General Esm W900

Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system. Vulnerabilities affect nearly every vendor virtually every week, so be sure to read through to find the updates your distributor have made available.


LinuxSecurity.com Feature Extras:

- Social engineering is the practice of learning and obtaining valuable information by exploiting human vulnerabilities. It is an art of deception that is considered to be vital for a penetration tester when there is a lack of information about the target that can be exploited.

- When you’re dealing with a security incident it’s essential you – and the rest of your team – not only have the skills they need to comprehensively deal with an issue, but also have a framework to support them as they approach it. This framework means they can focus purely on what they need to do, following a process that removes any vulnerabilities and threats in a proper way – so everyone who depends upon the software you protect can be confident that it’s secure and functioning properly.


  Debian: DSA-3883-1: rt-authen-externalauth security update (Jun 15)
 

It was discovered that RT::Authen::ExternalAuth, an external authentication module for Request Tracker, is vulnerable to timing side-channel attacks for user passwords. Only ExternalAuth in DBI (database) mode is vulnerable.

  Debian: DSA-3882-1: request-tracker4 security update (Jun 15)
 

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. The Common Vulnerabilities and Exposures project identifies the following problems:

  Debian: DSA-3881-1: firefox-esr security update (Jun 14)
 

Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors, use-after-frees, buffer overflows and other implementation errors may lead to the execution of arbitrary code, denial of service or domain spoofing.

  Debian: DSA-3880-1: libgcrypt20 security update (Jun 14)
 

It was discovered that a side channel attack in the EdDSA session key handling in Libgcrypt may result in information disclosure. For the stable distribution (jessie), this problem has been fixed in

  Debian: DSA-3879-1: libosip2 security update (Jun 13)
 

Multiple security vulnerabilities have been found in oSIP, a library implementing the Session Initiation Protocol, which might result in denial of service through malformed SIP messages.

  Debian: DSA-3878-1: zziplib security update (Jun 12)
 

Agostino Sarubbo discovered multiple vulnerabilities in zziplib, a library to access Zip archives, which could result in denial of service and potentially the execution of arbitrary code if a malformed archive is processed.

  Debian: DSA-3877-1: tor security update (Jun 10)
 

It has been discovered that Tor, a connection-based low-latency anonymous communication system, contain a flaw in the hidden service code when receiving a BEGIN_DIR cell on a hidden service rendezvous circuit. A remote attacker can take advantage of this flaw to cause a

  Debian: DSA-3876-1: otrs2 security update (Jun 9)
 

Joerg-Thomas Vogt discovered that the SecureMode was insufficiently validated in the OTRS ticket system, which could allow agents to escalate their privileges.

  Debian: DSA-3875-1: libmwaw security update (Jun 9)
 

It was discovered that a buffer overflow in libmwaw, a library to open old Mac text documents might result in the execution of arbitrary code if a malformed document is opened.

  Debian: DSA-3874-1: ettercap security update (Jun 9)
 

Agostino Sarubbo and AromalUllas discovered that ettercap, a network security tool for traffic interception, contains vulnerabilities that allowed an attacker able to provide maliciously crafted filters to cause a denial-of-service via application crash.

 
  Fedora 26: firefox Security Update (Jun 16)
 

- new upstream update (54.0)

  Fedora 26: network-manager-applet Security Update (Jun 16)
 

Update to version 1.8.2. The upstream release notes: https://mail.gnome.org/archives/ftp-release-list/2017-June/msg00015.html

  Fedora 26: mariadb Security Update (Jun 16)
 

**Rebase to 10.1.24** Plugin oqgraph enabled Plugin jemalloc enabled Sphinx engine enabled Build dependecies Bison and Libarchive added, others corrected Disabling Mroonga engine for i686 architecture, as it is not supported by MariaDB **Removed patches: (fixed by upstream)** Patch5: %{pkgnamepatch}-file-contents.patch Patch14: %{pkgnamepatch}-example-config-

