-
Notifications
You must be signed in to change notification settings - Fork 2.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update Ubuntu (esp. for CVE-2017-9445) #3311
Conversation
Diff:diff --git a/_bashbrew-list b/_bashbrew-list
index ba7222d..6d13801 100644
--- a/_bashbrew-list
+++ b/_bashbrew-list
@@ -3,13 +3,13 @@ ubuntu:16.04
ubuntu:17.04
ubuntu:17.10
ubuntu:artful
-ubuntu:artful-20170716
+ubuntu:artful-20170728
ubuntu:devel
ubuntu:latest
ubuntu:rolling
ubuntu:trusty
-ubuntu:trusty-20170719
+ubuntu:trusty-20170728
ubuntu:xenial
-ubuntu:xenial-20170710
+ubuntu:xenial-20170802
ubuntu:zesty
ubuntu:zesty-20170703
diff --git a/ubuntu_devel/build-info.txt b/ubuntu_devel/build-info.txt
index 20c4cfd..a0fd21a 100644
--- a/ubuntu_devel/build-info.txt
+++ b/ubuntu_devel/build-info.txt
@@ -1 +1 @@
-SERIAL=20170716
+SERIAL=20170728
diff --git a/ubuntu_devel/ubuntu-artful-core-cloudimg-amd64-root.tar.gz b/ubuntu_devel/ubuntu-artful-core-cloudimg-amd64-root.tar.gz
index 1b35220..347a177 100644
Binary files a/ubuntu_devel/ubuntu-artful-core-cloudimg-amd64-root.tar.gz and b/ubuntu_devel/ubuntu-artful-core-cloudimg-amd64-root.tar.gz differ
diff --git a/ubuntu_devel/ubuntu-artful-core-cloudimg-amd64-root.tar.gz 'tar -t' b/ubuntu_devel/ubuntu-artful-core-cloudimg-amd64-root.tar.gz 'tar -t'
index 8977097..258875d 100644
--- a/ubuntu_devel/ubuntu-artful-core-cloudimg-amd64-root.tar.gz 'tar -t'
+++ b/ubuntu_devel/ubuntu-artful-core-cloudimg-amd64-root.tar.gz 'tar -t'
@@ -51,7 +51,6 @@ bin/sleep
bin/stty
bin/su
bin/sync
-bin/tailf
bin/tar
bin/tempfile
bin/touch
@@ -678,7 +677,6 @@ usr/bin/last
usr/bin/lastb
usr/bin/lastlog
usr/bin/ldd
-usr/bin/line
usr/bin/link
usr/bin/linux32
usr/bin/linux64
@@ -717,7 +715,6 @@ usr/bin/paste
usr/bin/pathchk
usr/bin/perl
usr/bin/perl5.24.1
-usr/bin/pg
usr/bin/pgrep
usr/bin/pinentry
usr/bin/pinentry-curses
@@ -1876,7 +1873,6 @@ usr/sbin/rmt-tar
usr/sbin/rtcwake
usr/sbin/service
usr/sbin/tarcat
-usr/sbin/tunelp
usr/sbin/update-passwd
usr/sbin/update-rc.d
usr/sbin/useradd
@@ -1961,7 +1957,6 @@ usr/share/bash-completion/completions/mountpoint
usr/share/bash-completion/completions/namei
usr/share/bash-completion/completions/nsenter
usr/share/bash-completion/completions/partx
-usr/share/bash-completion/completions/pg
usr/share/bash-completion/completions/pivot_root
usr/share/bash-completion/completions/prlimit
usr/share/bash-completion/completions/raw
@@ -1980,9 +1975,7 @@ usr/share/bash-completion/completions/sfdisk
usr/share/bash-completion/completions/swaplabel
usr/share/bash-completion/completions/swapoff
usr/share/bash-completion/completions/swapon
-usr/share/bash-completion/completions/tailf
usr/share/bash-completion/completions/taskset
-usr/share/bash-completion/completions/tunelp
usr/share/bash-completion/completions/umount
usr/share/bash-completion/completions/unshare
usr/share/bash-completion/completions/utmpdump
@@ -2559,6 +2552,8 @@ usr/share/doc/util-linux/releases/v2.25-ReleaseNotes.gz
usr/share/doc/util-linux/releases/v2.26-ReleaseNotes.gz
usr/share/doc/util-linux/releases/v2.27-ReleaseNotes.gz
usr/share/doc/util-linux/releases/v2.28-ReleaseNotes.gz
+usr/share/doc/util-linux/releases/v2.29.1-ReleaseNotes.gz
+usr/share/doc/util-linux/releases/v2.29.2-ReleaseNotes
usr/share/doc/util-linux/releases/v2.29-ReleaseNotes.gz
usr/share/doc/util-linux/source-code-management.txt
usr/share/doc/zlib1g/
@@ -3353,7 +3348,6 @@ usr/share/man/man1/kbxutil.1.gz
usr/share/man/man1/kill.1.gz
usr/share/man/man1/last.1.gz
usr/share/man/man1/lastb.1.gz
-usr/share/man/man1/line.1.gz
usr/share/man/man1/link.1.gz
usr/share/man/man1/linux32.1.gz
usr/share/man/man1/linux64.1.gz
@@ -3397,7 +3391,6 @@ usr/share/man/man1/paste.1.gz
usr/share/man/man1/pathchk.1.gz
usr/share/man/man1/perl.1.gz
usr/share/man/man1/perl5.24.1.1.gz
-usr/share/man/man1/pg.1.gz
usr/share/man/man1/pgrep.1.gz
usr/share/man/man1/pinentry.1.gz
usr/share/man/man1/pinentry-curses.1.gz
@@ -3461,7 +3454,6 @@ usr/share/man/man1/sync.1.gz
usr/share/man/man1/tabs.1.gz
usr/share/man/man1/tac.1.gz
usr/share/man/man1/tail.1.gz
-usr/share/man/man1/tailf.1.gz
usr/share/man/man1/tar.1.gz
usr/share/man/man1/tarcat.1.gz
usr/share/man/man1/taskset.1.gz
@@ -3732,7 +3724,6 @@ usr/share/man/man8/swapon.8.gz
usr/share/man/man8/switch_root.8.gz
usr/share/man/man8/sysctl.8.gz
usr/share/man/man8/tune2fs.8.gz
-usr/share/man/man8/tunelp.8.gz
usr/share/man/man8/umount.8.gz
usr/share/man/man8/unix_chkpwd.8.gz
usr/share/man/man8/unix_update.8.gz
@@ -4591,7 +4582,6 @@ var/lib/dpkg/info/libustr-1.0-1:amd64.symbols
var/lib/dpkg/info/libustr-1.0-1:amd64.triggers
var/lib/dpkg/info/libuuid1:amd64.list
var/lib/dpkg/info/libuuid1:amd64.md5sums
-var/lib/dpkg/info/libuuid1:amd64.postinst
var/lib/dpkg/info/libuuid1:amd64.shlibs
var/lib/dpkg/info/libuuid1:amd64.symbols
var/lib/dpkg/info/libuuid1:amd64.triggers
diff --git a/ubuntu_devel/ubuntu-artful-core-cloudimg-amd64.manifest b/ubuntu_devel/ubuntu-artful-core-cloudimg-amd64.manifest
index 1d4d955..0916ccb 100644
--- a/ubuntu_devel/ubuntu-artful-core-cloudimg-amd64.manifest
+++ b/ubuntu_devel/ubuntu-artful-core-cloudimg-amd64.manifest
@@ -3,10 +3,10 @@ apt 1.5~beta1
base-files 9.6ubuntu101
base-passwd 3.5.43
bash 4.4-5ubuntu1
-bsdutils 1:2.29-1ubuntu3
+bsdutils 1:2.29.2-2ubuntu1
coreutils 8.26-3ubuntu3
dash 0.5.8-2.3ubuntu1
-debconf 1.5.60ubuntu1
+debconf 1.5.63
debianutils 4.8.1.1
diffutils 1:3.5-3
dpkg 1.18.24ubuntu1
@@ -27,15 +27,15 @@ libassuan0:amd64 2.4.3-2
libattr1:amd64 1:2.4.47-2build1
libaudit-common 1:2.7.7-1ubuntu1
libaudit1:amd64 1:2.7.7-1ubuntu1
-libblkid1:amd64 2.29-1ubuntu3
+libblkid1:amd64 2.29.2-2ubuntu1
libbz2-1.0:amd64 1.0.6-8.1
-libc-bin 2.24-9ubuntu2
-libc6:amd64 2.24-9ubuntu2
-libcap-ng0:amd64 0.7.7-3
+libc-bin 2.24-12ubuntu1
+libc6:amd64 2.24-12ubuntu1
+libcap-ng0:amd64 0.7.7-3build1
libcomerr2:amd64 1.43.4-2
libdb5.3:amd64 5.3.28-13
libdebconfclient0:amd64 0.213ubuntu1
-libfdisk1:amd64 2.29-1ubuntu3
+libfdisk1:amd64 2.29.2-2ubuntu1
libffi6:amd64 3.2.1-6
libgcc1:amd64 1:7.1.0-7ubuntu1
libgcrypt20:amd64 1.7.8-2
@@ -47,7 +47,7 @@ libidn11:amd64 1.33-1
libksba8:amd64 1.3.5-2
liblz4-1:amd64 0.0~r131-2ubuntu2
liblzma5:amd64 5.2.2-1.2
-libmount1:amd64 2.29-1ubuntu3
+libmount1:amd64 2.29.2-2ubuntu1
libncurses5:amd64 6.0+20160625-1ubuntu1
libncursesw5:amd64 6.0+20160625-1ubuntu1
libnettle6:amd64 3.3-1
@@ -57,28 +57,28 @@ libpam-modules:amd64 1.1.8-3.2ubuntu3
libpam-modules-bin 1.1.8-3.2ubuntu3
libpam-runtime 1.1.8-3.2ubuntu3
libpam0g:amd64 1.1.8-3.2ubuntu3
-libpcre3:amd64 2:8.39-3
+libpcre3:amd64 2:8.39-4
libprocps6:amd64 2:3.3.12-1ubuntu2
libreadline7:amd64 7.0-0ubuntu2
libselinux1:amd64 2.6-3build1
libsemanage-common 2.6-2build1
libsemanage1:amd64 2.6-2build1
libsepol1:amd64 2.6-2
-libsmartcols1:amd64 2.29-1ubuntu3
-libsqlite3-0:amd64 3.19.3-2
+libsmartcols1:amd64 2.29.2-2ubuntu1
+libsqlite3-0:amd64 3.19.3-3
libss2:amd64 1.43.4-2
libstdc++6:amd64 7.1.0-7ubuntu1
libsystemd0:amd64 233-8ubuntu3
-libtasn1-6:amd64 4.12-2
+libtasn1-6:amd64 4.12-2.1
libtinfo5:amd64 6.0+20160625-1ubuntu1
libudev1:amd64 233-8ubuntu3
libustr-1.0-1:amd64 1.0.4-6
-libuuid1:amd64 2.29-1ubuntu3
+libuuid1:amd64 2.29.2-2ubuntu1
login 1:4.2-3.2ubuntu2
lsb-base 9.20160110ubuntu5
mawk 1.3.3-17ubuntu2
-mount 2.29-1ubuntu3
-multiarch-support 2.24-9ubuntu2
+mount 2.29.2-2ubuntu1
+multiarch-support 2.24-12ubuntu1
ncurses-base 6.0+20160625-1ubuntu1
ncurses-bin 6.0+20160625-1ubuntu1
passwd 1:4.2-3.2ubuntu2
@@ -89,7 +89,7 @@ readline-common 7.0-0ubuntu2
sed 4.4-1
sensible-utils 0.0.9+nmu1
sysvinit-utils 2.88dsf-59.8git1
-tar 1.29b-1.1
+tar 1.29b-2
ubuntu-keyring 2016.10.27
-util-linux 2.29-1ubuntu3
+util-linux 2.29.2-2ubuntu1
zlib1g:amd64 1:1.2.11.dfsg-0ubuntu1
diff --git a/ubuntu_latest/build-info.txt b/ubuntu_latest/build-info.txt
index 8511328..7d4dc56 100644
--- a/ubuntu_latest/build-info.txt
+++ b/ubuntu_latest/build-info.txt
@@ -1 +1 @@
-SERIAL=20170710
+SERIAL=20170802
diff --git a/ubuntu_latest/ubuntu-xenial-core-cloudimg-amd64-root.tar.gz b/ubuntu_latest/ubuntu-xenial-core-cloudimg-amd64-root.tar.gz
index 4233355..c7bd623 100644
Binary files a/ubuntu_latest/ubuntu-xenial-core-cloudimg-amd64-root.tar.gz and b/ubuntu_latest/ubuntu-xenial-core-cloudimg-amd64-root.tar.gz differ
diff --git a/ubuntu_latest/ubuntu-xenial-core-cloudimg-amd64-root.tar.gz 'tar -t' b/ubuntu_latest/ubuntu-xenial-core-cloudimg-amd64-root.tar.gz 'tar -t'
index a3b3782..b4f52b1 100644
--- a/ubuntu_latest/ubuntu-xenial-core-cloudimg-amd64-root.tar.gz 'tar -t'
+++ b/ubuntu_latest/ubuntu-xenial-core-cloudimg-amd64-root.tar.gz 'tar -t'
@@ -450,6 +450,7 @@ etc/systemd/system/sysinit.target.wants/
etc/systemd/system/sysinit.target.wants/systemd-timesyncd.service
etc/systemd/system/timers.target.wants/
etc/systemd/system/timers.target.wants/apt-daily.timer
+etc/systemd/system/timers.target.wants/apt-daily-upgrade.timer
etc/systemd/timesyncd.conf
etc/systemd/user/
etc/systemd/user.conf
@@ -488,6 +489,8 @@ lib/systemd/network/80-container-ve.network
lib/systemd/system/
lib/systemd/system/apt-daily.service
lib/systemd/system/apt-daily.timer
+lib/systemd/system/apt-daily-upgrade.service
+lib/systemd/system/apt-daily-upgrade.timer
lib/systemd/system/autovt@.service
lib/systemd/system/basic.target
lib/systemd/system/bluetooth.target
@@ -756,6 +759,8 @@ lib/systemd/system/systemd-random-seed.service
lib/systemd/system/systemd-reboot.service
lib/systemd/system/systemd-remount-fs.service
lib/systemd/system/systemd-resolved.service
+lib/systemd/system/systemd-resolved.service.d/
+lib/systemd/system/systemd-resolved.service.d/resolvconf.conf
lib/systemd/system/systemd-rfkill.service
lib/systemd/system/systemd-rfkill.socket
lib/systemd/system/systemd-suspend.service
@@ -5485,8 +5490,10 @@ var/lib/systemd/catalog/
var/lib/systemd/catalog/database
var/lib/systemd/deb-systemd-helper-enabled/
var/lib/systemd/deb-systemd-helper-enabled/apt-daily.timer.dsh-also
+var/lib/systemd/deb-systemd-helper-enabled/apt-daily-upgrade.timer.dsh-also
var/lib/systemd/deb-systemd-helper-enabled/timers.target.wants/
var/lib/systemd/deb-systemd-helper-enabled/timers.target.wants/apt-daily.timer
+var/lib/systemd/deb-systemd-helper-enabled/timers.target.wants/apt-daily-upgrade.timer
var/lib/update-rc.d/
var/lib/urandom/
var/local/
diff --git a/ubuntu_latest/ubuntu-xenial-core-cloudimg-amd64.manifest b/ubuntu_latest/ubuntu-xenial-core-cloudimg-amd64.manifest
index 23c0c8a..f0b9bf9 100644
--- a/ubuntu_latest/ubuntu-xenial-core-cloudimg-amd64.manifest
+++ b/ubuntu_latest/ubuntu-xenial-core-cloudimg-amd64.manifest
@@ -1,6 +1,6 @@
adduser 3.113+nmu3ubuntu4
-apt 1.2.20
-base-files 9.4ubuntu4.4
+apt 1.2.24
+base-files 9.4ubuntu4.5
base-passwd 3.5.39
bash 4.3-14ubuntu1.2
bsdutils 1:2.27.1-6ubuntu3.3
@@ -26,7 +26,7 @@ initscripts 2.88dsf-59.3ubuntu2
insserv 1.14.0-5ubuntu3
