libpng (SSA:2011-210-01)

[slackware-security] libpng (SSA:2011-210-01)

New libpng packages are available for Slackware 8.1, 9.0, 9.1, 10.0,
10.1, 10.2, 11.0, 12.0, 12.1, 12.2, 13.0, 13.1, 13.37, and -current
to fix security issues.

Here are the details from the Slackware 13.37 ChangeLog:
+————————–+
patches/packages/libpng-1.4.8-i486-1_slack13.37.txz: Upgraded.
Fixed uninitialized memory read in png_format_buffer()
(Bug report by Frank Busse, related to CVE-2004-0421).
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0421
(* Security fix *)
+————————–+

Where to find the new packages:
+—————————–+

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 8.1:
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/libpng-1.2.46-i386-1_slack8.1.tgz

Updated package for Slackware 9.0:
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/libpng-1.2.46-i386-1_slack9.0.tgz

Updated package for Slackware 9.1:
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/libpng-1.2.46-i486-1_slack9.1.tgz

Updated package for Slackware 10.0:
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/libpng-1.2.46-i486-1_slack10.0.tgz

Updated package for Slackware 10.1:
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/libpng-1.2.46-i486-1_slack10.1.tgz

Updated package for Slackware 10.2:
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/libpng-1.2.46-i486-1_slack10.2.tgz

Updated package for Slackware 11.0:
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/libpng-1.2.46-i486-1_slack11.0.tgz

Updated package for Slackware 12.0:
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/libpng-1.2.46-i486-1_slack12.0.tgz

Updated package for Slackware 12.1:
ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/libpng-1.2.46-i486-1_slack12.1.tgz

Updated package for Slackware 12.2:
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/libpng-1.2.46-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/libpng-1.2.46-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/libpng-1.2.46-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/libpng-1.4.8-i486-1_slack13.1.txz

Updated package for Slackware x86_64 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/libpng-1.4.8-x86_64-1_slack13.1.txz

Updated package for Slackware 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/libpng-1.4.8-i486-1_slack13.37.txz

Updated package for Slackware x86_64 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/libpng-1.4.8-x86_64-1_slack13.37.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/libpng-1.4.8-i486-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/libpng-1.4.8-x86_64-1.txz

MD5 signatures:
+————-+

Slackware 8.1 package:
ad0f8dc2b0b9269c342a0d61bd007c5e libpng-1.2.46-i386-1_slack8.1.tgz

Slackware 9.0 package:
365bea389c02fdc3b920b36b1f5f5a4d libpng-1.2.46-i386-1_slack9.0.tgz

Slackware 9.1 package:
b96cf4fb882decd82bba233b615df3ba libpng-1.2.46-i486-1_slack9.1.tgz

Slackware 10.0 package:
64b11f971f7379ed0af5dc766daf2dd4 libpng-1.2.46-i486-1_slack10.0.tgz

Slackware 10.1 package:
13927173b5ecc4a33a0290363e4e53cd libpng-1.2.46-i486-1_slack10.1.tgz

Slackware 10.2 package:
b32cb1ee9694579a42e47128323b0412 libpng-1.2.46-i486-1_slack10.2.tgz

Slackware 11.0 package:
bc0efc812d8b1a52bb5c480a5b2f9200 libpng-1.2.46-i486-1_slack11.0.tgz

Slackware 12.0 package:
c4fb87f7ecf7aebcd380765d25d0f751 libpng-1.2.46-i486-1_slack12.0.tgz

Slackware 12.1 package:
8f1d8ec6a325c95725b3740dbd41c311 libpng-1.2.46-i486-1_slack12.1.tgz

Slackware 12.2 package:
c846762291145276057dad5c58bb2f89 libpng-1.2.46-i486-1_slack12.2.tgz

Slackware 13.0 package:
e0bc86aa7eeed92f8f8734efa0b54483 libpng-1.2.46-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:
3d2a8eb7474420519c947f666635ece8 libpng-1.2.46-x86_64-1_slack13.0.txz

Slackware 13.1 package:
406d411805cf2f99c567c97f53bce69b libpng-1.4.8-i486-1_slack13.1.txz

Slackware x86_64 13.1 package:
972fb84c00c4a0d7ab9134f6e65c657f libpng-1.4.8-x86_64-1_slack13.1.txz

Slackware 13.37 package:
a323c2d1ff04054ec8423710200c7682 libpng-1.4.8-i486-1_slack13.37.txz

Slackware x86_64 13.37 package:
a56d0776e600625505cc12e6853c50cc libpng-1.4.8-x86_64-1_slack13.37.txz

Slackware -current package:
ebf0f61c96738b840afa104e6ed3a71f libpng-1.4.8-i486-1.txz

Slackware x86_64 -current package:
c3ea775b59fde83c9e65a1d9648945c9 libpng-1.4.8-x86_64-1.txz

Installation instructions:
+————————+

Upgrade the packages as root:
# upgradepkg libpng-1.4.8-i486-1_slack13.37.txz

+—–+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

+————————————————————————+
| To leave the slackware-security mailing list: |
+————————————————————————+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message: |
| |
| unsubscribe slackware-security |
| |
| You will get a confirmation message back containing instructions to |
| complete the process. Please do not reply to this email address. |
+————————————————————————+
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk4zP5QACgkQakRjwEAQIjPfegCbBnFw1QdOai4sesIY28bPFLYb
H7QAn3NXN3LynFA2nYNYy1mqFO01spcD
=tOZ9
—–END PGP SIGNATURE—–

Slackware-Security , , , , , , , Leave a comment

mozilla-firefox (SSA:2011-195-02)

[slackware-security] mozilla-firefox (SSA:2011-195-02)

New mozilla-firefox packages are available for Slackware 13.0 and 13.1 to
fix security issues.

Here are the details from the Slackware 13.1 ChangeLog:
+————————–+
patches/packages/mozilla-firefox-3.6.19-i686-1.txz: Upgraded.
This release contains security fixes and improvements.
For more information, see:
http://www.mozilla.org/security/known-vulnerabilities/firefox36.html
(* Security fix *)
+————————–+

Where to find the new packages:
+—————————–+

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/mozilla-firefox-3.6.19-i686-1.txz

Updated package for Slackware x86_64 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/mozilla-firefox-3.6.19-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/mozilla-firefox-3.6.19-i686-1.txz

Updated package for Slackware x86_64 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/mozilla-firefox-3.6.19-x86_64-1_slack13.1.txz

MD5 signatures:
+————-+

Slackware 13.0 package:
309909b61a49053c4e12e213287c7f5b mozilla-firefox-3.6.19-i686-1.txz

Slackware x86_64 13.0 package:
bbad9abc9da5ee386a68bedb5c9a5796 mozilla-firefox-3.6.19-x86_64-1_slack13.0.txz

Slackware 13.1 package:
4c3369ad77514cf4697b99a566ab0da1 mozilla-firefox-3.6.19-i686-1.txz

Slackware x86_64 13.1 package:
2a4ab812cf3d6e8d18304b53dadde2c0 mozilla-firefox-3.6.19-x86_64-1_slack13.1.txz

Installation instructions:
+————————+

Upgrade the package as root:
# upgradepkg mozilla-firefox-3.6.19-i686-1.txz

+—–+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

+————————————————————————+
| To leave the slackware-security mailing list: |
+————————————————————————+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message: |
| |
| unsubscribe slackware-security |
| |
| You will get a confirmation message back containing instructions to |
| complete the process. Please do not reply to this email address. |
+————————————————————————+
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk4fgmAACgkQakRjwEAQIjMlAQCfcsE1lb+cWajHdCgNy6CSfuZc
67AAnRuELlQF+KN8XRLl3rg0Wxdv3Ulu
=2+ta
—–END PGP SIGNATURE—–

Slackware-Security , , , , , , , Leave a comment

seamonkey (SSA:2011-195-01)

[slackware-security] seamonkey (SSA:2011-195-01)

New seamonkey packages are available for Slackware 13.37, and -current to
fix security issues.

Here are the details from the Slackware 13.37 ChangeLog:
+————————–+
patches/packages/seamonkey-2.2-i486-1_slack13.37.txz: Upgraded.
This update contains security fixes and improvements.
For more information, see:
http://www.mozilla.org/security/announce/
(* Security fix *)
patches/packages/seamonkey-solibs-2.2-i486-1_slack13.37.txz: Upgraded.
This update contains security fixes and improvements.
For more information, see:
http://www.mozilla.org/security/announce/
(* Security fix *)
+————————–+

Where to find the new packages:
+—————————–+

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/seamonkey-2.2-i486-1_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/seamonkey-solibs-2.2-i486-1_slack13.37.txz

Updated package for Slackware x86_64 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/seamonkey-2.2-x86_64-1_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/seamonkey-solibs-2.2-x86_64-1_slack13.37.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/seamonkey-solibs-2.2-i486-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/seamonkey-2.2-i486-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/seamonkey-solibs-2.2-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/seamonkey-2.2-x86_64-1.txz

MD5 signatures:
+————-+

Slackware 13.37 package:
b96aff564252e24662cd833df957587c seamonkey-2.2-i486-1_slack13.37.txz
e5aca9eec859b12b97047d87e80d8d72 seamonkey-solibs-2.2-i486-1_slack13.37.txz

Slackware x86_64 13.37 package:
49178faed12f0f3a190ad342021bc87d seamonkey-2.2-x86_64-1_slack13.37.txz
403b14137c521f8d385d11f252eaa100 seamonkey-solibs-2.2-x86_64-1_slack13.37.txz

Slackware -current package:
fc1987372842b610cc7f5cb0f280b65f l/seamonkey-solibs-2.2-i486-1.txz
71e14c6f70f1869a044021e4f2a03768 xap/seamonkey-2.2-i486-1.txz

Slackware x86_64 -current package:
a2d6bafed1cd6ee6c1fd3841df4b7ab9 l/seamonkey-solibs-2.2-x86_64-1.txz
7a4fe27ad0a5498cd87d43c61609cc83 xap/seamonkey-2.2-x86_64-1.txz

