slackware-current/source/ap
Patrick J Volkerding 1e755d579a Tue Oct 1 18:01:38 UTC 2024
Several ELF objects were found to have rpaths pointing into /tmp, a world
writable directory. This could have allowed a local attacker to launch denial
of service attacks or execute arbitrary code when the affected binaries are
run by placing crafted ELF objects in the /tmp rpath location. All rpaths with
an embedded /tmp path have been scrubbed from the binaries, and makepkg has
gained a lint feature to detect these so that they won't creep back in.
a/kernel-firmware-20241001_95bfe08-noarch-1.txz:  Upgraded.
a/kernel-generic-6.10.12-x86_64-1.txz:  Upgraded.
a/pkgtools-15.1-noarch-12.txz:  Rebuilt.
  makepkg: when looking for ELF objects with --remove-rpaths or
  --remove-tmp-rpaths, avoid false hits on files containing 'ELF' as part
  of the directory or filename.
  Also warn about /tmp rpaths after the package is built.
ap/cups-2.4.11-x86_64-1.txz:  Upgraded.
ap/cups-browsed-2.0.1-x86_64-2.txz:  Rebuilt.
  Mitigate security issue that could lead to a denial of service or
  the execution of arbitrary code.
  Rebuilt with --with-browseremoteprotocols=none to disable incoming
  connections, since this daemon has been shown to be insecure. If you
  actually use cups-browsed, be sure to install the new
  /etc/cups/cups-browsed.conf.new containing this line:
  BrowseRemoteProtocols none
  For more information, see:
    https://www.cve.org/CVERecord?id=CVE-2024-47176
  (* Security fix *)
d/kernel-headers-6.10.12-x86-1.txz:  Upgraded.
d/llvm-18.1.8-x86_64-3.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
d/luajit-2.1.1727621189-x86_64-1.txz:  Upgraded.
d/ruby-3.3.5-x86_64-2.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
k/kernel-source-6.10.12-noarch-1.txz:  Upgraded.
kde/kimageformats-5.116.0-x86_64-2.txz:  Rebuilt.
  Recompiled against openexr-3.3.0.
kde/kio-extras-23.08.5-x86_64-2.txz:  Rebuilt.
  Recompiled against openexr-3.3.0.
kde/krita-5.2.5-x86_64-2.txz:  Rebuilt.
  Recompiled against openexr-3.3.0.
kde/libindi-2.1.0-x86_64-1.txz:  Upgraded.
l/cryfs-0.10.3-x86_64-13.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
l/espeak-ng-1.51.1-x86_64-2.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
l/ffmpeg-7.1-x86_64-1.txz:  Upgraded.
l/gegl-0.4.48-x86_64-3.txz:  Rebuilt.
  Recompiled against openexr-3.3.0.
l/gst-plugins-bad-free-1.24.8-x86_64-2.txz:  Rebuilt.
  Recompiled against openexr-3.3.0.
l/imagemagick-7.1.1_38-x86_64-2.txz:  Rebuilt.
  Recompiled against openexr-3.3.0.
l/libgsf-1.14.53-x86_64-1.txz:  Upgraded.
l/librsvg-2.58.5-x86_64-1.txz:  Upgraded.
l/libvncserver-0.9.14-x86_64-3.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
l/mozjs128-128.3.0esr-x86_64-1.txz:  Upgraded.
l/netpbm-11.08.00-x86_64-1.txz:  Upgraded.
l/opencv-4.10.0-x86_64-3.txz:  Rebuilt.
  Recompiled against openexr-3.3.0.
l/openexr-3.3.0-x86_64-1.txz:  Upgraded.
  Shared library .so-version bump.
l/python-glad2-2.0.8-x86_64-1.txz:  Upgraded.
l/python-pyproject-hooks-1.2.0-x86_64-1.txz:  Upgraded.
l/spirv-llvm-translator-18.1.4-x86_64-2.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
l/woff2-20231106_0f4d304-x86_64-2.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
n/openobex-1.7.2-x86_64-6.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
x/marisa-0.2.6-x86_64-11.txz:  Rebuilt.
  Remove rpaths from binaries.
  (* Security fix *)
xap/gimp-2.10.38-x86_64-2.txz:  Rebuilt.
  Recompiled against openexr-3.3.0.
xap/mozilla-firefox-128.3.0esr-x86_64-1.txz:  Upgraded.
  This update contains security fixes and improvements.
  For more information, see:
    https://www.mozilla.org/en-US/firefox/128.3.0/releasenotes/
    https://www.mozilla.org/security/advisories/mfsa2024-47
    https://www.cve.org/CVERecord?id=CVE-2024-9392
    https://www.cve.org/CVERecord?id=CVE-2024-9393
    https://www.cve.org/CVERecord?id=CVE-2024-9394
    https://www.cve.org/CVERecord?id=CVE-2024-8900
    https://www.cve.org/CVERecord?id=CVE-2024-9396
    https://www.cve.org/CVERecord?id=CVE-2024-9397
    https://www.cve.org/CVERecord?id=CVE-2024-9398
    https://www.cve.org/CVERecord?id=CVE-2024-9399
    https://www.cve.org/CVERecord?id=CVE-2024-9400
    https://www.cve.org/CVERecord?id=CVE-2024-9401
    https://www.cve.org/CVERecord?id=CVE-2024-9402
  (* Security fix *)
xap/xlockmore-5.80-x86_64-1.txz:  Upgraded.
isolinux/initrd.img:  Rebuilt.
kernels/*:  Upgraded.
testing/packages/kernel-generic-6.11.1-x86_64-1.txz:  Upgraded.
testing/packages/kernel-headers-6.11.1-x86-1.txz:  Upgraded.
testing/packages/kernel-source-6.11.1-noarch-1.txz:  Upgraded.
usb-and-pxe-installers/usbboot.img:  Rebuilt.
2024-10-01 22:04:37 +02:00
..
a2ps Wed May 10 23:42:53 UTC 2023 2023-05-11 02:57:05 +02:00
acct
alsa-utils Thu May 4 19:02:58 UTC 2023 2023-05-04 21:36:43 +02:00
amp Sun May 12 19:10:12 UTC 2024 2024-05-12 21:28:58 +02:00
at
bc Sat May 4 17:37:11 UTC 2024 2024-05-04 20:01:05 +02:00
bpe Sun May 12 19:10:12 UTC 2024 2024-05-12 21:28:58 +02:00
cdparanoia
cdrdao Thu Feb 9 00:59:27 UTC 2023 2023-02-09 02:38:53 +01:00
cdrtools Sun May 12 19:10:12 UTC 2024 2024-05-12 21:28:58 +02:00
cups Tue Oct 1 18:01:38 UTC 2024 2024-10-01 22:04:37 +02:00
cups-browsed Tue Oct 1 18:01:38 UTC 2024 2024-10-01 22:04:37 +02:00
cups-filters Thu Aug 15 20:07:37 UTC 2024 2024-08-15 23:02:34 +02:00
dash
dc3dd Thu Mar 9 20:28:23 UTC 2023 2023-03-09 22:34:46 +01:00
ddrescue
diffstat Mon Jan 29 19:17:30 UTC 2024 2024-01-29 21:03:28 +01:00
diffutils
dmapi
dmidecode
dvd+rw-tools
enscript
flac Sun Nov 20 00:54:24 UTC 2022 2022-11-20 07:00:14 +01:00
ghostscript Thu Sep 19 19:16:36 UTC 2024 2024-09-19 22:04:38 +02:00
ghostscript-fonts-std
gphoto2
groff Tue Apr 16 18:50:13 UTC 2024 2024-04-16 21:36:10 +02:00
gutenprint Sun May 12 19:10:12 UTC 2024 2024-05-12 21:28:58 +02:00
hplip Mon Jun 17 17:36:12 UTC 2024 2024-06-17 19:59:40 +02:00
htop
inxi Thu Sep 5 22:14:23 UTC 2024 2024-09-06 01:14:21 +02:00
ispell Thu Sep 26 18:28:55 UTC 2024 2024-09-26 21:02:37 +02:00
itstool
jed
joe Sat May 4 17:37:11 UTC 2024 2024-05-04 20:01:05 +02:00
jove Sun Apr 28 19:20:42 UTC 2024 2024-04-28 21:59:59 +02:00
ksh93 Mon Aug 5 21:58:24 UTC 2024 2024-08-06 01:03:55 +02:00
libx86 Sun May 12 19:10:12 UTC 2024 2024-05-12 21:28:58 +02:00
linuxdoc-tools Mon Apr 15 22:28:37 UTC 2024 2024-04-16 01:59:06 +02:00
lm_sensors
lsof
lsscsi
lxc Tue Sep 17 23:29:04 UTC 2024 2024-09-18 02:05:31 +02:00
madplay
man-db Thu Sep 19 19:16:36 UTC 2024 2024-09-19 22:04:38 +02:00
man-pages Mon May 20 18:42:49 UTC 2024 2024-05-20 21:38:42 +02:00
mariadb Fri Aug 9 21:22:03 UTC 2024 2024-08-10 00:09:19 +02:00
mc Sat Aug 24 23:36:26 UTC 2024 2024-08-25 01:59:25 +02:00
moc Tue Aug 13 20:33:27 UTC 2024 2024-08-13 23:09:21 +02:00
most
mpg123 Fri Aug 9 03:39:11 UTC 2024 2024-08-09 06:05:42 +02:00
nano Thu Sep 5 22:14:23 UTC 2024 2024-09-06 01:14:21 +02:00
neofetch
normalize
nvme-cli Mon Aug 5 21:58:24 UTC 2024 2024-08-06 01:03:55 +02:00
opus-tools Sun Nov 20 00:54:24 UTC 2022 2022-11-20 07:00:14 +01:00
pamixer Tue Apr 16 21:57:56 UTC 2024 2024-04-17 00:28:26 +02:00
powertop Sat May 4 17:37:11 UTC 2024 2024-05-04 20:01:05 +02:00
qpdf Mon May 22 19:05:02 UTC 2023 2023-05-22 21:32:45 +02:00
radeontool
rdfind Fri Nov 10 18:46:44 UTC 2023 2023-11-10 20:43:58 +01:00
rpm Tue Jul 23 18:54:25 UTC 2024 2024-07-23 22:50:05 +02:00
rzip Sun May 12 19:10:12 UTC 2024 2024-05-12 21:28:58 +02:00
sc Sun May 12 19:10:12 UTC 2024 2024-05-12 21:28:58 +02:00
sc-im Sat Aug 17 18:14:54 UTC 2024 2024-08-17 20:30:46 +02:00
scdoc Sat Aug 17 18:14:54 UTC 2024 2024-08-17 20:30:46 +02:00
screen Fri Aug 30 17:52:19 UTC 2024 2024-08-30 20:49:55 +02:00
seejpeg Sun May 12 19:10:12 UTC 2024 2024-05-12 21:28:58 +02:00
slackpkg Tue Jul 23 18:54:25 UTC 2024 2024-07-23 22:50:05 +02:00
soma Fri Feb 16 20:18:59 UTC 2024 2024-02-16 22:05:09 +01:00
sox Sun May 12 19:10:12 UTC 2024 2024-05-12 21:28:58 +02:00
sqlite Tue Aug 13 20:33:27 UTC 2024 2024-08-13 23:09:21 +02:00
squashfs-tools Mon Mar 20 18:26:23 UTC 2023 2023-03-20 21:32:56 +01:00
stow Mon Sep 9 17:27:00 UTC 2024 2024-09-09 19:59:46 +02:00
sudo Mon Sep 2 19:56:17 UTC 2024 2024-09-02 22:40:20 +02:00
sysstat
terminus-font
texinfo Mon Sep 9 00:53:17 UTC 2024 2024-09-09 04:00:54 +02:00
tmux Fri Sep 27 21:10:23 UTC 2024 2024-09-28 00:02:43 +02:00
undervolt Sat Mar 30 20:58:19 UTC 2024 2024-03-30 22:28:04 +01:00
usbmuxd Sat Dec 2 20:46:52 UTC 2023 2023-12-02 22:28:02 +01:00
vbetool
vim Fri Aug 30 17:52:19 UTC 2024 2024-08-30 20:49:55 +02:00
vorbis-tools Sun May 12 19:10:12 UTC 2024 2024-05-12 21:28:58 +02:00
xfsdump Tue Sep 3 21:07:09 UTC 2024 2024-09-04 00:33:23 +02:00
xmltoman Fri Feb 23 02:27:35 UTC 2024 2024-02-23 03:58:34 +01:00
xorriso Mon Jun 12 20:37:03 UTC 2023 2023-06-13 00:02:22 +02:00
zsh Sun May 12 19:10:12 UTC 2024 2024-05-12 21:28:58 +02:00
FTBFSlog Wed Mar 1 20:18:13 UTC 2023 2023-03-01 22:33:18 +01:00