Chapter 1. Package Updates
76
Users of ghostscript are advised to apply this update.
1.69. giflib
1.69.1. RHSA-2009:0444: Important security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:0444
455
Updated giflib packages that fix several security issues are now available for Red Hat Enterprise Linux
5.
This update has been rated as having important security impact by the Red Hat Security Response
Team.
The giflib packages contain a shared library of functions for loading and saving GIF image files. This
library is API and ABI compatible with libungif, the library that supported uncompressed GIF image
files while the Unisys LZW patent was in effect.
Several flaws were discovered in the way giflib decodes GIF images. An attacker could create a
carefully crafted GIF image that could cause an application using giflib to crash or, possibly, execute
arbitrary code when opened by a victim. (
CVE-2005-2974
456
,
CVE-2005-3350
457
)
All users of giflib are advised to upgrade to these updated packages, which contain backported
patches to resolve these issues. All running applications using giflib must be restarted for the update
to take effect.
1.70. glib2
1.70.1. RHSA-2009:0336: Moderate security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:0336
458
Updated glib2 packages that fix several security issues are now available for Red Hat Enterprise Linux
5.
This update has been rated as having moderate security impact by the Red Hat Security Response
Team.
456
https://www.redhat.com/security/data/cve/CVE-2005-2974.html
457
https://www.redhat.com/security/data/cve/CVE-2005-3350.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...