[Whitebox-announce] [WBSA-2004:233-01] Updated cvs package fixes security issues

John Morris jmorris@beau.org
Thu, 10 Jun 2004 23:46:12 -0500 (CDT)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ----------------------------------------------------------------------
                   Security Advisory

Synopsis:          Updated cvs package fixes security issues
Advisory ID:       [WBSA-2004:233-01]
Issue date:        2004-06-09
Updated on:        2004-06-10
Product:           White Box Enterprise Linux 3.0 (i386, x86_64)
Keywords:          
Cross references:  
Obsoletes:         WBSA-2004:190
CVE Names:         CAN-2004-0414 CAN-2004-0416 CAN-2004-0417 CAN-2004-041
- ----------------------------------------------------------------------

An updated cvs package that fixes several server vulnerabilities, which
could be exploited by a malicious client, is now available.

More information is available in Red Hat, Inc's original advisory 
available on their site at:

http://www.redhat.com/archives/enterprise-watch-list/2004-June/msg00003.html

To install this new package on your White Box Enterprise Linux system
use the Up2Date Network or Yum.

Note: Be sure to change the default Up2Date or Yum server from the
initial location to prevent undue load to the whiteboxlinux.org
server, which doesn't have a lot of outbound bandwidth.  The config
files already have entries for mirror sites commented out.

Up2Date's configuration file is at /etc/sysconfig/rhn/sources

Yum's configuration is in /etc/yum.conf


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
Comment: Made with pgp4pine 1.76

iD8DBQFAyTkbqME6bvnsqA8RAobaAJwJnbb/RgGFUMpSGtOkq7oGFNkiHACfWEy8
v6u1vNSVnruRjZTsByxElPI=
=0SIA
-----END PGP SIGNATURE-----