apticron report [Sun, 25 Oct 2015 00:38:10 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
quigon.federez.net
[ 160.228.155.65 ]
The following packages are currently pending an upgrade:
libgdk-pixbuf2.0-0 2.31.1-2+deb8u3
libgdk-pixbuf2.0-common 2.31.1-2+deb8u3
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour gdk-pixbuf (libgdk-pixbuf2.0-0 libgdk-pixbuf2.0-common) ---
gdk-pixbuf (2.31.1-2+deb8u3) jessie-security; urgency=high
* Non-maintainer upload by the Security Team.
* Add patches to fix CVE-2015-7673.
CVE-2015-7673: Heap overflow and DoS vulnerability when scaling a TGA
file.
* Add patch to fix CVE-2015-7674.
CVE-2015-7674: Heap overflow when scaling a GIF file.
-- Salvatore Bonaccorso <carnil(a)debian.org> Sat, 24 Oct 2015 16:43:46 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on quigon.federez.net
--
apticron
E: Impossible d'obtenir le verrou /var/lib/dpkg/lock - open (11: Ressource temporairement non disponible)
E: Impossible de verrouiller le répertoire d'administration (/var/lib/dpkg/). Il est possible qu'un autre processus l'utilise.
apticron report [Sat, 24 Oct 2015 10:48:20 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
hexagon.federez.net
[ 5.39.82.35 2001:41d0:8:9423::1 5.39.82.35 2001:41d0:8:9423::1 ]
The following packages are currently pending an upgrade:
libmysqlclient18 5.5.46-0+deb8u1
mysql-client-5.5 5.5.46-0+deb8u1
mysql-common 5.5.46-0+deb8u1
mysql-server 5.5.46-0+deb8u1
mysql-server-5.5 5.5.46-0+deb8u1
mysql-server-core-5.5 5.5.46-0+deb8u1
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour mysql-5.5 (libmysqlclient18 mysql-client-5.5 mysql-common mysql-server mysql-server-5.5 mysql-server-core-5.5) ---
mysql-5.5 (5.5.46-0+deb8u1) jessie-security; urgency=high
* Non-maintainer upload by the Security Team.
* Imported Upstream version 5.5.46 to fix security issues:
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- CVE-2015-4792 CVE-2015-4802 CVE-2015-4815 CVE-2015-4816 CVE-2015-4819
CVE-2015-4826 CVE-2015-4830 CVE-2015-4836 CVE-2015-4858 CVE-2015-4861
CVE-2015-4870 CVE-2015-4879 CVE-2015-4913
(Closes: #802564)
* Add fix-test-suite-failure-caused-by-arbitrary-date-in-the-future.patch.
Fix test suite failure caused by arbitrary date in the future.
Thanks to Marc Deslauriers <marc.deslauriers(a)canonical.com>
-- Salvatore Bonaccorso <carnil(a)debian.org> Fri, 23 Oct 2015 13:35:23 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on hexagon.federez.net
--
apticron
apticron report [Wed, 21 Oct 2015 10:48:19 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
hexagon.federez.net
[ 5.39.82.35 2001:41d0:8:9423::1 5.39.82.35 2001:41d0:8:9423::1 ]
The following packages are currently pending an upgrade:
libpq5 9.4.5-0+deb8u1
tzdata 2015g-0+deb8u1
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour postgresql-9.4 (libpq5) ---
postgresql-9.4 (9.4.5-0+deb8u1) jessie-security; urgency=medium
* New upstream security release.
+ Guard against stack overflows in json parsing (Oskari Saarenmaa)
If an application constructs PostgreSQL json or jsonb values from
arbitrary user input, the application's users can reliably crash the
PostgreSQL server, causing momentary denial of service. (CVE-2015-5289)
+ Fix contrib/pgcrypto to detect and report too-short crypt() salts
(Josh Kupershmidt)
Certain invalid salt arguments crashed the server or disclosed a few
bytes of server memory. We have not ruled out the viability of attacks
that arrange for presence of confidential information in the disclosed
bytes, but they seem unlikely. (CVE-2015-5288)
-- Christoph Berg <christoph.berg(a)credativ.de> Thu, 08 Oct 2015 14:24:00 +0200
--- Modifications pour tzdata ---
tzdata (2015g-0+deb8u1) stable; urgency=medium
[ Aurelien Jarno ]
* New upstream version, affecting the following future time stamps:
- Fiji
- Fort Nelson, British Columbia
- Norfolk Island
- Turkey (closes: #801172)
-- Aurelien Jarno <aurel32(a)debian.org> Wed, 07 Oct 2015 16:06:53 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on hexagon.federez.net
--
apticron
apticron report [Wed, 21 Oct 2015 00:38:10 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
quigon.federez.net
[ 160.228.155.65 ]
The following packages are currently pending an upgrade:
tzdata 2015g-0+deb8u1
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour tzdata ---
tzdata (2015g-0+deb8u1) stable; urgency=medium
[ Aurelien Jarno ]
* New upstream version, affecting the following future time stamps:
- Fiji
- Fort Nelson, British Columbia
- Norfolk Island
- Turkey (closes: #801172)
-- Aurelien Jarno <aurel32(a)debian.org> Wed, 07 Oct 2015 16:06:53 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on quigon.federez.net
--
apticron
apticron report [Tue, 20 Oct 2015 18:44:17 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
baldrick.crans.org
[ 138.231.142.239 2a01:240:fe3d:4:62:61ff:fe6c:6401 138.231.142.239 ]
[ 2a01:240:fe3d:4:62:61ff:fe6c:6401 ]
The following packages are currently pending an upgrade:
libpq5 9.4.5-0+deb8u1
tzdata 2015g-0+deb8u1
tzdata-java 2015g-0+deb8u1
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour postgresql-9.4 (libpq5) ---
postgresql-9.4 (9.4.5-0+deb8u1) jessie-security; urgency=medium
* New upstream security release.
+ Guard against stack overflows in json parsing (Oskari Saarenmaa)
If an application constructs PostgreSQL json or jsonb values from
arbitrary user input, the application's users can reliably crash the
PostgreSQL server, causing momentary denial of service. (CVE-2015-5289)
+ Fix contrib/pgcrypto to detect and report too-short crypt() salts
(Josh Kupershmidt)
Certain invalid salt arguments crashed the server or disclosed a few
bytes of server memory. We have not ruled out the viability of attacks
that arrange for presence of confidential information in the disclosed
bytes, but they seem unlikely. (CVE-2015-5288)
-- Christoph Berg <christoph.berg(a)credativ.de> Thu, 08 Oct 2015 14:24:00 +0200
--- Modifications pour tzdata (tzdata tzdata-java) ---
tzdata (2015g-0+deb8u1) stable; urgency=medium
[ Aurelien Jarno ]
* New upstream version, affecting the following future time stamps:
- Fiji
- Fort Nelson, British Columbia
- Norfolk Island
- Turkey (closes: #801172)
-- Aurelien Jarno <aurel32(a)debian.org> Wed, 07 Oct 2015 16:06:53 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on baldrick.crans.org
--
apticron
apticron report [Tue, 20 Oct 2015 10:48:19 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
hexagon.federez.net
[ 5.39.82.35 2001:41d0:8:9423::1 5.39.82.35 2001:41d0:8:9423::1 ]
The following packages are currently pending an upgrade:
libpq5 9.4.5-0+deb8u1
tzdata 2015g-0+deb8u1
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour postgresql-9.4 (libpq5) ---
postgresql-9.4 (9.4.5-0+deb8u1) jessie-security; urgency=medium
* New upstream security release.
+ Guard against stack overflows in json parsing (Oskari Saarenmaa)
If an application constructs PostgreSQL json or jsonb values from
arbitrary user input, the application's users can reliably crash the
PostgreSQL server, causing momentary denial of service. (CVE-2015-5289)
+ Fix contrib/pgcrypto to detect and report too-short crypt() salts
(Josh Kupershmidt)
Certain invalid salt arguments crashed the server or disclosed a few
bytes of server memory. We have not ruled out the viability of attacks
that arrange for presence of confidential information in the disclosed
bytes, but they seem unlikely. (CVE-2015-5288)
-- Christoph Berg <christoph.berg(a)credativ.de> Thu, 08 Oct 2015 14:24:00 +0200
--- Modifications pour tzdata ---
tzdata (2015g-0+deb8u1) stable; urgency=medium
[ Aurelien Jarno ]
* New upstream version, affecting the following future time stamps:
- Fiji
- Fort Nelson, British Columbia
- Norfolk Island
- Turkey (closes: #801172)
-- Aurelien Jarno <aurel32(a)debian.org> Wed, 07 Oct 2015 16:06:53 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on hexagon.federez.net
--
apticron
apticron report [Tue, 20 Oct 2015 00:38:10 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
quigon.federez.net
[ 160.228.155.65 ]
The following packages are currently pending an upgrade:
tzdata 2015g-0+deb8u1
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour tzdata ---
tzdata (2015g-0+deb8u1) stable; urgency=medium
[ Aurelien Jarno ]
* New upstream version, affecting the following future time stamps:
- Fiji
- Fort Nelson, British Columbia
- Norfolk Island
- Turkey (closes: #801172)
-- Aurelien Jarno <aurel32(a)debian.org> Wed, 07 Oct 2015 16:06:53 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on quigon.federez.net
--
apticron