diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest b/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest index 61dd37b893..f1ef660e97 100644 --- a/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest @@ -1,23 +1,23 @@ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 -MANIFEST Manifest.files.gz 449647 BLAKE2B 8803d7d7f47c464cfd8f60beebc66a2a666a58eced0da3542b3aa3258b2801c9603a06ee88dc1b3d88b18763967fd4df415a2267ef2059485f617f508c374276 SHA512 19ad2e1287d270dc62f5d69c91b20e5b243af42fac29e8d0aef1d81bebaee04f64f471f8dadc1f923158b7380eb0face42df28d6a6f48575d0150c58354966e3 -TIMESTAMP 2019-11-22T17:38:48Z +MANIFEST Manifest.files.gz 450288 BLAKE2B 3798da941a15fcee18382da626450662d799e35257d8ad4a0b1552a6ddaae69d623b969c7ea2a3ff528f29e7ea6067f37208f6499dc6674753bd8f0bc73ac9b6 SHA512 c989a03018fd5d5d0ec3658457962a1285eb9736eaf370cd03c34b1c2e6807a141280958db2771efc54eda1120570c478512f7e244686722c0c6fc53bcfde64c +TIMESTAMP 2019-11-25T18:08:47Z -----BEGIN PGP SIGNATURE----- -iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAl3YHShfFIAAAAAALgAo +iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAl3cGK9fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEUx RDZBQkI2M0JGQ0ZCNEJBMDJGREYxQ0VDNTkwRUVBQzkxODkyNTAACgkQ7FkO6skY -klB87w//UoGHDGr8v7UijB9Op29ia5ExY66P8cQLQah48TTTzUFJuhW+1cxaxuM8 -8TtUbHf7n6HwmFs35WrsjI3zDMYxz67gKQtu4sCEDBvq0k/7wOmVomxa6Idt+ADC -BfmkdbYLiRDpnBc3l/uLgMCrocUTmrCoH/BjDAlh0tW8ViuQ1ah72dtmhwOPtkkK -mH4PPzOFPujoIGwn7lgQE2MPinExpgQ1x31mMNUvqld2OXMmm1VrjcF7LD6WxjuL -gAFcPnVf8ru/H/gMD14/VZ1Lkf7a7jV3aDOZk7dj+0+G9rDRWMcnLga+N3nnlizk -8I2E3mGM6U858gc7TZkPxycsV35PGCCOWg9HoHRDkjfe5gCR97tVHrREBPnUa8hT -fbSRic6HO0fLb4tX3w7y4GdiUDeQ9IarZngkbWpy8ZDRFhIonYDj8N1drWfSQu15 -lwGu3s7R2HAhGfO3HxhXuHpbmxf3TQlayBASyXofp3zx+hCCUdKXD/O+NwfqNveE -57SQ3lW0kEWL2jQgvocn4LiMzrDuMImAiwubcY5nfXaQZWwjSIV1T+MVcC/kb9Yt -JzKWlTFOl8eaNnjiXA8wMU4cLNFW4v9OQfrqrKUT8kO3nWkB20aiqPJxp0XRRA+B -jR1SxQVNdu2P2JmJOpuS0m5ybAubZ0oIG0Y0VtqRYIboolBXjFQ= -=uGfw +klD6eBAApy6F7OqvbNHOVDfc0l99xjuiTuxAyp5DZ87Z0b635086T9+HLyFh2TuW +FlVMqkPe05RVyOH6Tq+fEmixQfzWucRdFCV9IpAdzIgLCue/4Ey1v/mZhoYqj3ve +2JUrfCmYKNU1N5qqdkSqdHG88wH/XjABodvPJLC3pgAMVQZ0Ln/t0HGwDr+q/zo8 +N6sUV34fvm8aF5qQfJCyaoOTmJQNDAuZ7t0Dcfz8XlHCgOFSsW03gyIxeUJfdaRW +ADn0WJGAgyXhtMdQJMTRZ5H3n79B9VaNOJAuSR1SHv6MZf0ARgYpAT9QeQE1LH4y +CMQfmqHu/pHGJxAxOqV4Q7/bV6Ppv5iIXjCysEA66ySGLn/ZSX/aMssooe9l/ymi +rMkbovWSnq4B4o6JwqtRFONliQ/N/axJWTn9hcndsJRqv/kF5AVSXyogBMQQb8rR +hz76WpLx9ccwnFnrfRLLOBY1MVBSrBH7cj5jEv/uK26E48CwACJjDvJ6FREAJzx7 +AWyGIGFS0fEwOiBEYWzLb46CsWNPMqm9js2002ygUe/FgnOQ0GwxX5y2UMvPn58h +1tHsy+RYTGE7VkKCMvw7RdNZZ3zDu1Zi/iFIArK4gtgrD7Ojf/XPNcpNVQz3MSh9 +GJe1zeh4iKwlMJnsMydIP3UZTSc7V85Y/+t5JEYCj72swdPbr8U= +=AYYs -----END PGP SIGNATURE----- diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest.files.gz b/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest.files.gz index 87a4ce20a9..07b7a7ec9a 100644 Binary files a/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest.files.gz and b/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest.files.gz differ diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201911-05.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201911-05.xml new file mode 100644 index 0000000000..24d2ac578a --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201911-05.xml @@ -0,0 +1,50 @@ + + + + Adobe Flash Player: Multiple vulnerabilities + Multiple vulnerabilities have been found in Adobe Flash Player, the + worst of which could result in the arbitrary execution of code. + + adobe,flash + 2019-11-25 + 2019-11-25 + 694352 + remote + + + 32.0.0.255 + 32.0.0.255 + + + +

The Adobe Flash Player is a renderer for the SWF file format, which is + commonly used to provide interactive websites. +

+
+ +

Multiple vulnerabilities have been discovered in Adobe Flash Player. + Please review the CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Adobe Flash Player users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose + ">=www-plugins/adobe-flash-32.0.0.255" + +
+ + CVE-2019-8069 + CVE-2019-8070 + + whissi + b-man +
diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201911-06.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201911-06.xml new file mode 100644 index 0000000000..5a18614823 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201911-06.xml @@ -0,0 +1,135 @@ + + + + Chromium, Google Chrome: Multiple vulnerabilities + Multiple vulnerabilities have been found in Chromium and Google + Chrome, the worst of which could result in the arbitrary execution of code. + + chromium,chrome,google + 2019-11-25 + 2019-11-25 + 692916 + 694002 + 694954 + 697506 + 698398 + 699068 + remote + + + 78.0.3904.87 + 78.0.3904.87 + + + 78.0.3904.87 + 78.0.3904.87 + + + +

Chromium is an open-source browser project that aims to build a safer, + faster, and more stable way for all users to experience the web. +

+ +

Google Chrome is one fast, simple, and secure browser for all your + devices. +

+
+ +

Multiple vulnerabilities have been discovered in Chromium and Google + Chrome. Please review the CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Chromium users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose + ">=www-client/chromium-78.0.3904.87" + + +

All Google Chrome users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose + ">=www-client/google-chrome-78.0.3904.87" + +
+ + CVE-2019-13659 + CVE-2019-13660 + CVE-2019-13661 + CVE-2019-13662 + CVE-2019-13663 + CVE-2019-13664 + CVE-2019-13665 + CVE-2019-13666 + CVE-2019-13667 + CVE-2019-13668 + CVE-2019-13669 + CVE-2019-13670 + CVE-2019-13671 + CVE-2019-13673 + CVE-2019-13674 + CVE-2019-13675 + CVE-2019-13676 + CVE-2019-13677 + CVE-2019-13678 + CVE-2019-13679 + CVE-2019-13680 + CVE-2019-13681 + CVE-2019-13682 + CVE-2019-13683 + CVE-2019-13685 + CVE-2019-13686 + CVE-2019-13687 + CVE-2019-13688 + CVE-2019-13693 + CVE-2019-13694 + CVE-2019-13695 + CVE-2019-13696 + CVE-2019-13697 + CVE-2019-13699 + CVE-2019-13700 + CVE-2019-13701 + CVE-2019-13703 + CVE-2019-13704 + CVE-2019-13705 + CVE-2019-13706 + CVE-2019-13707 + CVE-2019-13708 + CVE-2019-13709 + CVE-2019-13710 + CVE-2019-13711 + CVE-2019-13713 + CVE-2019-13714 + CVE-2019-13715 + CVE-2019-13716 + CVE-2019-13717 + CVE-2019-13718 + CVE-2019-13719 + CVE-2019-13721 + CVE-2019-5869 + CVE-2019-5870 + CVE-2019-5871 + CVE-2019-5872 + CVE-2019-5873 + CVE-2019-5874 + CVE-2019-5875 + CVE-2019-5876 + CVE-2019-5877 + CVE-2019-5878 + CVE-2019-5879 + CVE-2019-5880 + CVE-2019-5881 + + whissi + b-man +
diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201911-07.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201911-07.xml new file mode 100644 index 0000000000..bc52455147 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201911-07.xml @@ -0,0 +1,66 @@ + + + + Mozilla Firefox: Multiple vulnerabilities + Multiple vulnerabilities have been found in Mozilla Firefox, the + worst of which could result in the arbitrary execution of code. + + firefox + 2019-11-25 + 2019-11-25 + 693442 + 698512 + remote + + + 68.2.0 + 68.2.0 + + + 68.2.0 + 68.2.0 + + + +

Mozilla Firefox is a popular open-source web browser from the Mozilla + Project. +

+
+ +

Multiple vulnerabilities have been discovered in Mozilla Firefox. Please + review the CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Firefox users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/firefox-68.2.0" + + +

All Firefox binary users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/firefox-bin-68.2.0" + +
+ + CVE-2019-11740 + CVE-2019-11742 + CVE-2019-11743 + CVE-2019-11744 + CVE-2019-11746 + CVE-2019-11752 + CVE-2019-9812 + + b-man + b-man +
diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201911-08.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201911-08.xml new file mode 100644 index 0000000000..4a8bad9133 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-201911-08.xml @@ -0,0 +1,48 @@ + + + + Expat: Multiple vulnerabilities + Multiple vulnerabilities have been found in Expat, the worst of + which could result in a Denial of Service condition. + + expat + 2019-11-25 + 2019-11-25 + 688734 + 694362 + remote + + + 2.2.8 + 2.2.8 + + + +

Expat is a set of XML parsing libraries.

+
+ +

Multiple vulnerabilities have been discovered in Expat. Please review + the CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Expat users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-libs/expat-2.2.8" + +
+ + CVE-2018-20843 + CVE-2019-15903 + + whissi + b-man +
diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.chk b/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.chk index caca29ca0b..ad596e5625 100644 --- a/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.chk +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.chk @@ -1 +1 @@ -Fri, 22 Nov 2019 17:38:45 +0000 +Mon, 25 Nov 2019 18:08:44 +0000 diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.commit b/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.commit index 3d9c875b21..14ac9c2950 100644 --- a/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.commit +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.commit @@ -1 +1 @@ -435541275775881e78e6acc96aca7536a5955224 1574160598 2019-11-19T10:49:58+00:00 +751af6f91da06f53265195cff434eb66a145af73 1574641117 2019-11-25T00:18:37+00:00