Commit graph

4 commits

Author SHA1 Message Date
Patrick J Volkerding
06728159b3 Sat Sep 14 18:15:34 UTC 2024
a/mkinitrd-1.4.11-x86_64-36.txz:  Rebuilt.
  setup.01.mkinitrd (aka geninitrd): Set GENINITRD_SILENT to anything to
  generate the initrd silently.
l/iso-codes-4.17.0-noarch-1.txz:  Upgraded.
l/libarchive-3.7.5-x86_64-1.txz:  Upgraded.
  This update fixes the following security issues:
  fix multiple vulnerabilities identified by SAST (#2251, #2256)
  cpio: ignore out-of-range gid/uid/size/ino and harden AFIO parsing (#2258)
  lzop: prevent integer overflow (#2174)
  rar4: protect copy_from_lzss_window_to_unp() (#2172, CVE-2024-20696)
  rar4: fix CVE-2024-26256 (#2269)
  rar4: fix OOB in delta and audio filter (#2148, #2149)
  rar4: fix out of boundary access with large files (#2179)
  rar4: add boundary checks to rgb filter (#2210)
  rar4: fix OOB access with unicode filenames (#2203)
  rar5: clear 'data ready' cache on window buffer reallocs (#2265)
  rpm: calculate huge header sizes correctly (#2158)
  unzip: unify EOF handling (#2175)
  util: fix out of boundary access in mktemp functions (#2160)
  uu: stop processing if lines are too long (#2168)
  For more information, see:
    https://www.cve.org/CVERecord?id=CVE-2024-20696
    https://www.cve.org/CVERecord?id=CVE-2024-26256
  (* Security fix *)
l/python-hatch-vcs-0.4.0-x86_64-1.txz:  Added.
  This is needed to build urllib3-2.2.3.
l/python-idna-3.9-x86_64-1.txz:  Upgraded.
l/python-urllib3-2.2.3-x86_64-1.txz:  Upgraded.
n/bind-9.20.1-x86_64-1.txz:  Upgraded.
xap/xlockmore-5.79-x86_64-1.txz:  Upgraded.
2024-09-14 20:58:45 +02:00
Patrick J Volkerding
ff95264870 Fri Apr 26 20:12:32 UTC 2024
a/kernel-firmware-20240426_fc21f47-noarch-1.txz:  Upgraded.
ap/cups-2.4.7-x86_64-3.txz:  Rebuilt.
  Rebuild using --with-rundir=/run/cups.
ap/cups-browsed-2.0.0-x86_64-1.txz:  Added.
  This is the CUPS/IPP print queue browser daemon, previously part of the
  cups-filters package.
ap/cups-filters-2.0.0-x86_64-1.txz:  Upgraded.
l/libarchive-3.7.4-x86_64-1.txz:  Upgraded.
l/libcupsfilters-2.0.0-x86_64-1.txz:  Added.
  This is required by cups-filters-2.0.0.
l/libppd-2.0.0-x86_64-1.txz:  Added.
  This is required by cups-filters-2.0.0.
l/libproxy-0.5.6-x86_64-1.txz:  Upgraded.
x/wayland-protocols-1.36-noarch-1.txz:  Upgraded.
xap/mozilla-firefox-125.0.2-x86_64-1.txz:  Upgraded.
xap/mozilla-thunderbird-125.0-x86_64-1.txz:  Upgraded.
extra/rust-for-mozilla/rust-1.70.0-x86_64-4.txz:  Removed.
2024-04-26 23:57:49 +02:00
Patrick J Volkerding
c302fc308c Mon Apr 8 18:44:37 UTC 2024
l/imagemagick-7.1.1_30-x86_64-1.txz:  Upgraded.
l/libarchive-3.7.3-x86_64-1.txz:  Upgraded.
  This update fixes a security issue:
  Fix possible vulnerability in tar error reporting introduced in f27c173
  by JiaT75.
  For more information, see:
    f27c173d17
    https://github.com/libarchive/libarchive/pull/2101
  (* Security fix *)
n/net-snmp-5.9.4-x86_64-3.txz:  Rebuilt.
  [PATCH] Add Linux 6.7 compatibility parsing /proc/net/snmp.
  Thanks to walecha.
n/rsync-3.3.0-x86_64-1.txz:  Upgraded.
x/xorg-sgml-doctools-1.12.1-x86_64-1.txz:  Upgraded.
xap/gimp-2.10.36-x86_64-3.txz:  Rebuilt.
  [PATCH] QuitDialog: disconnect signal handler on dialog destroy.
  This fixes a crash on quit.
  Thanks to USUARIONUEVO.
xap/xlockmore-5.77-x86_64-1.txz:  Upgraded.
2024-04-08 21:32:38 +02:00
Patrick J Volkerding
59d1b9557c Mon Jun 17 03:26:28 UTC 2019
Sorry, no new kernel today. ;-)
a/shadow-4.7-x86_64-1.txz:  Upgraded.
a/sysvinit-2.95-x86_64-1.txz:  Upgraded.
l/gmm-5.3-noarch-1.txz:  Upgraded.
l/gobject-introspection-1.60.2-x86_64-1.txz:  Upgraded.
l/libarchive-3.4.0-x86_64-1.txz:  Upgraded.
l/libbluray-1.1.2-x86_64-1.txz:  Upgraded.
l/libical-3.0.5-x86_64-1.txz:  Upgraded.
l/python-certifi-2019.6.16-x86_64-1.txz:  Upgraded.
n/mutt-1.12.1-x86_64-1.txz:  Upgraded.
x/libevdev-1.7.0-x86_64-1.txz:  Upgraded.
2019-06-17 08:59:46 +02:00