Paket update pertama untuk Slackware 12.1 telah keluar, yaitu paket PHP dan Mozilla-Thunderbird. Harap diperhatikan bahwa untuk beberapa versi Slackware sebelumnya, PHP 5 belum menjadi paket default, sehingga keputusan untuk melakukan upgrade ada di tangan Anda (bagi pengguna Slackware 10.2 dan 11.0)
New php packages are available for Slackware 10.2, 11.0, 12.0, 12.1, and -current to fix security issues.
Note that PHP5 is not the default PHP for Slackware 10.2 or 11.0 (those use
PHP4), so if your PHP code is not ready for PHP5, don't upgrade until it is
or you'll (by definition) run into problems.
More details about one of the issues may be found in the Common
Vulnerabilities and Exposures (CVE) database:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0599
Here are the details from the Slackware 12.1 ChangeLog:
+--------------------------+
patches/packages/php-5.2.6
Upgraded to php-5.2.6.
This version of PHP contains many fixes and enhancements. Some of the fixes
are security related, and the PHP release announcement provides this list:
* Fixed possible stack buffer overflow in the FastCGI SAPI identified by
Andrei Nigmatulin.
* Fixed integer overflow in printf() identified by Maksymilian Aciemowicz.
* Fixed security issue detailed in CVE-2008-0599 identified by Ryan Permeh.
* Fixed a safe_mode bypass in cURL identified by Maksymilian Arciemowicz.
* Properly address incomplete multibyte chars inside escapeshellcmd()
identified by Stefan Esser.
* Upgraded bundled PCRE to version 7.6
When last checked, CVE-2008-0599 was not yet open. However, additional
information should become available at this URL:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0599
The list reproduced above, as well as additional information about other
fixes in PHP 5.2.6 may be found in the PHP release announcement here:
http://www.php.net/releases/5_2_6.php
(* Security fix *)
+--------------------------+
Updated package for Slackware 10.2:
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/testing/packages/php5/php-5.2.6-i486-1_slack10.2.tgz
Updated package for Slackware 11.0:
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/extra/php5/php-5.2.6-i486-1_slack11.0.tgz
Updated package for Slackware 12.0:
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/php-5.2.6-i486-1_slack12.0.tgz
Updated package for Slackware 12.1:
ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/php-5.2.6-i486-1_slack12.1.tgz
Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/php-5.2.6-i486-1.tgz
New mozilla-thunderbird packages are available for Slackware 10.2, 11.0, 12.0,
12.1, and -current to fix security issues, including crashes that can corrupt
memory, as well as a JavaScript privilege escalation and arbitrary code
execution flaw.
More details about these issues may be found here:
http://www.mozilla.org/projects/security/known-vulnerabilities.html#thunderbird
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1233
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1234
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1235
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1236
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1237
Here are the details from the Slackware 12.1 ChangeLog:
+--------------------------+
patches/packages/mozilla
Upgraded to thunderbird-2.0.0.14.
This upgrade fixes some more security bugs.
For more information, see:
http://www.mozilla.org/projects/security/known-vulnerabilities.html#thunderbird
(* Security fix *)
+--------------------------+
Updated package for Slackware 10.2:
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/mozilla-thunderbird-2.0.0.14-i686-1.tgz
Updated package for Slackware 11.0:
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/mozilla-thunderbird-2.0.0.14-i686-1.tgz
Updated package for Slackware 12.0:
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/mozilla-thunderbird-2.0.0.14-i686-1.tgz
Updated package for Slackware 12.1:
ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/mozilla-thunderbird-2.0.0.14-i686-1.tgz
Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/mozilla-thunderbird-2.0.0.14-i686-1.tgz
Saturday, December 27, 2008
Security Update: PHP, Mozilla-Thunderbird For Slackware 12.1
-i486-1_slack12.1.tgz:
-thunderbird-2.0.0.14-i686-1.tgz:
Subscribe to:
Post Comments (Atom)
Link Exchange
Donation
Visitor
Online
Do you like this blog
Arsip Blog
-
▼
2008
(90)
-
▼
December
(38)
- Download contoh program vb6
- Google Kini Berbahasa Indonesia, AdSense Sebentar ...
- Bisnis dari rumah dapat duit
- Security Update: PHP, Mozilla-Thunderbird For Slac...
- BIKIN BLOG ANDA MENGHASILKAN UANG
- Tak Punya Kartu Kredit, Verifikasi Paypal dengan S...
- Visual Basic
- Kiat Agar Mudah Mendapatkan Klik Iklan
- 11 CARA GOOGLE MENDETEKSI KLIK PALSU
- Meningkatkan Traffic Pengunjung Website (I)
- Panduan Instalasi Mandriva Linux 2008 Free Edition
- Mandriva 2009 Rilis Candidate dengan KDE 4.1.1
- Mandriva
- CARA INSTALASI MANDRIVA (dibaca "Man-dree-vah"!) L...
- Pengenalan dan Panduan Google Webmaster Tools
- Opera Mini - Phone Browser
- Opera Mini 4.2 beta - Sudah Release
- Jalankan aplikasi windows di linux dengan CrossOver
- Open Source CMS Award 2008
- Rilis terbaru Mandriva 2009
- Mandriva Linux
- Telepon Murah Bahkan Gratis Menggunakan Skype vers...
- Distro Linux Mandriva 2009 Segera Diluncurkan
- Rilis: Mandriva Linux 2008
- Mempercepat OpenOffice di Mandriva
- Tips Memilih Distro Linux
- Tips dan Trik untuk Pengguna Linux Pemula
- Perintah Dasar Linux
- Apa Itu Mount??
- LinuxMint 6 Felicia sudah dirilis
- Dokumentasi Komunitas / Tutorial Repositori Lokal ...
- Dokumentasi Komunitas / Tutorial Repositori Lokal
- Memperbaiki Blog Template Yang Bandwidth Exceeded
- Tutorial Program menggunakan Visual Basic 6.0
- Tambah Bandwidth Internet pada Windows
- Speed Connect Internet Accelerator v7.5 - Download
- Internet Download Manager 5.15 Full version (no vi...
- TIPs and TRICKS Browsing dan Download Tanpa Batas
-
▼
December
(38)
0 comments:
Post a Comment