[ubuntu/xenial-security] libtomcrypt 1.17-7ubuntu0.1 (Accepted)

2018-08-06 Thread Eduardo dos Santos Barretto
libtomcrypt (1.17-7ubuntu0.1) xenial-security; urgency=medium * SECURITY UPDATE: Fix possible bleichenbacher signature attack. - debian/patches/CVE-2016-6129.patch: fix in src/pk/rsa/rsa_verify_hash.c - CVE-2016-6129 * SECURITY UPDATE: Memory side-channel attack on ECDSA

[ubuntu/xenial-updates] libtomcrypt 1.17-7ubuntu0.1 (Accepted)

2018-08-06 Thread Ubuntu Archive Robot
libtomcrypt (1.17-7ubuntu0.1) xenial-security; urgency=medium * SECURITY UPDATE: Fix possible bleichenbacher signature attack. - debian/patches/CVE-2016-6129.patch: fix in src/pk/rsa/rsa_verify_hash.c - CVE-2016-6129 * SECURITY UPDATE: Memory side-channel attack on ECDSA

[ubuntu/xenial-security] znc 1.6.3-1ubuntu0.1 (Accepted)

2018-08-06 Thread Alex Murray
znc (1.6.3-1ubuntu0.1) xenial-security; urgency=medium * SECURITY UPDATE: Privilege escalation for non-admin users (LP: #1781925) - debian/patches/CVE-2018-14055-1.patch: Remove newlines from incoming network configuration change directives. Based on upstream patch. -

[ubuntu/xenial-security] gnupg 1.4.20-1ubuntu3.3 (Accepted)

2018-08-06 Thread Alex Murray
gnupg (1.4.20-1ubuntu3.3) xenial-security; urgency=medium * SECURITY UPDATE: full RSA key recovery via side-channel attack - debian/patches/CVE-2017-7526-1.patch: simplify loop in mpi/mpi-pow.c. - debian/patches/CVE-2017-7526-2.patch: use same computation for square and multiply

[ubuntu/xenial-updates] gnupg 1.4.20-1ubuntu3.3 (Accepted)

2018-08-06 Thread Ubuntu Archive Robot
gnupg (1.4.20-1ubuntu3.3) xenial-security; urgency=medium * SECURITY UPDATE: full RSA key recovery via side-channel attack - debian/patches/CVE-2017-7526-1.patch: simplify loop in mpi/mpi-pow.c. - debian/patches/CVE-2017-7526-2.patch: use same computation for square and multiply

[ubuntu/xenial-updates] znc 1.6.3-1ubuntu0.1 (Accepted)

2018-08-06 Thread Ubuntu Archive Robot
znc (1.6.3-1ubuntu0.1) xenial-security; urgency=medium * SECURITY UPDATE: Privilege escalation for non-admin users (LP: #1781925) - debian/patches/CVE-2018-14055-1.patch: Remove newlines from incoming network configuration change directives. Based on upstream patch. -

[ubuntu/xenial-updates] nux 4.0.8+16.04.20180622.2-0ubuntu1 (Accepted)

2018-08-06 Thread Łukasz Zemczak
nux (4.0.8+16.04.20180622.2-0ubuntu1) xenial; urgency=medium * debian/control: update Vcs * debian/nux-tools.preinst: - Restore backup config files before installing nux-tools, so that they will be updaded with the fixed versions (LP: #1768610) nux (4.0.8+16.04.20180613.1-0ubuntu1)

[ubuntu/xenial-security] libxcursor 1:1.1.14-1ubuntu0.16.04.2 (Accepted)

2018-08-06 Thread Leonidas S. Barbosa
libxcursor (1:1.1.14-1ubuntu0.16.04.2) xenial-security; urgency=medium * SECURITY UPDATE: Denial of service - debian/patches/CVE-2015-9262.patch: fix in src/library.c. - CVE-2015-9262 Date: 2018-08-02 15:01:13.519398+00:00 Changed-By: leo.barb...@canonical.com (Leonidas S. Barbosa)

[ubuntu/xenial-updates] openssl-ibmca 1.3.0-0ubuntu2.16.04.2 (Accepted)

2018-08-06 Thread Łukasz Zemczak
openssl-ibmca (1.3.0-0ubuntu2.16.04.2) xenial; urgency=medium * Apply upstream patch to resolve crashes when libssl attempts to initialise engine a few times too many. LP: #1543455 Date: 2018-07-24 15:32:08.880851+00:00 Changed-By: Dimitri John Ledkov Signed-By: Łukasz Zemczak

[ubuntu/xenial-security] lftp 4.6.3a-1ubuntu0.1 (Accepted)

2018-08-06 Thread Leonidas S. Barbosa
lftp (4.6.3a-1ubuntu0.1) xenial-security; urgency=medium * SECURITY UPDATE: Incorrectly sanitize remote file names - debian/patches/CVE-2018-10196.patch: fix in src/MirrorJob.cc. - CVE-2018-10196 Date: 2018-08-03 16:55:24.842833+00:00 Changed-By: leo.barb...@canonical.com (Leonidas S.

[ubuntu/xenial-proposed] linux-signed-azure 4.15.0-1019.19~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-signed-azure (4.15.0-1019.19~16.04.1) xenial; urgency=medium * Master version: 4.15.0-1019.19~16.04.1 Date: 2018-07-27 08:21:15.559269+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-signed-azure/4.15.0-1019.19~16.04.1 Sorry,

[ubuntu/xenial-proposed] linux-azure 4.15.0-1019.19~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-azure (4.15.0-1019.19~16.04.1) xenial; urgency=medium [ Ubuntu: 4.15.0-30.32 ] * CVE-2018-5390 - tcp: free batches of packets in tcp_prune_ofo_queue() - tcp: avoid collapses in tcp_prune_queue() if possible - tcp: detect malicious patterns in tcp_collapse_ofo_queue() -

[ubuntu/xenial-proposed] linux-meta-azure 4.15.0.1019.25 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-azure (4.15.0.1019.25) xenial; urgency=medium * Bump ABI 4.15.0-1019 Date: 2018-07-27 08:21:12.870682+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-azure/4.15.0.1019.25 Sorry, changesfile not available.-- Xenial-changes

[ubuntu/xenial-proposed] linux-meta-azure-edge 4.15.0.1019.16 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-azure-edge (4.15.0.1019.16) xenial; urgency=medium * Bump ABI 4.15.0-1019 Date: 2018-07-27 11:41:13.432373+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-azure-edge/4.15.0.1019.16 Sorry, changesfile not available.--

[ubuntu/xenial-proposed] linux-azure_4.15.0-1019.19~16.04.1_amd64.tar.gz - (Accepted)

2018-08-06 Thread Stefan Bader
linux-azure (4.15.0-1019.19~16.04.1) xenial; urgency=medium [ Ubuntu: 4.15.0-30.32 ] * CVE-2018-5390 - tcp: free batches of packets in tcp_prune_ofo_queue() - tcp: avoid collapses in tcp_prune_queue() if possible - tcp: detect malicious patterns in tcp_collapse_ofo_queue() -

[ubuntu/xenial-proposed] linux-hwe_4.15.0-30.32~16.04.1_ppc64el.tar.gz - (Accepted)

2018-08-06 Thread Stefan Bader
linux-hwe (4.15.0-30.32~16.04.1) xenial; urgency=medium * CVE-2018-5390 - tcp: free batches of packets in tcp_prune_ofo_queue() - tcp: avoid collapses in tcp_prune_queue() if possible - tcp: detect malicious patterns in tcp_collapse_ofo_queue() - tcp: call tcp_drop() from

[ubuntu/xenial-proposed] linux-hwe_4.15.0-30.32~16.04.1_amd64.tar.gz - (Accepted)

2018-08-06 Thread Stefan Bader
linux-hwe (4.15.0-30.32~16.04.1) xenial; urgency=medium * CVE-2018-5390 - tcp: free batches of packets in tcp_prune_ofo_queue() - tcp: avoid collapses in tcp_prune_queue() if possible - tcp: detect malicious patterns in tcp_collapse_ofo_queue() - tcp: call tcp_drop() from

[ubuntu/xenial-updates] libxcursor 1:1.1.14-1ubuntu0.16.04.2 (Accepted)

2018-08-06 Thread Ubuntu Archive Robot
libxcursor (1:1.1.14-1ubuntu0.16.04.2) xenial-security; urgency=medium * SECURITY UPDATE: Denial of service - debian/patches/CVE-2015-9262.patch: fix in src/library.c. - CVE-2015-9262 Date: 2018-08-02 15:01:13.519398+00:00 Changed-By: leo.barb...@canonical.com (Leonidas S. Barbosa)

[ubuntu/xenial-proposed] linux-gcp 4.15.0-1015.15~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-gcp (4.15.0-1015.15~16.04.1) xenial; urgency=medium [ Ubuntu: 4.15.0-30.32 ] * CVE-2018-5390 - tcp: free batches of packets in tcp_prune_ofo_queue() - tcp: avoid collapses in tcp_prune_queue() if possible - tcp: detect malicious patterns in tcp_collapse_ofo_queue() -

[ubuntu/xenial-proposed] linux-meta-hwe 4.15.0.30.52 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-hwe (4.15.0.30.52) xenial; urgency=medium * Bump ABI 4.15.0-30 Date: 2018-07-27 11:15:12.440680+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.15.0.30.52 Sorry, changesfile not available.-- Xenial-changes mailing

[ubuntu/xenial-proposed] linux-meta-gcp 4.15.0.1015.27 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-gcp (4.15.0.1015.27) xenial; urgency=medium * Bump ABI 4.15.0-1015 Date: 2018-07-27 08:23:13.088331+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-gcp/4.15.0.1015.27 Sorry, changesfile not available.-- Xenial-changes

[ubuntu/xenial-proposed] linux-hwe 4.15.0-30.32~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-hwe (4.15.0-30.32~16.04.1) xenial; urgency=medium * CVE-2018-5390 - tcp: free batches of packets in tcp_prune_ofo_queue() - tcp: avoid collapses in tcp_prune_queue() if possible - tcp: detect malicious patterns in tcp_collapse_ofo_queue() - tcp: call tcp_drop() from

[ubuntu/xenial-proposed] linux-signed-hwe 4.15.0-30.32~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-signed-hwe (4.15.0-30.32~16.04.1) xenial; urgency=medium * Master version: 4.15.0-30.32~16.04.1 Date: 2018-07-27 11:15:16.716923+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-signed-hwe/4.15.0-30.32~16.04.1 Sorry, changesfile not

[ubuntu/xenial-proposed] linux-meta-hwe-edge 4.15.0.30.51 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-hwe-edge (4.15.0.30.51) xenial; urgency=medium * Bump ABI 4.15.0-30 Date: 2018-07-27 11:39:12.362392+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-hwe-edge/4.15.0.30.51 Sorry, changesfile not available.-- Xenial-changes

[ubuntu/xenial-updates] linux-meta-azure 4.15.0.1019.25 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-azure (4.15.0.1019.25) xenial; urgency=medium * Bump ABI 4.15.0-1019 Date: 2018-07-27 08:21:12.870682+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-azure/4.15.0.1019.25 Sorry, changesfile not available.-- Xenial-changes

[ubuntu/xenial-updates] linux-azure 4.15.0-1019.19~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-azure (4.15.0-1019.19~16.04.1) xenial; urgency=medium [ Ubuntu: 4.15.0-30.32 ] * CVE-2018-5390 - tcp: free batches of packets in tcp_prune_ofo_queue() - tcp: avoid collapses in tcp_prune_queue() if possible - tcp: detect malicious patterns in tcp_collapse_ofo_queue() -

[ubuntu/xenial-security] linux-signed-azure 4.15.0-1019.19~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-signed-azure (4.15.0-1019.19~16.04.1) xenial; urgency=medium * Master version: 4.15.0-1019.19~16.04.1 Date: 2018-07-27 08:21:15.559269+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-signed-azure/4.15.0-1019.19~16.04.1 Sorry,

[ubuntu/xenial-security] linux-gcp 4.15.0-1015.15~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-gcp (4.15.0-1015.15~16.04.1) xenial; urgency=medium [ Ubuntu: 4.15.0-30.32 ] * CVE-2018-5390 - tcp: free batches of packets in tcp_prune_ofo_queue() - tcp: avoid collapses in tcp_prune_queue() if possible - tcp: detect malicious patterns in tcp_collapse_ofo_queue() -

[ubuntu/xenial-security] linux-azure 4.15.0-1019.19~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-azure (4.15.0-1019.19~16.04.1) xenial; urgency=medium [ Ubuntu: 4.15.0-30.32 ] * CVE-2018-5390 - tcp: free batches of packets in tcp_prune_ofo_queue() - tcp: avoid collapses in tcp_prune_queue() if possible - tcp: detect malicious patterns in tcp_collapse_ofo_queue() -

[ubuntu/xenial-updates] linux-signed-azure 4.15.0-1019.19~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-signed-azure (4.15.0-1019.19~16.04.1) xenial; urgency=medium * Master version: 4.15.0-1019.19~16.04.1 Date: 2018-07-27 08:21:15.559269+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-signed-azure/4.15.0-1019.19~16.04.1 Sorry,

[ubuntu/xenial-updates] linux-gcp 4.15.0-1015.15~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-gcp (4.15.0-1015.15~16.04.1) xenial; urgency=medium [ Ubuntu: 4.15.0-30.32 ] * CVE-2018-5390 - tcp: free batches of packets in tcp_prune_ofo_queue() - tcp: avoid collapses in tcp_prune_queue() if possible - tcp: detect malicious patterns in tcp_collapse_ofo_queue() -

[ubuntu/xenial-security] linux-meta-azure 4.15.0.1019.25 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-azure (4.15.0.1019.25) xenial; urgency=medium * Bump ABI 4.15.0-1019 Date: 2018-07-27 08:21:12.870682+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-azure/4.15.0.1019.25 Sorry, changesfile not available.-- Xenial-changes

[ubuntu/xenial-updates] linux-meta-azure-edge 4.15.0.1019.16 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-azure-edge (4.15.0.1019.16) xenial; urgency=medium * Bump ABI 4.15.0-1019 Date: 2018-07-27 11:41:13.432373+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-azure-edge/4.15.0.1019.16 Sorry, changesfile not available.--

[ubuntu/xenial-security] linux-meta-azure-edge 4.15.0.1019.16 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-azure-edge (4.15.0.1019.16) xenial; urgency=medium * Bump ABI 4.15.0-1019 Date: 2018-07-27 11:41:13.432373+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-azure-edge/4.15.0.1019.16 Sorry, changesfile not available.--

[ubuntu/xenial-updates] linux-meta-hwe 4.15.0.30.52 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-hwe (4.15.0.30.52) xenial; urgency=medium * Bump ABI 4.15.0-30 Date: 2018-07-27 11:15:12.440680+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.15.0.30.52 Sorry, changesfile not available.-- Xenial-changes mailing

[ubuntu/xenial-security] linux-meta-hwe-edge 4.15.0.30.51 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-hwe-edge (4.15.0.30.51) xenial; urgency=medium * Bump ABI 4.15.0-30 Date: 2018-07-27 11:39:12.362392+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-hwe-edge/4.15.0.30.51 Sorry, changesfile not available.-- Xenial-changes

[ubuntu/xenial-updates] linux-hwe 4.15.0-30.32~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-hwe (4.15.0-30.32~16.04.1) xenial; urgency=medium * CVE-2018-5390 - tcp: free batches of packets in tcp_prune_ofo_queue() - tcp: avoid collapses in tcp_prune_queue() if possible - tcp: detect malicious patterns in tcp_collapse_ofo_queue() - tcp: call tcp_drop() from

[ubuntu/xenial-security] linux-hwe 4.15.0-30.32~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-hwe (4.15.0-30.32~16.04.1) xenial; urgency=medium * CVE-2018-5390 - tcp: free batches of packets in tcp_prune_ofo_queue() - tcp: avoid collapses in tcp_prune_queue() if possible - tcp: detect malicious patterns in tcp_collapse_ofo_queue() - tcp: call tcp_drop() from

[ubuntu/xenial-security] linux-signed-hwe 4.15.0-30.32~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-signed-hwe (4.15.0-30.32~16.04.1) xenial; urgency=medium * Master version: 4.15.0-30.32~16.04.1 Date: 2018-07-27 11:15:16.716923+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-signed-hwe/4.15.0-30.32~16.04.1 Sorry, changesfile not

[ubuntu/xenial-updates] linux-meta-hwe-edge 4.15.0.30.51 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-hwe-edge (4.15.0.30.51) xenial; urgency=medium * Bump ABI 4.15.0-30 Date: 2018-07-27 11:39:12.362392+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-hwe-edge/4.15.0.30.51 Sorry, changesfile not available.-- Xenial-changes

[ubuntu/xenial-security] linux-meta-gcp 4.15.0.1015.27 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-gcp (4.15.0.1015.27) xenial; urgency=medium * Bump ABI 4.15.0-1015 Date: 2018-07-27 08:23:13.088331+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-gcp/4.15.0.1015.27 Sorry, changesfile not available.-- Xenial-changes

[ubuntu/xenial-updates] linux-meta-gcp 4.15.0.1015.27 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-gcp (4.15.0.1015.27) xenial; urgency=medium * Bump ABI 4.15.0-1015 Date: 2018-07-27 08:23:13.088331+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-gcp/4.15.0.1015.27 Sorry, changesfile not available.-- Xenial-changes

[ubuntu/xenial-updates] lftp 4.6.3a-1ubuntu0.1 (Accepted)

2018-08-06 Thread Ubuntu Archive Robot
lftp (4.6.3a-1ubuntu0.1) xenial-security; urgency=medium * SECURITY UPDATE: Incorrectly sanitize remote file names - debian/patches/CVE-2018-10196.patch: fix in src/MirrorJob.cc. - CVE-2018-10196 Date: 2018-08-03 16:55:24.842833+00:00 Changed-By: leo.barb...@canonical.com (Leonidas S.

[ubuntu/xenial-updates] linux-signed-hwe 4.15.0-30.32~16.04.1 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-signed-hwe (4.15.0-30.32~16.04.1) xenial; urgency=medium * Master version: 4.15.0-30.32~16.04.1 Date: 2018-07-27 11:15:16.716923+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-signed-hwe/4.15.0-30.32~16.04.1 Sorry, changesfile not

[ubuntu/xenial-security] linux-meta-hwe 4.15.0.30.52 (Accepted)

2018-08-06 Thread Andy Whitcroft
linux-meta-hwe (4.15.0.30.52) xenial; urgency=medium * Bump ABI 4.15.0-30 Date: 2018-07-27 11:15:12.440680+00:00 Changed-By: Stefan Bader Signed-By: Andy Whitcroft https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.15.0.30.52 Sorry, changesfile not available.-- Xenial-changes mailing

[ubuntu/xenial-updates] linux-azure_4.15.0-1019.19~16.04.1_amd64.tar.gz - (Accepted)

2018-08-06 Thread Stefan Bader
linux-azure (4.15.0-1019.19~16.04.1) xenial; urgency=medium [ Ubuntu: 4.15.0-30.32 ] * CVE-2018-5390 - tcp: free batches of packets in tcp_prune_ofo_queue() - tcp: avoid collapses in tcp_prune_queue() if possible - tcp: detect malicious patterns in tcp_collapse_ofo_queue() -

[ubuntu/xenial-updates] linux-hwe_4.15.0-30.32~16.04.1_amd64.tar.gz - (Accepted)

2018-08-06 Thread Stefan Bader
linux-hwe (4.15.0-30.32~16.04.1) xenial; urgency=medium * CVE-2018-5390 - tcp: free batches of packets in tcp_prune_ofo_queue() - tcp: avoid collapses in tcp_prune_queue() if possible - tcp: detect malicious patterns in tcp_collapse_ofo_queue() - tcp: call tcp_drop() from