New ark packages are available for Slackware 15.0 and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] ark (SSA:2025-051-01) New ark packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/ark-21.12.1-i586-2_slack15.0.txz: Rebuilt. The ark archive tool in KDE was found to extract to absolute paths if they are present in the archive, which may be surprising to those who haven't examined an archive before extracting it. It has been patched to discard any leading '/' in paths to prevent this unlikely occurrence. Thanks to pbslxw for the heads-up. For more information, see: https://www.cve.org/CVERecord?id=CVE-2024-57966 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/ark-21.12.1-i586-2_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/ark-21.12.1-x86_64-2_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/kde/ark-23.08.5-i686-2.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/kde/ark-23.08.5-x86_64-2.txz MD5 signatures: +-------------+ Slackware 15.0 package: 6a839223f6254618afbcfbb10eb175ef ark-21.12.1-i586-2_slack15.0.txz Slackware x86_64 15.0 package: 9aa453fdefa4a6adb19bf0e68891e407 ark-21.12.1-x86_64-2_slack15.0.txz Slackware -currentpackage: 87f69391f541b78904f74d32153f3ef8 kde/ark-23.08.5-i686-2.txz Slackware x86_64 -current package: cabab889f60ab143a3042bdca497d478 kde/ark-23.08.5-x86_64-2.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg ark-21.12.1-i586-2_slack15.0.txz +-----+ . Fresh ark plugins launched for Slackware 15.0 to address vulnerabilities and boost overall system protection.. Slackware Packages, Ark Security Fix, Archive Tool Update. . Severity: Critical. LinuxSecurity.com Team
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-328 2006-04-17 ---------------------------------------------------------------------Product : Fedora Core 5 Name : file-roller Version : 2.14.1 Release : 1.fc5.1 Summary : File Roller is a tool for viewing and creating archives. Description : File Roller is an application for creating and viewing archives files, such as tar files. ---------------------------------------------------------------------Update Information: version 2.14.1 -------------- * Ask for the password when trying to open a password protected rar or arj archive. * Updated the user's guide. * Added help button to all the dialogs. * Install theme-friendly icon. * Fixed bug #335035 - mistake in file-roller's License. * Fixed bug #336908 - backshalshes not supported in paths. * Fixed bug #336632 - Help for Extract Dialog pointing to incorrect location. * Fixed bug #336854 - crash on twice unpacking to the same location. * Fixed bug #335659 - File Roller should move not copy files. * Fixed bug #335368 - Crash when opening large 7z-archive. * Fixed buf #326193 - file-roller creates empty 7zip archives. * Fixed bug #337754 - Drag and Drop extraction only works when source already has focus. * Fixed bug #337331 - Cut/Paste same file results in loss of file. ---------------------------------------------------------------------* Mon Apr 10 2006 Matthias Clasen - 2.14.1-1.fc5.1 - Update to 2.14.1 ---------------------------------------------------------------------This update can be downloaded from: 027e7b0c00c088c0d02df8475bc2d07d8e4341cb SRPMS/file-roller-2.14.1-1.fc5.1.src.rpm 0de2708e96ae7c825f77c0d61c03ed8bd4f89078 ppc/file-roller-2.14.1-1.fc5.1.ppc.rpm 3dbf847412d28844c98b257369c8b53869db99d4 ppc/debug/file-roller-debuginfo-2.14.1-1.fc5.1.ppc.rpm ed99f6903276ef5a1e4ac1bf630d7a03b387b77d x86_64/file-roller-2.14.1-1.fc5.1.x86_64.rpm a9a3d2d14eceb506642eae6b3dced9d4e7424c22 x86_64/debug/file-roller-debuginfo-2.14.1-1.fc5.1.x86_64.rpm 00c0e026a2105bedac2d7c32846a4e80245a0eef i386/file-roller-2.14.1-1.fc5.1.i386.rpm b58ac82ae9f889243c57a056891130f031b5f127 i386/debug/file-roller-debuginfo-2.14.1-1.fc5.1.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-855 2005-09-07 ---------------------------------------------------------------------Product : Fedora Core 4 Name : tar Version : 1.15.1 Release : 10.FC4 Summary : A GNU file archiving program. Description : The GNU tar program saves many files together in one archive and can restore individual files (or all of the files) from that archive. Tar can also be used to add supplemental files to an archive and to update or list files in the archive. Tar includes multivolume support, automatic archive compression/decompression, the ability to perform remote archives, and the ability to perform incremental and full backups. If you want to use tar for remote backups, you also need to install the rmt package. ---------------------------------------------------------------------* Tue Sep 6 2005 Peter Vrabec 1.15.1-10.FC4 - provide man page (#163709, #54243, #56041) ---------------------------------------------------------------------This update can be downloaded from: 0142f48cc079e6bab19d5b7a88b3e590 SRPMS/tar-1.15.1-10.FC4.src.rpm 807c63a19f8c832aa2647b68583c04ab ppc/tar-1.15.1-10.FC4.ppc.rpm 36505d7dc69b64e73209499bbf731b27 ppc/debug/tar-debuginfo-1.15.1-10.FC4.ppc.rpm 05303dfde8fbadb751b8029da44d07b2 x86_64/tar-1.15.1-10.FC4.x86_64.rpm eb9965fb9e3c4d0ff51db15a5081d48e x86_64/debug/tar-debuginfo-1.15.1-10.FC4.x86_64.rpm a0c983af676e5c6cd6e3a717d33147d5 i386/tar-1.15.1-10.FC4.i386.rpm af817337aa72eed126277d85f14983c9 i386/debug/tar-debuginfo-1.15.1-10.FC4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.