Slackware-10.0 ChangeLog (2007-09-12)

Wed Sep 12 15:20:06 CDT 2007

patches/packages/openssh-4.7p1-i486-1_slack10.0.tgz:
Upgraded to openssh-4.7p1.
From the OpenSSH release notes:
“Security bugs resolved in this release: Prevent ssh(1) from using a
trusted X11 cookie if creation of an untrusted cookie fails; found and
fixed by Jan Pechanec.”
While it's fair to say that we here at Slackware don't see how this could
be leveraged to compromise a system, a) the OpenSSH people (who presumably
understand the code better) characterize this as a security bug, b) it has
been assigned a CVE entry, and c) OpenSSH is one of the most commonly used
network daemons. Better safe than sorry.
More information should appear here eventually:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4752
(* Security fix *)
patches/packages/samba-3.0.26a-i486-1_slack10.0.tgz:
Upgraded to samba-3.0.26a.
This fixes a security issue in all Samba 3.0.25 versions:
“Incorrect primary group assignment for domain users using the rfc2307
or sfu winbind nss info plugin.”
For more information, see:
http://www.samba.org/samba/security/CVE-2007-4138.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4138
(* Security fix *)
  • news/2007/09/12/slackware-10.0-changelog.txt
  • Last modified: 13 months ago
  • by Giuseppe Di Terlizzi