Saturday, February 11, 2006

Bunch of Updates

Today, i checked the Slackware changelog for i386 architecture and i saw that Patrick Volkerding has updated the changelog with a bunch of updates. The list are tremendous :

Thu Feb 9 17:24:25 CST 2006
a/aaa_elflibs-10.2.0-i486-4.tgz: Added /lib/libgcc_s.so.1 ->
/usr/lib/libgcc_s.so.1 symlink, needed by Oracle 10g RAC support.
Thanks to Luigi Genoni.
Upgraded various other libraries.
a/bash-3.1-i486-1.tgz: Upgraded to bash-3.1.
a/coreutils-5.93-i486-1.tgz: Upgraded to coreutils-5.93.
The DEFAULT_POSIX2_VERSION=199209 is set to provide more
traditional behavior (thanks to Eric Hameleers), but this may change
in the future as the newer standards are accepted. Added
the uname patch (suggested by many), and moved color ls setup
out of /etc/profile and /etc/csh.login and into scripts in
/etc/profile.d/. These scripts also replace some functionality
(setting up aliases and defaults) that is no longer part of the
dircolors tool.
a/cups-1.1.23-i486-2.tgz: Recompiled against new OpenSSL.
a/cxxlibs-6.0.3-i486-1.tgz: Upgraded to libstdc++ from gcc-3.4.5.
a/etc-5.1-noarch-11.tgz: Removed color ls setup from /etc/profile
and /etc/csh.login. Fixed csh.login in cases where $TERM or $MANPATH
are not set. (thanks to Jim Diamond)
a/gettext-0.14.5-i486-1.tgz: Upgraded to gettext-0.14.5.
a/glibc-solibs-2.3.6-i486-2.tgz: Recompiled with gcc-3.4.5
against the 2.4.32 and 2.6.15.3 kernel headers.
a/glibc-zoneinfo-2.3.6-noarch-2.tgz: Recompiled.
a/gpm-1.20.1-i486-1.tgz: Upgraded to gpm-1.20.1, with many, many patches.
a/openssl-solibs-0.9.8a-i486-1.tgz: Upgraded to openssl-0.9.8a.
This may require many things to be recompiled. Let me know if I
skipped anything that matters. :-)
a/pkgtools-10.2.0-i486-6.tgz: Upgraded subset of terminfo database from
ncurses-5.5. Upgraded to dialog-1.0-20060126.
a/procps-3.2.6-i486-1.tgz: Upgraded to procps-3.2.6.
a/tcsh-6.14.00-i486-2.tgz: Patched to remove built-in color ls, as the new
coreutils adds an 'su' feature to the shared $LS_COLORS variable that
causes tcsh to exit. Perhaps tcsh should use a different variable name or
be less strict about using LS_COLORS? The GNU ls version is probably
better for most purposes anyway, though.
ap/espgs-8.15.1-i486-1.tgz: Upgraded to espgs-8.15.1.
ap/linuxdoc-tools-0.9.21-i486-1.tgz: Added linuxdoc-tools-0.9.21.
This package replaces the sgml-tools package and should contain the
essentials needed to handle modern Linux Docbook/SGML documents. Huge
thanks are due to Stuart Winter for doing most of the work on transitioning
Slackware from the old sgml-tools system to this one! :-)
ap/man-1.6c-i486-1.tgz: Upgraded to man-1.6c.
ap/man-pages-2.22-noarch-1.tgz: Upgraded to man-pages-2.22.
ap/mdadm-2.3.1-i486-1.tgz: Upgraded to mdadm-2.3.1.
ap/mysql-5.0.18-i486-1.tgz: Upgraded to mysql-5.0.18.
(this will require everything linked to MySQL libs to be recompiled)
ap/sgml-tools-1.0.9-i486-12.tgz: Removed. (replaced with linuxdoc-tools)
ap/sudo-1.6.8p12-i486-1.tgz: Upgraded to sudo-1.6.8p12.
This fixes an issue where a user able to run a Python script through sudo
may be able to gain root access.
IMHO, running any kind of scripting language from sudo is still not safe...
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0151
(* Security fix *)
ap/vorbis-tools-1.1.1-i486-2.tgz: Recompiled.
d/automake-1.9.6-noarch-1.tgz: Upgraded to automake-1.9.6.
d/bison-2.1-i486-1.tgz: Upgraded to bison-2.1.
