From b2be182d49eea46686b5cf2680d457df61e89dc4 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Sat, 30 Jun 2018 08:49:38 +0100 Subject: gentoo resync : 30.06.2018 --- metadata/glsa/Manifest | 30 +++++++++++------------ metadata/glsa/Manifest.files.gz | Bin 426460 -> 426775 bytes metadata/glsa/glsa-201806-08.xml | 50 +++++++++++++++++++++++++++++++++++++++ metadata/glsa/glsa-201806-09.xml | 48 +++++++++++++++++++++++++++++++++++++ metadata/glsa/timestamp.chk | 2 +- metadata/glsa/timestamp.commit | 2 +- 6 files changed, 115 insertions(+), 17 deletions(-) create mode 100644 metadata/glsa/glsa-201806-08.xml create mode 100644 metadata/glsa/glsa-201806-09.xml (limited to 'metadata/glsa') diff --git a/metadata/glsa/Manifest b/metadata/glsa/Manifest index c3553df7de4c..a5551cd238a8 100644 --- a/metadata/glsa/Manifest +++ b/metadata/glsa/Manifest @@ -1,23 +1,23 @@ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 -MANIFEST Manifest.files.gz 426460 BLAKE2B 47694bd3ef3c615341d613415950b0242b5038a27c4ebe5cfbcbd26dbd4cdf9a80251ec31f482f1575b622e4c7b6577fa42adb2ec5074a46b45ff15ddfdfe1b1 SHA512 685738a5c048270cbefc11e9bf44bb952395b8423bf32612d4c7c6519b5b09941e4920caa34fcbd798a247315ab3dfb6d919b8a36b224acdcaaa2909bff6f2d0 -TIMESTAMP 2018-06-23T05:08:35Z +MANIFEST Manifest.files.gz 426775 BLAKE2B 0a924e893bc7d02fb872d05ff4b63ad4d237b75711b0c6a09d632bbc7eeb1a14506448cef5b376ba25b504b6e4c16d40d6662762ee100207b8ee92abf972340d SHA512 811f8949726f5f714f93c3522b7ae6b1eb5aad37a0229ee9d5f5ee0ddb8c5273a4f3b0d4055d44a1dbeed5fc458aeb2e5620e47889961d9b7a4e961c24e5877b +TIMESTAMP 2018-06-30T07:08:25Z -----BEGIN PGP SIGNATURE----- -iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAlst1dNfFIAAAAAALgAo +iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAls3LGlfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEUx RDZBQkI2M0JGQ0ZCNEJBMDJGREYxQ0VDNTkwRUVBQzkxODkyNTAACgkQ7FkO6skY -klDpRBAAl1JkdnDs6d7s9940Xtc9YxlM3sTHuAu64OewaOspcxboylRccoE2vV9c -HAEo2bglwianSToQRa9ajiU+5YojQCAOhC7v1+pQ7W7uq+XvODd96wwm520bw/GT -bxEnF7an5o856GcBZyqoGZZRvxR2/jWRZgDUGGtIUq2ny9xNfjJO61ETw0vl46QA -aVKzwXDkiKrUgV8TSW4Kobj0NJEqEUKFeHv1nnchhBYOGjHvxUhW6INy6UZ9pnPJ -msdYrj5cjRtKdr/b4GxpDNt0ie3fTcAEanVfcfKNhxAsodYCjTENTcoouq2o3s2Y -bvIpPDzw1epNzPh9VWS8fkSbTyR7P+0Xdvis4ND9XU2K/uuvbEjuNCkgiWSRIJMA -RsbIgItieA6vj1aw/0w+jlTm358ST06IqRGGwHhRLtTAkNoX1V4UNH9yMUJREq4D -m8B7UxYhUlAKOj2iow2OY/ATouyc4D1n/FjzuLlafQRleWAx3QdU72qznbbjQC6H -hAPd3FFF1mRdALo3rnKy9tNH1FGiWhH8XzBayaPuyUrcG6pFUYfrrn1bRJzJh920 -W70n6iF+OHxtPAFoT8xgzSlriBii7APum9SwtLbXyCfPwvD2dnRiv9EupHfR6LU6 -jtW1QKfqW6KU82Z4Gn7pg/AojdECS7fAijdnvsBPt8nGiLiCiqQ= -=nzqZ +klCubBAAgAIlJDlNndR3hT9QajPepEt6d4MGSsvdVdWa2DNZQWXypOX0WysVeN0r +yuP6oZGAbMzolh0hUdzNeR6Wz8wTGKjeAYR1E2MfcowkRPEQKM9Oe4IpvbTK3DPh +hNxYC7Jp6vWuZCIb5O0K3bU9JhWjob3h1mxWY8V6lFaz214AwZ5ZFGInDlqdsgAy +yGVmBltIDl1KgNnppKyzi8SKpwoWcsWdPbu2zsrBYNnBnmEWxZ7uNz0SpyiR25M8 +2+omqnu4sI61zFFsg8g5j0BB8HfVl10Rs7EqpDi1COu0v185XoTKGN4t6TUefvHV +CgqeNTXajEbQPOoKaTSFag0+RyqqzPjeECF0OVDtwK9BeuSwf45hEKVgeZ5yT+nw +kNMQ9yrL5yiuXzT28jpEyvrvwzuAFAY+5BDWlFhvLtpmUdRI5Xn+aWGYRzXAREda +Nk0WZ+6MOUvxsEogb2CDIE1dSQH7jgcLTF1e0RAlkD9xPSh8LtndXPVCLrLZNHjx +vujgumcMkWBXsniqRb1GyrKjXc0+qSGrST/zoyDejbO7L9b1ADpGKVAU2zGZVAOU ++3LHH2nSmVjvO+0E1puz2ibYKzuYtiMys2NsUolq/iaoib/otRKmruBGk3Jy+JDI +F7sz8rSnu8iqV2ylO838PBQ3IUb5aQVUohFhZUej5MdOCDRQSvg= +=ahb4 -----END PGP SIGNATURE----- diff --git a/metadata/glsa/Manifest.files.gz b/metadata/glsa/Manifest.files.gz index b789ac8f5af8..f740db1e7b5d 100644 Binary files a/metadata/glsa/Manifest.files.gz and b/metadata/glsa/Manifest.files.gz differ diff --git a/metadata/glsa/glsa-201806-08.xml b/metadata/glsa/glsa-201806-08.xml new file mode 100644 index 000000000000..9d4493b3898f --- /dev/null +++ b/metadata/glsa/glsa-201806-08.xml @@ -0,0 +1,50 @@ + + + + file: Denial of service + A vulnerability in file could lead to a Denial of Service + condition. + + file + 2018-06-23 + 2018-06-23 + 657930 + remote + + + 5.33-r2 + 5.33-r2 + + + +

file is a utility that guesses a file format by scanning binary data for + patterns. +

+
+ +

File does not properly utilize the do_core_note function in readelf.c in + libmagic.a. +

+
+ +

A remote attacker could send a specially crafted ELF file possibly + resulting in a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All file users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-apps/file-5.33-r2" + +
+ + CVE-2018-10360 + + b-man + Zlogene +
diff --git a/metadata/glsa/glsa-201806-09.xml b/metadata/glsa/glsa-201806-09.xml new file mode 100644 index 000000000000..3cd03fbde533 --- /dev/null +++ b/metadata/glsa/glsa-201806-09.xml @@ -0,0 +1,48 @@ + + + + PNP4Nagios: Root privilege escalation + A vulnerability in PNP4Nagios which may allow local attackers to + gain root privileges. + + pnp4nagios + 2018-06-24 + 2018-06-24 + 637640 + local + + + 0.6.26-r9 + 0.6.26-r9 + + + +

PNP4Nagios is an addon for the Nagios Network Monitoring System.

+
+ +

It was found that PHP4Nagios creates files owned by an unprivileged user + that are used by root. +

+
+ +

A local attacker could escalate privileges to root.

+
+ +

There is no known workaround at this time.

+
+ +

All PNP4Nagios users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose + ">=net-analyzer/pnp4nagios-0.6.26-r9" + + +
+ + CVE-2017-16834 + + b-man + irishluck83 +
diff --git a/metadata/glsa/timestamp.chk b/metadata/glsa/timestamp.chk index c30cc2b38f99..390466fb48fe 100644 --- a/metadata/glsa/timestamp.chk +++ b/metadata/glsa/timestamp.chk @@ -1 +1 @@ -Sat, 23 Jun 2018 05:08:31 +0000 +Sat, 30 Jun 2018 07:08:22 +0000 diff --git a/metadata/glsa/timestamp.commit b/metadata/glsa/timestamp.commit index 48672ed37550..371b226d6874 100644 --- a/metadata/glsa/timestamp.commit +++ b/metadata/glsa/timestamp.commit @@ -1 +1 @@ -5b6712dd5c527643b1249a76e15d0921eda06151 1529454280 2018-06-20T00:24:40+00:00 +676a0a13a2c9c89e7a04d5a85550b5b48c25f9b4 1529809898 2018-06-24T03:11:38+00:00 -- cgit v1.2.3