Oval Definition:oval:com.redhat.rhba:def:20090070
Revision Date:2009-01-20Version:635
Title:RHBA-2009:0070: util-linux bug-fix update (Low)
Description:The util-linux package contains a large variety of low-level system utilities that are necessary for a Linux system to function. Among others, util-linux contains the fdisk configuration tool and the login program.

This update fixes the following bugs:

The login command segmentation fault on EOF.
  • The script command does not log all commands to the typescript file.
  • Obsolete information in the mkfs man page.
  • Obsolete information about fstab-sync in the fstab man page.
  • Obsolete information in the fdisk man page.
  • The blockdev command calls the blkpg ioctl with a wrong data structure.
  • The mount command does not check for validity of mtab information.
  • The mkswap defaults to v0 format on ppc64.
  • The fdisk command does not warn about DOS partition table limitations on on large hard drives.
  • The fdisk command does not properly detect VMware partitions.
  • The sfdisk command does not work correctly with large hard drives.
  • The logger command cannot be used when /usr is non-root partition.
  • The audit log injection attack via the login command.
  • The swapon command with the "-a" option does not complain about missing devices.

    Users of util-linux are advised to upgrade to this updated package, which resolves these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-1926
    RHBA-2009:0070
    RHBA-2009:0070-01
    RHBA-2009:0070-01
    RHBA-2009:0070
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND util-linux is earlier than 0:2.13-0.50.el5
  • AND util-linux is signed with Red Hat redhatrelease2 key
  • BACK