-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - --------------------------------------------------------------------- Fedora Test Update Notification FEDORA-2004-1224 Bugzilla https://bugzilla.fedora.us/show_bug.cgi?id=1224 2004-02-23 - --------------------------------------------------------------------- Name : mc Version 7.2 : 4.5.51-37.legacy Version 7.3 : mc-4.5.55-6.legacy Version 8.0 : mc-4.5.55-13.legacy Summary : A user-friendly file manager and visual shell. Description : Midnight Commander is a visual shell much like a file manager, only with many more features. It is a text mode application, but it also includes mouse support if you are running GPM. Midnight Commander's best features are its ability to FTP, view tar and zip files, and to poke into RPMs for specific files. - --------------------------------------------------------------------- Update Information: CAN-2003-1023: Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion. - --------------------------------------------------------------------- Changelog: * Sun Jan 25 2004 Michael Schwendt <mschwendt[AT]users.sf.net> - - Fix up missing build requirements. - - Move PAM dependency to mcserv package. * Sun Jan 18 2004 Jesse Keating <jkeating@xxxxxxxxxxxxxxx> - - updated to 4.5.51-37.legacy - - added patch for CAN-2003-1023 - --------------------------------------------------------------------- This update can be downloaded from: http://download.fedoralegacy.org/redhat/ 9f8a003f130fa1f9a97c77bb481791445885f1b5 7.2/updates-testing/SRPMS/mc-4.5.51-37.legacy.src.rpm b9a4452ffc5d1aaf99fcc2eff940dd6252c24446 7.2/updates-testing/i386/mc-4.5.51-37.legacy.i386.rpm 8c3ff32790268aa8d38e3b0c2a63da6c8b603363 7.2/updates-testing/i386/mcserv-4.5.51-37.legacy.i386.rpm f62558a3f57a388887376be2d3ede32334e4099d 7.2/updates-testing/i386/gmc-4.5.51-37.legacy.i386.rpm 045b05e94d3971759110bf6e5faf3797e8c771f1 7.3/updates-testing/SRPMS/mc-4.5.55-6.legacy.src.rpm d56d82b210636fe30c09d0ce09b38cf8572e4ab5 7.3/updates-testing/i386/mc-4.5.55-6.legacy.i386.rpm be63f46bf7e3b003b9d07a731ee158ec33215ff6 8.0/updates-testing/SRPMS/mc-4.5.55-13.legacy.src.rpm 34cfea3816c76dba42e3fb1ac4f15c6b48704b2d 8.0/updates-testing/i386/mc-4.5.55-13.legacy.i386.rpm Please note that this update is also available via yum and apt through the updates-testing channel. Many people find this an easier way to apply updates. - --------------------------------------------------------------------- - -- Jesse Keating RHCE (http://geek.j2solutions.net) Fedora Legacy Team (http://www.fedoralegacy.org) -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iD8DBQFAOwMP4v2HLvE71NURAryhAKCADo2MF+EtYqKN/VfyNn068IWBLQCgvJ5z YxeDZLasOHYV+Us7hxm1gAM= =Laru -----END PGP SIGNATURE-----