-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
=============================================================================
FreeBSD-EN-18:06.tzdata Errata Notice
The FreeBSD Project
Topic: Timezone database information update
Category: contrib
Module: zoneinfo
Announced: 2018-05-08
Credits: Philip Paeps
Affects: All supported versions of FreeBSD.
Corrected: 2018-05-07 06:58:19 UTC (stable/11, 11.2-PRERELEASE)
2018-05-08 17:18:24 UTC (releng/11.1, 11.1-RELEASE-p10)
2018-05-07 07:02:26 UTC (stable/10, 10.4-STABLE)
2018-05-08 17:18:24 UTC (releng/10.4, 10.4-RELEASE-p9)
For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.
I. Background
The tzsetup(8) program allows the user to specify the default local timezone.
Based on the selected timezone, tzsetup(8) copies one of the files from
/usr/share/zoneinfo to /etc/localtime. This file actually controls the
conversion.
II. Problem Description
Several changes in Daylight Savings Time happened after previous FreeBSD
releases were released that would affect many people who live in different
countries. Because of these changes, the data in the zoneinfo files need to
be updated, and if the local timezone on the running system is affected,
tzsetup(8) needs to be run so the /etc/localtime is updated.
III. Impact
An incorrect time will be displayed on a system configured to use one of the
affected timezones if the /usr/share/zoneinfo and /etc/localtime files are
not updated, and all applications on the system that rely on the system time,
such as cron(8) and syslog(8), will be affected.
IV. Workaround
The system administrator can install an updated timezone database from the
misc/zoneinfo port and run tzsetup(8) to get the timezone database corrected.
Applications that store and display times in Coordinated Universal Time (UTC)
are not affected.
V. Solution
Please note that some third party software, for instance PHP, Ruby, Java and
Perl, may be using different zoneinfo data source, in such cases this
software must be updated separately. For software packages that is installed
via binary packages, they can be upgraded by executing `pkg upgrade'.
Following the instructions in this Errata Notice will update all of the
zoneinfo files to be the same as what was released with FreeBSD release.
Perform one of the following:
1) Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date. Restart all the affected
applications and daemons, or reboot the system.
2) To update your system via a binary patch:
Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:
# freebsd-update fetch
# freebsd-update install
Restart all the affected applications and daemons, or reboot the system.
3) To update your system via a source code patch:
The following patches have been verified to apply to the applicable
FreeBSD release branches.
a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.
# fetch https://security.FreeBSD.org/patches/EN-18:06/tzdata-2018e.patch
# fetch https://security.FreeBSD.org/patches/EN-18:06/tzdata-2018e.patch.asc
# gpg --verify tzdata-2018e.patch.asc
b) Apply the patch. Execute the following commands as root:
# cd /usr/src
# patch < /path/to/patch
c) Recompile the operating system using buildworld and installworld as
described in <URL:https://www.FreeBSD.org/handbook/makeworld.html>.
Restart all the affected applications and daemons, or reboot the system.
VI. Correction details
The following list contains the correction revision numbers for each
affected branch.
Branch/path Revision
- -------------------------------------------------------------------------
stable/10/ r333313
releng/10.4/ r333375
stable/11/ r333312
releng/11.1/ r333375
- -------------------------------------------------------------------------
To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:
# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base
Or visit the following URL, replacing NNNNNN with the revision number:
<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>
VII. References
The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-18:06.tzdata.asc>
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAlrx3G1fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEZD
MEU4NzhBRTVBRkU3ODgwMjhENjM1NUQzOTc5MkY0OUVBN0U1QzIACgkQ05eS9J6n
5cIzdg//a6Vn9B/eW4na7jAcX4rUCUJGBFE1A4MhX4NGULx+L4v6qkcdj4O6CWYR
rbqNRzEtb5oF0We9K0XyekigmOVmb5TwDXHbjiaw13DrLWM4WhEAerRP04DrDV7k
31SGAq92L3oP4u8FrxwdtKZ2TY5naH/3GdGEL0JJmUaqUSrtLeiOvqVwCKZIy7i9
Q4DqQh7cEtBK5J8V+VqqbKNKOTPKS0uH27UAjzPhTc+GbZ4YRnD4YKVfNZMEDmiy
5TgXJrVOX+eJZlB1jgZXJY38wZtQELbs+2I2haNvzKz3Ypt7Rtan9MxAWkBkC+g6
/tbiJFYaJ5GC0CTBymBa8gm5oqvpWzb3h3kNpld4SDyO1iDcIcD7/+VqnNoFynVa
Fgf/icLc3Ck48n0ZZQlkGk22kTmBwe69p6QLnL5cuDbm3ZpRM/+1GjguG2Ow5eYD
Y6p6eMozALZh2JdHdxAtKEuSfc03UOMcEu2kBtVE/XtoJqPb+2SmaSRvXmMiio2E
TPjjdAzUUITDcESmyJLmHoqwHR40i2+ZSwH6BbD/1qeoH7PSXS+/Nh/wv2KEsC0S
tbAYiwuj4uDlgPIPm0tr2xDB+2BaSVe/0AituXyzFQVnrNJHisLrk0tZ7Y3WmN0B
Fn/5LIRGjT51Sw/0D0XpedwcdWoUQ9vz/FpoC6xQDcaXhW/ViDo=
=0QUF
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"
Tuesday, May 8, 2018
[FreeBSD-Announce] FreeBSD Errata Notice FreeBSD-EN-18:05.mem
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
=============================================================================
FreeBSD-EN-18:05.mem Errata Notice
The FreeBSD Project
Topic: Multiple small kernel memory disclosures
Category: core
Module: kernel
Announced: 2018-05-08
Credits: Ilja van Sprundel, IOActive
Vlad Tsyrklevich
Affects: All supported versions of FreeBSD.
Corrected: 2018-04-08 20:50:16 UTC (stable/11, 11.1-STABLE)
2018-05-08 17:14:54 UTC (releng/11.1, 11.1-RELEASE-p10)
2018-04-09 12:55:09 UTC (stable/10, 10.4-STABLE)
2018-05-08 17:14:54 UTC (releng/10.4, 10.4-RELEASE-p9)
CVE Name: CVE-2018-6920, CVE-2018-6921
For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.
I. Background
FreeBSD includes drivers for Atheros wireless interfaces, a TCP network
stack, and the ability to execute Linux binaries.
II. Problem Description
Due to insufficient initialization of memory copied to userland in the
components described above small amounts of kernel memory may be disclosed
to userland processes.
The disclosure in the Atheros wireless driver and Linux subsystem applies to
both FreeBSD 10.x and 11.x (CVE-2018-6920).
