diff options
author | V3n3RiX <venerix@redcorelinux.org> | 2018-06-30 08:49:38 +0100 |
---|---|---|
committer | V3n3RiX <venerix@redcorelinux.org> | 2018-06-30 08:49:38 +0100 |
commit | b2be182d49eea46686b5cf2680d457df61e89dc4 (patch) | |
tree | c66442ced2011c5ca81c3114cc51041e314c6d33 /metadata/glsa | |
parent | e23cdda4dbb0c83b9e682ab5e916085a35203da5 (diff) |
gentoo resync : 30.06.2018
Diffstat (limited to 'metadata/glsa')
-rw-r--r-- | metadata/glsa/Manifest | 30 | ||||
-rw-r--r-- | metadata/glsa/Manifest.files.gz | bin | 426460 -> 426775 bytes | |||
-rw-r--r-- | metadata/glsa/glsa-201806-08.xml | 50 | ||||
-rw-r--r-- | metadata/glsa/glsa-201806-09.xml | 48 | ||||
-rw-r--r-- | metadata/glsa/timestamp.chk | 2 | ||||
-rw-r--r-- | metadata/glsa/timestamp.commit | 2 |
6 files changed, 115 insertions, 17 deletions
diff --git a/metadata/glsa/Manifest b/metadata/glsa/Manifest index c3553df7de4c..a5551cd238a8 100644 --- a/metadata/glsa/Manifest +++ b/metadata/glsa/Manifest @@ -1,23 +1,23 @@ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 -MANIFEST Manifest.files.gz 426460 BLAKE2B 47694bd3ef3c615341d613415950b0242b5038a27c4ebe5cfbcbd26dbd4cdf9a80251ec31f482f1575b622e4c7b6577fa42adb2ec5074a46b45ff15ddfdfe1b1 SHA512 685738a5c048270cbefc11e9bf44bb952395b8423bf32612d4c7c6519b5b09941e4920caa34fcbd798a247315ab3dfb6d919b8a36b224acdcaaa2909bff6f2d0 -TIMESTAMP 2018-06-23T05:08:35Z +MANIFEST Manifest.files.gz 426775 BLAKE2B 0a924e893bc7d02fb872d05ff4b63ad4d237b75711b0c6a09d632bbc7eeb1a14506448cef5b376ba25b504b6e4c16d40d6662762ee100207b8ee92abf972340d SHA512 811f8949726f5f714f93c3522b7ae6b1eb5aad37a0229ee9d5f5ee0ddb8c5273a4f3b0d4055d44a1dbeed5fc458aeb2e5620e47889961d9b7a4e961c24e5877b +TIMESTAMP 2018-06-30T07:08:25Z -----BEGIN PGP SIGNATURE----- -iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAlst1dNfFIAAAAAALgAo +iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAls3LGlfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEUx RDZBQkI2M0JGQ0ZCNEJBMDJGREYxQ0VDNTkwRUVBQzkxODkyNTAACgkQ7FkO6skY -klDpRBAAl1JkdnDs6d7s9940Xtc9YxlM3sTHuAu64OewaOspcxboylRccoE2vV9c -HAEo2bglwianSToQRa9ajiU+5YojQCAOhC7v1+pQ7W7uq+XvODd96wwm520bw/GT -bxEnF7an5o856GcBZyqoGZZRvxR2/jWRZgDUGGtIUq2ny9xNfjJO61ETw0vl46QA -aVKzwXDkiKrUgV8TSW4Kobj0NJEqEUKFeHv1nnchhBYOGjHvxUhW6INy6UZ9pnPJ -msdYrj5cjRtKdr/b4GxpDNt0ie3fTcAEanVfcfKNhxAsodYCjTENTcoouq2o3s2Y -bvIpPDzw1epNzPh9VWS8fkSbTyR7P+0Xdvis4ND9XU2K/uuvbEjuNCkgiWSRIJMA -RsbIgItieA6vj1aw/0w+jlTm358ST06IqRGGwHhRLtTAkNoX1V4UNH9yMUJREq4D -m8B7UxYhUlAKOj2iow2OY/ATouyc4D1n/FjzuLlafQRleWAx3QdU72qznbbjQC6H -hAPd3FFF1mRdALo3rnKy9tNH1FGiWhH8XzBayaPuyUrcG6pFUYfrrn1bRJzJh920 -W70n6iF+OHxtPAFoT8xgzSlriBii7APum9SwtLbXyCfPwvD2dnRiv9EupHfR6LU6 -jtW1QKfqW6KU82Z4Gn7pg/AojdECS7fAijdnvsBPt8nGiLiCiqQ= -=nzqZ +klCubBAAgAIlJDlNndR3hT9QajPepEt6d4MGSsvdVdWa2DNZQWXypOX0WysVeN0r +yuP6oZGAbMzolh0hUdzNeR6Wz8wTGKjeAYR1E2MfcowkRPEQKM9Oe4IpvbTK3DPh +hNxYC7Jp6vWuZCIb5O0K3bU9JhWjob3h1mxWY8V6lFaz214AwZ5ZFGInDlqdsgAy +yGVmBltIDl1KgNnppKyzi8SKpwoWcsWdPbu2zsrBYNnBnmEWxZ7uNz0SpyiR25M8 +2+omqnu4sI61zFFsg8g5j0BB8HfVl10Rs7EqpDi1COu0v185XoTKGN4t6TUefvHV +CgqeNTXajEbQPOoKaTSFag0+RyqqzPjeECF0OVDtwK9BeuSwf45hEKVgeZ5yT+nw +kNMQ9yrL5yiuXzT28jpEyvrvwzuAFAY+5BDWlFhvLtpmUdRI5Xn+aWGYRzXAREda +Nk0WZ+6MOUvxsEogb2CDIE1dSQH7jgcLTF1e0RAlkD9xPSh8LtndXPVCLrLZNHjx +vujgumcMkWBXsniqRb1GyrKjXc0+qSGrST/zoyDejbO7L9b1ADpGKVAU2zGZVAOU ++3LHH2nSmVjvO+0E1puz2ibYKzuYtiMys2NsUolq/iaoib/otRKmruBGk3Jy+JDI +F7sz8rSnu8iqV2ylO838PBQ3IUb5aQVUohFhZUej5MdOCDRQSvg= +=ahb4 -----END PGP SIGNATURE----- diff --git a/metadata/glsa/Manifest.files.gz b/metadata/glsa/Manifest.files.gz Binary files differindex b789ac8f5af8..f740db1e7b5d 100644 --- a/metadata/glsa/Manifest.files.gz +++ b/metadata/glsa/Manifest.files.gz diff --git a/metadata/glsa/glsa-201806-08.xml b/metadata/glsa/glsa-201806-08.xml new file mode 100644 index 000000000000..9d4493b3898f --- /dev/null +++ b/metadata/glsa/glsa-201806-08.xml @@ -0,0 +1,50 @@ +<?xml version="1.0" encoding="UTF-8"?> +<!DOCTYPE glsa SYSTEM "http://www.gentoo.org/dtd/glsa.dtd"> +<glsa id="201806-08"> + <title>file: Denial of service</title> + <synopsis>A vulnerability in file could lead to a Denial of Service + condition. + </synopsis> + <product type="ebuild">file</product> + <announced>2018-06-23</announced> + <revised count="1">2018-06-23</revised> + <bug>657930</bug> + <access>remote</access> + <affected> + <package name="sys-apps/file" auto="yes" arch="*"> + <unaffected range="ge">5.33-r2</unaffected> + <vulnerable range="lt">5.33-r2</vulnerable> + </package> + </affected> + <background> + <p>file is a utility that guesses a file format by scanning binary data for + patterns. + </p> + </background> + <description> + <p>File does not properly utilize the do_core_note function in readelf.c in + libmagic.a. + </p> + </description> + <impact type="normal"> + <p>A remote attacker could send a specially crafted ELF file possibly + resulting in a Denial of Service condition. + </p> + </impact> + <workaround> + <p>There is no known workaround at this time.