-
-
Notifications
You must be signed in to change notification settings - Fork 14.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerability Roundup 8 #20274
Comments
Chromium was patched in master with this merge: c67a7ee (note: don't cherry-pick merges!) and is waiting a successful build before going to 16.09. |
Libtiff: d9db320 plus many other commits around this issue. |
We're good against the current jasper issues reported here, but there are two more releases since our last update: https://github.com/mdadams/jasper/releases |
Ported sudo patches:
|
Solves vulnerabilities mentioned in #20274
#633086 dbus: denial of service dbus 1.10.12 is not vulnerable |
All the java stuff is covered by what we have |
#705915 ansible: two vulnerabilities We already have ansible 2.2.x. |
#705566 libreswan: denial of service CVE-2016-5361 was misissued because this is a protocol flaw. See http://www.openwall.com/lists/oss-security/2016/06/13/1. |
#705671 libwebp: integer overflows Vulnerable code (examples/giflib.c) is not present in our version of libwebp. https://chromium-review.googlesource.com/#/c/396007/ |
#705568 libvirt: privilege escalation Debian considers CVE-2015-5160 a minor issue: https://security-tracker.debian.org/tracker/CVE-2015-5160 There were already patches on the qemu ML in 2011: https://www.redhat.com/archives/libvir-list/2011-November/msg00853.html. Not sure if it has been fixed in current versions, but there is no clear fix available. |
#705672 oracle-jre-bin: unspecified vulnerability We have Oracle JRE/JDK > 8u102. |
We are good for the two kernel issues, our kernels are up-to-date |
#667153 libraw: two vulnerabilities Fix is in our version of libraw (0.17.1): LibRaw/LibRaw@89d0654 |
#705560 389-ds-base: two vulnerabilities CVE-2016-5405: No fix available? |
I don't think qemu has anything available, it would have to be manual patching |
#705373 python-django: two vulnerabilities We have the fixes already: https://www.djangoproject.com/weblog/2016/nov/01/security-releases/ |
#705580 openjpeg2: code execution Fix is in openjpeg 2.1.2, which we already have. |
Thank you all! Here is a bit of an update on my position: I moved very recently, and have been spending most of my spare time dealing with that. Due to that, I haven't been able to help in the same capacity. That should be coming back to normal within the next couple weeks. Thank you all for stepping up and getting these done :) |
Commenting here for potential involvement in a future roundup :) |
Solves vulnerabilities mentioned in NixOS#20274 (cherry picked from commit 20d16f8)
cc NixOS#20274 (cherry picked from commit 3190a6c)
cc NixOS#20274 (cherry picked from commit 14a3d2d)
Here are all the vulnerabilities from https://lwn.net/Vulnerabilities since
our last hunt.
cc @rycee @fpletz @NeQuissimus @vcunat @shlevy @FRidh who were involved in the last one.
Notes on the list
isn't perfect, but is intended to help identify if a whole group
of reports is resolved already.
For example, there are sometimes problems that impact thunderbird,
and firefox. LWN might report in one vulnerability "thunderbird
firefox". These names have been split to make sure both packages get
addressed.
a Github search by filename. These are to help, but may not return
results when we do in fact package the software. If a search
doesn't turn up, please try altering the search criteria or
looking in nixpkgs manually before asserting we don't have it.
Instructions:
vulnerable, tick the box or add a comment with the report number,
stating it isn't vulnerable.
either leave a comment on this issue saying so, even open a pull
request with the fix. If you open a PR, make sure to tag this
issue so we can coordinate.
"Triaged and Resolved Issues"
details
block below.Upon Completion ...
summary.
Without further ado...
Assorted (31 issues)
#705578
(search, files) qemu: multiple vulnerabilities#705370
(search, files) mailman: cross-site request forgery#667153
(search, files) libraw: two vulnerabilities#705372
(search, files) oxide-qt: information disclosure#705560
(search, files) 389-ds-base: two vulnerabilities#705579
(search, files) spip: multiple vulnerabilities#705581
(search, files) nvidia-graphics-drivers-367: privilege escalation#705580
(search, files) openjpeg2: code execution#705822
(search, files) tomcat: multiple vulnerabilities#705373
(search, files) python-django: two vulnerabilities#705568
(search, files) libvirt: privilege escalation#705361
(search, files) java: unspecified vulnerability#705574
(search, files) subscription-manager: information disclosure#705915
(search, files) ansible: two vulnerabilities#705566
(search, files) libreswan: denial of service#639784
(search, files) powerpc-utils-python: code execution#705917
(search, files) java-1.8.0-openjdk-aarch32: multiple vulnerabilities#705572
(search, files) resteasy-base: code execution#705672
(search, files) oracle-jre-bin: unspecified vulnerability#705671
(search, files) libwebp: integer overflows#705363
(search, files) libwmf: denial of service#705913
(search, files) python-imaging: two vulnerabilities#705575
(search, files) sudo: information disclosure#705366
(search, files) libtiff: denial of service#705362
(search, files) bind: denial of service#703767
(search, files) chromium-browser: multiple vulnerabilities#705823
(search, files) chromium: memory leak#705216
(search, files) tar: file overwrite#625494
(search, files) rpm: code execution#705815
(search, files) libxslt: code execution#633086
(search, files) dbus: denial of servicecurl (2 issues)
#705367
(search, files) curl: multiple vulnerabilities#705577
(search, files) curl: insufficient validationjasper (2 issues)
#705824
(search, files) jasper: multiple vulnerabilities#705673
(search, files) jasper: multiple vulnerabilitieskernel (2 issues)
#705918
(search, files) kernel: two vulnerabilities#705565
(search, files) kernel: three vulnerabilitiespacemaker (2 issues)
#705571
(search, files) pacemaker: privilege escalation#705570
(search, files) pacemaker: denial of servicetiff (2 issues)
#705364
(search, files) tiff: multiple vulnerabilities#635993
(search, files) tiff: multiple vulnerabilitiesThe text was updated successfully, but these errors were encountered: