Slackware security

Condividi contenuti
Latest ten Slackware Security Announces
Aggiornato: 11 min 44 sec fa

2010-08-28 xorg-server (SSA:2010-240-06)

11 min 44 sec fa

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] xorg-server (SSA:2010-240-06)

New xorg-server packages are available for Slackware 12.0, 12.1, 12.2, 13.0,

13.1, and -current to fix a security issue.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/xorg-server-1.7.7-i486-2_slack13.1.txz: Rebuilt.

Patched to prevent overwriting stack memory and bypassing security mechanisms

on systems that use a 2.6 Linux kernel. Reported by Rafal Wojtczuk.

For more information, see:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2240

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated packages for Slackware 12.0:

ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/xorg-server-1.3.0.0-i486-3_slack12.0.tgz

ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/xorg-server-xdmx-1.3.0.0-i486-3_slack12.0.tgz

ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/xorg-server-xnest-1.3.0.0-i486-3_slack12.0.tgz

ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/xorg-server-xvfb-1.3.0.0-i486-3_slack12.0.tgz

Updated packages for Slackware 12.1:

ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/xorg-server-1.4.2-i486-2_slack12.1.tgz

ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/xorg-server-xnest-1.4.2-i486-2_slack12.1.tgz

ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/xorg-server-xvfb-1.4.2-i486-2_slack12.1.tgz

Updated packages for Slackware 12.2:

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/xorg-server-1.4.2-i486-2_slack12.2.tgz

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/xorg-server-xnest-1.4.2-i486-2_slack12.2.tgz

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/xorg-server-xvfb-1.4.2-i486-2_slack12.2.tgz

Updated packages for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/xorg-server-1.6.3-i486-2_slack13.0.txz

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/xorg-server-xephyr-1.6.3-i486-2_slack13.0.txz

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/xorg-server-xnest-1.6.3-i486-2_slack13.0.txz

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/xorg-server-xvfb-1.6.3-i486-2_slack13.0.txz

Updated packages for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/xorg-server-1.6.3-x86_64-2_slack13.0.txz

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/xorg-server-xephyr-1.6.3-x86_64-2_slack13.0.txz

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/xorg-server-xnest-1.6.3-x86_64-2_slack13.0.txz

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/xorg-server-xvfb-1.6.3-x86_64-2_slack13.0.txz

Updated packages for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/xorg-server-1.7.7-i486-2_slack13.1.txz

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/xorg-server-xephyr-1.7.7-i486-2_slack13.1.txz

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/xorg-server-xnest-1.7.7-i486-2_slack13.1.txz

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/xorg-server-xvfb-1.7.7-i486-2_slack13.1.txz

Updated packages for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/xorg-server-1.7.7-x86_64-2_slack13.1.txz

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/xorg-server-xephyr-1.7.7-x86_64-2_slack13.1.txz

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/xorg-server-xnest-1.7.7-x86_64-2_slack13.1.txz

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/xorg-server-xvfb-1.7.7-x86_64-2_slack13.1.txz

Updated packages for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/x/xorg-server-1.7.7-i486-2.txz

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/x/xorg-server-xephyr-1.7.7-i486-2.txz

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/x/xorg-server-xnest-1.7.7-i486-2.txz

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/x/xorg-server-xvfb-1.7.7-i486-2.txz

Updated packages for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/x/xorg-server-1.7.7-x86_64-2.txz

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/x/xorg-server-xephyr-1.7.7-x86_64-2.txz

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/x/xorg-server-xnest-1.7.7-x86_64-2.txz

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/x/xorg-server-xvfb-1.7.7-x86_64-2.txz

MD5 signatures:

+-------------+

Slackware 12.0 packages:

948e4d6012f7c349be58318622941508 xorg-server-1.3.0.0-i486-3_slack12.0.tgz

c9d5f136423384d7a68f971992f6049f xorg-server-xdmx-1.3.0.0-i486-3_slack12.0.tgz

bb3da6748a08c142c47633e642c7137d xorg-server-xnest-1.3.0.0-i486-3_slack12.0.tgz

dfb6bdba04491ca4acb15fafd89638b2 xorg-server-xvfb-1.3.0.0-i486-3_slack12.0.tgz

Slackware 12.1 packages:

a8ab8b3976df8633257d65b3913b8883 xorg-server-1.4.2-i486-2_slack12.1.tgz

4fdf655f8fc4ffdd478a6c3981b0a6fd xorg-server-xnest-1.4.2-i486-2_slack12.1.tgz

93e4c5e23fa6efc9a5c222da5edac3ba xorg-server-xvfb-1.4.2-i486-2_slack12.1.tgz

Slackware 12.2 packages:

bcd28e761bb4adbf24dec715c49d297b xorg-server-1.4.2-i486-2_slack12.2.tgz

25723efc09e09d915ebb36e1205d70b1 xorg-server-xnest-1.4.2-i486-2_slack12.2.tgz

d1c5206344d115c19f4349faa92a02a1 xorg-server-xvfb-1.4.2-i486-2_slack12.2.tgz

Slackware 13.0 packages:

dc4780c806670dd2b1bbf849f1de135a xorg-server-1.6.3-i486-2_slack13.0.txz

3d7ecec9719e890d76f773f284dfe339 xorg-server-xephyr-1.6.3-i486-2_slack13.0.txz

67bd1e1772b5b56a3437b328a25b32d1 xorg-server-xnest-1.6.3-i486-2_slack13.0.txz

d6f8fd0392ded6db5d8a8a38a21aa0bd xorg-server-xvfb-1.6.3-i486-2_slack13.0.txz

Slackware x86_64 13.0 packages:

dcba378af605ce9215b59f1c9b695765 xorg-server-1.6.3-x86_64-2_slack13.0.txz

471d08f7e17f1b00a27801d53ca7ac0e xorg-server-xephyr-1.6.3-x86_64-2_slack13.0.txz

1ab068bc4ae868eb8474a37cae643c3f xorg-server-xnest-1.6.3-x86_64-2_slack13.0.txz

ce6fff885eaeb0bacffed8de5bff696f xorg-server-xvfb-1.6.3-x86_64-2_slack13.0.txz

Slackware 13.1 packages:

ea462ea066e90341443e135a34cc74e7 xorg-server-1.7.7-i486-2_slack13.1.txz

dd01a6d98fed4d0135aef3ba4434d713 xorg-server-xephyr-1.7.7-i486-2_slack13.1.txz

4650b8a0248c225172367c3a49c2b8ea xorg-server-xnest-1.7.7-i486-2_slack13.1.txz

b28c1a2118f9e68c44e794d85d214c4b xorg-server-xvfb-1.7.7-i486-2_slack13.1.txz

Slackware x86_64 13.1 packages:

5a94d24124740a99e4961c2511f40ae4 xorg-server-1.7.7-x86_64-2_slack13.1.txz

de80c9498875b726f46612f344223b98 xorg-server-xephyr-1.7.7-x86_64-2_slack13.1.txz

47c55a47f8c0d3fef964984cf35d7327 xorg-server-xnest-1.7.7-x86_64-2_slack13.1.txz

838b0c430f248e8f4db8ab7b2a310f90 xorg-server-xvfb-1.7.7-x86_64-2_slack13.1.txz

Slackware -current packages:

5d47df75439e8be839648d62dff8a067 x/xorg-server-1.7.7-i486-2.txz

5567692e94ab8d77e78a947aa6761dce x/xorg-server-xephyr-1.7.7-i486-2.txz

0c3112b8b3de5dfa5546c4808b0fd1ab x/xorg-server-xnest-1.7.7-i486-2.txz

c227768380dbfcf6e10e252b0ed63559 x/xorg-server-xvfb-1.7.7-i486-2.txz

Slackware x86_64 -current packages:

fd708c0e164edf215ed3c26f2ee37721 x/xorg-server-1.7.7-x86_64-2.txz

eab6cd91332a734466fd1b8f295d5842 x/xorg-server-xephyr-1.7.7-x86_64-2.txz

eac24a47e7906236c6cb4971a24f61d9 x/xorg-server-xnest-1.7.7-x86_64-2.txz

c9c3d50532fd43cabee7bfbea1cce0e1 x/xorg-server-xvfb-1.7.7-x86_64-2.txz

Installation instructions:

+------------------------+

Upgrade the packages as root:

# upgradepkg xorg-server-*z

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkx5PsAACgkQakRjwEAQIjNcgQCfWY8/gTTmSSqKn1zwRbe2Quy+

ND4AoI4OB9YlVbEnlHMUITn+sm3wY+44

=ldTg

-----END PGP SIGNATURE-----

2010-08-28 pidgin (SSA:2010-240-05)

11 min 44 sec fa

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] pidgin (SSA:2010-240-05)

New pidgin packages are available for Slackware 12.0, 12.1, 12.2, 13.0, 13.1,

and -current to fix security issues.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/pidgin-2.7.3-i486-1_slack13.1.txz: Upgraded.

This fixes a crash due to malformed X-Status messages.

For more information, see:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2528

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 12.0:

ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/pidgin-2.7.3-i486-1_slack12.0.tgz

Updated package for Slackware 12.1:

ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/pidgin-2.7.3-i486-1_slack12.1.tgz

Updated package for Slackware 12.2:

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/pidgin-2.7.3-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/pidgin-2.7.3-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/pidgin-2.7.3-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/pidgin-2.7.3-i486-1_slack13.1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/pidgin-2.7.3-x86_64-1_slack13.1.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/pidgin-2.7.3-i486-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/pidgin-2.7.3-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 12.0 package:

fb7245579aa4015f005d0044aeb7fd52 pidgin-2.7.3-i486-1_slack12.0.tgz

Slackware 12.1 package:

ba4084ade603a89b4e90e46bcd0c2b23 pidgin-2.7.3-i486-1_slack12.1.tgz

Slackware 12.2 package:

5f8e30a3bb04c445040b2b089fc6c04c pidgin-2.7.3-i486-1_slack12.2.tgz

Slackware 13.0 package:

10bf842cd6588250ee109c336ab89990 pidgin-2.7.3-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:

b395ee451748d348a0eec5b92d939581 pidgin-2.7.3-x86_64-1_slack13.0.txz

Slackware 13.1 package:

16b7bdbe33fa6939b550913c1014680c pidgin-2.7.3-i486-1_slack13.1.txz

Slackware x86_64 13.1 package:

e84ee7496de30290c1c379b17ce25e32 pidgin-2.7.3-x86_64-1_slack13.1.txz

Slackware -current package:

e55e0f4e6a656e50dfa01da2da847cd7 xap/pidgin-2.7.3-i486-1.txz

Slackware x86_64 -current package:

e33c22e97f622500be3b84cde060b503 xap/pidgin-2.7.3-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg pidgin-2.7.3-i486-1_slack13.1.txz

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkx5PsAACgkQakRjwEAQIjMkJwCdGXvRG78rtmiv70rOnNignVOR

blgAnjjrZ3q2/nqGWn5XkQIwwbxHqABJ

=NXfU

-----END PGP SIGNATURE-----

2010-08-28 php (SSA:2010-240-04)

11 min 44 sec fa

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] php (SSA:2010-240-04)

New php packages are available for Slackware 11.0 (extra), 12.0, 12.1, 12.2,

13.0, 13.1, and -current to fix security issues.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/php-5.2.14-i486-1_slack13.1.txz: Upgraded.

Fixed several security issues.

For more information, see:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1917

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2225

http://www.php-security.org/2010/05/31/mops-2010-060-php-session-serializer-session-data-injection-vulnerability/index.html

http://www.php-security.org/2010/06/25/mops-2010-061-php-splobjectstorage-deserialization-use-after-free-vulnerability/index.html

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 11.0 (extra package):

ftp://ftp.slackware.com/pub/slackware/slackware-11.0/extra/php5/php-5.2.14-i486-1_slack11.0.tgz

Updated package for Slackware 12.0:

ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/php-5.2.14-i486-1_slack12.0.tgz

Updated package for Slackware 12.1:

ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/php-5.2.14-i486-1_slack12.1.tgz

Updated package for Slackware 12.2:

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/php-5.2.14-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/php-5.2.14-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/php-5.2.14-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/php-5.2.14-i486-1_slack13.1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/php-5.2.14-x86_64-1_slack13.1.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/php-5.2.14-i486-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/php-5.2.14-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 11.0 package:

2486886930228a69dcf24855fa191a33 php-5.2.14-i486-1_slack11.0.tgz

Slackware 12.0 package:

39939678a81c6540346084d5636dbeb5 php-5.2.14-i486-1_slack12.0.tgz

Slackware 12.1 package:

dcba3ce28a66dd850d1505e64b93892e php-5.2.14-i486-1_slack12.1.tgz

Slackware 12.2 package:

47c960d87d203f36821b93a315dcfc11 php-5.2.14-i486-1_slack12.2.tgz

Slackware 13.0 package:

f77e140103994b23a674145e3165dba3 php-5.2.14-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:

180ce96682a29c7886e879f4f44039f5 php-5.2.14-x86_64-1_slack13.0.txz

Slackware 13.1 package:

45db44e597510b60a9317a5b42dfe858 php-5.2.14-i486-1_slack13.1.txz

Slackware x86_64 13.1 package:

a0518cf82dda7aaa683f175803039d40 php-5.2.14-x86_64-1_slack13.1.txz

Slackware -current package:

71f3b18bc9def838ac70923e9802c5cd n/php-5.2.14-i486-1.txz

Slackware x86_64 -current package:

ed7e1aae19b996734865738857a1d24a n/php-5.2.14-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg php-5.2.14-i486-1_slack13.1.txz

Then, restart Apache httpd:

# /etc/rc.d/rc.httpd stop

# /etc/rc.d/rc.httpd start

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkx5PsAACgkQakRjwEAQIjOrFwCdHxzS7BRCuyZnq6wNripcTwvZ

C9UAn0xLlqrLRXFVkyocSDHSJZOXkbku

=iSJV

-----END PGP SIGNATURE-----

2010-08-28 kdegraphics (SSA:2010-240-03)

11 min 44 sec fa

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] kdegraphics (SSA:2010-240-03)

New kdegraphics packages are available for Slackware 13.1 to

fix a security issue in the okular document viewer.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/kdegraphics-4.4.3-i486-3_slack13.1.txz: Rebuilt.

Patched "Okular PDB Processing Memory Corruption Vulnerability"

For more information, see:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2575

http://www.kde.org/info/security/advisory-20100825-1.txt

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/kdegraphics-4.4.3-i486-3_slack13.1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/kdegraphics-4.4.3-x86_64-3_slack13.1.txz

MD5 signatures:

+-------------+

Slackware 13.1 package:

21c7fd40063530df60cb99445086feea kdegraphics-4.4.3-i486-3_slack13.1.txz

Slackware x86_64 13.1 package:

d340d60ece11e615dbadac8834a0935a kdegraphics-4.4.3-x86_64-3_slack13.1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg kdegraphics-4.4.3-i486-3_slack13.1.txz

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkx5PsAACgkQakRjwEAQIjP2ugCbBhu/MHIuV9H+qWikX//R1kuI

XIAAnRldrYM90yxyplhyyRwFOmC6r/bO

=L8aJ

-----END PGP SIGNATURE-----

2010-08-28 httpd (SSA:2010-240-02)

11 min 44 sec fa

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] httpd (SSA:2010-240-02)

New httpd packages are available for Slackware 12.0, 12.1, 12.2, 13.0, 13.1,

and -current to fix a security issue.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/httpd-2.2.16-i486-1_slack13.1.txz: Upgraded.

Fix Handling of requests without a path segment.

