summaryrefslogtreecommitdiff
path: root/metadata/glsa
diff options
context:
space:
mode:
authorV3n3RiX <venerix@redcorelinux.org>2018-06-30 08:49:38 +0100
committerV3n3RiX <venerix@redcorelinux.org>2018-06-30 08:49:38 +0100
commitb2be182d49eea46686b5cf2680d457df61e89dc4 (patch)
treec66442ced2011c5ca81c3114cc51041e314c6d33 /metadata/glsa
parente23cdda4dbb0c83b9e682ab5e916085a35203da5 (diff)
gentoo resync : 30.06.2018
Diffstat (limited to 'metadata/glsa')
-rw-r--r--metadata/glsa/Manifest30
-rw-r--r--metadata/glsa/Manifest.files.gzbin426460 -> 426775 bytes
-rw-r--r--metadata/glsa/glsa-201806-08.xml50
-rw-r--r--metadata/glsa/glsa-201806-09.xml48
-rw-r--r--metadata/glsa/timestamp.chk2
-rw-r--r--metadata/glsa/timestamp.commit2
6 files changed, 115 insertions, 17 deletions
diff --git a/metadata/glsa/Manifest b/metadata/glsa/Manifest
index c3553df7de4c..a5551cd238a8 100644
--- a/metadata/glsa/Manifest
+++ b/metadata/glsa/Manifest
@@ -1,23 +1,23 @@
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
-MANIFEST Manifest.files.gz 426460 BLAKE2B 47694bd3ef3c615341d613415950b0242b5038a27c4ebe5cfbcbd26dbd4cdf9a80251ec31f482f1575b622e4c7b6577fa42adb2ec5074a46b45ff15ddfdfe1b1 SHA512 685738a5c048270cbefc11e9bf44bb952395b8423bf32612d4c7c6519b5b09941e4920caa34fcbd798a247315ab3dfb6d919b8a36b224acdcaaa2909bff6f2d0
-TIMESTAMP 2018-06-23T05:08:35Z
+MANIFEST Manifest.files.gz 426775 BLAKE2B 0a924e893bc7d02fb872d05ff4b63ad4d237b75711b0c6a09d632bbc7eeb1a14506448cef5b376ba25b504b6e4c16d40d6662762ee100207b8ee92abf972340d SHA512 811f8949726f5f714f93c3522b7ae6b1eb5aad37a0229ee9d5f5ee0ddb8c5273a4f3b0d4055d44a1dbeed5fc458aeb2e5620e47889961d9b7a4e961c24e5877b
+TIMESTAMP 2018-06-30T07:08:25Z
-----BEGIN PGP SIGNATURE-----
-iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAlst1dNfFIAAAAAALgAo
+iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAls3LGlfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEUx
RDZBQkI2M0JGQ0ZCNEJBMDJGREYxQ0VDNTkwRUVBQzkxODkyNTAACgkQ7FkO6skY
-klDpRBAAl1JkdnDs6d7s9940Xtc9YxlM3sTHuAu64OewaOspcxboylRccoE2vV9c
-HAEo2bglwianSToQRa9ajiU+5YojQCAOhC7v1+pQ7W7uq+XvODd96wwm520bw/GT
-bxEnF7an5o856GcBZyqoGZZRvxR2/jWRZgDUGGtIUq2ny9xNfjJO61ETw0vl46QA
-aVKzwXDkiKrUgV8TSW4Kobj0NJEqEUKFeHv1nnchhBYOGjHvxUhW6INy6UZ9pnPJ
-msdYrj5cjRtKdr/b4GxpDNt0ie3fTcAEanVfcfKNhxAsodYCjTENTcoouq2o3s2Y
-bvIpPDzw1epNzPh9VWS8fkSbTyR7P+0Xdvis4ND9XU2K/uuvbEjuNCkgiWSRIJMA
-RsbIgItieA6vj1aw/0w+jlTm358ST06IqRGGwHhRLtTAkNoX1V4UNH9yMUJREq4D
