Security

oniguruma Dec 6, 2019, 01:53 PMDec 6, 2019, 01:53 PM
Version: 6.9.4-alt1
Summary: Regular expressions library
Changelog:
- 6.9.4
- fixes:
	* CVE-2019-19012 Integer overflow related to reg->dmax in search_in_range()
	* CVE-2019-19203 heap-buffer-overflow in gb18030_mbc_enc_len()
	* CVE-2019-19204 heap-buffer-overflow in fetch_interval_quantifier()
sudo Oct 31, 2019, 05:11 AMOct 31, 2019, 05:11 AM
Version: 1.8.28-alt1
Summary: Allows command execution as another user
Changelog:
- Update to autumn security release (closes: 37334)
- Code execution with euid==0 in rare box configurations (fixes: CVE-2019-14287)
- Fix post script for sudowheel control in case of upgrade in not default state
libXfont2 Oct 7, 2019, 03:31 PMOct 7, 2019, 03:31 PM
Version: 2.0.3-alt1
Summary: X.Org libXfont runtime library
Changelog:
- fixes:
 + CVE-2017-16611 Open files with O_NOFOLLOW
libspice-gtk Sep 25, 2019, 05:16 PMSep 25, 2019, 05:16 PM
Version: 0.34-alt0.M80C.1
Summary: A GTK widget for SPICE clients
Changelog:
- Port to c8.1 branch due to upgrade of the server side (SPICE);
- (Fixes: CVE-2016-3066).
dovecot-pigeonhole Aug 30, 2019, 01:37 PMAug 30, 2019, 01:37 PM
Version: 0.4.11-alt1.M80C.1
Summary: Sieve language and the ManageSieve protocol for the Dovecot Secure IMAP Server
Changelog:
- Applied upstream security fix (fixes CVE-2019-11500).
dovecot Aug 30, 2019, 01:35 PMAug 30, 2019, 01:35 PM
Version: 2.2.21-alt1.M80C.1
Summary: Dovecot secure IMAP/POP3 server
Changelog:
- Applied upstream security fix (fixes CVE-2019-11500).
firmware-intel-ucode Aug 6, 2019, 02:26 PMAug 6, 2019, 02:26 PM
Version: 9-alt1.20190514
Summary: Microcode definitions for Intel processors
Changelog:
- Sync with Debian 3.20190514.1:
  + New upstream microcode datafile 20190514
  + SECURITY UPDATE
    Implements MDS mitigation (RIDL, Fallout, Zombieload), INTEL-SA-00223
    CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091
  + New Microcodes:
    sig 0x00030678, pf_mask 0x02, 2019-04-22, rev 0x0838, size 52224
    sig 0x00030678, pf_mask 0x0c, 2019-04-22, rev 0x0838, size 52224
    sig 0x00030679, pf_mask 0x0f, 2019-04-23, rev 0x090c, size 52224
    sig 0x000406c3, pf_mask 0x01, 2019-04-23, rev 0x0368, size 69632
    sig 0x000406c4, pf_mask 0x01, 2019-04-23, rev 0x0411, size 68608
    sig 0x00050657, pf_mask 0xbf, 2019-02-27, rev 0x5000021, size 47104
  + Updated Microcodes:
    sig 0x000206a7, pf_mask 0x12, 2019-02-17, rev 0x002f, size 12288
    sig 0x000306a9, pf_mask 0x12, 2019-02-13, rev 0x0021, size 14336
    sig 0x000306c3, pf_mask 0x32, 2019-02-26, rev 0x0027, size 23552
    sig 0x000306d4, pf_mask 0xc0, 2019-03-07, rev 0x002d, size 19456
    sig 0x000306e4, pf_mask 0xed, 2019-03-14, rev 0x042e, size 16384
    sig 0x000306e7, pf_mask 0xed, 2019-03-14, rev 0x0715, size 17408
    sig 0x000306f2, pf_mask 0x6f, 2019-03-01, rev 0x0043, size 34816
    sig 0x000306f4, pf_mask 0x80, 2019-03-01, rev 0x0014, size 18432
