Toon posts:

[Slackware 8] Security fixes

Pagina: 1
Acties:

Verwijderd

Topicstarter
Op de slackware security list een paar belangrijke meldingen over fixes voor Slackware 8 ivm security:
A buffer overflow has been found in the glob(3) function in glibc.
Fixed packages for Slackware 8.0 are now available.

Here's the information from the Slackware 8.0 ChangeLog:

Fri Jan 11 14:07:07 PST 2002
patches/packages/glibc.tgz, patches/packages/glibcso.tgz:
Fixed a buffer overflow in the glob(3) function. This bug may be
exploited through external services that might make use of it, like the
port of OpenBSD's FTP server (not included in Slackware, but an example
that's known to be affected). It's highly recommended that internet-
connected machines or machines with local users who might try to exploit
setuid root binaries be upgraded as soon as possible.

Thanks to Flávio Veloso and Jakub Jelinek for finding this problem and
working out a patch.

We urge all Slackware users to upgrade to these new glibc packages as soon
as possible.


WHERE TO FIND THE NEW PACKAGES:
-------------------------------
Updated glibc package for Slackware 8.0:
ftp://ftp.slackware.com/pub/slackware/slackware-8.0/patches/packages/glibc.tgz

Updated glibcso package for Slackware 8.0:
ftp://ftp.slackware.com/pub/slackware/slackware-8.0/patches/packages/glibcso.tgz



MD5 SIGNATURES:
---------------

Here are the md5sums for the packages:

b01db77386dfcd292018701c68d312d5 glibc.tgz
857ac96829be1b409503ba8ee1e96d63 glibcso.tgz


INSTALLATION INSTRUCTIONS:
--------------------------

Simply upgrade as root:

# upgradepkg glibcso.tgz glibc.tgz


Remember, it's also a good idea to backup configuration files before
upgrading packages.

- Slackware Linux Security Team
http://www.slackware.com
An exploitable overflow has been found in the address handling code of the
mutt mail client version 1.2.5i supplied with Slackware 8.0. A new
mutt-1.2.5.1 has been released which addresses this problem, and packages
are now available for Slackware 8.0 and -current.

We urge all Slackware users to upgrade to this new version of mutt as soon
as possible.


WHERE TO FIND THE NEW PACKAGES:
-------------------------------
Updated mutt package for Slackware 8.0:
ftp://ftp.slackware.com/pub/slackware/slackware-8.0/patches/packages/mutt.tgz

Updated mutt package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/mutt-1.2.5.1/packages/mutt-1.2.5.1-i386-1.tgz


MD5 SIGNATURES:
---------------

Here are the md5sums for the packages:

Slackware 8.0:
3172435c584b0cb22ede37b7fafc25c6 mutt.tgz

Slackware -current:
3172435c584b0cb22ede37b7fafc25c6 mutt-1.2.5.1-i386-1.tgz


INSTALLATION INSTRUCTIONS:
--------------------------

Simply upgrade (or install) as root:

# upgradepkg mutt.tgz

or

# installpkg mutt.tgz


Remember, it's also a good idea to backup configuration files before
upgrading packages.

- Slackware Linux Security Team
http://www.slackware.com
[Edit]En er schijnt ook nog een security fix voor pine te zijn waar ik (nog) geen mail van heb gehad. Changelog:
Slackware-8.0 Security Update -- Pine update fixes insecure URL-handling:
Posted Sunday, January 13, 2002 by mRgOBLIN
Pine 4.44 packages are now available to fix a problem with insecure URL handling.
Fixed packages for Slackware 8.0 are now available.
Full details of this are in the Slackware-8.0 ChangeLog.txt
Patch is:
Updated pine package for Slackware 8.0:
We recommend upgrading Pine as soon as possible.

  • BezurK
  • Registratie: Juni 2001
  • Laatst online: 14-06 09:12
Heb de glibso al gedownload, glibc is 30mb en dat is nogal veel als die k*t ftp niet sneller als 3kb/s wil :(

Rookworst zonder R is ook worst.


Verwijderd

Topicstarter
ftp://dl.xs4all.nl/pub/mirror/slackware/slackware-8.0/patches/
Ik zag dat die mirror eindelijk ook weer op orde was :)

  • zeikstraal
  • Registratie: April 2000
  • Laatst online: 01-05 08:34
Bedankt voor de tip, heb me zelf eindelijk ook maar ingeschreven voor die mails, want ik was de laatste tijd redelijk laat met updates :+

Quidquid id est, timeo puellas, et oscula dantes


Verwijderd

Topicstarter
Irritant dat ze niet op de Slackware site zelf staan. Op mij wekt het allemaal niet zo'n positieve indruk, geen site updates, forum gesloten zonder commentaar of mededeling, updates gaan traag, communicatie van Slackware moet je bij elkaar vissen op verschillende sites etc.
http://userlocal.com is wel een goede bron meestal.

  • Super_ik
  • Registratie: Maart 2001
  • Laatst online: 09:32

Super_ik

haklust!

heb je deze fixes in je mail gekrege of van ergens op een andere site gezien of uit de changelogs gehaald? k wil me systeem nmlk wa meer up to date houden dan dak vroeger deed,kep me net al aangemeld bij bijde mailing lists

8<------------------------------------------------------------------------------------
Als ik zo door ga haal ik m'n dood niet. | ik hou van goeie muziek


Verwijderd

Topicstarter
Mailinglist via de Slackware site. Pine was er vanochtend ook als mail van de mailinglist. userlocal is dus een goede bron voor Slackware info. :)

  • imdos
  • Registratie: Maart 2000
  • Laatst online: 05-08 12:09

imdos

I use FreeNAS and Ubuntu

Ik heb ze per mail gekregen! Het duurde alleen 3 dagen doordat de mail-server van m'n provider wat troubles had ..

pvoutput. Waarom makkelijk doen, als het ook moeilijk kan! Every solution has a new problem


  • Super_ik
  • Registratie: Maart 2001
  • Laatst online: 09:32

Super_ik

haklust!

userlocal ziet er wel beter uit dan de slack site himself :D
*bookmarked*

8<------------------------------------------------------------------------------------
Als ik zo door ga haal ik m'n dood niet. | ik hou van goeie muziek


  • BezurK
  • Registratie: Juni 2001
  • Laatst online: 14-06 09:12
Gewoon af en toe (of dagelijks :P) #slackware op openprojectsnet bezoeken, in het topic staan daar altijd belangrijke dingen mbt de slackware distro of de linux kernel...

Rookworst zonder R is ook worst.

Pagina: 1