ELSA-2007-0878

ELSA-2007-0878 - Moderate: cyrus-sasl security update

Type:SECURITY
Impact:MODERATE
Release Date:2007-09-04

Description


[- 2.1.15-15]
- Changed spec file to include the mech patch all the time.
- Added patch to prevent printing null realm
- Applied existing mech for 1.5 to 2.1
Related: rhbz#189814

[2.1.15-14]
- temporarily back out the fixes for #157012, #190113

[2.1.15-13]
- add unapplied patches which make the DIGEST-MD5 plugins omit the realm
argument when the environment has
set to a
non-zero value, for testing purposes
- add missing build dependency on zlib-devel (#190113)

[2.1.15-12]
- make v1 of the sasl library use /dev/urandom instead of /dev/random, as
we do in v2 of the library at compile-time (#157012)

[2.1.15-11]
- backport fix for segfault in the digest-md5 module in cases when the
client didn't supply a realm (#189814, CVE-2006-1721)


Related CVEs



Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 3 (i386) cyrus-sasl-2.1.15-15.src.rpme66e8b5b517c18470a6046a15a886386c732b8837be8552bc1cfcf7ba7f10507-el3_i386_latest
cyrus-sasl-2.1.15-15.src.rpme66e8b5b517c18470a6046a15a886386c732b8837be8552bc1cfcf7ba7f10507-el3_u9_i386_patch
cyrus-sasl-2.1.15-15.i386.rpm6bd697bc9aaeffc44a30e071bed228df0a414c028d43ef5bef3a0d7661bd8620-el3_i386_latest
cyrus-sasl-2.1.15-15.i386.rpm6bd697bc9aaeffc44a30e071bed228df0a414c028d43ef5bef3a0d7661bd8620-el3_u9_i386_patch
cyrus-sasl-devel-2.1.15-15.i386.rpm6c2c0cd060c97d773f5856ee33e0e2d8cf844178acecf91794ee889a96847006-el3_i386_latest
cyrus-sasl-devel-2.1.15-15.i386.rpm6c2c0cd060c97d773f5856ee33e0e2d8cf844178acecf91794ee889a96847006-el3_u9_i386_patch
cyrus-sasl-gssapi-2.1.15-15.i386.rpm0b692f063f59a86bbc535cd311ca060368af5e8ca1683ff2523a070208d920df-el3_i386_latest
cyrus-sasl-gssapi-2.1.15-15.i386.rpm0b692f063f59a86bbc535cd311ca060368af5e8ca1683ff2523a070208d920df-el3_u9_i386_patch
cyrus-sasl-md5-2.1.15-15.i386.rpmcd7a3c486c2c8c345e98c82ba0e641e9a2a569134e19fcb0cf9f10c53fd3f174-el3_i386_latest
cyrus-sasl-md5-2.1.15-15.i386.rpmcd7a3c486c2c8c345e98c82ba0e641e9a2a569134e19fcb0cf9f10c53fd3f174-el3_u9_i386_patch
cyrus-sasl-plain-2.1.15-15.i386.rpm486bedb6614959a579f40305da01b4f6971766d5a6dd1925a29d4a0a807f11d3-el3_i386_latest
cyrus-sasl-plain-2.1.15-15.i386.rpm486bedb6614959a579f40305da01b4f6971766d5a6dd1925a29d4a0a807f11d3-el3_u9_i386_patch
Oracle Linux 3 (x86_64) cyrus-sasl-2.1.15-15.src.rpme66e8b5b517c18470a6046a15a886386c732b8837be8552bc1cfcf7ba7f10507-el3_u9_x86_64_patch
cyrus-sasl-2.1.15-15.src.rpme66e8b5b517c18470a6046a15a886386c732b8837be8552bc1cfcf7ba7f10507-el3_x86_64_latest
cyrus-sasl-2.1.15-15.i386.rpm6bd697bc9aaeffc44a30e071bed228df0a414c028d43ef5bef3a0d7661bd8620-el3_u9_x86_64_patch
cyrus-sasl-2.1.15-15.i386.rpm6bd697bc9aaeffc44a30e071bed228df0a414c028d43ef5bef3a0d7661bd8620-el3_x86_64_latest
cyrus-sasl-2.1.15-15.x86_64.rpmfffd02accb96faacff6d54fa9f80a4958d6a783d1480a128d068c92cbe66143c-el3_u9_x86_64_patch
cyrus-sasl-2.1.15-15.x86_64.rpmfffd02accb96faacff6d54fa9f80a4958d6a783d1480a128d068c92cbe66143c-el3_x86_64_latest
cyrus-sasl-devel-2.1.15-15.x86_64.rpm9415a512053dc8c910256b968e9521b0d0a5bf00b32daaf5f87cb90987473b71-el3_u9_x86_64_patch
cyrus-sasl-devel-2.1.15-15.x86_64.rpm9415a512053dc8c910256b968e9521b0d0a5bf00b32daaf5f87cb90987473b71-el3_x86_64_latest
cyrus-sasl-gssapi-2.1.15-15.i386.rpm0b692f063f59a86bbc535cd311ca060368af5e8ca1683ff2523a070208d920df-el3_u9_x86_64_patch
cyrus-sasl-gssapi-2.1.15-15.i386.rpm0b692f063f59a86bbc535cd311ca060368af5e8ca1683ff2523a070208d920df-el3_x86_64_latest
cyrus-sasl-gssapi-2.1.15-15.x86_64.rpm584c475c3846d686366f1d0e49f1947bef1bb4c2ad1756760b216e7da129febc-el3_u9_x86_64_patch
cyrus-sasl-gssapi-2.1.15-15.x86_64.rpm584c475c3846d686366f1d0e49f1947bef1bb4c2ad1756760b216e7da129febc-el3_x86_64_latest
cyrus-sasl-md5-2.1.15-15.i386.rpmcd7a3c486c2c8c345e98c82ba0e641e9a2a569134e19fcb0cf9f10c53fd3f174-el3_u9_x86_64_patch
cyrus-sasl-md5-2.1.15-15.i386.rpmcd7a3c486c2c8c345e98c82ba0e641e9a2a569134e19fcb0cf9f10c53fd3f174-el3_x86_64_latest
cyrus-sasl-md5-2.1.15-15.x86_64.rpm530d421ee1bd7526ba3a1e2f15147186381e5d6f4e5f2dafc8606afa48181b94-el3_u9_x86_64_patch
cyrus-sasl-md5-2.1.15-15.x86_64.rpm530d421ee1bd7526ba3a1e2f15147186381e5d6f4e5f2dafc8606afa48181b94-el3_x86_64_latest
cyrus-sasl-plain-2.1.15-15.i386.rpm486bedb6614959a579f40305da01b4f6971766d5a6dd1925a29d4a0a807f11d3-el3_u9_x86_64_patch
cyrus-sasl-plain-2.1.15-15.i386.rpm486bedb6614959a579f40305da01b4f6971766d5a6dd1925a29d4a0a807f11d3-el3_x86_64_latest
cyrus-sasl-plain-2.1.15-15.x86_64.rpme573f7e1f8f35cffa7160995a53c8e47cd75f6aaaf96dd4145af443fd2d43211-el3_u9_x86_64_patch
cyrus-sasl-plain-2.1.15-15.x86_64.rpme573f7e1f8f35cffa7160995a53c8e47cd75f6aaaf96dd4145af443fd2d43211-el3_x86_64_latest



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete