| Commit message (Expand) | Author | Age | Files | Lines |
* | Fri Apr 5 20:11:23 UTC 2024...a/etc-15.1-x86_64-10.txz: Rebuilt.
Added nut user (218) and nut group (218).
a/genpower-1.0.5-x86_64-5.txz: Removed.
a/nut-2.8.2-x86_64-1.txz: Added.
This is a package to support uninterruptible power supplies, and replaces
the obsolete genpower package.
Thanks to V'yacheslav Stetskevych for the original SBo script.
a/sysvinit-scripts-15.1-noarch-16.txz: Rebuilt.
rc.M: start the NUT init scripts rc.nut-drvctl, rc.nut-upsd, and
rc.nut-upsmon. Remove the genpower block.
rc.6: support stopping the UPS inverter on the way down if we see
/etc/killpower. Remove the genpower block.
a/tcsh-6.24.12-x86_64-1.txz: Upgraded.
ap/man-db-2.12.1-x86_64-1.txz: Upgraded.
ap/mpg123-1.32.6-x86_64-1.txz: Upgraded.
ap/vim-9.1.0265-x86_64-1.txz: Upgraded.
d/cargo-vendor-filterer-0.5.14-x86_64-1.txz: Upgraded.
d/nasm-2.16.02-x86_64-1.txz: Upgraded.
l/libproxy-0.5.5-x86_64-1.txz: Upgraded.
l/python-hatchling-1.22.5-x86_64-1.txz: Upgraded.
l/python-typing_extensions-4.11.0-x86_64-1.txz: Upgraded.
x/xdm-1.1.16-x86_64-1.txz: Upgraded.
xap/vim-gvim-9.1.0265-x86_64-1.txz: Upgraded.
extra/bash-completion/bash-completion-2.13.0-noarch-1.txz: Upgraded.
extra/tigervnc/tigervnc-1.13.1-x86_64-5.txz: Rebuilt.
Recompiled against xorg-server-21.1.12 to fix security issues:
Heap buffer overread/data leakage in ProcXIGetSelectedEvents.
Heap buffer overread/data leakage in ProcXIPassiveGrabDevice.
Heap buffer overread/data leakage in ProcAppleDRICreatePixmap.
Use-after-free in ProcRenderAddGlyphs.
For more information, see:
https://lists.x.org/archives/xorg-announce/2024-April/003497.html
https://www.cve.org/CVERecord?id=CVE-2024-31080
https://www.cve.org/CVERecord?id=CVE-2024-31081
https://www.cve.org/CVERecord?id=CVE-2024-31082
https://www.cve.org/CVERecord?id=CVE-2024-31083
(* Security fix *)
20240405201123 | Patrick J Volkerding | 2024-04-05 | 1 | -2/+1 |
* | Wed Apr 3 19:58:56 UTC 2024...a/kernel-generic-6.6.24-x86_64-1.txz: Upgraded.
a/kernel-huge-6.6.24-x86_64-1.txz: Upgraded.
a/kernel-modules-6.6.24-x86_64-1.txz: Upgraded.
d/kernel-headers-6.6.24-x86-1.txz: Upgraded.
d/python3-3.11.9-x86_64-1.txz: Upgraded.
k/kernel-source-6.6.24-noarch-1.txz: Upgraded.
-AMD_MEM_ENCRYPT_ACTIVE_BY_DEFAULT n
-GCC11_NO_ARRAY_BOUNDS y
NUMA_BALANCING n -> y
+GCC10_NO_ARRAY_BOUNDS y
+NUMA_BALANCING_DEFAULT_ENABLED y
kde/libindi-2.0.7-x86_64-1.txz: Upgraded.
l/SDL2-2.30.2-x86_64-1.txz: Upgraded.
l/aom-3.8.2-x86_64-1.txz: Added.
Needed to add AV1 encode/decode support to ffmpeg.
Thanks to Andrew Strong.
l/dav1d-1.4.1-x86_64-1.txz: Added.
Needed to add AV1 decode support to ffmpeg.
l/ffmpeg-6.1.1-x86_64-2.txz: Rebuilt.
Patched to build with nv-codec-headers-12.2.72.0. Thanks to J_W.
Compiled against aom-3.8.2 and dav1d-1.4.1 for AV1 support.
Thanks to glennmcc.
l/gtk4-4.14.2-x86_64-1.txz: Upgraded.
n/whois-5.5.22-x86_64-1.txz: Upgraded.
Fixed a segmentation fault with --no-recursion.
Updated the .bm and .vi TLD servers.
Removed 4 new gTLDs which are no longer active.
xap/MPlayer-20240403-x86_64-1.txz: Upgraded.
Compiled using --enable-libaom-lavc and --enable-libdav1d-lavc.
Thanks to glennmcc.
xap/pan-0.157-x86_64-1.txz: Upgraded.
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
usb-and-pxe-installers/usbboot.img: Rebuilt.
20240403195856 | Patrick J Volkerding | 2024-04-03 | 1 | -0/+1 |
* | Sun Mar 31 18:28:19 UTC 2024...ap/hplip-3.23.12-x86_64-4.txz: Rebuilt.
Add a few patches from Arch, including one to fix a Unicode error with the
sixext.py script that causes hp-setup to crash after detecting a printer.
Thanks to truepatriot76.
d/Cython-3.0.10-x86_64-1.txz: Upgraded.
d/cargo-vendor-filterer-0.5.13-x86_64-1.txz: Upgraded.
d/poke-4.0-x86_64-1.txz: Upgraded.
l/editorconfig-core-c-0.12.7-x86_64-1.txz: Upgraded.
l/jasper-4.2.3-x86_64-1.txz: Upgraded.
l/libical-3.0.18-x86_64-1.txz: Upgraded.
l/pango-1.52.2-x86_64-1.txz: Upgraded.
l/python-lxml-5.2.0-x86_64-1.txz: Upgraded.
l/wireplumber-0.5.1-x86_64-1.txz: Upgraded.
n/c-ares-1.28.1-x86_64-1.txz: Upgraded.
xap/blueman-2.4-x86_64-1.txz: Upgraded.
20240331182819 | Patrick J Volkerding | 2024-03-31 | 1 | -0/+3 |
* | Fri Mar 29 20:39:11 UTC 2024...Everything in this batch besides aaa_libraries, xz, mcelog, and harfbuzz is a
rebuild or upgrade to build against python-3.11.8. Looking at the python
readiness page, it seems like a lot of stuff we use is not certified for
python-3.12 yet (although to be fair, about half as much isn't certified for
python-3.11 either). But 3.11 seems to be the safer choice even though the
final bugfix update is scheduled for Monday. And, if we do decide to move
ahead to 3.12 later on, it'll be a lot easier than this update was.
Enjoy! :-)
a/aaa_libraries-15.1-x86_64-29.txz: Rebuilt.
Upgraded: libzstd.so.1.5.6, libexpat.so.1.9.2, libglib-2.0.so.0.8000.0,
libgmodule-2.0.so.0.8000.0, libgobject-2.0.so.0.8000.0,
libgthread-2.0.so.0.8000.0.
Removed: libboost_*.so.1.83.0.
a/libblockdev-2.28-x86_64-3.txz: Rebuilt.
a/libbytesize-2.8-x86_64-2.txz: Rebuilt.
a/libpwquality-1.4.5-x86_64-2.txz: Rebuilt.
a/mcelog-198-x86_64-1.txz: Upgraded.
a/util-linux-2.40-x86_64-2.txz: Rebuilt.
a/volume_key-0.3.12-x86_64-8.txz: Rebuilt.
a/xz-5.6.1-x86_64-2.txz: Rebuilt.
Seems like a good idea to build this from a git pull rather than the signed
release tarballs. :-)
The liblzma in the previous packages were not found to be vulnerable by the
detection script, but I'd rather not carry the bad m4 files in our sources.
Here's a test script for anyone wanting to try it:
if hexdump -ve '1/1 "%.2x"' /lib*/liblzma.so.5 | grep -q f30f1efa554889f54c89ce5389fb81e7000000804883ec28488954241848894c2410 ; then
echo probably vulnerable
else
echo probably not vulnerable
fi
ap/hplip-3.23.12-x86_64-3.txz: Rebuilt.
ap/linuxdoc-tools-0.9.82-x86_64-5.txz: Rebuilt.
ap/rpm-4.19.1.1-x86_64-2.txz: Rebuilt.
ap/undervolt-20210815_e39aea1-x86_64-3.txz: Rebuilt.
ap/vim-9.1.0225-x86_64-1.txz: Upgraded.
d/Cython-3.0.9-x86_64-2.txz: Rebuilt.
d/distcc-3.4-x86_64-5.txz: Rebuilt.
d/gdb-14.2-x86_64-2.txz: Rebuilt.
d/gyp-20210831_d6c5dd51-x86_64-3.txz: Rebuilt.
d/llvm-18.1.2-x86_64-2.txz: Rebuilt.
d/mercurial-6.7.1-x86_64-2.txz: Rebuilt.
d/meson-1.4.0-x86_64-2.txz: Rebuilt.
d/python-pip-24.0-x86_64-2.txz: Rebuilt.
d/python-setuptools-69.2.0-x86_64-2.txz: Rebuilt.
d/python3-3.11.8-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
d/scons-4.7.0-x86_64-2.txz: Rebuilt.
kde/cantor-23.08.5-x86_64-4.txz: Rebuilt.
kde/kapidox-5.115.0-x86_64-2.txz: Rebuilt.
kde/kdev-python-23.08.5-x86_64-2.txz: Rebuilt.
kde/kig-23.08.5-x86_64-2.txz: Rebuilt.
kde/kmymoney-5.1.3-x86_64-4.txz: Rebuilt.
kde/kopeninghours-23.08.5-x86_64-2.txz: Rebuilt.
kde/krita-5.2.2-x86_64-6.txz: Rebuilt.
l/M2Crypto-0.41.0-x86_64-2.txz: Rebuilt.
l/Mako-1.3.2-x86_64-2.txz: Rebuilt.
l/PyQt-builder-1.15.4-x86_64-2.txz: Rebuilt.
l/PyQt5-5.15.10-x86_64-2.txz: Rebuilt.
l/PyQt5_sip-12.13.0-x86_64-2.txz: Rebuilt.
l/QScintilla-2.14.1-x86_64-3.txz: Rebuilt.
l/avahi-20240306_709e60f-x86_64-2.txz: Rebuilt.
l/brotli-1.1.0-x86_64-2.txz: Rebuilt.
l/dbus-python-1.3.2-x86_64-2.txz: Rebuilt.
l/gexiv2-0.14.2-x86_64-3.txz: Rebuilt.
l/gi-docgen-2023.3-x86_64-2.txz: Rebuilt.
l/glade-3.40.0-x86_64-2.txz: Rebuilt.
l/gobject-introspection-1.80.0-x86_64-2.txz: Rebuilt.
l/harfbuzz-8.4.0-x86_64-1.txz: Upgraded.
l/lensfun-0.3.4-x86_64-2.txz: Rebuilt.
l/libcaca-0.99.beta20-x86_64-2.txz: Rebuilt.
l/libcap-ng-0.8.4-x86_64-2.txz: Rebuilt.
l/libieee1284-0.2.11-x86_64-8.txz: Rebuilt.
l/libimobiledevice-20231007_04c0233-x86_64-2.txz: Rebuilt.
l/libnvme-1.8-x86_64-2.txz: Rebuilt.
l/libplist-2.4.0-x86_64-2.txz: Rebuilt.
l/libwebp-1.3.2-x86_64-3.txz: Rebuilt.
l/libxml2-2.12.6-x86_64-3.txz: Rebuilt.
l/libxslt-1.1.39-x86_64-2.txz: Rebuilt.
l/newt-0.52.24-x86_64-3.txz: Rebuilt.
l/protobuf-26.1-x86_64-2.txz: Rebuilt.
l/pycairo-1.26.0-x86_64-3.txz: Rebuilt.
l/pycups-2.0.1-x86_64-7.txz: Rebuilt.
l/pycurl-7.45.3-x86_64-2.txz: Rebuilt.
l/pygobject3-3.48.1-x86_64-2.txz: Rebuilt.
l/pyparsing-3.1.2-x86_64-2.txz: Rebuilt.
l/python-Jinja2-3.1.3-x86_64-2.txz: Rebuilt.
l/python-MarkupSafe-2.1.5-x86_64-2.txz: Rebuilt.
l/python-PyYAML-6.0.1-x86_64-3.txz: Rebuilt.
l/python-alabaster-0.7.16-x86_64-2.txz: Rebuilt.
l/python-appdirs-1.4.4-x86_64-7.txz: Rebuilt.
l/python-babel-2.14.0-x86_64-2.txz: Rebuilt.
l/python-build-1.2.1-x86_64-2.txz: Rebuilt.
l/python-calver-2022.6.26-x86_64-2.txz: Rebuilt.
l/python-certifi-2024.2.2-x86_64-2.txz: Rebuilt.
l/python-cffi-1.16.0-x86_64-2.txz: Rebuilt.
l/python-chardet-5.2.0-x86_64-2.txz: Rebuilt.
l/python-charset-normalizer-3.3.2-x86_64-2.txz: Rebuilt.
l/python-distro-1.9.0-x86_64-2.txz: Rebuilt.
l/python-dnspython-2.6.1-x86_64-2.txz: Rebuilt.
l/python-docutils-0.20.1-x86_64-2.txz: Rebuilt.
l/python-doxypypy-0.8.8.7-x86_64-2.txz: Rebuilt.
l/python-doxyqml-0.5.3-x86_64-2.txz: Rebuilt.
l/python-editables-0.5-x86_64-2.txz: Rebuilt.
l/python-flit-core-3.9.0-x86_64-2.txz: Rebuilt.
l/python-future-1.0.0-x86_64-2.txz: Rebuilt.
l/python-glad2-2.0.6-x86_64-2.txz: Rebuilt.
l/python-hatchling-1.22.4-x86_64-2.txz: Rebuilt.
l/python-html5lib-1.1-x86_64-2.txz: Rebuilt.
l/python-idna-3.6-x86_64-2.txz: Rebuilt.
l/python-imagesize-1.4.1-x86_64-2.txz: Rebuilt.
l/python-importlib_metadata-7.1.0-x86_64-2.txz: Rebuilt.
l/python-installer-0.7.0-x86_64-2.txz: Rebuilt.
l/python-lxml-5.1.1-x86_64-1.txz: Upgraded.
l/python-markdown-3.6-x86_64-2.txz: Rebuilt.
l/python-notify2-0.3.1-x86_64-11.txz: Rebuilt.
l/python-packaging-24.0-x86_64-2.txz: Rebuilt.
l/python-pathspec-0.12.1-x86_64-2.txz: Rebuilt.
l/python-pbr-6.0.0-x86_64-2.txz: Rebuilt.
l/python-pillow-10.2.0-x86_64-2.txz: Rebuilt.
l/python-pluggy-1.4.0-x86_64-2.txz: Rebuilt.
l/python-ply-3.11-x86_64-9.txz: Rebuilt.
l/python-psutil-5.9.8-x86_64-2.txz: Rebuilt.
l/python-pycparser-2.21-x86_64-2.txz: Rebuilt.
