Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
New nvi packages are available for Slackware 15.0 and -current to fix a security issue.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] nvi (SSA:2026-063-01) New nvi packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/nvi-1.81.6-i586-4_slack15.0.txz: Rebuilt. Merge patchset from Debian. This makes a number of fixes and improvements, especially concerning wide-character support. It also fixes a possible heap-based buffer overflow in the regex handling affecting 32-bit platforms. Thanks to r1w1s1. For more information, see: https://www.cve.org/CVERecord?id=CVE-2015-2305 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/nvi-1.81.6-i586-4_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/nvi-1.81.6-x86_64-4_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/a/nvi-1.81.6-i686-4.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/a/nvi-1.81.6-x86_64-4.txz MD5 signatures: +-------------+ Slackware 15.0 package: 20b4be275459ec1004777c855d60cc69 nvi-1.81.6-i586-4_slack15.0.txz Slackware x86_64 15.0 package: 6aeebbc3cc5934e740217a674675e4bb nvi-1.81.6-x86_64-4_slack15.0.txz Slackware -current package: c19f6b9fe31e116ea08ee985d84b3007 a/nvi-1.81.6-i686-4.txz Slackware x86_64 -currentpackage: 0f6f7f41edb565c9ec5b45b016b00a4d a/nvi-1.81.6-x86_64-4.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg nvi-1.81.6-i586-4_slack15.0.txz +-----+ . New nvi packages for Slackware address an important buffer overflow issue to enhance system security and performance.. nvi package updates, Slackware 15.0 security, buffer overflow patch, slackware security advisory. . Severity: Important. LinuxSecurity.com Team
When a filename is saved, it ought to get displayed on the screen.The routine handling this didn't escape format strings.. -------------------------------------------------------------------------- Debian Security Advisory DSA 085-1
Get the latest Linux and open source security news straight to your inbox.