    sig 0x00040651, pf_mask 0x72, 2019-02-26, rev 0x0025, size 21504
    sig 0x00040661, pf_mask 0x32, 2019-02-26, rev 0x001b, size 25600
    sig 0x00040671, pf_mask 0x22, 2019-03-07, rev 0x0020, size 14336
    sig 0x000406e3, pf_mask 0xc0, 2019-04-01, rev 0x00cc, size 100352
    sig 0x000406f1, pf_mask 0xef, 2019-03-02, rev 0xb000036, size 30720
    sig 0x00050654, pf_mask 0xb7, 2019-04-02, rev 0x200005e, size 32768
    sig 0x00050662, pf_mask 0x10, 2019-03-23, rev 0x001a, size 32768
    sig 0x00050663, pf_mask 0x10, 2019-03-23, rev 0x7000017, size 24576
    sig 0x00050664, pf_mask 0x10, 2019-03-23, rev 0xf000015, size 23552
    sig 0x00050665, pf_mask 0x10, 2019-03-23, rev 0xe00000d, size 19456
    sig 0x000506c9, pf_mask 0x03, 2019-01-15, rev 0x0038, size 17408
    sig 0x000506ca, pf_mask 0x03, 2019-03-01, rev 0x0016, size 15360
    sig 0x000506e3, pf_mask 0x36, 2019-04-01, rev 0x00cc, size 100352
    sig 0x000506f1, pf_mask 0x01, 2019-03-21, rev 0x002e, size 11264
    sig 0x000706a1, pf_mask 0x01, 2019-01-02, rev 0x002e, size 73728
    sig 0x000806e9, pf_mask 0x10, 2019-04-01, rev 0x00b4, size 98304
    sig 0x000806e9, pf_mask 0xc0, 2019-04-01, rev 0x00b4, size 99328
    sig 0x000806ea, pf_mask 0xc0, 2019-04-01, rev 0x00b4, size 99328
    sig 0x000806eb, pf_mask 0xd0, 2019-03-30, rev 0x00b8, size 98304
    sig 0x000806ec, pf_mask 0x94, 2019-03-30, rev 0x00b8, size 97280
    sig 0x000906e9, pf_mask 0x2a, 2019-04-01, rev 0x00b4, size 99328
    sig 0x000906ea, pf_mask 0x22, 2019-04-01, rev 0x00b4, size 98304
    sig 0x000906eb, pf_mask 0x02, 2019-04-01, rev 0x00b4, size 99328
    sig 0x000906ec, pf_mask 0x22, 2019-02-14, rev 0x00ae, size 98304
    sig 0x000906ed, pf_mask 0x22, 2019-03-17, rev 0x00b8, size 97280
samba-DC Aug 5, 2019, 08:56 PMAug 5, 2019, 08:56 PM
Version: 4.6.16-alt1.M80C.1
Summary: Samba Active Directory Domain Controller
Changelog:
- Update to latest samba-4.6 security release
- Security fixes:
  + CVE-2018-10858 Insufficient input validation on client directory
    listing in libsmbclient
  + CVE-2018-10919 Confidential attribute disclosure from the AD LDAP server
samba Aug 5, 2019, 08:22 PMAug 5, 2019, 08:22 PM
Version: 4.6.16-alt1.M80C.1
Summary: The Samba4 CIFS and AD client and server suite
Changelog:
- Update to latest samba-4.6 security release
- Security fixes:
  + CVE-2018-10858 Insufficient input validation on client directory
    listing in libsmbclient
  + CVE-2018-10919 Confidential attribute disclosure from the AD LDAP server
libxmlsec1 May 21, 2019, 12:09 PMMay 21, 2019, 12:09 PM
Version: 1.2.26-alt1.M80C.1
Summary: Library providing support for "XML Signature" and "XML Encryption" standards
Changelog:
- for c8, soap reenabled
(Fixes: CVE-2017-1000061)
dhcpcd May 14, 2019, 08:09 PMMay 14, 2019, 08:09 PM
Version: 6.11.7-alt1
Summary: DHCP Client
Changelog:
- Fix crash on lease renewals (closes: #36730).
