LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 03-10-2022, 10:15 PM   #16
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,362

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075

Quote:
Originally Posted by Tonus View Post
Not so sure. Average users depend on Pat's reactivity and for more advanced or concerned users, there're mailing lists and so on...
This is not necessarily only for users, advanced or not
The main goal, here, is to post what people found elsewhere (nist.gov, gentoo, arch, ...) and give visibility for everyone, Mr. Volkerding icluded

This may or may not be useful, but it has the merit to exist.

If you look at the changelog, there are many patches that have been applied thanks to user reports.

Last edited by marav; 03-10-2022 at 10:23 PM.
 
Old 03-11-2022, 07:30 AM   #17
Tonus
Senior Member
 
Registered: Jan 2007
Location: Paris, France
Distribution: Slackware-15.0
Posts: 1,405
Blog Entries: 3

Rep: Reputation: 514Reputation: 514Reputation: 514Reputation: 514Reputation: 514Reputation: 514
Yes indeed. I just believe our BDFL does not rely on sticky posts and subscribe to the most relevent threads.
I like the less for the number of sticky posts and subscribe to (too) much more threads.
 
2 members found this post helpful.
Old 03-11-2022, 08:21 AM   #18
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,362

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
Quote:
Originally Posted by Tonus View Post
Yes indeed. I just believe our BDFL does not rely on sticky posts and subscribe to the most relevent threads.
I like the less for the number of sticky posts and subscribe to (too) much more threads.
5 sticky threads is not that much (if we remove, in my POV, the useless one ...)
 
1 members found this post helpful.
Old 03-25-2022, 05:31 AM   #19
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,362

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
zlib 1.2.11

zlib 1.2.11 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

CVE:
https://nvd.nist.gov/vuln/detail/CVE-2018-25032

Patch:
https://github.com/madler/zlib/commi...7c615f8020c531
 
2 members found this post helpful.
Old 03-25-2022, 05:39 PM   #20
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,362

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
For Slackware 15.0

CVE:
https://nvd.nist.gov/vuln/detail/CVE-2022-0995

https://git.kernel.org/pub/scm/linux...9921b3cba63fbb

Fixed for kernel >= 5.15.29

https://git.kernel.org/pub/scm/linux...h=linux-5.15.y

Last edited by marav; 03-25-2022 at 05:40 PM.
 
Old 03-28-2022, 07:50 PM   #21
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,362

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
libarchive 3.6.0

CVE:
https://nvd.nist.gov/vuln/detail/CVE-2022-26280

Patch:
https://github.com/libarchive/libarc...8f94fce37d6aff
 
1 members found this post helpful.
Old 03-30-2022, 08:27 AM   #22
FTIO
Member
 
Registered: Mar 2015
Location: Las Vegas, NV
Distribution: Slackware 15.0 x64, Slackware Live 15.0 x64
Posts: 618

Rep: Reputation: 361Reputation: 361Reputation: 361Reputation: 361
Quote:
Originally Posted by Tonus View Post
Not so sure. Average users depend on Pat's reactivity and for more advanced or concerned users, there're mailing lists and so on...
This. It seems easier to simply keep getting the 'upgrade' notices via e-mails that also already have the download link for the file.
 
Old 03-30-2022, 09:24 AM   #23
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,362

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
Vim 8.2.x

Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646

CVE-2022-1154:
https://nvd.nist.gov/vuln/detail/CVE-2022-1154

EDIT:
+
heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.
CVE-2022-1160:
https://nvd.nist.gov/vuln/detail/CVE-2022-1160


Update:
Latest version 8.2.46494650

Last edited by marav; 03-30-2022 at 04:35 PM.
 
2 members found this post helpful.
Old 03-30-2022, 09:47 AM   #24
ceed
Member
 
Registered: Jul 2014
Distribution: Slackware_x64 15
Posts: 68

Rep: Reputation: Disabled
Well it certainly seems that someone is finding this thread useful:

Code:
patches/packages/zlib-1.2.12-x86_64-1_slack15.0.txz:  Upgraded.
  This update fixes memory corruption when deflating (i.e., when compressing)
  if the input has many distant matches. Thanks to marav.
  For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-25032
  (* Security fix *)
As previously stated by the OP, the thread is not expressly for the benefit of end-users; but rather, a place slackers can report vulnerabilities spotted in the wild.

