Commit graph

2 commits

Author SHA1 Message Date
Patrick J Volkerding
e2bd8d2383 Thu Apr 18 21:13:58 UTC 2019
ap/ksh93-20190416_7d7bba3e-x86_64-1.txz:  Upgraded.
ap/sysstat-12.1.4-x86_64-1.txz:  Upgraded.
l/gvfs-1.40.1-x86_64-2.txz:  Rebuilt.
  Recompiled against libcdio-2.1.0.
l/icu4c-64.2-x86_64-1.txz:  Upgraded.
l/libcddb-1.3.2-x86_64-6.txz:  Rebuilt.
  Recompiled against libcdio-2.1.0.
l/libcdio-2.1.0-x86_64-1.txz:  Upgraded.
  Shared library .so-version bump.
l/libcdio-paranoia-10.2+2.0.0-x86_64-2.txz:  Rebuilt.
  Recompiled against libcdio-2.1.0.
l/zstd-1.4.0-x86_64-1.txz:  Upgraded.
n/dhcpcd-7.2.0-x86_64-1.txz:  Upgraded.
n/dovecot-2.3.5.2-x86_64-1.txz:  Upgraded.
  This update fixes a security issue:
  Trying to login with 8bit username containing invalid UTF8 input causes
  auth process to crash if auth policy is enabled. This could be used rather
  easily to cause a DoS. Similar crash also happens during mail delivery
  when using invalid UTF8 in From or Subject header when OX push
  notification driver is used.
  For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10691
  (* Security fix *)
n/nghttp2-1.38.0-x86_64-1.txz:  Upgraded.
n/openssh-8.0p1-x86_64-1.txz:  Upgraded.
  This release contains a mitigation for a weakness in the scp(1) tool
  and protocol (CVE-2019-6111): when copying files from a remote system
  to a local directory, scp(1) did not verify that the filenames that
  the server sent matched those requested by the client. This could
  allow a hostile server to create or clobber unexpected local files
  with attacker-controlled content.
  For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6111
  (* Security fix *)
xap/MPlayer-20190418-x86_64-1.txz:  Upgraded.
  Compiled against libcdio-2.1.0.
xap/audacious-plugins-3.10.1-x86_64-2.txz:  Rebuilt.
  Recompiled against libcdio-2.1.0.
extra/pure-alsa-system/MPlayer-20190418-x86_64-1_alsa.txz:  Upgraded.
  Compiled against libcdio-2.1.0.
extra/pure-alsa-system/audacious-plugins-3.10.1-x86_64-2_alsa.txz:  Rebuilt.
  Recompiled against libcdio-2.1.0.
2019-04-19 08:59:44 +02:00
Patrick J Volkerding
44f92d940d Thu Nov 22 05:56:56 UTC 2018
a/kernel-generic-4.19.3-x86_64-1.txz:  Upgraded.
a/kernel-huge-4.19.3-x86_64-1.txz:  Upgraded.
a/kernel-modules-4.19.3-x86_64-1.txz:  Upgraded.
a/openssl-solibs-1.1.1a-x86_64-1.txz:  Upgraded.
a/sysvinit-scripts-2.1-noarch-21.txz:  Rebuilt.
  rc.S: Don't run rc.fuse - udev takes care of the FUSE module and filesystem.
  rc.S: Support replacing the /etc/mtab file with a symlink to /proc/mounts.
  rc.6: Show more information when unmounting filesystems at shutdown.
ap/ghostscript-9.26-x86_64-1.txz:  Upgraded.
ap/mariadb-10.3.11-x86_64-1.txz:  Upgraded.
  This update fixes bugs and security issues.
  For more information, see:
    https://mariadb.com/kb/en/library/mariadb-10311-release-notes/
    https://cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2018-3282
    https://cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2016-9843
    https://cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2018-3174
    https://cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2018-3143
    https://cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2018-3156
    https://cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2018-3251
    https://cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2018-3185
    https://cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2018-3277
    https://cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2018-3162
    https://cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2018-3173
    https://cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2018-3200
    https://cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2018-3284
  (* Security fix *)
d/cmake-3.13.0-x86_64-1.txz:  Upgraded.
d/git-2.19.2-x86_64-1.txz:  Upgraded.
d/kernel-headers-4.14.63-x86-1.txz:  Upgraded.
d/kernel-headers-4.19.3-x86-1.txz:  Upgraded.
d/vala-0.42.3-x86_64-1.txz:  Added.
k/kernel-source-4.19.3-noarch-1.txz:  Upgraded.
l/adwaita-icon-theme-3.30.0-noarch-1.txz:  Upgraded.
l/at-spi2-atk-2.30.0-x86_64-1.txz:  Upgraded.
l/at-spi2-core-2.30.0-x86_64-1.txz:  Upgraded.
l/atk-2.30.0-x86_64-1.txz:  Upgraded.
l/atkmm-2.28.0-x86_64-1.txz:  Upgraded.
l/dconf-0.28.0-x86_64-1.txz:  Upgraded.
  dconf and dconf-editor require Vala; the alternative would be to try to
  stick with the old versions forever, and we don't want to do that.
l/dconf-editor-3.30.2-x86_64-1.txz:  Upgraded.
l/gcr-3.28.0-x86_64-3.txz:  Rebuilt.
  Recompiled to add Vala bindings.
l/gdk-pixbuf2-2.38.0-x86_64-1.txz:  Upgraded.
l/gexiv2-0.10.9-x86_64-1.txz:  Upgraded.
l/glib-networking-2.58.0-x86_64-1.txz:  Upgraded.
l/glib2-2.58.1-x86_64-1.txz:  Upgraded.
l/glibmm-2.58.0-x86_64-1.txz:  Upgraded.
l/gobject-introspection-1.58.0-x86_64-1.txz:  Upgraded.
l/gtk+3-3.24.1-x86_64-1.txz:  Upgraded.
l/gtkmm3-3.24.0-x86_64-1.txz:  Upgraded.
l/gvfs-1.38.1-x86_64-1.txz:  Upgraded.
l/libcap-2.26-x86_64-1.txz:  Upgraded.
l/libpsl-0.20.1-x86_64-1.txz:  Added.
  Required by libsoup.
l/libsoup-2.64.2-x86_64-1.txz:  Upgraded.
l/pangomm-2.42.0-x86_64-1.txz:  Upgraded.
l/pygobject3-3.30.2-x86_64-1.txz:  Upgraded.
l/vte-0.54.2-x86_64-1.txz:  Upgraded.
n/openssl-1.1.1a-x86_64-1.txz:  Upgraded.
  This update fixes timing side channel attacks on DSA and ECDSA signature
  generation that could allow an attacker to recover the private key.
  For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0734
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0735
  (* Security fix *)
x/pixman-0.36.0-x86_64-1.txz:  Upgraded.
xfce/xfce4-terminal-0.8.7.4-x86_64-2.txz:  Rebuilt.
isolinux/initrd.img:  Rebuilt.
kernels/*:  Upgraded.
usb-and-pxe-installers/usbboot.img:  Rebuilt.
2018-11-22 17:59:46 +01:00