Advisory: Slackware Essential and Critical Security Patch Updates
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
CVS is a client/server version control system. As a server, it is used to host source code repositories. As a client, it is used to access such repositories. This advisory deals with the use of CVS as a server.
Rsync is a file transfer client and server. A security problem which may lead to unauthorized machine access or code execution has been fixed by upgrading to rsync-2.5.7. This problem only affects machines running rsync in daemon mode,
The recently issued kernel advisory (SSA:2003-336-01) reads: "More details about the Apache issue may be found in the Common Vulnerabilities and Exposures (CVE) database: This should say "kernel", not "Apache". Sorry for any confusion.
New kernels are available for Slackware 9.1 and -current. These have been upgraded to Linux kernel version 2.4.23, which fixes a bug in the kernel's do_brk() function that could be exploited to gain root privileges. These updated kernels and modules should be
Apache httpd is a hypertext transfer protocol server, and is used by over two thirds of the Internet's web sites. Upgraded Apache packages are available for Slackware 8.1, 9.0, 9.1, and -current. These fix local vulnerabilities that could allow users
GDM is the GNOME Display Manager, and is commonly used to provide a graphical login for local users. Upgraded gdm packages are available for Slackware 9.0, 9.1, and -current. These fix two vulnerabilities which could allow a local
Fetchmail is a mail-retrieval and forwarding utility. Upgraded fetchmail packages are available for Slackware 8.1, 9.0, 9.1, and -current. These fix a vulnerability where a specially crafted email could crash fetchmail, preventing the user from
These fix problems with ASN.1 parsing whichcould lead to a denial of service. It is not known whether theproblems could lead to the running of malicious code on theserver, but it has not been ruled out.
Upgraded OpenSSH 3.7.1p2 packages are available for Slackware 8.1,9.0 and -current. This fixes security problems with PAMauthentication. It also includes several code cleanups from SolarDesigner.
Upgraded ProFTPD packages are available for Slackware 8.1, 9.0 and-current. These fix a security issue where an attacker could gaina root shell by downloading a specially crafted file.
Upgraded WU-FTPD packages are available for Slackware 9.0 and-current. These fix a problem where an attacker could use aspecially crafted filename in conjunction with WU-FTPD'sconversion feature to execute arbitrary commands on the server.
There are multiple vulnerabilities in the sendmail package.
These packages fix additional buffer managementerrors that were not corrected in the recent 3.7p1 release.
These fix a buffer management error found in versions ofOpenSSH earlier than 3.7. The possibility exists that this errorcould allow a remote exploit, so we recommend all sites runningOpenSSH upgrade to the new OpenSSH package immediately.
Upgraded pine packages are available for Slackware 8.1, 9.0 and- -current.
These updates fix a previously hard-coded limit of 256connections-per-minute, after which the given service is disabledfor ten minutes.
These fix a security issue where a specially crafted archive mayoverwrite files (including system files anywhere on the filesystem)upon extraction by a user with sufficient permissions.
This fixes a bug where a local user may read any system file by making a symlink to it from $HOME/.xsession-errors and using GDM's error browser to read the file.
Note that this update addresses a security problem in Konqueror which may cause authentication credentials to be leaked to an unintended website through the HTTP-referer header when they have been entered into Konqueror as a URL
There is an off-by-one overflow in xlog() in the nfs-utils package.