ChangeLog for: 2016-05-17 22:52:11
a/aaa_elflibs-14.2-x86_64-14.txz: Rebuilt.
d/mercurial-3.8.2-x86_64-1.txz: Upgraded.
l/gdbm-1.12-x86_64-1.txz: Upgraded.
l/libmtp-1.1.11-x86_64-1.txz: Upgraded.
n/libndp-1.6-x86_64-1.txz: Upgraded.
This update fixes a security issue. It was found that libndp did
not properly validate and check the origin of Neighbor Discovery
Protocol (NDP) messages. An attacker on a non-local network could
use this flaw to advertise a node as a router, allowing them to
perform man-in-the-middle attacks on a connecting client, or
disrupt the network connectivity of that client.
Thanks to Julien Bernard (Viagénie) for reporting this issue.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3698
(* Security fix *)
xap/gnuplot-5.0.3-x86_64-2.txz: Rebuilt.
Added libcaca support. Thanks to Andrew Clemons.