Versions of sudo prior to 1.6.4 would not clear the environment beforesending an email notification about unauthorized sudo attempts, making itpossible for an attacker to supply parameters to the mail program.
New groff packages have been made available that fix an overflow in groff.If the printing system running this is a security issue, it is recommendedto update to the new, fixed packages.
Updated namazu packages are available for Red Hat Linux 7.0J. Thesepackages fix cross-site scripting vulnerabilities. It also fixes a possiblebuffer overflow.
Updated exim packages are available, which fix a problem when handling certain types of addresses with some configurations. The default configuration does not exhibit this problem.
Updated stunnel packages are now available for Red Hat Linux 7.2. Theseupdates close a format-string vulnerability which is present in someearlier versions of stunnel.
New mutt packages that fix an overflow in mutt's address parsing code areavailable. It is recommended that all mutt users update to the fixed packages.