cups (SSA:2025-331-01)
New cups packages are available for Slackware 15.0 and -current to fix security issues. These updates address various bugs and security vulnerabilities, including local denial-of-service (DoS) issues and unresponsive cupsd processes. The updated packages can be downloaded from the official Slackware FTP server or other mirror sites listed on the "Get Slack" section of slackware.com. To install the update, users should upgrade the package as root using upgradepkg, followed by restarting the CUPS server with /etc/rc.d/rc.cups restart.
cups (SSA:2025-331-01)
cups (SSA:2025-331-01)
The libpng package for Slackware 15.0 and -current has been updated to address security issues, including CVE-2025-64505, CVE-2025-64506, CVE-2025-64720, and CVE-2025-65018. These updates fix heap buffer overflows and over-reads in the PNG library, which could potentially be exploited by attackers.
libpng (SSA:2025-327-01)
libpng (SSA:2025-327-01)
New gnutls packages are available for Slackware 15.0 and -current to fix security issues, including a stack overwrite vulnerability in libgnutls that was reported by Luigino Camastra from Aisle Research (CVE-2025-9820).
gnutls (SSA:2025-324-01)
gnutls (SSA:2025-324-01)
New openvpn packages are available for Slackware 15.0 and -current to fix security issues. The update, which includes OpenVPN version 2.6.16, fixes a bug that renders HMAC-based protection against state exhaustion when receiving spoofed TLS handshake packets inefficient. Users can find the new packages at ftp.slackware.com or additional mirror sites listed on slackware.com.
openvpn (SSA:2025-323-01)
openvpn (SSA:2025-323-01)
New libarchive packages have been released for Slackware 15.0 and -current to fix several security issues. The update includes patches to prevent buffer overruns, including one in LHA when using p[H_LEVEL_OFFSET] and another in 7-Zip when reading truncated headers.
libarchive (SSA:2025-322-01)
libarchive (SSA:2025-322-01)
New xpdf packages have been released for Slackware 15.0 to fix several security issues. The packages contain fixes for bugs and security issues listed in CVE records from 2024 to 2025.
xpdf (SSA:2025-319-01)
xpdf (SSA:2025-319-01)
Mozilla Thunderbird packages have been updated to fix security issues. The new versions are available for Slackware 15.0 and -current, with the release containing various security fixes and improvements.
mozilla-thunderbird (SSA:2025-316-01)
mozilla-thunderbird (SSA:2025-316-01)
Mozilla Firefox packages have been updated to fix security issues for Slackware 15.0 and -current. The update, version 140.5.0esr, includes security fixes and improvements, as detailed in the Mozilla release notes and security advisories.
mozilla-firefox (SSA:2025-315-01)
mozilla-firefox (SSA:2025-315-01)
New SeaMonkey packages are available for Slackware 15.0 and -current to fix security issues, with an update from version 2.53.21 to 2.53.22. The updated packages contain security fixes and improvements, as mentioned on the official SeaMonkey website. Users can download the new packages from the Slackware FTP server or additional mirror sites listed on the "Get Slack" section of the Slackware website. To upgrade, users should run the command upgradepkg seamonkey-2.53.22-i686-1_slack15.0.txz as root.
seamonkey (SSA:2025-305-01)
seamonkey (SSA:2025-305-01)
New packages are available for Slackware 15.0 and -current to address security issues in tigervnc and xorg-server. The security issues include use-after-free vulnerabilities in XPresentNotify structure creation, use-after-free vulnerabilities in Xkb client resource removal, and value overflow in Xkb extension XkbSetCompatMap().
tigervnc (SSA:2025-302-02)
xorg-server (SSA:2025-302-01)
tigervnc (SSA:2025-302-02)
xorg-server (SSA:2025-302-01)
A security update for the OpenSSL package has been released to fix a moderate severity issue. The vulnerability, identified as CVE-2025-9230, allows an attacker to potentially overread and overwrite data by up to 8 bytes, but the probability of a successful exploit is considered low.
openssl (SSA:2025-296-01)
openssl (SSA:2025-296-01)
New versions of the bind package are available to fix security issues for Slackware 15.0 and -current. The update fixes several vulnerabilities, including DNSSEC validation failures, spoofing attacks, and cache poisoning due to a weak pseudo-random number generator.
bind (SSA:2025-295-01)
bind (SSA:2025-295-01)
A new version of stunnel, a secure tunneling package, has been released to address a security issue. The update fixes a vulnerability that could lead to unintended configurations when using service-level multivalued options with global defaults. Updated packages are available for Slackware 15.0 and -current, including both i586 and x86_64 architectures.
stunnel (SSA:2025-291-01)
stunnel (SSA:2025-291-01)
New packages for libarchive and sqlite are available to fix security issues on Slackware 15.0 and -current. The libarchive update fixes out-of-boundary access and incorrect result checking, while the SQLite update addresses a memory corruption issue caused by improper handling of aggregate terms in a query.
libarchive (SSA:2025-290-01)
sqlite (SSA:2025-290-02)
libarchive (SSA:2025-290-01)
sqlite (SSA:2025-290-02)
New Samba packages are available for Slackware 15.0 and -current to fix security issues, including uninitialized memory disclosure via vfs_streams_xattr and command injection via the WINS server hook script. The vulnerabilities, identified as CVE-2025-9640 and CVE-2025-10230, have been addressed in the new package releases.
samba (SSA:2025-288-01)
samba (SSA:2025-288-01)
New packages for Mozilla Thunderbird and Firefox are available to fix security issues on Slackware 15.0 and -current. The updates contain security fixes and improvements, with details available through links provided by the Slackware Linux Security Team. Users can download the updated packages from the Slackware FTP server or other mirror sites listed in the "Get Slack" section of the Slackware website. To upgrade the package, users should run the command upgradepkg as root on the downloaded package file.
mozilla-thunderbird (SSA:2025-287-02)
mozilla-firefox (SSA:2025-287-01)
mozilla-thunderbird (SSA:2025-287-02)
mozilla-firefox (SSA:2025-287-01)
New packages of Python 3 have been released for Slackware 15.0 and -current to address security issues. The updates include python3-3.9.24 for Slackware 15.0 and python3-3.12.12 for Slackware-current, with the latter being a different version than previously installed on the system.
python3 (SSA:2025-282-01)
python3 (SSA:2025-282-01)
New fetchmail packages are available for Slackware 15.0 and -current to address a security issue where the SMTP client can crash when authenticating. The updated packages, which include version 6.4.27 for Slackware 15.0 and version 6.5.6 for Slackware-current, can be downloaded from the Slackware FTP site or additional mirror sites. To install the updates, users should run the command "upgradepkg fetchmail-6.4.27-i586-2_slack15.0.txz" as root.
fetchmail (SSA:2025-276-01)
fetchmail (SSA:2025-276-01)
A security issue has been identified in the Expat package, which is used by Slackware Linux 15.0. To resolve this issue, new packages are available for download that upgrade Expat to version 2.7.3.
expat (SSA:2025-268-01)
expat (SSA:2025-268-01)
The Slackware Linux Security Team has released new packages to fix security issues for three applications: expat, mozilla-firefox, and mozilla-thunderbird. The updated packages are available for Slackware 15.0 and -current, and can be downloaded from the Slackware project's FTP servers or mirror sites. The updates include security fixes and improvements for expat (version 2.7.2), mozilla-firefox (version 140.3.0esr), and mozilla-thunderbird (version 140.3.0esr).
expat (SSA:2025-260-01)
mozilla-firefox (SSA:2025-260-02)
mozilla-thunderbird (SSA:2025-260-03)
expat (SSA:2025-260-01)
mozilla-firefox (SSA:2025-260-02)
mozilla-thunderbird (SSA:2025-260-03)