<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Slackware Linux</title>
  <link>https://cvedaily.com/pages/tags/slackware.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/slackware.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Slackware Linux</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:12 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2013-7172 – Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7172</guid>
    <pubDate>Thu, 21 Nov 2019 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-7172</strong></p>
  <p>Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-7171 – Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7171</guid>
    <pubDate>Thu, 21 Nov 2019 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-7171</strong></p>
  <p>Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root privileges.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-3499 – SlackRoll before 8 accepts gpg exit codes other than 0 and 1 as evidence of a va...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-3499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-3499</guid>
    <pubDate>Fri, 29 Jun 2007 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-3499</strong></p>
  <p>SlackRoll before 8 accepts gpg exit codes other than 0 and 1 as evidence of a valid signature, which allows remote Slackware mirror sites or man-in-the-middle attackers to cause a denial of service (data inconsistency) or possibly install Trojan horse packages via malformed gpg signatures.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-3499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2007-0822 – umount, when running with the Linux 2.6.15 kernel on Slackware Linux 10.2, allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0822</guid>
    <pubDate>Wed, 07 Feb 2007 20:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2007-0822</strong></p>
  <p>umount, when running with the Linux 2.6.15 kernel on Slackware Linux 10.2, allows local users to trigger a NULL dereference and application crash by invoking the program with a pathname for a USB pen drive that was mounted and then physically removed, which might allow the users to obtain sensitive information, including core file contents.</p>
  <p><strong>CVSS:</strong> 1.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2007-0823 – xterm on Slackware Linux 10.2 stores information that had been displayed for a d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0823</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0823</guid>
    <pubDate>Wed, 07 Feb 2007 20:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2007-0823</strong></p>
  <p>xterm on Slackware Linux 10.2 stores information that had been displayed for a different user account using the same xterm process, which might allow local users to bypass file permissions and read other users' files, or obtain other sensitive information, by reading the xterm process memory.  NOTE: it could be argued that this is an expected consequence of multiple users sharing the same interac…</p>
  <p><strong>CVSS:</strong> 1.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0823">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-0530 – The PHP package in Slackware 8.1, 9.0, and 9.1, when linked against a static lib...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-0530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-0530</guid>
    <pubDate>Fri, 06 Aug 2004 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-0530</strong></p>
  <p>The PHP package in Slackware 8.1, 9.0, and 9.1, when linked against a static library, includes /tmp in the search path, which allows local users to execute arbitrary code as the PHP user by inserting shared libraries into the appropriate path.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-0530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2003-0335 – rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the file...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2003-0335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2003-0335</guid>
    <pubDate>Thu, 22 May 2003 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2003-0335</strong></p>
  <p>rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the filesystem to be remounted and possibly reset security-relevant mount flags such as nosuid, nodev, and noexec.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2003-0335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2001-1036 – GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2001-1036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2001-1036</guid>
    <pubDate>Fri, 31 Aug 2001 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2001-1036</strong></p>
  <p>GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2001-1036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-1999-0856 – login in Slackware 7.0 allows remote attackers to identify valid users on the sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-0856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-0856</guid>
    <pubDate>Wed, 01 Dec 1999 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-1999-0856</strong></p>
  <p>login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-0856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-1999-0421 – During a reboot after an installation of Linux Slackware 3.6, a remote attacker ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-0421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-0421</guid>
    <pubDate>Wed, 17 Mar 1999 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-1999-0421</strong></p>
  <p>During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account without a password.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-0421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-1999-1422 – The default configuration of Slackware 3.4, and possibly other versions, include...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-1422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-1422</guid>
    <pubDate>Sat, 02 Jan 1999 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-1999-1422</strong></p>
  <p>The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-1422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-1999-1434 – login in Slackware Linux 3.2 through 3.5 does not properly check for an error wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-1434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-1434</guid>
    <pubDate>Mon, 13 Jul 1998 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-1999-1434</strong></p>
  <p>login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to any local user who logs on to the server.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-1434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-1999-1498 – Slackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-1498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-1498</guid>
    <pubDate>Mon, 06 Apr 1998 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-1999-1498</strong></p>
  <p>Slackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary files via a symlink attack on the reply file.</p>
  <p><strong>CVSS:</strong> 3.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-1498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-1999-1445 – Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-1445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-1445</guid>
    <pubDate>Mon, 02 Feb 1998 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-1999-1445</strong></p>
  <p>Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-1445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-1999-0340 – Buffer overflow in Linux Slackware crond program allows local users to gain root...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-0340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-0340</guid>
    <pubDate>Mon, 01 Dec 1997 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-1999-0340</strong></p>
  <p>Buffer overflow in Linux Slackware crond program allows local users to gain root access.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-0340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-1999-1489 – Buffer overflow in TestChip function in XFree86 SuperProbe in Slackware Linux 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-1489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-1489</guid>
    <pubDate>Tue, 04 Mar 1997 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-1999-1489</strong></p>
  <p>Buffer overflow in TestChip function in XFree86 SuperProbe in Slackware Linux 3.1 allows local users to gain root privileges via a long -nopr argument.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-1489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-1999-0298 – ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-0298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-0298</guid>
    <pubDate>Wed, 05 Feb 1997 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-1999-0298</strong></p>
  <p>ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-0298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-1999-1186 – rxvt, when compiled with the PRINT_PIPE option in various Linux operating system...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-1186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-1186</guid>
    <pubDate>Tue, 02 Jan 1996 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-1999-1186</strong></p>
  <p>rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-1186">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
