Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system. Vulnerabilities affect nearly every vendor virtually every week, so be sure to read through to find the updates your distributor have made available.

LinuxSecurity.com Feature Extras:

IBM Closes its $34 Billion Acquisition of Red Hat: A Monumental Moment for Open Source - In the tech giants largest deal ever and one of the biggest deals in US history, IBM closed its $34 billion acquisition of Red Hat on Tuesday July 9, 2019. Red Hat will now be a unit of IBMs hybrid cloud division and Red Hat CEO Jim Whitehurst will join IBMs senior management team. This event has significant meaning that extends beyond is monetary value: it is a testament to the power of Open Source and the opportunity it offers businesses of all sizes across all industries.

Guardian Digital Celebrates 20 Years of Revolutionizing Digital Security, Securing Email with Open Source - Pioneers of business email security for the past 20 years, Guardian Digital draws on the merits of Open Source coupled with expert engineering and unparalleled customer support.


  Debian: DSA-4483-1: libreoffice security update (Jul 16)
 

Two security issues have been discovered in LibreOffice: CVE-2019-9848

  Debian: DSA-4482-1: thunderbird security update (Jul 14)
 

Multiple security issues have been found in Thunderbird which could potentially result in the execution of arbitrary code, cross-site scripting, spoofing, information disclosure, denial of service or cross-site request forgery.

  Debian: DSA-4481-1: ruby-mini-magick security update (Jul 13)
 

Harsh Jaiswal discovered a remote shell execution vulnerability in ruby-mini-magick, a Ruby library providing a wrapper around ImageMagick or GraphicsMagick, exploitable when using MiniMagick::Image.open with specially crafted URLs coming from unsanitized user input.

  Debian: DSA-4480-1: redis security update (Jul 11)
 

Multiple vulnerabilities were discovered in the HyperLogLog implementation of Redis, a persistent key-value database, which could result in denial of service or potentially the execution of arbitrary code.

  Debian: DSA-4479-1: firefox-esr security update (Jul 11)
 

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, cross-site scripting, spoofing, information disclosure, denial of service or cross-site request forgery.


  Fedora 29: kernel FEDORA-2019-a95015e60f (Jul 18)
 

Update to v5.1.18 ---- Update to v5.1.17

  Fedora 29: kernel-headers FEDORA-2019-a95015e60f (Jul 18)
 

Update to v5.1.18 ---- Update to v5.1.17

  Fedora 29: knot-resolver FEDORA-2019-20f95b0b39 (Jul 18)
 

- fixes security issues CVE-2019-10190 and CVE-2019-10191 -

  Fedora 30: knot-resolver FEDORA-2019-fdb50c675d (Jul 18)
 

- fixes security issues CVE-2019-10190 and CVE-2019-10191 -

  Fedora 29: freetds FEDORA-2019-14d102033e (Jul 18)
 

Upgrade to 1.1.11

  Fedora 30: freetds FEDORA-2019-f74072a45d (Jul 18)
 

Upgrade to 1.1.11

  Fedora 29: expat FEDORA-2019-139fcda84d (Jul 15)
 

This update includes a fix for a security vulnerability, CVE-2018-20843: > Fix extraction of namespace prefixes from XML names; XML names with multiple colons could end up in the wrong namespace, and take a high amount of RAM and CPU resources while processing, opening the door to use for denial-of-service attacks For more information on the changes in 2.2.7, see the upstream release

  Fedora 29: radare2 FEDORA-2019-e612286002 (Jul 15)
 

Rebase to radare2 3.6.0 and fixes CVE-2019-12790 and CVE-2019-12802

  Fedora 29: snapd-glib FEDORA-2019-bc3dfb389f (Jul 12)
 

#### Update to v1.48 * New API: - `snapd_client_get_connections_async` - `snapd_client_get_connections_finish` - `snapd_client_get_connections_sync` - `snapd_client_get_interfaces2_async` - `snapd_client_get_interfaces2_finish` - `snapd_client_get_interfaces2_sync` - `snapd_client_get_snap_conf_async`

  Fedora 30: thunderbird FEDORA-2019-83c570c2eb (Jul 12)
 

- New upstream version (60.8.0)

  Fedora 30: snapd-glib FEDORA-2019-b6612c5fe5 (Jul 12)
 

#### Update to v1.48 * New API: - `snapd_client_get_connections_async` - `snapd_client_get_connections_finish` - `snapd_client_get_connections_sync` - `snapd_client_get_interfaces2_async` - `snapd_client_get_interfaces2_finish` - `snapd_client_get_interfaces2_sync` - `snapd_client_get_snap_conf_async`

  Fedora 30: fossil FEDORA-2019-f350634b40 (Jul 12)
 

- Update to 2.8 fixes rhbz#1581180 rhbz#1603993 rhbz#1674893 and rhbz#1524335 - Removed upstreamed patch - Bug 1524335 - CVE-2017-17459 fossil: Command injection via malicious ssh URLs [fedora-all] - Bug 1581180 - Update fossil version to 2.6 (currently is 2.2) - Bug 1603993 - fossil: FTBFS in Fedora rawhide - Bug 1674893 - fossil: FTBFS in Fedora rawhide/f30

  Fedora 30: python-django FEDORA-2019-d9aa58d863 (Jul 12)
 

update to 2.1.10, security fix for CVE-2019-12781


  RedHat: RHSA-2019-1799:01 Important: thunderbird security and bug fix update (Jul 16)
 

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-1797:01 Important: Red Hat JBoss BPM Suite 6.4.12 (Jul 16)
 

An update is now available for Red Hat JBoss BPM Suite. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-1793:01 Important: vim security update (Jul 16)
 

An update for vim is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2019-1792:01 Important: keepalived security update (Jul 16)
 

An update for keepalived is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2019-1791:01 Important: libssh2 security update (Jul 16)
 

An update for libssh2 is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2019-1790:01 Important: perl security update (Jul 16)
 

An update for perl is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2019-1789:01 Important: 389-ds-base security update (Jul 16)
 

An update for 389-ds-base is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2019-1782:01 Important: Red Hat JBoss BRMS 6.4.12 security (Jul 15)
 

An update is now available for Red Hat JBoss BRMS. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-1777:01 Important: thunderbird security update (Jul 15)
 

An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-1774:01 Important: vim security update (Jul 15)
 

An update for vim is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-1775:01 Important: thunderbird security update (Jul 15)
 

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-1771:01 Important: cyrus-imapd security update (Jul 15)
 

An update for cyrus-imapd is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-1763:01 Critical: firefox security update (Jul 11)
 

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-1765:01 Critical: firefox security update (Jul 11)
 

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-1764:01 Critical: firefox security update (Jul 11)
 

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-1762:01 Important: virt:8.0.0 security update (Jul 11)
 

An update for the virt:8.0.0 module is now available for Red Hat Enterprise Linux 8 Advanced Virtualization. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,


  Slackware: 2019-195-01: bzip2 Security Update (Jul 14)
 

New bzip2 packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.


  SUSE: 2019:1895-1 moderate: tomcat (Jul 18)
 

An update that solves two vulnerabilities and has one errata is now available.

  SUSE: 2019:1896-1 moderate: libxml2 (Jul 18)
 

An update that solves one vulnerability and has two fixes is now available.

  SUSE: 2019:14127-1 important: the Linux Kernel (Jul 18)
 

An update that solves 7 vulnerabilities and has four fixes is now available.

  SUSE: 2019:1894-1 moderate: LibreOffice (Jul 18)
 

An update that solves one vulnerability and has 11 fixes is now available.

  SUSE: 2019:1888-1 important: the Linux Kernel (Live Patch 2 for SLE 15 SP1) (Jul 18)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1882-1 important: the Linux Kernel (Live Patch 9 for SLE 15) (Jul 18)
 

An update that fixes three vulnerabilities is now available.

  SUSE: 2019:1889-1 important: the Linux Kernel (Live Patch 0 for SLE 15 SP1) (Jul 18)
 

An update that fixes two vulnerabilities is now available.

  SUSE: 2019:1877-1 moderate: glibc (Jul 18)
 

An update that solves two vulnerabilities and has three fixes is now available.

  SUSE: 2019:1866-1 moderate: tomcat (Jul 17)
 

An update that fixes three vulnerabilities is now available.

  SUSE: 2019:14124-1 important: MozillaFirefox (Jul 17)
 

An update that fixes 12 vulnerabilities is now available.

  SUSE: 2019:1867-1 moderate: libxslt (Jul 17)
 

An update that fixes two vulnerabilities is now available.

  SUSE: 2019:1869-1 important: MozillaFirefox (Jul 17)
 

An update that fixes 10 vulnerabilities is now available.

  SUSE: 2019:1870-1 important: the Linux Kernel (Jul 17)
 

An update that solves 7 vulnerabilities and has three fixes is now available.

  SUSE: 2019:1861-1 important: MozillaFirefox (Jul 17)
 

An update that fixes 10 vulnerabilities is now available.

  SUSE: 2019:1862-1 important: ardana and crowbar (Jul 17)
 

An update that solves 5 vulnerabilities and has 10 fixes is now available.

  SUSE: 2019:1860-1 important: xrdp (Jul 16)
 

An update that solves three vulnerabilities and has 7 fixes is now available.

  SUSE: 2019:1859-1 moderate: libgcrypt (Jul 16)
 

An update that solves one vulnerability and has two fixes is now available.

  SUSE: 2019:1364-2 moderate: systemd (Jul 15)
 

An update that solves four vulnerabilities and has 9 fixes is now available.

  SUSE: 2019:1852-1 important: the Linux Kernel (Jul 15)
 

An update that solves 11 vulnerabilities and has 29 fixes is now available.

  SUSE: 2019:1849-1 moderate: podofo (Jul 15)
 

An update that fixes 5 vulnerabilities is now available.

  SUSE: 2019:14122-1 important: bzip2 (Jul 15)
 

An update that fixes two vulnerabilities is now available.

  SUSE: 2019:1850-1 important: webkit2gtk3 (Jul 15)
 

An update that fixes 20 vulnerabilities is now available.

  SUSE: 2019:1847-1 important: xrdp (Jul 15)
 

An update that solves three vulnerabilities and has 5 fixes is now available.

  SUSE: 2019:1846-1 important: bzip2 (Jul 15)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1823-2 important: the Linux Kernel (Jul 15)
 

An update that solves 11 vulnerabilities and has two fixes is now available.

  SUSE: 2019:1838-1 important: Test SUSE:SLE-12-SP5 (Jul 12)
 

An update that contains security fixes can now be installed.

  SUSE: 2019:1830-1 important: glib2 (Jul 12)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2019:1834-1 moderate: expat (Jul 12)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1833-1 moderate: glib2 (Jul 12)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1832-1 moderate: php7 (Jul 12)
 

An update that fixes two vulnerabilities is now available.

  SUSE: 2019:1835-1 moderate: expat (Jul 12)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1826-1 important: bubblewrap (Jul 12)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1825-1 moderate: tomcat (Jul 12)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1352-2 moderate: python3 (Jul 12)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2019:1824-1 important: glib2 (Jul 12)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1823-1 important: the Linux Kernel (Jul 12)
 

An update that solves 11 vulnerabilities and has two fixes is now available.

  SUSE: 2019:1793-1 important: Test SUSE:SLE-12-SP5 (Jul 11)
 

An update that contains security fixes can now be installed.

  SUSE: 2019:1819-1 fence-agents (Jul 11)
 

An update that solves one vulnerability and has one errata is now available.


  Ubuntu: Ubuntu 18.10 (Cosmic Cuttlefish) End of Life reached on July 18 2019 (Jul 18)
 

  Ubuntu 4066-1: libmspack vulnerability (Jul 18)
 

libmspack could be made to expose sensitive information if it received a specially crafted CHM file.

  Ubuntu 4065-1: Squid vulnerabilities (Jul 18)
 

Several security issues were fixed in Squid.

  Ubuntu 4064-1: Thunderbird vulnerabilities (Jul 17)
 

Several security issues were fixed in Thunderbird.

  Ubuntu 4063-1: LibreOffice vulnerabilities (Jul 17)
 

Several security issues were fixed in LibreOffice.

  Ubuntu 4059-2: Squid vulnerabilities (Jul 17)
 

Several security issues were fixed in Squid.

  Ubuntu 4062-1: WavPack vulnerabilities (Jul 16)
 

WavPack could be made to crash if it received a specially crafted WAV file.

  Ubuntu 4060-2: NSS vulnerabilities (Jul 16)
 

Several security issues were fixed in NSS.

  Ubuntu 4061-1: Redis vulnerabilities (Jul 16)
 

Several security issues were fixed in Redis.

  Ubuntu 4060-1: NSS vulnerabilities (Jul 16)
 

Several security issues were fixed in NSS.

  Ubuntu 4059-1: Squid vulnerabilities (Jul 15)
 

Several security issues were fixed in Squid.

  Ubuntu 4058-1: Bash vulnerability (Jul 15)
 

A system hardening measure could be bypassed.

  Ubuntu 4057-1: Zipios vulnerability (Jul 15)
 

Zipios could be made to crash or consume system resources if it received specially crafted input.

  Ubuntu 4056-1: Exiv2 vulnerabilities (Jul 15)
 

Several security issues were fixed in Exiv2.

  Ubuntu 4055-1: flightcrew vulnerabilities (Jul 15)
 

Several security issues were fixed in FlightCrew.

  Ubuntu 4054-1: Firefox vulnerabilities (Jul 12)
 

Firefox could be made to crash or run programs as your login if it opened a malicious website.


  Debian LTS: DLA-1833-2: bzip2 regression update (Jul 18)
 

The original fix for CVE-2019-12900 in bzip2, a high-quality block-sorting file compressor, introduces regressions when extracting

  Debian LTS: DLA-1854-1: libonig security update (Jul 17)
 

A use-after-free in onig_new_deluxe() in regext.c allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker

  Debian LTS: DLA-1853-1: libspring-java security update (Jul 13)
 

Vulnerabilities have been identified in libspring-java, a modular Java/J2EE application framework.

  Debian LTS: DLA-1852-1: python3.4 security update (Jul 11)
 

The urllib library in Python ships support for a second, not well known URL scheme for accessing local files ("local_file://"). This scheme can be used to circumvent protections that try to block local file access


  ArchLinux: 201907-6: chromium: multiple issues (Jul 17)
 

The package chromium before version 75.0.3770.142-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

  ArchLinux: 201907-5: squid: arbitrary code execution (Jul 17)
 

The package squid before version 4.8-1 is vulnerable to arbitrary code execution.

  ArchLinux: 201907-4: firefox: multiple issues (Jul 17)
 

The package firefox before version 68.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, cross-site request forgery, sandbox escape, arbitrary filesystem access, content spoofing, cross-site scripting, denial of service, information disclosure, insufficient validation and silent downgrade.


  CentOS: CESA-2019-1775: Important CentOS 7 thunderbird (Jul 17)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1775

  CentOS: CESA-2019-1774: Important CentOS 6 vim (Jul 17)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1774

  CentOS: CESA-2019-1777: Important CentOS 6 thunderbird (Jul 17)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1777

  CentOS: CESA-2019-1763: Critical CentOS 7 firefox (Jul 12)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1763

  CentOS: CESA-2019-1765: Critical CentOS 6 firefox (Jul 12)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1765

  CentOS: CESA-2019-1726: Important CentOS 6 dbus (Jul 11)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1726


  SciLinux: SLSA-2019-1777-1 Important: thunderbird on SL6.x i386/x86_64 (Jul 15)
 

This update upgrades Thunderbird to version 60.8.0. * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following [More...]

  SciLinux: SLSA-2019-1775-1 Important: thunderbird on SL7.x x86_64 (Jul 15)
 

This update upgrades Thunderbird to version 60.8.0. * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following [More...]

  SciLinux: SLSA-2019-1774-1 Important: vim on SL6.x i386/x86_64 (Jul 15)
 

vim/neovim: ':source!' command allows arbitrary command execution via modelines (CVE-2019-12735) SL6 x86_64 vim-X11-7.4.629-5.el6_10.2.x86_64.rpm vim-common-7.4.629-5.el6_10.2.x86_64.rpm vim-debuginfo-7.4.629-5.el6_10.2.x86_64.rpm vim-enhanced-7.4.629-5.el6_10.2.x86_64.rpm vim-filesystem-7.4.629-5.el6_10.2.x86_64.rpm vim-minimal-7.4.629-5.el6_10.2.x86_64.rpm i386 [More...]

  SciLinux: SLSA-2019-1765-1 Critical: firefox on SL6.x i386/x86_64 (Jul 11)
 

This update upgrades Firefox to version 60.8.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following [More...]

  SciLinux: SLSA-2019-1763-1 Critical: firefox on SL7.x x86_64 (Jul 11)
 

This update upgrades Firefox to version 60.8.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following [More...]


  openSUSE: 2019:1718-1: moderate: libqb (Jul 19)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2019:1719-1: fence-agents (Jul 19)
 

An update that solves one vulnerability and has one errata is now available.

  openSUSE: 2019:1721-1: important: bubblewrap (Jul 19)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2019:1723-1: moderate: tomcat (Jul 19)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2019:1708-1: moderate: libu2f-host, pam_u2f (Jul 19)
 

An update that fixes three vulnerabilities is now available.

  openSUSE: 2019:1702-1: moderate: monitoring-plugins (Jul 14)
 

An update that solves one vulnerability and has 11 fixes is now available.

  openSUSE: 2019:1703-1: moderate: helm (Jul 14)
 

An update that fixes three vulnerabilities is now available.


  Mageia 2019-0208: ffmpeg security update (Jul 11)
 

This update provides ffmpeg version 4.1.4, which fixes several security vulnerabilities and other bugs which were corrected upstream References: - https://bugs.mageia.org/show_bug.cgi?id=25109