Installation instructions:
+————————+

Upgrade the packages as root:
# upgradepkg seamonkey-2.2-i486-1_slack13.37.txz seamonkey-solibs-2.2-i486-1_slack13.37.txz

+—–+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

+————————————————————————+
| To leave the slackware-security mailing list: |
+————————————————————————+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message: |
| |
| unsubscribe slackware-security |
| |
| You will get a confirmation message back containing instructions to |
| complete the process. Please do not reply to this email address. |
+————————————————————————+
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk4fgl4ACgkQakRjwEAQIjP4nwCfeQHkMcu6Gdc0lorKZx/VOVkN
Ly8An1VdR1zB5mXsY3WpR8XiDXZ/Os5O
=Ks5Z
—–END PGP SIGNATURE—–

Slackware-Security , , , , , , , Leave a comment

mozilla-thunderbird (SSA:2011-189-02)

[slackware-security] mozilla-thunderbird (SSA:2011-189-02)

New mozilla-thunderbird packages are available for Slackware 13.0, 13.1, 13.37,
and -current to fix security issues.

Here are the details from the Slackware 13.37 ChangeLog:
+————————–+
patches/packages/mozilla-thunderbird-3.1.11-i486-1_slack13.37.txz: Upgraded.
This release contains security fixes and improvements.
For more information, see:
http://www.mozilla.org/security/known-vulnerabilities/thunderbird30.html
(* Security fix *)
+————————–+

Where to find the new packages:
+—————————–+

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/mozilla-thunderbird-3.1.11-i686-1.txz

Updated package for Slackware x86_64 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/mozilla-thunderbird-3.1.11-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/mozilla-thunderbird-3.1.11-i686-1.txz

Updated package for Slackware x86_64 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/mozilla-thunderbird-3.1.11-x86_64-1_slack13.1.txz

Updated package for Slackware 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/mozilla-thunderbird-3.1.11-i486-1_slack13.37.txz

Updated package for Slackware x86_64 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/mozilla-thunderbird-3.1.11-x86_64-1_slack13.37.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/mozilla-thunderbird-3.1.11-i486-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/mozilla-thunderbird-3.1.11-x86_64-1.txz

MD5 signatures:
+————-+

Slackware 13.0 package:
67b87516b8834e37caa3dd56ebd1eeb8 mozilla-thunderbird-3.1.11-i686-1.txz

Slackware x86_64 13.0 package:
fde85a7ccc837e773f776c04ef20fb0d mozilla-thunderbird-3.1.11-x86_64-1_slack13.0.txz

Slackware 13.1 package:
8301393fda44746777e9252ca0cd38ff mozilla-thunderbird-3.1.11-i686-1.txz

Slackware x86_64 13.1 package:
7087a2f4619a1f109146196f3c230e7f mozilla-thunderbird-3.1.11-x86_64-1_slack13.1.txz

Slackware 13.37 package:
085255140003a9155ec18b22fc6ad84d mozilla-thunderbird-3.1.11-i486-1_slack13.37.txz

Slackware x86_64 13.37 package:
ae412c6b31ba2f110d0f25bb74493f8a mozilla-thunderbird-3.1.11-x86_64-1_slack13.37.txz

Slackware -current package:
1e98a712858c9300da9113276f39d403 mozilla-thunderbird-3.1.11-i486-1.txz

Slackware x86_64 -current package:
03a1eea4cab85fa048c308b5f6acec03 mozilla-thunderbird-3.1.11-x86_64-1.txz

Installation instructions:
+————————+

Upgrade the package as root:
# upgradepkg mozilla-thunderbird-3.1.11-i486-1_slack13.37.txz

+—–+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

+————————————————————————+
| To leave the slackware-security mailing list: |
+————————————————————————+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message: |
| |
| unsubscribe slackware-security |
| |
| You will get a confirmation message back containing instructions to |
| complete the process. Please do not reply to this email address. |
+————————————————————————+
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk4XV8QACgkQakRjwEAQIjNBpACghxdZTjtZZFg2jwhboQPnLuyk
jaMAnjkQ4SfN815nNWCN2KhFfLvOM42v
=5TsB
—–END PGP SIGNATURE—–

Slackware-Security , , , , , , , Leave a comment

bind (SSA:2011-189-01)

[slackware-security] bind (SSA:2011-189-01)

New bind packages are available for Slackware 13.37, and -current to
fix a security issue.

