New mozilla-firefox packages are available for Slackware 10.2, 11.0,
12.0, and 12.1 to fix security issues.
More details about the issues may be found on the Mozilla site:
http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox
New bind packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2,
11.0, 12.0, 12.1, and -current to address a security problem.
More details may be found at the following links:
http://www.isc.org/sw/bind/bind-security.php
http://www.kb.cert.org/vuls/id/800113
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447
New ruby packages are available for Slackware 11.0, 12.0, 12.1, and -current to
fix security issues.
More details about this issue may be found in the Common
Vulnerabilities and Exposures (CVE) database:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2662
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2663
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2664
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2725
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2726
New samba packages are available for Slackware 10.0, 10.1, 10.2, 11.0, 12.0,
12.1, and -current to fix a security issue:
"Specifically crafted SMB responses can result in a heap overflow in the
Samba client code. Because the server process, smbd, can itself act as
a client during operations such as printer notification and domain
authentication, this issue affects both Samba client and server
installations."
New rdesktop packages are available for Slackware 11.0, 12.0, 12.1,
and -current to fix a security issue caused by using rdesktop to connect
to a malicious or compromised RDP server.
More details about this issue may be found in the Common
Vulnerabilities and Exposures (CVE) database:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1801
New php packages are available for Slackware 10.2, 11.0, 12.0, 12.1,
and -current to fix security issues.
Note that PHP5 is not the default PHP for Slackware 10.2 or 11.0 (those use
PHP4), so if your PHP code is not ready for PHP5, don't upgrade until it is
or you'll (by definition) run into problems.
More details about one of the issues may be found in the Common
Vulnerabilities and Exposures (CVE) database:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0599
New mozilla-thunderbird packages are available for Slackware 10.2, 11.0, 12.0,
12.1, and -current to fix security issues, including crashes that can corrupt
memory, as well as a JavaScript privilege escalation and arbitrary code
execution flaw.
More details about these issues may be found here:
http://www.mozilla.org/projects/security/known-vulnerabilities.html#thunderbird