[A-1324] New on ARMedslack-current

View previous topic View next topic Go down

[A-1324] New on ARMedslack-current

Post  Oncle Jean on Fri Oct 29, 2010 3:56 pm

Fri Oct 29 19:20:54 UTC 2010

a/glibc-solibs-2.12.1-arm-3.tgz: Rebuilt.
Patched "The GNU C library dynamic linker will dlopen arbitrary DSOs
during setuid loads." This security issue allows a local attacker to
gain root by specifying an unsafe DSO in the library search path to be
used with a setuid binary in LD_AUDIT mode.
Bug found by Tavis Ormandy (with thanks to Ben Hawkes and Julien Tinnes).
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3856
http://seclists.org/fulldisclosure/2010/Oct/344
(* Security fix *)
a/glibc-zoneinfo-2.12.1-noarch-3.tgz: Rebuilt.
Upgraded to tzcode2010n and tzdata2010n.
a/grep-2.7-arm-1.tgz: Upgraded.
a/xz-5.0.0-arm-1.tgz: Upgraded.
ap/alsa-utils-1.0.23-arm-3.tgz: Rebuilt.
Don't try to load ALSA OSS modules if they aren't available.
Thanks to John Fitzgerald for the patch.
l/glibc-2.12.1-arm-3.tgz: Rebuilt.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3856
http://seclists.org/fulldisclosure/2010/Oct/344
(* Security fix *)
l/glibc-i18n-2.12.1-arm-3.tgz: Rebuilt.
l/glibc-profile-2.12.1-arm-3.tgz: Rebuilt.
xap/mozilla-firefox-3.6.12-armv5t-1.tgz: Upgraded.
This fixes some security issues.
For more information, see:
http://www.mozilla.org/security/known-vulnerabilities/firefox36.html
(* Security fix *)

ftp://ftp.armedslack.org/armedslack/armedslack-current/ChangeLog.txt

_________________
Oncle Jean

- Newsletter
http://tech.groups.yahoo.com/group/slack_linux_fans/

Oncle Jean
Admin

Posts: 8322
Join date: 2009-10-24
Age: 53
Location: Québec

http://slacklinux.darkbb.com

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

Permissions in this forum:
You cannot reply to topics in this forum