Oracle Linux Bulletin - April 2019

Description

The Oracle Linux Bulletin lists all CVEs that had been resolved and announced in Oracle Linux Security Advisories (ELSA) in the last one month prior to the release of the bulletin. Oracle Linux Bulletins are published on the same day as Oracle Critical Patch Updates are released. These bulletins will also be updated for the following two months after their release (i.e., the two months between the normal quarterly Critical Patch Update publication dates) to cover all CVEs that had been resolved in those two months following the bulletin's publication. In addition, Oracle Linux Bulletins may also be updated for vulnerability fixes deemed too critical to wait for the next scheduled bulletin publication date.

Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Oracle Linux Bulletin fixes as soon as possible.

Patch Availability

Please see ULN Advisory https://linux.oracle.com/ol-pad-bulletin

Oracle Linux Bulletin Schedule

Oracle Linux Bulletins are released on the Tuesday closest to the 17th day of January, April, July and October. The next four dates are:

  • 16 July 2019
  • 15 October 2019
  • 14 January 2020
  • 14 April 2020

References

Modification History

2019-June-18 Rev 3. New CVEs added.
2019-May-17 Rev 2. New CVEs added.
2019-April-16 Rev 1. Initial Release

Oracle Linux Executive Summary

This Oracle Linux Bulletin contains 115 new security fixes for the Oracle Linux.  115 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password. 

Oracle Linux Risk Matrix

Revision 3: Published on 2019-06-18

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 2.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base Score Access Vector Access Complexity Authen- tication Confiden- tiality Integrity Avail- ability
CVE-2018-5743 Oracle Linux bind Undefined 7
CVE-2016-8615 Oracle Linux curl Undefined 6,7
CVE-2016-8616 Oracle Linux curl Undefined 6,7
CVE-2016-8617 Oracle Linux curl Undefined 6,7
CVE-2016-8618 Oracle Linux curl Undefined 6,7
CVE-2016-8619 Oracle Linux curl Undefined 6,7
CVE-2016-8620 Oracle Linux curl Undefined 6,7
CVE-2016-8621 Oracle Linux curl Undefined 6,7
CVE-2016-8622 Oracle Linux curl Undefined 6,7
CVE-2016-8623 Oracle Linux curl Undefined 6,7
CVE-2016-8624 Oracle Linux curl Undefined 6,7
CVE-2016-8625 Oracle Linux curl Undefined 6,7
CVE-2017-5715 Oracle Linux edk2 Undefined 7
CVE-2017-5731 Oracle Linux edk2 Undefined 7
CVE-2017-5732 Oracle Linux edk2 Undefined 7
CVE-2017-5733 Oracle Linux edk2 Undefined 7
CVE-2017-5734 Oracle Linux edk2 Undefined 7
CVE-2017-5735 Oracle Linux edk2 Undefined 7
CVE-2017-5753 Oracle Linux edk2 Undefined 7
CVE-2018-12178 Oracle Linux edk2 Undefined 7
CVE-2018-12180 Oracle Linux edk2 Undefined 7
CVE-2018-12181 Oracle Linux edk2 Undefined 7
CVE-2018-3630 Oracle Linux edk2 Undefined 7
CVE-2018-18511 Oracle Linux firefox Undefined 6,7
CVE-2019-11691 Oracle Linux firefox Undefined 6,7
CVE-2019-11692 Oracle Linux firefox Undefined 6,7
CVE-2019-11693 Oracle Linux firefox Undefined 6,7
CVE-2019-11698 Oracle Linux firefox Undefined 6,7
CVE-2019-5798 Oracle Linux firefox Undefined 6,7
CVE-2019-7317 Oracle Linux firefox Undefined 6,7
CVE-2019-9797 Oracle Linux firefox Undefined 6,7
CVE-2019-9800 Oracle Linux firefox Undefined 6,7
CVE-2019-9816 Oracle Linux firefox Undefined 6,7
CVE-2019-9817 Oracle Linux firefox Undefined 6,7
CVE-2019-9819 Oracle Linux firefox Undefined 6,7
CVE-2019-9820 Oracle Linux firefox Undefined 6,7
CVE-2019-10132 Oracle Linux libvirt Undefined 7
CVE-2019-10132 Oracle Linux libvirt Undefined 7
CVE-2019-9636 Oracle Linux python Undefined 6
CVE-2018-18511 Oracle Linux thunderbird Undefined 6,7
CVE-2019-11691 Oracle Linux thunderbird Undefined 6,7
CVE-2019-11692 Oracle Linux thunderbird Undefined 6,7
CVE-2019-11693 Oracle Linux thunderbird Undefined 6,7
CVE-2019-11698 Oracle Linux thunderbird Undefined 6,7
CVE-2019-5798 Oracle Linux thunderbird Undefined 6,7
CVE-2019-7317 Oracle Linux thunderbird Undefined 6,7
CVE-2019-9797 Oracle Linux thunderbird Undefined 6,7
CVE-2019-9800 Oracle Linux thunderbird Undefined 6,7
CVE-2019-9817 Oracle Linux thunderbird Undefined 6,7
CVE-2019-9819 Oracle Linux thunderbird Undefined 6,7
CVE-2019-9820 Oracle Linux thunderbird Undefined 6,7
CVE-2011-1079 Oracle Linux Unbreakable Enterprise kernel Undefined 7
CVE-2018-12126 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2018-12127 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2018-12130 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2018-14633 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2018-20836 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2019-11091 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2019-11477 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2019-11478 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2019-11479 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2019-11810 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2019-11815 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2019-11884 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2019-3459 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2019-3819 Oracle Linux Unbreakable Enterprise kernel Undefined 6

Revision 2: Published on 2019-05-17

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 2.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base Score Access Vector Access Complexity Authen- tication Confiden- tiality Integrity Avail- ability
CVE-2018-12126 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-12127 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-12130 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2019-11091 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2019-10063 Oracle Linux flatpak Undefined 7
CVE-2019-11234 Oracle Linux freeradius Undefined 7
CVE-2019-11235 Oracle Linux freeradius Undefined 7
CVE-2019-3839 Oracle Linux ghostscript Undefined 7
CVE-2019-2602 Oracle Linux java-1.7.0-openjdk Undefined 6,7
CVE-2019-2684 Oracle Linux java-1.7.0-openjdk Undefined 6,7
CVE-2019-2698 Oracle Linux java-1.7.0-openjdk Undefined 6,7
CVE-2019-2602 Oracle Linux java-1.8.0-openjdk Undefined 6
CVE-2019-2684 Oracle Linux java-1.8.0-openjdk Undefined 6
CVE-2019-2698 Oracle Linux java-1.8.0-openjdk Undefined 6
CVE-2019-2602 Oracle Linux java-1.8.0-openjdk Undefined 7
CVE-2019-2684 Oracle Linux java-1.8.0-openjdk Undefined 7
CVE-2019-2698 Oracle Linux java-1.8.0-openjdk Undefined 7
CVE-2019-2602 Oracle Linux java-11-openjdk Undefined 7
CVE-2019-2684 Oracle Linux java-11-openjdk Undefined 7
CVE-2018-12126 Oracle Linux kernel Undefined 6
CVE-2018-12127 Oracle Linux kernel Undefined 6
CVE-2018-12130 Oracle Linux kernel Undefined 6
CVE-2019-11091 Oracle Linux kernel Undefined 6
CVE-2019-6974 Oracle Linux kernel Undefined 7
CVE-2019-7221 Oracle Linux kernel Undefined 7
CVE-2018-12126 Oracle Linux kernel Undefined 7
CVE-2018-12127 Oracle Linux kernel Undefined 7
CVE-2018-12130 Oracle Linux kernel Undefined 7
CVE-2019-11091 Oracle Linux kernel Undefined 7
CVE-2018-12126 Oracle Linux libvirt Undefined 6,7
CVE-2018-12127 Oracle Linux libvirt Undefined 6,7
CVE-2018-12130 Oracle Linux libvirt Undefined 6,7
CVE-2019-11091 Oracle Linux libvirt Undefined 6,7
CVE-2019-3877 Oracle Linux mod_auth_mellon Undefined 7
CVE-2019-3878 Oracle Linux mod_auth_mellon Undefined 7
CVE-2018-12180 Oracle Linux ovmf Undefined 7
CVE-2016-10745 Oracle Linux python-jinja2 Undefined 7
CVE-2018-12126 Oracle Linux qemu Undefined 7
CVE-2018-12127 Oracle Linux qemu Undefined 7
CVE-2018-12130 Oracle Linux qemu Undefined 7
CVE-2018-18438 Oracle Linux qemu Undefined 7
CVE-2018-19665 Oracle Linux qemu Undefined 7
CVE-2018-20123 Oracle Linux qemu Undefined 7
CVE-2018-20815 Oracle Linux qemu Undefined 7
CVE-2019-11091 Oracle Linux qemu Undefined 7
CVE-2019-3812 Oracle Linux qemu Undefined 7
CVE-2019-6501 Oracle Linux qemu Undefined 7
CVE-2019-6778 Oracle Linux qemu Undefined 7
CVE-2019-8934 Oracle Linux qemu Undefined 7
CVE-2019-9824 Oracle Linux qemu Undefined 7
CVE-2018-12126 Oracle Linux qemu-kvm Undefined 6,7
CVE-2018-12127 Oracle Linux qemu-kvm Undefined 6,7
CVE-2018-12130 Oracle Linux qemu-kvm Undefined 6,7
CVE-2019-11091 Oracle Linux qemu-kvm Undefined 6,7
CVE-2019-8322 Oracle Linux ruby Undefined 7
CVE-2019-8323 Oracle Linux ruby Undefined 7
CVE-2019-8324 Oracle Linux ruby Undefined 7
CVE-2019-8325 Oracle Linux ruby Undefined 7
CVE-2019-5953 Oracle Linux wget Undefined 7
CVE-2015-5327 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2017-13305 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2017-18360 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2018-12126 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-12127 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-12130 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2018-19985 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2019-10124 Oracle Linux Unbreakable Enterprise kernel Undefined 7
CVE-2019-11091 Oracle Linux Unbreakable Enterprise kernel Undefined 6,7
CVE-2019-11190 Oracle Linux Unbreakable Enterprise kernel Undefined 6

