpath:sles-11/0.71.14_12.6.1-1-1

Description:

This updates fixed to the sysconfig and dhcpcd packages, that have to be
installed together, because sysconfig requires synchronization changes
provided by the dhcpcd package.



The sysconfig package provides following fixes:



 The udevmountd rule provided in sysconfig was updated to prevent
udevmountd from mounting encrypted volumes in the background while boot.crypto
tries to do the same in the foreground (bnc#568577). 
 Fix to allow ifup tap when it already exists, e.g. created by kvm
(bnc#557864). 
 Synchronized ifup-dhcp and dhcpcd configuration steps to report status
after dhcpcd really finished all its steps (bnc#518219). 
 Improved detection if a dhcp client is running, causing ifup-dhcp and the
network script to report false  failures, when the client forks at the moment
of the check (bnc#562030 and others). 
 Avoid error message, when pcmcia device does not provide its vendor/name
info via sysfs device/prod_id files  (bnc#551640). 
 Fixed to not set WIRELESS_AP at all for wl driver (bnc#555774).
 Fixed typo in convert_persistent_name_rules script causing to generate
persistent name rules on update, not matching the MAC address (bnc#546575). 



The dhcpcd package provides following fixes:



 dhcpcd was not using gateway component of dhcp option 121 (classless
routes) in host routes (bnc#565030) 
 dhcpcd was setting bad routes when the gateway address were not in our
network (bnc#569972) 
 correctly remove the domain name part from hostname when -HHH option is
set as used in sysconfig (bnc#556613) 
 call dhcpcd script (/etc/sysconfig/network/scripts/dhcpcd-hook) once
again with "complete" when all configuration is done and hostname is set, to
allow ifup-dhcp to synchronize using it and report correct status (bnc#518219) 
 dhcp client swamps network with dhcp requests although the ip address is
already obtained (bnc#552916) 
 dhcpcd does not honor -p / --persistent option breaking nfs/iscsi root
systems (bnc#551376) 
 dhcpcd-3.x does not provide DHCPGIADDR and DHCPSIADDR info file as
dhcpcd-1.x did and breaks initrd nfs scripts (bnc#558744) 
 dhcpcd -T eth0 always returned error code 1 (bnc#551350), fixed implicit
pwrite(2) 




References:
    https://bugzilla.novell.com/show_bug.cgi?id=518219
    https://bugzilla.novell.com/show_bug.cgi?id=546575
    https://bugzilla.novell.com/show_bug.cgi?id=551350
    https://bugzilla.novell.com/show_bug.cgi?id=551376
    https://bugzilla.novell.com/show_bug.cgi?id=551640
    https://bugzilla.novell.com/show_bug.cgi?id=552916
    https://bugzilla.novell.com/show_bug.cgi?id=555774
    https://bugzilla.novell.com/show_bug.cgi?id=556613
    https://bugzilla.novell.com/show_bug.cgi?id=557864
    https://bugzilla.novell.com/show_bug.cgi?id=558744
    https://bugzilla.novell.com/show_bug.cgi?id=562030
    https://bugzilla.novell.com/show_bug.cgi?id=565030
    https://bugzilla.novell.com/show_bug.cgi?id=568577
    https://bugzilla.novell.com/show_bug.cgi?id=569972

From announce-noreply@rpath.com Mon Feb  1 13:38:40 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o11IcepO006095
	for <sle-announce@lists.rpath.com>; Mon, 1 Feb 2010 13:38:40 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o11IceMr002990
	for <sle-announce@lists.rpath.com>; Mon, 1 Feb 2010 13:38:40 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o11IcdLd019386;
	Mon, 1 Feb 2010 13:38:39 -0500
Date: Mon, 1 Feb 2010 13:38:39 -0500
Message-Id: <201002011838.o11IcdLd019386@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for avahi
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 01 Feb 2010 18:38:40 -0000

Published: 2010-02-01
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    python-avahi=sle.rpath.com@rpath:sles-11/0.6.23_11.14.1-1-1
    libhowl0=sle.rpath.com@rpath:sles-11/0.6.23_11.14.1-1-1
    avahi-lang=sle.rpath.com@rpath:sles-11/0.6.23_11.14.1-1-1
    avahi=sle.rpath.com@rpath:sles-11/0.6.23_11.14.1-1-1
    libdns_sd=sle.rpath.com@rpath:sles-11/0.6.23_11.14.1-1-1

Description:
The avahi-daemon reflector could cause packet storms when reflecting legacy unicast mDNS traffic (CVE-2009-0758). This has been fixed.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=480865
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0758

From announce-noreply@rpath.com Mon Feb  1 13:38:41 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o11IcfUI006099
	for <sle-announce@lists.rpath.com>; Mon, 1 Feb 2010 13:38:41 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o11IcepJ002993
	for <sle-announce@lists.rpath.com>; Mon, 1 Feb 2010 13:38:40 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o11IcewT019391;
	Mon, 1 Feb 2010 13:38:40 -0500
Date: Mon, 1 Feb 2010 13:38:40 -0500
Message-Id: <201002011838.o11IcewT019391@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for acl and libacl
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 01 Feb 2010 18:38:41 -0000

Published: 2010-02-01
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    acl=sle.rpath.com@rpath:sles-11/2.2.47_30.5.1-1-1

Description:
The setfacl tool followed symbolic links in recursive (-R) mode even if the --physical (-P) option was specified (CVE-2009-4411). This has been fixed.


