April | 2011 | Proyecto Slackware Linux

Monthly Archives: April 2011

rdesktop (SSA:2011-110-01)

Descargar artículo en formato PDF [slackware-security] rdesktop (SSA:2011-110-01) New rdesktop packages are available for Slackware 11.0, 12.0, 12.1, 12.2, 13.0, 13.1, and -current to fix a security issue. Here are the details from the Slackware 13.1 ChangeLog: +————————–+ patches/packages/rdesktop-1.6.0-i486-2_slack13.1.txz: Rebuilt. Patched a traversal vulnerability (disallow /.. requests). http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1595 (* Security fix *) +————————–+ Where to [...]

Slackware-Security Tagged , , , , , , , Leave a comment

polkit (SSA:2011-109-01)

Descargar artículo en formato PDF [slackware-security] polkit (SSA:2011-109-01) New polkit packages are available for Slackware 13.1 and -current to fix a security issue. Here are the details from the Slackware 13.1 ChangeLog: +————————–+ patches/packages/polkit-1_14bdfd8-i486-2_slack13.1.txz: Rebuilt. Patched to fix a race condition that could allow a local user to execute arbitrary code as root. Thanks to [...]

Slackware-Security Tagged , , , , , , , Leave a comment

acl (SSA:2011-108-01)

Descargar artículo en formato PDF [slackware-security] acl (SSA:2011-108-01) New acl packages are available for Slackware 11.0, 12.0, 12.1, 12.2, 13.0, 13.1, and -current to fix a security issue. Here are the details from the Slackware 13.1 ChangeLog: +————————–+ patches/packages/acl-2.2.50-i486-1_slack13.1.txz: Upgraded. Fix the –physical option in setfacl and getfacl to prevent symlink attacks. Thanks to Martijn [...]

Slackware-Security Tagged , , , , , , , Leave a comment

kdelibs (SSA:2011-101-02)

Descargar artículo en formato PDF [slackware-security] kdelibs (SSA:2011-101-02) A new kdelibs package is available for Slackware 13.1 to fix a security issue. Here are the details from the Slackware 13.1 ChangeLog: +————————–+ patches/packages/kdelibs-4.4.3-i486-2_slack13.1.txz: Rebuilt. Patched CVE-2011-1168. For more information, see: http://www.kde.org/info/security/advisory-20110411-1.txt http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1168 (* Security fix *) +————————–+ Where to find the new package: +—————————–+ HINT: [...]

Slackware-Security Tagged , , , , , , , Leave a comment

libtiff (SSA:2011-098-01)

Descargar artículo en formato PDF [slackware-security] libtiff (SSA:2011-098-01) New libtiff packages are available for Slackware 9.0, 9.1, 10.0, 10.1, 10.2, 11.0, 12.0, 12.1, 12.2, 13.0, 13.1, and -current to fix security issues. Here are the details from the Slackware 13.1 ChangeLog: +————————–+ patches/packages/libtiff-3.9.4-i486-2_slack13.1.txz: Rebuilt. Patched overflows that could lead to arbitrary code execution when parsing [...]

Slackware-Security Tagged , , , , , , , Leave a comment

xrdb (SSA:2011-096-01)

Descargar artículo en formato PDF [slackware-security] xrdb (SSA:2011-096-01) New xrdb packages are available for Slackware 12.0, 12.1, 12.2, 13.0, 13.1, and -current to fix a security issue. Here are the details from the Slackware 13.1 ChangeLog: +————————–+ patches/packages/xrdb-1.0.9-i486-1_slack13.1.txz: Upgraded. This fixes a security issue where improperly sanitized input could lead to privilege escalation or arbitrary [...]

Slackware-Security Tagged , , , , , , , Leave a comment

shadow (SSA:2011-101-01)

Descargar artículo en formato PDF [slackware-security] shadow (SSA:2011-101-01) New shadow packages are available for Slackware 13.1, and -current to fix a security issue. Here are the details from the Slackware 13.1 ChangeLog: +————————–+ patches/packages/shadow-4.1.4.3-i486-2_slack13.1.txz: Rebuilt. Corrected a packaging error where incorrect permissions on /usr/sbin/lastlog and /usr/sbin/faillog allow any user to set login failure limits on [...]

Slackware-Security Tagged , , , , , , , Leave a comment

dhcp (SSA:2011-097-01)

Descargar artículo en formato PDF [slackware-security] dhcp (SSA:2011-097-01) New dhcp packages are available for Slackware 9.0, 9.1, 10.0, 10.1, 10.2, 11.0, 12.0, 12.1, 12.2, 13.0, 13.1, and -current to fix a security issue. Here are the details from the Slackware 13.1 ChangeLog: +————————–+ patches/packages/dhcp-4.1_ESV_R2-i486-1_slack13.1.txz: Upgraded. In dhclient, check the data for some string options for [...]

Slackware-Security Tagged , , , , , , , Leave a comment

proftpd (SSA:2011-095-01)

Descargar artículo en formato PDF [slackware-security] proftpd (SSA:2011-095-01) New proftpd packages are available for Slackware 11.0, 12.0, 12.1, 12.2, 13.0, 13.1, and -current to fix security issues. Here are the details from the Slackware 13.1 ChangeLog: +————————–+ patches/packages/proftpd-1.3.3e-i486-1_slack13.1.txz: Upgraded. Fixes CVE-2011-1137 (badly formed SSH messages cause DoS). For more information, see: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1137 (* Security fix [...]

Slackware-Security Tagged , , , , , , , Leave a comment