For more information, see:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1452

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 12.0:

ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/httpd-2.2.16-i486-1_slack12.0.tgz

Updated package for Slackware 12.1:

ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/httpd-2.2.16-i486-1_slack12.1.tgz

Updated package for Slackware 12.2:

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/httpd-2.2.16-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/httpd-2.2.16-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/httpd-2.2.16-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/httpd-2.2.16-i486-1_slack13.1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/httpd-2.2.16-x86_64-1_slack13.1.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/httpd-2.2.16-i486-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/httpd-2.2.16-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 12.0 package:

dced048e8d6016fe7c1c906198e49756 httpd-2.2.16-i486-1_slack12.0.tgz

Slackware 12.1 package:

0d27c0980ffed539bffe7255c8f20994 httpd-2.2.16-i486-1_slack12.1.tgz

Slackware 12.2 package:

e5eb1a2520c1e4e55f27429fa7f09c27 httpd-2.2.16-i486-1_slack12.2.tgz

Slackware 13.0 package:

c1e292a28e7bccf6db12b7215b7c73da httpd-2.2.16-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:

a6639d43ff7143c55be2dcca66487afe httpd-2.2.16-x86_64-1_slack13.0.txz

Slackware 13.1 package:

9794f02c68318c1be429d533267854fd httpd-2.2.16-i486-1_slack13.1.txz

Slackware x86_64 13.1 package:

1ee92abd81274dec6f39b12d29531b62 httpd-2.2.16-x86_64-1_slack13.1.txz

Slackware -current package:

531139abd2c4f00243474a6b269c4d39 n/httpd-2.2.16-i486-1.txz

Slackware x86_64 -current package:

0b9dec426e71b8f64c32acf7317dfd0d n/httpd-2.2.16-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg httpd-2.2.16-i486-1_slack13.1.txz

Then, restart Apache httpd:

# /etc/rc.d/rc.httpd stop

# /etc/rc.d/rc.httpd start

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkx5PsAACgkQakRjwEAQIjORJgCgk9Jh11t7rrKdORb5O4L22Zqt

rqwAnAqIqtvhqcSG5g9/Z6c0nM7258a4

=oL6v

-----END PGP SIGNATURE-----

2010-08-28 gnupg2 (SSA:2010-240-01)

11 min 44 sec fa

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] gnupg2 (SSA:2010-240-01)

New gnupg2 packages are available for Slackware 12.0, 12.1, 12.2, 13.0, 13.1,

and -current to fix a security issue.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/gnupg2-2.0.14-i486-3_slack13.1.txz: Rebuilt.

Patched to fix "Realloc Bug with X.509 certificates in GnuPG".

For more information, see:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2547

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 12.0:

ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/gnupg2-2.0.4-i486-2_slack12.0.tgz

Updated package for Slackware 12.1:

ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/gnupg2-2.0.9-i486-2_slack12.1.tgz

Updated package for Slackware 12.2:

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/gnupg2-2.0.9-i486-2_slack12.2.tgz

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/gnupg2-2.0.12-i486-2_slack13.0.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/gnupg2-2.0.12-x86_64-2_slack13.0.txz

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/gnupg2-2.0.14-i486-3_slack13.1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/gnupg2-2.0.14-x86_64-3_slack13.1.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/gnupg2-2.0.16-i486-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/gnupg2-2.0.16-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 12.0 package:

d4fd5033a8d84ca1b24f5ec8d2b5dcec gnupg2-2.0.4-i486-2_slack12.0.tgz

Slackware 12.1 package:

f06f083946e1567a558d339982e9982e gnupg2-2.0.9-i486-2_slack12.1.tgz

Slackware 12.2 package:

b1cdbd61297affafe01ea4740e900ef9 gnupg2-2.0.9-i486-2_slack12.2.tgz

Slackware 13.0 package:

513900baef7865900d0bb026d252e112 gnupg2-2.0.12-i486-2_slack13.0.txz

Slackware x86_64 13.0 package:

8f1a8ff8e567940794060f9d5e34ed9b gnupg2-2.0.12-x86_64-2_slack13.0.txz

Slackware 13.1 package:

4b1241472b91e1d2b9704852ba3a1d5f gnupg2-2.0.14-i486-3_slack13.1.txz

Slackware x86_64 13.1 package:

7a7d35d3aec7d5ba0169c92f7f47c9f6 gnupg2-2.0.14-x86_64-3_slack13.1.txz

Slackware -current package:

eb31dd8fea4da735f188990e67231839 n/gnupg2-2.0.16-i486-1.txz

Slackware x86_64 -current package:

764c74e54177d6f6bd39bd5b5ecf6a98 n/gnupg2-2.0.16-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg gnupg2-2.0.14-i486-3_slack13.1.txz

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkx5PsAACgkQakRjwEAQIjMexQCggohBy0GjjlptLOkf09NzMO/F

6IQAmwZc/FHbS+4/7eWaUytIoWZQ4wm2

=DduU

-----END PGP SIGNATURE-----

2010-07-24 mozilla-firefox (SSA:2010-204-01)

11 min 44 sec fa

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] mozilla-firefox (SSA:2010-204-01)

New mozilla-firefox packages are available for Slackware 13.0, 13.1,

and -current to fix a regression.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/mozilla-firefox-3.6.8-i686-1.txz: Upgraded.

This fixes a regression in Firefox 3.6.7.

For more information, see:

http://www.mozilla.org/security/known-vulnerabilities/firefox36.html

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/mozilla-firefox-3.6.8-i686-1.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/mozilla-firefox-3.6.8-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/mozilla-firefox-3.6.8-i686-1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/mozilla-firefox-3.6.8-x86_64-1_slack13.1.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/mozilla-firefox-3.6.8-i686-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/mozilla-firefox-3.6.8-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 12.2 package:

44a3d85cb39de9b698fc266ea54ce1fa mozilla-firefox-3.0.19-i686-1.tgz

Slackware 13.0 package:

4a00d33baba7adb6a8f0ad4d12d02c86 mozilla-firefox-3.6.8-i686-1.txz

Slackware x86_64 13.0 package:

6352a44f086d17b296bda093df7fcb6a mozilla-firefox-3.6.8-x86_64-1_slack13.0.txz

Slackware 13.1 package:

4a00d33baba7adb6a8f0ad4d12d02c86 mozilla-firefox-3.6.8-i686-1.txz

Slackware x86_64 13.1 package:

b7ca8139147a6b88ea1b6978dc36221d mozilla-firefox-3.6.8-x86_64-1_slack13.1.txz

Slackware -current package:

4a00d33baba7adb6a8f0ad4d12d02c86 xap/mozilla-firefox-3.6.8-i686-1.txz

Slackware x86_64 -current package:

a564c8307d2e4f276839beadd0a6d730 xap/mozilla-firefox-3.6.8-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg mozilla-firefox-3.6.8-i686-1.txz

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkxKX9EACgkQakRjwEAQIjM/VwCeOLqb5jcNi5SvYzE188OXnDQq

qHcAnj1FxHrsrDEGMAjkFJmtBJt81289

=K1Uc

-----END PGP SIGNATURE-----

2010-07-21 seamonkey (SSA:2010-202-03)

11 min 44 sec fa

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] seamonkey (SSA:2010-202-03)

New seamonkey packages are available for Slackware 12.2, 13.0, 13.1,

and -current to fix security issues.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/seamonkey-2.0.6-i486-1_slack13.1.txz: Upgraded.

This release fixes some more security vulnerabilities.

