Slackware-14.0 ChangeLog (2017-10-06)
Fri Oct 6 06:32:32 UTC 2017
Packages
Upgraded
- patches/packages/curl-7.56.0-i486-1_slack14.0.txz
This update fixes a security issue:
libcurl may read outside of a heap allocated buffer when doing FTP.
For more information, see:
https://curl.haxx.se/docs/adv_20171004.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000254
(* Security fix *)
Rebuilt
- patches/packages/xorg-server-1.12.4-i486-4_slack14.0.txz
This update fixes a security issue:
Generating strings for XKB data used a single shared static buffer,
which offered several opportunities for errors. Use a ring of
resizable buffers instead, to avoid problems when strings end up
longer than anticipated.
For more information, see:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13723
(* Security fix *) - patches/packages/xorg-server-xephyr-1.12.4-i486-4_slack14.0.txz
- patches/packages/xorg-server-xnest-1.12.4-i486-4_slack14.0.txz
- patches/packages/xorg-server-xvfb-1.12.4-i486-4_slack14.0.txz