Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: Golden Eagle
Before you guys flame me, let me just say I use this method on my Suse partition almost purely out of laziness...

But perhaps our friend here can see yet another way on how you don't have to go through all this trouble.

I don't have Quake, and I'm not putting it on my system. Though I used more or less the same process for MPlayer.

Assuming you put other sites (e.g. Packman, Guru, official SuSE mirrors, etc.) on YaST, YaST will automatically find the dependencies and install them.

129 posted on 03/08/2006 2:23:24 PM PST by rzeznikj at stout (This is a darkroom. Keep the door closed or you'll let all the dark out...)
[ Post Reply | Private Reply | To 74 | View Replies ]


To: rzeznikj at stout

WOW, you better be CAREFUL! There's a known vulnerability just out about using YaST, you could be trojaned if you're not real careful about where you're getting your updates.

http://www.linuxsecurity.com/content/view/121777/112/

Problem Description and Brief Discussion

This is a reissue of SUSE-SA:2006:009, after we found out that also
gpg version < 1.4.x are affected by the signature checking problem
of CVE-2006-0455.

With certain handcraft-able signatures GPG was returning a 0 (valid
signature) when used on command-line with option --verify.

This could make automated checkers, like for instance the patch file
verification checker of the YaST Online Update, pass malicious patch
files as correct and allow remote code execution.

Also, the YaST Online Update script signature verification had used a
feature which was not meant to be used for signature verification,
making it possible to supply any kind of script which would be
considered correct. This would also allow code execution.


133 posted on 03/08/2006 5:21:23 PM PST by Golden Eagle
[ Post Reply | Private Reply | To 129 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson