The Linux Netfilter team has found a problem in the "IRC connectiontracking" component of the firewall within the linux kernel. This problemaffects Red Hat Linux versions 7.1 and 7.2.
New squid packages are available that fix various vulnerabilities. Some ofthese vulnerabilities could be used to perform a denial of service (DoS)attack or allow remote users to execute code as the user squid.
A problem has been found in ncurses version 5.0 that could cause a bufferoverflow. This overflow could be locally exploited if the library islinked into a program that runs setuid or setgid.
This updated at package fixes two minor problems and one majorproblem where the environment can get wiped out prior to the execution of ascheduled command.
There was an error in the original bugfix patch for thesecurity problem - the new rsync could fail under some circumstances. Thishas been fixed in a new build.