Slackware news: 4 Октомври 2009
октомври 4th, 2009
Има две важни промени днес PHP и Samba. Промените са направени едновременно в -Stable и в -Current. В -Current, обаче има и доста други промени като MySQL, Amarok, QT, Perl, както и GCC 4.4.1.
Това е последното от -Current changelog-а:
Sun Oct 4 00:17:50 CDT 2009 ap/mysql-5.1.39-i486-1.txz: Upgraded. This bumps the version of the shared libraries to .so.16.0.0. d/perl-5.10.1-i486-1.txz: Upgraded. Compiled against mysql-5.1.39, upgraded to perl-5.10.1, DBD-mysql-4.013, DBI-1.609, and URI-1.40. kde/amarok-2.2.0-i486-1.txz: Upgraded. l/qt-4.5_0bd8418-i486-1.txz: Upgraded. This is the KDE Qt 4.5.2-patched git branch, compiled against mysql-5.1.39. l/redland-1.0.9-i486-1.txz: Upgraded. Compiled against mysql-5.1.39. l/soprano-2.3.1-i486-1.txz: Upgraded. l/taglib-1.6-i486-1.txz: Upgraded. l/taglib-extras-1.0.1-i486-1.txz: Upgraded. n/openssh-5.3p1-i486-1.txz: Upgraded. n/php-5.2.11-i486-1.txz: Upgraded. This release fixes some possible security issues, all of which have "unknown impact and attack vectors".For more information, see: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3291 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3292 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3293 (* Security fix *) Also, thanks to Frank Gingras and Rich Bowen for helping to improve the syntax in mod_php.conf. n/samba-3.4.2-i486-1.txz: Upgraded. This update fixes the following security issues. A misconfigured /etc/passwd with no defined home directory could allow security restrictions to be bypassed. mount.cifs could allow a local user to read the first line of an arbitrary file if installed setuid. (On Slackware, it was not installed setuid) Specially crafted SMB requests could cause a denial of service. For more information, see: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2948 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906 (* Security fix *) testing/packages/gcc-4.4.1/gcc-4.4.1-i486-1.txz: Added. testing/packages/gcc-4.4.1/gcc-g++-4.4.1-i486-1.txz: Added. testing/packages/gcc-4.4.1/gcc-gfortran-4.4.1-i486-1.txz: Added. testing/packages/gcc-4.4.1/gcc-gnat-4.4.1-i486-1.txz: Added. testing/packages/gcc-4.4.1/gcc-java-4.4.1-i486-1.txz: Added. testing/packages/gcc-4.4.1/gcc-objc-4.4.1-i486-1.txz: Added.

Possibly Related Posts:
- GoblinX 3.0
- Facebook пуска свободен високопроизводителен сървър
- Linux 2.6.31
- Излезе KDE 4.3.0
- Slackware News: 17 Юни 2009
Filed under: Новини | No Comments »
KDE 4.2.4 CornRow
юни 4th, 2009
От KDE не спират да ни изненадват тези дни. Днес беше пуснато KDE 4.2.4. KDE 4.2.4 се препоръчва на всички, които са чакали до сега да пробват KDE 4.2.
За момента изглежда, че от KDE се опитват да концентрират всички усилия за следващата версия 4.3.0, която вече започва да се оформя, и е много верятно да няма KDE 4.2.5. Ако няма сериозни проблеми или дупки по сигурността, се очаква KDE 4.2.4 да е последната от KDE 4.2 сериите.
По-рано днес сорса е пуснат официално, което означава че скоро може да се очакват готови пакети.
Possibly Related Posts:
- Slackware news: 4 Октомври 2009
- GoblinX 3.0
- Facebook пуска свободен високопроизводителен сървър
- Linux 2.6.31
- Излезе KDE 4.3.0
Filed under: Новини | No Comments »
Slackware news: 21 Март 2009
март 21st, 2009
Днес беше обновено ядрото в -Current до 2.6.28.8 според последния -Current changelog. Освен това са обновени и някои други пакети като gcc и glibc, както и gimp. Ето го и сравнително малкия changelog:
Thu Mar 19 20:35:06 CDT 2009 a/glibc-solibs-2.9-i486-2.tgz: Recompiled against 2.6.28.8 headers. a/glibc-zoneinfo-2.9-noarch-2.tgz: Upgraded to tzdata2009c. a/kernel-firmware-2.6.28.8-noarch-1.tgz: Upgraded to Linux 2.6.28.8 firmware. a/kernel-generic-2.6.28.8-i486-1.tgz: Upgraded to Linux 2.6.28.8. a/kernel-generic-smp-2.6.28.8_smp-i686-1.tgz: Upgraded to Linux 2.6.28.8. a/kernel-huge-2.6.28.8-i486-1.tgz: Upgraded to Linux 2.6.28.8. a/kernel-huge-smp-2.6.28.8_smp-i686-1.tgz: Upgraded to Linux 2.6.28.8. a/kernel-modules-2.6.28.8-i486-1.tgz: Upgraded to Linux 2.6.28.8. a/kernel-modules-smp-2.6.28.8_smp-i686-1.tgz: Upgraded to Linux 2.6.28.8. ap/hplip-3.9.2-i486-2.tgz: Patched an issue that could cause high CPU utilization after switching to a different user. d/kernel-headers-2.6.28.8_smp-x86-1.tgz: Upgraded to Linux 2.6.28.8. k/kernel-source-2.6.28.8_smp-noarch-1.tgz: Upgraded to Linux 2.6.28.8. l/glibc-2.9-i486-2.tgz: Recompiled. l/glibc-i18n-2.9-i486-2.tgz: Rebuilt. l/glibc-profile-2.9-i486-2.tgz: Recompiled. l/lesstif-0.95.0-i486-3.tgz: Patched to compile with gcc-4.3.x. xap/gimp-2.6.6-i486-1.tgz: Upgraded to gimp-2.6.6. xap/gimp-help-2-0.8-noarch-1.tgz: Removed. This is out of date, the newer versions are very large, and using the online help (which is the built-in default) works fine. extra/grub/grub-0.97-i486-7.tgz: Patched to fix loading x86-64 Linux kernels. extra/linux-2.6.28.8-nosmp-sdk/: Updated SMP to no-SMP kernel source patch. isolinux/initrd.img: Rebuilt with newly compiled kernel modules. usb-and-pxe-installers/: Rebuilt usbboot.img with newly compiled kernel modules.
Possibly Related Posts:
- Slackware news: 4 Октомври 2009
- GoblinX 3.0
- Facebook пуска свободен високопроизводителен сървър
- Linux 2.6.31
- Излезе KDE 4.3.0
Filed under: Новини | No Comments »
Slackware news: 16 Март 2009
март 17th, 2009
Няколко дни след големия ъпдейт на – Current следва още един, само че този е по-малък. Changelog :
Mon Mar 16 00:11:40 CDT 2009 ChangeLog bugs in the last update: eigen was removed, not moved from /testing. This was intentional, as we are not aware of anything that has not moved to using eigen2 now. k3b was upgraded to k3b-r936571 in kde/, but does not seem to be stable. The installers were updated and now support ext4. a/cpio-2.9-i486-2.tgz: Patched for new gcc version. Thanks to Fred Emmott. ap/foomatic-filters-4.0_20090315-i486-1.tgz: Upgraded to foomatic-filters-4.0_20090315. Thanks to Beej Jorgensen for pointing out this version with many bugfixes. d/gcc-4.3.3-i486-2.tgz: Recompiled with --enable-libssp. Removing that was a regression as there are binaries out there that expect to link with libspp. If it causes any problems, let me know. d/gcc-g++-4.3.3-i486-2.tgz: Recompiled. d/gcc-gfortran-4.3.3-i486-2.tgz: Recompiled. d/gcc-gnat-4.3.3-i486-2.tgz: Recompiled. d/gcc-java-4.3.3-i486-2.tgz: Recompiled. d/gcc-objc-4.3.3-i486-2.tgz: Recompiled. kde/kdebase-workspace-4.2.1-i486-2.tgz: Recompiled against freetype-2.3.9, removed broken hicolor theme index. l/cairo-1.8.6-i486-2.tgz: Recompiled against freetype-2.3.9. l/freetype-2.3.9-i486-1.tgz: Upgraded to freetype-2.3.9. freetype-2.3.8 accidentally broke the ABI. Binaries linked with 2.3.8 that use the FT_Get_PS_Font_Info function will need to be recompiled. l/hicolor-icon-theme-0.10-noarch-5.tgz: Rebuilt. l/libcap-2.16-i486-1.tgz: Upgraded to libcap-2.16. l/libwnck-2.24.2-i486-1.tgz: Upgraded to libwnck-2.24.2. l/qt-r931082-i486-2.tgz: Recompiled against freetype-2.3.9. n/iwlwifi-4965-ucode-228.57.2.23-fw-1.tgz: Upgraded iwlwifi-4965-2.ucode firmware to version 228.57.2.23. x/compiz-0.7.8-i486-3.tgz: Recompiled against libwnck-2.24.2. xap/pidgin-2.5.5-i486-1.tgz: Upgraded to pidgin-2.5.5. xap/xfce-4.6.0-i486-2.tgz: Recompiled against libwnck-2.24.2. xap/xfce4-power-manager-0.6.4-i486-2.tgz: Patched to only start the power manager inside the Xfce environment.
