Monday, March 28, 2022

[USN-5342-1] Python vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5342-1
March 28, 2022

python2.7, python3.4, python3.5, python3.6, python3.8 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

Several security issues were fixed in Python.

Software Description:
- python3.8: An interactive high-level object-oriented language
- python2.7: An interactive high-level object-oriented language
- python3.6: An interactive high-level object-oriented language
- python3.5: An interactive high-level object-oriented language
- python3.4: An interactive high-level object-oriented language

Details:

David Schwörer discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 18.04 LTS. (CVE-2021-3426)

It was discovered that Python incorrectly handled certain FTP requests.
An attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, and Ubuntu 18.04 LTS.
(CVE-2021-4189)

It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2022-0391)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
python3.8 3.8.10-0ubuntu1~20.04.4
python3.8-minimal 3.8.10-0ubuntu1~20.04.4

Ubuntu 18.04 LTS:
python2.7 2.7.17-1~18.04ubuntu1.7
python2.7-minimal 2.7.17-1~18.04ubuntu1.7
python3.6 3.6.9-1~18.04ubuntu1.7
python3.6-minimal 3.6.9-1~18.04ubuntu1.7

Ubuntu 16.04 ESM:
python2.7 2.7.12-1ubuntu0~16.04.18+esm1
python2.7-minimal 2.7.12-1ubuntu0~16.04.18+esm1
python3.5 3.5.2-2ubuntu0~16.04.13+esm2
python3.5-minimal 3.5.2-2ubuntu0~16.04.13+esm2

Ubuntu 14.04 ESM:
python3.4 3.4.3-1ubuntu1~14.04.7+esm12
python3.4-minimal 3.4.3-1ubuntu1~14.04.7+esm12

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5342-1
CVE-2021-3426, CVE-2021-4189, CVE-2022-0391

Package Information:
https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.4
https://launchpad.net/ubuntu/+source/python2.7/2.7.17-1~18.04ubuntu1.7
https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.7

Orphaned packages (incl. go-rpm-macros) looking for new maintainers

The following packages are orphaned and will be retired when they
are orphaned for six weeks, unless someone adopts them. If you know for sure
that the package should be retired, please do so now with a proper reason:
https://fedoraproject.org/wiki/How_to_remove_a_package_at_end_of_life

Note: If you received this mail directly you (co)maintain one of the affected
packages or a package that depends on one. Please adopt the affected package or
retire your depending package to avoid broken dependencies, otherwise your
package will fail to install and/or build when the affected package gets retired.

Request package ownership via the *Take* button in he left column on
https://src.fedoraproject.org/rpms/<pkgname>

Full report available at:
https://churchyard.fedorapeople.org/orphans-2022-03-28.txt
grep it for your FAS username and follow the dependency chain.

For human readable dependency chains,
see https://packager-dashboard.fedoraproject.org/
For all orphaned packages,
see https://packager-dashboard.fedoraproject.org/orphan

Package (co)maintainers Status Change
================================================================================
augeas-vala orphan 4 weeks ago
beanstalk-client orphan 3 weeks ago
gela-asis orphan, reznik 1 weeks ago
go-rpm-macros eclipseo, go-sig, jcajka, 0 weeks ago
orphan, qulogic
gocl orphan 4 weeks ago
golang-github-influxdata- go-sig, orphan 0 weeks ago
influxdb
golang-github-mdlayher-wifi go-sig, orphan 2 weeks ago
lua-ldap orphan 3 weeks ago
mcrouter dcavalca, filbranden, orphan 0 weeks ago
python-aiohttp-cors orphan, python-sig 3 weeks ago
python-aiohttp-negotiate orphan 3 weeks ago
python-fastimport orphan 3 weeks ago
python-hkdf orphan 4 weeks ago
python-lrparsing orphan 3 weeks ago
python-magic-wormhole orphan 4 weeks ago
python-magic-wormhole-mailbox- orphan 4 weeks ago
server
python-magic-wormhole-transit- orphan 4 weeks ago
relay
python-ofxparse orphan 3 weeks ago
python-plyvel orphan 3 weeks ago
python-pystalk orphan 3 weeks ago
python-spake2 orphan 4 weeks ago
python-txtorcon orphan 4 weeks ago
qcommandline orphan 3 weeks ago
qt5-qtcanvas3d kde-sig, orphan 1 weeks ago
qt5-qtenginio kde-sig, lupinix, orphan 1 weeks ago
rubygem-database_cleaner orphan 5 weeks ago
rust-diffus orphan, rust-sig 1 weeks ago
rust-diffus-derive orphan, rust-sig 1 weeks ago
rust-newsblur_api orphan, rust-sig 1 weeks ago
rust-opml orphan, rust-sig 1 weeks ago
rust-xmltree orphan, rust-sig 1 weeks ago
sems orphan 1 weeks ago
yecht orphan 2 weeks ago

The following packages require above mentioned packages:
Depending on: go-rpm-macros (1957), status change: 2022-03-22 (0 weeks ago)
Too many dependencies for go-rpm-macros, not all listed here
See https://churchyard.fedorapeople.org/orphans-2022-03-28.txt

Depending on: golang-github-mdlayher-wifi (1), status change: 2022-03-11 (2
weeks ago)
golang-github-prometheus-node-exporter (maintained by: eclipseo, go-sig)
golang-github-prometheus-node-exporter-1.3.1-6.fc36.src requires
golang(github.com/mdlayher/wifi) = 0-0.12.20200729git84f0b94.fc36
golang-github-prometheus-node-exporter-devel-1.3.1-6.fc36.noarch requires
golang(github.com/mdlayher/wifi) = 0-0.12.20200729git84f0b94.fc36

Depending on: python-aiohttp-cors (1), status change: 2022-03-02 (3 weeks ago)
gns3-server (maintained by: kwizart, nucleo)
gns3-server-2.2.31-2.fc37.noarch requires python3.10dist(aiohttp-cors) = 0.7

Depending on: python-hkdf (2), status change: 2022-02-23 (4 weeks ago)
python-magic-wormhole (maintained by: orphan)
python-magic-wormhole-0.12.0-7.fc36.src requires python3dist(hkdf) = 0.0.3,
python3dist(spake2) = 0.8
python3-magic-wormhole-0.12.0-7.fc36.noarch requires python3.10dist(hkdf) =
0.0.3, python3.10dist(spake2) = 0.8

python-spake2 (maintained by: orphan)
python-spake2-0.8-12.fc36.src requires python3dist(hkdf) = 0.0.3
python3-spake2-0.8-12.fc36.noarch requires python3.10dist(hkdf) = 0.0.3,
python3dist(hkdf) = 0.0.3

Depending on: python-magic-wormhole-mailbox-server (1), status change:
2022-02-23 (4 weeks ago)
python-magic-wormhole (maintained by: orphan)
python-magic-wormhole-0.12.0-7.fc36.src requires
python3dist(magic-wormhole-mailbox-server) = 0.4.1

Depending on: python-magic-wormhole-transit-relay (1), status change:
2022-02-23 (4 weeks ago)
python-magic-wormhole (maintained by: orphan)
python-magic-wormhole-0.12.0-7.fc36.src requires
python3dist(magic-wormhole-transit-relay) = 0.2.1

