Re: [RHSA-2002:026-35] Vulnerability in zlib library

From: helmut g. katzgraber (dummkopfat_private)
Date: Tue Mar 12 2002 - 13:23:31 PST

  • Next message: hologram: "zlibscan : script to find suid binaries possibly affected by zlib vulnerability"

    hm... when i look at the rpm list below i notice that redhat 
    seems to be doing the same thing they did last time there was a 
    big upgrade: issue new kernel rpms, forget about the kernel 
    headers. while these might not change, several programs will barf 
    if the directory in which the headers are, does not match the 
    kernel version.... unless they put the headers now in the 
    kernel, which i doubt. a quick check of the 6.2 kernel rpm
    kernel-2.2.19-6.2.15.alpha.rpm shows that
    
    [debussy ~]$ rpm -qlf kernel-2.2.19-6.2.15.alpha.rpm | grep include
    
    it does not contain header files. please redhat, provide the 
    necessary rpms (in time)...
    
    i'd be careful to start patching without the headers. i'd be 
    careful without patching either...
    
    h.
    
    
    header of redhat advisory:
    
    # ---------------------------------------------------------------------
    #                    Red Hat, Inc. Red Hat Security Advisory
    # 
    # Synopsis:          Vulnerability in zlib library
    # Advisory ID:       RHSA-2002:026-35
    # Issue date:        2002-02-11
    # Updated on:        2002-03-11
    # Product:           Red Hat Linux
    # Keywords:          zlib double free
    # Cross references:  RHSA-2002:028 RHSA-2002:027
    # Obsoletes:         
    # ---------------------------------------------------------------------
    
    _______________________________________________________________
    Dr. Helmut G. Katzgraber           dummkopfat_private
    Department of Physics              http://nacaq.ucdavis.edu/
    University of California, Davis    Phone:     (+1) 530-752-9855
    One Shields Ave, Davis, CA 95616   Fax:       (+1) 530-752-4717
    



    This archive was generated by hypermail 2b30 : Tue Mar 12 2002 - 20:17:32 PST