Updated udev packages are available for Slackware 12.2, and -current to fix a serial device ownership regression in 12.2, adjust the perms on /dev/rtc0, and make sure that the /dev/root symlink is properly created. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] udev reissued for 12.2/current (SSA:2009-111-02) Updated udev packages are available for Slackware 12.2, and -current to fix a serial device ownership regression in 12.2, adjust the perms on /dev/rtc0, and make sure that the /dev/root symlink is properly created. Here are the details from the Slackware 12.2 ChangeLog: +--------------------------+ patches/packages/udev-141-i486-2_slack12.2.tgz: Fixed a regression with serial/dialout device ownership. Slackware 12.2 uses the 'uucp' group for these devices, but the newer version of udev has changed them to 'dialout', leading to log errors and an incorrect group ownership for serial devices since the 'dialout' group does not exist on Slackware 12.2. This update changes the serial device group ownership back to 'uucp'. Thanks to Alexander Pravdin for the fast bug report. Changed the permissions on the real time clock (/dev/rtc0) so that all users can read it. Modified rc.udev so that the /dev/root symlink is created. Thanks to Piter Punk! +--------------------------+ Here are the details from the Slackware -current ChangeLog: +--------------------------+ a/udev-141-i486-2.tgz: Changed the permissions on the real time clock (/dev/rtc0) so that all users can read it. Modified rc.udev so that the /dev/root symlink is created. Thanks to Piter Punk! +--------------------------+ Where to find the new packages: +-----------------------------+ HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com. Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donatingadditional FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 12.2: ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/udev-141-i486-2_slack12.2.tgz Updated package for Slackware -current: MD5 signatures: +-------------+ Slackware 12.2 package: fdbf627e259420d39313888873f9dcf8 udev-141-i486-2_slack12.2.tgz Slackware -current package: cd8596667b978e1ec6e221f48c3cb224 udev-141-i486-2.tgz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg udev-141-i486-2_slack12.2.tgz Restart udev: # /etc/rc.d/rc.udev restart +-----+ . Fortify your Slackware 12.2 platform by implementing udev patches that rectify concerns related to device ownership and permission settings.. Slackware Updates, Udev Fixes, Device Ownership, Linux Permissions. . Severity: Important. LinuxSecurity.com Team
New udev packages are available for Slackware 10.2, 11.0, 12.0, 12.1, 12.2, and -current to fix security issues. The udev packages in Slackware 10.2, 11.0, 12.0, 12.1, 12.2, and -current contained a local root hole vulnerability: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] udev (SSA:2009-111-01) New udev packages are available for Slackware 10.2, 11.0, 12.0, 12.1, 12.2, and -current to fix security issues. The udev packages in Slackware 10.2, 11.0, 12.0, 12.1, 12.2, and -current contained a local root hole vulnerability: https://www.cve.org/CVERecord?id=CVE-2009-1185 The udev packages in Slackware 12.0, 12.1, 12.2, and -current had an integer overflow which could result in a denial of service: https://www.cve.org/CVERecord?id=CVE-2009-1186 Note that udev is only used with 2.6 kernels, which are not used by default with Slackware 10.2 and 11.0. Here are the details from the Slackware 12.2 ChangeLog: +--------------------------+ patches/packages/udev-141-i486-1_slack12.2.tgz: Upgraded to udev-141. This upgrade fixes a local root hole and a denial of service issue. For more information, see: https://www.cve.org/CVERecord?id=CVE-2009-1185 https://www.cve.org/CVERecord?id=CVE-2009-1186 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com. Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 10.2: ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/udev-064-i486-4_slack10.2.tgz Updated package for Slackware11.0: ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/udev-097-i486-11_slack11.0.tgz Updated package for Slackware 12.0: ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/udev-111-i486-6_slack12.0.tgz Updated package for Slackware 12.1: ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/udev-118-i486-4_slack12.1.tgz Updated package for Slackware 12.2: Updated package for Slackware -current: MD5 signatures: +-------------+ Slackware 10.2 package: 4bfa5de16024b6d5ddfe19aea0794bef udev-064-i486-4_slack10.2.tgz Slackware 11.0 package: 024033959fd5586079de2daacec96eb1 udev-097-i486-11_slack11.0.tgz Slackware 12.0 package: da24ba5c832c38d96ea87fbd4997e20b udev-111-i486-6_slack12.0.tgz Slackware 12.1 package: 7068aab244ff3df7775ba1bc6b75b409 udev-118-i486-4_slack12.1.tgz Slackware 12.2 package: 7be35f9ebfce6c1512f083d57c913ea1 udev-141-i486-1_slack12.2.tgz Slackware -current package: 53b946e0313fda94686e4bde19271072 udev-141-i486-1.tgz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg udev-141-i486-1_slack12.2.tgz Then, restart udev: # sh /etc/rc.d/rc.udev restart +-----+ . Updated udev components for Slackware resolve local privilege escalation vulnerabilities and denial of service concerns, with comprehensive installation guidelines provided.. Slackware Security,Udev Update,Root Hole Fix,Package Upgrade. . Severity: Critical. LinuxSecurity.com Team
fixed a case where reading /proc/ide/hd?/media returns EIO (bug rh#142713) and added simple dvb rules. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2004-552 2004-12-16 ---------------------------------------------------------------------Product : Fedora Core 3 Name : udev Version : 039 Release : 10.FC3.6 Summary : A userspace implementation of devfs Description : udev is a implementation of devfs in userspace using sysfs and /sbin/hotplug. It requires a 2.6 kernel to run properly. ---------------------------------------------------------------------* Tue Dec 14 2004 Harald Hoyer - 039-10.FC3.6 - fixed a case where reading /proc/ide/hd?/media returns EIO (bug rh#142713) - added simple dvb rules ---------------------------------------------------------------------This update can be downloaded from: ffd7251f16de538f00ce0f796930775f SRPMS/udev-039-10.FC3.6.src.rpm 25a19bc8ed1b352b887e9cdf9d829407 x86_64/udev-039-10.FC3.6.x86_64.rpm b8e32ebfd894fee14d4764195473efd4 x86_64/debug/udev-debuginfo-039-10.FC3.6.x86_64.rpm 8ff13d9e61dd88ffcbe42e4ea3ccc9cb i386/udev-039-10.FC3.6.i386.rpm b46ab5dfae14993d67dd71be872a1aab i386/debug/udev-debuginfo-039-10.FC3.6.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
fixed udev.rules for cdrom symlinks (bug 141897). ---------------------------------------------------------------------Fedora Update Notification FEDORA-2004-513 2004-12-07 ---------------------------------------------------------------------Product : Fedora Core 3 Name : udev Version : 039 Release : 10.FC3.5 Summary : A userspace implementation of devfs Description : udev is a implementation of devfs in userspace using sysfs and /sbin/hotplug. It requires a 2.6 kernel to run properly. ---------------------------------------------------------------------* Mon Dec 06 2004 Harald Hoyer - 039-10.FC3.5 - fixed udev.rules for cdrom symlinks (bug 141897) ---------------------------------------------------------------------This update can be downloaded from: bbf534baf0273b717536b6880b2cc2cf SRPMS/udev-039-10.FC3.5.src.rpm 6cf968ff52188196cb9a13877b61a33e x86_64/udev-039-10.FC3.5.x86_64.rpm 85b23295d13d0d1c2e3d052c0ac00628 x86_64/debug/udev-debuginfo-039-10.FC3.5.x86_64.rpm 1a3c34c2a192c01b22929dd91134ebe4 i386/udev-039-10.FC3.5.i386.rpm 0f546e0ae35b9d5341f8300e9e121a8c i386/debug/udev-debuginfo-039-10.FC3.5.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.