Author: ken
Date: Thu Apr 1 16:46:06 2021
New Revision: 1785
Log:
Advisories: change markup to remove <b> and <i>.
Modified:
html/trunk/blfs/advisories/10.0.html
html/trunk/blfs/advisories/10.1.html
html/trunk/blfs/advisories/consolidated.html
html/trunk/lfs/advisories/10.0.html
html/trunk/lfs/advisories/10.1.html
Modified: html/trunk/blfs/advisories/10.0.html
==============================================================================
--- html/trunk/blfs/advisories/10.0.html Thu Apr 1 12:13:44 2021
(r1784)
+++ html/trunk/blfs/advisories/10.0.html Thu Apr 1 16:46:06 2021
(r1785)
@@ -17,8 +17,8 @@
<a id="BLFS10.0"/>
<p>BLFS-10.0 was released on 2020-09-01</p>
- <p><i>This page is in alphabetical order of packages, and if a package has
- multiple advisories the newer come first.</i></p>
+ <p style="font-style: italic;">This page is in alphabetical order of
packages,
+ and if a package has multiple advisories the newer come first.</p>
<p> The links at the end of each item point to fuller details which have
links to the
@@ -200,7 +200,7 @@
<h4>10.0 079 Glib Date: 2021-02-04 Severity: High</h4>
<p>Glib before 2.66.6 was vulnerable to integer truncation leading to
potentially exploitable heap-overflow vulnerabilities. The issue was
- raised in a <i>public</i> report, so this is now classed as a zero-day
+ raised in a <em>public</em> report, so this is now classed as a zero-day
vulnerability requiring urgent update to Glib-2.66.1 or later.
<a href="consolidated.html#sa-10.0-079">10.0-079</a></p>
@@ -689,10 +689,10 @@
<h3>Thunderbird</h3>
<!-- to save putting this in each thunderbird advisory: -->
- <p><i>In general, flaws in Mozilla advisories for Thunderbird cannot be
- exploited through email in the Thunderbird product because scripting is
- disabled when reading mail, but are potentially risks in browser or
- browser-like contexts.</i></p>
+ <p style="font-style: italic;">In general, flaws in Mozilla advisories for
+ Thunderbird cannot be exploited through email in the Thunderbird product
+ because scripting is disabled when reading mail, but are potentially risks
+ in browser or browser-like contexts.</p>
<a id="sa-10.0-100"/>
<h4>10.0 100 Thunderbird Date: 2021-02-24 Severity: High</h4>
@@ -819,14 +819,14 @@
<h4>10.0 048 Xorg-Server Date: 2020-12-05 Severity: High</h4>
<p>In Xorg-Server before version 1.20.10 two input validation failures
in X server extensions were found. These can lead to local privilege
- escalations (to root) <b>if the X server is running privileged</b>.
+ escalations (to root) <em>if the X server is running privileged</em>.
Update to Xorg-Server-1.20.10 or later.
<a href="consolidated.html#sa-10.0-048">10.0-048</a></p>
<h4>10.0 002 Xorg-Server Date: 2020-09-03 Severity: High</h4>
<p>In Xorg-Server before version 1.20.9 several input validation failures
in X server extensions were found. These can lead to local privilege
- escalations (to root) <b>if the X server is running privileged</b>.
+ escalations (to root) <em>if the X server is running privileged</em>.
Update to Xorg-Server-1.20.9 or later.