For more information, see:

http://www.mozilla.org/security/known-vulnerabilities/seamonkey20.html

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 12.2:

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/seamonkey-solibs-2.0.6-i486-1_slack12.2.tgz

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/seamonkey-2.0.6-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/seamonkey-2.0.6-i486-1_slack13.0.txz seamonkey-solibs-2.0.6-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/seamonkey-2.0.6-x86_64-1_slack13.0.txz seamonkey-solibs-2.0.6-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/seamonkey-2.0.6-i486-1_slack13.1.txz seamonkey-solibs-2.0.6-i486-1_slack13.1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/seamonkey-2.0.6-x86_64-1_slack13.1.txz seamonkey-solibs-2.0.6-x86_64-1_slack13.1.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/seamonkey-solibs-2.0.6-i486-1.txz

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/seamonkey-2.0.6-i486-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/seamonkey-solibs-2.0.6-x86_64-1.txz

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/seamonkey-2.0.6-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 12.2 package:

4c55bb853a8686ccb10b4039bbe7ad63 seamonkey-2.0.6-i486-1_slack12.2.tgz

efea54f758932f3decdefdda2b1daa23 seamonkey-solibs-2.0.6-i486-1_slack12.2.tgz

Slackware 13.0 package:

2e8e454452d94020ba56bce95335e809 seamonkey-2.0.6-i486-1_slack13.0.txz

fbab2e8d8b454f8b7ea2afb6e99706c3 seamonkey-solibs-2.0.6-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:

acc1ab6da9b63a473f18f1161d83f76f seamonkey-2.0.6-x86_64-1_slack13.0.txz

312de679b48bfec84635b5bab7fa57ab seamonkey-solibs-2.0.6-x86_64-1_slack13.0.txz

Slackware 13.1 package:

a3a18ccdfaff4cc1d89c2ddf83d66078 seamonkey-2.0.6-i486-1_slack13.1.txz

6383393026c73fbfcb4b25fabd40b200 seamonkey-solibs-2.0.6-i486-1_slack13.1.txz

Slackware x86_64 13.1 package:

861ad1b4317aedbdcab2969a3a290a8b seamonkey-2.0.6-x86_64-1_slack13.1.txz

1de96a60146252ef53118f6178ebd995 seamonkey-solibs-2.0.6-x86_64-1_slack13.1.txz

Slackware -current package:

5be899b1f8aa124ccf31b8e0eb7b07a8 l/seamonkey-solibs-2.0.6-i486-1.txz

ea9f96856e357a690729d9e9d1f657e8 xap/seamonkey-2.0.6-i486-1.txz

Slackware x86_64 -current package:

1b4fb337150387124e350c8d4f0cabd7 l/seamonkey-solibs-2.0.6-x86_64-1.txz

04f921b7c18893de63bd59b16f98c001 xap/seamonkey-2.0.6-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the packages as root:

# upgradepkg seamonkey-2.0.6-i486-1_slack13.1.txz seamonkey-solibs-2.0.6-i486-1_slack13.1.txz

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkxHf7wACgkQakRjwEAQIjOvNACfdsBq7iN2t5Or3+kMBsHymJij

umIAnA9LqxIV+mEmcpxwnx5gOb6yxzti

=2AlV

-----END PGP SIGNATURE-----

2010-07-21 mozilla-thunderbird (SSA:2010-202-02)

11 min 44 sec fa

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] mozilla-thunderbird (SSA:2010-202-02)

New mozilla-thunderbird packages are available for Slackware 13.1

and -current to fix security issues.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/mozilla-thunderbird-3.0.6-i686-1.txz: Upgraded.

This upgrade fixes some more security bugs.

For more information, see:

http://www.mozilla.org/security/known-vulnerabilities/thunderbird30.html

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/mozilla-thunderbird-3.0.6-i686-1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/mozilla-thunderbird-3.0.6-x86_64-1.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/mozilla-thunderbird-3.1.1-i686-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/mozilla-thunderbird-3.1.1-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 13.1 package:

e589b7c96b219b47ec014083ae434299 mozilla-thunderbird-3.0.6-i686-1.txz

Slackware x86_64 13.1 package:

ca6ce46af239cd95a066298f03138a75 mozilla-thunderbird-3.0.6-x86_64-1.txz

Slackware -current package:

a3a835332a544f626c998c9bbfac0b65 xap/mozilla-thunderbird-3.1.1-i686-1.txz

Slackware x86_64 -current package:

6c7c9e216d8e2d89a6e51999ef308ecf xap/mozilla-thunderbird-3.1.1-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg mozilla-thunderbird-3.0.6-i686-1.txz

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkxHf7kACgkQakRjwEAQIjPCHACfQ1u2/L14HXGhmUhHkVTIOcAs

Xa0AoIFHMvY6FtqDEnAhkXZmtvNvyZ3H

=yg3A

-----END PGP SIGNATURE-----

2010-07-21 mozilla-firefox (SSA:2010-202-01)

11 min 44 sec fa

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] mozilla-firefox (SSA:2010-202-01)

New mozilla-firefox packages are available for Slackware 12.2,

13.0, 13.1, and -current to fix security issues.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/mozilla-firefox-3.6.7-i686-1.txz: Upgraded.

This fixes some security issues.

For more information, see:

http://www.mozilla.org/security/known-vulnerabilities/firefox36.html

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 12.2:

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/mozilla-firefox-3.0.19-i686-1.tgz

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/mozilla-firefox-3.6.7-i686-1.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/mozilla-firefox-3.6.7-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/mozilla-firefox-3.6.7-i686-1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/mozilla-firefox-3.6.7-x86_64-1_slack13.1.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/mozilla-firefox-3.6.7-i686-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/mozilla-firefox-3.6.7-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 12.2 package:

44a3d85cb39de9b698fc266ea54ce1fa mozilla-firefox-3.0.19-i686-1.tgz

Slackware 13.0 package:

27251b1c809031585d3619af9206d109 mozilla-firefox-3.6.7-i686-1.txz

Slackware x86_64 13.0 package:

bf7ea6920981a4f378f750db463ad4b6 mozilla-firefox-3.6.7-x86_64-1_slack13.0.txz

Slackware 13.1 package:

27251b1c809031585d3619af9206d109 mozilla-firefox-3.6.7-i686-1.txz

Slackware x86_64 13.1 package:

eab7c07941ee876df8aca72d1254c10d mozilla-firefox-3.6.7-x86_64-1_slack13.1.txz

Slackware -current package:

27251b1c809031585d3619af9206d109 xap/mozilla-firefox-3.6.7-i686-1.txz

Slackware x86_64 -current package:

eef82fb1cd79faeeb209b1f1cc3fe04a xap/mozilla-firefox-3.6.7-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg mozilla-firefox-3.6.7-i686-1.txz

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkxHf7YACgkQakRjwEAQIjNrTQCfbFWBjMXdmZOVhenRBNY1fprf

T5EAoI02tc2YGYW6EbPyU/Umh8AONCW9

=z2FA

-----END PGP SIGNATURE-----

2010-06-29 libtiff (SSA:2010-180-02)

Sab, 08/28/2010 - 18:00

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] libtiff (SSA:2010-180-02)

New libtiff packages are available for Slackware 9.0, 9.1, 10.0, 10.1, 10.2,

11.0, 12.0, 12.1, 12.2, 13.0, 13.1, and -current to fix security issues.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/libtiff-3.9.4-i486-1_slack13.1.txz: Upgraded.

This fixes image structure handling bugs that could lead to crashes or

execution of arbitrary code if a specially-crafted TIFF image is loaded.

