Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Slackware 14.2 SSA:2018-120-01 Critical: libwmf DoS Threat

slackware
Calendar Grey May 1, 2018
Dist Slackware Esm H88
Libwmf package for Slackware receives critical security updates to mitigate DoS threats and enhance system security.
New libwmf packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues

Summary

Here are the details from the Slackware 14.2 ChangeLog: patches/packages/libwmf-0.2.8.4-i586-7_slack14.1.txz: Rebuilt. Patched denial of service and possible execution of arbitrary code security issues. For more information, see: https://www.cve.org/CVERecord?id=CVE-2004-0941 https://www.cve.org/CVERecord?id=CVE-2006-3376 https://www.cve.org/CVERecord?id=CVE-2007-0455 https://www.cve.org/CVERecord?id=CVE-2007-2756 https://www.cve.org/CVERecord?id=CVE-2007-3472 https://www.cve.org/CVERecord?id=CVE-2007-3473 https://www.cve.org/CVERecord?id=CVE-2007-3477 https://www.cve.org/CVERecord?id=CVE-2009-3546 https://www.cve.org/CVERecord?id=CVE-2015-0848 https://www.cve.org/CVERecord?id=CVE-2015-4588 https://www.cve.org/CVERecord?id=CVE-2015-4695 https://www.cve.org/CVERecord?id=CVE-2015-4696 https://www.cve.org/CVERecord?id=CVE-2016-10167 https://www.cve.org/CVERecord?id=CVE-2016-10168

Read the Full Advisory

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 13.0: ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/libwmf-0.2.8.4-i486-5_slack13.0.txz
Updated package for Slackware x86_64 13.0: ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/libwmf-0.2.8.4-x86_64-5_slack13.0.txz
Updated package for Slackware 13.1: ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/libwmf-0.2.8.4-i486-6_slack13.1.txz
Updated package for Slackware x86_64 13.1: ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/libwmf-0.2.8.4-x86_64-6_slack13.1.txz
Updated package for Slackware 13.37: ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/libwmf-0.2.8.4-i486-6_slack13.37.txz
Updated package fo...

Read the Full Advisory

MD5 Signatures

Slackware 13.0 package: 6d0143e7e105188714f767aea522f4cb libwmf-0.2.8.4-i486-5_slack13.0.txz
Slackware x86_64 13.0 package: 3f47383d824d93c4518f8fc738c0c820 libwmf-0.2.8.4-x86_64-5_slack13.0.txz
Slackware 13.1 package: 871f2ed8d5b43a139607a4d6f959ff93 libwmf-0.2.8.4-i486-6_slack13.1.txz
Slackware x86_64 13.1 package: a8cff7e3b53153589eab0a0bab9209de libwmf-0.2.8.4-x86_64-6_slack13.1.txz
Slackware 13.37 package: 5db38178040f541080caf9776256331d libwmf-0.2.8.4-i486-6_slack13.37.txz
Slackware x86_64 13.37 package: 5d308a63d03d940622ec21d870b01cde libwmf-0.2.8.4-x86_64-6_slack13.37.txz
Slackware 14.0 package: c806e42bd0498db0f3b70957c7c3a401 libwmf-0.2.8.4-i486-6_slack14.0.txz
Slackware x86_64 14.0 package: 376835bf78178bb15bb3c56cee454eb4 libwmf-0.2.8.4-x86_64-6_slack14.0.txz
Slackware 14.1 package: 8a30446ddb36004db6d5ce10728807af libwmf-0.2.8.4-i486-6_slack14.1.txz
Slackware x86_64 14.1 package: ceb7fa835645c9d55c3ad5eac9eab754 libwmf-0.2.8.4-x86_64-6_slack14.1.txz
Slackware 14.2 package: 4d98c4cad02f173e00570dccccba226a libwmf-0.2.8.4-i586-7_slack14.1.txz
Slackware x86_64 14.2 package: 0750711520b0cf4ff5a9a6e363815702 libwmf-0.2.8.4-x86_64-7_slack14.1.txz
Slackware -current package: ac7070e538cf1d1bb08b68cf7883de6d l/libwmf-0.2.8.4-i586-8.txz
Slackware x86_64 -current package: 5a60b94c51180b5a2d53dba2fe430379 l/libwmf-0.2.8.4-x86_64-8.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg libwmf-0.2.8.4-i586-7_slack14.1.txz

Related News

Your message here