From 9f285815b938707157a3cfd605280829c1d5a715 Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Thu, 7 Mar 2024 20:40:08 +0000 Subject: Thu Mar 7 20:40:08 UTC 2024 patches/packages/ghostscript-9.55.0-x86_64-2_slack15.0.txz: Rebuilt. Fixes security issues: A vulnerability was identified in the way Ghostscript/GhostPDL called tesseract for the OCR devices, which could allow arbitrary code execution. Thanks to J_W for the heads-up. Mishandling of permission validation for pipe devices could allow arbitrary code execution. For more information, see: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-36664 (* Security fix *) --- ChangeLog.txt | 12 ++++++++++++ 1 file changed, 12 insertions(+) (limited to 'ChangeLog.txt') diff --git a/ChangeLog.txt b/ChangeLog.txt index 9247152f5..d85bac921 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -1,3 +1,15 @@ +Thu Mar 7 20:40:08 UTC 2024 +patches/packages/ghostscript-9.55.0-x86_64-2_slack15.0.txz: Rebuilt. + Fixes security issues: + A vulnerability was identified in the way Ghostscript/GhostPDL called + tesseract for the OCR devices, which could allow arbitrary code execution. + Thanks to J_W for the heads-up. + Mishandling of permission validation for pipe devices could allow arbitrary + code execution. + For more information, see: + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-36664 + (* Security fix *) ++--------------------------+ Tue Mar 5 21:16:50 UTC 2024 patches/packages/mozilla-thunderbird-115.8.1-x86_64-1_slack15.0.txz: Upgraded. This release contains security fixes and improvements. -- cgit v1.2.3-79-gdb01