Depending on: python-spake2 (1), status change: 2022-02-23 (4 weeks ago)
python-magic-wormhole (maintained by: orphan)
python-magic-wormhole-0.12.0-7.fc36.src requires python3dist(spake2) = 0.8
python3-magic-wormhole-0.12.0-7.fc36.noarch requires python3.10dist(spake2) = 0.8

Depending on: python-txtorcon (1), status change: 2022-02-23 (4 weeks ago)
python-magic-wormhole (maintained by: orphan)
python-magic-wormhole-0.12.0-7.fc36.src requires python3dist(txtorcon) = 21.1
python3-magic-wormhole-0.12.0-7.fc36.noarch requires python3.10dist(txtorcon)
= 21.1

Depending on: rust-diffus (1), status change: 2022-03-20 (1 weeks ago)
newsflash (maintained by: ignatenkobrain, rust-sig)
newsflash-1.5.1-2.fc36.src requires crate(diffus/default) = 0.10.0,
crate(diffus/derive) = 0.10.0

Depending on: rust-diffus-derive (2), status change: 2022-03-20 (1 weeks ago)
rust-diffus (maintained by: orphan, rust-sig)
rust-diffus+derive-devel-0.10.0-2.fc36.noarch requires
crate(diffus-derive/default) = 0.10.0
rust-diffus+diffus-derive-devel-0.10.0-2.fc36.noarch requires
crate(diffus-derive/default) = 0.10.0
rust-diffus+serialize-impl-devel-0.10.0-2.fc36.noarch requires
crate(diffus-derive/serialize-impl) = 0.10.0

newsflash (maintained by: ignatenkobrain, rust-sig)
newsflash-1.5.1-2.fc36.src requires crate(diffus/default) = 0.10.0,
crate(diffus/derive) = 0.10.0

Depending on: rust-newsblur_api (2), status change: 2022-03-15 (1 weeks ago)
rust-news-flash (maintained by: ignatenkobrain, rust-sig)
rust-news-flash-1.2.1-6.fc36.src requires crate(newsblur_api/default) = 0.1.2
rust-news-flash-devel-1.2.1-6.fc36.noarch requires
crate(newsblur_api/default) = 0.1.2

newsflash (maintained by: ignatenkobrain, rust-sig)
newsflash-1.5.1-2.fc36.src requires crate(news-flash/default) = 1.2.1

Depending on: rust-opml (2), status change: 2022-03-20 (1 weeks ago)
rust-news-flash (maintained by: ignatenkobrain, rust-sig)
rust-news-flash-1.2.1-6.fc36.src requires crate(opml/default) = 1.1.1
rust-news-flash-devel-1.2.1-6.fc36.noarch requires crate(opml/default) = 1.1.1

newsflash (maintained by: ignatenkobrain, rust-sig)
newsflash-1.5.1-2.fc36.src requires crate(news-flash/default) = 1.2.1

Depending on: rust-xmltree (1), status change: 2022-03-20 (1 weeks ago)
newsflash (maintained by: ignatenkobrain, rust-sig)
newsflash-1.5.1-2.fc36.src requires crate(xmltree/default) = 0.10.3

Affected (co)maintainers (either directly or via packages' dependencies):
abulimov: go-rpm-macros
acui: go-rpm-macros
agerstmayr: go-rpm-macros
ajax: go-rpm-macros
akoutsou: go-rpm-macros
alexsaezm: go-rpm-macros
appadeia: go-rpm-macros
athoscr: go-rpm-macros
atim: go-rpm-macros
baude: go-rpm-macros
bboozzoo: go-rpm-macros
bcl: go-rpm-macros
bdperkin: go-rpm-macros
bgilbert: go-rpm-macros
blowry: go-rpm-macros
carlwgeorge: go-rpm-macros
cheeselee: go-rpm-macros
churchyard: go-rpm-macros
clime: go-rpm-macros
comzeradd: go-rpm-macros
container-sig: go-rpm-macros
copart: go-rpm-macros
cypret: go-rpm-macros
darkmuggle: go-rpm-macros
dcavalca: mcrouter, go-rpm-macros
ddd: go-rpm-macros
decathorpe: go-rpm-macros
deepinde-sig: go-rpm-macros
deparker: go-rpm-macros
dfateyev: go-rpm-macros
dmoerner: go-rpm-macros
dustymabe: go-rpm-macros
dwalsh: go-rpm-macros
dwd: go-rpm-macros
dzickus: go-rpm-macros
eclipseo: golang-github-mdlayher-wifi, go-rpm-macros
elmarco: go-rpm-macros
eparis: go-rpm-macros
ericedens: go-rpm-macros
etrunko: go-rpm-macros
fab: go-rpm-macros
fale: go-rpm-macros
felixonmars: go-rpm-macros
ffesti: go-rpm-macros
filbranden: mcrouter, go-rpm-macros
fpokorny: go-rpm-macros
fredlima: go-rpm-macros
fweimer: go-rpm-macros
germano: go-rpm-macros
go-sig: golang-github-influxdata-influxdb, golang-github-mdlayher-wifi,
go-rpm-macros
gotmax23: go-rpm-macros
gscrivano: go-rpm-macros
gundersanne: go-rpm-macros
haircommander: go-rpm-macros
harrymichal: go-rpm-macros
hedayat: go-rpm-macros
hhorak: go-rpm-macros
humaton: go-rpm-macros
ignatenkobrain: rust-xmltree, rust-diffus, rust-opml, rust-diffus-derive,
rust-newsblur_api
infra-sig: go-rpm-macros
isimluk: go-rpm-macros
jasonbrooks: go-rpm-macros
jaymzh: go-rpm-macros
jcajka: go-rpm-macros
jchaloup: go-rpm-macros
jcm: go-rpm-macros
jdoss: go-rpm-macros
jjames: go-rpm-macros
jjelen: go-rpm-macros
jkurik: go-rpm-macros
jlebon: go-rpm-macros
jnovy: go-rpm-macros
kde-sig: qt5-qtcanvas3d, qt5-qtenginio
kshlm: go-rpm-macros
ktock: go-rpm-macros
kwizart: python-aiohttp-cors
larsu: go-rpm-macros
limb: go-rpm-macros
linkdupont: go-rpm-macros
lkiesow: go-rpm-macros
logic: go-rpm-macros
lpabon: go-rpm-macros
lsm5: go-rpm-macros
lucab: go-rpm-macros
lupinix: qt5-qtenginio
mattia: go-rpm-macros
maxamillion: go-rpm-macros
mayorga: go-rpm-macros
mgoodwin: go-rpm-macros
mhayden: go-rpm-macros
mheon: go-rpm-macros
mikelo2: go-rpm-macros
mikep: go-rpm-macros
miminar: go-rpm-macros
mosquito: go-rpm-macros
mrunge: go-rpm-macros
mskalick: go-rpm-macros
nalin: go-rpm-macros
nathans: go-rpm-macros
navidys: go-rpm-macros
ngompa: go-rpm-macros
nucleo: python-aiohttp-cors
obudai: go-rpm-macros
ochosi: go-rpm-macros
ogutierrez: go-rpm-macros
olem: go-rpm-macros
osbuild-sig: go-rpm-macros
packit: go-rpm-macros
panovotn: go-rpm-macros
pghmcfc: go-rpm-macros
philipp: go-rpm-macros
pmatilai: go-rpm-macros
podvody: go-rpm-macros
pwouters: go-rpm-macros
python-sig: python-aiohttp-cors
qulogic: go-rpm-macros
rathann: go-rpm-macros
reznik: gela-asis
rga: go-rpm-macros
rhcontainerbot: go-rpm-macros
rishi: go-rpm-macros
rominf: go-rpm-macros
runcom: go-rpm-macros
rust-sig: rust-xmltree, rust-diffus, rust-opml, rust-diffus-derive,
rust-newsblur_api
salimma: go-rpm-macros
santiago: go-rpm-macros
sejeff: go-rpm-macros
siddhesh: go-rpm-macros
skottler: go-rpm-macros
slowrie: go-rpm-macros
sohank2602: go-rpm-macros
strigazi: go-rpm-macros
thomasfedb: go-rpm-macros
tibbs: go-rpm-macros
tkorbar: go-rpm-macros
tomegun: go-rpm-macros
tomsweeneyredhat: go-rpm-macros
ttomecek: go-rpm-macros
vbatts: go-rpm-macros
vrothberg: go-rpm-macros
walters: go-rpm-macros
wef: go-rpm-macros
yanqiyu: go-rpm-macros
yselkowitz: go-rpm-macros
zdohnal: go-rpm-macros
zsun: go-rpm-macros
zyga: go-rpm-macros

