No Image

USN-3443-1: Linux kernel vulnerabilities

2017-10-11 KENNETH 0

USN-3443-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3443-1 10th October, 2017 linux, linux-raspi2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Summary Several security issues were fixed in the Linux kernel. Software description linux – Linux kernel linux-raspi2 – Linux kernel for Raspberry Pi 2 Details It was discovered that on the PowerPC architecture, the kernel did notproperly sanitize the signal stack when handling sigreturn(). A localattacker could use this to cause a denial of service (system crash) orpossibly execute arbitrary code. (CVE-2017-1000255) Andrey Konovalov discovered that a divide-by-zero error existed in the TCPstack implementation in the Linux kernel. A local attacker could use thisto cause a denial of service (system crash). (CVE-2017-14106) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.04: linux-image-powerpc-smp 4.10.0.37.37 linux-image-powerpc-e500mc [ more… ]

No Image

USN-3443-2: Linux kernel (HWE) vulnerabilities

2017-10-11 KENNETH 0

USN-3443-2: Linux kernel (HWE) vulnerabilities Ubuntu Security Notice USN-3443-2 10th October, 2017 linux-hwe vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the Linux kernel. Software description linux-hwe – Linux hardware enablement (HWE) kernel Details USN-3443-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.This update provides the corresponding updates for the Linux HardwareEnablement (HWE) kernel from Ubuntu 17.04 for Ubuntu 16.04 LTS. It was discovered that on the PowerPC architecture, the kernel did notproperly sanitize the signal stack when handling sigreturn(). A localattacker could use this to cause a denial of service (system crash) orpossibly execute arbitrary code. (CVE-2017-1000255) Andrey Konovalov discovered that a divide-by-zero error existed in the TCPstack implementation in the Linux kernel. A local attacker could use thisto cause a denial of service [ more… ]

No Image

USN-3424-2: libxml2 vulnerabilities

2017-10-11 KENNETH 0

USN-3424-2: libxml2 vulnerabilities Ubuntu Security Notice USN-3424-2 10th October, 2017 libxml2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in libxml2. Software description libxml2 – GNOME XML library Details USN-3424-1 fixed several vulnerabilities in libxml2. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that a type confusion error existed in libxml2. An attacker could use this to specially construct XML data that could cause a denial of service or possibly execute arbitrary code. (CVE-2017-0663) It was discovered that libxml2 did not properly validate parsed entity references. An attacker could use this to specially construct XML data that could expose sensitive information. (CVE-2017-7375) It was discovered that a buffer overflow existed in libxml2 when handling HTTP redirects. An attacker could use [ more… ]

No Image

RHEA-2017:2873-1: gcc-libraries bug fix and enhancement update

2017-10-11 KENNETH 0

RHEA-2017:2873-1: gcc-libraries bug fix and enhancement update Red Hat Enterprise Linux: Updated gcc-libraries packages that fix several bugs and add various enhancements are now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Source: RHEA-2017:2873-1: gcc-libraries bug fix and enhancement update

No Image

RHBA-2017:2874-1: gcc-libraries bug fix and enhancement update

2017-10-11 KENNETH 0

RHBA-2017:2874-1: gcc-libraries bug fix and enhancement update Red Hat Enterprise Linux: Updated gcc-libraries packages that fix several bugs and add various enhancements are now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Source: RHBA-2017:2874-1: gcc-libraries bug fix and enhancement update