[slackware-security] php (SSA:2024-327-01)
New php packages are available for Slackware 15.0 and -current to
fix security issues.
Here are the details from the Slackware 15.0 ChangeLog:
+--------------------------+
extra/php81/php81-8.1.31-i586-1_slack15.0.txz: Upgraded.
This update fixes bugs and security issues:
LDAP: Fixed bug GHSA-g665-fm4p-vhff (OOB access in ldap_escape).
(CVE-2024-8932)
MySQLnd: Fixed bug GHSA-h35g-vwh6-m678 (Leak partial content of the heap
through heap buffer over-read). (CVE-2024-8929)
PDO DBLIB: Fixed bug GHSA-5hqh-c84r-qjcv (Integer overflow in the dblib
quoter causing OOB writes). (CVE-2024-11236)
PDO Firebird: Fixed bug GHSA-5hqh-c84r-qjcv (Integer overflow in the
firebird quoter causing OOB writes). (CVE-2024-11236)
Streams: Fixed bug GHSA-c5f2-jwm7-mmq2 (Configuring a proxy in a stream
context might allow for CRLF injection in URIs). (CVE-2024-11234)
Fixed bug GHSA-r977-prxv-hc43 (Single byte overread with
convert.quoted-printable-decode filter). (CVE-2024-11233)
For more information, see:
https://www.php.net/ChangeLog-8.php#8.1.31
https://www.cve.org/CVERecord?id=CVE-2024-8932
https://www.cve.org/CVERecord?id=CVE-2024-8929
https://www.cve.org/CVERecord?id=CVE-2024-11236
https://www.cve.org/CVERecord?id=CVE-2024-11234
https://www.cve.org/CVERecord?id=CVE-2024-11233
(* Security fix *)
+--------------------------+
More support for network sessions in DirectPlay.
Header fixes for C++ compilation.
I/O completion fixes.
More formats supported in D3DX9.
Various bug fixes (16).
Mer info via länken ovan...
[slackware-security] expat (SSA:2024-312-01)
New expat packages are available for Slackware 15.0 and -current to
fix security issues.
Here are the details from the Slackware 15.0 ChangeLog:
+--------------------------+
patches/packages/expat-2.6.4-i586-1_slack15.0.txz: Upgraded.
This update fixes bugs and a security issue:
Fix crash within function XML_ResumeParser from a NULL pointer dereference
by disallowing function XML_StopParser to (stop or) suspend an unstarted
parser. A new error code XML_ERROR_NOT_STARTED was introduced to properly
communicate this situation.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2024-50602
(* Security fix *)
+--------------------------+
tigervnc
mozilla-firefox
mozilla-thunderbird
xorg-server
För fullständig information, se ChangeLog för Slackware 15.0 (länken är för 64-bit 15.0)
Bundled Capstone library for disassembly in WineDbg.
More formats supported in D3DX9.
Static analysis and JUnit test reports in Gitlab CI.
More support for network sessions in DirectPlay.
Various bug fixes (15).
För mer info, se länken ovan...
RSS resultat...
Till minne av Håkan Nilsson
Mitt Slackware
Appendix Programhantering