From 22910f5d14da606bd7f06e19a2f61c5d1a8fc94b Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Fri, 25 May 2018 15:22:17 +0100 Subject: gentoo resync : 25.05.2018 --- metadata/glsa/Manifest | 30 ++++++++--------- metadata/glsa/Manifest.files.gz | Bin 423926 -> 424400 bytes metadata/glsa/glsa-201805-07.xml | 57 +++++++++++++++++++++++++++++++ metadata/glsa/glsa-201805-08.xml | 70 +++++++++++++++++++++++++++++++++++++++ metadata/glsa/glsa-201805-09.xml | 48 +++++++++++++++++++++++++++ metadata/glsa/timestamp.chk | 2 +- metadata/glsa/timestamp.commit | 2 +- 7 files changed, 192 insertions(+), 17 deletions(-) create mode 100644 metadata/glsa/glsa-201805-07.xml create mode 100644 metadata/glsa/glsa-201805-08.xml create mode 100644 metadata/glsa/glsa-201805-09.xml (limited to 'metadata/glsa') diff --git a/metadata/glsa/Manifest b/metadata/glsa/Manifest index 42d14a5e8db9..2c9803a78d0b 100644 --- a/metadata/glsa/Manifest +++ b/metadata/glsa/Manifest @@ -1,23 +1,23 @@ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 -MANIFEST Manifest.files.gz 423926 BLAKE2B ef432334c8c41dcc3beb779f71caadf29384449b3e8258f043d5ba442df8bec61eb0e37f0cffe178b49845e496a10322c4f299da85b1bef970a8198b7030cc19 SHA512 0362ff52a0a0f49a21f40c02923be72cf39507aeca71c57ba328332b55d1e4bad4c29b86943b37860f673358dafc794b408fa2b01f8a8d43fb4c3f1ae168a8c9 -TIMESTAMP 2018-05-22T12:08:39Z +MANIFEST Manifest.files.gz 424400 BLAKE2B 9a73c11ed4c1391d31d1574a9de4d159bae31fe3f5714411d8384fe4e643e59a86fea9f31f62f9bf6ec36e61f4753cce7561cd7aac8bc004d5ad304a9cbd5fd0 SHA512 0fabe1e7393fe3aa88503bbf861fd29966bc3149d4306beec0ac9dd8c1ca947a5da2e44f96f0574aa884a1a3191f2c44649c75b64b46bf96048e6516ea5dcb4b +TIMESTAMP 2018-05-25T13:38:48Z -----BEGIN PGP SIGNATURE----- -iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAlsECEdfFIAAAAAALgAo +iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAlsIEehfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEUx RDZBQkI2M0JGQ0ZCNEJBMDJGREYxQ0VDNTkwRUVBQzkxODkyNTAACgkQ7FkO6skY -klC6ERAAsISjzASzQtwX2Qxz+kHc7ZJ9x4risbP+f53v/qt9Z9yYcM/CBJaj9A6D -Oj+/dnDVx1TqNbBS7OVXWuL02E7NyqQGV/6vjQ5YzcWJB2+2/5wt6tBWbiuf71eF -IAvro3ZNr2XVeuqXMGfUE5M5AzGpib4jT5ZapDZv89rdOM0LA1ASnLM6TQjFWZ9w -t4j5jwz9B0fd7bnxcYTHZf/gapp2Zfs+BO3C27NbYUhR9k2nsEdxpZN4+m3grQcD -Zh5VCPidbXgJNnvrvWu1jNIMx1sDHjla3ClgacB2I7DuUUpuX1Qn3jcVISbgM7+n -t7Aqx+78TutydnwcqHHbrvyldUQK3FV82rYN0twwvIdrDZy7aMSkGhtvP00gLpST -MupXPuaZZ4W8PNZjs14vPkYFsRXiW9xtERA4uE6/HvDeTaQwh9y7wZZyWQ8VS2Xb -guw2A7be3S6KOh1jmrzGzt+v1QEpMhDmk2NSJujUfjf1nXJ9rshLOzTgLhuataiu -7LF26gAX5W6nOuCoalapM/LBdg6HyJIkihv+mMZtOrCREdqJq8plF4J46HiHVyIg -ncj445vdqsowxaVLPy6CZ94xW3SfQmHzCboDqN2xA27FkTTEifsKWn3IsFTqKtNh -Ftvcdk0NmBCxgzHe2m4R06CVLW2hcDhAyYarg5FOXsMPUDGzVdk= -=fYcE +klA9QQ/+PMvah9YFz+dqGel6WnojoODRBfcaJmNPluFlguaoesOhyGh6Vga3Wdqn +fbC4YK9EOWEIxK5b/LLYWxhIfMemK3/bkEzzewDhQlZS5eVq+4UWSa8fp7kwcYRR +jIBur8P08cqf8KXZGV/nc6qcGk0S2S1Ewp9pDqOJMdSJXpTQDalTOHti3G6hBSqC +i3NaLyc0rBu7tMM21mV8YvMrLJ2hR+tUqOtSsYLY4wN6p9RpqMQ53y76uRmlRpOO +egTVzbVSVNXJJu36wfdivEORsLQYf17bIpcYuJo2zHHxblGF2q7BgKy6g92C4OJU +ZsMCUG2mF9ZckZB0CChh9cKgV9m1KNeiHEqcuL86ghJa4DK4P1hySSJABJrmJFi/ +pwtuUgEVKWPC2lc4ComTyIXufmYhU9XmKsX0TS2Pza3ecCcvoVhvPCTTYEIObQvu +3HE2EaO821yXgV+mvhy7TQkl/yfL4MkY24gJUn8aY8AVAqReTq6uShDAY5SIh06b +47l68W8ODXs03cQkLUjYDwNCFz58Bg2o9JyI6slSg5y+nv2FFgXnCG2lcU1Z/HdE +s016fmLwmyZneC1i43/RuZULeD7cXoelBiDd2S/uafPztc/t7+e+WdRaawg9C5Y0 +YYSadRlI+UyxPJomg1+ncZGuOwpnI4WNhdUVUr8ErxBgSA7yIEM= +=cpLK -----END PGP SIGNATURE----- diff --git a/metadata/glsa/Manifest.files.gz b/metadata/glsa/Manifest.files.gz index 8d89a3629bf8..07e00db62d75 100644 Binary files a/metadata/glsa/Manifest.files.gz and b/metadata/glsa/Manifest.files.gz differ diff --git a/metadata/glsa/glsa-201805-07.xml b/metadata/glsa/glsa-201805-07.xml new file mode 100644 index 000000000000..f57a6fb9d6d1 --- /dev/null +++ b/metadata/glsa/glsa-201805-07.xml @@ -0,0 +1,57 @@ + + + + Samba: Multiple vulnerabilities + Multiple vulnerabilities have been found in Samba, the worst of + which may allow remote execution of arbitrary code. + + samba + 2018-05-22 + 2018-05-22 + 588262 + 619516 + 639024 + 650382 + remote + + + 4.5.16 + 4.5.16 + + + +

Samba is a suite of SMB and CIFS client/server programs.

+
+ +

Multiple vulnerabilities have been discovered in Samba. Please review + the CVE identifiers referenced below for details. +

+
+ +

A remote attacker could possibly execute arbitrary code, cause a Denial + of Service condition, conduct a man-in-the-middle attack, or obtain + sensitive information. +

+
+ +

There is no known workaround at this time.

+
+ +

All Samba users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-fs/samba-4.5.16" + +
+ + CVE-2016-2119 + CVE-2017-14746 + CVE-2017-15275 + CVE-2017-7494 + CVE-2018-1050 + CVE-2018-1057 + + b-man + b-man +
diff --git a/metadata/glsa/glsa-201805-08.xml b/metadata/glsa/glsa-201805-08.xml new file mode 100644 index 000000000000..5b8b52935500 --- /dev/null +++ b/metadata/glsa/glsa-201805-08.xml @@ -0,0 +1,70 @@ + + + + VirtualBox: Multiple vulnerabilities + Multiple vulnerabilities have been found in VirtualBox, the worst + of which could allow an attacker to take control of VirtualBox. + + virtualbox + 2018-05-22 + 2018-05-22 + 655186 + remote + + + 5.1.36 + 5.1.36 + + + 5.1.36.122089 + 5.1.36.122089 + + + +

VirtualBox is a powerful virtualization product from Oracle.

+
+ +

Multiple vulnerabilities have been discovered in VirtualBox. Please + review the CVE identifiers referenced below for details. +

+
+ +

An attacker could take control of VirtualBox resulting in the execution + of arbitrary code with the privileges of the process, a Denial of Service + condition, or other unspecified impacts. +

+
+ +

There is no known workaround at this time.

+
+ +

All VirtualBox users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-emulation/virtualbox-5.1.36" + + +

All VirtualBox binary users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose + ">=app-emulation/virtualbox-bin-5.1.36.122089" + +
+ + CVE-2018-2830 + CVE-2018-2831 + CVE-2018-2835 + CVE-2018-2836 + CVE-2018-2837 + CVE-2018-2842 + CVE-2018-2843 + CVE-2018-2844 + CVE-2018-2845 + CVE-2018-2860 + + b-man + b-man +
diff --git a/metadata/glsa/glsa-201805-09.xml b/metadata/glsa/glsa-201805-09.xml new file mode 100644 index 000000000000..f4af27e4d2fc --- /dev/null +++ b/metadata/glsa/glsa-201805-09.xml @@ -0,0 +1,48 @@ + + + + Shadow: security bypass + A vulnerability found in Shadow may allow local attackers to bypass + security restrictions. + + shadow + 2018-05-22 + 2018-05-22 + 647790 + remote + + + 4.6 + 4.6 + + + +

Shadow is a set of tools to deal with user accounts.

+
+ +

A local attacker could possibly bypass security restrictions if an + administrator used “group blacklisting” to restrict access to file + system paths. +

+
+ +

A local attacker could possibly bypass security restrictions.

+
+ +

There is no known workaround at this time.

+
+ +

All shadow users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-apps/shadow-4.6" + + +
+ + CVE-2018-7169 + + Zlogene + Zlogene +
diff --git a/metadata/glsa/timestamp.chk b/metadata/glsa/timestamp.chk index 9c2593d3e940..82049acb5f24 100644 --- a/metadata/glsa/timestamp.chk +++ b/metadata/glsa/timestamp.chk @@ -1 +1 @@ -Tue, 22 May 2018 12:08:36 +0000 +Fri, 25 May 2018 13:38:44 +0000 diff --git a/metadata/glsa/timestamp.commit b/metadata/glsa/timestamp.commit index d21b59c7a136..fcae362f2608 100644 --- a/metadata/glsa/timestamp.commit +++ b/metadata/glsa/timestamp.commit @@ -1 +1 @@ -255e6e014a866f68f8eba7d65248d45008988f31 1526827283 2018-05-20T14:41:23+00:00 +000a4ecebe264f405efd60fbeab45f98ae1183f7 1527028655 2018-05-22T22:37:35+00:00 -- cgit v1.2.3