news:2014:06:06:slackware-14.1-changelog

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
news:2014:06:06:slackware-14.1-changelog [2015/03/10 12:23] – creata Giuseppe Di Terlizzinews:2014:06:06:slackware-14.1-changelog [2023/08/15 18:31] (current) Giuseppe Di Terlizzi
Line 2: Line 2:
  
 ====== Fri Jun  6 04:27:01 UTC 2014 ====== ====== Fri Jun  6 04:27:01 UTC 2014 ======
- 
- 
 ===== Packages ===== ===== Packages =====
  
 ==== Upgraded ==== ==== Upgraded ====
-  * [[slackware.14.1>patches/packages/gnutls-3.1.25-i486-1_slack14.1.txz]] (Security fix) +  * [[slackware.14.1>patches/packages/gnutls-3.1.25-i486-1_slack14.1.txz]] \\   A security issue has been corrected in gnutls.  This vulnerability \\   affects the client side of the gnutls library.  A server that sends \\   a specially crafted ServerHello could corrupt the memory of a requesting \\   client.  This may allow a remote attacker to execute arbitrary code. \\   Additional vulnerabilities in the embedded libtasn1 library have also \\   been patched. \\   Thanks to mancha for the backported patches. \\   For more information, see: \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3465 \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3466 \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3467 \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3468 \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3469 \\   (Security fix *
-  * [[slackware.14.1>patches/packages/libtasn1-3.6-i486-1_slack14.1.txz]] (Security fix) +  * [[slackware.14.1>patches/packages/libtasn1-3.6-i486-1_slack14.1.txz]] \\   Multiple security issues have been corrected in the libtasn1 library. \\   These errors allow a remote attacker to cause a denial of service, or \\   possibly to execute arbitrary code. \\   For more information, see: \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3467 \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3468 \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3469 \\   (Security fix *
-  * [[slackware.14.1>patches/packages/openssl-1.0.1h-i486-1_slack14.1.txz]] (Security fix)+  * [[slackware.14.1>patches/packages/openssl-1.0.1h-i486-1_slack14.1.txz]] \\   Multiple security issues have been corrected, including a possible \\   man-in-the-middle attack where weak keying material is forced, denial \\   of service, and the execution of arbitrary code. \\   For more information, see: \\     http://www.openssl.org/news/secadv_20140605.txt \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5298 \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0195 \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0198 \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0221 \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224 \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3470 \\   (Security fix *)
   * [[slackware.14.1>patches/packages/openssl-solibs-1.0.1h-i486-1_slack14.1.txz]]   * [[slackware.14.1>patches/packages/openssl-solibs-1.0.1h-i486-1_slack14.1.txz]]
-  * [[slackware.14.1>patches/packages/sendmail-8.14.9-i486-1_slack14.1.txz]] (Security fix)+  * [[slackware.14.1>patches/packages/sendmail-8.14.9-i486-1_slack14.1.txz]] \\   This release fixes one security related bug by properly closing file \\   descriptors (except stdin, stdout, and stderr) before executing programs. \\   This bug could enable local users to interfere with an open SMTP \\   connection if they can execute their own program for mail delivery \\   (e.g., via procmail or the prog mailer). \\   For more information, see: \\     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3956 \\   (* Security fix *)
   * [[slackware.14.1>patches/packages/sendmail-cf-8.14.9-noarch-1_slack14.1.txz]]   * [[slackware.14.1>patches/packages/sendmail-cf-8.14.9-noarch-1_slack14.1.txz]]
-===== ChangeLog ===== 
-<code> 
-Fri Jun  6 04:27:01 UTC 2014 
-patches/packages/gnutls-3.1.25-i486-1_slack14.1.txz:  Upgraded. 
-  A security issue has been corrected in gnutls.  This vulnerability 
-  affects the client side of the gnutls library.  A server that sends 
-  a specially crafted ServerHello could corrupt the memory of a requesting 
-  client.  This may allow a remote attacker to execute arbitrary code. 
-  Additional vulnerabilities in the embedded libtasn1 library have also 
-  been patched. 
-  Thanks to mancha for the backported patches. 
-  For more information, see: 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3465 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3466 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3467 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3468 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3469 
-  (* Security fix *) 
-patches/packages/libtasn1-3.6-i486-1_slack14.1.txz:  Upgraded. 
-  Multiple security issues have been corrected in the libtasn1 library. 
-  These errors allow a remote attacker to cause a denial of service, or 
-  possibly to execute arbitrary code. 
-  For more information, see: 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3467 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3468 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3469 
-  (* Security fix *) 
-patches/packages/openssl-1.0.1h-i486-1_slack14.1.txz:  Upgraded. 
-  Multiple security issues have been corrected, including a possible 
-  man-in-the-middle attack where weak keying material is forced, denial 
-  of service, and the execution of arbitrary code. 
-  For more information, see: 
-    http://www.openssl.org/news/secadv_20140605.txt 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5298 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0195 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0198 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0221 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3470 
-  (* Security fix *) 
-patches/packages/openssl-solibs-1.0.1h-i486-1_slack14.1.txz:  Upgraded. 
-patches/packages/sendmail-8.14.9-i486-1_slack14.1.txz:  Upgraded. 
-  This release fixes one security related bug by properly closing file 
-  descriptors (except stdin, stdout, and stderr) before executing programs. 
-  This bug could enable local users to interfere with an open SMTP 
-  connection if they can execute their own program for mail delivery 
-  (e.g., via procmail or the prog mailer). 
-  For more information, see: 
-    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3956 
-  (* Security fix *) 
-patches/packages/sendmail-cf-8.14.9-noarch-1_slack14.1.txz:  Upgraded. 
-</code> 
- 
  
  
-{{tag>slackware changelog slackware-14.1 2014/06}}+{{tag>slackware changelog slackware-14.1 2014-06}}
  
  • news/2014/06/06/slackware-14.1-changelog.1425986636.txt.gz
  • Last modified: 9 years ago
  • by Giuseppe Di Terlizzi