  Fedora 25: gajim Security Update (Jun 15)
 

Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability of delivery recipes * Many minor

  Fedora 25: ettercap Security Update (Jun 15)
 

FIx for CVE-2017-8366

  Fedora 24: gajim Security Update (Jun 15)
 

Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability of delivery recipes * Many minor

  Fedora 24: ettercap Security Update (Jun 15)
 

FIx for CVE-2017-8366

  Fedora 24: libsndfile Security Update (Jun 15)
 

fixes buffer overflows for flac and pcm

  Fedora 24: webkitgtk4 Security Update (Jun 15)
 

This update addresses the following vulnerabilities: * [CVE-2017-2496](https://www.cve.org/CVERecord?id=CVE-2017-2496), [CVE-2017-2539](https://www.cve.org/CVERecord?id=CVE-2017-2539), [CVE-2017-2510](https://www.cve.org/CVERecord?id=CVE-2017-2510) Additional fixes: * Fix URL shown in the title of beforeunload dialogs. * Focus

  Fedora 24: poppler Security Update (Jun 15)
 

CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents

  Fedora 26: yara Security Update (Jun 14)
 

Update to a bugfix release of yara.

  Fedora 24: kernel Security Update (Jun 13)
 

The 4.11.4 update contains a number of important fixes across the tree ---- This is a rebase to the 4.11 series of kernels. It includes all fixes

  Fedora 26: mingw-gnutls Security Update (Jun 13)
 

https://lists.gnupg.org/pipermail/gnutls-devel/2017-June/008446.html

  Fedora 26: gajim Security Update (Jun 13)
 

Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability of delivery recipes * Many minor

  Fedora 25: libsndfile Security Update (Jun 12)
 

fixes buffer overflows for flac and pcm

  Fedora 25: log4j12 Security Update (Jun 12)
 

Security fix for CVE-2017-5645

  Fedora 24: log4j12 Security Update (Jun 12)
 

Security fix for CVE-2017-5645

  Fedora 24: postgresql Security Update (Jun 12)
 

Per release notes: https://www.postgresql.org/docs/9.5/release-9-5-7.html

  Fedora 25: oniguruma Security Update (Jun 10)
 

Multiple security flaws were found on oniguruma currently being shipped on Fedora. This new rpm should fix the issue. Fixed CVEs: CVE-2017-9226 CVE-2017-9225 CVE-2017-9224 CVE-2017-9227 CVE-2017-9229 CVE-2017-9228

  Fedora 24: oniguruma Security Update (Jun 10)
 

Multiple security flaws were found on oniguruma currently being shipped on Fedora. This new rpm should fix the issue. Fixed CVEs: CVE-2017-9226 CVE-2017-9224 CVE-2017-9227 CVE-2017-9229 CVE-2017-9228

  Fedora 24: wget Security Update (Jun 10)
 

Fixed CVE-2017-6508: CRLF injection in the url_parse function in url.c

  Fedora 26: libstaroffice Security Update (Jun 9)
 

Security fix for CVE-2017-9432

  Fedora 26: gnutls Security Update (Jun 9)
 

- Update to upstream 3.5.13 release

  Fedora 26: libsndfile Security Update (Jun 9)
 

fixes buffer overflows for flac and pcm

  Fedora 26: ettercap Security Update (Jun 9)
 

FIx for CVE-2017-8366

  Fedora 26: mingw-libtiff Security Update (Jun 9)
 

Security fixes.

  Fedora 26: log4j12 Security Update (Jun 9)
 

Security fix for CVE-2017-5645

  Fedora 26: wget Security Update (Jun 9)
 

* fixed CVE-2017-6508 CRLF injection in the url_parse function in url.c * fixed use of .netrc

  Fedora 26: sudo Security Update (Jun 9)
 

- update to 1.8.20p2 - added sudo package to dnf/yum protected packages ---- - update to 1.8.20p1 - fixes CVE-2017-1000367

  Fedora 26: perl-File-Path Security Update (Jun 9)
 

This release fixes a possible setting arbitrary mode on an arbitrary file in rmtree() and remove_tree() calls known as CVE-2017-6512.

