slackware-current/patches/source/ca-certificates
Patrick J Volkerding 40bf9bf864 Thu Jun 23 05:30:51 UTC 2022
patches/packages/ca-certificates-20220622-noarch-1_slack15.0.txz:  Upgraded.
  This update provides the latest CA certificates to check for the
  authenticity of SSL connections.
patches/packages/openssl-1.1.1p-x86_64-1_slack15.0.txz:  Upgraded.
  In addition to the c_rehash shell command injection identified in
  CVE-2022-1292, further circumstances where the c_rehash script does not
  properly sanitise shell metacharacters to prevent command injection were
  found by code review.
  When the CVE-2022-1292 was fixed it was not discovered that there
  are other places in the script where the file names of certificates
  being hashed were possibly passed to a command executed through the shell.
  For more information, see:
    https://www.openssl.org/news/secadv/20220621.txt
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2068
  (* Security fix *)
patches/packages/openssl-solibs-1.1.1p-x86_64-1_slack15.0.txz:  Upgraded.
2022-06-24 01:30:06 +02:00
..
ca-certificates.SlackBuild Thu Mar 10 02:30:54 UTC 2022 2022-03-10 13:29:56 +01:00
certdata-20220622.txt Thu Jun 23 05:30:51 UTC 2022 2022-06-24 01:30:06 +02:00
doinst.sh Thu Mar 10 02:30:54 UTC 2022 2022-03-10 13:29:56 +01:00
fixup_update-ca-certificates.diff Thu Mar 10 02:30:54 UTC 2022 2022-03-10 13:29:56 +01:00
get-certdata.txt.sh Thu Mar 10 02:30:54 UTC 2022 2022-03-10 13:29:56 +01:00
setup.11.cacerts Thu Mar 10 02:30:54 UTC 2022 2022-03-10 13:29:56 +01:00
slack-desc Thu Mar 10 02:30:54 UTC 2022 2022-03-10 13:29:56 +01:00
update-ca-certificates.c_rehash.diff Thu Mar 10 02:30:54 UTC 2022 2022-03-10 13:29:56 +01:00