Oval Definition:oval:com.redhat.rhsa:def:20111327
Revision Date:2011-09-21Version:639
Title:RHSA-2011:1327: frysk security update (Moderate)
Description:frysk is an execution-analysis technology implemented using native Java and C++. It provides developers and system administrators with the ability to examine and analyze multi-host, multi-process, and multithreaded systems while they are running. frysk is released as a Technology Preview for Red Hat Enterprise Linux 4.

  • A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping engine used in the embedded Pango library. If a frysk application were used to debug or trace a process that uses HarfBuzz while it loaded a specially-crafted font file, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. (CVE-2011-3193)

    Users of frysk are advised to upgrade to this updated package, which contains a backported patch to correct this issue. All running frysk applications must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2011-3193
    RHSA-2011:1327
    RHSA-2011:1327-01
    RHSA-2011:1327-01
    Platform(s):Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND frysk is earlier than 0:0.0.1.2007.08.03-8.el4
  • AND frysk is signed with Red Hat redhatrelease2 key
  • BACK