For more information, see:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1411

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2065

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2067

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 9.0:

ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/libtiff-3.8.2-i386-2_slack9.0.tgz

Updated package for Slackware 9.1:

ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/libtiff-3.8.2-i486-2_slack9.1.tgz

Updated package for Slackware 10.0:

ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/libtiff-3.8.2-i486-2_slack10.0.tgz

Updated package for Slackware 10.1:

ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/libtiff-3.8.2-i486-2_slack10.1.tgz

Updated package for Slackware 10.2:

ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/libtiff-3.8.2-i486-2_slack10.2.tgz

Updated package for Slackware 11.0:

ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/libtiff-3.8.2-i486-3_slack11.0.tgz

Updated package for Slackware 12.0:

ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/libtiff-3.8.2-i486-4_slack12.0.tgz

Updated package for Slackware 12.1:

ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/libtiff-3.8.2-i486-4_slack12.1.tgz

Updated package for Slackware 12.2:

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/libtiff-3.8.2-i486-4_slack12.2.tgz

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/libtiff-3.8.2-i486-4_slack13.0.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/libtiff-3.8.2-x86_64-4_slack13.0.txz

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/libtiff-3.9.4-i486-1_slack13.1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/libtiff-3.9.4-x86_64-1_slack13.1.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/libtiff-3.9.4-i486-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/libtiff-3.9.4-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 9.0 package:

c38a88c8084f3967eb9edf6b5fd0caa8 libtiff-3.8.2-i386-2_slack9.0.tgz

Slackware 9.1 package:

825a5c065e3d282b602368a3f9615a54 libtiff-3.8.2-i486-2_slack9.1.tgz

Slackware 10.0 package:

339b81c7b3a93975befa61e320f6c384 libtiff-3.8.2-i486-2_slack10.0.tgz

Slackware 10.1 package:

9c5fb4c9b467fb7fdc1b262027de12ed libtiff-3.8.2-i486-2_slack10.1.tgz

Slackware 10.2 package:

1f33480c8da08982a417cc4c89daf1dd libtiff-3.8.2-i486-2_slack10.2.tgz

Slackware 11.0 package:

3b5d3c4f84a58eaf59cf911c87fffe94 libtiff-3.8.2-i486-3_slack11.0.tgz

Slackware 12.0 package:

f4e6738e11bb43999a9ad383070c0a37 libtiff-3.8.2-i486-4_slack12.0.tgz

Slackware 12.1 package:

e6e4e9ee16529a706e5def3bec247312 libtiff-3.8.2-i486-4_slack12.1.tgz

Slackware 12.2 package:

d259c69e06f91c532377856f3dc7d07d libtiff-3.8.2-i486-4_slack12.2.tgz

Slackware 13.0 package:

5d9b2f249ec7c816b119920994f8b6a7 libtiff-3.8.2-i486-4_slack13.0.txz

Slackware x86_64 13.0 package:

cba93decce7063d7179f37d1b7e074be libtiff-3.8.2-x86_64-4_slack13.0.txz

Slackware 13.1 package:

d9da15c41ba17a348a8e052ae0e64750 libtiff-3.9.4-i486-1_slack13.1.txz

Slackware x86_64 13.1 package:

f173686da98205b32950e9d23fbb0d32 libtiff-3.9.4-x86_64-1_slack13.1.txz

Slackware -current package:

c5067a3a1ffaedd8cfe7737927ba36c2 l/libtiff-3.9.4-i486-1.txz

Slackware x86_64 -current package:

953bac895882fb63cf1af2c29a7693aa l/libtiff-3.9.4-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg libtiff-3.9.4-i486-1_slack13.1.txz

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkwqzvEACgkQakRjwEAQIjO4LACfcb7+f04ox2hCPVfIApuGNvvE

bOgAn2L5NbZFRC6aHZ2YqXAem5a8dYi1

=cknM

-----END PGP SIGNATURE-----

2010-06-29 libpng (SSA:2010-180-01)

Sab, 08/28/2010 - 18:00

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] libpng (SSA:2010-180-01)

New libpng packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1,

10.2, 11.0, 12.0, 12.1, 12.2, 13.0, 13.1, and -current to fix security issues.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/libpng-1.4.3-x86_64-1_slack13.1.txz: Upgraded.

Upgraded to libpng-1.2.44 and libpng-1.4.3.

This fixes out-of-bounds memory write bugs that could lead to crashes

or the execution of arbitrary code, and a memory leak bug which could

lead to application crashes.

For more information, see:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1205

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2249

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 8.1:

ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/libpng-1.2.44-i386-1_slack8.1.tgz

Updated package for Slackware 9.0:

ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/libpng-1.2.44-i386-1_slack9.0.tgz

Updated package for Slackware 9.1:

ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/libpng-1.2.44-i486-1_slack9.1.tgz

Updated package for Slackware 10.0:

ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/libpng-1.2.44-i486-1_slack10.0.tgz

Updated package for Slackware 10.1:

ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/libpng-1.2.44-i486-1_slack10.1.tgz

Updated package for Slackware 10.2:

ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/libpng-1.2.44-i486-1_slack10.2.tgz

Updated package for Slackware 11.0:

ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/libpng-1.2.44-i486-1_slack11.0.tgz

Updated package for Slackware 12.0:

ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/libpng-1.2.44-i486-1_slack12.0.tgz

Updated package for Slackware 12.1:

ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/libpng-1.2.44-i486-1_slack12.1.tgz

Updated package for Slackware 12.2:

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/libpng-1.2.44-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/libpng-1.2.44-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/libpng-1.2.44-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/libpng-1.4.3-i486-1_slack13.1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/libpng-1.4.3-x86_64-1_slack13.1.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/libpng-1.4.3-i486-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/libpng-1.4.3-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 8.1 package:

bdb6dcd9e95528e322bc1d4bd12577c5 libpng-1.2.44-i386-1_slack8.1.tgz

Slackware 9.0 package:

671e4efac517aab683ec3594936841e3 libpng-1.2.44-i386-1_slack9.0.tgz

Slackware 9.1 package:

f9be33ae1dab63722309f7eb6f909de9 libpng-1.2.44-i486-1_slack9.1.tgz

Slackware 10.0 package:

f62bc1d55bf067ef87271edef98cd811 libpng-1.2.44-i486-1_slack10.0.tgz

Slackware 10.1 package:

92c37a054de753b91843587be7baa093 libpng-1.2.44-i486-1_slack10.1.tgz

Slackware 10.2 package:

46fff313eea09bf7d8dc5aa7d5f02e50 libpng-1.2.44-i486-1_slack10.2.tgz

Slackware 11.0 package:

53cb0cd66561a896570f63fb7b902c53 libpng-1.2.44-i486-1_slack11.0.tgz

Slackware 12.0 package:

ca4e5349663e5c89535b499250749a81 libpng-1.2.44-i486-1_slack12.0.tgz

Slackware 12.1 package:

24b8375f21db062f2d737155f34d43b8 libpng-1.2.44-i486-1_slack12.1.tgz

Slackware 12.2 package:

506640f2470264ed5893cff4ac7b1c71 libpng-1.2.44-i486-1_slack12.2.tgz

Slackware 13.0 package:

d555896cea03edf4d58a31fdee4406de libpng-1.2.44-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:

66e99767c446f36d5556b9964931f61c libpng-1.2.44-x86_64-1_slack13.0.txz

Slackware 13.1 package:

0c51a2a6efe13123eaa59211333ace60 libpng-1.4.3-i486-1_slack13.1.txz

Slackware x86_64 13.1 package:

5f546d986b469fdc65f6f24e61fbb1ae libpng-1.4.3-x86_64-1_slack13.1.txz

Slackware -current package:

f8c1549a3845b2e5c6507fc0c5da1a8b l/libpng-1.4.3-i486-1.txz

Slackware x86_64 -current package:

359d7cf5d6b491dbf9160c13618d8425 l/libpng-1.4.3-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg libpng-1.4.3-i486-1_slack13.1.txz

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkwqzu8ACgkQakRjwEAQIjNZJACePhJQjrMRSOSC92z/gStiVtvC

zO4AnAnRmu9Z98lsRNdoxJViI7M7zvUQ

=2RYD

-----END PGP SIGNATURE-----

2010-06-25 cups (SSA:2010-176-05)

Sab, 08/28/2010 - 18:00

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] cups (SSA:2010-176-05)

New cups packages are available for Slackware 13.1 and -current to

fix security issues.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/cups-1.4.4-i486-1_slack13.1.txz: Upgraded.

Fixed a memory allocation error in texttops.

Fixed a Cross-Site Request Forgery (CSRF) that could allow a remote

attacker to reconfigure or disable CUPS if a CUPS admin logged into the

web interface visited a specially-crafted website.

Fixed a bug where uninitialized memory from the cupsd process could

reveal sensitive information.

For more information, see:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0540

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0542

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1748

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/cups-1.4.4-i486-1_slack13.1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/cups-1.4.4-x86_64-1_slack13.1.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/a/cups-1.4.4-i486-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/a/cups-1.4.4-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 13.1 package:

2828baed64ca4e479b91a961bedf99df cups-1.4.4-i486-1_slack13.1.txz

Slackware x86_64 13.1 package:

628ace74afcc27261b0a0f92c78a451b cups-1.4.4-x86_64-1_slack13.1.txz

Slackware -current package:

e9b20c637552192d3e72fe2c2ba1b4ca a/cups-1.4.4-i486-1.txz

Slackware x86_64 -current package:

d830972a63e5f0cb526f25ec812bb4ce a/cups-1.4.4-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg cups-1.4.4-i486-1_slack13.1.txz

Then, restart CUPS:

# sh /etc/rc.d/rc.cups restart

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkwk5EcACgkQakRjwEAQIjNCJACbBWRg0kTPxNdguQm8ghU6/Ojd

01sAoILfopPKLDJChC6JMQ6YOGF85qOa

=KovX

-----END PGP SIGNATURE-----

2010-06-25 mozilla-thunderbird (SSA:2010-176-04)

Sab, 08/28/2010 - 18:00

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] mozilla-thunderbird (SSA:2010-176-04)

New mozilla-thunderbird packages are available for Slackware 13.1

and -current to fix security issues.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/mozilla-thunderbird-3.0.5-i686-1.txz: Upgraded.

This upgrade fixes some more security bugs.

For more information, see:

http://www.mozilla.org/security/known-vulnerabilities/thunderbird30.html

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/mozilla-thunderbird-3.0.5-i686-1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/mozilla-thunderbird-3.0.5-x86_64-1.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/mozilla-thunderbird-3.1-i686-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/mozilla-thunderbird-3.1-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 13.1 package:

d110266bdd1463f0e469246ab414b76a mozilla-thunderbird-3.0.5-i686-1.txz

Slackware x86_64 13.1 package:

ed712fac0fc58cebe7e4e4d389a8ef0a mozilla-thunderbird-3.0.5-x86_64-1.txz

Slackware -current package:

583a5912732515918c344f13108ea507 xap/mozilla-thunderbird-3.1-i686-1.txz

Slackware x86_64 -current package:

16958ec8ea0b7941065c8720bd23c556 xap/mozilla-thunderbird-3.1-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg mozilla-thunderbird-3.0.5-i686-1.txz

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkwk5EQACgkQakRjwEAQIjMuvACfTbmI93VRYO1BIS/OYpyTwLF7

+EUAnRAhgwpt4EH4HmlFSgqxXhM7WhkL

=HXuO

-----END PGP SIGNATURE-----

2010-06-25 seamonkey (SSA:2010-176-03)

Sab, 08/28/2010 - 18:00

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] seamonkey (SSA:2010-176-03)

New seamonkey packages are available for Slackware 12.2, 13.0, 13.1,

and -current to fix security issues.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/seamonkey-2.0.5-i486-1_slack13.1.txz: Upgraded.

This release fixes some more security vulnerabilities.

For more information, see:

http://www.mozilla.org/security/known-vulnerabilities/seamonkey20.html

(* Security fix *)

patches/packages/seamonkey-solibs-2.0.5-i486-1_slack13.1.txz: Upgraded.

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 12.2:

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/seamonkey-2.0.5-i486-1_slack12.2.tgz

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/seamonkey-solibs-2.0.5-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/seamonkey-2.0.5-i486-1_slack13.0.txz

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/seamonkey-solibs-2.0.5-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/seamonkey-2.0.5-x86_64-1_slack13.0.txz

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/seamonkey-solibs-2.0.5-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/seamonkey-2.0.5-i486-1_slack13.1.txz

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/seamonkey-solibs-2.0.5-i486-1_slack13.1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/seamonkey-2.0.5-x86_64-1_slack13.1.txz

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/seamonkey-solibs-2.0.5-x86_64-1_slack13.1.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/seamonkey-solibs-2.0.5-i486-1.txz

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/seamonkey-2.0.5-i486-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/seamonkey-solibs-2.0.5-x86_64-1.txz

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/seamonkey-2.0.5-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 12.2 package:

0056c22bc7ffbc6cedc56c20eae0f6f6 seamonkey-2.0.5-i486-1_slack12.2.tgz

c5f5e1edcc1ad319a778e261d14085f2 seamonkey-solibs-2.0.5-i486-1_slack12.2.tgz

Slackware 13.0 package:

fd24cb7c12a7b3d222891f9c225b4220 seamonkey-2.0.5-i486-1_slack13.0.txz

132f7cae7f26919ba14b09fc6f0771f2 seamonkey-solibs-2.0.5-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:

4c2047cb0d628a88d8d2ceadf3d1fb34 seamonkey-2.0.5-x86_64-1_slack13.0.txz

e42053917b1d7eb9a10ae2fd81276667 seamonkey-solibs-2.0.5-x86_64-1_slack13.0.txz

Slackware 13.1 package:

5b433ebdcfde1135bc5e0ba62ee1af9e seamonkey-2.0.5-i486-1_slack13.1.txz

9c123bc1d423476039ab716461db5864 seamonkey-solibs-2.0.5-i486-1_slack13.1.txz

Slackware x86_64 13.1 package:

99423dcfa92024c5c25b756ab933e295 seamonkey-2.0.5-x86_64-1_slack13.1.txz

55c4a3bc8130930c40702eb2613f2b78 seamonkey-solibs-2.0.5-x86_64-1_slack13.1.txz

Slackware -current package:

d45bca55e9d28483f91e7b60bdcd6dc8 l/seamonkey-solibs-2.0.5-i486-1.txz

b41d488f770e49018f99aa5ff4de9bd8 xap/seamonkey-2.0.5-i486-1.txz

Slackware x86_64 -current package:

46f86ac5e2d74b839fab64daec15ec66 l/seamonkey-solibs-2.0.5-x86_64-1.txz

228168831bc89d40de75cbbc24188888 xap/seamonkey-2.0.5-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the packages as root:

# upgradepkg seamonkey-2.0.5-i486-1_slack13.1.txz

# upgradepkg seamonkey-solibs-2.0.5-i486-1_slack13.1.txz

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkwk5EIACgkQakRjwEAQIjNMlwCfZmnFtVOey02g7kitd3T/a3lw

G3cAn0Op9heuljir3dHXLWLuPJhUs9fp

=Qes3

-----END PGP SIGNATURE-----

2010-06-25 mozilla-firefox (SSA:2010-176-02)

Sab, 08/28/2010 - 18:00

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] mozilla-firefox (SSA:2010-176-02)

New mozilla-firefox packages are available for Slackware 13.0, 13.1,

and -current to fix security issues.

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/mozilla-firefox-3.6.4-i686-1.txz: Upgraded.

This fixes some security issues.

For more information, see:

http://www.mozilla.org/security/known-vulnerabilities/firefox36.html

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/mozilla-firefox-3.6.4-i686-1.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/mozilla-firefox-3.6.4-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/mozilla-firefox-3.6.4-i686-1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/mozilla-firefox-3.6.4-x86_64-1_slack13.0.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/mozilla-firefox-3.6.4-i686-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/mozilla-firefox-3.6.4-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 13.0 package:

cbca3a5859da4f5284d35472f2a752b7 mozilla-firefox-3.6.4-i686-1.txz

Slackware x86_64 13.0 package:

7078cf27f8c5bc35f05a3a8e6798ed01 mozilla-firefox-3.6.4-x86_64-1_slack13.0.txz

Slackware 13.1 package:

cbca3a5859da4f5284d35472f2a752b7 mozilla-firefox-3.6.4-i686-1.txz

Slackware x86_64 13.1 package:

313323a25a7a170523ec58b1e35b55aa mozilla-firefox-3.6.4-x86_64-1_slack13.0.txz

Slackware -current package:

cbca3a5859da4f5284d35472f2a752b7 xap/mozilla-firefox-3.6.4-i686-1.txz

Slackware x86_64 -current package:

8a3b62d464cc628621a867f27f3c9817 xap/mozilla-firefox-3.6.4-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg mozilla-firefox-3.6.4-i686-1.txz

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkwk5D8ACgkQakRjwEAQIjN0kACcCGvF+YB+vKX6LOZL7tZEbTwf

ukQAnio//33wh5n9AKg+hu60+sGQwrGh

=oLIb

-----END PGP SIGNATURE-----

2010-06-25 bind (SSA:2010-176-01)

Sab, 07/24/2010 - 18:00

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] bind (SSA:2010-176-01)

New bind packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2,

11.0, 12.0, 12.1, 12.2, 13.0, 13.1, and -current to fix security issues when

DNSSEC is enabled (which is not the default setting).

Here are the details from the Slackware 13.1 ChangeLog:

+--------------------------+

patches/packages/bind-9.4.3_P5-i486-1_slack13.1.txz: Upgraded.

This fixes possible DNS cache poisoning attacks when DNSSEC is enabled

and checking is disabled (CD).

For more information, see:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0097

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 8.1:

ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/bind-9.4.3_P5-i386-1_slack8.1.tgz

Updated package for Slackware 9.0:

ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/bind-9.4.3_P5-i386-1_slack9.0.tgz

Updated package for Slackware 9.1:

ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/bind-9.4.3_P5-i486-1_slack9.1.tgz

Updated package for Slackware 10.0:

ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/bind-9.4.3_P5-i486-1_slack10.0.tgz

Updated package for Slackware 10.1:

ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/bind-9.4.3_P5-i486-1_slack10.1.tgz

Updated package for Slackware 10.2:

ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/bind-9.4.3_P5-i486-1_slack10.2.tgz

Updated package for Slackware 11.0:

ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/bind-9.4.3_P5-i486-1_slack11.0.tgz

Updated package for Slackware 12.0:

ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/bind-9.4.3_P5-i486-1_slack12.0.tgz

Updated package for Slackware 12.1:

ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/bind-9.4.3_P5-i486-1_slack12.1.tgz

Updated package for Slackware 12.2:

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/bind-9.4.3_P5-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/bind-9.4.3_P5-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/bind-9.4.3_P5-x86_64-1_slack13.0.txz

Updated package for Slackware 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/bind-9.4.3_P5-i486-1_slack13.1.txz

Updated package for Slackware x86_64 13.1:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/bind-9.4.3_P5-x86_64-1_slack13.1.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/bind-9.7.1-i486-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/bind-9.7.1-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 8.1 package:

c78e8a6cde34015681063a3d1c40c6c1 bind-9.4.3_P5-i386-1_slack8.1.tgz

Slackware 9.0 package:

9fcb18dfc779ecc7f6d69171e398c620 bind-9.4.3_P5-i386-1_slack9.0.tgz

Slackware 9.1 package:

3eb9a4b1973b6a3a2f779a3038269a31 bind-9.4.3_P5-i486-1_slack9.1.tgz

Slackware 10.0 package:

7e11d017c1962f8ef92cfb1e9f39139b bind-9.4.3_P5-i486-1_slack10.0.tgz

Slackware 10.1 package:

4dddfb400d6d928e41c7aa4bf7339547 bind-9.4.3_P5-i486-1_slack10.1.tgz

Slackware 10.2 package:

fe87668c84020ebf28b46910df71bb07 bind-9.4.3_P5-i486-1_slack10.2.tgz

Slackware 11.0 package:

639efc6a35ccee727f0177089d241857 bind-9.4.3_P5-i486-1_slack11.0.tgz

Slackware 12.0 package:

195c3bd1898d5118fe5cedfe6131e83b bind-9.4.3_P5-i486-1_slack12.0.tgz

Slackware 12.1 package:

95fc95a77a99df46d35a578e069a965b bind-9.4.3_P5-i486-1_slack12.1.tgz

Slackware 12.2 package:

aa8bdaedd7b7f6f36ff22be779182ff9 bind-9.4.3_P5-i486-1_slack12.2.tgz

Slackware 13.0 package:

8d7ed3c0ae07a33aea7f506b25bec015 bind-9.4.3_P5-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:

bb1f6aa2682743173135776e1ff0fadd bind-9.4.3_P5-x86_64-1_slack13.0.txz

Slackware 13.1 package:

c619cc02e89ba23a62dfb7726105e40e bind-9.4.3_P5-i486-1_slack13.1.txz

Slackware x86_64 13.1 package:

cb61186275370d1eddc62024725f5d05 bind-9.4.3_P5-x86_64-1_slack13.1.txz

Slackware -current package:

011ae9faeb16bf6e37ed9c8cbf8bb718 n/bind-9.7.1-i486-1.txz

Slackware x86_64 -current package:

e2d2e29b620581c725e68e75af7ba759 n/bind-9.7.1-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg bind-9.4.3_P5-i486-1_slack13.1.txz

Then, restart the name server:

# /etc/rc.d/rc.bind restart

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkwk5D0ACgkQakRjwEAQIjMMYgCfU0uxUj22Busz107qoNDSEjNl

oHkAn1A5TXObPtGrpMtlAqVexIkJAGZM

=4SNK

-----END PGP SIGNATURE-----

2010-06-18 samba (SSA:2010-169-01)

Gio, 07/22/2010 - 04:00

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] samba (SSA:2010-169-01)

New samba packages are available for Slackware 10.0, 10.1, 10.2, 11.0, 12.0,

12.1, 12.2, and 13.0 to fix a security issue.

Here are the details from the Slackware 13.0 ChangeLog:

+--------------------------+

patches/packages/samba-3.2.15-i486-2_slack13.0.txz: Rebuilt.

Patched a buffer overflow in smbd that allows remote attackers to cause

a denial of service (memory corruption and daemon crash) or possibly

execute arbitrary code via a crafted field in a packet.

For more information, see:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2063

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 10.0:

ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/samba-3.0.37-i486-2_slack10.0.tgz

Updated package for Slackware 10.1:

ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/samba-3.0.37-i486-2_slack10.1.tgz

Updated package for Slackware 10.2:

ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/samba-3.0.37-i486-2_slack10.2.tgz

Updated package for Slackware 11.0:

ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/samba-3.0.37-i486-2_slack11.0.tgz

Updated package for Slackware 12.0:

ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/samba-3.0.37-i486-2_slack12.0.tgz

Updated package for Slackware 12.1:

ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/samba-3.0.37-i486-2_slack12.1.tgz

Updated package for Slackware 12.2:

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/samba-3.2.15-i486-2_slack12.2.tgz

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/samba-3.2.15-i486-2_slack13.0.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/samba-3.2.15-x86_64-2_slack13.0.txz

MD5 signatures:

+-------------+

Slackware 10.0 package:

10a993bff58438b18bddd294cc725a41 samba-3.0.37-i486-2_slack10.0.tgz

Slackware 10.1 package:

225648b0ab9e1a4ecc222d1024d4288a samba-3.0.37-i486-2_slack10.1.tgz

Slackware 10.2 package:

8913ff3bf21984f56af81919e0fac4f4 samba-3.0.37-i486-2_slack10.2.tgz

Slackware 11.0 package:

1e0d6af565abe474a5bfc1714f2573ab samba-3.0.37-i486-2_slack11.0.tgz

Slackware 12.0 package:

cbac23dd62fb2acd49bf456b4d89146f samba-3.0.37-i486-2_slack12.0.tgz

Slackware 12.1 package:

ea0b7fa2a0bff911c4826b3265afa66a samba-3.0.37-i486-2_slack12.1.tgz

Slackware 12.2 package:

bb15e8c8ab8d21974e8b9322d9c9b254 samba-3.2.15-i486-2_slack12.2.tgz

Slackware 13.0 package:

9128f7e9777d0bc6494ea967d839b0c0 samba-3.2.15-i486-2_slack13.0.txz

Slackware x86_64 13.0 package:

ea5bbde1ad107f92585429e3cb40a434 samba-3.2.15-x86_64-2_slack13.0.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg samba-3.2.15-i486-2_slack13.0.txz

Then, restart samba.

