[ubuntu/xenial-proposed] python-apt 1.1.0~beta1ubuntu0.16.04.2 (Accepted)

2018-07-11 Thread Julian Andres Klode
python-apt (1.1.0~beta1ubuntu0.16.04.2) xenial; urgency=medium * python/tag.cc: Fix invalid read in TagFileNext * DepCache: Check that candidate we are setting belongs to package * Raise CacheMismatchError if objects passed to DepCache are from different cache (LP: #1737441); also inclu

[ubuntu/xenial-security] imagemagick 8:6.8.9.9-7ubuntu5.12 (Accepted)

2018-07-11 Thread Marc Deslauriers
imagemagick (8:6.8.9.9-7ubuntu5.12) xenial-security; urgency=medium * SECURITY UPDATE: out-of-bounds write in ReadBMPImage and WriteBMPImage - debian/patches/CVE-2018-12599.patch: use proper lengths in coders/bmp.c. - CVE-2018-12599 * SECURITY UPDATE: out-of-bounds write in ReadD

[ubuntu/xenial-updates] imagemagick 8:6.8.9.9-7ubuntu5.12 (Accepted)

2018-07-11 Thread Ubuntu Archive Robot
imagemagick (8:6.8.9.9-7ubuntu5.12) xenial-security; urgency=medium * SECURITY UPDATE: out-of-bounds write in ReadBMPImage and WriteBMPImage - debian/patches/CVE-2018-12599.patch: use proper lengths in coders/bmp.c. - CVE-2018-12599 * SECURITY UPDATE: out-of-bounds write in ReadD

[ubuntu/xenial-proposed] ceph 10.2.10-0ubuntu0.16.04.1 (Accepted)

2018-07-11 Thread James Page
ceph (10.2.10-0ubuntu0.16.04.1) xenial; urgency=medium * d/watch: Scope to 10.2.x series, use tarball download site. * New upstream point release (LP: #1780930). Date: Wed, 11 Jul 2018 11:10:52 +0100 Changed-By: James Page Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/+source/c

[ubuntu/xenial-security] libpng 1.2.54-1ubuntu1.1 (Accepted)

2018-07-11 Thread Leonidas S. Barbosa
libpng (1.2.54-1ubuntu1.1) xenial-security; urgency=medium * SECURITY UPDATE: Null pointer dereference - debian/patches/CVE-2016-10087.patch: fix in png.c. - CVE-2016-10087 Date: 2018-07-10 20:18:21.479601+00:00 Changed-By: leo.barb...@canonical.com (Leonidas S. Barbosa) https://launchp

[ubuntu/xenial-updates] libpng 1.2.54-1ubuntu1.1 (Accepted)

2018-07-11 Thread Ubuntu Archive Robot
libpng (1.2.54-1ubuntu1.1) xenial-security; urgency=medium * SECURITY UPDATE: Null pointer dereference - debian/patches/CVE-2016-10087.patch: fix in png.c. - CVE-2016-10087 Date: 2018-07-10 20:18:21.479601+00:00 Changed-By: leo.barb...@canonical.com (Leonidas S. Barbosa) Signed-By: Ubun

[ubuntu/xenial-security] cups 2.1.3-4ubuntu0.5 (Accepted)

2018-07-11 Thread Marc Deslauriers
cups (2.1.3-4ubuntu0.5) xenial-security; urgency=medium * SECURITY UPDATE: scheduler crash via DBUS notifications - debian/patches/CVE-2017-18248.patch: validate requesting-user-name in scheduler/ipp.c. - CVE-2017-18248 * SECURITY UPDATE: privilege escalation in dnssd backend

[ubuntu/xenial-updates] cups 2.1.3-4ubuntu0.5 (Accepted)

2018-07-11 Thread Ubuntu Archive Robot
cups (2.1.3-4ubuntu0.5) xenial-security; urgency=medium * SECURITY UPDATE: scheduler crash via DBUS notifications - debian/patches/CVE-2017-18248.patch: validate requesting-user-name in scheduler/ipp.c. - CVE-2017-18248 * SECURITY UPDATE: privilege escalation in dnssd backend