LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 08-29-2022, 02:35 PM   #76
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,361

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075

libtiff

CVE-2022-2953
Code:
LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, 
allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile 
libtiff from sources, the fix is available with commit 48d6ece8.
https://nvd.nist.gov/vuln/detail/CVE-2022-2953
 
1 members found this post helpful.
Old 08-29-2022, 03:42 PM   #77
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,361

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
poppler 22.08

JBIG2Stream_Fix_crash_on_broken_file
Cf. https://nvd.nist.gov/vuln/detail/CVE-2022-38171

Patch:
https://gitlab.freedesktop.org/poppl...354e9d96.patch
 
1 members found this post helpful.
Old 08-31-2022, 08:17 AM   #78
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,361

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
glibc 2.36

CVE-2022-39046
Code:
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed 
a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and 
prints it to the target log file, potentially revealing a portion of the contents of the heap.
https://nvd.nist.gov/vuln/detail/CVE-2022-39046
 
2 members found this post helpful.
Old 09-01-2022, 01:25 AM   #79
nobodino
Senior Member
 
Registered: Jul 2010
Location: Near Bordeaux in France
Distribution: slackware, slackware from scratch, LFS, slackware [arm], linux Mint...
Posts: 1,564

Rep: Reputation: 892Reputation: 892Reputation: 892Reputation: 892Reputation: 892Reputation: 892Reputation: 892
Binutils

CVE-2022-38533 received a patch, follow link:

https://sourceware.org/git/?p=binuti...5c6b87dcef08cd
 
1 members found this post helpful.
Old 09-01-2022, 09:23 PM   #80
regdub
Member
 
Registered: Apr 2008
Location: France
Distribution: Slackware
Posts: 101

Rep: Reputation: 33
Since "91.13.0 is the final release of Thunderbird 91", I would expect mozilla-thunderbird-102.2.1 landing in 15.0.

https://www.thunderbird.net/en-US/th.../releasenotes/
 
Old 09-02-2022, 07:28 PM   #81
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,361

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
libvncclient

CVE-2020-29260
Code:
libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().
https://nvd.nist.gov/vuln/detail/CVE-2020-29260

[PATCH] libvncclient: free vncRec memory in rfbClientCleanup()
https://github.com/LibVNC/libvncserv...fbd757ec.patch
 
1 members found this post helpful.
Old 09-03-2022, 04:10 PM   #82
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,361

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
Vim

CVE-2022-3099
Code:
Use After Free in GitHub repository vim/vim prior to 9.0.0359
https://nvd.nist.gov/vuln/detail/CVE-2022-3099
 
Old 09-06-2022, 04:14 PM   #83
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,361

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
Quote:
Originally Posted by regdub View Post
Since "91.13.0 is the final release of Thunderbird 91", I would expect mozilla-thunderbird-102.2.1 landing in 15.0.

https://www.thunderbird.net/en-US/th.../releasenotes/
Done
Code:
Tue Sep  6 20:21:24 UTC 2022
...
patches/packages/mozilla-thunderbird-102.2.1-x86_64-1_slack15.0.txz:  Upgraded.
...
http://ftp.slackware.com/pub/slackwa.../ChangeLog.txt
 
1 members found this post helpful.
Old 09-06-2022, 10:47 PM   #84
regdub
Member
 
Registered: Apr 2008
Location: France
Distribution: Slackware
Posts: 101

Rep: Reputation: 33
Quote:
Originally Posted by marav View Post
Done
Code:
Tue Sep  6 20:21:24 UTC 2022
...
patches/packages/mozilla-thunderbird-102.2.1-x86_64-1_slack15.0.txz:  Upgraded.
...
http://ftp.slackware.com/pub/slackwa.../ChangeLog.txt
Nice.

And we get firefox 102esr with a little advance.
 
Old 09-07-2022, 10:06 AM   #85
Thom1b
Member
 
Registered: Mar 2010
Location: France
Distribution: Slackware
Posts: 484

Rep: Reputation: 337Reputation: 337Reputation: 337Reputation: 337
python3-3.9.14 is released with security fix.