References:
    https://bugzilla.novell.com/show_bug.cgi?id=567090
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4411

From announce-noreply@rpath.com Mon Feb  1 20:44:18 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o121iIsN008031
	for <sle-announce@lists.rpath.com>; Mon, 1 Feb 2010 20:44:18 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o121iIfr017803
	for <sle-announce@lists.rpath.com>; Mon, 1 Feb 2010 20:44:18 -0500
Received: from build10.eng.rpath.com (build10.eng.rpath.com [172.16.160.210])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o121iISt003323;
	Mon, 1 Feb 2010 20:44:18 -0500
Date: Mon, 1 Feb 2010 20:44:18 -0500
Message-Id: <201002020144.o121iISt003323@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for net-snmp
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 02 Feb 2010 01:44:18 -0000

Published: 2010-02-01
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    net-snmp=sle.rpath.com@rpath:sles-10/5.3.0.1_25.32.3-1-1

Description:

This update of net-snmp fixes the following bugs:



 memory leak in snmp_udp_transport (bnc#559498)
 file descriptor leaks (bnc#541004)
 32-bit integer truncation logged as debug rather than error (bnc#535603)
 crash when 64-bit counters wrap (bnc#523553)
 incorrect CPU load calculation on multi-CPU machines (bnc#517852)
 process checking race condition (bnc#517369)
 lookups of fully qualified OID names (bnc#517254)
 unknown host names in snmp traps (bnc#514333)
 snmptrapd failing to handle command line option -A (bnc#514333)




From announce-noreply@rpath.com Mon Feb  1 21:31:17 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o122VHpE008221
	for <sle-announce@lists.rpath.com>; Mon, 1 Feb 2010 21:31:17 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o122VGps019050
	for <sle-announce@lists.rpath.com>; Mon, 1 Feb 2010 21:31:16 -0500
Received: from build10.eng.rpath.com (build10.eng.rpath.com [172.16.160.210])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o122VG4i004906;
	Mon, 1 Feb 2010 21:31:16 -0500
Date: Mon, 1 Feb 2010 21:31:16 -0500
Message-Id: <201002020231.o122VG4i004906@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for net-snmp
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 02 Feb 2010 02:31:17 -0000

Published: 2010-02-01
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    libsnmp15=sle.rpath.com@rpath:sles-11/5.4.2.1_8.2.1-1-1
    perl-SNMP=sle.rpath.com@rpath:sles-11/5.4.2.1_8.2.1-1-1
    snmp-mibs=sle.rpath.com@rpath:sles-11/5.4.2.1_8.2.1-1-1
    net-snmp=sle.rpath.com@rpath:sles-11/5.4.2.1_8.2.1-1-1

Description:

This update of net-snmp fixes the following bugs:



 truncated walk of hrSWRunPath (bnc#565586)
 crash when 64-bit counters wrap (bnc#523553)
 unknown host names in snmp traps (bnc#514333)




References:
    https://bugzilla.novell.com/show_bug.cgi?id=514333
    https://bugzilla.novell.com/show_bug.cgi?id=523553
    https://bugzilla.novell.com/show_bug.cgi?id=565586

From announce-noreply@rpath.com Mon Feb  1 21:31:17 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o122VHRv008222
	for <sle-announce@lists.rpath.com>; Mon, 1 Feb 2010 21:31:17 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o122VGQD019051
	for <sle-announce@lists.rpath.com>; Mon, 1 Feb 2010 21:31:16 -0500
Received: from build10.eng.rpath.com (build10.eng.rpath.com [172.16.160.210])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o122VGsQ004908;
	Mon, 1 Feb 2010 21:31:16 -0500
Date: Mon, 1 Feb 2010 21:31:16 -0500
Message-Id: <201002020231.o122VGsQ004908@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for ethtool
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 02 Feb 2010 02:31:17 -0000

Published: 2010-02-01
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    ethtool=sle.rpath.com@rpath:sles-11/6_78.23.1-1-1

Description:

ethtool was updated to fix the following bug:



 bnc#557016: ethtool is unable to set speed to 10Gbe




References:
    https://bugzilla.novell.com/show_bug.cgi?id=557016

From announce-noreply@rpath.com Wed Feb  3 14:28:58 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o13JSwwk019165
	for <sle-announce@lists.rpath.com>; Wed, 3 Feb 2010 14:28:58 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o13JSwKf005064
	for <sle-announce@lists.rpath.com>; Wed, 3 Feb 2010 14:28:58 -0500
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o13JSvtm002805;
	Wed, 3 Feb 2010 14:28:58 -0500
Date: Wed, 3 Feb 2010 14:28:57 -0500
Message-Id: <201002031928.o13JSvtm002805@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for ethtool
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 03 Feb 2010 19:28:58 -0000

Published: 2010-02-03
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    ethtool=sle.rpath.com@rpath:sles-10/3_15.15.1-1-1

Description:

ethtool was updated to fix the following bug: 



 #557025: ethtool does not support setting speed to 10Gbe




From announce-noreply@rpath.com Wed Mar 17 16:12:02 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o2HKC1DP026062
	for <sle-announce@lists.rpath.com>; Wed, 17 Mar 2010 16:12:01 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o2HKC1hT002079
	for <sle-announce@lists.rpath.com>; Wed, 17 Mar 2010 16:12:01 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o2HKC1Oq014580;
	Wed, 17 Mar 2010 16:12:01 -0400
Date: Wed, 17 Mar 2010 16:12:01 -0400
Message-Id: <201003172012.o2HKC1Oq014580@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for MySQL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 17 Mar 2010 20:12:02 -0000

