Revision Date: | 2008-03-20 | Version: | 639 |
Title: | RHSA-2007:0542: mcstrans security and bug fix update (Low) |
Description: | mcstrans is the translation daemon used on SELinux machines to translate program context into human readable form.
An algorithmic complexity weakness was found in the way the mcstrans daemon handled ranges of compartments in sensitivity labels. A local user could trigger this flaw causing mctransd to temporarily stop responding to other requests; a partial denial of service. (CVE-2007-4570)
This update also fixes a problem where the mcstrans daemon was preventing SSH connections into an SELinux box, that was running a Multi-Level Security (MLS) Policy with multiple categories.
Users of mcstrans are advised to upgrade to this updated package, which resolves this issue.
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | CVE-2007-4570 RHSA-2007:0542 RHSA-2007:0542-05 RHSA-2007:0542-05
|
Platform(s): | Red Hat Enterprise Linux 5
| Product(s): | |
Definition Synopsis |
Red Hat Enterprise Linux must be installed OR Package Information
Red Hat Enterprise Linux 5 is installed
AND mcstrans is earlier than 0:0.2.6-1.el5
AND mcstrans is signed with Red Hat redhatrelease2 key
|