Oracle Linux Bulletin - April 2018

Description

The Oracle Linux Bulletin lists all CVEs that had been resolved and announced in Oracle Linux Security Advisories (ELSA) in the last one month prior to the release of the bulletin. Oracle Linux Bulletins are published on the same day as Oracle Critical Patch Updates are released. These bulletins will also be updated for the following two months after their release (i.e., the two months between the normal quarterly Critical Patch Update publication dates) to cover all CVEs that had been resolved in those two months following the bulletin's publication. In addition, Oracle Linux Bulletins may also be updated for vulnerability fixes deemed too critical to wait for the next scheduled bulletin publication date.

Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Oracle Linux Bulletin fixes as soon as possible.

Patch Availability

Please see ULN Advisory http://linux.oracle.com/ol-pad-bulletin

Oracle Linux Bulletin Schedule

Oracle Linux Bulletins are released on the Tuesday closest to the 17th day of January, April, July and October. The next four dates are:

  • 17 July 2018
  • 16 October 2018
  • 15 January 2019
  • 16 April 2019

References

Modification History

2018-June-18 Rev 3. New CVEs added.
2018-May-21 Rev 2. New CVEs added.
2018-April-17 Rev 1. Initial Release

Oracle Linux Executive Summary

This Oracle Linux Bulletin contains 133 new security fixes for the Oracle Linux.  133 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password. 

Oracle Linux Risk Matrix

Revision 3: Published on 2018-06-18

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 2.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base Score Access Vector Access Complexity Authen­tication Confid­entiality Inte­grity Avail­ability
CVE-2017-1000410 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-18203 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-1000199 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-10323 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-10675 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-3639 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-5333 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-5750 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-6927 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-3639 Oracle Linux java-1.7.0-openjdk Undefined 6,7
CVE-2018-3639 Oracle Linux java-1.8.0-openjdk Undefined 6,7
CVE-2018-3639 Oracle Linux kernel Undefined 6
CVE-2018-3639 Oracle Linux kernel Undefined 7
CVE-2018-3665 Oracle Linux kernel Undefined 7
CVE-2018-3639 Oracle Linux libvirt Undefined 6,7
CVE-2018-1124 Oracle Linux procps Undefined 6
CVE-2018-1126 Oracle Linux procps Undefined 6
CVE-2018-1124 Oracle Linux procps-ng Undefined 7
CVE-2018-1126 Oracle Linux procps-ng Undefined 7
CVE-2018-3639 Oracle Linux qemu-kvm Undefined 6,7
CVE-2018-5150 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5154 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5155 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5159 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5161 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5162 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5168 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5170 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5178 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5183 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5184 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5185 Oracle Linux thunderbird Undefined 6,7
CVE-2016-5003 Oracle Linux xmlrpc3 Undefined 6
CVE-2016-2384 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2016-2543 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2016-2544 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2016-2545 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2016-2547 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2016-2548 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2016-2549 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2017-16939 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-1000199 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2018-3665 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7

Revision 2: Published on 2018-05-21

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 2.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base Score Access Vector Access Complexity Authen­tication Confid­entiality Inte­grity Avail­ability
CVE-2018-1089 Oracle Linux 389-ds-base Undefined 7
CVE-2018-1089 Oracle Linux 389-ds-base Undefined 6
CVE-2018-1106 Oracle Linux PackageKit Undefined 7
CVE-2017-15116 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-15129 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-15299 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-15537 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-16532 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-16646 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-16994 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-17448 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-17449 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-17741 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-7294 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-1068 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-1087 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-5332 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-8897 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-1084 Oracle Linux corosync Undefined 7
CVE-2018-1111 Oracle Linux dhcp Undefined 6,7
CVE-2018-5148 Oracle Linux firefox Undefined 7
CVE-2018-5150 Oracle Linux firefox Undefined 6,7
CVE-2018-5154 Oracle Linux firefox Undefined 6,7
CVE-2018-5155 Oracle Linux firefox Undefined 6,7
CVE-2018-5157 Oracle Linux firefox Undefined 6,7
CVE-2018-5158 Oracle Linux firefox Undefined 6,7
CVE-2018-5159 Oracle Linux firefox Undefined 6,7
CVE-2018-5168 Oracle Linux firefox Undefined 6,7
CVE-2018-5178 Oracle Linux firefox Undefined 6,7
CVE-2018-5183 Oracle Linux firefox Undefined 6,7
CVE-2018-2790 Oracle Linux java-1.7.0-openjdk Undefined 6,7
CVE-2018-2794 Oracle Linux java-1.7.0-openjdk Undefined 6,7
CVE-2018-2795 Oracle Linux java-1.7.0-openjdk Undefined 6,7
CVE-2018-2796 Oracle Linux java-1.7.0-openjdk Undefined 6,7
CVE-2018-2797 Oracle Linux java-1.7.0-openjdk Undefined 6,7
CVE-2018-2798 Oracle Linux java-1.7.0-openjdk Undefined 6,7
CVE-2018-2799 Oracle Linux java-1.7.0-openjdk Undefined 6,7
CVE-2018-2800 Oracle Linux java-1.7.0-openjdk Undefined 6,7
CVE-2018-2814 Oracle Linux java-1.7.0-openjdk Undefined 6,7
CVE-2018-2815 Oracle Linux java-1.7.0-openjdk Undefined 6,7
CVE-2018-2790 Oracle Linux java-1.8.0-openjdk Undefined 6,7
CVE-2018-2794 Oracle Linux java-1.8.0-openjdk Undefined 6,7
CVE-2018-2795 Oracle Linux java-1.8.0-openjdk Undefined 6,7
CVE-2018-2796 Oracle Linux java-1.8.0-openjdk Undefined 6,7
CVE-2018-2797 Oracle Linux java-1.8.0-openjdk Undefined 6,7
CVE-2018-2798 Oracle Linux java-1.8.0-openjdk Undefined 6,7
CVE-2018-2799 Oracle Linux java-1.8.0-openjdk Undefined 6,7
CVE-2018-2800 Oracle Linux java-1.8.0-openjdk Undefined 6,7
CVE-2018-2814 Oracle Linux java-1.8.0-openjdk Undefined 6,7
CVE-2018-2815 Oracle Linux java-1.8.0-openjdk Undefined 6,7
CVE-2017-1000410 Oracle Linux kernel Undefined 6
CVE-2017-13166 Oracle Linux kernel Undefined 6
CVE-2017-18017 Oracle Linux kernel Undefined 6
CVE-2017-7645 Oracle Linux kernel Undefined 6
CVE-2017-8824 Oracle Linux kernel Undefined 6
CVE-2018-8897 Oracle Linux kernel Undefined 6
CVE-2017-16939 Oracle Linux kernel Undefined 7
CVE-2018-1000199 Oracle Linux kernel Undefined 7
CVE-2018-1068 Oracle Linux kernel Undefined 7
CVE-2018-1087 Oracle Linux kernel Undefined 7
CVE-2018-1091 Oracle Linux kernel Undefined 7
CVE-2018-8897 Oracle Linux kernel Undefined 7
CVE-2018-1000140 Oracle Linux librelp Undefined 6,7
CVE-2018-1064 Oracle Linux libvirt Undefined 7
CVE-2018-5748 Oracle Linux libvirt Undefined 7
CVE-2018-7225 Oracle Linux libvncserver Undefined 7
CVE-2018-5146 Oracle Linux libvorbis Undefined 7
CVE-2018-1000156 Oracle Linux patch Undefined 6,7
CVE-2018-1000119 Oracle Linux pcs Undefined 7
CVE-2018-1079 Oracle Linux pcs Undefined 7
CVE-2018-1086 Oracle Linux pcs Undefined 7
CVE-2018-7858 Oracle Linux qemu-kvm Undefined 7
CVE-2017-12146 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-15299 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2017-16532 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2017-16537 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2017-16643 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-16645 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-17448 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2017-17558 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2018-100199 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-1068 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2018-1093 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-5332 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2018-8897 Oracle Linux Unbreakable Enterprise kernel Undefined 6

