云网牛站
所在位置:首页 > Linux下载 > Debian 10.2发布下载,旧版本可直接升级,附更新介绍

Debian 10.2发布下载,旧版本可直接升级,附更新介绍

2019-11-17 09:01:50作者:戴进稿源:云网牛站

Debian GNU/Linux 10.2 “Buster”正式发布并提供debian-10.2.0-amd64-netinst.iso下载了,使用Debian GNU/Linux 10和10.1的用户可运行sudo apt-get update && sudo apt-get dist-upgrade命令进行安装,或者通过图形方式来安装。该版本是Debian 10系列的第二次更新,主要对安全性问题进行了更正,并针对严重问题进行了一些调整。请注意,该发行版并不构成Debian 10的新版本,而仅更新了其中包括的某些软件包,如果是安装旧的Debian 10 ISO(参考:安装Debian 10 Buster的方法),那么可以使用最新的Debian镜像将软件包升级到当前版本,那些经常从security.debian.org安装更新的用户将不必更新许多软件包,并且大多数此类更新都包含在该发行版中。

Debian 10.2发布下载,旧版本可直接升级,附更新介绍

 

Debian 10.2更新介绍

1、错误修正

此稳定的更新对以下程序包进行了一些重要的更正:

Package

Reason

aegisub

Fix crash when selecting a language from the bottom of the Spell checker language list; fix crash when right-clicking in the subtitles text box

akonadi

Fix various crashes / deadlock issues

base-files

Update /etc/debian_version for the point release

capistrano

Fix failure to remove old releases when there were too many

cron

Stop using obsolete SELinux API

cyrus-imapd

Fix data loss on upgrade from version 3.0.0 or earlier

debian-edu-config

Handle newer Firefox ESR configuration files; add post-up stanza to /etc/network/interfaces eth0 entry conditionally

debian-installer

Fix unreadable fonts on hidpi displays in netboot images booted with EFI

debian-installer-netboot-images

Rebuild against proposed-updates

distro-info-data

Add Ubuntu 20.04 LTS, Focal Fossa

dkimpy-milter

New upstream stable release; fix sysvinit support; catch more ASCII encoding errors to improve resilience against bad data; fix message extraction so that signing in the same pass through the milter as verifying works correctly

emacs

Update the EPLA packaging key

fence-agents

Fix incomplete removal of fence_amt_ws

flatpak

New upstream stable release

flightcrew

Security fixes [CVE-2019-13032 CVE-2019-13241]

fonts-noto-cjk

Fix over-aggressive font selection of Noto CJK fonts in modern web browsers under Chinese locale

freetype

Properly handle phantom points for variable hinted fonts

gdb

Rebuild against new libbabeltrace, with higher version number to avoid conflict with earlier upload

glib2.0

Ensure libdbus clients can authenticate with a GDBusServer like the one in ibus

gnome-shell

New upstream stable release; fix truncation of long messages in Shell-modal dialogs; avoid crash on reallocation of dead actors

gnome-sound-recorder

Fix crash when selecting a recording

gnustep-base

Disable gdomap daemon that was accidentally enabled on upgrades from stretch

graphite-web

Remove unused send_email function [CVE-2017-18638]; avoid hourly error in cron when there is no whisper database

inn2

Fix negotiation of DHE ciphersuites

libapache-mod-auth-kerb

Fix use after free bug leading to crash

libdate-holidays-de-perl

Mark International Childrens Day (Sep 20th) as a holiday in Thuringia from 2019 onwards

libdatetime-timezone-perl

Update included data

libofx

Fix null pointer dereference issue [CVE-2019-9656]

libreoffice

Fix the postgresql driver with PostgreSQL 12

libsixel

Fix several security issues [CVE-2018-19756 CVE-2018-19757 CVE-2018-19759 CVE-2018-19761 CVE-2018-19762 CVE-2018-19763 CVE-2019-3573 CVE-2019-3574]

libxslt

Fix dangling pointer in xsltCopyText [CVE-2019-18197]

lucene-solr

Disable obsolete call to ContextHandler in solr-jetty9.xml; fix Jetty permissions on SOLR index

mariadb-10.3

New upstream stable release

modsecurity-crs

Fix PHP script upload rules [CVE-2019-13464]

mutter

New upstream stable release

ncurses

Fix several security issues [CVE-2019-17594 CVE-2019-17595] and other issues in tic

ndppd

Avoid world writable PID file, that was breaking daemon init scripts

network-manager

Fix file permissions for /var/lib/NetworkManager/secret_key and /var/lib/NetworkManager

node-fstream

Fix arbitrary file overwrite issue [CVE-2019-13173]

node-set-value

Fix prototype pollution [CVE-2019-10747]

node-yarnpkg

Force using HTTPS for regular registries

nx-libs

Fix regressions introduced in previous upload, affecting x2go

open-vm-tools

Fix memory leaks and error handling

openvswitch

Update debian/ifupdown.sh to allow setting-up the MTU; fix Python dependencies to use Python 3

picard

Update translations to fix crash with Spanish locale

plasma-applet-redshift-control

Fix manual mode when used with redshift versions above 1.12

postfix

New upstream stable release; work around poor TCP loopback performance

python-cryptography

Fix test suite failures when built against newer OpenSSL versions; fix a memory leak triggerable when parsing x509 certificate extensions like AIA

python-flask-rdf

Add Depends on python{3,}-rdflib

python-oslo.messaging

New upstream stable release; fix switch connection destination when a rabbitmq cluster node disappears

python-werkzeug

Ensure Docker containers have unique debugger PINs [CVE-2019-14806]

python2.7

Fix several security issues [CVE-2018-20852 CVE-2019-10160 CVE-2019-16056 CVE-2019-16935 CVE-2019-9740 CVE-2019-9947]

quota

Fix rpc.rquotad spinning at 100% CPU

rpcbind

Allow remote calls to be enabled at run-time

shelldap

Repair SASL authentications, add a 'sasluser' option

sogo

Fix display of PGP-signed e-mails

spf-engine

New upstream stable release; fix sysvinit support

standardskriver

Fix deprecation warning from config.RawConfigParser; use external ip command rather than deprecated ifconfig command

swi-prolog

Use HTTPS when contacting upstream pack servers

systemd

core: never propagate reload failure to service result; fix sync_file_range failures in nspawn containers on arm, ppc; fix RootDirectory not working when used in combination with User; ensure that access controls on systemd-resolved's D-Bus interface are enforced correctly [CVE-2019-15718]; fix StopWhenUnneeded=true for mount units; make MountFlags=shared work again

tmpreaper

Prevent breaking of systemd services that use PrivateTmp=true

trapperkeeper-webserver-jetty9-clojure

Restore SSL compatibility with newer Jetty versions

tzdata

New upstream release

ublock-origin

New upstream version, compatible with Firefox ESR68

uim

Resurrect libuim-data as a transitional package, fixing some issues after upgrades to buster

vanguards

New upstream stable release; prevent a reload of tor's configuration via SIGHUP causing a denial-of-service for vanguards protections

2、安全更新

此版将以下安全更新添加到稳定版本中:

Advisory ID

Package

DSA-4509

apache2

DSA-4511

nghttp2

DSA-4512

qemu

DSA-4514

varnish

DSA-4515

webkit2gtk

DSA-4516

firefox-esr

DSA-4517

exim4

DSA-4518

ghostscript

DSA-4519

libreoffice

DSA-4520

trafficserver

DSA-4521

docker.io

DSA-4523

thunderbird

DSA-4524

dino-im

DSA-4525

ibus

DSA-4526

opendmarc

DSA-4527

php7.3

DSA-4528

bird

DSA-4530

expat

DSA-4531

linux-signed-amd64

DSA-4531

linux-signed-i386

DSA-4531

linux

DSA-4531

linux-signed-arm64

DSA-4532

spip

DSA-4533

lemonldap-ng

DSA-4534

golang-1.11

DSA-4535

e2fsprogs

DSA-4536

exim4

DSA-4538

wpa

DSA-4539

openssl

DSA-4539

openssh

DSA-4541

libapreq2

DSA-4542

jackson-databind

DSA-4543

sudo

DSA-4544

unbound

DSA-4545

mediawiki

DSA-4547

tcpdump

DSA-4549

firefox-esr

DSA-4550

file

DSA-4551

golang-1.11

DSA-4553

php7.3

DSA-4554

ruby-loofah

DSA-4555

pam-python

DSA-4556

qtbase-opensource-src

DSA-4557

libarchive

DSA-4558

webkit2gtk

DSA-4559

proftpd-dfsg

DSA-4560

simplesamlphp

DSA-4561

fribidi

DSA-4562

chromium

3、移除的包

由于超出我们的控制范围,以下软件包已被删除:

Package

Reason

firefox-esr

[armel] No longer supportable due to nodejs build-dependency

4、Debian安装程序

安装程序已经得到了更新,已纳入稳定的修复程序。

 

下载链接

Debian首页

Debian下载地址

 

相关主题

在Debian 10上安装及升级/更新谷歌Chrome浏览器的方法

精选文章
热门文章