slacknews.org Всичко за Slackware

13фев/090

Slackware news : 13 Февруари 2009

Днес беше пусната поправка за kdelibs-4.2.0-i486-3.tgz. Поправен е бъг в ktorrent.

Possibly Related Posts:


12фев/090

Slackware news : 9 Февруари 2009

Днес бяха ъпдейтнати няколко пакета. Най-същественото е ъпдейта на wicd. Повече информация от ChangLog-a :

ap/cdrtools-2.01.01a57-i486-1.tgz: Upgraded to cdrtools-2.01.01a57.
Also, fixed a build script error so that the utilities look for locale files
in the correct directory. Thanks to Krasimir Kazakov for the bug report.
Anyone who had problems with k3b previously should upgrade this package.
extra/wicd/wicd-1.5.9-noarch-1.tgz: Upgraded to wicd-1.5.9.
This fixes a security problem with the D-Bus configuration file that allows
local users to intercept D-Bus messages, possibly including wireless network
credentials.
For more information, see:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0489

(* Security fix *)
testing/packages/kde4/deps/eigen2-r922425-i486-1.tgz:
Upgraded to eigen2-r922425.
testing/packages/kde4/kde/kdelibs-4.2.0-i486-2.tgz: Added bugfix patches from
SVN: r917170, r918403, r918654, r918838.
testing/packages/kde4/kde/kdevelop-3.9.91-i486-1.tgz:
Upgraded to kdevelop-3.9.91.
testing/packages/kde4/kde/kdevplatform-0.9.91-i486-1.tgz:
Upgraded to kdevplatform-0.9.91.
testing/packages/kde4/kde/koffice-1.9.98.6-i486-1.tgz:
Upgraded to koffice-1.9.98.6.
testing/packages/kde4/kde-l10n/koffice-l10n-*-1.9.98.6-noarch-1.tgz:
Upgraded to koffice-1.9.98.6 l10n packages.

Possibly Related Posts:


7фев/090

Slackware news: 5 Февруари 2009

Ъпгрейднати са ghostscript и mozilla-firefox до версии съответно 8.64 и 3.0.6. С ъпгрейда към Firefox 3.0.6 се коригират някой дупки в сигурността. Повече информация за тях можете да намерите тук.

Possibly Related Posts:


7фев/090

Slackware News: 2 Февруари 2009

Ъпдеитнати са  xdg-utils. Ето извадка от Changelog-a :

This update fixes two security issues.  First, use of xdg-open in
/etc/mailcap was found to be unsafe -- xdg-open passes along downloaded files
without indicating what mime type they initially presented themselves as,
leaving programs further down the processing chain to discover the file type
again.  This makes it rather trivial to present a script (such as a .desktop
file) as a document type (like a PDF) so that it looks safe to click on in a
browser, but will result in the execution of an arbitrary script.  It might
be safe to send files to trusted applications in /etc/mailcap, but it does
not seem to be safe to send files to xdg-open in /etc/mailcap.
This package will comment out calls to xdg-open in /etc/mailcap if they are
determined to have been added by a previous version of this package.
If you've made any local customizations to /etc/mailcap, be sure to check
that there are no uncommented calls to xdg-open after installing this update.
Thanks to Manuel Reimer for discovering this issue.
Another bug in xdg-open fails to sanitize input properly allowing the
execution of arbitrary commands.  This was fixed in the xdg-utils repository
quite some time ago (prior to the inclusion of xdg-utils in Slackware), but
was never fixed in the official release of xdg-utils.  The sources for
xdg-utils in Slackware have now been updated from the repo to fix the problem.

За повече информация по темата може да намерите тук и тук.

Possibly Related Posts:


4фев/090

Slackware News : 27 Януари 2009

Днес беше обявено добавянето на KDE 4.2.0 в Slackware 12.2. Пълен списък с промените от Changelog-a :

testing/packages/kde4/deps/automoc4-0.9.88-i486-1.tgz:
  Upgraded to automoc4-0.9.88.
testing/packages/kde4/deps/clucene-0.9.21b-i486-1.tgz:
  Upgraded to clucene-0.9.21b.
testing/packages/kde4/extragear/guidance-power-manager-4.2.0-i486-1.tgz:
  Upgraded to guidance-power-manager-4.2.0.
testing/packages/kde4/extragear/konq-plugins-4.2.0-i486-1.tgz:
  Upgraded to konq-plugins-4.2.0.
testing/packages/kde4/extragear/skanlite-0.2_kde4.2.0-i486-1.tgz:
  Upgraded to skanlite-0.2_kde4.2.0.
testing/packages/kde4/kde/kdeaccessibility-4.2.0-i486-1.tgz:
  Upgraded to kdeaccessibility-4.2.0.
testing/packages/kde4/kde/kdeadmin-4.2.0-i486-1.tgz:
  Upgraded to kdeadmin-4.2.0.
testing/packages/kde4/kde/kdeartwork-4.2.0-i486-1.tgz:
  Upgraded to kdeartwork-4.2.0.
testing/packages/kde4/kde/kdebase-4.2.0-i486-1.tgz:
  Upgraded to kdebase-4.2.0.
testing/packages/kde4/kde/kdebase-runtime-4.2.0-i486-1.tgz:
  Upgraded to kdebase-runtime-4.2.0.
testing/packages/kde4/kde/kdebase-workspace-4.2.0-i486-1.tgz:
  Upgraded to kdebase-workspace-4.2.0.
testing/packages/kde4/kde/kdebindings-4.2.0-i486-1.tgz:
  Upgraded to kdebindings-4.2.0.
testing/packages/kde4/kde/kdeedu-4.2.0-i486-1.tgz:
  Upgraded to kdeedu-4.2.0.
testing/packages/kde4/kde/kdegames-4.2.0-i486-1.tgz:
  Upgraded to kdegames-4.2.0.
testing/packages/kde4/kde/kdegraphics-4.2.0-i486-1.tgz:
  Upgraded to kdegraphics-4.2.0.
testing/packages/kde4/kde/kdelibs-4.2.0-i486-1.tgz:
  Upgraded to kdelibs-4.2.0.
testing/packages/kde4/kde/kdemultimedia-4.2.0-i486-1.tgz:
  Upgraded to kdemultimedia-4.2.0.
testing/packages/kde4/kde/kdenetwork-4.2.0-i486-2.tgz:
  Upgraded to kdenetwork-4.2.0.
testing/packages/kde4/kde/kdepim-4.2.0-i486-1.tgz:
  Upgraded to kdepim-4.2.0.
testing/packages/kde4/kde/kdepimlibs-4.2.0-i486-1.tgz:
  Upgraded to kdepimlibs-4.2.0.
testing/packages/kde4/kde/kdeplasma-addons-4.2.0-i486-1.tgz:
  Upgraded to kdeplasma-addons-4.2.0.
testing/packages/kde4/kde/kdesdk-4.2.0-i486-1.tgz:
  Upgraded to kdesdk-4.2.0.
testing/packages/kde4/kde/kdetoys-4.2.0-i486-1.tgz:
  Upgraded to kdetoys-4.2.0.
testing/packages/kde4/kde/kdeutils-4.2.0-i486-1.tgz:
  Upgraded to kdeutils-4.2.0.
testing/packages/kde4/kde/kdewebdev-4.2.0-i486-1.tgz:
  Upgraded to kdewebdev-4.2.0.
testing/packages/kde4/kde-l10n/kde-l10n-*-4.2.0-noarch-1.tgz:
  Upgraded to KDE 4.2.0 l10n packages.

Possibly Related Posts: