Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE
  • Updated Debian 8: 8.7 released (1/2)

    From =?utf-8?Q?C=C3=A9dric?= Boutillier@21:1/5 to All on Sat Jan 14 20:50:01 2017
    ------------------------------------------------------------------------
    The Debian Project https://www.debian.org/ Updated Debian 8: 8.7 released [email protected] January 14th, 2017 https://www.debian.org/News/2017/20170114 ------------------------------------------------------------------------


    The Debian project is pleased to announce the seventh update of its
    stable distribution Debian 8 (codename "jessie"). This update mainly
    adds corrections for security problems to the stable release, along with
    a few adjustments for serious problems. Security advisories were already published separately and are referenced where available.

    Please note that this update does not constitute a new version of Debian
    8 but only updates some of the packages included. There is no need to
    throw away old "jessie" CDs or DVDs but only to update via an up-to-date
    Debian mirror after an installation, to cause any out of date packages
    to be updated.

    Those who frequently install updates from security.debian.org won't have
    to update many packages and most updates from security.debian.org are
    included in this update.

    New installation media and CD and DVD images containing updated packages
    will be available soon at the regular locations.

    Upgrading to this revision online is usually done by pointing the
    aptitude (or apt) package tool (see the sources.list(5) manual page) to
    one of Debian's many FTP or HTTP mirrors. A comprehensive list of
    mirrors is available at:

    https://www.debian.org/mirror/list



    Miscellaneous Bugfixes
    ----------------------

    This stable update adds a few important corrections to the following
    packages:

    +--------------------------+------------------------------------------+
    | Package | Reason | +--------------------------+------------------------------------------+
    | ark [1] | Stop crashing on exit when being used |
    | | solely as a KPart |
    | | |
    | asterisk [2] | Fix security issue due to non-printable |
    | | ASCII chars treated as whitespace |
    | | [CVE-2016-9938] |
    | | |
    | asused [3] | Use created fields instead of changed, |
    | | in line with changes to source data |
    | | |
    | base-files [4] | Change /etc/debian_version to 8.7 |
    | | |
    | bash [5] | Fix arbitrary code execution via |
    | | malicious hostname [CVE-2016-0634] and |
    | | specially crafted SHELLOPTS+PS4 |
    | | variables allows command substitution |
    | | [CVE-2016-7543] |
    | | |
    | ca-certificates [6] | Update Mozilla certificate authority |
    | | bundle to version 2.9; postinst: run |
    | | update-certificates without hooks to |
    | | initially populate /etc/ssl/certs |
    | | |
    | cairo [7] | Fix DoS via using SVG to generate |
    | | invalid pointers [CVE-2016-9082] |
    | | |
    | ccache [8] | [amd64] Rebuild in a clean environment |
    | | |
    | ceph [9] | Fix short CORS request issue [CVE-2016- |
    | | 9579], mon DoS [CVE-2016-5009], |
    | | anonymous read on ACL [CVE-2016-7031], |
    | | RGW DoS [CVE-2016-8626] |
    | | |
    | chirp [10] | Disable reporting of telemetry by |
    | | default |
    | | |
    | cyrus-imapd-2.4 [11] | Fix LIST GROUP support |
    | | |
    | darktable [12] | Fix integer overflow in ljpeg_start() |
    | | [CVE-2015-3885] |
    | | |
    | dbus [13] | Fix potential format string |
    | | vulnerability; dbus.prerm: ensure that |
    | | dbus.socket is stopped before removal |
    | | |
    | debian-edu-doc [14] | Update Debian Edu Jessie manual from the |
    | | wiki; fix (da|nl) Jessie manual PO files |
    | | to get the PDF manuals built; |
    | | translation updates |
    | | |
    | debian-edu-install [15] | Update version number to 8+edu1 |
    | | |
    | debian-installer [16] | Rebuild for the point release |
    | | |
    | debian-installer- | Rebuild for the point release |
    | netboot-images [17] | |
    | | |
    | duck [18] | Fix loading of code from untrusted |
    | | location [CVE-2016-1239] |
    | | |
    | e2fsprogs [19] | Rebuild against dietlibc |
    | | 0.33~cvs20120325-6+deb8u1, to pick up |
    | | included security fixes |
    | | |
    | ebook-speaker [20] | Fix hint about installing html2text to |
    | | read html files |
    | | |
    | elog [21] | Fix posting entry as arbitrary username |
    | | [CVE-2016-6342] |
    | | |
    | evolution-data- | Fix premature drop of connection with |
    | server [22] | reduced TCP window sizes and resulting |
    | | loss of data |
    | | |
    | exim4 [23] | Fix GnuTLS memory leak |
    | | |
    | file [24] | Fix memory leak in magic loader |
    | | |
    | ganeti-instance- | Fix losetup invocations by replacing -s |
    | debootstrap [25] | with --show |
    | | |
    | glibc [26] | Do not unconditionally use the fsqrt |
    | | instruction on 64-bit PowerPC CPUs; fix |
    | | a regression introduced by cvs-resolv- |
    | | ipv6-nameservers.diff in hesiod; disable |
    | | lock elision (aka Intel TSX) on x86 |
    | | architectures |
    | | |
    | glusterfs [27] | Quota: Fix could not start auxiliary |
    | | mount issue |
    | | |
    | gnutls28 [28] | Fix incorrect certificate validation |
    | | when using OCSP responses [GNUTLS- |
    | | SA-2016-3 / CVE-2016-7444]; ensure |
    | | compatibility with CVE-2016-6489-patched |
    | | nettle |
    | | |
    | hplip [29] | Use full gpg key fingerprint when |
    | | fetching key from keyservers [CVE-2015- |
    | | 0839] |
    | | |
    | ieee-data [30] | Disable monthly update cron job |
    | | |
    | intel-microcode [31] | Update microcode |
    | | |
    | irssi [32] | Fix information exposure issue via |
    | | buf.pl and /upgrade [CVE-2016-7553]; fix |
    | | NULL pointer dereference in the nickcmp |
    | | function [CVE-2017-5193], use-after-free |
    | | when receiving invalid nick message |
    | | [CVE-2017-5194] and out-of-bounds read |
    | | in certain incomplete control codes |
    | | [CVE-2017-5195] |
    | | |
    | isenkram [33] | Download firmware using curl; use HTTPS |
    | | when downloading modaliases; change |
    | | mirror from http.debian.net to |
    | | httpredir.debian.org |
    | | |
    | jq [34] | Fix heap buffer overflow [CVE-2015-8863] |
    | | and stack exhaustion [CVE-2016-4074] |
    | | |
    | libclamunrar [35] | Fix out-of-band access |
    | | |
    | libdatetime-timezone- | Update to 2016h; update included data to |
    | perl [36] | 2016i; update to 2016j; update to 2016g |
    | | |
    | libfcgi-perl [37] | Fix "numerous connections cause |
    | | segfault DoS" [CVE-2012-6687] |
    | | |
    | libio-socket-ssl- | Fix issue with incorrect "unreadable |
    | perl [38] | SSL_key_file" error when using |
    | | filesystem ACLs |
    | | |
    | libmateweather [39] | Switch from discontinued |
    | | weather.noaa.gov to aviationweather.gov |
    | | |
    | libphp-adodb [40] | Fix XSS vulnerability [CVE-2016-4855] |
    | | and SQL injection issue [CVE-2016-7405] |
    | | |
    | libpng [41] | Fix null pointer deference issue |
    | | [CVE-2016-10087] |
    | | |
    | libwmf [42] | Fix allocating huge block of memory |
    | | [CVE-2016-9011] |
    | | |
    | linkchecker [43] | Fix HTTPS checks |
    | | |
    | linux [44] | Update to stable 3.16.39; add chaoskey |
    | | driver, backported from 4.8, support for |
    | | n25q256a11 SPI flash device; |
    | | security,perf: Allow unprivileged use of |
    | | perf_event_open to be disabled; several |
    | | bug and security fixes |
    | | |
    | lxc [45] | Attach: do not send procfd to attached |
    | | process [CVE-2016-8649]; remount bind |
    | | mounts if read-only flag is provided; |
    | | fix Alpine Linux container creation |
    | | |
    | mapserver [46] | Fix FTBFS with php >= 5.6.25; fix |
    | | information leak via error messages |
    | | [CVE-2016-9839] |
    | | |
    | mdadm [47] | Allow '--grow --continue' to |
