Saturday, December 17, 2022

Updated Debian 11: 11.6 released

------------------------------------------------------------------------
The Debian Project https://www.debian.org/
Updated Debian 11: 11.6 released press@debian.org
December 17th, 2022 https://www.debian.org/News/2022/20221217
------------------------------------------------------------------------


The Debian project is pleased to announce the sixth update of its stable
distribution Debian 11 (codename "bullseye"). This point release mainly
adds corrections for security issues, along with a few adjustments for
serious problems. Security advisories have already been published
separately and are referenced where available.

Please note that the point release does not constitute a new version of
Debian 11 but only updates some of the packages included. There is no
need to throw away old "bullseye" media. After installation, packages
can be upgraded to the current versions using an up-to-date Debian
mirror.

Those who frequently install updates from security.debian.org won't have
to update many packages, and most such updates are included in the point
release.

New installation images will be available soon at the regular locations.

Upgrading an existing installation to this revision can be achieved by
pointing the package management system at one of Debian's many HTTP
mirrors. A comprehensive list of mirrors is available at:

https://www.debian.org/mirror/list



Miscellaneous Bugfixes
----------------------

This stable update adds a few important corrections to the following
packages:

+-------------------------+-------------------------------------------+
| Package | Reason |
+-------------------------+-------------------------------------------+
| awstats [1] | Fix cross site scripting issue [CVE-2022- |
| | 46391] |
| | |
| base-files [2] | Update /etc/debian_version for the 11.6 |
| | point release |
| | |
| binfmt-support [3] | Run binfmt-support.service after systemd- |
| | binfmt.service |
| | |
| clickhouse [4] | Fix out-of-bounds read issues [CVE-2021- |
| | 42387 CVE-2021-42388], buffer overflow |
| | issues [CVE-2021-43304 CVE-2021-43305] |
| | |
| containerd [5] | CRI plugin: Fix goroutine leak during |
| | Exec [CVE-2022-23471] |
| | |
| core-async-clojure [6] | Fix build failures in test suite |
| | |
| dcfldd [7] | Fix SHA1 output on big-endian |
| | architectures |
| | |
| debian-installer [8] | Rebuild against proposed-updates; |
| | increase Linux kernel ABI to 5.10.0-20 |
| | |
| debian-installer- | Rebuild against proposed-updates |
| netboot-images [9] | |
| | |
| debmirror [10] | Add non-free-firmware to the default |
| | section list |
| | |
| distro-info-data [11] | Add Ubuntu 23.04, Lunar Lobster; update |
| | Debian ELTS end dates; correct Debian 8 |
| | (jessie) release date |
| | |
| dojo [12] | Fix prototype pollution issue [CVE-2021- |
| | 23450] |
| | |
| dovecot-fts-xapian [13] | Generate dependency on dovecot ABI |
| | version in use during build |
| | |
| efitools [14] | Fix intermittent build failure due to |
| | incorrect dependency in makefile |
| | |
| evolution [15] | Move Google Contacts addressbooks to |
| | CalDAV since the Google Contacts API has |
| | been turned off |
| | |
| evolution-data- | Move Google Contacts addressbooks to |
| server [16] | CalDAV since the Google Contacts API has |
| | been turned off; fix compatibility with |
| | Gmail OAuth changes |
| | |
| evolution-ews [17] | Fix retrieval of user certificates |
| | belonging to contacts |
| | |
| g810-led [18] | Control device access with uaccess |
| | instead of making everything world- |
| | writable [CVE-2022-46338] |
| | |
| glibc [19] | Fix regression in wmemchr and wcslen on |
| | CPUs that have AVX2 but not BMI2 (e.g. |
| | Intel Haswell) |
| | |
| golang-github-go-chef- | Fix intermittent test failure |
| chef [20] | |
| | |
| grub-efi-amd64- | Don't strip Xen binaries, so they work |
| signed [21] | again; include fonts in the memdisk build |
| | for EFI images; fix bug in core file code |
| | so errors are handled better; bump Debian |
| | SBAT level to 4 |
| | |
| grub-efi-arm64- | Don't strip Xen binaries, so they work |
| signed [22] | again; include fonts in the memdisk build |
| | for EFI images; fix bug in core file code |
| | so errors are handled better; bump Debian |
| | SBAT level to 4 |
| | |
| grub-efi-ia32- | Don't strip Xen binaries, so they work |
| signed [23] | again; include fonts in the memdisk build |
| | for EFI images; fix bug in core file code |
| | so errors are handled better; bump Debian |
| | SBAT level to 4 |
| | |
| grub2 [24] | Don't strip Xen binaries, so they work |
| | again; include fonts in the memdisk build |
| | for EFI images; fix bug in core file code |
| | so errors are handled better; bump Debian |
| | SBAT level to 4 |
| | |
| hydrapaper [25] | Add missing dependeny on python3-pil |
| | |
| isoquery [26] | Fix test failure caused by a French |
| | translation change in the iso-codes |
| | package |
| | |
| jtreg6 [27] | New package, required to build newer |
| | openjdk-11 versions |
| | |
| lemonldap-ng [28] | Improve session destroy propagation |
| | [CVE-2022-37186] |
| | |
| leptonlib [29] | Fix divide-by-zero [CVE-2022-38266] |
| | |
| libapache2-mod-auth- | Fix open redirect issue [CVE-2021-3639] |
| mellon [30] | |
| | |
| libbluray [31] | Fix BD-J support with recent Oracle Java |
| | updates |
| | |
| libconfuse [32] | Fix a heap-based buffer over-read in |
| | cfg_tilde_expand [CVE-2022-40320] |
| | |
| libdatetime-timezone- | Update included data |
| perl [33] | |
| | |
| libtasn1-6 [34] | Fix out-of-bounds read issue [CVE-2021- |
| | 46848] |
| | |
| libvncserver [35] | Fix memory leak [CVE-2020-29260]; support |
| | larger screen sizes |
| | |
| linux [36] | New upstream stable release; increase ABI |
| | to 20; [rt] Update to 5.10.158-rt77 |
| | |
| linux-signed-amd64 [37] | New upstream stable release; increase ABI |
| | to 20; [rt] Update to 5.10.158-rt77 |
| | |
| linux-signed-arm64 [38] | New upstream stable release; increase ABI |
| | to 20; [rt] Update to 5.10.158-rt77 |
| | |
| linux-signed-i386 [39] | New upstream stable release; increase ABI |
| | to 20; [rt] Update to 5.10.158-rt77 |
| | |
| mariadb-10.5 [40] | New upstream stable release; security |
| | fixes [CVE-2018-25032 CVE-2021-46669 |
| | CVE-2022-27376 CVE-2022-27377 CVE-2022- |
| | 27378 CVE-2022-27379 CVE-2022-27380 |
| | CVE-2022-27381 CVE-2022-27382 CVE-2022- |
| | 27383 CVE-2022-27384 CVE-2022-27386 |
| | CVE-2022-27387 CVE-2022-27444 CVE-2022- |
| | 27445 CVE-2022-27446 CVE-2022-27447 |
| | CVE-2022-27448 CVE-2022-27449 CVE-2022- |
| | 27451 CVE-2022-27452 CVE-2022-27455 |
| | CVE-2022-27456 CVE-2022-27457 CVE-2022- |
| | 27458 CVE-2022-32081 CVE-2022-32082 |
| | CVE-2022-32083 CVE-2022-32084 CVE-2022- |
| | 32085 CVE-2022-32086 CVE-2022-32087 |
| | CVE-2022-32088 CVE-2022-32089 CVE-2022- |
| | 32091] |
| | |
| mod-wsgi [41] | Drop X-Client-IP header when it is not a |
| | trusted header [CVE-2022-2255] |
| | |
| mplayer [42] | Fix several security issues [CVE-2022- |
| | 38850 CVE-2022-38851 CVE-2022-38855 |
| | CVE-2022-38858 CVE-2022-38860 CVE-2022- |
| | 38861 CVE-2022-38863 CVE-2022-38864 |
| | CVE-2022-38865 CVE-2022-38866] |
| | |
| mutt [43] | Fix gpgme crash when listing keys in a |
| | public key block, and public key block |
| | listing for old versions of gpgme |
| | |
| nano [44] | Fix crashes and a potential data loss |
| | issue |
| | |
| nftables [45] | Fix off-by-one / double free error |
| | |
| node-hawk [46] | Parse URLs using stdlib [CVE-2022-29167] |
| | |
| node-loader-utils [47] | Fix prototype pollution issue [CVE-2022- |
| | 37599 CVE-2022-37601], regular |
| | expression-based denial of service issue |
| | [CVE-2022-37603] |
| | |
| node-minimatch [48] | Improve protection against regular |
| | expression-based denial of service |
| | [CVE-2022-3517]; fix regression in patch |
| | for CVE-2022-3517 |
| | |
| node-qs [49] | Fix prototype pollution issue [CVE-2022- |
| | 24999] |
| | |
| node-xmldom [50] | Fix prototype pollution issue [CVE-2022- |
| | 37616]; prevent insertion of non-well- |
| | formed nodes [CVE-2022-39353] |
| | |
| nvidia-graphics- | New upstream release; security fixes |
| drivers [51] | [CVE-2022-34670 CVE-2022-34674 CVE-2022- |
| | 34675 CVE-2022-34677 CVE-2022-34679 |
| | CVE-2022-34680 CVE-2022-34682 CVE-2022- |
| | 42254 CVE-2022-42255 CVE-2022-42256 |
| | CVE-2022-42257 CVE-2022-42258 CVE-2022- |
| | 42259 CVE-2022-42260 CVE-2022-42261 |
| | CVE-2022-42262 CVE-2022-42263 CVE-2022- |
| | 42264] |
| | |
| nvidia-graphics- | New upstream release; security fixes |
| drivers- | [CVE-2022-34670 CVE-2022-34674 CVE-2022- |
| legacy-390xx [52] | 34675 CVE-2022-34677 CVE-2022-34680 |
| | CVE-2022-42257 CVE-2022-42258 CVE-2022- |
| | 42259] |
| | |
| nvidia-graphics- | New upstream release; security fixes |
| drivers-tesla-450 [53] | [CVE-2022-34670 CVE-2022-34674 CVE-2022- |
| | 34675 CVE-2022-34677 CVE-2022-34679 |
| | CVE-2022-34680 CVE-2022-34682 CVE-2022- |
| | 42254 CVE-2022-42256 CVE-2022-42257 |
| | CVE-2022-42258 CVE-2022-42259 CVE-2022- |
| | 42260 CVE-2022-42261 CVE-2022-42262 |
| | CVE-2022-42263 CVE-2022-42264] |
| | |
| nvidia-graphics- | New upstream release; security fixes |
| drivers-tesla-470 [54] | [CVE-2022-34670 CVE-2022-34674 CVE-2022- |
| | 34675 CVE-2022-34677 CVE-2022-34679 |
| | CVE-2022-34680 CVE-2022-34682 CVE-2022- |
| | 42254 CVE-2022-42255 CVE-2022-42256 |
| | CVE-2022-42257 CVE-2022-42258 CVE-2022- |
| | 42259 CVE-2022-42260 CVE-2022-42261 |
| | CVE-2022-42262 CVE-2022-42263 CVE-2022- |
| | 42264] |
| | |
| omnievents [55] | Add missing dependency on libjs-jquery to |
| | the omnievents-doc package |
| | |
| onionshare [56] | Fix denial of service issue [CVE-2022- |
| | 21689], HTML injection issue [CVE-2022- |
| | 21690] |
| | |
| openvpn-auth- | Support verify-client-cert directive |
| radius [57] | |
| | |
| postfix [58] | New upstream stable release |
| | |
| postgresql-13 [59] | New upstream stable release |
| | |
| powerline- | Fix command injection via malicious |
| gitstatus [60] | repository config [CVE-2022-42906] |
| | |
| pysubnettree [61] | Fix module build |
| | |
| speech-dispatcher [62] | Reduce espeak buffer size to avoid synth |
| | artifacts |
| | |
| spf-engine [63] | Fix pyspf-milter failing to start due to |
| | an invalid import statement |
| | |
| tinyexr [64] | Fix heap overflow issues [CVE-2022-34300 |
| | CVE-2022-38529] |
| | |
| tinyxml [65] | Fix infinite loop [CVE-2021-42260] |
| | |
| tzdata [66] | Update data for Fiji, Mexico and |
| | Palestine; update leap seconds list |
| | |
| virglrenderer [67] | Fix out-of-bounds write issue [CVE-2022- |
| | 0135] |
| | |
| x2gothinclient [68] | Make the x2gothinclient-minidesktop |
| | package provide the lightdm-greeter |
| | virtual package |
| | |
| xfig [69] | Fix buffer overflow issue [CVE-2021- |
| | 40241] |
| | |
+-------------------------+-------------------------------------------+