I think it's a valuable thread and agree that it ought to be pinned. Thanks to you marav.
 
4 members found this post helpful.
Old 03-30-2022, 03:39 PM   #25
Tonus
Senior Member
 
Registered: Jan 2007
Location: Paris, France
Distribution: Slackware-15.0
Posts: 1,405
Blog Entries: 3

Rep: Reputation: 514Reputation: 514Reputation: 514Reputation: 514Reputation: 514Reputation: 514
It's indeed a very valuable thread ! Do not misread me : I do not think it's useful to have it sticky. I believe our BDFL will/have subscribe/d.
 
1 members found this post helpful.
Old 04-03-2022, 05:55 AM   #26
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,362

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
libtiff 4.3.0

Code:
A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the 
TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched 
remotely but requires user interaction. 
The exploit has been disclosed to the public and may be used.
CVE:
https://nvd.nist.gov/vuln/detail/CVE-2022-1210

No patch yet
 
2 members found this post helpful.
Old 04-07-2022, 07:02 PM   #27
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,362

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
xz 5.2.5

xzgrep: Fix escaping of malicious filenames (ZDI-CAN-16587).
Code:
Malicious filenames can make xzgrep to write to arbitrary files
or (with a GNU sed extension) lead to arbitrary code execution.

xzgrep from XZ Utils versions up to and including 5.2.5 are
affected. 5.3.1alpha and 5.3.2alpha are affected as well.
This patch works for all of them.

This bug was inherited from gzip's zgrep. gzip 1.12 includes
a fix for zgrep.
Patch:
https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch

Last edited by marav; 04-08-2022 at 10:53 AM. Reason: patch url
 
Old 04-12-2022, 07:25 PM   #28
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,362

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
libimobiledevice-glue

Fix a memory leak
https://github.com/libimobiledevice/...e-glue/pull/21

Commit:
https://github.com/libimobiledevice/...6298a5d689c4fa
 
1 members found this post helpful.
Old 04-12-2022, 08:10 PM   #29
Daedra
Senior Member
 
Registered: Dec 2005
Location: Springfield, MO
Distribution: Slackware64-15.0
Posts: 2,683

Rep: Reputation: 1375Reputation: 1375Reputation: 1375Reputation: 1375Reputation: 1375Reputation: 1375Reputation: 1375Reputation: 1375Reputation: 1375Reputation: 1375
Git 2.35.2

https://www.phoronix.com/scan.php?pa...CVE-2022-24765

Technically this doesn't really affect non-windows systems, but worth mentioning.

Last edited by Daedra; 04-12-2022 at 08:11 PM.
 
Old 04-13-2022, 05:12 AM   #30
semiprime
Member
 
Registered: Apr 2019
Location: UK
Distribution: Slackware
Posts: 51

Rep: Reputation: 59
Quote:
Originally Posted by Daedra View Post

Git 2.35.2

https://www.phoronix.com/scan.php?pa...CVE-2022-24765

Technically this doesn't really affect non-windows systems, but worth mentioning.
According to https://lwn.net/Articles/891112/ and https://github.blog/2022-04-12-git-s...ity-announced/ the vulnerability affects multi-user systems, including Linux.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Draft data loss mitigation method for spanned LVM (would like suggestions) ACiD GRiM Linux - General 1 10-18-2009 03:17 AM
LXer: This week at LWN: Interrupt mitigation in the block layer LXer Syndicated Linux News 0 08-25-2009 12:20 PM
Stateful Firewall/IDS/Filter/DDoS Mitigation - What Would You Advise? Xolo Linux - Security 17 07-27-2006 11:21 PM
Phục hồi dữ liệu bị mất???, cứ pollsite General 1 06-27-2005 12:39 PM
Gotta love those ٱٱٱٱٱٱٱ&# iLLuSionZ Linux - General 5 11-18-2003 07:14 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 05:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration