Monday, February 5, 2018
[USN-3550-2] ClamAV vulnerabilities
Ubuntu Security Notice USN-3550-2
February 05, 2018
clamav vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 ESM
Summary:
Several security issues were fixed in ClamAV.
Software Description:
- clamav: Anti-virus utility for Unix
Details:
USN-3550-1 fixed several vulnerabilities in ClamAV. This update
provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that ClamAV incorrectly handled parsing certain mail
messages. A remote attacker could use this issue to cause ClamAV to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2017-12374, CVE-2017-12375, CVE-2017-12379, CVE-2017-12380)
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2017-12376)
It was discovered that ClamAV incorrectly handled parsing certain mew
packet files. A remote attacker could use this issue to cause ClamAV
to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2017-12377)
It was discovered that ClamAV incorrectly handled parsing certain TAR
files. A remote attacker could possibly use this issue to cause ClamAV
to crash, resulting in a denial of service. (CVE-2017-12378)
In the default installation, attackers would be isolated by the ClamAV
AppArmor profile.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 ESM:
clamav 0.99.3+addedllvm-0ubuntu0.12.04.1
This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
References:
https://www.ubuntu.com/usn/usn-3550-2
https://www.ubuntu.com/usn/usn-3550-1
CVE-2017-12374, CVE-2017-12375, CVE-2017-12376, CVE-2017-12377,
CVE-2017-12378, CVE-2017-12379, CVE-2017-12380
Friday, February 2, 2018
OpenBSD Errata: February 2nd, 2018 (kernel)
OpenBSD 6.2 and 6.1.
Specially crafted IPsec AH packets with IP options or IPv6 extension
headers could cause a crash or hang.
Processing IPv6 fragments could incorrectly access memory of an mbuf
chain that is not within an mbuf, which may cause a crash.
If the EtherIP tunnel protocol was disabled, IPv6 packets were not
discarded properly, which causes a double free.
Binary updates for the amd64, i386, and arm64 platforms are available via
the syspatch utility. Source code patches can be found on the respective
errata pages:
https://www.openbsd.org/errata61.html
https://www.openbsd.org/errata62.html
As these affect the kernel, a reboot will be needed after patching.
[Guidelines change] Changes to the packaging guidelines
The Scriptlet guidelines have received several changes regarding the
installation of shared libraries and ldconfig. Use of the new macros
is detailed, and there is a new section on the scriptlets required when
linker configuration files are installed.
* https://fedoraproject.org/wiki/Packaging:Guidelines#Shared_Libraries
* https://fedoraproject.org/wiki/Packaging:Scriptlets#Shared_Libraries
* https://pagure.io/packaging-committee/issue/654
Please note the following before attempting to use the new macros
outside of rawhide builds:
1) The updates for F27 (redhat-rpm-config-70.1.fc27) and F26
(redhat-rpm-cponfig-64.1.fc26) which provide the new macros are
currently on their way to stable and will hopefully be generally
available in a day or so.
