From f1af93971b7490792d8541bc790e0d8c6d787059 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Fri, 6 Sep 2019 10:28:05 +0100 Subject: gentoo resync : 06.08.2019 --- metadata/glsa/Manifest | 30 +++++++++++----------- metadata/glsa/Manifest.files.gz | Bin 446941 -> 447571 bytes metadata/glsa/glsa-201908-03.xml | 5 ++-- metadata/glsa/glsa-201908-26.xml | 54 +++++++++++++++++++++++++++++++++++++++ metadata/glsa/glsa-201908-27.xml | 46 +++++++++++++++++++++++++++++++++ metadata/glsa/glsa-201908-28.xml | 47 ++++++++++++++++++++++++++++++++++ metadata/glsa/glsa-201908-29.xml | 52 +++++++++++++++++++++++++++++++++++++ metadata/glsa/timestamp.chk | 2 +- metadata/glsa/timestamp.commit | 2 +- 9 files changed, 218 insertions(+), 20 deletions(-) create mode 100644 metadata/glsa/glsa-201908-26.xml create mode 100644 metadata/glsa/glsa-201908-27.xml create mode 100644 metadata/glsa/glsa-201908-28.xml create mode 100644 metadata/glsa/glsa-201908-29.xml (limited to 'metadata/glsa') diff --git a/metadata/glsa/Manifest b/metadata/glsa/Manifest index 43909281f0ca..14342aa9db71 100644 --- a/metadata/glsa/Manifest +++ b/metadata/glsa/Manifest @@ -1,23 +1,23 @@ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 -MANIFEST Manifest.files.gz 446941 BLAKE2B 27348febfa1e8b0c37a6262b9e1c30afa2668e0702870fc19e3e8e049c8aa3fce3a0a847ecfdfa1843e08f25b1c541365b360bee2789c88b7c7abd1d0af7a0a4 SHA512 b604df11b0bda8c02e03d8c0f183f427ec63dd525e2cbd5b7473a5dbfd7112d964e04f46efec437421b06496482ba2148b26225bcbd4b736cd57023d4aeb1ea7 -TIMESTAMP 2019-08-18T16:09:02Z +MANIFEST Manifest.files.gz 447571 BLAKE2B 5dcbf22acab4aa936027b65cb350fd1f2f1c1e2537d9521e947b1cbe33f4d7b2b6fbb6bb4805bdf0c5ff45c77fcb33345e4c8d8b89729f3fa2275febb0067a24 SHA512 85251d26f1a84f633b1f394aeaeb284222b79a86f4ce32b3e4e3dbc431b1a27e54bd1e6b1023f766bdacf2a7c3226992247aab3e13dd008f70ff63b9b31dcd87 +TIMESTAMP 2019-09-06T08:39:04Z -----BEGIN PGP SIGNATURE----- -iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAl1ZeB5fFIAAAAAALgAo +iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAl1yGyhfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEUx RDZBQkI2M0JGQ0ZCNEJBMDJGREYxQ0VDNTkwRUVBQzkxODkyNTAACgkQ7FkO6skY -klAlMw//Y9l50sTL8BwL9tH0qPOFngKNjcjMJzJGgU69fY+GrSyTWN0U1GMQzpcR -KqaTOuUJiSAxYhm8AZueZ73wGp21lm4qFUvKGHjWvTLT7YtlMqenG6kX/HeKoaM/ -5U1KHEAHVFgXOyQOD/h9ETZNnvB/oJhjXUgf46nYUnZi5UXrj73b8Z0G6jfNERO6 -9VQ3+VkOFYp6oOKplqDfyxrDCqwTzQRXap2dpmdozxVbydpr6BfquEbYy+0NijYC -FNsEWNCwEo8GeWSdYFS8Q/eB3Vp6oCVAwBtW6+GZwsMEpt7/yGQe1Y9Zat1VGze2 -MsCQ06nnL/G/lnRpe1LtfzEugKh1RPzv78ZruY6dqkqo/wfrIkMksM2l9IU8zsE1 -XQgI/cFLfZoMNe7DhYvWPhe9Jj8jgIjiXY5F2RuiVt+B3K8DcJoBB0LeyrTSs9w+ -1q3eOiunW4Z6wTfeYpXmnIrW/ZDM0xw0SU/fgAKmf/u1QRy9ctNVGwB02u/Oif/o -xbX5yfRQxEA7qK3RN6tPU1r+9QYbbyIUBePFXbbMCEv41QUpj9shNh3g5kC1LQPQ -VG7l+/ewS57u6wUBRAEFosLVcU5zKZydHkmqJTY4mCpGbDcJQ/q16Es/kNBprEsM -GkSyKT4EJrp8XUnqfXBVVADUP2aGqiJTQ8GPsBn5CUkb33fO2gY= -=z3VN +klCTtxAAhLPXP6XvR+/h9wHgS6IrEhLTQ3N5A5s8veo5JxxSv6qrosvcmz5D1Enx +1TjSiBhfKZMacSjIbDbwn0LZ5r5e7RcZnY8wPpieL7xcYhgRF935Py4CTsjkEZXR +EjCQWPbsSsPgTSya/RkMowmHib4ruGJtqKc12MJFB4XXGizIfGxT5sE278hJ4kKn +oysYDsJgdq4Md9KRwr04f59oncNx3cvtfDCNfYDl9G1m57GZC/A/uuCdyx6wRk8B +jdKDwxE7Yz3rJAHDnbiN629i3HaaN1Csu1IVgXKbUToCaKwRwno5W4uJE9tnNZjk +RIFsdPrV/C62PdZXyxB8koPk5pVx/fmwn8hdh3Q23pITZXnUKQdEHg5gqV447KGk +WlNi40qMmw5npaUmKWUGNCyNj4211BGPzbjn4xOKGQwZOAZZkE3eyNBWiS6kNALL +2LkBmHjPe8It97gXBBfdyMElxMUhK1GljNFF7K8X10kT4Tnqy04q2heRN7e2pcaH +y8H9iQlzFvi0fJt2yZZfKmc/ktlHwXiQJeFzk9ym+PiM2dmr35roCfR26aKF7yio +LMCmGWvAW7WDxpAKDzfSmS05oavvtT9nI7H1MjZHSoHHescL6vVQU2drelNIyCuQ +QVoSn7xRqg3yPU6F2lwhGCNKq95XcprgmmRseY8RnxHOEdddRXA= +=x/mL -----END PGP SIGNATURE----- diff --git a/metadata/glsa/Manifest.files.gz b/metadata/glsa/Manifest.files.gz index 8dde4ddcf57d..8045ca98ae1e 100644 Binary files a/metadata/glsa/Manifest.files.gz and b/metadata/glsa/Manifest.files.gz differ diff --git a/metadata/glsa/glsa-201908-03.xml b/metadata/glsa/glsa-201908-03.xml index 2b768c68c862..4a5520a3d11c 100644 --- a/metadata/glsa/glsa-201908-03.xml +++ b/metadata/glsa/glsa-201908-03.xml @@ -7,7 +7,7 @@ jasper 2019-08-09 - 2019-08-09 + 2019-08-28 614028 614032 624988 @@ -63,7 +63,6 @@ CVE-2017-13753 CVE-2017-14132 CVE-2017-14229 - CVE-2017-14232 CVE-2017-5503 CVE-2017-5504 CVE-2017-5505 @@ -76,5 +75,5 @@ CVE-2018-9154 b-man - b-man + b-man diff --git a/metadata/glsa/glsa-201908-26.xml b/metadata/glsa/glsa-201908-26.xml new file mode 100644 index 000000000000..9a757dd8348d --- /dev/null +++ b/metadata/glsa/glsa-201908-26.xml @@ -0,0 +1,54 @@ + + + + libofx: Multiple vulnerabilities + Multiple vulnerabilities have been found in libofx, the worst of + which could result in the arbitrary execution of code. + + libofx + 2019-08-31 + 2019-08-31 + 631304 + 636062 + 662910 + remote + + + 0.9.14 + 0.9.14 + + + +