Here are the details from the Slackware 13.37 ChangeLog:
+————————–+
patches/packages/bind-9.7.3_P3-i486-1_slack13.37.txz: Upgraded.
A specially constructed packet will cause BIND 9 (“named”) to exit,
affecting DNS service. The issue exists in BIND 9.6.3 and newer.
“Change #2912 (see CHANGES) exposed a latent bug in the DNS message
processing code that could allow certain UPDATE requests to crash
named. This was fixed by disambiguating internal database
representation vs DNS wire format data. [RT #24777] [CVE-2011-2464]“
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2464
(* Security fix *)
+————————–+

Where to find the new packages:
+—————————–+

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/bind-9.7.3_P3-i486-1_slack13.37.txz

Updated package for Slackware x86_64 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/bind-9.7.3_P3-x86_64-1_slack13.37.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/bind-9.7.3_P3-i486-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/bind-9.7.3_P3-x86_64-1.txz

MD5 signatures:
+————-+

Slackware 13.37 package:
6aa159ec74146d5794cd46075541405c bind-9.7.3_P3-i486-1_slack13.37.txz

Slackware x86_64 13.37 package:
08abf6bfffc52c0a392658ebd3fa046c bind-9.7.3_P3-x86_64-1_slack13.37.txz

Slackware -current package:
e5e1be017f8204ba3e3b4ad9e30f3714 n/bind-9.7.3_P3-i486-1.txz

Slackware x86_64 -current package:
3d1e556bc5a7646cf331398a8f09d582 n/bind-9.7.3_P3-x86_64-1.txz

Installation instructions:
+————————+

Upgrade the package as root:
# upgradepkg bind-9.7.3_P3-i486-1_slack13.37.txz

Then, restart the name server:

# /etc/rc.d/rc.bind restart

+—–+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

+————————————————————————+
| To leave the slackware-security mailing list: |
+————————————————————————+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message: |
| |
| unsubscribe slackware-security |
| |
| You will get a confirmation message back containing instructions to |
| complete the process. Please do not reply to this email address. |
+————————————————————————+
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk4XV8EACgkQakRjwEAQIjOoiACfVoeAsXh6sqgfLPQryh6c1f5B
NM0An1NigRXBr2/waCYrMVMj7VDHy1ff
=K7Jq
—–END PGP SIGNATURE—–

Slackware-Security , , , , , , , Leave a comment

pidgin (SSA:2011-178-01)

[slackware-security] pidgin (SSA:2011-178-01)

New pidgin packages are available for Slackware 12.2, 13.0, 13.1, 13.37,
and -current to fix a security issue.

Here are the details from the Slackware 13.37 ChangeLog:
+————————–+
patches/packages/pidgin-2.9.0-i486-1_slack13.37.txz: Upgraded.
Fixed a remote denial of service. A remote attacker could set a specially
crafted GIF file as their buddy icon causing vulerable versions of pidgin
to crash due to excessive memory use.
For more information, see:
http://pidgin.im/news/security/?id=52
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2485
(* Security fix *)
+————————–+

Where to find the new packages:
+—————————–+

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 12.2:
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/pidgin-2.9.0-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/pidgin-2.9.0-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/pidgin-2.9.0-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/pidgin-2.9.0-i486-1_slack13.1.txz

Updated package for Slackware x86_64 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/pidgin-2.9.0-x86_64-1_slack13.1.txz

Updated package for Slackware 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/pidgin-2.9.0-i486-1_slack13.37.txz

Updated package for Slackware x86_64 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/pidgin-2.9.0-x86_64-1_slack13.37.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/pidgin-2.9.0-i486-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/pidgin-2.9.0-x86_64-1.txz

MD5 signatures:
+————-+

Slackware 12.2 package:
fc1a92d8fcce2b11d3eea747255aadd5 pidgin-2.9.0-i486-1_slack12.2.tgz

Slackware 13.0 package:
4523a538f5c1f6dbc267a05c3f0c3d39 pidgin-2.9.0-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:
b10d74b33d814f41bb3e7e3a65013d83 pidgin-2.9.0-x86_64-1_slack13.0.txz

Slackware 13.1 package:
815fe39274fea0b7618dee8465be5b09 pidgin-2.9.0-i486-1_slack13.1.txz

Slackware x86_64 13.1 package:
e7d6da493c76f3898c25590d4ec09490 pidgin-2.9.0-x86_64-1_slack13.1.txz

Slackware 13.37 package:
276ab5a94fad246d9120c33a396fb484 pidgin-2.9.0-i486-1_slack13.37.txz

Slackware x86_64 13.37 package:
6625960c550a8ee6373abb5338c25818 pidgin-2.9.0-x86_64-1_slack13.37.txz

Slackware -current package:
517f9f04054fd5ce1df1e63b5b12811f xap/pidgin-2.9.0-i486-1.txz

Slackware x86_64 -current package:
98d49d72f76fae74eee558a8173ef98a xap/pidgin-2.9.0-x86_64-1.txz

Installation instructions:
+————————+

Upgrade the package as root:
# upgradepkg pidgin-2.9.0-i486-1_slack13.37.txz

+—–+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

+————————————————————————+
| To leave the slackware-security mailing list: |
+————————————————————————+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message: |
| |
| unsubscribe slackware-security |
| |
| You will get a confirmation message back containing instructions to |
| complete the process. Please do not reply to this email address. |
+————————————————————————+
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk4JVWkACgkQakRjwEAQIjPfXQCfdMnHVK3m9IKIR7vcN+9/Qlb3
0NkAnilbAF+m2ov1UJ3WmTL1UoJ284+C
=odOQ
—–END PGP SIGNATURE—–

Slackware-Security , , , , , , , Leave a comment

mozilla-firefox (SSA:2011-174-01)

[slackware-security] mozilla-firefox (SSA:2011-174-01)

New mozilla-firefox packages are available for Slackware 13.0, 13.1,
13.37, and -current to fix security issues.

Here are the details from the Slackware 13.37 ChangeLog:
+————————–+
patches/packages/mozilla-firefox-5.0-i486-1_slack13.37.txz: Upgraded.
This release contains security fixes and improvements.
For more information, see:
http://www.mozilla.org/security/known-vulnerabilities/firefox.html
(* Security fix *)
+————————–+

Where to find the new packages:
+—————————–+

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/mozilla-firefox-3.6.18-i686-1.txz

Updated package for Slackware x86_64 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/mozilla-firefox-3.6.18-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/mozilla-firefox-3.6.18-i686-1.txz

Updated package for Slackware x86_64 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/mozilla-firefox-3.6.18-x86_64-1_slack13.1.txz

Updated package for Slackware 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/mozilla-firefox-5.0-i486-1_slack13.37.txz

Updated package for Slackware x86_64 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/mozilla-firefox-5.0-x86_64-1_slack13.37.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/mozilla-firefox-5.0-i486-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/mozilla-firefox-5.0-x86_64-1.txz

MD5 signatures:
+————-+

Slackware 13.0 package:
6bae11a48ff0dbd131535523da47dfa3 mozilla-firefox-3.6.18-i686-1.txz

Slackware x86_64 13.0 package:
9c6b5b65cb74692f8e51e92a9af1b174 mozilla-firefox-3.6.18-x86_64-1_slack13.0.txz

Slackware 13.1 package:
5de7a771024cf248144cc84bf22e6c0b mozilla-firefox-3.6.18-i686-1.txz

Slackware x86_64 13.1 package:
9868ece365ad9c8fb88492e98124e989 mozilla-firefox-3.6.18-x86_64-1_slack13.1.txz

Slackware 13.37 package:
0f44d12d4cab622f99c20025090cc344 mozilla-firefox-5.0-i486-1_slack13.37.txz

Slackware x86_64 13.37 package:
cd7eb8f9e363e10026b1ecfa88a927b1 mozilla-firefox-5.0-x86_64-1_slack13.37.txz

Slackware -current package:
082655c72f19e52b4d6b97881d3b4388 xap/mozilla-firefox-5.0-i486-1.txz

Slackware x86_64 -current package:
a9dd701bf34e6141b386530ad38d4292 xap/mozilla-firefox-5.0-x86_64-1.txz

Installation instructions:
+————————+

Upgrade the package as root:
# upgradepkg mozilla-firefox-5.0-i486-1_slack13.37.txz

+—–+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

+————————————————————————+
| To leave the slackware-security mailing list: |
+————————————————————————+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message: |
| |
| unsubscribe slackware-security |
| |
| You will get a confirmation message back containing instructions to |
| complete the process. Please do not reply to this email address. |
+————————————————————————+
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk4EBSMACgkQakRjwEAQIjMwHwCfSJ6RGhyqjlfcuGfui6zU9luK
+nQAniMYu/CkNbxvCIyKZExZGJhBAa0z
=HW74
—–END PGP SIGNATURE—–

Slackware-Security , , , , , , , Leave a comment

fetchmail (SSA:2011-171-01)

[slackware-security] fetchmail (SSA:2011-171-01)

New fetchmail packages are available for Slackware 8.1, 9.0, 9.1, 10.0,
10.1, 10.2, 11.0, 12.0, 12.1, 12.2, 13.0, 13.1, 13.37, and -current
to fix a security issue.

Here are the details from the Slackware 13.37 ChangeLog:
+————————–+
patches/packages/fetchmail-6.3.20-i486-1_slack13.37.txz: Upgraded.
This release fixes a denial of service in STARTTLS protocol phases.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1947
http://www.fetchmail.info/fetchmail-SA-2011-01.txt
(* Security fix *)
+————————–+

Where to find the new packages:
+—————————–+

HINT: Getting slow download speeds from ftp.slackware.com?
Give slackware.osuosl.org a try. This is another primary FTP site
for Slackware that can be considerably faster than downloading
directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating additional FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 8.1:
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/fetchmail-6.3.20-i386-1_slack8.1.tgz

Updated package for Slackware 9.0:
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/fetchmail-6.3.20-i386-1_slack9.0.tgz

Updated package for Slackware 9.1:
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/fetchmail-6.3.20-i486-1_slack9.1.tgz

Updated package for Slackware 10.0:
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/fetchmail-6.3.20-i486-1_slack10.0.tgz

Updated package for Slackware 10.1:
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/fetchmail-6.3.20-i486-1_slack10.1.tgz

Updated package for Slackware 10.2:
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/fetchmail-6.3.20-i486-1_slack10.2.tgz

Updated package for Slackware 11.0:
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/fetchmail-6.3.20-i486-1_slack11.0.tgz

Updated package for Slackware 12.0:
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/fetchmail-6.3.20-i486-1_slack12.0.tgz

Updated package for Slackware 12.1:
ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/fetchmail-6.3.20-i486-1_slack12.1.tgz

Updated package for Slackware 12.2:
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/fetchmail-6.3.20-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/fetchmail-6.3.20-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/fetchmail-6.3.20-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/fetchmail-6.3.20-i486-1_slack13.1.txz

Updated package for Slackware 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/fetchmail-6.3.20-i486-1_slack13.37.txz

Updated package for Slackware x86_64 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/fetchmail-6.3.20-x86_64-1_slack13.1.txz

Updated package for Slackware x86_64 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/fetchmail-6.3.20-x86_64-1_slack13.37.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/fetchmail-6.3.20-i486-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/fetchmail-6.3.20-x86_64-1.txz

MD5 signatures:
+————-+

Slackware 8.1 package:
ed020b7bf1a553e92092664a495adf17 fetchmail-6.3.20-i386-1_slack8.1.tgz

Slackware 9.0 package:
2aba52a35229d979a472d121bb7c2339 fetchmail-6.3.20-i386-1_slack9.0.tgz

Slackware 9.1 package:
d58750a18677fa0fa63efc47dd8cd4e5 fetchmail-6.3.20-i486-1_slack9.1.tgz

Slackware 10.0 package:
d9944ebd68c0300b494cd0b278b1eaec fetchmail-6.3.20-i486-1_slack10.0.tgz

Slackware 10.1 package:
5fddac4a8afdcbeba13703f94f98003f fetchmail-6.3.20-i486-1_slack10.1.tgz

Slackware 10.2 package:
8abf48200bedc5897bde83c3e9bd58a6 fetchmail-6.3.20-i486-1_slack10.2.tgz

Slackware 11.0 package:
cea9c8de9094ac4a899a6d2ba53ffcbb fetchmail-6.3.20-i486-1_slack11.0.tgz

Slackware 12.0 package:
b0558f407456fbadf58f6b3f18f87ce9 fetchmail-6.3.20-i486-1_slack12.0.tgz

Slackware 12.1 package:
e0bc2ae10534550cd862a1ff7e95b784 fetchmail-6.3.20-i486-1_slack12.1.tgz

Slackware 12.2 package:
39e2505382098cccae8ca52a835f8e36 fetchmail-6.3.20-i486-1_slack12.2.tgz

Slackware 13.0 package:
569fb0ca5a8d849eb3ca2af344737a6a fetchmail-6.3.20-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:
5f913ce96a9bf2d8ac819a11f028fafe fetchmail-6.3.20-x86_64-1_slack13.0.txz

Slackware 13.1 package:
6b5e9308b587e49af7b300c99d5d6289 fetchmail-6.3.20-i486-1_slack13.1.txz

Slackware 13.37 package:
bf124b737550c50bba8cdb3312c994b3 fetchmail-6.3.20-i486-1_slack13.37.txz

Slackware x86_64 13.1 package:
ae05ca4a125ce8e69c0852bfc32ba5a0 fetchmail-6.3.20-x86_64-1_slack13.1.txz

Slackware x86_64 13.37 package:
8d85bad773a70e37933abc99156eecc8 fetchmail-6.3.20-x86_64-1_slack13.37.txz

Slackware -current package:
39b55e908cf0424d2dc36107873d46d8 n/fetchmail-6.3.20-i486-1.txz

Slackware x86_64 -current package:
45f75a0df71ec1a20eae45e955bc1068 n/fetchmail-6.3.20-x86_64-1.txz

Installation instructions:
+————————+

Upgrade the package as root:
# upgradepkg fetchmail-6.3.20-i486-1_slack13.37.txz

+—–+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

+————————————————————————+
| To leave the slackware-security mailing list: |
+————————————————————————+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message: |
| |
| unsubscribe slackware-security |
| |
| You will get a confirmation message back containing instructions to |
| complete the process. Please do not reply to this email address. |
+————————————————————————+
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk3/dc8ACgkQakRjwEAQIjMl4QCePcA9lcwoVQ10Fk40WdUDCFki
KcAAn03ptahx0E/cO4Y30tGaZOK7Cc7t
=nYGz
—–END PGP SIGNATURE—–

Slackware-Security , , , , , , , Leave a comment

bind (SSA:2011-147-01)

[slackware-security] bind (SSA:2011-147-01)

New bind packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2,
11.0, 12.0, 12.1, 12.2, 13.0, 13.1, 13.37, and -current to fix security issues.

Here are the details from the Slackware 13.37 ChangeLog:
+————————–+
patches/packages/bind-9.7.3_P1-i486-1_slack13.37.txz: Upgraded.
This release fixes security issues:
* A large RRSET from a remote authoritative server that results in
the recursive resolver trying to negatively cache the response can
hit an off by one code error in named, resulting in named crashing.
[RT #24650] [CVE-2011-1910]
* Zones that have a DS record in the parent zone but are also listed
in a DLV and won’t validate without DLV could fail to validate. [RT
#24631]
For more information, see:
http://www.isc.org/software/bind/advisories/cve-2011-1910
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1910
(* Security fix *)
+————————–+

Where to find the new packages:
+—————————–+

HINT: Getting slow download speeds from ftp.slackware.com?
Give slackware.osuosl.org a try. This is another primary FTP site
for Slackware that can be considerably faster than downloading
directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating additional FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 8.1:
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/bind-9.4_ESV_R4_P1-i386-1_slack8.1.tgz

Updated package for Slackware 9.0:
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/bind-9.4_ESV_R4_P1-i386-1_slack9.0.tgz

Updated package for Slackware 9.1:
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/bind-9.4_ESV_R4_P1-i486-1_slack9.1.tgz

Updated package for Slackware 10.0:
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/bind-9.4_ESV_R4_P1-i486-1_slack10.0.tgz

Updated package for Slackware 10.1:
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/bind-9.4_ESV_R4_P1-i486-1_slack10.1.tgz

Updated package for Slackware 10.2:
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/bind-9.4_ESV_R4_P1-i486-1_slack10.2.tgz

Updated package for Slackware 11.0:
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/bind-9.4_ESV_R4_P1-i486-1_slack11.0.tgz

Updated package for Slackware 12.0:
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/bind-9.4_ESV_R4_P1-i486-1_slack12.0.tgz

Updated package for Slackware 12.1:
ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/bind-9.4_ESV_R4_P1-i486-1_slack12.1.tgz

Updated package for Slackware 12.2:
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/bind-9.4_ESV_R4_P1-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/bind-9.4_ESV_R4_P1-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/bind-9.4_ESV_R4_P1-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/bind-9.4_ESV_R4_P1-i486-1_slack13.1.txz

Updated package for Slackware 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/bind-9.7.3_P1-i486-1_slack13.37.txz

Updated package for Slackware x86_64 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/bind-9.4_ESV_R4_P1-x86_64-1_slack13.1.txz

Updated package for Slackware x86_64 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/bind-9.7.3_P1-x86_64-1_slack13.37.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/bind-9.7.3_P1-i486-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/bind-9.7.3_P1-x86_64-1.txz

MD5 signatures:
+————-+

Slackware 8.1 package:
8aa76355e5ce1432688a18f2fe354533 bind-9.4_ESV_R4_P1-i386-1_slack8.1.tgz

Slackware 9.0 package:
8ef7d9bd5dab0da250a505c4e5836095 bind-9.4_ESV_R4_P1-i386-1_slack9.0.tgz

Slackware 9.1 package:
a85a3d84d502a4523259783636bd95d1 bind-9.4_ESV_R4_P1-i486-1_slack9.1.tgz

Slackware 10.0 package:
52ebf11a85312213a8aac6a7d47e7366 bind-9.4_ESV_R4_P1-i486-1_slack10.0.tgz

Slackware 10.1 package:
53f8132077bd77fb818b402030d10ff8 bind-9.4_ESV_R4_P1-i486-1_slack10.1.tgz

Slackware 10.2 package:
75f1f4be1eb53356bf0375d06cb94e8e bind-9.4_ESV_R4_P1-i486-1_slack10.2.tgz

Slackware 11.0 package:
0064358785c0d118600d75a58005a944 bind-9.4_ESV_R4_P1-i486-1_slack11.0.tgz

Slackware 12.0 package:
152ca0eb0b0e1e16a3d4fc6de1b4fa11 bind-9.4_ESV_R4_P1-i486-1_slack12.0.tgz

Slackware 12.1 package:
6162c65c46f3e52de36c19d1ebe880d1 bind-9.4_ESV_R4_P1-i486-1_slack12.1.tgz

Slackware 12.2 package:
82441358f2653c2b6c8feebe4274c8de bind-9.4_ESV_R4_P1-i486-1_slack12.2.tgz

Slackware 13.0 package:
697e60fcdf95e468a9c51beefc444992 bind-9.4_ESV_R4_P1-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:
322abb43ddd20aabccaa2bfa2433aa9c bind-9.4_ESV_R4_P1-x86_64-1_slack13.0.txz

Slackware 13.1 package:
d7d4386738483088b4ef6d6f72f18478 bind-9.4_ESV_R4_P1-i486-1_slack13.1.txz

Slackware 13.37 package:
98dccb44c9193d8e8392e28db9cdca5d bind-9.7.3_P1-i486-1_slack13.37.txz

Slackware x86_64 13.1 package:
a7faea792671b6a60c7a386907b8e143 bind-9.4_ESV_R4_P1-x86_64-1_slack13.1.txz

Slackware x86_64 13.37 package:
58c7dd0fc47d0e0eeeb2e6a3663a8507 bind-9.7.3_P1-x86_64-1_slack13.37.txz

Slackware -current package:
b720d39eee93e2681532a6db509c3fd8 n/bind-9.7.3_P1-i486-1.txz

Slackware x86_64 -current package:
9ffcbc127fb1bfa67b75b77ceba123a9 n/bind-9.7.3_P1-x86_64-1.txz

Installation instructions:
+————————+

Upgrade the package as root:
# upgradepkg bind-9.7.3_P1-i486-1_slack13.37.txz

Then, restart the name server:

# /etc/rc.d/rc.bind restart

+—–+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

+————————————————————————+
| To leave the slackware-security mailing list: |
+————————————————————————+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message: |
| |
| unsubscribe slackware-security |
| |
| You will get a confirmation message back containing instructions to |
| complete the process. Please do not reply to this email address. |
+————————————————————————+
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk3gNwgACgkQakRjwEAQIjPMpwCfUuXaixmpqxnLM6y5YdzG3Vm8
fJMAnjcBWGgw6REGS3lrLTUDZMWQXs85
=Zmm3
—–END PGP SIGNATURE—–

Slackware-Security , , , , , , , 1 Comment

httpd (SSA:2011-145-02)

[slackware-security] httpd (SSA:2011-145-02)

New httpd packages are available for Slackware 12.0, 12.1, 12.2, 13.0, 13.1,
13.37, and -current to fix accidental ABI breakage caused by httpd-2.2.18.

Here are the details from the Slackware 13.37 ChangeLog:
+————————–+
patches/packages/httpd-2.2.19-i486-1_slack13.37.txz: Upgraded.
Revert ABI breakage in 2.2.18 caused by the function signature change
of ap_unescape_url_keep2f(). This release restores the signature from
2.2.17 and prior, and introduces ap_unescape_url_keep2f_ex().
Apache httpd-2.2.18 is considered abandoned. All users must upgrade.
+————————–+

Where to find the new packages:
+—————————–+

HINT: Getting slow download speeds from ftp.slackware.com?
Give slackware.osuosl.org a try. This is another primary FTP site
for Slackware that can be considerably faster than downloading
directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating additional FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 12.0:
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/httpd-2.2.19-i486-1_slack12.0.tgz

Updated package for Slackware 12.1:
ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/httpd-2.2.19-i486-1_slack12.1.tgz

Updated package for Slackware 12.2:
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/httpd-2.2.19-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/httpd-2.2.19-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/httpd-2.2.19-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/httpd-2.2.19-i486-1_slack13.1.txz

Updated package for Slackware 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/httpd-2.2.19-i486-1_slack13.37.txz

Updated package for Slackware x86_64 13.1:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/httpd-2.2.19-x86_64-1_slack13.1.txz

Updated package for Slackware x86_64 13.37:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/httpd-2.2.19-x86_64-1_slack13.37.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/httpd-2.2.19-i486-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/httpd-2.2.19-x86_64-1.txz

MD5 signatures:
+————-+

Slackware 12.0 package:
390545a63786ce48dabac271307d8e91 httpd-2.2.19-i486-1_slack12.0.tgz

Slackware 12.1 package:
9a033f2c378816cec179947b26a43b3b httpd-2.2.19-i486-1_slack12.1.tgz

Slackware 12.2 package:
dc503a2e86da7e2ebe88620f49318d07 httpd-2.2.19-i486-1_slack12.2.tgz

Slackware 13.0 package:
0605d648aedc564607cbfa619a4d5648 httpd-2.2.19-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:
24badd3802df48e4f153f52be1b9f4d4 httpd-2.2.19-x86_64-1_slack13.0.txz

Slackware 13.1 package:
1a5c7e9a1c4de170d0876f0517d7eff0 httpd-2.2.19-i486-1_slack13.1.txz

Slackware 13.37 package:
11e0bf5494eb823aebe589a2de854efa httpd-2.2.19-i486-1_slack13.37.txz

Slackware x86_64 13.1 package:
84ccfe6186280cb11e2e0e0cfb170d57 httpd-2.2.19-x86_64-1_slack13.1.txz

Slackware x86_64 13.37 package:
48f826cc13c187a08ddb3491706b671d httpd-2.2.19-x86_64-1_slack13.37.txz

Slackware -current package:
ab8137394f625633ba756b4d43a2d7b1 n/httpd-2.2.19-i486-1.txz

Slackware x86_64 -current package:
ade8d482a468d3d58e41fd98b093f7b2 n/httpd-2.2.19-x86_64-1.txz

Installation instructions:
+————————+

Upgrade the package as root:
# upgradepkg httpd-2.2.19-i486-1_slack13.37.txz

Then, restart Apache httpd:

# /etc/rc.d/rc.httpd stop
# /etc/rc.d/rc.httpd start

+—–+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

+————————————————————————+
| To leave the slackware-security mailing list: |
+————————————————————————+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message: |
| |
| unsubscribe slackware-security |
| |
| You will get a confirmation message back containing instructions to |
| complete the process. Please do not reply to this email address. |
+————————————————————————+
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk3ddE4ACgkQakRjwEAQIjMuGgCfb4f1Hdv6VcTQNt0kuE3X/nbX
PcYAnjAf4G50EihW9FMB7Rh9IHH2aIwL
=MeMr
—–END PGP SIGNATURE—–

Slackware-Security , , , , , , , Leave a comment