|
发表于 2007-4-4 17:02:14
|
显示全部楼层
Tue Apr 3 15:57:41 CDT 2007
a/aaa_base-11.1.0-noarch-3.tgz: Removed /usr/etc directory.
a/cups-1.2.10-i486-1.tgz: Upgraded to cups-1.2.10.
a/etc-11.1-noarch-2.tgz: Removed /usr/etc/printcap symlink. I don't think
anything has used this in years, but let me know if something still wants it.
a/file-4.20-i486-1.tgz: Upgraded to file-4.20.
This fixes a heap overflow that could allow code to be executed as the
user running file (note that there are many scenarios where file might be
used automatically, such as in virus scanners or spam filters).
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1536
(* Security fix *)
a/sysvinit-2.86-i486-3.tgz: In functions, change usleep calls to sleep calls.
a/tcsh-6.15.00-i486-1.tgz: Upgraded to tcsh-6.15.00.
ap/espgs-8.15.4-i486-1.tgz: Upgraded to espgs-8.15.4.
ap/zsh-4.3.2-i486-1.tgz: Upgraded to zsh-4.3.2.
d/gdb-6.6-i486-2.tgz: Recompiled against new libexpat.
Thanks to Giacomo Lozito for noticing this last link to the past.
d/m4-1.4.9-i486-1.tgz: Upgraded to m4-1.4.9.
kde/kdelibs-3.5.6-i486-3.tgz: Recompiled with a patch to kjs.
Changed --sysconfdir from /usr/etc to /etc/X11.
Thanks to Giacomo Lozito for the heads-up on this one as well.
kde/kdegraphics-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdesdk-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdeedu-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdemultimedia-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/amarok-1.4.5-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdebindings-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdegames-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdetoys-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdebase-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdeaccessibility-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdewebdev-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdepim-3.5.6-i486-3.tgz: Patched to update timezone information for Kmail.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdenetwork-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdevelop-3.4.0-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdeartwork-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdeadmin-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdeaddons-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/kdeutils-3.5.6-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
kde/koffice-1.6.2-i486-3.tgz: Recompiled.
Changed --sysconfdir from /usr/etc to /etc/X11.
l/arts-1.5.6-i486-3.tgz: Recompiled.
l/libmikmod-3.1.11a-i486-2.tgz: Removed. There's better libmikmod support in
audacious-plugins, and after XMMS's removal nothing in Slackware was using
this library any longer.
l/qt-3.3.8-i486-3.tgz: Patched an issue where the Qt UTF 8 decoder may in some
instances fail to reject overlong sequences, possibly allowing "/../" path
injection or XSS errors.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0242
(* Security fix *)
Also, restored /usr/lib/qt/lib to /etc/ld.so.conf fixing "make xconfig" in
the kernel. Thanks to all those who reported this issue.
l/slang-2.0.7-i486-1.tgz: Upgraded to slang-2.0.7, moved --sysconfig to /etc.
l/svgalib-1.9.25_2.6.18.8_smp-i486-2.tgz: Changed to slacktrack for build
method, as the SlackBuild method was embedding some incorrect paths.
n/openldap-client-2.3.32-i486-1.tgz: Upgraded to openldap-2.3.32 client libs.
n/openssh-4.6p1-i486-1.tgz: Upgraded to openssh-4.6p1. Changed rc.sshd
slightly to avoid the potential to be disconnected from a remote box without
sshd being restarted when using "sh /etc/rc.d/rc.sshd restart".
Thanks to Robby Workman.
x/compiz-0.5.0-i486-1.tgz: Upgraded to compiz-0.5.0.
x/libX11-1.1.1-i486-3.tgz: Restored XCB support after being informed of some
benchmarks that show a significant performance increase.
x/libxcb-1.0-i486-2.tgz: Patched to work around the locking problem that was
affecting Java and other programs. I would have preferred to hold out for a
new release of libxcb, but we can see what happens with this for now.
Thanks to Luigi Genoni for convincing me to try this patch.
x/xf86-input-joystick-1.2.0-i486-1.tgz: Upgraded to xf86-input-joystick-1.2.0.
x/xf86-video-intel-1.9.94-i486-1.tgz: Upgraded to xf86-video-intel-1.9.94.
x/xf86-video-nv-2.0.1-i486-1.tgz: Upgraded to xf86-video-nv-2.0.1.
x/xorg-server-1.2.99.903-i486-1.tgz: Upgraded to xorg-server-1.2.99.903.
x/xorg-server-xdmx-1.2.99.903-i486-1.tgz: Upgraded to xorg-server-1.2.99.903.
x/xorg-server-xnest-1.2.99.903-i486-1.tgz: Upgraded to xorg-server-1.2.99.903.
x/xorg-server-xvfb-1.2.99.903-i486-1.tgz: Upgraded to xorg-server-1.2.99.903.
xap/audacious-plugins-1.3.1-i486-2.tgz: Recompiled using --enable-chardet.
xap/audacious-1.3.1-i486-2.tgz: Recompiled using --enable-chardet instead of
the incorrect --enable-charset.
xap/gqview-2.1.5-i486-2.tgz: Fixed non-Slackware-compliant slack-desc: (not 11
info lines, missing editing instructions/ruler, "GQview" improperly
capitalized, top line should have the Slackware package name followed by
the (description), and "empty" lines shouldn't have whitespace after the ":".
Thanks to Selkfoster for pointing out the first of these minor issues.
xap/pan-0.126-i486-1.tgz: Upgraded to pan-0.126.
xap/x3270-3.3.5-i486-1.tgz: Upgraded to x3270-3.3.5. Moved config file from
/usr/etc/x3270/ to /etc/X11/x3270/ and added config() installation.
extra/k3b/k3b-1.0-i486-1.tgz: Upgraded to k3b-1.0.
extra/k3b/k3b-i18n-1.0-noarch-1.tgz: Upgraded to k3b-i18n-1.0.
extra/ktorrent/ktorrent-2.1.3-i486-1.tgz: Upgraded to ktorrent-2.1.3.
A directory traversal vulnerability in torrent.cpp in versions < 2.1.2 may
allow remote attackers to overwrite the ktorrent user's files. A bug in
chunkcounter.cpp in versions < 2.1.2 allows remote attackers to crash
ktorrent and cause heap corruption by the use of an invalid idx value.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1384
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1385
(* Security fix *)
11.1快出了--再发大神current更新贴 |
|