Slackware-14.2 ChangeLog (2022-10-25)

Tue Oct 25 18:38:58 UTC 2022

  • patches/packages/expat-2.4.3-i586-8_slack14.2.txz
    This update fixes a security issue:
    Fix heap use-after-free after overeager destruction of a shared DTD in
    function XML_ExternalEntityParserCreate in out-of-memory situations.
    Expected impact is denial of service or potentially arbitrary code
    execution.
    For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43680
    (* Security fix *)
  • patches/packages/rsync-3.2.7-i586-2_slack14.2.txz
    This is a bugfix release, fixing the list of supported auth checksums when
    rsync is built against 1.0.x.
    Thanks to niksoggia.
  • news/2022/10/25/slackware-14.2-changelog.txt
  • Last modified: 16 months ago
  • by Giuseppe Di Terlizzi