Quote:
CVE-2020-10735

Converting between int and str in bases other than 2 (binary), 4, 8 (octal), 16 (hexadecimal), or 32 such as base 10 (decimal) now raises a ValueError if the number of digits in string form is above a limit to avoid potential denial of service attacks due to the algorithmic complexity.

Security releases for 3.9.14, 3.8.14, and 3.7.14 are made available simultaneously to address this issue, along with some less urgent security content.

Upgrading your installations is highly recommended.
 
1 members found this post helpful.
Old 09-08-2022, 12:00 PM   #86
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,361

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
Vim

CVE-2022-3153
Code:
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0404.
https://nvd.nist.gov/vuln/detail/CVE-2022-3153
 
Old 09-09-2022, 05:16 AM   #87
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,361

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
plasma-workspace

Code:
it appears that Plasma 5.25.5 has introduced a regression:
https://bugs.kde.org/show_bug.cgi?id=458829

A fix for it has been in master for a while, but was never put in stable
because it appeared to not affect stable.

Since there are no scheduled bugfixes releases for Plasma 5.25 anymore
(and the discussion about unscheduled ones is still ongoing) please
apply
https://mail.kde.org/pipermail/distr...er/001287.html

Patch:
https://invent.kde.org/plasma/plasma...c39e1acf967454
 
Old 09-14-2022, 04:09 AM   #88
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,361

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
plasma-integration

Code:
For more details, check QTBUG-95817. But to summarize it in a couple of
words: a window will stop pushing buffers when it's resized and using
threaded render loop.
[PATCH] Bring back workaround for threaded render loop not working on NVIDIA Wayland
https://invent.kde.org/plasma/plasma...52bd3c9c.patch
 
Old 09-14-2022, 08:05 AM   #89
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,361

Original Poster
Rep: Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075Reputation: 4075
plasma-workspace

Delay ksplash until after env is set up
Code:
otherwise we can dbus invoke with the wrong environment. specifically
this happens with the latest qtbase changes that introduced color
picking support on wayland. when we start a qguiapplication with
incomplete environment that dbus invokes the xdg-portal system and that
in turn has an incomplete environment resulting in theming and the likes
not properly applying because the portal doesn't know that it runs
inside a plasma session.

qt/qt/qtbase@2dc083df

BUG: 458865
Patch:
https://invent.kde.org/plasma/plasma...af6de91e.patch
 
1 members found this post helpful.
Old 09-14-2022, 01:19 PM   #90
volkerdi
Slackware Maintainer
 
Registered: Dec 2002
Location: Minnesota
Distribution: Slackware! :-)
Posts: 2,504

Rep: Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461
Quote:
Originally Posted by marav View Post
plasma-workspace

Delay ksplash until after env is set up
Code:
otherwise we can dbus invoke with the wrong environment. specifically
this happens with the latest qtbase changes that introduced color
picking support on wayland. when we start a qguiapplication with
incomplete environment that dbus invokes the xdg-portal system and that
in turn has an incomplete environment resulting in theming and the likes
not properly applying because the portal doesn't know that it runs
inside a plasma session.

qt/qt/qtbase@2dc083df

BUG: 458865
Patch:
https://invent.kde.org/plasma/plasma...af6de91e.patch
This one looks to be already applied.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Draft data loss mitigation method for spanned LVM (would like suggestions) ACiD GRiM Linux - General 1 10-18-2009 03:17 AM
LXer: This week at LWN: Interrupt mitigation in the block layer LXer Syndicated Linux News 0 08-25-2009 12:20 PM
Stateful Firewall/IDS/Filter/DDoS Mitigation - What Would You Advise? Xolo Linux - Security 17 07-27-2006 11:21 PM
Phục hồi dữ liệu bị mất???, cứ pollsite General 1 06-27-2005 12:39 PM
Gotta love those ٱٱٱٱٱٱٱ&# iLLuSionZ Linux - General 5 11-18-2003 07:14 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 10:33 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration