ChangeLog for: 2026-07-07 22:49:57
a/mcelog-211-x86_64-1.txz: Upgraded.
ap/scdoc-1.11.5-x86_64-1.txz: Upgraded.
ap/vim-9.2.0782-x86_64-1.txz: Upgraded.
d/patchelf-0.19.1-x86_64-1.txz: Upgraded.
l/enchant-2.8.19-x86_64-1.txz: Upgraded.
l/mlt-7.40.0-x86_64-1.txz: Upgraded.
l/python-cffi-2.1.0-x86_64-1.txz: Upgraded.
l/python-scikit-build-core-1.0.1-x86_64-1.txz: Upgraded.
l/rnnoise-0.2-x86_64-1.txz: Added.
Needed by mlt-7.40.0.
l/zxing-cpp-3.1.0-x86_64-1.txz: Upgraded.
n/postfix-3.11.5-x86_64-1.txz: Upgraded.
n/tftp-hpa-5.4-x86_64-1.txz: Upgraded.
This update fixes bugs and security issues:
Fix several security-relevant bugs in path validation
(tftpd/path.c): an uninitialized buffer read and a broken
path tokenizer could let a crafted or unlucky request bypass
path restrictions or crash the daemon.
Fix buffer overflows in the tftp client: an unbounded strcpy()
when building requests, an out-of-bounds write when putting
multiple files to a remote directory, and an unbounded write
into the interactive command-line argument array.
Fix an out-of-bounds read while scanning request fields in
tftpd, and an incorrect address family used when creating the
per-transfer socket on platforms without recvmsg().
(* Security fix *)
xap/vim-gvim-9.2.0782-x86_64-1.txz: Upgraded.