ChangeLog for: 2025-12-04 23:21:59
a/libbytesize-2.12-x86_64-1.txz: Upgraded.
ap/a2ps-4.15.8-x86_64-1.txz: Upgraded.
ap/cups-2.4.16-x86_64-1.txz: Upgraded.
The hotfix release 2.4.16 includes fix for infinite loop in GTK, which was
caused by change of internal behavior in libcups on which GTK depended on,
and workaround for stopping the scheduler if configuration includes unknown
directives.
ap/linuxdoc-tools-0.9.86-x86_64-1.txz: Upgraded.
Upgraded to linuxdoc-tools 0.9.86, docbook-utils 0.6.15, gtk-doc 1.35.1,
and xmlto 0.0.29.
docbook2x: Minor corrections to a man page.
Thanks to Stuart Winter.
kde/calligra-3.2.1-x86_64-60.txz: Rebuilt.
Recompiled against poppler-25.12.0.
kde/cantor-23.08.5-x86_64-26.txz: Rebuilt.
Recompiled against poppler-25.12.0.
kde/kfilemetadata-5.116.0-x86_64-22.txz: Rebuilt.
Recompiled against poppler-25.12.0.
kde/kile-2.9.93-x86_64-52.txz: Rebuilt.
Recompiled against poppler-25.12.0.
kde/kitinerary-23.08.5-x86_64-24.txz: Rebuilt.
Recompiled against poppler-25.12.0.
kde/krita-5.2.13-x86_64-3.txz: Rebuilt.
Recompiled against poppler-25.12.0.
kde/labplot-2.11.1-x86_64-18.txz: Rebuilt.
Recompiled against poppler-25.12.0.
kde/okular-23.08.5-x86_64-23.txz: Rebuilt.
Recompiled against poppler-25.12.0.
l/immer-0.9.0-x86_64-1.txz: Upgraded.
l/libpaper-2.2.7-x86_64-1.txz: Upgraded.
l/libpng-1.6.52-x86_64-1.txz: Upgraded.
This update fixes a high severity security issue:
Out-of-bounds read in `png_image_read_composite`.
(Reported by flyfish101 .)
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2025-66293
(* Security fix *)
l/libxkbcommon-1.13.1-x86_64-1.txz: Upgraded.
l/poppler-25.12.0-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
l/python-sphinx-9.0.4-x86_64-1.txz: Upgraded.
n/httpd-2.4.66-x86_64-1.txz: Upgraded.
This release fixes bugs and the following security issues:
mod_userdir+suexec bypass via AllowOverride FileInfo.
CGI environment variable override.
NTLM Leakage on Windows through UNC SSRF.
Server Side Includes adds query string to #exec cmd=...
mod_md (ACME), unintended retry intervals.
For more information, see:
https://downloads.apache.org/httpd/CHANGES_2.4.66
https://www.cve.org/CVERecord?id=CVE-2025-66200
https://www.cve.org/CVERecord?id=CVE-2025-65082
https://www.cve.org/CVERecord?id=CVE-2025-59775
https://www.cve.org/CVERecord?id=CVE-2025-58098
https://www.cve.org/CVERecord?id=CVE-2025-55753
(* Security fix *)
n/libnftnl-1.3.1-x86_64-1.txz: Upgraded.
x/mesa-25.3.1-x86_64-1.txz: Upgraded.
x/xkbcomp-1.5.0-x86_64-1.txz: Upgraded.