-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIbBAEBCgAGBQJVt9ZDAAoJEGVp2FWnRL6TprcP90dXXVQIq1nh8JnttekgHZth
M7uaupYdx4nwQk2hpfAqJLYhlknzAse64XbXQHtWiRP7idztNj01qVDuK3dhfoE9
r23ZC3kWoBESGrRFg8fqEEnSuOfZDbKm1fuZGkwhDVNqMEf5Qd9l/MSe5j61cFJZ
Uo6kU140iUA9UpXVYYwFodV9HQDb2KDicGIrh0xyaJh2C/PxhsQakbFDp9j3R2py
U/7cuYwCXpirIyqRVzLo+hBY8a1jPYQGyDi9Z1XkZrXlSqn9T9nRqWXVMtu+kvZX
AFju7ghyXiv+S4zAIu0tswXP6ADU+brOkqbNyT3WppvmcN6MeeSX1b+GBP2hmFaJ
GN2VJNGfNPq7XssthwNWo56qascyUIdW7wOnl2KP7rAkBopcjx1on7WCE014JsQL
IsbzgvxTdBYwFATfJQZt0kgC2++YrYSbY2fcyRe73TjIX9bDoYmQNCm2lqhtrVS2
COzhIhV2H26sYYCMWjHxUVOI2/NfEPORO8wUNWsWfr79kP31vYA2rQR5RGltU5ym
ANHYW4VEff/vlXGAXl8Lb6TcEAXsrgkXZaibfCNNmCu68QWwSg6c4sj7yKzA9ENs
TpngKHoF5uTMURAXHe4lvf21KnSK2WZjl8lRkl6ZZN9EjqtdQ+4VuYUpXhcwVtKG
RdBLHNW9mDjuA0rO4Tg=
=pI8+
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2693-1
July 28, 2015
bind9 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
Bind could be made to crash if it received specially crafted network
traffic.
Software Description:
- bind9: Internet Domain Name Server
Details:
Jonathan Foote discovered that Bind incorrectly handled certain TKEY
queries. A remote attacker could use this issue with a specially crafted
packet to cause Bind to crash, resulting in a denial of service.
(CVE-2015-5477)
Pories Ediansyah discovered that Bind incorrectly handled certain
configurations involving DNS64. A remote attacker could use this issue with
a specially crafted query to cause Bind to crash, resulting in a denial of
service. This issue only affected Ubuntu 12.04 LTS. (CVE-2012-5689)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 15.04:
bind9 1:9.9.5.dfsg-9ubuntu0.2
Ubuntu 14.04 LTS:
bind9 1:9.9.5.dfsg-3ubuntu0.4
Ubuntu 12.04 LTS:
bind9 1:9.8.1.dfsg.P1-4ubuntu0.12
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2693-1
CVE-2012-5689, CVE-2015-5477
Package Information:
https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-9ubuntu0.2
https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.4
https://launchpad.net/ubuntu/+source/bind9/1:9.8.1.dfsg.P1-4ubuntu0.12
Tuesday, July 28, 2015
[USN-2692-1] QEMU vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJVt7EFAAoJEGVp2FWnRL6TAOYQAJaudq+tp9MiOFKvV0QiSAbq
mWbxhfJuACwbJ6VkKnmwOvU6oq+k5Wxm38r2MDGDaCA7V5wbUnZWqAyiW2dHsYAo
pwTBGgUAjZYHNKGXQtuk96uPYhrxGb8e7bvv5MAmO/2C3w7VJTLeaJySIMHqWeB5
EMKvFP+yeCG394x/FBua8IB9N5vUjIwuTc2hrIjon5AjWrVAHF0Pcj3s67jWiZrT
FU+AEm5zd2fvBhm/6pTtqyF5PcnQqJC918EuU0MH4FPVqHpkJzt9XHIAi1HJ952Q
AwMOMxOOoBQpaJ7CmE9sugw3K0hWn8Q6FIFkAIUWzkDW7efgWyaDZ7OhrnWt+Inm
tcAV13Agh4COPNcrS0XnJIaXWygXn/NOp1y5c78IyObLRSiJXjgqc65rd35HrrST
qqdo+JnnZmBHKvli+L6FDGf2EqUQDqynLkwrsLlGKYaxazctQVdlB3N887QDibKi
HQANTx4iZF84wCShbMyydBmRnvnyuPKX3Lich8Sd2n1g6KVKt8B77HWu8ZanqaDM
zRvP1R7okuHSlngMI3XufpEScMfh4UrRjCOXUD8T8EonquD5DWBqUJgWaUuKhswK
viSTCB+ehTA2AHYF9+6HVD64gYgiwxNNSMFFLoWQgxFVQNbereG9jUWfI+ven3mU
kFaiKgjSHZqyYXGPgOPy
=txio
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2692-1
July 28, 2015
qemu vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 15.04
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in QEMU.
Software Description:
- qemu: Machine emulator and virtualizer
Details:
Matt Tait discovered that QEMU incorrectly handled PIT emulation. In a
non-default configuration, a malicious guest could use this issue to cause
a denial of service, or possibly execute arbitrary code on the host as the
user running the QEMU process. In the default installation, when QEMU is
used with libvirt, attackers would be isolated by the libvirt AppArmor
profile. (CVE-2015-3214)
Kevin Wolf discovered that QEMU incorrectly handled processing ATAPI
commands. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2015-5154)
Zhu Donghai discovered that QEMU incorrectly handled the SCSI driver. A
malicious guest could use this issue to cause a denial of service, or
possibly execute arbitrary code on the host as the user running the QEMU
process. In the default installation, when QEMU is used with libvirt,
attackers would be isolated by the libvirt AppArmor profile. This issue
only affected Ubuntu 15.04. (CVE-2015-5158)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 15.04:
qemu-system 1:2.2+dfsg-5expubuntu9.3
qemu-system-aarch64 1:2.2+dfsg-5expubuntu9.3
qemu-system-arm 1:2.2+dfsg-5expubuntu9.3
qemu-system-mips 1:2.2+dfsg-5expubuntu9.3
qemu-system-misc 1:2.2+dfsg-5expubuntu9.3
qemu-system-ppc 1:2.2+dfsg-5expubuntu9.3
qemu-system-sparc 1:2.2+dfsg-5expubuntu9.3
qemu-system-x86 1:2.2+dfsg-5expubuntu9.3
Ubuntu 14.04 LTS:
qemu-system 2.0.0+dfsg-2ubuntu1.15
qemu-system-aarch64 2.0.0+dfsg-2ubuntu1.15
qemu-system-arm 2.0.0+dfsg-2ubuntu1.15
qemu-system-mips 2.0.0+dfsg-2ubuntu1.15
qemu-system-misc 2.0.0+dfsg-2ubuntu1.15
qemu-system-ppc 2.0.0+dfsg-2ubuntu1.15
qemu-system-sparc 2.0.0+dfsg-2ubuntu1.15
qemu-system-x86 2.0.0+dfsg-2ubuntu1.15
After a standard system update you need to restart all QEMU virtual
machines to make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2692-1
CVE-2015-3214, CVE-2015-5154, CVE-2015-5158
Package Information:
https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.3
https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.15
Version: GnuPG v1
iQIcBAEBCgAGBQJVt7EFAAoJEGVp2FWnRL6TAOYQAJaudq+tp9MiOFKvV0QiSAbq
mWbxhfJuACwbJ6VkKnmwOvU6oq+k5Wxm38r2MDGDaCA7V5wbUnZWqAyiW2dHsYAo
pwTBGgUAjZYHNKGXQtuk96uPYhrxGb8e7bvv5MAmO/2C3w7VJTLeaJySIMHqWeB5
EMKvFP+yeCG394x/FBua8IB9N5vUjIwuTc2hrIjon5AjWrVAHF0Pcj3s67jWiZrT
FU+AEm5zd2fvBhm/6pTtqyF5PcnQqJC918EuU0MH4FPVqHpkJzt9XHIAi1HJ952Q
AwMOMxOOoBQpaJ7CmE9sugw3K0hWn8Q6FIFkAIUWzkDW7efgWyaDZ7OhrnWt+Inm
tcAV13Agh4COPNcrS0XnJIaXWygXn/NOp1y5c78IyObLRSiJXjgqc65rd35HrrST
qqdo+JnnZmBHKvli+L6FDGf2EqUQDqynLkwrsLlGKYaxazctQVdlB3N887QDibKi
HQANTx4iZF84wCShbMyydBmRnvnyuPKX3Lich8Sd2n1g6KVKt8B77HWu8ZanqaDM
zRvP1R7okuHSlngMI3XufpEScMfh4UrRjCOXUD8T8EonquD5DWBqUJgWaUuKhswK
viSTCB+ehTA2AHYF9+6HVD64gYgiwxNNSMFFLoWQgxFVQNbereG9jUWfI+ven3mU
kFaiKgjSHZqyYXGPgOPy
=txio
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2692-1
July 28, 2015
qemu vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 15.04
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in QEMU.
