slackware-current/source/n/proftpd
Patrick J Volkerding 71ceb94a14 Sun Oct 20 19:39:21 UTC 2019
d/python-2.7.17-x86_64-1.txz:  Upgraded.
  This update fixes bugs and security issues:
  Update vendorized expat library version to 2.2.8.
  Disallow URL paths with embedded whitespace or control characters into the
  underlying http client request. Such potentially malicious header injection
  URLs now cause an httplib.InvalidURL exception to be raised.
  Avoid file reading by disallowing ``local-file://`` and ``local_file://``
  URL schemes in :func:`urllib.urlopen`, :meth:`urllib.URLopener.open` and
  :meth:`urllib.URLopener.retrieve`.
  For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15903
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9740
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9948
  (* Security fix *)
n/proftpd-1.3.6b-x86_64-1.txz:  Upgraded.
2019-10-21 08:59:48 +02:00
..
etc Mon May 28 19:12:29 UTC 2018 2018-05-31 23:39:35 +02:00
doinst.sh Slackware 13.0 2018-05-31 22:41:17 +02:00
proftpd.SlackBuild Sun Oct 20 19:39:21 UTC 2019 2019-10-21 08:59:48 +02:00
slack-desc Mon May 28 19:12:29 UTC 2018 2018-05-31 23:39:35 +02:00