Possibly Related Posts:
- Slackware news: 4 Октомври 2009
- GoblinX 3.0
- Facebook пуска свободен високопроизводителен сървър
- Linux 2.6.31
- Излезе KDE 4.3.0
Filed under: Новини | No Comments »
Slackware news: 21 Февруари 2009
февруари 21st, 2009
Два ъпдейта в сигурността и и някой други пакети бяха добавени днес в -Current и -Stable. Changelog :
a/cpio-2.9-i486-1.tgz: Upgraded to cpio-2.9.
ap/cdrtools-2.01.01a57-i486-2.tgz: Fixed build script to put the charset
conversion tables in /usr/lib/siconv. Hopefully this will work correctly
with k3b now. Thanks to Krasimir Kazakov for the bug report.
ap/sqlite-3.6.11-i486-1.tgz: Upgraded to sqlite-3.6.11.
d/git-1.6.1.3-i486-1.tgz: Upgraded to git-1.6.1.3.
This fixes a vulnerability where running git-diff or git-grep on a hostile
git repository would result in the execution of arbirary code as the git user.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3546
(* Security fix *)
d/subversion-1.5.5-i486-1.tgz: Upgraded to subversion-1.5.5.
l/libpng-1.2.35-i486-1.tgz: Upgraded to libpng-1.2.35.
This fixes multiple memory-corruption vulnerabilities due to a failure to
properly initialize data structures.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0040
ftp://ftp.simplesystems.org/pub/png/src/libpng-1.2.34-ADVISORY.txt
(* Security fix *)
n/dnsmasq-2.47-i486-1.tgz: Upgraded to dnsmasq-2.47.
n/vsftpd-2.1.0-i486-1.tgz: Upgraded to vsftpd-2.1.0.
testing/packages/kde4/extragear/ktorrent-3.2-i486-1.tgz:
Upgraded to ktorrent-3.2.Possibly Related Posts:
- Slackware news: 4 Октомври 2009
- GoblinX 3.0
- Facebook пуска свободен високопроизводителен сървър
- Linux 2.6.31
- Излезе KDE 4.3.0
Filed under: Новини | No Comments »
Slackware news: 5 Февруари 2009
февруари 7th, 2009
Ъпгрейднати са ghostscript и mozilla-firefox до версии съответно 8.64 и 3.0.6. С ъпгрейда към Firefox 3.0.6 се коригират някой дупки в сигурността. Повече информация за тях можете да намерите тук.
Possibly Related Posts:
- Slackware news : 13 Февруари 2009
- Slackware news : 9 Февруари 2009
- Slackware News: 2 Февруари 2009
- Slackware News : 27 Януари 2009
Filed under: Промени | No Comments »
Slackware News: 2 Февруари 2009
февруари 7th, 2009
Ъпдеитнати са xdg-utils. Ето извадка от Changelog-a :
This update fixes two security issues. First, use of xdg-open in /etc/mailcap was found to be unsafe -- xdg-open passes along downloaded files without indicating what mime type they initially presented themselves as, leaving programs further down the processing chain to discover the file type again. This makes it rather trivial to present a script (such as a .desktop file) as a document type (like a PDF) so that it looks safe to click on in a browser, but will result in the execution of an arbitrary script. It might be safe to send files to trusted applications in /etc/mailcap, but it does not seem to be safe to send files to xdg-open in /etc/mailcap. This package will comment out calls to xdg-open in /etc/mailcap if they are determined to have been added by a previous version of this package. If you've made any local customizations to /etc/mailcap, be sure to check that there are no uncommented calls to xdg-open after installing this update. Thanks to Manuel Reimer for discovering this issue. Another bug in xdg-open fails to sanitize input properly allowing the execution of arbitrary commands. This was fixed in the xdg-utils repository quite some time ago (prior to the inclusion of xdg-utils in Slackware), but was never fixed in the official release of xdg-utils. The sources for xdg-utils in Slackware have now been updated from the repo to fix the problem.