I think enough of the upstream sources are expecting bison-2.x now, but let
me know if you find breakage (for which patches or pointers to upgrades
would be welcome.)
d/clisp-2.38-i486-1.tgz: Upgraded to clisp-2.38.
d/doxygen-1.4.6-i486-1.tgz: Upgraded to doxygen-1.4.6.
d/gdb-6.4-i486-1.tgz: Upgraded to gdb-6.4.
d/gettext-tools-0.14.5-i486-1.tgz: Upgraded to gettext-0.14.5 tools.
d/m4-1.4.4-i486-1.tgz: Upgraded to m4-1.4.4.
d/make-3.80-i486-2.tgz: Fixed an out-of-memory bug in make, since
nobody upstream seems concerned about putting out a fixed make
release any time soon. Is "make" dead? ;-)
Reported here by: Mihnea-Costin Grigore, penguinista, and ePAc.
d/nasm-0.98.39-i486-1.tgz: Upgraded to nasm-0.98.39.
d/perl-5.8.8-i486-1.tgz: Upgraded to perl-5.8.8 and DBI-1.50.
d/pkgconfig-0.20-i486-1.tgz: Upgraded to pkgconfig-0.20.
d/python-2.4.2-i486-1.tgz: Upgraded to python-2.4.2.
The bsddb module didn't build against the new 4.4.x version of
Berkeley DB. Does anyone care? Or perhaps have a patch? :-)
d/python-demo-2.4.2-noarch-1.tgz: Upgraded to python-2.4.2 demos.
d/python-tools-2.4.2-noarch-1.tgz: Upgraded to python-2.4.2 tools.
d/strace-4.5.14-i486-1.tgz: Upgraded to strace-4.5.14.
kde/k*.tgz: Upgraded to KDE 3.5.1.
kde/koffice-1.4.2-i486-1.tgz: Upgraded to koffice-1.4.2.
kde/qt-3.3.5-i486-1.tgz: Upgraded to qt-3.3.5.
l/arts-1.5.1-i486-1.tgz: Upgraded to arts-1.5.1.
l/aspell-0.60.2-i486-2.tgz: Recompiled.
l/atk-1.10.3-i486-1.tgz: Upgraded to atk-1.10.3.
l/cairo-1.0.2-i486-1.tgz: Added cairo graphics library for GTK+2.
l/db4-4.4.20-i486-1.tgz: Upgraded to Berkeley DB 4.4.20. This will
require rebuilding any databases that use the older spec as things
are recompiled to use this, and I'm planning to do that whereever
possible. Just be glad I don't do this with every new BDB release
like I used to. :-)
l/glib2-2.8.6-i486-1.tgz: Upgraded to glib-2.8.6.
l/glibc-2.3.6-i486-2.tgz: Recompiled with gcc-3.4.5
against the 2.4.32 and 2.6.15.3 kernel headers.
l/glibc-i18n-2.3.6-noarch-2.tgz: Rebuilt.
l/glibc-profile-2.3.6-i486-2.tgz: Recompiled with gcc-3.4.5
against the 2.4.32 and 2.6.15.3 kernel headers.
l/gmp-4.1.4-i486-3.tgz: Recompiled.
l/gtk+2-2.8.11-i486-1.tgz: Upgraded to gtk+-2.8.11.
l/jre-1_5_0_06-i586-1.tgz: Upgraded to Java(TM) 2 Platform Standard Edition
Runtime Environment Version 5.0, Release 6.
l/libogg-1.1.3-i486-1.tgz: Upgraded to libogg-1.1.3.
l/libtiff-3.7.4-i486-1.tgz: Upgraded to libtiff-3.7.4.
l/libvorbis-1.1.2-i486-1.tgz: Upgraded to libvorbis-1.1.2.
l/libwpd-0.8.4-i486-1.tgz: Upgraded to libwpd-0.8.4.
l/libxml2-2.6.23-i486-1.tgz: Upgraded to libxml2-2.6.23.
l/ncurses-5.5-i486-1.tgz: Upgraded to ncurses-5.5.
l/pango-1.10.3-i486-1.tgz: Upgraded to pango-1.10.3.
l/pcre-6.4-i486-2.tgz: Recompiled.
l/readline-5.1-i486-1.tgz: Upgraded to readline-5.1.
l/sdl-1.2.9-i486-2.tgz: Recompiled.
l/taglib-1.4-i486-2.tgz: Recompiled.
n/apache-1.3.34-i486-2.tgz: Recompiled against db-4.4.
Support for db-3.3 removed.
n/bind-9.3.2-i486-1.tgz: Upgraded to bind-9.3.2.
n/bitchx-1.1-i486-3.tgz: Recompiled.
n/curl-7.15.1-i486-1.tgz: Upgraded to curl-7.15.1.
n/dhcpcd-2.0.1-i486-1.tgz: Upgraded to dhcpcd-2.0.1.
n/dnsmasq-2.26-i486-1.tgz: Upgraded to dnsmasq-2.26.
n/epic4-2.2-i486-1.tgz: Upgraded to epic4-2.2.
n/fetchmail-6.3.2-i486-1.tgz: Upgraded to fetchmail-6.3.2.
Presumably this replaces all the known security problems with
a batch of new unknown ones. (fetchmail is improving, really ;-)
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3088
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4348
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0321
(* Security fix *)
n/getmail-4.4.4-noarch-1.tgz: Upgraded to getmail-4.4.4.
n/imapd-4.64-i486-2.tgz: Recompiled against OpenLDAP client libs.
n/iproute2-2.6.15_060110-i486-1.tgz: Upgraded to iproute2-2.6.15-060110.
n/iptables-1.3.5-i486-1.tgz: Upgraded to iptables-1.3.5.
n/irssi-0.8.10a-i486-1.tgz: Upgraded to irssi-0.8.10a.
n/lftp-3.4.0-i486-1.tgz: Upgraded to lftp-3.4.0.
n/links-2.1pre20-i486-1.tgz: Upgraded to links-2.1pre20.
n/lynx-2.8.5rel.5-i486-2.tgz: Recompiled.
n/mod_ssl-2.8.25_1.3.34-i486-2.tgz: Recompiled against new OpenSSL.
n/mutt-1.4.2.1i-i486-2.tgz: Recompiled against new OpenSSL.
n/nail-11.25-i486-1.tgz: Upgraded to nail-11.25.
n/nmap-4.00-i486-1.tgz: Upgraded to nmap-4.00.
n/openldap-client-2.3.17-i486-1.tgz: Added client libraries and
binaries for LDAP authentication. (Thanks to Eric Hameleers for
help with the ./configure options).
n/openssh-4.3p1-i486-1.tgz: Upgraded to openssh-4.3p1.
This fixes a security issue when using scp to copy files that could
cause commands embedded in filenames to be executed.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0225
(* Security fix *)
n/openssl-0.9.8a-i486-1.tgz: Upgraded to openssl-0.9.8a.
n/php-4.4.2-i486-1.tgz: Upgraded to php-4.4.2.
Compiled against db-4.4.
Support for db-3.3 removed.
Claims to fix "a few small security issues".
For more information, see:
http://www.php.net/release_4_4_2.php
(* Security fix *)
n/pidentd-3.0.19-i486-1.tgz: Upgraded to pidentd-3.0.19.
n/pine-4.64-i486-2.tgz: Recompiled.
n/procmail-3.22-i486-1.tgz: Upgraded to procmail-3.22.
n/proftpd-1.3.0rc3-i486-1.tgz: Upgraded to proftpd-1.3.0rc3. Generally I
don't like to use release candidates (especially with network services),
but this one was needed in order to work with the new OpenSSL.
n/rp-pppoe-3.7-i486-1.tgz: Upgraded to rp-pppoe-3.7.
n/samba-3.0.21b-i486-1.tgz: Upgraded to samba-3.0.21b linked with OpenLDAP.
n/sendmail-8.13.5-i486-1.tgz: Upgraded to sendmail-8.13.5.
This has been relinked with db-4.4.20, so any databases in /etc/mail will
have to be rebuilt. ( cd /etc/mail ; rm *.db ; make )
n/sendmail-cf-8.13.5-noarch-1.tgz: Upgraded to sendmail-8.13.5 config files.
n/slrn-0.9.8.1-i486-2.tgz: Recompiled.
n/stunnel-4.14-i486-1.tgz: Upgraded to stunnel-4.14.
n/tcpdump-3.9.4-i486-2.tgz: Recompiled.
n/tcpip-0.17-i486-36.tgz: Upgraded to vlan.1.9 and tftp-hpa-0.41.
Applied Debian's net-tools patch at Cesare Tensi's urging. :-)
n/vsftpd-2.0.4-i486-1.tgz: Upgraded to vsftpd-2.0.4.
n/wget-1.10.2-i486-2.tgz: Recompiled.
n/whois-4.7.11-i486-1.tgz: Upgraded to whois-4.7.11.
n/ytalk-3.3.0-i486-1.tgz: Upgraded to ytalk-3.3.0.
xap/fluxbox-0.9.14-i486-1.tgz: Upgraded to fluxbox-0.9.14.
xap/gaim-1.5.0-i486-2.tgz: Recompiled.
xap/gimp-2.2.10-i486-1.tgz: Upgraded to gimp-2.2.10.
xap/gxine-0.5.4-i486-1.tgz: Upgraded to gxine-0.5.4.
Thanks to Peter Santoro for the heads-up on the Javascript engine issue.
xap/imagemagick-6.2.6_1-i486-1.tgz: Upgraded to imagemagick-6.2.6-1.
This has a new major library version number and will require anything
linked with the ImageMagick shared libraries to be recompiled.
Several security issues are fixed in this release.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4601
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0082
(* Security fix *)
xap/mozilla-1.7.12-i486-2.tgz: Linked libmozjs.so into /usr/lib since gxine
needs to be able to find it.
xap/mozilla-firefox-1.5.0.1-i686-1.tgz: Upgraded to firefox-1.5.0.1.
