Oval Definition:oval:com.redhat.rhsa:def:20050033
Revision Date:2005-02-15Version:502
Title:RHSA-2005:033: alsa-lib security update (Important)
Description:The alsa-lib package provides a library of functions for communication with kernel sound drivers.

A flaw in the alsa mixer code was discovered that caused stack execution protection to be disabled for the libasound.so library. The effect of this flaw is that stack execution protection, through NX or Exec-Shield, would be disabled for any application linked to libasound. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0087 to this issue

Users are advised to upgrade to this updated package, which contains a patched version of the library which correctly enables stack execution protection.
Family:unixClass:patch
Status:Reference(s):CVE-2005-0087
RHSA-2005:033-01
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 4 is installed
  • AND Package Information
  • alsa-lib-devel is earlier than 0:1.0.6-5.RHEL4
  • AND alsa-lib-devel is signed with Red Hat master key
  • OR
  • alsa-lib is earlier than 0:1.0.6-5.RHEL4
  • AND alsa-lib is signed with Red Hat master key
  • BACK