No Image

USN-5022-1: MySQL vulnerabilities

2021-07-26 KENNETH 0

USN-5022-1: MySQL vulnerabilities Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.26 in Ubuntu 20.04 LTS and Ubuntu 21.04. Ubuntu 18.04 LTS has been updated to MySQL 5.7.35. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-35.html https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-26.html https://www.oracle.com/security-alerts/cpujul2021.html Source: USN-5022-1: MySQL vulnerabilities

No Image

LSN-0079-1: Kernel Live Patch Security Notice

2021-07-26 KENNETH 0

LSN-0079-1: Kernel Live Patch Security Notice It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.(CVE-2021-3600) It was discovered that the virtual file system implementation in the Linux kernel contained an unsigned to signed integer conversion error. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code.(CVE-2021-33909) Source: LSN-0079-1: Kernel Live Patch Security Notice

No Image

USN-5021-1: curl vulnerabilities

2021-07-23 KENNETH 0

USN-5021-1: curl vulnerabilities Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled TELNET connections when the -t option was used on the command line. Uninitialized data possibly containing sensitive information could be sent to the remote server, contrary to expectations. (CVE-2021-22898, CVE-2021-22925) Harry Sintonen discovered that curl incorrectly reused connections in the connection pool. This could result in curl reusing the wrong connections. (CVE-2021-22924) Source: USN-5021-1: curl vulnerabilities

No Image

USN-5020-1: Ruby vulnerabilities

2021-07-21 KENNETH 0

USN-5020-1: Ruby vulnerabilities It was discovered that Ruby incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. (CVE-2021-31799) It was discovered that Ruby incorrectly handled certain inputs. An attacker could possibly use this issue to conduct port scans and service banner extractions. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2021-31810) It was discovered that Ruby incorrectly handled certain inputs. An attacker could possibly use this issue to perform man-in-the-middle attackers to bypass the TLS protection. (CVE-2021-32066) Source: USN-5020-1: Ruby vulnerabilities

No Image

USN-4336-2: GNU binutils vulnerabilities

2021-07-21 KENNETH 0

USN-4336-2: GNU binutils vulnerabilities USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides the corresponding update for Ubuntu 16.04 ESM. Original advisory details: It was discovered that GNU binutils contained a large number of security issues. If a user or automated system were tricked into processing a specially-crafted file, a remote attacker could cause GNU binutils to crash, resulting in a denial of service, or possibly execute arbitrary code. Source: USN-4336-2: GNU binutils vulnerabilities