За повече информация по темата може да намерите тук и тук.
Possibly Related Posts:
- Slackware news : 13 Февруари 2009
- Slackware news : 9 Февруари 2009
- Slackware news: 5 Февруари 2009
- Slackware News : 27 Януари 2009
Filed under: Промени | No Comments »
Slackware News : 27 Януари 2009
февруари 4th, 2009
Днес беше обявено добавянето на KDE 4.2.0 в Slackware 12.2. Пълен списък с промените от Changelog-a :
testing/packages/kde4/deps/automoc4-0.9.88-i486-1.tgz: Upgraded to automoc4-0.9.88. testing/packages/kde4/deps/clucene-0.9.21b-i486-1.tgz: Upgraded to clucene-0.9.21b. testing/packages/kde4/extragear/guidance-power-manager-4.2.0-i486-1.tgz: Upgraded to guidance-power-manager-4.2.0. testing/packages/kde4/extragear/konq-plugins-4.2.0-i486-1.tgz: Upgraded to konq-plugins-4.2.0. testing/packages/kde4/extragear/skanlite-0.2_kde4.2.0-i486-1.tgz: Upgraded to skanlite-0.2_kde4.2.0. testing/packages/kde4/kde/kdeaccessibility-4.2.0-i486-1.tgz: Upgraded to kdeaccessibility-4.2.0. testing/packages/kde4/kde/kdeadmin-4.2.0-i486-1.tgz: Upgraded to kdeadmin-4.2.0. testing/packages/kde4/kde/kdeartwork-4.2.0-i486-1.tgz: Upgraded to kdeartwork-4.2.0. testing/packages/kde4/kde/kdebase-4.2.0-i486-1.tgz: Upgraded to kdebase-4.2.0. testing/packages/kde4/kde/kdebase-runtime-4.2.0-i486-1.tgz: Upgraded to kdebase-runtime-4.2.0. testing/packages/kde4/kde/kdebase-workspace-4.2.0-i486-1.tgz: Upgraded to kdebase-workspace-4.2.0. testing/packages/kde4/kde/kdebindings-4.2.0-i486-1.tgz: Upgraded to kdebindings-4.2.0. testing/packages/kde4/kde/kdeedu-4.2.0-i486-1.tgz: Upgraded to kdeedu-4.2.0. testing/packages/kde4/kde/kdegames-4.2.0-i486-1.tgz: Upgraded to kdegames-4.2.0. testing/packages/kde4/kde/kdegraphics-4.2.0-i486-1.tgz: Upgraded to kdegraphics-4.2.0. testing/packages/kde4/kde/kdelibs-4.2.0-i486-1.tgz: Upgraded to kdelibs-4.2.0. testing/packages/kde4/kde/kdemultimedia-4.2.0-i486-1.tgz: Upgraded to kdemultimedia-4.2.0. testing/packages/kde4/kde/kdenetwork-4.2.0-i486-2.tgz: Upgraded to kdenetwork-4.2.0. testing/packages/kde4/kde/kdepim-4.2.0-i486-1.tgz: Upgraded to kdepim-4.2.0. testing/packages/kde4/kde/kdepimlibs-4.2.0-i486-1.tgz: Upgraded to kdepimlibs-4.2.0. testing/packages/kde4/kde/kdeplasma-addons-4.2.0-i486-1.tgz: Upgraded to kdeplasma-addons-4.2.0. testing/packages/kde4/kde/kdesdk-4.2.0-i486-1.tgz: Upgraded to kdesdk-4.2.0. testing/packages/kde4/kde/kdetoys-4.2.0-i486-1.tgz: Upgraded to kdetoys-4.2.0. testing/packages/kde4/kde/kdeutils-4.2.0-i486-1.tgz: Upgraded to kdeutils-4.2.0. testing/packages/kde4/kde/kdewebdev-4.2.0-i486-1.tgz: Upgraded to kdewebdev-4.2.0. testing/packages/kde4/kde-l10n/kde-l10n-*-4.2.0-noarch-1.tgz: Upgraded to KDE 4.2.0 l10n packages.
Possibly Related Posts:
- Slackware news : 13 Февруари 2009
- Slackware news : 9 Февруари 2009
- Slackware news: 5 Февруари 2009
- Slackware News: 2 Февруари 2009
Filed under: Промени | No Comments »