Security Fixes 10.06.120
Firefox
- Updated Firefox browser to version 60.8.0 ESR.
Fixed mfsa2019-22 security issues:
- Fixed mfsa2019-19 security issue CVE-2019-11708.
- Fixed mfsa2019-18 security issue CVE-2019-11707.
Fixed mfsa2019-08 security issues:
- Fixed mfsa2019-05 security issues CVE-2018-18356 and CVE-2019-5785.
- Fixed mfsa2019-02 security issues CVE-2018-18500, CVE-2018-18505 and CVE-2018-18501.
Shared Workplace
- Fixed login in Shared Workplace which accepts any user credentials in the 10.06.100 release. However, no user settings were applied to the device.
Base system
- Updated kernel to version 4.19.65.
- Fixed security issue CVE-2019-1125 aka Spectre SWAPGS gadget vulnerability.
- Fixed a vulnerability in Java configuration script.
- Fixed possibly malicious owner change with TC setup configuration.
- Fixed policykit-1 security issues CVE-2018-19788 and CVE-2019-6133.
- Fixed NSS security issues CVE-2018-18508, CVE-2018-12404, CVE-2018-12384 and CVE-2018-0495.
- Fixed PPP security issue CVE-2018-11574.
Fixed imagemagick security issues.
Fixed systemd security issues.
- Fixed CUPS security issue CVE-2018-4700.
Fixed libarchive security issues.
- Fixed avahi security issues CVE-2018-1000845 and CVE-2017-6519.
- Fixed bind9 security issues CVE-2019-6465, CVE-2018-5745, and CVE-2018-5743.
Fixed libcaca security issues.
- Fixed libgd2 security issues CVE-2019-6978 and CVE-2019-6977.
Fixed ghostscript security issues.
Fixed krb5 security issues.
- Fixed texlive-bin security issue CVE-2018-17407.
- Fixed LDB security issue CVE-2019-3824.
- Fixed libmspack security issues CVE-2018-18585 and CVE-2018-18584.
- Fixed Perl security issues CVE-2018-18314, CVE-2018-18313, CVE-2018-18312 and CVE-2018-18311.
Fixed poppler security issues.
- Fixed Python 3.5 security issues CVE-2018-14647, CVE-2018-1061, CVE-2018-1060 and CVE-2018-106.
- Fixed Net-SNMP security issue CVE-2018-18065.
- Fixed OpenSSL security issues CVE-2019-1559, CVE-2018-5407 and CVE-2018-0734.
Fixed TIFF security issues.
Fixed libvncserver security issues.
- Fixed WavPack security issue CVE-2018-19840.
Fixed Samba security issues.
Fixed libxkbcommon security issues.
Fixed OpenSSH security issues.
Fixed Python 2.7 security issues.
- Fixed lxml security issue CVE-2018-19787.
Fixed gdk-pixbuf security issues.
- Fixed file security issues CVE-2019-8907 and CVE-2019-8905.
- Fixed wget security issue CVE-2019-5953.
- Fixed nvidia-graphic-drivers-390 security issue CVE‑2018‑6260.
- Fixed libxslt security issue CVE-2019-11068.
- Fixed Evince security issue CVE-2019-11459.
Fixed webkit2gtk security issues.
- Fixed gst-plugins-base0.10 security issue CVE-2019-9928.
Fixed WPA security issues.
- Fixed Heimdal security issues CVE-2019-12098 and CVE-2018-16860.
- Fixed libimobiledevice security issue CVE-2016-5104.
- Fixed libpng1.6 security issues CVE-2019-7317 and CVE-2018-13785.
Fixed GIMP security issues.
- Fixed libtomcrypt security issue CVE-2018-12437.
Fixed curl security issues.
- Fixed gnutls28 security issues CVE-2018-10846, CVE-2018-10845, CVE-2018-10844 and CVE-2018-1084.
- Fixed qtbase-opensource-src security issues CVE-2018-19873, CVE-2018-19870 and CVE-2018-15518.
- Fixed db5.3 security issue CVE-2019-8457.
Fixed libssh2 security issues.
- Fixed network-manager security issue CVE-2018-15688.
Fixed elfutils security issues.
Fixed libsndfile security issues.
- Fixed dbus security issue CVE-2019-12749.
Fixed Vim security issues CVE-2019-12735 and CVE-2017-5953.
Fixed sqlite3 security issues.- Fixed libseccomp security issue CVE-2019-9893.
- Fixed bzip2 security issues CVE-2019-12900 and CVE-2016-3189.
- Fixed Expat security issue CVE-2018-20843.
- Fixed unzip security issues CVE-2019-13232, CVE-2018-1000035, CVE-2016-9844 and CVE-2014-9913.
- Mount partitions with "nodev" flag option.
- The home directory of the remote users is now /home/ruser.
- Default umask is set to 0077 for all non-root users.
- Fixed a vulnerability in the custom environment variable framework.
- Fixed kernel TCP vulnerabilities CVE-2019-11477: SACK Panic, CVE-2019-11478: SACK Slowness and CVE-2019-11479: Excess Resource Consumption Due to Low MSS Values.
- Changed minimally allowed MSS size to "1000" to prevent possible denial-of-service attacks.