ChangeLog for: 2017-12-20 04:05:58

ap/pamixer-1.3.1-x86_64-5.txz: Rebuilt. Recompiled against boost-1.66.0. ap/vim-8.0.1415-x86_64-1.txz: Upgraded. d/meson-0.44.0-x86_64-1.txz: Upgraded. d/python3-3.6.4-x86_64-1.txz: Upgraded. d/ruby-2.4.3-x86_64-1.txz: Upgraded. This update fixes a security issue: Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the pipe character "|", the command following the pipe character is executed. The default value of localfile is File.basename(remotefile), so malicious FTP servers could cause arbitrary command execution. For more information, see: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17405 (* Security fix *) kde/calligra-2.9.11-x86_64-18.txz: Rebuilt. Recompiled against boost-1.66.0. kde/kig-4.14.3-x86_64-7.txz: Rebuilt. Recompiled against boost-1.66.0. l/LibRaw-0.18.6-x86_64-1.txz: Upgraded. l/akonadi-1.13.0-x86_64-8.txz: Rebuilt. Recompiled against boost-1.66.0. l/boost-1.66.0-x86_64-1.txz: Upgraded. Shared library .so-version bump. l/gmime-2.6.23-x86_64-2.txz: Upgraded. Revert to gmime-2 until the issues with pan are worked out. Nothing else in Slackware is using this library. l/lcms2-2.9-x86_64-1.txz: Upgraded. l/libogg-1.3.3-x86_64-1.txz: Upgraded. l/librsvg-2.40.20-x86_64-1.txz: Upgraded. l/pygobject-2.28.7-x86_64-1.txz: Upgraded. n/NetworkManager-1.10.2-x86_64-1.txz: Upgraded. n/gpgme-1.10.0-x86_64-1.txz: Upgraded. n/libassuan-2.5.1-x86_64-1.txz: Upgraded. n/libgcrypt-1.8.2-x86_64-1.txz: Upgraded. n/mutt-1.9.2-x86_64-1.txz: Upgraded. n/pinentry-1.1.0-x86_64-1.txz: Upgraded. xap/network-manager-applet-1.8.10-x86_64-1.txz: Upgraded. xap/pan-0.143-x86_64-3.txz: Rebuilt. Recompiled against gmime-2. xap/vim-gvim-8.0.1415-x86_64-1.txz: Upgraded. xfce/xfce4-notifyd-0.4.1-x86_64-1.txz: Upgraded. testing/packages/linux-4.14.7/kernel-generic-4.14.7-x86_64-1.txz: Upgraded. testing/packages/linux-4.14.7/kernel-headers-4.14.7-x86-1.txz: Upgraded. testing/packages/linux-4.14.7/kernel-huge-4.14.7-x86_64-1.txz: Upgraded. testing/packages/linux-4.14.7/kernel-modules-4.14.7-x86_64-1.txz: Upgraded. testing/packages/linux-4.14.7/kernel-source-4.14.7-noarch-1.txz: Upgraded. These sources have been patched with two patches that have been submitted upstream but have yet to appear in the mainline or stable kernels. With the patches applied this kernel seems stable now on both 32 and 64-bit x86. Thanks to Michele Ballabio for reporting the issue to the upstream kernel developers, and to Ming Lei for the fix. Once these patches appear in the 4.14.x kernel series (and barring any other major regressions), we'll be moving these kernels back into the main tree.