summaryrefslogtreecommitdiffstats
path: root/ChangeLog.txt
diff options
context:
space:
mode:
author Patrick J Volkerding <volkerdi@slackware.com>2022-03-15 00:13:59 +0000
committer Eric Hameleers <alien@slackware.com>2022-03-15 13:30:00 +0100
commit44c9fcd8776c083b8de52d292b23aca6b99a59d4 (patch)
tree840d61c69fdd0f22921baf99bd01fdbd4f25291a /ChangeLog.txt
parent477bd290fa9a178a3db0fe07169bcad10037cdcd (diff)
downloadcurrent-44c9fcd8776c083b8de52d292b23aca6b99a59d4.tar.gz
current-44c9fcd8776c083b8de52d292b23aca6b99a59d4.tar.xz
Tue Mar 15 00:13:59 UTC 202220220315001359_15.0
patches/packages/httpd-2.4.53-x86_64-1_slack15.0.txz: Upgraded. This update fixes bugs and the following security issues: mod_sed: Read/write beyond bounds core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody HTTP request smuggling vulnerability mod_lua: Use of uninitialized value in r:parsebody For more information, see: https://downloads.apache.org/httpd/CHANGES_2.4.53 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23943 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22721 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22720 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22719 (* Security fix *) patches/packages/mozilla-firefox-91.7.1esr-x86_64-1_slack15.0.txz: Upgraded. This release makes the following change: Yandex and Mail.ru have been removed as optional search providers in the drop-down search menu in Firefox. For more information, see: https://www.mozilla.org/en-US/firefox/91.7.1/releasenotes/ (* Security fix *)
Diffstat (limited to 'ChangeLog.txt')
-rw-r--r--ChangeLog.txt23
1 files changed, 23 insertions, 0 deletions
diff --git a/ChangeLog.txt b/ChangeLog.txt
index 8ecb25329..98cbbf992 100644
--- a/ChangeLog.txt
+++ b/ChangeLog.txt
@@ -1,3 +1,26 @@
+Tue Mar 15 00:13:59 UTC 2022
+patches/packages/httpd-2.4.53-x86_64-1_slack15.0.txz: Upgraded.
+ This update fixes bugs and the following security issues:
+ mod_sed: Read/write beyond bounds
+ core: Possible buffer overflow with very large or unlimited
+ LimitXMLRequestBody
+ HTTP request smuggling vulnerability
+ mod_lua: Use of uninitialized value in r:parsebody
+ For more information, see:
+ https://downloads.apache.org/httpd/CHANGES_2.4.53
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23943
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22721
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22720
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22719
+ (* Security fix *)
+patches/packages/mozilla-firefox-91.7.1esr-x86_64-1_slack15.0.txz: Upgraded.
+ This release makes the following change:
+ Yandex and Mail.ru have been removed as optional search providers in the
+ drop-down search menu in Firefox.
+ For more information, see:
+ https://www.mozilla.org/en-US/firefox/91.7.1/releasenotes/
+ (* Security fix *)
++--------------------------+
Sat Mar 12 20:57:35 UTC 2022
patches/packages/polkit-0.120-x86_64-3_slack15.0.txz: Rebuilt.
Patched to fix a security issue where an unprivileged user could cause a