Updated glibc packages that resolve vulnerabilities and address several bugs are now available.
Relevant releases/architectures:
Red Hat Linux 7.1 - i386, i686
Red Hat Linux 7.2 - i386, i686, ia64
Red Hat Linux 7.3 - i386, i686
Red Hat Linux 8.0 - i386, i686
Red Hat Linux 9 - i386, i686
А реально сюда прикрутить lpd, а то cups рушит систему в "Яйкс", как в прочем и сендмыло который вешает систему. Просто ещё не пробовал лпдешку ставить.
A bug in the getgrouplist function can cause a buffer overflow if
the size of the group list is too small to hold all the user's groups.
This overflow can cause segmentation faults in user applications, which may
have security implications, depending on the application in question. This
vulnerability exists only when an administrator has placed a user in a
number of groups larger than that expected by an application. Therefore,
there is no risk in instances where users are members of few groups. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2003-0689 to this issue.
И вот это потом виндовые аналитики приравняют к виндовой баге, позволяющей удаленно запускать произвольный код.
Потом решат, что этого мало, и посчитают релиз от каждого дистрибутива как отдельный.
Неудивительно, что после всего этого появляются статьи о том, какой же линукс на самом деле дырявый.
такой вот вопрос: у меня стоит RedHat 7.3 kernel2.4.22 я к нему прикрутил apt-get и обновляю софт с помошью него , так что если redhat перестанет поддерживать 7.3 я не смогу апдейтится через apt-get ??