The disclosure in the TCP network stack was introduced in 11.0. As such,
only FreeBSD 11.x is affected by this issue (CVE-2018-6921).
III. Impact
A user who can access these drivers, use TCP sockets, or execute Linux
binaries may be able to read the contents of small portions of kernel memory.
Such memory might contain sensitive information, such as portions of the file
cache or terminal buffers. This information might be directly useful, or it
might be leveraged to obtain elevated privileges in some way; for example,
a terminal buffer might include a user-entered password.
IV. Workaround
No workaround is available.
V. Solution
Perform one of the following:
1) Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date.
Afterward, reboot the system.
2) To update your system via a binary patch:
Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:
# freebsd-update fetch
# freebsd-update install
Afterward, reboot the system.
3) To update your system via a source code patch:
The following patches have been verified to apply to the applicable
FreeBSD release branches.
a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.
[FreeBSD 11.1]
# fetch https://security.FreeBSD.org/patches/EN-18:05/mem.11.1.patch
# fetch https://security.FreeBSD.org/patches/EN-18:05/mem.11.1.patch.asc
# gpg --verify mem.11.1.patch.asc
[FreeBSD 10.4]
# fetch https://security.FreeBSD.org/patches/EN-18:05/mem.10.4.patch
# fetch https://security.FreeBSD.org/patches/EN-18:05/mem.10.4.patch.asc
# gpg --verify mem.10.4.patch.asc
b) Apply the patch. Execute the following commands as root:
# cd /usr/src
# patch < /path/to/patch
c) Recompile your kernel as described in
<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
system.
VI. Correction details
The following list contains the correction revision numbers for each
affected branch.
Branch/path Revision
- -------------------------------------------------------------------------
stable/10/ r332321
releng/10.4/ r333372
stable/11/ r332303
releng/11.1/ r333372
- -------------------------------------------------------------------------
To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:
# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base
Or visit the following URL, replacing NNNNNN with the revision number:
<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>
VII. References
<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6920>
<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6921>
The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-18:05.mem.asc>
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAlrx3F5fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEZD
MEU4NzhBRTVBRkU3ODgwMjhENjM1NUQzOTc5MkY0OUVBN0U1QzIACgkQ05eS9J6n
5cLEJw/+O78dItjByrV33QHG6FG99Sk2tMvYJaD5jmM7qUiV2TiumFz4n8a3IjDe
kEmH68jkHxkSvWHvpOKMYx/CzzGG1UkMQvrFseGO6d/azZMqY4V3WqXeKcD6lwLI
qggFdIBDr2ltGQ19jLuD8ucfuyC8DurdhiEzn1s7e2YjpPaCgNSc9kHf/+Ez/MBu
v9ozlq/uS9+tLWHCoY6r4WFXWBrT96LFs9O+5TMVXZ+1ZuIvj4/2y+7HtgJalt85
5+bce0+qFdmk/gpcw7SQOZ1ngeXPWi9fDOv7LR+YkDaHcpJP9sXp9Ej2Tro97CMK
oQ0QGiJ+h1iGuYIw76chchZ5mK+UEVSbdxK70fpPC1zi+g8l0smVSpOs8oNFGX0m
F0pHhIz3LwMMDyZgJsEMUIkBF7nbKS8Mc+noq9DOaOjZjb0yyBFbc8s82LIdbOhO
IIJftNF1NSlH4tKJtFdet/TrxHX/UZ0xp52SHev+U3c3gXaoP4EUHQ71R/lnlyJc
R+H6G/xZjcsNrklKgJJMV+5znKbjDaqavaaAxo17eRqLG/M4ZIac3xzqJUyeuUPY
RnErPTRQzGL4C9CldxjIfI+iY3f2uTsNclzonV98kcLxbRdMsNIybUV6mNBYVmlx
4A6IN3zP1+bsbjOdZMhpAUIjsflj/KzdF/f4/BjoCgBv3O030ec=
=jxlW
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"
Hash: SHA512
=============================================================================
FreeBSD-EN-18:05.mem Errata Notice
The FreeBSD Project
Topic: Multiple small kernel memory disclosures
Category: core
Module: kernel
Announced: 2018-05-08
Credits: Ilja van Sprundel, IOActive
Vlad Tsyrklevich
Affects: All supported versions of FreeBSD.
Corrected: 2018-04-08 20:50:16 UTC (stable/11, 11.1-STABLE)
2018-05-08 17:14:54 UTC (releng/11.1, 11.1-RELEASE-p10)
2018-04-09 12:55:09 UTC (stable/10, 10.4-STABLE)
2018-05-08 17:14:54 UTC (releng/10.4, 10.4-RELEASE-p9)
CVE Name: CVE-2018-6920, CVE-2018-6921
For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.
I. Background
FreeBSD includes drivers for Atheros wireless interfaces, a TCP network
stack, and the ability to execute Linux binaries.
II. Problem Description
Due to insufficient initialization of memory copied to userland in the
components described above small amounts of kernel memory may be disclosed
to userland processes.
The disclosure in the Atheros wireless driver and Linux subsystem applies to
both FreeBSD 10.x and 11.x (CVE-2018-6920).
The disclosure in the TCP network stack was introduced in 11.0. As such,
only FreeBSD 11.x is affected by this issue (CVE-2018-6921).
III. Impact
A user who can access these drivers, use TCP sockets, or execute Linux
binaries may be able to read the contents of small portions of kernel memory.
Such memory might contain sensitive information, such as portions of the file
cache or terminal buffers. This information might be directly useful, or it
might be leveraged to obtain elevated privileges in some way; for example,
a terminal buffer might include a user-entered password.
IV. Workaround
No workaround is available.
V. Solution
Perform one of the following:
1) Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date.
Afterward, reboot the system.
2) To update your system via a binary patch:
Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:
# freebsd-update fetch
# freebsd-update install
Afterward, reboot the system.
3) To update your system via a source code patch:
The following patches have been verified to apply to the applicable
FreeBSD release branches.
a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.
[FreeBSD 11.1]
# fetch https://security.FreeBSD.org/patches/EN-18:05/mem.11.1.patch
# fetch https://security.FreeBSD.org/patches/EN-18:05/mem.11.1.patch.asc
# gpg --verify mem.11.1.patch.asc
[FreeBSD 10.4]
# fetch https://security.FreeBSD.org/patches/EN-18:05/mem.10.4.patch
# fetch https://security.FreeBSD.org/patches/EN-18:05/mem.10.4.patch.asc
# gpg --verify mem.10.4.patch.asc
b) Apply the patch. Execute the following commands as root:
# cd /usr/src
# patch < /path/to/patch
c) Recompile your kernel as described in
<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
system.
VI. Correction details
The following list contains the correction revision numbers for each
affected branch.
Branch/path Revision
- -------------------------------------------------------------------------
stable/10/ r332321
releng/10.4/ r333372
stable/11/ r332303
releng/11.1/ r333372
- -------------------------------------------------------------------------
To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:
# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base
Or visit the following URL, replacing NNNNNN with the revision number:
<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>
VII. References
<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6920>
<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6921>
The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-18:05.mem.asc>
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAlrx3F5fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEZD
MEU4NzhBRTVBRkU3ODgwMjhENjM1NUQzOTc5MkY0OUVBN0U1QzIACgkQ05eS9J6n
5cLEJw/+O78dItjByrV33QHG6FG99Sk2tMvYJaD5jmM7qUiV2TiumFz4n8a3IjDe
kEmH68jkHxkSvWHvpOKMYx/CzzGG1UkMQvrFseGO6d/azZMqY4V3WqXeKcD6lwLI
qggFdIBDr2ltGQ19jLuD8ucfuyC8DurdhiEzn1s7e2YjpPaCgNSc9kHf/+Ez/MBu
v9ozlq/uS9+tLWHCoY6r4WFXWBrT96LFs9O+5TMVXZ+1ZuIvj4/2y+7HtgJalt85
5+bce0+qFdmk/gpcw7SQOZ1ngeXPWi9fDOv7LR+YkDaHcpJP9sXp9Ej2Tro97CMK
oQ0QGiJ+h1iGuYIw76chchZ5mK+UEVSbdxK70fpPC1zi+g8l0smVSpOs8oNFGX0m
F0pHhIz3LwMMDyZgJsEMUIkBF7nbKS8Mc+noq9DOaOjZjb0yyBFbc8s82LIdbOhO
IIJftNF1NSlH4tKJtFdet/TrxHX/UZ0xp52SHev+U3c3gXaoP4EUHQ71R/lnlyJc
R+H6G/xZjcsNrklKgJJMV+5znKbjDaqavaaAxo17eRqLG/M4ZIac3xzqJUyeuUPY
RnErPTRQzGL4C9CldxjIfI+iY3f2uTsNclzonV98kcLxbRdMsNIybUV6mNBYVmlx
4A6IN3zP1+bsbjOdZMhpAUIjsflj/KzdF/f4/BjoCgBv3O030ec=
=jxlW
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"
[FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-18:06.debugreg
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
=============================================================================
FreeBSD-SA-18:06.debugreg Security Advisory
The FreeBSD Project
Topic: Mishandling of x86 debug exceptions
Category: core
Module: kernel
Announced: 2018-05-08
Credits: Nick Peterson, Everdox Tech LLC
https://www.linkedin.com/in/everdox
Andy Lutomirski
Affects: All supported versions of FreeBSD.
Corrected: 2018-05-08 17:03:33 UTC (stable/11, 11.2-PRERELEASE)
2018-05-08 17:12:10 UTC (releng/11.1, 11.1-RELEASE-p10)
2018-05-08 17:05:39 UTC (stable/10, 10.4-STABLE)
2018-05-08 17:12:10 UTC (releng/10.4, 10.4-RELEASE-p9)
CVE Name: CVE-2018-8897
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit <URL:https://security.FreeBSD.org/>.
I. Background
On x86 architecture systems, the stack is represented by the combination of
a stack segment and a stack pointer, which must remain in sync for proper
operation. Instructions related to manipulating the stack segment have
special handling to facilitate consistency with changes to the stack pointer.
II. Problem Description
The MOV SS and POP SS instructions inhibit debug exceptions until the
instruction boundary following the next instruction. If that instruction is
a system call or similar instruction that transfers control to the operating
system, the debug exception will be handled in the kernel context instead of
the user context.
III. Impact
An authenticated local attacker may be able to read sensitive data in kernel
memory, control low-level operating system functions, or may panic the
system.
IV. Workaround
No workaround is available.
V. Solution
Upgrade your vulnerable system to a supported FreeBSD stable or
release / security branch (releng) dated after the correction date,
using either a binary or source code patch, and then reboot.
1) To update your vulnerable system via a binary patch:
Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:
# freebsd-update fetch
# freebsd-update install
And reboot.
2) To update your vulnerable system via a source code patch:
The following patches have been verified to apply to the applicable
FreeBSD release branches.
a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.
[FreeBSD 11.1]
# fetch https://security.FreeBSD.org/patches/SA-18:06/debugreg.11.1.patch
# fetch https://security.FreeBSD.org/patches/SA-18:06/debugreg.11.1.patch.asc
# gpg --verify debugreg.11.1.patch.asc
[FreeBSD 10.4]
# fetch https://security.FreeBSD.org/patches/SA-18:06/debugreg.10.4.patch
# fetch https://security.FreeBSD.org/patches/SA-18:06/debugreg.10.4.patch.asc
# gpg --verify debugreg.10.4.patch.asc
b) Apply the patch. Execute the following commands as root:
# cd /usr/src
# patch < /path/to/patch
c) Recompile and install your kernel as described in
<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
system.
VI. Correction details
The following list contains the correction revision numbers for each
affected branch.
Branch/path Revision
- -------------------------------------------------------------------------
stable/10/ r333370
releng/10.4/ r333371
stable/11/ r333369
releng/11.1/ r333371
- -------------------------------------------------------------------------
To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:
# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base
Or visit the following URL, replacing NNNNNN with the revision number:
<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>
VII. References
<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8897>
The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-18:06.debugreg.asc>
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAlrx3HhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEZD
MEU4NzhBRTVBRkU3ODgwMjhENjM1NUQzOTc5MkY0OUVBN0U1QzIACgkQ05eS9J6n
5cK/jhAAmPPCFZRMvbyG0VBCBqo5COFZ/32IMOWFDGMlsSi+CEgcGM51SzYZi97c
zsT/2RgMsvBdggk41wvXqp1gKxgIbJe22af7l+D18e6rDEesueJqSiizcHmfGQul
X+ZRUkFxTkCNz0Ajp4clqbavuHNiCmiKmH/0X8LMk31SXIVE3oH0Pphf0W8qJqxz
4k2nvc6NoPWEMVA0rsj3n6sB0NhvV1ddLLmGpoDgedSyz77PCDgWGMoh5ny5sY12
tHNB1r+gL624Y0l8xoyVJP0Snk0emzeQQ5HOTa8DRIwD/a0Uxy+xKcvDMorW9U6M
zsxrMs9EwSJYpwLxsQ/YVTgFvyQbkHXFXg56hxqUvnnEEahGfF47d/9x2lyzDr8r
H+ncl9a+PfOCJ5OcwkjzorQv+Pq65JFlc15bxLS+zyU4g6yJDnHdk7Azbc60Uwq/
chauKmosm1I1CVH60JG00rmvoiX7b5ZRdEGEzAFt4XIX+EuXPnI84C5DxiD1YG+3
n7IygNZNGtGfIrNhWEn2VK+VGzFEm2p4RkreWbGwrWQIxfd5gOJxvjAPSwjgy5rl
dwRW7bMzowIGnrlzCF18Qc2xnFD31JPYDdsI+Fa8d1YkCVWRZ79VX57Locw50/de
c5nZRJGk4AQ1lXxkNTkxWnstfb/q8fBVPkIEQKVHpVnGiI/pQpQ=
=Oyxs
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"
Hash: SHA512
=============================================================================
FreeBSD-SA-18:06.debugreg Security Advisory
The FreeBSD Project
Topic: Mishandling of x86 debug exceptions
Category: core
Module: kernel
Announced: 2018-05-08
Credits: Nick Peterson, Everdox Tech LLC
https://www.linkedin.com/in/everdox
Andy Lutomirski
Affects: All supported versions of FreeBSD.
Corrected: 2018-05-08 17:03:33 UTC (stable/11, 11.2-PRERELEASE)
2018-05-08 17:12:10 UTC (releng/11.1, 11.1-RELEASE-p10)
2018-05-08 17:05:39 UTC (stable/10, 10.4-STABLE)
2018-05-08 17:12:10 UTC (releng/10.4, 10.4-RELEASE-p9)
CVE Name: CVE-2018-8897
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit <URL:https://security.FreeBSD.org/>.
I. Background
On x86 architecture systems, the stack is represented by the combination of
a stack segment and a stack pointer, which must remain in sync for proper
operation. Instructions related to manipulating the stack segment have
special handling to facilitate consistency with changes to the stack pointer.
II. Problem Description
The MOV SS and POP SS instructions inhibit debug exceptions until the
instruction boundary following the next instruction. If that instruction is
a system call or similar instruction that transfers control to the operating
system, the debug exception will be handled in the kernel context instead of
the user context.
III. Impact
An authenticated local attacker may be able to read sensitive data in kernel
memory, control low-level operating system functions, or may panic the
system.
IV. Workaround
No workaround is available.
V. Solution
Upgrade your vulnerable system to a supported FreeBSD stable or
release / security branch (releng) dated after the correction date,
using either a binary or source code patch, and then reboot.
1) To update your vulnerable system via a binary patch:
Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:
# freebsd-update fetch
# freebsd-update install
And reboot.
2) To update your vulnerable system via a source code patch:
The following patches have been verified to apply to the applicable
FreeBSD release branches.
a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.
[FreeBSD 11.1]
# fetch https://security.FreeBSD.org/patches/SA-18:06/debugreg.11.1.patch
# fetch https://security.FreeBSD.org/patches/SA-18:06/debugreg.11.1.patch.asc
# gpg --verify debugreg.11.1.patch.asc
[FreeBSD 10.4]
# fetch https://security.FreeBSD.org/patches/SA-18:06/debugreg.10.4.patch
# fetch https://security.FreeBSD.org/patches/SA-18:06/debugreg.10.4.patch.asc
# gpg --verify debugreg.10.4.patch.asc
b) Apply the patch. Execute the following commands as root:
# cd /usr/src
# patch < /path/to/patch
c) Recompile and install your kernel as described in
<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
system.
VI. Correction details
The following list contains the correction revision numbers for each
affected branch.
Branch/path Revision
- -------------------------------------------------------------------------
stable/10/ r333370
releng/10.4/ r333371
stable/11/ r333369
releng/11.1/ r333371
- -------------------------------------------------------------------------
To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:
# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base
Or visit the following URL, replacing NNNNNN with the revision number:
<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>
VII. References
<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8897>
The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-18:06.debugreg.asc>
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAlrx3HhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEZD
MEU4NzhBRTVBRkU3ODgwMjhENjM1NUQzOTc5MkY0OUVBN0U1QzIACgkQ05eS9J6n
5cK/jhAAmPPCFZRMvbyG0VBCBqo5COFZ/32IMOWFDGMlsSi+CEgcGM51SzYZi97c
zsT/2RgMsvBdggk41wvXqp1gKxgIbJe22af7l+D18e6rDEesueJqSiizcHmfGQul
X+ZRUkFxTkCNz0Ajp4clqbavuHNiCmiKmH/0X8LMk31SXIVE3oH0Pphf0W8qJqxz
4k2nvc6NoPWEMVA0rsj3n6sB0NhvV1ddLLmGpoDgedSyz77PCDgWGMoh5ny5sY12
tHNB1r+gL624Y0l8xoyVJP0Snk0emzeQQ5HOTa8DRIwD/a0Uxy+xKcvDMorW9U6M
zsxrMs9EwSJYpwLxsQ/YVTgFvyQbkHXFXg56hxqUvnnEEahGfF47d/9x2lyzDr8r
H+ncl9a+PfOCJ5OcwkjzorQv+Pq65JFlc15bxLS+zyU4g6yJDnHdk7Azbc60Uwq/
chauKmosm1I1CVH60JG00rmvoiX7b5ZRdEGEzAFt4XIX+EuXPnI84C5DxiD1YG+3
n7IygNZNGtGfIrNhWEn2VK+VGzFEm2p4RkreWbGwrWQIxfd5gOJxvjAPSwjgy5rl
dwRW7bMzowIGnrlzCF18Qc2xnFD31JPYDdsI+Fa8d1YkCVWRZ79VX57Locw50/de
c5nZRJGk4AQ1lXxkNTkxWnstfb/q8fBVPkIEQKVHpVnGiI/pQpQ=
=Oyxs
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"
[USN-3640-1] WebKitGTK+ vulnerability
-----BEGIN PGP SIGNATURE-----
iQIcBAEBCgAGBQJa8b/GAAoJEGVp2FWnRL6T2CwP/004adky2VXiY8XA8zqQlmzL
0+NRSubIC+pYwow2iLcupC5Pd0e5iEQBIvJ9it5QaAqz9CLBArkA4xpIfvO5QqoC
NxI7ql9K5nnCh3cqo5jiGAOOV6gDZh673IocTuklYBrtH16utHLSsBAR81L/IAoE
I038j42F4yqG5Po7eOBLLFRkwxlEUcdq7rdB9eSqj+6sEE5yRpsnUK5CALcUyfwu
C8Qz4sME6RABIfIw57unps2Rgt15IrPt0YsU12Nv1Qpgf7ckWGcgxljKbsFt3DTL
RXwt6Dzhcp/hz/wc81xdQ9kdgIVU81EDbTkGkTzBYSzmcgErHDLZkKYvbkG3R/1+
pWda4A3X2YXwIfopl9gVFJYuypsNtlZ/uUsIKp3ryX8xxbxn8G6VYOHYP9gGs93j
FqVT/+mm6rT3ST8S4DAZGYut/itCmTQomFQSF9EeP6nnLz9r2q5b1FwIP09rUYbb
6VOWj5xIqoKAP5pBtG2btDHB6WTI3JO702CJaHDg7DNXnUy9sPFId0iD6YNgLl1g
c8sphAqGllR2hcDTDjosC4JdNGZxcnQexrZz01aM0+9O+ckGAqBYUZYPJoLpZiZ1
YX5mFjXWUee4CWet+YvKNzBsJNirUfyYbg0+Pwvc2OKq1AQeaIxBKqffXSRBB6Zz
NrFsS4/XN8Na6RjXbXnG
=uyfI
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3640-1
May 08, 2018
webkit2gtk vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 17.10
- Ubuntu 16.04 LTS
Summary:
A security issue was fixed in WebKitGTK+.
