---
title: "Security Team Weekly Summary: August 31, 2017\n    | Ubuntu"
description: 'The Security Team weekly reports are intended to be very short summaries
  of the Security Team’s weekly activities. If you would like to reach the Security
  Team, you can find us at the #ubuntu-hardened channel on FreeNode. Alternatively,
  you can mail the Ubuntu Hardened mailing list at: ubuntu-hardened@lists.ubuntu.com
  During the last week […]'
url: https://ubuntu.com/blog/security-team-weekly-summary-august-31-2017?format=md
keywords: index, follow
---

1. [Blog](https://ubuntu.com/blog)
2. Article

---

[Canonical](https://ubuntu.com/blog/author/canonical "More about Canonical")

30 August 2017

# Security Team Weekly Summary: August 31, 2017

---

Share the article

The [Security Team](https://wiki.ubuntu.com/SecurityTeam) weekly reports are intended to be very short summaries of the Security Team’s weekly activities.

If you would like to reach the Security Team, you can find us at the #ubuntu-hardened channel on [FreeNode](https://wiki.ubuntu.com/FreeNode). Alternatively, you can mail the Ubuntu Hardened mailing list at: [ubuntu-hardened@lists.ubuntu.com](mailto:ubuntu-hardened@lists.ubuntu.com)

During the last week, the Ubuntu Security team:

* Triaged 287 public security vulnerability reports, retaining the 61 that applied to Ubuntu.
* Published 6 Ubuntu Security Notices which fixed 13 security issues (CVEs) across 6 supported packages.

### Ubuntu Security Notices

* [[USN-3402-1] PySAML2 vulnerability](https://www.ubuntu.com/usn/usn-3402-1)
* [[USN-3401-1] TeX Live vulnerability](https://www.ubuntu.com/usn/usn-3401-1)
* [[USN-3400-1] Augeas vulnerability](https://www.ubuntu.com/usn/usn-3400-1)
* [[USN-3399-1] cvs vulnerability](https://www.ubuntu.com/usn/usn-3399-1)
* [[USN-3398-1] graphite2 vulnerabilities](https://www.ubuntu.com/usn/usn-3398-1)
* [[USN-3397-1] strongSwan vulnerability](https://www.ubuntu.com/usn/usn-3397-1)

### Bug Triage

* Backlog: <https://bugs.launchpad.net/~ubuntu-security/+subscribedbugs>

### Mainline Inclusion Requests

* websockify (LP: #[1108935](https://bugs.launchpad.net/bugs/1108935 "Bug")) underway
* MIR backlog: <https://bugs.launchpad.net/~ubuntu-security/+assignedbugs?field.searchtext=%5BMIR%5D>

### Updates to Community Supported Packages

* Simon Quigley (tsimonq2) provided a debdiff for trusty for kdepimlibs (LP: #[1630700](https://bugs.launchpad.net/bugs/1630700 "Bug"))
* Simon Quigley (tsimonq2) provided a debdiff for xenial for kcoreaddons (LP: #[1630700](https://bugs.launchpad.net/bugs/1630700 "Bug"))
* Simon Quigley (tsimonq2) provided debdiffs for trusty-zesty for varnish (LP: #[1708354](https://bugs.launchpad.net/bugs/1708354 "Bug"))

### Development

* Updated review tools to calculate uncompressed squashfs size and error out if too large. Update to unpack to SNAP\_USER\_COMMON and cleanup stale review directories.
* review-tools fix for LP: #[1712476](https://bugs.launchpad.net/bugs/1712476 "Bug")
* review-tools: implement new ‘reload-command’ yaml and new execstack checks
* Submitted apparmor pull for artful to the Kernel Team.
* Submitted seccomp logging patch set for both artful 4.12 and artful 4.13 kernels.
* Submitted PR 3804 for user and group name lookups in snap-seccomp in support of snap privilege dropping.
* Submitted PR 3805 to stop hardcoding uids and gids (for ‘root’ and ‘shadow’).
* Submitted libseccomp PR for improved logging changes (<https://github.com/seccomp/libseccomp/pull/92>).
* fixed a libseccomp test runner bug that was causing a class of tests to not run (<https://github.com/seccomp/libseccomp/pull/91>).
* Work with design on ‘Snap interfaces GUI descriptions’
* Perform various PR reviews in support of cross-distro and improved udev tagging
* Meet with snapd team (Gustavo) on final designs for new desktop interfaces (PR 3719)

### What the Security Team is Reading This Week

* [Weird Python Integers](https://kate.io/blog/2017/08/22/weird-python-integers/)
* [Rethinking the dbus message bus](https://dvdhrm.github.io/rethinking-the-dbus-message-bus/)

### Weekly Meeting

* Weekly meeting was cancelled this week (eclipse watching)
* Info: <https://wiki.ubuntu.com/SecurityTeam/Meeting>

### More Info

* [Ubuntu CVE Tracker](http://people.canonical.com/~ubuntu-security/cve/)
* [Ubuntu security notices](https://www.ubuntu.com/usn/)
* [Follow Ubuntu Security on Twitter](https://www.twitter.com/ubuntu_sec)
* [How to help improve Ubuntu security](https://wiki.ubuntu.com/SecurityTeam/GettingInvolved)

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Newsletter signup

Get the latest Ubuntu news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/data-privacy).

Sign up

## Share on

---

## Related posts

[### Beyond the 10-year mark: Extending Ubuntu Pro 16.04 LTS security coverage](https://ubuntu.com/blog/extending-ubuntu-pro-16-04-coverage)

A decade ago, Canonical launched Ubuntu 16.04 LTS (codenamed “Xenial Xerus”). As a Long-Term Support (LTS) release, it comes with 5 years of standard security coverage, which...

[Carlos Bravo](https://ubuntu.com/blog/author/carlos-bravo)

17 September 2026

[### Android™ development shouldn’t start with a physical device](https://ubuntu.com/blog/android-development-shouldnt-start-with-a-physical-device)

How on-demand Android environments lay the foundation for Android engineering Software engineering has evolved dramatically over the last decade. Development environments that...

[Bertrand Boisseau](https://ubuntu.com/blog/author/bboisseau)

17 September 2026

[### Bring Zenoh to ROS 2 with snaps](https://ubuntu.com/blog/bring-zenoh-to-ros-2-with-snaps)

ROS 2 gives robotics developers the freedom to choose the middleware that fits their system. As a communication protocol for ROS, Zenoh has gained strong traction. It delivers...

[gbeuzeboc](https://ubuntu.com/blog/author/gbeuzeboc)

15 September 2026

[### Evolution of the RISC-V ISA. What next after RVA23?](https://ubuntu.com/blog/evolution-of-the-risc-v-isa-what-next-after-rva23)

Introduction Releasing the RVA23 specification was a major milestone for the RISC-V community. While it provides an excellent baseline for deployment at scale, innovation...

[Jon Taylor](https://ubuntu.com/blog/author/jon-taylor)

15 September 2026
