Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Slackware: 2005-310-02 Urgent: Libpng Security Flaw Exploited

slackware
Calendar Grey November 6, 2005
Scroller Slackware
Important patch release for Slackware over vulnerabilities in curl and wget that exposed potential buffer overflow risks.
New curl packages are available for Slackware 9.1, 10.0, 10.1, 10.2, and -current, and new wget packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, and -current

Summary

Here are the details from the Slackware 10.2 ChangeLog: patches/packages/curl-7.12.2-i486-2.tgz: Patched. This addresses a buffer overflow in libcurl's NTLM function that could have possible security implications. For more details, see: https://curl.se/docs/security.html https://www.cve.org/CVERecord?id=CVE-2005-3185 (* Security fix *) patches/packages/wget-1.10.2-i486-1.tgz: Upgraded to wget-1.10.2. This addresses a buffer overflow in wget's NTLM handling function that could have possible security implications. For more details, see: https://www.cve.org/CVERecord?id=CVE-2005-3185 (* Security fix *)

Where Find New Packages

Updated package for Slackware 8.1: ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/wget-1.10.2-i386-1.tgz
Updated package for Slackware 9.0: ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/wget-1.10.2-i386-1.tgz
Updated packages for Slackware 9.1: ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/wget-1.10.2-i486-1.tgz
Updated packages for Slackware 10.0: ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/wget-1.10.2-i486-1.tgz
Updated packages for Slackware 10.1: ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/wget-1.10.2-i486-1.tgz
Updated packages for Slackware 10.2: ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/wget-1.10.2-i486-1.tgz
Updated packages for Slackware -current:

MD5 Signatures

Slackware 8.1 package: 27cd415d071ec3e397108262e0e19dbd wget-1.10.2-i386-1.tgz
Slackware 9.0 package: 409ba702f5be1ef48cd82465d97b97a3 wget-1.10.2-i386-1.tgz
Slackware 9.1 packages: 3901bd669c514ebc3d921a3363a88346 curl-7.10.7-i486-2.tgz e96a319ca40c7017718b9bcdfe9f0ad7 wget-1.10.2-i486-1.tgz
Slackware 10.0 packages: e8475472a1bd8700aaca2186ebd4701f curl-7.12.2-i486-2.tgz ebfe7ed62214e55e43d08e46cba08feb wget-1.10.2-i486-1.tgz
Slackware 10.1 packages: 5c9158d6d48a9c6f857355b498eae68f curl-7.12.2-i486-2.tgz e304815a073f47ae744c93eec7f70efa wget-1.10.2-i486-1.tgz
Slackware 10.2 packages: 6596c737f2814c96ba9d3be7434f036d curl-7.12.2-i486-2.tgz 59747d7f14d8dc76b0fcad2a8a803e03 wget-1.10.2-i486-1.tgz
Slackware -current packages: 6596c737f2814c96ba9d3be7434f036d curl-7.12.2-i486-2.tgz 59747d7f14d8dc76b0fcad2a8a803e03 wget-1.10.2-i486-1.tgz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the packages as root: # upgradepkg curl-7.12.2-i486-2.tgz # upgradepkg wget-1.10.2-i486-1.tgz