    | | successfully reshape an array when using |
    | | backup space on a 'spare' device |
    | | |
    | metar [48] | Update report URL |
    | | |
    | minissdpd [49] | Fix improper validation of array index |
    | | vulnerability [CVE-2016-3178 CVE-2016- |
    | | 3179] |
    | | |
    | monotone [50] | Change the sigpipe test case to write 1M |
    | | of test data to increase chances of |
    | | overflowing the pipe buffer |
    | | |
    | most [51] | Fix shell injection attack when opening |
    | | lzma-compressed files [CVE-2016-1253] |
    | | |
    | mpg123 [52] | Fix DoS with crafted ID3v2 tags |
    | | |
    | musl [53] | Fix integer overflow [CVE-2016-8859] |
    | | |
    | nbd [54] | Stop mixing global flags into the flags |
    | | field that gets sent to the kernel, so |
    | | that connecting to nbd-server >= 3.9 |
    | | does not cause every export to be |
    | | (incorrectly) marked as read-only |
    | | |
    | nettle [55] | Protect against potential side-channel |
    | | attacks against exponentiation |
    | | operations [CVE-2016-6489] |
    | | |
    | nss-pam-ldapd [56] | Have init script stop action only return |
    | | when nslcd has actually stopped |
    | | |
    | nvidia-graphics- | Update to new driver version, including |
    | drivers [57] | security fixes [CVE-2016-8826 CVE-2016- |
    | | 7382 CVE-2016-7389] |
    | | |
    | nvidia-graphics-drivers- | Update to new driver version, including |
    | legacy-304xx [58] | security fixes [CVE-2016-8826 CVE-2016- |
    | | 7382 CVE-2016-7389] |
    | | |
    | nvidia-graphics- | Rebuild against nvidia-kernel-source |
    | modules [59] | 340.101 |
    | | |
    | openbox [60] | Add libxcursor-dev build-dependency to |
    | | fix loading of startup notifications; |
    | | replace getgrent with getgroups so as |
    | | not to enumerate all groups at startup |
    | | |
    | opendkim [61] | Fix relaxed canonicalization of folded |
    | | headers, which broke signatures |
    | | |
    | pam [62] | Fix handling of loginuid in containers |
    | | |
    | pgpdump [63] | Fix endless loop parsing specially |
    | | crafted input in read_binary [CVE-2016- |
    | | 4021] and buffer overrun in read_radix64 |
    | | |
    | postgresql-9.4 [64] | New upstream release |
    | | |
    | postgresql-common [65] | Pg_upgradecluster: Properly upgrade |
    | | databases with non-login role owners; |
    | | pg_ctlcluster: Protect against symlink |
    | | in /var/log/postgresql/ allowing the |
    | | creation of arbitrary files elsewhere |
    | | [CVE-2016-1255] |
    | | |
    | potrace [66] | Security fixes [CVE-2016-8694 CVE-2016- |
    | | 8695 CVE-2016-8696 CVE-2016-8697 |
    | | CVE-2016-8698 CVE-2016-8699 CVE-2016- |
    | | 8700 CVE-2016-8701 CVE-2016-8702 |
    | | CVE-2016-8703] |
    | | |
    | python-crypto [67] | Raise a warning when IV is used with ECB |
    | | or CTR and ignore the IV [CVE-2013-7459] |
    | | |
    | python-werkzeug [68] | Fix XSS issue in debugger |
    | | |
    | qtbase-opensource- | Prevent bad-ptrs deref in |
    | src [69] | QNetworkConfigurationManagerPrivate; fix |
    | | X11 tray icons on some desktops |
    | | |
    | rawtherapee [70] | Fix buffer overflow in dcraw [CVE-2015- |
    | | 8366] |
    | | |
    | redmine [71] | Handle dependency check failure when |
    | | triggered, to avoid breaking in the |
    | | middle of dist-upgrades; avoid opening |
    | | database configuration that are not |
    | | readable |
    | | |
    | samba [72] | Fix "client side SMB2/3 required |
    | | signing can be downgraded" [CVE-2016- |
    | | 2119], various regressions introduced by |
    | | the 4.2.10 security fixes, segfault with |
    | | clustering |
    | | |
    | sed [73] | Ensure consistent permissions with |
    | | different umasks |
    | | |
    | shutter [74] | Fix insecure usage of system() |
    | | [CVE-2015-0854] |
    | | |
    | sniffit [75] | Security fix [CVE-2014-5439] |
    | | |
    | suckless-tools [76] | Fix SEGV in slock when user's account |
    | | has been disabled [CVE-2016-6866] |
    | | |
    | sympa [77] | Fix logrotate configuration so that |
    | | sympa is not left in a confused state |
    | | when systemd is used |
    | | |
    | systemd [78] | Don't return any error in |
    | | manager_dispatch_notify_fd() [CVE-2016- |
    | | 7796]; core: Rework logic to determine |
    | | when we decide to add automatic deps for |
    | | mounts; various ordering fixes for |
    | | ifupdown; systemctl: Fix argument |
    | | handling when invoked as shutdown; |
    | | localed: tolerate absence of /etc/ |
    | | default/keyboard; systemctl, loginctl, |
    | | etc.: Don't start polkit agent when |
    | | running as root |
    | | |
    | tevent [79] | New upstream version, required for samba |
    | | |
    | tre [80] | Fix regex integer overflow in buffer |
    | | size computations [CVE-2016-8859] |
    | | |
    | tzdata [81] | Update included data to 2016h; update to |
    | | 2016g; update to 2016j; update included |
    | | data to 2016i |
    | | |
    | unrtf [82] | Fix buffer overflow in various cmd_ |
    | | functions [CVE-2016-10091] |
    | | |
    | w3m [83] | Several security fixes [CVE-2016-9430 |
    | | CVE-2016-9434 CVE-2016-9438 CVE-2016- |
    | | 9440 CVE-2016-9441 CVE-2016-9423 |
    | | CVE-2016-9431 CVE-2016-9424 CVE-2016- |
    | | 9432 CVE-2016-9433 CVE-2016-9437 |
    | | CVE-2016-9422 CVE-2016-9435 CVE-2016- |
    | | 9436 CVE-2016-9426 CVE-2016-9425 |
    | | CVE-2016-9428 CVE-2016-9442 CVE-2016- |
    | | 9443 CVE-2016-9429 CVE-2016-9621 |
    | | CVE-2016-9439 CVE-2016-9622 CVE-2016- |
    | | 9623 CVE-2016-9624 CVE-2016-9625 |
    | | CVE-2016-9626 CVE-2016-9627 CVE-2016- |
    | | 9628 CVE-2016-9629 CVE-2016-9631 |
    | | CVE-2016-9630 CVE-2016-9632 CVE-2016- |
    | | 9633] |
    | | |
    | wireless-regdb [84] | Update included data |
    | | |
    | wot [85] | Remove plugin due to privacy issues |
    | | |
    | xwax [86] | Replace ffmpeg with avconv from libav- |
    | | tools |
    | | |
    | zookeeper [87] | Fix buffer overflow via the input |
    | | command when using the "cmd:" batch |
    | | mode syntax [CVE-2016-5017] |
    | | | +--------------------------+------------------------------------------+

    1: https://packages.debian.org/src:ark
    2: https://packages.debian.org/src:asterisk
    3: https://packages.debian.org/src:asused
    4: https://packages.debian.org/src:base-files
    5: https://packages.debian.org/src:bash
    6: https://packages.debian.org/src:ca-certificates
    7: https://packages.debian.org/src:cairo
    8: https://packages.debian.org/src:ccache
    9: https://packages.debian.org/src:ceph
    10: https://packages.debian.org/src:chirp
    11: https://packages.debian.org/src:cyrus-imapd-2.4
    12: https://packages.debian.org/src:darktable
    13: https://packages.debian.org/src:dbus
    14: https://packages.debian.org/src:debian-edu-doc
    15: https://packages.debian.org/src:debian-edu-install
    16: https://packages.debian.org/src:debian-installer
    17: https://packages.debian.org/src:debian-installer-netboot-images
    18: https://packages.debian.org/src:duck
    19: https://packages.debian.org/src:e2fsprogs
    20: https://packages.debian.org/src:ebook-speaker
    21: https://packages.debian.org/src:elog
    22: https://packages.debian.org/src:evolution-data-server
    23: https://packages.debian.org/src:exim4
    24: https://packages.debian.org/src:file
    25: https://packages.debian.org/src:ganeti-instance-debootstrap
    26: https://packages.debian.org/src:glibc
    27: https://packages.debian.org/src:glusterfs
    28: https://packages.debian.org/src:gnutls28
    29: https://packages.debian.org/src:hplip
    30: https://packages.debian.org/src:ieee-data
    31: https://packages.debian.org/src:intel-microcode
    32: https://packages.debian.org/src:irssi
    33: https://packages.debian.org/src:isenkram
    34: https://packages.debian.org/src:jq
    35: https://packages.debian.org/src:libclamunrar
    36: https://packages.debian.org/src:libdatetime-timezone-perl
    37: https://packages.debian.org/src:libfcgi-perl
    38: https://packages.debian.org/src:libio-socket-ssl-perl
    39: https://packages.debian.org/src:libmateweather
    40: https://packages.debian.org/src:libphp-adodb
    41: https://packages.debian.org/src:libpng
    42: https://packages.debian.org/src:libwmf
    43: https://packages.debian.org/src:linkchecker
    44: https://packages.debian.org/src:linux
    45: https://packages.debian.org/src:lxc
    46: https://packages.debian.org/src:mapserver
    47: https://packages.debian.org/src:mdadm
    48: https://packages.debian.org/src:metar
    49: https://packages.debian.org/src:minissdpd
    50: https://packages.debian.org/src:monotone
    51: https://packages.debian.org/src:most
    52: https://packages.debian.org/src:mpg123
    53: https://packages.debian.org/src:musl
    54: https://packages.debian.org/src:nbd
    55: https://packages.debian.org/src:nettle
    56: https://packages.debian.org/src:nss-pam-ldapd
    57: https://packages.debian.org/src:nvidia-graphics-drivers
    58: https://packages.debian.org/src:nvidia-graphics-drivers-legacy-304xx
    59: https://packages.debian.org/src:nvidia-graphics-modules
    60: https://packages.debian.org/src:openbox
    61: https://packages.debian.org/src:opendkim
    62: https://packages.debian.org/src:pam
    63: https://packages.debian.org/src:pgpdump
    64: https://packages.debian.org/src:postgresql-9.4
    65: https://packages.debian.org/src:postgresql-common
    66: https://packages.debian.org/src:potrace
    67: https://packages.debian.org/src:python-crypto
    68: https://packages.debian.org/src:python-werkzeug
    69: https://packages.debian.org/src:qtbase-opensource-src
    70: https://packages.debian.org/src:rawtherapee
    71: https://packages.debian.org/src:redmine
    72: https://packages.debian.org/src:samba
    73: https://packages.debian.org/src:sed
    74: https://packages.debian.org/src:shutter
    75: https://packages.debian.org/src:sniffit
    76: https://packages.debian.org/src:suckless-tools
    77: https://packages.debian.org/src:sympa
    78: https://packages.debian.org/src:systemd
    79: https://packages.debian.org/src:tevent
    80: https://packages.debian.org/src:tre
    81: https://packages.debian.org/src:tzdata
    82: https://packages.debian.org/src:unrtf
    83: https://packages.debian.org/src:w3m
    84: https://packages.debian.org/src:wireless-regdb
    85: https://packages.debian.org/src:wot
    86: https://packages.debian.org/src:xwax
    87: https://packages.debian.org/src:zookeeper

    Security Updates
    ----------------

    This revision adds the following security updates to the stable release.
    The Security Team has already released an advisory for each of these
    updates:

    +----------------+----------------------------+
    | Advisory ID | Package | +----------------+----------------------------+
    | DSA-3636 [88] | collectd [89] |
    | | |
    | DSA-3665 [90] | openjpeg2 [91] |
    | | |
    | DSA-3666 [92] | mysql-5.5 [93] |
    | | |
    | DSA-3667 [94] | chromium-browser [95] |
    | | |
    | DSA-3668 [96] | mailman [97] |
    | | |
    | DSA-3669 [98] | tomcat7 [99] |
    | | |
    | DSA-3670 [100] | tomcat8 [101] |
    | | |
    | DSA-3671 [102] | wireshark [103] |
    | | |
    | DSA-3672 [104] | irssi [105] |
    | | |
    | DSA-3673 [106] | openssl [107] |
    | | |
    | DSA-3674 [108] | firefox-esr [109] |
    | | |
    | DSA-3675 [110] | imagemagick [111] |
    | | |
    | DSA-3676 [112] | unadf [113] |
    | | |
    | DSA-3677 [114] | libarchive [115] |
    | | |
    | DSA-3678 [116] | python-django [117] |
    | | |
    | DSA-3679 [118] | jackrabbit [119] |
    | | |
    | DSA-3680 [120] | bind9 [121] |

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Fri Jun 5 17:52:51 2026
      from Sheboygan, Wi via Telnet
    • Gwylbert
      Fri Jun 5 06:28:52 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Thu Jun 4 23:42:23 2026
      from Berea, Ohio via Telnet
    • Michal Wronka
      Thu Jun 4 23:19:58 2026
      from Wroclaw, Poland via Telnet
    • Michal Wronka
      Thu Jun 4 23:17:20 2026
      from Wroclaw, Poland via SSH
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (3 / 13)
    Uptime: 143:20:17
    Calls: 12,089
    Calls today: 2
    Files: 15,000
    Messages: 6,517,461

© >>> Magnum BBS <<<, 2026