No Image

USN-4554-1: libPGF vulnerability

2020-09-29 KENNETH 0

USN-4554-1: libPGF vulnerability It was discovered that libPGF lacked proper validation when opening a specially crafted PGF file. An attacker could possibly use this issue to cause a denial of service. Source: USN-4554-1: libPGF vulnerability

No Image

USN-4552-1: Pam-python vulnerability

2020-09-29 KENNETH 0

USN-4552-1: Pam-python vulnerability Malte Kraus discovered that Pam-python mishandled certain environment variables. A local attacker could potentially use this vulnerability to execute programs as root. Source: USN-4552-1: Pam-python vulnerability

No Image

USN-4553-1: Teeworlds vulnerability

2020-09-29 KENNETH 0

USN-4553-1: Teeworlds vulnerability It was discovered that Teeworlds server did not properly handler certain network traffic. A remote, unauthenticated attacker could use this vulnerability to cause Teeworlds server to crash. Source: USN-4553-1: Teeworlds vulnerability

No Image

USN-4551-1: Squid vulnerabilities

2020-09-29 KENNETH 0

USN-4551-1: Squid vulnerabilities Alex Rousskov and Amit Klein discovered that Squid incorrectly handled certain Content-Length headers. A remote attacker could possibly use this issue to perform an HTTP request smuggling attack, resulting in cache poisoning. (CVE-2020-15049) Amit Klein discovered that Squid incorrectly validated certain data. A remote attacker could possibly use this issue to perform an HTTP request smuggling attack, resulting in cache poisoning. (CVE-2020-15810) Régis Leroy discovered that Squid incorrectly validated certain data. A remote attacker could possibly use this issue to perform an HTTP request splitting attack, resulting in cache poisoning. (CVE-2020-15811) Lubos Uhliarik discovered that Squid incorrectly handled certain Cache Digest response messages sent by trusted peers. A remote attacker could possibly use this issue to cause Squid to consume resources, resulting in a denial of service. (CVE-2020-24606) Source: USN-4551-1: Squid vulnerabilities

No Image

USN-4550-1: DPDK vulnerabilities

2020-09-29 KENNETH 0

USN-4550-1: DPDK vulnerabilities Ryan Hall discovered that DPDK incorrectly handled vhost crypto. An attacker inside a guest could use these issues to perform multiple attacks, including denial of service attacks, obtaining sensitive information from the host, and possibly executing arbitrary code on the host. Source: USN-4550-1: DPDK vulnerabilities