ChangeLog for: 2016-12-24 03:36:05
a/aaa_elflibs-14.2-x86_64-24.txz:  Rebuilt.
  Added libform.so.6.0, libformw.so.6.0, libhistory.so.7.0, libmenu.so.6.0,
  libmenuw.so.6.0, libncurses.so.6.0, libncursesw.so.6.0, libpanel.so.6.0,
  libpanelw.so.6.0, libreadline.so.7.0, and libtinfo.so.6.0.
l/libtermcap-1.2.3-x86_64-7.txz:  Removed.
  Replaced by equivalent functionality in the ncurses package.
l/ncurses-6.0-x86_64-1.txz:  Upgraded.
  Shared library .so-version bump.
  Rebuild of linked binaries pending, but the old library versions are
  in the aaa_elflibs package.
l/readline-7.0-x86_64-1.txz:  Upgraded.
  Shared library .so-version bump.
  Rebuild of linked binaries pending, but the old library versions are
  in the aaa_elflibs package.
n/curl-7.52.1-x86_64-1.txz:  Upgraded.
n/gpa-0.9.10-x86_64-1.txz:  Upgraded.
n/gpgme-1.7.1-x86_64-1.txz:  Upgraded.
n/httpd-2.4.25-x86_64-1.txz:  Upgraded.
  This update fixes the following security issues:
  * CVE-2016-8740: mod_http2: Mitigate DoS memory exhaustion via endless
    CONTINUATION frames.
  * CVE-2016-5387: core: Mitigate [f]cgi "httpoxy" issues.
  * CVE-2016-2161: mod_auth_digest: Prevent segfaults during client entry
    allocation when the shared memory space is exhausted.
  * CVE-2016-0736: mod_session_crypto: Authenticate the session data/cookie
    with a MAC (SipHash) to prevent deciphering or tampering with a padding
    oracle attack.
  * CVE-2016-8743: Enforce HTTP request grammar corresponding to RFC7230 for
    request lines and request headers, to prevent response splitting and
    cache pollution by malicious clients or downstream proxies.
  For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8740
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5387
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2161
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0736
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8743
  (* Security fix *)
n/lftp-4.7.4-x86_64-1.txz:  Upgraded.
n/libassuan-2.4.3-x86_64-1.txz:  Upgraded.
n/libgcrypt-1.7.5-x86_64-1.txz:  Upgraded.
n/libksba-1.3.5-x86_64-1.txz:  Upgraded.
n/nettle-3.3-x86_64-1.txz:  Upgraded.
n/nmap-7.40-x86_64-1.txz:  Upgraded.
n/openssh-7.4p1-x86_64-1.txz:  Upgraded.
  This is primarily a bugfix release, and also addresses security issues.
  ssh-agent(1): Will now refuse to load PKCS#11 modules from paths outside
    a trusted whitelist.
  sshd(8): When privilege separation is disabled, forwarded Unix-domain
    sockets would be created by sshd(8) with the privileges of 'root'.
  sshd(8): Avoid theoretical leak of host private key material to
    privilege-separated child processes via realloc().
  sshd(8): The shared memory manager used by pre-authentication compression
    support had a bounds checks that could be elided by some optimising
    compilers to potentially allow attacks against the privileged monitor.
    process from the sandboxed privilege-separation process.
  sshd(8): Validate address ranges for AllowUser and DenyUsers directives at
    configuration load time and refuse to accept invalid ones.  It was
    previously possible to specify invalid CIDR address ranges
    (e.g. user@127.1.2.3/55) and these would always match, possibly resulting
    in granting access where it was not intended.
  For more information, see:
    https://www.openssh.com/txt/release-7.4
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10009
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10010
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10011
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10012
  (* Security fix *)
n/pinentry-1.0.0-x86_64-1.txz:  Upgraded.
xfce/xfce4-weather-plugin-0.8.8-x86_64-1.txz:  Upgraded.
  Package upgraded to fix the API used to fetch weather data.
  Thanks to Robby Workman.
testing/packages/gcc-6.3.0-x86_64-1.txz:  Upgraded.
testing/packages/gcc-g++-6.3.0-x86_64-1.txz:  Upgraded.
testing/packages/gcc-gfortran-6.3.0-x86_64-1.txz:  Upgraded.
testing/packages/gcc-gnat-6.3.0-x86_64-1.txz:  Upgraded.
testing/packages/gcc-go-6.3.0-x86_64-1.txz:  Upgraded.
testing/packages/gcc-java-6.3.0-x86_64-1.txz:  Upgraded.
testing/packages/gcc-objc-6.3.0-x86_64-1.txz:  Upgraded.