Commit graph

2 commits

Author SHA1 Message Date
Patrick J Volkerding
ddd9fe141f Sat Dec 17 21:14:11 UTC 2022
a/xz-5.4.0-x86_64-1.txz:  Upgraded.
l/harfbuzz-6.0.0-x86_64-1.txz:  Upgraded.
l/libmpc-1.3.1-x86_64-1.txz:  Upgraded.
n/NetworkManager-1.40.8-x86_64-1.txz:  Upgraded.
n/samba-4.17.4-x86_64-1.txz:  Upgraded.
  This update fixes security issues:
  This is the Samba CVE for the Windows Kerberos RC4-HMAC Elevation of
  Privilege Vulnerability disclosed by Microsoft on Nov 8 2022.
  A Samba Active Directory DC will issue weak rc4-hmac session keys for
  use between modern clients and servers despite all modern Kerberos
  implementations supporting the aes256-cts-hmac-sha1-96 cipher.
  On Samba Active Directory DCs and members
  'kerberos encryption types = legacy'
  would force rc4-hmac as a client even if the server supports
  aes128-cts-hmac-sha1-96 and/or aes256-cts-hmac-sha1-96.
  This is the Samba CVE for the Windows Kerberos Elevation of Privilege
  Vulnerability disclosed by Microsoft on Nov 8 2022.
  A service account with the special constrained delegation permission
  could forge a more powerful ticket than the one it was presented with.
  The "RC4" protection of the NetLogon Secure channel uses the same
  algorithms as rc4-hmac cryptography in Kerberos, and so must also be
  assumed to be weak.
  Note that there are several important behavior changes included in this
  release, which may cause compatibility problems interacting with system
  still expecting the former behavior.
  Please read the advisories of CVE-2022-37966, CVE-2022-37967 and
  CVE-2022-38023 carefully!
  For more information, see:
    https://www.samba.org/samba/security/CVE-2022-37966.html
    https://www.samba.org/samba/security/CVE-2022-37967.html
    https://www.samba.org/samba/security/CVE-2022-38023.html
    https://www.cve.org/CVERecord?id=CVE-2022-37966
    https://www.cve.org/CVERecord?id=CVE-2022-37967
    https://www.cve.org/CVERecord?id=CVE-2022-38023
  (* Security fix *)
xfce/exo-4.18.0-x86_64-1.txz:  Upgraded.
xfce/garcon-4.18.0-x86_64-1.txz:  Upgraded.
xfce/libxfce4ui-4.18.0-x86_64-1.txz:  Upgraded.
xfce/libxfce4util-4.18.0-x86_64-1.txz:  Upgraded.
xfce/thunar-4.18.0-x86_64-1.txz:  Upgraded.
xfce/thunar-volman-4.18.0-x86_64-1.txz:  Upgraded.
xfce/tumbler-4.18.0-x86_64-1.txz:  Upgraded.
xfce/xfce4-appfinder-4.18.0-x86_64-1.txz:  Upgraded.
xfce/xfce4-dev-tools-4.18.0-x86_64-1.txz:  Upgraded.
xfce/xfce4-notifyd-0.6.5-x86_64-1.txz:  Upgraded.
xfce/xfce4-panel-4.18.0-x86_64-1.txz:  Upgraded.
xfce/xfce4-power-manager-4.18.0-x86_64-1.txz:  Upgraded.
xfce/xfce4-session-4.18.0-x86_64-1.txz:  Upgraded.
xfce/xfce4-settings-4.18.0-x86_64-1.txz:  Upgraded.
xfce/xfce4-weather-plugin-0.11.0-x86_64-1.txz:  Upgraded.
xfce/xfconf-4.18.0-x86_64-1.txz:  Upgraded.
xfce/xfdesktop-4.18.0-x86_64-1.txz:  Upgraded.
xfce/xfwm4-4.18.0-x86_64-1.txz:  Upgraded.
2022-12-17 23:32:53 +01:00
Patrick J Volkerding
addce63adb Mon Jan 18 13:50:16 UTC 2021
Hey folks, a little status update here. First, huge thanks are due to
nobodino for helping to shake out packages that weren't building from source.
With all those fixes in place (plus a few more), we have tested and found that
everything in the tree compiles cleanly against glibc-2.32. So, the plan is to
have another mass rebuild soon against that. Although the ABI didn't
technically change, I've heard that libpthread may not be 100% compatible in
some corner cases, so we'll err on the side of caution. Hopefully we can get a
little testing done on the recompiled system and then go through it all again
at the beginning of next month when glibc-2.33 is released. Other than that,
how's Mesa working these days? If there are still issues that are resolved by
dropping back to the previous branch, let's try to figure those out. I'd rather
not revert Mesa unless there's no other choice. I'm hoping that the (probably
unrelated) issues with Intel video hardware will be helped by today's
xorg-server patch that uses the modesetting driver with newer chipsets. Please
report any improvement on the LQ thread.
Beta approaches. :-)
a/sysklogd-2.2.0-x86_64-1.txz:  Upgraded.
d/distcc-3.3.5-x86_64-2.txz:  Rebuilt.
  Properly install distccmon-gnome.desktop. Thanks to marco70.
d/python-setuptools-51.3.3-x86_64-1.txz:  Upgraded.
l/imagemagick-7.0.10_58-x86_64-1.txz:  Upgraded.
l/libodfgen-0.1.8-x86_64-1.txz:  Upgraded.
l/libsigsegv-2.13-x86_64-1.txz:  Upgraded.
n/inetd-1.79s-x86_64-12.txz:  Rebuilt.
  Rebuilt to link with libtirpc. Thanks to nobodino.
n/nftables-0.9.8-x86_64-1.txz:  Upgraded.
n/postfix-3.5.9-x86_64-1.txz:  Upgraded.
n/tcp_wrappers-7.6-x86_64-4.txz:  Rebuilt.
  Use strerror(), not sys_errlist(). Thanks to nobodino.
x/xorg-server-1.20.10-x86_64-3.txz:  Rebuilt.
  Only use the Intel DDX with pre-gen4 hardware. Newer hardware will use the
  modesetting driver.
x/xorg-server-xephyr-1.20.10-x86_64-3.txz:  Rebuilt.
x/xorg-server-xnest-1.20.10-x86_64-3.txz:  Rebuilt.
x/xorg-server-xvfb-1.20.10-x86_64-3.txz:  Rebuilt.
x/xorg-server-xwayland-1.20.10-x86_64-3.txz:  Rebuilt.
xfce/xfce4-appfinder-4.16.1-x86_64-1.txz:  Upgraded.
2021-01-19 08:59:50 +01:00