Published: 2010-03-17
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    mysql-shared=sle.rpath.com@rpath:sles-10/5.0.26_12.24.5-1-1
    mysql-Max=sle.rpath.com@rpath:sles-10/5.0.26_12.24.5-1-1
    mysql=sle.rpath.com@rpath:sles-10/5.0.26_12.24.5-1-1
    mysql-client=sle.rpath.com@rpath:sles-10/5.0.26_12.24.5-1-1

Description:
This update fixes various security issues (bnc#557669) :


 upstream #47320 - checking server certificates (CVE-2009-4028)
 upstream #48291 - error handling in subqueries (CVE-2009-4019)
 upstream #47780 - preserving null_value flag in GeomFromWKB() (CVE-2009-4019)
 upstream #39277 - symlink behaviour fixed (CVE-2008-7247)
 upstream #32167 - symlink behaviour refixed (CVE-2009-4030)
 fixing remote buffer overflow (CVE-2009-4484)




From announce-noreply@rpath.com Wed Mar 17 16:12:02 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o2HKC1RN026063
	for <sle-announce@lists.rpath.com>; Wed, 17 Mar 2010 16:12:02 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o2HKC1Bx002080
	for <sle-announce@lists.rpath.com>; Wed, 17 Mar 2010 16:12:01 -0400
Received: from build06.eng.rpath.com (build06.eng.rpath.com [172.16.160.206])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o2HKC11N014582;
	Wed, 17 Mar 2010 16:12:01 -0400
Date: Wed, 17 Mar 2010 16:12:01 -0400
Message-Id: <201003172012.o2HKC11N014582@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for cron
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 17 Mar 2010 20:12:02 -0000

Published: 2010-03-17
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    cron=sle.rpath.com@rpath:sles-10/4.1_45.27.2-1-1

Description:

This update of cron fixes a race condition in crontab that can be used to change the time-stamp of arbitrary files while editing the crontab entry.



 CVE-2010-0424: CVSS v2 Base Score: 3.6
Additionally the return value of initgroups() is verified now.




From announce-noreply@rpath.com Sat Mar 20 13:25:27 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o2KHPRws011567
	for <sle-announce@lists.rpath.com>; Sat, 20 Mar 2010 13:25:27 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o2KHPRtg027175
	for <sle-announce@lists.rpath.com>; Sat, 20 Mar 2010 13:25:27 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o2KHPRxP014615;
	Sat, 20 Mar 2010 13:25:27 -0400
Date: Sat, 20 Mar 2010 13:25:27 -0400
Message-Id: <201003201725.o2KHPRxP014615@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for syslog-ng
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Sat, 20 Mar 2010 17:25:28 -0000

Published: 2010-03-20
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    syslog-ng=sle.rpath.com@rpath:sles-11/2.0.9_27.23.1-1-1

Description:


References:
    https://bugzilla.novell.com/show_bug.cgi?id=541802

From announce-noreply@rpath.com Mon Mar 22 08:48:39 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o2MCmdIP021986
	for <sle-announce@lists.rpath.com>; Mon, 22 Mar 2010 08:48:39 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o2MCmddI032371
	for <sle-announce@lists.rpath.com>; Mon, 22 Mar 2010 08:48:39 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o2MCmd0R005467;
	Mon, 22 Mar 2010 08:48:39 -0400
Date: Mon, 22 Mar 2010 08:48:39 -0400
Message-Id: <201003221248.o2MCmd0R005467@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Samba
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Mon, 22 Mar 2010 12:48:40 -0000

Published: 2010-03-22
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    samba-client=sle.rpath.com@rpath:sles-11/3.2.7_11.9.1-1-1
    libwbclient0=sle.rpath.com@rpath:sles-11/3.2.7_11.9.1-1-1
    libsmbclient0=sle.rpath.com@rpath:sles-11/3.2.7_11.9.1-1-1
    libsmbsharemodes0=sle.rpath.com@rpath:sles-11/3.2.7_11.9.1-1-1
    ldapsmb=sle.rpath.com@rpath:sles-11/3.2.7_11.9.1-1-1
    libtdb1=sle.rpath.com@rpath:sles-11/3.2.7_11.9.1-1-1
    samba-winbind=sle.rpath.com@rpath:sles-11/3.2.7_11.9.1-1-1
    libtalloc1=sle.rpath.com@rpath:sles-11/3.2.7_11.9.1-1-1
    samba=sle.rpath.com@rpath:sles-11/3.2.7_11.9.1-1-1
    libnetapi0=sle.rpath.com@rpath:sles-11/3.2.7_11.9.1-1-1
    samba-krb-printing=sle.rpath.com@rpath:sles-11/3.2.7_11.9.1-1-1
    cifs-mount=sle.rpath.com@rpath:sles-11/3.2.7_11.9.1-1-1

Description:

With enabled "wide links" Samba follows symbolic links on the server
side, therefore allowing clients to overwrite arbitrary files
(CVE-2010-0926). This update changes the default setting to have
"wide links" disabled by default. The new default only works if
"wide links" is not set explicitly in smb.conf.



