Account Links: Cart | Register | Log In

Skip to content

Red Hat Linux 5.0 General Errata

The following are known problems with Red Hat Linux 5.0 on multiple platforms. Updates are available for FTP from:


Please note that newer versions of some of these packages may be available in the same location; any new versions which are made available will fix all of the bugs older versions did, so you can use the latest version with no problems.

We are no longer seperating the errata into general and platform specific errata If you are unsure whether an errata update is for your system, the following information should help:
Intel and Intel-based platform specific rpms will have the i386 extension, Sparc rpms will have the sparc extension, and rpms for the Alpha systems will have the alpha extension. This extension is before .rpm. For example:
foo.1.2-3.i386.rpm would be for the Intel systems
foo.1.2-3.sparc.rpm would be for Sparc systems
foo.1.2-3.alpha.rpm would be for Alpha systems

If you experience problems downloading the RPMS using Netscape or Internet Explorer, you will need to explicitely download to file versus opening in a window. The problem you are encountering is that both browsers think that .rpm files are text files and thus try to show the contents. In netscape, you can Shift-Click to correctly download the file.


Overview


Detailed Errata

  • Package: NFS

    Updated: 19-Apr-1999

    Problem:

    • (19-Apr-1999)Please update to the latest

      Same as before. We are moving NFS Updates to the top of the list and also updating it to the latest version. If you have an older version installed, please update.

    • (03-Jan-1999)Security Fix -- Risk High

      Due to many reports of continued security breaches from NFS, we are moving the NFS update to the top of the list to make sure people update to it if they have not already.

    Solution:


  • Package: procmail

    Updated: 16-Apr-1999

    Problem:

    • (16-Apr-1999):Security Fix

      Potential security problems have been identified in all the procmail packages shipped with Red Hat Linux. Currently Red Hat is not aware of any exploits built on these vulnerabilities.

      Red Hat would like to thank the members of the Bugtraq list for reporting these problems and the authors of procmail for quickly providing an update.

      Users of Red Hat Linux are recommended to upgrade to the new packages available under updates directory on our ftp site:

    Solution:


  • Package: lpr

    Updated: 16-Apr-1999

    Problem:

    • (16-Apr-1999) Security Fix:

      Security vulnerabilities have been found in the versions of lpr that ship with Red Hat Linux. Thanks go to the Linux Security Audit team for discovering the vulnerability. It is recommended that all users of Red Hat Linux upgrade to the new packages.

    • (23-Apr-1998) Security Fix:

      More buffer overflows have been found in lpr 0.30 as released on Saturday. As these flaws may allow users to gain root access to the local system, Red Hat, Inc. recommends that all users upgrade to lpr 0.31 immediately.

      Thanks to Niall Smart for finding this problem.

    • (18-Apr-1998) Security Fix:

      A major security problem has been found in all versions of lpr shipped with Red Hat Linux. Version 0.30 of lpr fixes this and is now available. Red Hat, Inc. encourages all users of Red Hat to upgrade to this new version immediately.

    Solution:


  • Package: XFree86

    Updated: (01-Apr-1999)

    Problem:

    Solution:

    In some circumstances, you may be required to add --force and/or --nodeps to the rpm command line options to insure a proper upgrade. Add these options if the command line given gives an error. Also as with all newer RPM packages you will need to upgrade to the latest RPM before installing these packages.


  • Package: pine

    Updated: (01-Apr-1999)

    Problem:

    • (01-Apr-1999):Security Fix

      An problem in the mime handling code could allow a remote user to execute certain commands on a local system.

      Red Hat would like to thank the members of the BUGTRAQ mailing list, the members of the Linux Security Audit team, and others. All users of Red Hat Linux are encouraged to upgrade to the new packages immediately. As always, these packages have been signed with the Red Hat PGP key.

    • (18-Dec-1997) pine locks when sending out a message after you invoke the alternate editor to compose a message.
    • (30-Dec-1997) Fixes window resizing problems (neither pine, nor pico were resizing properly
    • (08-Feb-1998) Corrects problems using external filters.

    Solution:


  • Package: mutt

    Updated: (01-Apr-1999)

    Problem:

    • (01-Apr-1999):Security Fix

      An problem in the mime handling code could allow a remote user to execute certain commands on a local system.

      Red Hat would like to thank the members of the BUGTRAQ mailing list, the members of the Linux Security Audit team, and others. All users of Red Hat Linux are encouraged to upgrade to the new packages immediately. As always, these packages have been signed with the Red Hat PGP key.

    Solution:


  • Package: zgv

    Updated: 01-Apr-1999

    Problem:

    • (01-Apr-1999):Security Fix
      Local users could gain root access.

