[ubuntu/xenial-security] graphicsmagick 1.3.23-1ubuntu0.6 (Accepted)

2020-02-04 Thread Eduardo dos Santos Barretto
Date: 2020-02-04 17:55:15.020890+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.6 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https

[ubuntu/xenial-security] graphicsmagick 1.3.23-1ubuntu0.6 (Accepted)

2020-02-04 Thread Eduardo dos Santos Barretto
() - debian/patches/CVE-2017-18231.patch: Verify pBits memory allocation. - CVE-2017-18231 Date: 2020-02-04 17:55:15.020890+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.6 Sorry, changesfile not available.-- Xenial-changes mailing

[ubuntu/xenial-security] openjdk-8 8u242-b08-0ubuntu3~16.04 (Accepted)

2020-01-28 Thread Eduardo dos Santos Barretto
00 Changed-By: Tiago Stürmer Daitx Signed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/openjdk-8/8u242-b08-0ubuntu3~16.04 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.

[ubuntu/xenial-security] graphicsmagick 1.3.23-1ubuntu0.5 (Accepted)

2020-01-22 Thread Eduardo dos Santos Barretto
() - debian/patches/CVE-2017-17783.patch: Fix heap buffer overflow in Q8 build while initializing color palette. - CVE-2017-17783 Date: 2020-01-22 16:40:19.357787+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.5 Sorry

[ubuntu/xenial-security] sdl-image1.2 1.2.12-5+deb9u1ubuntu0.16.04.1 (Accepted)

2020-01-14 Thread Eduardo dos Santos Barretto
: validate image size when loading BMP files. - CVE-2019-13616 Date: 2020-01-14 13:22:07.870521+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/sdl-image1.2/1.2.12-5+deb9u1ubuntu0.16.04.1 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial

[ubuntu/xenial-security] graphicsmagick 1.3.23-1ubuntu0.4 (Accepted)

2020-01-08 Thread Eduardo dos Santos Barretto
UPDATE: Memory information disclosure in DescribeImage() - debian/patches/CVE-2017-16353.patch: Fix weaknesses while describing the IPTC profile. - CVE-2017-16353 Date: 2020-01-08 15:20:39.828370+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source

[ubuntu/xenial-security] graphicsmagick 1.3.23-1ubuntu0.3 (Accepted)

2019-12-16 Thread Eduardo dos Santos Barretto
.patch: Fix DOS issues. - CVE-2017-13776 - CVE-2017-13777 Date: 2019-12-16 14:52:14.979278+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.3 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes

[ubuntu/xenial-security] librabbitmq 0.7.1-1ubuntu0.2 (Accepted)

2019-12-11 Thread Eduardo dos Santos Barretto
rdo dos Santos Barretto https://launchpad.net/ubuntu/+source/librabbitmq/0.7.1-1ubuntu0.2 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/xenial-changes

[ubuntu/xenial-security] graphicsmagick 1.3.23-1ubuntu0.2 (Accepted)

2019-12-02 Thread Eduardo dos Santos Barretto
-11637 Date: 2019-12-02 17:10:16.441687+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.2 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https

[ubuntu/xenial-security] ruby-nokogiri 1.6.7.2-3ubuntu0.1 (Accepted)

2019-11-05 Thread Eduardo dos Santos Barretto
ruby-nokogiri (1.6.7.2-3ubuntu0.1) xenial-security; urgency=medium * SECURITY UPDATE: Command injection vulnerability. - debian/patches/CVE-2019-5477.patch: prefer File.open to Kernel.open. - CVE-2019-5477 Date: 2019-11-04 19:58:16.927948+00:00 Changed-By: Eduardo dos Santos Barretto

[ubuntu/xenial-security] uw-imap 8:2007f~dfsg-4+deb8u1build0.16.04.1 (Accepted)

2019-10-21 Thread Eduardo dos Santos Barretto
uw-imap (8:2007f~dfsg-4+deb8u1build0.16.04.1) xenial-security; urgency=medium * SECURITY UPDATE: Sync from Debian. - Fixes CVE-2018-19518. Date: 2019-10-21 18:04:14.503259+00:00 Changed-By: Eduardo dos Santos Barretto Maintainer: Magnus Holmgren https://launchpad.net/ubuntu/+source/uw

[ubuntu/xenial-security] ruby-rack 1.6.4-3ubuntu0.1 (Accepted)

2019-08-07 Thread Eduardo dos Santos Barretto
: 2019-08-07 15:17:14.116578+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/ruby-rack/1.6.4-3ubuntu0.1 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com

[ubuntu/xenial-security] sox 14.4.1-5+deb8u4ubuntu0.1 (Accepted)

2019-07-30 Thread Eduardo dos Santos Barretto
7-30 17:01:14.288185+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/sox/14.4.1-5+deb8u4ubuntu0.1 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listi

[ubuntu/xenial-security] tmpreaper 1.6.13+nmu1+deb9u1build0.16.04.1 (Accepted)

2019-07-29 Thread Eduardo dos Santos Barretto
tmpreaper (1.6.13+nmu1+deb9u1build0.16.04.1) xenial-security; urgency=medium * SECURITY UPDATE: Sync from Debian - fixes CVE-2019-3461. Date: 2019-07-29 14:21:13.887960+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/tmpreaper/1.6.13+nmu1

[ubuntu/xenial-security] redis 2:3.0.6-1ubuntu0.4 (Accepted)

2019-07-16 Thread Eduardo dos Santos Barretto
Klode Signed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/redis/2:3.0.6-1ubuntu0.4 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/xenial-changes

[ubuntu/xenial-security] zeromq3 4.1.4-7ubuntu0.1 (Accepted)

2019-07-08 Thread Eduardo dos Santos Barretto
-13132.patch: create buffers large enough to contain arbitrary metadata. - CVE-2019-13132 Date: 2019-07-08 16:09:15.911307+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/zeromq3/4.1.4-7ubuntu0.1 Sorry, changesfile not available.-- Xenial-changes mailing

[ubuntu/xenial-security] mosquitto 1.4.8-1ubuntu0.16.04.7 (Accepted)

2019-06-20 Thread Eduardo dos Santos Barretto
Date: 2019-06-19 19:08:13.166199+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/mosquitto/1.4.8-1ubuntu0.16.04.7 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https

[ubuntu/xenial-security] apparmor 2.10.95-0ubuntu2.11 (Accepted)

2019-06-05 Thread Eduardo dos Santos Barretto
denied. (LP: #1830802) - 0001-dnsmasq-allow-libvirt_leaseshelper-m-permission-on-i.patch - 0001-handle_children-automatically-add-m-permissions-on-i.patch Date: 2019-05-28 22:07:37.328480+00:00 Changed-By: Tyler Hicks Signed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu

[ubuntu/xenial-security] xmltooling 1.5.6-2ubuntu0.3 (Accepted)

2019-03-26 Thread Eduardo dos Santos Barretto
by an untrusted attacker. - debian/patches/CVE-2019-9628.patch - CVE-2019-9628 - https://shibboleth.net/community/advisories/secadv_20190311.txt - LP: #1819912 Date: 2019-03-21 17:38:17.608912+00:00 Changed-By: Etienne Dysli Metref Signed-By: Eduardo dos Santos Barretto https

[ubuntu/xenial-security] xml-security-c 1.7.3-1ubuntu0.1 (Accepted)

2019-03-13 Thread Eduardo dos Santos Barretto
12:30:36.369912+00:00 Changed-By: Alejandro Claro Signed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/xml-security-c/1.7.3-1ubuntu0.1 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https

[ubuntu/xenial-security] faad2 2.8.0~cvs20150510-1ubuntu0.1 (Accepted)

2019-02-26 Thread Eduardo dos Santos Barretto
-9218 - CVE-2017-9219 - CVE-2017-9220 - CVE-2017-9221 - CVE-2017-9222 - CVE-2017-9223 - CVE-2017-9253 - CVE-2017-9254 - CVE-2017-9255 - CVE-2017-9256 - CVE-2017-9257 Date: 2019-02-26 17:07:21.505412+00:00 Changed-By: Eduardo dos Santos Barretto https

[ubuntu/xenial-security] coturn 4.5.0.3-1ubuntu0.2 (Accepted)

2019-02-14 Thread Eduardo dos Santos Barretto
coturn (4.5.0.3-1ubuntu0.2) xenial-security; urgency=medium * Disable autotests on armhf for now as tests segfault (when tried multiple times). Date: 2019-02-14 19:11:33.030643+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/coturn/4.5.0.3-1ubuntu0.2

[ubuntu/xenial-security] mosquitto 1.4.8-1ubuntu0.16.04.6 (Accepted)

2019-02-14 Thread Eduardo dos Santos Barretto
mosquitto (1.4.8-1ubuntu0.16.04.6) xenial-security; urgency=medium * Fix regression in update for CVE-2018-12546. Date: 2019-02-13 20:23:12.640360+00:00 Changed-By: Roger Light Signed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/mosquitto/1.4.8-1ubuntu0.16.04.6 Sorry

[ubuntu/xenial-security] mosquitto 1.4.8-1ubuntu0.16.04.5 (Accepted)

2019-02-11 Thread Eduardo dos Santos Barretto
this information across broker restarts. - CVE-2018-12546 Date: 2019-02-11 13:17:12.946390+00:00 Changed-By: Roger Light Signed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/mosquitto/1.4.8-1ubuntu0.16.04.5 Sorry, changesfile not available.-- Xenial-changes mailing list

[ubuntu/xenial-security] jetty 6.1.26-5ubuntu0.1 (Accepted)

2019-01-30 Thread Eduardo dos Santos Barretto
jetty (6.1.26-5ubuntu0.1) xenial-security; urgency=medium * SECURITY UPDATE: Possible Timing Attack. - debian/patches/CVE-2017-9735.patch: A timing channel in Password.java. - CVE-2017-9735 Date: 2019-01-30 18:13:22.250855+00:00 Changed-By: Eduardo dos Santos Barretto https

[ubuntu/xenial-security] virtualbox 5.1.38-dfsg-0ubuntu1.16.04.2 (Accepted)

2019-01-22 Thread Eduardo dos Santos Barretto
Konrad Signed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/virtualbox/5.1.38-dfsg-0ubuntu1.16.04.2 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo

[ubuntu/xenial-security] krb5 1.13.2+dfsg-5ubuntu2.1 (Accepted)

2019-01-14 Thread Eduardo dos Santos Barretto
with permission to add principals to an LDAP Kerberos can DoS or bypass DN container check. - debian/patches/CVE-2018-5729-CVE-2018-5730.patch: Fix flaws in LDAP DN checking - CVE-2018-5729 - CVE-2018-5730 Date: 2019-01-14 14:23:16.443521+00:00 Changed-By: Eduardo dos Santos

[ubuntu/xenial-security] chrony 2.1.1-1ubuntu0.1 (Accepted)

2018-12-06 Thread Eduardo dos Santos Barretto
cified key. - CVE-2016-1567 Date: 2018-12-06 16:49:12.043844+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/chrony/2.1.1-1ubuntu0.1 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe

[ubuntu/xenial-security] mercurial 3.7.3-1ubuntu1.2 (Accepted)

2018-11-27 Thread Eduardo dos Santos Barretto
:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/mercurial/3.7.3-1ubuntu1.2 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/xenial-changes

[ubuntu/xenial-security] tor 0.2.9.14-1ubuntu1~16.04.3 (Accepted)

2018-11-22 Thread Eduardo dos Santos Barretto
:12.857577+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/tor/0.2.9.14-1ubuntu1~16.04.3 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo

[ubuntu/xenial-security] mercurial 3.7.3-1ubuntu1.1 (Accepted)

2018-11-22 Thread Eduardo dos Santos Barretto
. - CVE-2018-1000132 Date: 2018-11-22 17:57:12.046749+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/mercurial/3.7.3-1ubuntu1.1 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https

[ubuntu/xenial-security] graphicsmagick 1.3.23-1ubuntu0.1 (Accepted)

2018-11-05 Thread Eduardo dos Santos Barretto
imensions of the JPEG embedded in a JDAT chunk must match the JHDR dimensions. - CVE-2016-9830 Date: 2018-11-01 21:15:15.029983+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.1 Sorry, changesfile not available.-- Xe

[ubuntu/xenial-security] tomcat7 7.0.68-1ubuntu0.4 (Accepted)

2018-10-30 Thread Eduardo dos Santos Barretto
: remove policy directory. Date: 2018-10-30 15:00:21.735159+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/tomcat7/7.0.68-1ubuntu0.4 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe

[ubuntu/xenial-security] tomcat7 7.0.68-1ubuntu0.3 (Accepted)

2018-10-24 Thread Eduardo dos Santos Barretto
/tomcat7.init: further hardening. Date: 2018-10-24 19:24:15.823240+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/tomcat7/7.0.68-1ubuntu0.3 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe

[ubuntu/xenial-security] monit 1:5.16-2ubuntu0.2 (Accepted)

2018-10-01 Thread Eduardo dos Santos Barretto
-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/monit/1:5.16-2ubuntu0.2 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/xenial-changes

[ubuntu/xenial-security] opencv 2.4.9.1+dfsg-1.5ubuntu1.1 (Accepted)

2018-09-19 Thread Eduardo dos Santos Barretto
-By: Eduardo dos Santos Barretto Maintainer: Kubuntu Members https://launchpad.net/ubuntu/+source/opencv/2.4.9.1+dfsg-1.5ubuntu1.1 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo

[ubuntu/xenial-security] mpg123 1.22.4-1ubuntu0.1 (Accepted)

2018-09-06 Thread Eduardo dos Santos Barretto
- CVE-2017-10683 Date: 2018-09-06 16:24:17.671149+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/mpg123/1.22.4-1ubuntu0.1 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe

[ubuntu/xenial-security] mosquitto 1.4.8-1ubuntu0.16.04.4 (Accepted)

2018-09-06 Thread Eduardo dos Santos Barretto
values after reloading configuration by SIGHUP signal. - CVE-2017-7652 Date: 2018-09-06 14:41:19.684483+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/mosquitto/1.4.8-1ubuntu0.16.04.4 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial

[ubuntu/xenial-security] openjpeg2 2.1.2-1.1+deb9u2build0.1 (Accepted)

2018-09-03 Thread Eduardo dos Santos Barretto
, no changes needed Date: 2018-08-31 18:50:24.019443+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/openjpeg2/2.1.2-1.1+deb9u2build0.1 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe

[ubuntu/xenial-security] hdf5 1.8.16+docs-4ubuntu1.1 (Accepted)

2018-08-28 Thread Eduardo dos Santos Barretto
: 2018-08-28 18:24:13.180179+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/hdf5/1.8.16+docs-4ubuntu1.1 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com

[ubuntu/xenial-security] ffmpeg 7:2.8.15-0ubuntu0.16.04.1 (Accepted)

2018-08-23 Thread Eduardo dos Santos Barretto
ffmpeg (7:2.8.15-0ubuntu0.16.04.1) xenial-security; urgency=medium * SECURITY UPDATE: New upstream bugfix release. - Fixes CVE-2018-7557, CVE-2018-12458 and CVE-2018-13302. Date: 2018-08-23 14:30:13.159120+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source

[ubuntu/xenial-security] monit 1:5.16-2ubuntu0.1 (Accepted)

2018-08-13 Thread Eduardo dos Santos Barretto
Date: 2018-08-10 18:46:32.297863+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/monit/1:5.16-2ubuntu0.1 Sorry, changesfile not available.-- Xenial-changes mailing list Xenial-changes@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com

[ubuntu/xenial-security] libtomcrypt 1.17-7ubuntu0.1 (Accepted)

2018-08-06 Thread Eduardo dos Santos Barretto
signatures. - debian/patches/CVE-2018-12437.patch: fix in src/pk/ecc/ecc_sign_hash.c - CVE-2018-12437 Date: 2018-08-06 18:16:20.430797+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/libtomcrypt/1.17-7ubuntu0.1 Sorry, changesfile not available.-- Xenial

[ubuntu/xenial-security] jansson 2.7-3ubuntu0.1 (Accepted)

2018-08-01 Thread Eduardo dos Santos Barretto
jansson (2.7-3ubuntu0.1) xenial-security; urgency=medium * SECURITY UPDATE: Stack exhaustion parsing a JSON file - debian/patches/CVE-2016-4425.patch: Fix in src/load.c and src/jansson_config.h.in - CVE-2016-4425 Date: 2018-08-01 15:17:28.191606+00:00 Changed-By: Eduardo dos

[ubuntu/xenial-security] capnproto 0.5.3-2ubuntu1.1 (Accepted)

2018-07-31 Thread Eduardo dos Santos Barretto
capnproto (0.5.3-2ubuntu1.1) xenial-security; urgency=medium * SECURITY UPDATE: Prevent compiler from eliding bound checks. - debian/patches/CVE-2017-7892.patch: fix in src/capnp/arena.h - CVE-2017-7892 Date: 2018-07-31 12:58:13.405841+00:00 Changed-By: Eduardo dos Santos Barretto

[ubuntu/xenial-security] libonig 5.9.6-1ubuntu0.1 (Accepted)

2018-07-30 Thread Eduardo dos Santos Barretto
and regparse.c - CVE-2017-9224 - CVE-2017-9226 - CVE-2017-9227 - CVE-2017-9228 - CVE-2017-9229 Date: 2018-07-27 18:43:20.448509+00:00 Changed-By: Eduardo dos Santos Barretto https://launchpad.net/ubuntu/+source/libonig/5.9.6-1ubuntu0.1 Sorry, changesfile not available.-- Xenial-changes