Slackware 1216 Published by Philipp Esselbach 0

New packages for PHP have been released to address security issues in Slackware 15.0 and -current. The updates fix vulnerabilities in PDO quoting, array_merge(), and getimagesize(). Users can find the updated packages at various mirror sites, including ftp.slackware.com and osuosl.org. To install the new package, users should upgrade as root and then restart Apache httpd.

php (SSA:2025-353-01)

Slackware 1216 Published by Philipp Esselbach 0

Mozilla Firefox has released new packages to fix security issues, available for Slackware 15.0 and -current. The update includes security fixes and improvements, and can be found on the official Mozilla website. To install the update, users should run "upgradepkg mozilla-firefox-140.6.0esr-i686-1_slack15.0.txz" as root.

mozilla-firefox (SSA:2025-343-01)

Slackware 1216 Published by Philipp Esselbach 0

Security updates are available for libpng and httpd packages on Slackware 15.0 and -current. The libpng update fixes a high-severity security issue related to an out-of-bounds read, while the httpd update addresses multiple security issues, including bugs and vulnerabilities that could allow bypasses or data leaks. The updated packages can be downloaded from the Slackware FTP site or other mirror sites listed on the project's website. To install the updates, run the upgradepkg command as root and then restart Apache httpd.

libpng (SSA:2025-338-02)
httpd (SSA:2025-338-01)

Slackware 1216 Published by Philipp Esselbach 0

New libxslt packages are available for Slackware 15.0 and -current to fix security issues. The updates address vulnerabilities including CVE-2025-9714, CVE-2025-7424, and CVE-2025-11731. These fixes were contributed by Apple's engineers, who identified type confusion in xmlNode.psvi between stylesheet and source nodes.

libxslt (SSA:2025-332-01)

Slackware 1216 Published by Philipp Esselbach 0

New cups packages are available for Slackware 15.0 and -current to fix security issues. These updates address various bugs and security vulnerabilities, including local denial-of-service (DoS) issues and unresponsive cupsd processes. The updated packages can be downloaded from the official Slackware FTP server or other mirror sites listed on the "Get Slack" section of slackware.com. To install the update, users should upgrade the package as root using upgradepkg, followed by restarting the CUPS server with /etc/rc.d/rc.cups restart.

cups (SSA:2025-331-01)

Slackware 1216 Published by Philipp Esselbach 0

The libpng package for Slackware 15.0 and -current has been updated to address security issues, including CVE-2025-64505, CVE-2025-64506, CVE-2025-64720, and CVE-2025-65018. These updates fix heap buffer overflows and over-reads in the PNG library, which could potentially be exploited by attackers.

libpng (SSA:2025-327-01)

Slackware 1216 Published by Philipp Esselbach 0

New openvpn packages are available for Slackware 15.0 and -current to fix security issues. The update, which includes OpenVPN version 2.6.16, fixes a bug that renders HMAC-based protection against state exhaustion when receiving spoofed TLS handshake packets inefficient. Users can find the new packages at ftp.slackware.com or additional mirror sites listed on slackware.com.

openvpn (SSA:2025-323-01)

Slackware 1216 Published by Philipp Esselbach 0

New libarchive packages have been released for Slackware 15.0 and -current to fix several security issues. The update includes patches to prevent buffer overruns, including one in LHA when using p[H_LEVEL_OFFSET] and another in 7-Zip when reading truncated headers.

libarchive (SSA:2025-322-01)

Slackware 1216 Published by Philipp Esselbach 0

New SeaMonkey packages are available for Slackware 15.0 and -current to fix security issues, with an update from version 2.53.21 to 2.53.22. The updated packages contain security fixes and improvements, as mentioned on the official SeaMonkey website. Users can download the new packages from the Slackware FTP server or additional mirror sites listed on the "Get Slack" section of the Slackware website. To upgrade, users should run the command upgradepkg seamonkey-2.53.22-i686-1_slack15.0.txz as root.

seamonkey (SSA:2025-305-01)

Slackware 1216 Published by Philipp Esselbach 0

A security update for the OpenSSL package has been released to fix a moderate severity issue. The vulnerability, identified as CVE-2025-9230, allows an attacker to potentially overread and overwrite data by up to 8 bytes, but the probability of a successful exploit is considered low.

openssl (SSA:2025-296-01)

Slackware 1216 Published by Philipp Esselbach 0

New versions of the bind package are available to fix security issues for Slackware 15.0 and -current. The update fixes several vulnerabilities, including DNSSEC validation failures, spoofing attacks, and cache poisoning due to a weak pseudo-random number generator.

bind (SSA:2025-295-01)

Slackware 1216 Published by Philipp Esselbach 0

A new version of stunnel, a secure tunneling package, has been released to address a security issue. The update fixes a vulnerability that could lead to unintended configurations when using service-level multivalued options with global defaults. Updated packages are available for Slackware 15.0 and -current, including both i586 and x86_64 architectures.

stunnel (SSA:2025-291-01)

Slackware 1216 Published by Philipp Esselbach 0

New Samba packages are available for Slackware 15.0 and -current to fix security issues, including uninitialized memory disclosure via vfs_streams_xattr and command injection via the WINS server hook script. The vulnerabilities, identified as CVE-2025-9640 and CVE-2025-10230, have been addressed in the new package releases.

samba (SSA:2025-288-01)