From 6e7b66a8ed16321cec52c0c2b246e9f65aaf7fef Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Mon, 14 Oct 2019 21:39:02 +0000 Subject: Mon Oct 14 21:39:02 UTC 2019 ap/sudo-1.8.28-x86_64-1.txz: Upgraded. Fixed a bug where an sudo user may be able to run a command as root when the Runas specification explicitly disallows root access as long as the ALL keyword is listed first. For more information, see: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14287 (* Security fix *) --- ChangeLog.txt | 34 ++++++++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) (limited to 'ChangeLog.txt') diff --git a/ChangeLog.txt b/ChangeLog.txt index 7ff1e8934..0f192eaac 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -1,3 +1,37 @@ +Mon Oct 14 21:39:02 UTC 2019 +ap/sudo-1.8.28-x86_64-1.txz: Upgraded. + Fixed a bug where an sudo user may be able to run a command as root when + the Runas specification explicitly disallows root access as long as the + ALL keyword is listed first. + For more information, see: + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14287 + (* Security fix *) ++--------------------------+ +Mon Oct 14 19:50:41 UTC 2019 +a/aaa_elflibs-15.0-x86_64-13.txz: Rebuilt. + Added temporarily until third party packages have been recompiled: + libdvdread.so.4.2.0. + Removed (anything still using these must be recompiled): + libicudata.so.64.2, libicui18n.so.64.2, libicuio.so.64.2, + libicutest.so.64.2, libicutu.so.64.2, libicuuc.so.64.2. +a/kernel-firmware-20191014_4c3e853-noarch-1.txz: Upgraded. +ap/qpdf-9.0.2-x86_64-1.txz: Upgraded. +kde/k3b-2.0.3-x86_64-6.txz: Rebuilt. + Recompiled against libdvdread-6.0.2. +l/libdvdnav-6.0.1-x86_64-1.txz: Upgraded. + Compiled against libdvdread-6.0.2. +l/libdvdread-6.0.2-x86_64-1.txz: Upgraded. + Shared library .so-version bump. +l/librsvg-2.46.2-x86_64-1.txz: Upgraded. +xap/MPlayer-20191014-x86_64-1.txz: Upgraded. + Compiled against libdvdread-6.0.2. +xap/xine-lib-1.2.9-x86_64-6.txz: Rebuilt. + Recompiled against libdvdread-6.0.2. +extra/pure-alsa-system/MPlayer-20191014-x86_64-1_alsa.txz: Upgraded. + Compiled against libdvdread-6.0.2. +extra/pure-alsa-system/xine-lib-1.2.9-x86_64-6_alsa.txz: Rebuilt. + Recompiled against libdvdread-6.0.2. ++--------------------------+ Sun Oct 13 19:01:25 UTC 2019 a/pkgtools-15.0-noarch-26.txz: Rebuilt. upgradepkg: add spaces to --dry-run package list. Thanks to Markus Wiesner. -- cgit v1.2.3-79-gdb01