summaryrefslogtreecommitdiffstats
path: root/ChangeLog.rss
diff options
context:
space:
mode:
author Patrick J Volkerding <volkerdi@slackware.com>2023-10-03 22:19:10 +0000
committer Eric Hameleers <alien@slackware.com>2023-10-04 01:08:21 +0200
commit7a2ee07f950f14ce482ae370d28b18de8fcbde69 (patch)
treeb1ff69f347e10c2054f5faa019944d89990d1596 /ChangeLog.rss
parentcb4e8726f423a41c65ca89c8b8346b0974417940 (diff)
downloadcurrent-7a2ee07f950f14ce482ae370d28b18de8fcbde69.tar.gz
current-7a2ee07f950f14ce482ae370d28b18de8fcbde69.tar.xz
Tue Oct 3 22:19:10 UTC 202320231003221910
a/aaa_glibc-solibs-2.37-x86_64-3.txz: Rebuilt. a/dialog-1.3_20231002-x86_64-1.txz: Upgraded. ap/mpg123-1.32.3-x86_64-1.txz: Upgraded. d/llvm-17.0.2-x86_64-1.txz: Upgraded. d/meson-1.2.2-x86_64-2.txz: Rebuilt. [PATCH] Revert rust: apply global, project, and environment C args to bindgen. This fixes building Mesa. Thanks to lucabon and marav. kde/calligra-3.2.1-x86_64-34.txz: Rebuilt. Recompiled against poppler-23.10.0. kde/cantor-23.08.1-x86_64-2.txz: Rebuilt. Recompiled against poppler-23.10.0. kde/kfilemetadata-5.110.0-x86_64-2.txz: Rebuilt. Recompiled against poppler-23.10.0. kde/kile-2.9.93-x86_64-28.txz: Rebuilt. Recompiled against poppler-23.10.0. kde/kitinerary-23.08.1-x86_64-2.txz: Rebuilt. Recompiled against poppler-23.10.0. kde/krita-5.1.5-x86_64-15.txz: Rebuilt. Recompiled against poppler-23.10.0. kde/okular-23.08.1-x86_64-2.txz: Rebuilt. Recompiled against poppler-23.10.0. l/glibc-2.37-x86_64-3.txz: Rebuilt. l/glibc-i18n-2.37-x86_64-3.txz: Rebuilt. Patched to fix the "Looney Tunables" vulnerability, a local privilege escalation in ld.so. This vulnerability was introduced in April 2021 (glibc 2.34) by commit 2ed18c. Thanks to Qualys Research Labs for reporting this issue. For more information, see: https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt https://www.cve.org/CVERecord?id=CVE-2023-4911 (* Security fix *) l/glibc-profile-2.37-x86_64-3.txz: Rebuilt. l/mozilla-nss-3.94-x86_64-1.txz: Upgraded. l/poppler-23.10.0-x86_64-1.txz: Upgraded. Shared library .so-version bump. n/NetworkManager-1.44.2-x86_64-1.txz: Upgraded. n/irssi-1.4.5-x86_64-1.txz: Upgraded. x/fcitx5-5.1.1-x86_64-1.txz: Upgraded. x/fcitx5-anthy-5.1.1-x86_64-1.txz: Upgraded. x/fcitx5-chinese-addons-5.1.1-x86_64-1.txz: Upgraded. x/fcitx5-gtk-5.1.0-x86_64-1.txz: Upgraded. x/fcitx5-hangul-5.1.0-x86_64-1.txz: Upgraded. x/fcitx5-kkc-5.1.0-x86_64-1.txz: Upgraded. x/fcitx5-m17n-5.1.0-x86_64-1.txz: Upgraded. x/fcitx5-qt-5.1.1-x86_64-1.txz: Upgraded. x/fcitx5-sayura-5.1.0-x86_64-1.txz: Upgraded. x/fcitx5-table-extra-5.1.0-x86_64-1.txz: Upgraded. x/fcitx5-table-other-5.1.0-x86_64-1.txz: Upgraded. x/fcitx5-unikey-5.1.1-x86_64-1.txz: Upgraded. x/libX11-1.8.7-x86_64-1.txz: Upgraded. This update fixes security issues: libX11: out-of-bounds memory access in _XkbReadKeySyms(). libX11: stack exhaustion from infinite recursion in PutSubImage(). libX11: integer overflow in XCreateImage() leading to a heap overflow. For more information, see: https://lists.x.org/archives/xorg-announce/2023-October/003424.html https://www.cve.org/CVERecord?id=CVE-2023-43785 https://www.cve.org/CVERecord?id=CVE-2023-43786 https://www.cve.org/CVERecord?id=CVE-2023-43787 (* Security fix *) x/libXpm-3.5.17-x86_64-1.txz: Upgraded. This update fixes security issues: libXpm: out of bounds read in XpmCreateXpmImageFromBuffer(). libXpm: out of bounds read on XPM with corrupted colormap. For more information, see: https://lists.x.org/archives/xorg-announce/2023-October/003424.html https://www.cve.org/CVERecord?id=CVE-2023-43788 https://www.cve.org/CVERecord?id=CVE-2023-43789 (* Security fix *) testing/packages/aaa_glibc-solibs-2.38-x86_64-2.txz: Rebuilt. testing/packages/glibc-2.38-x86_64-2.txz: Rebuilt. Patched to fix the "Looney Tunables" vulnerability, a local privilege escalation in ld.so. This vulnerability was introduced in April 2021 (glibc 2.34) by commit 2ed18c. Thanks to Qualys Research Labs for reporting this issue. For more information, see: https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt https://www.cve.org/CVERecord?id=CVE-2023-4911 (* Security fix *) testing/packages/glibc-i18n-2.38-x86_64-2.txz: Rebuilt. testing/packages/glibc-profile-2.38-x86_64-2.txz: Rebuilt.
Diffstat (limited to 'ChangeLog.rss')
-rw-r--r--ChangeLog.rss96
1 files changed, 94 insertions, 2 deletions
diff --git a/ChangeLog.rss b/ChangeLog.rss
index ce59e27d2..642419c80 100644
--- a/ChangeLog.rss
+++ b/ChangeLog.rss
@@ -11,10 +11,102 @@
<description>Tracking Slackware development in git.</description>
<language>en-us</language>
<id xmlns="http://www.w3.org/2005/Atom">urn:uuid:c964f45e-6732-11e8-bbe5-107b4450212f</id>
- <pubDate>Mon, 2 Oct 2023 19:12:58 GMT</pubDate>
- <lastBuildDate>Mon, 2 Oct 2023 19:29:18 GMT</lastBuildDate>
+ <pubDate>Tue, 3 Oct 2023 22:19:10 GMT</pubDate>
+ <lastBuildDate>Tue, 3 Oct 2023 23:08:17 GMT</lastBuildDate>
<generator>maintain_current_git.sh v 1.17</generator>
<item>
+ <title>Tue, 3 Oct 2023 22:19:10 GMT</title>
+ <pubDate>Tue, 3 Oct 2023 22:19:10 GMT</pubDate>
+ <link>https://git.slackware.nl/current/tag/?h=20231003221910</link>
+ <guid isPermaLink="false">20231003221910</guid>
+ <description>
+ <![CDATA[<pre>
+a/aaa_glibc-solibs-2.37-x86_64-3.txz: Rebuilt.
+a/dialog-1.3_20231002-x86_64-1.txz: Upgraded.
+ap/mpg123-1.32.3-x86_64-1.txz: Upgraded.
+d/llvm-17.0.2-x86_64-1.txz: Upgraded.
+d/meson-1.2.2-x86_64-2.txz: Rebuilt.
+ [PATCH] Revert rust: apply global, project, and environment C args to bindgen.
+ This fixes building Mesa.
+ Thanks to lucabon and marav.
+kde/calligra-3.2.1-x86_64-34.txz: Rebuilt.
+ Recompiled against poppler-23.10.0.
+kde/cantor-23.08.1-x86_64-2.txz: Rebuilt.
+ Recompiled against poppler-23.10.0.
+kde/kfilemetadata-5.110.0-x86_64-2.txz: Rebuilt.
+ Recompiled against poppler-23.10.0.
+kde/kile-2.9.93-x86_64-28.txz: Rebuilt.
+ Recompiled against poppler-23.10.0.
+kde/kitinerary-23.08.1-x86_64-2.txz: Rebuilt.
+ Recompiled against poppler-23.10.0.
+kde/krita-5.1.5-x86_64-15.txz: Rebuilt.
+ Recompiled against poppler-23.10.0.
+kde/okular-23.08.1-x86_64-2.txz: Rebuilt.
+ Recompiled against poppler-23.10.0.
+l/glibc-2.37-x86_64-3.txz: Rebuilt.
+l/glibc-i18n-2.37-x86_64-3.txz: Rebuilt.
+ Patched to fix the "Looney Tunables" vulnerability, a local privilege
+ escalation in ld.so. This vulnerability was introduced in April 2021
+ (glibc 2.34) by commit 2ed18c.
+ Thanks to Qualys Research Labs for reporting this issue.
+ For more information, see:
+ https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
+ https://www.cve.org/CVERecord?id=CVE-2023-4911
+ (* Security fix *)
+l/glibc-profile-2.37-x86_64-3.txz: Rebuilt.
+l/mozilla-nss-3.94-x86_64-1.txz: Upgraded.
+l/poppler-23.10.0-x86_64-1.txz: Upgraded.
+ Shared library .so-version bump.
+n/NetworkManager-1.44.2-x86_64-1.txz: Upgraded.
+n/irssi-1.4.5-x86_64-1.txz: Upgraded.
+x/fcitx5-5.1.1-x86_64-1.txz: Upgraded.
+x/fcitx5-anthy-5.1.1-x86_64-1.txz: Upgraded.
+x/fcitx5-chinese-addons-5.1.1-x86_64-1.txz: Upgraded.
+x/fcitx5-gtk-5.1.0-x86_64-1.txz: Upgraded.
+x/fcitx5-hangul-5.1.0-x86_64-1.txz: Upgraded.
+x/fcitx5-kkc-5.1.0-x86_64-1.txz: Upgraded.
+x/fcitx5-m17n-5.1.0-x86_64-1.txz: Upgraded.
+x/fcitx5-qt-5.1.1-x86_64-1.txz: Upgraded.
+x/fcitx5-sayura-5.1.0-x86_64-1.txz: Upgraded.
+x/fcitx5-table-extra-5.1.0-x86_64-1.txz: Upgraded.
+x/fcitx5-table-other-5.1.0-x86_64-1.txz: Upgraded.
+x/fcitx5-unikey-5.1.1-x86_64-1.txz: Upgraded.
+x/libX11-1.8.7-x86_64-1.txz: Upgraded.
+ This update fixes security issues:
+ libX11: out-of-bounds memory access in _XkbReadKeySyms().
+ libX11: stack exhaustion from infinite recursion in PutSubImage().
+ libX11: integer overflow in XCreateImage() leading to a heap overflow.
+ For more information, see:
+ https://lists.x.org/archives/xorg-announce/2023-October/003424.html
+ https://www.cve.org/CVERecord?id=CVE-2023-43785
+ https://www.cve.org/CVERecord?id=CVE-2023-43786
+ https://www.cve.org/CVERecord?id=CVE-2023-43787
+ (* Security fix *)
+x/libXpm-3.5.17-x86_64-1.txz: Upgraded.
+ This update fixes security issues:
+ libXpm: out of bounds read in XpmCreateXpmImageFromBuffer().
+ libXpm: out of bounds read on XPM with corrupted colormap.
+ For more information, see:
+ https://lists.x.org/archives/xorg-announce/2023-October/003424.html
+ https://www.cve.org/CVERecord?id=CVE-2023-43788
+ https://www.cve.org/CVERecord?id=CVE-2023-43789
+ (* Security fix *)
+testing/packages/aaa_glibc-solibs-2.38-x86_64-2.txz: Rebuilt.
+testing/packages/glibc-2.38-x86_64-2.txz: Rebuilt.
+ Patched to fix the "Looney Tunables" vulnerability, a local privilege
+ escalation in ld.so. This vulnerability was introduced in April 2021
+ (glibc 2.34) by commit 2ed18c.
+ Thanks to Qualys Research Labs for reporting this issue.
+ For more information, see:
+ https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
+ https://www.cve.org/CVERecord?id=CVE-2023-4911
+ (* Security fix *)
+testing/packages/glibc-i18n-2.38-x86_64-2.txz: Rebuilt.
+testing/packages/glibc-profile-2.38-x86_64-2.txz: Rebuilt.
+ </pre>]]>
+ </description>
+ </item>
+ <item>
<title>Mon, 2 Oct 2023 19:12:58 GMT</title>
<pubDate>Mon, 2 Oct 2023 19:12:58 GMT</pubDate>
<link>https://git.slackware.nl/current/tag/?h=20231002191258</link>