Oval Definition:oval:com.redhat.rhsa:def:20141507
Revision Date:2014-10-14Version:638
Title:RHSA-2014:1507: trousers security, bug fix, and enhancement update (Low)
Description:TrouSerS is an implementation of the Trusted Computing Group's Software Stack (TSS) specification. You can use TrouSerS to write applications that make use of your TPM hardware. TPM hardware can create, store and use RSA keys securely (without ever being exposed in memory), verify a platform's software state using cryptographic hashes and more.

  • A flaw was found in the way tcsd, the daemon that manages Trusted Computing resources, processed incoming TCP packets. A remote attacker could send a specially crafted TCP packet that, when processed by tcsd, could cause the daemon to crash. Note that by default tcsd accepts requests on localhost only. (CVE-2012-0698)

    Red Hat would like to thank Andrew Lutomirski for reporting this issue.

  • The trousers package has been upgraded to upstream version 0.3.13, which provides a number of bug fixes and enhancements over the previous version, including corrected internal symbol names to avoid collisions with other applications, fixed memory leaks, added IPv6 support, fixed buffer handling in tcsd, as well as changed the license to BSD. (BZ#633584, BZ#1074634)

    All trousers users are advised to upgrade to these updated packages, which correct these issues and add these enhancements.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-0698
    CVE-2012-0698
    RHSA-2014:1507
    RHSA-2014:1507-01
    RHSA-2014:1507-02
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • trousers is earlier than 0:0.3.13-2.el6
  • AND trousers is signed with Red Hat redhatrelease2 key
  • trousers-devel is earlier than 0:0.3.13-2.el6
  • AND trousers-devel is signed with Red Hat redhatrelease2 key
  • trousers-static is earlier than 0:0.3.13-2.el6
  • AND trousers-static is signed with Red Hat redhatrelease2 key
  • BACK