From 96bf53e55d898cd6e2090476ee0f9066138d9ea3 Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Wed, 11 May 2022 19:01:59 +0000 Subject: Wed May 11 19:01:59 UTC 2022 patches/packages/curl-7.83.1-x86_64-1_slack15.0.txz: Upgraded. This update fixes security issues: HSTS bypass via trailing dot. TLS and SSH connection too eager reuse. CERTINFO never-ending busy-loop. percent-encoded path separator in URL host. cookie for trailing dot TLD. curl removes wrong file on error. For more information, see: https://curl.se/docs/CVE-2022-30115.html https://curl.se/docs/CVE-2022-27782.html https://curl.se/docs/CVE-2022-27781.html https://curl.se/docs/CVE-2022-27780.html https://curl.se/docs/CVE-2022-27779.html https://curl.se/docs/CVE-2022-27778.html https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30115 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27782 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27781 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27780 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27779 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27778 (* Security fix *) --- ChangeLog.rss | 36 ++++++++++++++++++++++++++++++++++-- 1 file changed, 34 insertions(+), 2 deletions(-) (limited to 'ChangeLog.rss') diff --git a/ChangeLog.rss b/ChangeLog.rss index e1ee1742b..6a1b14b50 100644 --- a/ChangeLog.rss +++ b/ChangeLog.rss @@ -11,9 +11,41 @@ Tracking Slackware development in git. en-us urn:uuid:c964f45e-6732-11e8-bbe5-107b4450212f - Mon, 9 May 2022 21:33:25 GMT - Tue, 10 May 2022 11:29:52 GMT + Wed, 11 May 2022 19:01:59 GMT + Thu, 12 May 2022 11:29:40 GMT maintain_current_git.sh v 1.17 + + Wed, 11 May 2022 19:01:59 GMT + Wed, 11 May 2022 19:01:59 GMT + https://git.slackware.nl/current/tag/?h=20220511190159 + 20220511190159 + + +patches/packages/curl-7.83.1-x86_64-1_slack15.0.txz: Upgraded. + This update fixes security issues: + HSTS bypass via trailing dot. + TLS and SSH connection too eager reuse. + CERTINFO never-ending busy-loop. + percent-encoded path separator in URL host. + cookie for trailing dot TLD. + curl removes wrong file on error. + For more information, see: + https://curl.se/docs/CVE-2022-30115.html + https://curl.se/docs/CVE-2022-27782.html + https://curl.se/docs/CVE-2022-27781.html + https://curl.se/docs/CVE-2022-27780.html + https://curl.se/docs/CVE-2022-27779.html + https://curl.se/docs/CVE-2022-27778.html + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30115 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27782 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27781 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27780 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27779 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27778 + (* Security fix *) + ]]> + + Mon, 9 May 2022 21:33:25 GMT Mon, 9 May 2022 21:33:25 GMT -- cgit v1.2.3-80-g2a13