[Bluewhite64 Linux Security] udev (BW64SA:20090422-01)
Hash: SHA1
[Bluewhite64 Linux Security] udev (BW64SA:20090422-01)
New udev packages are available for Bluewhite64 Linux 11.0, 12.0, 12.1, 12.2,
and -current to fix security issues.
The udev packages in Bluewhite64 Linux 11.0, 12.0, 12.1, 12.2, and -current
contained a local root hole vulnerability:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1185
The udev packages in Bluewhite64 Linux 12.0, 12.1, 12.2, and -current had an integer
overflow which could result in a denial of service:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1186
Here are the details from the Bluewhite64 12.2 ChangeLog:
- -----------------------------------------------------------
PATCHES/packages/udev-141-x86_64-1.tgz: Upgraded to udev-141.
This upgrade fixes a local root hole and a denial of service issue.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1185
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1186
[*** Security fix ***]
Download the new packages from:
- ---------------------------------
For Bluewhite64 Linux 11.0:
http://data.bluewhite64.com/bluewhite64-11.0/patches/packages/udev-097-x86_64-9.tgz
For Bluewhite64 Linux 12.0:
http://data.bluewhite64.com/bluewhite64-12.0/patches/packages/udev-111-x86_64-6.tgz
For Bluewhite64 Linux 12.1:
http://data.bluewhite64.com/bluewhite64-12.1/patches/packages/udev-118-x86_64-4.tgz
For Bluewhite64 Linux 12.2:
http://data.bluewhite64.com/bluewhite64-12.2/patches/packages/udev-141-x86_64-2.tgz
For Bluewhite64 Linux -current:
http://data.bluewhite64.com/bluewhite64-current/bluewhite64/a/udev-141-x86_64-2.tgz
Also, please see the "Get Bluewhite64" section on http://www.bluewhite64.com for
additional mirror sites near you.
MD5 signatures:
- -----------------
Bluewhite64 11.0 package:
29ea772e4c87c2bbf0e34f94f62ee4a2 udev-097-x86_64-9.tgz
Bluewhite64 12.0 package:
306224fe0dc3dad96e773a7a6374a100 udev-111-x86_64-6.tgz
Bluewhite64 12.1 package:
0898fc69ab9da6e7ff112578985e686f udev-118-x86_64-4.tgz
Bluewhite64 12.2 package:
cb07fa2295ecefff7bdecc9ca8de7e74 udev-141-x86_64-2.tgz
Bluewhite64 -current package:
38b5da9b9c8f6b972486dd6b9b668073 udev-141-x86_64-2.tgz
Installation instructions:
- ---------------------------
Upgrade the package as root:
# upgradepkg udev-141-x86_64-2.tgz
Then, restart udev:
# sh /etc/rc.d/rc.udev restart
- ----
Bluewhite64 Linux Security Team
http://bluewhite64.com/gpg-key
+-------------------------------------------------------+
| To leave the bluewhite64-security mailing list:
+-------------------------------------------------------+
| Send a blank email to
|
| bluewhite64-security-unsubscribe©bluewhite64.com
|
| You will get a confirmation message back containing
| instructions to complete the process.
|
| Please do not reply to this email address.
+-------------------------------------------------------+
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAknvTYUACgkQpTOsxuDdlY4qaACfRPdBzrrlbqzqzKssfMOD5LBo
kEwAoIO0E+sL6mSbRfFV/npdepUDwbDw
=y6t5
-----END PGP SIGNATURE-----


