From 387b2bc525d80b10c96f2f6ab17e50635dd0effc Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Tue, 25 Oct 2022 18:38:58 +0000 Subject: Tue Oct 25 18:38:58 UTC 2022 ap/alsa-utils-1.2.8-x86_64-1.txz: Upgraded. l/alsa-lib-1.2.8-x86_64-1.txz: Upgraded. l/expat-2.5.0-x86_64-1.txz: Upgraded. This update fixes a security issue: Fix heap use-after-free after overeager destruction of a shared DTD in function XML_ExternalEntityParserCreate in out-of-memory situations. Expected impact is denial of service or potentially arbitrary code execution. For more information, see: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43680 (* Security fix *) n/samba-4.17.2-x86_64-1.txz: Upgraded. This update fixes the following security issues: There is a limited write heap buffer overflow in the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal (included in Samba). A malicious client can use a symlink to escape the exported directory. For more information, see: https://www.samba.org/samba/security/CVE-2022-3437.html https://www.samba.org/samba/security/CVE-2022-3592.html https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3437 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3592 (* Security fix *) --- source/l/expat/expat.url | 4 ++-- source/n/samba/samba.url | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) (limited to 'source') diff --git a/source/l/expat/expat.url b/source/l/expat/expat.url index 6dead6436..ed04fb252 100644 --- a/source/l/expat/expat.url +++ b/source/l/expat/expat.url @@ -1,2 +1,2 @@ -https://github.com/libexpat/libexpat/releases/download/R_2_4_9/expat-2.4.9.tar.lz -https://github.com/libexpat/libexpat/releases/download/R_2_4_9/expat-2.4.9.tar.lz.asc +https://github.com/libexpat/libexpat/releases/download/R_2_5_0/expat-2.5.0.tar.lz +https://github.com/libexpat/libexpat/releases/download/R_2_5_0/expat-2.5.0.tar.lz.asc diff --git a/source/n/samba/samba.url b/source/n/samba/samba.url index 3ff921501..9471b1176 100644 --- a/source/n/samba/samba.url +++ b/source/n/samba/samba.url @@ -1,2 +1,2 @@ -https://download.samba.org/pub/samba/stable/samba-4.17.1.tar.gz -https://download.samba.org/pub/samba/stable/samba-4.17.1.tar.asc +https://download.samba.org/pub/samba/stable/samba-4.17.2.tar.gz +https://download.samba.org/pub/samba/stable/samba-4.17.2.tar.asc -- cgit v1.2.3-65-gdbad