Software Description:
- qemu: Machine emulator and virtualizer
Details:
Matt Tait discovered that QEMU incorrectly handled PIT emulation. In a
non-default configuration, a malicious guest could use this issue to cause
a denial of service, or possibly execute arbitrary code on the host as the
user running the QEMU process. In the default installation, when QEMU is
used with libvirt, attackers would be isolated by the libvirt AppArmor
profile. (CVE-2015-3214)
Kevin Wolf discovered that QEMU incorrectly handled processing ATAPI
commands. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2015-5154)
Zhu Donghai discovered that QEMU incorrectly handled the SCSI driver. A
malicious guest could use this issue to cause a denial of service, or
possibly execute arbitrary code on the host as the user running the QEMU
process. In the default installation, when QEMU is used with libvirt,
attackers would be isolated by the libvirt AppArmor profile. This issue
only affected Ubuntu 15.04. (CVE-2015-5158)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 15.04:
qemu-system 1:2.2+dfsg-5expubuntu9.3
qemu-system-aarch64 1:2.2+dfsg-5expubuntu9.3
qemu-system-arm 1:2.2+dfsg-5expubuntu9.3
qemu-system-mips 1:2.2+dfsg-5expubuntu9.3
qemu-system-misc 1:2.2+dfsg-5expubuntu9.3
qemu-system-ppc 1:2.2+dfsg-5expubuntu9.3
qemu-system-sparc 1:2.2+dfsg-5expubuntu9.3
qemu-system-x86 1:2.2+dfsg-5expubuntu9.3
Ubuntu 14.04 LTS:
qemu-system 2.0.0+dfsg-2ubuntu1.15
qemu-system-aarch64 2.0.0+dfsg-2ubuntu1.15
qemu-system-arm 2.0.0+dfsg-2ubuntu1.15
qemu-system-mips 2.0.0+dfsg-2ubuntu1.15
qemu-system-misc 2.0.0+dfsg-2ubuntu1.15
qemu-system-ppc 2.0.0+dfsg-2ubuntu1.15
qemu-system-sparc 2.0.0+dfsg-2ubuntu1.15
qemu-system-x86 2.0.0+dfsg-2ubuntu1.15
After a standard system update you need to restart all QEMU virtual
machines to make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2692-1
CVE-2015-3214, CVE-2015-5154, CVE-2015-5158
Package Information:
https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.3
https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.15
reallost1.fbsd2233449 zgz9y
reallost1.fbsd2233449
附件中的内容希望对您的工作过和学习有所帮助,感谢您百忙中查收这份邮件!
司徒亮忠
祝您工作愉快,事业腾达
[CentOS-announce] CESA-2015:1510 Moderate CentOS 7 clutter Security Update
CentOS Errata and Security Advisory 2015:1510 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1510.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
422da424622a034a70451c8cf418aa35af6b5ee7270ed7917d7d6567cfd3db1b clutter-1.14.4-12.el7_1.1.i686.rpm
f4bbca8534f0fa1fff3b5ceb525df8b7a63787439daddcbe4e3105143c551804 clutter-1.14.4-12.el7_1.1.x86_64.rpm
de955940935d5530a58439afb7e6ccf6e59607b93c8085a89f911d76c6dd4241 clutter-devel-1.14.4-12.el7_1.1.i686.rpm
269a7293b0dba679ae8ca3a6e926076f8935a1334cb923e86f38d92173ddf0e4 clutter-devel-1.14.4-12.el7_1.1.x86_64.rpm
cb2f6e0a5e1de37806d8db6afbe1c66f712e7bf5e78d5246725cd3a62fe9cf48 clutter-doc-1.14.4-12.el7_1.1.x86_64.rpm
Source:
5a5c7ba92da951a3b9e973efb0635d08b470ebe9de33c19a746d52f9491e9ac7 clutter-1.14.4-12.el7_1.1.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1510.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
422da424622a034a70451c8cf418aa35af6b5ee7270ed7917d7d6567cfd3db1b clutter-1.14.4-12.el7_1.1.i686.rpm
f4bbca8534f0fa1fff3b5ceb525df8b7a63787439daddcbe4e3105143c551804 clutter-1.14.4-12.el7_1.1.x86_64.rpm
de955940935d5530a58439afb7e6ccf6e59607b93c8085a89f911d76c6dd4241 clutter-devel-1.14.4-12.el7_1.1.i686.rpm
269a7293b0dba679ae8ca3a6e926076f8935a1334cb923e86f38d92173ddf0e4 clutter-devel-1.14.4-12.el7_1.1.x86_64.rpm
cb2f6e0a5e1de37806d8db6afbe1c66f712e7bf5e78d5246725cd3a62fe9cf48 clutter-doc-1.14.4-12.el7_1.1.x86_64.rpm
Source:
5a5c7ba92da951a3b9e973efb0635d08b470ebe9de33c19a746d52f9491e9ac7 clutter-1.14.4-12.el7_1.1.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[USN-2691-1] Linux kernel vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJVt0pMAAoJEAUvNnAY1cPYdK4P/0il6XKeIX2IzEsydOYT4RdR
hwFZl6/6oESO2tgWawCB6NPWAnPryJDjQwKSgXu+TSLjX5wDbX3MDEw2moYIw9NM
NB1YWeUJ+CUq7rw0cfdGNUESaaSWJ6soIoJfl7PMjCj90LvoDnmu5CqMje7Rv8Tt
ax8rFKU5MPdaCf6/GYz6kT29JhjQLGxQyA0g1+XJ/49n47imN4wYI+1QAYsG15F/
hPmgBJJXhGb8mq745RcPslA0OqXddvCzAuWQwMkyxJaEq8xCXTnQb9XFaoAAn3Zw
73XhmOgiv0SXyPpfdgF8R5J80Uwdk6CTgFvNxF6d8f/c7y6/xHQreJWJKNDdthsY
iCnuobI8aOVV0obbz54E/f6xsrnipZQChPTcPts+TRIuTwYN8wf7KYAhePp9qhiA
ga4931NBOSqjXxY4ibFxmx3K5xmLBR954DMiVyPNBHfRKCCWMJfMUVyE5fl9Cx1j
c15qRtgdAGmkIcmhU/EBmfvaKH9d0i8DQLA7r0lj5RKgVEcfqi3uU763jlFqgbfw
oblqsy6IKtCoS6gZlo3561Yh0l+bMyW3QfKIo9pCYM7J3BATxN/E02dDIVoYc6+H
dHA0VITN/fvBO26SKmnuA6CNVJRsAFBXHh8sCNCRx8qhpvGIxqvH4SKZXAlncqOb
8+RvhXQhPtZemWdz6OYv
=Spy7
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2691-1
July 28, 2015
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 15.04
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs resulting in unspecified effects. (CVE-2015-3291)
Andy Lutomirski and Petr Matousek discovered that an NMI (non-maskable
interrupt) that interrupts userspace and encounters an IRET fault is
incorrectly handled by the Linux kernel. An unprivileged local user could
exploit this flaw to cause a denial of service (kernel OOPs), corruption,
or potentially escalate privileges on the system. (CVE-2015-5157)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 15.04:
linux-image-3.19.0-25-generic 3.19.0-25.26
linux-image-3.19.0-25-generic-lpae 3.19.0-25.26
linux-image-3.19.0-25-lowlatency 3.19.0-25.26
linux-image-3.19.0-25-powerpc-e500mc 3.19.0-25.26
linux-image-3.19.0-25-powerpc-smp 3.19.0-25.26
linux-image-3.19.0-25-powerpc64-emb 3.19.0-25.26
linux-image-3.19.0-25-powerpc64-smp 3.19.0-25.26
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2691-1
CVE-2015-1333, CVE-2015-3290, CVE-2015-3291, CVE-2015-5157
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.19.0-25.26
Version: GnuPG v1
iQIcBAEBCgAGBQJVt0pMAAoJEAUvNnAY1cPYdK4P/0il6XKeIX2IzEsydOYT4RdR
hwFZl6/6oESO2tgWawCB6NPWAnPryJDjQwKSgXu+TSLjX5wDbX3MDEw2moYIw9NM
NB1YWeUJ+CUq7rw0cfdGNUESaaSWJ6soIoJfl7PMjCj90LvoDnmu5CqMje7Rv8Tt
ax8rFKU5MPdaCf6/GYz6kT29JhjQLGxQyA0g1+XJ/49n47imN4wYI+1QAYsG15F/
hPmgBJJXhGb8mq745RcPslA0OqXddvCzAuWQwMkyxJaEq8xCXTnQb9XFaoAAn3Zw
73XhmOgiv0SXyPpfdgF8R5J80Uwdk6CTgFvNxF6d8f/c7y6/xHQreJWJKNDdthsY
iCnuobI8aOVV0obbz54E/f6xsrnipZQChPTcPts+TRIuTwYN8wf7KYAhePp9qhiA
ga4931NBOSqjXxY4ibFxmx3K5xmLBR954DMiVyPNBHfRKCCWMJfMUVyE5fl9Cx1j
c15qRtgdAGmkIcmhU/EBmfvaKH9d0i8DQLA7r0lj5RKgVEcfqi3uU763jlFqgbfw
oblqsy6IKtCoS6gZlo3561Yh0l+bMyW3QfKIo9pCYM7J3BATxN/E02dDIVoYc6+H
dHA0VITN/fvBO26SKmnuA6CNVJRsAFBXHh8sCNCRx8qhpvGIxqvH4SKZXAlncqOb
8+RvhXQhPtZemWdz6OYv
=Spy7
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2691-1
July 28, 2015
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 15.04
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs resulting in unspecified effects. (CVE-2015-3291)
Andy Lutomirski and Petr Matousek discovered that an NMI (non-maskable
interrupt) that interrupts userspace and encounters an IRET fault is
incorrectly handled by the Linux kernel. An unprivileged local user could
exploit this flaw to cause a denial of service (kernel OOPs), corruption,
or potentially escalate privileges on the system. (CVE-2015-5157)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 15.04:
linux-image-3.19.0-25-generic 3.19.0-25.26
linux-image-3.19.0-25-generic-lpae 3.19.0-25.26
linux-image-3.19.0-25-lowlatency 3.19.0-25.26
linux-image-3.19.0-25-powerpc-e500mc 3.19.0-25.26
linux-image-3.19.0-25-powerpc-smp 3.19.0-25.26
linux-image-3.19.0-25-powerpc64-emb 3.19.0-25.26
linux-image-3.19.0-25-powerpc64-smp 3.19.0-25.26
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2691-1
CVE-2015-1333, CVE-2015-3290, CVE-2015-3291, CVE-2015-5157
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.19.0-25.26
[USN-2690-1] Linux kernel (Vivid HWE) vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJVt0okAAoJEAUvNnAY1cPYTwoP/2Vzy82FTLOHUGxbzGd/YLiJ
OESY+stkklLKlsfXIzKgK63P6zmWhtxoBBYcVnJ7RPxKSH0avRgXUHG4hEo1N+am
Z23jOEEbD47cBr2w/tAX+hJoEluVM48g6YXwuH2GTaEW+OYjmm/+VdEC8rjkK8mL
X4/kNs2TkKwVyHED6VPidosavKDgKHUthUe8oZvRa7oapU4iK6wQiXCWgAFZ9PBB
yUT50UXITbh8e5H78gwCXIu8XPZNB6TBacsBs1IE0F52CkudnUmDIUaLob1mpUdU
ojOErb1ehfMRA2O3LvFXHhI0Ev14TXJPCgu5ZfGLLIRqKeSAlF/KUSFd47mZdHlc
hSR5wlglNnU5oKAI0Cu/ZRKI26prTISQCXfascovtedOSJ/POjPr2O6L5y7RXoOc
aGAnwJIhDRJxH3LsO2S4FMNwR+PqGJPkmmxA0hdSOFdFHFR+bbc7g127Ty8pAuWq
s7y/2vlh4M5Nq7VHxVYOERxvZnGWFhZ8a7T/UTKHPijUIRuw/GNyqYuM5uvzX49S
idjb81trd/ueDBhPbe2aLplUmlB+6mtzl1Etwijk/rPfQ2hCyH9DVdIwlopA2lMd
lvmMuf/wCovMpOEm8hZi53QPioGJ5AqFf1MfuTNXjGJ2uYoX1c17Zpy2WDC2j2VW
4QaH1WvpntEhAHmWzejp
=nvXh
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2690-1
July 28, 2015
linux-lts-vivid vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-vivid: Linux hardware enablement kernel from Vivid
Details:
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs resulting in unspecified effects. (CVE-2015-3291)
Andy Lutomirski and Petr Matousek discovered that an NMI (non-maskable
interrupt) that interrupts userspace and encounters an IRET fault is
incorrectly handled by the Linux kernel. An unprivileged local user could
exploit this flaw to cause a denial of service (kernel OOPs), corruption,
or potentially escalate privileges on the system. (CVE-2015-5157)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
linux-image-3.19.0-25-generic 3.19.0-25.26~14.04.1
linux-image-3.19.0-25-generic-lpae 3.19.0-25.26~14.04.1
linux-image-3.19.0-25-lowlatency 3.19.0-25.26~14.04.1
linux-image-3.19.0-25-powerpc-e500mc 3.19.0-25.26~14.04.1
linux-image-3.19.0-25-powerpc-smp 3.19.0-25.26~14.04.1
linux-image-3.19.0-25-powerpc64-emb 3.19.0-25.26~14.04.1
linux-image-3.19.0-25-powerpc64-smp 3.19.0-25.26~14.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2690-1
CVE-2015-1333, CVE-2015-3290, CVE-2015-3291, CVE-2015-5157
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-vivid/3.19.0-25.26~14.04.1
Version: GnuPG v1
iQIcBAEBCgAGBQJVt0okAAoJEAUvNnAY1cPYTwoP/2Vzy82FTLOHUGxbzGd/YLiJ
OESY+stkklLKlsfXIzKgK63P6zmWhtxoBBYcVnJ7RPxKSH0avRgXUHG4hEo1N+am
Z23jOEEbD47cBr2w/tAX+hJoEluVM48g6YXwuH2GTaEW+OYjmm/+VdEC8rjkK8mL
X4/kNs2TkKwVyHED6VPidosavKDgKHUthUe8oZvRa7oapU4iK6wQiXCWgAFZ9PBB
yUT50UXITbh8e5H78gwCXIu8XPZNB6TBacsBs1IE0F52CkudnUmDIUaLob1mpUdU
ojOErb1ehfMRA2O3LvFXHhI0Ev14TXJPCgu5ZfGLLIRqKeSAlF/KUSFd47mZdHlc
hSR5wlglNnU5oKAI0Cu/ZRKI26prTISQCXfascovtedOSJ/POjPr2O6L5y7RXoOc
aGAnwJIhDRJxH3LsO2S4FMNwR+PqGJPkmmxA0hdSOFdFHFR+bbc7g127Ty8pAuWq
s7y/2vlh4M5Nq7VHxVYOERxvZnGWFhZ8a7T/UTKHPijUIRuw/GNyqYuM5uvzX49S
idjb81trd/ueDBhPbe2aLplUmlB+6mtzl1Etwijk/rPfQ2hCyH9DVdIwlopA2lMd
lvmMuf/wCovMpOEm8hZi53QPioGJ5AqFf1MfuTNXjGJ2uYoX1c17Zpy2WDC2j2VW
4QaH1WvpntEhAHmWzejp
=nvXh
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2690-1
July 28, 2015
linux-lts-vivid vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-vivid: Linux hardware enablement kernel from Vivid
Details:
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs resulting in unspecified effects. (CVE-2015-3291)
Andy Lutomirski and Petr Matousek discovered that an NMI (non-maskable
interrupt) that interrupts userspace and encounters an IRET fault is
incorrectly handled by the Linux kernel. An unprivileged local user could
exploit this flaw to cause a denial of service (kernel OOPs), corruption,
or potentially escalate privileges on the system. (CVE-2015-5157)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
linux-image-3.19.0-25-generic 3.19.0-25.26~14.04.1
linux-image-3.19.0-25-generic-lpae 3.19.0-25.26~14.04.1
linux-image-3.19.0-25-lowlatency 3.19.0-25.26~14.04.1
linux-image-3.19.0-25-powerpc-e500mc 3.19.0-25.26~14.04.1
linux-image-3.19.0-25-powerpc-smp 3.19.0-25.26~14.04.1
linux-image-3.19.0-25-powerpc64-emb 3.19.0-25.26~14.04.1
linux-image-3.19.0-25-powerpc64-smp 3.19.0-25.26~14.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2690-1
CVE-2015-1333, CVE-2015-3290, CVE-2015-3291, CVE-2015-5157
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-vivid/3.19.0-25.26~14.04.1
[USN-2689-1] Linux kernel (Utopic HWE) vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJVt0oFAAoJEAUvNnAY1cPYzZ0P/1U4BymHnzhHdURaKrwwJRXd
/8VdwawG2GQ4COCdYgoVU/w37PdNwlxjjE5QyfMrDHem/mmVb80GyYEuWYL2ipJP
qFpToGmOfEcInq+tCqEu8qhpnbjGYwrHxD4sfSxuheHTMFUTAYGkhgmZ/rO088mf
x0r/fl73uN5m2W2IB0YK6Q7buF5oywLFpSl9rqBRtvzHvkvMR0V3bV4bf3mGOaKe
IamY4OL9kUNcVvMpM4kAGeHKCYJw6o6vncNKJObjLXSvHuJbwM6KLT9IXSstl+c8
Mgkme18hcXRCVm2K3bOk/F3f97nzpVSPGgYb2aenooXwKUd8Frew4yadkiFo99BG
XzauWWX+GEXZ89AoTYOE18bi5JrNQeNDP8l1ciulv65i3eEUOwzzO1zP7Xj1GSbt
4fM2lmtVuUQpF3PbF0GK8G0I1TskRQlcQpYz2l7se8u9aQQ/vyGMKUBMFw3J+h+c
GiIWZlt1ZROSuqH3esIMdJUtJvqpVgROVSPVIDvPdwkzwJzmI3B4E6peVbo4GiMo
uzcSqhMFrcVhnrte77zUQxd4iK9ktE2nOX5KeinAJ+ETWM6IlEcfVgn7vtv1TzL6
sSbBsCE8k+1oPuuD7sWooS4ZBWHlTB1EudCU5VZMPOrK3crqVB//qVq+ttlMQl7C
1a4Fvu4vyKOxYPywGvJ6
=tr2X
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2689-1
July 28, 2015
linux-lts-utopic vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-utopic: Linux hardware enablement kernel from Utopic
Details:
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs resulting in unspecified effects. (CVE-2015-3291)
Andy Lutomirski and Petr Matousek discovered that an NMI (non-maskable
interrupt) that interrupts userspace and encounters an IRET fault is
incorrectly handled by the Linux kernel. An unprivileged local user could
exploit this flaw to cause a denial of service (kernel OOPs), corruption,
or potentially escalate privileges on the system. (CVE-2015-5157)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
linux-image-3.16.0-45-generic 3.16.0-45.60~14.04.1
linux-image-3.16.0-45-generic-lpae 3.16.0-45.60~14.04.1
linux-image-3.16.0-45-lowlatency 3.16.0-45.60~14.04.1
linux-image-3.16.0-45-powerpc-e500mc 3.16.0-45.60~14.04.1
linux-image-3.16.0-45-powerpc-smp 3.16.0-45.60~14.04.1
linux-image-3.16.0-45-powerpc64-emb 3.16.0-45.60~14.04.1
linux-image-3.16.0-45-powerpc64-smp 3.16.0-45.60~14.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2689-1
CVE-2015-1333, CVE-2015-3290, CVE-2015-3291, CVE-2015-5157
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-45.60~14.04.1
Version: GnuPG v1
iQIcBAEBCgAGBQJVt0oFAAoJEAUvNnAY1cPYzZ0P/1U4BymHnzhHdURaKrwwJRXd
/8VdwawG2GQ4COCdYgoVU/w37PdNwlxjjE5QyfMrDHem/mmVb80GyYEuWYL2ipJP
qFpToGmOfEcInq+tCqEu8qhpnbjGYwrHxD4sfSxuheHTMFUTAYGkhgmZ/rO088mf
x0r/fl73uN5m2W2IB0YK6Q7buF5oywLFpSl9rqBRtvzHvkvMR0V3bV4bf3mGOaKe
IamY4OL9kUNcVvMpM4kAGeHKCYJw6o6vncNKJObjLXSvHuJbwM6KLT9IXSstl+c8
Mgkme18hcXRCVm2K3bOk/F3f97nzpVSPGgYb2aenooXwKUd8Frew4yadkiFo99BG
XzauWWX+GEXZ89AoTYOE18bi5JrNQeNDP8l1ciulv65i3eEUOwzzO1zP7Xj1GSbt
4fM2lmtVuUQpF3PbF0GK8G0I1TskRQlcQpYz2l7se8u9aQQ/vyGMKUBMFw3J+h+c
GiIWZlt1ZROSuqH3esIMdJUtJvqpVgROVSPVIDvPdwkzwJzmI3B4E6peVbo4GiMo
uzcSqhMFrcVhnrte77zUQxd4iK9ktE2nOX5KeinAJ+ETWM6IlEcfVgn7vtv1TzL6
sSbBsCE8k+1oPuuD7sWooS4ZBWHlTB1EudCU5VZMPOrK3crqVB//qVq+ttlMQl7C
1a4Fvu4vyKOxYPywGvJ6
=tr2X
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2689-1
July 28, 2015
linux-lts-utopic vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-utopic: Linux hardware enablement kernel from Utopic
Details:
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs resulting in unspecified effects. (CVE-2015-3291)
Andy Lutomirski and Petr Matousek discovered that an NMI (non-maskable
interrupt) that interrupts userspace and encounters an IRET fault is
incorrectly handled by the Linux kernel. An unprivileged local user could
exploit this flaw to cause a denial of service (kernel OOPs), corruption,
or potentially escalate privileges on the system. (CVE-2015-5157)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
linux-image-3.16.0-45-generic 3.16.0-45.60~14.04.1
linux-image-3.16.0-45-generic-lpae 3.16.0-45.60~14.04.1
linux-image-3.16.0-45-lowlatency 3.16.0-45.60~14.04.1
linux-image-3.16.0-45-powerpc-e500mc 3.16.0-45.60~14.04.1
linux-image-3.16.0-45-powerpc-smp 3.16.0-45.60~14.04.1
linux-image-3.16.0-45-powerpc64-emb 3.16.0-45.60~14.04.1
linux-image-3.16.0-45-powerpc64-smp 3.16.0-45.60~14.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2689-1
CVE-2015-1333, CVE-2015-3290, CVE-2015-3291, CVE-2015-5157
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-45.60~14.04.1
[USN-2688-1] Linux kernel vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJVt0nnAAoJEAUvNnAY1cPYDJsP/iUTBluSOmCefBWVr3bzImGJ
enyj5jVuViS7U3Hx+bW3JXS1U1gxUNBo3Y/M6lNgcvn7FdC9hIn4a+R4QIngB13O
ocxQrk5Bn2nX87YqiVNpfmYMVFlVu2bRQUJn29+L0pnFjnxulzvdRlNxNeDa533r
YpPgYKIYzYYNhvcnr2TKpcWnGwLxz7T2DkFSxvz7H6wzEPUsVVf3JGnJ2MLkNFWf
EQjHfis4dD7/oMtoWzFU9As0Uf20ZzBfg5W4vAZBtwObJWfixBpkE/wbfCrSkpSx
Igj259JXEzQgtr2fE0WBlPBi/nqPAhlbQ4mxfOOUW8GPKA6Uqe47gZNSwGtcuiU9
iIqRxqE8ZzwR3xqF6Q855Aa1/YTkB4plf7USaUXWKIpcnJzR24i9SP6yQA6H7Xam
dnDVADY3ZzNa9S8pW6X5llnF25aDhVG0OtUvIkJzaLQKMgROBpswU3Fm9v4bNMy+
epo81IYrenMq4ZUAm88m2vAYWKex7ePQbJTyMByD+Ss/m1ZCmJVuYdR9+rD4Vch3
9BOJnDHVp8hu0lK/UdE3BxddujTSoQNN3HnkQLwwRM7F156MUKmgEZVKtU/WdJJo
Ubm5L91UsW0Hctx/Hh/oUMq+oQtx4wXf2dBgS2WvRNrUteFcvxrj7GLp2jPZSLgs
qOSwdV8UJ687aGxcaEwK
=PLGG
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2688-1
July 28, 2015
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs resulting in unspecified effects. (CVE-2015-3291)
Andy Lutomirski and Petr Matousek discovered that an NMI (non-maskable
interrupt) that interrupts userspace and encounters an IRET fault is
incorrectly handled by the Linux kernel. An unprivileged local user could
exploit this flaw to cause a denial of service (kernel OOPs), corruption,
or potentially escalate privileges on the system. (CVE-2015-5157)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
linux-image-3.13.0-59-generic 3.13.0-59.98
linux-image-3.13.0-59-generic-lpae 3.13.0-59.98
linux-image-3.13.0-59-lowlatency 3.13.0-59.98
linux-image-3.13.0-59-powerpc-e500 3.13.0-59.98
linux-image-3.13.0-59-powerpc-e500mc 3.13.0-59.98
linux-image-3.13.0-59-powerpc-smp 3.13.0-59.98
linux-image-3.13.0-59-powerpc64-emb 3.13.0-59.98
linux-image-3.13.0-59-powerpc64-smp 3.13.0-59.98
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2688-1
CVE-2015-1333, CVE-2015-3290, CVE-2015-3291, CVE-2015-5157
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.13.0-59.98
Version: GnuPG v1
iQIcBAEBCgAGBQJVt0nnAAoJEAUvNnAY1cPYDJsP/iUTBluSOmCefBWVr3bzImGJ
enyj5jVuViS7U3Hx+bW3JXS1U1gxUNBo3Y/M6lNgcvn7FdC9hIn4a+R4QIngB13O
ocxQrk5Bn2nX87YqiVNpfmYMVFlVu2bRQUJn29+L0pnFjnxulzvdRlNxNeDa533r
YpPgYKIYzYYNhvcnr2TKpcWnGwLxz7T2DkFSxvz7H6wzEPUsVVf3JGnJ2MLkNFWf
EQjHfis4dD7/oMtoWzFU9As0Uf20ZzBfg5W4vAZBtwObJWfixBpkE/wbfCrSkpSx
Igj259JXEzQgtr2fE0WBlPBi/nqPAhlbQ4mxfOOUW8GPKA6Uqe47gZNSwGtcuiU9
iIqRxqE8ZzwR3xqF6Q855Aa1/YTkB4plf7USaUXWKIpcnJzR24i9SP6yQA6H7Xam
dnDVADY3ZzNa9S8pW6X5llnF25aDhVG0OtUvIkJzaLQKMgROBpswU3Fm9v4bNMy+
epo81IYrenMq4ZUAm88m2vAYWKex7ePQbJTyMByD+Ss/m1ZCmJVuYdR9+rD4Vch3
9BOJnDHVp8hu0lK/UdE3BxddujTSoQNN3HnkQLwwRM7F156MUKmgEZVKtU/WdJJo
Ubm5L91UsW0Hctx/Hh/oUMq+oQtx4wXf2dBgS2WvRNrUteFcvxrj7GLp2jPZSLgs
qOSwdV8UJ687aGxcaEwK
=PLGG
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2688-1
July 28, 2015
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs resulting in unspecified effects. (CVE-2015-3291)
Andy Lutomirski and Petr Matousek discovered that an NMI (non-maskable
interrupt) that interrupts userspace and encounters an IRET fault is
incorrectly handled by the Linux kernel. An unprivileged local user could
exploit this flaw to cause a denial of service (kernel OOPs), corruption,
or potentially escalate privileges on the system. (CVE-2015-5157)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
linux-image-3.13.0-59-generic 3.13.0-59.98
linux-image-3.13.0-59-generic-lpae 3.13.0-59.98
linux-image-3.13.0-59-lowlatency 3.13.0-59.98
linux-image-3.13.0-59-powerpc-e500 3.13.0-59.98
linux-image-3.13.0-59-powerpc-e500mc 3.13.0-59.98
linux-image-3.13.0-59-powerpc-smp 3.13.0-59.98
linux-image-3.13.0-59-powerpc64-emb 3.13.0-59.98
linux-image-3.13.0-59-powerpc64-smp 3.13.0-59.98
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2688-1
CVE-2015-1333, CVE-2015-3290, CVE-2015-3291, CVE-2015-5157
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.13.0-59.98
[USN-2687-1] Linux kernel (Trusty HWE) vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJVt0nAAAoJEAUvNnAY1cPYlssP/iui6WsNLKdYwlHSKcqm3c7A
L/SzLJa5UJEWqTkJw78hBefiHrYantyzSxQMgcKFqXknysnI4wUEpydVhUqXDynj
Aq6pBDMX8/71gIuULNUxEgQpjEyRTkcbYIlJ8uUCLPpwDavO34+en79lZVZMb+5l
LgEfLRoOI8eCpc3o3yyHmxhJNqqgSyY02Apl45FF4Jy1B82a1iZR6/vQb9Ivc1le
ISBUCXInouWrJE4V5SIXhH1CI0+Ot9G0a2QzjAvjSMKTgze1G8cQJKJEOO8RJotm
6+cm69g4Y3rBwz7P5d79JxOVMZoGFgm18paw+OD74lggM4SeW/k60Mp1ngwRsGKX
W4Rd8BIc6zMYR5TANj7hMXwWBKuejBsvOIvJbB/Rb4BNfKg6fZIbWBkKw22wZWsW
5srSetE861Rn8foc7zG0TnAv3J/KrMFJkhULTmoluAVSeBAJYlGwenaKjweFucId
j0WZ3exrVfz3l8c5Q1MuThbuvOZ93BntGwmZq7yyaZFDWPp4sEA1/kDfdkF7YV49
ut2ghc+AAfNTcY+idQPqcPdYoJXBfDtkni9zOQruwcaWb89oszkVOi1EZktdJt2y
W5828dMwkCcYJRqul6NGFMCXObZmRVmgaI0wUyTFVJTlWXJTxZPhNqZ/2jtPQ7DJ
WLoixAqQZOeI4mUhiWJl
=UMjC
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2687-1
July 28, 2015
linux-lts-trusty vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-trusty: Linux hardware enablement kernel from Trusty
Details:
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs resulting in unspecified effects. (CVE-2015-3291)
Andy Lutomirski and Petr Matousek discovered that an NMI (non-maskable
interrupt) that interrupts userspace and encounters an IRET fault is
incorrectly handled by the Linux kernel. An unprivileged local user could
exploit this flaw to cause a denial of service (kernel OOPs), corruption,
or potentially escalate privileges on the system. (CVE-2015-5157)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.13.0-59-generic 3.13.0-59.98~precise1
linux-image-3.13.0-59-generic-lpae 3.13.0-59.98~precise1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2687-1
CVE-2015-1333, CVE-2015-3290, CVE-2015-3291, CVE-2015-5157
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-59.98~precise1
Version: GnuPG v1
iQIcBAEBCgAGBQJVt0nAAAoJEAUvNnAY1cPYlssP/iui6WsNLKdYwlHSKcqm3c7A
L/SzLJa5UJEWqTkJw78hBefiHrYantyzSxQMgcKFqXknysnI4wUEpydVhUqXDynj
Aq6pBDMX8/71gIuULNUxEgQpjEyRTkcbYIlJ8uUCLPpwDavO34+en79lZVZMb+5l
LgEfLRoOI8eCpc3o3yyHmxhJNqqgSyY02Apl45FF4Jy1B82a1iZR6/vQb9Ivc1le
ISBUCXInouWrJE4V5SIXhH1CI0+Ot9G0a2QzjAvjSMKTgze1G8cQJKJEOO8RJotm
6+cm69g4Y3rBwz7P5d79JxOVMZoGFgm18paw+OD74lggM4SeW/k60Mp1ngwRsGKX
W4Rd8BIc6zMYR5TANj7hMXwWBKuejBsvOIvJbB/Rb4BNfKg6fZIbWBkKw22wZWsW
5srSetE861Rn8foc7zG0TnAv3J/KrMFJkhULTmoluAVSeBAJYlGwenaKjweFucId
j0WZ3exrVfz3l8c5Q1MuThbuvOZ93BntGwmZq7yyaZFDWPp4sEA1/kDfdkF7YV49
ut2ghc+AAfNTcY+idQPqcPdYoJXBfDtkni9zOQruwcaWb89oszkVOi1EZktdJt2y
W5828dMwkCcYJRqul6NGFMCXObZmRVmgaI0wUyTFVJTlWXJTxZPhNqZ/2jtPQ7DJ
WLoixAqQZOeI4mUhiWJl
=UMjC
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2687-1
July 28, 2015
linux-lts-trusty vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-trusty: Linux hardware enablement kernel from Trusty
Details:
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs resulting in unspecified effects. (CVE-2015-3291)
Andy Lutomirski and Petr Matousek discovered that an NMI (non-maskable
interrupt) that interrupts userspace and encounters an IRET fault is
incorrectly handled by the Linux kernel. An unprivileged local user could
exploit this flaw to cause a denial of service (kernel OOPs), corruption,
or potentially escalate privileges on the system. (CVE-2015-5157)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.13.0-59-generic 3.13.0-59.98~precise1
linux-image-3.13.0-59-generic-lpae 3.13.0-59.98~precise1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2687-1
CVE-2015-1333, CVE-2015-3290, CVE-2015-3291, CVE-2015-5157
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-59.98~precise1
Monday, July 27, 2015
[USN-2686-1] Apache HTTP Server vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJVtnEgAAoJEGVp2FWnRL6TLDQP/izUDoZluIVt490NmuHFTBeN
D64GSpjdL7wLRuzAnBxKLcXp7Nd9OIXiFp0HQkVzrrhKOtxBj6mKwjRRP6CrZ3ax
oQ2vUWhYgEFPZsovT9Yp37TwQfJGjVS9XaxYmcq6zaBaln1orAggqeUAHPzXFPX1
+ehsyjCrdBgsc6f+3Xyg8f2y1+ef3iU+v+nYwi4Rd2sjB0/49U0B3ljzqfaESdbJ
D3hErOZ8uwKts2hLNgT6N0lIpCFOoXGLE8Oy+os2NEz63+/fZ5MF8FbQZzRkOZaf
5AtDyWyz7niOGT6DGpICueJlh/g3DvPI/5YRTTrKYuNOJdQKNStmUcRH6jKstBY3
seTAzs+xn/HQV8kGO7Drv0QYPcjkZDU6pRUhZpb4olMGeHm/3ShalQmoGDdC4aGH
AoFbPASJO3L8QHbNxuMWosNpA4xMd3DRyosCa1ZuehCLfigo4gz5zpPJ8Ih6qDBR
moK5+FE6XA3D/kpdfTKuUcX4wq0mAC9dZj3a4ecwr5oKWCZSYMZN7EDRp6C0cYkm
avgTAW/JgotjfPDz0/U5KN5XxvlbhRUz59qwaiWRp+xUBvJZBPs8LOKtOTcWBhh8
vA6KcxG2SPA/tprkIJNEHn44MMjpMKeeiAW4I+KgJHw3cfuLnI/dxfuNY4aeolgW
yDZIZCXSRCrmiaCqy7od
=juYX
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2686-1
July 27, 2015
apache2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the Apache HTTP server.
Software Description:
- apache2: Apache HTTP server
Details:
It was discovered that the Apache HTTP Server incorrectly parsed chunk
headers. A remote attacker could possibly use this issue to perform HTTP
request smuggling attacks. (CVE-2015-3183)
It was discovered that the Apache HTTP Server incorrectly handled the
ap_some_auth_required API. A remote attacker could possibly use this issue
to bypass intended access restrictions. This issue only affected Ubuntu
14.04 LTS and Ubuntu 15.04. (CVE-2015-3185)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 15.04:
apache2.2-bin 2.4.10-9ubuntu1.1
Ubuntu 14.04 LTS:
apache2.2-bin 2.4.7-1ubuntu4.5
Ubuntu 12.04 LTS:
apache2.2-bin 2.2.22-1ubuntu1.10
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2686-1
CVE-2015-3183, CVE-2015-3185
Package Information:
https://launchpad.net/ubuntu/+source/apache2/2.4.10-9ubuntu1.1
https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.5
https://launchpad.net/ubuntu/+source/apache2/2.2.22-1ubuntu1.10
Version: GnuPG v1
iQIcBAEBCgAGBQJVtnEgAAoJEGVp2FWnRL6TLDQP/izUDoZluIVt490NmuHFTBeN
D64GSpjdL7wLRuzAnBxKLcXp7Nd9OIXiFp0HQkVzrrhKOtxBj6mKwjRRP6CrZ3ax
oQ2vUWhYgEFPZsovT9Yp37TwQfJGjVS9XaxYmcq6zaBaln1orAggqeUAHPzXFPX1
+ehsyjCrdBgsc6f+3Xyg8f2y1+ef3iU+v+nYwi4Rd2sjB0/49U0B3ljzqfaESdbJ
D3hErOZ8uwKts2hLNgT6N0lIpCFOoXGLE8Oy+os2NEz63+/fZ5MF8FbQZzRkOZaf
5AtDyWyz7niOGT6DGpICueJlh/g3DvPI/5YRTTrKYuNOJdQKNStmUcRH6jKstBY3
seTAzs+xn/HQV8kGO7Drv0QYPcjkZDU6pRUhZpb4olMGeHm/3ShalQmoGDdC4aGH
AoFbPASJO3L8QHbNxuMWosNpA4xMd3DRyosCa1ZuehCLfigo4gz5zpPJ8Ih6qDBR
moK5+FE6XA3D/kpdfTKuUcX4wq0mAC9dZj3a4ecwr5oKWCZSYMZN7EDRp6C0cYkm
avgTAW/JgotjfPDz0/U5KN5XxvlbhRUz59qwaiWRp+xUBvJZBPs8LOKtOTcWBhh8
vA6KcxG2SPA/tprkIJNEHn44MMjpMKeeiAW4I+KgJHw3cfuLnI/dxfuNY4aeolgW
yDZIZCXSRCrmiaCqy7od
=juYX
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2686-1
July 27, 2015
apache2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the Apache HTTP server.
Software Description:
- apache2: Apache HTTP server
Details:
It was discovered that the Apache HTTP Server incorrectly parsed chunk
headers. A remote attacker could possibly use this issue to perform HTTP
request smuggling attacks. (CVE-2015-3183)
It was discovered that the Apache HTTP Server incorrectly handled the
ap_some_auth_required API. A remote attacker could possibly use this issue
to bypass intended access restrictions. This issue only affected Ubuntu
14.04 LTS and Ubuntu 15.04. (CVE-2015-3185)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 15.04:
apache2.2-bin 2.4.10-9ubuntu1.1
Ubuntu 14.04 LTS:
apache2.2-bin 2.4.7-1ubuntu4.5
Ubuntu 12.04 LTS:
apache2.2-bin 2.2.22-1ubuntu1.10
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2686-1
CVE-2015-3183, CVE-2015-3185
Package Information:
https://launchpad.net/ubuntu/+source/apache2/2.4.10-9ubuntu1.1
https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.5
https://launchpad.net/ubuntu/+source/apache2/2.2.22-1ubuntu1.10
new errata for TCP, exec, and patch
A few patches are now available. Please consult the website for details.
