Sun Mar 24 18:21:46 UTC 2024

patches/packages/emacs-29.3-x86_64-1_slack15.0.txz:  Upgraded.
  GNU Emacs through 28.2 allows attackers to execute commands via shell
  metacharacters in the name of a source-code file, because lib-src/etags.c
  uses the system C library function in its implementation of the ctags
  program. For example, a victim may use the "ctags *" command (suggested in
  the ctags documentation) in a situation where the current working directory
  has contents that depend on untrusted input.
  For more information, see:
    https://www.cve.org/CVERecord?id=CVE-2022-45939
  (* Security fix *)
This commit is contained in:
Patrick J Volkerding 2024-03-24 18:21:46 +00:00 committed by Eric Hameleers
parent fca48db86c
commit 9543d326f2
7 changed files with 65 additions and 9330 deletions

View file

@ -11,9 +11,29 @@
<description>Tracking Slackware development in git.</description>
<language>en-us</language>
<id xmlns="http://www.w3.org/2005/Atom">urn:uuid:c964f45e-6732-11e8-bbe5-107b4450212f</id>
<pubDate>Sat, 23 Mar 2024 19:34:02 GMT</pubDate>
<lastBuildDate>Sun, 24 Mar 2024 12:30:30 GMT</lastBuildDate>
<pubDate>Sun, 24 Mar 2024 18:21:46 GMT</pubDate>
<lastBuildDate>Mon, 25 Mar 2024 12:30:31 GMT</lastBuildDate>
<generator>maintain_current_git.sh v 1.17</generator>
<item>
<title>Sun, 24 Mar 2024 18:21:46 GMT</title>
<pubDate>Sun, 24 Mar 2024 18:21:46 GMT</pubDate>
<link>https://git.slackware.nl/current/tag/?h=20240324182146</link>
<guid isPermaLink="false">20240324182146</guid>
<description>
<![CDATA[<pre>
patches/packages/emacs-29.3-x86_64-1_slack15.0.txz: Upgraded.
GNU Emacs through 28.2 allows attackers to execute commands via shell
metacharacters in the name of a source-code file, because lib-src/etags.c
uses the system C library function in its implementation of the ctags
program. For example, a victim may use the "ctags *" command (suggested in
the ctags documentation) in a situation where the current working directory
has contents that depend on untrusted input.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2022-45939
(* Security fix *)
</pre>]]>
</description>
</item>
<item>
<title>Sat, 23 Mar 2024 19:34:02 GMT</title>
<pubDate>Sat, 23 Mar 2024 19:34:02 GMT</pubDate>

View file

@ -1,3 +1,15 @@
Sun Mar 24 18:21:46 UTC 2024
patches/packages/emacs-29.3-x86_64-1_slack15.0.txz: Upgraded.
GNU Emacs through 28.2 allows attackers to execute commands via shell
metacharacters in the name of a source-code file, because lib-src/etags.c
uses the system C library function in its implementation of the ctags
program. For example, a victim may use the "ctags *" command (suggested in
the ctags documentation) in a situation where the current working directory
has contents that depend on untrusted input.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2022-45939
(* Security fix *)
+--------------------------+
Sat Mar 23 19:34:02 UTC 2024
patches/packages/mozilla-firefox-115.9.1esr-x86_64-1_slack15.0.txz: Upgraded.
This update fixes a critical security issue:

View file

@ -1,20 +1,20 @@
Sat Mar 23 19:37:37 UTC 2024
Sun Mar 24 18:24:40 UTC 2024
Here is the file list for this directory. If you are using a
mirror site and find missing or extra files in the disk
subdirectories, please have the archive administrator refresh
the mirror.
drwxr-xr-x 12 root root 4096 2024-03-23 19:34 .
drwxr-xr-x 12 root root 4096 2024-03-24 18:21 .
-rw-r--r-- 1 root root 5767 2022-02-02 22:44 ./ANNOUNCE.15.0
-rw-r--r-- 1 root root 16609 2022-03-30 19:03 ./CHANGES_AND_HINTS.TXT
-rw-r--r-- 1 root root 1227749 2024-03-20 21:13 ./CHECKSUMS.md5
-rw-r--r-- 1 root root 195 2024-03-20 21:13 ./CHECKSUMS.md5.asc
-rw-r--r-- 1 root root 1227749 2024-03-23 19:37 ./CHECKSUMS.md5
-rw-r--r-- 1 root root 195 2024-03-23 19:37 ./CHECKSUMS.md5.asc
-rw-r--r-- 1 root root 17976 1994-06-10 02:28 ./COPYING
-rw-r--r-- 1 root root 35147 2007-06-30 04:21 ./COPYING3
-rw-r--r-- 1 root root 19573 2016-06-23 20:08 ./COPYRIGHT.TXT
-rw-r--r-- 1 root root 616 2006-10-02 04:37 ./CRYPTO_NOTICE.TXT
-rw-r--r-- 1 root root 2102437 2024-03-23 19:34 ./ChangeLog.txt
-rw-r--r-- 1 root root 2103082 2024-03-24 18:21 ./ChangeLog.txt
drwxr-xr-x 3 root root 4096 2013-03-20 22:17 ./EFI
drwxr-xr-x 2 root root 4096 2022-02-02 08:21 ./EFI/BOOT
-rw-r--r-- 1 root root 1187840 2021-06-15 19:16 ./EFI/BOOT/bootx64.efi
@ -25,7 +25,7 @@ drwxr-xr-x 2 root root 4096 2022-02-02 08:21 ./EFI/BOOT
-rwxr-xr-x 1 root root 2504 2019-07-05 18:54 ./EFI/BOOT/make-grub.sh
-rw-r--r-- 1 root root 10722 2013-09-21 19:02 ./EFI/BOOT/osdetect.cfg
-rw-r--r-- 1 root root 1273 2013-08-12 21:08 ./EFI/BOOT/tools.cfg
-rw-r--r-- 1 root root 1603988 2024-03-20 21:13 ./FILELIST.TXT
-rw-r--r-- 1 root root 1603988 2024-03-23 19:37 ./FILELIST.TXT
-rw-r--r-- 1 root root 1572 2012-08-29 18:27 ./GPG-KEY
-rw-r--r-- 1 root root 864745 2022-02-02 08:25 ./PACKAGES.TXT
-rw-r--r-- 1 root root 8034 2022-02-02 03:36 ./README.TXT
@ -828,13 +828,13 @@ drwxr-xr-x 2 root root 4096 2022-12-17 19:52 ./pasture/source/samba
-rw-r--r-- 1 root root 7921 2018-04-29 17:31 ./pasture/source/samba/smb.conf.default
-rw-r--r-- 1 root root 7933 2018-01-14 20:41 ./pasture/source/samba/smb.conf.default.orig
-rw-r--r-- 1 root root 536 2017-03-23 19:18 ./pasture/source/samba/smb.conf.diff.gz
drwxr-xr-x 4 root root 4096 2024-03-23 19:37 ./patches
-rw-r--r-- 1 root root 109868 2024-03-23 19:37 ./patches/CHECKSUMS.md5
-rw-r--r-- 1 root root 195 2024-03-23 19:37 ./patches/CHECKSUMS.md5.asc
-rw-r--r-- 1 root root 150038 2024-03-23 19:37 ./patches/FILE_LIST
-rw-r--r-- 1 root root 15301897 2024-03-23 19:37 ./patches/MANIFEST.bz2
-rw-r--r-- 1 root root 77641 2024-03-23 19:37 ./patches/PACKAGES.TXT
drwxr-xr-x 5 root root 32768 2024-03-23 19:37 ./patches/packages
drwxr-xr-x 4 root root 4096 2024-03-24 18:24 ./patches
-rw-r--r-- 1 root root 109769 2024-03-24 18:24 ./patches/CHECKSUMS.md5
-rw-r--r-- 1 root root 195 2024-03-24 18:24 ./patches/CHECKSUMS.md5.asc
-rw-r--r-- 1 root root 149921 2024-03-24 18:24 ./patches/FILE_LIST
-rw-r--r-- 1 root root 15353847 2024-03-24 18:24 ./patches/MANIFEST.bz2
-rw-r--r-- 1 root root 77641 2024-03-24 18:24 ./patches/PACKAGES.TXT
drwxr-xr-x 5 root root 32768 2024-03-24 18:24 ./patches/packages
-rw-r--r-- 1 root root 360 2023-09-26 19:28 ./patches/packages/Cython-0.29.36-x86_64-1_slack15.0.txt
-rw-r--r-- 1 root root 2389564 2023-09-26 19:28 ./patches/packages/Cython-0.29.36-x86_64-1_slack15.0.txz
-rw-r--r-- 1 root root 163 2023-09-26 19:28 ./patches/packages/Cython-0.29.36-x86_64-1_slack15.0.txz.asc
@ -892,9 +892,9 @@ drwxr-xr-x 5 root root 32768 2024-03-23 19:37 ./patches/packages
-rw-r--r-- 1 root root 443 2024-02-14 03:10 ./patches/packages/dnsmasq-2.90-x86_64-1_slack15.0.txt
-rw-r--r-- 1 root root 413640 2024-02-14 03:10 ./patches/packages/dnsmasq-2.90-x86_64-1_slack15.0.txz
-rw-r--r-- 1 root root 163 2024-02-14 03:10 ./patches/packages/dnsmasq-2.90-x86_64-1_slack15.0.txz.asc
-rw-r--r-- 1 root root 481 2022-12-08 18:53 ./patches/packages/emacs-27.2-x86_64-2_slack15.0.txt
-rw-r--r-- 1 root root 39096876 2022-12-08 18:53 ./patches/packages/emacs-27.2-x86_64-2_slack15.0.txz
-rw-r--r-- 1 root root 163 2022-12-08 18:53 ./patches/packages/emacs-27.2-x86_64-2_slack15.0.txz.asc
-rw-r--r-- 1 root root 481 2024-03-24 17:57 ./patches/packages/emacs-29.3-x86_64-1_slack15.0.txt
-rw-r--r-- 1 root root 48104164 2024-03-24 17:57 ./patches/packages/emacs-29.3-x86_64-1_slack15.0.txz
-rw-r--r-- 1 root root 195 2024-03-24 17:57 ./patches/packages/emacs-29.3-x86_64-1_slack15.0.txz.asc
-rw-r--r-- 1 root root 301 2024-03-13 19:23 ./patches/packages/expat-2.6.2-x86_64-1_slack15.0.txt
-rw-r--r-- 1 root root 135556 2024-03-13 19:23 ./patches/packages/expat-2.6.2-x86_64-1_slack15.0.txz
-rw-r--r-- 1 root root 195 2024-03-13 19:23 ./patches/packages/expat-2.6.2-x86_64-1_slack15.0.txz.asc
@ -1213,7 +1213,7 @@ drwxr-xr-x 2 root root 4096 2023-11-21 21:09 ./patches/packages/old-linux
-rw-r--r-- 1 root root 463 2023-04-05 18:16 ./patches/packages/zstd-1.5.5-x86_64-1_slack15.0.txt
-rw-r--r-- 1 root root 459652 2023-04-05 18:16 ./patches/packages/zstd-1.5.5-x86_64-1_slack15.0.txz
-rw-r--r-- 1 root root 163 2023-04-05 18:16 ./patches/packages/zstd-1.5.5-x86_64-1_slack15.0.txz.asc
drwxr-xr-x 110 root root 4096 2024-03-23 19:29 ./patches/source
drwxr-xr-x 110 root root 4096 2024-03-24 18:04 ./patches/source
drwxr-xr-x 2 root root 4096 2023-09-26 19:22 ./patches/source/Cython
-rw-r--r-- 1 root root 1623580 2023-07-04 19:24 ./patches/source/Cython/Cython-0.29.36.tar.lz
-rwxr-xr-x 1 root root 3041 2023-09-26 19:23 ./patches/source/Cython/Cython.SlackBuild
@ -1372,12 +1372,11 @@ drwxr-xr-x 2 root root 4096 2024-02-14 03:01 ./patches/source/dnsmasq
-rw-r--r-- 1 root root 345 2021-04-25 18:48 ./patches/source/dnsmasq/doinst.sh.gz
-rw-r--r-- 1 root root 383 2021-04-25 18:44 ./patches/source/dnsmasq/rc.dnsmasq.gz
-rw-r--r-- 1 root root 898 2018-02-27 06:13 ./patches/source/dnsmasq/slack-desc
drwxr-xr-x 2 root root 4096 2022-12-08 18:47 ./patches/source/emacs
-rw-r--r-- 1 root root 125229 2022-12-08 18:41 ./patches/source/emacs/d48bb4874bc6cd3e69c7a15fc3c91cc141025c51.patch.gz
drwxr-xr-x 2 root root 4096 2024-03-24 17:54 ./patches/source/emacs
-rw-r--r-- 1 root root 312 2008-04-06 03:10 ./patches/source/emacs/doinst.sh.gz
-rw-r--r-- 1 root root 44624480 2021-03-25 11:53 ./patches/source/emacs/emacs-27.2.tar.xz
-rw-r--r-- 1 root root 473 2021-03-25 11:53 ./patches/source/emacs/emacs-27.2.tar.xz.sig
-rwxr-xr-x 1 root root 7566 2022-12-08 18:48 ./patches/source/emacs/emacs.SlackBuild
-rw-r--r-- 1 root root 52203168 2024-03-24 14:02 ./patches/source/emacs/emacs-29.3.tar.xz
-rw-r--r-- 1 root root 833 2024-03-24 14:02 ./patches/source/emacs/emacs-29.3.tar.xz.sig
-rwxr-xr-x 1 root root 7479 2024-03-24 17:54 ./patches/source/emacs/emacs.SlackBuild
-rw-r--r-- 1 root root 559 2021-01-12 18:45 ./patches/source/emacs/slack-desc
drwxr-xr-x 2 root root 4096 2024-03-13 19:23 ./patches/source/expat
-rw-r--r-- 1 root root 483830 2024-03-13 16:55 ./patches/source/expat/expat-2.6.2.tar.lz
@ -2650,8 +2649,8 @@ drwxr-xr-x 2 root root 20480 2022-02-02 08:24 ./slackware64/a
-rw-r--r-- 1 root root 591 2021-12-10 20:45 ./slackware64/a/mcelog-180-x86_64-1.txt
-rw-r--r-- 1 root root 349496 2021-12-10 20:45 ./slackware64/a/mcelog-180-x86_64-1.txz
-rw-r--r-- 1 root root 163 2021-12-10 20:45 ./slackware64/a/mcelog-180-x86_64-1.txz.asc
-rw-r--r-- 1 root root 470 2022-01-02 00:40 ./slackware64/a/mdadm-4.2-x86_64-1.txt
-rw-r--r-- 1 root root 359540 2022-01-02 00:40 ./slackware64/a/mdadm-4.2-x86_64-1.txz
-rw-r--r-- 1 root root 470 2022-01-02 00:40 ./slackware64/a/mdadm-4.2-x86_64-1.txt
-rw-r--r-- 1 root root 359540 2022-01-02 00:40 ./slackware64/a/mdadm-4.2-x86_64-1.txz
-rw-r--r-- 1 root root 163 2022-01-02 00:40 ./slackware64/a/mdadm-4.2-x86_64-1.txz.asc
-rw-r--r-- 1 root root 378 2021-02-13 11:11 ./slackware64/a/minicom-2.8-x86_64-3.txt
-rw-r--r-- 1 root root 313728 2021-02-13 11:11 ./slackware64/a/minicom-2.8-x86_64-3.txz
@ -5400,7 +5399,7 @@ drwxr-xr-x 2 root root 69632 2022-02-02 04:20 ./slackware64/l
-rw-r--r-- 1 root root 163 2021-11-03 00:43 ./slackware64/l/python-random2-1.0.1-x86_64-5.txz.asc
-rw-r--r-- 1 root root 599 2021-11-03 00:43 ./slackware64/l/python-requests-2.26.0-x86_64-3.txt
-rw-r--r-- 1 root root 85912 2021-11-03 00:43 ./slackware64/l/python-requests-2.26.0-x86_64-3.txz
-rw-r--r-- 1 root root 163 2021-11-03 00:43 ./slackware64/l/python-requests-2.26.0-x86_64-3.txz.asc
-rw-r--r-- 1 root root 163 2021-11-03 00:43 ./slackware64/l/python-requests-2.26.0-x86_64-3.txz.asc
-rw-r--r-- 1 root root 328 2021-11-03 00:43 ./slackware64/l/python-sane-2.9.1-x86_64-5.txt
-rw-r--r-- 1 root root 18720 2021-11-03 00:43 ./slackware64/l/python-sane-2.9.1-x86_64-5.txz
-rw-r--r-- 1 root root 163 2021-11-03 00:43 ./slackware64/l/python-sane-2.9.1-x86_64-5.txz.asc
@ -8357,8 +8356,8 @@ drwxr-xr-x 2 root root 4096 2021-11-02 19:02 ./source/a/volume_key
-rw-r--r-- 1 root root 67 2020-10-28 19:01 ./source/a/volume_key/volume_key.url
drwxr-xr-x 2 root root 4096 2021-02-13 05:31 ./source/a/which
-rw-r--r-- 1 root root 1032 2018-02-27 06:13 ./source/a/which/slack-desc
-rw-r--r-- 1 root root 149305 2015-03-20 16:38 ./source/a/which/which-2.21.tar.gz
-rw-r--r-- 1 root root 152 2015-03-20 16:38 ./source/a/which/which-2.21.tar.gz.sig
-rw-r--r-- 1 root root 149305 2015-03-20 16:38 ./source/a/which/which-2.21.tar.gz
-rw-r--r-- 1 root root 152 2015-03-20 16:38 ./source/a/which/which-2.21.tar.gz.sig
-rwxr-xr-x 1 root root 3493 2021-02-13 05:31 ./source/a/which/which.SlackBuild
drwxr-xr-x 2 root root 4096 2021-08-21 18:50 ./source/a/xfsprogs
-rw-r--r-- 1 root root 950 2018-02-27 06:13 ./source/a/xfsprogs/slack-desc
@ -11366,7 +11365,7 @@ drwxr-xr-x 2 root root 4096 2022-01-25 19:26 ./source/kde/kde/src/plasma-e
-rw-r--r-- 1 root root 64968 2022-01-04 10:08 ./source/kde/kde/src/plasma/plasma-thunderbolt-5.23.5.tar.xz
-rw-r--r-- 1 root root 833 2022-01-04 10:08 ./source/kde/kde/src/plasma/plasma-thunderbolt-5.23.5.tar.xz.sig
-rw-r--r-- 1 root root 176288 2022-01-04 10:08 ./source/kde/kde/src/plasma/plasma-vault-5.23.5.tar.xz
-rw-r--r-- 1 root root 833 2022-01-04 10:08 ./source/kde/kde/src/plasma/plasma-vault-5.23.5.tar.xz.sig
-rw-r--r-- 1 root root 833 2022-01-04 10:08 ./source/kde/kde/src/plasma/plasma-vault-5.23.5.tar.xz.sig
-rw-r--r-- 1 root root 9010724 2022-01-04 10:10 ./source/kde/kde/src/plasma/plasma-workspace-5.23.5.tar.xz
-rw-r--r-- 1 root root 833 2022-01-04 10:10 ./source/kde/kde/src/plasma/plasma-workspace-5.23.5.tar.xz.sig
-rw-r--r-- 1 root root 57049508 2022-01-04 10:11 ./source/kde/kde/src/plasma/plasma-workspace-wallpapers-5.23.5.tar.xz
@ -14857,8 +14856,8 @@ drwxr-xr-x 2 root root 4096 2021-02-13 05:32 ./source/x/libXaw3dXft
drwxr-xr-x 2 root root 4096 2021-02-13 05:32 ./source/x/libXcm
-rw-r--r-- 1 root root 262054 2016-12-09 22:32 ./source/x/libXcm/libXcm-0.5.4.tar.lz
-rwxr-xr-x 1 root root 3492 2021-02-13 05:32 ./source/x/libXcm/libXcm.SlackBuild
-rw-r--r-- 1 root root 47 2018-11-11 20:22 ./source/x/libXcm/libXcm.url
-rw-r--r-- 1 root root 766 2018-02-26 22:56 ./source/x/libXcm/slack-desc
-rw-r--r-- 1 root root 47 2018-11-11 20:22 ./source/x/libXcm/libXcm.url
-rw-r--r-- 1 root root 766 2018-02-26 22:56 ./source/x/libXcm/slack-desc
drwxr-xr-x 2 root root 4096 2022-01-03 19:53 ./source/x/libdrm
-rw-r--r-- 1 root root 433708 2021-11-25 20:36 ./source/x/libdrm/libdrm-2.4.109.tar.xz
-rw-r--r-- 1 root root 566 2021-11-25 20:36 ./source/x/libdrm/libdrm-2.4.109.tar.xz.sig

