软件包 |
原因 |
bareos |
修复 bareos-dir logrotate 配置权限;修复使用 SHA1 签名时的文件破坏 |
base-files |
为小版本更新提供文件 |
bind9 |
导入即将启用的 DNSSEC KSK-2017 |
cups |
默认禁用 SSLv3 和 RC4 以解决 POODLE 问题 |
db |
在 db_home 未设置时不要访问 DB_CONFIG [CVE-2017-10140] |
db5.3 |
在 db_home 未设置时不要访问 DB_CONFIG [CVE-2017-10140] |
debian-installer |
为小版本更新重新构建 |
debian-installer-netboot-images |
为小版本更新重新构建 |
debmirror |
容忍 *.diff/Index 文件中的未知行;镜像 DEP-11 元数据文件;更偏好 xz 文件而非 gz 文件,处理两者均不存在的情况;镜像并验证 InRelease 文件 |
dns-root-data |
更新 root.hints 至 2017072601 版本;将 KSK-2017 添加至 root.key 文件 |
dput |
dput.cf:替换 security-master.debian.org 为 ftp.upload.security.debian.org |
dwww |
修复 Last-Modified 头名称 |
elog |
更新补丁 0005_elogd_CVE-2016-6342_fix 以授予普通用户以访问权限 |
flightgear |
修复任意文件覆写问题 [CVE-2017-13709] |
gsoap |
修复大型 XML 文档导致的整数溢出 [CVE-2017-9765] |
hexchat |
修复 /server 指令带来的段错误问题 |
icu |
修复 createMetazoneMappings() 中的重复 free() 问题 [CVE-2017-14952] |
kdepim |
修复send Later with Delay bypasses OpenPGP [CVE-2017-9604] |
kedpm |
修复命令历史文件带来的信息泄漏问题 [CVE-2017-8296] |
keyringer |
Handle subkeys without expiration date and public keys listed multiple times |
krb5 |
Security fixes - remote authenticated attackers can crash the KDC [CVE-2017-11368]; kdc crash on restrict_anon_to_tgt [CVE-2016-3120]; remote DOS with ldap for authenticated attackers [CVE-2016-3119]; prevent requires_preauth bypass [CVE-2015-2694] |
libdatetime-timezone-perl |
更新包含的数据 |
libdbi |
Re-enable error handler call in dbi_result_next_row() |
libembperl-perl |
Change hard dependency on mod_perl in zembperl.load to Recommends, fixing an installation failure when libapache2-mod-perl2 is not installed |
libio-socket-ssl-perl |
Fix segfault using malformed client certificates |
liblouis |
Fix multiple stack-based buffer overflows [CVE-2014-8184] |
libofx |
安全修复 [CVE-2017-2816 CVE-2017-14731] |
libwnckmm |
收紧软件包之间的依赖关系;使用来自 libjs-jquery 包的 jquery.js |
libwpd |
安全修复 [CVE-2017-14226] |
libx11 |
Fix insufficient validation of data from the X server can cause out of boundary memory read (XGetImage()) or write (XListFonts()) [CVE-2016-7942 CVE-2016-7943] |
libxfixes |
Fix integer overflow on illegal server response [CVE-2016-7944] |
libxi |
Fix insufficient validation of data from the X server can cause out of boundary memory access or endless loops [CVE-2016-7945 CVE-2016-7946] |
libxrandr |
Avoid out of boundary accesses on illegal responses [CVE-2016-7947 CVE-2016-7948] |
libxtst |
Fix insufficient validation of data from the X server can cause out of boundary memory access or endless loops [CVE-2016-7951 CVE-2016-7952] |
libxv |
Fix protocol handling issues in libXv [CVE-2016-5407] |
libxvmc |
Avoid buffer underflow on empty strings [CVE-2016-7953] |
linux |
New stable kernel version 3.16.51 |
ncurses |
Fix various crash bugs in the tic library and the tic binary [CVE-2017-10684 CVE-2017-10685 CVE-2017-11112 CVE-2017-11113 CVE-2017-13728 CVE-2017-13729 CVE-2017-13730 CVE-2017-13731 CVE-2017-13732 CVE-2017-13734 CVE-2017-13733] |
openssh |
Test configuration before starting or reloading sshd under systemd; make -- before the hostname terminate argument processing after the hostname too |
pdns |
Add missing check on API operations [CVE-2017-15091] |
pdns-recursor |
Fix configuration file injection in the API [CVE-2017-15093] |
postgresql-9.4 |
新上游漏洞修复版本 |
python-tablib |
安全地加载 YAML [CVE-2017-2810] |
request-tracker4 |
Fix regression in previous security release where incorrect SHA256 passwords could trigger an error |
ruby-ox |
Avoid crash with invalid XML passed to Oj.parse_obj() [CVE-2017-15928] |
sam2p |
Fix several integer overflow or heap-based buffer overflow issues [CVE-2017-14628 CVE-2017-14629 CVE-2017-14630 CVE-2017-14631 CVE-2017-14636 CVE-2017-14637 CVE-2017-16663] |
slurm-llnl |
Fix security issue caused by insecure file path handling triggered by the failure of a Prolog script [CVE-2016-10030] |
sudo |
修复任意终端访问 [CVE-2017-1000368] |
syslinux |
Fix boot problem for old BIOS firmware by correcting C/H/S order |
tor |
Add Bastet directory authority; update geoip and geoip6 to the October 4 2017 Maxmind GeoLite2 country database; fix a memset() off the end of an array when packing cells |
transfig |
Add input sanitisation on FIG files [CVE-2017-16899]; sanitize input of fill patterns |
tzdata |
上游新版本 |
unbound |
Fix install of trust anchor when two anchors are present; include root trust anchor id 20326 |
weechat |
logger: call strftime before replacing buffer local variables [CVE-2017-14727] |