OpenBSD 5.6 errata:
http://www.openbsd.org/errata56.html
027: SECURITY FIX: July 14, 2015 All architectures
A TCP socket can become confused and not properly cleanup resources.
A source code patch exists which remedies this problem.
028: RELIABILITY FIX: July 26, 2015 All architectures
A kernel memory leak could be triggered by an unprivileged user in a failure
case when using execve under systrace.
A source code patch exists which remedies this problem.
029: SECURITY FIX: July 26, 2015 All architectures
The patch utility could be made to invoke arbitrary commands via the obsolete
SCCS and RCS support when processing a crafted input file. This patch deletes
the SCCS and RCS support.
A source code patch exists which remedies this problem.
OpenBSD 5.7 errata:
http://www.openbsd.org/errata57.html
010: SECURITY FIX: July 14, 2015 All architectures
A TCP socket can become confused and not properly cleanup resources.
A source code patch exists which remedies this problem.
011: RELIABILITY FIX: July 26, 2015 All architectures
A kernel memory leak could be triggered by an unprivileged user in a failure
case when using execve under systrace.
A source code patch exists which remedies this problem.
012: SECURITY FIX: July 26, 2015 All architectures
The patch utility could be made to invoke arbitrary commands via the obsolete
RCS support when processing a crafted input file. This patch deletes the RCS
support.
A source code patch exists which remedies this problem.
OpenBSD 5.6 errata:
http://www.openbsd.org/errata56.html
027: SECURITY FIX: July 14, 2015 All architectures
A TCP socket can become confused and not properly cleanup resources.
A source code patch exists which remedies this problem.
028: RELIABILITY FIX: July 26, 2015 All architectures
A kernel memory leak could be triggered by an unprivileged user in a failure
case when using execve under systrace.
A source code patch exists which remedies this problem.
029: SECURITY FIX: July 26, 2015 All architectures
The patch utility could be made to invoke arbitrary commands via the obsolete
SCCS and RCS support when processing a crafted input file. This patch deletes
the SCCS and RCS support.
A source code patch exists which remedies this problem.
OpenBSD 5.7 errata:
http://www.openbsd.org/errata57.html
010: SECURITY FIX: July 14, 2015 All architectures
A TCP socket can become confused and not properly cleanup resources.
A source code patch exists which remedies this problem.
011: RELIABILITY FIX: July 26, 2015 All architectures
A kernel memory leak could be triggered by an unprivileged user in a failure
case when using execve under systrace.
A source code patch exists which remedies this problem.
012: SECURITY FIX: July 26, 2015 All architectures
The patch utility could be made to invoke arbitrary commands via the obsolete
RCS support when processing a crafted input file. This patch deletes the RCS
support.
A source code patch exists which remedies this problem.
[CentOS-announce] CESA-2015:1507 Important CentOS 7 qemu-kvm Security Update
CentOS Errata and Security Advisory 2015:1507 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1507.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
861d13528a31a1114727af715fee344d97163bd393928f76f51998e3f95360af libcacard-1.5.3-86.el7_1.5.i686.rpm
4dcf8e78916bf67ffad805b0dfcc4825bb74c88e5ee1dba3fa28a5944109fc08 libcacard-1.5.3-86.el7_1.5.x86_64.rpm
816d598531dccf3ad9d79ad5ec3af15299b9dd9edf2edbdf6935518ddf34eb99 libcacard-devel-1.5.3-86.el7_1.5.i686.rpm
73f02219eb9cc9e4fa2f5e3a0fad38dbb93834fd66f70c18e68ab4736b3fb849 libcacard-devel-1.5.3-86.el7_1.5.x86_64.rpm
d7861e184d938cb03a0ffbbbc8ba4c204504463faccea5acce1629331c85b64a libcacard-tools-1.5.3-86.el7_1.5.x86_64.rpm
4d4519f0482f828a0629daa35df2feb77a2753a12bcddf0bf56f8629f6faf466 qemu-img-1.5.3-86.el7_1.5.x86_64.rpm
2f5804453c5cc56665f76dcae66d24438f09a95ecebca811521a03be09f97287 qemu-kvm-1.5.3-86.el7_1.5.x86_64.rpm
47b2fa087ce0b0ce1e35ed226a55b3b1dfe9d339acd12a5243f080d010e1622c qemu-kvm-common-1.5.3-86.el7_1.5.x86_64.rpm
c347022a36db3f9a7a62d6a630628672f3091a15798d404501d92b4cf2d7c1db qemu-kvm-tools-1.5.3-86.el7_1.5.x86_64.rpm
Source:
41c44588a8ea4cfb0183447609fac4ce5219192508cb37fcc0a8f816dd50809d qemu-kvm-1.5.3-86.el7_1.5.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1507.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
861d13528a31a1114727af715fee344d97163bd393928f76f51998e3f95360af libcacard-1.5.3-86.el7_1.5.i686.rpm
4dcf8e78916bf67ffad805b0dfcc4825bb74c88e5ee1dba3fa28a5944109fc08 libcacard-1.5.3-86.el7_1.5.x86_64.rpm
816d598531dccf3ad9d79ad5ec3af15299b9dd9edf2edbdf6935518ddf34eb99 libcacard-devel-1.5.3-86.el7_1.5.i686.rpm
73f02219eb9cc9e4fa2f5e3a0fad38dbb93834fd66f70c18e68ab4736b3fb849 libcacard-devel-1.5.3-86.el7_1.5.x86_64.rpm
d7861e184d938cb03a0ffbbbc8ba4c204504463faccea5acce1629331c85b64a libcacard-tools-1.5.3-86.el7_1.5.x86_64.rpm
4d4519f0482f828a0629daa35df2feb77a2753a12bcddf0bf56f8629f6faf466 qemu-img-1.5.3-86.el7_1.5.x86_64.rpm
2f5804453c5cc56665f76dcae66d24438f09a95ecebca811521a03be09f97287 qemu-kvm-1.5.3-86.el7_1.5.x86_64.rpm
47b2fa087ce0b0ce1e35ed226a55b3b1dfe9d339acd12a5243f080d010e1622c qemu-kvm-common-1.5.3-86.el7_1.5.x86_64.rpm
c347022a36db3f9a7a62d6a630628672f3091a15798d404501d92b4cf2d7c1db qemu-kvm-tools-1.5.3-86.el7_1.5.x86_64.rpm
Source:
41c44588a8ea4cfb0183447609fac4ce5219192508cb37fcc0a8f816dd50809d qemu-kvm-1.5.3-86.el7_1.5.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Subscribe to:
Posts (Atom)