This is an old revision of the document!
Slackwarearm-14.2 ChangeLog (2018-08-27)
Mon Aug 27 08:08:08 UTC 2018
Packages
Upgraded
- patches/packages/libX11-1.6.6-arm-1_slack14.2.txz
This update fixes some security issues:
Fixed crash on invalid reply (CVE-2018-14598).
Fixed off-by-one writes (CVE-2018-14599).
Fixed out of boundary write (CVE-2018-14600).
For more information, see:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14598
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14599
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14600
(* Security fix *) - patches/packages/samba-4.6.16-arm-1_slack14.2.txz
This is a security release in order to address the following defects:
Insufficient input validation on client directory listing in libsmbclient.
A malicious server could return a directory entry that could corrupt
libsmbclient memory.
Confidential attribute disclosure from the AD LDAP server.
Missing access control checks allow discovery of confidential attribute
values via authenticated LDAP search expressions.
For more information, see:
https://www.samba.org/samba/security/CVE-2018-10858.html
https://www.samba.org/samba/security/CVE-2018-10919.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10858
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10919
(* Security fix *)