No Image

USN-6283-1: Linux kernel vulnerabilities

2023-08-11 KENNETH 0

USN-6283-1: Linux kernel vulnerabilities Ruihan Li discovered that the bluetooth subsystem in the Linux kernel did not properly perform permissions checks when handling HCI sockets. A physically proximate attacker could use this to cause a denial of service (bluetooth communication). (CVE-2023-2002) Zheng Zhang discovered that the device-mapper implementation in the Linux kernel did not properly handle locking during table_clear() operations. A local attacker could use this to cause a denial of service (kernel deadlock). (CVE-2023-2269) It was discovered that the Ricoh R5C592 MemoryStick card reader driver in the Linux kernel contained a race condition during module unload, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-3141) Quentin Minster discovered that the KSMBD implementation in the Linux kernel did not properly validate pointers in some [ more… ]

No Image

USN-6278-2: .NET vulnerabilities

2023-08-11 KENNETH 0

USN-6278-2: .NET vulnerabilities USN-6278-1 fixed several vulnerabilities in .NET. This update provides the corresponding updates for Ubuntu 22.04 LTS. Original advisory details: It was discovered that .NET did properly handle the execution of certain commands. An attacker could possibly use this issue to achieve remote code execution. (CVE-2023-35390) Benoit Foucher discovered that .NET did not properly implement the QUIC stream limit in HTTP/3. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-38178) It was discovered that .NET did not properly handle the disconnection of potentially malicious clients interfacing with a Kestrel server. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-38180) Source: USN-6278-2: .NET vulnerabilities

No Image

USN-6277-2: Dompdf vulnerabilities

2023-08-11 KENNETH 0

USN-6277-2: Dompdf vulnerabilities USN-6277-1 fixed vulnerabilities in Dompdf. This update provides the corresponding updates for Ubuntu 22.04 LTS. Original advisory details: It was discovered that Dompdf was not properly validating untrusted input when processing HTML content under certain circumstances. An attacker could possibly use this issue to expose sensitive information or execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2014-5011, CVE-2014-5012, CVE-2014-5013) It was discovered that Dompdf was not properly validating processed HTML content that referenced PHAR files, which could result in the deserialization of untrusted data. An attacker could possibly use this issue to execute arbitrary code. (CVE-2021-3838) It was discovered that Dompdf was not properly validating processed HTML content that referenced both a remote base and a local file, which could result in the bypass of a chroot check. An attacker could possibly use this issue [ more… ]

No Image

Releasing Windows 10 Build 19045.3391 to Release Preview Channel

2023-08-11 KENNETH 0

Releasing Windows 10 Build 19045.3391 to Release Preview Channel Hello Windows Insiders, today we are releasing Windows 10 22H2 Build 19045.3391 (KB5029331) to the Release Preview Channel for those Insiders who are on Windows 10, version 22H2. This update includes the following improvements: New! This update improves how Windows detects your location. This helps to give you better weather, news, and traffic information. New! This update expands the roll out of notification badging for Microsoft accounts on the Start menu. A Microsoft account is what connects Windows to your Microsoft apps. The account backs up all your data and helps you to manage your subscriptions. You can also add extra security steps to keep you from being locked out of your account. This feature gives you quick access to important account-related notifications. This update makes daylight saving time (DST) changes [ more… ]

No Image

Releasing Windows 11 Build 22000.2359 to the Release Preview Channel

2023-08-11 KENNETH 0

Releasing Windows 11 Build 22000.2359 to the Release Preview Channel Hello Windows Insiders, today we’re releasing Windows 11 Build 22000.2359 (KB5029332) to Insiders in the Release Preview Channel on Windows 11 (original release).   This update includes the following improvements: New! This update improves how Windows detects your location. This helps to give you better weather, news, and traffic information. This update makes daylight saving time (DST) changes for Israel. This update addresses an issue that affects the Group Policy Service. It will not wait for 30 seconds, which is the default wait time, for the network to be available. Because of this, policies are not correctly processed. This update adds a new API for D3D12 Independent Devices. You can use it to create multiple D3D12 devices on the same adapter. To learn more, see D3D12 Independent Devices. This update [ more… ]