openSUSE Security Update: bzip2 security update
______________________________________________________________________________
Announcement ID: openSUSE-SU-2010:0684-1
Rating: important
References: #636978
Cross-References: CVE-2010-0405
Affected Products:
openSUSE 11.3
openSUSE 11.2
openSUSE 11.1
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
This update fixes an integer overflow in the BZ2_decompress
function of bzip2/libbz2. This can be exploited via a
crafted archive to cause a denial of service or even
execute arbitrary code. (CVE-2010-0405)
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.3:
zypper in -t patch bzip2-3183
- openSUSE 11.2:
zypper in -t patch bzip2-3183
- openSUSE 11.1:
zypper in -t patch bzip2-3183
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 11.3 (i586 x86_64):
bzip2-1.0.5-39.1.1
libbz2-1-1.0.5-39.1.1
libbz2-devel-1.0.5-39.1.1
- openSUSE 11.3 (x86_64):
libbz2-1-32bit-1.0.5-39.1.1
- openSUSE 11.3 (noarch):
bzip2-doc-1.0.5-39.1.1
- openSUSE 11.2 (i586 x86_64):
bzip2-1.0.5-36.7.1
bzip2-doc-1.0.5-36.7.1
libbz2-1-1.0.5-36.7.1
libbz2-devel-1.0.5-36.7.1
- openSUSE 11.2 (x86_64):
libbz2-1-32bit-1.0.5-36.7.1
- openSUSE 11.1 (i586 ppc x86_64):
bzip2-1.0.5-34.6.1
bzip2-doc-1.0.5-34.6.1
libbz2-1-1.0.5-34.6.1
libbz2-devel-1.0.5-34.6.1
- openSUSE 11.1 (x86_64):
libbz2-1-32bit-1.0.5-34.6.1
- openSUSE 11.1 (ppc):
libbz2-1-64bit-1.0.5-34.6.1
References:
http://support.novell.com/security/cve/CVE-2010-0405.htmlhttps://bugzilla.novell.com/636978
openSUSE Recommended Update: xorg-x11-server: Collective update for xorg-x11-server
______________________________________________________________________________
Announcement ID: openSUSE-RU-2010:0683-1
Rating: low
References: #546062 #597232 #618152
Affected Products:
openSUSE 11.2
______________________________________________________________________________
An update that has three recommended fixes can now be
installed.
Description:
The following bugs are fixed by this update:
- Powersave turns screen black when user is watching a movie
- build Xserver again with '-O2' instead of '-O0', which
had been an unintentional change
- Prevent the xdmcp code from sending IPv6 link local
addresses to xdm as potential display numbers, because
they are unusable for xdm and e.g. break vnc based remote
adminstration.
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.2:
zypper in -t patch xorg-x11-Xvnc-3196
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 11.2 (i586 x86_64):
xorg-x11-Xvnc-7.4-61.65.1
xorg-x11-server-7.4-61.65.1
xorg-x11-server-extra-7.4-61.65.1
xorg-x11-server-sdk-7.4-61.65.1
References:
https://bugzilla.novell.com/546062https://bugzilla.novell.com/597232https://bugzilla.novell.com/618152
openSUSE Recommended Update: xorg-x11-server: Collective update for xorg-x11-server
______________________________________________________________________________
Announcement ID: openSUSE-RU-2010:0682-1
Rating: low
References: #546632 #597232 #618152
Affected Products:
openSUSE 11.1
______________________________________________________________________________
An update that has three recommended fixes can now be
installed.
Description:
The following bugs are fixed by this update:
- Powersave turns screen black when user is watching a movie
- build Xserver again with '-O2' instead of '-O0', which
had been an unintentional change
- Prevent the xdmcp code from sending IPv6 link local
addresses to xdm as potential display numbers, because
they are unusable for xdm and e.g. break vnc based remote
adminstration.
- Memory corruption issues in the Xrender extension have
been fixed (bnc#597232)
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.1:
zypper in -t patch xorg-x11-Xvnc-3190
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 11.1 (i586 ppc x86_64):
xorg-x11-Xvnc-7.4-17.9.5
xorg-x11-server-7.4-17.9.5
xorg-x11-server-extra-7.4-17.9.5
xorg-x11-server-sdk-7.4-17.9.5
References:
https://bugzilla.novell.com/546632https://bugzilla.novell.com/597232https://bugzilla.novell.com/618152
openSUSE Recommended Update: virtualbox-ose-guest-tools: Fix 'mount -t vboxsf' failure
______________________________________________________________________________
Announcement ID: openSUSE-RU-2010:0681-1
Rating: low
References: #636347
Affected Products:
openSUSE 11.3
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update fixes 'mount -t vboxsf' failing, because the
mount.vboxsf mount helper is installed in /usr/sbin, but
mount(8) expects it to be in /sbin.
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.3:
zypper in -t patch virtualbox-ose-guest-tools-3193
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 11.3 (i586 x86_64):
virtualbox-ose-guest-tools-3.2.6-2.1.1
References:
https://bugzilla.novell.com/636347
openSUSE Recommended Update: xorg-x11-driver-input: Update for clickpad and synaptics touchpad devices
______________________________________________________________________________
Announcement ID: openSUSE-RU-2010:0680-1
Rating: low
References: #620000 #620328
Affected Products:
openSUSE 11.3
______________________________________________________________________________
An update that has two recommended fixes can now be
installed.
Description:
Lots of fixes for synaptics touchpad device, especially for
clickpad device:
- Fix / improve the behavior in clickpad button area
- Fix left/right-button capability check
- Fix 64bit compatibility
- Avoid unexpected jumps by multiple finger touches
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.3:
zypper in -t patch xorg-x11-driver-input-3127
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 11.3 (i586 x86_64):
xorg-x11-driver-input-7.5-9.1.1
References:
https://bugzilla.novell.com/620000https://bugzilla.novell.com/620328
openSUSE Recommended Update: yast2-apparmor: This update fixes the function of AppArmor YaST module (control center)
______________________________________________________________________________
Announcement ID: openSUSE-RU-2010:0675-1
Rating: moderate
References: #635830
Affected Products:
openSUSE 11.3
______________________________________________________________________________
An update that has one recommended fix can now be
installed. It includes one version update.
Description:
This update fixes a packaging bug in yast2-apparmor
(Immunix/Notify.pm component located outside Perl @INC
path), due to which some parts of AppArmor YaST modules,
especially its control center, were broken.
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.3:
zypper in -t patch yast2-apparmor-3186
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 11.3 (noarch) [New Version: 2.19.1]:
yast2-apparmor-2.19.1-0.1.1
References:
https://bugzilla.novell.com/635830
openSUSE Recommended Update: iotop: It shows too high values. Fixed by this update
______________________________________________________________________________
Announcement ID: openSUSE-RU-2010:0674-1
Rating: low
References: #617281
Affected Products:
openSUSE 11.3
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
Because of changed alignment in the data iotop used T/s and
P/s instead of K/s or M/s on x86-64 systems. This update
fixes iotop and take the coorect field size from the data
header and then displays the correct values.
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.3:
zypper in -t patch iotop-3185
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 11.3 (i586 x86_64):
iotop-0.2.1-38.1.1
References:
https://bugzilla.novell.com/617281
openSUSE Recommended Update: pm-utils: This updates fixes a wrong function use
______________________________________________________________________________
Announcement ID: openSUSE-RU-2010:0673-1
Rating: low
References: #623290
Affected Products:
openSUSE 11.3
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
The log() is declared in the pm-functions. But pm-functions
includes functions. The correct solution is to put the
log() into the functions. Fixed by this update.
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.3:
zypper in -t patch pm-utils-3113
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 11.3 (i586 x86_64):
pm-utils-1.3.0-10.1.1
pm-utils-ndiswrapper-1.3.0-10.1.1
References:
https://bugzilla.novell.com/623290