libvorbis
157
• libvirt-cim would generate an incorrect boot tag for fully virtualized Xen guests, which would cause
a 'Missing boot device' error. Boot tags will now generate in the form <boot dev='hd'> instead of
<boot>hd</boot>, and guests will be able to start normally. (
BZ#503724
1175
)
This package also adds the following enhancements:
• KVM virtualization in Red Hat Enterprise Linux, as mentioned above, requires an updated version of
libvirt-cim to support the new hypervisor. libvirt-based CIM providers have been updated to enable
support for third-party system management tools for Xen and KVM. (
BZ#474681
1176
)
• Red Hat Enterprise Linux 4 introduced higher permission sensitivity to directory creation when
installing packages. When the root's umask was changed prior to installation, and a package did not
explicitly define directory permissions for a file, the installer would create directories based on the
umask of the user who ran the installation. This could result in an 'Unowned Directory' error. libvirt-
cim now includes full permission information, so directories are set up correctly during installation.
(
BZ#481810
1177
)
All users are advised to upgrade to this enhanced package, which resolves these issues.
1.129. libvorbis
1.129.1. RHSA-2009:1219: Important security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:1219
1178
Updated libvorbis packages that fix one security issue are now available for Red Hat Enterprise Linux
3, 4, and 5.
This update has been rated as having important security impact by the Red Hat Security Response
Team.
The libvorbis packages contain runtime libraries for use in programs that support Ogg Vorbis. Ogg
Vorbis is a fully open, non-proprietary, patent-and royalty-free, general-purpose compressed audio
format.
An insufficient input validation flaw was found in the way libvorbis processes the codec file headers
(static mode headers and encoding books) of the Ogg Vorbis audio file format (Ogg). A remote
attacker could provide a specially-crafted Ogg file that would cause a denial of service (memory
corruption and application crash) or, potentially, execute arbitrary code with the privileges of an
application using the libvorbis library when opened by a victim. (
CVE-2009-2663
1179
)
Users of libvorbis should upgrade to these updated packages, which contain a backported patch to
correct this issue. The desktop must be restarted (log out, then log back in) for this update to take
effect.
1179
https://www.redhat.com/security/data/cve/CVE-2009-2663.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...