New slocate packages are available for Slackware 12.1, 12.2, 13.0, 13.1, 13.37, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] slocate (SSA:2012-244-05) New slocate packages are available for Slackware 12.1, 12.2, 13.0, 13.1, 13.37, and -current to fix a security issue. Here are the details from the Slackware 13.37 ChangeLog: +--------------------------+ Patched to use lstat64 and -D_LARGEFILE64_SOURCE. Thanks to Mancha+. Patched to fix information leak of filenames in protected directories. For more information, see: https://www.cve.org/CVERecord?id=CVE-2007-0227 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 12.1: ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/slocate-3.1-i486-2_slack12.1.tgz Updated package for Slackware 12.2: ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/slocate-3.1-i486-2_slack12.2.tgz Updated package for Slackware 13.0: ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/slocate-3.1-i486-4_slack13.0.txz Updated package for Slackware x86_64 13.0: ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/slocate-3.1-x86_64-4_slack13.0.txz Updated package for Slackware 13.1: ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/slocate-3.1-i486-4_slack13.1.txz Updated package for Slackware x86_64 13.1: ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/slocate-3.1-x86_64-4_slack13.1.txz Updated package for Slackware 13.37: ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/slocate-3.1-i486-4_slack13.37.txz Updated package for Slackwarex86_64 13.37: ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/slocate-3.1-x86_64-4_slack13.37.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 12.1 package: 294638d315522d39a548320f8ecb8dfe slocate-3.1-i486-2_slack12.1.tgz Slackware 12.2 package: 314118b4aa53120c98049c3979a91bd9 slocate-3.1-i486-2_slack12.2.tgz Slackware 13.0 package: c355a02276b1dd619d4097aff1f6deaa slocate-3.1-i486-4_slack13.0.txz Slackware x86_64 13.0 package: d81b496d4d5eeb64b6d58e006a671019 slocate-3.1-x86_64-4_slack13.0.txz Slackware 13.1 package: de3ac5c264fcc7e0916d603ca6f11e41 slocate-3.1-i486-4_slack13.1.txz Slackware x86_64 13.1 package: df3c40f8666d2d1bf9c4aa9b383c87ff slocate-3.1-x86_64-4_slack13.1.txz Slackware 13.37 package: 83670d384a248f24e3a8e2bfdfebb14f slocate-3.1-i486-4_slack13.37.txz Slackware x86_64 13.37 package: df0cf00f72804b549283e4c719eff4ec slocate-3.1-x86_64-4_slack13.37.txz Slackware -current package: 5c32ada3968815e063e5abd8cef507b4 a/slocate-3.1-i486-4.txz Slackware x86_64 -current package: 69e300421110474e99fcce4d6dcbe6a3 a/slocate-3.1-x86_64-4.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg slocate-3.1-i486-4_slack13.37.txz +-----+ . Recent updates to slocate packages for Slackware address a critical information disclosure vulnerability. Please upgrade to maintain your system's security.. slocate packages, Slackware update, security patches. . Severity: Important. LinuxSecurity.com Team
Michel Kaempf reported a security problem in slocate on bugtraqwhich was originally discovered by zorgon.. - ------------------------------------------------------------------------ Debian Security Advisory DSA-005-1
Get the latest Linux and open source security news straight to your inbox.