<a href="consolidated.html#sa-10.0-002">10.0-002</a></p>
Modified: html/trunk/blfs/advisories/10.1.html
==============================================================================
--- html/trunk/blfs/advisories/10.1.html Thu Apr 1 12:13:44 2021
(r1784)
+++ html/trunk/blfs/advisories/10.1.html Thu Apr 1 16:46:06 2021
(r1785)
@@ -17,8 +17,8 @@
-->
<!-- Editors: do the consolidated file first, to get the next number -->
- <p><i>This page is in alphabetical order of packages, and if a package has
- multiple advisories the newer come first.</i></p>
+ <p style="font-style: italic;">This page is in alphabetical order of
packages,
+ and if a package has multiple advisories the newer come first.</p>
<p> The links at the end of each item point to fuller details which have
links to the
@@ -172,10 +172,10 @@
<h3>Thunderbird</h3>
<!-- to save putting this in each thunderbird advisory: -->
- <p><i>In general, flaws in Mozilla advisories for Thunderbird cannot be
- exploited through email in the Thunderbird product because scripting is
- disabled when reading mail, but are potentially risks in browser or
- browser-like contexts.</i></p>
+ <p style="font-style: italic;">In general, flaws in Mozilla advisories for
+ Thunderbird cannot be exploited through email in the Thunderbird product
+ because scripting is disabled when reading mail, but are potentially risks
+ in browser or browser-like contexts.</p>
<a id="sa-10.1-012"/>
<h4>10.1 012 Thunderbird Date: 2021-02-26 Severity: High</h4>
Modified: html/trunk/blfs/advisories/consolidated.html
==============================================================================
--- html/trunk/blfs/advisories/consolidated.html Thu Apr 1 12:13:44
2021 (r1784)
+++ html/trunk/blfs/advisories/consolidated.html Thu Apr 1 16:46:06
2021 (r1785)
@@ -15,7 +15,7 @@
mostly updating them to point to the latest version in the development book
and updating the brief text if a subsequent vulnerability was reported.</p>
- <p><b>This page is a consolidated list for both LFS and BLFS.</b></p>
+ <p><em>This page is a consolidated list for both LFS and BLFS.</em></p>
<p>This list contains summary details and links to upstreams or CVEs where
available. Please note that vulnerabilities to package versions before
those
@@ -23,8 +23,8 @@
before 10.0 you should check the Errata for past releases as well as
monitoring the items here.</p>
- <p><i>This page is ordered like the Changelog of the books, with newest
- items first.</i></p>
+ <p style="font-style: italic;">This page is ordered like the Changelog of
the
+ books, with newest items first.</p>
<p>The severity ratings are best estimates unless either upstream
or NVD has assigned a rating. If no other analysis is available,
@@ -670,11 +670,11 @@
Red Hat this can be worked around by not processing untrusted input in this
encoding:
<a href="https://access.redhat.com/security/cve/cve-2021-3326">Red
Hat</a>.</p>
- <p>To fix these, build a new version of LFS. <i>If you have usable backups
and
+ <p>To fix these, build a new version of LFS. <em>If you have usable
backups and
have tested a way to restore them via a rescue stick or similar, it might
be
possible to build glibc-2.33 in place and then immediately make an unclean
- shutdown, e.g. using MagicSysRQ if that is enabled in your kernel. <b>Such
a
- procedure is not recommended, nor has it been tested.</b></i></p>
+ shutdown, e.g. using MagicSysRQ if that is enabled in your kernel. Such a
+ procedure is not recommended, nor has it been tested.</em></p>
<a id="sa-10.0-081"/>
<h4>10.0 081 Firefox UpDated: 2021-02-07 Severity: None</h4>
@@ -705,7 +705,7 @@
<h4>10.0 079 Glib Date: 2021-02-04 Severity: High</h4>
<p>Glib before 2.66.6 was vulnerable to integer truncation leading to
potentially exploitable heap-overflow vulnerabilities. The issue was
- raised in a <i>public</i> report, so this is now classed as a zero-day
+ raised in a <em>public</em> report, so this is now classed as a zero-day
vulnerability requiring urgent update.