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkwbva8ACgkQakRjwEAQIjPyEgCeK4g2kqh7mN9TYi9YqLJgPOWs

yacAn2nMKKeaV+gvxDRB7BJh9O2ydsto

=y62a

-----END PGP SIGNATURE-----

2010-05-18 pidgin (SSA:2010-138-01)

Gio, 07/22/2010 - 04:00

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] pidgin (SSA:2010-138-01)

New pidgin packages are available for Slackware 12.0, 12.1, 12.2, 13.0,

and -current to fix a security issue.

Here are the details from the Slackware 13.0 ChangeLog:

+--------------------------+

patches/packages/pidgin-2.7.0-i486-1_slack13.0.txz: Upgraded.

Upgraded to pidgin-2.7.0 and pidgin-encryption-3.1.

The msn_emoticon_msg function in slp.c in the MSN protocol plugin in

libpurple in Pidgin before 2.7.0 allows remote attackers to cause

a denial of service (application crash) via a custom emoticon in a

malformed SLP message.

For more information, see:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1624

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 12.0:

ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/pidgin-2.7.0-i486-1_slack12.0.tgz

Updated package for Slackware 12.1:

ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/pidgin-2.7.0-i486-1_slack12.1.tgz

Updated package for Slackware 12.2:

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/pidgin-2.7.0-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/pidgin-2.7.0-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/pidgin-2.7.0-x86_64-1_slack13.0.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/pidgin-2.7.0-i486-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/pidgin-2.7.0-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 12.0 package:

b988b50b9eacdb945e23f87d727cd9ea pidgin-2.7.0-i486-1_slack12.0.tgz

Slackware 12.1 package:

18d32120919d0042d370813ab90a7d1d pidgin-2.7.0-i486-1_slack12.1.tgz

Slackware 12.2 package:

d3686755cf78d1f1b1c0e61663325c5f pidgin-2.7.0-i486-1_slack12.2.tgz

Slackware 13.0 package:

80002e97f1979c926b2a5c72ef7e4847 pidgin-2.7.0-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:

03ac23f92b3884911718a9e4fce8d3b3 pidgin-2.7.0-x86_64-1_slack13.0.txz

Slackware -current package:

2573c594996ef632e013a0ffcb95fe75 pidgin-2.7.0-i486-1.txz

Slackware x86_64 -current package:

b65ac72c257d0fa7b82728030a79bb36 pidgin-2.7.0-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg pidgin-2.7.0-i486-1_slack13.0.txz

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkvzFogACgkQakRjwEAQIjPOlACfSE9KskrcGb0ZCcVj5G5qLG8e

6wAAn3d2DTWA6ZpmUFIYHKrsJn84pDKf

=uDL6

-----END PGP SIGNATURE-----

2010-05-16 fetchmail (SSA:2010-136-01)

Gio, 07/22/2010 - 04:00

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] fetchmail (SSA:2010-136-01)

New fetchmail packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1,

10.2, 11.0, 12.0, 12.1, 12.2, 13.0, and -current to fix a security issue.

Here are the details from the Slackware 13.0 ChangeLog:

+--------------------------+

patches/packages/fetchmail-6.3.17-i486-1_slack13.0.txz: Upgraded.

A crafted header or POP3 UIDL list could cause a memory leak and crash

leading to a denial of service.

For more information, see:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1167

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?

Give slackware.osuosl.org a try. This is another primary FTP site

for Slackware that can be considerably faster than downloading

directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating additional FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 8.1:

ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/fetchmail-6.3.17-i386-1_slack8.1.tgz

Updated package for Slackware 9.0:

ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/fetchmail-6.3.17-i386-1_slack9.0.tgz

Updated package for Slackware 9.1:

ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/fetchmail-6.3.17-i486-1_slack9.1.tgz

Updated package for Slackware 10.0:

ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/fetchmail-6.3.17-i486-1_slack10.0.tgz

Updated package for Slackware 10.1:

ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/fetchmail-6.3.17-i486-1_slack10.1.tgz

Updated package for Slackware 10.2:

ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/fetchmail-6.3.17-i486-1_slack10.2.tgz

Updated package for Slackware 11.0:

ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/fetchmail-6.3.17-i486-1_slack11.0.tgz

Updated package for Slackware 12.0:

ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/fetchmail-6.3.17-i486-1_slack12.0.tgz

Updated package for Slackware 12.1:

ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/fetchmail-6.3.17-i486-1_slack12.1.tgz

Updated package for Slackware 12.2:

ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/fetchmail-6.3.17-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/fetchmail-6.3.17-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:

ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/fetchmail-6.3.17-x86_64-1_slack13.0.txz

Updated package for Slackware -current:

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/fetchmail-6.3.17-i486-1.txz

Updated package for Slackware x86_64 -current:

ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/fetchmail-6.3.17-x86_64-1.txz

MD5 signatures:

+-------------+

Slackware 8.1 package:

954d5af2d7a73d30e74f28a5d2daa271 fetchmail-6.3.17-i386-1_slack8.1.tgz

Slackware 9.0 package:

6e7602e1573181709cd1aa475d9d26e0 fetchmail-6.3.17-i386-1_slack9.0.tgz

Slackware 9.1 package:

d45e5345faf0b365baa32a3af36a8045 fetchmail-6.3.17-i486-1_slack9.1.tgz

Slackware 10.0 package:

321a11f1e1463ec1c4727dd3046c1efa fetchmail-6.3.17-i486-1_slack10.0.tgz

Slackware 10.1 package:

06e126d0fe6e91048caa76d46462f9d9 fetchmail-6.3.17-i486-1_slack10.1.tgz

Slackware 10.2 package:

01471be554c3dcb74ee9291fa93ac73f fetchmail-6.3.17-i486-1_slack10.2.tgz

Slackware 11.0 package:

a601fc584b65cdd76356861c8b70014e fetchmail-6.3.17-i486-1_slack11.0.tgz

Slackware 12.0 package:

240bec2e78149aad8bd324182345edab fetchmail-6.3.17-i486-1_slack12.0.tgz

Slackware 12.1 package:

d645afc797b455c4a6d6d13f115696b6 fetchmail-6.3.17-i486-1_slack12.1.tgz

Slackware 12.2 package:

8fbdf6195fe2183bab784f507e5380ff fetchmail-6.3.17-i486-1_slack12.2.tgz

Slackware 13.0 package:

4df616b4e26ee1c1281fdd420faedade fetchmail-6.3.17-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:

d805ea49a10834b8a057a86a3006f2d4 fetchmail-6.3.17-x86_64-1_slack13.0.txz

Slackware -current package:

cf3846641063e520649b235888dfda44 n/fetchmail-6.3.17-i486-1.txz

Slackware x86_64 -current package:

410cd426c48dd47e0c4e4b27e2cfd913 n/fetchmail-6.3.17-x86_64-1.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg fetchmail-6.3.17-i486-1_slack13.0.txz

+-----+

Slackware Linux Security Team

http://slackware.com/gpg-key

security@slackware.com

+------------------------------------------------------------------------+

| To leave the slackware-security mailing list: |

+------------------------------------------------------------------------+

| Send an email to majordomo@slackware.com with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkvwUhMACgkQakRjwEAQIjMvQQCfchXmn+CG1T04jlV+SuXUV1f3

omUAniEC4DwOSoRjQxp2wNqWvB5uJ+T9

=XwSM

-----END PGP SIGNATURE-----