-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - --------------------------------------------------------------------- Fedora Legacy Test Update Notification FEDORALEGACY-2004-1230 Bugzilla https://bugzilla.fedora.us/show_bug.cgi?id=1230 2004-01-22 - --------------------------------------------------------------------- Name : elm Version 7.2 : 2.5.6-3 Version 7.3 : 2.5.6-4 Summary : The elm mail user agent. Description : Elm is a terminal mode email user agent. Elm includes all standard mailhandling features, including MIME support via metamail. Elm is still used by some people, but is no longer in active development. If you have used Elm before and you are devoted to it, you should install the elm package. If you want to use metamail's MIME support, you also need to install the metamail package. Install the screen package if you need a screen manager that can support multiple logins on one terminal. - --------------------------------------------------------------------- Update Information: CAN-2003-0966: Buffer overflow in the frm command in elm 2.5.6 and earlier allows remote attackers to execute arbitrary code via a long Subject line. - --------------------------------------------------------------------- Changelog: * Wed Jan 21 2004 Jonny Strom <jonny.strom@xxxxxxxxxx> - - 2.5.6, minor security fix CAN-2003-0966. - --------------------------------------------------------------------- This update can be downloaded from: http://download.fedoralegacy.org/redhat/ (sha1sums) 638ec1d1bee210ac094a9264a09c4aba24708620 7.2/updates-testing/SRPMS/elm-2.5.6-3.legacy.src.rpm 58e7d0bbb603585ea19fd7a25abe2375e3e1d991 7.2/updates-testing/i386/elm-2.5.6-3.legacy.i386.rpm 29d060d14c7fda79e26db4a8b5022e4f74efb826 7.3/updates-testing/SRPMS/elm-2.5.6-4.legacy.src.rpm 1146719b902bee3221cc8fdd571675497cd602bd 7.3/updates-testing/i386/elm-2.5.6-4.legacy.i386.rpm - --------------------------------------------------------------------- Notes: RHL 8.0 did not ship with elm. This is a re-issue to fix the fact that the 7.3 rpms were not gpg signed. Now they've been signed and therefor the sha1sums have changed. Please test and comment in bugzilla. - -- Jesse Keating RHCE MCSE (http://geek.j2solutions.net) Fedora Legacy Team (http://www.fedora.us/wiki/FedoraLegacy) Mondo DevTeam (www.mondorescue.org) GPG Public Key (http://geek.j2solutions.net/jkeating.j2solutions.pub) Was I helpful? Let others know: http://svcs.affero.net/rm.php?r=jkeating -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iD8DBQFAD/Vy4v2HLvE71NURAkznAKCGhzJ9VVarHpygqiX+4mAseby0dwCgtOTt p4sHUGfDmdGhWx/wJhClK+E= =Ur97 -----END PGP SIGNATURE-----