No Image

RHSA-2017:1574-1: Moderate: sudo security update

2017-06-23 KENNETH 0

RHSA-2017:1574-1: Moderate: sudo security update Red Hat Enterprise Linux: An update for sudo is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2017-1000368 Source: RHSA-2017:1574-1: Moderate: sudo security update

No Image

RHBA-2017:1572-1: Red Hat Certification bug fix and enhancement update

2017-06-22 KENNETH 0

RHBA-2017:1572-1: Red Hat Certification bug fix and enhancement update Red Hat Enterprise Linux: An updated redhat-certification package that fixes several bugs and adds various enhancements is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Source: RHBA-2017:1572-1: Red Hat Certification bug fix and enhancement update

No Image

USN-3335-2: Linux kernel (Trusty HWE) vulnerability

2017-06-22 KENNETH 0

USN-3335-2: Linux kernel (Trusty HWE) vulnerability Ubuntu Security Notice USN-3335-2 21st June, 2017 linux-lts-trusty vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary The system could be made to run programs as an administrator. Software description linux-lts-trusty – Linux hardware enablement kernel from Trusty for Precise Details USN-3335-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04LTS. This update provides the corresponding updates for the LinuxHardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu12.04 ESM. It was discovered that the stack guard page for processes in the Linuxkernel was not sufficiently large enough to prevent overlapping with theheap. An attacker could leverage this with another vulnerability to executearbitrary code and gain administrative privileges Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: [ more… ]

No Image

USN-3338-1: Linux kernel vulnerabilities

2017-06-22 KENNETH 0

USN-3338-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3338-1 21st June, 2017 linux vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in the Linux kernel. Software description linux – Linux kernel Details It was discovered that the stack guard page for processes in the Linuxkernel was not sufficiently large enough to prevent overlapping with theheap. An attacker could leverage this with another vulnerability to executearbitrary code and gain administrative privileges (CVE-2017-1000364) Jesse Hertz and Tim Newsham discovered that the Linux netfilterimplementation did not correctly perform validation when handling 32 bitcompatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A localunprivileged attacker could use this to cause a denial of service (systemcrash) or execute arbitrary code with administrative privileges.(CVE-2016-4997) Update instructions The problem can be corrected by updating your system to [ more… ]

No Image

USN-3337-1: Valgrind vulnerabilities

2017-06-22 KENNETH 0

USN-3337-1: Valgrind vulnerabilities Ubuntu Security Notice USN-3337-1 21st June, 2017 valgrind vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Valgrind could be made to crash or run programs if it opened a specially crafted file. Software description valgrind – instrumentation framework for building dynamic analysis tools Details It was discovered that Valgrind incorectly handled certain stringoperations. If a user or automated system were tricked into processing aspecially crafted binary, a remote attacker could possibly executearbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04LTS and Ubuntu 16.10. (CVE-2016-2226) It was discovered that Valgrind incorrectly handled parsing certainbinaries. If a user or automated system were tricked into processing aspecially crafted binary, a remote attacker could use this issue to causeValgrind to crash, resulting in a [ more… ]