Due to a race condition in mount.cifs a local attacker could corrupt
/etc/mtab if mount.cifs is installed setuid root. mount.cifs is not
setuid root by default and it's not recommended to change that
(CVE-2010-0547).




References:
    https://bugzilla.novell.com/show_bug.cgi?id=577868
    https://bugzilla.novell.com/show_bug.cgi?id=577925
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0547
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0926

From announce-noreply@rpath.com Fri Mar 26 17:27:52 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o2QLRqJs016848
	for <sle-announce@lists.rpath.com>; Fri, 26 Mar 2010 17:27:52 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o2QLRqXY008213
	for <sle-announce@lists.rpath.com>; Fri, 26 Mar 2010 17:27:52 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o2QLRqk5006943;
	Fri, 26 Mar 2010 17:27:52 -0400
Date: Fri, 26 Mar 2010 17:27:52 -0400
Message-Id: <201003262127.o2QLRqk5006943@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for PolicyKit
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 26 Mar 2010 21:27:52 -0000

Published: 2010-03-26
Products:
    SLES 11 Delivered by rPath

Updated Versions:
    PolicyKit=sle.rpath.com@rpath:sles-11/0.9_14.27.1-1-1

Description:


References:
    https://bugzilla.novell.com/show_bug.cgi?id=509108

From announce-noreply@rpath.com Tue Mar 30 17:14:16 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o2ULEGJH007958
	for <sle-announce@lists.rpath.com>; Tue, 30 Mar 2010 17:14:16 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o2ULEFUi002565
	for <sle-announce@lists.rpath.com>; Tue, 30 Mar 2010 17:14:15 -0400
Received: from build09.eng.rpath.com (build09.eng.rpath.com [172.16.160.209])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o2ULEF5I021416;
	Tue, 30 Mar 2010 17:14:15 -0400
Date: Tue, 30 Mar 2010 17:14:15 -0400
Message-Id: <201003302114.o2ULEF5I021416@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenSSL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 30 Mar 2010 21:14:16 -0000

Published: 2010-03-30
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    openssl=sle.rpath.com@rpath:sles-10/0.9.8a_18.39.6-1-1

Description:

This update adds support for RFC5746 TLS renegotiations to address vulnerabilities tracked as (CVE-2009-3555). It also fixes a mishandling of OOM conditions in bn_wexpand (CVE-2009-3245).

Installation notes

This update is provided as RPM packages that can easily be installed onto a running system by using this command:

rpm -Fvh openssl.rpm openssl-devel.rpm openssl-doc.rpm

From announce-noreply@rpath.com Tue Apr  6 14:42:30 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o36IgUbV016727
	for <sle-announce@lists.rpath.com>; Tue, 6 Apr 2010 14:42:30 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o36IgUbT001384
	for <sle-announce@lists.rpath.com>; Tue, 6 Apr 2010 14:42:30 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o36IgU7X030454;
	Tue, 6 Apr 2010 14:42:30 -0400
Date: Tue, 6 Apr 2010 14:42:30 -0400
Message-Id: <201004061842.o36IgU7X030454@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Samba
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Tue, 06 Apr 2010 18:42:30 -0000

Published: 2010-04-06
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    samba-python=sle.rpath.com@rpath:sles-10/3.0.32_0.18-1-1
    samba-krb-printing=sle.rpath.com@rpath:sles-10/3.0.32_0.18-1-1
    samba-vscan=sle.rpath.com@rpath:sles-10/3.0.32_0.18-1-1
    libsmbclient=sle.rpath.com@rpath:sles-10/3.0.32_0.18-1-1
    samba-client=sle.rpath.com@rpath:sles-10/3.0.32_0.18-1-1
    samba-winbind=sle.rpath.com@rpath:sles-10/3.0.32_0.18-1-1
    libmsrpc=sle.rpath.com@rpath:sles-10/3.0.32_0.18-1-1
    cifs-mount=sle.rpath.com@rpath:sles-10/3.0.32_0.18-1-1

Description:

With enabled "wide links" samba follows symbolic links on the server
side, therefore allowing clients to overwrite arbitrary files
(CVE-2010-0926). This update changes the default setting to have
"wide links" disabled by default. The new default only works if
"wide links" is not set explicitly in smb.conf.



Due to a race condition in mount.cifs a local attacker could corrupt
/etc/mtab if mount.cifs is installed setuid root. mount.cifs is not
setuid root by default and it's not recommended to change that
(CVE-2010-0547).




From announce-noreply@rpath.com Fri Apr  9 08:24:34 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o39COXA0001810
	for <sle-announce@lists.rpath.com>; Fri, 9 Apr 2010 08:24:34 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o39COXuq007365
	for <sle-announce@lists.rpath.com>; Fri, 9 Apr 2010 08:24:33 -0400
Received: from build07.eng.rpath.com (build07.eng.rpath.com [172.16.160.207])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o39COXPR018197;
	Fri, 9 Apr 2010 08:24:33 -0400
Date: Fri, 9 Apr 2010 08:24:33 -0400
Message-Id: <201004091224.o39COXPR018197@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for module-init-tools
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Fri, 09 Apr 2010 12:24:34 -0000

Published: 2010-04-09
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    module-init-tools=sle.rpath.com@rpath:sles-10/3.2.2_32.37.2-1-1

Description:
This update to module-init-tools contains various fixes:


The weak-modules script has been fixed to not symlink modules for different kernel flavors.
The modprobe configuration file has been updated to avoid a deadlock when mounting the binfmt_misc filesystem.
The configuration has been updated to load USB HCI drivers in the correct order.


