[A-4617] New on Slackware-current

View previous topic View next topic Go down

[A-4617] New on Slackware-current

Post  Oncle Jean on Tue Apr 24, 2012 5:21 am

32 bits

Mon Apr 23 18:18:31 UTC 2012
a/openssl-solibs-0.9.8v-i486-1.txz: Upgraded.
Fixes some potentially exploitable buffer overflows.
Thanks to Tavis Ormandy, Google Security Team, for discovering this issue and to Adam Langley <agl@chromium.org> for fixing it.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2110
(* Security fix *)
d/gdb-7.4-i486-2.txz: Rebuilt.
Changed to --with-python, requested by Benjamin Trigona-Harany.
The last time this was tried it caused some problems, as noted in this bug:
http://bugs.gentoo.org/show_bug.cgi?id=291328
Please test and let me know if any issues remain.
kde/calligra-2.4.0-i486-3.txz: Rebuilt.
Applied upstream patch to fix calligrawords compiled with gcc-4.7.0.
Thanks to Willy Sudiarto Raharjo and David Gabriel Rodriguez Castillo.
n/openssl-0.9.8v-i486-1.txz: Upgraded.
Fixes some potentially exploitable buffer overflows.
Thanks to Tavis Ormandy, Google Security Team, for discovering this issue and to Adam Langley <agl@chromium.org> for fixing it.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2110
(* Security fix *)
extra/wicd/wicd-1.7.2.1-i486-1.txz: Upgraded.
This fixes a local privilege escalation that allows a user to set arbitrary pre/post-connection scripts through D-Bus which are then executed as the wicd user (generally root).
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2095
Thanks to dapal for the workaround allowing us to skip the pybabel requirement (for now), and to Robby Workman for the script update.
(* Security fix *)

ftp://ftp.osuosl.org/pub/slackware/slackware-current/ChangeLog.txt


64 bits

Mon Apr 23 18:18:31 UTC 2012
a/openssl-solibs-0.9.8v-x86_64-1.txz
Fixes some potentially exploitable buffer overflows.
Thanks to Tavis Ormandy, Google Security Team, for discovering this issue and to Adam Langley <agl@chromium.org> for fixing it.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2110
(* Security fix *)
d/gdb-7.4-x86_64-2.txz: Rebuilt.
Changed to --with-python, requested by Benjamin Trigona-Harany.
The last time this was tried it caused some problems, as noted in this bug:
http://bugs.gentoo.org/show_bug.cgi?id=291328
Please test and let me know if any issues remain.
n/openssl-0.9.8v-x86_64-1.txz
Fixes some potentially exploitable buffer overflows.
Thanks to Tavis Ormandy, Google Security Team, for discovering this issue and to Adam Langley <agl@chromium.org> for fixing it.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2110
(* Security fix *)
kde/calligra-2.4.0-x86_64-3.txz: Rebuilt.
Applied upstream patch to fix calligrawords compiled with gcc-4.7.0.
Thanks to Willy Sudiarto Raharjo and David Gabriel Rodriguez Castillo.
extra/wicd/wicd-1.7.2.1-x86_64-1.txz: Upgraded.
This fixes a local privilege escalation that allows a user to set arbitrary pre/post-connection scripts through D-Bus which are then executed as the wicd user (generally root).
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2095
Thanks to dapal for the workaround allowing us to skip the pybabel requirement (for now), and to Robby Workman for the script update.
(* Security fix *)

ftp://ftp.osuosl.org/pub/slackware/slackware64-current/ChangeLog.txt

_________________
Oncle Jean

- Newsletter
http://tech.groups.yahoo.com/group/slack_linux_fans/

Oncle Jean
Admin

Posts: 8322
Join date: 2009-10-24
Age: 53
Location: Québec

http://slacklinux.darkbb.com

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

Permissions in this forum:
You cannot reply to topics in this forum