From 15dd12c06b7e2a46943dee0b3b096e2593406b8c Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Wed, 21 Jul 2021 18:16:58 +0000 Subject: Wed Jul 21 18:16:58 UTC 2021 a/mcelog-178-x86_64-1.txz: Upgraded. l/dbus-python-1.2.18-x86_64-1.txz: Upgraded. n/curl-7.78.0-x86_64-1.txz: Upgraded. This update fixes security issues: CURLOPT_SSLCERT mixup with Secure Transport TELNET stack contents disclosure again Bad connection reuse due to flawed path name checks Metalink download sends credentials Wrong content via metalink not discarded For more information, see: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22926 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22925 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22924 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22923 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22922 (* Security fix *) --- ChangeLog.txt | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) (limited to 'ChangeLog.txt') diff --git a/ChangeLog.txt b/ChangeLog.txt index 817be29f7..d1705b2f8 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -1,3 +1,21 @@ +Wed Jul 21 18:16:58 UTC 2021 +a/mcelog-178-x86_64-1.txz: Upgraded. +l/dbus-python-1.2.18-x86_64-1.txz: Upgraded. +n/curl-7.78.0-x86_64-1.txz: Upgraded. + This update fixes security issues: + CURLOPT_SSLCERT mixup with Secure Transport + TELNET stack contents disclosure again + Bad connection reuse due to flawed path name checks + Metalink download sends credentials + Wrong content via metalink not discarded + For more information, see: + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22926 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22925 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22924 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22923 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22922 + (* Security fix *) ++--------------------------+ Wed Jul 21 05:30:44 UTC 2021 a/kernel-generic-5.13.4-x86_64-1.txz: Upgraded. a/kernel-huge-5.13.4-x86_64-1.txz: Upgraded. -- cgit v1.2.3