apticron report [Wed, 22 Apr 2015 17:38:12 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
quigon.federez.net
[ 160.228.155.65 ]
The following packages are currently pending an upgrade:
curl 7.26.0-1+wheezy13
libcurl3 7.26.0-1+wheezy13
libcurl3-gnutls 7.26.0-1+wheezy13
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour curl (curl libcurl3 libcurl3-gnutls) ---
curl (7.26.0-1+wheezy13) wheezy-security; urgency=high
* Fix re-using authenticated connection when unauthenticated
as per CVE-2015-3143
http://curl.haxx.se/docs/adv_20150422A.html
* Fix Negotiate not treated as connection-oriented as per CVE-2015-3148
http://curl.haxx.se/docs/adv_20150422B.html
-- Alessandro Ghedini <ghedo(a)debian.org> Tue, 21 Apr 2015 13:51:57 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on quigon.federez.net
--
apticron
apticron report [Tue, 21 Apr 2015 16:44:05 +0000]
========================================================================
apticron has detected that some packages need upgrading on:
baldrick
[ 138.231.142.239 2a01:240:fe3d:4:62:61ff:fe6c:6401 138.231.142.239 ]
[ 2a01:240:fe3d:4:62:61ff:fe6c:6401 ]
The following packages are currently pending an upgrade:
tzdata 2015c-0+deb7u1
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour tzdata ---
tzdata (2015c-0+deb7u1) stable; urgency=medium
* New upstream version:
- DST rule fix for Egypt.
-- Aurelien Jarno <aurel32(a)debian.org> Thu, 16 Apr 2015 22:29:09 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on baldrick
--
apticron
apticron report [Tue, 21 Apr 2015 17:38:13 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
quigon.federez.net
[ 160.228.155.65 ]
The following packages are currently pending an upgrade:
libdatetime-timezone-perl 1:1.58-1+2015c
tzdata 2015c-0+deb7u1
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour libdatetime-timezone-perl ---
libdatetime-timezone-perl (1:1.58-1+2015c) stable-proposed-updates; urgency=medium
* Update to Olson database version 2015c.
-- gregor herrmann <gregoa(a)debian.org> Wed, 15 Apr 2015 21:00:27 +0200
--- Modifications pour tzdata ---
tzdata (2015c-0+deb7u1) stable; urgency=medium
* New upstream version:
- DST rule fix for Egypt.
-- Aurelien Jarno <aurel32(a)debian.org> Thu, 16 Apr 2015 22:29:09 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on quigon.federez.net
--
apticron
apticron report [Tue, 21 Apr 2015 10:48:15 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
hexagon.federez.net
[ 5.39.82.35 2001:41d0:8:9423::1 5.39.82.35 2001:41d0:8:9423::1 ]
The following packages are currently pending an upgrade:
tzdata 2015c-0+deb7u1
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour tzdata ---
tzdata (2015c-0+deb7u1) stable; urgency=medium
* New upstream version:
- DST rule fix for Egypt.
-- Aurelien Jarno <aurel32(a)debian.org> Thu, 16 Apr 2015 22:29:09 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on hexagon.federez.net
--
apticron
apticron report [Sun, 19 Apr 2015 10:48:15 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
hexagon.federez.net
[ 5.39.82.35 2001:41d0:8:9423::1 5.39.82.35 2001:41d0:8:9423::1 ]
The following packages are currently pending an upgrade:
libmysqlclient18 5.5.43-0+deb7u1
mysql-client-5.5 5.5.43-0+deb7u1
mysql-common 5.5.43-0+deb7u1
mysql-server 5.5.43-0+deb7u1
mysql-server-5.5 5.5.43-0+deb7u1
mysql-server-core-5.5 5.5.43-0+deb7u1
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour mysql-5.5 (libmysqlclient18 mysql-client-5.5 mysql-common mysql-server mysql-server-5.5 mysql-server-core-5.5) ---
mysql-5.5 (5.5.43-0+deb7u1) wheezy-security; urgency=high
* Non-maintainer upload by the Security Team.
* Imported Upstream version 5.5.43 to fix security issues:
- http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html
- CVE-2015-0433 CVE-2015-0441 CVE-2015-0499 CVE-2015-0501 CVE-2015-0505
CVE-2015-2568 CVE-2015-2571 CVE-2015-2573
(Closes: #782645)
* Update copyright years for upstream files
-- Salvatore Bonaccorso <carnil(a)debian.org> Fri, 17 Apr 2015 20:14:17 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on hexagon.federez.net
--
apticron
W: Une erreur s'est produite lors du contrôle de la signature. Le dépôt n'est pas mis à jour et les fichiers d'index précédents seront utilisés. Erreur de GPG : http://http.debian.net wheezy-backports Release : Les signatures suivantes ne sont pas valables : BADSIG 8B48AD6246925553 Debian Archive Automatic Signing Key (7.0/wheezy) <ftpmaster(a)debian.org>
W: Impossible de récupérer http://http.debian.net/debian/dists/wheezy-backports/Release
W: Le téléchargement de quelques fichiers d'index a échoué, ils ont été ignorés, ou les anciens ont été utilisés à la place.
apticron report [Tue, 14 Apr 2015 10:48:16 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
hexagon.federez.net
[ 5.39.82.35 2001:41d0:8:9423::1 5.39.82.35 2001:41d0:8:9423::1 ]
The following packages are currently pending an upgrade:
libxrender1 1:0.9.7-1+deb7u2
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour libxrender (libxrender1) ---
libxrender (1:0.9.7-1+deb7u2) wheezy-security; urgency=medium
* Tighten build dependency on libx11-dev (Closes: #782505)
-- Sebastien Delafond <seb(a)debian.org> Mon, 13 Apr 2015 18:29:02 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on hexagon.federez.net
--
apticron
apticron report [Mon, 13 Apr 2015 17:38:14 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
quigon.federez.net
[ 160.228.155.65 ]
The following packages are currently pending an upgrade:
libxrender1 1:0.9.7-1+deb7u1+b1
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour libxrender (libxrender1) ---
libxrender (1:0.9.7-1+deb7u1+b1) wheezy-security; urgency=low, binary-only=yes
* Binary-only non-maintainer upload for amd64; no source changes.
* Rebuild against fixed libx11 for DSA 3224
-- amd64 / i386 Build Daemon (brahms) <buildd_amd64-brahms(a)buildd.debian.org> Tue, 14 May 2013 19:28:26 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on quigon.federez.net
--
apticron
apticron report [Sun, 12 Apr 2015 16:44:06 +0000]
========================================================================
apticron has detected that some packages need upgrading on:
baldrick
[ 138.231.142.239 2a01:240:fe3d:4:62:61ff:fe6c:6401 138.231.142.239 ]
[ 2a01:240:fe3d:4:62:61ff:fe6c:6401 ]
The following packages are currently pending an upgrade:
ntpdate 1:4.2.6.p5+dfsg-2+deb7u4
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour ntp (ntpdate) ---
ntp (1:4.2.6.p5+dfsg-2+deb7u4) wheezy-security; urgency=medium
* Fix CVE-2015-1798 and CVE-2015-1799 (Closes: #782095)
* Fix endless loop and non-random key generation using
ntp-keygen on big endian machines.
-- Kurt Roeckx <kurt(a)roeckx.be> Fri, 10 Apr 2015 20:36:48 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on baldrick
--
apticron
apticron report [Sun, 12 Apr 2015 10:48:15 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
hexagon.federez.net
[ 5.39.82.35 2001:41d0:8:9423::1 5.39.82.35 2001:41d0:8:9423::1 ]
The following packages are currently pending an upgrade:
dpkg 1.16.16
dpkg-dev 1.16.16
libdpkg-perl 1.16.16
libtasn1-3 2.13-2+deb7u2
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour dpkg (dpkg dpkg-dev libdpkg-perl) ---
dpkg (1.16.16) wheezy-security; urgency=high
[ Guillem Jover ]
* Do not leak long tar names on bogus or truncated archives.
* Do not leak the filepackages iterator when a directory is used by other
packages.
* Do not leak color string on «dselect --color».
* Fix memory leaks when parsing alternatives.
* Fix memory leaks in buffer_copy() on error conditions.
* Fix possible out of bounds buffer read access in the error output on
bogus ar member sizes.
* Fix file triggers/Unincorp descriptor leak on subprocesses. Regression
introduced with the initial triggers implementation in dpkg 1.14.17.
Closes: #751021
* Fix a descriptor leak on dselect subprocesses when --debug is used.
* Do not run qsort() over the scandir() list in libcompat if it is NULL.
* Fix off-by-one stack buffer overrun in start-stop-daemon on GNU/Linux and
GNU/kFreeBSD if the executable pathname is longer than _POSIX_PATH_MAX.
Although this should not have security implications as the buffer is
surrounded by two arrays (so those catch accesses even if the stack
grows up or down), and we are compiling with -fstack-protector anyway.
* Add a workaround to start-stop-daemon for bogus OpenVZ Linux kernels that
prepend, instead of appending, the " (deleted)" marker in /proc/PID/exe.
Closes: #731530
* Fix off-by-one error in libdpkg command argv size calculation.
Based on a patch by Bálint Réczey <balint(a)balintreczey.hu>. Closes: #760690
* Escape package and architecture names on control file parsing warning,
as those get injected into a variable that is used as a format string,
and they come from the package fields, which are under user control.
Regression introduced in dpkg 1.16.0. Fixes CVE-2014-8625. Closes: #768485
Reported by Joshua Rogers <megamansec(a)gmail.com>.
* Do not match partial field names in control files. Closes: #769119
Regression introduced in dpkg 1.10.
* Fix out-of-bounds buffer read accesses when parsing field and trigger
names or checking package ownership of conffiles and directories.
Reported by Joshua Rogers <megamansec(a)gmail.com>.
* Add powerpcel support to cputable. Thanks to Jae Junh <jaejunh(a)embian.com>.
* Fix OpenPGP Armor Header Line parsing in Dpkg::Control::Hash. We should
only accept [\r\t ] as trailing whitespace, although RFC4880 does not
clarify what whitespace really maps to, we should really match the GnuPG
implementation anyway, as that's what we use to verify the signatures.
Reported by Jann Horn <jann(a)thejh.net>. Fixes CVE-2015-0840.
[ Raphaël Hertzog ]
* Drop myself from Uploaders.
[ Updated scripts translations ]
* Fix typos in German (Helge Kreutzmann)
* Swedish (Peter Krefting).
[ Updated man page translations ]
* Fix typos in German (Helge Kreutzmann)
* Swedish (Peter Krefting).
-- Guillem Jover <guillem(a)debian.org> Thu, 09 Apr 2015 08:45:47 +0200
--- Modifications pour libtasn1-3 ---
libtasn1-3 (2.13-2+deb7u2) wheezy-security; urgency=high
* Non-maintainer upload by the Security Team.
* Add CVE-2015-2806.patch patch.
CVE-2015-2806: stack overflow in asn1_der_decoding.
-- Salvatore Bonaccorso <carnil(a)debian.org> Sat, 11 Apr 2015 14:38:36 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on hexagon.federez.net
--
apticron