[FLSA-2004:1620] Updated cvs resolves security vulnerabilities

Dominic Hargreaves dom at earth.li
Fri Jun 4 13:22:16 UTC 2004


On Thu, Jun 03, 2004 at 11:28:58PM -0700, Jesse Keating wrote:
> -----------------------------------------------------------------------
>                Fedora Legacy Update Advisory
> 
> Synopsis:          Updated cvs resolves security vulnerability
> Advisory ID:       FLSA:1620
> Issue date:        2004-06-02
> Product:           Red Hat Linux
> Keywords:          Security
> Cross references:  https://bugzilla.fedora.us/show_bug.cgi?id=1620
> CVE Names:         CAN-2004-0180 CAN-2004-0396 CAN-2004-0405
> -----------------------------------------------------------------------

Hmm. Seems I missed the updates-testing for these packages, but I get
the following errors whilst installing onto my redhat 7.3 boxes:

Preparing...
##################################################
cvs
##################################################
install-info: warning: no info dir entry in
`//usr/share/info/cvs.info.gz'
install-info: warning: no info dir entry in
`//usr/share/info/cvsclient.info.gz'

Additionally the packages seem to be much smaller than the original
redhat updates and previous legacy updates:

cvs-1.11.1p1-8.7.i386.rpm                              17-Jan-2003 01:19  1.0M
cvs-1.11.1p1-9.7.legacy.i386.rpm                       24-Jan-2004 03:55  1.0M
cvs-1.11.1p1-14.legacy.3.i386.rpm                      04-Jun-2004 02:12  898K

Anyone else seen this?

Cheers,

Dominic.





More information about the fedora-legacy-list mailing list