Revision 1: Published on 2019-04-16

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 2.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base Score Access Vector Access Complexity Authen- tication Confiden- tiality Integrity Avail- ability
CVE-2019-0816 Oracle Linux cloud-init Undefined 7
CVE-2018-18506 Oracle Linux firefox Undefined 6,7
CVE-2019-9788 Oracle Linux firefox Undefined 6,7
CVE-2019-9790 Oracle Linux firefox Undefined 6,7
CVE-2019-9791 Oracle Linux firefox Undefined 6,7
CVE-2019-9792 Oracle Linux firefox Undefined 6,7
CVE-2019-9793 Oracle Linux firefox Undefined 6,7
CVE-2019-9795 Oracle Linux firefox Undefined 6,7
CVE-2019-9796 Oracle Linux firefox Undefined 6,7
CVE-2019-9810 Oracle Linux firefox Undefined 6,7
CVE-2019-9813 Oracle Linux firefox Undefined 6,7
CVE-2018-8786 Oracle Linux freerdp Undefined 7
CVE-2018-8787 Oracle Linux freerdp Undefined 7
CVE-2018-8788 Oracle Linux freerdp Undefined 7
CVE-2019-3835 Oracle Linux ghostscript Undefined 7
CVE-2019-3838 Oracle Linux ghostscript Undefined 7
CVE-2018-13405 Oracle Linux kernel Undefined 6
CVE-2019-3855 Oracle Linux libssh2 Undefined 7
CVE-2019-3856 Oracle Linux libssh2 Undefined 7
CVE-2019-3857 Oracle Linux libssh2 Undefined 7
CVE-2019-3863 Oracle Linux libssh2 Undefined 7
CVE-2018-15473 Oracle Linux openssh Undefined 6
CVE-2019-3816 Oracle Linux openwsman Undefined 7
CVE-2019-9636 Oracle Linux python Undefined 7
CVE-2018-18506 Oracle Linux thunderbird Undefined 6,7
CVE-2019-9788 Oracle Linux thunderbird Undefined 6,7
CVE-2019-9790 Oracle Linux thunderbird Undefined 6,7
CVE-2019-9791 Oracle Linux thunderbird Undefined 6,7
CVE-2019-9792 Oracle Linux thunderbird Undefined 6,7
CVE-2019-9793 Oracle Linux thunderbird Undefined 6,7
CVE-2019-9795 Oracle Linux thunderbird Undefined 6,7
CVE-2019-9796 Oracle Linux thunderbird Undefined 6,7
CVE-2019-9810 Oracle Linux thunderbird Undefined 6,7
CVE-2019-9813 Oracle Linux thunderbird Undefined 6,7
CVE-2018-10877 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2018-10882 Oracle Linux Unbreakable Enterprise kernel Undefined 6
CVE-2019-3701 Oracle Linux Unbreakable Enterprise kernel Undefined 7
CVE-2019-6974 Oracle Linux Unbreakable Enterprise kernel Undefined 7
CVE-2019-7221 Oracle Linux Unbreakable Enterprise kernel Undefined 7
CVE-2019-7222 Oracle Linux Unbreakable Enterprise kernel Undefined 7
CVE-2019-8912 Oracle Linux Unbreakable Enterprise kernel Undefined 7
CVE-2019-8980 Oracle Linux Unbreakable Enterprise kernel Undefined 7
CVE-2019-9213 Oracle Linux Unbreakable Enterprise kernel Undefined 7