Software Description:
- webkit2gtk: Web content engine library for GTK+
Details:
Ivan Fratric discovered that WebKitGTK+ incorrectly handled certain web
content. If a user were tricked into viewing a malicious website, a remote
attacker could possibly exploit this to execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
libjavascriptcoregtk-4.0-18 2.20.2-0ubuntu0.18.04.1
libwebkit2gtk-4.0-37 2.20.2-0ubuntu0.18.04.1
Ubuntu 17.10:
libjavascriptcoregtk-4.0-18 2.20.2-0ubuntu0.17.10.1
libwebkit2gtk-4.0-37 2.20.2-0ubuntu0.17.10.1
Ubuntu 16.04 LTS:
libjavascriptcoregtk-4.0-18 2.20.2-0ubuntu0.16.04.1
libwebkit2gtk-4.0-37 2.20.2-0ubuntu0.16.04.1
This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK+, such as Epiphany, to make all the necessary changes.
References:
https://usn.ubuntu.com/usn/usn-3640-1
CVE-2018-4200
Package Information:
https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.18.04.1
https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.17.10.1
https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.16.04.1
iQIcBAEBCgAGBQJa8b/GAAoJEGVp2FWnRL6T2CwP/004adky2VXiY8XA8zqQlmzL
0+NRSubIC+pYwow2iLcupC5Pd0e5iEQBIvJ9it5QaAqz9CLBArkA4xpIfvO5QqoC
NxI7ql9K5nnCh3cqo5jiGAOOV6gDZh673IocTuklYBrtH16utHLSsBAR81L/IAoE
I038j42F4yqG5Po7eOBLLFRkwxlEUcdq7rdB9eSqj+6sEE5yRpsnUK5CALcUyfwu
C8Qz4sME6RABIfIw57unps2Rgt15IrPt0YsU12Nv1Qpgf7ckWGcgxljKbsFt3DTL
RXwt6Dzhcp/hz/wc81xdQ9kdgIVU81EDbTkGkTzBYSzmcgErHDLZkKYvbkG3R/1+
pWda4A3X2YXwIfopl9gVFJYuypsNtlZ/uUsIKp3ryX8xxbxn8G6VYOHYP9gGs93j
FqVT/+mm6rT3ST8S4DAZGYut/itCmTQomFQSF9EeP6nnLz9r2q5b1FwIP09rUYbb
6VOWj5xIqoKAP5pBtG2btDHB6WTI3JO702CJaHDg7DNXnUy9sPFId0iD6YNgLl1g
c8sphAqGllR2hcDTDjosC4JdNGZxcnQexrZz01aM0+9O+ckGAqBYUZYPJoLpZiZ1
YX5mFjXWUee4CWet+YvKNzBsJNirUfyYbg0+Pwvc2OKq1AQeaIxBKqffXSRBB6Zz
NrFsS4/XN8Na6RjXbXnG
=uyfI
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3640-1
May 08, 2018
webkit2gtk vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 17.10
- Ubuntu 16.04 LTS
Summary:
A security issue was fixed in WebKitGTK+.
Software Description:
- webkit2gtk: Web content engine library for GTK+
Details:
Ivan Fratric discovered that WebKitGTK+ incorrectly handled certain web
content. If a user were tricked into viewing a malicious website, a remote
attacker could possibly exploit this to execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
libjavascriptcoregtk-4.0-18 2.20.2-0ubuntu0.18.04.1
libwebkit2gtk-4.0-37 2.20.2-0ubuntu0.18.04.1
Ubuntu 17.10:
libjavascriptcoregtk-4.0-18 2.20.2-0ubuntu0.17.10.1
libwebkit2gtk-4.0-37 2.20.2-0ubuntu0.17.10.1
Ubuntu 16.04 LTS:
libjavascriptcoregtk-4.0-18 2.20.2-0ubuntu0.16.04.1
libwebkit2gtk-4.0-37 2.20.2-0ubuntu0.16.04.1
This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK+, such as Epiphany, to make all the necessary changes.
References:
https://usn.ubuntu.com/usn/usn-3640-1
CVE-2018-4200
Package Information:
https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.18.04.1
https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.17.10.1
https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.16.04.1
[USN-3639-1] LibRaw vulnerabilities
==========================================================================
Ubuntu Security Notice USN-3639-1
May 08, 2018
libraw vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 17.10
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in LibRaw.
Software Description:
- libraw: raw image decoder library
Details:
It was discovered that LibRaw incorrectly handled certain files.
An attacker could possibly use this to execute arbitrary code.
(CVE-2018-10528)
It was discovered that LibRaw incorrectly handled certain files.
An attacker could possibly use this to obtain sensitive information.
(CVE-2018-10529)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
libraw16 0.18.8-1ubuntu0.1
Ubuntu 17.10:
libraw16 0.18.2-2ubuntu0.3
Ubuntu 16.04 LTS:
libraw15 0.17.1-1ubuntu0.3
After a standard system update you need to restart your session
to make all the necessary changes.
References:
https://usn.ubuntu.com/usn/usn-3639-1
CVE-2018-10528, CVE-2018-10529
Package Information:
https://launchpad.net/ubuntu/+source/libraw/0.18.8-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libraw/0.18.2-2ubuntu0.3
https://launchpad.net/ubuntu/+source/libraw/0.17.1-1ubuntu0.3
Ubuntu Security Notice USN-3639-1
May 08, 2018
libraw vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 17.10
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in LibRaw.
Software Description:
- libraw: raw image decoder library
Details:
It was discovered that LibRaw incorrectly handled certain files.
