From 216e5284961bf8c173702c05ba4329cfaca9015f Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Fri, 17 Sep 2021 04:17:57 +0000 Subject: Fri Sep 17 04:17:57 UTC 2021 a/cryptsetup-2.4.1-x86_64-1.txz: Upgraded. a/sysvinit-scripts-15.0-noarch-5.txz: Rebuilt. Stop D-Bus after NFS partitions are unmounted to avoid a hang. Thanks to vulcan59 and bassmadrigal. ap/sudo-1.9.8p1-x86_64-1.txz: Upgraded. l/fftw-3.3.10-x86_64-1.txz: Upgraded. l/libxkbcommon-1.3.1-x86_64-1.txz: Upgraded. l/pipewire-0.3.36-x86_64-1.txz: Upgraded. n/dhcpcd-9.4.0-x86_64-2.txz: Rebuilt. Applied upstream patch: DHCP6: Only send FQDN for SOLICIT, REQUEST, RENEW, or REBIND messages. Thanks to marav. n/httpd-2.4.49-x86_64-1.txz: Upgraded. This release contains security fixes and improvements. mod_proxy: Server Side Request Forgery (SSRF) vulnerabilty [Yann Ylavic] core: ap_escape_quotes buffer overflow mod_proxy_uwsgi: Out of bound read vulnerability [Yann Ylavic] core: null pointer dereference on malformed request mod_http2: Request splitting vulnerability with mod_proxy [Stefan Eissing] For more information, see: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40438 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39275 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36160 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34798 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33193 (* Security fix *) x/ibus-libpinyin-1.12.1-x86_64-1.txz: Upgraded. x/libpinyin-2.6.1-x86_64-1.txz: Upgraded. xap/mozilla-thunderbird-91.1.1-x86_64-1.txz: Upgraded. This is a bugfix release. For more information, see: https://www.mozilla.org/en-US/thunderbird/91.1.1/releasenotes/ --- ChangeLog.rss | 46 ++++++++++++++++++++++++++++++++++++++++++++-- 1 file changed, 44 insertions(+), 2 deletions(-) (limited to 'ChangeLog.rss') diff --git a/ChangeLog.rss b/ChangeLog.rss index e004f24c..e919a679 100644 --- a/ChangeLog.rss +++ b/ChangeLog.rss @@ -11,9 +11,51 @@ Tracking Slackware development in git. en-us urn:uuid:c964f45e-6732-11e8-bbe5-107b4450212f - Thu, 16 Sep 2021 18:33:01 GMT - Fri, 17 Sep 2021 06:59:47 GMT + Fri, 17 Sep 2021 04:17:57 GMT + Fri, 17 Sep 2021 15:59:43 GMT maintain_current_git.sh v 1.12 + + Fri, 17 Sep 2021 04:17:57 GMT + Fri, 17 Sep 2021 04:17:57 GMT + https://git.slackware.nl/current/tag/?h=20210917041757 + 20210917041757 + + +a/cryptsetup-2.4.1-x86_64-1.txz: Upgraded. +a/sysvinit-scripts-15.0-noarch-5.txz: Rebuilt. + Stop D-Bus after NFS partitions are unmounted to avoid a hang. + Thanks to vulcan59 and bassmadrigal. +ap/sudo-1.9.8p1-x86_64-1.txz: Upgraded. +l/fftw-3.3.10-x86_64-1.txz: Upgraded. +l/libxkbcommon-1.3.1-x86_64-1.txz: Upgraded. +l/pipewire-0.3.36-x86_64-1.txz: Upgraded. +n/dhcpcd-9.4.0-x86_64-2.txz: Rebuilt. + Applied upstream patch: + DHCP6: Only send FQDN for SOLICIT, REQUEST, RENEW, or REBIND messages. + Thanks to marav. +n/httpd-2.4.49-x86_64-1.txz: Upgraded. + This release contains security fixes and improvements. + mod_proxy: Server Side Request Forgery (SSRF) vulnerabilty [Yann Ylavic] + core: ap_escape_quotes buffer overflow + mod_proxy_uwsgi: Out of bound read vulnerability [Yann Ylavic] + core: null pointer dereference on malformed request + mod_http2: Request splitting vulnerability with mod_proxy [Stefan Eissing] + For more information, see: + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40438 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39275 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36160 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34798 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33193 + (* Security fix *) +x/ibus-libpinyin-1.12.1-x86_64-1.txz: Upgraded. +x/libpinyin-2.6.1-x86_64-1.txz: Upgraded. +xap/mozilla-thunderbird-91.1.1-x86_64-1.txz: Upgraded. + This is a bugfix release. + For more information, see: + https://www.mozilla.org/en-US/thunderbird/91.1.1/releasenotes/ + ]]> + + Thu, 16 Sep 2021 18:33:01 GMT Thu, 16 Sep 2021 18:33:01 GMT -- cgit v1.2.3