Skip to content
  1. Jul 27, 2017
  2. Jul 26, 2017
    • Thomas De Schampheleire's avatar
      tcpdump: security bump to 4.9.1 · e5888857
      Thomas De Schampheleire authored
      Fixes CVE-2017-11108/Fix bounds checking for STP
      
      Changelog: http://www.tcpdump.org/tcpdump-changes.txt
      
      
      
      [Peter: add signature link as suggested by Baruch]
      Signed-off-by: default avatarThomas De Schampheleire <thomas.de_schampheleire@nokia.com>
      Signed-off-by: default avatarPeter Korsgaard <peter@korsgaard.com>
      e5888857
    • Peter Korsgaard's avatar
      webkitgtk: security bump to version 2.16.6 · b5582d54
      Peter Korsgaard authored
      Fixes the following security issues:
      
      CVE-2017-7018 - An issue was discovered in certain Apple products.  iOS
      before 10.3.3 is affected.  Safari before 10.1.2 is affected.  iCloud before
      6.2.2 on Windows is affected.  iTunes before 12.6.2 on Windows is affected.
      tvOS before 10.2.2 is affected.  The issue involves the "WebKit" component.
      It allows remote attackers to execute arbitrary code or cause a denial of
      service (memory corruption and application crash) via a crafted web site.
      
      CVE-2017-7030 - An issue was discovered in certain Apple products.  iOS
      before 10.3.3 is affected.  Safari before 10.1.2 is affected.  iCloud before
      6.2.2 on Windows is affected.  iTunes before 12.6.2 on Windows is affected.
      tvOS before 10.2.2 is affected.  The issue involves the "WebKit" component.
      It allows remote attackers to execute arbitrary code or cause a denial of
      service (memory corruption and application crash) via a crafted web site.
      
      CVE-2017-7034 - An issue was discovered in certain Apple products.  iOS
      before 10.3.3 is affected.  Safari before 10.1.2 is affected.  iCloud before
      6.2.2 on Windows is affected.  iTunes before 12.6.2 on Windows is affected.
      tvOS before 10.2.2 is affected.  The issue involves the "WebKit" component.
      It allows remote attackers to execute arbitrary code or cause a denial of
      service (memory corruption and application crash) via a crafted web site.
      
      CVE-2017-7037 - An issue was discovered in certain Apple products.  iOS
      before 10.3.3 is affected.  Safari before 10.1.2 is affected.  iCloud before
      6.2.2 on Windows is affected.  iTunes before 12.6.2 on Windows is affected.
      tvOS before 10.2.2 is affected.  The issue involves the "WebKit" component.
      It allows remote attackers to execute arbitrary code or cause a denial of
      service (memory corruption and application crash) via a crafted web site.
      
      CVE-2017-7039 - An issue was discovered in certain Apple products.  iOS
      before 10.3.3 is affected.  Safari before 10.1.2 is affected.  iCloud before
      6.2.2 on Windows is affected.  iTunes before 12.6.2 on Windows is affected.
      tvOS before 10.2.2 is affected.  The issue involves the "WebKit" component.
      It allows remote attackers to execute arbitrary code or cause a denial of
      service (memory corruption and application crash) via a crafted web site.
      
      CVE-2017-7046 - An issue was discovered in certain Apple products.  iOS
      before 10.3.3 is affected.  Safari before 10.1.2 is affected.  iCloud before
      6.2.2 on Windows is affected.  iTunes before 12.6.2 on Windows is affected.
      tvOS before 10.2.2 is affected.  The issue involves the "WebKit" component.
      It allows remote attackers to execute arbitrary code or cause a denial of
      service (memory corruption and application crash) via a crafted web site.
      
      CVE-2017-7048 - An issue was discovered in certain Apple products.  iOS
      before 10.3.3 is affected.  Safari before 10.1.2 is affected.  iCloud before
      6.2.2 on Windows is affected.  iTunes before 12.6.2 on Windows is affected.
      tvOS before 10.2.2 is affected.  The issue involves the "WebKit" component.
      It allows remote attackers to execute arbitrary code or cause a denial of
      service (memory corruption and application crash) via a crafted web site.
      
      CVE-2017-7055 - An issue was discovered in certain Apple products.  iOS
      before 10.3.3 is affected.  Safari before 10.1.2 is affected.  iCloud before
      6.2.2 on Windows is affected.  iTunes before 12.6.2 on Windows is affected.
      tvOS before 10.2.2 is affected.  The issue involves the "WebKit" component.
      It allows remote attackers to execute arbitrary code or cause a denial of
      service (memory corruption and application crash) via a crafted web site.
      
      CVE-2017-7056 - An issue was discovered in certain Apple products.  iOS
      before 10.3.3 is affected.  Safari before 10.1.2 is affected.  iCloud before
      6.2.2 on Windows is affected.  iTunes before 12.6.2 on Windows is affected.
      tvOS before 10.2.2 is affected.  The issue involves the "WebKit" component.
      It allows remote attackers to execute arbitrary code or cause a denial of
      service (memory corruption and application crash) via a crafted web site.
      
      CVE-2017-7061 - An issue was discovered in certain Apple products.  iOS
      before 10.3.3 is affected.  Safari before 10.1.2 is affected.  iCloud before
      6.2.2 on Windows is affected.  iTunes before 12.6.2 on Windows is affected.
      tvOS before 10.2.2 is affected.  The issue involves the "WebKit" component.
      It allows remote attackers to execute arbitrary code or cause a denial of
      service (memory corruption and application crash) via a crafted web site.
      
      CVE-2017-7064 - An issue was discovered in certain Apple products.  iOS
      before 10.3.3 is affected.  Safari before 10.1.2 is affected.  iCloud before
      6.2.2 on Windows is affected.  iTunes before 12.6.2 on Windows is affected.
      The issue involves the "WebKit" component.  It allows attackers to bypass
      intended memory-read restrictions via a crafted app.
      
      For more details, see the announcement:
      https://webkitgtk.org/2017/07/24/webkitgtk2.16.6-released.html
      
      
      
      Signed-off-by: default avatarPeter Korsgaard <peter@korsgaard.com>
      Reviewed-by: default avatar"Adrian Perez de Castro" <aperez@igalia.com>
      Signed-off-by: default avatarPeter Korsgaard <peter@korsgaard.com>
      b5582d54
  3. Jul 25, 2017
Loading