l/python-pygments-2.17.2-x86_64-2.txz: Rebuilt.
l/python-pyproject-hooks-1.0.0-x86_64-2.txz: Rebuilt.
l/python-pysol_cards-0.16.0-x86_64-2.txz: Rebuilt.
l/python-pytz-2024.1-x86_64-2.txz: Rebuilt.
l/python-random2-1.0.2-x86_64-2.txz: Rebuilt.
l/python-requests-2.31.0-x86_64-2.txz: Rebuilt.
l/python-sane-2.9.1-x86_64-6.txz: Rebuilt.
l/python-setuptools_scm-8.0.4-x86_64-2.txz: Rebuilt.
l/python-six-1.16.0-x86_64-4.txz: Rebuilt.
l/python-smartypants-2.0.1-x86_64-2.txz: Rebuilt.
l/python-snowballstemmer-2.2.0-x86_64-2.txz: Rebuilt.
l/python-sphinx-7.2.6-x86_64-2.txz: Rebuilt.
l/python-sphinx_rtd_theme-2.0.0-x86_64-2.txz: Rebuilt.
l/python-tomli-2.0.1-x86_64-2.txz: Rebuilt.
l/python-tomli-w-1.0.0-x86_64-2.txz: Rebuilt.
l/python-trove-classifiers-2024.3.25-x86_64-2.txz: Rebuilt.
l/python-typing_extensions-4.10.0-x86_64-2.txz: Rebuilt.
l/python-typogrify-2.0.7-x86_64-2.txz: Rebuilt.
l/python-urllib3-2.2.1-x86_64-2.txz: Rebuilt.
l/python-webencodings-0.5.1-x86_64-2.txz: Rebuilt.
l/python-wheel-0.43.0-x86_64-2.txz: Rebuilt.
l/python-zipp-3.18.1-x86_64-2.txz: Rebuilt.
l/sip-6.8.3-x86_64-2.txz: Rebuilt.
l/speech-dispatcher-0.11.5-x86_64-2.txz: Rebuilt.
l/system-config-printer-1.5.18-x86_64-2.txz: Rebuilt.
l/talloc-2.4.2-x86_64-2.txz: Rebuilt.
l/tdb-1.4.10-x86_64-2.txz: Rebuilt.
l/tevent-0.16.1-x86_64-2.txz: Rebuilt.
n/epic5-2.1.12-x86_64-7.txz: Rebuilt.
n/fetchmail-6.4.38-x86_64-2.txz: Rebuilt.
n/getmail-6.18.14-x86_64-2.txz: Rebuilt.
n/gpgme-1.23.2-x86_64-3.txz: Rebuilt.
n/net-snmp-5.9.4-x86_64-2.txz: Rebuilt.
n/nftables-1.0.9-x86_64-2.txz: Rebuilt.
n/nmap-7.94-x86_64-2.txz: Rebuilt.
n/nss-pam-ldapd-0.9.12-x86_64-4.txz: Rebuilt.
n/obexftp-0.24.2-x86_64-12.txz: Rebuilt.
n/pssh-2.3.5-x86_64-2.txz: Rebuilt.
n/samba-4.20.0-x86_64-2.txz: Rebuilt.
x/ibus-1.5.29-x86_64-3.txz: Rebuilt.
x/ibus-anthy-1.5.16-x86_64-2.txz: Rebuilt.
x/ibus-hangul-1.5.5-x86_64-2.txz: Rebuilt.
x/ibus-libpinyin-1.15.7-x86_64-2.txz: Rebuilt.
x/ibus-table-1.17.4-x86_64-2.txz: Rebuilt.
x/marisa-0.2.6-x86_64-9.txz: Rebuilt.
x/pyxdg-0.28-x86_64-2.txz: Rebuilt.
x/xcb-proto-1.16.0-x86_64-3.txz: Rebuilt.
xap/blueman-2.3.5-x86_64-2.txz: Rebuilt.
xap/hexchat-2.16.2-x86_64-2.txz: Rebuilt.
xap/vim-gvim-9.1.0225-x86_64-1.txz: Upgraded.
extra/brltty/brltty-6.6-x86_64-3.txz: Rebuilt.
20240329203911 | Patrick J Volkerding | 2024-03-29 | 1 | -5/+0 |
* | Sat Mar 23 19:34:02 UTC 2024...ap/vim-9.1.0199-x86_64-1.txz: Upgraded.
Dropped python2 support. Thanks to Audrius Kažukauskas.
l/duktape-2.7.0-x86_64-1.txz: Added.
Needed by polkit.
l/gjs-1.80.1-x86_64-1.txz: Upgraded.
l/libdeflate-1.20-x86_64-1.txz: Upgraded.
l/mozjs102-102.15.1esr-x86_64-2.txz: Removed.
l/mozjs115-115.9.1esr-x86_64-1.txz: Upgraded.
l/polkit-123-x86_64-2.txz: Rebuilt.
Use duktape instead of mozjs102 as the JavaScript engine.
x/iceauth-1.0.10-x86_64-2.txz: Rebuilt.
It's never too early to build with --enable-year2038. Thanks to bigbadaboum.
xap/geeqie-2.4-x86_64-1.txz: Upgraded.
xap/mozilla-firefox-115.9.1esr-x86_64-1.txz: Upgraded.
This update fixes a critical security issue:
An attacker was able to inject an event handler into a privileged object
that would allow arbitrary JavaScript execution in the parent process.
For more information, see:
https://www.mozilla.org/en-US/firefox/115.9.1esr/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2024-16/
https://www.cve.org/CVERecord?id=CVE-2024-29944
(* Security fix *)
xap/vim-gvim-9.1.0199-x86_64-1.txz: Upgraded.
Dropped python2 support. Thanks to Audrius Kažukauskas.
20240323193402 | Patrick J Volkerding | 2024-03-23 | 1 | -13/+0 |
* | Fri Mar 22 20:16:55 UTC 2024...a/volume_key-0.3.12-x86_64-7.txz: Rebuilt.
Build python3 bindings.
l/atkmm2-2.36.3-x86_64-1.txz: Added.
l/boost-1.84.0-x86_64-2.txz: Rebuilt.
Drop python2 support.
l/glibmm-2.66.7-x86_64-1.txz: Upgraded.
l/gst-plugins-bad-free-1.24.1-x86_64-1.txz: Upgraded.
l/gst-plugins-base-1.24.1-x86_64-1.txz: Upgraded.
l/gst-plugins-good-1.24.1-x86_64-1.txz: Upgraded.
l/gst-plugins-libav-1.24.1-x86_64-1.txz: Upgraded.
l/gstreamer-1.24.1-x86_64-1.txz: Upgraded.
l/gtkmm4-4.14.0-x86_64-1.txz: Upgraded.
l/unicode-ucd-15.1.0-noarch-1.txz: Added.
153MB installed... oh well. Needed by gucharmap.
xap/gucharmap-15.1.3-x86_64-1.txz: Upgraded.
xap/x3270-4.3ga7-x86_64-1.txz: Upgraded.
20240322201655 | Patrick J Volkerding | 2024-03-22 | 1 | -1/+4 |
* | Wed Mar 20 00:08:59 UTC 2024...a/sysvinit-scripts-15.1-noarch-14.txz: Rebuilt.
rc.S: fix motd matching so that it works on a fresh install.
d/scons-4.7.0-x86_64-1.txz: Upgraded.
l/adwaita-icon-theme-46.0-noarch-1.txz: Upgraded.
l/at-spi2-core-2.52.0-x86_64-1.txz: Upgraded.
l/gcr4-4.2.1-x86_64-1.txz: Added.
l/gjs-1.80.0-x86_64-1.txz: Upgraded.
l/glib-networking-2.80.0-x86_64-1.txz: Upgraded.
l/glib2-2.80.0-x86_64-1.txz: Upgraded.
l/gobject-introspection-1.80.0-x86_64-1.txz: Upgraded.
l/gsettings-desktop-schemas-46.0-x86_64-1.txz: Upgraded.
l/gtk4-4.14.1-x86_64-1.txz: Upgraded.
l/gvfs-1.54.0-x86_64-1.txz: Upgraded.
l/librsvg-2.58.0-x86_64-1.txz: Upgraded.
l/mozjs115-115.9.0esr-x86_64-1.txz: Added.
Needed by gjs-1.80.0.
l/newt-0.52.24-x86_64-2.txz: Rebuilt.
Drop python2 support.
l/pygobject3-3.48.1-x86_64-1.txz: Upgraded.
l/python-glad2-2.0.6-x86_64-1.txz: Upgraded.
l/python-hatchling-1.22.3-x86_64-1.txz: Upgraded.
l/vte-0.76.0-x86_64-1.txz: Upgraded.
l/wireplumber-0.5.0-x86_64-1.txz: Upgraded.
n/gnutls-3.8.4-x86_64-1.txz: Upgraded.
This update fixes two medium severity security issues:
libgnutls: Fix side-channel in the deterministic ECDSA.
Reported by George Pantelakis (#1516).
libgnutls: Fixed a bug where certtool crashed when verifying a certificate
chain with more than 16 certificates. Reported by William Woodruff (#1525)
and yixiangzhike (#1527).
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2024-28834
https://www.cve.org/CVERecord?id=CVE-2024-28835
(* Security fix *)
xap/mozilla-firefox-115.9.0esr-x86_64-1.txz: Upgraded.
This update contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/firefox/115.9.0/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2024-13/
https://www.cve.org/CVERecord?id=CVE-2024-0743
https://www.cve.org/CVERecord?id=CVE-2024-2605
https://www.cve.org/CVERecord?id=CVE-2024-2607
https://www.cve.org/CVERecord?id=CVE-2024-2608
https://www.cve.org/CVERecord?id=CVE-2024-2616
https://www.cve.org/CVERecord?id=CVE-2023-5388
https://www.cve.org/CVERecord?id=CVE-2024-2610
https://www.cve.org/CVERecord?id=CVE-2024-2611
https://www.cve.org/CVERecord?id=CVE-2024-2612
https://www.cve.org/CVERecord?id=CVE-2024-2614
(* Security fix *)
xap/mozilla-thunderbird-115.9.0-x86_64-1.txz: Upgraded.
This release contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/thunderbird/115.9.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2024-14/
https://www.cve.org/CVERecord?id=CVE-2024-0743
https://www.cve.org/CVERecord?id=CVE-2024-2605
https://www.cve.org/CVERecord?id=CVE-2024-2607
https://www.cve.org/CVERecord?id=CVE-2024-2608
https://www.cve.org/CVERecord?id=CVE-2024-2616
https://www.cve.org/CVERecord?id=CVE-2023-5388
https://www.cve.org/CVERecord?id=CVE-2024-2610
https://www.cve.org/CVERecord?id=CVE-2024-2611
https://www.cve.org/CVERecord?id=CVE-2024-2612
https://www.cve.org/CVERecord?id=CVE-2024-2614
(* Security fix *)
20240320000859 | Patrick J Volkerding | 2024-03-20 | 1 | -0/+13 |
* | Thu Mar 14 20:01:17 UTC 2024...a/cryptsetup-2.7.1-x86_64-1.txz: Upgraded.
a/elogind-252.23-x86_64-2.txz: Rebuilt.
Install /etc/pam.d/elogind-user as .new. Thanks to Markus Wiesner.
a/kmod-32-x86_64-1.txz: Upgraded.
a/tcsh-6.24.11-x86_64-1.txz: Upgraded.
ap/a2ps-4.15.6-x86_64-1.txz: Upgraded.
d/vala-0.56.16-x86_64-1.txz: Upgraded.
l/avahi-20240306_709e60f-x86_64-1.txz: Upgraded.
Don't reload dbus from the installer.
x/mesa-24.0.3-x86_64-1.txz: Upgraded.
xap/xlockmore-5.76-x86_64-1.txz: Upgraded.
xfce/xfce4-screensaver-4.18.3-x86_64-2.txz: Rebuilt.
Install /etc/pam.d/xfce4-screensaver as .new. Thanks to Markus Wiesner.
20240314200117 | Patrick J Volkerding | 2024-03-14 | 1 | -3/+1 |
* | Wed Mar 13 19:46:48 UTC 2024...a/etc-15.1-x86_64-9.txz: Rebuilt.
Added proftpd user (97) and proftpd group (97).
Added nm-openvpn user (320) and nm-openvpn group (320).
Added openvpn user (443) and openvpn group (443).
Added overflowuid user (65534) and overflowgid group (65534).
Thanks to opty for encouraging us to think about nobody.
d/meson-1.4.0-x86_64-1.txz: Upgraded.
d/python-setuptools-69.2.0-x86_64-1.txz: Upgraded.
l/expat-2.6.2-x86_64-1.txz: Upgraded.
Prevent billion laughs attacks with isolated use of external parsers.
For more information, see:
https://github.com/libexpat/libexpat/commit/1d50b80cf31de87750103656f6eb693746854aa8
https://www.cve.org/CVERecord?id=CVE-2024-28757
(* Security fix *)
l/pipewire-1.0.4-x86_64-1.txz: Upgraded.
l/python-zipp-3.18.0-x86_64-1.txz: Upgraded.
n/openvpn-2.6.9-x86_64-2.txz: Rebuilt.
Run as openvpn:openvpn. Thanks to rkelsen.
n/proftpd-1.3.8b-x86_64-2.txz: Rebuilt.
Run as proftpd:proftpd.
x/libva-2.21.0-x86_64-1.txz: Upgraded.
x/libva-utils-2.21.0-x86_64-1.txz: Upgraded.
xap/NetworkManager-openvpn-1.10.2-x86_64-2.txz: Rebuilt.
Run as nm-openvpn:nm-openvpn. Thanks to Markus Wiesner.
20240313194648 | Patrick J Volkerding | 2024-03-13 | 1 | -1/+0 |
* | Tue Mar 12 19:49:57 UTC 2024...a/elogind-252.23-x86_64-1.txz: Upgraded.
ap/sqlite-3.45.2-x86_64-1.txz: Upgraded.
l/jasper-4.2.2-x86_64-1.txz: Upgraded.
l/libpaper-2.2.5-x86_64-1.txz: Upgraded.
l/netpbm-11.05.03-x86_64-1.txz: Upgraded.
l/python-wheel-0.43.0-x86_64-1.txz: Upgraded.
n/iproute2-6.8.0-x86_64-1.txz: Upgraded.
xap/sane-1.3.0-x86_64-1.txz: Upgraded.
20240312194957 | Patrick J Volkerding | 2024-03-12 | 1 | -1/+0 |
* | Sat Mar 9 21:56:02 UTC 2024...a/aaa_libraries-15.1-x86_64-28.txz: Rebuilt.
Upgraded: libelf-0.191.so, liblzma.so.5.6.1, libexpat.so.1.9.1.
a/shadow-4.15.0-x86_64-1.txz: Upgraded.
a/xz-5.6.1-x86_64-1.txz: Upgraded.
d/llvm-18.1.1-x86_64-1.txz: Upgraded.
l/libclc-18.1.1-x86_64-1.txz: Upgraded.
l/xapian-core-1.4.25-x86_64-1.txz: Upgraded.
n/mutt-2.2.13-x86_64-1.txz: Upgraded.
20240309215602 | Patrick J Volkerding | 2024-03-09 | 1 | -1/+0 |
* | Fri Mar 8 19:20:11 UTC 2024...n/bluez-5.73-x86_64-1.txz: Upgraded.
xap/geeqie-2.3-x86_64-1.txz: Upgraded.
xfce/libxfce4ui-4.18.6-x86_64-1.txz: Upgraded.
xfce/xfce4-weather-plugin-0.11.2-x86_64-1.txz: Upgraded.
20240308192011 | Patrick J Volkerding | 2024-03-08 | 1 | -1/+0 |
* | Thu Mar 7 20:40:08 UTC 2024...ap/ghostscript-10.03.0-x86_64-1.txz: Upgraded.
This update addresses a security issue:
A vulnerability was identified in the way Ghostscript/GhostPDL called
tesseract for the OCR devices, which could allow arbitrary code execution.
Thanks to J_W for the heads-up.
(* Security fix *)
ap/lxc-4.0.12-x86_64-3.txz: Rebuilt.
lxc-slackware.in: include gnupg2 (not gnupg) for slackpkg.
ap/slackpkg-15.0.10-noarch-3.txz: Rebuilt.
core-functions.sh: use gpg2, not gpg.
d/Cython-3.0.9-x86_64-1.txz: Upgraded.
d/git-2.44.0-x86_64-2.txz: Rebuilt.
Include git-subtree. Thanks to gwhl.
d/llvm-18.1.0-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
kde/kdevelop-23.08.5-x86_64-2.txz: Rebuilt.
Recompiled against llvm-18.1.0.
l/openexr-3.2.3-x86_64-1.txz: Upgraded.
l/python-importlib_metadata-7.0.2-x86_64-1.txz: Upgraded.
l/python-trove-classifiers-2024.3.3-x86_64-1.txz: Upgraded.
l/qt5-5.15.12_20240228_6609503f-x86_64-1.txz: Upgraded.
Compiled against llvm-18.1.0.
l/qt6-6.6.2_20240210_15b7e743-x86_64-3.txz: Rebuilt.
Recompiled against llvm-18.1.0.
l/spirv-llvm-translator-18.1.0-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
n/gnupg2-2.4.5-x86_64-1.txz: Upgraded.
n/libassuan-2.5.7-x86_64-1.txz: Upgraded.
n/postfix-3.9.0-x86_64-1.txz: Upgraded.
x/mesa-24.0.2-x86_64-2.txz: Rebuilt.
Recompiled against llvm-18.1.0 and spirv-llvm-translator-18.1.0.
isolinux/initrd.img: Rebuilt.
Fixed kernel version. Thanks to chrisVV.
usb-and-pxe-installers/usbboot.img: Rebuilt.
Fixed kernel version. Thanks to chrisVV.
20240307204008 | Patrick J Volkerding | 2024-03-07 | 1 | -0/+1 |
* | Wed Feb 28 18:36:48 UTC 2024...d/parallel-20240222-noarch-1.txz: Upgraded.
kde/krita-5.2.2-x86_64-4.txz: Rebuilt.
Recompiled against libunibreak-6.0.
l/accountsservice-23.13.9-x86_64-1.txz: Upgraded.
Thanks to reddog83.
l/libass-0.17.1-x86_64-2.txz: Rebuilt.
Recompiled against libunibreak-6.0.
l/libunibreak-6.0-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
l/orc-0.4.38-x86_64-1.txz: Upgraded.
l/python-requests-2.31.0-x86_64-1.txz: Upgraded.
l/python-urllib3-2.2.1-x86_64-1.txz: Upgraded.
l/qt6-6.6.2_20240210_15b7e743-x86_64-1.txz: Added.
n/wpa_supplicant-2.10-x86_64-3.txz: Rebuilt.
Patched the implementation of PEAP in wpa_supplicant to prevent an
authentication bypass. For a successful attack, wpa_supplicant must be
configured to not verify the network's TLS certificate during Phase 1
authentication, and an eap_peap_decrypt vulnerability can then be abused
to skip Phase 2 authentication. The attack vector is sending an EAP-TLV
Success packet instead of starting Phase 2. This allows an adversary to
impersonate Enterprise Wi-Fi networks.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2023-52160
(* Security fix *)
xap/gparted-1.6.0-x86_64-1.txz: Upgraded.
20240228183648 | Patrick J Volkerding | 2024-02-28 | 1 | -0/+1 |
* | Fri Feb 23 20:37:29 UTC 2024...a/dcron-4.5-x86_64-17.txz: Rebuilt.
run-parts.8: document skiping *.orig files. Thanks to metaed.
a/etc-15.1-x86_64-6.txz: Rebuilt.
Add support for nss-mdns to /etc/nsswitch.conf.
a/kernel-firmware-20240220_97b693d-noarch-1.txz: Upgraded.
a/kernel-generic-6.6.18-x86_64-1.txz: Upgraded.
a/kernel-huge-6.6.18-x86_64-1.txz: Upgraded.
a/kernel-modules-6.6.18-x86_64-1.txz: Upgraded.
ap/cups-filters-1.28.17-x86_64-5.txz: Rebuilt.
Don't specify --with-browseremoteprotocols=cups in order to get the default
values of cups and dnssd, which should enable discovering shared printers on
the network. We'll refrain from sharing your printer -- you'll need to change
that setting yourself. ;-)
Thanks to TurboBlaze.
ap/hplip-3.23.12-x86_64-2.txz: Rebuilt.
The new --disable-imageProcessor-build option doesn't do squat, so we'll hit
it with the good old patch again.
Thanks to Petri Kaukasoina and Stuart Winter.
d/kernel-headers-6.6.18-x86-1.txz: Upgraded.
k/kernel-source-6.6.18-noarch-1.txz: Upgraded.
l/gvfs-1.52.2-x86_64-2.txz: Rebuilt.
Added -Ddnssd=true option and recompiled against avahi.
l/libsecret-0.21.4-x86_64-1.txz: Upgraded.
n/c-ares-1.27.0-x86_64-1.txz: Upgraded.
n/libgpg-error-1.48-x86_64-1.txz: Upgraded.
n/nss-mdns-0.15.1-x86_64-1.txz: Added.
Needed for .local lookups. Thanks to Lockywolf.
xap/pidgin-2.14.13-x86_64-1.txz: Upgraded.
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
usb-and-pxe-installers/usbboot.img: Rebuilt.
20240223203729 | Patrick J Volkerding | 2024-02-23 | 1 | -1/+1 |
* | Fri Feb 23 02:27:35 UTC 2024...a/aaa_libraries-15.1-x86_64-26.txz: Rebuilt.
Upgraded: libacl.so.1.1.2302, libattr.so.1.1.2502, liblzma.so.5.4.6,
libpcre2-8.so.0.12.0, libz.so.1.3.1, libcares.so.2.11.0,
libexpat.so.1.9.0, libffi.so.8.1.4, libglib-2.0.so.0.7800.4,
libgmodule-2.0.so.0.7800.4, libgobject-2.0.so.0.7800.4,
libgthread-2.0.so.0.7800.4, libidn.so.12.6.5, libidn2.so.0.4.0,
libpng16.so.16.41.0, libpsl.so.5.3.5, libtdb.so.1.4.10, libusb-1.0.so.0.4.0.
a/etc-15.1-x86_64-5.txz: Rebuilt.
Added UID 214 and GID 214 for avahi.
a/gettext-0.22.5-x86_64-1.txz: Upgraded.
a/pkgtools-15.1-noarch-9.txz: Rebuilt.
setup.services: support rc.avahidaemon and rc.avahidnsconfd.
a/sysvinit-scripts-15.1-noarch-13.txz: Rebuilt.
rc.M: start (if executable) rc.avahidaemon and rc.avahidnsconfd.
ap/cups-2.4.7-x86_64-2.txz: Rebuilt.
Recompiled against avahi.
ap/cups-filters-1.28.17-x86_64-4.txz: Rebuilt.
Recompiled against avahi.
ap/hplip-3.23.12-x86_64-1.txz: Upgraded.
Compiled against avahi.
ap/xmltoman-0.6-x86_64-1.txz: Added.
This is needed to generate manpages for avahi.
d/distcc-3.4-x86_64-4.txz: Rebuilt.
Recompiled against avahi.
d/gettext-tools-0.22.5-x86_64-1.txz: Upgraded.
l/avahi-20240220_dffd549-x86_64-1.txz: Added.
It was either this, or drop (or fork) hplip. We'll enjoy it in the long run.
Thanks to David Somero for the original build script, and to Robby Workman
for years of maintenance.
Signed-off-by: volkerdi
Acked-by: alienBOB
l/libdaemon-0.14-x86_64-1.txz: Added.
This is needed by avahi.
l/pipewire-1.0.3-x86_64-5.txz: Rebuilt.
Recompiled against avahi.
l/pulseaudio-17.0-x86_64-3.txz: Rebuilt.
Recompiled against avahi.
n/NetworkManager-1.46.0-x86_64-1.txz: Upgraded.
n/netatalk-3.1.18-x86_64-2.txz: Rebuilt.
Recompiled against avahi.
n/samba-4.19.5-x86_64-2.txz: Rebuilt.
Recompiled against avahi.
xap/pidgin-2.14.12-x86_64-3.txz: Rebuilt.
Recompiled against avahi.
xap/sane-1.2.1-x86_64-3.txz: Rebuilt.
Recompiled against avahi.
extra/bash-completion/bash-completion-2.12.0-noarch-1.txz: Upgraded.
20240223022735 | Patrick J Volkerding | 2024-02-23 | 1 | -4/+2 |
* | Wed Feb 21 20:00:08 UTC 2024...a/dcron-4.5-x86_64-16.txz: Rebuilt.
run-parts: skip *.orig files. Thanks to metaed.
l/libplist-2.4.0-x86_64-1.txz: Upgraded.
xap/mozilla-thunderbird-115.8.0-x86_64-1.txz: Upgraded.
This release contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/thunderbird/115.8.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2024-07/
https://www.cve.org/CVERecord?id=CVE-2024-1546
https://www.cve.org/CVERecord?id=CVE-2024-1547
https://www.cve.org/CVERecord?id=CVE-2024-1548
https://www.cve.org/CVERecord?id=CVE-2024-1549
https://www.cve.org/CVERecord?id=CVE-2024-1550
https://www.cve.org/CVERecord?id=CVE-2024-1551
https://www.cve.org/CVERecord?id=CVE-2024-1552
https://www.cve.org/CVERecord?id=CVE-2024-1553
(* Security fix *)
20240221200008 | Patrick J Volkerding | 2024-02-21 | 1 | -1/+0 |
* | Tue Feb 20 18:41:59 UTC 2024...a/gptfdisk-1.0.10-x86_64-1.txz: Upgraded.
l/cxxopts-3.2.1-x86_64-1.txz: Upgraded.
l/jasper-4.2.1-x86_64-1.txz: Upgraded.
x/xterm-390-x86_64-1.txz: Upgraded.
xap/mozilla-firefox-115.8.0esr-x86_64-1.txz: Upgraded.
This update contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/firefox/115.8.0/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2024-06/
https://www.cve.org/CVERecord?id=CVE-2024-1546
https://www.cve.org/CVERecord?id=CVE-2024-1547
https://www.cve.org/CVERecord?id=CVE-2024-1548
https://www.cve.org/CVERecord?id=CVE-2024-1549
https://www.cve.org/CVERecord?id=CVE-2024-1550
https://www.cve.org/CVERecord?id=CVE-2024-1551
https://www.cve.org/CVERecord?id=CVE-2024-1552
https://www.cve.org/CVERecord?id=CVE-2024-1553
(* Security fix *)
20240220184159 | Patrick J Volkerding | 2024-02-20 | 1 | -3/+0 |
* | Fri Feb 16 20:18:59 UTC 2024...a/kernel-generic-6.6.17-x86_64-1.txz: Upgraded.
a/kernel-huge-6.6.17-x86_64-1.txz: Upgraded.
a/kernel-modules-6.6.17-x86_64-1.txz: Upgraded.
ap/soma-3.3.7-noarch-3.txz: Rebuilt.
Strip trailing whitespace from soma.desktop. Thanks to DryFalls.
d/kernel-headers-6.6.17-x86-1.txz: Upgraded.
k/kernel-source-6.6.17-noarch-1.txz: Upgraded.
l/mozilla-nss-3.98-x86_64-1.txz: Upgraded.
n/ca-certificates-20240216-noarch-1.txz: Upgraded.
This update provides the latest CA certificates to check for the
authenticity of SSL connections.
x/ibus-m17n-1.4.28-x86_64-1.txz: Upgraded.
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
usb-and-pxe-installers/usbboot.img: Rebuilt.
20240216201859 | Patrick J Volkerding | 2024-02-16 | 1 | -1/+0 |
* | Fri Feb 16 02:19:13 UTC 2024...a/etc-15.1-x86_64-4.txz: Rebuilt.
Added UID 303 and GID 303 for colord.
ap/nvme-cli-2.8-x86_64-1.txz: Upgraded.
kde/akonadi-23.08.5-x86_64-1.txz: Upgraded.
kde/akonadi-calendar-23.08.5-x86_64-1.txz: Upgraded.
kde/akonadi-calendar-tools-23.08.5-x86_64-1.txz: Upgraded.
kde/akonadi-contacts-23.08.5-x86_64-1.txz: Upgraded.
kde/akonadi-import-wizard-23.08.5-x86_64-1.txz: Upgraded.
kde/akonadi-mime-23.08.5-x86_64-1.txz: Upgraded.
kde/akonadi-notes-23.08.5-x86_64-1.txz: Upgraded.
kde/akonadi-search-23.08.5-x86_64-1.txz: Upgraded.
kde/akonadiconsole-23.08.5-x86_64-1.txz: Upgraded.
kde/akregator-23.08.5-x86_64-1.txz: Upgraded.
kde/alligator-23.08.5-x86_64-1.txz: Upgraded.
kde/analitza-23.08.5-x86_64-1.txz: Upgraded.
kde/ark-23.08.5-x86_64-1.txz: Upgraded.
kde/artikulate-23.08.5-x86_64-1.txz: Upgraded.
kde/audiocd-kio-23.08.5-x86_64-1.txz: Upgraded.
kde/baloo-widgets-23.08.5-x86_64-1.txz: Upgraded.
kde/blinken-23.08.5-x86_64-1.txz: Upgraded.
kde/bomber-23.08.5-x86_64-1.txz: Upgraded.
kde/bovo-23.08.5-x86_64-1.txz: Upgraded.
kde/calendarsupport-23.08.5-x86_64-1.txz: Upgraded.
kde/cantor-23.08.5-x86_64-1.txz: Upgraded.
kde/cervisia-23.08.5-x86_64-1.txz: Upgraded.
kde/colord-kde-23.08.5-x86_64-1.txz: Added.
kde/dolphin-23.08.5-x86_64-1.txz: Upgraded.
kde/dolphin-plugins-23.08.5-x86_64-1.txz: Upgraded.
kde/dragon-23.08.5-x86_64-1.txz: Upgraded.
kde/elisa-23.08.5-x86_64-1.txz: Upgraded.
kde/eventviews-23.08.5-x86_64-1.txz: Upgraded.
kde/falkon-23.08.5-x86_64-1.txz: Upgraded.
kde/ffmpegthumbs-23.08.5-x86_64-1.txz: Upgraded.
kde/filelight-23.08.5-x86_64-1.txz: Upgraded.
kde/ghostwriter-23.08.5-x86_64-1.txz: Upgraded.
kde/granatier-23.08.5-x86_64-1.txz: Upgraded.
kde/grantlee-editor-23.08.5-x86_64-1.txz: Upgraded.
kde/grantleetheme-23.08.5-x86_64-1.txz: Upgraded.
kde/gwenview-23.08.5-x86_64-1.txz: Upgraded.
kde/incidenceeditor-23.08.5-x86_64-1.txz: Upgraded.
kde/itinerary-23.08.5-x86_64-1.txz: Upgraded.
kde/juk-23.08.5-x86_64-1.txz: Upgraded.
kde/k3b-23.08.5-x86_64-1.txz: Upgraded.
kde/kaddressbook-23.08.5-x86_64-1.txz: Upgraded.
kde/kalarm-23.08.5-x86_64-1.txz: Upgraded.
kde/kalgebra-23.08.5-x86_64-1.txz: Upgraded.
kde/kalzium-23.08.5-x86_64-1.txz: Upgraded.
kde/kamera-23.08.5-x86_64-1.txz: Upgraded.
kde/kamoso-23.08.5-x86_64-1.txz: Upgraded.
kde/kanagram-23.08.5-x86_64-1.txz: Upgraded.
kde/kapman-23.08.5-x86_64-1.txz: Upgraded.
kde/kapptemplate-23.08.5-x86_64-1.txz: Upgraded.
kde/kate-23.08.5-x86_64-1.txz: Upgraded.
kde/katomic-23.08.5-x86_64-1.txz: Upgraded.
kde/kbackup-23.08.5-x86_64-1.txz: Upgraded.
kde/kblackbox-23.08.5-x86_64-1.txz: Upgraded.
kde/kblocks-23.08.5-x86_64-1.txz: Upgraded.
kde/kbounce-23.08.5-x86_64-1.txz: Upgraded.
kde/kbreakout-23.08.5-x86_64-1.txz: Upgraded.
kde/kbruch-23.08.5-x86_64-1.txz: Upgraded.
kde/kcachegrind-23.08.5-x86_64-1.txz: Upgraded.
kde/kcalc-23.08.5-x86_64-1.txz: Upgraded.
kde/kcalutils-23.08.5-x86_64-1.txz: Upgraded.
kde/kcharselect-23.08.5-x86_64-1.txz: Upgraded.
kde/kcolorchooser-23.08.5-x86_64-1.txz: Upgraded.
kde/kcron-23.08.5-x86_64-1.txz: Upgraded.
kde/kde-dev-scripts-23.08.5-x86_64-1.txz: Upgraded.
kde/kde-dev-utils-23.08.5-x86_64-1.txz: Upgraded.
kde/kde-inotify-survey-23.08.5-x86_64-1.txz: Upgraded.
kde/kdebugsettings-23.08.5-x86_64-1.txz: Upgraded.
kde/kdeconnect-kde-23.08.5-x86_64-1.txz: Upgraded.
kde/kdeedu-data-23.08.5-x86_64-1.txz: Upgraded.
kde/kdegraphics-mobipocket-23.08.5-x86_64-1.txz: Upgraded.
kde/kdegraphics-thumbnailers-23.08.5-x86_64-1.txz: Upgraded.
kde/kdenetwork-filesharing-23.08.5-x86_64-1.txz: Upgraded.
kde/kdenlive-23.08.5-x86_64-1.txz: Upgraded.
kde/kdepim-addons-23.08.5-x86_64-1.txz: Upgraded.
kde/kdepim-runtime-23.08.5-x86_64-1.txz: Upgraded.
kde/kdesdk-kio-23.08.5-x86_64-1.txz: Upgraded.
kde/kdesdk-thumbnailers-23.08.5-x86_64-1.txz: Upgraded.
kde/kdev-php-23.08.5-x86_64-1.txz: Upgraded.
kde/kdev-python-23.08.5-x86_64-1.txz: Upgraded.
kde/kdevelop-23.08.5-x86_64-1.txz: Upgraded.
kde/kdf-23.08.5-x86_64-1.txz: Upgraded.
kde/kdialog-23.08.5-x86_64-1.txz: Upgraded.
kde/kdiamond-23.08.5-x86_64-1.txz: Upgraded.
kde/keditbookmarks-23.08.5-x86_64-1.txz: Upgraded.
kde/keysmith-23.08.5-x86_64-1.txz: Upgraded.
kde/kfind-23.08.5-x86_64-1.txz: Upgraded.
kde/kfourinline-23.08.5-x86_64-1.txz: Upgraded.
kde/kgeography-23.08.5-x86_64-1.txz: Upgraded.
kde/kget-23.08.5-x86_64-1.txz: Upgraded.
kde/kgoldrunner-23.08.5-x86_64-1.txz: Upgraded.
kde/kgpg-23.08.5-x86_64-1.txz: Upgraded.
kde/khangman-23.08.5-x86_64-1.txz: Upgraded.
kde/khelpcenter-23.08.5-x86_64-1.txz: Upgraded.
kde/kidentitymanagement-23.08.5-x86_64-1.txz: Upgraded.
kde/kig-23.08.5-x86_64-1.txz: Upgraded.
kde/kigo-23.08.5-x86_64-1.txz: Upgraded.
kde/killbots-23.08.5-x86_64-1.txz: Upgraded.
kde/kimagemapeditor-23.08.5-x86_64-1.txz: Upgraded.
kde/kimap-23.08.5-x86_64-1.txz: Upgraded.
kde/kio-admin-23.08.5-x86_64-1.txz: Upgraded.
kde/kio-extras-23.08.5-x86_64-1.txz: Upgraded.
kde/kio-gdrive-23.08.5-x86_64-1.txz: Upgraded.
kde/kio-zeroconf-23.08.5-x86_64-1.txz: Upgraded.
kde/kipi-plugins-23.08.5-x86_64-1.txz: Upgraded.
kde/kirigami-gallery-23.08.5-x86_64-1.txz: Upgraded.
kde/kiriki-23.08.5-x86_64-1.txz: Upgraded.
kde/kiten-23.08.5-x86_64-1.txz: Upgraded.
kde/kitinerary-23.08.5-x86_64-1.txz: Upgraded.
kde/kjumpingcube-23.08.5-x86_64-1.txz: Upgraded.
kde/kldap-23.08.5-x86_64-1.txz: Upgraded.
kde/kleopatra-23.08.5-x86_64-1.txz: Upgraded.
kde/klickety-23.08.5-x86_64-1.txz: Upgraded.
kde/klines-23.08.5-x86_64-1.txz: Upgraded.
kde/kmag-23.08.5-x86_64-1.txz: Upgraded.
kde/kmahjongg-23.08.5-x86_64-1.txz: Upgraded.
kde/kmail-23.08.5-x86_64-1.txz: Upgraded.
kde/kmail-account-wizard-23.08.5-x86_64-1.txz: Upgraded.
kde/kmailtransport-23.08.5-x86_64-1.txz: Upgraded.
kde/kmbox-23.08.5-x86_64-1.txz: Upgraded.
kde/kmime-23.08.5-x86_64-1.txz: Upgraded.
kde/kmines-23.08.5-x86_64-1.txz: Upgraded.
kde/kmix-23.08.5-x86_64-1.txz: Upgraded.
kde/kmousetool-23.08.5-x86_64-1.txz: Upgraded.
kde/kmouth-23.08.5-x86_64-1.txz: Upgraded.
kde/kmplot-23.08.5-x86_64-1.txz: Upgraded.
kde/knavalbattle-23.08.5-x86_64-1.txz: Upgraded.
kde/knetwalk-23.08.5-x86_64-1.txz: Upgraded.
kde/knights-23.08.5-x86_64-1.txz: Upgraded.
kde/knotes-23.08.5-x86_64-1.txz: Upgraded.
kde/kolf-23.08.5-x86_64-1.txz: Upgraded.
kde/kollision-23.08.5-x86_64-1.txz: Upgraded.
kde/kolourpaint-23.08.5-x86_64-1.txz: Upgraded.
kde/kompare-23.08.5-x86_64-1.txz: Upgraded.
kde/konqueror-23.08.5-x86_64-1.txz: Upgraded.
kde/konquest-23.08.5-x86_64-1.txz: Upgraded.
kde/konsole-23.08.5-x86_64-1.txz: Upgraded.
kde/kontact-23.08.5-x86_64-1.txz: Upgraded.
kde/kontactinterface-23.08.5-x86_64-1.txz: Upgraded.
kde/kontrast-23.08.5-x86_64-1.txz: Upgraded.
kde/konversation-23.08.5-x86_64-1.txz: Upgraded.
kde/kopeninghours-23.08.5-x86_64-1.txz: Upgraded.
kde/kopete-23.08.5-x86_64-1.txz: Upgraded.
kde/korganizer-23.08.5-x86_64-1.txz: Upgraded.
kde/kosmindoormap-23.08.5-x86_64-1.txz: Upgraded.
kde/kpat-23.08.5-x86_64-1.txz: Upgraded.
kde/kpimtextedit-23.08.5-x86_64-1.txz: Upgraded.
kde/kpkpass-23.08.5-x86_64-1.txz: Upgraded.
kde/kpmcore-23.08.5-x86_64-1.txz: Upgraded.
kde/kpublictransport-23.08.5-x86_64-1.txz: Upgraded.
kde/kqtquickcharts-23.08.5-x86_64-1.txz: Upgraded.
kde/krdc-23.08.5-x86_64-1.txz: Upgraded.
kde/kreversi-23.08.5-x86_64-1.txz: Upgraded.
kde/krfb-23.08.5-x86_64-1.txz: Upgraded.
kde/kross-interpreters-23.08.5-x86_64-1.txz: Upgraded.
kde/kruler-23.08.5-x86_64-1.txz: Upgraded.
kde/ksanecore-23.08.5-x86_64-1.txz: Upgraded.
kde/kshisen-23.08.5-x86_64-1.txz: Upgraded.
kde/ksirk-23.08.5-x86_64-1.txz: Upgraded.
kde/ksmtp-23.08.5-x86_64-1.txz: Upgraded.
kde/ksnakeduel-23.08.5-x86_64-1.txz: Upgraded.
kde/kspaceduel-23.08.5-x86_64-1.txz: Upgraded.
kde/ksquares-23.08.5-x86_64-1.txz: Upgraded.
kde/ksudoku-23.08.5-x86_64-1.txz: Upgraded.
kde/ksystemlog-23.08.5-x86_64-1.txz: Upgraded.
kde/kteatime-23.08.5-x86_64-1.txz: Upgraded.
kde/ktimer-23.08.5-x86_64-1.txz: Upgraded.
kde/ktnef-23.08.5-x86_64-1.txz: Upgraded.
kde/ktorrent-23.08.5-x86_64-1.txz: Upgraded.
kde/ktouch-23.08.5-x86_64-1.txz: Upgraded.
kde/kturtle-23.08.5-x86_64-1.txz: Upgraded.
kde/kubrick-23.08.5-x86_64-1.txz: Upgraded.
kde/kwalletmanager-23.08.5-x86_64-1.txz: Upgraded.
kde/kwave-23.08.5-x86_64-1.txz: Upgraded.
kde/kwordquiz-23.08.5-x86_64-1.txz: Upgraded.
kde/libgravatar-23.08.5-x86_64-1.txz: Upgraded.
kde/libkcddb-23.08.5-x86_64-1.txz: Upgraded.
kde/libkcompactdisc-23.08.5-x86_64-1.txz: Upgraded.
kde/libkdcraw-23.08.5-x86_64-1.txz: Upgraded.
kde/libkdegames-23.08.5-x86_64-1.txz: Upgraded.
kde/libkdepim-23.08.5-x86_64-1.txz: Upgraded.
kde/libkeduvocdocument-23.08.5-x86_64-1.txz: Upgraded.
kde/libkexiv2-23.08.5-x86_64-1.txz: Upgraded.
kde/libkgapi-23.08.5-x86_64-1.txz: Upgraded.
kde/libkipi-23.08.5-x86_64-1.txz: Upgraded.
kde/libkleo-23.08.5-x86_64-1.txz: Upgraded.
kde/libkmahjongg-23.08.5-x86_64-1.txz: Upgraded.
kde/libkomparediff2-23.08.5-x86_64-1.txz: Upgraded.
kde/libksane-23.08.5-x86_64-1.txz: Upgraded.
kde/libksieve-23.08.5-x86_64-1.txz: Upgraded.
kde/libktorrent-23.08.5-x86_64-1.txz: Upgraded.
kde/lokalize-23.08.5-x86_64-1.txz: Upgraded.
kde/lskat-23.08.5-x86_64-1.txz: Upgraded.
kde/mailcommon-23.08.5-x86_64-1.txz: Upgraded.
kde/mailimporter-23.08.5-x86_64-1.txz: Upgraded.
kde/marble-23.08.5-x86_64-1.txz: Upgraded.
kde/markdownpart-23.08.5-x86_64-1.txz: Upgraded.
kde/mbox-importer-23.08.5-x86_64-1.txz: Upgraded.
kde/merkuro-23.08.5-x86_64-1.txz: Upgraded.
kde/messagelib-23.08.5-x86_64-1.txz: Upgraded.
kde/minuet-23.08.5-x86_64-1.txz: Upgraded.
kde/okular-23.08.5-x86_64-1.txz: Upgraded.
kde/palapeli-23.08.5-x86_64-1.txz: Upgraded.
kde/parley-23.08.5-x86_64-1.txz: Upgraded.
kde/partitionmanager-23.08.5-x86_64-1.txz: Upgraded.
kde/picmi-23.08.5-x86_64-1.txz: Upgraded.
kde/pim-data-exporter-23.08.5-x86_64-1.txz: Upgraded.
kde/pim-sieve-editor-23.08.5-x86_64-1.txz: Upgraded.
kde/pimcommon-23.08.5-x86_64-1.txz: Upgraded.
kde/poxml-23.08.5-x86_64-1.txz: Upgraded.
kde/print-manager-23.08.5-x86_64-1.txz: Upgraded.
kde/rocs-23.08.5-x86_64-1.txz: Upgraded.
kde/skanlite-23.08.5-x86_64-1.txz: Upgraded.
kde/skanpage-23.08.5-x86_64-1.txz: Upgraded.
kde/spectacle-23.08.5-x86_64-1.txz: Upgraded.
kde/step-23.08.5-x86_64-1.txz: Upgraded.
kde/svgpart-23.08.5-x86_64-1.txz: Upgraded.
kde/sweeper-23.08.5-x86_64-1.txz: Upgraded.
kde/umbrello-23.08.5-x86_64-1.txz: Upgraded.
kde/yakuake-23.08.5-x86_64-1.txz: Upgraded.
kde/zanshin-23.08.5-x86_64-1.txz: Upgraded.
l/colord-1.4.7-x86_64-1.txz: Added.
Thanks to Willy Sudiarto Raharjo.
l/cxxopts-3.2.0-x86_64-1.txz: Upgraded.
l/libffi-3.4.5-x86_64-1.txz: Upgraded.
l/libgusb-0.4.8-x86_64-1.txz: Added.
This is needed by colord.
Thanks to Willy Sudiarto Raharjo.
l/taglib-extras-1.0.1-x86_64-4.txz: Removed.
This package is obsolete.
n/php-8.3.3-x86_64-1.txz: Upgraded.
This is a bugfix release.
For more information, see:
https://www.php.net/ChangeLog-8.php#8.3.3
x/mesa-24.0.1-x86_64-1.txz: Upgraded.
xfce/xfce4-settings-4.18.4-x86_64-2.txz: Rebuilt.
Recompiled using --enable-colord.
20240216021913 | Patrick J Volkerding | 2024-02-16 | 1 | -3/+1 |
* | Mon Feb 12 20:58:46 UTC 2024...a/procps-ng-4.0.4-x86_64-1.txz: Upgraded.
a/shadow-4.14.4-x86_64-1.txz: Upgraded.
ap/man-pages-6.06-noarch-1.txz: Upgraded.
ap/vim-9.1.0098-x86_64-1.txz: Upgraded.
d/libgccjit-13.2.0-x86_64-1.txz: Added.
If we can ship GCC's D and Modula-2 support, then we can ship this.
We'll probably find a use for it. ;-)
Thanks to Didier Spaier for hints on the build script.
d/mercurial-6.6.3-x86_64-1.txz: Upgraded.
d/rust-1.76.0-x86_64-1.txz: Upgraded.
l/gegl-0.4.48-x86_64-1.txz: Upgraded.
l/openexr-3.2.2-x86_64-1.txz: Upgraded.
l/pango-1.51.2-x86_64-1.txz: Upgraded.
l/python-calver-2022.6.26-x86_64-1.txz: Added.
Needed for python-trove-classifiers. Thanks to lucabon.
n/openvpn-2.6.9-x86_64-1.txz: Upgraded.
xap/vim-gvim-9.1.0098-x86_64-1.txz: Upgraded.
extra/rust-for-mozilla/rust-1.70.0-x86_64-4.txz: Added.
Let's move this here since it's lagging behind the latest Rust.
20240212205846 | Patrick J Volkerding | 2024-02-12 | 1 | -1/+1 |
* | Sat Feb 10 21:19:10 UTC 2024...d/git-2.43.1-x86_64-1.txz: Upgraded.
kde/attica-5.115.0-x86_64-1.txz: Upgraded.
kde/baloo-5.115.0-x86_64-1.txz: Upgraded.
kde/bluez-qt-5.115.0-x86_64-1.txz: Upgraded.
kde/breeze-icons-5.115.0-noarch-1.txz: Upgraded.
kde/extra-cmake-modules-5.115.0-x86_64-1.txz: Upgraded.
kde/frameworkintegration-5.115.0-x86_64-1.txz: Upgraded.
kde/kactivities-5.115.0-x86_64-1.txz: Upgraded.
kde/kactivities-stats-5.115.0-x86_64-1.txz: Upgraded.
kde/kapidox-5.115.0-x86_64-1.txz: Upgraded.
kde/karchive-5.115.0-x86_64-1.txz: Upgraded.
kde/kauth-5.115.0-x86_64-1.txz: Upgraded.
kde/kbookmarks-5.115.0-x86_64-1.txz: Upgraded.
kde/kcalendarcore-5.115.0-x86_64-1.txz: Upgraded.
kde/kcmutils-5.115.0-x86_64-1.txz: Upgraded.
kde/kcodecs-5.115.0-x86_64-1.txz: Upgraded.
kde/kcompletion-5.115.0-x86_64-1.txz: Upgraded.
kde/kconfig-5.115.0-x86_64-1.txz: Upgraded.
kde/kconfigwidgets-5.115.0-x86_64-1.txz: Upgraded.
kde/kcontacts-5.115.0-x86_64-1.txz: Upgraded.
kde/kcoreaddons-5.115.0-x86_64-1.txz: Upgraded.
kde/kcrash-5.115.0-x86_64-1.txz: Upgraded.
kde/kdav-5.115.0-x86_64-1.txz: Upgraded.
kde/kdbusaddons-5.115.0-x86_64-1.txz: Upgraded.
kde/kdeclarative-5.115.0-x86_64-1.txz: Upgraded.
kde/kded-5.115.0-x86_64-1.txz: Upgraded.
kde/kdelibs4support-5.115.0-x86_64-1.txz: Upgraded.
kde/kdesignerplugin-5.115.0-x86_64-1.txz: Upgraded.
kde/kdesu-5.115.0-x86_64-1.txz: Upgraded.
kde/kdewebkit-5.115.0-x86_64-1.txz: Upgraded.
kde/kdnssd-5.115.0-x86_64-1.txz: Upgraded.
kde/kdoctools-5.115.0-x86_64-1.txz: Upgraded.
kde/kemoticons-5.115.0-x86_64-1.txz: Upgraded.
kde/kfilemetadata-5.115.0-x86_64-1.txz: Upgraded.
kde/kglobalaccel-5.115.0-x86_64-1.txz: Upgraded.
kde/kguiaddons-5.115.0-x86_64-1.txz: Upgraded.
kde/kholidays-5.115.0-x86_64-1.txz: Upgraded.
kde/khtml-5.115.0-x86_64-1.txz: Upgraded.
kde/ki18n-5.115.1-x86_64-1.txz: Upgraded.
kde/kiconthemes-5.115.0-x86_64-1.txz: Upgraded.
kde/kidletime-5.115.0-x86_64-1.txz: Upgraded.
kde/kimageformats-5.115.0-x86_64-1.txz: Upgraded.
kde/kinit-5.115.0-x86_64-1.txz: Upgraded.
kde/kio-5.115.0-x86_64-1.txz: Upgraded.
kde/kirigami2-5.115.0-x86_64-1.txz: Upgraded.
kde/kitemmodels-5.115.0-x86_64-1.txz: Upgraded.
kde/kitemviews-5.115.0-x86_64-1.txz: Upgraded.
kde/kjobwidgets-5.115.0-x86_64-1.txz: Upgraded.
kde/kjs-5.115.0-x86_64-1.txz: Upgraded.
kde/kjsembed-5.115.0-x86_64-1.txz: Upgraded.
kde/kmediaplayer-5.115.0-x86_64-1.txz: Upgraded.
kde/knewstuff-5.115.0-x86_64-1.txz: Upgraded.
kde/knotifications-5.115.0-x86_64-1.txz: Upgraded.
kde/knotifyconfig-5.115.0-x86_64-1.txz: Upgraded.
kde/kpackage-5.115.0-x86_64-1.txz: Upgraded.
kde/kparts-5.115.0-x86_64-1.txz: Upgraded.
kde/kpeople-5.115.0-x86_64-1.txz: Upgraded.
kde/kplotting-5.115.0-x86_64-1.txz: Upgraded.
kde/kpty-5.115.0-x86_64-1.txz: Upgraded.
kde/kquickcharts-5.115.0-x86_64-1.txz: Upgraded.
kde/kross-5.115.0-x86_64-1.txz: Upgraded.
kde/krunner-5.115.0-x86_64-1.txz: Upgraded.
kde/kservice-5.115.0-x86_64-1.txz: Upgraded.
kde/ktexteditor-5.115.0-x86_64-1.txz: Upgraded.
kde/ktextwidgets-5.115.0-x86_64-1.txz: Upgraded.
kde/kunitconversion-5.115.0-x86_64-1.txz: Upgraded.
kde/kwallet-5.115.0-x86_64-1.txz: Upgraded.
kde/kwayland-5.115.0-x86_64-1.txz: Upgraded.
kde/kwidgetsaddons-5.115.0-x86_64-1.txz: Upgraded.
kde/kwindowsystem-5.115.0-x86_64-1.txz: Upgraded.
kde/kxmlgui-5.115.0-x86_64-1.txz: Upgraded.
kde/kxmlrpcclient-5.115.0-x86_64-1.txz: Upgraded.
kde/modemmanager-qt-5.115.0-x86_64-1.txz: Upgraded.
kde/networkmanager-qt-5.115.0-x86_64-1.txz: Upgraded.
kde/oxygen-icons-5.115.0-noarch-1.txz: Upgraded.
kde/plasma-framework-5.115.0-x86_64-1.txz: Upgraded.
kde/prison-5.115.0-x86_64-1.txz: Upgraded.
kde/purpose-5.115.0-x86_64-1.txz: Upgraded.
kde/qqc2-desktop-style-5.115.0-x86_64-1.txz: Upgraded.
kde/solid-5.115.0-x86_64-1.txz: Upgraded.
kde/sonnet-5.115.0-x86_64-1.txz: Upgraded.
kde/syndication-5.115.0-x86_64-1.txz: Upgraded.
kde/syntax-highlighting-5.115.0-x86_64-1.txz: Upgraded.
kde/threadweaver-5.115.0-x86_64-1.txz: Upgraded.
l/babl-0.1.108-x86_64-1.txz: Upgraded.
l/glib-networking-2.78.0-x86_64-2.txz: Rebuilt.
Recompiled against libproxy-0.5.4.
l/libproxy-0.5.4-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
l/neon-0.33.0-x86_64-2.txz: Rebuilt.
Recompiled against libproxy-0.5.4.
l/pipewire-1.0.3-x86_64-3.txz: Rebuilt.
Removed bundled wireplumber.
l/wireplumber-0.4.17-x86_64-1.txz: Added.
This has been broken out as a new package.
Thanks to alex14641 for the suggestion.
20240210211910 | Patrick J Volkerding | 2024-02-10 | 1 | -0/+1 |
* | Thu Feb 8 22:17:18 UTC 2024...a/kernel-firmware-20240208_fbef4d3-noarch-1.txz: Upgraded.
a/kernel-generic-6.6.16-x86_64-1.txz: Upgraded.
a/kernel-huge-6.6.16-x86_64-1.txz: Upgraded.
a/kernel-modules-6.6.16-x86_64-1.txz: Upgraded.
d/kernel-headers-6.6.16-x86-1.txz: Upgraded.
k/kernel-source-6.6.16-noarch-1.txz: Upgraded.
-VIDEO_ATOMISP m
-VIDEO_ATOMISP_GC0310 n
-VIDEO_ATOMISP_GC2235 n
-VIDEO_ATOMISP_ISP2401 n
-VIDEO_ATOMISP_LM3554 n
-VIDEO_ATOMISP_MSRLIST_HELPER n
-VIDEO_ATOMISP_MT9M114 n
-VIDEO_ATOMISP_OV2722 n
-VIDEO_ATOMISP_OV5693 n
INTEL_ATOMISP y -> n
+INTEL_ATOMISP2_PM m
l/enchant-2.6.7-x86_64-1.txz: Upgraded.
l/libsecret-0.21.3-x86_64-1.txz: Upgraded.
l/libuv-1.48.0-x86_64-1.txz: Upgraded.
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
testing/packages/rust-1.76.0-x86_64-1.txz: Upgraded.
usb-and-pxe-installers/usbboot.img: Rebuilt.
20240208221718 | Patrick J Volkerding | 2024-02-09 | 1 | -0/+1 |
* | Fri Feb 2 22:12:45 UTC 2024...A test mass rebuild here didn't find any new failure-to-build-from-source, so
we'll go ahead and upgrade to the new glibc. Enjoy! :-)
a/aaa_glibc-solibs-2.39-x86_64-1.txz: Upgraded.
kde/calligra-3.2.1-x86_64-36.txz: Rebuilt.
Recompiled against poppler-24.02.0.
kde/cantor-23.08.4-x86_64-2.txz: Rebuilt.
Recompiled against poppler-24.02.0.
kde/kfilemetadata-5.114.0-x86_64-3.txz: Rebuilt.
Recompiled against poppler-24.02.0.
kde/kile-2.9.93-x86_64-30.txz: Rebuilt.
Recompiled against poppler-24.02.0.
kde/kitinerary-23.08.4-x86_64-2.txz: Rebuilt.
Recompiled against poppler-24.02.0.
kde/krita-5.2.2-x86_64-3.txz: Rebuilt.
Recompiled against poppler-24.02.0.
kde/okular-23.08.4-x86_64-2.txz: Rebuilt.
Recompiled against poppler-24.02.0.
l/SDL2-2.30.0-x86_64-1.txz: Upgraded.
l/glibc-2.39-x86_64-1.txz: Upgraded.
This fixes a few __vsyslog_internal related overflows that could result in
an application crash or local privilege escalation.
The issues affected glibc 2.36 and newer.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2023-6246
https://www.cve.org/CVERecord?id=CVE-2023-6779
https://www.cve.org/CVERecord?id=CVE-2023-6780
(* Security fix *)
l/glibc-i18n-2.39-x86_64-1.txz: Upgraded.
l/glibc-profile-2.39-x86_64-1.txz: Upgraded.
l/pipewire-1.0.3-x86_64-1.txz: Upgraded.
l/poppler-24.02.0-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
n/ipset-7.20-x86_64-1.txz: Upgraded.
20240202221245 | Patrick J Volkerding | 2024-02-02 | 1 | -2/+0 |
* | Wed Jan 31 21:19:19 UTC 2024...ap/nvme-cli-2.7.1-x86_64-1.txz: Upgraded.
l/libnvme-1.7.1-x86_64-1.txz: Added.
This is required by nvme-cli.
l/pipewire-1.0.2-x86_64-1.txz: Upgraded.
n/curl-8.6.0-x86_64-1.txz: Upgraded.
n/libmilter-8.18.1-x86_64-1.txz: Upgraded.
extra/sendmail/sendmail-8.18.1-x86_64-1.txz: Upgraded.
sendmail through 8.17.2 allows SMTP smuggling in certain configurations.
Remote attackers can use a published exploitation technique to inject e-mail
messages with a spoofed MAIL FROM address, allowing bypass of an SPF
protection mechanism. This occurs because sendmail supports <LF>.<CR><LF>
but some other popular e-mail servers do not. This is resolved in 8.18 and
later versions with 'o' in srv_features.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2023-51765
(* Security fix *)
extra/sendmail/sendmail-cf-8.18.1-noarch-1.txz: Upgraded.
20240131211919 | Patrick J Volkerding | 2024-01-31 | 1 | -0/+1 |
* | Tue Jan 30 22:01:28 UTC 2024...a/lzip-1.24-x86_64-1.txz: Upgraded.
a/openssl-solibs-3.2.1-x86_64-1.txz: Upgraded.
ap/alsa-utils-1.2.11-x86_64-1.txz: Upgraded.
ap/sqlite-3.45.1-x86_64-1.txz: Upgraded.
d/binutils-2.42-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
d/cmake-3.28.2-x86_64-1.txz: Upgraded.
d/oprofile-1.4.0-x86_64-13.txz: Rebuilt.
Recompiled against binutils-2.42.
d/strace-6.7-x86_64-1.txz: Upgraded.
kde/digikam-8.2.0-x86_64-5.txz: Rebuilt.
Recompiled against libpng-1.6.42.
l/alsa-lib-1.2.11-x86_64-1.txz: Upgraded.
l/libpng-1.6.42-x86_64-1.txz: Upgraded.
Fixed the implementation of the macro function png_check_sig().
This was an API regression, introduced in libpng-1.6.41.
Reported by Matthieu Darbois.
l/lmdb-0.9.32-x86_64-1.txz: Upgraded.
l/neon-0.33.0-x86_64-1.txz: Upgraded.
l/opencv-4.9.0-x86_64-3.txz: Rebuilt.
Recompiled against libpng-1.6.42.
l/qt5-5.15.12_20240103_b8fd1448-x86_64-4.txz: Rebuilt.
Recompiled against libpng-1.6.42.
l/talloc-2.4.2-x86_64-1.txz: Upgraded.
l/tdb-1.4.10-x86_64-1.txz: Upgraded.
l/tevent-0.16.1-x86_64-1.txz: Upgraded.
n/openldap-2.6.7-x86_64-1.txz: Upgraded.
n/openssl-3.2.1-x86_64-1.txz: Upgraded.
This update fixes possible denial-of-service security issues:
A file in PKCS12 format can contain certificates and keys and may come from
an untrusted source. The PKCS12 specification allows certain fields to be
NULL, but OpenSSL did not correctly check for this case. A fix has been
applied to prevent a NULL pointer dereference that results in OpenSSL
crashing. If an application processes PKCS12 files from an untrusted source
using the OpenSSL APIs then that application will be vulnerable to this
issue prior to this fix.
OpenSSL APIs that were vulnerable to this are: PKCS12_parse(),
PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes()
and PKCS12_newpass().
When function EVP_PKEY_public_check() is called on RSA public keys,
a computation is done to confirm that the RSA modulus, n, is composite.
For valid RSA keys, n is a product of two or more large primes and this
computation completes quickly. However, if n is an overly large prime,
then this computation would take a long time.
An application that calls EVP_PKEY_public_check() and supplies an RSA key
obtained from an untrusted source could be vulnerable to a Denial of Service
attack.
The function EVP_PKEY_public_check() is not called from other OpenSSL
functions however it is called from the OpenSSL pkey command line
application. For that reason that application is also vulnerable if used
with the "-pubin" and "-check" options on untrusted data.
To resolve this issue RSA keys larger than OPENSSL_RSA_MAX_MODULUS_BITS will
now fail the check immediately with an RSA_R_MODULUS_TOO_LARGE error reason.
Fix excessive time spent in DH check / generation with large Q parameter
value.
Applications that use the functions DH_generate_key() to generate an
X9.42 DH key may experience long delays. Likewise, applications that use
DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check()
to check an X9.42 DH key or X9.42 DH parameters may experience long delays.
Where the key or parameters that are being checked have been obtained from
an untrusted source this may lead to a Denial of Service.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2024-0727
https://www.cve.org/CVERecord?id=CVE-2023-6237
https://www.cve.org/CVERecord?id=CVE-2023-5678
(* Security fix *)
xap/MPlayer-20240130-x86_64-1.txz: Upgraded.
Fixed build script to exit on errors.
Patched to build against gettext-0.22.4.
Thanks to Matteo Bernardini.
xap/xine-lib-1.2.13-x86_64-7.txz: Rebuilt.
Recompiled against libpng-1.6.42.
20240130220128 | Patrick J Volkerding | 2024-01-30 | 1 | -0/+1 |
* | Mon Jan 29 19:17:30 UTC 2024...ap/diffstat-1.66-x86_64-1.txz: Upgraded.
ap/moc-2.6_alpha3-x86_64-3.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
ap/vim-9.1.0061-x86_64-1.txz: Upgraded.
d/nv-codec-headers-12.1.14.0-x86_64-1.txz: Added.
Needed to build support for nvidia hardware decoders/encoders on newer GPUs.
gst-plugins-bad can use it too.
Thanks to Heinz Wiesinger.
kde/digikam-8.2.0-x86_64-4.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
kde/ffmpegthumbs-23.08.4-x86_64-2.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
kde/k3b-23.08.4-x86_64-2.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
kde/kfilemetadata-5.114.0-x86_64-2.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
kde/kpipewire-5.27.10-x86_64-2.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
l/Imath-3.1.10-x86_64-1.txz: Upgraded.
l/alsa-plugins-1.2.7.1-x86_64-3.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
l/ffmpeg-6.1.1-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
Added some new build options in the SlackBuild.
Use shaderc instead of glslang.
Build against libgcrypt to enable support for RTMP[E].
Enable support for lcms2.
Build against libass, libplacebo, and nv-codec-headers.
Thanks to Heinz Wiesinger.
l/gegl-0.4.46-x86_64-4.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
l/gst-plugins-bad-free-1.22.9-x86_64-2.txz: Rebuilt.
Recompiled against libass-0.17.1.
l/gst-plugins-libav-1.22.9-x86_64-2.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
l/libass-0.17.1-x86_64-1.txz: Added.
Adds ASS/SSA subtitle renderer (commonly used in the anime community).
adapted SlackBuild from SBo, original by Larry Hajali/Matteo Bernardini.
MPlayer and gst-plugins-bad can use it too.
Thanks to Heinz Wiesinger.
l/libplacebo-6.338.2-x86_64-1.txz: Added.
Adds various hardware accelerated filters such as HDR -> SDR tone mapping.
adapted SlackBuild from SBo, original by Hunter Sezen/Christoph Willing.
Thanks to Heinz Wiesinger.
l/mlt-7.22.0-x86_64-2.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
l/netpbm-11.05.02-x86_64-1.txz: Upgraded.
l/opencv-4.9.0-x86_64-2.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
l/pipewire-1.0.1-x86_64-2.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
l/qt5-5.15.12_20240103_b8fd1448-x86_64-3.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
x/pixman-0.43.2-x86_64-1.txz: Upgraded.
xap/MPlayer-20240127-x86_64-1.txz: Upgraded.
Compiled against ffmpeg-6.1.1 and libass-0.17.1.
xap/audacious-plugins-4.3.1-x86_64-2.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
xap/ffmpegthumbnailer-2.2.2-x86_64-5.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
xap/freerdp-2.11.5-x86_64-2.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
xap/ssr-0.4.4-x86_64-2.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
xap/vim-gvim-9.1.0061-x86_64-1.txz: Upgraded.
xap/xine-lib-1.2.13-x86_64-6.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
xap/xscreensaver-6.08-x86_64-2.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
extra/tigervnc/tigervnc-1.13.1-x86_64-4.txz: Rebuilt.
Recompiled against ffmpeg-6.1.1.
20240129191730 | Patrick J Volkerding | 2024-01-29 | 1 | -3/+1 |
* | Fri Jan 26 20:59:27 UTC 2024...a/pam-1.6.0-x86_64-1.txz: Upgraded.
pam_namespace.so: fixed a possible local denial-of-service vulnerability.
For more information, see:
https://seclists.org/oss-sec/2024/q1/31
https://www.cve.org/CVERecord?id=CVE-2024-22365
(* Security fix *)
a/xz-5.4.6-x86_64-1.txz: Upgraded.
l/python-hatchling-1.21.1-x86_64-1.txz: Upgraded.
20240126205927 | Patrick J Volkerding | 2024-01-26 | 1 | -20/+3 |
* | Mon Jan 15 21:08:12 UTC 2024...a/kernel-firmware-20240115_9b6d0b0-noarch-1.txz: Upgraded.
a/kernel-generic-6.6.12-x86_64-1.txz: Upgraded.
a/kernel-huge-6.6.12-x86_64-1.txz: Upgraded.
a/kernel-modules-6.6.12-x86_64-1.txz: Upgraded.
d/kernel-headers-6.6.12-x86-1.txz: Upgraded.
k/kernel-source-6.6.12-noarch-1.txz: Upgraded.
l/libxml2-2.12.4-x86_64-1.txz: Upgraded.
l/pulseaudio-17.0-x86_64-2.txz: Rebuilt.
Patch regressions:
[PATCH] alsa-ucm: Check UCM verb before working with device status.
[PATCH] alsa-ucm: Replace port device UCM context assertion with an error.
l/readline-8.2.010-x86_64-1.txz: Upgraded.
x/libinput-1.25.0-x86_64-1.txz: Upgraded.
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
usb-and-pxe-installers/usbboot.img: Rebuilt.
20240115210812 | Patrick J Volkerding | 2024-01-15 | 1 | -0/+2 |
* | Thu Jan 11 20:27:14 UTC 2024...ap/mpg123-1.32.4-x86_64-1.txz: Upgraded.
l/nodejs-20.11.0-x86_64-1.txz: Upgraded.
l/pipewire-1.0.1-x86_64-1.txz: Upgraded.
x/mesa-23.3.3-x86_64-1.txz: Upgraded.
x/sddm-0.20.0-x86_64-4.txz: Rebuilt.
20240111202714 | Patrick J Volkerding | 2024-01-11 | 1 | -0/+1 |
* | Tue Jan 9 01:52:43 UTC 2024...a/procps-ng-3.3.17-x86_64-3.txz: Rebuilt.
Add /etc/default/sysctl to support custom options for sysctl in rc.S.
Thanks to lostintime.
a/sysvinit-scripts-15.1-noarch-12.txz: Rebuilt.
rc.S: support /etc/default/sysctl for custom options.
Thanks to lostintime.
l/imagemagick-7.1.1_26-x86_64-1.txz: Upgraded.
l/qt5-5.15.12_20240103_b8fd1448-x86_64-1.txz: Upgraded.
n/samba-4.19.4-x86_64-1.txz: Upgraded.
x/imake-1.0.10-x86_64-1.txz: Upgraded.
20240109015243 | Patrick J Volkerding | 2024-01-09 | 1 | -0/+1 |
* | Thu Jan 4 20:54:16 UTC 2024...a/dcron-4.5-x86_64-14.txz: Rebuilt.
Add /etc/default/run-parts. Thanks to lostintime.
kde/fcitx5-configtool-5.1.3-x86_64-1.txz: Upgraded.
x/fcitx5-5.1.6-x86_64-1.txz: Upgraded.
x/fcitx5-qt-5.1.4-x86_64-1.txz: Upgraded.
x/pixman-0.43.0-x86_64-1.txz: Upgraded.
x/xcb-imdkit-1.0.6-x86_64-1.txz: Upgraded.
20240104205416 | Patrick J Volkerding | 2024-01-04 | 1 | -1/+0 |
* | Fri Dec 29 21:02:02 UTC 2023...a/sysvinit-scripts-15.1-noarch-10.txz: Rebuilt.
rc.M: Fix the name of the LDAP name service daemon (rc.nss-pam-ldap).
Thanks to 0XBF.
d/subversion-1.14.3-x86_64-1.txz: Upgraded.
l/libvisual-0.4.2-x86_64-1.txz: Upgraded.
l/libvisual-plugins-0.4.2-x86_64-1.txz: Upgraded.
l/netpbm-11.05.01-x86_64-1.txz: Upgraded.
xfce/thunar-4.18.9-x86_64-1.txz: Upgraded.
testing/packages/grub-2.12-x86_64-1.txz: Added.
20231229210202 | Patrick J Volkerding | 2023-12-29 | 1 | -3/+1 |
* | Thu Dec 14 20:09:31 UTC 2023...l/libxml2-2.12.3-x86_64-2.txz: Rebuilt.
Rebuilt using the --with-legacy option (maximum ABI compatibility) and
--with-ftp option (functionality included by default in libxml2 2.9).
n/bluez-5.71-x86_64-1.txz: Upgraded.
This update fixes a security issue:
It may have been possible for an attacker within Bluetooth range to inject
keystrokes (and possibly execute commands) while devices were discoverable.
Thanks to marav for the heads-up.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2023-45866
(* Security fix *)
x/compiz-0.8.18-x86_64-4.txz: Rebuilt.
Patched to work properly with libxml2-2.12.3.
Thanks to saxa.
20231214200931 | Patrick J Volkerding | 2023-12-14 | 1 | -0/+1 |
* | Thu Dec 14 18:33:00 UTC 2023...ap/sudo-1.9.15p3-x86_64-1.txz: Upgraded.
l/PyQt-builder-1.15.4-x86_64-1.txz: Added.
l/PyQt5-5.15.10-x86_64-1.txz: Upgraded.
l/PyQt5_sip-12.13.0-x86_64-1.txz: Added.
l/QScintilla-2.14.1-x86_64-1.txz: Upgraded.
l/SDL2_image-2.8.1-x86_64-1.txz: Upgraded.
l/sip-6.8.1-x86_64-1.txz: Upgraded.
x/mesa-23.3.1-x86_64-1.txz: Upgraded.
20231214183300 | Patrick J Volkerding | 2023-12-14 | 1 | -2/+0 |
* | Mon Dec 11 22:18:13 UTC 2023...We've gone ahead and moved the 6.6 kernel into the main tree. As previously
mentioned when this branch first appeared in /testing, on the 32-bit side
there are no longer any -smp labeled kernel packages, so if you were using
those previously, you'll need to switch to using to kernel-generic or
kernel-huge kernel, including the changes needed to your bootloader setup to
load this instead of the -smp labeled kernel. Also, if you happen to be using
a first generation Pentium M chip, you will need to append forcepae to your
kernel command-line options. Enjoy! :-)
a/kernel-firmware-20231211_f2e52a1-noarch-1.txz: Upgraded.
a/kernel-generic-6.6.6-x86_64-1.txz: Upgraded.
a/kernel-huge-6.6.6-x86_64-1.txz: Upgraded.
a/kernel-modules-6.6.6-x86_64-1.txz: Upgraded.
ap/qpdf-11.6.4-x86_64-1.txz: Upgraded.
d/kernel-headers-6.6.6-x86-1.txz: Upgraded.
k/kernel-source-6.6.6-noarch-1.txz: Upgraded.
l/imagemagick-7.1.1_23-x86_64-1.txz: Upgraded.
l/libsecret-0.21.2-x86_64-1.txz: Upgraded.
Thanks to reddog83 and saxa.
l/zxing-cpp-2.2.1-x86_64-1.txz: Upgraded.
n/postfix-3.8.3-x86_64-2.txz: Rebuilt.
OpenSSL upstream says that major versions are ABI/API compatible, so stop
warning in the logs that they might not be.
Thanks to gildbg and Markus Wiesner.
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
usb-and-pxe-installers/usbboot.img: Rebuilt.
20231211221813 | Patrick J Volkerding | 2023-12-12 | 1 | -1/+1 |
* | Sun Dec 10 01:12:17 UTC 2023...l/libxml2-2.12.2-x86_64-2.txz: Rebuilt.
Add --sysconfdir=/etc option so that this can find the xml catalog.
Thanks to SpiderTux.
Fix the following security issues:
Fix integer overflows with XML_PARSE_HUGE.
Fix dict corruption caused by entity reference cycles.
Hashing of empty dict strings isn't deterministic.
Fix null deref in xmlSchemaFixupComplexType.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2022-40303
https://www.cve.org/CVERecord?id=CVE-2022-40304
https://www.cve.org/CVERecord?id=CVE-2023-29469
https://www.cve.org/CVERecord?id=CVE-2023-28484
(* Security fix *)
20231210011217 | Patrick J Volkerding | 2023-12-10 | 1 | -2/+0 |
* | Wed Dec 6 05:03:11 UTC 2023...a/aaa_libraries-15.1-x86_64-23.txz: Rebuilt.
Upgraded: libelf-0.190.so, libcares.so.2.9.0, libglib-2.0.so.0.7800.2,
libgmodule-2.0.so.0.7800.2, libgobject-2.0.so.0.7800.2,
libgthread-2.0.so.0.7800.2.
Added: libtiff.so.6.0.2, libtiffxx.so.6.0.2.
a/util-linux-2.39.3-x86_64-1.txz: Upgraded.
ap/cups-filters-1.28.17-x86_64-3.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
ap/ghostscript-10.02.1-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
ap/rpm-4.19.0-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
e/emacs-29.1-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
kde/bluedevil-5.27.10-x86_64-1.txz: Upgraded.
kde/breeze-5.27.10-x86_64-1.txz: Upgraded.
kde/breeze-grub-5.27.10-x86_64-1.txz: Upgraded.
kde/breeze-gtk-5.27.10-x86_64-1.txz: Upgraded.
kde/digikam-8.2.0-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
kde/drkonqi-5.27.10-x86_64-1.txz: Upgraded.
kde/gwenview-23.08.3-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
kde/kactivitymanagerd-5.27.10-x86_64-1.txz: Upgraded.
kde/kde-cli-tools-5.27.10-x86_64-1.txz: Upgraded.
kde/kde-gtk-config-5.27.10-x86_64-1.txz: Upgraded.
kde/kdecoration-5.27.10-x86_64-1.txz: Upgraded.
kde/kdeplasma-addons-5.27.10-x86_64-1.txz: Upgraded.
kde/kgamma5-5.27.10-x86_64-1.txz: Upgraded.
kde/khotkeys-5.27.10-x86_64-1.txz: Upgraded.
kde/kinfocenter-5.27.10-x86_64-1.txz: Upgraded.
kde/kmenuedit-5.27.10-x86_64-1.txz: Upgraded.
kde/kpipewire-5.27.10-x86_64-1.txz: Upgraded.
kde/krita-5.2.1-x86_64-3.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
kde/kscreen-5.27.10-x86_64-1.txz: Upgraded.
kde/kscreenlocker-5.27.10-x86_64-1.txz: Upgraded.
kde/ksshaskpass-5.27.10-x86_64-1.txz: Upgraded.
kde/ksystemstats-5.27.10-x86_64-1.txz: Upgraded.
kde/kwallet-pam-5.27.10-x86_64-1.txz: Upgraded.
kde/kwayland-integration-5.27.10-x86_64-1.txz: Upgraded.
kde/kwin-5.27.10-x86_64-1.txz: Upgraded.
kde/kwrited-5.27.10-x86_64-1.txz: Upgraded.
kde/layer-shell-qt-5.27.10-x86_64-1.txz: Upgraded.
kde/libkscreen-5.27.10-x86_64-1.txz: Upgraded.
kde/libksysguard-5.27.10-x86_64-1.txz: Upgraded.
kde/milou-5.27.10-x86_64-1.txz: Upgraded.
kde/okular-23.08.3-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
kde/oxygen-5.27.10-x86_64-1.txz: Upgraded.
kde/oxygen-sounds-5.27.10-x86_64-1.txz: Upgraded.
kde/plasma-browser-integration-5.27.10-x86_64-1.txz: Upgraded.
kde/plasma-desktop-5.27.10-x86_64-1.txz: Upgraded.
kde/plasma-disks-5.27.10-x86_64-1.txz: Upgraded.
kde/plasma-firewall-5.27.10-x86_64-1.txz: Upgraded.
kde/plasma-integration-5.27.10-x86_64-1.txz: Upgraded.
kde/plasma-nm-5.27.10-x86_64-1.txz: Upgraded.
kde/plasma-pa-5.27.10-x86_64-1.txz: Upgraded.
kde/plasma-sdk-5.27.10-x86_64-1.txz: Upgraded.
kde/plasma-systemmonitor-5.27.10-x86_64-1.txz: Upgraded.
kde/plasma-vault-5.27.10-x86_64-1.txz: Upgraded.
kde/plasma-workspace-5.27.10-x86_64-1.txz: Upgraded.
kde/plasma-workspace-wallpapers-5.27.10-noarch-1.txz: Upgraded.
kde/polkit-kde-agent-1-5.27.10-x86_64-1.txz: Upgraded.
kde/powerdevil-5.27.10-x86_64-1.txz: Upgraded.
kde/qqc2-breeze-style-5.27.10-x86_64-1.txz: Upgraded.
kde/sddm-kcm-5.27.10-x86_64-1.txz: Upgraded.
kde/systemsettings-5.27.10-x86_64-1.txz: Upgraded.
kde/xdg-desktop-portal-kde-5.27.10-x86_64-1.txz: Upgraded.
l/SDL2_image-2.6.3-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
l/djvulibre-3.5.28-x86_64-4.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
l/gd-2.3.3-x86_64-3.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
l/gdk-pixbuf2-2.42.10-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
l/gegl-0.4.46-x86_64-3.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
l/glib2-2.78.2-x86_64-1.txz: Upgraded.
l/gtk4-4.12.4-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
l/imagemagick-7.1.1_22-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
l/lcms-1.19-x86_64-7.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
l/lcms2-2.16-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
l/libtiff-4.6.0-x86_64-1.txz: Upgraded.
Probably best to get this one out of the way...
From the release announcement:
Pay attention to the following warning:
This version removes a big number of utilities that have suffered from lack
of maintenance over the years and were the source of various reported
security issues. See "Removed functionality" below for the list of removed
utilities. Starting with libtiff v4.6.0, their source code, at this time,
will still be available in the source distribution, but they will no longer
be built by default, and issues related to them will no longer be accepted
in the libtiff bug tracker. The only remaining supported TIFF tools are
tiffinfo, tiffdump, tiffcp, tiffset and tiffsplit.
Shared library .so-version bump.
l/libwebp-1.3.2-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
l/netpbm-11.04.04-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
l/opencv-4.8.1-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
l/poppler-23.12.0-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
l/python-pillow-8.4.0-x86_64-3.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
l/qt5-5.15.11_20231125_4765fa1d-x86_64-1.txz: Upgraded.
Compiled against libtiff-4.6.0.
l/sdl-1.2.15-x86_64-15.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
n/links-2.29-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
t/xfig-3.2.9-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
xap/geeqie-2.1-x86_64-4.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
xap/gimp-2.10.36-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
xap/sane-1.2.1-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
xap/windowmaker-0.96.0-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
xap/xpaint-3.1.4-x86_64-2.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
xap/xsane-0.999-x86_64-6.txz: Rebuilt.
Recompiled against libtiff-4.6.0.
20231206050311 | Patrick J Volkerding | 2023-12-06 | 1 | -3/+0 |
* | Mon Nov 27 21:54:37 UTC 2023...l/libqalculate-4.9.0-x86_64-1.txz: Upgraded.
l/mozilla-nss-3.95-x86_64-1.txz: Upgraded.
l/v4l-utils-1.26.0-x86_64-2.txz: Rebuilt.
Do not overwrite gconv-modules from glibc - instead, install it to
gconv-modules.d/v4l-utils.conf.
If your /usr/lib{,64}/gconv/gconv-modules was overwritten causing character
conversion errors, reinstall the glibc package to fix this.
Thanks to glennmcc.
n/php-8.3.0-x86_64-1.txz: Upgraded.
n/samba-4.19.3-x86_64-1.txz: Upgraded.
This is a security release in order to address the following defect:
An information leak vulnerability was discovered in Samba's LDAP server.
Due to missing access control checks, an authenticated but unprivileged
attacker could discover the names and preserved attributes of deleted objects
in the LDAP store. Upgrading to this package will not prevent this
information leak - if you are using Samba as an Active Directory Domain
Controller, you will need to follow the instructions in the samba.org link
given below.
For more information, see:
https://www.samba.org/samba/security/CVE-2018-14628.html
https://www.cve.org/CVERecord?id=CVE-2018-14628
(* Security fix *)
x/libwacom-2.9.0-x86_64-1.txz: Upgraded.
20231127215437 | Patrick J Volkerding | 2023-11-27 | 1 | -4/+0 |
* | Sat Nov 25 19:44:38 UTC 2023...a/shadow-4.14.2-x86_64-2.txz: Rebuilt.
adduser: fixed chown syntax to silence warnings. Thanks to Stuart Winter.
l/gi-docgen-2023.3-x86_64-1.txz: Added.
Thanks to Heinz Wiesinger.
l/python-smartypants-2.0.1-x86_64-1.txz: Added.
Needed for gi-docgen. Thanks to Heinz Wiesinger.
l/python-toml-0.10.2-x86_64-1.txz: Added.
Needed for gi-docgen. Thanks to Heinz Wiesinger.
l/python-typogrify-2.0.7-x86_64-1.txz: Added.
Needed for gi-docgen. Thanks to Heinz Wiesinger.
x/xdg-desktop-portal-1.18.2-x86_64-1.txz: Upgraded.
Thanks to 0XBF.
testing/packages/php-8.3.0-x86_64-1.txz: Added.
20231125194438 | Patrick J Volkerding | 2023-11-25 | 1 | -0/+5 |
* | Fri Nov 24 20:52:02 UTC 2023...a/openssl-solibs-3.2.0-x86_64-1.txz: Upgraded.
ap/sqlite-3.44.2-x86_64-1.txz: Upgraded.
ap/vim-9.0.2127-x86_64-1.txz: Upgraded.
Fixed security issues.
Thanks to marav for the heads-up.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2023-48231
https://www.cve.org/CVERecord?id=CVE-2023-48232
https://www.cve.org/CVERecord?id=CVE-2023-48233
https://www.cve.org/CVERecord?id=CVE-2023-48234
https://www.cve.org/CVERecord?id=CVE-2023-48235
https://www.cve.org/CVERecord?id=CVE-2023-48236
https://www.cve.org/CVERecord?id=CVE-2023-48237
(* Security fix *)
d/parallel-20231122-noarch-1.txz: Upgraded.
l/cfitsio-4.3.1-x86_64-1.txz: Upgraded.
l/ffmpeg-5.1.4-x86_64-2.txz: Rebuilt.
Recompiled against vulkan-sdk-1.3.268.0.
n/openssl-3.2.0-x86_64-1.txz: Upgraded.
OpenSSL 3.2.0 is a feature release adding significant new functionality.
This release incorporates the following potentially significant or
incompatible changes:
* The default SSL/TLS security level has been changed from 1 to 2.
* The `x509`, `ca`, and `req` apps now always produce X.509v3 certificates.
* Subject or issuer names in X.509 objects are now displayed as UTF-8 strings
by default.
x/vulkan-sdk-1.3.268.0-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
xap/vim-gvim-9.0.2127-x86_64-1.txz: Upgraded.
20231124205202 | Patrick J Volkerding | 2023-11-24 | 1 | -2/+0 |
* | Tue Nov 21 21:15:30 UTC 2023...We have fresh 6.6 kernels in /testing! You may notice that on the 32-bit side
we have done away with the -smp labeled kernel packages, but it's actually the
other kernels that were retired -- the non-SMP, non-PAE ones. If you were
previously using kernel-generic-smp or kernel-huge-smp, you'll need to make
some adjustments to your bootloader setup to load kernel-generic or kernel-huge
instead. About the only non-obsolete CPUs that may have an issue with this are
the first generation Pentium M chips, which supported PAE but unfortunately did
not advertise this in the CPU flags. But these will support PAE if the kernel
option "forcepae" is appended at boot time. Enjoy! :-)
a/gettext-0.22.4-x86_64-1.txz: Upgraded.
a/kbd-2.6.3-x86_64-3.txz: Rebuilt.
Installed extra console fonts.
a/kernel-firmware-20231120_9552083-noarch-1.txz: Upgraded.
a/kernel-generic-6.1.63-x86_64-1.txz: Upgraded.
a/kernel-huge-6.1.63-x86_64-1.txz: Upgraded.
a/kernel-modules-6.1.63-x86_64-1.txz: Upgraded.
a/mkinitrd-1.4.11-x86_64-34.txz: Rebuilt.
Fix tests for including jfs/xfs repair tools. Thanks to regdub.
a/pkgtools-15.1-noarch-8.txz: Rebuilt.
Make vim the default vi choice.
ap/vim-9.0.2116-x86_64-1.txz: Upgraded.
d/gettext-tools-0.22.4-x86_64-1.txz: Upgraded.
d/git-2.43.0-x86_64-1.txz: Upgraded.
d/kernel-headers-6.1.63-x86-1.txz: Upgraded.
d/mercurial-6.6-x86_64-1.txz: Upgraded.
d/meson-1.3.0-x86_64-1.txz: Upgraded.
d/scons-4.6.0-x86_64-1.txz: Upgraded.
k/kernel-source-6.1.63-noarch-1.txz: Upgraded.
l/readline-8.2.007-x86_64-1.txz: Upgraded.
n/c-ares-1.22.1-x86_64-1.txz: Upgraded.
n/nfs-utils-2.6.4-x86_64-1.txz: Upgraded.
x/libdrm-2.4.118-x86_64-1.txz: Upgraded.
xap/mozilla-firefox-115.5.0esr-x86_64-1.txz: Upgraded.
This update contains security fixes and improvements.
Thanks to zuriel for the taskbar icon fix on Wayland. :-)
For more information, see:
https://www.mozilla.org/en-US/firefox/115.5.0/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2023-50/
https://www.cve.org/CVERecord?id=CVE-2023-6204
https://www.cve.org/CVERecord?id=CVE-2023-6205
https://www.cve.org/CVERecord?id=CVE-2023-6206
https://www.cve.org/CVERecord?id=CVE-2023-6207
https://www.cve.org/CVERecord?id=CVE-2023-6208
https://www.cve.org/CVERecord?id=CVE-2023-6209
https://www.cve.org/CVERecord?id=CVE-2023-6212
(* Security fix *)
xap/vim-gvim-9.0.2116-x86_64-1.txz: Upgraded.
xap/xsnow-3.7.6-x86_64-1.txz: Upgraded.
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
testing/packages/kernel-generic-6.6.2-x86_64-1.txz: Added.
testing/packages/kernel-headers-6.6.2-x86-1.txz: Added.
testing/packages/kernel-huge-6.6.2-x86_64-1.txz: Added.
testing/packages/kernel-modules-6.6.2-x86_64-1.txz: Added.
testing/packages/kernel-source-6.6.2-noarch-1.txz: Added.
usb-and-pxe-installers/usbboot.img: Rebuilt.
20231121211530 | Patrick J Volkerding | 2023-11-21 | 1 | -0/+2 |
* | Fri Nov 10 18:46:44 UTC 2023...a/bash-5.2.021-x86_64-1.txz: Upgraded.
ap/rdfind-1.6.0-x86_64-1.txz: Added.
ap/sudo-1.9.15p2-x86_64-1.txz: Upgraded.
l/ffmpeg-5.1.4-x86_64-1.txz: Upgraded.
n/dhcpcd-10.0.5-x86_64-1.txz: Upgraded.
n/whois-5.5.20-x86_64-1.txz: Upgraded.
Added the .gn TLD server.
Removed 6 new gTLDs which are no longer active.
xfce/xfce4-whiskermenu-plugin-2.8.1-x86_64-1.txz: Upgraded.
20231110184644 | Patrick J Volkerding | 2023-11-10 | 1 | -2/+0 |
* | Wed Nov 8 22:04:25 UTC 2023...a/kbd-2.6.3-x86_64-1.txz: Upgraded.
Thanks to Robby Workman.
a/kernel-firmware-20231107_2340796-noarch-1.txz: Upgraded.
a/kernel-generic-6.1.62-x86_64-1.txz: Upgraded.
a/kernel-huge-6.1.62-x86_64-1.txz: Upgraded.
a/kernel-modules-6.1.62-x86_64-1.txz: Upgraded.
ap/sudo-1.9.15p1-x86_64-1.txz: Upgraded.
This is a bugfix release:
Fixed a bug introduced in sudo 1.9.15 that prevented LDAP-based sudoers
from being able to read the ldap.conf file.
d/kernel-headers-6.1.62-x86-1.txz: Upgraded.
k/kernel-source-6.1.62-noarch-1.txz: Upgraded.
kde/plasma-wayland-protocols-1.11.0-x86_64-1.txz: Upgraded.
l/liburing-2.5-x86_64-1.txz: Upgraded.
xap/mozilla-thunderbird-115.4.2-x86_64-1.txz: Upgraded.
This is a bugfix release.
For more information, see:
https://www.mozilla.org/en-US/thunderbird/115.4.2/releasenotes/
xap/xlockmore-5.74-x86_64-1.txz: Upgraded.
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
usb-and-pxe-installers/usbboot.img: Rebuilt.
20231108220425 | Patrick J Volkerding | 2023-11-08 | 1 | -8/+3 |
* | Fri Oct 27 19:47:36 UTC 2023...a/exfatprogs-1.2.2-x86_64-1.txz: Upgraded.
kde/digikam-8.1.0-x86_64-2.txz: Rebuilt.
Recompiled against exiv2-0.28.0.
kde/gwenview-23.08.2-x86_64-2.txz: Rebuilt.
Recompiled against exiv2-0.28.0.
kde/kfilemetadata-5.111.0-x86_64-2.txz: Rebuilt.
Recompiled against exiv2-0.28.0.
kde/krename-5.0.2-x86_64-2.txz: Rebuilt.
Recompiled against exiv2-0.28.0.
kde/krita-5.2.0-x86_64-2.txz: Rebuilt.
Recompiled against exiv2-0.28.0.
kde/libkexiv2-23.08.2-x86_64-2.txz: Rebuilt.
Recompiled against exiv2-0.28.0.
l/QtAV-20220226_fdc613dc-x86_64-1.txz: Removed.
This is no longer used by digikam, so let's just remove it.
l/exiv2-0.28.0-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
l/libsoup3-3.4.4-x86_64-1.txz: Upgraded.
n/c-ares-1.21.0-x86_64-1.txz: Upgraded.
n/gpgme-1.23.1-x86_64-1.txz: Upgraded.
n/nghttp2-1.58.0-x86_64-1.txz: Upgraded.
xap/geeqie-2.1-x86_64-3.txz: Rebuilt.
Recompiled against exiv2-0.28.0.
20231027194736 | Patrick J Volkerding | 2023-10-27 | 1 | -2/+2 |
* | Sun Oct 22 19:30:42 UTC 2023...a/lvm2-2.03.22-x86_64-1.txz: Upgraded.
kde/kstars-3.6.7-x86_64-1.txz: Upgraded.
It's time for KStars in Slackware to be less of a toy and more of a useful
tool. The required dependencies have been added for EKOS, the INDI client
included in KStars, which will allow for computer control of astronomy
devices. Additional deps and drivers may be required, but these are runtime
dependencies. See (for example) gpsd, libdc1394, libftdi1, libindi-libraries,
and libindi-drivers, all of which can be found on slackbuilds.org.
Huge thanks to Edward W. Koenig for the detailed writeup - it was extremely
helpful! :-) Here's a link to the article:
https://www.linuxgalaxy.org/kingbeowulf/astronomy-device-control-in-slackware-15-and-current/
kde/libindi-2.0.4-x86_64-1.txz: Added.
This is required by kstars-3.6.7.
kde/libnova-0.15.0-x86_64-1.txz: Added.
This is required by kstars-3.6.7.
Thanks to Chris Abela, Ryan P.C. McQuen, and Philip Lacroix.
kde/stellarsolver-2.5-x86_64-1.txz: Added.
This is required by kstars-3.6.7.
kde/wcslib-8.1-x86_64-1.txz: Added.
This is required by kstars-3.6.7.
l/LibRaw-0.21.1-x86_64-2.txz: Rebuilt.
This update fixes a security issue:
A heap-buffer-overflow was found in raw2image_ex(int), which may lead to
application crash by maliciously crafted input file.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2023-1729
(* Security fix *)
l/imagemagick-7.1.1_21-x86_64-1.txz: Upgraded.
l/libev-4.33-x86_64-1.txz: Added.
This is required by kstars-3.6.7.
As this package may have more general usage than just kstars, we'll put it
in the L series.
Thanks to AA ime Ramov and Matteo Bernardini.
l/vte-0.74.1-x86_64-1.txz: Upgraded.
20231022193042 | Patrick J Volkerding | 2023-10-22 | 1 | -0/+1 |
* | Mon Oct 9 18:10:01 UTC 2023...a/aaa_glibc-solibs-2.38-x86_64-2.txz: Rebuilt.
ap/qpdf-11.6.2-x86_64-1.txz: Upgraded.
ap/vim-9.0.2009-x86_64-1.txz: Upgraded.
l/desktop-file-utils-0.27-x86_64-1.txz: Upgraded.
l/glibc-2.38-x86_64-2.txz: Rebuilt.
These glibc packages are the exact ones that were previously in /testing.
A test mass rebuild was done here finding no new FTBFS, so I think these
are good to go. :)
l/glibc-i18n-2.38-x86_64-2.txz: Rebuilt.
l/glibc-profile-2.38-x86_64-2.txz: Rebuilt.
l/imagemagick-7.1.1_20-x86_64-1.txz: Upgraded.
l/libxkbcommon-1.6.0-x86_64-1.txz: Upgraded.
l/shared-mime-info-2.3-x86_64-1.txz: Upgraded.
n/c-ares-1.20.0-x86_64-1.txz: Upgraded.
n/libtirpc-1.3.4-x86_64-1.txz: Upgraded.
n/proftpd-1.3.8a-x86_64-1.txz: Upgraded.
n/whois-5.5.19-x86_64-1.txz: Upgraded.
Fixed english support for Japanese queries to not add again the /e argument
if it had already been provided by the user. (Closes: #1050171)
Added the .ye and .*************** (.xn--54b7fta0cc, Bangladesh) TLD servers.
Updated the .ba, .bb, .dk, .es, .gt, .jo, .ml, .mo, .pa, .pn, .sv, .uy,
.a+-la-r+-d+.n+, (.xn--mgbayh7gpa, Jordan) and .****** (.xn--mix891f, Macao)
TLD servers.
Upgraded the TLD URLs to HTTPS whenever possible.
Updated the charset for whois.jprs.jp.
Removed 3 new gTLDs which are no longer active.
Removed support for the obsolete as32 dot notation.
x/xterm-386-x86_64-1.txz: Upgraded.
xap/vim-gvim-9.0.2009-x86_64-1.txz: Upgraded.
20231009181001 | Patrick J Volkerding | 2023-10-09 | 1 | -9/+2 |
* | Thu Oct 5 21:44:34 UTC 2023...kde/krita-5.2.0-x86_64-1.txz: Upgraded.
l/fftw-3.3.10-x86_64-2.txz: Rebuilt.
Build and package missing FFTW3LibraryDepends.cmake.
This is needed for krita-5.2.0.
l/immer-0.8.1-x86_64-1.txz: Added.
This is needed for krita-5.2.0.
l/lager-0.1.0-x86_64-1.txz: Added.
This is needed for krita-5.2.0.
l/libunibreak-5.1-x86_64-1.txz: Added.
This is needed for krita-5.2.0.
l/zug-0.1.0-x86_64-1.txz: Added.
This is needed for krita-5.2.0.
xap/network-manager-applet-1.34.0-x86_64-1.txz: Upgraded.
20231005214434 | Patrick J Volkerding | 2023-10-06 | 1 | -1/+0 |
* | Tue Oct 3 22:19:10 UTC 2023...a/aaa_glibc-solibs-2.37-x86_64-3.txz: Rebuilt.
a/dialog-1.3_20231002-x86_64-1.txz: Upgraded.
ap/mpg123-1.32.3-x86_64-1.txz: Upgraded.
d/llvm-17.0.2-x86_64-1.txz: Upgraded.
d/meson-1.2.2-x86_64-2.txz: Rebuilt.
[PATCH] Revert rust: apply global, project, and environment C args to bindgen.
This fixes building Mesa.
Thanks to lucabon and marav.
kde/calligra-3.2.1-x86_64-34.txz: Rebuilt.
Recompiled against poppler-23.10.0.
kde/cantor-23.08.1-x86_64-2.txz: Rebuilt.
Recompiled against poppler-23.10.0.
kde/kfilemetadata-5.110.0-x86_64-2.txz: Rebuilt.
Recompiled against poppler-23.10.0.
kde/kile-2.9.93-x86_64-28.txz: Rebuilt.
Recompiled against poppler-23.10.0.
kde/kitinerary-23.08.1-x86_64-2.txz: Rebuilt.
Recompiled against poppler-23.10.0.
kde/krita-5.1.5-x86_64-15.txz: Rebuilt.
Recompiled against poppler-23.10.0.
kde/okular-23.08.1-x86_64-2.txz: Rebuilt.
Recompiled against poppler-23.10.0.
l/glibc-2.37-x86_64-3.txz: Rebuilt.
l/glibc-i18n-2.37-x86_64-3.txz: Rebuilt.
Patched to fix the "Looney Tunables" vulnerability, a local privilege
escalation in ld.so. This vulnerability was introduced in April 2021
(glibc 2.34) by commit 2ed18c.
Thanks to Qualys Research Labs for reporting this issue.
For more information, see:
https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
https://www.cve.org/CVERecord?id=CVE-2023-4911
(* Security fix *)
l/glibc-profile-2.37-x86_64-3.txz: Rebuilt.
l/mozilla-nss-3.94-x86_64-1.txz: Upgraded.
l/poppler-23.10.0-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
n/NetworkManager-1.44.2-x86_64-1.txz: Upgraded.
n/irssi-1.4.5-x86_64-1.txz: Upgraded.
x/fcitx5-5.1.1-x86_64-1.txz: Upgraded.
x/fcitx5-anthy-5.1.1-x86_64-1.txz: Upgraded.
x/fcitx5-chinese-addons-5.1.1-x86_64-1.txz: Upgraded.
x/fcitx5-gtk-5.1.0-x86_64-1.txz: Upgraded.
x/fcitx5-hangul-5.1.0-x86_64-1.txz: Upgraded.
x/fcitx5-kkc-5.1.0-x86_64-1.txz: Upgraded.
x/fcitx5-m17n-5.1.0-x86_64-1.txz: Upgraded.
x/fcitx5-qt-5.1.1-x86_64-1.txz: Upgraded.
x/fcitx5-sayura-5.1.0-x86_64-1.txz: Upgraded.
x/fcitx5-table-extra-5.1.0-x86_64-1.txz: Upgraded.
x/fcitx5-table-other-5.1.0-x86_64-1.txz: Upgraded.
x/fcitx5-unikey-5.1.1-x86_64-1.txz: Upgraded.
x/libX11-1.8.7-x86_64-1.txz: Upgraded.
This update fixes security issues:
libX11: out-of-bounds memory access in _XkbReadKeySyms().
libX11: stack exhaustion from infinite recursion in PutSubImage().
libX11: integer overflow in XCreateImage() leading to a heap overflow.
For more information, see:
https://lists.x.org/archives/xorg-announce/2023-October/003424.html
https://www.cve.org/CVERecord?id=CVE-2023-43785
https://www.cve.org/CVERecord?id=CVE-2023-43786
https://www.cve.org/CVERecord?id=CVE-2023-43787
(* Security fix *)
x/libXpm-3.5.17-x86_64-1.txz: Upgraded.
This update fixes security issues:
libXpm: out of bounds read in XpmCreateXpmImageFromBuffer().
libXpm: out of bounds read on XPM with corrupted colormap.
For more information, see:
https://lists.x.org/archives/xorg-announce/2023-October/003424.html
https://www.cve.org/CVERecord?id=CVE-2023-43788
https://www.cve.org/CVERecord?id=CVE-2023-43789
(* Security fix *)
testing/packages/aaa_glibc-solibs-2.38-x86_64-2.txz: Rebuilt.
testing/packages/glibc-2.38-x86_64-2.txz: Rebuilt.
Patched to fix the "Looney Tunables" vulnerability, a local privilege
escalation in ld.so. This vulnerability was introduced in April 2021
(glibc 2.34) by commit 2ed18c.
Thanks to Qualys Research Labs for reporting this issue.
For more information, see:
https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
https://www.cve.org/CVERecord?id=CVE-2023-4911
(* Security fix *)
testing/packages/glibc-i18n-2.38-x86_64-2.txz: Rebuilt.
testing/packages/glibc-profile-2.38-x86_64-2.txz: Rebuilt.
20231003221910 | Patrick J Volkerding | 2023-10-04 | 1 | -2/+2 |
* | Thu Sep 28 21:37:06 UTC 2023...ap/mpg123-1.32.2-x86_64-1.txz: Upgraded.
l/cairo-1.18.0-x86_64-1.txz: Upgraded.
l/gtk4-4.12.3-x86_64-1.txz: Upgraded.
x/fonttosfnt-1.2.3-x86_64-1.txz: Upgraded.
xap/geeqie-2.1-x86_64-2.txz: Rebuilt.
Patched and recompiled against lua-5.4.6.
xap/mozilla-firefox-115.3.1esr-x86_64-1.txz: Upgraded.
This update contains a security fix.
For more information, see:
https://www.mozilla.org/en-US/firefox/115.3.1/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/
https://www.cve.org/CVERecord?id=CVE-2023-5217
(* Security fix *)
xfce/xfce4-panel-4.18.5-x86_64-1.txz: Upgraded.
testing/packages/aaa_glibc-solibs-2.38-x86_64-1.txz: Added.
testing/packages/glibc-2.38-x86_64-1.txz: Added.
Instead of building the deprecated glibc crypt library, bundle
libxcrypt-4.4.36 (both .so.1 compat version and .so.2 new API version).
testing/packages/glibc-i18n-2.38-x86_64-1.txz: Added.
testing/packages/glibc-profile-2.38-x86_64-1.txz: Added.
20230928213706 | Patrick J Volkerding | 2023-09-29 | 1 | -0/+6 |