General Esm W900

Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system. Vulnerabilities affect nearly every vendor virtually every week, so be sure to read through to find the updates your distributor have made available.


LinuxSecurity.com Feature Extras:

- Social engineering is the practice of learning and obtaining valuable information by exploiting human vulnerabilities. It is an art of deception that is considered to be vital for a penetration tester when there is a lack of information about the target that can be exploited.

- When you’re dealing with a security incident it’s essential you – and the rest of your team – not only have the skills they need to comprehensively deal with an issue, but also have a framework to support them as they approach it. This framework means they can focus purely on what they need to do, following a process that removes any vulnerabilities and threats in a proper way – so everyone who depends upon the software you protect can be confident that it’s secure and functioning properly.


  Debian: DSA-3909-1: samba security update (Jul 14)
 

Jeffrey Altman, Viktor Duchovni and Nico Williams identified a mutual authentication bypass vulnerability in samba, the SMB/CIFS file, print, and login server. Also known as Orpheus' Lyre, this vulnerability is located in Samba Kerberos Key Distribution Center (KDC-REP) component and could be used by

  Debian: DSA-3908-1: nginx security update (Jul 12)
 

An integer overflow has been found in the HTTP range module of Nginx, a high-performance web and reverse proxy server, which may result in information disclosure.

  Debian: DSA-3907-1: spice security update (Jul 11)
 

Frediano Ziglio discovered a buffer overflow in spice, a SPICE protocol client and server library which may result in memory disclosure, denial of service and potentially the execution of arbitrary code.

  Debian: DSA-3906-1: undertow security update (Jul 11)
 

Two vulnerabilities have been discovered in Undertow, a web server written in Java, which may lead to denial of service or HTTP request smuggling.

  Debian: DSA-3905-1: xorg-server security update (Jul 9)
 

Two security issues have been discovered in the X.org X server, which may lead to privilege escalation or an information leak. For the oldstable distribution (jessie), these problems have been fixed

  Debian: DSA-3904-1: bind9 security update (Jul 8)
 

Clément Berthaux from Synaktiv discovered two vulnerabilities in BIND, a DNS server implementation. They allow an attacker to bypass TSIG authentication by sending crafted DNS packets to a server.

 
  Fedora 26: evince Security Update (Jul 14)
 

- CVE-2017-1000083: Evince command injection vulnerability in CBT handler (#1468488)

  Fedora 26: expat Security Update (Jul 14)
 

https://github.com/libexpat/libexpat/blob/R_2_2_1/expat/Changes

  Fedora 26: cacti Security Update (Jul 14)
 

- Update to 1.1.12 - Fix Cross-site Scripting (XSS) issue with link.php (CVE-2017-10970) Release notes: Release notes:

  Fedora 26: myproxy Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 26: jabberd Security Update (Jul 14)
 

updated to 2.6.1 (security bugfix release)

  Fedora 26: globus-xio-gsi-driver Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 26: globus-xio-pipe-driver Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 26: globus-xio Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 26: globus-xio-udt-driver Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 26: globus-gram-job-manager Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 26: globus-gridftp-server Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 26: globus-net-manager Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 26: globus-gssapi-gsi Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 26: globus-io Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 26: globus-gass-cache-program Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 26: globus-gass-copy Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 26: globus-ftp-client Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 26: globus-gram-job-manager-condor Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 26: globus-gram-client Security Update (Jul 14)
 

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public

  Fedora 25: php Security Update (Jul 13)
 

**PHP version 7.0.21** (06 Jul 2017) **Core:** * Fixed bug php#74738 (Multiple [PATH=] and [HOST=] sections not properly parsed). (Manuel Mausz) * Fixed bug php#74658 (Undefined constants in array properties result in broken properties). (Laruence) * Fixed misparsing of abstract unix domain socket names. (Sara) * Fixed bug php#74101, bug php#74614 (Unserialize Heap Use-After-Free (READ: 1) in

  Fedora 25: perl-DBD-MySQL Security Update (Jul 13)
 

Updated to the latest version; Security fix for CVE-2017-10788

  Fedora 26: perl-DBD-MySQL Security Update (Jul 13)
 

