Slackware-13.1 ChangeLog (2011-09-06)
Tue Sep 6 00:15:03 UTC 2011
Packages
Upgraded
- patches/packages/httpd-2.2.20-i486-1_slack13.1.txz
SECURITY: CVE-2011-3192 (cve.mitre.org)
core: Fix handling of byte-range requests to use less memory, to avoid
denial of service. If the sum of all ranges in a request is larger than
the original file, ignore the ranges and send the complete file.
PR 51714. [Stefan Fritsch, Jim Jagielski, Ruediger Pluem, Eric Covener]
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3192
(* Security fix *) - patches/packages/mozilla-firefox-3.6.22-i686-1.txz
This release contains security fixes and improvements.
For more information, see:
http://www.mozilla.org/security/known-vulnerabilities/firefox36.html
http://www.mozilla.org/security/known-vulnerabilities/firefox.html
http://www.mozilla.org/security/announce/2011/mfsa2011-34.html
(* Security fix *) - patches/packages/mozilla-thunderbird-3.1.13-i686-1.txz
This release contains security fixes and improvements.
For more information, see:
http://www.mozilla.org/security/known-vulnerabilities/thunderbird31.html
http://www.mozilla.org/security/announce/2011/mfsa2011-34.html
(* Security fix *)