Security Fixes 11.03.100
Firefox
- Updated Mozilla Firefox to 68.2.0esr
Fixes for mfsa2019-33.
Fixes for mfsa2019-26.
Base system
- Added cryptographic signatures to OS 11 firmware files to prevent reading from corrupt images or disks.
- Updates to firmwares without valid signatures are blocked.
- When a signature error on the system partition is detected, the system is halted immediately. For system recovery a reinstallation via the OS Creator tool (OSC) is required.
A signature error during early boot is signalized by a beep sequence. When a signature error in another partition is detected the partition is removed and a firmware update is triggered to reinstall the corrupt partition.
- Added user visible notification about partition signature errors.
- Fixed admin logout from rescue shell after suspend.
- Fixed security issue CVE-2019-15902 in 4.19.x kernel.
- Updated Intel microcodes to version 20191115 to fix various security issues (CVE-2019-11135, CVE-2019-0117 and CVE-2019-11139).
- Fixed cups security issues CVE-2019-8696, CVE-2019-8675 and CVE-2019-86.
- Fixed openjpeg2 security issues CVE-2018-6616, CVE-2018-5785, CVE-2018-18088, CVE-2018-14423 and CVE-2017-17480.
- Fixed xorg-server security issue CVE-2018-14665.
- Fixed expat security issue CVE-2019-15903.
- Fixed freetype security issue CVE-2015-9383.
Fixed ghostscript security issues.
Fixed python2.7 security issues.
Fixed python3.5 security issues.
- Fixed giflib security issues CVE-2019-15133 and CVE-2018-11490.
Fixed libvirt security issues.
- Fixed e2fsprogs security issue CVE-2019-5094.
- Fixed rpcbind security issues CVE-2017-8779 and CVE-2015-7236.
- Fixed wpa security issues CVE-2019-16275 and CVE-2019-13377.
- Fixed tiff security issues CVE-2019-17546 and CVE-2019-14973.
- Fixed aspell security issue CVE-2019-17544.
Fixed libsdl1.2 security issues.
- Fixed libsoup2.4 security issues CVE-2019-17266, CVE-2018-12910 and CVE-2017-2885.
- Fixed rtlwifi driver security issue CVE-2019-17666 .
- Fixed libxslt security issues CVE-2019-18197, CVE-2019-13118 and CVE-2019-13117.
- Fixed opus security issue CVE-2017-0381.
- Fixed curl security issues CVE-2019-5482 and CVE-2019-5481.
- Fixed libidn2 security issues CVE-2019-18224 and CVE-2019-12290.
- Fixed libarchive security issue CVE-2019-18408.
- Fixed samba security issues CVE-2019-14847 and CVE-2019-10218.
- Fixed file security issue CVE-2019-18218.
Fixed imagemagick security issues.
- Fixed libjpeg-turbo security issues CVE-2019-2201, CVE-2018-20330 and CVE-2018-19664.
- Fixed python-ecdsa security issues CVE-2019-14859, CVE-2019-14853 and CVE-2019-1485.
- Restricted access to journalctl log file for root only.
Limit list of allowed TLS ciphers according to the Germany BSI recommendation (TR-0210202 Version 2019-01). The functionality is controlled by a parameter.