Open Source - Red Hat Release Coincides with Host of Related Application, Kernel Fixes - eWeek Security Watch

Red Hat Release Coincides with Host of Related Application, Kernel Fixes

Written By
Lisa Vaas
Lisa Vaas
Mar 17, 2007
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

It turns out that, after years of engineering work and collaboration efforts with strategic partners such as IBM, Red Hat’s March 14 release of Red Hat Enterprise Linux 5 had the misfortune of coinciding with the company’s release of a whopping 11 security advisories.

Three of the advisories are rated critical, but those three pertain to other applications with critical flaws, the updated versions of which now are available for RHEL 5. They include multiple flaws, such as cross-site scripting and JavaScript handling errors, in the open-source Firefox browser. A second critical advisory covers flaws in Thunderbird, the open-source mail client. The third critical advisory concerns flaws in Ekiga, a tool for communicating with video and audio over the Internet.

The rest of Red Hat’s advisories were rated important or low. One of the important advisories included a fix to Red Hat’s RHEL 5 kernel. The vulnerabilities fixed in the Linux kernel include a flaw in the keyctl subsystem that allowed a local user to cause a DOS, a flaw in the Omnikey CardMan 4040 driver that allowed a local user to take over a system with kernel privileges, and a flaw in the core-dump handling that allowed a local user to create core dumps from unreadable binaries via PT_INTERP.

As has been noted in posts, the flaws aren’t unique to Red Hat.

“These aren’t Red [Hat] vulnerabilities per se—they affect a lot of distros,” wrote “NetArch” in response to a blog. “It’s just that they were discovered and fixed after Red Hat froze the code base. RH was just in the unfortunate position that the flaws were found very late in the release cycle. None of the other distros are releasing a new version right now, so RH ‘catches all the flak.'”

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.