ChangeLog for: 2016-03-18 21:02:40
d/git-2.7.4-x86_64-1.txz: Upgraded.
NOTE: Issuing this patch again since the bug reporter listed the
wrong git version (2.7.1) as fixed. The vulnerability was actually
patched in git-2.7.4.
Fixed buffer overflows allowing server and client side remote code
execution in all git versions before 2.7.4.
For more information, see:
http://seclists.org/oss-sec/2016/q1/645
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2315
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2324
(* Security fix *)
xap/hexchat-2.12.0-x86_64-1.txz: Upgraded.
xap/mozilla-thunderbird-38.7.0-x86_64-1.txz: Upgraded.
This update contains security fixes and improvements.
For more information, see:
http://www.mozilla.org/security/known-vulnerabilities/thunderbird.html
(* Security fix *)
extra/bash-completion/bash-completion-2.2-noarch-2.txz: Rebuilt.
Applied upstream patches to fix tar filename completion and related issues.
Thanks to Robby Workman.