This is an old revision of the document!
Slackware64-14.2 ChangeLog (2018-03-29)
Thu Mar 29 20:48:28 UTC 2018
Packages
Upgraded
- patches/packages/ruby-2.2.10-x86_64-1_slack14.2.txz
This release includes some bug fixes and some security fixes:
HTTP response splitting in WEBrick.
Unintentional file and directory creation with directory traversal in
tempfile and tmpdir.
DoS by large request in WEBrick.
Buffer under-read in String#unpack.
Unintentional socket creation by poisoned NUL byte in UNIXServer
and UNIXSocket.
Unintentional directory traversal by poisoned NUL byte in Dir.
Multiple vulnerabilities in RubyGems.
For more information, see:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17742
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6914
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8777
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8778
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8779
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8780
(* Security fix *)
Thu Mar 29 01:02:50 UTC 2018
Packages
Upgraded
- patches/packages/openssl-1.0.2o-x86_64-1_slack14.2.txz
This update fixes a security issue:
Constructed ASN.1 types with a recursive definition could exceed the stack.
For more information, see:
https://www.openssl.org/news/secadv/20180327.txt
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0739
(* Security fix *) - patches/packages/openssl-solibs-1.0.2o-x86_64-1_slack14.2.txz