--
The script creating this output is run and developed by Fedora
Release Engineering. Please report issues at its pagure instance:
https://pagure.io/releng/
The sources of this script can be found at:
https://pagure.io/releng/blob/main/f/scripts/find_unblocked_orphans.py

Report finished at 2022-03-28 08:34:24 UTC
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Saturday, March 26, 2022

Updated Debian 10: 10.12 released

------------------------------------------------------------------------
The Debian Project https://www.debian.org/
Updated Debian 10: 10.12 released press@debian.org
March 26th, 2022 https://www.debian.org/News/2022/2022032602
------------------------------------------------------------------------


The Debian project is pleased to announce the twelfth update of its
oldstable distribution Debian 10 (codename "buster"). This point release
mainly adds corrections for security issues, along with a few
adjustments for serious problems. Security advisories have already been
published separately and are referenced where available.

Please note that the point release does not constitute a new version of
Debian 10 but only updates some of the packages included. There is no
need to throw away old "buster" media. After installation, packages can
be upgraded to the current versions using an up-to-date Debian mirror.

Those who frequently install updates from security.debian.org won't have
to update many packages, and most such updates are included in the point
release.

New installation images will be available soon at the regular locations.

Upgrading an existing installation to this revision can be achieved by
pointing the package management system at one of Debian's many HTTP
mirrors. A comprehensive list of mirrors is available at:

https://www.debian.org/mirror/list



OpenSSL signature algorithm check tightening
--------------------------------------------

The OpenSSL update provided in this point release includes a change to
ensure that the requested signature algorithm is supported by the active
security level.

Although this will not affect most use-cases, it could lead to error
messages being generated if a non-supported algorithm is requested - for
example, use of RSA+SHA1 signatures with the default security level of
2.

In such cases, the security level will need to be explicitly lowered,
either for individual requests or more globally. This may require
changes to the configuration of applications. For OpenSSL itself, per-
request lowering can be achieved using a command-line option such as:

-cipher "ALL:@SECLEVEL=1"

with the relevant system-level configuration being found in /etc/ssl/
openssl.cnf


Miscellaneous Bugfixes
----------------------

This oldstable update adds a few important corrections to the following
packages:

+--------------------------+------------------------------------------+
| Package | Reason |
+--------------------------+------------------------------------------+
| apache-log4j1.2 [1] | Resolve security issues [CVE-2021-4104 |
| | CVE-2022-23302 CVE-2022-23305 CVE-2022- |
| | 23307], by removing support for the |
| | JMSSink, JDBCAppender, JMSAppender and |
| | Apache Chainsaw modules |
| | |
| apache-log4j2 [2] | Fix remote code execution issue |
| | [CVE-2021-44832] |
| | |
| atftp [3] | Fix information leak issue [CVE-2021- |
| | 46671] |
| | |
| base-files [4] | Update for the 10.12 point release |
| | |
| beads [5] | Rebuild against updated cimg to fix |
| | multiple heap buffer overflows |
| | [CVE-2020-25693] |
| | |
| btrbk [6] | Fix regression in the update for |
| | CVE-2021-38173 |
| | |
| cargo-mozilla [7] | New package, backported from Debian 11, |
| | to help build new rust versions |
| | |
| chrony [8] | Allow reading the chronyd configuration |
| | file that timemaster(8) generates |
| | |
| cimg [9] | Fix heap buffer overflow issues |
| | [CVE-2020-25693] |
| | |
| clamav [10] | New upstream stable release; fix denial |
| | of service issue [CVE-2022-20698] |
| | |
| cups [11] | Fix "an input validation issue might |
| | allow a malicious application to read |
| | restricted memory" [CVE-2020-10001] |
| | |
| debian-installer [12] | Rebuild against oldstable-proposed- |
| | updates; update kernel ABI to -20 |
| | |
| debian-installer- | Rebuild against oldstable-proposed- |
| netboot-images [13] | updates |
| | |
| detox [14] | Fix processing of large files on ARM |
| | architectures |
| | |
| evolution-data- | Fix crash on malformed server reponse |
| server [15] | [CVE-2020-16117] |
| | |
| flac [16] | Fix out of bounds read issue [CVE-2020- |
| | 0499] |
| | |
| gerbv [17] | Fix code execution issue [CVE-2021- |
| | 40391] |
| | |
| glibc [18] | Import several fixes from upstream's |
| | stable branch; simplify the check for |
| | supported kernel versions, as 2.x |
| | kernels are no longer supported; support |
| | installation on kernels with a release |
| | number greater than 255 |
| | |
| gmp [19] | Fix integer and buffer overflow issue |
| | [CVE-2021-43618] |
| | |
| graphicsmagick [20] | Fix buffer overflow issue [CVE-2020- |
| | 12672] |
| | |
| htmldoc [21] | Fix out-of-bounds read issue [CVE-2022- |
| | 0534], buffer overflow issues [CVE-2021- |
| | 43579 CVE-2021-40985] |
| | |
| http-parser [22] | Resolve inadvertent ABI break |
| | |
| icu [23] | Fix "pkgdata" utility |
| | |
| intel-microcode [24] | Update included microcode; mitigate some |
| | security issues [CVE-2020-8694 CVE-2020- |
| | 8695 CVE-2021-0127 CVE-2021-0145 |
| | CVE-2021-0146 CVE-2021-33120] |
| | |
| jbig2dec [25] | Fix buffer overflow issue [CVE-2020- |
| | 12268] |
| | |
| jtharness [26] | New upstream version to support builds |
| | of newer OpenJDK-11 versions |
| | |
| jtreg [27] | New upstream version to support builds |
| | of newer OpenJDK-11 versions |
| | |
| lemonldap-ng [28] | Fix auth process in password-testing |
| | plugins [CVE-2021-20874]; add recommends |
| | on gsfonts, fixing captcha |
| | |
| leptonlib [29] | Fix denial of service issue [CVE-2020- |
| | 36277], buffer over-read issues |
| | [CVE-2020-36278 CVE-2020-36279 CVE-2020- |
| | 36280 CVE-2020-36281] |
| | |
| libdatetime-timezone- | Update included data |
| perl [30] | |
| | |
| libencode-perl [31] | Fix a memory leak in Encode.xs |
| | |
| libetpan [32] | Fix STARTTLS response injection issue |
| | [CVE-2020-15953] |
| | |
| libextractor [33] | Fix invalid read issue [CVE-2019-15531] |
| | |
| libjackson-json- | Fix code execution issues [CVE-2017- |
| java [34] | 15095 CVE-2017-7525], XML external |
| | entity issues [CVE-2019-10172] |
| | |
| libmodbus [35] | Fix out of bound read issues [CVE-2019- |
| | 14462 CVE-2019-14463] |
| | |
| libpcap [36] | Check PHB header length before using it |
| | to allocate memory [CVE-2019-15165] |
| | |
| libsdl1.2 [37] | Properly handle input focus events; fix |
| | buffer overflow issues [CVE-2019-13616 |
| | CVE-2019-7637], buffer over-read issues |
| | [CVE-2019-7572 CVE-2019-7573 CVE-2019- |
| | 7574 CVE-2019-7575 CVE-2019-7576 |
| | CVE-2019-7577 CVE-2019-7578 CVE-2019- |
| | 7635 CVE-2019-7636 CVE-2019-7638] |
| | |
| libxml2 [38] | Fix use-after-free issue [CVE-2022- |
| | 23308] |
| | |
| linux [39] | New upstream stable release; [rt] Update |
| | to 4.19.233-rt105; increase ABI to 20 |
| | |
| linux-latest [40] | Update to 4.19.0-20 ABI |
| | |
| linux-signed-amd64 [41] | New upstream stable release; [rt] Update |
| | to 4.19.233-rt105; increase ABI to 20 |
| | |
| linux-signed-arm64 [42] | New upstream stable release; [rt] Update |
| | to 4.19.233-rt105; increase ABI to 20 |
| | |
| linux-signed-i386 [43] | New upstream stable release; [rt] Update |
| | to 4.19.233-rt105; increase ABI to 20 |
| | |
| llvm-toolchain-11 [44] | New package, backported from Debian 11, |
| | to help build new rust versions |
| | |
| lxcfs [45] | Fix misreporting of swap usage |
| | |
| mailman [46] | Fix cross-site scripting issue |
| | [CVE-2021-43331]; fix "a list moderator |
| | can crack the list admin password |
| | encrypted in a CSRF token" [CVE-2021- |
| | 43332]; fix potential CSRF attack |
| | against a list admin from a list member |
| | or moderator [CVE-2021-44227]; fix |
| | regressions in fixes for CVE-2021-42097 |
| | and CVE-2021-44227 |
| | |
| mariadb-10.3 [47] | New upstream stable release; security |
| | fixes [CVE-2021-35604 CVE-2021-46659 |
| | CVE-2021-46661 CVE-2021-46662 CVE-2021- |
| | 46663 CVE-2021-46664 CVE-2021-46665 |
| | CVE-2021-46667 CVE-2021-46668 CVE-2022- |
| | 24048 CVE-2022-24050 CVE-2022-24051 |
| | CVE-2022-24052] |
| | |
| node-getobject [48] | Fix prototype pollution issue [CVE-2020- |
| | 28282] |
| | |
| opensc [49] | Fix out-of-bounds access issues |
| | [CVE-2019-15945 CVE-2019-15946], crash |
| | due to read of unknown memory [CVE-2019- |
| | 19479], double free issue [CVE-2019- |
| | 20792], buffer overflow issues |
| | [CVE-2020-26570 CVE-2020-26571 CVE-2020- |
| | 26572] |
| | |
| openscad [50] | Fix buffer overflows in STL parser |
| | [CVE-2020-28599 CVE-2020-28600] |
| | |
| openssl [51] | New upstream release |
| | |
| php-illuminate- | Fix query binding issue [CVE-2021- |
| database [52] | 21263], SQL injection issue when used |
| | with Microsoft SQL Server |
| | |
| phpliteadmin [53] | Fix cross-site scripting issue |
| | [CVE-2021-46709] |
| | |
| plib [54] | Fix integer overflow issue [CVE-2021- |
| | 38714] |
| | |
| privoxy [55] | Fix memory leak [CVE-2021-44540] and |
| | cross-site scripting issue [CVE-2021- |
| | 44543] |
| | |
| publicsuffix [56] | Update included data |
| | |
| python-virtualenv [57] | Avoid attempting to install |
| | pkg_resources from PyPI |
| | |
| raptor2 [58] | Fix out of bounds array access issue |
| | [CVE-2020-25713] |
| | |
| ros-ros-comm [59] | Fix denial of service issue [CVE-2021- |
| | 37146] |
| | |
| rsyslog [60] | Fix heap overflow issues [CVE-2019-17041 |
| | CVE-2019-17042] |
| | |
| ruby-httpclient [61] | Use system certificate store |
| | |
| rust-cbindgen [62] | New upstream stable release to support |
| | builds of newer firefox-esr and |
| | thunderbird versions |
| | |
| rustc-mozilla [63] | New source package to support building |
| | of newer firefox-esr and thunderbird |
| | versions |
| | |
| s390-dasd [64] | Stop passing deprecated -f option to |
| | dasdfmt |
| | |
| spip [65] | Fix cross-site scripting issue |
| | |
| tzdata [66] | Update data for Fiji and Palestine |
| | |
| vim [67] | Fix ability to execute code while in |
| | restricted mode [CVE-2019-20807], buffer |
| | overflow issues [CVE-2021-3770 CVE-2021- |
| | 3778 CVE-2021-3875], use after free |
| | issue [CVE-2021-3796]; remove |
| | accidentally included patch |
| | |
| wavpack [68] | Fix use of uninitialized values |
| | [CVE-2019-1010317 CVE-2019-1010319] |
| | |
| weechat [69] | Fix several denial of service issues |
| | [CVE-2020-8955 CVE-2020-9759 CVE-2020- |
| | 9760 CVE-2021-40516] |
| | |
| wireshark [70] | Fix several security issues in |
| | dissectors [CVE-2021-22207 CVE-2021- |
| | 22235 CVE-2021-39921 CVE-2021-39922 |
| | CVE-2021-39923 CVE-2021-39924 CVE-2021- |
| | 39928 CVE-2021-39929] |
| | |
| xterm [71] | Fix buffer overflow issue [CVE-2022- |
| | 24130] |
| | |
| zziplib [72] | Fix denial of service issue [CVE-2020- |
| | 18442] |
| | |
+--------------------------+------------------------------------------+

1: https://packages.debian.org/src:apache-log4j1.2
2: https://packages.debian.org/src:apache-log4j2
3: https://packages.debian.org/src:atftp
4: https://packages.debian.org/src:base-files
5: https://packages.debian.org/src:beads
6: https://packages.debian.org/src:btrbk
7: https://packages.debian.org/src:cargo-mozilla
8: https://packages.debian.org/src:chrony
9: https://packages.debian.org/src:cimg
10: https://packages.debian.org/src:clamav
11: https://packages.debian.org/src:cups
12: https://packages.debian.org/src:debian-installer
13: https://packages.debian.org/src:debian-installer-netboot-images
14: https://packages.debian.org/src:detox
15: https://packages.debian.org/src:evolution-data-server
16: https://packages.debian.org/src:flac
17: https://packages.debian.org/src:gerbv
18: https://packages.debian.org/src:glibc
19: https://packages.debian.org/src:gmp
20: https://packages.debian.org/src:graphicsmagick
21: https://packages.debian.org/src:htmldoc
22: https://packages.debian.org/src:http-parser
23: https://packages.debian.org/src:icu
24: https://packages.debian.org/src:intel-microcode
25: https://packages.debian.org/src:jbig2dec
26: https://packages.debian.org/src:jtharness
27: https://packages.debian.org/src:jtreg
28: https://packages.debian.org/src:lemonldap-ng
29: https://packages.debian.org/src:leptonlib
30: https://packages.debian.org/src:libdatetime-timezone-perl
31: https://packages.debian.org/src:libencode-perl
32: https://packages.debian.org/src:libetpan
33: https://packages.debian.org/src:libextractor
34: https://packages.debian.org/src:libjackson-json-java
35: https://packages.debian.org/src:libmodbus
36: https://packages.debian.org/src:libpcap
37: https://packages.debian.org/src:libsdl1.2
38: https://packages.debian.org/src:libxml2
39: https://packages.debian.org/src:linux
40: https://packages.debian.org/src:linux-latest
41: https://packages.debian.org/src:linux-signed-amd64
42: https://packages.debian.org/src:linux-signed-arm64
43: https://packages.debian.org/src:linux-signed-i386
44: https://packages.debian.org/src:llvm-toolchain-11
45: https://packages.debian.org/src:lxcfs
46: https://packages.debian.org/src:mailman
47: https://packages.debian.org/src:mariadb-10.3
48: https://packages.debian.org/src:node-getobject
49: https://packages.debian.org/src:opensc
50: https://packages.debian.org/src:openscad
51: https://packages.debian.org/src:openssl
52: https://packages.debian.org/src:php-illuminate-database
53: https://packages.debian.org/src:phpliteadmin
54: https://packages.debian.org/src:plib
55: https://packages.debian.org/src:privoxy
56: https://packages.debian.org/src:publicsuffix
57: https://packages.debian.org/src:python-virtualenv
58: https://packages.debian.org/src:raptor2
59: https://packages.debian.org/src:ros-ros-comm
60: https://packages.debian.org/src:rsyslog
61: https://packages.debian.org/src:ruby-httpclient
62: https://packages.debian.org/src:rust-cbindgen
63: https://packages.debian.org/src:rustc-mozilla
64: https://packages.debian.org/src:s390-dasd
65: https://packages.debian.org/src:spip
66: https://packages.debian.org/src:tzdata
67: https://packages.debian.org/src:vim
68: https://packages.debian.org/src:wavpack
69: https://packages.debian.org/src:weechat
70: https://packages.debian.org/src:wireshark
71: https://packages.debian.org/src:xterm
72: https://packages.debian.org/src:zziplib

Security Updates
----------------

This revision adds the following security updates to the oldstable
release. The Security Team has already released an advisory for each of
these updates:

+----------------+----------------------------+
| Advisory ID | Package |
+----------------+----------------------------+
| DSA-4513 [73] | samba [74] |
| | |
| DSA-4982 [75] | apache2 [76] |
| | |
| DSA-4983 [77] | neutron [78] |
| | |
| DSA-4985 [79] | wordpress [80] |
| | |
| DSA-4986 [81] | tomcat9 [82] |
| | |
| DSA-4987 [83] | squashfs-tools [84] |
| | |
| DSA-4989 [85] | strongswan [86] |
| | |
| DSA-4990 [87] | ffmpeg [88] |
| | |
| DSA-4991 [89] | mailman [90] |
| | |
| DSA-4993 [91] | php7.3 [92] |
| | |
| DSA-4994 [93] | bind9 [94] |
| | |
| DSA-4995 [95] | webkit2gtk [96] |
| | |
| DSA-4997 [97] | tiff [98] |
| | |
| DSA-5000 [99] | openjdk-11 [100] |
| | |
| DSA-5001 [101] | redis [102] |
| | |
| DSA-5004 [103] | libxstream-java [104] |
| | |
| DSA-5005 [105] | ruby-kaminari [106] |
| | |
| DSA-5006 [107] | postgresql-11 [108] |
| | |
| DSA-5010 [109] | libxml-security-java [110] |
| | |
| DSA-5011 [111] | salt [112] |
| | |
| DSA-5013 [113] | roundcube [114] |
| | |
| DSA-5014 [115] | icu [116] |
| | |
| DSA-5015 [117] | samba [118] |
| | |
| DSA-5016 [119] | nss [120] |
| | |
| DSA-5018 [121] | python-babel [122] |
| | |
| DSA-5019 [123] | wireshark [124] |
| | |
| DSA-5020 [125] | apache-log4j2 [126] |
| | |
| DSA-5021 [127] | mediawiki [128] |
| | |
| DSA-5022 [129] | apache-log4j2 [130] |
| | |
| DSA-5023 [131] | modsecurity-apache [132] |
| | |
| DSA-5024 [133] | apache-log4j2 [134] |
| | |
| DSA-5027 [135] | xorg-server [136] |
| | |
| DSA-5028 [137] | spip [138] |
| | |
| DSA-5029 [139] | sogo [140] |
| | |
| DSA-5030 [141] | webkit2gtk [142] |
| | |
| DSA-5032 [143] | djvulibre [144] |
| | |
| DSA-5035 [145] | apache2 [146] |
| | |
| DSA-5036 [147] | sphinxsearch [148] |
| | |
| DSA-5037 [149] | roundcube [150] |
| | |
| DSA-5038 [151] | ghostscript [152] |
| | |
| DSA-5039 [153] | wordpress [154] |
| | |
| DSA-5040 [155] | lighttpd [156] |
| | |
| DSA-5043 [157] | lxml [158] |
| | |
| DSA-5047 [159] | prosody [160] |
| | |
| DSA-5051 [161] | aide [162] |
| | |
| DSA-5052 [163] | usbview [164] |
| | |
| DSA-5053 [165] | pillow [166] |
| | |
| DSA-5056 [167] | strongswan [168] |
| | |
| DSA-5057 [169] | openjdk-11 [170] |
| | |
| DSA-5059 [171] | policykit-1 [172] |
| | |
| DSA-5060 [173] | webkit2gtk [174] |
| | |
| DSA-5062 [175] | nss [176] |
| | |
| DSA-5063 [177] | uriparser [178] |
| | |
| DSA-5065 [179] | ipython [180] |
| | |
| DSA-5066 [181] | ruby2.5 [182] |
| | |
| DSA-5071 [183] | samba [184] |
| | |
| DSA-5072 [185] | debian-edu-config [186] |
| | |
| DSA-5073 [187] | expat [188] |
| | |
| DSA-5075 [189] | minetest [190] |
| | |
| DSA-5076 [191] | h2database [192] |
| | |
| DSA-5078 [193] | zsh [194] |
| | |
| DSA-5081 [195] | redis [196] |
| | |
| DSA-5083 [197] | webkit2gtk [198] |
| | |
| DSA-5085 [199] | expat [200] |
| | |
| DSA-5087 [201] | cyrus-sasl2 [202] |
| | |
| DSA-5088 [203] | varnish [204] |
| | |
| DSA-5093 [205] | spip [206] |
| | |
| DSA-5096 [207] | linux-latest [208] |
| | |
| DSA-5096 [209] | linux-signed-amd64 [210] |
| | |
| DSA-5096 [211] | linux-signed-arm64 [212] |
| | |
| DSA-5096 [213] | linux-signed-i386 [214] |
| | |
| DSA-5096 [215] | linux [216] |
| | |
| DSA-5098 [217] | tryton-server [218] |
| | |
| DSA-5099 [219] | tryton-proteus [220] |
| | |
| DSA-5100 [221] | nbd [222] |
| | |
| DSA-5101 [223] | libphp-adodb [224] |
| | |
| DSA-5103 [225] | openssl [226] |
| | |
| DSA-5105 [227] | bind9 [228] |
| | |
+----------------+----------------------------+

73: https://www.debian.org/security/2019/dsa-4513
74: https://packages.debian.org/src:samba
75: https://www.debian.org/security/2021/dsa-4982
76: https://packages.debian.org/src:apache2
77: https://www.debian.org/security/2021/dsa-4983
78: https://packages.debian.org/src:neutron
79: https://www.debian.org/security/2021/dsa-4985
80: https://packages.debian.org/src:wordpress
81: https://www.debian.org/security/2021/dsa-4986
82: https://packages.debian.org/src:tomcat9
83: https://www.debian.org/security/2021/dsa-4987
84: https://packages.debian.org/src:squashfs-tools
85: https://www.debian.org/security/2021/dsa-4989
86: https://packages.debian.org/src:strongswan
87: https://www.debian.org/security/2021/dsa-4990
88: https://packages.debian.org/src:ffmpeg
89: https://www.debian.org/security/2021/dsa-4991
90: https://packages.debian.org/src:mailman
91: https://www.debian.org/security/2021/dsa-4993
92: https://packages.debian.org/src:php7.3
93: https://www.debian.org/security/2021/dsa-4994
94: https://packages.debian.org/src:bind9
95: https://www.debian.org/security/2021/dsa-4995
96: https://packages.debian.org/src:webkit2gtk
97: https://www.debian.org/security/2021/dsa-4997
98: https://packages.debian.org/src:tiff
99: https://www.debian.org/security/2021/dsa-5000
100: https://packages.debian.org/src:openjdk-11
101: https://www.debian.org/security/2021/dsa-5001
102: https://packages.debian.org/src:redis
103: https://www.debian.org/security/2021/dsa-5004
104: https://packages.debian.org/src:libxstream-java
105: https://www.debian.org/security/2021/dsa-5005
106: https://packages.debian.org/src:ruby-kaminari
107: https://www.debian.org/security/2021/dsa-5006
108: https://packages.debian.org/src:postgresql-11
109: https://www.debian.org/security/2021/dsa-5010
110: https://packages.debian.org/src:libxml-security-java
111: https://www.debian.org/security/2021/dsa-5011
112: https://packages.debian.org/src:salt
113: https://www.debian.org/security/2021/dsa-5013
114: https://packages.debian.org/src:roundcube
115: https://www.debian.org/security/2021/dsa-5014
116: https://packages.debian.org/src:icu
117: https://www.debian.org/security/2021/dsa-5015
118: https://packages.debian.org/src:samba
119: https://www.debian.org/security/2021/dsa-5016
120: https://packages.debian.org/src:nss
121: https://www.debian.org/security/2021/dsa-5018
122: https://packages.debian.org/src:python-babel
123: https://www.debian.org/security/2021/dsa-5019
124: https://packages.debian.org/src:wireshark
125: https://www.debian.org/security/2021/dsa-5020
126: https://packages.debian.org/src:apache-log4j2
127: https://www.debian.org/security/2021/dsa-5021
128: https://packages.debian.org/src:mediawiki
129: https://www.debian.org/security/2021/dsa-5022
130: https://packages.debian.org/src:apache-log4j2
131: https://www.debian.org/security/2021/dsa-5023
132: https://packages.debian.org/src:modsecurity-apache
133: https://www.debian.org/security/2021/dsa-5024
134: https://packages.debian.org/src:apache-log4j2
135: https://www.debian.org/security/2021/dsa-5027
136: https://packages.debian.org/src:xorg-server
137: https://www.debian.org/security/2021/dsa-5028
138: https://packages.debian.org/src:spip
139: https://www.debian.org/security/2021/dsa-5029
140: https://packages.debian.org/src:sogo
141: https://www.debian.org/security/2021/dsa-5030
142: https://packages.debian.org/src:webkit2gtk
143: https://www.debian.org/security/2021/dsa-5032
144: https://packages.debian.org/src:djvulibre
145: https://www.debian.org/security/2022/dsa-5035
146: https://packages.debian.org/src:apache2
147: https://www.debian.org/security/2022/dsa-5036
148: https://packages.debian.org/src:sphinxsearch
149: https://www.debian.org/security/2022/dsa-5037
150: https://packages.debian.org/src:roundcube
151: https://www.debian.org/security/2022/dsa-5038
152: https://packages.debian.org/src:ghostscript
153: https://www.debian.org/security/2022/dsa-5039
154: https://packages.debian.org/src:wordpress
155: https://www.debian.org/security/2022/dsa-5040
156: https://packages.debian.org/src:lighttpd
157: https://www.debian.org/security/2022/dsa-5043
158: https://packages.debian.org/src:lxml
159: https://www.debian.org/security/2022/dsa-5047
160: https://packages.debian.org/src:prosody
161: https://www.debian.org/security/2022/dsa-5051
162: https://packages.debian.org/src:aide
163: https://www.debian.org/security/2022/dsa-5052
164: https://packages.debian.org/src:usbview
165: https://www.debian.org/security/2022/dsa-5053
166: https://packages.debian.org/src:pillow
167: https://www.debian.org/security/2022/dsa-5056
168: https://packages.debian.org/src:strongswan
169: https://www.debian.org/security/2022/dsa-5057
170: https://packages.debian.org/src:openjdk-11
171: https://www.debian.org/security/2022/dsa-5059
172: https://packages.debian.org/src:policykit-1
173: https://www.debian.org/security/2022/dsa-5060
174: https://packages.debian.org/src:webkit2gtk
175: https://www.debian.org/security/2022/dsa-5062
176: https://packages.debian.org/src:nss
177: https://www.debian.org/security/2022/dsa-5063
178: https://packages.debian.org/src:uriparser
179: https://www.debian.org/security/2022/dsa-5065
180: https://packages.debian.org/src:ipython
181: https://www.debian.org/security/2022/dsa-5066
182: https://packages.debian.org/src:ruby2.5
183: https://www.debian.org/security/2022/dsa-5071
184: https://packages.debian.org/src:samba
185: https://www.debian.org/security/2022/dsa-5072
186: https://packages.debian.org/src:debian-edu-config
187: https://www.debian.org/security/2022/dsa-5073
188: https://packages.debian.org/src:expat
189: https://www.debian.org/security/2022/dsa-5075
190: https://packages.debian.org/src:minetest
191: https://www.debian.org/security/2022/dsa-5076
192: https://packages.debian.org/src:h2database
193: https://www.debian.org/security/2022/dsa-5078
194: https://packages.debian.org/src:zsh
195: https://www.debian.org/security/2022/dsa-5081
196: https://packages.debian.org/src:redis
197: https://www.debian.org/security/2022/dsa-5083
198: https://packages.debian.org/src:webkit2gtk
199: https://www.debian.org/security/2022/dsa-5085
200: https://packages.debian.org/src:expat
201: https://www.debian.org/security/2022/dsa-5087
202: https://packages.debian.org/src:cyrus-sasl2
203: https://www.debian.org/security/2022/dsa-5088
204: https://packages.debian.org/src:varnish
205: https://www.debian.org/security/2022/dsa-5093
206: https://packages.debian.org/src:spip
207: https://www.debian.org/security/2022/dsa-5096
208: https://packages.debian.org/src:linux-latest
209: https://www.debian.org/security/2022/dsa-5096
210: https://packages.debian.org/src:linux-signed-amd64
211: https://www.debian.org/security/2022/dsa-5096
212: https://packages.debian.org/src:linux-signed-arm64
213: https://www.debian.org/security/2022/dsa-5096
214: https://packages.debian.org/src:linux-signed-i386
215: https://www.debian.org/security/2022/dsa-5096
216: https://packages.debian.org/src:linux
217: https://www.debian.org/security/2022/dsa-5098
218: https://packages.debian.org/src:tryton-server
219: https://www.debian.org/security/2022/dsa-5099
220: https://packages.debian.org/src:tryton-proteus
221: https://www.debian.org/security/2022/dsa-5100
222: https://packages.debian.org/src:nbd
223: https://www.debian.org/security/2022/dsa-5101
224: https://packages.debian.org/src:libphp-adodb
225: https://www.debian.org/security/2022/dsa-5103
226: https://packages.debian.org/src:openssl
227: https://www.debian.org/security/2022/dsa-5105
228: https://packages.debian.org/src:bind9

Removed packages
----------------

The following packages were removed due to circumstances beyond our
control:

+----------------------------+------------------+
| Package | Reason |
+----------------------------+------------------+
| angular-maven-plugin [229] | No longer useful |
| | |
| minify-maven-plugin [230] | No longer useful |
| | |
+----------------------------+------------------+

229: https://packages.debian.org/src:angular-maven-plugin
230: https://packages.debian.org/src:minify-maven-plugin

Debian Installer
----------------

The installer has been updated to include the fixes incorporated into
oldstable by the point release.


URLs
----

The complete lists of packages that have changed with this revision:

https://deb.debian.org/debian/dists/buster/ChangeLog


The current oldstable distribution:

https://deb.debian.org/debian/dists/oldstable/


Proposed updates to the oldstable distribution:

https://deb.debian.org/debian/dists/oldstable-proposed-updates


oldstable distribution information (release notes, errata etc.):

https://www.debian.org/releases/oldstable/


Security announcements and information:

https://www.debian.org/security/



About Debian
------------

The Debian Project is an association of Free Software developers who
volunteer their time and effort in order to produce the completely free
operating system Debian.


Contact Information
-------------------

For further information, please visit the Debian web pages at
https://www.debian.org/, send mail to <press@debian.org>, or contact the
stable release team at <debian-release@lists.debian.org>.

Updated Debian 11: 11.3 released

------------------------------------------------------------------------
The Debian Project https://www.debian.org/
Updated Debian 11: 11.3 released press@debian.org
March 26th, 2022 https://www.debian.org/News/2022/20220326
------------------------------------------------------------------------


The Debian project is pleased to announce the third update of its stable
distribution Debian 11 (codename "bullseye"). This point release mainly
adds corrections for security issues, along with a few adjustments for
serious problems. Security advisories have already been published
separately and are referenced where available.

Please note that the point release does not constitute a new version of
Debian 11 but only updates some of the packages included. There is no
need to throw away old "bullseye" media. After installation, packages
can be upgraded to the current versions using an up-to-date Debian
mirror.

Those who frequently install updates from security.debian.org won't have
to update many packages, and most such updates are included in the point
release.

New installation images will be available soon at the regular locations.

Upgrading an existing installation to this revision can be achieved by
pointing the package management system at one of Debian's many HTTP
mirrors. A comprehensive list of mirrors is available at:

https://www.debian.org/mirror/list



Miscellaneous Bugfixes
----------------------

This stable update adds a few important corrections to the following
packages:

