No Image

Join the Microsoft Edge team next week at Ignite 2019

2019-10-31 KENNETH 0

Join the Microsoft Edge team next week at Ignite 2019 Next week, we will be travelling to Microsoft Ignite 2019 to share what’s new in Microsoft Edge for enterprises, IT professionals, and web developers. We’re very excited to share more about our journey with Chromium over the past year, what it means to your customers, and to hear your feedback. In this post, we’ve outlined all the breakout sessions and other activities our team will be presenting at Ignite next week, so you can easily track which sessions you want to attend or review later. This year, Ignite is also introducing Roundtable Topics, which are a great opportunity to share your experiences with the product team directly, provide feedback, and help us understand how we can empower you and your organization with Microsoft Edge. The full list of sessions is [ more… ]

No Image

USN-4170-2: Whoopsie regression

2019-10-30 KENNETH 0

USN-4170-2: Whoopsie regression whoopsie regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary USN-4170-1 caused a regression in Whoopsie. Software Description whoopsie – Ubuntu error tracker submission Details USN-4170-1 fixed a vulnerability in Whoopsie. The update caused Whoopsie to crash when sending reports. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Kevin Backhouse discovered Whoopsie incorrectly handled very large crash reports. A local attacker could possibly use this issue to cause a denial of service, expose sensitive information or execute code as the whoopsie user. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 libwhoopsie0 – 0.2.66ubuntu0.2 whoopsie – 0.2.66ubuntu0.2 Ubuntu 19.04 libwhoopsie0 – 0.2.64ubuntu0.3 whoopsie – 0.2.64ubuntu0.3 Ubuntu 18.04 LTS libwhoopsie0 [ more… ]

No Image

USN-4173-1: FreeTDS vulnerability

2019-10-30 KENNETH 0

USN-4173-1: FreeTDS vulnerability freetds vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Summary FreeTDS could be made to crash or run programs if it received specially crafted network traffic. Software Description freetds – libraries for connecting to MS SQL and Sybase SQL servers Details Felix Wilhelm discovered that FreeTDS incorrectly handled certain types after a protocol downgrade. A remote attacker could use this issue to cause FreeTDS to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 freetds-bin – 1.1.6-1ubuntu0.1 libct4 – 1.1.6-1ubuntu0.1 libsybdb5 – 1.1.6-1ubuntu0.1 tdsodbc – 1.1.6-1ubuntu0.1 Ubuntu 19.04 freetds-bin – 1.00.104-1ubuntu0.1 libct4 – 1.00.104-1ubuntu0.1 libsybdb5 – 1.00.104-1ubuntu0.1 tdsodbc – 1.00.104-1ubuntu0.1 Ubuntu 18.04 LTS freetds-bin – [ more… ]

No Image

USN-4172-1: file vulnerability

2019-10-30 KENNETH 0

USN-4172-1: file vulnerability file vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary file could be made to crash or run programs if it opened a specially crafted file. Software Description file – Tool to determine file types Details It was discovered that file incorrectly handled certain malformed files. An attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 file – 1:5.37-5ubuntu0.1 libmagic1 – 1:5.37-5ubuntu0.1 Ubuntu 19.04 file – 1:5.35-4ubuntu0.1 libmagic1 – 1:5.35-4ubuntu0.1 Ubuntu 18.04 LTS file – 1:5.32-2ubuntu0.3 libmagic1 – 1:5.32-2ubuntu0.3 Ubuntu 16.04 LTS file – 1:5.25-2ubuntu1.3 libmagic1 – 1:5.25-2ubuntu1.3 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In [ more… ]

No Image

USN-4171-1: Apport vulnerabilities

2019-10-30 KENNETH 0

USN-4171-1: Apport vulnerabilities apport vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in Apport. Software Description apport – automatically generate crash reports for debugging Details Kevin Backhouse discovered Apport would read its user-controlled settings file as the root user. This could be used by a local attacker to possibly crash Apport or have other unspecified consequences. (CVE-2019-11481) Sander Bos discovered a race-condition in Apport during core dump creation. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user. (CVE-2019-11482) Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process [ more… ]