Commit graph

3 commits

Author SHA1 Message Date
Patrick J Volkerding
48a597699d Sun Dec 10 01:12:17 UTC 2023
l/libxml2-2.12.2-x86_64-2.txz:  Rebuilt.
  Add --sysconfdir=/etc option so that this can find the xml catalog.
  Thanks to SpiderTux.
  Fix the following security issues:
  Fix integer overflows with XML_PARSE_HUGE.
  Fix dict corruption caused by entity reference cycles.
  Hashing of empty dict strings isn't deterministic.
  Fix null deref in xmlSchemaFixupComplexType.
  For more information, see:
    https://www.cve.org/CVERecord?id=CVE-2022-40303
    https://www.cve.org/CVERecord?id=CVE-2022-40304
    https://www.cve.org/CVERecord?id=CVE-2023-29469
    https://www.cve.org/CVERecord?id=CVE-2023-28484
  (* Security fix *)
2023-12-10 02:58:55 +01:00
Patrick J Volkerding
29cb9e3b02 Tue Mar 1 05:05:48 UTC 2022
a/dbus-1.12.22-x86_64-1.txz:  Upgraded.
a/kernel-firmware-20220228_ee0667a-noarch-1.txz:  Upgraded.
ap/sysstat-12.5.6-x86_64-1.txz:  Upgraded.
d/ccache-4.6-x86_64-1.txz:  Upgraded.
d/rcs-5.10.1-x86_64-1.txz:  Upgraded.
l/libjpeg-turbo-2.1.3-x86_64-1.txz:  Upgraded.
l/libxml2-2.9.13-x86_64-1.txz:  Upgraded.
  This update fixes bugs and the following security issues:
  Use-after-free of ID and IDREF attributes
  (Thanks to Shinji Sato for the report)
  Use-after-free in xmlXIncludeCopyRange (David Kilzer)
  Fix Null-deref-in-xmlSchemaGetComponentTargetNs (huangduirong)
  Fix memory leak in xmlXPathCompNodeTest
  Fix null pointer deref in xmlStringGetNodeList
  Fix several memory leaks found by Coverity (David King)
  For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23308
  (* Security fix *)
l/libxslt-1.1.35-x86_64-1.txz:  Upgraded.
  This update fixes bugs and the following security issues:
  Fix use-after-free in xsltApplyTemplates
  Fix memory leak in xsltDocumentElem (David King)
  Fix memory leak in xsltCompileIdKeyPattern (David King)
  Fix double-free with stylesheets containing entity nodes
  For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30560
  (* Security fix *)
n/wget-1.21.3-x86_64-1.txz:  Upgraded.
x/xterm-371-x86_64-1.txz:  Upgraded.
xap/xscreensaver-6.03-x86_64-1.txz:  Upgraded.
2022-03-01 06:59:47 +01:00
Patrick J Volkerding
8160de57c4 Thu Oct 31 21:31:50 UTC 2019
a/kernel-firmware-20191030_9e194c7-noarch-1.txz:  Upgraded.
d/cmake-3.15.5-x86_64-1.txz:  Upgraded.
l/imagemagick-6.9.10_71-x86_64-1.txz:  Upgraded.
l/libxml2-2.9.10-x86_64-1.txz:  Upgraded.
l/libxslt-1.1.34-x86_64-1.txz:  Upgraded.
n/bluez-5.52-x86_64-1.txz:  Upgraded.
xap/mozilla-thunderbird-68.2.1-x86_64-1.txz:  Upgraded.
  This is a bugfix release.
  For more information, see:
    https://www.mozilla.org/en-US/thunderbird/68.2.1/releasenotes/
  Added option: --disable-updater
2019-11-01 08:59:50 +01:00