Commit graph

3 commits

Author SHA1 Message Date
Patrick J Volkerding
b42f821834 Fri Feb 12 21:42:42 UTC 2021
a/inih-53-x86_64-1.txz:  Upgraded.
a/kernel-firmware-20210211_f7915a0-noarch-1.txz:  Upgraded.
a/util-linux-2.36.2-x86_64-1.txz:  Upgraded.
d/binutils-2.36.1-x86_64-1.txz:  Upgraded.
d/oprofile-1.4.0-x86_64-6.txz:  Rebuilt.
  Recompiled against binutils-2.36.1.
kde/digikam-7.1.0-x86_64-4.txz:  Rebuilt.
  Recompiled against imagemagick-7.0.10_62.
l/glib2-2.66.7-x86_64-1.txz:  Upgraded.
l/openexr-2.5.5-x86_64-1.txz:  Upgraded.
2021-02-13 08:59:53 +01:00
Patrick J Volkerding
2c78f43e26 Sat Jan 30 21:55:04 UTC 2021
a/e2fsprogs-1.46.0-x86_64-1.txz:  Upgraded.
a/kernel-generic-5.10.12-x86_64-1.txz:  Upgraded.
a/kernel-huge-5.10.12-x86_64-1.txz:  Upgraded.
a/kernel-modules-5.10.12-x86_64-1.txz:  Upgraded.
a/sysklogd-2.2.1-x86_64-1.txz:  Upgraded.
d/binutils-2.35.2-x86_64-1.txz:  Upgraded.
  We're probably better off with this branch for now.
d/kernel-headers-5.10.12-x86-1.txz:  Upgraded.
d/oprofile-1.4.0-x86_64-5.txz:  Rebuilt.
  Recompiled against binutils-2.35.2.
k/kernel-source-5.10.12-noarch-1.txz:  Upgraded.
l/gd-2.3.1-x86_64-1.txz:  Upgraded.
l/libwebp-1.2.0-x86_64-1.txz:  Upgraded.
l/python-packaging-20.9-x86_64-1.txz:  Upgraded.
x/fcitx-libpinyin-0.5.4-x86_64-1.txz:  Upgraded.
isolinux/initrd.img:  Rebuilt.
kernels/*:  Upgraded.
usb-and-pxe-installers/usbboot.img:  Rebuilt.
2021-01-31 08:59:50 +01:00
Patrick J Volkerding
e833eebc98 Tue Jan 26 21:20:58 UTC 2021
ap/sudo-1.9.5p2-x86_64-1.txz:  Upgraded.
  When invoked as sudoedit, the same set of command line options
  are now accepted as for "sudo -e". The -H and -P options are
  now rejected for sudoedit and "sudo -e" which matches the sudo
  1.7 behavior. This is part of the fix for CVE-2021-3156.
  Fixed a potential buffer overflow when unescaping backslashes
  in the command's arguments. Normally, sudo escapes special
  characters when running a command via a shell (sudo -s or sudo
  -i). However, it was also possible to run sudoedit with the -s
  or -i flags in which case no escaping had actually been done,
  making a buffer overflow possible. This fixes CVE-2021-3156.
  For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3156
  (* Security fix *)
d/binutils-2.36-x86_64-2.txz:  Rebuilt.
  Revert commit d1bcae833b32f1408485ce69f844dcd7ded093a8:
  [PATCH] ELF: Don't generate unused section symbols
  This fixes building the kernel.
l/loudmouth-1.5.4-x86_64-1.txz:  Upgraded.
n/autofs-5.1.7-x86_64-1.txz:  Upgraded.
n/dnsmasq-2.84-x86_64-1.txz:  Upgraded.
n/tin-2.4.5-x86_64-1.txz:  Upgraded.
xap/gparted-1.2.0-x86_64-1.txz:  Upgraded.
xap/mozilla-thunderbird-78.7.0-x86_64-1.txz:  Upgraded.
  This release contains security fixes and improvements.
  For more information, see:
    https://www.mozilla.org/en-US/thunderbird/78.7.0/releasenotes/
    https://www.mozilla.org/en-US/security/advisories/mfsa2021-05/
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23953
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23954
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15685
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26976
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23960
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23964
  (* Security fix *)
2021-01-27 14:59:56 +01:00