Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system. Vulnerabilities affect nearly every vendor virtually every week, so be sure to read through to find the updates your distributor have made available.

LinuxSecurity.com Feature Extras:

- Social engineering is the practice of learning and obtaining valuable information by exploiting human vulnerabilities. It is an art of deception that is considered to be vital for a penetration tester when there is a lack of information about the target that can be exploited.

- When you’re dealing with a security incident it’s essential you – and the rest of your team – not only have the skills they need to comprehensively deal with an issue, but also have a framework to support them as they approach it. This framework means they can focus purely on what they need to do, following a process that removes any vulnerabilities and threats in a proper way – so everyone who depends upon the software you protect can be confident that it’s secure and functioning properly.


  Debian: DSA-4057-1: erlang security update (Dec 8)
 

It was discovered that the TLS server in Erlang is vulnerable to an adaptive chosen ciphertext attack against RSA keys. For the oldstable distribution (jessie), this problem has been fixed

  Debian: DSA-4056-1: nova security update (Dec 7)
 

George Shuklin from servers.com discovered that Nova, a cloud computing fabric controller, did not correctly enforce its image- or hosts-filters. This allowed an authenticated user to bypass those filters by simply rebuilding an instance.

  Debian: DSA-4055-1: heimdal security update (Dec 7)
 

Michael Eder and Thomas Kittel discovered that Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos, did not correctly handle ASN.1 data. This would allow an unauthenticated remote attacker to cause a denial of service (crash of

  Debian: DSA-4054-1: tor security update (Dec 3)
 

Multiple vulnerabilities have been found in Tor, a connection-based low-latency anonymous communication system. For the oldstable distribution (jessie), these problems have been fixed

  Debian: DSA-4053-1: exim4 security update (Nov 30)
 

Several vulnerabilities have been discovered in Exim, a mail transport agent. The Common Vulnerabilities and Exposures project identifies the following issues:


  Fedora 25: qt5-qtwebengine Security Update (Dec 4)
 

An update of QtWebEngine to the security and bugfix release 5.9.3, including: * Security fixes from Chromium up to version 62.0.3202.89. Including: CVE-2017-5124, CVE-2017-5126, CVE-2017-5127, CVE-2017-5128, CVE-2017-5129, CVE-2017-5132, CVE-2017-5133, CVE-2017-15386, CVE-2017-15387, CVE-2017-15388, CVE-2017-15390, CVE-2017-15392, CVE-2017-15394, CVE-2017-15396, CVE-2017-15398.

  Fedora 25: python Security Update (Dec 4)
 

Security fix for CVE-2017-1000158

  Fedora 26: qt5-qtwebengine Security Update (Dec 4)
 

An update of QtWebEngine to the security and bugfix release 5.9.3, including: * Security fixes from Chromium up to version 62.0.3202.89. Including: CVE-2017-5124, CVE-2017-5126, CVE-2017-5127, CVE-2017-5128, CVE-2017-5129, CVE-2017-5132, CVE-2017-5133, CVE-2017-15386, CVE-2017-15387, CVE-2017-15388, CVE-2017-15390, CVE-2017-15392, CVE-2017-15394, CVE-2017-15396, CVE-2017-15398.

  Fedora 26: kernel Security Update (Dec 4)
 

Contains several backported bugfixes, including the fix for CVE-2017-1000405

  Fedora 26: java-9-openjdk Security Update (Dec 4)
 

added link to cacerts ---- This is experimental build You are on your own!

  Fedora 27: qt5-qtwebengine Security Update (Dec 4)
 

An update of QtWebEngine to the security and bugfix release 5.9.3, including: * Security fixes from Chromium up to version 62.0.3202.89. Including: CVE-2017-5124, CVE-2017-5126, CVE-2017-5127, CVE-2017-5128, CVE-2017-5129, CVE-2017-5132, CVE-2017-5133, CVE-2017-15386, CVE-2017-15387, CVE-2017-15388, CVE-2017-15390, CVE-2017-15392, CVE-2017-15394, CVE-2017-15396, CVE-2017-15398.

  Fedora 27: kernel Security Update (Dec 4)
 

Contains several backported bugfixes, including the fix for CVE-2017-1000405

  Fedora 25: qbittorrent Security Update (Dec 3)
 

Update to the latest releases

  Fedora 25: rb_libtorrent Security Update (Dec 3)
 

Update to the latest releases

  Fedora 26: rb_libtorrent Security Update (Dec 3)
 

Update to latest releases

  Fedora 26: qbittorrent Security Update (Dec 3)
 

Update to latest releases

  Fedora 27: rb_libtorrent Security Update (Dec 3)
 

Update to latest releases

  Fedora 27: qbittorrent Security Update (Dec 3)
 

Update to latest releases

  Fedora 26: mupdf Security Update (Dec 2)
 

CVE-2017-15369 CVE-2017-15587 CVE-2017-9216 CVE-2017-14685 CVE-2017-14686 CVE-2017-14687

  Fedora 26: python-sanic Security Update (Dec 2)
 

Update to 0.6.0

  Fedora 25: moodle Security Update (Dec 2)
 

Fix for CVE-2017-15110.

  Fedora 25: kernel Security Update (Dec 2)
 

The 4.13.16 update contains various fixes across the tree.

  Fedora 27: python-sanic Security Update (Dec 2)
 

Update to 0.6.0

  Fedora 27: qpid-cpp Security Update (Dec 2)
 

Rebuilt against qpid-

  Fedora 27: kernel Security Update (Dec 1)
 

The 4.13.16 update contains various fixes across the tree.

  Fedora 26: kernel Security Update (Dec 1)
 

The 4.13.16 update contains various fixes across the tree.

  Fedora 26: moodle Security Update (Dec 1)
 

Fix for CVE-2017-15110.

  Fedora 26: python-werkzeug Security Update (Dec 1)
 

Update to 0.12.2 which also fixes CVE-2016-10516

  Fedora 26: nodejs-brace-expansion Security Update (Dec 1)
 

Update to upstream 1.1.7 release to remediate DoS issue npm:brace- expansion:20170302

  Fedora 26: nodejs-balanced-match Security Update (Dec 1)
 

Update to upstream 1.1.7 release to remediate DoS issue npm:brace- expansion:20170302

  Fedora 27: python-werkzeug Security Update (Nov 30)
 

Update to 0.12.2 which also fixes CVE-2016-10516

  Fedora 27: moodle Security Update (Nov 30)
 

Fix for CVE-2017-15110.

  Fedora 27: mediawiki Security Update (Nov 30)
 

https://lists.wikimedia.org/hyperkitty/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/EIECM2E7PQ2VN3O4DSZBCE6K7HDW7AJC/


  RedHat: RHSA-2017-3404:01 Moderate: rh-postgresql95-postgresql security (Dec 8)
 

An update for rh-postgresql95-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2017-3405:01 Moderate: rh-postgresql96-postgresql security (Dec 8)
 

An update for rh-postgresql96-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2017-3402:01 Moderate: postgresql security update (Dec 8)
 

An update for postgresql is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3403:01 Moderate: rh-postgresql94-postgresql security (Dec 8)
 

An update for rh-postgresql94-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2017-3401:01 Critical: chromium-browser security update (Dec 7)
 

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2017-3399:01 Important: Red Hat JBoss Enterprise Application (Dec 7)
 

An update is now available for Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 5 and Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

  RedHat: RHSA-2017-3400:01 Important: Red Hat JBoss Enterprise Application (Dec 7)
 

An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2017-3389:01 Moderate: Red Hat OpenShift Enterprise security, (Dec 7)
 

An update is now available for Red Hat OpenShift Container Platform 3.4, Red Hat OpenShift Container Platform 3.5, and Red Hat OpenShift Container Platform 3.6. Red Hat Product Security has rated this update as having a security impact

  RedHat: RHSA-2017-3392:01 Important: java-1.7.0-openjdk security and bug (Dec 6)
 

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2017-3384:01 Moderate: liblouis security update (Dec 5)
 

An update for liblouis is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3382:01 Important: firefox security update (Dec 5)
 

An update for firefox is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2017-3379:01 Moderate: sssd security and bug fix update (Dec 5)
 

An update for sssd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3375:01 Low: Red Hat Enterprise Linux 7.2 Extended Update (Dec 4)
 

This is the final notification for the retirement of Red Hat Enterprise Linux 7.2 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 7.2.

  RedHat: RHSA-2017-3376:01 Low: Red Hat Enterprise Linux 6.5 TUS Retirement (Dec 4)
 

This is the final notification for the retirement of Red Hat Enterprise Linux 6.5 Telecommunications Update Support (TUS). This notification applies only to those customers subscribed to the Telecommunications Update Support (TUS) channel for Red Hat Enterprise Linux 6.5.

  RedHat: RHSA-2017-3372:01 Important: thunderbird security update (Dec 4)
 

An update for thunderbird is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2017-3315:01 Important: kernel security and bug fix update (Nov 30)
 

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2017-3368:01 Moderate: qemu-kvm security update (Nov 30)
 

An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3369:01 Moderate: qemu-kvm-rhev security and bug fix (Nov 30)
 

An update for qemu-kvm-rhev is now available for Red Hat Enterprise Virtualization (RHEV) 4.X, Red Hat Enterprise Virtualization Hypervisor (RHEV-H) and Agents for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

  RedHat: RHSA-2017-3295:01 Moderate: kernel-rt security and bug fix update (Nov 30)
 

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3354:01 Moderate: Red Hat JBoss BRMS 6.4.7 security update (Nov 30)
 

An update is now available for Red Hat JBoss BRMS. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3355:01 Moderate: Red Hat JBoss BPM Suite 6.4.7 security (Nov 30)
 

An update is now available for Red Hat JBoss BPM Suite. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3322:01 Moderate: kernel-rt security, bug fix, (Nov 30)
 

An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2017-3335:01 Low: Red Hat Enterprise Linux 6.2 AMC One-Month (Nov 30)
 

This is the one-month notification for the retirement of Red Hat Enterprise Linux 6.2 Advanced Mission Critical (AMC). This notification applies only to those customers subscribed to the Advanced Mission Critical (AMC) channel for Red Hat Enterprise Linux 6.2.


  openSUSE: 2017:3244-1: important: chromium (Dec 8)
 

An update that fixes 18 vulnerabilities is now available. An update that fixes 18 vulnerabilities is now available. An update that fixes 18 vulnerabilities is now available.

  openSUSE: 2017:3245-1: important: chromium (Dec 8)
 

An update that fixes 41 vulnerabilities is now available. An update that fixes 41 vulnerabilities is now available. An update that fixes 41 vulnerabilities is now available.

  SuSE: 2017:3242-1: important: xen (Dec 8)
 

An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes is now available. is now available.

  openSUSE: 2017:3241-1: important: opensaml (Dec 8)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  SuSE: 2017:3239-1: important: xen (Dec 8)
 

An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes is now available. is now available.

  SuSE: 2017:3235-1: important: java-1_6_0-ibm (Dec 7)
 

An update that fixes 15 vulnerabilities is now available. An update that fixes 15 vulnerabilities is now available. An update that fixes 15 vulnerabilities is now available.

  SuSE: 2017:3236-1: important: xen (Dec 7)
 

An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes is now available. is now available.

  SuSE: 2017:3233-1: important: MozillaFirefox (Dec 7)
 

An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

  SuSE: 2017:3234-1: important: opensaml (Dec 7)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  openSUSE: 2017:3229-1: important: shibboleth-sp (Dec 7)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  SuSE: 2017:3226-1: important: the Linux Kernel (Dec 6)
 

An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

  SuSE: 2017:3225-1: important: the Linux Kernel (Dec 6)
 

An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

  openSUSE: 2017:3223-1: important: GraphicsMagick (Dec 6)
 

An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available.

  openSUSE: 2017:3220-1: important: exim (Dec 6)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  SuSE: 2017:3215-1: important: shibboleth-sp (Dec 5)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  SuSE: 2017:3213-1: important: MozillaFirefox (Dec 5)
 

An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

  SuSE: 2017:3212-1: important: xen (Dec 5)
 

An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two fixes is now available. fixes is now available.

  SuSE: 2017:3210-1: important: the Linux Kernel (Dec 4)
 

An update that fixes 14 vulnerabilities is now available. An update that fixes 14 vulnerabilities is now available. An update that fixes 14 vulnerabilities is now available.

  openSUSE: 2017:3194-1: important: xen (Dec 2)
 

An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four fixes is now available. fixes is now available.

  openSUSE: 2017:3193-1: important: xen (Dec 2)
 

An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four fixes is now available. fixes is now available.

  SuSE: 2017:3183-1: important: ncurses (Dec 1)
 

An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available.

  SuSE: 2017:3177-1: important: openvpn-openssl1 (Dec 1)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  SuSE: 2017:3178-1: important: xen (Dec 1)
 

An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four fixes is now available. fixes is now available.

  SuSE: 2017:3165-1: important: the Linux Kernel (Nov 30)
 

An update that solves 5 vulnerabilities and has 17 fixes is An update that solves 5 vulnerabilities and has 17 fixes is An update that solves 5 vulnerabilities and has 17 fixes is now available. now available.

  SuSE: 2017:3160-1: important: the Linux Kernel (Live Patch 20 for SLE 12) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3159-1: important: the Linux Kernel (Live Patch 5 for SLE 12 SP2) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3158-1: important: the Linux Kernel (Live Patch 21 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3157-1: important: the Linux Kernel (Live Patch 19 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3156-1: important: the Linux Kernel (Live Patch 2 for SLE 12 SP2) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3154-1: important: the Linux Kernel (Live Patch 19 for SLE 12) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3153-1: important: the Linux Kernel (Live Patch 16 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3152-1: important: the Linux Kernel (Live Patch 18 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3151-1: important: the Linux Kernel (Live Patch 18 for SLE 12) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3150-1: important: the Linux Kernel (Live Patch 17 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3149-1: important: the Linux Kernel (Live Patch 21 for SLE 12) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3148-1: important: the Linux Kernel (Live Patch 20 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3147-1: important: the Linux Kernel (Live Patch 11 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3146-1: important: the Linux Kernel (Live Patch 22 for SLE 12) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3145-1: important: the Linux Kernel (Live Patch 15 for SLE 12 SP1) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  openSUSE: 2017:3144-1: important: kernel-firmware (Nov 30)
 

An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

  openSUSE: 2017:3141-1: important: samba (Nov 30)
 

An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

  SuSE: 2017:3139-1: important: the Linux Kernel (Live Patch 6 for SLE 12 SP2) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3136-1: important: the Linux Kernel (Live Patch 3 for SLE 12 SP2) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:3134-1: important: the Linux Kernel (Live Patch 4 for SLE 12 SP2) (Nov 30)
 

An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.


  Ubuntu 3507-2: Linux kernel (GCP) vulnerabilities (Dec 8)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 0033-1: Linux kernel vulnerability (Dec 8)
 

Several security issues were fixed in the kernel.

  Ubuntu 3511-1: Linux kernel (Azure) vulnerabilities (Dec 8)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3510-1: Linux kernel vulnerabilities (Dec 8)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3509-2: Linux kernel (Xenial HWE) vulnerabilities (Dec 8)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3510-2: Linux kernel (Trusty HWE) vulnerabilities (Dec 8)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3509-1: Linux kernel vulnerabilities (Dec 8)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3508-1: Linux kernel vulnerabilities (Dec 8)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3507-1: Linux kernel vulnerabilities (Dec 8)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3508-2: Linux kernel (HWE) vulnerabilities (Dec 8)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3506-2: rsync vulnerabilities (Dec 7)
 

Several security issues were fixed in rsync.

  Ubuntu 3506-1: rsync vulnerabilities (Dec 7)
 

Several security issues were fixed in rsync.

  Ubuntu 3505-1: Linux firmware vulnerabilities (Dec 6)
 

Several security issues were fixed in linux-firmware.

  Ubuntu 3504-2: libxml2 vulnerability (Dec 5)
 

curl could be made to crash if it received specially crafted input.

  Ubuntu 3504-1: libxml2 vulnerability (Dec 5)
 

libxml2 could be made to crash if it opened a specially craftedfile.

  Ubuntu 3498-2: curl vulnerability (Dec 4)
 

curl could be made to crash if it received specially crafted input.