From 89d895f1ff30ec2a473919179e995715d0ddf23a Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Sat, 22 Sep 2018 22:41:41 +0000 Subject: Sat Sep 22 22:41:41 UTC 2018 a/eudev-3.2.6-x86_64-2.txz: Rebuilt. Removed unneeded groups "render" and "kvm" from 50-udev-default.rules. Thanks to Richard David Sherman. a/grub-2.02-x86_64-4.txz: Rebuilt. Applied a patch needed when compiling with recent binutils. Thanks to ivandi. d/parallel-20180922-noarch-1.txz: Upgraded. x/xterm-337-x86_64-1.txz: Upgraded. xap/mozilla-firefox-60.2.1esr-x86_64-1.txz: Upgraded. This release contains security fixes and improvements. A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. For more information, see: https://www.mozilla.org/security/known-vulnerabilities/firefoxESR.html https://www.mozilla.org/en-US/security/advisories/mfsa2018-23/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12383 (* Security fix *) --- ChangeLog.rss | 35 +++++++++++++++++++++++++++++++++-- 1 file changed, 33 insertions(+), 2 deletions(-) (limited to 'ChangeLog.rss') diff --git a/ChangeLog.rss b/ChangeLog.rss index 6d43c7712..f7c429781 100644 --- a/ChangeLog.rss +++ b/ChangeLog.rss @@ -11,9 +11,40 @@ Tracking Slackware development in git. en-us urn:uuid:c964f45e-6732-11e8-bbe5-107b4450212f - Fri, 21 Sep 2018 18:51:07 GMT - Sat, 22 Sep 2018 07:00:35 GMT + Sat, 22 Sep 2018 22:41:41 GMT + Sun, 23 Sep 2018 07:00:27 GMT maintain_current_git.sh v 1.10 + + Sat, 22 Sep 2018 22:41:41 GMT + Sat, 22 Sep 2018 22:41:41 GMT + https://git.slackware.nl/current/tag/?h=20180922224141 + 20180922224141 + + +a/eudev-3.2.6-x86_64-2.txz: Rebuilt. + Removed unneeded groups "render" and "kvm" from 50-udev-default.rules. + Thanks to Richard David Sherman. +a/grub-2.02-x86_64-4.txz: Rebuilt. + Applied a patch needed when compiling with recent binutils. Thanks to ivandi. +d/parallel-20180922-noarch-1.txz: Upgraded. +x/xterm-337-x86_64-1.txz: Upgraded. +xap/mozilla-firefox-60.2.1esr-x86_64-1.txz: Upgraded. + This release contains security fixes and improvements. + A potentially exploitable crash in TransportSecurityInfo used for SSL + can be triggered by data stored in the local cache in the user profile + directory. This issue is only exploitable in combination with another + vulnerability allowing an attacker to write data into the local cache + or from locally installed malware. This issue also triggers a + non-exploitable startup crash for users switching between the Nightly + and Release versions of Firefox if the same profile is used. + For more information, see: + https://www.mozilla.org/security/known-vulnerabilities/firefoxESR.html + https://www.mozilla.org/en-US/security/advisories/mfsa2018-23/ + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12383 + (* Security fix *) + ]]> + + Fri, 21 Sep 2018 18:51:07 GMT Fri, 21 Sep 2018 18:51:07 GMT -- cgit v1.2.3