Updated to the latest version; Security fix for CVE-2017-10788

  Fedora 26: qt5-qtwebengine Security Update (Jul 12)
 

This update updates QtWebEngine to the 5.9.1 release, a security and bugfix release from the 5.9 branch. QtWebEngine 5.9.1 is part of the Qt 5.9.1 release, but only the QtWebEngine component is included in this update. The update fixes the following security issues in QtWebEngine 5.9.0: CVE-2017-5070, CVE-2017-5071, CVE-2017-5075, CVE-2017-5076, CVE-2017-5077, CVE-2017-5078,

  Fedora 25: expat Security Update (Jul 12)
 

https://github.com/libexpat/libexpat/blob/R_2_2_1/expat/Changes

  Fedora 25: GraphicsMagick Security Update (Jul 12)
 

New stable upstream release, primarily includes security fixes for CVE-2017-10794, CVE-2017-10799, CVE-2017-10800 See also http://www.graphicsmagick.org/NEWS.html#july-4-2017

  Fedora 25: yara Security Update (Jul 12)
 

Security fix for CVE-2017-9304, CVE-2017-9465

  Fedora 25: mosquitto Security Update (Jul 11)
 

Fix CVE-2017-9868 (rhbz#1464946)

  Fedora 25: qt5-qtwebengine Security Update (Jul 11)
 

This update updates QtWebEngine to the 5.9.0 release. QtWebEngine 5.9.0 is part of the Qt 5.9.0 release, but only the QtWebEngine component is included in this update. The update fixes the following security issues in QtWebEngine 5.8.0: CVE-2017-5006, CVE-2017-5007, CVE-2017-5008, CVE-2017-5009, CVE-2017-5010, CVE-2017-5011, CVE-2017-5012, CVE-2017-5013, CVE-2017-5014, CVE-2017-5015,

  Fedora 25: libdb Security Update (Jul 11)
 

Security fix for DB_CONFIG parsing when db_home is not set. This update also introduces modified fixes for rhbz#1394862 once again and additionally fixes ppc specific hangs described in rhbz#1460003. Please be aware that this update is expected to cause **DB_VERSION_MISMATCH** errors during installation if you are still running an older release of libdb. These errors are a result of packages

  Fedora 25: xen Security Update (Jul 11)
 

xen: various flaws (#1463247) blkif responses leak backend stack data [XSA-216] page transfer may allow PV guest to elevate privilege [XSA-217] Races in the grant table unmap code [XSA-218] x86: insufficient reference counts during shadow emulation [XSA-219] x86: PKRU and BND* leakage between vCPU-s [XSA-220] stale P2M mappings due to insufficient error checking [XSA-222] ARM guest

  Fedora 25: libsndfile Security Update (Jul 11)
 

fix CVE-2017-6892

  Fedora 24: expat Security Update (Jul 11)
 

https://github.com/libexpat/libexpat/blob/R_2_2_1/expat/Changes

  Fedora 24: yara Security Update (Jul 11)
 

Security fix for CVE-2017-9304, CVE-2017-9465

  Fedora 24: mosquitto Security Update (Jul 11)
 

Fix CVE-2017-9868 (rhbz#1464946)

  Fedora 24: dnsperf Security Update (Jul 11)
 

Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140

  Fedora 24: bind-dyndb-ldap Security Update (Jul 11)
 

Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140

  Fedora 24: bind Security Update (Jul 11)
 

Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140

  Fedora 24: jetty Security Update (Jul 11)
 

Backport fix for CVE-2017-9735

  Fedora 24: httpd Security Update (Jul 11)
 

Security fix for CVE-2017-3167 CVE-2017-3169 CVE-2017-7659 CVE-2017-7668 CVE-2017-7679

  Fedora 24: libdb Security Update (Jul 11)
 

Security fix for DB_CONFIG parsing when db_home is not set. This update also introduces modified fixes for rhbz#1394862 once again and additionally fixes ppc specific hangs described in rhbz#1460003. Please be aware that this update is expected to cause **DB_VERSION_MISMATCH** errors during installation if you are still running an older release of libdb. These errors are a result of packages

  Fedora 24: flatpak Security Update (Jul 11)
 

