slackware-current/source/xap
Patrick J Volkerding b98f1614c2 Wed Dec 7 18:48:07 UTC 2022
d/cargo-vendor-filterer-0.5.7-x86_64-1.txz:  Added.
  Thanks to Heinz Wiesinger.
d/cbindgen-0.24.3-x86_64-1.txz:  Added.
d/python3-3.9.16-x86_64-1.txz:  Upgraded.
  This update fixes security issues:
  gh-98739: Updated bundled libexpat to 2.5.0 to fix CVE-2022-43680
  (heap use-after-free).
  gh-98433: The IDNA codec decoder used on DNS hostnames by socket or asyncio
  related name resolution functions no longer involves a quadratic algorithm
  to fix CVE-2022-45061. This prevents a potential CPU denial of service if an
  out-of-spec excessive length hostname involving bidirectional characters were
  decoded. Some protocols such as urllib http 3xx redirects potentially allow
  for an attacker to supply such a name.
  gh-100001: python -m http.server no longer allows terminal control characters
  sent within a garbage request to be printed to the stderr server log.
  gh-87604: Avoid publishing list of active per-interpreter audit hooks via the
  gc module.
  gh-97514: On Linux the multiprocessing module returns to using filesystem
  backed unix domain sockets for communication with the forkserver process
  instead of the Linux abstract socket namespace. Only code that chooses to use
  the "forkserver" start method is affected. This prevents Linux CVE-2022-42919
  (potential privilege escalation) as abstract sockets have no permissions and
  could allow any user on the system in the same network namespace (often the
  whole system) to inject code into the multiprocessing forkserver process.
  Filesystem based socket permissions restrict this to the forkserver process
  user as was the default in Python 3.8 and earlier.
  gh-98517: Port XKCP's fix for the buffer overflows in SHA-3 to fix
  CVE-2022-37454.
  gh-68966: The deprecated mailcap module now refuses to inject unsafe text
  (filenames, MIME types, parameters) into shell commands to address
  CVE-2015-20107. Instead of using such text, it will warn and act as if a
  match was not found (or for test commands, as if the test failed).
  For more information, see:
    https://pythoninsider.blogspot.com/2022/12/python-3111-3109-3916-3816-3716-and.html
    https://www.cve.org/CVERecord?id=CVE-2022-43680
    https://www.cve.org/CVERecord?id=CVE-2022-45061
    https://www.cve.org/CVERecord?id=CVE-2022-42919
    https://www.cve.org/CVERecord?id=CVE-2022-37454
    https://www.cve.org/CVERecord?id=CVE-2015-20107
  (* Security fix *)
d/rust-bindgen-0.63.0-x86_64-1.txz:  Added.
  Thanks to Heinz Wiesinger.
l/pcre2-10.41-x86_64-1.txz:  Upgraded.
n/proftpd-1.3.8-x86_64-1.txz:  Upgraded.
x/mesa-22.3.0-x86_64-1.txz:  Upgraded.
  Compiled with Rusticl support. Thanks to Heinz Wiesinger.
x/xdm-1.1.14-x86_64-1.txz:  Upgraded.
2022-12-07 22:19:17 +01:00
..
audacious Sun Jul 10 18:49:34 UTC 2022 2022-07-11 07:00:12 +02:00
audacious-plugins Sun Nov 20 00:54:24 UTC 2022 2022-11-20 07:00:14 +01:00
blackbox Mon Oct 10 18:45:33 UTC 2022 2022-10-11 07:00:35 +02:00
blueman Fri Feb 11 01:09:45 UTC 2022 2022-02-11 07:43:07 +01:00
ddd Mon Nov 21 20:23:13 UTC 2022 2022-11-22 07:00:14 +01:00
easytag Sun Nov 20 00:54:24 UTC 2022 2022-11-20 07:00:14 +01:00
electricsheep Tue Nov 29 20:56:03 UTC 2022 2022-11-30 01:00:18 +01:00
ffmpegthumbnailer Mon Oct 10 18:45:33 UTC 2022 2022-10-11 07:00:35 +02:00
fluxbox Mon Jan 17 22:44:42 UTC 2022 2022-01-18 08:59:56 +01:00
freerdp Fri Oct 14 01:39:37 UTC 2022 2022-10-14 09:00:17 +02:00
fvwm Fri Nov 4 19:29:28 UTC 2022 2022-11-05 07:00:18 +01:00
geeqie Mon Aug 8 23:29:31 UTC 2022 2022-08-09 07:00:15 +02:00
gftp Tue Sep 6 20:21:24 UTC 2022 2022-09-07 07:00:17 +02:00
gimp Mon Jun 13 21:02:58 UTC 2022 2022-06-14 07:00:10 +02:00
gkrellm Mon Feb 15 19:23:44 UTC 2021 2021-02-16 08:59:54 +01:00
gnuchess Wed Jul 14 17:57:37 UTC 2021 2021-07-15 00:00:46 +02:00
gnuplot Mon Jun 7 18:53:49 UTC 2021 2021-06-07 23:59:59 +02:00
gparted Mon May 3 19:58:20 UTC 2021 2021-05-03 23:59:55 +02:00
gucharmap Mon Feb 15 19:23:44 UTC 2021 2021-02-16 08:59:54 +01:00
gv Mon Feb 15 19:23:44 UTC 2021 2021-02-16 08:59:54 +01:00
hexchat Fri Jun 3 16:51:58 UTC 2022 2022-06-04 07:00:07 +02:00
libnma Mon Dec 5 02:40:12 UTC 2022 2022-12-05 07:00:11 +01:00
mozilla-firefox Wed Dec 7 18:48:07 UTC 2022 2022-12-07 22:19:17 +01:00
mozilla-thunderbird Wed Dec 7 18:48:07 UTC 2022 2022-12-07 22:19:17 +01:00
MPlayer Tue Nov 29 20:56:03 UTC 2022 2022-11-30 01:00:18 +01:00
network-manager-applet Wed Mar 23 17:25:36 UTC 2022 2022-03-24 06:59:46 +01:00
NetworkManager-openvpn Tue Sep 6 20:21:24 UTC 2022 2022-09-07 07:00:17 +02:00
pan Fri Dec 24 20:43:23 UTC 2021 2021-12-25 08:59:54 +01:00
pavucontrol Sat Aug 21 04:38:34 UTC 2021 2021-08-21 17:59:54 +02:00
pidgin Mon Jun 7 18:53:49 UTC 2021 2021-06-07 23:59:59 +02:00
rdesktop Mon Feb 15 19:23:44 UTC 2021 2021-02-16 08:59:54 +01:00
rxvt-unicode Tue Sep 6 20:21:24 UTC 2022 2022-09-07 07:00:17 +02:00
sane Tue Feb 16 20:57:36 UTC 2021 2021-02-17 08:59:52 +01:00
seamonkey Wed Aug 10 18:50:54 UTC 2022 2022-08-11 07:00:16 +02:00
seyon Tue Sep 6 20:21:24 UTC 2022 2022-09-07 07:00:17 +02:00
ssr Mon Oct 10 18:45:33 UTC 2022 2022-10-11 07:00:35 +02:00
windowmaker Mon Feb 15 19:23:44 UTC 2021 2021-02-16 08:59:54 +01:00
x11-ssh-askpass Mon Feb 15 19:23:44 UTC 2021 2021-02-16 08:59:54 +01:00
x3270 Tue Sep 6 20:21:24 UTC 2022 2022-09-07 07:00:17 +02:00
xaos Mon Nov 21 20:23:13 UTC 2022 2022-11-22 07:00:14 +01:00
xgames Mon Feb 15 19:23:44 UTC 2021 2021-02-16 08:59:54 +01:00
xine-lib Sun Nov 20 00:54:24 UTC 2022 2022-11-20 07:00:14 +01:00
xine-ui Fri Dec 17 20:47:13 UTC 2021 2021-12-18 08:59:54 +01:00
xlockmore Tue Aug 31 20:58:13 UTC 2021 2021-09-01 08:59:56 +02:00
xmms Mon Feb 15 19:23:44 UTC 2021 2021-02-16 08:59:54 +01:00
xpaint Sat Mar 27 20:11:55 UTC 2021 2021-03-28 08:59:53 +02:00
xpdf Tue Apr 26 19:45:46 UTC 2022 2022-04-27 06:59:51 +02:00
xsane Mon Feb 15 19:23:44 UTC 2021 2021-02-16 08:59:54 +01:00
xscreensaver Sat Jun 4 18:43:17 UTC 2022 2022-06-05 07:00:07 +02:00
xsnow Tue Sep 6 20:21:24 UTC 2022 2022-09-07 07:00:17 +02:00
FTBFSlog Mon Oct 10 18:45:33 UTC 2022 2022-10-11 07:00:35 +02:00
vim-gvim Slackware 13.0 2018-05-31 22:41:17 +02:00