LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Closed Thread
  Search this Thread
Old 05-28-2017, 04:31 AM   #2356
GazL
LQ Veteran
 
Registered: May 2008
Posts: 6,910

Rep: Reputation: 5026Reputation: 5026Reputation: 5026Reputation: 5026Reputation: 5026Reputation: 5026Reputation: 5026Reputation: 5026Reputation: 5026Reputation: 5026Reputation: 5026

With the default character encoding now being UTF8, maybe it's worth reevaluating whether to switch from man to man-db in order to avoid issues like this one.?
 
3 members found this post helpful.
Old 05-28-2017, 12:02 PM   #2357
Thom1b
Member
 
Registered: Mar 2010
Location: France
Distribution: Slackware
Posts: 485

Rep: Reputation: 339Reputation: 339Reputation: 339Reputation: 339
Quote:
Originally Posted by GazL View Post
With the default character encoding now being UTF8, maybe it's worth reevaluating whether to switch from man to man-db in order to avoid issues like this one.?
+1 for man-db.

It could be nice to include rxvt-unicode too.
 
Old 05-31-2017, 12:44 PM   #2358
CTM
Member
 
Registered: Apr 2004
Distribution: Slackware
Posts: 308

Rep: Reputation: 287Reputation: 287Reputation: 287
Is there a reason that new kernels haven't been issued for all stable releases of Slackware to mitigate CVE-2016-10229? It's a low-complexity network exploit that can lead to arbitrary code execution, so if Slackware is affected, it's worth patching.
 
Old 05-31-2017, 03:59 PM   #2359
kjhambrick
Senior Member
 
Registered: Jul 2005
Location: Round Rock, TX
Distribution: Slackware64 15.0 + Multilib
Posts: 2,159

Rep: Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512
CTM --

Not that I will be updating the official Slackware Kernels, but ...

I can't find the commit for CVE-2016-10229 in any recent ChangeLogs.

Do you know the Kernel Versions where it was merged ?

Thanks.

-- kjh
 
Old 05-31-2017, 04:23 PM   #2360
mats_b_tegner
Member
 
Registered: Nov 2009
Location: Gothenburg, Sweden
Distribution: Slackware
Posts: 946

Rep: Reputation: 649Reputation: 649Reputation: 649Reputation: 649Reputation: 649Reputation: 649
Quote:
Originally Posted by kjhambrick View Post
CTM --

Not that I will be updating the official Slackware Kernels, but ...

I can't find the commit for CVE-2016-10229 in any recent ChangeLogs.

Do you know the Kernel Versions where it was merged ?

Thanks.

-- kjh
For 4.4.x it was merged in 4.4.21:
https://www.spinics.net/lists/kernel/msg2508594.html

Last edited by mats_b_tegner; 05-31-2017 at 04:27 PM.
 
1 members found this post helpful.
Old 05-31-2017, 04:26 PM   #2361
kjhambrick
Senior Member
 
Registered: Jul 2005
Location: Round Rock, TX
Distribution: Slackware64 15.0 + Multilib
Posts: 2,159

Rep: Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512
CTM --

You made me look.

The most recent Official Slackware 14.2 Kernel is 4.4.38 and commit 197c949e7798fbf28cfadc69d9ca0c2abbf93191 appears to have already been included in net/ipv4/udp.c and in net/ipv6/udp.c ...

Looks like we're 'OK'

-- kjh
 
3 members found this post helpful.
Old 05-31-2017, 04:37 PM   #2362
bassmadrigal
LQ Guru
 
Registered: Nov 2003
Location: West Jordan, UT, USA
Distribution: Slackware
Posts: 8,792

Rep: Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656
Quote:
Originally Posted by CTM View Post
Is there a reason that new kernels haven't been issued for all stable releases of Slackware to mitigate CVE-2016-10229? It's a low-complexity network exploit that can lead to arbitrary code execution, so if Slackware is affected, it's worth patching.
14.2 isn't affected. Any kernels 4.4.30 and below are affected in the 4.4 series, and 14.2 now has 4.4.38.
14.1 isn't affected. Any kernels 3.10.90 and below are affected in the 3.10 series, and 14.1 now has 3.10.104.
14.0 isn't affected. Any kernels 3.2.82 and below are affected in the 3.2 series, and 14.0 now has 3.2.83.

SOURCE:
http://www.securityfocus.com/bid/97397
https://en.wikipedia.org/wiki/Slackware

However, it does seem that the kernels in 13.0, 13.1, and 13.37 are affected, but it doesn't look like there were ever any patches pushed by kernel developers to fix this issue. All those kernels were EOLed before this CVE came to light.
 
6 members found this post helpful.
Old 05-31-2017, 05:29 PM   #2363
kjhambrick
Senior Member
 
Registered: Jul 2005
Location: Round Rock, TX
Distribution: Slackware64 15.0 + Multilib
Posts: 2,159

Rep: Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512
bassmadrigal --

Thanks for the links.

I saw them earlier but you made me actually read the list

Now I see how the list 'works'.

-- kjh
 
Old 05-31-2017, 07:49 PM   #2364
USUARIONUEVO
Senior Member
 
Registered: Apr 2015
Posts: 2,338

Rep: Reputation: 930Reputation: 930Reputation: 930Reputation: 930Reputation: 930Reputation: 930Reputation: 930Reputation: 930
cmake-3.8.2
https://cmake.org/files/v3.8/cmake-3.8.2.tar.gz
 
Old 06-01-2017, 11:48 AM   #2365
kjhambrick
Senior Member
 
Registered: Jul 2005
Location: Round Rock, TX
Distribution: Slackware64 15.0 + Multilib
Posts: 2,159

Rep: Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512
Maybe a tad premature, but Perl 5.26.0 has been released.

-- kjh
 
1 members found this post helpful.
Old 06-01-2017, 01:30 PM   #2366
USUARIONUEVO
Senior Member
 
Registered: Apr 2015
Posts: 2,338

Rep: Reputation: 930Reputation: 930Reputation: 930Reputation: 930Reputation: 930Reputation: 930Reputation: 930Reputation: 930
Quote:
Originally Posted by kjhambrick View Post
Maybe a tad premature, but Perl 5.26.0 has been released.

-- kjh
Some security fixes
Code:
Security 
Removal of the current directory (".") from @INC
Escaped colons and relative paths in PATH
New -Di switch is now required for PerlIO debugging output
 
Old 06-01-2017, 04:01 PM   #2367
ttk
Senior Member
 
Registered: May 2012
Location: Sebastopol, CA
Distribution: Slackware64
Posts: 1,038
Blog Entries: 27

Rep: Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484
Quote:
Originally Posted by USUARIONUEVO View Post
Code:
Removal of the current directory (".") from @INC
This is known to break some modules in CPAN, though most such code has been fixed. qv "inc failed" rows here: http://cpan.simcop2387.info/test.html

Of particular interest there are DBD::SQLite and DBD::mysql.

That having been said, if v5.26.x is incorporated into Slackware before these modules have been fixed, I'd be willing to contribute some SlackBuilds for some of them which apply patches to fix the errant behavior.
 
2 members found this post helpful.
Old 06-02-2017, 03:15 AM   #2368
gmgf
Senior Member
 
Registered: Jun 2012
Location: Bergerac, France
Distribution: Slackware
Posts: 2,227

Rep: Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015
Quote:
Originally Posted by gmgf View Post
just infos for new sane-backends the SlackBuild need changes:

need --docdir, instead --with-docdir
need --with-usb, instead --enable-libusb_1_0

need to add this option:

--without-api-spec,

no build without this option on slack-current, (because need other tools who are not present in slackware) and probably api-spec is just used by developper.
 
1 members found this post helpful.
Old 06-02-2017, 07:48 AM   #2369
CTM
Member
 
Registered: Apr 2004
Distribution: Slackware
Posts: 308

Rep: Reputation: 287Reputation: 287Reputation: 287
Quote:
Originally Posted by bassmadrigal View Post
14.2 isn't affected. Any kernels 4.4.30 and below are affected in the 4.4 series, and 14.2 now has 4.4.38.
14.1 isn't affected. Any kernels 3.10.90 and below are affected in the 3.10 series, and 14.1 now has 3.10.104.
14.0 isn't affected. Any kernels 3.2.82 and below are affected in the 3.2 series, and 14.0 now has 3.2.83.

SOURCE:
http://www.securityfocus.com/bid/97397
https://en.wikipedia.org/wiki/Slackware

However, it does seem that the kernels in 13.0, 13.1, and 13.37 are affected, but it doesn't look like there were ever any patches pushed by kernel developers to fix this issue. All those kernels were EOLed before this CVE came to light.
Good call, thanks (also kjhambrick).
 
Old 06-02-2017, 08:28 AM   #2370
kjhambrick
Senior Member
 
Registered: Jul 2005
Location: Round Rock, TX
Distribution: Slackware64 15.0 + Multilib
Posts: 2,159

Rep: Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512
Quote:
Originally Posted by ttk View Post
This is known to break some modules in CPAN, though most such code has been fixed. qv "inc failed" rows here: http://cpan.simcop2387.info/test.html

Of particular interest there are DBD::SQLite and DBD::mysql.

That having been said, if v5.26.x is incorporated into Slackware before these modules have been fixed, I'd be willing to contribute some SlackBuilds for some of them which apply patches to fix the errant behavior.
Nice Link ! Thanks ttk !!

Yes, broken sqlite and mysql CPAN modules might indeed break a lot of code all over the world

And thanks for the offer to fix the SlackBuilds !

As always, I too, would also submit diffs for any of the few CPAN Modules that I use to the CPAN and SBo maintainers should I run into and fix issues with Perl 5.26.0 in -current.

-- kjh
 
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] how to show the current time at the top in the current shell Always ? rohitchauhan Linux - General 5 04-09-2014 03:05 PM
Slackware ARM (current) epic mistake: the current Android kernels are kicked out! Darth Vader Slackware 16 08-25-2013 04:36 PM
[SOLVED] setup fails on most current Slackware-current March 26, 2012 AlleyTrotter Slackware 15 04-09-2012 06:05 AM
Observation of Feb -current vs March -current Hangaber Slackware 14 03-12-2010 08:26 AM
cvs diff the most current and second last current version powah Linux - Software 1 03-30-2006 01:02 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 07:16 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration