No Image

USN-3285-1: LightDM vulnerability

2017-05-12 KENNETH 0

USN-3285-1: LightDM vulnerability Ubuntu Security Notice USN-3285-1 11th May, 2017 lightdm vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Summary LightDM could allow unintended access to files. Software description lightdm – Display Manager Details Tyler Hicks discovered that LightDM did not confine the user session for guestusers. An attacker with physical access could use this issue to access filesand other resources that they should not be able to access. In the defaultinstallation, this includes files in the home directories of other users on thesystem. This update fixes the issue by disabling the guest session. It may bere-enabled in a future update. Please see the bug referenced below forinstructions on how to manually re-enable the guest session. Update instructions The problem can be corrected by updating your system to the following package version: [ more… ]

No Image

USN-3260-2: Firefox regression

2017-05-12 KENNETH 0

USN-3260-2: Firefox regression Ubuntu Security Notice USN-3260-2 11th May, 2017 firefox regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary USN-3260-1 caused a regression in Firefox. Software description firefox – Mozilla Open Source web browser Details USN-3260-1 fixed vulnerabilities in Firefox. The update caused thedate picker panel and form validation errors to close immediately onopening. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to read uninitialized memory, obtain sensitive information, spoof the addressbar contents or other UI elements, escape the sandbox to read local files, conduct cross-site scripting (XSS) attacks, cause a denial of service via [ more… ]

No Image

RHBA-2017:1227-1: Red Hat Certification bug fix and enhancement update

2017-05-12 KENNETH 0

RHBA-2017:1227-1: Red Hat Certification bug fix and enhancement update Red Hat Enterprise Linux: An updated redhat-certification package that fixes several bugs and adds various enhancements is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Source: RHBA-2017:1227-1: Red Hat Certification bug fix and enhancement update

No Image

RHSA-2017:1228-1: Important: chromium-browser security update

2017-05-12 KENNETH 0

RHSA-2017:1228-1: Important: chromium-browser security update Red Hat Enterprise Linux: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2017-5068 Source: RHSA-2017:1228-1: Important: chromium-browser security update