summaryrefslogtreecommitdiffstats
path: root/ChangeLog.rss
diff options
context:
space:
mode:
author Patrick J Volkerding <volkerdi@slackware.com>2018-09-22 22:41:41 +0000
committer Eric Hameleers <alien@slackware.com>2018-09-23 09:00:31 +0200
commit89d895f1ff30ec2a473919179e995715d0ddf23a (patch)
tree8f4a22a94e02980ddd7816003901a120265b9fa0 /ChangeLog.rss
parent48e09f463d219d8975a3fb82f2d7d52a88472a9f (diff)
downloadcurrent-89d895f1ff30ec2a473919179e995715d0ddf23a.tar.gz
current-89d895f1ff30ec2a473919179e995715d0ddf23a.tar.xz
Sat Sep 22 22:41:41 UTC 201820180922224141
a/eudev-3.2.6-x86_64-2.txz: Rebuilt. Removed unneeded groups "render" and "kvm" from 50-udev-default.rules. Thanks to Richard David Sherman. a/grub-2.02-x86_64-4.txz: Rebuilt. Applied a patch needed when compiling with recent binutils. Thanks to ivandi. d/parallel-20180922-noarch-1.txz: Upgraded. x/xterm-337-x86_64-1.txz: Upgraded. xap/mozilla-firefox-60.2.1esr-x86_64-1.txz: Upgraded. This release contains security fixes and improvements. A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. For more information, see: https://www.mozilla.org/security/known-vulnerabilities/firefoxESR.html https://www.mozilla.org/en-US/security/advisories/mfsa2018-23/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12383 (* Security fix *)
Diffstat (limited to 'ChangeLog.rss')
-rw-r--r--ChangeLog.rss35
1 files changed, 33 insertions, 2 deletions
diff --git a/ChangeLog.rss b/ChangeLog.rss
index 6d43c7712..f7c429781 100644
--- a/ChangeLog.rss
+++ b/ChangeLog.rss
@@ -11,10 +11,41 @@
<description>Tracking Slackware development in git.</description>
<language>en-us</language>
<id xmlns="http://www.w3.org/2005/Atom">urn:uuid:c964f45e-6732-11e8-bbe5-107b4450212f</id>
- <pubDate>Fri, 21 Sep 2018 18:51:07 GMT</pubDate>
- <lastBuildDate>Sat, 22 Sep 2018 07:00:35 GMT</lastBuildDate>
+ <pubDate>Sat, 22 Sep 2018 22:41:41 GMT</pubDate>
+ <lastBuildDate>Sun, 23 Sep 2018 07:00:27 GMT</lastBuildDate>
<generator>maintain_current_git.sh v 1.10</generator>
<item>
+ <title>Sat, 22 Sep 2018 22:41:41 GMT</title>
+ <pubDate>Sat, 22 Sep 2018 22:41:41 GMT</pubDate>
+ <link>https://git.slackware.nl/current/tag/?h=20180922224141</link>
+ <guid isPermaLink="false">20180922224141</guid>
+ <description>
+ <![CDATA[<pre>
+a/eudev-3.2.6-x86_64-2.txz: Rebuilt.
+ Removed unneeded groups "render" and "kvm" from 50-udev-default.rules.
+ Thanks to Richard David Sherman.
+a/grub-2.02-x86_64-4.txz: Rebuilt.
+ Applied a patch needed when compiling with recent binutils. Thanks to ivandi.
+d/parallel-20180922-noarch-1.txz: Upgraded.
+x/xterm-337-x86_64-1.txz: Upgraded.
+xap/mozilla-firefox-60.2.1esr-x86_64-1.txz: Upgraded.
+ This release contains security fixes and improvements.
+ A potentially exploitable crash in TransportSecurityInfo used for SSL
+ can be triggered by data stored in the local cache in the user profile
+ directory. This issue is only exploitable in combination with another
+ vulnerability allowing an attacker to write data into the local cache
+ or from locally installed malware. This issue also triggers a
+ non-exploitable startup crash for users switching between the Nightly
+ and Release versions of Firefox if the same profile is used.
+ For more information, see:
+ https://www.mozilla.org/security/known-vulnerabilities/firefoxESR.html
+ https://www.mozilla.org/en-US/security/advisories/mfsa2018-23/
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12383
+ (* Security fix *)
+ </pre>]]>
+ </description>
+ </item>
+ <item>
<title>Fri, 21 Sep 2018 18:51:07 GMT</title>
<pubDate>Fri, 21 Sep 2018 18:51:07 GMT</pubDate>
<link>https://git.slackware.nl/current/tag/?h=20180921185107</link>