Slackwarearm-current ChangeLog (2016-11-22)
Tue Nov 22 23:23:23 UTC 2016
Packages
Upgraded
- a/bash-4.4.005-arm-1.txz
- a/kernel-firmware-20161118git-noarch-1.txz
- ap/ghostscript-9.20-arm-1.txz
- n/nmap-7.31-arm-1.txz
- n/ntp-4.2.8p9-arm-1.txz
In addition to bug fixes and enhancements, this release fixes the
following 1 high- (Windows only , 2 medium-, 2 medium-/low, and
5 low-severity vulnerabilities, and provides 28 other non-security
fixes and improvements.
CVE-2016-9311: Trap crash
CVE-2016-9310: Mode 6 unauthenticated trap info disclosure and DDoS vector
CVE-2016-7427: Broadcast Mode Replay Prevention DoS
CVE-2016-7428: Broadcast Mode Poll Interval Enforcement DoS
CVE-2016-9312: Windows: ntpd DoS by oversized UDP packet
CVE-2016-7431: Regression: 010-origin: Zero Origin Timestamp Bypass
CVE-2016-7434: Null pointer dereference in _IO_str_init_static_internal()
CVE-2016-7429: Interface selection attack
CVE-2016-7426: Client rate limiting and server responses
CVE-2016-7433: Reboot sync calculation problem
For more information, see:
https://www.kb.cert.org/vuls/id/633847
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9311
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9310
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7427
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7428
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9312
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7431
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7434
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7429
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7426
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7433
(* Security fix *) - n/samba-4.5.1-arm-1.txz
- x/freeglut-3.0.0-arm-1.txz
- x/libdrm-2.4.73-arm-1.txz
- x/libxcb-1.12-arm-1.txz
- x/mesa-13.0.1-arm-1.txz
- x/xcb-proto-1.12-arm-1.txz
- x/xcb-util-cursor-0.1.3-arm-1.txz
- x/xf86-input-evdev-2.10.4-arm-1.txz
- x/xf86-input-joystick-1.6.3-arm-1.txz
- x/xf86-input-keyboard-1.9.0-arm-1.txz
- x/xf86-input-mouse-1.9.2-arm-1.txz
- x/xf86-input-synaptics-1.9.0-arm-1.txz
- x/xf86-video-amdgpu-1.2.0-arm-1.txz
- x/xf86-video-armsoc-1.4.1-arm-1.txz
- x/xf86-video-ati-7.8.0-arm-1.txz
- x/xf86-video-nouveau-1.0.13-arm-1.txz
- x/xf86-video-opentegra-0.7.0-arm-1.txz
- x/xf86-video-vmware-13.2.1-arm-1.txz
- x/xorg-server-1.19.0-arm-1.txz
- x/xorg-server-xephyr-1.19.0-arm-1.txz
- x/xorg-server-xnest-1.19.0-arm-1.txz
- x/xorg-server-xvfb-1.19.0-arm-1.txz
- x/xproto-7.0.31-arm-1.txz
- x/xterm-326-arm-1.txz
- xap/mozilla-firefox-50.0-arm-1.txz
This release contains security fixes and improvements.
For more information, see:
http://www.mozilla.org/security/known-vulnerabilities/firefox.html
(* Security fix *) - extra/tigervnc/tigervnc-1.7.0-arm-1.txz
Rebuilt
- a/grep-2.26-arm-2.txz
Reverted a speedup patch that is causing regressions when output is directed
to /dev/null. Thanks to SeB. - x/xf86-input-acecad-1.5.0-arm-2.txz
- x/xf86-input-penmount-1.5.0-arm-2.txz
- x/xf86-input-void-1.4.0-arm-2.txz
- x/xf86-input-wacom-0.33.0-arm-2.txz
- x/xf86-video-apm-1.2.5-arm-2.txz
- x/xf86-video-ark-0.7.5-arm-2.txz
- x/xf86-video-ast-1.1.5-arm-2.txz
- x/xf86-video-cirrus-1.5.3-arm-2.txz
- x/xf86-video-dummy-0.3.7-arm-2.txz
- x/xf86-video-fbdev-0.4.4-arm-2.txz
- x/xf86-video-fbturbo-199.f9a6ed7-arm-2.txz
- x/xf86-video-i128-1.3.6-arm-2.txz
- x/xf86-video-mach64-6.9.5-arm-2.txz
- x/xf86-video-neomagic-1.2.9-arm-2.txz
- x/xf86-video-openchrome-0.5.0-arm-2.txz
- x/xf86-video-rendition-4.2.6-arm-2.txz
- x/xf86-video-s3-0.6.5-arm-2.txz
- x/xf86-video-s3virge-1.10.7-arm-2.txz
- x/xf86-video-sisusb-0.9.6-arm-2.txz
- x/xf86-video-tga-1.2.2-arm-2.txz
- x/xf86-video-tseng-1.2.5-arm-2.txz
- x/xf86-video-v4l-0.2.0-arm-2.txz
- x/xf86-video-vesa-2.3.4-arm-2.txz
- x/xf86-video-voodoo-1.2.5-arm-2.txz
Added
- x/libXfont2-2.0.1-arm-1.txz
Removed
x/xf86-video-chips-1.2.6-arm-1.txzx/xf86-video-glint-1.2.8-arm-1.txzx/xf86-video-i740-1.3.5-arm-1.txzx/xf86-video-mga-1.6.4-arm-1.txzx/xf86-video-nv-2.1.20-arm-1.txzx/xf86-video-r128-6.10.1-arm-1.txzx/xf86-video-savage-2.3.8-arm-1.txzx/xf86-video-siliconmotion-1.7.8-arm-1.txzx/xf86-video-sis-0.10.8-arm-1.txzx/xf86-video-tdfx-1.4.6-arm-1.txzx/xf86-video-trident-1.3.7-arm-1.txzx/xf86-video-xgi-1.6.0git_2012_08_06-arm-1.txz
This had been kept patched in Slackware ARM 14.2 for the armv5 OpenRD Client system,
but is now redundant.x/xf86-video-xgixp-1.8.1-arm-1.txz