  Fedora 26: mingw-poppler Security Update (Jun 9)
 

This update fixes CVEs 2017-7511 and 2017-9083.

  Fedora 26: dolphin-emu Security Update (Jun 9)
 

Rebuild with new bochs version

  Fedora 26: poppler Security Update (Jun 9)
 

CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents

  Fedora 26: mingw-libtasn1 Security Update (Jun 9)
 

Noteworthy changes in release 4.11 (released 2017-05-27) [stable] - Introduced the ASN1_TIME_ENCODING_ERROR error code to indicate an invalid encoding in the DER time fields. - Introduced flag ASN1_DECODE_FLAG_ALLOW_INCORRECT_TIME. This flag allows decoding errors in time fields even when in strict DER mode. That is introduced in order to allow toleration of invalid times in X.509

  Fedora 26: freeradius Security Update (Jun 9)
 

Upgrade FreeRADIUS to upstream v3.0.14 release. The release includes fixes for various issues, including security issues, one of which is CVE-2017-9148.

  Fedora 26: oniguruma Security Update (Jun 9)
 

Multiple security flaws were found on the previous version of oniguruma. This new version should fix the issue. Fixed CVEs: CVE-2017-9226 CVE-2017-9225 CVE-2017-9224 CVE-2017-9227 CVE-2017-9229 CVE-2017-9228

  Fedora 26: libtasn1 Security Update (Jun 9)
 

Update to 4.12 (#1456190)

  Fedora 26: dropbear Security Update (Jun 9)
 

Security fixes for CVE-2017-9078 CVE-2017-9079

  Fedora 26: webkitgtk4 Security Update (Jun 9)
 

This update addresses the following vulnerabilities: * [CVE-2017-2496](https://www.cve.org/CVERecord?id=CVE-2017-2496), [CVE-2017-2539](https://www.cve.org/CVERecord?id=CVE-2017-2539), [CVE-2017-2510](https://www.cve.org/CVERecord?id=CVE-2017-2510) Additional fixes: * Fix URL shown in the title of beforeunload dialogs. * Focus

  Fedora 26: puppet Security Update (Jun 9)
 

Contains fixes to ensure Puppet can start correctly and a security fix for remote code execution tracked as [CVE-2017-2295](https://bugzilla.redhat.com/show_bug.cgi?id=1452654). * Fix remote code execution in Puppet master during fact uploads - Fedora#1452654 * Fix SSL monkey patches error on startup - Fedora#1440710 , Fedora#1443673 * Fix

  Fedora 26: perltidy Security Update (Jun 9)
 

Cumulative bug-fix, enhancement and security update, including fix for CVE-2016-10374: perltidy relies on the current working directory for certain output files and did not have a symlink-attack protection mechanism, which allowed local users to overwrite arbitrary files by creating a symlink, as demonstrated by creating a perltidy.ERR symlink that the victim could not

  Fedora 26: libtirpc Security Update (Jun 9)
 

Fix for CVE-2017-8779

  Fedora 26: wordpress Security Update (Jun 9)
 

**WordPress 4.7.5** is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately. WordPress versions 4.7.4 and earlier are affected by six security issues: * Insufficient redirect validation in the HTTP class. Reported by Ronni Skansing. * Improper handling of post meta data values in the XML-RPC

  Fedora 26: authconfig Security Update (Jun 9)
 

New release fixing moderate (information leak) issue with PAM configuration when authentication to remote services via SSSD is enabled. To fix the incorrect configuration run: authconfig --updateall

  Fedora 26: chromium Security Update (Jun 9)
 

Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069

  Fedora 26: chromium-native_client Security Update (Jun 9)
 

Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069

  Fedora 26: rpcbind Security Update (Jun 9)
 

Fixed typo in memory leaks patch

  Fedora 26: FlightCrew Security Update (Jun 9)
 

- security fix for rhbz 1450956

  Fedora 26: FlightGear Security Update (Jun 9)
 

This updates fixes a security bug in the route manager, to prevent it from overwriting arbitrary files (CVE-2017-8921)

  Fedora 26: menu-cache Security Update (Jun 9)
 

A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.

  Fedora 26: lxterminal Security Update (Jun 9)
 

A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.

  Fedora 26: pcmanfm Security Update (Jun 9)
 

A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.

  Fedora 26: chicken Security Update (Jun 9)
 

Fix for CVE-2017-6949, also bump to 4.12.0

  Fedora 26: mingw-postgresql Security Update (Jun 9)
 

Fixes CVE-2017-7484 CVE-2017-7485 CVE-2017-7486.

  Fedora 26: smb4k Security Update (Jun 9)
 

Security fix for CVE-2017-8849. https://kde.org/info/security/advisory-20170510-2.txt

  Fedora 26: lynis Security Update (Jun 9)
 

Update to 2.5.0 / https://cisofy.com/security/cve/cve-2017-8108/

  Fedora 26: squirrelmail Security Update (Jun 9)
 

fix insufficient escaping of user-supplied data (CVE-2017-7692)

  Fedora 25: mingw-poppler Security Update (Jun 9)
 

This update fixes CVEs 2017-7511 and 2017-9083.

  Fedora 25: freeradius Security Update (Jun 9)
 

Upgrade FreeRADIUS to upstream v3.0.14 release. The release includes fixes for various issues, including security issues, one of which is CVE-2017-9148.

  Fedora 24: mingw-poppler Security Update (Jun 9)
 

This update fixes CVEs 2017-7511 and 2017-9083.

  Fedora 24: sudo Security Update (Jun 8)
 

- update to 1.8.20p2 - added sudo package to dnf/yum protected packages ---- - update to 1.8.20p1 - fixes CVE-2017-1000367

 
  Slackware: 2017-165-02: mozilla-firefox Security Update (Jun 15)
 

New mozilla-firefox packages are available for Slackware 14.2, and -current to fix security issues.

  Slackware: 2017-165-01: bind Security Update (Jun 15)
 

New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

  Slackware: 2017-158-01: irssi Security Update (Jun 8)
 

New irssi packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

 
  openSUSE: 2017:1572-1: important: mercurial (Jun 15)
 

An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

  SuSE: 2017:1568-1: important: jakarta-taglibs-standard (Jun 14)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  SuSE: 2017:1558-1: important: mercurial (Jun 13)
 

An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

  openSUSE: 2017:1513-1: important: the Linux Kernel (Jun 8)
 

An update that solves 8 vulnerabilities and has 68 fixes is An update that solves 8 vulnerabilities and has 68 fixes is An update that solves 8 vulnerabilities and has 68 fixes is now available. now available.

  openSUSE: 2017:1507-1: important: java-1_8_0-openjdk (Jun 8)
 

An update that fixes 8 vulnerabilities is now available. An update that fixes 8 vulnerabilities is now available. An update that fixes 8 vulnerabilities is now available.

 
  Ubuntu 3319-1: libmwaw vulnerability (Jun 15)
 

libmwaw could be made to crash or run programs as your login if it opened a specially crafted file.

  Ubuntu 3320-1: zziplib vulnerabilities (Jun 15)
 

zziplib could be made to crash or run programs as your login if it opened a specially crafted file.

  Ubuntu 3315-1: Firefox vulnerabilities (Jun 15)
 

Firefox could be made to crash or run programs as your login if it opened a malicious website.

  Ubuntu 3318-1: GnuTLS vulnerabilities (Jun 13)
 

Several security issues were fixed in GnuTLS.