A library to support the Open Financial eXchange XML format

+
+ +

Multiple vulnerabilities have been discovered in libofx. Please review + the CVE identifiers referenced below for details. +

+
+ +

A remote attacker could entice a user to process a specially crafted + file using an application linked against libofx, possibly resulting in + execution of arbitrary code with the privileges of the process or a + Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All libofx users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-libs/libofx-0.9.14" + +
+ + CVE-2017-14731 + CVE-2017-2816 + CVE-2017-2920 + + b-man + b-man +
diff --git a/metadata/glsa/glsa-201908-27.xml b/metadata/glsa/glsa-201908-27.xml new file mode 100644 index 000000000000..6f7af7bbed67 --- /dev/null +++ b/metadata/glsa/glsa-201908-27.xml @@ -0,0 +1,46 @@ + + + + Nautilus: Security bypass + A vulnerability in Nautilus may allow attackers to escape the + sandbox. + + nautilus + 2019-08-31 + 2019-08-31 + 692784 + local + + + 3.30.5-r1 + 3.30.5-r1 + + + +

Default file manager for the GNOME desktop

+
+ +

A vulnerability was discovered in Nautilus which allows an attacker to + escape the sandbox. +

+
+ +

A local attacker could possibly bypass sandbox protection.

+
+ +

There is no known workaround at this time.

+
+ +

All Nautilus users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=gnome-base/nautilus-3.30.5-r1" + +
+ + CVE-2019-11461 + + b-man + b-man +
diff --git a/metadata/glsa/glsa-201908-28.xml b/metadata/glsa/glsa-201908-28.xml new file mode 100644 index 000000000000..19818590fbcb --- /dev/null +++ b/metadata/glsa/glsa-201908-28.xml @@ -0,0 +1,47 @@ + + + + GNOME desktop library: Security bypass + A vulnerability in the GNOME desktop library may allow attackers to + escape the sandbox. + + gnome-desktop + 2019-08-31 + 2019-08-31 + 692782 + local + + + 3.30.2.3 + 3.30.2.3 + + + +

Library with common API for various GNOME modules.

+
+ +

A vulnerability was discovered in the GNOME desktop library which allows + an attacker to escape the sandbox. +

+
+ +

A local attacker could possibly bypass sandbox protection.

+
+ +

There is no known workaround at this time.

+
+ +

All GNOME desktop library users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose + ">=gnome-base/gnome-desktop-3.30.2.3" + +
+ + CVE-2019-11460 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-201908-29.xml b/metadata/glsa/glsa-201908-29.xml new file mode 100644 index 000000000000..4b86c592f6fa --- /dev/null +++ b/metadata/glsa/glsa-201908-29.xml @@ -0,0 +1,52 @@ + + + + Dovecot: Multiple vulnerabilities + Multiple vulnerabilities have been found in Dovecot, the worst of + which could result in the arbitrary execution of code. + + dovecot + 2019-08-31 + 2019-08-31 + 683732 + 692572 + local, remote + + + 2.3.7.2 + 2.3.7.2 + + + +

Dovecot is an open source IMAP and POP3 email server.

+
+ +

Multiple vulnerabilities have been discovered in Dovecot. Please review + the CVE identifiers referenced below for details. +

+
+ +

An unauthenticated remote attacker could send a specially crafted mail + or use crafted IMAP commands possibly resulting in the execution of + arbitrary code with the privileges of the process or a Denial of Service + condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All Dovecot users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-mail/dovecot-2.3.7.2" + +
+ + CVE-2019-10691 + CVE-2019-11500 + + whissi + whissi +
diff --git a/metadata/glsa/timestamp.chk b/metadata/glsa/timestamp.chk index 7a755efccb78..2f6a7762bf94 100644 --- a/metadata/glsa/timestamp.chk +++ b/metadata/glsa/timestamp.chk @@ -1 +1 @@ -Sun, 18 Aug 2019 16:08:59 +0000 +Fri, 06 Sep 2019 08:39:01 +0000 diff --git a/metadata/glsa/timestamp.commit b/metadata/glsa/timestamp.commit index a0dca6b11934..ac1358016db9 100644 --- a/metadata/glsa/timestamp.commit +++ b/metadata/glsa/timestamp.commit @@ -1 +1 @@ -55b0fff2f98b275d6a6bcaf8e12164157936324c 1566095478 2019-08-18T02:31:18+00:00 +b3e8c925d3f6eb29b568169ff67ed18a2ff264c2 1567285941 2019-08-31T21:12:21+00:00 -- cgit v1.2.3