Xmlsec1; Xorg-X11-Drivers - Red Hat ENTERPRISE LINUX 5.5 - TECHNICAL NOTES Manual

Table of Contents

Advertisement

Chapter 1. Package Updates

1.219. xmlsec1

1.219.1. RHSA-2009:1428: Moderate security update
Important
This update has already been released (prior to the GA of this release) as the security
RHSA-2009:1428
errata
Updated xmlsec1 packages that fix one security issue are now available for Red Hat Enterprise Linux
4 and 5.
This update has been rated as having moderate security impact by the Red Hat Security Response
Team.
The XML Security Library is a C library based on libxml2 and OpenSSL. It implements the XML
Signature Syntax and Processing and XML Encryption Syntax and Processing standards. HMAC is
used for message authentication using cryptographic hash functions. The HMAC algorithm allows the
hash output to be truncated (as documented in RFC 2104).
A missing check for the recommended minimum length of the truncated form of HMAC-based XML
signatures was found in xmlsec1. An attacker could use this flaw to create a specially-crafted XML file
that forges an XML signature, allowing the attacker to bypass authentication that is based on the XML
Signature specification.
Users of xmlsec1 should upgrade to these updated packages, which contain a backported patch to
correct this issue. After installing the updated packages, applications that use the XML Security Library
must be restarted for the update to take effect.

1.220. xorg-x11-drivers

1.220.1. RHEA-2010:0323: enhancement update
An updated xorg-x11-drivers package that adds an enhancement is now available.
xorg-x11-drivers is a metapackage that pulls in all the X drivers typically required for a particular
platform.
This updated package adds the following enhancement:
* The qxl driver is added to i386, AMD64 and Intel 64 platforms. qxl is an accelerated paravirtualized
graphics device in Red Hat's KVM virtualization platform.
All users should upgrade to this updated package, which adds this enhancement.
2188
https://www.redhat.com/security/data/cve/CVE-2009-0217.html
278
2187
2188
(CVE-2009-0217
)

Advertisement

Table of Contents
loading

This manual is also suitable for:

Enterprise linux 5.5

Table of Contents