LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Closed Thread
  Search this Thread
Old 11-15-2021, 08:30 PM   #1
max.b
Member
 
Registered: Feb 2013
Distribution: Debian 11, GNOME
Posts: 100

Rep: Reputation: 5
Exclamation Mr. Volkerding, please don't forget about security updates


Mr. Volkerding,

100 vulnerabilities are discovered in Firefox every year:

https://cve.mitre.org/cgi-bin/cvekey...eyword=firefox

A typical one is not limited to an OS or recent versions.

Slackware released 0 updates to it in 2021.

Updates to other packages seem similarly sparse.

This is a friendly reminder to release them if you got them.

Last edited by max.b; 11-15-2021 at 10:38 PM.
 
Old 11-15-2021, 09:01 PM   #2
RadicalDreamer
Senior Member
 
Registered: Jul 2016
Location: USA
Distribution: Slackware64-Current
Posts: 1,816

Rep: Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981
Thank you for sharing. Have a nice day.
 
Old 11-15-2021, 09:46 PM   #3
max.b
Member
 
Registered: Feb 2013
Distribution: Debian 11, GNOME
Posts: 100

Original Poster
Rep: Reputation: 5
Quote:
Originally Posted by RadicalDreamer View Post
Thank you for sharing. Have a nice day.
You are welcome. HAND.
 
Old 11-15-2021, 09:51 PM   #4
cwizardone
LQ Veteran
 
Registered: Feb 2007
Distribution: Slackware64-current with "True Multilib" and KDE4Town.
Posts: 9,111

Rep: Reputation: 7288Reputation: 7288Reputation: 7288Reputation: 7288Reputation: 7288Reputation: 7288Reputation: 7288Reputation: 7288Reputation: 7288Reputation: 7288Reputation: 7288
Quote:
Originally Posted by max.b View Post
.....Firefox....

Slackware released 0 updates to it in 2021.
On the off chance you are not a troll, but simply grossly misinformed, check the
change log for security updates.
http://slackware.oregonstate.edu/sla.../ChangeLog.txt

You do know how to use the search function in your browser?
 
4 members found this post helpful.
Old 11-15-2021, 10:13 PM   #5
RadicalDreamer
Senior Member
 
Registered: Jul 2016
Location: USA
Distribution: Slackware64-Current
Posts: 1,816

Rep: Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981
Quote:
Originally Posted by cwizardone View Post
On the off chance you are not a troll, but simply grossly misinformed, check the
change log for security updates.
http://slackware.oregonstate.edu/sla.../ChangeLog.txt

You do know how to use the search function in your browser?
That isn't entirely correct.
http://slackware.oregonstate.edu/sla.../ChangeLog.txt

He snagged one, good catch!
 
1 members found this post helpful.
Old 11-15-2021, 11:00 PM   #6
Gerard Lally
Senior Member
 
Registered: Sep 2009
Location: Leinster, IE
Distribution: Slackware, NetBSD
Posts: 2,181

Rep: Reputation: 1763Reputation: 1763Reputation: 1763Reputation: 1763Reputation: 1763Reputation: 1763Reputation: 1763Reputation: 1763Reputation: 1763Reputation: 1763Reputation: 1763
Quote:
Originally Posted by max.b View Post
Mr. Volkerding,

100 vulnerabilities are discovered in Firefox every year
In that case, shouldn't you be directing your sneer towards Mozilla instead?

Defective software is the responsibility of those who write it. As an aspiring professional programmer, you ought to know this. And, if certain FOSS businesses and organisations keep producing defective software, perhaps the solution is to stop shipping it, until they can come up with something that doesn't fall victim to two vulnerabilities every week of the year.
 
5 members found this post helpful.
Old 11-15-2021, 11:15 PM   #7
RadicalDreamer
Senior Member
 
Registered: Jul 2016
Location: USA
Distribution: Slackware64-Current
Posts: 1,816

Rep: Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981
I give up. People be handing out freebies like it is Epic Games Store. Time to bring out the popcorn!
https://www.youtube.com/watch?v=YfdLh0MHqKw
 
1 members found this post helpful.
Old 11-15-2021, 11:22 PM   #8
drgibbon
Senior Member
 
Registered: Nov 2014
Distribution: Slackware64 15.0
Posts: 1,221

Rep: Reputation: 943Reputation: 943Reputation: 943Reputation: 943Reputation: 943Reputation: 943Reputation: 943Reputation: 943
OP may be generally trolling around here, but in this case it's an absolutely solid point. According to packages.slackware.com, Slackware stable is still shipping Firefox 68.12.0, released August 25th 2020! If you care even a bit about security that is just not viable. For another example from stable see openssl-1.0.2u, which upstream hasn't supported for yonks: "All older versions (including 1.1.0, 1.0.2, 1.0.0 and 0.9.8) are now out of support and should not be used". It's been years since I considered Slackware stable to be an option, sad to see (especially when SBo remains tethered to it)!
 
