summaryrefslogtreecommitdiffstats
path: root/ChangeLog.txt
diff options
context:
space:
mode:
Diffstat (limited to 'ChangeLog.txt')
-rw-r--r--ChangeLog.txt52
1 files changed, 52 insertions, 0 deletions
diff --git a/ChangeLog.txt b/ChangeLog.txt
index 9c095ccac..f09775449 100644
--- a/ChangeLog.txt
+++ b/ChangeLog.txt
@@ -1,3 +1,55 @@
+Fri Sep 30 17:52:21 UTC 2022
+extra/php80/php80-8.0.24-x86_64-1_slack15.0.txz: Upgraded.
+ This update fixes bugs and security issues:
+ phar wrapper: DOS when using quine gzip file.
+ Don't mangle HTTP variable names that clash with ones that have a specific
+ semantic meaning.
+ For more information, see:
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31628
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31629
+ (* Security fix *)
+extra/php81/php81-8.1.11-x86_64-1_slack15.0.txz: Upgraded.
+ This update fixes bugs and security issues:
+ phar wrapper: DOS when using quine gzip file.
+ Don't mangle HTTP variable names that clash with ones that have a specific
+ semantic meaning.
+ For more information, see:
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31628
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31629
+ (* Security fix *)
+patches/packages/mozilla-thunderbird-102.3.1-x86_64-1_slack15.0.txz: Upgraded.
+ This release contains security fixes and improvements.
+ For more information, see:
+ https://www.mozilla.org/en-US/thunderbird/102.3.1/releasenotes/
+ https://www.mozilla.org/en-US/security/advisories/mfsa2022-43/
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39249
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39250
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39251
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39236
+ (* Security fix *)
+patches/packages/php-7.4.32-x86_64-1_slack15.0.txz: Upgraded.
+ This update fixes bugs and security issues:
+ phar wrapper: DOS when using quine gzip file.
+ Don't mangle HTTP variable names that clash with ones that have a specific
+ semantic meaning.
+ For more information, see:
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31628
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31629
+ (* Security fix *)
+patches/packages/seamonkey-2.53.14-x86_64-1_slack15.0.txz: Upgraded.
+ This update contains security fixes and improvements.
+ For more information, see:
+ https://www.seamonkey-project.org/releases/seamonkey2.53.14
+ (* Security fix *)
+patches/packages/vim-9.0.0623-x86_64-1_slack15.0.txz: Upgraded.
+ Fixed use-after-free and stack-based buffer overflow.
+ Thanks to marav for the heads-up.
+ For more information, see:
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-3352
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-3324
+ (* Security fix *)
+patches/packages/vim-gvim-9.0.0623-x86_64-1_slack15.0.txz: Upgraded.
++--------------------------+
Wed Sep 28 18:59:51 UTC 2022
patches/packages/xorg-server-xwayland-21.1.4-x86_64-2_slack15.0.txz: Rebuilt.
xkb: switch to array index loops to moving pointers.