slackware-current/extra/source
Patrick J Volkerding 4657194ae3 Tue Oct 1 18:01:38 UTC 2024
Several ELF objects were found to have rpaths pointing into /tmp, a world
writable directory. This could have allowed a local attacker to launch denial
of service attacks or execute arbitrary code when the affected binaries are
run by placing crafted ELF objects in the /tmp rpath location. All rpaths with
an embedded /tmp path have been scrubbed from the binaries, and makepkg has
gained a lint feature to detect these so that they won't creep back in.
extra/llvm-17.0.6-x86_64-2_slack15.0.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
patches/packages/cryfs-0.10.3-x86_64-5_slack15.0.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
patches/packages/cups-filters-1.28.17-x86_64-2_slack15.0.txz:  Rebuilt.
  Mitigate security issue that could lead to a denial of service or
  the execution of arbitrary code.
  Rebuilt with --with-browseremoteprotocols=none to disable incoming
  connections, since this daemon has been shown to be insecure. If you
  actually use cups-browsed, be sure to install the new
  /etc/cups/cups-browsed.conf.new containing this line:
  BrowseRemoteProtocols none
  For more information, see:
    https://www.cve.org/CVERecord?id=CVE-2024-47176
  (* Security fix *)
patches/packages/espeak-ng-1.50-x86_64-4_slack15.0.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
patches/packages/libvncserver-0.9.13-x86_64-4_slack15.0.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
patches/packages/marisa-0.2.6-x86_64-5_slack15.0.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
patches/packages/mlt-7.4.0-x86_64-2_slack15.0.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
patches/packages/mozilla-firefox-115.16.0esr-x86_64-1_slack15.0.txz:  Upgraded.
  This update contains security fixes and improvements.
  For more information, see:
    https://www.mozilla.org/en-US/firefox/115.16.0/releasenotes/
    https://www.mozilla.org/security/advisories/mfsa2024-48
    https://www.cve.org/CVERecord?id=CVE-2024-9392
    https://www.cve.org/CVERecord?id=CVE-2024-9393
    https://www.cve.org/CVERecord?id=CVE-2024-9394
    https://www.cve.org/CVERecord?id=CVE-2024-9401
  (* Security fix *)
patches/packages/openobex-1.7.2-x86_64-6_slack15.0.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
patches/packages/pkgtools-15.0-noarch-44_slack15.0.txz:  Rebuilt.
  makepkg: when looking for ELF objects with --remove-rpaths or
  --remove-tmp-rpaths, avoid false hits on files containing 'ELF' as part
  of the directory or filename.
  Also warn about /tmp rpaths after the package is built.
patches/packages/spirv-llvm-translator-13.0.0-x86_64-2_slack15.0.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
testing/packages/llvm-18.1.8-x86_64-2_slack15.0.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
2024-10-02 13:30:38 +02:00
..
aspell-word-lists Tue May 26 20:35:03 UTC 2020 2020-05-26 23:59:47 +02:00
bash-completion Mon Jun 7 18:53:49 UTC 2021 2021-06-07 23:59:59 +02:00
bittornado Mon Sep 30 21:08:32 UTC 2019 2019-10-01 08:59:50 +02:00
brltty Tue Nov 16 19:04:47 UTC 2021 2021-11-17 08:59:57 +01:00
fltk Sun Nov 21 20:16:54 UTC 2021 2021-11-22 08:59:57 +01:00
getty-ps Fri Oct 18 21:00:50 UTC 2019 2019-10-19 08:59:48 +02:00
java Mon Sep 30 21:08:32 UTC 2019 2019-10-01 08:59:50 +02:00
llvm Tue Oct 1 18:01:38 UTC 2024 2024-10-02 13:30:38 +02:00
llvm13-compat Sun Feb 18 21:03:57 UTC 2024 2024-02-19 13:30:46 +01:00
php80 Mon Aug 7 19:22:02 UTC 2023 2023-08-08 13:30:34 +02:00
php81 Thu Jun 6 19:44:49 UTC 2024 2024-06-07 13:30:44 +02:00
rust-for-mozilla Fri Aug 4 20:17:36 UTC 2023 2023-08-05 13:30:38 +02:00
sendmail Wed Jan 31 21:19:19 UTC 2024 2024-02-01 13:30:49 +01:00
tigervnc Fri Apr 5 20:11:23 UTC 2024 2024-04-06 13:30:47 +02:00
xf86-video-fbdev Mon Sep 30 21:08:32 UTC 2019 2019-10-01 08:59:50 +02:00
xfractint Sun Aug 2 18:20:30 UTC 2020 2020-08-03 08:59:53 +02:00
xv Fri Oct 18 21:00:50 UTC 2019 2019-10-19 08:59:48 +02:00
alpine Thu Apr 29 18:49:00 UTC 2021 2021-04-30 08:59:55 +02:00