From announce-noreply@rpath.com Wed Apr 21 10:20:24 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKO4I006617
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOxm016469
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKND7017098;
	Wed, 21 Apr 2010 10:20:23 -0400
Date: Wed, 21 Apr 2010 10:20:23 -0400
Message-Id: <201004211420.o3LEKND7017098@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for e2fsprogs
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:25 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    e2fsprogs=sle.rpath.com@rpath:sles-10/1.38_25.36.1-1-1
    libcom_err=sle.rpath.com@rpath:sles-10/1.38_25.36.1-1-1

Description:

This collective update for e2fsprogs contains the following fixes:



 #558035 - resize2fs leaves corrupt file system when resizing from 12MB to 20GB
 #545734 - uuid_generate_time generates sometimes duplicate UUIDs
 #572945 - Support the creation of  16TB file systems
 #380579 - man page refers to ext2resize tool which does not exist on the system




From announce-noreply@rpath.com Wed Apr 21 10:20:24 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKOsJ006618
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOpK016468
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKNhd017096;
	Wed, 21 Apr 2010 10:20:23 -0400
Date: Wed, 21 Apr 2010 10:20:23 -0400
Message-Id: <201004211420.o3LEKNhd017096@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for cron
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:25 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    cron=sle.rpath.com@rpath:sles-10/4.1_45.31.1-1-1

Description:

This update of cron fixes a race condition in crontab that can be used to change the time-stamp of arbitrary files while editing the crontab entry.



 CVE-2010-0424: CVSS v2 Base Score: 3.6
Additionally the return value of initgroups() is verified now.




From announce-noreply@rpath.com Wed Apr 21 10:20:24 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKOwB006619
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKO8i016470
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKN7L017100;
	Wed, 21 Apr 2010 10:20:23 -0400
Date: Wed, 21 Apr 2010 10:20:23 -0400
Message-Id: <201004211420.o3LEKN7L017100@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for timezone
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:25 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    timezone=sle.rpath.com@rpath:sles-10/2010h_0.4.1-1-1

Description:

Updated tzdata version to 2010h:



 DST changes: Asia/Dhaka, Asia/Karachi, Asia/Gaza, Asia/Damascus,
    Pacific/Apia, Pacific/Fiji, Africa/Tunis
    America/Santiago, Pacific/Easter, America/Asuncion
 New zones: America/Matamoros, America/Ojinaga, America/Santa_Isabel
 GMT offset changes: Europe/Samara, Asia/Kamchatka, Asia/Anadyr
 Various Antarctica timezone changes
 Number of Time Zones used in Russia were reduced to 9 and several
    regions changed timezones.




From announce-noreply@rpath.com Wed Apr 21 10:20:25 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKOg4006620
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOZh016471
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKNGu017102;
	Wed, 21 Apr 2010 10:20:23 -0400
Date: Wed, 21 Apr 2010 10:20:23 -0400
Message-Id: <201004211420.o3LEKNGu017102@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for expat
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:26 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    expat=sle.rpath.com@rpath:sles-10/2.0.0_13.9.1-1-1

Description:
The previous expat security update (CVE-2009-3560) caused
parse errors with some xml documents.


From announce-noreply@rpath.com Wed Apr 21 10:20:25 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKOwA006629
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOPF016475
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKObL017110;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKObL017110@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenLDAP 2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:26 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    openldap2-client=sle.rpath.com@rpath:sles-10/2.3.32_0.36.91-1-1

Description:
This update of openldap2 makes SSL certificate verification
more robust against uses of the special character \0 in the
subjects name. (CVE-2009-2408)


From announce-noreply@rpath.com Wed Apr 21 10:20:25 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKOtv006625
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOah016474
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKOpK017108;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKOpK017108@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for sudo
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:26 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    sudo=sle.rpath.com@rpath:sles-10/1.6.8p12_18.17.1-1-1

Description:

This update fixes the following security issue:



 CVE-2010-0426:CVSS v2 Base Score: 6.6
    A privilege escalation flaw was found in the way
    sudo used to check file paths for pseudocommands.
    If local, unprivileged user was authorized by sudoers
    file to edit one or more files, it could lead to
    execution of arbitrary code, with the privileges
    of privileged system user (root).




From announce-noreply@rpath.com Wed Apr 21 10:20:25 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKOYO006623
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOFv016472
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKN6k017104;
	Wed, 21 Apr 2010 10:20:23 -0400
Date: Wed, 21 Apr 2010 10:20:23 -0400
Message-Id: <201004211420.o3LEKN6k017104@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for xntp
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:26 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    xntp=sle.rpath.com@rpath:sles-10/4.2.4p3_48.15.1-1-1

Description:
By sending specially crafted NTP packets attackers could
make ntpd flood it's log file with error messages or even
run into an endless loop (CVE-2009-3563).


