From f15476bf3e7de9998ebd2488dc769e2ea6b3d23d Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Tue, 29 Sep 2020 18:11:08 +0000 Subject: Tue Sep 29 18:11:08 UTC 2020 n/php-7.4.11-x86_64-1.txz: Upgraded. This update fixes bugs and two security issues: Core: PHP parses encoded cookie names so malicious `__Host-` cookies can be sent. OpenSSL: Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV. For more information, see: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7070 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7069 (* Security fix *) x/mesa-20.2.0-x86_64-1.txz: Upgraded. --- ChangeLog.txt | 12 ++++++++++++ 1 file changed, 12 insertions(+) (limited to 'ChangeLog.txt') diff --git a/ChangeLog.txt b/ChangeLog.txt index 82f9b9baf..f4d96e849 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -1,3 +1,15 @@ +Tue Sep 29 18:11:08 UTC 2020 +n/php-7.4.11-x86_64-1.txz: Upgraded. + This update fixes bugs and two security issues: + Core: PHP parses encoded cookie names so malicious `__Host-` cookies + can be sent. + OpenSSL: Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV. + For more information, see: + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7070 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7069 + (* Security fix *) +x/mesa-20.2.0-x86_64-1.txz: Upgraded. ++--------------------------+ Mon Sep 28 18:29:52 UTC 2020 a/grep-3.5-x86_64-1.txz: Upgraded. a/kernel-firmware-20200928_b78a66c-noarch-1.txz: Upgraded. -- cgit v1.2.3