No Image

Windows 10 SDK Preview Build 18922 available now!

2019-06-26 KENNETH 0

Windows 10 SDK Preview Build 18922 available now! Today, we released a new Windows 10 Preview Build of the SDK to be used in conjunction with Windows 10 Insider Preview (Build 18922 or greater). The Preview SDK Build 18922 contains bug fixes and under development changes to the API surface area. The Preview SDK can be downloaded from developer section on Windows Insider. For feedback and updates to the known issues, please see the developer forum. For new developer feature requests, head over to our Windows Platform UserVoice. Things to note: This build works in conjunction with previously released SDKs and Visual Studio 2017 and 2019. You can install this SDK and still also continue to submit your apps that target Windows 10 build 1903 or earlier to the Microsoft Store. The Windows SDK will now formally only be supported by Visual Studio 2017 [ more… ]

No Image

USN-4037-1: policykit-desktop-privileges update

2019-06-25 KENNETH 0

USN-4037-1: policykit-desktop-privileges update policykit-desktop-privileges update A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary A security improvement has been made to policykit-desktop-privileges. Software Description policykit-desktop-privileges – run common desktop actions without password Details The policykit-desktop-privileges Startup Disk Creator policy allowed administrative users to overwrite disks. As a security improvement, this operation now requires authentication. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 policykit-desktop-privileges – 0.20ubuntu19.04.1 Ubuntu 18.10 policykit-desktop-privileges – 0.20ubuntu18.10.1 Ubuntu 18.04 LTS policykit-desktop-privileges – 0.20ubuntu18.04.1 Ubuntu 16.04 LTS policykit-desktop-privileges – 0.20ubuntu16.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References LP: 1832337 Source: USN-4037-1: policykit-desktop-privileges update

No Image

USN-4036-1: OpenStack Neutron vulnerability

2019-06-25 KENNETH 0

USN-4036-1: OpenStack Neutron vulnerability neutron vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 16.04 LTS Summary A system hardening measure could be bypassed. Software Description neutron – OpenStack Virtual Network Service Details Erik Olof Gunnar Andersson discovered that OpenStack Neutron incorrectly handled certain security group rules in the iptables firewall module. An authenticated attacker could possibly use this issue to block further application of security group rules for other instances. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10 python-neutron – 2:13.0.2-0ubuntu3.4 python3-neutron – 2:13.0.2-0ubuntu3.4 Ubuntu 16.04 LTS python-neutron – 2:8.4.0-0ubuntu7.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-9735 Source: USN-4036-1: OpenStack Neutron vulnerability

No Image

USN-4035-1: Ceph vulnerabilities

2019-06-25 KENNETH 0

USN-4035-1: Ceph vulnerabilities ceph vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 16.04 LTS Summary Several security issues were fixed in Ceph. Software Description ceph – distributed storage and file system Details It was discovered that Ceph incorrectly handled read only permissions. An authenticated attacker could use this issue to obtain dm-crypt encryption keys. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-14662) It was discovered that Ceph incorrectly handled certain OMAPs holding bucket indices. An authenticated attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-16846) It was discovered that Ceph incorrectly sanitized certain debug logs. A local attacker could possibly use this issue to obtain encryption key information. This issue was only addressed in Ubuntu 18.10 and Ubuntu 19.04. (CVE-2018-16889) [ more… ]

No Image

USN-4034-1: ImageMagick vulnerabilities

2019-06-25 KENNETH 0

USN-4034-1: ImageMagick vulnerabilities imagemagick vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in ImageMagick. Software Description imagemagick – Image manipulation programs and library Details It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program. Due to a large number of issues discovered in GhostScript that prevent it from being used by ImageMagick safely, the update for Ubuntu 18.10 and Ubuntu 19.04 includes a default policy change that disables support for the Postscript and PDF formats in ImageMagick. This policy [ more… ]