5 members found this post helpful.
Old 11-16-2021, 01:56 AM   #9
max.b
Member
 
Registered: Feb 2013
Distribution: Debian 11, GNOME
Posts: 100

Original Poster
Rep: Reputation: 5
Quote:
Originally Posted by Gerard Lally View Post
In that case, shouldn't you be directing your sneer towards Mozilla instead?

Defective software is the responsibility of those who write it. As an aspiring professional programmer, you ought to know this. And, if certain FOSS businesses and organisations keep producing defective software, perhaps the solution is to stop shipping it, until they can come up with something that doesn't fall victim to two vulnerabilities every week of the year.

None of what you say is true.

The rule of thumb for widely used and well-tested software is 1 defect per 1kloc.

For browsers, servers, etc., many of these become vulnerabilities, if discovered. You do the math.

Lastly, no developer is required to fix outdated versions. That's an utterly delusional expectation.
 
Old 11-16-2021, 02:02 AM   #10
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,376

Rep: Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088
I still don't understand why a Debian user comes to post on a Slackware forum, with zero posts on the Debian forum...
Has the opposite ever happened?

 
3 members found this post helpful.
Old 11-16-2021, 02:14 AM   #11
Nobby6
Member
 
Registered: Jul 2012
Location: Sunshine Coast, Australia
Distribution: Slackware 64
Posts: 237
Blog Entries: 1

Rep: Reputation: 212Reputation: 212Reputation: 212
Wink

Quote:
Originally Posted by marav View Post
I still don't understand why a Debian user comes to post on a Slackware forum, with zero posts on the Debian forum...
Has the opposite ever happened?

yeah, and coz like debian neevvvvvvveeeeeerrrrrrrrrrrrrrr uses old software
 
Old 11-16-2021, 02:26 AM   #12
max.b
Member
 
Registered: Feb 2013
Distribution: Debian 11, GNOME
Posts: 100

Original Poster
Rep: Reputation: 5
Quote:
Originally Posted by Gerard Lally View Post
And, if certain FOSS businesses and organisations keep producing defective software, perhaps the solution is to stop shipping it, until they can come up with something that doesn't fall victim to two vulnerabilities every week of the year.

You will be using wget and then staring at the HTML in vim.

Because Chrome gets twice as many vulns discovered a year.

Not because it's worse though. See above.
 
Old 11-16-2021, 02:39 AM   #13
max.b
Member
 
Registered: Feb 2013
Distribution: Debian 11, GNOME
Posts: 100

Original Poster
Rep: Reputation: 5
Quote:
Originally Posted by Nobby6 View Post
yeah, and coz like debian neevvvvvvveeeeeerrrrrrrrrrrrrrr uses old software
I haven't found anything better, but it's far from flawless.
 
Old 11-16-2021, 02:46 AM   #14
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,376

Rep: Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088Reputation: 4088
Quote:
Originally Posted by max.b View Post
I haven't found anything better, but it's far from flawless.
And this is true for all major distributions, which everyone uses
 
1 members found this post helpful.
Old 11-16-2021, 02:47 AM   #15
chrisretusn
Senior Member
 
Registered: Dec 2005
Location: Philippines
Distribution: Slackware64-current
Posts: 2,975

Rep: Reputation: 1552Reputation: 1552Reputation: 1552Reputation: 1552Reputation: 1552Reputation: 1552Reputation: 1552Reputation: 1552Reputation: 1552Reputation: 1552Reputation: 1552
Quote:
Originally Posted by max.b View Post
Mr. Volkerding,

100 vulnerabilities are discovered in Firefox every year:

https://cve.mitre.org/cgi-bin/cvekey...eyword=firefox

A typical one is not limited to an OS or recent versions.

Slackware released 0 updates to it in 2021.
What are these then?

Code:
+--------------------------+
Thu Nov  4 04:43:31 UTC 2021
xap/mozilla-firefox-91.3.0esr-x86_64-1.txz:  Upgraded.
  This release contains security fixes and improvements.
  For more information, see:
    https://www.mozilla.org/en-US/firefox/91.3.0/releasenotes/
    https://www.mozilla.org/security/advisories/mfsa2021-49/
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38503
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38504
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38505
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38506
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38507
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38508
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38509
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38510
  (* Security fix *)
+--------------------------+
Wed Oct  6 00:02:15 UTC 2021
xap/mozilla-firefox-91.2.0esr-x86_64-1.txz:  Upgraded.
  This release contains security fixes and improvements.
  For more information, see:
    https://www.mozilla.org/en-US/firefox/91.2.0/releasenotes/
    https://www.mozilla.org/security/advisories/mfsa2021-45/
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38496
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38497
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38498
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32810
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38500
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38501
  (* Security fix *)
+--------------------------+
Mon Sep  6 18:55:54 UTC 2021
xap/mozilla-firefox-91.1.0esr-x86_64-1.txz:  Upgraded.
  This release contains security fixes and improvements.
  For more information, see:
    https://www.mozilla.org/en-US/firefox/91.1.0/releasenotes/
    https://www.mozilla.org/security/advisories/mfsa2021-40/
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38492
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38495
  (* Security fix *)
+--------------------------+
Tue Aug 17 20:08:40 UTC 2021
xap/mozilla-firefox-91.0.1-x86_64-1.txz: Upgraded.
       This release contains security fixes and improvements.
       For more information, see:
       https://www.mozilla.org/en-US/firefox/91.0.1/releasenotes/
       https://www.mozilla.org/security/advisories/mfsa2021-37/
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29991
       (* Security fix *)

+--------------------------+
Mon Aug 16 05:28:16 UTC 2021
xap/mozilla-firefox-91.0-x86_64-1.txz: Upgraded.
       New ESR release :-)
       This release contains security fixes and improvements.
       For more information, see:
       https://www.mozilla.org/en-US/firefox/91.0/releasenotes/
       https://www.mozilla.org/security/advisories/mfsa2021-33/
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29986
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29981
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29988
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29983
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29984
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29980
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29987
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29985
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29982
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29989
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29990
       (* Security fix *)
+--------------------------+
Mon Jul 12 19:17:02 UTC 2021
xap/mozilla-firefox-90.0-x86_64-1.txz: Upgraded.
       This release contains security fixes and improvements.
       For more information, see:
       https://www.mozilla.org/en-US/firefox/90.0/releasenotes/
       (* Security fix *)
+--------------------------+
Wed Jun 16 01:06:18 UTC 2021
xap/mozilla-firefox-89.0.1-x86_64-1.txz: Upgraded.
       This release contains security fixes and improvements.
       For more information, see:
       https://www.mozilla.org/en-US/firefox/89.0.1/releasenotes/
       (* Security fix *)
+--------------------------+
Wed May 5 19:56:53 UTC 2021
xap/mozilla-firefox-88.0.1-x86_64-1.txz: Upgraded.
       This release contains security fixes and improvements.
       For more information, see:
       https://www.mozilla.org/en-US/firefox/88.0.1/releasenotes/
       https://www.mozilla.org/security/advisories/mfsa2021-20/
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29953
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29952
       (* Security fix *)
+--------------------------+
Mon Apr 19 21:40:04 UTC 2021
xap/mozilla-firefox-88.0-x86_64-1.txz: Upgraded.
       This release contains security fixes and improvements.
       For more information, see:
       https://www.mozilla.org/en-US/firefox/88.0/releasenotes/
       https://www.mozilla.org/security/advisories/mfsa2021-16/
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23994
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23995
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23996
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23997
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23998
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23999
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24000
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24001
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24002
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29945
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29944
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29946
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29947
       (* Security fix *)
+--------------------------+
Wed Mar 24 04:29:15 UTC 2021
xap/mozilla-firefox-87.0-x86_64-1.txz: Upgraded.
       This release contains security fixes and improvements.
       For more information, see:
       https://www.mozilla.org/en-US/firefox/87.0/releasenotes/
       https://www.mozilla.org/en-US/security/advisories/mfsa2021-10/
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23981
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23982
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23983
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23984
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23985
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23986
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23987
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23988
       (* Security fix *)
+--------------------------+
Mon Feb 22 20:58:01 UTC 2021
xap/mozilla-firefox-78.8.0esr-x86_64-1.txz: Upgraded.
       This release contains security fixes and improvements.
       For more information, see:
       https://www.mozilla.org/en-US/firefox/78.8.0/releasenotes/
       (* Security fix *)
+--------------------------+
Fri Feb 5 21:18:59 UTC 2021
xap/mozilla-firefox-78.7.1esr-x86_64-1.txz: Upgraded.
       This release contains a security fix.
       For more information, see:
       https://www.mozilla.org/en-US/firefox/78.7.1/releasenotes/
       https://www.mozilla.org/en-US/security/advisories/mfsa2021-06/#MOZ-2021-0001
       (* Security fix *)
+--------------------------+
Mon Jan 25 20:42:50 UTC 2021
xap/mozilla-firefox-78.7.0esr-x86_64-1.txz: Upgraded.
       This release contains security fixes and improvements.
       For more information, see:
       https://www.mozilla.org/en-US/firefox/78.7.0/releasenotes/
       (* Security fix *)
+--------------------------+
Wed Jan 6 22:59:38 UTC 2021
xap/mozilla-firefox-78.6.1esr-x86_64-1.txz: Upgraded.
       This release contains a security fix:
       A malicious peer could have modified a COOKIE-ECHO chunk in a SCTP packet
       in a way that potentially resulted in a use-after-free. We presume that with
       enough effort it could have been exploited to run arbitrary code.
       For more information, see:
       https://www.mozilla.org/en-US/firefox/78.6.1/releasenotes/
       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16044
       (* Security fix *)
 
2 members found this post helpful.
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Mr. Volkerding please release 15.0 as soon as possible even sooner igadoter Slackware 517 02-04-2022 07:01 AM
[SOLVED] Mr. Volkerding, Mr. Hameleers, there is no more GeoIP for KTorrent. Please, disable the support for it, both in -current and Plasma5! LuckyCyborg Slackware 10 03-22-2019 02:22 PM
Please a question about Mr Patrick Volkerding afreitascs Slackware 4 05-17-2012 07:55 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 01:24 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration