|

楼主 |
发表于 2006-8-19 08:29:53
|
显示全部楼层
Post by ossymbian
大大没有看疯狂的石头吗?^_^
看了。我说的就是啊。你再好好看看。杜杰怎么说的。
Fri Aug 18 00:20:46 CDT 2006
a/aaa_elflibs-11.0.0-i486-8.tgz: Upgraded to the mm-1.4.2 library, patched
libtiff, upgraded to pcre-6.7 libraries, and included the recompiled
cups-1.1.23 and slang libraries.
a/cups-1.1.23-i486-4.tgz: Fixed broken es and fr man page symlinks.
d/git-1.4.2-i486-1.tgz: Upgraded to git-1.4.2.
kde/kdenetwork-3.5.4-i486-2.tgz: Patched a bug in kopete that could freeze
KDE under certain circumstances. Thanks to JaguarWan and Olivier Goffart.
l/libtiff-3.8.2-i486-2.tgz: Patched vulnerabilities in libtiff which were
found by Tavis Ormandy of the Google Security Team. These issues could
be used to crash programs linked to libtiff or possibly to execute code
as the program's user. A low risk command-line overflow in tiffsplit was
also patched.
For more details, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3459
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3460
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3461
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3462
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3463
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3464
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3465
(* Security fix *)
l/mm-1.4.2-i486-1.tgz: Upgraded to mm-1.4.2.
l/pcre-6.7-i486-1.tgz: Upgraded to pcre-6.7.
l/slang-2.0.6-i486-2.tgz: Fixed uncompressed manpage.
n/php-4.4.4-i486-1.tgz: Upgraded to php-4.4.4.
Some of the security issues fixed in this release include:
* Added missing safe_mode/open_basedir checks inside the error_log(),
file_exists(), imap_open() and imap_reopen() functions.
* Fixed possible open_basedir/safe_mode bypass in cURL extension.
* Fixed a buffer overflow inside sscanf() function.
(* Security fix *)
testing/packages/cups-1.2.2/cups-1.2.2-i486-2.tgz:
Removed /usr/man/man8/disable.8.gz symlink.
testing/packages/php-5.1.5/php-5.1.5-i486-1.tgz:
Upgraded to php-5.1.5.
Some of the security issues fixed in this release include:
* Added missing safe_mode/open_basedir checks inside the error_log(),
file_exists(), imap_open() and imap_reopen() functions.
* Fixed possible open_basedir/safe_mode bypass in cURL extension and on
PHP 5 with realpath cache.
* Fixed a buffer overflow inside sscanf() function.
(* Security fix *)
kernels/sata.i/: Recompiled with Silicon Image PATA support. (there was
a conflict before with this and the Sil SATA driver but it was fixed) |
|