-m8B7UxYhUlAKOj2iow2OY/ATouyc4D1n/FjzuLlafQRleWAx3QdU72qznbbjQC6H
-hAPd3FFF1mRdALo3rnKy9tNH1FGiWhH8XzBayaPuyUrcG6pFUYfrrn1bRJzJh920
-W70n6iF+OHxtPAFoT8xgzSlriBii7APum9SwtLbXyCfPwvD2dnRiv9EupHfR6LU6
-jtW1QKfqW6KU82Z4Gn7pg/AojdECS7fAijdnvsBPt8nGiLiCiqQ=
-=nzqZ
+klCubBAAgAIlJDlNndR3hT9QajPepEt6d4MGSsvdVdWa2DNZQWXypOX0WysVeN0r
+yuP6oZGAbMzolh0hUdzNeR6Wz8wTGKjeAYR1E2MfcowkRPEQKM9Oe4IpvbTK3DPh
+hNxYC7Jp6vWuZCIb5O0K3bU9JhWjob3h1mxWY8V6lFaz214AwZ5ZFGInDlqdsgAy
+yGVmBltIDl1KgNnppKyzi8SKpwoWcsWdPbu2zsrBYNnBnmEWxZ7uNz0SpyiR25M8
+2+omqnu4sI61zFFsg8g5j0BB8HfVl10Rs7EqpDi1COu0v185XoTKGN4t6TUefvHV
+CgqeNTXajEbQPOoKaTSFag0+RyqqzPjeECF0OVDtwK9BeuSwf45hEKVgeZ5yT+nw
+kNMQ9yrL5yiuXzT28jpEyvrvwzuAFAY+5BDWlFhvLtpmUdRI5Xn+aWGYRzXAREda
+Nk0WZ+6MOUvxsEogb2CDIE1dSQH7jgcLTF1e0RAlkD9xPSh8LtndXPVCLrLZNHjx
+vujgumcMkWBXsniqRb1GyrKjXc0+qSGrST/zoyDejbO7L9b1ADpGKVAU2zGZVAOU
++3LHH2nSmVjvO+0E1puz2ibYKzuYtiMys2NsUolq/iaoib/otRKmruBGk3Jy+JDI
+F7sz8rSnu8iqV2ylO838PBQ3IUb5aQVUohFhZUej5MdOCDRQSvg=
+=ahb4
-----END PGP SIGNATURE-----
diff --git a/metadata/glsa/Manifest.files.gz b/metadata/glsa/Manifest.files.gz
index b789ac8f5af8..f740db1e7b5d 100644
--- a/metadata/glsa/Manifest.files.gz
+++ b/metadata/glsa/Manifest.files.gz
Binary files differ
diff --git a/metadata/glsa/glsa-201806-08.xml b/metadata/glsa/glsa-201806-08.xml
new file mode 100644
index 000000000000..9d4493b3898f
--- /dev/null
+++ b/metadata/glsa/glsa-201806-08.xml
@@ -0,0 +1,50 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<!DOCTYPE glsa SYSTEM "http://www.gentoo.org/dtd/glsa.dtd">
+<glsa id="201806-08">
+ <title>file: Denial of service</title>
+ <synopsis>A vulnerability in file could lead to a Denial of Service
+ condition.
+ </synopsis>
+ <product type="ebuild">file</product>
+ <announced>2018-06-23</announced>
+ <revised count="1">2018-06-23</revised>
+ <bug>657930</bug>
+ <access>remote</access>
+ <affected>
+ <package name="sys-apps/file" auto="yes" arch="*">
+ <unaffected range="ge">5.33-r2</unaffected>
+ <vulnerable range="lt">5.33-r2</vulnerable>
+ </package>
+ </affected>
+ <background>
+ <p>file is a utility that guesses a file format by scanning binary data for
+ patterns.
+ </p>
+ </background>
+ <description>
+ <p>File does not properly utilize the do_core_note function in readelf.c in
+ libmagic.a.
+ </p>
+ </description>
+ <impact type="normal">
+ <p>A remote attacker could send a specially crafted ELF file possibly
+ resulting in a Denial of Service condition.
+ </p>
+ </impact>
+ <workaround>
+ <p>There is no known workaround at this time.</p>
+ </workaround>
+ <resolution>
+ <p>All file users should upgrade to the latest version:</p>
+
+ <code>
+ # emerge --sync
+ # emerge --ask --oneshot --verbose "&gt;=sys-apps/file-5.33-r2"
+ </code>
+ </resolution>
+ <references>
+ <uri link="https://nvd.nist.gov/vuln/detail/CVE-2018-10360">CVE-2018-10360</uri>
+ </references>
+ <metadata tag="requester" timestamp="2018-06-23T00:28:49Z">b-man</metadata>
+ <metadata tag="submitter" timestamp="2018-06-23T21:38:00Z">Zlogene</metadata>
+</glsa>
diff --git a/metadata/glsa/glsa-201806-09.xml b/metadata/glsa/glsa-201806-09.xml
new file mode 100644
index 000000000000..3cd03fbde533
--- /dev/null
+++ b/metadata/glsa/glsa-201806-09.xml
@@ -0,0 +1,48 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<!DOCTYPE glsa SYSTEM "http://www.gentoo.org/dtd/glsa.dtd">
+<glsa id="201806-09">
+ <title>PNP4Nagios: Root privilege escalation</title>
+ <synopsis>A vulnerability in PNP4Nagios which may allow local attackers to
+ gain root privileges.
+ </synopsis>
+ <product type="ebuild">pnp4nagios</product>
+ <announced>2018-06-24</announced>
+ <revised count="1">2018-06-24</revised>
+ <bug>637640</bug>
+ <access>local</access>
+ <affected>
+ <package name="net-analyzer/pnp4nagios" auto="yes" arch="*">
+ <unaffected range="ge">0.6.26-r9</unaffected>
+ <vulnerable range="lt">0.6.26-r9</vulnerable>
+ </package>
+ </affected>
+ <background>
+ <p>PNP4Nagios is an addon for the Nagios Network Monitoring System.</p>
+ </background>
+ <description>
+ <p>It was found that PHP4Nagios creates files owned by an unprivileged user
+ that are used by root.
+ </p>
+ </description>
+ <impact type="normal">
+ <p>A local attacker could escalate privileges to root.</p>
+ </impact>
+ <workaround>
+ <p>There is no known workaround at this time.</p>
+ </workaround>
+ <resolution>
+ <p>All PNP4Nagios users should upgrade to the latest version:</p>
+
+ <code>
+ # emerge --sync
+ # emerge --ask --oneshot --verbose
+ "&gt;=net-analyzer/pnp4nagios-0.6.26-r9"
+ </code>
+
+ </resolution>
+ <references>
+ <uri link="https://nvd.nist.gov/vuln/detail/CVE-2017-16834">CVE-2017-16834</uri>
+ </references>
+ <metadata tag="requester" timestamp="2018-06-19T23:53:20Z">b-man</metadata>
+ <metadata tag="submitter" timestamp="2018-06-24T03:10:22Z">irishluck83</metadata>
+</glsa>
diff --git a/metadata/glsa/timestamp.chk b/metadata/glsa/timestamp.chk
index c30cc2b38f99..390466fb48fe 100644
--- a/metadata/glsa/timestamp.chk
+++ b/metadata/glsa/timestamp.chk
@@ -1 +1 @@
-Sat, 23 Jun 2018 05:08:31 +0000
+Sat, 30 Jun 2018 07:08:22 +0000
diff --git a/metadata/glsa/timestamp.commit b/metadata/glsa/timestamp.commit
index 48672ed37550..371b226d6874 100644
--- a/metadata/glsa/timestamp.commit
+++ b/metadata/glsa/timestamp.commit
@@ -1 +1 @@
-5b6712dd5c527643b1249a76e15d0921eda06151 1529454280 2018-06-20T00:24:40+00:00
+676a0a13a2c9c89e7a04d5a85550b5b48c25f9b4 1529809898 2018-06-24T03:11:38+00:00