Archive for October, 2010
Another glibc multilib update
Barely a week has passed, and we have yet another local root hole in glibc that needed patching. The Slackware ChangeLog said it like this: a/glibc-solibs-2.12.1-x86_64-3.txz: Rebuilt. Patched “The GNU C library dynamic linker will dlopen arbitrary DSOs during setuid loads.” This security issue allows a local attacker to gain root by specifying an unsafe […]
Posted: 29 October, 2010 in Slackware, Software.
Tags: exploit, glibc, multilib, root
Comments: 7
New multilib glibc packages fix local root hole
New glibc packages for Slackware arrived on the mirrors last night. They close a serious local root hole. From the ChangeLog: Patched “dynamic linker expands $ORIGIN in setuid library search path”. This security issue allows a local attacker to gain root if they can create a hard link to a setuid root binary. Thanks to […]
Posted: 21 October, 2010 in Slackware, Software.
Tags: exploit, glibc, multilib
Comments: 15
Slackware gcc multilib packages rebuilt
Pat Volkerding rebuilt the gcc 4.5.1 packages for Slackware-current, adding support for LTO (Link Time Optimization). Apparently that feature was requested a lot. Consequently I have rebuilt my multilib versions of the gcc-4.5.1 packages for Slackware64-current; get them at http://slackware.com/~alien/multilib/current/ (mirror site: http://taper.alienbase.nl/mirrors/people/alien/multilib/current/). Eric
Posted: 19 October, 2010 in Slackware, Software.
Tags: gcc, multilib.lto
Comments: 10
Compositing hard lock in KDE 4.5
People have written about their computer locking up with KDE 4.5.x in Slackware. These locks seem to be caused by the open source video drivers that are part of X.Org. These drivers incorrectly advertise some OpenGL capabilities when the KDE compositing manager queries them. As a result, the KDE window manager tries to enable non-working […]
Posted: 16 October, 2010 in Slackware, Software.
Tags: compositing, kde45, opengl, xorg
Comments: 6
New multilib packages for 64-bit Slackware-current
As you may have noticed already, there are interesting updates in the Slackware ChangeLog.txt ! A new kernel, and new glibc plus gcc packages means there has to be an updated set of multilib packages too or else you bunch of hybrid lovers would be left out in the cold. Well actually there is an […]
Posted: 13 October, 2010 in Slackware, Software.
Tags: gcc, glibc, multilib, x86_64
Comments: 7