From 90b9714d2f62f8500252c7f3f5281c0e3777541e Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Fri, 29 Mar 2024 02:25:21 +0000 Subject: Fri Mar 29 02:25:21 UTC 2024 a/coreutils-9.5-x86_64-1.txz: Upgraded. chmod -R now avoids a race where an attacker may replace a traversed file with a symlink, causing chmod to operate on an unintended file. [This bug was present in "the beginning".] split --line-bytes with a mixture of very long and short lines no longer overwrites the heap. For more information, see: https://www.cve.org/CVERecord?id=CVE-2024-0684 (* Security fix *) --- ChangeLog.rss | 23 +++++++++++++-- ChangeLog.txt | 11 ++++++++ FILELIST.TXT | 50 ++++++++++++++++----------------- source/a/coreutils/coreutils.SlackBuild | 1 + 4 files changed, 58 insertions(+), 27 deletions(-) diff --git a/ChangeLog.rss b/ChangeLog.rss index f201813d7..71b9df021 100644 --- a/ChangeLog.rss +++ b/ChangeLog.rss @@ -11,9 +11,28 @@ Tracking Slackware development in git. en-us urn:uuid:c964f45e-6732-11e8-bbe5-107b4450212f - Thu, 28 Mar 2024 21:40:08 GMT - Thu, 28 Mar 2024 22:48:21 GMT + Fri, 29 Mar 2024 02:25:21 GMT + Fri, 29 Mar 2024 03:01:33 GMT maintain_current_git.sh v 1.17 + + Fri, 29 Mar 2024 02:25:21 GMT + Fri, 29 Mar 2024 02:25:21 GMT + https://git.slackware.nl/current/tag/?h=20240329022521 + 20240329022521 + + +a/coreutils-9.5-x86_64-1.txz: Upgraded. + chmod -R now avoids a race where an attacker may replace a traversed file + with a symlink, causing chmod to operate on an unintended file. + [This bug was present in "the beginning".] + split --line-bytes with a mixture of very long and short lines no longer + overwrites the heap. + For more information, see: + https://www.cve.org/CVERecord?id=CVE-2024-0684 + (* Security fix *) + ]]> + + Thu, 28 Mar 2024 21:40:08 GMT Thu, 28 Mar 2024 21:40:08 GMT diff --git a/ChangeLog.txt b/ChangeLog.txt index 49d56fb2d..1483ea341 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -1,3 +1,14 @@ +Fri Mar 29 02:25:21 UTC 2024 +a/coreutils-9.5-x86_64-1.txz: Upgraded. + chmod -R now avoids a race where an attacker may replace a traversed file + with a symlink, causing chmod to operate on an unintended file. + [This bug was present in "the beginning".] + split --line-bytes with a mixture of very long and short lines no longer + overwrites the heap. + For more information, see: + https://www.cve.org/CVERecord?id=CVE-2024-0684 + (* Security fix *) ++--------------------------+ Thu Mar 28 21:40:08 UTC 2024 a/btrfs-progs-6.8-x86_64-1.txz: Upgraded. a/gpm-1.20.7-x86_64-10.txz: Rebuilt. diff --git a/FILELIST.TXT b/FILELIST.TXT index f207c2450..0d57141ad 100644 --- a/FILELIST.TXT +++ b/FILELIST.TXT @@ -1,20 +1,20 @@ -Thu Mar 28 21:45:22 UTC 2024 +Fri Mar 29 02:29:55 UTC 2024 Here is the file list for this directory. If you are using a mirror site and find missing or extra files in the disk subdirectories, please have the archive administrator refresh the mirror. -drwxr-xr-x 12 root root 4096 2024-03-28 21:40 . +drwxr-xr-x 12 root root 4096 2024-03-29 02:25 . -rw-r--r-- 1 root root 5767 2022-02-02 22:44 ./ANNOUNCE.15.0 -rw-r--r-- 1 root root 16617 2022-02-02 23:27 ./CHANGES_AND_HINTS.TXT --rw-r--r-- 1 root root 1147577 2024-03-27 19:21 ./CHECKSUMS.md5 --rw-r--r-- 1 root root 195 2024-03-27 19:21 ./CHECKSUMS.md5.asc +-rw-r--r-- 1 root root 1147560 2024-03-28 21:45 ./CHECKSUMS.md5 +-rw-r--r-- 1 root root 195 2024-03-28 21:45 ./CHECKSUMS.md5.asc -rw-r--r-- 1 root root 17976 1994-06-10 02:28 ./COPYING -rw-r--r-- 1 root root 35147 2007-06-30 04:21 ./COPYING3 -rw-r--r-- 1 root root 19573 2016-06-23 20:08 ./COPYRIGHT.TXT -rw-r--r-- 1 root root 616 2006-10-02 04:37 ./CRYPTO_NOTICE.TXT --rw-r--r-- 1 root root 1018688 2024-03-28 21:40 ./ChangeLog.txt +-rw-r--r-- 1 root root 1019173 2024-03-29 02:25 ./ChangeLog.txt drwxr-xr-x 3 root root 4096 2013-03-20 22:17 ./EFI drwxr-xr-x 2 root root 4096 2024-03-27 19:15 ./EFI/BOOT -rw-r--r-- 1 root root 1187840 2021-06-15 19:16 ./EFI/BOOT/bootx64.efi @@ -25,9 +25,9 @@ drwxr-xr-x 2 root root 4096 2024-03-27 19:15 ./EFI/BOOT -rwxr-xr-x 1 root root 2504 2019-07-05 18:54 ./EFI/BOOT/make-grub.sh -rw-r--r-- 1 root root 10722 2013-09-21 19:02 ./EFI/BOOT/osdetect.cfg -rw-r--r-- 1 root root 1273 2013-08-12 21:08 ./EFI/BOOT/tools.cfg --rw-r--r-- 1 root root 1502145 2024-03-27 19:20 ./FILELIST.TXT +-rw-r--r-- 1 root root 1502128 2024-03-28 21:45 ./FILELIST.TXT -rw-r--r-- 1 root root 1572 2012-08-29 18:27 ./GPG-KEY --rw-r--r-- 1 root root 906957 2024-03-28 21:44 ./PACKAGES.TXT +-rw-r--r-- 1 root root 906957 2024-03-29 02:29 ./PACKAGES.TXT -rw-r--r-- 1 root root 8034 2022-02-02 03:36 ./README.TXT -rw-r--r-- 1 root root 3629 2024-03-27 18:54 ./README.initrd -rw-r--r-- 1 root root 34114 2023-12-11 20:35 ./README_CRYPT.TXT @@ -683,13 +683,13 @@ drwxr-xr-x 2 root root 4096 2022-02-03 07:02 ./patches -rw-r--r-- 1 root root 575 2022-02-03 07:02 ./patches/FILE_LIST -rw-r--r-- 1 root root 14 2022-02-03 07:02 ./patches/MANIFEST.bz2 -rw-r--r-- 1 root root 224 2022-02-03 07:02 ./patches/PACKAGES.TXT -drwxr-xr-x 17 root root 4096 2024-03-28 21:45 ./slackware64 --rw-r--r-- 1 root root 353879 2024-03-28 21:45 ./slackware64/CHECKSUMS.md5 --rw-r--r-- 1 root root 195 2024-03-28 21:45 ./slackware64/CHECKSUMS.md5.asc --rw-r--r-- 1 root root 438264 2024-03-28 21:44 ./slackware64/FILE_LIST --rw-r--r-- 1 root root 4600350 2024-03-28 21:44 ./slackware64/MANIFEST.bz2 +drwxr-xr-x 17 root root 4096 2024-03-29 02:29 ./slackware64 +-rw-r--r-- 1 root root 353879 2024-03-29 02:29 ./slackware64/CHECKSUMS.md5 +-rw-r--r-- 1 root root 195 2024-03-29 02:29 ./slackware64/CHECKSUMS.md5.asc +-rw-r--r-- 1 root root 438264 2024-03-29 02:28 ./slackware64/FILE_LIST +-rw-r--r-- 1 root root 4602512 2024-03-29 02:28 ./slackware64/MANIFEST.bz2 lrwxrwxrwx 1 root root 15 2009-08-23 23:34 ./slackware64/PACKAGES.TXT -> ../PACKAGES.TXT -drwxr-xr-x 2 root root 32768 2024-03-28 21:43 ./slackware64/a +drwxr-xr-x 2 root root 32768 2024-03-29 02:28 ./slackware64/a -rw-r--r-- 1 root root 327 2022-02-15 18:16 ./slackware64/a/aaa_base-15.1-x86_64-2.txt -rw-r--r-- 1 root root 10720 2022-02-15 18:16 ./slackware64/a/aaa_base-15.1-x86_64-2.txz -rw-r--r-- 1 root root 163 2022-02-15 18:16 ./slackware64/a/aaa_base-15.1-x86_64-2.txz.asc @@ -723,9 +723,9 @@ drwxr-xr-x 2 root root 32768 2024-03-28 21:43 ./slackware64/a -rw-r--r-- 1 root root 477 2021-02-13 10:55 ./slackware64/a/bzip2-1.0.8-x86_64-3.txt -rw-r--r-- 1 root root 92456 2021-02-13 10:55 ./slackware64/a/bzip2-1.0.8-x86_64-3.txz -rw-r--r-- 1 root root 163 2021-02-13 10:55 ./slackware64/a/bzip2-1.0.8-x86_64-3.txz.asc --rw-r--r-- 1 root root 523 2023-08-29 18:25 ./slackware64/a/coreutils-9.4-x86_64-1.txt --rw-r--r-- 1 root root 2789448 2023-08-29 18:25 ./slackware64/a/coreutils-9.4-x86_64-1.txz --rw-r--r-- 1 root root 163 2023-08-29 18:25 ./slackware64/a/coreutils-9.4-x86_64-1.txz.asc +-rw-r--r-- 1 root root 523 2024-03-29 02:24 ./slackware64/a/coreutils-9.5-x86_64-1.txt +-rw-r--r-- 1 root root 2740308 2024-03-29 02:24 ./slackware64/a/coreutils-9.5-x86_64-1.txz +-rw-r--r-- 1 root root 195 2024-03-29 02:24 ./slackware64/a/coreutils-9.5-x86_64-1.txz.asc -rw-r--r-- 1 root root 487 2024-01-14 19:01 ./slackware64/a/cpio-2.15-x86_64-1.txt -rw-r--r-- 1 root root 252060 2024-01-14 19:01 ./slackware64/a/cpio-2.15-x86_64-1.txz -rw-r--r-- 1 root root 163 2024-01-14 19:01 ./slackware64/a/cpio-2.15-x86_64-1.txz.asc @@ -5777,11 +5777,11 @@ drwxr-xr-x 2 root root 4096 2023-03-08 20:34 ./slackware64/y -rw-r--r-- 1 root root 1491108 2023-02-19 18:31 ./slackware64/y/nethack-3.6.7-x86_64-1.txz -rw-r--r-- 1 root root 163 2023-02-19 18:31 ./slackware64/y/nethack-3.6.7-x86_64-1.txz.asc -rw-r--r-- 1 root root 26 2020-12-30 21:55 ./slackware64/y/tagfile -drwxr-xr-x 18 root root 4096 2024-03-28 21:45 ./source --rw-r--r-- 1 root root 616035 2024-03-28 21:45 ./source/CHECKSUMS.md5 --rw-r--r-- 1 root root 195 2024-03-28 21:45 ./source/CHECKSUMS.md5.asc --rw-r--r-- 