1: https://packages.debian.org/src:awstats
2: https://packages.debian.org/src:base-files
3: https://packages.debian.org/src:binfmt-support
4: https://packages.debian.org/src:clickhouse
5: https://packages.debian.org/src:containerd
6: https://packages.debian.org/src:core-async-clojure
7: https://packages.debian.org/src:dcfldd
8: https://packages.debian.org/src:debian-installer
9: https://packages.debian.org/src:debian-installer-netboot-images
10: https://packages.debian.org/src:debmirror
11: https://packages.debian.org/src:distro-info-data
12: https://packages.debian.org/src:dojo
13: https://packages.debian.org/src:dovecot-fts-xapian
14: https://packages.debian.org/src:efitools
15: https://packages.debian.org/src:evolution
16: https://packages.debian.org/src:evolution-data-server
17: https://packages.debian.org/src:evolution-ews
18: https://packages.debian.org/src:g810-led
19: https://packages.debian.org/src:glibc
20: https://packages.debian.org/src:golang-github-go-chef-chef
21: https://packages.debian.org/src:grub-efi-amd64-signed
22: https://packages.debian.org/src:grub-efi-arm64-signed
23: https://packages.debian.org/src:grub-efi-ia32-signed
24: https://packages.debian.org/src:grub2
25: https://packages.debian.org/src:hydrapaper
26: https://packages.debian.org/src:isoquery
27: https://packages.debian.org/src:jtreg6
28: https://packages.debian.org/src:lemonldap-ng
29: https://packages.debian.org/src:leptonlib
30: https://packages.debian.org/src:libapache2-mod-auth-mellon
31: https://packages.debian.org/src:libbluray
32: https://packages.debian.org/src:libconfuse
33: https://packages.debian.org/src:libdatetime-timezone-perl
34: https://packages.debian.org/src:libtasn1-6
35: https://packages.debian.org/src:libvncserver
36: https://packages.debian.org/src:linux
37: https://packages.debian.org/src:linux-signed-amd64
38: https://packages.debian.org/src:linux-signed-arm64
39: https://packages.debian.org/src:linux-signed-i386
40: https://packages.debian.org/src:mariadb-10.5
41: https://packages.debian.org/src:mod-wsgi
42: https://packages.debian.org/src:mplayer
43: https://packages.debian.org/src:mutt
44: https://packages.debian.org/src:nano
45: https://packages.debian.org/src:nftables
46: https://packages.debian.org/src:node-hawk
47: https://packages.debian.org/src:node-loader-utils
48: https://packages.debian.org/src:node-minimatch
49: https://packages.debian.org/src:node-qs
50: https://packages.debian.org/src:node-xmldom
51: https://packages.debian.org/src:nvidia-graphics-drivers
52: https://packages.debian.org/src:nvidia-graphics-drivers-legacy-390xx
53: https://packages.debian.org/src:nvidia-graphics-drivers-tesla-450
54: https://packages.debian.org/src:nvidia-graphics-drivers-tesla-470
55: https://packages.debian.org/src:omnievents
56: https://packages.debian.org/src:onionshare
57: https://packages.debian.org/src:openvpn-auth-radius
58: https://packages.debian.org/src:postfix
59: https://packages.debian.org/src:postgresql-13
60: https://packages.debian.org/src:powerline-gitstatus
61: https://packages.debian.org/src:pysubnettree
62: https://packages.debian.org/src:speech-dispatcher
63: https://packages.debian.org/src:spf-engine
64: https://packages.debian.org/src:tinyexr
65: https://packages.debian.org/src:tinyxml
66: https://packages.debian.org/src:tzdata
67: https://packages.debian.org/src:virglrenderer
68: https://packages.debian.org/src:x2gothinclient
69: https://packages.debian.org/src:xfig

Security Updates
----------------

This revision adds the following security updates to the stable release.
The Security Team has already released an advisory for each of these
updates:

+----------------+------------------------------+
| Advisory ID | Package |
+----------------+------------------------------+
| DSA-5212 [70] | chromium [71] |
| | |
| DSA-5223 [72] | chromium [73] |
| | |
| DSA-5224 [74] | poppler [75] |
| | |
| DSA-5225 [76] | chromium [77] |
| | |
| DSA-5226 [78] | pcs [79] |
| | |
| DSA-5227 [80] | libgoogle-gson-java [81] |
| | |
| DSA-5228 [82] | gdk-pixbuf [83] |
| | |
| DSA-5229 [84] | freecad [85] |
| | |
| DSA-5230 [86] | chromium [87] |
| | |
| DSA-5231 [88] | connman [89] |
| | |
| DSA-5232 [90] | tinygltf [91] |
| | |
| DSA-5233 [92] | e17 [93] |
| | |
| DSA-5234 [94] | fish [95] |
| | |
| DSA-5235 [96] | bind9 [97] |
| | |
| DSA-5236 [98] | expat [99] |
| | |
| DSA-5239 [100] | gdal [101] |
| | |
| DSA-5240 [102] | webkit2gtk [103] |
| | |
| DSA-5241 [104] | wpewebkit [105] |
| | |
| DSA-5242 [106] | maven-shared-utils [107] |
| | |
| DSA-5243 [108] | lighttpd [109] |
| | |
| DSA-5244 [110] | chromium [111] |
| | |
| DSA-5245 [112] | chromium [113] |
| | |
| DSA-5246 [114] | mediawiki [115] |
| | |
| DSA-5247 [116] | barbican [117] |
| | |
| DSA-5248 [118] | php-twig [119] |
| | |
| DSA-5249 [120] | strongswan [121] |
| | |
| DSA-5250 [122] | dbus [123] |
| | |
| DSA-5251 [124] | isc-dhcp [125] |
| | |
| DSA-5252 [126] | libreoffice [127] |
| | |
| DSA-5253 [128] | chromium [129] |
| | |
| DSA-5254 [130] | python-django [131] |
| | |
| DSA-5255 [132] | libksba [133] |
| | |
| DSA-5256 [134] | bcel [135] |
| | |
| DSA-5257 [136] | linux-signed-arm64 [137] |
| | |
| DSA-5257 [138] | linux-signed-amd64 [139] |
| | |
| DSA-5257 [140] | linux-signed-i386 [141] |
| | |
| DSA-5257 [142] | linux [143] |
| | |
| DSA-5258 [144] | squid [145] |
| | |
| DSA-5260 [146] | lava [147] |
| | |
| DSA-5261 [148] | chromium [149] |
| | |
| DSA-5263 [150] | chromium [151] |
| | |
| DSA-5264 [152] | batik [153] |
| | |
| DSA-5265 [154] | tomcat9 [155] |
| | |
| DSA-5266 [156] | expat [157] |
| | |
| DSA-5267 [158] | pysha3 [159] |
| | |
| DSA-5268 [160] | ffmpeg [161] |
| | |
| DSA-5269 [162] | pypy3 [163] |
| | |
| DSA-5270 [164] | ntfs-3g [165] |
| | |
| DSA-5271 [166] | libxml2 [167] |
| | |
| DSA-5272 [168] | xen [169] |
| | |
| DSA-5273 [170] | webkit2gtk [171] |
| | |
| DSA-5274 [172] | wpewebkit [173] |
| | |
| DSA-5275 [174] | chromium [175] |
| | |
| DSA-5276 [176] | pixman [177] |
| | |
| DSA-5277 [178] | php7.4 [179] |
| | |
| DSA-5278 [180] | xorg-server [181] |
| | |
| DSA-5279 [182] | wordpress [183] |
| | |
| DSA-5280 [184] | grub-efi-amd64-signed [185] |
| | |
| DSA-5280 [186] | grub-efi-arm64-signed [187] |
| | |
| DSA-5280 [188] | grub-efi-ia32-signed [189] |
| | |
| DSA-5280 [190] | grub2 [191] |
| | |
| DSA-5281 [192] | nginx [193] |
| | |
| DSA-5283 [194] | jackson-databind [195] |
| | |
| DSA-5285 [196] | asterisk [197] |
| | |
| DSA-5286 [198] | krb5 [199] |
| | |
| DSA-5287 [200] | heimdal [201] |
| | |
| DSA-5288 [202] | graphicsmagick [203] |
| | |
| DSA-5289 [204] | chromium [205] |
| | |
| DSA-5290 [206] | commons-configuration2 [207] |
| | |
| DSA-5291 [208] | mujs [209] |
| | |
| DSA-5292 [210] | snapd [211] |
| | |
| DSA-5293 [212] | chromium [213] |
| | |
| DSA-5294 [214] | jhead [215] |
| | |
| DSA-5295 [216] | chromium [217] |
| | |
| DSA-5296 [218] | xfce4-settings [219] |
| | |
| DSA-5297 [220] | vlc [221] |
| | |
| DSA-5298 [222] | cacti [223] |
| | |
| DSA-5299 [224] | openexr [225] |
| | |
+----------------+------------------------------+

70: https://www.debian.org/security/2022/dsa-5212
71: https://packages.debian.org/src:chromium
72: https://www.debian.org/security/2022/dsa-5223
73: https://packages.debian.org/src:chromium
74: https://www.debian.org/security/2022/dsa-5224
75: https://packages.debian.org/src:poppler
76: https://www.debian.org/security/2022/dsa-5225
77: https://packages.debian.org/src:chromium
78: https://www.debian.org/security/2022/dsa-5226
79: https://packages.debian.org/src:pcs
80: https://www.debian.org/security/2022/dsa-5227
81: https://packages.debian.org/src:libgoogle-gson-java
82: https://www.debian.org/security/2022/dsa-5228
83: https://packages.debian.org/src:gdk-pixbuf
84: https://www.debian.org/security/2022/dsa-5229
85: https://packages.debian.org/src:freecad
86: https://www.debian.org/security/2022/dsa-5230
87: https://packages.debian.org/src:chromium
88: https://www.debian.org/security/2022/dsa-5231
89: https://packages.debian.org/src:connman
90: https://www.debian.org/security/2022/dsa-5232
91: https://packages.debian.org/src:tinygltf
92: https://www.debian.org/security/2022/dsa-5233
93: https://packages.debian.org/src:e17
94: https://www.debian.org/security/2022/dsa-5234
95: https://packages.debian.org/src:fish
96: https://www.debian.org/security/2022/dsa-5235
97: https://packages.debian.org/src:bind9
98: https://www.debian.org/security/2022/dsa-5236
99: https://packages.debian.org/src:expat
100: https://www.debian.org/security/2022/dsa-5239
101: https://packages.debian.org/src:gdal
102: https://www.debian.org/security/2022/dsa-5240
103: https://packages.debian.org/src:webkit2gtk
104: https://www.debian.org/security/2022/dsa-5241
105: https://packages.debian.org/src:wpewebkit
106: https://www.debian.org/security/2022/dsa-5242
107: https://packages.debian.org/src:maven-shared-utils
108: https://www.debian.org/security/2022/dsa-5243
109: https://packages.debian.org/src:lighttpd
110: https://www.debian.org/security/2022/dsa-5244
111: https://packages.debian.org/src:chromium
112: https://www.debian.org/security/2022/dsa-5245
113: https://packages.debian.org/src:chromium
114: https://www.debian.org/security/2022/dsa-5246
115: https://packages.debian.org/src:mediawiki
116: https://www.debian.org/security/2022/dsa-5247
117: https://packages.debian.org/src:barbican
118: https://www.debian.org/security/2022/dsa-5248
119: https://packages.debian.org/src:php-twig
120: https://www.debian.org/security/2022/dsa-5249
121: https://packages.debian.org/src:strongswan
122: https://www.debian.org/security/2022/dsa-5250
123: https://packages.debian.org/src:dbus
124: https://www.debian.org/security/2022/dsa-5251
125: https://packages.debian.org/src:isc-dhcp
126: https://www.debian.org/security/2022/dsa-5252
127: https://packages.debian.org/src:libreoffice
128: https://www.debian.org/security/2022/dsa-5253
129: https://packages.debian.org/src:chromium
130: https://www.debian.org/security/2022/dsa-5254
131: https://packages.debian.org/src:python-django
132: https://www.debian.org/security/2022/dsa-5255
133: https://packages.debian.org/src:libksba
134: https://www.debian.org/security/2022/dsa-5256
135: https://packages.debian.org/src:bcel
136: https://www.debian.org/security/2022/dsa-5257
137: https://packages.debian.org/src:linux-signed-arm64
138: https://www.debian.org/security/2022/dsa-5257
139: https://packages.debian.org/src:linux-signed-amd64
140: https://www.debian.org/security/2022/dsa-5257
141: https://packages.debian.org/src:linux-signed-i386
142: https://www.debian.org/security/2022/dsa-5257
143: https://packages.debian.org/src:linux
144: https://www.debian.org/security/2022/dsa-5258
145: https://packages.debian.org/src:squid
146: https://www.debian.org/security/2022/dsa-5260
147: https://packages.debian.org/src:lava
148: https://www.debian.org/security/2022/dsa-5261
149: https://packages.debian.org/src:chromium
150: https://www.debian.org/security/2022/dsa-5263
151: https://packages.debian.org/src:chromium
152: https://www.debian.org/security/2022/dsa-5264
153: https://packages.debian.org/src:batik
154: https://www.debian.org/security/2022/dsa-5265
155: https://packages.debian.org/src:tomcat9
156: https://www.debian.org/security/2022/dsa-5266
157: https://packages.debian.org/src:expat
158: https://www.debian.org/security/2022/dsa-5267
159: https://packages.debian.org/src:pysha3
160: https://www.debian.org/security/2022/dsa-5268
161: https://packages.debian.org/src:ffmpeg
162: https://www.debian.org/security/2022/dsa-5269
163: https://packages.debian.org/src:pypy3
164: https://www.debian.org/security/2022/dsa-5270
165: https://packages.debian.org/src:ntfs-3g
166: https://www.debian.org/security/2022/dsa-5271
167: https://packages.debian.org/src:libxml2
168: https://www.debian.org/security/2022/dsa-5272
169: https://packages.debian.org/src:xen
170: https://www.debian.org/security/2022/dsa-5273
171: https://packages.debian.org/src:webkit2gtk
172: https://www.debian.org/security/2022/dsa-5274
173: https://packages.debian.org/src:wpewebkit
174: https://www.debian.org/security/2022/dsa-5275
175: https://packages.debian.org/src:chromium
176: https://www.debian.org/security/2022/dsa-5276
177: https://packages.debian.org/src:pixman
178: https://www.debian.org/security/2022/dsa-5277
179: https://packages.debian.org/src:php7.4
180: https://www.debian.org/security/2022/dsa-5278
181: https://packages.debian.org/src:xorg-server
182: https://www.debian.org/security/2022/dsa-5279
183: https://packages.debian.org/src:wordpress
184: https://www.debian.org/security/2022/dsa-5280
185: https://packages.debian.org/src:grub-efi-amd64-signed
186: https://www.debian.org/security/2022/dsa-5280
187: https://packages.debian.org/src:grub-efi-arm64-signed
188: https://www.debian.org/security/2022/dsa-5280
189: https://packages.debian.org/src:grub-efi-ia32-signed
190: https://www.debian.org/security/2022/dsa-5280
191: https://packages.debian.org/src:grub2
192: https://www.debian.org/security/2022/dsa-5281
193: https://packages.debian.org/src:nginx
194: https://www.debian.org/security/2022/dsa-5283
195: https://packages.debian.org/src:jackson-databind
196: https://www.debian.org/security/2022/dsa-5285
197: https://packages.debian.org/src:asterisk
198: https://www.debian.org/security/2022/dsa-5286
199: https://packages.debian.org/src:krb5
200: https://www.debian.org/security/2022/dsa-5287
201: https://packages.debian.org/src:heimdal
202: https://www.debian.org/security/2022/dsa-5288
203: https://packages.debian.org/src:graphicsmagick
204: https://www.debian.org/security/2022/dsa-5289
205: https://packages.debian.org/src:chromium
206: https://www.debian.org/security/2022/dsa-5290
207: https://packages.debian.org/src:commons-configuration2
208: https://www.debian.org/security/2022/dsa-5291
209: https://packages.debian.org/src:mujs
210: https://www.debian.org/security/2022/dsa-5292
211: https://packages.debian.org/src:snapd
212: https://www.debian.org/security/2022/dsa-5293
213: https://packages.debian.org/src:chromium
214: https://www.debian.org/security/2022/dsa-5294
215: https://packages.debian.org/src:jhead
216: https://www.debian.org/security/2022/dsa-5295
217: https://packages.debian.org/src:chromium
218: https://www.debian.org/security/2022/dsa-5296
219: https://packages.debian.org/src:xfce4-settings
220: https://www.debian.org/security/2022/dsa-5297
221: https://packages.debian.org/src:vlc
222: https://www.debian.org/security/2022/dsa-5298
223: https://packages.debian.org/src:cacti
224: https://www.debian.org/security/2022/dsa-5299
225: https://packages.debian.org/src:openexr

Debian Installer
----------------

The installer has been updated to include the fixes incorporated into
stable by the point release.