View file

@ -1,6 +1,6 @@
#!/bin/bash
# Copyright 2008, 2009, 2010, 2011, 2012, 2014, 2015, 2017, 2018, 2019, 2020, 2021 Patrick J. Volkerding, Sebeka, MN, USA
# Copyright 2008, 2009, 2010, 2011, 2012, 2014, 2015, 2017, 2018, 2019, 2020, 2021, 2024 Patrick J. Volkerding, Sebeka, MN, USA
# All rights reserved.
#
# Redistribution and use of this script, with or without modification, is
@ -27,7 +27,7 @@
cd $(dirname $0) ; CWD=$(pwd)
PKGNAM=emacs
BUILD=${BUILD:-2_slack15.0}
BUILD=${BUILD:-1_slack15.0}
# Determine version number the tarball is labeled with:
TARBALLVER=${TARBALLVER:-$(echo $PKGNAM-*.tar.xz | rev | cut -f 3- -d . | cut -f 1 -d - | rev)}
# OK, now what's being used as the source directory version number... account
@ -88,8 +88,6 @@ rm -rf $PKGNAM-$TARBALLVER
tar xvf $CWD/$PKGNAM-$TARBALLVER.tar.xz || exit 1
cd $PKGNAM-$SRCDIRVER || exit 1
zcat $CWD/d48bb4874bc6cd3e69c7a15fc3c91cc141025c51.patch.gz | patch -p1 --verbose || exit 1
chown -R root:root .
find . \
\( -perm 777 -o -perm 775 -o -perm 711 -o -perm 555 -o -perm 511 \) \

View file

@ -1303,7 +1303,6 @@ gzip ./patches/source/sdl/libsdl-1.2.15-resizing.patch
gzip ./patches/source/postfix/postfix.script.starting.message.diff
gzip ./patches/source/postfix/postfix.only.warn.regular.files.diff
gzip ./patches/source/postfix/doinst.sh
gzip ./patches/source/emacs/d48bb4874bc6cd3e69c7a15fc3c91cc141025c51.patch
gzip ./patches/source/emacs/doinst.sh
gzip ./patches/source/xorg-server/patch/xorg-server/CVE-2022-46342.patch
gzip ./patches/source/xorg-server/patch/xorg-server/CVE-2023-5380.patch