apticron report [Sat, 03 Nov 2018 21:38:05 +0100]
========================================================================
apticron has detected that some packages need upgrading on:
quigon.federez.net
[ 160.228.155.65 ]
The following packages are currently pending an upgrade:
curl 7.52.1-5+deb9u8
libcurl3 7.52.1-5+deb9u8
libcurl3-gnutls 7.52.1-5+deb9u8
libdatetime-timezone-perl 1:2.09-1+2018g
libruby2.3 2.3.3-1+deb9u4
ruby2.3 2.3.3-1+deb9u4
tzdata 2018g-0+deb9u1
========================================================================
Package Details:
apt-listchanges : Lecture des fichiers de modifications (« changelog »)...
apt-listchanges : journaux des modifications (« changelogs »)
-------------------------------------------------------------
--- Modifications pour curl (curl libcurl3 libcurl3-gnutls) ---
curl (7.52.1-5+deb9u8) stretch-security; urgency=high
* Fix SASL password overflow via integer overflow as per CVE-2018-16839
https://curl.haxx.se/docs/CVE-2018-16839.html
* Fix warning message out-of-buffer read as per CVE-2018-16842
https://curl.haxx.se/docs/CVE-2018-16842.html
-- Alessandro Ghedini <ghedo(a)debian.org> Tue, 30 Oct 2018 21:39:11 +0000
--- Modifications pour ruby2.3 (libruby2.3 ruby2.3) ---
ruby2.3 (2.3.3-1+deb9u4) stretch-security; urgency=high
* Non-maintainer upload by the Security Team.
* OpenSSL::X509::Name equality check does not work correctly
(CVE-2018-16395)
* pack.c: avoid returning uninitialized String
* Tainted flags are not propagated in Array#pack and String#unpack with some
directives (CVE-2018-16396)
-- Salvatore Bonaccorso <carnil(a)debian.org> Sun, 28 Oct 2018 21:49:57 +0100
--- Modifications pour libdatetime-timezone-perl ---
libdatetime-timezone-perl (1:2.09-1+2018g) stretch; urgency=medium
* Update to Olson database version 2018g.
This update contains contemporary changes for Morocco.
-- gregor herrmann <gregoa(a)debian.org> Sat, 27 Oct 2018 15:44:52 +0200
--- Modifications pour tzdata ---
tzdata (2018g-0+deb9u1) stretch; urgency=medium
* New upstream version, affecting the following future timestamp:
- Morocco switches to permanent +01 on 2018-10-27.
-- Aurelien Jarno <aurel32(a)debian.org> Sat, 27 Oct 2018 15:20:17 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on
quigon.federez.net
--
apticron