ChangeLog for: 2016-05-11 06:20:01

a/dcron-4.5-x86_64-5.txz: Rebuilt. Patched bug where cron.update is not picked up while jobs are still running. Thanks to Jeroen Hendriks. ap/lxc-2.0.0-x86_64-4.txz: Rebuilt. Applied "[PATCH] cgfsng: don't require that systemd subsystem be mounted". Thanks to Johannes Schöpfer. ap/moc-2.5.1-x86_64-1.txz: Upgraded. ap/slackpkg-2.82.1-noarch-1.txz: Upgraded. Updated x86* mirrors lists for Slackware 14.2. n/openvpn-2.3.11-x86_64-1.txz: Upgraded. x/mesa-11.2.2-x86_64-1.txz: Upgraded. xap/imagemagick-6.9.4_1-x86_64-1.txz: Upgraded. This release addresses several security issues in ImageMagick, including: Insufficient shell characters filtering allows code execution (CVE-2016-3714) Server Side Request Forgery (CVE-2016-3718) File deletion (CVE-2016-3715) File moving (CVE-2016-3716) Local file read (CVE-2016-3717) In addition, the default policy.xml config file has been modified to disable all of the previously vulnerable coders, and to disable indirect reads. For more information, see: https://imagetragick.com http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3714 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3718 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3715 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3716 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3717 (* Security fix *)