Fedora Legacy Test Update Notification: gettext

Marc Deslauriers marcdeslauriers at videotron.ca
Sat Nov 19 16:04:11 UTC 2005


---------------------------------------------------------------------
Fedora Legacy Test Update Notification
FEDORALEGACY-2005-136323
Bugzilla https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136323
2005-11-19
---------------------------------------------------------------------

Name        : gettext
Versions    : rh9: gettext-0.11.4-7.2.legacy
Versions    : fc1: gettext-0.12.1-1.2.legacy
Versions    : fc2: gettext-0.14.1-2.1.2.legacy
Summary     : GNU libraries and utilities for producing multi-lingual
              messages.
Description :
The GNU gettext package provides a set of tools and documentation for
producing multi-lingual messages in programs. Tools include a set of
conventions about how programs should be written to support message
catalogs, a directory and file naming organization for the message
catalogs, a runtime library which supports the retrieval of translated
messages, and stand-alone programs for handling the translatable and
the already translated strings. Gettext provides an easy to use
library and tools for creating, using, and modifying natural language
catalogs and is a powerful and simple method for internationalizing
programs.

---------------------------------------------------------------------
Update Information:

An updated gettext package that fixes security bugs is now available.

The GNU gettext package provides a set of tools and documentation for
producing multi-lingual messages in programs.

Temporary file vulnerabilities were discovered in the gettext package. A
malicious user could use the "autopoint" and "gettextize" scripts to
create or overwrite another user's files. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CVE-2004-0966 to
this issue.

All users of gettext should upgrade to this updated package, which
includes a patch to correct these issues.

---------------------------------------------------------------------
Changelogs

rh9:
* Thu Nov 17 2005 Marc Deslauriers <marcdeslauriers at videotron.ca>
0.11.4-7.2.legacy
- Fixed typo in CAN-2004-0966 patch
- Added missing gcc-java and zlib-devel to BuildRequires

* Fri Oct 21 2005 Jeff Sheltren <sheltren at cs.ucsb.edu> 0.11.4-7.1.legacy
- Patch for CAN-2004-0966 (#136323)

fc1:
* Sat Nov 19 2005 Marc Deslauriers <marcdeslauriers at videotron.ca>
0.12.1.2.legacy
- Added missing gcc-java and zlib-devel to BuildRequires

* Fri Oct 21 2005 Jeff Sheltren <sheltren at cs.ucsb.edu> 0.12.1.1.legacy
- Patch for CAN-2004-0966 (#136323)

fc2:
* Sat Nov 19 2005 Marc Deslauriers <marcdeslauriers at videotron.ca>
0.14.1-2.1.2.legacy
- Added missing gcc-java and zlib-devel to BuildRequires

* Thu Oct 20 2005 Jeff Sheltren <sheltren at cs.ucsb.edu>
- Patch for CAN-2004-0966 (#136323)

---------------------------------------------------------------------
This update can be downloaded from:
  http://download.fedoralegacy.org/
(sha1sums)

rh9:
7b6dee52052cf366ae9d78f42d2266045992e8b2
redhat/9/updates-testing/i386/gettext-0.11.4-7.2.legacy.i386.rpm
ccb4260c2f1d4778bf1190bd6d96950c361b8131
redhat/9/updates-testing/SRPMS/gettext-0.11.4-7.2.legacy.src.rpm

fc1:
7b29432779dcbbb183b98fb5c60208366346ea93
fedora/1/updates-testing/i386/gettext-0.12.1-1.2.legacy.i386.rpm
22bc34eef7d35bad85cf013381187660a4a68c8d
fedora/1/updates-testing/SRPMS/gettext-0.12.1-1.2.legacy.src.rpm

fc2:
7851e6bb612ae72e3fae9870ca160d2a96e7123b
fedora/2/updates-testing/i386/gettext-0.14.1-2.1.2.legacy.i386.rpm
6c972dcef9866f7e53ba6855478078f8f24684d0
fedora/2/updates-testing/SRPMS/gettext-0.14.1-2.1.2.legacy.src.rpm

---------------------------------------------------------------------

Please test and comment in bugzilla.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: OpenPGP digital signature
URL: <http://listman.redhat.com/archives/fedora-legacy-list/attachments/20051119/8a01173e/attachment.sig>


More information about the fedora-legacy-list mailing list