URLs
----

The complete lists of packages that have changed with this revision:

https://deb.debian.org/debian/dists/bullseye/ChangeLog


The current stable distribution:

https://deb.debian.org/debian/dists/stable/


Proposed updates to the stable distribution:

https://deb.debian.org/debian/dists/proposed-updates


stable distribution information (release notes, errata etc.):

https://www.debian.org/releases/stable/


Security announcements and information:

https://www.debian.org/security/



About Debian
------------

The Debian Project is an association of Free Software developers who
volunteer their time and effort in order to produce the completely free
operating system Debian.


Contact Information
-------------------

For further information, please visit the Debian web pages at
https://www.debian.org/, send mail to <press@debian.org>, or contact the
stable release team at <debian-release@lists.debian.org>.

Friday, December 16, 2022

Re: Fedora elections voting now open

Remember that voting in the Fedora Linux 37 elections is open through
23:59 UTC on Thursday 22 December. Go to the Elections app[1] to cast
your vote. Voting closes at 23:59 UTC on Thursday 22 December. Don't
forget to claim your "I Voted" badge when you cast your ballot. Links
to candidate interviews are in the Elections app and on the Community
Blog[2].

[1] https://elections.fedoraproject.org/
[2] https://communityblog.fedoraproject.org/f37-elections-voting-now-open/

--
Ben Cotton
He / Him / His
Fedora Program Manager
Red Hat
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue

[USN-5783-1] Linux kernel (OEM) vulnerability

==========================================================================
Ubuntu Security Notice USN-5783-1
December 16, 2022

linux-oem-5.17 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS

Summary:

The system could be made to crash or run programs as an administrator.

Software Description:
- linux-oem-5.17: Linux kernel for OEM systems

Details:

Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation
in the Linux kernel contained multiple use-after-free vulnerabilities. A
physically proximate attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
linux-image-5.17.0-1025-oem 5.17.0-1025.26
linux-image-oem-22.04 5.17.0.1025.23
linux-image-oem-22.04a 5.17.0.1025.23

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-5783-1
CVE-2022-42896

Package Information:
https://launchpad.net/ubuntu/+source/linux-oem-5.17/5.17.0-1025.26

Thursday, December 15, 2022

OpenBSD Errata: December 16, 2022 (acme)

Errata patches for acme-client(8) have been released for OpenBSD
7.1 and 7.2.

Binary updates for the amd64, i386 and arm64 platform are available
via the syspatch utility. Source code patches can be found on the
respective errata page:

https://www.openbsd.org/errata71.html
https://www.openbsd.org/errata72.html

[USN-5782-1] Firefox vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5782-1
December 15, 2022

firefox vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in Firefox.

Software Description:
- firefox: Mozilla Open Source web browser

Details:

It was discovered that Firefox was using an out-of-date libusrsctp library.
An attacker could possibly use this library to perform a reentrancy issue
on Firefox. (CVE-2022-46871)

Nika Layzell discovered that Firefox was not performing a check on paste
received from cross-processes. An attacker could potentially exploit this
to obtain sensitive information. (CVE-2022-46872)

Pete Freitag discovered that Firefox did not implement the unsafe-hashes
CSP directive. An attacker who was able to inject markup into a page
otherwise protected by a Content Security Policy may have been able to
inject an executable script. (CVE-2022-46873)

Matthias Zoellner discovered that Firefox was not keeping the filename
ending intact when using the drag-and-drop event. An attacker could
possibly use this issue to add a file with a malicious extension, leading
to execute arbitrary code. (CVE-2022-46874)

Hafiizh discovered that Firefox was not handling fullscreen notifications
when the browser window goes into fullscreen mode. An attacker could
possibly use this issue to spoof the user and obtain sensitive information.
(CVE-2022-46877)

Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2022-46878,
CVE-2022-46879)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
firefox 108.0+build2-0ubuntu0.20.04.1

Ubuntu 18.04 LTS:
firefox 108.0+build2-0ubuntu0.18.04.1

After a standard system update you need to restart Firefox to make all the
necessary changes.

References:
https://ubuntu.com/security/notices/USN-5782-1
CVE-2022-46871, CVE-2022-46872, CVE-2022-46873, CVE-2022-46874,
CVE-2022-46877, CVE-2022-46878, CVE-2022-46879

Package Information:
https://launchpad.net/ubuntu/+source/firefox/108.0+build2-0ubuntu0.20.04.1
https://launchpad.net/ubuntu/+source/firefox/108.0+build2-0ubuntu0.18.04.1

Wednesday, December 14, 2022

[USN-5781-1] Emacs vulnerability

==========================================================================
Ubuntu Security Notice USN-5781-1
December 14, 2022

emacs24 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM

Summary:

Emacs could be made to run programs as your login if it received
specially crafted input.

