Mandriva Security http://www.mandriva.com/en/security/advisories Mandriva security advisories en-us MDVA-2009:007: kernel http://www.mandriva.com/en/security/advisories?name=MDVA-2009:007 The security fix for CVE-2007-6716 in previous kernel update introduced<br /> a problem in directio, when calling pvcreate.<br /> <br /> This update provides an updated patch fixing it. MDVA-2009:001-1: dos2unix http://www.mandriva.com/en/security/advisories?name=MDVA-2009:001-1 The dos2unix command removes the last line of a file if no newline<br /> character(s) follow. This package fixes the issue.<br /> <br /> Update:<br /> <br /> This update now provides corrected packages for Mandriva Linux 2008.x<br /> and Corporate Server 4.0. MDVA-2009:006: xen http://www.mandriva.com/en/security/advisories?name=MDVA-2009:006 The xen package released in Mandriva Linux 2009.0 lacks udev rules for<br /> handling hotplug events. As a result trying to create an HVM host<br /> will fail with this kind of error message: 'Error: Device 0 (vif)<br /> could not be connected Hotplug scripts not working'. Additionaly,<br /> it also add PCI pass-through support that was also missing in the<br /> release package.<br /> <br /> This update fixes this issue. MDVA-2009:005: x11-server http://www.mandriva.com/en/security/advisories?name=MDVA-2009:005 This updated x11-server-xorg package provides the following fixes:<br /> <br /> The OpenOffice.org application menu would trigger a bug in the X<br /> server's xkb cache code causing it to crash (segfault).<br /> <br /> Fake key events generated by the XTest extension would not change<br /> the state of the keyboard leds. This would cause the numlock led to<br /> be inverted when the enable_X11_numlock program was used (Mandriva's<br /> default behaviour).<br /> <br /> This update corrects both issues. MDVA-2009:004: rpmdrake http://www.mandriva.com/en/security/advisories?name=MDVA-2009:004 This update fixes several minor issues with rpmdrake:<br /> <br /> - it stops running with debuging perl pragmas, which should speed up<br /> some things<br /> - it makes edit-urpm-sources not drop the 'ignore' flag when updating<br /> a medium (bug #44930)<br /> - it makes edit-urpm-sources display the right type of altered<br /> mirrorlist media (bug #44930)<br /> - it makes rpmdrake list plasma applets in GUI package list too<br /> (bug #45835)<br /> <br /> It also enhances searching in rpmdrake by fixing a rare crash on<br /> searching (bug #46225), by scrolling the group list to the search<br /> category when displaying results, and by updating the GUI package list. MDVA-2009:003: draksnapshot http://www.mandriva.com/en/security/advisories?name=MDVA-2009:003 This update fixes a crash in draksnapshot when hal is confused<br /> (bug #44966). MDVA-2009:002: msec http://www.mandriva.com/en/security/advisories?name=MDVA-2009:002 This update fixes the following two issues with msec:<br /> <br /> - when changing to a higher security level, permit_root_login is not<br /> handled correctly (bug #19726)<br /> - daily reports with multi-byte characters are not sent correctly<br /> (bug #26773) MDVA-2009:001: dos2unix http://www.mandriva.com/en/security/advisories?name=MDVA-2009:001 The dos2unix command removes the last line of a file if no newline<br /> character(s) follow. This package fixes the issue. MDVSA-2008:246: kernel http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:246 Some vulnerabilities were discovered and corrected in the Linux<br /> 2.6 kernel:<br /> <br /> The chip_command function in drivers/media/video/tvaudio.c in the<br /> Linux kernel 2.6.25.x before 2.6.25.19, 2.6.26.x before 2.6.26.7,<br /> and 2.6.27.x before 2.6.27.3 allows attackers to cause a denial of<br /> service (NULL function pointer dereference and OOPS) via unknown<br /> vectors. (CVE-2008-5033)<br /> <br /> Stack-based buffer overflow in the hfs_cat_find_brec function<br /> in fs/hfs/catalog.c in the Linux kernel before 2.6.28-rc1 allows<br /> attackers to cause a denial of service (memory corruption or system<br /> crash) via an hfs filesystem image with an invalid catalog namelength<br /> field, a related issue to CVE-2008-4933. (CVE-2008-5025)<br /> <br /> Additionally, added enhancements for a newer revision of Nokia models<br /> 6300, XpressMusic 5200, 5610 and 7610, the support for the ub USB<br /> module was disabled, added fixes for the Wake On LAN feature of the<br /> r8169 module, added fixes for suspend and resume on the i915 module,<br /> added ALSA fixes for Intel HDA, added workaround for a bug on iwlagn,<br /> added the m5602 driver, fixed a crash on the ppscsi module, added<br /> fixes to the uvcvideo module.<br /> <br /> To update your kernel, please follow the directions located at:<br /> <br /> http://www.mandriva.com/en/security/kernelupdate MDVA-2008:241: mailscanner http://www.mandriva.com/en/security/advisories?name=MDVA-2008:241 Local users can use symlink attacks throughout a flaw on<br /> trend-autoupdate script of MailScanner by using /tmp/opr.ini.#####<br /> or /tmp/lpt temporary file (CVE-2008-5140).<br /> <br /> Local users can use symlink attacks throughout flaws on<br /> clamav-autoupdate, panda-autoupdate and rav-autoupdate scripts of<br /> MailScanner by using ClamAV.update.log, pav.zip and RavBusy.lock<br /> temporary files (CVE-2008-5312).<br /> <br /> Local users can use symlink attacks throughout flaws on<br /> kaspersky-wrapper, bitdefender-wrapper, rav-wrapper scripts and<br /> Quarentine.pm, TNEF.pm, SA.pm, WorkArea.pm MailScanner perl modules<br /> by using kavoutput.tmp.27073, log.bdc.27073, report.vir.27073,<br /> MailScanner.ownertest.27073, tnef.27073 and MS.bayes.rebuild.lock<br /> temporary files (CVE-2008-5313).<br /> <br /> Further MailScanner had symlink flaws on antivir-autoupdate,<br /> bitdefender-autoupdate, clamav-autoupdate, etrust-autoupdate,<br /> generic-autoupdate, inoculan-autoupdate, kaspersky-autoupdate,<br /> nod32-autoupdate, norman-autoupdate, rav-autoupdate,<br /> sophos-autoupdate, symscanengine-autoupdate, vexira-autoupdate,<br /> f-prot-autoupdate and css-autoupdate scripts under following<br /> temporary vulnerable files: AntiVirBusy.lock, BitDefenderBusy.lock,<br /> ClamAVBusy.lock, eTrustBusy.lock, GenericBusy.lock, InoculanBusy.lock,<br /> KasperskyBusy.lock, Nod32Busy.lock, NormanBusy.lock, RavBusy.lock,<br /> SophosBusy.lock, SymScanEngineBusy.lock, VexiraBusy.lock,<br /> FProtBusy.lock and SYMCScan.lock.<br /> <br /> This update provides fix for all symlink flaws described on this<br /> security advisory.