An attacker could possibly use this to execute arbitrary code.
(CVE-2018-10528)
It was discovered that LibRaw incorrectly handled certain files.
An attacker could possibly use this to obtain sensitive information.
(CVE-2018-10529)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
libraw16 0.18.8-1ubuntu0.1
Ubuntu 17.10:
libraw16 0.18.2-2ubuntu0.3
Ubuntu 16.04 LTS:
libraw15 0.17.1-1ubuntu0.3
After a standard system update you need to restart your session
to make all the necessary changes.
References:
https://usn.ubuntu.com/usn/usn-3639-1
CVE-2018-10528, CVE-2018-10529
Package Information:
https://launchpad.net/ubuntu/+source/libraw/0.18.8-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libraw/0.18.2-2ubuntu0.3
https://launchpad.net/ubuntu/+source/libraw/0.17.1-1ubuntu0.3
OpenBSD Errata: May 8th, 2018 (libcrypto)
Errata patches for libcrypto have been released for OpenBSD 6.3.
Incorrect checks in libcrypto can prevent Diffie-Hellman Exchange operations
from working.
Binary updates for the amd64, i386, and arm64 platforms are available via
the syspatch utility. Source code patches can be found on the errata page:
https://www.openbsd.org/errata63.html
Incorrect checks in libcrypto can prevent Diffie-Hellman Exchange operations
from working.
Binary updates for the amd64, i386, and arm64 platforms are available via
the syspatch utility. Source code patches can be found on the errata page:
https://www.openbsd.org/errata63.html
OpenBSD Errata: May 8th, 2018 (ipseclen)
Errata patches for IPsec have been released for OpenBSD 6.3 and 6.2.
Incorrect handling of fragmented IPsec packets could result in a system crash.
Binary updates for the amd64, i386, and arm64 platforms are available via
the syspatch utility. Source code patches can be found on the respective
errata pages:
https://www.openbsd.org/errata62.html
https://www.openbsd.org/errata63.html
As these affect the kernel, a reboot will be needed after patching.
Incorrect handling of fragmented IPsec packets could result in a system crash.
Binary updates for the amd64, i386, and arm64 platforms are available via
the syspatch utility. Source code patches can be found on the respective
errata pages:
https://www.openbsd.org/errata62.html
https://www.openbsd.org/errata63.html
As these affect the kernel, a reboot will be needed after patching.
Monday, May 7, 2018
[USN-3638-1] QPDF vulnerabilities
-----BEGIN PGP SIGNATURE-----
iQIcBAEBCgAGBQJa8JH4AAoJEGVp2FWnRL6TwCIP/0qcaT0UB43vWrFSyPI9pLLp
b/WYh6ha4ny6+FxHIPqO/mAW+9BcqAuZoxhRWghVodIIT+1aL1CYRI2myJ35ZPRt
Kx1xlHxS1BOH0iKsCP4UpGHQNszHg/DxgZtC9H/FImBAuFXmCPbf4uQZAM17xgf4
jfv5Zr7EL0nSCJZDvqxGDuvQ0Hz6eFIWOL3iv1VvhoiHNs6DSEU5J4BjeWfGfdnw
CxKPekQ8kKUzzjqHglImT7msanPaMnDoVMoZbmwEz4PRH+Gk7SHOWPufZmvUJCQv
GTH+aiDKJ/52hVXbk1sMS8y7XKrJ74XWfDQ+BzpDh5CHh78+9pQQpUKX6SnJNQk4
x+EKJFJZfPsxpHThq2fP+ybAEAPK4S36fBCLkFdj4VEIwdYXsLrOec2Oe2rLBMld
yB5gSGLmKJxEt9IxmSBDl181bLljotGhXxtPGLdK+JCgCCI5TAfJ/HXL/h6Onof9
/ZcBmAylrKUijmBO8tnXy+DmQD5aOUQ7Y9VFbKunB9yQTTa92k3TiJaAOvqaH8Ay
w1MjcP2xBqKix6ncbuEwhrUt1aA0lu8Uo7eCSmfBEoPaQwvxCirFlyIT+MmF9zpA
XiTkWKznFWbCk9VhARasDFsOH97l0R6PofXhIx7gAVXCXO1X08gv/knmb0cUahCd
7+/fNd+4qEn6To3TsdgR
=fSP6
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3638-1
May 07, 2018
qpdf vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 17.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in QPDF.
Software Description:
- qpdf: tools for transforming and inspecting PDF files
Details:
It was discovered that QPDF incorrectly handled certain malformed files. A
remote attacker could use this issue to cause QPDF to crash, resulting in a
denial of service, or possibly execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 17.10:
libqpdf21 8.0.2-3~17.10.1
qpdf 8.0.2-3~17.10.1
Ubuntu 16.04 LTS:
libqpdf21 8.0.2-3~16.04.1
qpdf 8.0.2-3~16.04.1
Ubuntu 14.04 LTS:
libqpdf21 8.0.2-3~14.04.1
qpdf 8.0.2-3~14.04.1
This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
References:
https://usn.ubuntu.com/usn/usn-3638-1
CVE-2015-9252, CVE-2017-11624, CVE-2017-11625, CVE-2017-11626,
CVE-2017-11627, CVE-2017-12595, CVE-2017-18183, CVE-2017-18184,
CVE-2017-18185, CVE-2017-18186, CVE-2017-9208, CVE-2017-9209,
CVE-2017-9210, CVE-2018-9918
Package Information:
https://launchpad.net/ubuntu/+source/qpdf/8.0.2-3~17.10.1
https://launchpad.net/ubuntu/+source/qpdf/8.0.2-3~16.04.1
https://launchpad.net/ubuntu/+source/qpdf/8.0.2-3~14.04.1
iQIcBAEBCgAGBQJa8JH4AAoJEGVp2FWnRL6TwCIP/0qcaT0UB43vWrFSyPI9pLLp
b/WYh6ha4ny6+FxHIPqO/mAW+9BcqAuZoxhRWghVodIIT+1aL1CYRI2myJ35ZPRt
Kx1xlHxS1BOH0iKsCP4UpGHQNszHg/DxgZtC9H/FImBAuFXmCPbf4uQZAM17xgf4
jfv5Zr7EL0nSCJZDvqxGDuvQ0Hz6eFIWOL3iv1VvhoiHNs6DSEU5J4BjeWfGfdnw
CxKPekQ8kKUzzjqHglImT7msanPaMnDoVMoZbmwEz4PRH+Gk7SHOWPufZmvUJCQv
GTH+aiDKJ/52hVXbk1sMS8y7XKrJ74XWfDQ+BzpDh5CHh78+9pQQpUKX6SnJNQk4
x+EKJFJZfPsxpHThq2fP+ybAEAPK4S36fBCLkFdj4VEIwdYXsLrOec2Oe2rLBMld
yB5gSGLmKJxEt9IxmSBDl181bLljotGhXxtPGLdK+JCgCCI5TAfJ/HXL/h6Onof9
/ZcBmAylrKUijmBO8tnXy+DmQD5aOUQ7Y9VFbKunB9yQTTa92k3TiJaAOvqaH8Ay
w1MjcP2xBqKix6ncbuEwhrUt1aA0lu8Uo7eCSmfBEoPaQwvxCirFlyIT+MmF9zpA
XiTkWKznFWbCk9VhARasDFsOH97l0R6PofXhIx7gAVXCXO1X08gv/knmb0cUahCd
7+/fNd+4qEn6To3TsdgR
=fSP6
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3638-1
May 07, 2018
qpdf vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 17.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in QPDF.