Software Description:
- emacs24: GNU Emacs editor

Details:

It was discovered that Emacs did not properly manage certain inputs.
An attacker could possibly use this issue to execute arbitrary commands.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
emacs24 24.5+1-6ubuntu1.1+esm1
emacs24-bin-common 24.5+1-6ubuntu1.1+esm1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5781-1
CVE-2022-45939

[USN-5780-1] Linux kernel (OEM) vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5780-1
December 14, 2022

linux-oem-6.0 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-oem-6.0: Linux kernel for OEM systems

Details:

It was discovered that a memory leak existed in the IPv6 implementation of
the Linux kernel. A local attacker could use this to cause a denial of
service (memory exhaustion). (CVE-2022-3524)

It was discovered that the Bluetooth HCI implementation in the Linux kernel
did not properly deallocate memory in some situations. An attacker could
possibly use this cause a denial of service (memory exhaustion).
(CVE-2022-3619)

It was discovered that the Broadcom FullMAC USB WiFi driver in the Linux
kernel did not properly perform bounds checking in some situations. A
physically proximate attacker could use this to craft a malicious USB
device that when inserted, could cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2022-3628)

Tamás Koczka discovered that the Bluetooth L2CAP implementation in the
Linux kernel did not properly initialize memory in some situations. A
physically proximate attacker could possibly use this to expose sensitive
information (kernel memory). (CVE-2022-42895)

Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation
in the Linux kernel contained multiple use-after-free vulnerabilities. A
physically proximate attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2022-42896)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
linux-image-6.0.0-1008-oem 6.0.0-1008.8
linux-image-oem-22.04b 6.0.0.1008.8

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-5780-1
CVE-2022-3524, CVE-2022-3619, CVE-2022-3628, CVE-2022-42895,
CVE-2022-42896

Package Information:
https://launchpad.net/ubuntu/+source/linux-oem-6.0/6.0.0-1008.8

[USN-5779-1] Linux kernel (Azure) vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5779-1
December 14, 2022

linux-azure, linux-azure-5.15, linux-azure-fde vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-azure-fde: Linux kernel for Microsoft Azure CVM cloud systems
- linux-azure-5.15: Linux kernel for Microsoft Azure cloud systems

Details:

It was discovered that the NFSD implementation in the Linux kernel did not
properly handle some RPC messages, leading to a buffer overflow. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2022-43945)

Jann Horn discovered that the Linux kernel did not properly track memory
allocations for anonymous VMA mappings in some situations, leading to
potential data structure reuse. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2022-42703)

It was discovered that a memory leak existed in the IPv6 implementation of
the Linux kernel. A local attacker could use this to cause a denial of
service (memory exhaustion). (CVE-2022-3524)

It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel, leading to a use-after-free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2022-3564)

It was discovered that the ISDN implementation of the Linux kernel
contained a use-after-free vulnerability. A privileged user could use this
to cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2022-3565)

It was discovered that the TCP implementation in the Linux kernel contained
a data race condition. An attacker could possibly use this to cause
undesired behaviors. (CVE-2022-3566)

It was discovered that the IPv6 implementation in the Linux kernel
contained a data race condition. An attacker could possibly use this to
cause undesired behaviors. (CVE-2022-3567)

It was discovered that the Realtek RTL8152 USB Ethernet adapter driver in
the Linux kernel did not properly handle certain error conditions. A local
attacker with physical access could plug in a specially crafted USB device
to cause a denial of service (memory exhaustion). (CVE-2022-3594)

It was discovered that a null pointer dereference existed in the NILFS2
file system implementation in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash). (CVE-2022-3621)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
linux-image-5.15.0-1029-azure 5.15.0-1029.36
linux-image-5.15.0-1029-azure-fde 5.15.0-1029.36.1
linux-image-azure 5.15.0.1029.25
linux-image-azure-fde 5.15.0.1029.36.6
linux-image-azure-lts-22.04 5.15.0.1029.25

Ubuntu 20.04 LTS:
linux-image-5.15.0-1029-azure 5.15.0-1029.36~20.04.1
linux-image-azure 5.15.0.1029.36~20.04.19

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-5779-1
CVE-2022-3524, CVE-2022-3564, CVE-2022-3565, CVE-2022-3566,
CVE-2022-3567, CVE-2022-3594, CVE-2022-3621, CVE-2022-42703,
CVE-2022-43945

Package Information:
https://launchpad.net/ubuntu/+source/linux-azure/5.15.0-1029.36
https://launchpad.net/ubuntu/+source/linux-azure-fde/5.15.0-1029.36.1
https://launchpad.net/ubuntu/+source/linux-azure-5.15/5.15.0-1029.36~20.04.1

OpenBSD Errata: December 14, 2022 (xserver vmd gpuinv)

Errata patches for Xorg(1), vmd(8), and inteldrm(4) have been
released for OpenBSD 7.2. Errata patches for Xorg(1) and inteldrm(4)
have been released for OpenBSD 7.1.

Binary updates for the amd64, i386 and arm64 platform are available
via the syspatch utility. Source code patches can be found on the
respective errata page:

https://www.openbsd.org/errata71.html
https://www.openbsd.org/errata72.html

[USN-5778-1] X.Org X Server vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5778-1
December 14, 2022

xorg-server, xorg-server-hwe-18.04, xwayland vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in X.Org X Server.

Software Description:
- xorg-server: X.Org X11 server
- xwayland: X server for running X clients under Wayland
- xorg-server-hwe-18.04: X.Org X11 server

Details:

Jan-Niklas Sohn discovered that X.Org X Server extensions contained
multiple security issues. An attacker could possibly use these issues to
cause the X Server to crash, execute arbitrary code, or escalate
privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
xserver-xorg-core 2:21.1.4-2ubuntu1.3
xwayland 2:22.1.3-2ubuntu0.2

Ubuntu 22.04 LTS:
xserver-xorg-core 2:21.1.3-2ubuntu2.5
xwayland 2:22.1.1-1ubuntu0.4

Ubuntu 20.04 LTS:
xserver-xorg-core 2:1.20.13-1ubuntu1~20.04.5
xwayland 2:1.20.13-1ubuntu1~20.04.5

