[slackware-security] sysklogd update (SSA:2004-124-02)

From: Slackware Security Team (security_at_slackware.com)
Date: 05/03/04

  • Next message: James Riden: "Re: After Ms patches last Wed ..."
    Date: Mon, 3 May 2004 13:06:43 -0700 (PDT)
    To: slackware-security@slackware.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    [slackware-security] sysklogd update (SSA:2004-124-02)

    New sysklogd packages are available for Slackware 8.1, 9.0, 9.1, and -current
    to fix a security issue where a user could cause syslogd to crash. Thanks to
    Steve Grubb who researched the issue.

    Here are the details from the Slackware 9.1 ChangeLog:
    +--------------------------+
    Sun May 2 17:16:41 PDT 2004
    patches/packages/sysklogd-1.4.1-i486-9.tgz: Patched a bug which could allow
      a user to cause syslogd to write to unallocated memory and crash.
      Thanks to Steve Grubb for finding the bug, and Solar Designer for refining
      the patch.
      (* Security fix *)
    +--------------------------+

    Where to find the new packages:
    +-----------------------------+

    Updated package for Slackware 8.1:
    ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/sysklogd-1.4.1-i386-7.tgz

    Updated package for Slackware 9.0:
    ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/sysklogd-1.4.1-i386-9.tgz

    Updated package for Slackware 9.1:
    ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/sysklogd-1.4.1-i486-9.tgz

    Updated package for Slackware -current:
    ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/a/sysklogd-1.4.1-i486-9.tgz

    MD5 signatures:
    +-------------+

    Slackware 8.1 package:
    4bcd73db9029567f73d7131f63421cdd sysklogd-1.4.1-i386-7.tgz

    Slackware 9.0 package:
    8e7563c3c060641acc2307b0ab8c1402 sysklogd-1.4.1-i386-9.tgz

    Slackware 9.1 package:
    f97b852f2202af2ed775a2e0c584bc26 sysklogd-1.4.1-i486-9.tgz

    Slackware -current package:
    5820b02d24994c1b5fff7a62b59dada0 sysklogd-1.4.1-i486-9.tgz

    Installation instructions:
    +------------------------+

    First, stop syslogd/klogd:
    # . /etc/rc.d/rc.syslog stop

    Next, upgrade the package as root:
    # upgradepkg sysklogd-1.4.1-i486-9.tgz

    Finally, restart the logging system:
    # . /etc/rc.d/rc.syslog start

    +-----+

    Slackware Linux Security Team
    http://slackware.com/gpg-key
    security@slackware.com

    +------------------------------------------------------------------------+
    | To leave the slackware-security mailing list: |
    +------------------------------------------------------------------------+
    | Send an email to majordomo@slackware.com with this text in the body of |
    | the email message: |
    | |
    | unsubscribe slackware-security |
    | |
    | You will get a confirmation message back containing instructions to |
    | complete the process. Please do not reply to this email address. |
    +------------------------------------------------------------------------+

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.4 (GNU/Linux)

    iD8DBQFAlqIpakRjwEAQIjMRAqG2AJ0TfBJ0P668pqrAavmP22Kyy6JeZACeIFFQ
    tUnQUODYj4t/dWVN8YKUq8k=
    =iQRP
    -----END PGP SIGNATURE-----


  • Next message: James Riden: "Re: After Ms patches last Wed ..."

    Relevant Pages

    • [slackware-security] kdelibs (SSA:2004-238-01)
      ... to fix security issues with URI handling. ... Here are the details from the Slackware 9.1 ChangeLog: ... Updated package for Slackware 9.0: ...
      (Bugtraq)
    • [slackware-security] lftp security update (SSA:2003-346-01)
      ... A security problem with lftp has been corrected with the release ... Here are the details from the Slackware 9.1 ChangeLog: ... this includes "security fixes in html ... WHERE TO FIND THE NEW PACKAGE: ...
      (Bugtraq)
    • [slackware-security] apache (SSA:2004-133-01)
      ... We recommend that sites running Apache upgrade ... Here are the details from the Slackware 9.1 ChangeLog: ... These security fixes were backported from Apache 1.3.31: ... Updated package for Slackware 8.1: ...
      (Bugtraq)
    • [slackware-security] mc (SSA:2004-136-01)
      ... fix security issues that These could lead to a denial of service or the ... Sites that use mc should upgrade to the new mc package. ... Here are the details from the Slackware 9.1 ChangeLog: ... service or the execution of arbitrary code as the user running mc. ...
      (Bugtraq)
    • TSLSA-2006-0024 - multi
      ... Trustix Secure Linux Security Advisory #2006-0024 ... Affected versions: Trustix Secure Linux 2.2 ... Package description: ... Mu Security has reported a vulnerability in Cyrus SASL ...
      (Bugtraq)