1 root root 859078 2024-03-28 21:45 ./source/FILE_LIST --rw-r--r-- 1 root root 28449594 2024-03-28 21:45 ./source/MANIFEST.bz2 +drwxr-xr-x 18 root root 4096 2024-03-29 02:29 ./source +-rw-r--r-- 1 root root 616035 2024-03-29 02:29 ./source/CHECKSUMS.md5 +-rw-r--r-- 1 root root 195 2024-03-29 02:29 ./source/CHECKSUMS.md5.asc +-rw-r--r-- 1 root root 859078 2024-03-29 02:29 ./source/FILE_LIST +-rw-r--r-- 1 root root 28462063 2024-03-29 02:29 ./source/MANIFEST.bz2 -rw-r--r-- 1 root root 828 2022-02-02 04:43 ./source/README.TXT drwxr-xr-x 124 root root 4096 2024-03-27 19:50 ./source/a -rw-r--r-- 1 root root 339 2023-09-28 19:06 ./source/a/FTBFSlog @@ -5910,13 +5910,13 @@ drwxr-xr-x 2 root root 4096 2021-02-13 05:31 ./source/a/bzip2 -rw-r--r-- 1 root root 307 2019-07-14 19:00 ./source/a/bzip2/bzip2.saneso.diff.gz -rw-r--r-- 1 root root 32 2019-06-28 18:17 ./source/a/bzip2/bzip2.url -rw-r--r-- 1 root root 930 2018-02-27 06:13 ./source/a/bzip2/slack-desc -drwxr-xr-x 2 root root 4096 2023-08-29 18:25 ./source/a/coreutils +drwxr-xr-x 2 root root 4096 2024-03-29 01:28 ./source/a/coreutils -rw-r--r-- 1 root root 1735 2021-09-27 17:36 ./source/a/coreutils/DIR_COLORS.gz --rw-r--r-- 1 root root 5979200 2023-08-29 15:09 ./source/a/coreutils/coreutils-9.4.tar.xz --rw-r--r-- 1 root root 833 2023-08-29 15:09 ./source/a/coreutils/coreutils-9.4.tar.xz.sig +-rw-r--r-- 1 root root 6007136 2024-03-28 15:20 ./source/a/coreutils/coreutils-9.5.tar.xz +-rw-r--r-- 1 root root 833 2024-03-28 15:20 ./source/a/coreutils/coreutils-9.5.tar.xz.sig -rw-r--r-- 1 root root 633 2017-11-28 22:34 ./source/a/coreutils/coreutils-dircolors.csh.gz -rw-r--r-- 1 root root 754 2017-11-28 22:35 ./source/a/coreutils/coreutils-dircolors.sh.gz --rwxr-xr-x 1 root root 7892 2023-08-29 18:22 ./source/a/coreutils/coreutils.SlackBuild +-rwxr-xr-x 1 root root 7914 2024-03-29 02:03 ./source/a/coreutils/coreutils.SlackBuild -rw-r--r-- 1 root root 1522 2022-04-17 18:30 ./source/a/coreutils/coreutils.uname.diff.gz -rw-r--r-- 1 root root 212 2023-08-29 18:25 ./source/a/coreutils/coreutils.wc.noavx2.diff.gz -rw-r--r-- 1 root root 327 2016-01-29 19:35 ./source/a/coreutils/doinst.sh.gz diff --git a/source/a/coreutils/coreutils.SlackBuild b/source/a/coreutils/coreutils.SlackBuild index 3d655f996..4805aa315 100755 --- a/source/a/coreutils/coreutils.SlackBuild +++ b/source/a/coreutils/coreutils.SlackBuild @@ -129,6 +129,7 @@ DEFAULT_POSIX2_VERSION=199209 \ --libdir=/usr/lib${LIBDIRSUFFIX} \ --enable-install-program=arch \ --with-openssl=no \ + --enable-year2038 \ --build=$ARCH-slackware-linux || exit 1 make $NUMJOBS || make || exit 1 -- cgit v1.2.3-65-gdbad