USN-3337-1: Valgrind vulnerabilities Ubuntu Security Notice USN-3337-1 21st June, 2017 valgrind vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Valgrind could be made to crash or run programs if it opened a specially crafted file. Software description valgrind – instrumentation framework for building dynamic analysis tools Details It was discovered that Valgrind incorectly handled certain stringoperations. If a user or automated system were tricked into processing aspecially crafted binary, a remote attacker could possibly executearbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04LTS and Ubuntu 16.10. (CVE-2016-2226) It was discovered that Valgrind incorrectly handled parsing certainbinaries. If a user or automated system were tricked into processing aspecially crafted binary, a remote attacker could use this issue to causeValgrind to crash, resulting in a [ more… ]