Slackware64-current ChangeLog (2014-10-24)
Fri Oct 24 21:11:15 UTC 2014
Packages
Rebuilt
- d/gcc-4.8.3-x86_64-2.txz
Patched bug pr61801, which caused some failures with glibc-2.20. - l/glibc-2.20-x86_64-2.txz
Recompiled with patched gcc.
Fri Oct 24 04:55:44 UTC 2014
Packages
Upgraded
- a/glibc-zoneinfo-2014i-noarch-1.txz
Upgraded to tzcode2014i and tzdata2014i. - l/glibc-2.20-x86_64-1.txz
This update fixes several security issues, and adds an extra security
hardening patch from Florian Weimer. Thanks to mancha for help with
tracking and backporting patches.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4424
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4412
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4237
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4788
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4458
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4043
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0475
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5119
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6040
(* Security fix *) - xap/pidgin-2.10.10-x86_64-1.txz
This update fixes several security issues:
Insufficient SSL certificate validation (CVE-2014-3694)
Remote crash parsing malformed MXit emoticon (CVE-2014-3695)
Remote crash parsing malformed Groupwise message (CVE-2014-3696)
Malicious smiley themes could alter arbitrary files (CVE-2014-3697)
Potential information leak from XMPP (CVE-2014-3698)
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3694
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3695
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3696
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3697
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3698
(* Security fix *)