From 139b76eee421713ee3f6c9054c40d326bacb20a6 Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Thu, 26 Jan 2023 00:34:41 +0000 Subject: Thu Jan 26 00:34:41 UTC 2023 patches/packages/bind-9.16.37-x86_64-1_slack15.0.txz: Upgraded. This update fixes bugs and the following security issues: An UPDATE message flood could cause :iscman:`named` to exhaust all available memory. This flaw was addressed by adding a new :any:`update-quota` option that controls the maximum number of outstanding DNS UPDATE messages that :iscman:`named` can hold in a queue at any given time (default: 100). :iscman:`named` could crash with an assertion failure when an RRSIG query was received and :any:`stale-answer-client-timeout` was set to a non-zero value. This has been fixed. :iscman:`named` running as a resolver with the :any:`stale-answer-client-timeout` option set to any value greater than ``0`` could crash with an assertion failure, when the :any:`recursive-clients` soft quota was reached. This has been fixed. For more information, see: https://kb.isc.org/docs/cve-2022-3094 https://kb.isc.org/docs/cve-2022-3736 https://kb.isc.org/docs/cve-2022-3924 https://www.cve.org/CVERecord?id=CVE-2022-3094 https://www.cve.org/CVERecord?id=CVE-2022-3736 https://www.cve.org/CVERecord?id=CVE-2022-3924 (* Security fix *) patches/packages/vim-9.0.1241-x86_64-1_slack15.0.txz: Upgraded. Fixed a security issue: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225. Thanks to marav for the heads-up. For more information, see: https://www.cve.org/CVERecord?id=CVE-2023-0433 (* Security fix *) patches/packages/vim-gvim-9.0.1241-x86_64-1_slack15.0.txz: Upgraded. testing/packages/bind-9.18.11-x86_64-1_slack15.0.txz: Upgraded. This update fixes bugs and the following security issues: An UPDATE message flood could cause :iscman:`named` to exhaust all available memory. This flaw was addressed by adding a new :any:`update-quota` option that controls the maximum number of outstanding DNS UPDATE messages that :iscman:`named` can hold in a queue at any given time (default: 100). :iscman:`named` could crash with an assertion failure when an RRSIG query was received and :any:`stale-answer-client-timeout` was set to a non-zero value. This has been fixed. :iscman:`named` running as a resolver with the :any:`stale-answer-client-timeout` option set to any value greater than ``0`` could crash with an assertion failure, when the :any:`recursive-clients` soft quota was reached. This has been fixed. For more information, see: https://kb.isc.org/docs/cve-2022-3094 https://kb.isc.org/docs/cve-2022-3736 https://kb.isc.org/docs/cve-2022-3924 https://www.cve.org/CVERecord?id=CVE-2022-3094 https://www.cve.org/CVERecord?id=CVE-2022-3736 https://www.cve.org/CVERecord?id=CVE-2022-3924 (* Security fix *) --- patches/packages/bind-9.16.36-x86_64-1_slack15.0.txt | 11 ----------- patches/packages/bind-9.16.37-x86_64-1_slack15.0.txt | 11 +++++++++++ patches/packages/vim-9.0.1146-x86_64-1_slack15.0.txt | 11 ----------- patches/packages/vim-9.0.1241-x86_64-1_slack15.0.txt | 11 +++++++++++ patches/packages/vim-gvim-9.0.1146-x86_64-1_slack15.0.txt | 11 ----------- patches/packages/vim-gvim-9.0.1241-x86_64-1_slack15.0.txt | 11 +++++++++++ 6 files changed, 33 insertions(+), 33 deletions(-) delete mode 100644 patches/packages/bind-9.16.36-x86_64-1_slack15.0.txt create mode 100644 patches/packages/bind-9.16.37-x86_64-1_slack15.0.txt delete mode 100644 patches/packages/vim-9.0.1146-x86_64-1_slack15.0.txt create mode 100644 patches/packages/vim-9.0.1241-x86_64-1_slack15.0.txt delete mode 100644 patches/packages/vim-gvim-9.0.1146-x86_64-1_slack15.0.txt create mode 100644 patches/packages/vim-gvim-9.0.1241-x86_64-1_slack15.0.txt (limited to 'patches') diff --git a/patches/packages/bind-9.16.36-x86_64-1_slack15.0.txt b/patches/packages/bind-9.16.36-x86_64-1_slack15.0.txt deleted file mode 100644 index d61583855..000000000 --- a/patches/packages/bind-9.16.36-x86_64-1_slack15.0.txt +++ /dev/null @@ -1,11 +0,0 @@ -bind: bind (DNS server and utilities) -bind: -bind: The named daemon and support utilities such as dig, host, and -bind: nslookup. Sample configuration files for running a simple caching -bind: nameserver are included. Documentation for advanced name server -bind: setup can be found in /usr/doc/bind-9.x.x/. -bind: -bind: -bind: -bind: -bind: diff --git a/patches/packages/bind-9.16.37-x86_64-1_slack15.0.txt b/patches/packages/bind-9.16.37-x86_64-1_slack15.0.txt new file mode 100644 index 000000000..d61583855 --- /dev/null +++ b/patches/packages/bind-9.16.37-x86_64-1_slack15.0.txt @@ -0,0 +1,11 @@ +bind: bind (DNS server and utilities) +bind: +bind: The named daemon and support utilities such as dig, host, and +bind: nslookup. Sample configuration files for running a simple caching +bind: nameserver are included. Documentation for advanced name server +bind: setup can be found in /usr/doc/bind-9.x.x/. +bind: +bind: +bind: +bind: +bind: diff --git a/patches/packages/vim-9.0.1146-x86_64-1_slack15.0.txt b/patches/packages/vim-9.0.1146-x86_64-1_slack15.0.txt deleted file mode 100644 index 4a843388d..000000000 --- a/patches/packages/vim-9.0.1146-x86_64-1_slack15.0.txt +++ /dev/null @@ -1,11 +0,0 @@ -vim: vim (Vi IMproved) -vim: -vim: Vim is an almost compatible version of the UNIX editor vi. Many new -vim: features have been added: multi level undo, command line history, -vim: filename completion, block operations, and more. -vim: -vim: Vim's development is led by Bram Moolenaar. -vim: -vim: This package also contains the Exuberant Ctags program -vim: written by Darren Hiebert. -vim: diff --git a/patches/packages/vim-9.0.1241-x86_64-1_slack15.0.txt b/patches/packages/vim-9.0.1241-x86_64-1_slack15.0.txt new file mode 100644 index 000000000..4a843388d --- /dev/null +++ b/patches/packages/vim-9.0.1241-x86_64-1_slack15.0.txt @@ -0,0 +1,11 @@ +vim: vim (Vi IMproved) +vim: +vim: Vim is an almost compatible version of the UNIX editor vi. Many new +vim: features have been added: multi level undo, command line history, +vim: filename completion, block operations, and more. +vim: +vim: Vim's development is led by Bram Moolenaar. +vim: +vim: This package also contains the Exuberant Ctags program +vim: written by Darren Hiebert. +vim: diff --git a/patches/packages/vim-gvim-9.0.1146-x86_64-1_slack15.0.txt b/patches/packages/vim-gvim-9.0.1146-x86_64-1_slack15.0.txt deleted file mode 100644 index 3b81553b1..000000000 --- a/patches/packages/vim-gvim-9.0.1146-x86_64-1_slack15.0.txt +++ /dev/null @@ -1,11 +0,0 @@ -vim-gvim: vim-gvim (gvim, the X/GTK3 enabled version of vim) -vim-gvim: -vim-gvim: Gvim is a graphical version of vim. Vim is an almost compatible -vim-gvim: version of the UNIX editor vi. Many new features have been added, -vim-gvim: such as multi level undo, command line history, filename completion, -vim-gvim: block operations, and more. -vim-gvim: -vim-gvim: The main vim package in the AP series is required to use this package. -vim-gvim: -vim-gvim: Vim's development is led by Bram Moolenaar. -vim-gvim: diff --git a/patches/packages/vim-gvim-9.0.1241-x86_64-1_slack15.0.txt b/patches/packages/vim-gvim-9.0.1241-x86_64-1_slack15.0.txt new file mode 100644 index 000000000..3b81553b1 --- /dev/null +++ b/patches/packages/vim-gvim-9.0.1241-x86_64-1_slack15.0.txt @@ -0,0 +1,11 @@ +vim-gvim: vim-gvim (gvim, the X/GTK3 enabled version of vim) +vim-gvim: +vim-gvim: Gvim is a graphical version of vim. Vim is an almost compatible +vim-gvim: version of the UNIX editor vi. Many new features have been added, +vim-gvim: such as multi level undo, command line history, filename completion, +vim-gvim: block operations, and more. +vim-gvim: +vim-gvim: The main vim package in the AP series is required to use this package. +vim-gvim: +vim-gvim: Vim's development is led by Bram Moolenaar. +vim-gvim: -- cgit v1.2.3-65-gdbad