Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system. Vulnerabilities affect nearly every vendor virtually every week, so be sure to read through to find the updates your distributor have made available.


LinuxSecurity.com Feature Extras:

Essential tools for hardening and securing Unix based Environments - System administrators are aware as how important their systems security is, not just the runtime of their servers. Intruders, spammers, DDOS attack, crackers, are all out there trying to get into people

Securing a Linux Web Server - With the significant prevalence of Linux web servers globally, security is often touted as a strength of the platform for such a purpose. However, a Linux based web server is only as secure as its configuration and very often many are quite vulnerable to compromise. While specific configurations vary wildly due to environments or specific use, there are various general steps that can be taken to insure basic security considerations are in place.


  Debian: DSA-4053-1: exim4 security update (Nov 30)
 

Several vulnerabilities have been discovered in Exim, a mail transport agent. The Common Vulnerabilities and Exposures project identifies the following issues:

  Debian: DSA-4052-1: bzr security update (Nov 29)
 

Adam Collard discovered that Bazaar, an easy to use distributed version control system, did not correctly handle maliciously constructed bzr+ssh URLs, allowing a remote attackers to run an arbitrary shell command.

  Debian: DSA-4051-1: curl security update (Nov 29)
 

Two vulnerabilities were discovered in cURL, an URL transfer library. CVE-2017-8816

  Debian: DSA-4050-1: xen security update (Nov 28)
 

Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, information leaks, privilege escalation or the execution of arbitrary code.

  Debian: DSA-4049-1: ffmpeg security update (Nov 27)
 

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.

  Debian: DSA-4048-1: openjdk-7 security update (Nov 23)
 

Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in impersonation of Kerberos services, denial of service, sandbox bypass or HTTP header injection.

  Debian: DSA-4047-1: otrs2 security update (Nov 23)
 

Two vulnerabilities were discovered in the Open Ticket Request System which could result in disclosure of database credentials or the execution of arbitrary shell commands by logged-in agents.

 
  Fedora 27: kernel Security Update (Dec 1)
 

The 4.13.16 update contains various fixes across the tree.

  Fedora 26: nodejs-brace-expansion Security Update (Dec 1)
 

Update to upstream 1.1.7 release to remediate DoS issue npm:brace- expansion:20170302

  Fedora 26: nodejs-balanced-match Security Update (Dec 1)
 

Update to upstream 1.1.7 release to remediate DoS issue npm:brace- expansion:20170302

  Fedora 26: moodle Security Update (Dec 1)
 

Fix for CVE-2017-15110.

  Fedora 26: python-werkzeug Security Update (Dec 1)
 

Update to 0.12.2 which also fixes CVE-2016-10516

  Fedora 26: kernel Security Update (Dec 1)
 

The 4.13.16 update contains various fixes across the tree.

  Fedora 27: moodle Security Update (Nov 30)
 

Fix for CVE-2017-15110.

  Fedora 27: python-werkzeug Security Update (Nov 30)
 

Update to 0.12.2 which also fixes CVE-2016-10516

  Fedora 27: mediawiki Security Update (Nov 30)
 

https://lists.wikimedia.org/hyperkitty/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/EIECM2E7PQ2VN3O4DSZBCE6K7HDW7AJC/

  Fedora 27: slurm Security Update (Nov 29)
 

Harden the Slurm build and allows it to operate in full relro with GOT sections of the ELF binaries marked read-only.

  Fedora 27: mupdf Security Update (Nov 29)
 

CVE-2017-15369 CVE-2017-15587 CVE-2017-9216 CVE-2017-14685 CVE-2017-14686 CVE-2017-14687

  Fedora 27: lucene4 Security Update (Nov 29)
 

Security fix for CVE-2017-12629

  Fedora 27: quagga Security Update (Nov 28)
 

rebase to version 1.2.2, solves CVE-2017-16227, solves error produced by install script

  Fedora 25: lucene4 Security Update (Nov 28)
 

Security fix for CVE-2017-12629

  Fedora 25: cacti Security Update (Nov 28)
 

- Update to 1.1.28 - CVE-2017-16641, CVE-2017-16660, CVE-2017-16661, CVE-2017-16785 Release notes:

  Fedora 25: jbig2dec Security Update (Nov 28)
 

update to 0.14 (bugfix release CVE-2017-9216)

  Fedora 25: webkitgtk4 Security Update (Nov 28)
 

This update addresses the following vulnerabilities: * [CVE-2017-13798](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13798), [CVE-2017-13788](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13788), [CVE-2017-13803](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13803) Additional fixes: * Improve calculation of font metrics to prevent scrollbars

  Fedora 25: rpm Security Update (Nov 28)
 

This latest stable release on rpm 4.13.x branch brings in several important bugfixes. For details see release notes at http://rpm.org/wiki/Releases/4.13.0.2.

  Fedora 25: openssl Security Update (Nov 28)
 

Minor security update 1.0.2m.

  Fedora 26: openssh Security Update (Nov 28)
 

Security fix for CVE-2017-15906: Improper write operations in readonly mode

  Fedora 26: lucene4 Security Update (Nov 28)
 

Security fix for CVE-2017-12629

  Fedora 26: git Security Update (Nov 28)
 

Previous versions of git mishandled layers of tree objects, which allowed remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.

  Fedora 26: xen Security Update (Nov 28)
 

fix an issue in patch for [XSA-240, CVE-2017-15595] that might be a security issue fix for [XSA-243, CVE-2017-15592] could cause hypervisor crash (DOS)

  Fedora 26: openssl Security Update (Nov 28)
 

Minor security update release 1.1.0g.

  Fedora 26: webkitgtk4 Security Update (Nov 28)
 

This update addresses the following vulnerabilities: * [CVE-2017-13798](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13798), [CVE-2017-13788](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13788), [CVE-2017-13803](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13803) Additional fixes: * Improve calculation of font metrics to prevent scrollbars

  Fedora 26: quagga Security Update (Nov 28)
 

rebase to version 1.2.2, solves CVE-2017-16227, solves error produced by install script

  Fedora 26: cacti Security Update (Nov 28)
 

- Update to 1.1.28 - CVE-2017-16641, CVE-2017-16660, CVE-2017-16661, CVE-2017-16785 Release notes:

  Fedora 27: cacti Security Update (Nov 28)
 

- Update to 1.1.28 - CVE-2017-16641, CVE-2017-16660, CVE-2017-16661, CVE-2017-16785 Release notes:

  Fedora 26: samba Security Update (Nov 28)
 

Security fix for CVE-2017-14746 and CVE-2017-15275

  Fedora 27: samba Security Update (Nov 27)
 

Security fix for CVE-2017-14746 and CVE-2017-15275

  Fedora 25: qt5-qtwebengine Security Update (Nov 25)
 

An update of QtWebEngine to the security and bugfix release 5.9.2, including: Chromium Snapshot: * Security fixes from Chromium up to version 61.0.3163.79 Including: CVE-2017-5092, CVE-2017-5093, CVE-2017-5095, CVE-2017-5097, CVE-2017-5099, CVE-2017-5102, CVE-2017-5103, CVE-2017-5107, CVE-2017-5112, CVE-2017-5114, CVE-2017-5117 and CVE-2017-5118 * Fixed Skia to to render text

  Fedora 26: mediawiki Security Update (Nov 25)
 

https://lists.wikimedia.org/hyperkitty/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/EIECM2E7PQ2VN3O4DSZBCE6K7HDW7AJC/

  Fedora 25: fedpkg Security Update (Nov 24)
 

**Update** - Fixed chain-build - Remove hard dependency of bash-completion from fedpkg **rpkg** - Ignore TestModulesCli if openidc-client is unavailable (cqi) - Port mbs-build to rpkg (mprahl) - Add .vscode to .gitignore (mprahl) - Fix TestPatch.test_rediff in order to run with old version of mock (cqi) - Allow to specify alternative Copr config file - #184 (cqi) - Tests for patch command

  Fedora 25: rpkg Security Update (Nov 24)
 

**Update** - Fixed chain-build - Remove hard dependency of bash-completion from fedpkg **rpkg** - Ignore TestModulesCli if openidc-client is unavailable (cqi) - Port mbs-build to rpkg (mprahl) - Add .vscode to .gitignore (mprahl) - Fix TestPatch.test_rediff in order to run with old version of mock (cqi) - Allow to specify alternative Copr config file - #184 (cqi) - Tests for patch command

  Fedora 26: fedpkg Security Update (Nov 23)
 

**Update** - Fixed chain-build - Remove hard dependency of bash-completion from fedpkg **rpkg** - Ignore TestModulesCli if openidc-client is unavailable (cqi) - Port mbs-build to rpkg (mprahl) - Add .vscode to .gitignore (mprahl) - Fix TestPatch.test_rediff in order to run with old version of mock (cqi) - Allow to specify alternative Copr config file - #184 (cqi) - Tests for patch command

  Fedora 26: rpkg Security Update (Nov 23)
 

**Update** - Fixed chain-build - Remove hard dependency of bash-completion from fedpkg **rpkg** - Ignore TestModulesCli if openidc-client is unavailable (cqi) - Port mbs-build to rpkg (mprahl) - Add .vscode to .gitignore (mprahl) - Fix TestPatch.test_rediff in order to run with old version of mock (cqi) - Allow to specify alternative Copr config file - #184 (cqi) - Tests for patch command

 
  RedHat: RHSA-2017-3315:01 Important: kernel security and bug fix update (Nov 30)
 

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2017-3368:01 Moderate: qemu-kvm security update (Nov 30)
 

An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3369:01 Moderate: qemu-kvm-rhev security and bug fix (Nov 30)
 

An update for qemu-kvm-rhev is now available for Red Hat Enterprise Virtualization (RHEV) 4.X, Red Hat Enterprise Virtualization Hypervisor (RHEV-H) and Agents for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

  RedHat: RHSA-2017-3295:01 Moderate: kernel-rt security and bug fix update (Nov 30)
 

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3354:01 Moderate: Red Hat JBoss BRMS 6.4.7 security update (Nov 30)
 

An update is now available for Red Hat JBoss BRMS. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3355:01 Moderate: Red Hat JBoss BPM Suite 6.4.7 security (Nov 30)
 

An update is now available for Red Hat JBoss BPM Suite. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3322:01 Moderate: kernel-rt security, bug fix, (Nov 30)
 

An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3335:01 Low: Red Hat Enterprise Linux 6.2 AMC One-Month (Nov 30)
 

This is the one-month notification for the retirement of Red Hat Enterprise Linux 6.2 Advanced Mission Critical (AMC). This notification applies only to those customers subscribed to the Advanced Mission Critical (AMC) channel for Red Hat Enterprise Linux 6.2.

  RedHat: RHSA-2017-3278:01 Important: samba4 security update (Nov 29)
 

An update for samba4 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2017-3277:01 Moderate: tcmu-runner security update (Nov 29)
 

An update for tcmu-runner is now available for Red Hat Gluster Storage 3.3.1 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2017-3270:01 Important: apr security update (Nov 28)
 

An update for apr is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2017-3269:01 Important: procmail security update (Nov 28)
 

An update for procmail is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2017-3188:01 Moderate: Red Hat OpenShift Container Platform (Nov 28)
 

An update is now available for Red Hat OpenShift Container Platform 3.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3268:01 Critical: java-1.7.1-ibm security update (Nov 28)
 

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2017-3267:01 Critical: java-1.8.0-ibm security update (Nov 28)
 

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2017-3265:01 Important: rh-mysql56-mysql security update (Nov 27)
 

An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2017-3264:01 Critical: java-1.8.0-ibm security update (Nov 27)
 

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2017-3263:01 Moderate: curl security update (Nov 27)
 

An update for curl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3260:01 Important: samba security update (Nov 27)
 

An update for samba is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2017-3261:01 Important: samba security update (Nov 27)
 

An update for samba is now available for Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6 and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

 
  Slackware: 2017-332-01: samba Security Update (Nov 28)
 

New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

 
  SuSE: 2017:3165-1: important: the Linux Kernel (Nov 30)
 

An update that solves 5 vulnerabilities and has 17 fixes is An update that solves 5 vulnerabilities and has 17 fixes is An update that solves 5 vulnerabilities and has 17 fixes is now available. now available.

  SuSE: 2017:3160-1: important: the Linux Kernel (Live Patch 20 for SLE 12) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3159-1: important: the Linux Kernel (Live Patch 5 for SLE 12 SP2) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3158-1: important: the Linux Kernel (Live Patch 21 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3157-1: important: the Linux Kernel (Live Patch 19 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3156-1: important: the Linux Kernel (Live Patch 2 for SLE 12 SP2) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3154-1: important: the Linux Kernel (Live Patch 19 for SLE 12) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3153-1: important: the Linux Kernel (Live Patch 16 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3152-1: important: the Linux Kernel (Live Patch 18 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3151-1: important: the Linux Kernel (Live Patch 18 for SLE 12) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3150-1: important: the Linux Kernel (Live Patch 17 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3148-1: important: the Linux Kernel (Live Patch 20 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3149-1: important: the Linux Kernel (Live Patch 21 for SLE 12) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3147-1: important: the Linux Kernel (Live Patch 11 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3146-1: important: the Linux Kernel (Live Patch 22 for SLE 12) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3145-1: important: the Linux Kernel (Live Patch 15 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  openSUSE: 2017:3144-1: important: kernel-firmware (Nov 30)
 

An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

  openSUSE: 2017:3141-1: important: samba (Nov 30)
 

An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

  SuSE: 2017:3139-1: important: the Linux Kernel (Live Patch 6 for SLE 12 SP2) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3136-1: important: the Linux Kernel (Live Patch 3 for SLE 12 SP2) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3134-1: important: the Linux Kernel (Live Patch 4 for SLE 12 SP2) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3132-1: important: the Linux Kernel (Live Patch 27 for SLE 12) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3131-1: important: the Linux Kernel (Live Patch 12 for SLE 12 SP1) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3130-1: important: the Linux Kernel (Live Patch 9 for SLE 12 SP1) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3128-1: important: the Linux Kernel (Live Patch 12 for SLE 12 SP2) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3129-1: important: the Linux Kernel (Live Patch 7 for SLE 12 SP2) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3127-1: important: the Linux Kernel (Live Patch 14 for SLE 12 SP1) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3126-1: important: the Linux Kernel (Live Patch 10 for SLE 12 SP2) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3125-1: important: the Linux Kernel (Live Patch 25 for SLE 12) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3124-1: important: the Linux Kernel (Live Patch 10 for SLE 12 SP1) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3122-1: important: the Linux Kernel (Live Patch 11 for SLE 12 SP2) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3123-1: important: the Linux Kernel (Live Patch 24 for SLE 12) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3121-1: important: the Linux Kernel (Live Patch 8 for SLE 12 SP2) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3120-1: important: the Linux Kernel (Live Patch 13 for SLE 12 SP2) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3119-1: important: the Linux Kernel (Live Patch 26 for SLE 12) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3118-1: important: the Linux Kernel (Live Patch 13 for SLE 12 SP1) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3117-1: important: the Linux Kernel (Live Patch 17 for SLE 12) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3116-1: important: the Linux Kernel (Live Patch 9 for SLE 12 SP2) (Nov 29)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3115-1: important: xen (Nov 29)
 

An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four fixes is now available. fixes is now available.

  SuSE: 2017:3106-1: important: kernel-firmware (Nov 27)
 

An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

  SuSE: 2017:3104-1: important: samba (Nov 27)
 

An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

  SuSE: 2017:3103-1: important: the Linux Kernel (Live Patch 23 for SLE 12) (Nov 27)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3086-1: important: samba (Nov 24)
 

An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

  SuSE: 2017:3084-1: important: kvm (Nov 24)
 

An update that solves 33 vulnerabilities and has 7 fixes is An update that solves 33 vulnerabilities and has 7 fixes is An update that solves 33 vulnerabilities and has 7 fixes is now available. now available.

  SuSE: 2017:3076-1: important: the Linux Kernel (Live Patch 2 for SLE 12 SP3) (Nov 24)
 

An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now available. fixes is now available.

  SuSE: 2017:3074-1: important: the Linux Kernel (Live Patch 3 for SLE 12 SP3) (Nov 24)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3072-1: important: the Linux Kernel (Live Patch 1 for SLE 12 SP3) (Nov 24)
 

An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now available. fixes is now available.

  openSUSE: 2017:3069-1: important: tomcat (Nov 24)
 

An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two fixes is now available. fixes is now available.

  SuSE: 2017:3059-1: important: tomcat (Nov 23)
 

An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

  openSUSE: 2017:3054-1: important: otrs (Nov 23)
 

An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

  openSUSE: 2017:3051-1: important: cacti, cacti-spine (Nov 23)
 

An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.

 
  Ubuntu 3497-1: OpenJDK 7 vulnerabilities (Nov 29)
 

Several security issues were fixed in OpenJDK 7.

  Ubuntu 3496-3: Python vulnerability (Nov 28)
 

Python could be made to run arbitrary code.

  Ubuntu 3496-2: Python vulnerability (Nov 28)
 

Python could be made to run arbitrary code.

  Ubuntu 3496-1: Python vulnerability (Nov 28)
 

Python could be made to run arbitrary code.

  Ubuntu 3476-2: postgresql-common vulnerabilities (Nov 27)
 

postgresql-common could be made to overwrite files as the administrator.

  Ubuntu 0032-2: Linux kernel vulnerability (Nov 23)
 

Several security issues were fixed in the kernel.

 
  Debian LTS: DLA-1197-1: sox security update (Dec 1)
 

Various security vulnerabilities were discovered in sox, a command line utility to convert audio formats, that may lead to a denial-of-service (application crash / infinite loop) or memory corruptions by processing a malformed input file.

  Debian LTS: DLA-1196-1: optipng security update (Nov 30)
 

optipng, an advanced PNG (Portable Network Graphics) optimizer, has been found vulnerable to a buffer overflow which allows remote attackers to cause a denial-of-service attack or other unspecified impact with a maliciously crafted GIF format file, related to an

  Debian LTS: DLA-1195-1: curl security update (Nov 30)
 

CVE-2017-8817 Fuzzing by the OSS-Fuzz project led to the discovery of a read out of

  Debian LTS: DLA-1194-1: libxml2 security update (Nov 30)
 

CVE-2017-16931 parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the

  Debian LTS: DLA-1193-1: roundcube security update (Nov 28)
 

A file disclosure vulnerability was discovered in roundcube, a skinnable AJAX based webmail solution for IMAP servers.

  Debian LTS: DLA-1191-1: python-werkzeug security update (Nov 24)
 

A security issue that allows XSS on the Werkzeug debugger allows remote attackers to inject arbitrary stuff via a field that contains an exception message.

  Debian LTS: DLA-1189-1: python2.7 security update (Nov 24)
 

A minor security vulnerability has been discovered in Python 2.7, an interactive high-level object-oriented language.

  Debian LTS: DLA-1190-1: python2.6 security update (Nov 24)
 

A minor security vulnerability has been discovered in Python 2.7, an interactive high-level object-oriented language.

  Debian LTS: DLA-1188-1: libxml2 security update (Nov 23)
 

Pranjal Jumde (@pjumde) reported an heap overflow in memory debug code of libxml2. For Debian 7 "Wheezy", these problems have been fixed in version

  Debian LTS: DLA-1187-1: openjdk-7 security update (Nov 23)
 

Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in impersonation of Kerberos services, denial of service, unauthorized access, sandbox bypass or HTTP header injection.

  Debian LTS: DLA-1186-1: xorg-server security update (Nov 23)
 

Several vulnerabilities have been discovered in the X.Org X server. An attacker who's able to connect to an X server could cause a denial of service or potentially the execution of arbitrary code.

 
  ArchLinux: 201711-30: powerdns: access restriction bypass (Nov 28)
 

The package powerdns before version 4.0.5-1 is vulnerable to access restriction bypass.

  ArchLinux: 201711-31: powerdns-recursor: multiple issues (Nov 28)
 

The package powerdns-recursor before version 4.0.7-1 is vulnerable to multiple issues including cross-site scripting, denial of service and insufficient validation.

 
  CentOS: CESA-2017-3269: Important CentOS 7 procmail (Nov 28)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2017:3269

  CentOS: CESA-2017-3270: Important CentOS 7 apr (Nov 28)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2017:3270

  CentOS: CESA-2017-3270: Important CentOS 6 apr (Nov 28)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2017:3270

  CentOS: CESA-2017-3260: Important CentOS 7 samba (Nov 27)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2017:3260

  CentOS: CESA-2017-3263: Moderate CentOS 7 curl (Nov 27)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2017:3263

 
  (Nov 29)
 

An out-of-bounds array dereference was found in apr_time_exp_get(). Anattacker could abuse an unvalidated usage of this function to cause adenial of service or potentially lead to data leak. (CVE-2017-12613)

  (Nov 29)
 

A memory disclosure flaw was found in samba. An attacker could retrieveparts of server memory, which could contain potentially sensitive data, bysending specially-crafted requests to the samba server. (CVE-2017-15275)

  (Nov 29)
 

A heap-based buffer overflow flaw was found in procmail's formailutility. A remote attacker could send a specially crafted email that, whenprocessed by formail, could cause formail to crash or, possibly, executearbitrary code as the user running formail. (CVE-2017-16844)

  (Nov 27)
 

A buffer overrun flaw was found in the IMAP handler of libcurl. Bytricking an unsuspecting user into connecting to a malicious IMAP server,an attacker could exploit this flaw to potentially cause informationdisclosure or crash the application. (CVE-2017-1000257)

  (Nov 27)
 

A memory disclosure flaw was found in samba. An attacker could retrieveparts of server memory, which could contain potentially sensitive data, bysending specially-crafted requests to the samba server. (CVE-2017-15275)