Wed Oct 9 21:09:16 UTC 2024

patches/packages/mozilla-firefox-115.16.1esr-x86_64-1_slack15.0.txz:  Upgraded.
  This update contains a critical security fix:
  Use-after-free in Animation timeline.
  "An attacker was able to achieve code execution in the content process by
  exploiting a use-after-free in Animation timelines. We have had reports of
  this vulnerability being exploited in the wild."
  For more information, see:
    https://www.mozilla.org/en-US/firefox/115.16.1/releasenotes/
    https://www.mozilla.org/security/advisories/mfsa2024-51/
    https://www.cve.org/CVERecord?id=CVE-2024-9680
  (* Security fix *)
This commit is contained in:
Patrick J Volkerding 2024-10-09 21:09:16 +00:00 committed by Eric Hameleers
parent 4657194ae3
commit c29a1ed636
5 changed files with 73 additions and 40 deletions

View file

@ -11,9 +11,30 @@
<description>Tracking Slackware development in git.</description>
<language>en-us</language>
<id xmlns="http://www.w3.org/2005/Atom">urn:uuid:c964f45e-6732-11e8-bbe5-107b4450212f</id>
<pubDate>Tue, 1 Oct 2024 18:01:38 GMT</pubDate>
<lastBuildDate>Wed, 2 Oct 2024 11:30:23 GMT</lastBuildDate>
<pubDate>Wed, 9 Oct 2024 21:09:16 GMT</pubDate>
<lastBuildDate>Thu, 10 Oct 2024 11:30:38 GMT</lastBuildDate>
<generator>maintain_current_git.sh v 1.17</generator>
<item>
<title>Wed, 9 Oct 2024 21:09:16 GMT</title>
<pubDate>Wed, 9 Oct 2024 21:09:16 GMT</pubDate>
<link>https://git.slackware.nl/current/tag/?h=20241009210916</link>
<guid isPermaLink="false">20241009210916</guid>
<description>
<![CDATA[<pre>
patches/packages/mozilla-firefox-115.16.1esr-x86_64-1_slack15.0.txz: Upgraded.
This update contains a critical security fix:
Use-after-free in Animation timeline.
"An attacker was able to achieve code execution in the content process by
exploiting a use-after-free in Animation timelines. We have had reports of
this vulnerability being exploited in the wild."
For more information, see:
https://www.mozilla.org/en-US/firefox/115.16.1/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2024-51/
https://www.cve.org/CVERecord?id=CVE-2024-9680
(* Security fix *)
</pre>]]>
</description>
</item>
<item>
<title>Tue, 1 Oct 2024 18:01:38 GMT</title>
<pubDate>Tue, 1 Oct 2024 18:01:38 GMT</pubDate>

View file

@ -1,3 +1,16 @@
Wed Oct 9 21:09:16 UTC 2024
patches/packages/mozilla-firefox-115.16.1esr-x86_64-1_slack15.0.txz: Upgraded.
This update contains a critical security fix:
Use-after-free in Animation timeline.
"An attacker was able to achieve code execution in the content process by
exploiting a use-after-free in Animation timelines. We have had reports of
this vulnerability being exploited in the wild."
For more information, see:
https://www.mozilla.org/en-US/firefox/115.16.1/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2024-51/
https://www.cve.org/CVERecord?id=CVE-2024-9680
(* Security fix *)
+--------------------------+
Tue Oct 1 18:01:38 UTC 2024
Several ELF objects were found to have rpaths pointing into /tmp, a world
writable directory. This could have allowed a local attacker to launch denial

View file

@ -1,20 +1,20 @@
Tue Oct 1 18:12:46 UTC 2024
Wed Oct 9 21:12:42 UTC 2024
Here is the file list for this directory. If you are using a
mirror site and find missing or extra files in the disk
subdirectories, please have the archive administrator refresh
the mirror.
drwxr-xr-x 12 root root 4096 2024-10-01 18:01 .
drwxr-xr-x 12 root root 4096 2024-10-09 21:09 .
-rw-r--r-- 1 root root 5767 2022-02-02 22:44 ./ANNOUNCE.15.0
-rw-r--r-- 1 root root 16609 2022-03-30 19:03 ./CHANGES_AND_HINTS.TXT
-rw-r--r-- 1 root root 1258796 2024-09-27 21:14 ./CHECKSUMS.md5
-rw-r--r-- 1 root root 195 2024-09-27 21:14 ./CHECKSUMS.md5.asc
-rw-r--r-- 1 root root 1263299 2024-10-03 18:35 ./CHECKSUMS.md5
-rw-r--r-- 1 root root 195 2024-10-03 18:35 ./CHECKSUMS.md5.asc
-rw-r--r-- 1 root root 17976 1994-06-10 02:28 ./COPYING
-rw-r--r-- 1 root root 35147 2007-06-30 04:21 ./COPYING3
-rw-r--r-- 1 root root 19573 2016-06-23 20:08 ./COPYRIGHT.TXT
-rw-r--r-- 1 root root 616 2006-10-02 04:37 ./CRYPTO_NOTICE.TXT
-rw-r--r-- 1 root root 2164209 2024-10-01 18:07 ./ChangeLog.txt
-rw-r--r-- 1 root root 2164866 2024-10-09 21:09 ./ChangeLog.txt
drwxr-xr-x 3 root root 4096 2013-03-20 22:17 ./EFI
drwxr-xr-x 2 root root 4096 2022-02-02 08:21 ./EFI/BOOT
-rw-r--r-- 1 root root 1187840 2021-06-15 19:16 ./EFI/BOOT/bootx64.efi
@ -25,7 +25,7 @@ drwxr-xr-x 2 root root 4096 2022-02-02 08:21 ./EFI/BOOT
-rwxr-xr-x 1 root root 2504 2019-07-05 18:54 ./EFI/BOOT/make-grub.sh
-rw-r--r-- 1 root root 10722 2013-09-21 19:02 ./EFI/BOOT/osdetect.cfg
-rw-r--r-- 1 root root 1273 2013-08-12 21:08 ./EFI/BOOT/tools.cfg
-rw-r--r-- 1 root root 1649874 2024-09-27 21:14 ./FILELIST.TXT
-rw-r--r-- 1 root root 1655758 2024-10-03 18:35 ./FILELIST.TXT
-rw-r--r-- 1 root root 1572 2012-08-29 18:27 ./GPG-KEY
-rw-r--r-- 1 root root 864745 2022-02-02 08:25 ./PACKAGES.TXT
-rw-r--r-- 1 root root 8034 2022-02-02 03:36 ./README.TXT
@ -39,12 +39,12 @@ drwxr-xr-x 2 root root 4096 2022-02-02 08:21 ./EFI/BOOT
-rw-r--r-- 1 root root 17294 2008-12-08 18:13 ./SPEAK_INSTALL.TXT
-rw-r--r-- 1 root root 57187 2022-02-01 19:37 ./Slackware-HOWTO
-rw-r--r-- 1 root root 8700 2022-01-26 05:44 ./UPGRADE.TXT
drwxr-xr-x 19 root root 4096 2024-10-01 18:12 ./extra
-rw-r--r-- 1 root root 56343 2024-10-01 18:12 ./extra/CHECKSUMS.md5
-rw-r--r-- 1 root root 195 2024-10-01 18:12 ./extra/CHECKSUMS.md5.asc
-rw-r--r-- 1 root root 70733 2024-10-01 18:12 ./extra/FILE_LIST
-rw-r--r-- 1 root root 3055089 2024-10-01 18:12 ./extra/MANIFEST.bz2
-rw-r--r-- 1 root root 37488 2024-10-01 18:12 ./extra/PACKAGES.TXT
drwxr-xr-x 19 root root 4096 2024-10-03 18:35 ./extra
-rw-r--r-- 1 root root 56343 2024-10-03 18:35 ./extra/CHECKSUMS.md5
-rw-r--r-- 1 root root 195 2024-10-03 18:35 ./extra/CHECKSUMS.md5.asc
-rw-r--r-- 1 root root 70733 2024-10-03 18:35 ./extra/FILE_LIST
-rw-r--r-- 1 root root 3058335 2024-10-03 18:35 ./extra/MANIFEST.bz2
-rw-r--r-- 1 root root 37488 2024-10-03 18:35 ./extra/PACKAGES.TXT
