Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Slackware 12.0: SSA:2007-305-02 Critical Remote Code Execution Flaw

slackware
Calendar Grey September 8, 2005
Dist Slackware Esm H88
Latest patches for Slackware -current tackle significant vulnerabilities. Ensure safety with these crucial updates and fixes.
This advisory summarizes recent security fixes in Slackware -current

Summary

Here are the details from the Slackware -current ChangeLog: ap/groff-1.19.1-i486-3.tgz: Fixed a /tmp bug in groffer. Groffer is a script to display formatted output on the console or X, and is not normally used in other scripts (for printers, etc) like most groff components are. The risk from this bug is probably quite low. The fix was pulled from the just-released groff-1.19.2. With Slackware 10.2 just around the corner it didn't seem prudent to upgrade to that -- the diff from 1.19.1 to 1.19.2 is over a megabyte compressed. For more information, see: https://www.cve.org/CVERecord?id=CAN-2004-0969 (* Security fix *) kde/kdebase-3.4.2-i486-2.tgz: Patched a bug in Konqueror's handling of characters such as '*', '[', and '?'. Generated new kdm config files. Added /opt/kde/man to $MANPATH. Patched a security bug in kcheckpass that could allow a local user to gain root privileges. For more information, see:

Read the Full Advisory

Where Find New Packages

Add of these packages are available in the slackware-current directory on ftp.slackware.com:

A .asc file is provided next to each package. This can be used along with 'gpg --verify' to verify the integrity of the packages.

MD5 Signatures

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Related News

Your message here