- Updated to 6.11.7 (fixes: CVE-2019-11766).
SPICE Apr 23, 2019, 07:24 AMApr 23, 2019, 07:24 AM
Version: 0.14.1-alt1
Summary: Implements the SPICE protocol
Changelog:
- 0.14.1 (Fixes: CVE-2018-10873)
nettle Jan 11, 2019, 02:32 PMJan 11, 2019, 02:32 PM
Version: 3.4.1-alt1
Summary: A low-level cryptographic library
Changelog:
- Updated to 3.4.1 (fixes: CVE-2018-16869).
systemd Jan 10, 2019, 05:13 PMJan 10, 2019, 05:13 PM
Version: 233-alt0.M80C.3
Summary: System and Session Manager
Changelog:
- journald: set a limit on the number of fields once more.
- Backported patches from upstream (fixes: CVE-2018-16864, CVE-2018-16865,
  CVE-2018-16866).
NetworkManager Nov 9, 2018, 06:29 PMNov 9, 2018, 06:29 PM
Version: 1.4.7-alt1.git3712c5180676
Summary: Install NetworkManager daemon and plugins
Changelog:
- Upstream git snapshot (nm-1-4 branch) (fixes: CVE-2018-15688).
libssh Oct 25, 2018, 02:55 PMOct 25, 2018, 02:55 PM
Version: 0.7.6-alt2
Summary: C library to authenticate in a simple manner to one or more SSH servers
Changelog:
- fix changelog
- security fixes: CVE-2018-10933
mariadb Sep 13, 2018, 08:20 PMSep 13, 2018, 08:20 PM
Version: 10.1.35-alt0.N.M80C.1
Summary: A very fast and reliable SQL database engine
Changelog:
- 10.1.35
- Fixes for the following security vulnerabilities:
  + CVE-2018-3064
  + CVE-2018-3063
  + CVE-2018-3058
  + CVE-2018-3066
- change mode of plugin dir in chroot (ALT #33259)
openssh Aug 24, 2018, 06:51 PMAug 24, 2018, 06:51 PM
Version: 7.2p2-alt2.M80C.3
Summary: OpenSSH free Secure Shell (SSH) implementation
Changelog:
- Correction for fix for CVE-2018-15473
ruby May 18, 2018, 02:47 PMMay 18, 2018, 02:47 PM
Version: 2.4.4-alt0.M80C.1
Summary: An Interpreted Object-Oriented Scripting Language
Changelog:
- New version.
- Fixes:
  + CVE-2017-17742: HTTP response splitting in WEBrick
  + CVE-2018-6914: Unintentional file and directory creation with directory traversal in tempfile and tmpdir
  + CVE-2018-8777: DoS by large request in WEBrick
  + CVE-2018-8778: Buffer under-read in String#unpack
  + CVE-2018-8779: Unintentional socket creation by poisoned NUL byte in UNIXServer and UNIXSocket
  + CVE-2018-8780: Unintentional directory traversal by poisoned NUL byte in Dir
curl Mar 31, 2018, 09:35 AMMar 31, 2018, 09:35 AM
Version: 7.59.0-alt1.N.M80C.1
Summary: Gets a file from a FTP, GOPHER or HTTP server
Changelog:
- new version 
- fixes: 
  * CVE-2018-1000120 FTP path trickery leads to NIL byte out of bounds write
  * CVE-2018-1000121 LDAP NULL pointer dereference
  * CVE-2018-1000122  RTSP RTP buffer over-read
Back to Top