Software Description:
- qpdf: tools for transforming and inspecting PDF files
Details:
It was discovered that QPDF incorrectly handled certain malformed files. A
remote attacker could use this issue to cause QPDF to crash, resulting in a
denial of service, or possibly execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 17.10:
libqpdf21 8.0.2-3~17.10.1
qpdf 8.0.2-3~17.10.1
Ubuntu 16.04 LTS:
libqpdf21 8.0.2-3~16.04.1
qpdf 8.0.2-3~16.04.1
Ubuntu 14.04 LTS:
libqpdf21 8.0.2-3~14.04.1
qpdf 8.0.2-3~14.04.1
This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
References:
https://usn.ubuntu.com/usn/usn-3638-1
CVE-2015-9252, CVE-2017-11624, CVE-2017-11625, CVE-2017-11626,
CVE-2017-11627, CVE-2017-12595, CVE-2017-18183, CVE-2017-18184,
CVE-2017-18185, CVE-2017-18186, CVE-2017-9208, CVE-2017-9209,
CVE-2017-9210, CVE-2018-9918
Package Information:
https://launchpad.net/ubuntu/+source/qpdf/8.0.2-3~17.10.1
https://launchpad.net/ubuntu/+source/qpdf/8.0.2-3~16.04.1
https://launchpad.net/ubuntu/+source/qpdf/8.0.2-3~14.04.1
Planned Outage - Ibiblio Servers (fedorapeople.org, torrent01.fedoraproject.org) 2018-05-09 12:00 UTC
Planned Outage - Server updates - 2018-05-09 12:00 UTC
There will be an outage starting at 2018-05-09 12:00 UTC,
which will last approximately 4 hours.
To convert UTC to your local time, take a look at
http://fedoraproject.org/wiki/Infrastructure/UTCHowto
or run:
date -d '2018-05-09 12:00UTC'
Reason for outage:
Ibiblio is moving systems to a newer rack with 10G SFP+ networks.
Systems will need to be powered down, moved over to the new racks,
powered back up, configured to use the new networks in failover mode.
Affected Services:
download-ib01.fedoraproject.org
pagure-proxy01.fedoraproject.org
proxy04.fedoraproject.org
noc02.fedoraproject.org
unbound-ib01.fedoraproject.org
ns02.fedoraproject.org
people02.fedoraproject.org
proxy12.fedoraproject.org
smtp-mm-ib01.fedoraproject.org
torrent02.fedoraproject.org
Torrent and people will be down during that time. Systems configured
to use download-ib02 will also be.
Ticket Link:
https://pagure.io/fedora-infrastructure/issue/6915
Please join #fedora-admin or #fedora-noc on irc.freenode.net
or add comments to the ticket for this outage above.
--
Stephen J Smoogen.
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
There will be an outage starting at 2018-05-09 12:00 UTC,
which will last approximately 4 hours.
To convert UTC to your local time, take a look at
http://fedoraproject.org/wiki/Infrastructure/UTCHowto
or run:
date -d '2018-05-09 12:00UTC'
Reason for outage:
Ibiblio is moving systems to a newer rack with 10G SFP+ networks.
Systems will need to be powered down, moved over to the new racks,
powered back up, configured to use the new networks in failover mode.
Affected Services:
download-ib01.fedoraproject.org
pagure-proxy01.fedoraproject.org
proxy04.fedoraproject.org
noc02.fedoraproject.org
unbound-ib01.fedoraproject.org
ns02.fedoraproject.org
people02.fedoraproject.org
proxy12.fedoraproject.org
smtp-mm-ib01.fedoraproject.org
torrent02.fedoraproject.org
Torrent and people will be down during that time. Systems configured
to use download-ib02 will also be.
Ticket Link:
https://pagure.io/fedora-infrastructure/issue/6915
Please join #fedora-admin or #fedora-noc on irc.freenode.net
or add comments to the ticket for this outage above.
--
Stephen J Smoogen.
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Planned Outage - Server updates - 2018-05-08 21:00 UTC
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEESz7rprBJHpbnMnrQSzew2A/7u14FAlrwhdAACgkQSzew2A/7
u15r5g/9GZqIYLVF7uKKCXFDyCnjFMQR5xad+/0a7mceALbGOrFBb4w0guwKpMD4
HbgzIt2FawNbBVOq+ZFw/87OXp8UjKOCAarxttKToG6+UY7D1JcjeuAH7YeQyF4o
apTd+DsvQ96KtqqTui6+Julfw3RDXNK3Gi9S601GPGqEkeBtekWaC/S6fug4Wk4z
hUCz4jTlYmV8VjzSd6Z9pR/VEBs/lP+D70xPY1JzGJijeQK3Yaeybv+t5VSamdgW
l1yXrhNHDWKTZMUQp2exqTYjMQXNulrdUeJZSB9HEBKi9xAnXOyvP9fOZ87TQpbZ
QlOAXOAPhU+/uwk3GuQ3oLdaJplP4mXl2I1aq40ojGZa5erE+dKzrIDBStYG7f1u
kBFMCMxrYQJNxVHkxGDRIxn4qjSXKesHrAcoctfS+CVdiYH/TQa2/4CH/5Xt5sLM
97YRkwZiDCY5b6ZLJ8dO5hSLnVlRK2vya8ZWe0rNd1yM7yFT93GwKyvBKSF6p1/z
iP6SZMwYHbWXVVvP3HXJJglkvwVjwIj5JTZ6Z6stN2SxDUlfNi6snMRGm8wKG0cQ
VyhATlvMoDLbkGefPyK2gkf4qooYfj5DCUlNrXsaDqT54NkpiOnsZS1QLbclvljV
3RxEa1reZKph0UHS4be8XwRmi6NsUUbsga3lZUSbUdMTwvpxDzU=
=O6SV
-----END PGP SIGNATURE-----
Planned Outage - Server updates - 2018-05-08 21:00 UTC
There will be an outage starting at 2018-05-08 21:00 UTC,
which will last approximately 6 hours.
To convert UTC to your local time, take a look at
http://fedoraproject.org/wiki/Infrastructure/UTCHowto
or run:
date -d '2018-05-08 21:00UTC'
Reason for outage:
We will be updating servers and rebooting them into the latest kernels.
While we will try and keep disruption to a minimum, services may be up
and down during the outage window.
Affected Services:
All services may be impacted for short times in the outage window.
Ticket Link:
https://pagure.io/fedora-infrastructure/issue/6914
Please join #fedora-admin or #fedora-noc on irc.freenode.net
or add comments to the ticket for this outage above.
iQIzBAEBCgAdFiEESz7rprBJHpbnMnrQSzew2A/7u14FAlrwhdAACgkQSzew2A/7
u15r5g/9GZqIYLVF7uKKCXFDyCnjFMQR5xad+/0a7mceALbGOrFBb4w0guwKpMD4
HbgzIt2FawNbBVOq+ZFw/87OXp8UjKOCAarxttKToG6+UY7D1JcjeuAH7YeQyF4o
apTd+DsvQ96KtqqTui6+Julfw3RDXNK3Gi9S601GPGqEkeBtekWaC/S6fug4Wk4z
hUCz4jTlYmV8VjzSd6Z9pR/VEBs/lP+D70xPY1JzGJijeQK3Yaeybv+t5VSamdgW
l1yXrhNHDWKTZMUQp2exqTYjMQXNulrdUeJZSB9HEBKi9xAnXOyvP9fOZ87TQpbZ
QlOAXOAPhU+/uwk3GuQ3oLdaJplP4mXl2I1aq40ojGZa5erE+dKzrIDBStYG7f1u
kBFMCMxrYQJNxVHkxGDRIxn4qjSXKesHrAcoctfS+CVdiYH/TQa2/4CH/5Xt5sLM
97YRkwZiDCY5b6ZLJ8dO5hSLnVlRK2vya8ZWe0rNd1yM7yFT93GwKyvBKSF6p1/z
iP6SZMwYHbWXVVvP3HXJJglkvwVjwIj5JTZ6Z6stN2SxDUlfNi6snMRGm8wKG0cQ
VyhATlvMoDLbkGefPyK2gkf4qooYfj5DCUlNrXsaDqT54NkpiOnsZS1QLbclvljV
3RxEa1reZKph0UHS4be8XwRmi6NsUUbsga3lZUSbUdMTwvpxDzU=
=O6SV
-----END PGP SIGNATURE-----
Planned Outage - Server updates - 2018-05-08 21:00 UTC
There will be an outage starting at 2018-05-08 21:00 UTC,
which will last approximately 6 hours.
To convert UTC to your local time, take a look at
http://fedoraproject.org/wiki/Infrastructure/UTCHowto
or run:
date -d '2018-05-08 21:00UTC'
Reason for outage:
We will be updating servers and rebooting them into the latest kernels.
While we will try and keep disruption to a minimum, services may be up
and down during the outage window.
Affected Services:
All services may be impacted for short times in the outage window.
Ticket Link:
https://pagure.io/fedora-infrastructure/issue/6914
Please join #fedora-admin or #fedora-noc on irc.freenode.net
or add comments to the ticket for this outage above.
F29 Self Contained Change: MySQL 8
= Proposed Self Contained Change: MySQL 8 =
https://fedoraproject.org/wiki/Changes/MySQL_8
Owner(s):
* Michal Schorm <mschorm at redhat dot com>
Update of MySQL ( community-mysql package) in Fedora from 5.7 to 8.0 version.
== Detailed description ==
Update of MySQL package in Fedora from 5.7 version to 8.0 version.
== Scope ==
* Proposal owners:
**Release MySQL 8.0.11 to Rawhide (done)
**Check software that requires community-mysql package (done, only
mysql-connector-odbc)
**Gather user input on the changes between mysql 5.7 and 8.0
* Other developers: N/A (not a System Wide Change)
* Release engineering:
https://pagure.io/releng/issue/7486
** List of deliverables: N/A (not a System Wide Change)
* Policies and guidelines: N/A (not a System Wide Change)
* Trademark approval: N/A (not needed for this Change)
--
Jan KuÅ™ík
JBoss EAP Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
https://fedoraproject.org/wiki/Changes/MySQL_8
Owner(s):
* Michal Schorm <mschorm at redhat dot com>
Update of MySQL ( community-mysql package) in Fedora from 5.7 to 8.0 version.
== Detailed description ==
Update of MySQL package in Fedora from 5.7 version to 8.0 version.
== Scope ==
* Proposal owners:
**Release MySQL 8.0.11 to Rawhide (done)
**Check software that requires community-mysql package (done, only
mysql-connector-odbc)
**Gather user input on the changes between mysql 5.7 and 8.0
* Other developers: N/A (not a System Wide Change)
* Release engineering:
https://pagure.io/releng/issue/7486
** List of deliverables: N/A (not a System Wide Change)
* Policies and guidelines: N/A (not a System Wide Change)
* Trademark approval: N/A (not needed for this Change)
--
Jan KuÅ™ík
JBoss EAP Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Saturday, May 5, 2018
Introducing Contributor Stories
Hello everyone,
The CommOps team is happy to present you the "Contributor Stories":
The contributor stories are the record of our best moments with our
Fedora friends.
The story can be about our work in Fedora or something personal or
unique which you would like to share with the community.
if want to read more about contributor stories check the community blog
post here:
https://communityblog.fedoraproject.org/contributor-stories/
We are sure that you have memories that you wish to share and say
thanks to all those contributors who have supported and inspired us
within the fedora project.
Best Regards,
_______________________________________________
announce mailing list -- announce@lists.fedoraproject.org
To unsubscribe send an email to announce-leave@lists.fedoraproject.org
The CommOps team is happy to present you the "Contributor Stories":
The contributor stories are the record of our best moments with our
Fedora friends.
The story can be about our work in Fedora or something personal or
unique which you would like to share with the community.
if want to read more about contributor stories check the community blog
post here:
https://communityblog.fedoraproject.org/contributor-stories/
We are sure that you have memories that you wish to share and say
thanks to all those contributors who have supported and inspired us
within the fedora project.
Best Regards,
_______________________________________________
announce mailing list -- announce@lists.fedoraproject.org
To unsubscribe send an email to announce-leave@lists.fedoraproject.org
Subscribe to:
Posts (Atom)