+--------------------------+------------------------------------------+
| Package | Reason |
+--------------------------+------------------------------------------+
| apache-log4j1.2 [1] | Resolve security issues [CVE-2021-4104 |
| | CVE-2022-23302 CVE-2022-23305 CVE-2022- |
| | 23307], by removing support for the |
| | JMSSink, JDBCAppender, JMSAppender and |
| | Apache Chainsaw modules |
| | |
| apache-log4j2 [2] | Fix remote code execution issue |
| | [CVE-2021-44832] |
| | |
| apache2 [3] | New upstream release; fix crash due to |
| | random memory read [CVE-2022-22719]; fix |
| | HTTP request smuggling issue [CVE-2022- |
| | 22720]; fix out-of-bounds write issues |
| | [CVE-2022-22721 CVE-2022-23943] |
| | |
| atftp [4] | Fix information leak issue [CVE-2021- |
| | 46671] |
| | |
| base-files [5] | Update for the 11.3 point release |
| | |
| bible-kjv [6] | Fix off-by-one-error in search |
| | |
| chrony [7] | Allow reading the chronyd configuration |
| | file that timemaster(8) generates |
| | |
| cinnamon [8] | Fix crash when adding an online account |
| | with login |
| | |
| clamav [9] | New upstream stable release; fix denial |
| | of service issue [CVE-2022-20698] |
| | |
| cups-filters [10] | Apparmor: allow reading from Debian |
| | Edu's cups-browsed configuration file |
| | |
| dask.distributed [11] | Fix undesired listening of workers on |
| | public interfaces [CVE-2021-42343]; fix |
| | compatibility with Python 3.9 |
| | |
| debian-installer [12] | Rebuild against proposed-updates; update |
| | Linux kernel ABI to 5.10.0-13 |
| | |
| debian-installer- | Rebuild against proposed-updates |
| netboot-images [13] | |
| | |
| debian-ports-archive- | Add "Debian Ports Archive Automatic |
| keyring [14] | Signing Key (2023)" ; move the |
| | 2021 signing key to the removed keyring |
| | |
| django-allauth [15] | Fix OpenID support |
| | |
| djbdns [16] | Raise the axfrdns, dnscache, and tinydns |
| | data limit |
| | |
| dpdk [17] | New upstream stable release |
| | |
| e2guardian [18] | Fix missing SSL certificate validation |
| | issue [CVE-2021-44273] |
| | |
| epiphany-browser [19] | Work around a bug in GLib, fixing a UI |
| | process crash |
| | |
| espeak-ng [20] | Drop spurious 50ms delay while |
| | processing events |
| | |
| espeakup [21] | debian/espeakup.service: Protect |
| | espeakup from system overloads |
| | |
| fcitx5-chinese- | fcitx5-table: add missing dependencies |
| addons [22] | on fcitx5-module-pinyinhelper and |
| | fcitx5-module-punctuation |
| | |
| flac [23] | Fix out-of-bounds write issue [CVE-2021- |
| | 0561] |
| | |
| freerdp2 [24] | Disable additional debug logging |
| | |
| galera-3 [25] | New upstream release |
| | |
| galera-4 [26] | New upstream release |
| | |
| gbonds [27] | Use Treasury API for redemption data |
| | |
| glewlwyd [28] | Fix possible privilege escalation |
| | |
| glibc [29] | Fix bad conversion from ISO-2022-JP-3 |
| | with iconv [CVE-2021-43396]; fix buffer |
| | overflow issues [CVE-2022-23218 |
| | CVE-2022-23219]; fix use-after-free |
| | issue [CVE-2021-33574]; stop replacing |
| | older versions of /etc/nsswitch.conf; |
| | simplify the check for supported kernel |
| | versions, as 2.x kernels are no longer |
| | supported; support installation on |
| | kernels with a release number greater |
| | than 255 |
| | |
| glx-alternatives [30] | After initial setup of the diversions, |
| | install a minimal alternative to the |
| | diverted files so that libraries are not |
| | missing until glx-alternative-mesa |
| | processes its triggers |
| | |
| gnupg2 [31] | scd: Fix CCID driver for SCM SPR332/ |
| | SPR532; avoid network interaction in |
| | generator, which can lead to hangs |
| | |
| gnuplot [32] | Fix division by zero [CVE-2021-44917] |
| | |
| golang-1.15 [33] | Fix IsOnCurve for big.Int values that |
| | are not valid coordinates [CVE-2022- |
| | 23806]; math/big: prevent large memory |
| | consumption in Rat.SetString [CVE-2022- |
| | 23772]; cmd/go: prevent branches from |
| | materializing into versions [CVE-2022- |
| | 23773]; fix stack exhaustion compiling |
| | deeply nested expressions [CVE-2022- |
| | 24921] |
| | |
| golang-github- | Update seccomp support to enable use of |
| containers-common [34] | newer kernel versions |
| | |
| golang-github- | Update seccomp support to enable use of |
| opencontainers- | newer kernel versions |
| specs [35] | |
| | |
| gtk+3.0 [36] | Fix missing search results when using |
| | NFS; prevent Wayland clipboard handling |
| | from locking up in certain corner cases; |
| | improve printing to mDNS-discovered |
| | printers |
| | |
| heartbeat [37] | Fix creation of /run/heartbeat on |
| | systems using systemd |
| | |
| htmldoc [38] | Fix out-of-bounds read issue [CVE-2022- |
| | 0534] |
| | |
| installation-guide [39] | Update documentation and translations |
| | |
| intel-microcode [40] | Update included microcode; mitigate some |
| | security issues [CVE-2020-8694 CVE-2020- |
| | 8695 CVE-2021-0127 CVE-2021-0145 |
| | CVE-2021-0146 CVE-2021-33120] |
| | |
| ldap2zone [41] | Use "mktemp" rather than the |
| | deprecated "tempfile" , avoiding |
| | warnings |
| | |
| lemonldap-ng [42] | Fix auth process in password-testing |
| | plugins [CVE-2021-40874] |
| | |
| libarchive [43] | Fix extracting hardlinks to symlinks; |
| | fix handling of symlink ACLs [CVE-2021- |
| | 23177]; never follow symlinks when |
| | setting file flags [CVE-2021-31566] |
| | |
| libdatetime-timezone- | Update included data |
| perl [44] | |
| | |
| libgdal-grass [45] | Rebuild against grass 7.8.5-1+deb11u1 |
| | |
| libpod [46] | Update seccomp support to enable use of |
| | newer kernel versions |
| | |
| libxml2 [47] | Fix use-after-free issue [CVE-2022- |
| | 23308] |
| | |
| linux [48] | New upstream stable release; [rt] Update |
| | to 5.10.106-rt64; increase ABI to 13 |
| | |
| linux-signed-amd64 [49] | New upstream stable release; [rt] Update |
| | to 5.10.106-rt64; increase ABI to 13 |
| | |
| linux-signed-arm64 [50] | New upstream stable release; [rt] Update |
| | to 5.10.106-rt64; increase ABI to 13 |
| | |
| linux-signed-i386 [51] | New upstream stable release; [rt] Update |
| | to 5.10.106-rt64; increase ABI to 13 |
| | |
| mariadb-10.5 [52] | New upstream release; security fixes |
| | [CVE-2021-35604 CVE-2021-46659 CVE-2021- |
| | 46661 CVE-2021-46662 CVE-2021-46663 |
| | CVE-2021-46664 CVE-2021-46665 CVE-2021- |
| | 46667 CVE-2021-46668 CVE-2022-24048 |
| | CVE-2022-24050 CVE-2022-24051 CVE-2022- |
| | 24052] |
| | |
| mpich [53] | Add Breaks: on older versions of |
| | libmpich1.0-dev, resolving some upgrade |
| | issues |
| | |
| mujs [54] | Fix buffer overflow issue [CVE-2021- |
| | 45005] |
| | |
| mutter [55] | Backport various fixes from upstream's |
| | stable branch |
| | |
| node-cached-path- | Fix prototype pollution issue [CVE-2021- |
| relative [56] | 23518] |
| | |
| node-fetch [57] | Don't forward secure headers to third |
| | party domains [CVE-2022-0235] |
| | |
| node-follow- | Don't send Cookie header across domains |
| redirects [58] | [CVE-2022-0155]; don't send confidential |
| | headers across schemes [CVE-2022-0536] |
| | |
| node-markdown-it [59] | Fix regular expression-based denial of |
| | service issue [CVE-2022-21670] |
| | |
| node-nth-check [60] | Fix regular expression-based denial of |
| | service issue [CVE-2021-3803] |
| | |
| node-prismjs [61] | Escape markup in command line output |
| | [CVE-2022-23647]; update minified files |
| | to ensure that Regular Expression Denial |
| | of Service issue is resolved [CVE-2021- |
| | 3801] |
| | |
| node-trim-newlines [62] | Fix regular expression-based denial of |
| | service issue [CVE-2021-33623] |
| | |
| nvidia-cuda-toolkit [63] | cuda-gdb: Disable non-functional python |
| | support causing segmentation faults; use |
| | a snapshot of openjdk-8-jre (8u312-b07- |
| | 1) |
| | |
| nvidia-graphics-drivers- | New upstream release; fix denial of |
| tesla-450 [64] | service issues [CVE-2022-21813 CVE-2022- |
| | 21814]; nvidia-kernel-support: Provide / |
| | etc/modprobe.d/nvidia-options.conf as a |
| | template |
| | |
| nvidia-modprobe [65] | New upstream release |
| | |
| openboard [66] | Fix application icon |
| | |
| openssl [67] | New upstream release; fix armv8 pointer |
| | authentication |
| | |
| openvswitch [68] | Fix use-after-free issue [CVE-2021- |
| | 36980]; fix installation of libofproto |
| | |
| ostree [69] | Fix compatibility with eCryptFS; avoid |
| | infinite recursion when recovering from |
| | certain errors; mark commits as partial |
| | before downloading; fix an assertion |
| | failure when using a backport or local |
| | build of GLib >= 2.71; fix the ability |
| | to fetch OSTree content from paths |
| | containing non-URI characters (such as |
| | backslashes) or non-ASCII |
| | |
| pdb2pqr [70] | Fix compatibility of propka with Python |
| | 3.8 or above |
| | |
| php-crypt-gpg [71] | Prevent additional options being passed |
| | to GPG [CVE-2022-24953] |
| | |
| php-laravel- | Fix cross-site scripting issue |
| framework [72] | [CVE-2021-43808], missing blocking of |
| | executable content upload [CVE-2021- |
| | 43617] |
| | |
| phpliteadmin [73] | Fix cross-site scripting issue |
| | [CVE-2021-46709] |
| | |
| prips [74] | Fix infinite wrapping if a range reaches |
| | 255.255.255.255; fix CIDR output with |
| | addresses that differ in their first bit |
| | |
| pypy3 [75] | Fix build failures by removing |
| | extraneous