From 08c68c550550eccbecbf7a50c7efbae69122c861 Mon Sep 17 00:00:00 2001 From: Ondrej Holy Date: Wed, 19 Jun 2019 09:34:22 +0200 Subject: Update NEWS for 1.41.3 release --- NEWS | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/NEWS b/NEWS index 491bb79c..1d5b9c53 100644 --- a/NEWS +++ b/NEWS @@ -1,3 +1,13 @@ +Major changes in 1.41.3 +======================= +* daemon: Only accept EXTERNAL authentication (CVE-2019-12795) +* daemon: Check that the connecting client is the same user (CVE-2019-12795) +* admin: Ensure correct ownership when moving to file:// uri (CVE-2019-12449) +* admin: Use fsuid to ensure correct file ownership (CVE-2019-12447) +* admin: Allow changing file owner (CVE-2019-12447) +* admin: Add query_info_on_read/write functionality (CVE-2019-12448) +* Translation updates + Major changes in 1.41.2 ======================= * build: Several meson improvements -- cgit v1.2.1