-rw-r--r-- 1 root root 149 2002-02-09 00:18 ./extra/README.TXT
drwxr-xr-x 2 root root 20480 2020-05-26 20:38 ./extra/aspell-word-lists
-rw-r--r-- 1 root root 171 2016-06-06 20:10 ./extra/aspell-word-lists/aspell-af-0.50_0-x86_64-5.txt
@ -597,7 +597,7 @@ drwxr-xr-x 3 root root 4096 2024-02-17 19:12 ./extra/source/llvm
-rw-r--r-- 1 root root 281 2022-06-28 03:34 ./extra/source/llvm/lldb.32-bit.link.libatomic.diff.gz
-rw-r--r-- 1 root root 59298244 2023-11-28 10:33 ./extra/source/llvm/llvm-17.0.6.src.tar.xz
-rw-r--r-- 1 root root 438 2023-11-28 10:33 ./extra/source/llvm/llvm-17.0.6.src.tar.xz.sig
-rwxr-xr-x 1 root root 13286 2024-09-29 16:39 ./extra/source/llvm/llvm.SlackBuild
-rwxr-xr-x 1 root root 13274 2024-10-02 21:29 ./extra/source/llvm/llvm.SlackBuild
-rw-r--r-- 1 root root 2175 2023-11-28 19:24 ./extra/source/llvm/llvm.url
drwxr-xr-x 2 root root 4096 2023-03-19 05:00 ./extra/source/llvm/missing-runtime-modules
-rw-r--r-- 1 root root 4005 2023-02-21 06:00 ./extra/source/llvm/missing-runtime-modules/HandleFlags.cmake
@ -832,13 +832,13 @@ drwxr-xr-x 2 root root 4096 2022-12-17 19:52 ./pasture/source/samba
-rw-r--r-- 1 root root 7921 2018-04-29 17:31 ./pasture/source/samba/smb.conf.default
-rw-r--r-- 1 root root 7933 2018-01-14 20:41 ./pasture/source/samba/smb.conf.default.orig
-rw-r--r-- 1 root root 536 2017-03-23 19:18 ./pasture/source/samba/smb.conf.diff.gz
drwxr-xr-x 4 root root 4096 2024-10-01 18:12 ./patches
-rw-r--r-- 1 root root 141044 2024-10-01 18:12 ./patches/CHECKSUMS.md5
-rw-r--r-- 1 root root 195 2024-10-01 18:12 ./patches/CHECKSUMS.md5.asc
-rw-r--r-- 1 root root 194490 2024-10-01 18:12 ./patches/FILE_LIST
-rw-r--r-- 1 root root 18271417 2024-10-01 18:12 ./patches/MANIFEST.bz2
-rw-r--r-- 1 root root 99128 2024-10-01 18:12 ./patches/PACKAGES.TXT
drwxr-xr-x 7 root root 32768 2024-10-01 18:12 ./patches/packages
drwxr-xr-x 4 root root 4096 2024-10-09 21:12 ./patches
-rw-r--r-- 1 root root 141044 2024-10-09 21:12 ./patches/CHECKSUMS.md5
-rw-r--r-- 1 root root 195 2024-10-09 21:12 ./patches/CHECKSUMS.md5.asc
-rw-r--r-- 1 root root 194490 2024-10-09 21:12 ./patches/FILE_LIST
-rw-r--r-- 1 root root 18267090 2024-10-09 21:12 ./patches/MANIFEST.bz2
-rw-r--r-- 1 root root 99128 2024-10-09 21:12 ./patches/PACKAGES.TXT
drwxr-xr-x 7 root root 32768 2024-10-09 21:12 ./patches/packages
-rw-r--r-- 1 root root 360 2023-09-26 19:28 ./patches/packages/Cython-0.29.36-x86_64-1_slack15.0.txt
-rw-r--r-- 1 root root 2389564 2023-09-26 19:28 ./patches/packages/Cython-0.29.36-x86_64-1_slack15.0.txz
-rw-r--r-- 1 root root 163 2023-09-26 19:28 ./patches/packages/Cython-0.29.36-x86_64-1_slack15.0.txz.asc
@ -1074,9 +1074,9 @@ drwxr-xr-x 2 root root 4096 2024-06-16 21:36 ./patches/packages/linux-5.1
-rw-r--r-- 1 root root 512 2024-09-30 18:09 ./patches/packages/mlt-7.4.0-x86_64-2_slack15.0.txt
-rw-r--r-- 1 root root 658260 2024-09-30 18:09 ./patches/packages/mlt-7.4.0-x86_64-2_slack15.0.txz
-rw-r--r-- 1 root root 195 2024-09-30 18:09 ./patches/packages/mlt-7.4.0-x86_64-2_slack15.0.txz.asc
-rw-r--r-- 1 root root 570 2024-10-01 03:16 ./patches/packages/mozilla-firefox-115.16.0esr-x86_64-1_slack15.0.txt
-rw-r--r-- 1 root root 61481332 2024-10-01 03:16 ./patches/packages/mozilla-firefox-115.16.0esr-x86_64-1_slack15.0.txz
-rw-r--r-- 1 root root 195 2024-10-01 03:16 ./patches/packages/mozilla-firefox-115.16.0esr-x86_64-1_slack15.0.txz.asc
-rw-r--r-- 1 root root 570 2024-10-09 18:28 ./patches/packages/mozilla-firefox-115.16.1esr-x86_64-1_slack15.0.txt
-rw-r--r-- 1 root root 61491080 2024-10-09 18:28 ./patches/packages/mozilla-firefox-115.16.1esr-x86_64-1_slack15.0.txz
-rw-r--r-- 1 root root 195 2024-10-09 18:28 ./patches/packages/mozilla-firefox-115.16.1esr-x86_64-1_slack15.0.txz.asc
-rw-r--r-- 1 root root 564 2023-01-06 19:37 ./patches/packages/mozilla-nss-3.87-x86_64-1_slack15.0.txt
-rw-r--r-- 1 root root 1838968 2023-01-06 19:37 ./patches/packages/mozilla-nss-3.87-x86_64-1_slack15.0.txz
-rw-r--r-- 1 root root 163 2023-01-06 19:37 ./patches/packages/mozilla-nss-3.87-x86_64-1_slack15.0.txz.asc
@ -1324,7 +1324,7 @@ drwxr-xr-x 2 root root 4096 2024-06-08 19:45 ./patches/packages/old-linux
-rw-r--r-- 1 root root 463 2023-04-05 18:16 ./patches/packages/zstd-1.5.5-x86_64-1_slack15.0.txt
-rw-r--r-- 1 root root 459652 2023-04-05 18:16 ./patches/packages/zstd-1.5.5-x86_64-1_slack15.0.txz
-rw-r--r-- 1 root root 163 2023-04-05 18:16 ./patches/packages/zstd-1.5.5-x86_64-1_slack15.0.txz.asc
drwxr-xr-x 134 root root 4096 2024-10-01 16:59 ./patches/source
drwxr-xr-x 134 root root 4096 2024-10-09 20:58 ./patches/source
drwxr-xr-x 2 root root 4096 2023-09-26 19:22 ./patches/source/Cython
-rw-r--r-- 1 root root 1623580 2023-07-04 19:24 ./patches/source/Cython/Cython-0.29.36.tar.lz
-rwxr-xr-x 1 root root 3041 2023-09-26 19:23 ./patches/source/Cython/Cython.SlackBuild
@ -1962,7 +1962,7 @@ drwxr-xr-x 2 root root 4096 2021-12-26 19:18 ./patches/source/mlt
-rw-r--r-- 1 root root 35 2019-02-10 13:42 ./patches/source/mlt/mlt.deps
-rw-r--r-- 1 root root 36 2020-09-29 01:18 ./patches/source/mlt/mlt.url
-rw-r--r-- 1 root root 963 2020-11-01 20:04 ./patches/source/mlt/slack-desc
drwxr-xr-x 3 root root 4096 2024-10-01 02:28 ./patches/source/mozilla-firefox
drwxr-xr-x 3 root root 4096 2024-10-09 17:42 ./patches/source/mozilla-firefox
-rw-r--r-- 1 root root 693 2021-03-22 17:58 ./patches/source/mozilla-firefox/0027-LTO-Only-enable-LTO-for-Rust-when-complete-build-use.patch.gz
drwxr-xr-x 5 root root 4096 2021-08-13 18:36 ./patches/source/mozilla-firefox/build-deps
-rwxr-xr-x 1 root root 2003 2023-07-23 19:20 ./patches/source/mozilla-firefox/build-deps.sh
@ -1974,14 +1974,14 @@ drwxr-xr-x 2 root root 4096 2023-09-13 18:47 ./patches/source/mozilla-fir
-rw-r--r-- 1 root root 163871 2023-09-13 09:14 ./patches/source/mozilla-firefox/build-deps/cbindgen/cbindgen-0.26.0.tar.lz
-rwxr-xr-x 1 root root 2032 2022-06-14 16:39 ./patches/source/mozilla-firefox/build-deps/cbindgen/cbindgen.build
-rw-r--r-- 1 root root 35 2021-06-25 03:11 ./patches/source/mozilla-firefox/build-deps/cbindgen/cbindgen.url
drwxr-xr-x 2 root root 4096 2024-08-21 20:20 ./patches/source/mozilla-firefox/build-deps/nodejs
-rw-r--r-- 1 root root 41751520 2024-08-21 12:46 ./patches/source/mozilla-firefox/build-deps/nodejs/node-v20.17.0.tar.xz
drwxr-xr-x 2 root root 4096 2024-10-04 18:21 ./patches/source/mozilla-firefox/build-deps/nodejs
-rw-r--r-- 1 root root 41937144 2024-10-03 09:27 ./patches/source/mozilla-firefox/build-deps/nodejs/node-v20.18.0.tar.xz
-rwxr-xr-x 1 root root 3003 2022-08-10 17:53 ./patches/source/mozilla-firefox/build-deps/nodejs/nodejs.build
-rw-r--r-- 1 root root 86 2019-07-08 21:02 ./patches/source/mozilla-firefox/build-deps/nodejs/nodejs.url
-rwxr-xr-x 1 root root 840 2018-03-13 12:55 ./patches/source/mozilla-firefox/fetch-and-repack.sh
-rw-r--r-- 1 root root 330 2019-07-08 18:41 ./patches/source/mozilla-firefox/ff.ui.scrollToClick.diff.gz
-rw-r--r-- 1 root root 515133700 2024-09-30 12:55 ./patches/source/mozilla-firefox/firefox-115.16.0esr.source.tar.xz
-rw-r--r-- 1 root root 833 2024-09-30 12:55 ./patches/source/mozilla-firefox/firefox-115.16.0esr.source.tar.xz.asc
-rw-r--r-- 1 root root 514949380 2024-10-09 11:20 ./patches/source/mozilla-firefox/firefox-115.16.1esr.source.tar.xz
-rw-r--r-- 1 root root 833 2024-10-09 11:20 ./patches/source/mozilla-firefox/firefox-115.16.1esr.source.tar.xz.asc
-rw-r--r-- 1 root root 2748 2017-12-04 21:30 ./patches/source/mozilla-firefox/firefox.desktop
-rw-r--r-- 1 root root 327 2008-06-17 17:19 ./patches/source/mozilla-firefox/firefox.moz_plugin_path.diff.gz
-rw-r--r-- 1 root root 518 2021-03-15 17:43 ./patches/source/mozilla-firefox/gkrust.a.no.networking.check.diff.gz
@ -17295,12 +17295,12 @@ drwxr-xr-x 2 root root 4096 2021-02-13 05:32 ./source/y/nethack
-rwxr-xr-x 1 root root 4998 2021-02-13 05:32 ./source/y/nethack/nethack.SlackBuild
-rw-r--r-- 1 root root 59 2020-12-30 20:25 ./source/y/nethack/nethack.url
-rw-r--r-- 1 root root 1031 2020-12-30 21:50 ./source/y/nethack/slack-desc
drwxr-xr-x 4 root root 4096 2024-10-01 18:12 ./testing
-rw-r--r-- 1 root root 3188 2024-10-01 18:12 ./testing/CHECKSUMS.md5
-rw-r--r-- 1 root root 195 2024-10-01 18:12 ./testing/CHECKSUMS.md5.asc
-rw-r--r-- 1 root root 4185 2024-10-01 18:12 ./testing/FILE_LIST
-rw-r--r-- 1 root root 3495172 2024-10-01 18:12 ./testing/MANIFEST.bz2
-rw-r--r-- 1 root root 1859 2024-10-01 18:12 ./testing/PACKAGES.TXT
drwxr-xr-x 4 root root 4096 2024-10-03 18:35 ./testing
-rw-r--r-- 1 root root 3188 2024-10-03 18:35 ./testing/CHECKSUMS.md5
-rw-r--r-- 1 root root 195 2024-10-03 18:35 ./testing/CHECKSUMS.md5.asc
-rw-r--r-- 1 root root 4185 2024-10-03 18:35 ./testing/FILE_LIST
-rw-r--r-- 1 root root 3495513 2024-10-03 18:35 ./testing/MANIFEST.bz2
-rw-r--r-- 1 root root 1859 2024-10-03 18:35 ./testing/PACKAGES.TXT
drwxr-xr-x 2 root root 4096 2024-10-01 18:12 ./testing/packages
-rw-r--r-- 1 root root 346 2024-09-29 03:56 ./testing/packages/llvm-18.1.8-x86_64-2_slack15.0.txt
-rw-r--r-- 1 root root 243229488 2024-09-29 03:56 ./testing/packages/llvm-18.1.8-x86_64-2_slack15.0.txz
@ -17323,7 +17323,7 @@ drwxr-xr-x 2 root root 4096 2022-02-02 06:50 ./testing/source/linux-5.16.5
drwxr-xr-x 2 root root 4096 2024-07-19 18:38 ./testing/source/llvm
-rw-r--r-- 1 root root 275 2024-03-06 20:03 ./testing/source/llvm/clang.toolchains.32-bit.triple.diff.gz
-rwxr-xr-x 1 root root 4278 2024-08-10 17:15 ./testing/source/llvm/libclc.SlackBuild
-rwxr-xr-x 1 root root 8100 2024-09-29 00:23 ./testing/source/llvm/llvm.SlackBuild
-rwxr-xr-x 1 root root 8088 2024-10-02 21:28 ./testing/source/llvm/llvm.SlackBuild
-rw-r--r-- 1 root root 77 2024-06-20 02:16 ./testing/source/llvm/llvm.url
-rw-r--r-- 1 root root 122282653 2024-06-15 17:21 ./testing/source/llvm/llvmorg-18.1.8.tar.lz
-rw-r--r-- 1 root root 830 2019-07-25 03:31 ./testing/source/llvm/slack-desc

View file

@ -227,7 +227,6 @@ cd build
-DCMAKE_C_FLAGS:STRING="$SLKCFLAGS" \
-DCMAKE_CXX_FLAGS:STRING="$SLKCFLAGS" \
-DCMAKE_INSTALL_PREFIX=/usr \
-DCMAKE_SKIP_RPATH=ON \
-DLLVM_LIBDIR_SUFFIX=${LIBDIRSUFFIX} \
-DLIBCXX_LIBDIR_SUFFIX=${LIBDIRSUFFIX} \
-DLIBCXXABI_LIBDIR_SUFFIX=${LIBDIRSUFFIX} \
@ -337,4 +336,4 @@ mkdir -p $PKG/install
cat $CWD/slack-desc > $PKG/install/slack-desc
cd $PKG
/sbin/makepkg -l y -c n $TMP/$PKGNAM-$VERSION-$ARCH-$BUILD.txz
/sbin/makepkg -l y -c n --remove-rpaths $TMP/$PKGNAM-$VERSION-$ARCH-$BUILD.txz