From announce-noreply@rpath.com Wed Apr 21 10:20:25 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKOYR006630
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOLP016476
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKOwm017112;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKOwm017112@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for libgcc
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:26 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    gcc=sle.rpath.com@rpath:sles-10/4.1.2_20070115_0.30.1-3-1
    cpp=sle.rpath.com@rpath:sles-10/4.1.2_20070115_0.30.1-3-1
    libgcc=sle.rpath.com@rpath:sles-10/4.1.2_20070115_0.30.1-3-1
    gcc-c++=sle.rpath.com@rpath:sles-10/4.1.2_20070115_0.30.1-3-1
    libstdc++=sle.rpath.com@rpath:sles-10/4.1.2_20070115_0.30.1-3-1

Description:
- #550916: libgcc33-32bit package silently overwrites newer
  /usr/lib/libgcc_s.so.1

This patch avoids issues when installing multilib variants
of the SLE9 based compilers from the SDK and fixes the
issues if that already happened.


From announce-noreply@rpath.com Wed Apr 21 10:20:25 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKO6o006626
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOTc016473
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKN07017106;
	Wed, 21 Apr 2010 10:20:23 -0400
Date: Wed, 21 Apr 2010 10:20:23 -0400
Message-Id: <201004211420.o3LEKN07017106@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for pwdutils
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:26 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    pwdutils=sle.rpath.com@rpath:sles-10/3.0.7.1_17.32.1-1-1

Description:
Fix a problem in userdel where it can run into an endless
loop if the admin is not allowed to modify data stored in
LDAP.


From announce-noreply@rpath.com Wed Apr 21 10:20:25 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKPa3006642
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOiN016477
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKOdL017114;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKOdL017114@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Samba
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:27 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    samba-krb-printing=sle.rpath.com@rpath:sles-10/3.0.36_0.9.1-1-1
    samba-vscan=sle.rpath.com@rpath:sles-10/3.0.36_0.9.1-1-1
    samba-client=sle.rpath.com@rpath:sles-10/3.0.36_0.9.1-1-1
    samba-python=sle.rpath.com@rpath:sles-10/3.0.36_0.9.1-1-1
    cifs-mount=sle.rpath.com@rpath:sles-10/3.0.36_0.9.1-1-1
    libsmbclient=sle.rpath.com@rpath:sles-10/3.0.36_0.9.1-1-1
    samba-winbind=sle.rpath.com@rpath:sles-10/3.0.36_0.9.1-1-1
    libmsrpc=sle.rpath.com@rpath:sles-10/3.0.36_0.9.1-1-1

Description:

With enabled "wide links" samba follows symbolic links on the server
side, therefore allowing clients to overwrite arbitrary files
(CVE-2010-0926). This update changes the default setting to have
"wide links" disabled by default. The new default only works if
"wide links" is not set explicitly in smb.conf.



Due to a race condition in mount.cifs a local attacker could corrupt
/etc/mtab if mount.cifs is installed setuid root. mount.cifs is not
setuid root by default and it's not recommended to change that
(CVE-2010-0547).




From announce-noreply@rpath.com Wed Apr 21 10:20:25 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKPPB006643
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOZE016487
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKOAH017127;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKOAH017127@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Kerberos 5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:27 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    krb5=sle.rpath.com@rpath:sles-10/1.4.3_19.44.1-1-1

Description:
Specially crafted AES and RC4 packets could allow unauthenticated
remote attackers to trigger an integer overflow leads to heap memory
corruption (CVE-2009-4212). This has been fixed.


From announce-noreply@rpath.com Wed Apr 21 10:20:25 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKPk4006639
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOWu016478
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKODk017116;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKODk017116@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for parted
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:27 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    parted=sle.rpath.com@rpath:sles-10/1.6.25.1_15.28.1-1-1

Description:
Race condition in parted might cause /proc/partitions being
outdated after modification of partition table. Mismatches
between partition layouts "on disk" and "in kernel data"
can lead to data loss.


From announce-noreply@rpath.com Wed Apr 21 10:20:26 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKP48006652
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKObc016504
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKO8u017137;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKO8u017137@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for PHP5
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:27 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    php5-sqlite=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-soap=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-openssl=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-mysql=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-mbstring=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-gettext=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-ldap=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-sysvsem=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-pear=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-wddx=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-pdo=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-odbc=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-xmlreader=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-sysvmsg=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-tokenizer=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-ncurses=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-dom=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-posix=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-pcntl=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-dbase=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-ctype=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-sysvshm=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-bz2=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-gmp=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-exif=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-fastcgi=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-iconv=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-bcmath=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-zlib=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-calendar=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-dba=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-sockets=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-xmlrpc=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-shmop=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1
    php5-ftp=sle.rpath.com@rpath:sles-10/5.2.5_9.25.1-1-1

Description:

This update of PHP5 fixes:



 CVE-2008-5624: CVSS v2 Base Score: 7.5 (HIGH) (AV:N/AC:L/Au:N/C:P/I:P/A:P): Permissions, Privileges, and Access Control (CWE-264)
 CVE-2008-5625: CVSS v2 Base Score: 7.5 (HIGH) (AV:N/AC:L/Au:N/C:P/I:P/A:P): Permissions, Privileges, and Access Control (CWE-264)
 CVE-2008-5814: CVSS v2 Base Score: 2.6 (LOW) (AV:N/AC:H/Au:N/C:N/I:P/A:N): Cross-Site Scripting (XSS) (CWE-79)
 CVE-2009-2626: CVSS v2 Base Score: 6.4 (MEDIUM) (AV:N/AC:L/Au:N/C:P/I:N/A:P): Other (CWE-Other)
 CVE-2009-2687: CVSS v2 Base Score: 4.3 (MEDIUM) (AV:N/AC:M/Au:N/C:N/I:N/A:P): Input Validation (CWE-20)
 CVE-2009-3546: CVSS v2 Base Score: 4.4 (moderate) (AV:L/AC:M/Au:N/C:P/I:P/A:P): Other (CWE-Other)
 CVE-2009-4017: CVSS v2 Base Score: 5.0 (moderate) (AV:N/AC:L/Au:N/C:N/I:N/A:P): Other (CWE-Other)
 CVE-2009-4142: CVSS v2 Base Score: 4.3 (MEDIUM) (AV:N/AC:M/Au:N/C:N/I:P/A:N): Cross-Site Scripting (XSS) (CWE-79)




From announce-noreply@rpath.com Wed Apr 21 10:20:26 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKPi0006648
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOZt016480
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKOSP017121;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKOSP017121@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for net-snmp
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:27 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    net-snmp=sle.rpath.com@rpath:sles-10/5.3.0.1_25.34.1-1-1

Description:

This update of net-snmp fixes the following bugs:



 memory leak in snmp_udp_transport (bnc#559498)
 file descriptor leaks (bnc#541004)
 32-bit integer truncation logged as debug rather than error (bnc#535603)
 crash when 64-bit counters wrap (bnc#523553)
 incorrect CPU load calculation on multi-CPU machines (bnc#517852)
 process checking race condition (bnc#517369)
 lookups of fully qualified OID names (bnc#517254)
 unknown host names in snmp traps (bnc#514333)
 snmptrapd failing to handle command line option -A (bnc#514333)




From announce-noreply@rpath.com Wed Apr 21 10:20:25 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKPuB006644
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOBr016483
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKOp3017123;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKOp3017123@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for Apache 2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:27 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    apache2=sle.rpath.com@rpath:sles-10/2.2.3_16.28.1-1-1
    apache2-worker=sle.rpath.com@rpath:sles-10/2.2.3_16.28.1-1-1
    apache2-prefork=sle.rpath.com@rpath:sles-10/2.2.3_16.28.1-1-1

Description:
This update of the Apache webserver fixes various security
issues:
- the option IncludesNOEXEC could be bypassed via .htaccess
  (CVE-2009-1195) 
- mod_proxy could run into an infinite loop when used as
  reverse  proxy (CVE-2009-1890) 
- mod_deflate continued to compress large files even after
  a network connection was closed, causing mod_deflate to
  consume large amounts of CPU (CVE-2009-1891)
- The ap_proxy_ftp_handler function in
  modules/proxy/proxy_ftp.c in the mod_proxy_ftp module
  allows remote FTP servers to cause a denial of service
  (NULL pointer dereference and child process crash) via a
  malformed reply to an EPSV command. (CVE-2009-3094)
- access restriction bypass in mod_proxy_ftp module
  (CVE-2009-3095)

Also a incompatibility between mod_cache and mod_rewrite
was fixed.


From announce-noreply@rpath.com Wed Apr 21 10:20:26 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKPDi006649
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOdi016492
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKO6o017129;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKO6o017129@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for nfs-utils
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:28 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    nfs-utils=sle.rpath.com@rpath:sles-10/1.0.7_36.37.1-1-1

Description:
Collective nfs-utils update:

- Fix bug where "exportfs -r" can sometimes unexport
  filesystems incorrectly.
- Fix bug in idmapd where a SIGHUP is not sufficient for it
  to reread it's configuration.


From announce-noreply@rpath.com Wed Apr 21 10:20:26 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKP0E006645
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOBo016479
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKOnG017118;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKOnG017118@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for sysstat
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:29 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    sysstat=sle.rpath.com@rpath:sles-10/8.0.4_1.8.1-1-1

Description:
Collective update for sysstat:

- #549608: Stray periodic auditd log traffic
- #550418: [sysstat] sar* files are missing information
  after 18:00:00
- #551377: bug sysstat :No statistic recorded


From announce-noreply@rpath.com Wed Apr 21 10:20:29 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKQf1006661
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:26 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKPXP016507
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKOmq017139;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKOmq017139@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for LVM2
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:30 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    lvm2=sle.rpath.com@rpath:sles-10/2.02.17_7.28.1-1-1

Description:

This update improves pvscan speed by using a label cache. 



Previous versions of LVM2 needed up to 20 minutes for scanning when many physical volumes where configured in a volume group.




From announce-noreply@rpath.com Wed Apr 21 10:20:28 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKQCe006657
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:26 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOJV016496
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKOMg017133;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKOMg017133@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for module-init-tools
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:30 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    module-init-tools=sle.rpath.com@rpath:sles-10/3.2.2_32.38.1-1-1

Description:
This update to module-init-tools contains various fixes:


The weak-modules script has been fixed to not symlink modules for different kernel flavors.
The modprobe configuration file has been updated to avoid a deadlock when mounting the binfmt_misc filesystem.


From announce-noreply@rpath.com Wed Apr 21 10:20:28 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKP95006653
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOr7016486
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:24 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKOkJ017125;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKOkJ017125@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for MySQL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:30 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    mysql-shared=sle.rpath.com@rpath:sles-10/5.0.26_12.28.1-1-1
    mysql-Max=sle.rpath.com@rpath:sles-10/5.0.26_12.28.1-1-1
    mysql=sle.rpath.com@rpath:sles-10/5.0.26_12.28.1-1-1
    mysql-client=sle.rpath.com@rpath:sles-10/5.0.26_12.28.1-1-1

Description:
This update fixes various security issues (bnc#557669):


 upstream #47320 - checking server certificates (CVE-2009-4028)
 upstream #48291 - error handling in subqueries (CVE-2009-4019)
 upstream #47780 - preserving null_value flag in GeomFromWKB() (CVE-2009-4019)
 upstream #39277 - symlink behaviour fixed (CVE-2008-7247)
 upstream #32167 - symlink behaviour refixed (CVE-2009-4030)
 fixing remote buffer overflow (CVE-2009-4484)




From announce-noreply@rpath.com Wed Apr 21 10:20:28 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKQXe006658
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:26 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKOsc016501
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKOE6017135;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKOE6017135@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for OpenSSL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:30 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    openssl=sle.rpath.com@rpath:sles-10/0.9.8a_18.42.2-1-1

Description:

This update adds support for RFC5746 TLS renegotiations to address vulnerabilities tracked as (CVE-2009-3555). It also fixes a mishandling of OOM conditions in bn_wexpand (CVE-2009-3245).

Installation notes

This update is provided as RPM packages that can easily be installed onto a running system by using this command:

rpm -Fvh openssl.rpm openssl-32bit.rpm openssl-64bit.rpm openssl-debuginfo.rpm openssl-devel.rpm openssl-devel-32bit.rpm openssl-devel-64bit.rpm openssl-doc.rpm openssl-x86.rpm

From announce-noreply@rpath.com Wed Apr 21 10:20:28 2010
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	o3LEKQGs006660
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:26 -0400
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id o3LEKO7c016495
	for <sle-announce@lists.rpath.com>; Wed, 21 Apr 2010 10:20:25 -0400
Received: from fred.rdu.rpath.com (fred.rdu.rpath.com [172.16.58.6])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id o3LEKOs0017131;
	Wed, 21 Apr 2010 10:20:24 -0400
Date: Wed, 21 Apr 2010 10:20:24 -0400
Message-Id: <201004211420.o3LEKOs0017131@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Security update for PostgreSQL
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2010 14:20:30 -0000

Published: 2010-04-21
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    postgresql-server=sle.rpath.com@rpath:sles-10/8.1.19_0.4.2-1-1
    postgresql-contrib=sle.rpath.com@rpath:sles-10/8.1.19_0.4.2-1-1
    postgresql=sle.rpath.com@rpath:sles-10/8.1.19_0.4.2-1-1

Description:

The following bugs have been fixed:



 An unprivileged, authenticated PostgreSQL user could create a table
which references functions with malicious content. Maintenance
operations carried out be the database superuser could execute such
functions (CVE-2009-4136).

 Embedded null bytes in the common name of SSL certificates could
bypass certificate hostname checks (CVE-2009-4034).



PostgreSQL was updated to the next upstream patchlevel update which also includes several bugfixes. See the package changelog for details.




From announce-noreply@rpath.com Wed Feb  2 17:45:42 2011
Received: from mx2.rpath.com (proxy1.eqx-dc2-be.rpath.com [172.16.180.40])
	by lists-app.eqx-dc2-be.rpath.com (8.13.7/8.13.7) with ESMTP id
	p12MjgZO029231
	for <sle-announce@lists.rpath.com>; Wed, 2 Feb 2011 17:45:42 -0500
Received: from rdu-nat.rpath.com (rdu-nat.rpath.com [66.192.95.194])
	by mx2.rpath.com (8.13.7/8.13.7) with ESMTP id p12MjgS1027887
	for <sle-announce@lists.rpath.com>; Wed, 2 Feb 2011 17:45:42 -0500
Received: from build08.eng.rpath.com (build08.eng.rpath.com [172.16.160.208])
	by rdu-nat.rpath.com (8.14.2/8.14.2) with ESMTP id p12MjfBA015250;
	Wed, 2 Feb 2011 17:45:41 -0500
Date: Wed, 2 Feb 2011 17:45:41 -0500
Message-Id: <201102022245.p12MjfBA015250@rdu-nat.rpath.com>
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rPath Update Announcements <announce-noreply@rpath.com>
To: sle-announce@lists.rpath.com
Subject: [sle-announce]  Recommended update for udev
X-BeenThere: sle-announce@lists.rpath.com
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Updates to SLES Delivered by rPath <sle-announce.lists.rpath.com>
List-Unsubscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=unsubscribe>
List-Archive: <http://lists.rpath.com/pipermail/sle-announce>
List-Post: <mailto:sle-announce@lists.rpath.com>
List-Help: <mailto:sle-announce-request@lists.rpath.com?subject=help>
List-Subscribe: <http://lists.rpath.com/mailman/listinfo/sle-announce>,
	<mailto:sle-announce-request@lists.rpath.com?subject=subscribe>
X-List-Received-Date: Wed, 02 Feb 2011 22:45:42 -0000

Published: 2011-02-02
Products:
    SLES 10 Delivered by rPath

Updated Versions:
    udev=sle.rpath.com@rpath:sles-10/085_30.58.3.6-1-1

Description:

This update for udev contains fixes for the following reports:

    * 619305: Slow passive path initialization on SUN CSM100RFC
    * 644655: udev event deadlock while renaming interfaces
    * 653712: Udev not consistently pointing to multipathed devices
    * 587955: allow to specify UDEVSETTLE_TIMEOUT=