Ubuntu 18.04 LTS:
xserver-xorg-core 2:1.19.6-1ubuntu4.13
xserver-xorg-core-hwe-18.04 2:1.20.8-2ubuntu2.2~18.04.9
xwayland 2:1.19.6-1ubuntu4.13
xwayland-hwe-18.04 2:1.20.8-2ubuntu2.2~18.04.9

After a standard system update you need to reboot your computer to make all
the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5778-1
CVE-2022-4283, CVE-2022-46340, CVE-2022-46341, CVE-2022-46342,
CVE-2022-46343, CVE-2022-46344

Package Information:
https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.4-2ubuntu1.3
https://launchpad.net/ubuntu/+source/xwayland/2:22.1.3-2ubuntu0.2
https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.3-2ubuntu2.5
https://launchpad.net/ubuntu/+source/xwayland/2:22.1.1-1ubuntu0.4
https://launchpad.net/ubuntu/+source/xorg-server/2:1.20.13-1ubuntu1~20.04.5
https://launchpad.net/ubuntu/+source/xorg-server/2:1.19.6-1ubuntu4.13

https://launchpad.net/ubuntu/+source/xorg-server-hwe-18.04/2:1.20.8-2ubuntu2.2~18.04.9

Tuesday, December 13, 2022

rpki-client 8.2 released

rpki-client 8.2 has just been released and will be available in the
rpki-client directory of any OpenBSD mirror soon.

rpki-client is a FREE, easy-to-use implementation of the Resource
Public Key Infrastructure (RPKI) for Relying Parties (RP) to
facilitate validation of BGP announcements. The program queries the
global RPKI repository system and validates untrusted network inputs.
The program outputs validated ROA payloads, BGPsec Router keys, and
ASPA payloads in configuration formats suitable for OpenBGPD and BIRD,
and supports emitting CSV and JSON for consumption by other routing
stacks.

See RFC 6480 and RFC 6811 for a description of how RPKI and BGP Prefix
Origin Validation help secure the global Internet routing system.

rpki-client was primarily developed by Kristaps Dzonsons, Claudio
Jeker, Job Snijders, Theo Buehler, Theo de Raadt and Sebastian Benoit
as part of the OpenBSD Project.

This release includes the following changes to the previous release:

- Add a new '-H' command line option to create a shortlist of
repositories to synchronize to. For example, when invoking
"rpki-client -H rpki.ripe.net -H chloe.sobornost.net", the utility
will not connect to any other hosts other than the two specified
through the -H option.

- Add support for validating Geofeed (RFC 9092) authenticators. To
see an example download https://sobornost.net/geofeed.csv and run
"rpki-client -f geofeed.csv"

- Add support for validating Trust Anchor Key (TAK) objects. TAK
objects can be used to produce new Trust Anchor Locators (TALs) signed
by and verified against the previous Trust Anchor. See
draft-ietf-sidrops-signed-tal for the full specification.

- Log lines related to RRDP/HTTPS connection problems now include the
IP address of the problematic endpoint (in brackets).

- Improve the error message when an invalid filename is encountered
in the rpkiManifest field in the Subject Access Information (SIA)
extension.

- Emit a warning when unexpected X.509 extensions are encountered.

- Restrict the ROA ipAddrBlocks field to only allow two
ROAIPAddressFamily structures (one per address family). See
draft-ietf-sidrops-rfc6482bis.

- Check the absence of the Path Length constraint in the Basic
Constraints extension.

- Restrict the SIA extension to only allow the signedObject and
rpkiNotify accessMethods.

- Check that the Signed Object access method is present in ROA, MFT,
ASPA, TAK, and GBR End-Entity certificates.

- In addition to the 'rsync://' scheme, also permit other schemes
(such as 'https://') in the SIA signedObject access method.

- Check that the KeyUsage extension is set to nothing but
digitalSignature on End-Entity certificates.

- Chect that the KeyUsage extension is set to nothing but keyCertSign
and CRLSign on CA certificates.

- Check that the ExtendedKeyUsage extension is absent on CA
certificates.

- Fix a bug in the handling of the port of http_proxy.

- The '-r' command line option has been deprecated.

- Filemode (-f) output is now presented as a text based table.

rpki-client works on all operating systems with a libcrypto library
based on OpenSSL 1.1 or LibreSSL 3.5, and a libtls library compatible
with LibreSSL 3.5 or later.

rpki-client is known to compile and run on at least the following
operating systems: Alpine, CentOS, Debian, Fedora, FreeBSD, Red Hat,
Rocky, Ubuntu, macOS, and of course OpenBSD!

It is our hope that packagers take interest and help adapt
rpki-client-portable to more distributions.

The mirrors where rpki-client can be found are on
https://www.rpki-client.org/portable.html

Reporting Bugs:
===============

General bugs may be reported to tech@openbsd.org

Portable bugs may be filed at
https://github.com/rpki-client/rpki-client-portable

We welcome feedback and improvements from the broader community.
Thanks to all of the contributors who helped make this release
possible.

Assistance to coordinate security issues is available via
security@openbsd.org.

[USN-5777-1] Pillow vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5777-1
December 13, 2022

pillow vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in Pillow.

Software Description:
- pillow: Python Imaging Library

Details:

It was discovered that Pillow incorrectly handled the deletion of temporary
files when using a temporary directory that contains spaces. An attacker
could
possibly use this issue to delete arbitrary files. This issue only affected
Ubuntu 20.04 LTS. (CVE-2022-24303)

It was discovered that Pillow incorrectly handled the decompression of
highly
compressed GIF data. An attacker could possibly use this issue to cause
Pillow
to crash, resulting in a denial of service. (CVE-2022-45198)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
  python3-pil                     9.0.1-1ubuntu0.1

Ubuntu 20.04 LTS:
  python3-pil                     7.0.0-4ubuntu0.7

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5777-1
  CVE-2022-24303, CVE-2022-45198

Package Information:
  https://launchpad.net/ubuntu/+source/pillow/9.0.1-1ubuntu0.1
  https://launchpad.net/ubuntu/+source/pillow/7.0.0-4ubuntu0.7