General Esm W900

Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system. Vulnerabilities affect nearly every vendor virtually every week, so be sure to read through to find the updates your distributor have made available.


LinuxSecurity.com Feature Extras:

- Social engineering is the practice of learning and obtaining valuable information by exploiting human vulnerabilities. It is an art of deception that is considered to be vital for a penetration tester when there is a lack of information about the target that can be exploited.

- When you’re dealing with a security incident it’s essential you – and the rest of your team – not only have the skills they need to comprehensively deal with an issue, but also have a framework to support them as they approach it. This framework means they can focus purely on what they need to do, following a process that removes any vulnerabilities and threats in a proper way – so everyone who depends upon the software you protect can be confident that it’s secure and functioning properly.


  Debian: DSA-3896-1: apache2 security update (Jun 22)
 

Several vulnerabilities have been found in the Apache HTTPD server. CVE-2017-3167

  Debian: DSA-3895-1: flatpak security update (Jun 22)
 

It was discovered that Flatpak, an application deployment framework for desktop apps insufficiently restricted file permissinons in third-party repositories, which could result in privilege escalation.

  Debian: DSA-3894-1: graphite2 security update (Jun 22)
 

Multiple vulnerabilities have been found in the Graphite font rendering engine which might result in denial of service or the execution of arbitrary code if a malformed font file is processed.

  Debian: DSA-3893-1: jython security update (Jun 22)
 

Alvaro Munoz and Christian Schneider discovered that jython, an implementation of the Python language seamlessly integrated with Java, is prone to arbitrary code execution triggered when sending a serialized function to the deserializer.

  Debian: DSA-3892-1: tomcat7 security update (Jun 22)
 

Aniket Nandkishor Kulkarni discovered that in tomcat7, a servlet and JSP engine, static error pages used the original request's HTTP method to serve content, instead of systematically using the GET method. This could under certain conditions result in undesirable results,

  Debian: DSA-3891-1: tomcat8 security update (Jun 22)
 

Aniket Nandkishor Kulkarni discovered that in tomcat8, a servlet and JSP engine, static error pages used the original request's HTTP method to serve content, instead of systematically using the GET method. This could under certain conditions result in undesirable results,

  Debian: DSA-3890-1: spip security update (Jun 21)
 

Emeric Boit of ANSSI reported that SPIP, a website engine for publishing, insufficiently sanitises the value from the X-Forwarded-Host HTTP header field. An unauthenticated attacker can take advantage of this flaw to cause remote code execution.

  Debian: DSA-3889-1: libffi security update (Jun 19)
 

libffi, a library used to call code written in one language from code written in a different language, was enforcing an executable stack on the i386 architecture. While this might not be considered a vulnerability by itself, this could be leveraged when exploiting other vulnerabilities, like for example

  Debian: DSA-3886-1: linux security update (Jun 19)
 

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

  Debian: DSA-3888-1: exim4 security update (Jun 19)
 

The Qualys Research Labs discovered a memory leak in the Exim mail transport agent. This is not a security vulnerability in Exim by itself, but can be used to exploit a vulnerability in stack handling. For the full details, please refer to their advisory published at:

  Debian: DSA-3887-1: glibc security update (Jun 19)
 

The Qualys Research Labs discovered various problems in the dynamic linker of the GNU C Library which allow local privilege escalation by clashing the stack. For the full details, please refer to their advisory published at:

  Debian: DSA-3885-1: irssi security update (Jun 18)
 

Multiple vulnerabilities have been discovered in Irssi, a terminal based IRC client. The Common Vulnerabilities and Exposures project identifies the following problems:

  Debian: DSA-3884-1: gnutls28 security update (Jun 16)
 

Hubert Kario discovered that GnuTLS, a library implementing the TLS and SSL protocols, does not properly decode a status response TLS extension, allowing a remote attacker to cause an application using the GnuTLS library to crash (denial of service).

  Debian: DSA-3883-1: rt-authen-externalauth security update (Jun 15)
 

It was discovered that RT::Authen::ExternalAuth, an external authentication module for Request Tracker, is vulnerable to timing side-channel attacks for user passwords. Only ExternalAuth in DBI (database) mode is vulnerable.

  Debian: DSA-3882-1: request-tracker4 security update (Jun 15)
 

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. The Common Vulnerabilities and Exposures project identifies the following problems:

 
  Fedora 25: thunderbird Security Update (Jun 22)
 

For changes see https://www.thunderbird.net/en-US/thunderbird/52.2.0/releasenotes/

  Fedora 25: glibc Security Update (Jun 22)
 

This update addresses CVE-2017-1000366, a vulnerability in the dynamic linker allowing local privilege escalation.

