Entries from September 2006
Here is the latest update to the Slackware-current changelog:
Sat Sep 30 22:05:20 CDT 2006
extra/linux-smp-2.6.17.13/kernel-modules-smp-2.6.17.13-i686-3.tgz:
This had been named i486 when it’s really an i686 arch package.
+————————–+
Posted automagically by ChangeLog Update (A work in progress)
Technorati Tags: slackware,linux,slackware-current,slackware-11.0
Categories: ChangeLogs · Slackware
Here is the latest update to the Slackware-current changelog:
Sat Sep 30 19:35:24 CDT 2006
a/etc-11.0-noarch-2.tgz: Added missing comment marks (#) for distcc ports
in /etc/services. Thanks to Michiel Broek.
n/popa3d-1.0.2-i486-2.tgz: Do better checking of passwd and group to avoid
adding redundant entries to these files. Thanks to Menno Duursma.
n/sendmail-8.13.8-i486-4.tgz: Do better checking of passwd and group to avoid
adding redundant entries to these files. Thanks to Menno Duursma.
n/sendmail-cf-8.13.8-noarch-4.tgz: Rebuilt.
extra/linux-smp-2.6.17.13/kernel-generic-smp-2.6.17.13-i686-3.tgz:
Recompiled to add missing SMP/SMT support.
Thanks to arny for noticing that I’d started with the wrong .config.
extra/linux-smp-2.6.17.13/kernel-headers-smp-2.6.17.13-i386-3.tgz: Rebuilt.
extra/linux-smp-2.6.17.13/kernel-modules-smp-2.6.17.13-i486-3.tgz: Recompiled.
+————————–+
Posted automagically by ChangeLog Update (A work in progress)
Technorati Tags: slackware,linux,slackware-current,slackware-11.0
Categories: Slackware
Here is the latest update to the Slackware-current changelog:
Sat Sep 30 01:52:09 CDT 2006
testing/packages/fontconfig-2.4.1-i486-1.tgz: Upgraded to fontconfig-2.4.1.
Thanks to Fr餩ric L. W. Meunier for pointing this out.
l/shared-mime-info-0.19-i486-1.tgz: Upgraded to shared-mime-info-0.19.
+————————–+
Posted automagically by ChangeLog Update (A work in progress)
Technorati Tags: slackware,linux,slackware-current,slackware-11.0
Categories: ChangeLogs · Slackware
Here is the latest update to the Slackware-current changelog:
Fri Sep 29 23:41:35 CDT 2006
l/libgpod-0.4.0-i486-1.tgz: Upgraded to libgpod-0.4.0. Thanks to Shilo Bacca.
l/pango-1.12.4-i486-1.tgz: Fixed bogus empty GPOS table warning and other
minor bugs.
extra/linux-smp-2.6.17.13/kernel-generic-smp-2.6.17.13-i686-2.tgz:
Rebuilt SMP kernels setting -smp in CONFIG_LOCALVERSION, not EXTRAVERSION.
Thanks to Tom B. for snapping me out of my old-skool ways.
extra/linux-smp-2.6.17.13/kernel-headers-smp-2.6.17.13-i386-2.tgz: Rebuilt.
extra/linux-smp-2.6.17.13/kernel-modules-smp-2.6.17.13-i486-2.tgz: Rebuilt.
testing/packages/iptables-1.3.6-i486-1.tgz: This one appeared too late to be
considered for mainline (not enough test time), but it _should_ be stable.
testing/packages/wpa_supplicant-0.4.9-i486-1.tgz: Added wpa_supplicant-0.4.9.
Thanks to Eric Hameleers for a good head-start on this one.
+————————–+
Posted automagically by ChangeLog Update (A work in progress)
Technorati Tags: slackware,linux,slackware-current,slackware-11.0
Categories: Slackware
September 29, 2006 · 1 Comment
Here is the latest update to the Slackware-current changelog:
Fri Sep 29 02:10:15 CDT 2006
a/openssl-solibs-0.9.8d-i486-1.tgz: Upgraded to shared libraries from
openssl-0.9.8d. See openssl package update below.
(* Security fix *)
n/openssh-4.4p1-i486-1.tgz: Upgraded to openssh-4.4p1.
This fixes a few security related issues. From the release notes found at
http://www.openssh.com/txt/release-4.4:
* Fix a pre-authentication denial of service found by Tavis Ormandy,
that would cause sshd(
to spin until the login grace time
expired.
* Fix an unsafe signal hander reported by Mark Dowd. The signal
handler was vulnerable to a race condition that could be exploited
to perform a pre-authentication denial of service. On portable
OpenSSH, this vulnerability could theoretically lead to
pre-authentication remote code execution if GSSAPI authentication
is enabled, but the likelihood of successful exploitation appears
remote.
* On portable OpenSSH, fix a GSSAPI authentication abort that could
be used to determine the validity of usernames on some platforms.
Links to the CVE entries will be found here:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4924
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5051
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5052
After this upgrade, make sure the permissions on /etc/rc.d/rc.sshd are set
the way you want them. Future upgrades will respect the existing permissions
settings. Thanks to Manuel Reimer for pointing out that upgrading openssh
would enable a previously disabled sshd daemon.
Do better checking of passwd, shadow, and group to avoid adding
redundant entries to these files. Thanks to Menno Duursma.
(* Security fix *)
n/openssl-0.9.8d-i486-1.tgz: Upgraded to openssl-0.9.8d.
This fixes a few security related issues:
During the parsing of certain invalid ASN.1 structures an error
condition is mishandled. This can result in an infinite loop which
consumes system memory (CVE-2006-2937). (This issue did not affect
OpenSSL versions prior to 0.9.7)
Thanks to Dr S. N. Henson of Open Network Security and NISCC.
Certain types of public key can take disproportionate amounts of
time to process. This could be used by an attacker in a denial of
service attack (CVE-2006-2940).
Thanks to Dr S. N. Henson of Open Network Security and NISCC.
A buffer overflow was discovered in the SSL_get_shared_ciphers()
utility function. An attacker could send a list of ciphers to an
application that uses this function and overrun a buffer.
(CVE-2006-373
Thanks to Tavis Ormandy and Will Drewry of the Google Security Team.
A flaw in the SSLv2 client code was discovered. When a client
application used OpenSSL to create an SSLv2 connection to a malicious
server, that server could cause the client to crash (CVE-2006-4343).
Thanks to Tavis Ormandy and Will Drewry of the Google Security Team.
Links to the CVE entries will be found here:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2937
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2940
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4343
(* Security fix *)
zipslack/zipslack.zip: Rebuilt ZipSlack with new openssl-solibs and
openssh packages.
+————————–+
Posted automagically by ChangeLog Update (A work in progress)
Technorati Tags: slackware,linux,slackware-current,slackware-11.0
Categories: Slackware
September 28, 2006 · 3 Comments
Here is the latest update to the Slackware-current changelog:
Thu Sep 28 03:33:49 CDT 2006
ap/vorbis-tools-1.1.1-i486-3.tgz: Fixed UTF8 support.
Thanks to Igor Pashev for providing a simple patch from Gene Pavlovsky.
kernels/huge26.s/*: Added support for USB and IEEE1394 storage devices.
kernels/test26.s/*: Added support for USB and IEEE1394 storage devices.
Thanks to Tais M. Hansen for pointing out that these kernels lacked support
for USB storage devices. Using these kernels with udev may cause a few
warnings at boot time as udev attempts to load the already built-in support,
but these seem to be harmless.
+————————–+
Posted automagically by ChangeLog Update (A work in progress)
Technorati Tags: slackware,linux,slackware-current,slackware-11.0
Categories: ChangeLogs · Slackware
September 26, 2006 · 1 Comment
Here is the latest update to the Slackware-current changelog:
Tue Sep 26 05:57:52 CDT 2006
a/aaa_base-11.0.0-noarch-2.tgz: Updated the “Welcome to Slackware” email.
Added /mount directory, subdirectories, and symbolic links recommended by
the FHS, along with README files to help me understand the difference
between this directory and /mnt. 
a/etc-11.0-noarch-1.tgz: Fixed a bug in /etc/csh.login that caused repeated
use of “csh -l” to duplicate search directories in the $path. Clearly
/etc/csh.login should set the path just as /etc/profile does.
This bug dates back at at least 1997, maybe earlier, so congratulations to
Dimitar Zhekov for winning this release’s “smite the oldest bug” award.
Added distcc port to /etc/services. Thanks to Erik Jan Tromp and
Robby Workman for the continual reminders. 
a/pkgtools-11.0.0-i486-4.tgz: Made upgradepkg a little bit more gentle — if
it is run on a corrupted .tgz it will no longer remove the original package.
Thanks to Ric Anderson for the report.
Added rc.scanluns to the services setup menu.
a/sysvinit-2.84-i486-69.tgz: Fixed path to /sbin/initscript shown in init.8
(again). Thanks to Robby Workman.
Changed rc.S to run rc.serial according to whether the script is executable.
a/util-linux-2.12r-i486-5.tgz: Treat /etc/rc.d/rc.serial (to preserve file
permissions), /etc/serial.conf, and /etc/fdprm as ‘.new’ config files.
ap/lm_sensors-2.10.0-i486-3.tgz: Fixed hardcoded /usr/local paths in
sensors-detect. Thanks to Jakub Jankowski.
kde/kdebase-3.5.4-i486-7.tgz: Patched to fix media:/ URLs in Konqueror without
requiring HAL. Thanks to everyone involved in reporting this issue and
seeing that it was addressed:
http://bugs.kde.org/show_bug.cgi?id=132281
A big thanks to coolo (Stephan Kulow) for coming up with a patch. 
zipslack/zipslack.zip: Added ZipSlack.
+————————–+
Posted automagically by ChangeLog Update (A work in progress)
Technorati Tags: slackware,linux,slackware-current,slackware-11.0
Categories: ChangeLogs · Slackware
Sorry about that guys and gals…I was doing some stuff to my machine over the weekend and I guess I overwrote one of the changelogs that my script uses…Well, this issue should be fixed now! Sorry about that!
Categories: General · Site News
Here is the latest update to the Slackware-current changelog:
Sat Sep 23 03:45:30 CDT 2006
a/sysvinit-2.84-i486-68.tgz: In rc.M, start rc.hplip if found. Fix the path
to /sbin/initscript shown in init.8. Thanks to Robby Workman.
xap/sane-1.0.18-i486-3.tgz: Added HPLIP backend (hpaio) to dll.conf.
testing/packages/cups-1.2.4/cups-1.2.4-i486-1.tgz: Upgraded to cups-1.2.4.
The web site says that more problems were fixed. I would still approach
this one cautiously, though I’m sure it (or its descendent) will be used
in Slackware 11.1. Unless you have a reason to need this now, I’d wait.
testing/packages/hplip-1.6.9-i486-1.tgz: Added hplip-1.6.9, a complete print,
scan, and fax system for HP devices. This isn’t being merged into the AP
series as a replacement for hpijs solely because I’d like to see it get more
testing first. It is working perfectly here. Thanks to Robby Workman for
doing the vast majority of the work on this package. 
testing/packages/gutenprint-5.0.0-i486-2.tgz: Don’t overwrite GIMP’s “print”
plugin — instead install the plugin as “gutenprint”.
Thanks again to Stefano Vesa.
+————————–+
Posted automagically by ChangeLog Update (A work in progress)
Technorati Tags: slackware,linux,slackware-current,slackware-11.0
Categories: ChangeLogs · Slackware
Categories: ChangeLogs · Slackware