Slackware-10.0 ChangeLog (2006-02-09)
Thu Feb 9 15:09:26 CST 2006
Packages
Upgraded to fetchmail-6.3.2
- patches/packages/fetchmail-6.3.2-i486-1.tgz
Presumably this replaces all the known security problems with
a batch of new unknown ones. (fetchmail is improving, really
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3088
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4348
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0321
(* Security fix *)
Patched integer and
- patches/packages/kdegraphics-3.2.3-i486-2.tgz
heap overflows in kpdf to fix possible security bugs with malformed
PDF files.
For more information, see:
http://www.kde.org/info/security/advisory-20051207-2.txt
http://www.kde.org/info/security/advisory-20060202-1.txt
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3191
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3192
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3193
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3624
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3625
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3626
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3627
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3628
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0301
(* Security fix *)
Patched a heap overflow
- patches/packages/kdelibs-3.2.3-i486-3.tgz
vulnerability in kjs, the JavaScript interpreter engine used by
Konqueror and other parts of KDE.
For more information, see:
http://www.kde.org/info/security/advisory-20060119-1.txt
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0019
(* Security fix *)
Upgraded to openssh-4.3p1
- patches/packages/openssh-4.3p1-i486-1.tgz
This fixes a security issue when using scp to copy files that could
cause commands embedded in filenames to be executed.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0225
(* Security fix *)
Upgraded to sudo-1.6.8p12
- patches/packages/sudo-1.6.8p12-i486-1.tgz
This fixes an issue where a user able to run a Python script through sudo
may be able to gain root access.
IMHO, running any kind of scripting language from sudo is still not safeā¦
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0151
(* Security fix *)
patches/packages/xpdf-3.01-i486-3.tgz: Recompiled with xpdf-3.01pl2.patch to
fix integer and heap overflows in xpdf triggered by malformed PDF files.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3191
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3192
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3193
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3624
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3625
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3626
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3627
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3628
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0301
(* Security fix *)