<a
href="https://gitlab.gnome.org/GNOME/glib/-/issues/2319">GHSL-2021-045</a>
.</p>
@@ -1406,18 +1406,18 @@
.</p>
<p>On systems running Gstreamer 1.16 versions, such as BLFS-10.0, update
to the
gstreamer-1.16.3 packages (gstreamer, -libav, -plugins, -vaapi) using the
instructions
- from the BLFS-10.0 book:
+ from the BLFS-10.0 book for
<a href="../view/10.0/multimedia/gstreamer10.html">Gstreamer 1.16
(sysv)</a>
- <i>et seq.</i> or
+ and the rest of the stack, or
<a href="../view/10.0-systemd/multimedia/gstreamer10.html">Gstreamer 1.16
(systemd)</a>
- <i> et seq.</i></p>
+ and the rest of the stack.</p>
<p>On systems running Gstreamer 1.18 versions, update to the
gstreamer-1.18.1 or later packages (gstreamer, -libav, -plugins, -vaapi)
using the instructions for
- <a href="../view/10.1/multimedia/gstreamer10.html">Gstreamer 1.18
(sysv)</a>i
- <i>et seq.</i> or
+ <a href="../view/10.1/multimedia/gstreamer10.html">Gstreamer 1.18
(sysv)</a>
+ and the rest of the stack, or
<a href="../view/10.1-systemd/multimedia/gstreamer10.html">Gstreamer 1.18
(systemd)</a>
- <i> et seq.</i></p>
+ and the rest of the stack.</p>
<a id="sa-10.0-025"/>
<h4>10.0 025 Thunderbird Date: 2020-10-23 Severity: High</h4>
Modified: html/trunk/lfs/advisories/10.0.html
==============================================================================
--- html/trunk/lfs/advisories/10.0.html Thu Apr 1 12:13:44 2021 (r1784)
+++ html/trunk/lfs/advisories/10.0.html Thu Apr 1 16:46:06 2021 (r1785)
@@ -16,8 +16,8 @@
<a id="LFS10.0"/>
<p>LFS-10.0 was released on 2020-09-01</p>
- <p><i>This page is in alphabetical order of packages, and if a package has
- multiple advisories the newer come first.</i></p>
+ <p style="font-style: italic;">This page is in alphabetical order of
packages,
+ and if a package has multiple advisories the newer come first.</p>
<p> The links at the end of each item point to fuller details which have
links to the
@@ -43,7 +43,8 @@
<h3>Glibc</h3>
- <p><i>In LFS the only safe way to update Glibc is to build a new
system.</i></p>
+ <p style="font-style: italic;">In LFS the only safe way to update Glibc is
to
+ build a new system.</p>
<h4>10.0 082 (LFS) GLIBC Date: 2021-02-07 Severity: High</h4>
@@ -84,12 +85,12 @@
<p>Python-3.9.2 contains fixes for a critical security vulnerability as
well
as a medium-level security vulnerability. The critical vulnerability can
lead to remote code execution. Update to Python-3.9.2 or later
- <i>using the BLFS instructions</i>.
+ <em>using the BLFS instructions</em>.
<a
href="../../blfs/advisories/consolidated.html#sa-10.0-097">10.0-097</a></p>
<h4>10.0 051 Python (LFS and BLFS) Date: 2020-12-15 Severity: High</h4>
<p>Python-3.9.1 includes three security fixes. Update to Python-3.9.1
- or later <i>using the BLFS instructions</i>.
+ or later <em>using the BLFS instructions</em>.
<a
href="../../blfs/advisories/consolidated.html#sa-10.0-051">10.0-051</a></p>
<!-- End of Python -->
Modified: html/trunk/lfs/advisories/10.1.html
==============================================================================
--- html/trunk/lfs/advisories/10.1.html Thu Apr 1 12:13:44 2021 (r1784)
+++ html/trunk/lfs/advisories/10.1.html Thu Apr 1 16:46:06 2021 (r1785)
@@ -19,8 +19,8 @@
in the directory where you put the books' html so that you can see
the LFS and BLFS advisories in your browser. -->
- <p><i>This page is in alphabetical order of packages, and if a package has
- multiple advisories the newer come first.</i></p>
+ <p style="font-style: italic;">This page is in alphabetical order of
packages,
+ and if a package has multiple advisories the newer come first.</p>
<p> The links at the end of each item point to fuller details which have
links to the
@@ -66,7 +66,8 @@
rebuilfding
<h3>Glibc</h3>
- <p><i>In LFS the only safe way to update Glibc is to build a new
system.</i></p>
+ <p style="font-style: italic;">In LFS the only safe way to update Glibc is
to
+ build a new system.</p>
<h4>10.1 NNN (LFS) GLIBC Date: 2021-02-07 Severity: High</h4>
--
http://lists.linuxfromscratch.org/listinfo/website
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page