libacl1:amd64 2.2.52-3
libapparmor1:amd64 2.10.95-0ubuntu2.6
-libapt-pkg5.0:amd64 1.2.20
+libapt-pkg5.0:amd64 1.2.24
libattr1:amd64 1:2.4.47-2
libaudit-common 1:2.4.5-1ubuntu2
libaudit1:amd64 1:2.4.5-1ubuntu2
@@ -45,7 +45,7 @@ libfdisk1:amd64 2.27.1-6ubuntu3.3
libgcc1:amd64 1:6.0.1-0ubuntu1
libgcrypt20:amd64 1.6.5-2ubuntu0.3
libgpg-error0:amd64 1.21-2ubuntu1
-libkmod2:amd64 22-1ubuntu4
+libkmod2:amd64 22-1ubuntu5
liblz4-1:amd64 0.0~r131-2ubuntu2
liblzma5:amd64 5.1.1alpha+20120614-2ubuntu2
libmount1:amd64 2.27.1-6ubuntu3.3
@@ -66,9 +66,9 @@ libsepol1:amd64 2.4-2
libsmartcols1:amd64 2.27.1-6ubuntu3.3
libss2:amd64 1.42.13-1ubuntu1
libstdc++6:amd64 5.4.0-6ubuntu1~16.04.4
-libsystemd0:amd64 229-4ubuntu17
+libsystemd0:amd64 229-4ubuntu19
libtinfo5:amd64 6.0+20160213-1ubuntu1
-libudev1:amd64 229-4ubuntu17
+libudev1:amd64 229-4ubuntu19
libusb-0.1-4:amd64 2:0.1.12-28
libustr-1.0-1:amd64 1.0.4-5
libuuid1:amd64 2.27.1-6ubuntu3.3
@@ -86,8 +86,8 @@ procps 2:3.3.10-4ubuntu2.3
readline-common 6.3-8ubuntu2
sed 4.2.2-7
sensible-utils 0.0.9
-systemd 229-4ubuntu17
-systemd-sysv 229-4ubuntu17
+systemd 229-4ubuntu19
+systemd-sysv 229-4ubuntu19
sysv-rc 2.88dsf-59.3ubuntu2
sysvinit-utils 2.88dsf-59.3ubuntu2
tar 1.28-2.1ubuntu0.1
diff --git a/ubuntu_trusty/build-info.txt b/ubuntu_trusty/build-info.txt
index 47dc49d..a0fd21a 100644
--- a/ubuntu_trusty/build-info.txt
+++ b/ubuntu_trusty/build-info.txt
@@ -1 +1 @@
-SERIAL=20170719
+SERIAL=20170728
diff --git a/ubuntu_trusty/ubuntu-trusty-core-cloudimg-amd64-root.tar.gz b/ubuntu_trusty/ubuntu-trusty-core-cloudimg-amd64-root.tar.gz
index f55b0ec..a9741ae 100644
Binary files a/ubuntu_trusty/ubuntu-trusty-core-cloudimg-amd64-root.tar.gz and b/ubuntu_trusty/ubuntu-trusty-core-cloudimg-amd64-root.tar.gz differ
diff --git a/ubuntu_trusty/ubuntu-trusty-core-cloudimg-amd64.manifest b/ubuntu_trusty/ubuntu-trusty-core-cloudimg-amd64.manifest
index fbf4eb4..af6cdaf 100644
--- a/ubuntu_trusty/ubuntu-trusty-core-cloudimg-amd64.manifest
+++ b/ubuntu_trusty/ubuntu-trusty-core-cloudimg-amd64.manifest
@@ -66,7 +66,7 @@ libdb5.3:amd64 5.3.28-3ubuntu3
libdbus-1-3:amd64 1.6.18-0ubuntu4.5
libdebconfclient0:amd64 0.187ubuntu1
libdevmapper1.02.1:amd64 2:1.02.77-6ubuntu2
-libdrm2:amd64 2.4.67-1ubuntu0.14.04.1
+libdrm2:amd64 2.4.67-1ubuntu0.14.04.2
libestr0 0.1.9-0ubuntu2
libexpat1:amd64 2.1.0-4ubuntu1.4
libffi6:amd64 3.1~rc1+r3.0.13-12ubuntu0.1
@@ -149,7 +149,7 @@ ncurses-bin 5.9+20140118-1ubuntu1
net-tools 1.60-25ubuntu2.1
netbase 5.2
netcat-openbsd 1.105-7ubuntu1
-ntpdate 1:4.2.6.p5+dfsg-3ubuntu2.14.04.11
+ntpdate 1:4.2.6.p5+dfsg-3ubuntu2.14.04.12
passwd 1:4.1.5.1-1ubuntu9.5
perl 5.18.2-2ubuntu1.1
perl-base 5.18.2-2ubuntu1.1
@@ -162,7 +162,7 @@ python3.4 3.4.3-1ubuntu1~14.04.5
python3.4-minimal 3.4.3-1ubuntu1~14.04.5
readline-common 6.3-4ubuntu2
resolvconf 1.69ubuntu1.1
-rsyslog 7.4.4-1ubuntu2.6
+rsyslog 7.4.4-1ubuntu2.7
sed 4.2.2-4ubuntu1
sensible-utils 0.0.9
sudo 1.8.9p5-1ubuntu1.4 |
This does not include the necessary bump for zesty 😞 (https://partner-images.canonical.com/core/zesty/ 😢) |
The zesty update for the CVE is already included: https://launchpad.net/ubuntu/zesty/+source/systemd "Uploaded: 2017-06-21" |
Missing |
@NeQuissimus it's included in the archive, but not in the published tarballs from Canonical |
Oh... bad Canonical! :D |
cc @OddBloke @gaughen -- shouldn't artful and zesty have triggered rebuilds for CVE-2017-9445 ? (xenial is updated and trusty is not-affected, but zesty and artful tarballs appear to still be outdated) |
Doh, thanks @OddBloke: |
Build test of #3311; cbeea22 ( $ bashbrew build ubuntu:17.10
Building bashbrew/cache:515506c456e31e9b27322710758d360cc96a796a08f4b3ef1d09407004da45b5 (ubuntu:17.10)
Tagging ubuntu:17.10
Tagging ubuntu:artful-20170728
Tagging ubuntu:artful
Tagging ubuntu:devel
$ test/run.sh ubuntu:17.10
testing ubuntu:17.10
'utc' [1/5]...passed
'cve-2014--shellshock' [2/5]...passed
'no-hard-coded-passwords' [3/5]...passed
'override-cmd' [4/5]...passed
'debian-apt-get' [5/5]...passed
$ bashbrew build ubuntu:14.04
Building bashbrew/cache:48de62e5fdaf9050eca4343fd47899a201ea9506e0bf0c1f2f902b4aead1ee29 (ubuntu:14.04)
Tagging ubuntu:14.04
Tagging ubuntu:trusty-20170728
Tagging ubuntu:trusty
$ test/run.sh ubuntu:14.04
testing ubuntu:14.04
'utc' [1/5]...passed
'cve-2014--shellshock' [2/5]...passed
'no-hard-coded-passwords' [3/5]...passed
'override-cmd' [4/5]...passed
'debian-apt-get' [5/5]...passed
$ bashbrew build ubuntu:16.04
Building bashbrew/cache:afcb24c3b9afc307dff3127d5c8d952b3f491b9bdef0e040a64efcee7a2f8c2b (ubuntu:16.04)
Tagging ubuntu:16.04
Tagging ubuntu:xenial-20170802
Tagging ubuntu:xenial
Tagging ubuntu:latest
$ test/run.sh ubuntu:16.04
testing ubuntu:16.04
'utc' [1/5]...passed
'cve-2014--shellshock' [2/5]...passed
'no-hard-coded-passwords' [3/5]...passed
'override-cmd' [4/5]...passed
'debian-apt-get' [5/5]...passed
$ bashbrew build ubuntu:17.04
Building bashbrew/cache:a9c861c634fdfeb7a8986465843d0667d48cdae85fa8f9eb99e6e5ea2e502d04 (ubuntu:17.04)
Tagging ubuntu:17.04
Tagging ubuntu:zesty-20170703
Tagging ubuntu:zesty
Tagging ubuntu:rolling
$ test/run.sh ubuntu:17.04
testing ubuntu:17.04
'utc' [1/5]...passed
'cve-2014--shellshock' [2/5]...passed
'no-hard-coded-passwords' [3/5]...passed
'override-cmd' [4/5]...passed
'debian-apt-get' [5/5]...passed
|
https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-9445.html