Security fix for CVE-2017-9780 Update to 0.8.7

  Fedora 24: php-horde-Horde-Image Security Update (Jul 11)
 

**Horde_Image 2.5.1** * [mjr] SECURITY: Fix more potential places for command injections. ---- **Horde_Image 2.5.0** * [mjr] **SECURITY**: Prevent DOS attack by preventing an infinite loop in certain conditions (CVE-2017-9773, reported by Fariskhi Vidyan). * [mjr] **SECURITY**: Prevent RCE attacks by properly sanitizing shell arguments (CVE-2017-9774, reported by Fariskhi

  Fedora 24: chromium-native_client Security Update (Jul 11)
 

Chromium 59. Add smaller logo files. Fix lots of security bugs: Security fix for CVE-2017-5070, CVE-2017-5071, CVE-2017-5072, CVE-2017-5073, CVE-2017-5074, CVE-2017-5075, CVE-2017-5086, CVE-2017-5076, CVE-2017-5077, CVE-2017-5078, CVE-2017-5079, CVE-2017-5080, CVE-2017-5081, CVE-2017-5082, CVE-2017-5083, CVE-2017-5085

  Fedora 24: libsndfile Security Update (Jul 11)
 

fix CVE-2017-6892

  Fedora 26: yara Security Update (Jul 11)
 

Security fix for CVE-2017-9304, CVE-2017-9465

  Fedora 26: mingw-LibRaw Security Update (Jul 11)
 

Update to 0.18.2, see https://www.libraw.org/news/libraw-0-18-2 for details.

  Fedora 26: php-horde-Horde-Image Security Update (Jul 11)
 

**Horde_Image 2.5.1** * [mjr] SECURITY: Fix more potential places for command injections. ---- **Horde_Image 2.5.0** * [mjr] **SECURITY**: Prevent DOS attack by preventing an infinite loop in certain conditions (CVE-2017-9773, reported by Fariskhi Vidyan). * [mjr] **SECURITY**: Prevent RCE attacks by properly sanitizing shell arguments (CVE-2017-9774, reported by Fariskhi

  Fedora 25: bind99 Security Update (Jul 8)
 

Update to new ISC supported version 9.9.10.

  Fedora 25: dhcp Security Update (Jul 8)
 

Update to new ISC supported version 9.9.10.

  Fedora 25: jetty-test-helper Security Update (Jul 8)
 

Update to latest upstream release in order to fix CVE-2017-9735

  Fedora 25: pius Security Update (Jul 8)
 

update

  Fedora 25: jetty Security Update (Jul 8)
 

Update to latest upstream release in order to fix CVE-2017-9735

  Fedora 25: jetty-alpn Security Update (Jul 8)
 

Update to latest upstream release in order to fix CVE-2017-9735

  Fedora 25: irssi Security Update (Jul 8)
 

This is new version with security fixes for CVE-2017-9468, CVE-2017-9469.

  Fedora 24: pius Security Update (Jul 8)
 

update

  Fedora 26: GraphicsMagick Security Update (Jul 8)
 

New stable upstream release, primarily includes security fixes for CVE-2017-10794, CVE-2017-10799, CVE-2017-10800 See also http://www.graphicsmagick.org/NEWS.html#july-4-2017

  Fedora 26: bind99 Security Update (Jul 8)
 

Update to new ISC supported version 9.9.10-P2 including security fixes.

  Fedora 26: qt5-qtwebkit Security Update (Jul 8)
 

Update to annulen-branch of qt5-qtwebkit, which contains a lot of security fixes. Drop-in replacement for the old unmaintained qt5-qtwebkit

  Fedora 26: dhcp Security Update (Jul 8)
 

Update to new ISC supported version 9.9.10-P2 including security fixes.

  Fedora 26: mosquitto Security Update (Jul 7)
 

Fix CVE-2017-9868 (rhbz#1464946)

  Fedora 26: bind Security Update (Jul 7)
 

Update to last supported version, fixes CVE-2017-3142 and CVE-2017-3143. Includes minor fix of missing dependencies.

  Fedora 26: libgcrypt Security Update (Jul 7)
 

New upstream release fixing moderate security issue CVE-2017-7526.

  Fedora 26: pius Security Update (Jul 7)
 

update

  Fedora 26: jetty Security Update (Jul 7)
 

Update to latest upstream release in order to fix CVE-2017-9735

  Fedora 26: httpd Security Update (Jul 7)
 

Security fix for CVE-2017-3167 CVE-2017-3169 CVE-2017-7659 CVE-2017-7668 CVE-2017-7679

  Fedora 26: irssi Security Update (Jul 7)
 

This is an security fix for CVE-2017-9468, CVE-2017-9469.

  Fedora 26: libdb Security Update (Jul 7)
 

Security fix for DB_CONFIG parsing when db_home is not set. This update also introduces modified fixes for rhbz#1394862 once again and additionally fixes ppc specific hangs described in rhbz#1460003. Please be aware that this update is expected to cause **DB_VERSION_MISMATCH** errors during installation if you are still running an older release of libdb. These errors are a result of packages

  Fedora 26: ocaml Security Update (Jul 7)
 

Fix: ocaml: Insufficient sanitisation allows privilege escalation for setuid binaries (CVE-2017-9772) (RHBZ#1464920).

  Fedora 26: drupal7 Security Update (Jul 7)
 

* [7.56](https://) * [SA- CORE-2017-003](https://)

  Fedora 26: zabbix Security Update (Jul 7)
 

- https://www.zabbix.com/rn/rn3.0.8 - https://www.zabbix.com/rn/rn3.0.9 - https://www.zabbix.com/documentation/3.0/en/manual/introduction/whatsnew308 - https://www.zabbix.com/documentation/3.0/en/manual/introduction/whatsnew309

  Fedora 26: xen Security Update (Jul 7)
 

xen: various flaws (#1463247) blkif responses leak backend stack data [XSA-216] page transfer may allow PV guest to elevate privilege [XSA-217] Races in the grant table unmap code [XSA-218] x86: insufficient reference counts during shadow emulation [XSA-219] x86: PKRU and BND* leakage between vCPU-s [XSA-220] NULL pointer deref in event channel poll [XSA-221] (#1463231) stale P2M mappings

  Fedora 26: tomcat Security Update (Jul 7)
 

This update includes a rebase from 8.0.43 up to 8.0.44 which resolves a single CVE along with various other bugs/features: * rhbz#1459160 CVE-2017-5664 tomcat: Security constrained bypass in error page mechanism

  Fedora 25: webkitgtk4 Security Update (Jul 7)
 

This update addresses the following vulnerabilities: * [CVE-2017-2538](https://www.cve.org/CVERecord?id=CVE-2017-2538) Additional fixes: * Fix web process deadlock when seeking youtube videos. * Fix blob downloads. * Improve theme rendering performance when using GTK+ >= 3.20. * Fix positioning of popup menus in Wayland. * Fix JavaScriptCore crashes on big-

  Fedora 26: qt5-qtwebengine Security Update (Jul 6)
 

This update updates QtWebEngine to the 5.9.0 release. QtWebEngine 5.9.0 is part of the Qt 5.9.0 release, but only the QtWebEngine component is included in this update. The update fixes the following security issues in QtWebEngine 5.8.0: CVE-2017-5006, CVE-2017-5007, CVE-2017-5008, CVE-2017-5009, CVE-2017-5010, CVE-2017-5011, CVE-2017-5012, CVE-2017-5013, CVE-2017-5014, CVE-2017-5015,

 
  (Jul 9)
 

A vulnerability in Gajim might allow remote attackers to intercept encrypted communications.

  (Jul 9)
 

Multiple vulnerabilities have been found in libcroco, the worst of which may have unspecified impacts.

  (Jul 9)
 

A vulnerability in MAN DB allows local users to gain root privileges.

  (Jul 8)
 

A vulnerability in RoundCube may allow authenticated users to bypass security restrictions.

  (Jul 8)
 

Multiple vulnerabilities have been found in VLC, the worst of which may allow remote attackers to execute arbitrary code.

  (Jul 8)
 

A vulnerability has been found in GNOME applet for NetworkManager allowing local attackers to access the local filesystem.

  (Jul 8)
 

A vulnerability in feh might allow remote attackers to execute arbitrary code.

  (Jul 8)
 

A vulnerability in phpMyAdmin might allow remote attackers to bypass authentication.

  (Jul 8)
 

Multiple vulnerabilities have been found in JasPer, the worst of which could could allow an attacker to execute arbitrary code.

  (Jul 8)
 

Multiple vulnerabilities have been found in virglrenderer, the worst of which could allow local guest OS users to cause a Denial of Service condition. [More...]

  (Jul 8)
 

Multiple vulnerabilities have been found in OpenSLP, the worst of which allows remote attackers to cause a Denial of Service condition or other unspecified impacts. [More...]

  (Jul 8)
 

Multiple vulnerabilities have been found in libsndfile, the worst of which might allow remote attackers to execute arbitrary code.

  (Jul 8)
 

Multiple vulnerabilities have been found in Game Music Emu, the worst of which could lead to the execution of arbitrary code.

 
  Slackware: 2017-191-01: libtirpc Security Update (Jul 10)
 

New libtirpc packages are available for Slackware 14.2 and -current to fix a security issue.

  Slackware: 2017-191-02: rpcbind Security Update (Jul 10)
 

New rpcbind packages are available for Slackware 14.2 and -current to fix a security issue.

  Slackware: 2017-190-01: irssi Security Update (Jul 9)
 

New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

  Slackware: 2017-188-01: php Security Update (Jul 7)
 

New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

 
  SuSE: 2017:1860-1: important: xorg-x11-server (Jul 14)
 

An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

  SuSE: 2017:1861-1: important: xorg-x11-server (Jul 14)
 

An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

  SuSE: 2017:1859-1: important: xorg-x11-server (Jul 14)
 

An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

  SuSE: 2017:1853-1: important: the Linux Kernel (Jul 13)
 

An update that solves 15 vulnerabilities and has 162 fixes An update that solves 15 vulnerabilities and has 162 fixes An update that solves 15 vulnerabilities and has 162 fixes is now available. is now available.

  SuSE: 2017:1850-1: important: xorg-x11-server (Jul 12)
 

An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

  openSUSE: 2017:1843-1: important: spice (Jul 12)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  SuSE: 2017:1839-1: important: spice (Jul 11)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  SuSE: 2017:1836-1: important: spice (Jul 11)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  SuSE: 2017:1837-1: important: spice (Jul 11)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  SuSE: 2017:1832-1: important: spice (Jul 11)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  openSUSE: 2017:1826-1: important: xen (Jul 8)
 

An update that fixes 11 vulnerabilities is now available. An update that fixes 11 vulnerabilities is now available. An update that fixes 11 vulnerabilities is now available.

  openSUSE: 2017:1825-1: important: the Linux Kernel (Jul 8)
 

An update that solves two vulnerabilities and has 14 fixes An update that solves two vulnerabilities and has 14 fixes An update that solves two vulnerabilities and has 14 fixes is now available. is now available.

  SuSE: 2017:1815-1: important: Recommended ncurses (Jul 7)
 

An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

  SuSE: 2017:1812-1: important: xen (Jul 7)
 

An update that solves 17 vulnerabilities and has one errata An update that solves 17 vulnerabilities and has one errata An update that solves 17 vulnerabilities and has one errata is now available. is now available.

  openSUSE: 2017:1809-1: important: bind (Jul 6)
 

An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

  openSUSE: 2017:1797-1: important: clamav (Jul 6)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  SuSE: 2017:1795-1: important: xen (Jul 6)
 

An update that solves 16 vulnerabilities and has two fixes An update that solves 16 vulnerabilities and has two fixes An update that solves 16 vulnerabilities and has two fixes is now available. is now available.

  SuSE: 2017:1790-1: important: Recommended ncurses (Jul 6)
 

An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

 
  Ubuntu 3352-1: nginx vulnerability (Jul 13)
 

nginx could be made to expose sensitive information over the network.

  Ubuntu 3351-1: Evince vulnerability (Jul 13)
 

Evince could be made run programs as your login if it opened a specially crafted file.

  Ubuntu 3350-1: poppler vulnerabilities (Jul 7)
 

poppler could be made to crash or run programs as your login if it opened a specially crafted file.