Slackwarearm-14.2 ChangeLog (2022-06-23)

Thu Jun 23 08:08:08 UTC 2022

  • patches/packages/ca-certificates-20220622-noarch-1_slack14.2.txz
    This update provides the latest CA certificates to check for the
    authenticity of SSL connections.
  • patches/packages/openssl-1.0.2u-arm-1_slack14.2.txz
    In addition to the c_rehash shell command injection identified in
    CVE-2022-1292, further circumstances where the c_rehash script does not
    properly sanitise shell metacharacters to prevent command injection were
    found by code review.
    When the CVE-2022-1292 was fixed it was not discovered that there
    are other places in the script where the file names of certificates
    being hashed were possibly passed to a command executed through the shell.
    For more information, see:
    https://www.openssl.org/news/secadv/20220621.txt
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2068
    (* Security fix *)
  • patches/packages/openssl-solibs-1.0.2u-arm-1_slack14.2.txz
  • news/2022/06/23/slackwarearm-14.2-changelog.txt
  • Last modified: 19 months ago
  • by Giuseppe Di Terlizzi