This fixes a DoS issue and some other security bugs.
For more information, see:
http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox1.5.0.1
(* Security fix *)
xap/pan-0.14.2.91-i486-2.tgz: Recompiled, fixed pan.desktop and moved it
into the standard .desktop directory.
xap/xpdf-3.01-i486-3.tgz: Recompiled with xpdf-3.01pl2.patch to fix
possible security bugs with malformed PDF files.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3191
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3192
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3193
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3624
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3625
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3626
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3627
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3628
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2006-0301
(* Security fix *)
xap/sane-1.0.17-i486-1.tgz: Upgraded to sane-backends-1.0.17 and
sane-frontends-1.0.14.
xap/xchat-2.6.1-i486-1.tgz: Upgraded to xchat-2.6.1.
xap/xfce-4.2.3.2-i486-1.tgz: Upgraded to xfce-4.2.3.2.
xap/xine-lib-1.1.1-i686-1.tgz: Upgraded to xine-lib-1.1.1.
xap/xpdf-3.01-i486-3.tgz: Patched with xpdf-3.01pl1.patch.
This fixes a problem where a malformed PDF can crash Xpdf.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3193
(* Security fix *)
xap/xscreensaver-4.23-i486-1.tgz: Upgraded to xscreensaver-4.23.
extra/bittornado/bittornado-0.3.14-noarch-1.tgz: Upgraded to
BitTornado-0.3.14.
extra/bittorrent/bittorrent-4.4.0-noarch-1.tgz: Upgraded to
BitTorrent-4.4.0. Thanks to Erik Jan Tromp for the doinst.sh
to automatically edit /etc/mailcap!
extra/jdk-1.5.0_06/jdk-1_5_0_06-i586-1.tgz: Upgraded to Java(TM) 2
Platform Standard Edition Development Kit Version 5.0, Release 6.
extra/k3b/k3b-0.12.10-i486-1.tgz: Upgraded to k3b-0.12.10.
Thanks to Robby Workman for noticing that CXXFLAGS needed to be set.
extra/k3b/k3b-i18n-0.12.10-noarch-1.tgz: Upgraded to k3b-i18n-0.12.10.
extra/linux-wlan-ng/linux-wlan-ng-0.2.3_2.6.15.3-i486-1.tgz:
Recompiled for Linux 2.6.15.3.
kernels/test26.s/*: Upgraded to full-featured Linux 2.6.15.3 kernel.
pasture/lprng-3.8.28-i486-2.tgz: Recompiled against new OpenSSL.
testing/packages/php-5.1.2/php-5.1.2-i486-1.tgz: Upgraded to php-5.1.2.
testing/packages/linux-2.6.15.3/alsa-driver-1.0.10_2.6.15.3-i486-1.tgz:
Recompiled ALSA modules for Linux 2.6.15.3.
testing/packages/linux-2.6.15.3/kernel-generic-2.6.15.3-i486-1.tgz:
Upgraded to Linux 2.6.15.3 generic kernel.
testing/packages/linux-2.6.15.3/kernel-headers-2.6.15.3-i386-1.tgz:
Upgraded to Linux 2.6.15.3 kernel headers.
testing/packages/linux-2.6.15.3/kernel-modules-2.6.15.3-i486-1.tgz:
Upgraded to Linux 2.6.15.3 kernel modules.
testing/packages/linux-2.6.15.3/kernel-source-2.6.15.3-noarch-1.tgz:
Upgraded to Linux 2.6.15.3 kernel source.
testing/packages/seamonkey-1.0-i486-1.tgz: Added seamonkey-1.0, which
will probably be replacing mozilla-1.7.12 in slackware/xap/ soon unless
doing so ends up breaking too many things. Hopefully it won't -- please
help test it.
# Old bison packages from slackware/d and /extra moved to /pasture.
# A few sources may still require these unless/until they are updated.
pasture/bison-1.35-i386-1.tgz: Moved to /pasture.
pasture/bison-1.875d-i486-1.tgz: Moved to /pasture.
# We'll see if we can get away with a mass removal of old Berkeley DB
# cruft. Yes, I know this will be painful, but it's not my fault that
# BDB does not stay compatible with itself. This mess had to be cleaned
# up sometime, and in preparation for a .0 release seems as good as any.
pasture/db3-3.3.11-i486-4.tgz: Moved to /pasture.
pasture/db31-3.1.17-i486-1.tgz: Moved to /pasture.
pasture/db4-4.1.25-i386-1.tgz: Moved to /pasture.
pasture/db4-4.2.52-i486-2.tgz: Moved to /pasture.

No comments:

Post a Comment