2) The epel-rpm-macros updates for EPEL7 and EPEL6, which provide the
new macros for those EPEL releases, are in the testing repositories
and need more karma before they can be pushed to stable:
* https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-c5ae067f71
* https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-580a31cb75
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Orphaned packages seeking new point of contact
iQIzBAEBCgAdFiEESz7rprBJHpbnMnrQSzew2A/7u14FAlp0rsEACgkQSzew2A/7
u17knw//ewJgqaSMSxr1HcsXWEJqxq9dliNVbRKu/p1heR+pGLo06OrLpOKd3565
isair4iQB1MxlTPXexGBkXsrViR6KY8JY1HsLiUsk1iBxgh6CbjQ/bCsHW1bgYiO
1bvcp47vq41vFflxuTEUx4Dl4Ui0oflyFQLMu9A+rxZKudIauLC9xG0vSpYUQVFB
toK/Nf7Eh3IqB8rmIlxCOCzfcT2MZaPJs7Gh1sPiuk9usWKXnv3tIU9s5Yu8uUxo
RXwsp1vA2sx0gfp7sc/1TAV34R78/CJZTHJqwHVfk0VuS07+nca58bTI4wMeTzHv
+r78qqRrZY7F5DvPDmFO4gcU93a7ReDz6jHGczm4OiW2iV0n/fxhElRn3/Vs19je
YhsgiNwbkZG9d1d2BvUbUeRKAf6FKGjWr2MbeC6REoIEDbXpi4ofRBDW9o/Ej+bE
c5KWL56+AId7RWg9YyB5sWsKbcp5IIe7Q24yzTL3sDGvISGZwJvA2G9Bq+Rk8DeS
sSDEMrExIZG2B/s/IYtRSCTM6znlfELXQSN6fI9MMnvjLrtqIz1LVSkzU8mKWkyY
EjbB9Bb67wq4qO3qaO84vYznxLgTuJIMmyJRFWgZFZRG90t7PBoENt18L2D3CQ6I
rqVbtuTAQHehUB7GnxLHbM4WTLrLe7gWSj2eMX2OTeoXyhBUBH8=
=/k0p
-----END PGP SIGNATURE-----
Greetings.
There's some packages that have been orphaned by FESCo and are seeking a
new point of contact to stay in the collection.
If you are interested in becoming the point of contact for these, please
note it in the appropriate ticket below for quickest processing.
(no need to reopen the ticket, just add your fas name and what packages
you want to take)
https://pagure.io/fesco/issue/1801
rpms/fotowall
rpms/monkeystudio
rpms/posterazor
https://pagure.io/fesco/issue/1836
rpms/minion
rpms/pastebinit
rpms/tlomt-orbitron-fonts
https://pagure.io/releng/issue/7173
rpms/cclive
rpms/cdm
rpms/faience-icon-theme
rpms/fbset
rpms/freedoom
rpms/freedoom-freedm
rpms/freehoo
rpms/getdata
rpms/gpm
rpms/gqview
rpms/hddtemp
rpms/iniparser
rpms/knapsen
rpms/ldd-pdf
rpms/libcryptui
rpms/npush
rpms/phatch
rpms/photoprint
rpms/prboom
rpms/prboom-plus
rpms/preload
rpms/pulseaudio-equalizer
rpms/PySolFC
rpms/PySolFC-cardsets
rpms/PySolFC-music
rpms/remind
rpms/sap
rpms/sipcalc
rpms/sudoku-savant
rpms/tong
rpms/tuxcmd
rpms/xcftools
rpms/yadex
rpms/yafc
Thanks,
kevin
Thursday, February 1, 2018
[CentOS-announce] CESA-2018:0262 Important CentOS 6 thunderbird Security Update
Upstream details at : https://access.redhat.com/errata/RHSA-2018:0262
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
4c5faa32a2ce2a7945e7e58a31c90a29f5c8bbc1522299ca8074ff0b179fe244 thunderbird-52.6.0-1.el6.centos.i686.rpm
x86_64:
4f97f078cdf9f020ebc5cad99100a54f18bb74b23673f8226fb77763320cebc8 thunderbird-52.6.0-1.el6.centos.x86_64.rpm
Source:
27aefaa5049fbe2eae663bca4d17c93281223bdae48cf918b774ee2ad6d7fec3 thunderbird-52.6.0-1.el6.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2018:0262 Important CentOS 7 thunderbird Security Update
Upstream details at : https://access.redhat.com/errata/RHSA-2018:0262
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
c5a42870fd0dbb44e82f8030a889a0bdf8cb2f8b1becb9d49763070d47820ff0 thunderbird-52.6.0-1.el7.centos.x86_64.rpm
Source:
92c034d0d0f6895453c4e371841d78a5bfdedb11df63cf21a1d1c341c5216f35 thunderbird-52.6.0-1.el7.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2018:0260 Moderate CentOS 7 systemd Security Update
Upstream details at : https://access.redhat.com/errata/RHSA-2018:0260
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
a7ff6697cba768a37cfbf5b08cd4fea42887544e64fa81d652726fac42328c22 libgudev1-219-42.el7_4.7.i686.rpm
ae8a35516e4db15022c7bdf3dc7fb17d565c3566bfe0598e9e83fd79f7bcb78e libgudev1-219-42.el7_4.7.x86_64.rpm
387700a80d251f5fd2c4ed4f4d6be0c0dd31cd13218034b7bee995602965c794 libgudev1-devel-219-42.el7_4.7.i686.rpm
b1e7c83f256176b876f5f9df330e2c97011efd1e301c8e2b8bd6951479f9fced libgudev1-devel-219-42.el7_4.7.x86_64.rpm
b048c461c24df985cf5d3daa80c79fddfd435b01c81ece0543b8f6e44902b3c2 systemd-219-42.el7_4.7.x86_64.rpm
5b8a7713fe41db817ca9e7d734f9fc7e3e9bb2c751317adec9129529b1a3a711 systemd-devel-219-42.el7_4.7.i686.rpm
df475636c40dff17bb76c95952b1a84df70234ce6164ec5d8d6e0622c18a26de systemd-devel-219-42.el7_4.7.x86_64.rpm
8b0f6580d8ac768bb2bdd2d3fea37471c12f69622070c028c6654a67d9ed62ba systemd-journal-gateway-219-42.el7_4.7.x86_64.rpm
39996be3a24fea93dd74b3858e849bd13d42b3618933646c014999301f74c989 systemd-libs-219-42.el7_4.7.i686.rpm
d7ba060ecee893b2e60d18394899768fe93a9199a3eba7eb0e2b2942a4d5b03f systemd-libs-219-42.el7_4.7.x86_64.rpm
efe57fcbf99513a07140cb9ab10780cc416bbc0a3fa51775fb628331ee99910a systemd-networkd-219-42.el7_4.7.x86_64.rpm
ccff4b016165af8c211c4ff5c0dd2668498487130c7a18da188281f0b8c2fcac systemd-python-219-42.el7_4.7.x86_64.rpm
6179b555b0aea983902a99e83a2e2687ef6cdba897e8fe804c9c860f36fa1642 systemd-resolved-219-42.el7_4.7.i686.rpm
73889e7ca81e3d4f6c918e5c7928ab47927f227a833a20821a2f9f994e393d80 systemd-resolved-219-42.el7_4.7.x86_64.rpm
4669da503e9376fc14044bd230db80452c595c09c439dc769d92b6844b4a5488 systemd-sysv-219-42.el7_4.7.x86_64.rpm
Source:
6857f944bb775fce5c2ec5942d5b9bbff74b3ac0d7466b4b0d2c10ed5c6e898a systemd-219-42.el7_4.7.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
[USN-3556-2] Dovecot vulnerabilities
Ubuntu Security Notice USN-3556-2
February 01, 2018
dovecot vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 ESM
Summary:
Several security issues were fixed in Dovecot.
Software Description:
- dovecot: IMAP and POP3 email server
Details:
USN-3556-1 fixed vulnerabilities in Dovecot. This update
provides the corresponding update for Ubuntu 12.04 ESM.
It was discovered that Dovecot incorrectly handled certain
authentications. An attacker could possibly use this to bypass
authentication and access sensitive information. (CVE-2013-6171)
Original advisory details:
It was discovered that Dovecot incorrectly handled certain
authentications.
An attacker could possibly use this to cause a denial of service.
(CVE-2017-15132)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 ESM:
dovecot-core 1:2.0.19-0ubuntu2.4
In general, a standard system update will make all the necessary
changes.
References:
https://www.ubuntu.com/usn/usn-3556-2
https://www.ubuntu.com/usn/usn-3556-1
CVE-2013-6171, CVE-2017-15132
[USN-3556-1] Dovecot vulnerability
Ubuntu Security Notice USN-3556-1
February 01, 2018
dovecot vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 17.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Dovecot could be made to crash if it received specially crafted input.
Software Description:
- dovecot: IMAP and POP3 email server
Details:
It was discovered that Dovecot incorrectly handled certain
authentications. An attacker could possibly use this to cause a denial
of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 17.10:
dovecot-core 1:2.2.27-3ubuntu1.2
Ubuntu 16.04 LTS:
dovecot-core 1:2.2.22-1ubuntu2.6
Ubuntu 14.04 LTS:
dovecot-core 1:2.2.9-1ubuntu2.3
In general, a standard system update will make all the necessary
changes.
References:
https://www.ubuntu.com/usn/usn-3556-1
CVE-2017-15132
Package Information:
https://launchpad.net/ubuntu/+source/dovecot/1:2.2.27-3ubuntu1.2
https://launchpad.net/ubuntu/+source/dovecot/1:2.2.22-1ubuntu2.6
https://launchpad.net/ubuntu/+source/dovecot/1:2.2.9-1ubuntu2.3
[USN-3555-2] w3m vulnerabilities
Ubuntu Security Notice USN-3555-2
February 01, 2018
w3m vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 ESM
Summary:
Several security issues were fixed in w3m.
Software Description:
- w3m: WWW browsable pager with excellent tables/frames support
Details:
USN-3555-2 fixed vulnerabilities in w3m. This update
provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that w3m incorrectly handled certain inputs.
An attacker could possibly use this to cause a denial of service.
(CVE-2018-6196, CVE-2018-6197)
It was discovered that w3m incorrectly handled temporary files.
An attacker could possibly use this to overwrite arbitrary files.
(CVE-2018-6198)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 ESM:
w3m 0.5.3-5ubuntu1.3
In general, a standard system update will make all the necessary
changes.
References:
https://www.ubuntu.com/usn/usn-3555-2
https://www.ubuntu.com/usn/usn-3555-1
CVE-2018-6196, CVE-2018-6197, CVE-2018-6198
[USN-3555-1] w3m vulnerabilities
Ubuntu Security Notice USN-3555-1
February 01, 2018
w3m vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 17.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in w3m.
Software Description:
- w3m: WWW browsable pager with excellent tables/frames support
Details:
It was discovered that w3m incorrectly handled certain inputs.
An attacker could possibly use this to cause a denial of service.
(CVE-2018-6196, CVE-2018-6197)
It was discovered that w3m incorrectly handled temporary files.
An attacker could possibly use this to overwrite arbitrary files.
(CVE-2018-6198)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 17.10:
w3m 0.5.3-34ubuntu0.1
Ubuntu 16.04 LTS:
w3m 0.5.3-26ubuntu0.2
Ubuntu 14.04 LTS:
w3m 0.5.3-15ubuntu0.2
In general, a standard system update will make all the necessary
changes.
References:
https://www.ubuntu.com/usn/usn-3555-1
CVE-2018-6196, CVE-2018-6197, CVE-2018-6198
Package Information:
https://launchpad.net/ubuntu/+source/w3m/0.5.3-34ubuntu0.1
https://launchpad.net/ubuntu/+source/w3m/0.5.3-26ubuntu0.2
https://launchpad.net/ubuntu/+source/w3m/0.5.3-15ubuntu0.2
lists.linuxfromscratch.org mailing list memberships reminder
lists.linuxfromscratch.org mailing list memberships. It includes your
subscription info and how to use it to change it or unsubscribe from a
list.
You can visit the URLs to change your membership status or
configuration, including unsubscribing, setting digest-style delivery
or disabling delivery altogether (e.g., for a vacation), and so on.
In addition to the URL interfaces, you can also use email to make such
changes. For more info, send a message to the '-request' address of
the list (for example, mailman-request@lists.linuxfromscratch.org)
containing just the word 'help' in the message body, and an email
message will be sent to you with instructions.
If you have questions, problems, comments, etc, send them to
mailman-owner@lists.linuxfromscratch.org. Thanks!
Passwords for reallost1.fbsd2233449@blogger.com:
List Password // URL
---- --------
lfs-announce@lists.linuxfromscratch.org vaozebru
http://lists.linuxfromscratch.org/options/lfs-announce/reallost1.fbsd2233449%40blogger.com