From 90fa2570505dbca1725a78f3d098a91bdf2159e7 Mon Sep 17 00:00:00 2001 From: David Michael Date: Tue, 19 Mar 2019 13:51:44 +0000 Subject: [PATCH] bump(metadata/glsa): sync with upstream --- .../portage-stable/metadata/glsa/Manifest | 30 +++++------ .../metadata/glsa/Manifest.files.gz | Bin 437429 -> 437590 bytes .../metadata/glsa/glsa-201903-15.xml | 50 ++++++++++++++++++ .../metadata/glsa/timestamp.chk | 2 +- .../metadata/glsa/timestamp.commit | 2 +- 5 files changed, 67 insertions(+), 17 deletions(-) create mode 100644 sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201903-15.xml diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest b/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest index 80ca09e0ad..7ad3d4e290 100644 --- a/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest @@ -1,23 +1,23 @@ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 -MANIFEST Manifest.files.gz 437429 BLAKE2B d71793c37518c554e77bcce22a3ca061890ae72b465c007c31dd2c429c8174741829feddc258347929fc21c74551873bd6be78db810aced844a0e1c497853ff8 SHA512 00d0bfb813b46cc0d061cd7f833014ba841445d5bb2ae0b2ba659c73836487cf7bae990c575667b3cc73306bb0dc54613f22d4fd84afe2cd7cee60f090008f3e -TIMESTAMP 2019-03-14T14:08:54Z +MANIFEST Manifest.files.gz 437590 BLAKE2B 89b5299a2ae5909a2f126e7d079e486a46a84b314ae3fd8e955c116ff1469671110300e3034ae816a3f8d7760ff951864b0f6a2ea8e63f69093f03e040aaa3f5 SHA512 af2b9c5421b1ff957533cc161bb0347cbaa2e3e90c9069b5b7e6141ce2a943b1cc971aacd34224e34915a04db19e7b1d06ff5519de5e8c67f4753e7fc7157bf3 +TIMESTAMP 2019-03-19T13:08:41Z -----BEGIN PGP SIGNATURE----- -iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAlyKYHZfFIAAAAAALgAo +iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAlyQ6dlfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEUx RDZBQkI2M0JGQ0ZCNEJBMDJGREYxQ0VDNTkwRUVBQzkxODkyNTAACgkQ7FkO6skY -klBZJQ//ZmGGCLyldR1zfBkQiVyYfY4xs3/AVZH+ZToWmEDYQ2Vx+FADUBloGgz7 -7zHL21o5+/KhkHinIaAETPvnUo8iiLpX0uC4HPjwwtmBldzE6no5evgpCHgh1j9+ -Kw/tFPRJ9wAavy824jAF8eFoOK6zsZWCL4QPIUTDUZER+fxCCGD35MDti4z9FBsE -jmcrRZWMZGCElNfTwBhI7aaQ01MM9CCw5yeaOZlmHjRbkO003e2Rr8EMWlUZIoHL -9UL+1hdrKNxwLqRtBTX23SBeCfVyG8hHOSGQm6Iy7DJesHSpuGWYQAc7P3Pog5Yz -7x4xanJ33mCDlxyZHRL6Ct35dgIS9+NdgWoQyPepKbxwM/EGliOVoy/5g045SueO -6e3yOSZzSXCQxEEHycKBqOMWMl+VTycN/fi54ArMlo39to5g7JbEF4T+Q2zB2a2J -0Dev4IkKyyJ4fK0JWQPrkhNNB3u//Wlry/g/TYWV1abFftoBrRLU8N4axwq5jJtH -twQAFmVtDAF1lrqVW/VoaKcOL0IM2HVDYHfLPCtRBjVkya/6xotL4+CiQ0AQcK88 -zZUPQpNP8PrkAZ8gDElNm+hbIBsY0G2Z0/oJWnOHbchcs6oq0Uf1tT4qOI/NPZgK -nqAytoy5ciJjvqXC1jKuYVpu2XnZlzNeHcyYZE5SilRAvle7i+M= -=nBaS +klCiIxAAtD8h+ihAUDvqNvCC9SdERlHiKbmJk96TjCAugmmp8BSF9AMOa7YktfUR +yfNqRUI2kG5hBz9OxV3ll1NyIB8knAoBnYEZsCSqCuCM1UXdiolduYy+bWrXeN57 +f5VtmkPXhCJEfDbURbCMBkraAVOYbBjV5f3P80zmmKgRawMOiQLAtDGSBgfDDWue +83ILR2ZANa+GCluDVEe9Y5+50D5ydKCdWFDD7YOC5gpM/98Yj4idOguQV1IBA0dv +9VPtH1amWCmmuYuPgkHAzyQpYAKFeWGZaCbaHVkhDPv15/BS05zKMqWbTCYcC14C +nn3JBR8tPPR135NG1n9skFg/ycTcfaJfkqZ1Mweh5NrJzsass9qEGMIK7sNsclcF +90SONSRWPzwasHtLoTs5uYp4Vtv04BdPOQDutoGenOrA+p83Phef3Qydn6TgVSfg +hwQTV8LyT7U7elU77+t4QiwMX090K++Ey4/zTZW/cdafiGRT+pMfY5/8SD0gb7lm +VRoyEz2IQxsHg84jRfC72jkpiDwRlJgFacbdy+Rzx5kRgJvA63c0GtQZNwTI4dQt +pK+Hnubpv+AP9BW89D3rpbdEYBr7mXS2Lx8ZW6zl0deBYUL77V3KBPDqC0au9usz +uQOXjuOvugjnJd9bnHS/ArJ30VJ01wVhqIktgyLzq1A7/jvOmK8= +=9XkB -----END PGP SIGNATURE----- diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest.files.gz b/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest.files.gz index 131fc099a6cc3a3a7aefa67a43388caf67954a49..01756e23b684a7b93a0b99dd6d5b10a42afa3fa8 100644 GIT binary patch delta 682 zcmV;b0#*IB*&5c`8i0fWgaU*Egam{IvHDWj!pF(6W>Y5;u5>kEj{ zf1ra4zaXL=9c0;_tk&OG435sFATsJGIF=o4&fmNgu4p{cohA{M@bJT&@YtCsAT@WHx zYOIVC&?1wTT{fnadb08PY_;AyDfcTUIxBq$M&|ep?NX`0C>0L*1qu|BngBOjS-LD~ zFK>M=aFR3&kKTd~M*La?0(+}!X|5OPptf|%v_+)0i!La*XvI}~tM(m5iTD5Rf436y zY~7k{1J<^!T7^n@5n6n9mW2O-xL40T6P2lF%WxvpmKJKzIw4nwoyKU*(w&j<{&A40 zs5q@xGQlHlAv?O_Oa+xyE`lI!g?@Gt-~CSGe+~zls*#+=sml(@qeyKFt4?2D;3e^Y zjdT)Nf-T&93MI1dUeyY+EB0{7ewrqM!Uq?a$Bzkd7v>BHmo-rpYe{`=$Y6vxjeAO5=E QUmq`j05nx+X+NtB0LO_^lmGw# delta 519 zcmV+i0{H#b+8VXl8i0fWgaU*Egam{IvT~Fs&`CV%Cy0HY{o zO1)XQxjzRQ!0=qopb_pruY$066N`HvmQl ze-&K#1tZweMV4?UTEDLtT%8?3B+${|TK4F0ey}N=!FZHAMIxl~Wb2rnngmg#DIFT1spmj4OLIC7aJF~)F%n2QKD~&&KKF?gBW*JL9Ll;}mxf^~0(RLS+*)b5lkh{)V zhUd+xmu(RZt0e38G+gcU8CSdDXv^gcJ64@@&3QRaWwn@@@8$KB$jb29rMVI6NDCY^cay8=q%l}?sqVEU+S>h+el@5l4U=baC~w(W8|`~X}- J0^1R)3;@Z6{to~E diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201903-15.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201903-15.xml new file mode 100644 index 0000000000..7683138d59 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201903-15.xml @@ -0,0 +1,50 @@ + + + + NTP: Multiple vulnerabilities + Multiple vulnerabilities have been found in NTP, the worst of which + could result in the remote execution of arbitrary code. + + ntp + 2019-03-19 + 2019-03-19 + 658576 + 679742 + remote + + + 4.2.8_p13 + 4.2.8_p13 + + + +

NTP contains software for the Network Time Protocol.

+
+ +

Multiple vulnerabilities have been discovered in NTP. Please review the + CVE identifiers referenced below for details. +

+
+ +

An attacker could cause a Denial of Service condition, escalate + privileges, or remotely execute arbitrary code. +

+
+ +

There is no known workaround at this time.

+
+ +

All NTP users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/ntp-4.2.8_p13" + +
+ + CVE-2018-12327 + CVE-2019-8936 + + BlueKnight + b-man +
diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.chk b/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.chk index df2152bdbe..234ab236bd 100644 --- a/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.chk +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.chk @@ -1 +1 @@ -Thu, 14 Mar 2019 14:08:50 +0000 +Tue, 19 Mar 2019 13:08:37 +0000 diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.commit b/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.commit index 43c20f3996..98bcf26d91 100644 --- a/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.commit +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.commit @@ -1 +1 @@ -17152e28d973dd918d88b38fdcc6e83f34c921f2 1552527902 2019-03-14T01:45:02+00:00 +0a72c299702ffceee8f32f22b9d7b2c33e5140a0 1552965642 2019-03-19T03:20:42+00:00