      Red Hat would like to thank the members of the BUGTRAQ mailing list, the members of the Linux Security Audit team, and others. All users of Red Hat Linux are encouraged to upgrade to the new packages immediately. As always, these packages have been signed with the Red Hat PGP key.

    Solution:


  • Package: Sysklogd

    Updated: 01-Apr-1999

    Problem:

    • (01-Apr-1999):Security Fix

      An overflow in the parsing code could lead to crashes of the system logger.

      Red Hat would like to thank the members of the BUGTRAQ mailing list, the members of the Linux Security Audit team, and others. All users of Red Hat Linux are encouraged to upgrade to the new packages immediately. As always, these packages have been signed with the Red Hat PGP key.

    Solution:

    Further Instructions

    Once you have downloaded the sysklogd package for your architecture, you will need to do the following as root:

    
        rpm -Uvh sysklogd*rpm
    
        /etc/rc.d/init.d/syslog restart
    
        

  • Package: Kernel

    Updated: 19-Feb-1999

    Problem:

    Solution:


  • Package: wu-ftpd

    Updated: 09-Feb-1999

    Problem:

    • (09-Feb-1999):Security Fix

      A security vulnerability has been identified in all versions of the wu-ftpd server binary shipped with Red Hat Linux. For more information, see http://www.netect.com/advisory_0209.html

      New packages are available, and all users of Red Hat Linux are encouraged to upgrade to the new wu-ftpd releases immediately. As always, these packages have been signed with the Red Hat PGP key.

    Solution:


  • Package: minicom

    Updated: 02-Jun-1998

    Problem:

    • (O9-Feb-1999) Security Fix:

      Current minicom packages have permissions set to allow all users to access a modem on a system. This update fixes this problem limiting users to those listed in the minicom configuration file.

      New packages are available for the supported versions of Red Hat Linux. All users of Red Hat Linux are encouraged to upgrade to the new minicom releases immediately. As always, these packages have been signed with the Red Hat PGP key.

    • (02-Jun-1998) Security Fix:

      Buffer overflows have been found in the minicom package. Red Hat suggests all users upgrade to a new minicom version immediately.

    Solution:


  • Package: FVWM2

    Updated: 19-Jan-1999

    Problem:

    • (19-Jan-1999):Notice
      Users who update to the latest XFree86 also need to update to the latest FVWM2 rpms for AnotherLevel (Red Hat default window manager) to work.

    Solution:


  • Package: pam

    Updated: 02-Jan-1998

    Problem:

    • (02-Jan-1998)Security Fix:
      1. Risk level: SMALL

        The default configuration as shipped with the supported releases of Red Hat Linux is not vulnerable to this problem.

      2. Description

        A race condition that can be exploited under some particular scenarios has been identified in all versions of the Linux-PAM library shipped with all versions of Red Hat Linux. The vulnerability is exhibited in the pam_unix_passwd.so module included in Red Hat Linux, but *not* used by either of the 4.2 or 5.x releases. Red Hat Linux uses the pam_pwdb.so module for performing PAM authentication.

        You are at risk if you enabled pam_unix_passwd.so and are using it instead of the pam_pwdb.so module. An exploit occurs when an user with a umask setting of 0 is trying to change the login password.

        As of this release there are no known exploits of this security problem.

    Solution:

  • Package: Netscape

    Updated: 22-Dec--1998

    Problem:

    Solution:


  • Package: FTP client

    Updated: 22-Dec-1998

    Problem:

    • (22-Dec-1998):Security

      A security vulnerability has been identified in all versions of the ftp client binary shipped with Red Hat Linux. An exploit for this vulnerability would have to rely on getting the user to connect using passive mode to a server running a ftp daemon under the attacker's control. As of this release time there are no known exploits of this security problem.

      All users of Red Hat Linux are encouraged to upgrade to the new package releases immediately. As always, these packages have been signed with the Red Hat PGP key.

    Solution:

    Further Instructions

    Once you have downloaded the NetKit package for your architecture, you will need to do the following as root:

    
        rpm -Uvh ftp-0.10-4*rpm
    
        

  • Package: samba

    Updated: 17-Nov-1998

    Problem:

    • (17-Nov-1998) Security Fix:

      Following our announcement yesterday about new samba packages being available for our 5.2 release we have received reports that samba packages available for older releases of Red Hat Linux might be vulnerable as well.

      As a result of this concern we are making available new samba packages for all supported releases of Red Hat Linux. We apologize for not doing so yesterday, when we tried to address a specific reported vulnerability.

      Once again we express our thanks to Andrew Tridgell and the Samba team for their assistance in addressing this problem.

    • (14-Jul-1998) Security Fix:

      Serious security problems have been found in all versions of Samba shipped with Red Hat Linux. All users of samba should upgrade to the latest version, and restart samba with: /etc/rc.d/init.d/smb stop; /etc/rc.d/init.d/smb start as soon as possible.

    Solution:

    Further Instructions

    Once you have downloaded the samba package for your architecture, you will need to do the following as root:

    
        rpm -Uvh samba*rpm
    
        /etc/rc.d/init.d/smb restart
    
        

  • Package: libc

    Updated: 13-Nov-1998

    Problem:

    • (13-Nov-1998) Security Fix:

      A buffer overflow has been identified in all versions of the libc 5 packages shipped with Red Hat Linux. The most affected systems are those that are libc 5 based (Red Hat Linux 4.2 and older). Only the Intel is affected in 5.x.

      The Red Hat Linux 5.x releases are glibc (libc 6) based, and Red Hat does not ship any binaries linked against libc 5 that might be used for compromising the system's security. However, Red Hat Linux 5.x releases do include for backwards compatibility a package containg a vulnerable library.

      Users of Red Hat Linux are recommended to upgrade to the new packages available under updates directory on our ftp site:

    • (31-Dec-1997) Updates fixing many problems have been added.

    Solution:


  • Package: svgalib

    Updated: 06-Nov-1998

    Problem:

    • (06-Nov-1998) Security Fix:

      svgalib has been found to leak file descriptors to /dev/mem. Red Hat would like to thank the users of the BUGTRAQ security list for identifying the problem and Kevin Vajk for providing a fix. Users of Red Hat Linux are recommended to upgrade to the new packages available under the updates directory on our ftp site: To upgrade this package use the rpm command: rpm -Uvh svgalib-1.2.13-6

    • (27-Jun-1997) Security Fix:

      Minor security problems have been found by the Linux Security Auditing group in svgalib which allow users to make the console unuseable.

    • (25-Mar-1998)Security Fix:

      /tmp exploits have been discovered in this package. As usual, the package has been PGP signed with the Red Hat PGP key.

    Solution:


  • Package: cyrix

    Updated: 27-Oct-1998

    Problem:

    • (27-Oct-1998) Changes on FTP site cause this errata to need to be changed. Users need to get the gcc/egcs from the 5.1 or upgrade to the 5.1 release.
    • (29-Dec-1997) Fixes problems involving sig 11 during compiling on older Cyrix chips.
    • (05-Dec-1997) Cyrix processors may have sig 11 and other problems.

    Solution:

    • Intel: This again is _not_ an official update. It has been tested in the lab that the 5.1 gcc/egcs combinations get around the Cyrix problem that people were having. Another fix is to use the normal 5.0 gcc without any optimizations.

  • Package: rpm

    Updated: 23-Sep-1998

    Problem:

    • (23-Sep-1998): Several small cosmetic fixes have been found to get the 2.5.3 version of RPM to work as older versions did. Users will need to do the following as root:
      1. several symbolic links will need to be made for glint and similar programs to work.
        
                cd /usr/lib
                ln -s rpm/rpmrc ./rpmrc
                ln -s rpm/rpmpopt ./rpmpopt
        
        
      2. In addition, users on older Red Hat systems (5.0, 4.2, ...) who wish to use rpm to recompile programs from src rpm's will need to insure that the file /usr/lib/rpm/rpmrc contains correct paths for the compression programs gzip and bzip2. The two lines in /usr/lib/rpm/rpmrc that tell rpm the location of these programs are typically
        
                gzipbin:        /bin/gzip
                bzip2bin:       /usr/bin/bzip2
        
        
        
    • (10-Sep-1998): A newer version of RPM will be needed to upgrade security packages from now on. This version of rpm fixes various problems that were found in the previous version.
    • (02-Jul-1998)

      RPM reports problems with failed trigger scripts

    • (28-May-1998) A newer version of RPM is needed to be able to upgrade security releases from now on.

    • (31-Dec-1997)Security Fix: This fixes problems with RPM's --setperms option setting improper permissions on files.
    • (08-Jan-1998)Many fixes such as the ftp fix have been added.

    Solution:


  • Package: bash

    Updated: 09-Sep-1998

    Problem:

    • (09-Sep-1998) Security Fix:

      A security vulnerability has been identified in all versions of bash shipped with Red Hat Linux. Details on the nature of the bug have been posted recently to the BUGTRAQ security list.

      The bug is not immediately exploitable - it will require that a user with shell account on one machine create a carefully constructed directory structure and then wait for somebody else with a root account to cd into that directory.

      Red Hat would like to thank Joao Manuel Carolino , Fiji , and Razvan Dragomirescu for identifying this bug and Wichert Akkerman for providing an idea of a fix.

    Solution:


  • Package: xscreensaver

    Updated: 29-Aug-1998

    Problem:

    • (29-Aug-1998) This update fixes problems with core dumps in the xlyap function of xscreensaver. Thanks to the many people reporting this on the redhat list.
    • (10-Jun-1998) Security Fix:

      Various, minor security problems were found in this package. Thanks to Jamie Zawinski for fixing this.

    Solution:


  • Package: apache

    Updated: 11-Aug-1998

    Problem:

    • (11-Aug-1998)Security Fix:

      A denial-of-service attack against the Apache web server has been found which lets remote sites disable your web server. This attack does not let remote users gain any sort of access to your computer, nor does it let local users gain any special access.

      Red Hat recommends upgrading apache on systems which are functioning as Internet servers.

      	rpm -Uvh apache-1.2.6-5*rpm	 
              /etc/rc.d/init.d/httpd stop
              /etc/rc.d/init.d/httpd start
               
    • (07-Jan-1998)Security Fix:

      Some potentially serious security flaws have been found in apache. While there problems do not allow any compromises by remote users, they do allow local users to gain access to the UID which apache is running as. Under all versions of Red Hat Linux, this is the user 'nobody', which greatly minimizes the impact of these problems.

    • (31-Dec-1997)Security Fix:

      A denial-of-service attack against apache http servers was recentely discovered. This fixes the problem for 5.0.

    Solution:


  • Package: REAL

    Updated: 30-Jul-1998

    Problem:

    • (30-Jul-1998)Security Fix:

      This update fixes the following problems:

      • UDP security exploit
      • Proxy host string in the Preferences dialog box has a bug where the first host in the comma separated list is ignored.
    • (05-Apr-1998) This release is the Gold 5.0 player for Real Media. It fixes many bugs found in the previous beta clients. It also has no expiration date.

    • (14-Dec-1998) These new packages fix bugs in pnserver and rvplayer and extend the licenses until 30-APR-98. a new update should be available before then.

    Solution:


  • Package: SysVinit

    Updated: 30-Jul-1998

    Problem:

    • (30-Jul-1998)Security Fix:

      Update corrects a root-usable overflow in SysVInit allowed securelevels to be subverted.

    Solution:


  • Package: mutt

    Updated: 30-Jul-1998

    Problem:

    • (30-Jul-1998)Security Fix:

      Fixes buffer overflow problems found by BugTraq people that can cause mutt to crash and possibly execute intruder's code.

    Solution:


  • Package: ncurses

    Updated: 24-Jul-1998

    Problem:

    • (24-Jul-1998) Security Fix:

      Potential security problems have been identified in all versions of ncurses packages shipped with Red Hat Linux. Users of Red Hat Linux are recommended to upgrade to the new packages available under updates directory on our ftp site:

    • (10-Dec-1997) This fixes the screen size problems seen in ncftp (among others).
    • (31-Dec-1997)

      Fixes same problem as above, however, now built properly on the alpha as well.

    Solution:


  • Package: imap

    Updated: 24-Jul-1998

    Problem:

    • (24-Jul-1998) Security Fix: This version fixes buffer overflow problems found by the Linux Security Audit group in the imap daemon.
    • (12-Dec-1997) Some users reported imapd segfaulting on some inboxes. The latest versioni of imap sources fix this problem for the the test cases we have access to.

    Solution:


  • Package: initscripts

    Updated: 23-Jul-1998

    Problem:

    • (23-Jul-1998)

      This newer version fixes module issues when booting with loaders other than LILO, i.e. linload, syslinux, grub, chos, and problems with module dependencies.

      NOTE: This version of initscripts is intended for more recent, 2.0.34 and 2.0.35, kernels. Please see the 5.0 Intel errata for the newest kernel.

    • (10-Mar-1998) Security Fix: The initscripts package has various temporary file creation race conditions. These bugs allow local users to create at least denial of service conditions and may allow local users to gain root access to affected systems. All systems with local users that do not have the root password should have these fixes applied. The fixes are available for Red Hat Linux 5.0. As always, these packages have been signed with the Red Hat PGP key.
    • (30-Dec-1997) /proc gets mounted properly with this package. The package initscripts-3.25 had a bug that caused problems with some clone network device configurations. This also fixes the extremely slow tar extractions (a specific case of general user and group lookname brokeness)

    Solution: