LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 08-02-2003, 08:00 AM   #1
phoeniXflame
Member
 
Registered: Feb 2003
Location: Somewhere, UK
Distribution: Slack, OpenBSD, Debian, SuSE
Posts: 189

Rep: Reputation: 30
Exclamation Slackware Security Update: KDE packages updated


I thought this might be helpful for everyone who isnt subscribed to the mailing lists ...

Quote:
[slackware-security] KDE packages updated (SSA:2003-213-01)

New KDE packages are available for Slackware 9.0. These address a
security issue where Konqueror may leak authentication credentials.


Here are the details from the Slackware 9.0 ChangeLog:
+--------------------------+
Fri Aug 1 15:15:51 PDT 2003
patches/packages/kde/*: Upgraded to KDE 3.1.3.
Note that this update addresses a security problem in Konqueror which may
cause authentication credentials to be leaked to an unintended website
through the HTTP-referer header when they have been entered into Konqueror
as a URL of the form:
http://userassword@host/
For more information about this issue, please see the KDE advisory:
http://www.kde.org/info/security/adv...20030729-1.txt
We recommend that sites running KDE install this update.
(* Security fix *)
patches/packages/kdei/*: New internationalization packages for KDE 3.1.3.
+--------------------------+


WHERE TO FIND THE NEW PACKAGES:
+-----------------------------+

Updated packages for Slackware 9.0:
ftp://ftp.slackware.com/pub/slackwar...ages/kde/*.tgz
ftp://ftp.slackware.com/pub/slackwar...ges/kdei/*.tgz

These packages are signed with our GPG key:
http://slackware.com/gpg-key


INSTALLATION INSTRUCTIONS:
+------------------------+

Upgrade using upgradepkg (as root):
upgradepkg *.tgz


+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com
 
Old 08-02-2003, 09:45 AM   #2
BearClaw
Member
 
Registered: Jun 2003
Location: USA
Distribution: Slackware-Current
Posts: 90

Rep: Reputation: 15
I have the "current" kde pkg's installed, i.e. kde-3.1.2-i486 series. These pkg's are i386 at the slack-9 mirrors, although they are kde-3.1.3.

I was wondering if I should get the 3.1.3 series, or will the 3.1.3-kde pkg's be released for 'slack-current'?

Thanks, BC
 
Old 08-04-2003, 09:03 AM   #3
Waldi
Member
 
Registered: Apr 2003
Location: Warsaw, Poland
Distribution: Slackware current
Posts: 133

Rep: Reputation: 15
Warning !!!
I downloaded KDE3.1.3 from one of KDE's mirrors (Slack *.tgz version), upgraded and reboot. And it occurs, that CUPS support is missing in kdelibs!!! Luckily I had kdelibs from 3.1.2 and I copied missing files from that manually. It works, but I wasted some time to workout, what's going on.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Updated GNOME 2.8.2 packages for Linux Slackware 10.1 LiNuCe Slackware 23 03-02-2005 09:39 AM
update distribution iso files with updated packages hipermc2 Linux - General 2 01-19-2005 11:02 AM
Problem after Kde security update Obscure Slackware 2 10-12-2004 05:10 AM
Slackware Security Update: GDM security update phoeniXflame Slackware 2 08-26-2003 04:21 PM
Slackware Security Update: sudo trickykid Slackware 3 05-01-2002 10:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 12:20 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration