Backporting of Discover/KNS fixes

Eric Hameleers alien at slackware.com
Sat Feb 19 10:36:43 GMT 2022


On Sat, 19 Feb 2022, Ben Cooksley wrote:

> Dear Distributions,
>
> It has recently come to my attention that some distributions have missed
> emails sent to this list recently regarding issues with Discover/KNS. As
> these issues are rather critical I am now requiring all distributions to
> explicitly acknowledge receipt of these emails and to declare the actions
> they have taken. As a reminder, end-user systems without these patches are
> participating in a distributed denial of service attack on KDE.org
> infrastructure.
>
> The two emails which distributions need to keep in mind are:
> - https://mail.kde.org/pipermail/distributions/2022-February/001140.html
> - https://mail.kde.org/pipermail/distributions/2022-February/001142.html
>
> These patches should be backported to all versions currently in support.
>
> For those distributions that have already backported these patches - thank
> you and apologies for the further inconvenience regarding this.
>
> Thanks,
> Ben Cooksley
> KDE Sysadmin

Hi Ben

Slackware does not ship Discover at all, but we also do not apply the 
patch to KNewStuff. What application other than Discover uses 
this function in knewstuff? Wwe wanted to wait for Frameworks 5.92 but 
please tell me if it is required to patch KNS regardless.

Cheers, Eric

-- 
Eric Hameleers <alien at slackware.com>
Home: http://alien.slackbook.org/blog/


More information about the Distributions mailing list