Revision 1: Published on 2018-04-17

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 2.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base Score Access Vector Access Complexity Authen­tication Confid­entiality Inte­grity Avail­ability
CVE-2018-5146 Oracle Linux firefox Undefined 6,7
CVE-2018-5148 Oracle Linux firefox Undefined 6
CVE-2017-11671 Oracle Linux gcc Undefined 7
CVE-2014-9402 Oracle Linux glibc Undefined 7
CVE-2015-5180 Oracle Linux glibc Undefined 7
CVE-2017-12132 Oracle Linux glibc Undefined 7
CVE-2017-15670 Oracle Linux glibc Undefined 7
CVE-2017-15804 Oracle Linux glibc Undefined 7
CVE-2018-1000001 Oracle Linux glibc Undefined 7
CVE-2016-3672 Oracle Linux kernel Undefined 7
CVE-2016-7913 Oracle Linux kernel Undefined 7
CVE-2016-8633 Oracle Linux kernel Undefined 7
CVE-2017-1000252 Oracle Linux kernel Undefined 7
CVE-2017-1000407 Oracle Linux kernel Undefined 7
CVE-2017-1000410 Oracle Linux kernel Undefined 7
CVE-2017-12154 Oracle Linux kernel Undefined 7
CVE-2017-12190 Oracle Linux kernel Undefined 7
CVE-2017-13166 Oracle Linux kernel Undefined 7
CVE-2017-14140 Oracle Linux kernel Undefined 7
CVE-2017-15116 Oracle Linux kernel Undefined 7
CVE-2017-15121 Oracle Linux kernel Undefined 7
CVE-2017-15126 Oracle Linux kernel Undefined 7
CVE-2017-15127 Oracle Linux kernel Undefined 7
CVE-2017-15129 Oracle Linux kernel Undefined 7
CVE-2017-15265 Oracle Linux kernel Undefined 7
CVE-2017-17448 Oracle Linux kernel Undefined 7
CVE-2017-17449 Oracle Linux kernel Undefined 7
CVE-2017-17558 Oracle Linux kernel Undefined 7
CVE-2017-18017 Oracle Linux kernel Undefined 7
CVE-2017-18203 Oracle Linux kernel Undefined 7
CVE-2017-7294 Oracle Linux kernel Undefined 7
CVE-2017-8824 Oracle Linux kernel Undefined 7
CVE-2017-9725 Oracle Linux kernel Undefined 7
CVE-2018-1000004 Oracle Linux kernel Undefined 7
CVE-2018-5750 Oracle Linux kernel Undefined 7
CVE-2018-6927 Oracle Linux kernel Undefined 7
CVE-2017-11368 Oracle Linux krb5 Undefined 7
CVE-2017-7562 Oracle Linux krb5 Undefined 7
CVE-2018-5146 Oracle Linux libvorbis Undefined 6
CVE-2017-6462 Oracle Linux ntp Undefined 7
CVE-2017-6463 Oracle Linux ntp Undefined 7
CVE-2017-6464 Oracle Linux ntp Undefined 7
CVE-2017-15906 Oracle Linux openssh Undefined 7
CVE-2017-3736 Oracle Linux openssl Undefined 7
CVE-2017-3737 Oracle Linux openssl Undefined 7
CVE-2017-3738 Oracle Linux openssl Undefined 7
CVE-2018-1063 Oracle Linux policycoreutils Undefined 7
CVE-2018-7750 Oracle Linux python-paramiko Undefined 6
CVE-2017-13672 Oracle Linux qemu-kvm Undefined 7
CVE-2017-13711 Oracle Linux qemu-kvm Undefined 7
CVE-2017-15124 Oracle Linux qemu-kvm Undefined 7
CVE-2017-15268 Oracle Linux qemu-kvm Undefined 7
CVE-2018-5683 Oracle Linux qemu-kvm Undefined 7
CVE-2018-8088 Oracle Linux slf4j Undefined 7
CVE-2018-5125 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5127 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5129 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5144 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5145 Oracle Linux thunderbird Undefined 6,7
CVE-2018-5146 Oracle Linux thunderbird Undefined 6,7
CVE-2017-15131 Oracle Linux xdg-user-dirs Undefined 7
CVE-2017-17052 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2017-7518 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7