</p> + </workaround> + <resolution> + <p>All file users should upgrade to the latest version:</p> + + <code> + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-apps/file-5.33-r2" + </code> + </resolution> + <references> + <uri link="https://nvd.nist.gov/vuln/detail/CVE-2018-10360">CVE-2018-10360</uri> + </references> + <metadata tag="requester" timestamp="2018-06-23T00:28:49Z">b-man</metadata> + <metadata tag="submitter" timestamp="2018-06-23T21:38:00Z">Zlogene</metadata> +</glsa> diff --git a/metadata/glsa/glsa-201806-09.xml b/metadata/glsa/glsa-201806-09.xml new file mode 100644 index 000000000000..3cd03fbde533 --- /dev/null +++ b/metadata/glsa/glsa-201806-09.xml @@ -0,0 +1,48 @@ +<?xml version="1.0" encoding="UTF-8"?> +<!DOCTYPE glsa SYSTEM "http://www.gentoo.org/dtd/glsa.dtd"> +<glsa id="201806-09"> + <title>PNP4Nagios: Root privilege escalation</title> + <synopsis>A vulnerability in PNP4Nagios which may allow local attackers to + gain root privileges. + </synopsis> + <product type="ebuild">pnp4nagios</product> + <announced>2018-06-24</announced> + <revised count="1">2018-06-24</revised> + <bug>637640</bug> + <access>local</access> + <affected> + <package name="net-analyzer/pnp4nagios" auto="yes" arch="*"> + <unaffected range="ge">0.6.26-r9</unaffected> + <vulnerable range="lt">0.6.26-r9</vulnerable> + </package> + </affected> + <background> + <p>PNP4Nagios is an addon for the Nagios Network Monitoring System.</p> + </background> + <description> + <p>It was found that PHP4Nagios creates files owned by an unprivileged user + that are used by root. + </p> + </description> + <impact type="normal"> + <p>A local attacker could escalate privileges to root.</p> + </impact> + <workaround> + <p>There is no known workaround at this time.</p> + </workaround> + <resolution> + <p>All PNP4Nagios users should upgrade to the latest version:</p> + + <code> + # emerge --sync + # emerge --ask --oneshot --verbose + ">=net-analyzer/pnp4nagios-0.6.26-r9" + </code> + + </resolution> + <references> + <uri link="https://nvd.nist.gov/vuln/detail/CVE-2017-16834">CVE-2017-16834</uri> + </references> + <metadata tag="requester" timestamp="2018-06-19T23:53:20Z">b-man</metadata> + <metadata tag="submitter" timestamp="2018-06-24T03:10:22Z">irishluck83</metadata> +</glsa> diff --git a/metadata/glsa/timestamp.chk b/metadata/glsa/timestamp.chk index c30cc2b38f99..390466fb48fe 100644 --- a/metadata/glsa/timestamp.chk +++ b/metadata/glsa/timestamp.chk @@ -1 +1 @@ -Sat, 23 Jun 2018 05:08:31 +0000 +Sat, 30 Jun 2018 07:08:22 +0000 diff --git a/metadata/glsa/timestamp.commit b/metadata/glsa/timestamp.commit index 48672ed37550..371b226d6874 100644 --- a/metadata/glsa/timestamp.commit +++ b/metadata/glsa/timestamp.commit @@ -1 +1 @@ -5b6712dd5c527643b1249a76e15d0921eda06151 1529454280 2018-06-20T00:24:40+00:00 +676a0a13a2c9c89e7a04d5a85550b5b48c25f9b4 1529809898 2018-06-24T03:11:38+00:00 |