  Fedora 26: libffi Security Update (Jun 22)
 

Disable executable stack for aarch64 builds.

  Fedora 26: glibc Security Update (Jun 22)
 

This update addresses CVE-2017-1000366, a vulnerability in the dynamic linker allowing local privilege escalation.

  Fedora 26: c-ares Security Update (Jun 22)
 

CVE-2017-1000381: c-ares NAPTR parser out of bounds access

  Fedora 26: chromium Security Update (Jun 22)
 

Update to .104. Fix mp3 playback. Security fix for CVE-2017-5087, CVE-2017-5088, CVE-2017-5089

  Fedora 26: love Security Update (Jun 22)
 

Rebuild for new luajit

  Fedora 26: thunderbird Security Update (Jun 20)
 

For changes see https://www.thunderbird.net/en-US/thunderbird/52.2.0/releasenotes/

  Fedora 26: mingw-curl Security Update (Jun 20)
 

Fixes CVE-2017-9502 (Windows builds only)

  Fedora 26: php-pear-PHP-CodeSniffer Security Update (Jun 19)
 

**Version 3.0.1** - This release contains a fix for a **security advisory** related to the improper handling of a shell command - A properly crafted filename would allow for arbitrary code execution when using the --filter=gitmodified command line option - All version 3 users are encouraged to upgrade to this version, especially if you are checking 3rd-party

  Fedora 26: wireshark Security Update (Jun 19)
 

Rebase to the newest upstream version. This release contains mostly bugfixes and no new features. ---- This update enables Lua support and also moves binaries into /usr/bin directory. The bug with scriptlets is resolved by removing the whole alternatives group prior to installing new packages. ---- New upstream release 2.2.6 with many CVE fixes ---- New upstream version and fixed issues

  Fedora 26: openvswitch Security Update (Jun 19)
 

Security fix for CVE-2017-9264 ---- Security fix for CVE-2017-9214

  Fedora 25: yara Security Update (Jun 17)
 

Update to a bugfix release of yara.

  Fedora 24: redis Security Update (Jun 17)
 

Upstream 3.2.8 ---- Upstream 3.2.7 (important security fix) ---- Security fix for CVE-2013-7458

  Fedora 24: yara Security Update (Jun 17)
 

Update to a bugfix release of yara.

  Fedora 26: libmwaw Security Update (Jun 17)
 

Security fix for CVE-2017-9433

  Fedora 26: systemd Security Update (Jun 17)
 

Mostly a bugfix update, but includes an update of the keyboard/mouse hwdb and various small fixes and a minor security issue and a boot issue on virtualized systems with no VGA console. No need to reboot or log out.

  Fedora 25: firefox Security Update (Jun 16)
 

- new upstream update (54.0)

  Fedora 25: mariadb Security Update (Jun 16)
 

**Rebase to 10.1.24** Plugin oqgraph enabled Plugin jemalloc enabled Sphinx engine enabled Build dependecies Bison and Libarchive added, others corrected Disabling Mroonga engine for i686 architecture, as it is not supported by MariaDB **Removed patches: (fixed by upstream)** Patch5: %{pkgnamepatch}-file-contents.patch Patch14: %{pkgnamepatch}-example-config-

  Fedora 25: perl-File-Path Security Update (Jun 16)
 

This release fixes a possible setting arbitrary mode on an arbitrary file in rmtree() and remove_tree() calls known as CVE-2017-6512.

  Fedora 25: golang Security Update (Jun 16)
 

* Bump to 1.7.6 * Security fix for CVE-2017-8932

  Fedora 25: dolphin-emu Security Update (Jun 16)
 

Rebuild with new bochs version

  Fedora 24: mariadb Security Update (Jun 16)
 

**Rebase to 10.1.24** Plugin oqgraph enabled Plugin jemalloc enabled Sphinx engine enabled Build dependecies Bison and Libarchive added, others corrected Disabling Mroonga engine for i686 architecture, as it is not supported by MariaDB **Removed patches: (fixed by upstream)** Patch5: %{pkgnamepatch}-file-contents.patch Patch14: %{pkgnamepatch}-example-config-

  Fedora 24: dolphin-emu Security Update (Jun 16)
 

Rebuild with new bochs version

  Fedora 24: perl-File-Path Security Update (Jun 16)
 

This release fixes a possible setting arbitrary mode on an arbitrary file in rmtree() and remove_tree() calls known as CVE-2017-6512.

  Fedora 26: firefox Security Update (Jun 16)
 

- new upstream update (54.0)

  Fedora 26: network-manager-applet Security Update (Jun 16)
 

Update to version 1.8.2. The upstream release notes: https://mail.gnome.org/archives/ftp-release-list/2017-June/msg00015.html

  Fedora 26: mariadb Security Update (Jun 16)
 

**Rebase to 10.1.24** Plugin oqgraph enabled Plugin jemalloc enabled Sphinx engine enabled Build dependecies Bison and Libarchive added, others corrected Disabling Mroonga engine for i686 architecture, as it is not supported by MariaDB **Removed patches: (fixed by upstream)** Patch5: %{pkgnamepatch}-file-contents.patch Patch14: %{pkgnamepatch}-example-config-

  Fedora 25: gajim Security Update (Jun 15)
 

Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability of delivery recipes * Many minor

  Fedora 25: ettercap Security Update (Jun 15)
 

FIx for CVE-2017-8366

  Fedora 24: gajim Security Update (Jun 15)
 

Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability of delivery recipes * Many minor

  Fedora 24: ettercap Security Update (Jun 15)
 

FIx for CVE-2017-8366

  Fedora 24: libsndfile Security Update (Jun 15)
 

fixes buffer overflows for flac and pcm

  Fedora 24: webkitgtk4 Security Update (Jun 15)
 

This update addresses the following vulnerabilities: * [CVE-2017-2496](https://www.cve.org/CVERecord?id=CVE-2017-2496), [CVE-2017-2539](https://www.cve.org/CVERecord?id=CVE-2017-2539), [CVE-2017-2510](https://www.cve.org/CVERecord?id=CVE-2017-2510) Additional fixes: * Fix URL shown in the title of beforeunload dialogs. * Focus

  Fedora 24: poppler Security Update (Jun 15)
 

CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents

 
  (Jun 22)
 

Multiple vulnerabilities have been found in Vim and gVim, the worst of which might allow remote attackers to execute arbitrary code.

  (Jun 22)
 

An out-of-bounds write in Graphite might allow remote attackers to execute arbitrary code.

  (Jun 22)
 

Multiple vulnerabilities have been found in jbig2dec, the worst of which might allow remote attackers to execute arbitrary code.

  (Jun 22)
 

Multiple vulnerabilities have been found in Urban Terror, the worst of which allows for the remote execution of arbitrary code.

  (Jun 22)
 

Multiple vulnerabilities have been found in libksba which might allow remote attackers to obtain sensitive information or crash an libksba-based application. [More...]

  (Jun 22)
 

A cache-related side channel vulnerability was found in nettle which might allow an attacker to obtain sensitive information.

  (Jun 20)
 

Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code.

  (Jun 20)
 

Multiple vulnerabilities have been found in the GNU C Library, the worst of which may allow execution of arbitrary code.

  (Jun 20)
 

Multiple vulnerabilities have been found in mbed TLS, the worst of which could lead to the remote execution of arbitrary code.

  (Jun 20)
 

Multiple vulnerabilities have been found in Kodi, the worst of which could allow remote attackers to execute arbitrary code.

  (Jun 20)
 

A header injection vulnerability in GNU Wget might allow remote attackers to inject arbitrary HTTP headers.

 
  Slackware: 2017-172-01: openvpn Security Update (Jun 21)
 

New openvpn packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

  Slackware: 2017-165-02: mozilla-firefox Security Update (Jun 15)
 

New mozilla-firefox packages are available for Slackware 14.2, and -current to fix security issues.

  Slackware: 2017-165-01: bind Security Update (Jun 15)
 

New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

 
  SuSE: 2017:1660-1: important: tomcat (Jun 23)
 

An update that fixes 12 vulnerabilities is now available. An update that fixes 12 vulnerabilities is now available. An update that fixes 12 vulnerabilities is now available.

  SuSE: 2017:1642-1: important: openvpn (Jun 21)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  SuSE: 2017:1635-1: important: openvpn (Jun 21)
 

An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

  openSUSE: 2017:1633-1: important: the Linux Kernel (Jun 21)
 

An update that solves four vulnerabilities and has 35 fixes An update that solves four vulnerabilities and has 35 fixes An update that solves four vulnerabilities and has 35 fixes is now available. is now available.

  SuSE: 2017:1632-1: important: tomcat6 (Jun 21)
 

An update that solves 10 vulnerabilities and has one errata An update that solves 10 vulnerabilities and has one errata An update that solves 10 vulnerabilities and has one errata is now available. is now available.

  openSUSE: 2017:1629-1: important: glibc (Jun 20)
 

An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

  SuSE: 2017:1628-1: critical: the Linux Kernel (Jun 20)
 

An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes is now available. is now available.

  SuSE: 2017:1627-1: important: sudo (Jun 20)
 

An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

  SuSE: 2017:1626-1: important: sudo (Jun 20)
 

An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

  openSUSE: 2017:1625-1: important: exim (Jun 20)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  SuSE: 2017:1622-1: important: openvpn (Jun 20)
 

An update that solves three vulnerabilities and has one An update that solves three vulnerabilities and has one An update that solves three vulnerabilities and has one errata is now available. errata is now available.

  SuSE: 2017:1621-1: important: glibc (Jun 19)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  openSUSE: 2017:1620-1: important: Mozilla based packages (Jun 19)
 

An update that fixes 26 vulnerabilities is now available. An update that fixes 26 vulnerabilities is now available. An update that fixes 26 vulnerabilities is now available.

  SuSE: 2017:1619-1: important: glibc (Jun 19)
 

An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

  SuSE: 2017:1614-1: important: glibc (Jun 19)
 

An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes is now available. is now available.

  SuSE: 2017:1615-1: critical: the Linux Kernel (Jun 19)
 

An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

  SuSE: 2017:1618-1: critical: the Linux Kernel (Jun 19)
 

An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

  SuSE: 2017:1613-1: critical: the Linux Kernel (Jun 19)
 

An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

  SuSE: 2017:1611-1: important: glibc (Jun 19)
 

An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes is now available. is now available.

  SuSE: 2017:1606-1: important: mercurial (Jun 19)
 

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

  openSUSE: 2017:1572-1: important: mercurial (Jun 15)
 

An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

 
  Ubuntu 3339-1: OpenVPN vulnerabilities (Jun 22)
 

Several security issues were fixed in OpenVPN.

  Ubuntu 0024-1: Linux kernel vulnerability (Jun 22)
 

Several security issues were fixed in the kernel.

  Ubuntu 3338-1: Linux kernel vulnerabilities (Jun 21)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3335-2: Linux kernel (Trusty HWE) vulnerability (Jun 21)
 

The system could be made to run programs as an administrator.

  Ubuntu 3337-1: Valgrind vulnerabilities (Jun 21)
 

Valgrind could be made to crash or run programs if it opened a specially crafted file.

  Ubuntu 3336-1: NSS vulnerability (Jun 21)
 

NSS could be made to crash if it received specially crafted network traffic.

  Ubuntu 3334-1: Linux kernel (Xenial HWE) vulnerabilities (Jun 20)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3332-1: Linux kernel (Raspberry Pi 2) vulnerabilities (Jun 20)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3331-1: Linux kernel (AWS) vulnerabilities (Jun 20)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3333-1: Linux kernel (HWE) vulnerabilities (Jun 20)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3335-1: Linux kernel vulnerabilities (Jun 20)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3330-1: Linux kernel (Qualcomm Snapdragon) vulnerabilities (Jun 20)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3325-1: Linux kernel (Raspberry Pi 2) vulnerabilities (Jun 20)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3328-1: Linux kernel vulnerabilities (Jun 20)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3329-1: Linux kernel vulnerabilities (Jun 20)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3326-1: Linux kernel (Jun 20)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3327-1: Linux kernel (Raspberry Pi 2) vulnerabilities (Jun 20)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3324-1: Linux kernel vulnerabilities (Jun 20)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 3311-2: libnl vulnerability (Jun 19)
 

libnl could be made to run programs as an administrator.

  Ubuntu 3322-1: Exim vulnerability (Jun 19)
 

Exim could be made to run programs as an administrator.

  Ubuntu 3323-1: GNU C Library vulnerability (Jun 19)
 

Gnu C library could be made to run programs as an administrator.

  Ubuntu 3319-1: libmwaw vulnerability (Jun 15)
 

libmwaw could be made to crash or run programs as your login if it opened a specially crafted file.

  Ubuntu 3320-1: zziplib vulnerabilities (Jun 15)
 

zziplib could be made to crash or run programs as your login if it opened a specially crafted file.

  Ubuntu 3315-1: Firefox vulnerabilities (Jun 15)
 

Firefox could be made to crash or run programs as your login if it opened a malicious website.