LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 02-14-2022, 03:50 PM   #211
saxa
Senior Member
 
Registered: Aug 2004
Location: Nova Gorica, Salvador
Distribution: Slackware
Posts: 1,215

Rep: Reputation: 298Reputation: 298Reputation: 298

vala-0.54.7
https://download.gnome.org/sources/v...-0.54.7.tar.xz
 
Old 02-14-2022, 11:47 PM   #212
gmgf
Senior Member
 
Registered: Jun 2012
Location: Bergerac, France
Distribution: Slackware
Posts: 2,227

Rep: Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015
For info util-linux-2.37.4:

util-linux 2.37.4 Release Notes


This release fixes security issue in chsh(1) and chfn(8):

CVE-2022-0563

The readline library uses INPUTRC= environment variable to get a path
to the library config file. When the library cannot parse the
specified file, it prints an error message containing data from the
file.

Unfortunately, the library does not use secure_getenv() (or a similar
concept), or sanitize the config file path to avoid vulnerabilities that
could occur if set-user-ID or set-group-ID programs.
 
Old 02-15-2022, 01:16 AM   #213
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,393

Rep: Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117
Quote:
Originally Posted by gmgf View Post
For info util-linux-2.37.4:

util-linux 2.37.4 Release Notes


This release fixes security issue in chsh(1) and chfn(8):

CVE-2022-0563

The readline library uses INPUTRC= environment variable to get a path
to the library config file. When the library cannot parse the
specified file, it prints an error message containing data from the
file.

Unfortunately, the library does not use secure_getenv() (or a similar
concept), or sanitize the config file path to avoid vulnerabilities that
could occur if set-user-ID or set-group-ID programs.
Code:
Tue Feb 15 02:14:30 UTC 2022
a/util-linux-2.37.4-x86_64-1.txz:  Upgraded.
 
Old 02-15-2022, 01:32 AM   #214
gmgf
Senior Member
 
Registered: Jun 2012
Location: Bergerac, France
Distribution: Slackware
Posts: 2,227

Rep: Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015
I said, for info CVE-2022-0563
 
1 members found this post helpful.
Old 02-15-2022, 01:38 AM   #215
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,393

Rep: Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117
Quote:
Originally Posted by gmgf View Post
I said, for info CVE-2022-0563
Ah ok, a reply before the coffee will always be a reply before the coffee

However, I also gave mine:
Quote:
Originally Posted by marav View Post
without more success:
Code:
Mon Feb 14 00:10:38 UTC 2022
ap/zsh-5.8.1-x86_64-1.txz:  Upgraded.


PS: Don't try to put the mess in the changelog "le nouvel-aquitain" ;-)

Last edited by marav; 02-15-2022 at 01:43 AM.
 
Old 02-15-2022, 02:01 AM   #216
gmgf
Senior Member
 
Registered: Jun 2012
Location: Bergerac, France
Distribution: Slackware
Posts: 2,227

Rep: Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015
Quote:
Originally Posted by marav View Post
Ah ok, a reply before the coffee will always be a reply before the coffee

However, I also gave mine:

without more success:
Code:
Mon Feb 14 00:10:38 UTC 2022
ap/zsh-5.8.1-x86_64-1.txz:  Upgraded.


PS: Don't try to put the mess in the changelog "le nouvel-aquitain" ;-)
The Parisian gets up late
 
1 members found this post helpful.
Old 02-15-2022, 02:24 AM   #217
gmgf
Senior Member
 
Registered: Jun 2012
Location: Bergerac, France
Distribution: Slackware
Posts: 2,227

Rep: Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015
xf86-input-wacom-1.0.0:

https://github.com/linuxwacom/xf86-input-wacom/releases
 
Old 02-15-2022, 07:46 AM   #218
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,393

Rep: Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117
Plasma 5.24.1

Announcement:
https://kde.org/announcements/plasma/5/5.24.1/

Full changelog:
https://kde.org/announcements/change...5.24.0-5.24.1/

Last edited by marav; 02-15-2022 at 07:47 AM.
 
2 members found this post helpful.
Old 02-15-2022, 12:46 PM   #219
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,393

Rep: Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117
gFTP 2.9.1b

Code:
Bugfix release to address pressing issues

    Fixed a critical segfault that may happen all the time!

FTP:

    fixed regressions
    fixed compatiblity with some broken servers
    detected but missing server features are disabled if error code = 500
 
Old 02-15-2022, 07:02 PM   #220
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,393

Rep: Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117
Thunderbird 91.6.1

Release notes
https://www.thunderbird.net/en-US/th.../releasenotes/

CVE-2022-0566:
Crafted email could trigger an out-of-bounds write
 
1 members found this post helpful.
Old 02-16-2022, 03:30 AM   #221
nullptr
Member
 
Registered: Nov 2019
Posts: 50

Rep: Reputation: Disabled
firewalld
 
2 members found this post helpful.
Old 02-16-2022, 12:56 PM   #222
gmgf
Senior Member
 
Registered: Jun 2012
Location: Bergerac, France
Distribution: Slackware
Posts: 2,227

Rep: Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015
xwayland-22.1.0:

https://cgit.freedesktop.org/xorg/xs...=xwayland-22.1

ftp://ftp.x.org/pub/individual/xserv...-22.1.0.tar.xz
 
1 members found this post helpful.
Old 02-16-2022, 01:36 PM   #223
gmgf
Senior Member
 
Registered: Jun 2012
Location: Bergerac, France
Distribution: Slackware
Posts: 2,227

Rep: Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015
kcron-21.12.2:

CVE-2022-24986

two patches fix this:

https://invent.kde.org/system/kcron/...2c04c9f6.patch
https://invent.kde.org/system/kcron/...ef4266e3.patch
 
Old 02-16-2022, 05:42 PM   #224
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,393

Rep: Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117Reputation: 4117
Firefox 97.0.1

Announcement (when available):
https://www.mozilla.org/en-US/firefo.../releasenotes/

https://ftp.mozilla.org/pub/firefox/....source.tar.xz
 
Old 02-17-2022, 02:11 AM   #225
Thom1b
Member
 
Registered: Mar 2010
Location: France
Distribution: Slackware
Posts: 485

Rep: Reputation: 339Reputation: 339Reputation: 339Reputation: 339
Wink

Quote:
Originally Posted by Didier Spaier View Post
I concur. I have installed the kernel packages 5.16.9 (with modules compressed with zstd) and here goes:
Code:
308M    /lib/modules/5.16.7
87M    /lib/modules/5.16.9
For what it's worth I attach a diff of the config files (which includes a few other modifications some probably due to having built with an older gcc version than in Slackware64-15.0).
I also tried to compile linux with zst compression, it works fine. Thanks Didier
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Apache 2.4 requests to non-SSL site with "Upgrade-Insecure-Requests: 1" and no trailing / get redirected to default site owendelong Linux - Server 2 06-22-2021 02:08 PM
[SOLVED] Requests for -current (20151216) rworkman Slackware 3441 12-28-2017 03:50 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 06:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration