DetailsAn updated lha package that fixes a buffer overflow is now available. LHA is an archiving and compression utility for LHarc format archives. SolutionBefore applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: http://www.redhat.com/docs/manuals/enterprise/ Updated packages
Bugs fixed (see bugzilla for more information)126740 - Buffer overflow in lha References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0694
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0745 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0769 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0771 http://marc.theaimsgroup.com/?l=bugtraq&m=108668791510153 http://lw.ftw.zamosc.pl/lha-exploit.txt These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from: https://www.redhat.com/security/team/key/#package The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/ |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||