An updated ia32el package that fixes several bugs is now available. This update has been rated as having low security impact by the Red Hat Security Response Team.
The ia32el package contains IA-32 Execution Layer platform which allows emulation of IA-32 binaries on IA-64. A flaw was found in the binfmt_elf loader of the Linux kernel which also affects the IA-32 Execution Layer. A local user could create an interpreter name string that is not NULL terminated, leading to a denial of service (crash). The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1072 to this issue. This update also addresses the following issues: -- Fixed execve to invoke ia32 interpreter -- Credential fixes -- Fixed a bug causing ibm-jvm to fail -- Other minor bug fixes Please refer to the package release notes for detailed information about these changes. All users of ia32el should upgrade to this updated package, which resolves these issues.
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center