Skip to navigation

Security Advisory Moderate: pwlib security update

Advisory: RHSA-2007:0932-2
Type: Security Advisory
Severity: Moderate
Issued on: 2007-10-08
Last updated on: 2007-10-08
Affected Products: RHEL Desktop Workstation (v. 5 client)
RHEL Optional Productivity Applications (v. 5 server)
Red Hat Enterprise Linux Desktop (v. 5 client)
CVEs (cve.mitre.org): CVE-2007-4897

Details

Updated pwlib packages that fix a security issue are now available for Red
Hat Enterprise Linux 5.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

PWLib is a library used to support cross-platform applications.

In Red Hat Enterprise Linux 5, the Ekiga teleconferencing application uses
PWLib.

A memory management flaw was discovered in PWLib. An attacker could use this
flaw to crash an application, such as Ekiga, which is linked with pwlib
(CVE-2007-4897).

Users should upgrade to these updated packages which contain a backported
patch to correct this issue.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

RHEL Desktop Workstation (v. 5 client)

SRPMS:
pwlib-1.10.1-7.0.1.el5.src.rpm     MD5: 12bf503921102722f4fd4a186dbfe33a
 
IA-32:
pwlib-devel-1.10.1-7.0.1.el5.i386.rpm     MD5: a89f52f37a42bb2f99fd46624c13288d
 
x86_64:
pwlib-devel-1.10.1-7.0.1.el5.x86_64.rpm     MD5: 1b5db71a779c5dce18f44545403c6462
 
RHEL Optional Productivity Applications (v. 5 server)

SRPMS:
pwlib-1.10.1-7.0.1.el5.src.rpm     MD5: 12bf503921102722f4fd4a186dbfe33a
 
IA-32:
pwlib-1.10.1-7.0.1.el5.i386.rpm     MD5: 817015505ca658d99a772f9767c9a68d
pwlib-devel-1.10.1-7.0.1.el5.i386.rpm     MD5: a89f52f37a42bb2f99fd46624c13288d
 
x86_64:
pwlib-1.10.1-7.0.1.el5.x86_64.rpm     MD5: 0d60956bb433f4806818e508ca834634
pwlib-devel-1.10.1-7.0.1.el5.x86_64.rpm     MD5: 1b5db71a779c5dce18f44545403c6462
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
pwlib-1.10.1-7.0.1.el5.src.rpm     MD5: 12bf503921102722f4fd4a186dbfe33a
 
IA-32:
pwlib-1.10.1-7.0.1.el5.i386.rpm     MD5: 817015505ca658d99a772f9767c9a68d
 
x86_64:
pwlib-1.10.1-7.0.1.el5.x86_64.rpm     MD5: 0d60956bb433f4806818e508ca834634
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

292831 - CVE-2007-4897 ekiga GetHostAddress remote DoS


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/