Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Core i7 8700K vs. Ryzen 7 2700X With Rise of The Tomb Raider On Linux and more
· OpenVPN Security Update (SSA:2018-116-01) for Slackware
· Red Hat Enterprise Linux 6.10 Beta released
· ZSH Security Update for openSUSE
· Ubuntu 18.04 LTS (Bionic Beaver) released
· Unbreakable Enterprise Kernel Security Update for Oracle Linux 6 and 7
· Drupal7 Security Update for Debian 7 LTS
· 4GHz CPU Battle: AMD 2nd-Gen Ryzen vs. Intel 8th-Gen Core and more
· BuildStream 1.1.3 released
· Windows 10 Insider Preview Build 17655 for Skip Ahead

Upcoming News
· Samsung 860 Pro SSD Review @ Vortez
· Raijintek Orcus 240 @ TechPowerUp
· Team Group Cardea Zero 240 GB @ TechPowerUp
· Guru3D Rig of the Month - January 2018
· Cooler Master MK750 Review @ Vortez
· Seagate Skyhawk 10TB SATA III HDD Review
· Vulkan Continues To Show Its Gaming Strength On Low-End Hardware
· Seagate IronWolf ST12000VN0007 12TB Hard Drive Review @ APH Networks
· Sennheiser Game One @ TechPowerUp
· be quiet! Straight Power 11 1000W Power Supply Review

Linux Compatibility
· Brother DCP-L2540DN
· Sound Blaster E5
· WD Elements 500GB external hard drive
· Canon D660U Flatbad scanner
· Umax Astra 4500 USB Scanner
· Logitech QuickCam Pro 4000
· Dell Latitude E6420
· Creative Sound Blaster Z
· Photosmart 5520
· TB-5300 Slimline Design Tablet

New Forum Topics
· Dale
by: Dale Blinco
on: 2018-02-05 00:26
1 replies, 1228 views

· modem driver needed
by: jongiffen777
on: 2017-12-13 11:11
1 replies, 2413 views

· Need a decent browser for XP Pro!
by: percy
on: 2017-12-05 11:02
2 replies, 4295 views

· Comodo Time Machine + Faronics Deep Freeze
by: Jabberwocky
on: 2017-11-15 23:17
1 replies, 2899 views

· Linux compatablity
by: ibme
on: 2017-10-04 18:05
1 replies, 4815 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android
· Oracle Linux
· Arch Linux

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » November 2005 » curl/wget (SSA:2005-310-01)

curl/wget (SSA:2005-310-01)

Posted by Philipp Esselbach on: 11/07/2005 01:49 AM [ Print | 0 comment(s) ]

New curl packages are available for Slackware 9.1, 10.0, 10.1, 10.2, and -current, and new wget packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, and -current. These address a buffer overflow in NTLM handling which may present a security problem, though no public exploits are known at this time.

More details about this issue may be found in the Common Vulnerabilities and Exposures (CVE) database:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3185




Here are the details from the Slackware 10.2 ChangeLog:
+--------------------------+
patches/packages/curl-7.12.2-i486-2.tgz: Patched. This addresses a buffer
overflow in libcurl's NTLM function that could have possible security
implications.
For more details, see:
http://curl.haxx.se/docs/security.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3185
(* Security fix *)
patches/packages/wget-1.10.2-i486-1.tgz: Upgraded to wget-1.10.2.
This addresses a buffer overflow in wget's NTLM handling function that could
have possible security implications.
For more details, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3185
(* Security fix *)
+--------------------------+


Where to find the new packages:
+-----------------------------+

Updated package for Slackware 8.1:
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/wget-1.10.2-i386-1.tgz

Updated package for Slackware 9.0:
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/wget-1.10.2-i386-1.tgz

Updated packages for Slackware 9.1:
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/curl-7.10.7-i486-2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/wget-1.10.2-i486-1.tgz

Updated packages for Slackware 10.0:
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/curl-7.12.2-i486-2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/wget-1.10.2-i486-1.tgz

Updated packages for Slackware 10.1:
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/curl-7.12.2-i486-2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/wget-1.10.2-i486-1.tgz

Updated packages for Slackware 10.2:
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/curl-7.12.2-i486-2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/wget-1.10.2-i486-1.tgz

Updated packages for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/curl-7.12.2-i486-2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/wget-1.10.2-i486-1.tgz


MD5 signatures:
+-------------+

Slackware 8.1 package:
27cd415d071ec3e397108262e0e19dbd wget-1.10.2-i386-1.tgz

Slackware 9.0 package:
409ba702f5be1ef48cd82465d97b97a3 wget-1.10.2-i386-1.tgz

Slackware 9.1 packages:
3901bd669c514ebc3d921a3363a88346 curl-7.10.7-i486-2.tgz
e96a319ca40c7017718b9bcdfe9f0ad7 wget-1.10.2-i486-1.tgz

Slackware 10.0 packages:
e8475472a1bd8700aaca2186ebd4701f curl-7.12.2-i486-2.tgz
ebfe7ed62214e55e43d08e46cba08feb wget-1.10.2-i486-1.tgz

Slackware 10.1 packages:
5c9158d6d48a9c6f857355b498eae68f curl-7.12.2-i486-2.tgz
e304815a073f47ae744c93eec7f70efa wget-1.10.2-i486-1.tgz

Slackware 10.2 packages:
6596c737f2814c96ba9d3be7434f036d curl-7.12.2-i486-2.tgz
59747d7f14d8dc76b0fcad2a8a803e03 wget-1.10.2-i486-1.tgz

Slackware -current packages:
6596c737f2814c96ba9d3be7434f036d curl-7.12.2-i486-2.tgz
59747d7f14d8dc76b0fcad2a8a803e03 wget-1.10.2-i486-1.tgz


Installation instructions:
+------------------------+

Upgrade the packages as root:
# upgradepkg curl-7.12.2-i486-2.tgz
# upgradepkg wget-1.10.2-i486-1.tgz


+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com


Bookmark and Share

« KOffice/KWord (SSA:2005-310-02) · Guikachu 1.5.6: GNOME Resource editor for PalmOS projects »

Linux Compatible » News » November 2005 » curl/wget (SSA:2005-310-01)
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2018 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition