From 7716b728c18deb9a2c780e148050e3683d4d93c1 Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Wed, 10 Oct 2018 23:09:36 +0000 Subject: Wed Oct 10 23:09:36 UTC 2018 a/kernel-firmware-20181008_c6b6265-noarch-1.txz: Upgraded. a/kernel-generic-4.14.75-x86_64-1.txz: Upgraded. a/kernel-huge-4.14.75-x86_64-1.txz: Upgraded. a/kernel-modules-4.14.75-x86_64-1.txz: Upgraded. d/git-2.19.1-x86_64-1.txz: Upgraded. Submodules' "URL"s come from the untrusted .gitmodules file, but we blindly gave it to "git clone" to clone submodules when "git clone --recurse-submodules" was used to clone a project that has such a submodule. The code has been hardened to reject such malformed URLs (e.g. one that begins with a dash). Credit for finding and fixing this vulnerability goes to joernchen and Jeff King, respectively. For more information, see: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17456 (* Security fix *) d/kernel-headers-4.14.75-x86-1.txz: Upgraded. d/make-4.2.1-x86_64-4.txz: Rebuilt. Use a non-blocking read with pselect to avoid hangs. Thanks to Linux.tar.gz and David Spencer. d/subversion-1.10.3-x86_64-1.txz: Upgraded. k/kernel-source-4.14.75-noarch-1.txz: Upgraded. Config changes since 4.14.74: FB_HYPERV n -> m Thanks to walecha. l/librsvg-2.44.7-x86_64-1.txz: Upgraded. l/python-pillow-5.3.0-x86_64-1.txz: Upgraded. n/nghttp2-1.34.0-x86_64-1.txz: Upgraded. x/libSM-1.2.3-x86_64-1.txz: Upgraded. x/libX11-1.6.7-x86_64-1.txz: Upgraded. x/libdrm-2.4.95-x86_64-1.txz: Upgraded. x/libxcb-1.13.1-x86_64-1.txz: Upgraded. x/vulkan-sdk-1.1.85.0-x86_64-1.txz: Upgraded. Thanks to dugan. xap/gnuplot-5.2.5-x86_64-1.txz: Upgraded. isolinux/initrd.img: Rebuilt. kernels/*: Upgraded. usb-and-pxe-installers/usbboot.img: Rebuilt. --- ChangeLog.rss | 50 ++++++++++++++++++++++++++++++++++++++++++++++++-- 1 file changed, 48 insertions(+), 2 deletions(-) (limited to 'ChangeLog.rss') diff --git a/ChangeLog.rss b/ChangeLog.rss index 5ef8ca061..70b56abbb 100644 --- a/ChangeLog.rss +++ b/ChangeLog.rss @@ -11,9 +11,55 @@ Tracking Slackware development in git. en-us urn:uuid:c964f45e-6732-11e8-bbe5-107b4450212f - Fri, 5 Oct 2018 22:43:41 GMT - Sat, 6 Oct 2018 07:00:29 GMT + Wed, 10 Oct 2018 23:09:36 GMT + Thu, 11 Oct 2018 07:00:28 GMT maintain_current_git.sh v 1.10 + + Wed, 10 Oct 2018 23:09:36 GMT + Wed, 10 Oct 2018 23:09:36 GMT + https://git.slackware.nl/current/tag/?h=20181010230936 + 20181010230936 + + +a/kernel-firmware-20181008_c6b6265-noarch-1.txz: Upgraded. +a/kernel-generic-4.14.75-x86_64-1.txz: Upgraded. +a/kernel-huge-4.14.75-x86_64-1.txz: Upgraded. +a/kernel-modules-4.14.75-x86_64-1.txz: Upgraded. +d/git-2.19.1-x86_64-1.txz: Upgraded. + Submodules' "URL"s come from the untrusted .gitmodules file, but we + blindly gave it to "git clone" to clone submodules when "git clone + --recurse-submodules" was used to clone a project that has such a + submodule. The code has been hardened to reject such malformed URLs + (e.g. one that begins with a dash). Credit for finding and fixing this + vulnerability goes to joernchen and Jeff King, respectively. + For more information, see: + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17456 + (* Security fix *) +d/kernel-headers-4.14.75-x86-1.txz: Upgraded. +d/make-4.2.1-x86_64-4.txz: Rebuilt. + Use a non-blocking read with pselect to avoid hangs. + Thanks to Linux.tar.gz and David Spencer. +d/subversion-1.10.3-x86_64-1.txz: Upgraded. +k/kernel-source-4.14.75-noarch-1.txz: Upgraded. + Config changes since 4.14.74: + FB_HYPERV n -> m + Thanks to walecha. +l/librsvg-2.44.7-x86_64-1.txz: Upgraded. +l/python-pillow-5.3.0-x86_64-1.txz: Upgraded. +n/nghttp2-1.34.0-x86_64-1.txz: Upgraded. +x/libSM-1.2.3-x86_64-1.txz: Upgraded. +x/libX11-1.6.7-x86_64-1.txz: Upgraded. +x/libdrm-2.4.95-x86_64-1.txz: Upgraded. +x/libxcb-1.13.1-x86_64-1.txz: Upgraded. +x/vulkan-sdk-1.1.85.0-x86_64-1.txz: Upgraded. + Thanks to dugan. +xap/gnuplot-5.2.5-x86_64-1.txz: Upgraded. +isolinux/initrd.img: Rebuilt. +kernels/*: Upgraded. +usb-and-pxe-installers/usbboot.img: Rebuilt. + ]]> + + Fri, 5 Oct 2018 22:43:41 GMT Fri, 5 Oct 2018 22:43:41 GMT -- cgit v1.2.3