LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 06-15-2017, 07:31 AM   #1
ndr
LQ Newbie
 
Registered: Aug 2009
Location: World
Distribution: Slackware
Posts: 11

Rep: Reputation: 8
Exclamation slackware-security ML is being incomplete


It's happening more and more often, lately, that the slackware-security mailing list fails to announce some of the package updates. I find out when I give `slackpkg upgrade-all` and unexpected packages appear in the list (for example, today it's `pkg-config`: updated, not announced).

So, being paranoid , I go and check the Changelog to see if the package has indeed been updated, or if something fishy is going on within my preferred mirror.

I wonder if should I give up on the mailing list and check the Changelog directly...

How does everyone keep up with the latest security news for Slackware?
 
Old 06-15-2017, 07:46 AM   #2
GazL
LQ Veteran
 
Registered: May 2008
Posts: 6,896

Rep: Reputation: 5018Reputation: 5018Reputation: 5018Reputation: 5018Reputation: 5018Reputation: 5018Reputation: 5018Reputation: 5018Reputation: 5018Reputation: 5018Reputation: 5018
pkg-config update was likely not security related, but yes, just keep an eye on the changelog instead. I've never subscribed to the ML.
 
1 members found this post helpful.
Old 06-15-2017, 07:51 AM   #3
magicm
Member
 
Registered: May 2003
Distribution: Slackware
Posts: 236

Rep: Reputation: 152Reputation: 152
First, I don't know for sure, but I expect that the slackware-security mailing list only mentions updates that are 'security-related' (for all I know, it might even require a CVE id). I rely on it to tell me that there is a security issue that has been patched.

But when something is patched, it doesn't mean that it is patched for a security bug. As slackpkg doesn't have an "upgrade-security" option, "upgrade-all" will pick up all that's been patched. Checking ChangeLog.txt is always appropriate, but I don't see an issue with waiting for the mailing list, to tell me I "should" update.

In the example you give, the ChangeLog.txt says
Code:
patches/packages/pkg-config-0.29.2-x86_64-1_slack14.2.txz:  Upgraded.
  This is a bugfix release, and is needed for some updates on slackbuilds.org
  to compile properly. Thanks to Willy Sudiarto Raharjo.
I don't see a security reason, there.
 
1 members found this post helpful.
Old 06-15-2017, 10:56 AM   #4
willysr
Senior Member
 
Registered: Jul 2004
Location: Jogja, Indonesia
Distribution: Slackware-Current
Posts: 4,661

Rep: Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784
pkg-config-0.29.2 is needed to build latest version of filezilla in SBo, so i asked Patrick after investigating whether the new version is safe to be included in -stable or not. It's purely bug fixes, so it wasn't listed in slackware-security mailing list.
 
1 members found this post helpful.
Old 06-16-2017, 08:44 AM   #5
drgibbon
Senior Member
 
Registered: Nov 2014
Distribution: Slackware64 15.0
Posts: 1,217

Rep: Reputation: 942Reputation: 942Reputation: 942Reputation: 942Reputation: 942Reputation: 942Reputation: 942Reputation: 942
Quote:
Originally Posted by ndr View Post
How does everyone keep up with the latest security news for Slackware?
RSS. If you wanted I'm sure you could filter/tag for security, etc.
 
1 members found this post helpful.
  


Reply

Tags
14.2


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Hardening, auditing, host security and network security on Slackware systems mralk3 Slackware 11 08-11-2015 03:53 PM
Am I DOA?.. Slackware install incomplete, can't boot. pmac_slack Linux - Newbie 11 09-21-2007 08:12 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 02:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration