LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 02-27-2023, 08:41 AM   #211
elcore
Senior Member
 
Registered: Sep 2014
Distribution: Slackware
Posts: 1,752

Rep: Reputation: Disabled

Grub2 explicitly requires a "net" module, before the kernel loads, so it may bypass firewall and/or any kernel level mitigations.
The module contains dns/dhcp/ipv4/ipv6/icmp4/icmp6 among others. Figured it's intended, found no way to compile without it, and ultimately had to deface the offending module.
 
1 members found this post helpful.
Old 03-01-2023, 02:57 PM   #212
Didier Spaier
LQ Addict
 
Registered: Nov 2008
Location: Paris, France
Distribution: Slint64-15.0
Posts: 11,055

Rep: Reputation: Disabled
Missing so libraries and header files in the reiserfsprogs package prevents btrfs-convert to convert from reiserfs to btrfs.

In the configure log of btrfs-progs 6.2 6.1.3:
checking for reiserfscore >= 3.6.27... no

This prevents to convert a file system from reiserfs to btrfs as displayed in the configure summary:
btrfs-convert: yes (ext2)

This is because reiserfsprogs 3.6.27 is built by Slackware with the option "--disable-shared" and the libraries and headers are not shipped in the package.

PS this is not a security issue, but I am not sure this one deserves its own thread.

PPS Same issue building 6.2 but the configure log just says:
checking for REISERFS... no

Last edited by Didier Spaier; 03-01-2023 at 03:21 PM.
 
1 members found this post helpful.
Old 03-01-2023, 03:48 PM   #213
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,323

Original Poster
Rep: Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039
Quote:
Originally Posted by Didier Spaier View Post
PS this is not a security issue, but I am not sure this one deserves its own thread.
Didier,
Next time, "request for current" or, better, directly in my Changelog thread ;-)
 
Old 03-01-2023, 03:55 PM   #214
Didier Spaier
LQ Addict
 
Registered: Nov 2008
Location: Paris, France
Distribution: Slint64-15.0
Posts: 11,055

Rep: Reputation: Disabled
Quote:
Originally Posted by marav View Post
Didier,
Next time, "request for current" or, better, directly in my Changelog thread ;-)
Well, actually this issue also exists in Slackware 15.0 Maybe I should have opened a new thread, as I don't see a thread "issues" and there is not bugzilla.

PS: anyway, already solved..

Last edited by Didier Spaier; 03-01-2023 at 03:57 PM.
 
Old 03-01-2023, 03:57 PM   #215
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,323

Original Poster
Rep: Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039
Quote:
Originally Posted by Didier Spaier View Post
Well, actually this issue also exists in Slackware 15.0 Maybe I should have opened a new thread, as I don't see a thread "issues" and there is not bugzilla.
ok, so this one seems fine
Anyway, this is one of the threads I think Pat is reading closely
 
Old 03-04-2023, 04:34 PM   #216
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,323

Original Poster
Rep: Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039
Python

CVE-2023-24329
Code:
An issue in the urllib.parse component of Python before v3.11 allows attackers to bypass blocklisting 
methods by supplying a URL that starts with blank characters.
https://www.cve.org/CVERecord?id=CVE-2023-24329
 
Old 03-10-2023, 05:17 AM   #217
GazL
LQ Veteran
 
Registered: May 2008
Posts: 6,895

Rep: Reputation: 5015Reputation: 5015Reputation: 5015Reputation: 5015Reputation: 5015Reputation: 5015Reputation: 5015Reputation: 5015Reputation: 5015Reputation: 5015Reputation: 5015
Guys, I just noticed that
https://imagemagick.org/archive/rele...7.1.1-1.tar.xz
doesn't match the contents of
https://imagemagick.org/archive/rele....1.1-1.tar.bz2

I've downloaded both and done a diff -Nurp and there are a lot of differences.
Also, the timestamp of the xz file on the archive doesn't match those of the other tarballs.

I've dropped ImageMagicks security folks a note so they can check it out, and it may be some sort of error rather than anything malicious, but in the meantime, a little caution might be in order.

There's already a 7.1.1-2, so maybe going to that might be prudent.

update: nevermind I mistyped the directory path on the diff file and instead of throwing an error it treated all the files like they were new, which is why there are differences showing.

Contents of the tarballs are identical, but the timestamp has changed and the sha256sum is different to what it was earlier so it does look like it was repackaged later than the other files.

Last edited by GazL; 03-10-2023 at 06:48 AM.
 
2 members found this post helpful.
Old 03-16-2023, 05:57 PM   #218
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,323

Original Poster
Rep: Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039
squashfs-tools

I noticed manpages are installed locally in /usr/local/man/man1

Here is the fix:
Code:
--- squashfs-tools.SlackBuild   2022-09-06 20:27:30.638132064 +0200
+++ squashfs-tools.SlackBuild.1 2023-03-16 23:53:22.826295781 +0100
@@ -101,7 +101,9 @@
   COMP_DEFAULT="xz" || exit 1
 
 # Install:
-make install INSTALL_DIR=$PKG/usr/bin || exit 1
+make install \
+    INSTALL_DIR=$PKG/usr/bin \
+    INSTALL_MANPAGES_DIR=$PKG/usr/man/man1 || exit 1
 
 # Fix (if needed) broken symlinks:
 ( cd $PKG/usr/bin

Last edited by marav; 03-16-2023 at 05:58 PM.
 
3 members found this post helpful.
Old 03-20-2023, 06:58 AM   #219
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,323

Original Poster
Rep: Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039
Vim

CVE-2023-1264
NULL pointer dereference issue in utfc_ptr2len
https://www.cve.org/CVERecord?id=CVE-2023-1264

CVE-2023-1175
Incorrect Calculation of Buffer Size
https://www.cve.org/CVERecord?id=CVE-2023-1175

CVE-2023-1170
Heap-based Buffer Overflow
https://www.cve.org/CVERecord?id=CVE-2023-1170
 
1 members found this post helpful.
Old 03-23-2023, 09:18 AM   #220
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,323

Original Poster
Rep: Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039
Tar

CVE-2022-48303
Code:
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. 
Exploitation to change the flow of control has not been demonstrated. 
The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.
https://www.cve.org/CVERecord?id=CVE-2022-48303

Patch:
https://git.savannah.gnu.org/cgit/ta...27ea40d794ede8

Last edited by marav; 03-23-2023 at 10:23 AM. Reason: upstream patch instead of fedora's one
 
1 members found this post helpful.
Old 03-25-2023, 09:11 PM   #221
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,323

Original Poster
Rep: Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039
...

Last edited by marav; 03-25-2023 at 09:13 PM.
 
1 members found this post helpful.
Old 03-27-2023, 10:30 AM   #222
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,323

Original Poster
Rep: Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039
kwin

Bug:
Code:
kwin_wayland crashes in KWaylandServer::OutputInterface::handle() when disabling and re-enabling 
a screen and letting it get turned off via power management
https://bugs.kde.org/show_bug.cgi?id=466346

Patch:
Code:
dpms: Make sure we are not calling the interface after the output is gone
https://invent.kde.org/plasma/kwin/-/commit/737af922
 
1 members found this post helpful.
Old 03-30-2023, 06:34 PM   #223
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,323

Original Poster
Rep: Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039
openssl 3.1.0

CVE-2023-0465
Code:
Invalid certificate policies in leaf certificates are silently ignored
Git commit:
https://git.openssl.org/gitweb/?p=op...e4a9965ea61d5c

Fixed in OpenSSL 3.1.1

CVE-2023-0466
Code:
Certificate policy check not enabled
Git commit:
https://git.openssl.org/gitweb/?p=op...462f5457aab061

Fixed in OpenSSL 3.1.1

https://www.openssl.org/news/vulnerabilities.html

Last edited by marav; 03-30-2023 at 06:36 PM.
 
1 members found this post helpful.
Old 04-03-2023, 07:08 AM   #224
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,323

Original Poster
Rep: Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039
xorg-server

CVE-2023-1393
Code:
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. 
If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling 
pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
https://www.cve.org/CVERecord?id=CVE-2023-1393

Affected at: 21.1.8

Ref:
https://bugzilla.redhat.com/show_bug.cgi?id=2180288
 
1 members found this post helpful.
Old 04-04-2023, 08:16 AM   #225
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,323

Original Poster
Rep: Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039Reputation: 4039
Quote:
Originally Posted by marav View Post
kwin

Bug:
Code:
kwin_wayland crashes in KWaylandServer::OutputInterface::handle() when disabling and re-enabling 
a screen and letting it get turned off via power management
https://bugs.kde.org/show_bug.cgi?id=466346

Patch:
Code:
dpms: Make sure we are not calling the interface after the output is gone
https://invent.kde.org/plasma/kwin/-/commit/737af922
Fixed in 5.27.4
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Draft data loss mitigation method for spanned LVM (would like suggestions) ACiD GRiM Linux - General 1 10-18-2009 03:17 AM
LXer: This week at LWN: Interrupt mitigation in the block layer LXer Syndicated Linux News 0 08-25-2009 12:20 PM
Stateful Firewall/IDS/Filter/DDoS Mitigation - What Would You Advise? Xolo Linux - Security 17 07-27-2006 11:21 PM
Phục hồi dữ liệu bị mất???, cứ pollsite General 1 06-27-2005 12:39 PM
Gotta love those ٱٱٱٱٱٱٱ&# iLLuSionZ Linux - General 5 11-18-2003 07:14 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 04:11 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration