Security Fixes 10.05.100
Firefox
Updated Mozilla Firefox to version 60.2.2esr.
- Firefox profile partition is now mounted at /userhome/.mozilla instead of /.ffpro.
- Firefox could only be started as user.
- For security reasons Java processes could not be started from a browser session now.
Added a registry parameter
java.browser.access
to control java access for all browser sessions.
Network
- Disabled ICMP redirects.
- Changed default LoginGraceTime from 120 to 30 sec.
Added new registry keys for a secure sshd configuration.
- Fixed SCEP client certificate request file access rights.
Base system
Added apparmor as an additional security layer for components like Firefox, evince, dhcpclient and cups.
- For security reasons graphical terminal sessions could now only be started by an administrator when an admin password is set. Administrator must authenticate before a terminal session is started. This does also affect graphical terminal sessions spawned by applications.
To allow users to start a terminal session again a registry key is defined.
- Fixed open-vm-tools security issue CVE-2015-5191.
- Fixed procps security issues CVE-2018-1126, CVE-2018-1125, CVE-2018-1124, CVE-2018-1123 and CVE-2018-1122.
Fixed imagemagick security issues.
- Fixed elfutils security issues CVE-2017-7613, CVE-2017-7612, CVE-2017-7611, CVE-2017-7610, CVE-2017-7609, CVE-2017-7608, CVE-2017-7607, CVE-2016-10255 and CVE-2016-10254.
- Fixed ghostscript security issues CVE-2018-10194, CVE-2016-10317, CVE-2018-16802, CVE-2018-16585, CVE-2018-16543, CVE-2018-16542, CVE-2018-16541, CVE-2018-16540, CVE-2018-16539, CVE-2018-16513, CVE-2018-16511, CVE-2018-16509, CVE-2018-15911, CVE-2018-15910, CVE-2018-15909, CVE-2018-15908, CVE-2018-11645, CVE-2018-1, CVE-2018-17183 and CVE-2018-16510.
- Fixed icu security issue CVE-2017-15422.
Fixed webkit2gtk security issues.
- Fixed perl security issues CVE-2018-6913, CVE-2018-6798, CVE-2018-6797, CVE-2017-6512, CVE-2016-6185 and CVE-2018-12015.
- Fixed poppler security issues CVE-2017-18267 and CVE-2018-13988.
- Fixed openssl security issues CVE-2018-0739, CVE-2018-0737, CVE-2018-0737, CVE-2018-0732 and CVE-2018-0495.
Fixed tiff security issues.
- Fixed libvncserver security issue CVE-2018-7225.
- Fixed libvorbis security issue CVE-2018-5146.
- Fixed samba security issues CVE-2018-1057, CVE-2018-1050, CVE-2018-10919 and CVE-2018-10858.
- Fixed wget security issue CVE-2018-0494.
- Fixed bluez security issue CVE-2017-1000250.
- Fixed libgcrypt20 security issue CVE-2018-0495.
- Fixed file security issue CVE-2018-10360.
- Fixed gnupg2 security issue CVE-2018-12020.
- Fixed isc-dhcp security issues CVE-2018-5733, CVE-2018-5732, CVE-2018-573, CVE-2017-3144 and CVE-2016-2774.
- Fixed curl security issues CVE-2018-1000303, CVE-2018-1000301, CVE-2018-1000300, CVE-2018-1000122, CVE-2018-1000121, CVE-2018-1000120, CVE-2017-8818, CVE-2018-14618 and CVE-2018-0500.
- Fixed python3.5 security issues CVE-2017-1000158, CVE-2016-5636, CVE-2016-1000110 and CVE-2016-0772.
- Fixed zlib security issues CVE-2016-9843, CVE-2016-9842, CVE-2016-9841 and CVE-2016-9840.
- Fixed libsoup2.4 security issue CVE-2018-12910.
- Fixed libjpeg-turbo security issue CVE-2018-1152.
- Fixed ntp security issues CVE-2018-7185 and CVE-2018-7183.
- Fixed libpng1.6 security issue CVE-2018-13785.
- Fixed cups security issues CVE-2018-6553, CVE-2018-4181, CVE-2018-4180, CVE-2018-418 and CVE-2017-18248.
- Fixed libpng security issue CVE-2016-10087.
- Fixed policykit-1 security issue CVE-2018-1116.
- Fixed jansson security issue CVE-2016-4425.
- Fixed libmspack security issues CVE-2018-14682, CVE-2018-14681, CVE-2018-14680 and CVE-2018-14679.
- Fixed libonig security issues CVE-2017-9229, CVE-2017-9228, CVE-2017-9227, CVE-2017-9226 and CVE-2017-9224.
- Fixed libxcursor security issue CVE-2015-9262.
- Fixed heimdal security issue CVE-2017-17439.
- Fixed libarchive security issues CVE-2017-14503, CVE-2017-14501, CVE-2017-14166, CVE-2016-10350, CVE-2016-10349 and CVE-2016-10209.
- Fixed libxml2 security issues CVE-2018-14567, CVE-2018-14404, CVE-2017-18258 and CVE-2016-9318.
- Fixed confuse security issue CVE-2018-14447.
- Fixed libgd2 security issues CVE-2018-5711 and CVE-2018-1000222.
- Fixed libx11 security issues CVE-2018-14600, CVE-2018-14599, CVE-2018-14598, CVE-2016-7943 and CVE-2016-7942.
- Fixed mpg123 security issues CVE-2017-10683 and CVE-2016-1000247.
- Fixed libtirpc security issues CVE-2018-14622, CVE-2017-8779 and CVE-2016-4429.
- Fixed jq security issue CVE-2015-8863.
- Fixed bind9 security issue CVE-2018-5740.
- Fixed lcms2 security issue CVE-2018-16435.
- Fixed xdg-utils security issue CVE-2017-18266.
- Root home is now /root.
- Removed system group (GID 0) which shadowed root group (GID 0).
- Stricter folder and file permissions.
X11 system
- Restricted desktop icon creation to administrator only. Therefore, "/userhome/Desktop" is owned by root now.