From 51dac8e0d6d3193cb63563eb91a2cd6c8084e20d Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Wed, 3 Jun 2020 20:21:52 +0000 Subject: Wed Jun 3 20:21:52 UTC 2020 a/dbus-1.12.18-x86_64-1.txz: Upgraded. a/kernel-generic-5.4.44-x86_64-1.txz: Upgraded. a/kernel-huge-5.4.44-x86_64-1.txz: Upgraded. a/kernel-modules-5.4.44-x86_64-1.txz: Upgraded. d/bison-3.6.3-x86_64-1.txz: Upgraded. d/kernel-headers-5.4.44-x86-1.txz: Upgraded. d/subversion-1.14.0-x86_64-1.txz: Upgraded. k/kernel-source-5.4.44-noarch-1.txz: Upgraded. l/harfbuzz-2.6.7-x86_64-1.txz: Upgraded. l/libcap-2.36-x86_64-1.txz: Upgraded. l/librsvg-2.48.6-x86_64-1.txz: Upgraded. n/gnutls-3.6.14-x86_64-1.txz: Upgraded. Fixed insecure session ticket key construction, since 3.6.4. The TLS server would not bind the session ticket encryption key with a value supplied by the application until the initial key rotation, allowing attacker to bypass authentication in TLS 1.3 and recover previous conversations in TLS 1.2. [GNUTLS-SA-2020-06-03, CVSS: high] (* Security fix *) n/iproute2-5.7.0-x86_64-1.txz: Upgraded. n/iptables-1.8.5-x86_64-1.txz: Upgraded. xap/audacious-4.0.4-x86_64-1.txz: Upgraded. xap/audacious-plugins-4.0.4-x86_64-1.txz: Upgraded. extra/pure-alsa-system/audacious-plugins-4.0.4-x86_64-1_alsa.txz: Upgraded. isolinux/initrd.img: Rebuilt. kernels/*: Upgraded. usb-and-pxe-installers/usbboot.img: Rebuilt. --- ChangeLog.txt | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) (limited to 'ChangeLog.txt') diff --git a/ChangeLog.txt b/ChangeLog.txt index fe02c42d9..ee9167450 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -1,3 +1,31 @@ +Wed Jun 3 20:21:52 UTC 2020 +a/dbus-1.12.18-x86_64-1.txz: Upgraded. +a/kernel-generic-5.4.44-x86_64-1.txz: Upgraded. +a/kernel-huge-5.4.44-x86_64-1.txz: Upgraded. +a/kernel-modules-5.4.44-x86_64-1.txz: Upgraded. +d/bison-3.6.3-x86_64-1.txz: Upgraded. +d/kernel-headers-5.4.44-x86-1.txz: Upgraded. +d/subversion-1.14.0-x86_64-1.txz: Upgraded. +k/kernel-source-5.4.44-noarch-1.txz: Upgraded. +l/harfbuzz-2.6.7-x86_64-1.txz: Upgraded. +l/libcap-2.36-x86_64-1.txz: Upgraded. +l/librsvg-2.48.6-x86_64-1.txz: Upgraded. +n/gnutls-3.6.14-x86_64-1.txz: Upgraded. + Fixed insecure session ticket key construction, since 3.6.4. The TLS server + would not bind the session ticket encryption key with a value supplied by + the application until the initial key rotation, allowing attacker to bypass + authentication in TLS 1.3 and recover previous conversations in TLS 1.2. + [GNUTLS-SA-2020-06-03, CVSS: high] + (* Security fix *) +n/iproute2-5.7.0-x86_64-1.txz: Upgraded. +n/iptables-1.8.5-x86_64-1.txz: Upgraded. +xap/audacious-4.0.4-x86_64-1.txz: Upgraded. +xap/audacious-plugins-4.0.4-x86_64-1.txz: Upgraded. +extra/pure-alsa-system/audacious-plugins-4.0.4-x86_64-1_alsa.txz: Upgraded. +isolinux/initrd.img: Rebuilt. +kernels/*: Upgraded. +usb-and-pxe-installers/usbboot.img: Rebuilt. ++--------------------------+ Tue Jun 2 19:31:39 UTC 2020 a/hwdata-0.336-noarch-1.txz: Upgraded. ap/man-db-2.9.2-x86_64-1.txz: Upgraded. -- cgit v1.2.3