Slackware: 2006-178-03: arts Security Update
Summary
Here are the details from the Slackware 10.2 ChangeLog: patches/packages/arts-1.4.2-i486-2_slack10.2.tgz: Patched to fix a possible exploit if artswrapper is setuid root (which, by default, it is not) and the system is running a 2.6 kernel. Systems running 2.4 kernels are not affected. The official KDE security advisory may be found here: https://kde.org/info/security/advisory-20060614-2.txt The CVE entry for this issue may be found here: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2916 (* Security fix *)
Where Find New Packages
HINT: Getting slow download speeds from ftp.slackware.com?
Give slackware.osuosl.org a try. This is another primary FTP site
for Slackware that can be considerably faster than downloading
from ftp.slackware.com.
Thanks to the friendly folks at the OSU Open Source Lab
(https://osuosl.org/) for donating additional FTP and rsync hosting
to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for
additional mirror sites near you.
Updated package for Slackware 10.0:
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/arts-1.2.3-i486-2_slack10.0.tgz
Updated package for Slackware 10.1:
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/arts-1.3.2-i486-2_slack10.1.tgz
Updated package for Slackware 10.2:
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/arts-1.4.2-i486-2_slack10.2.tgz
Updated package for Slackware -current:
MD5 Signatures
Slackware 10.0 package:
7c8a18fe4d477325006416ca05394e3e arts-1.2.3-i486-2_slack10.0.tgz
Slackware 10.1 package:
d9f7a473d19278583ab5246426fe12b7 arts-1.3.2-i486-2_slack10.1.tgz
Slackware 10.2 package:
41b1aff5b29f59556d86c9970506f7e6 arts-1.4.2-i486-2_slack10.2.tgz
Slackware -current package:
3e8872429c5f63157e2fd6f46c8261b8 arts-1.5.3-i486-2.tgz
Installation Instructions
Installation instructions: Upgrade the packages as root: # upgradepkg arts-1.4.2-i486-2_slack10.2.tgz