LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 04-17-2015, 08:47 PM   #196
frankiej
LQ Newbie
 
Registered: Feb 2013
Distribution: Fedora
Posts: 29

Rep: Reputation: 24

Quote:
Originally Posted by pataphysician View Post
So are people saying that firefox 31.5.0 ESR is a reasonably secure version of firefox to run on my 14.1 Slackware, and that there is no overly compelling reason for this to be updated.
There are five vulnerabilities corrected in 31.6.0 ESR. Two of them are listed as critical. However, one of the critical ones only applies if you are using the Fluendo mp3 plugin. The other just refers to general memory safety hazards.

I guess it depends on your usage as to whether or not you should be concerned about any of the vulnerabilities.
 
Old 04-17-2015, 10:54 PM   #197
pataphysician
Member
 
Registered: Oct 2012
Posts: 77

Rep: Reputation: Disabled
Quote:
Originally Posted by frankiej View Post
There are five vulnerabilities corrected in 31.6.0 ESR. Two of them are listed as critical. However, one of the critical ones only applies if you are using the Fluendo mp3 plugin. The other just refers to general memory safety hazards.

I guess it depends on your usage as to whether or not you should be concerned about any of the vulnerabilities.
your missing the two critical and interrelated vulnerabilities fixed in 31.5.2 and 31.5.3 that have not been updated in 14.1 as 14.1 is on version 31.5.0, they are right on the webpage you linked. The fix in 31.5.2 was released 28 days ago.

Those vulnerabilities actually have known exploits, and require no user interaction, work on stock firefox and the only way you can protect yourself without updating, is to turn of javascript completely, NoScript might not help you either because the second exploit can make firefox think the script has the same origin as another allowed script you might be running. I'm not completely sure turning of javascript completely would be adequate.

Last edited by pataphysician; 04-17-2015 at 11:08 PM.
 
3 members found this post helpful.
Old 04-18-2015, 12:58 AM   #198
lems
Member
 
Registered: May 2004
Distribution: BSD
Posts: 269

Rep: Reputation: 119Reputation: 119
Quote:
Originally Posted by dugan View Post
Who maintains the ARM and S/390 distributions?
ARM is, I think, maintained by Stuart Winter (drmozes). For S/390, see this. But S/390 seems dead, last -current updates were in 2009.

Last edited by lems; 04-18-2015 at 12:59 AM.
 
1 members found this post helpful.
Old 04-18-2015, 07:07 AM   #199
frankiej
LQ Newbie
 
Registered: Feb 2013
Distribution: Fedora
Posts: 29

Rep: Reputation: 24
Quote:
Originally Posted by pataphysician View Post
your missing the two critical and interrelated vulnerabilities fixed in 31.5.2 and 31.5.3 that have not been updated in 14.1 as 14.1 is on version 31.5.0, they are right on the webpage you linked. The fix in 31.5.2 was released 28 days ago.
Thanks. I completely ignored the post indicating 14.1 was on 31.5.0. I just made the (bad) assumption it was on the latest of the 31.5 line.
 
Old 04-18-2015, 03:06 PM   #200
re_nelson
Member
 
Registered: Oct 2011
Location: Texas, USA
Distribution: LFS-SVN, Gentoo~amd64, CentOS-7, Slackware64-current, FreeBSD-11.1, Arch
Posts: 229

Rep: Reputation: Disabled
Quote:
Originally Posted by bassmadrigal View Post
I think the only thing (s)he nailed is his/her incorrect belief that (s)he is owed updates. Where does (s)he have a contract with Pat to provide updates?

We are all at the gracious mercy of Patrick. We all want updates, but that doesn't mean that we are entitled to them. To quote the great (albeit a bit crazy) Frank Underwood, "You are entitled to nothing!"
If for no other reason than citing Congressman/VP/President Francis Underwood (FU), this post merits a laurel and hardy +999!
 
Old 04-18-2015, 05:08 PM   #201
Richard Cranium
Senior Member
 
Registered: Apr 2009
Location: McKinney, Texas
Distribution: Slackware64 15.0
Posts: 3,858

Rep: Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225
Quote:
Originally Posted by cwizardone View Post
There are those who have read this thread and know what I was trying to say without having to be so blunt as to spell it out. We've been through this before and I don't feel like having to explain it again, but to give you a clue, it is about a trait some people seem to be born with and others can learn, but like commonsense, it seems to be in short supply these days.
You don't feel like explaining your position, but you do feel like whining about it.

Passive aggressive behavior is not in short supply in your case. If you do have something to say, say it.
 
1 members found this post helpful.
Old 04-18-2015, 06:20 PM   #202
cwizardone
LQ Veteran
 
Registered: Feb 2007
Distribution: Slackware64-current with "True Multilib" and KDE4Town.
Posts: 9,126

Rep: Reputation: 7297Reputation: 7297Reputation: 7297Reputation: 7297Reputation: 7297Reputation: 7297Reputation: 7297Reputation: 7297Reputation: 7297Reputation: 7297Reputation: 7297
Oh, I did, D.H.
You might have read that far, by now.
 
Old 04-18-2015, 06:31 PM   #203
RandomTroll
Senior Member
 
Registered: Mar 2010
Distribution: Slackware
Posts: 1,971

Rep: Reputation: 271Reputation: 271Reputation: 271
He's spending his $2.8 billion.
 
Old 04-18-2015, 08:27 PM   #204
hitest
Guru
 
Registered: Mar 2004
Location: Canada
Distribution: Debian, Void, Slackware, VMs
Posts: 7,342

Rep: Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746
I'm looking forward to the updates. I predict that 14.2 will be first rate.
 
Old 04-19-2015, 05:00 AM   #205
willysr
Senior Member
 
Registered: Jul 2004
Location: Jogja, Indonesia
Distribution: Slackware-Current
Posts: 4,670

Rep: Reputation: 1786Reputation: 1786Reputation: 1786Reputation: 1786Reputation: 1786Reputation: 1786Reputation: 1786Reputation: 1786Reputation: 1786Reputation: 1786Reputation: 1786
Please be patient.
When the big update arrived, you will understand why it took so long to brew all those packages.
And i believe we all will be pleased with the smooth update in -current just like what we had so far. It's all due to carefull testing by Pat before he released it to public.

I'm sure it's worth to wait
 
13 members found this post helpful.
Old 04-19-2015, 05:41 AM   #206
ReaperX7
LQ Guru
 
Registered: Jul 2011
Location: California
Distribution: Slackware64-15.0 Multilib
Posts: 6,558
Blog Entries: 15

Rep: Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097
Not only that, but look at the queue of package updates that Robby pushed into the inbox as well. If you followed the massive submission of packages Bartgymnast started and everyone tracked down, the list was a full mile long of packages that could be submitted and used in 14.2. Plus many packages have been forked out into new versions like procps-ng, ConsoleKit2, etc. that are going to need some serious testing prior to finalization.

Trust those of us who have private repos when we say 14.2 when released is going to not just be great, but equally a groundbreaking release of Slackware worth the wait.
 
3 members found this post helpful.
Old 04-19-2015, 07:48 AM   #207
genss
Member
 
Registered: Nov 2013
Posts: 744

Rep: Reputation: Disabled
Pat's busy backporting kdbus to 3.14, leave him alone.
 
1 members found this post helpful.
Old 04-19-2015, 02:07 PM   #208
STDOUBT
Member
 
Registered: May 2010
Location: Stumptown
Distribution: Slackware64
Posts: 583

Rep: Reputation: 242Reputation: 242Reputation: 242
I would feel amiss if I did not clarify what I meant by cwizardone "nailed it".
https://www.linuxquestions.org/quest...ml#post5348142
I meant that he was right: pretty much the entire distribution does need recompiling/re-working.
The "blame" lies with upstream/freedesktop.org's sloppy work, apparently.
My apologies to cwizardone and everyone else for not making that clear.
FWIW, IMO, putting up with a rough patch like this in Slackware, beats the hell out of living with a constant rash in some other distro.
Also, I think it would help if people stopped looking to Patrick as a "leader".
I prefer to think of him as a mysterious wizard who makes my computer come to life.
We all know there are many places upstream that push half-baked, hipster crap, and the fact that out BDFL consistently wrests sanity from their madness speaks for itself.
 
5 members found this post helpful.
Old 04-19-2015, 02:57 PM   #209
ReaperX7
LQ Guru
 
Registered: Jul 2011
Location: California
Distribution: Slackware64-15.0 Multilib
Posts: 6,558
Blog Entries: 15

Rep: Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097
Quote:
Originally Posted by genss View Post
Pat's busy backporting kdbus to 3.14, leave him alone.
I'd like to give kdbus a backport, but the output might not be favorable.
 
Old 04-19-2015, 04:33 PM   #210
zbreaker
Member
 
Registered: Dec 2008
Location: New York
Distribution: Slack -current, siduction
Posts: 253

Rep: Reputation: 29
Quote:
Originally Posted by willysr View Post
Please be patient.
When the big update arrived, you will understand why it took so long to brew all those packages.
And i believe we all will be pleased with the smooth update in -current just like what we had so far. It's all due to carefull testing by Pat before he released it to public.

I'm sure it's worth to wait
Thanks Willy!

I quietly await greatness for my -current install.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
insulting patrick Nadim Slackware 4 08-12-2005 01:20 PM
What's the latest on Patrick? slackermike Slackware 5 06-09-2005 11:31 AM
Treatment for help Patrick V. Tony_Alrod Slackware 2 12-20-2004 12:49 PM
[Slackware] Patrick needs Help!!! scoban Linux - Software 1 11-16-2004 04:53 PM
Welcome Patrick Volkerding jeremy Slackware 29 01-07-2003 01:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 05:29 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration