No Image

USN-3157-1: Apport vulnerabilities

2016-12-15 KENNETH 0

USN-3157-1: Apport vulnerabilities Ubuntu Security Notice USN-3157-1 14th December, 2016 apport vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Apport could be made to run programs as your login if it opened a specially crafted file. Software description apport – automatically generate crash reports for debugging Details Donncha O Cearbhaill discovered that the crash file parser in Apportimproperly treated the CrashDB field as python code. An attacker coulduse this to convince a user to open a maliciously crafted crash fileand execute arbitrary code with the privileges of that user. This issueonly affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-9949) Donncha O Cearbhaill discovered that Apport did not properly sanitize thePackage and SourcePackage fields in crash files before processing packagespecific hooks. An attacker could [ more… ]

No Image

RHBA-2016:2949-1: openvswitch bug fix update

2016-12-15 KENNETH 0

RHBA-2016:2949-1: openvswitch bug fix update Red Hat Enterprise Linux: Updated openvswitch packages are now available for Red Hat OpenStack Platform for Red Hat Enterprise Linux 7.3 Source: RHBA-2016:2949-1: openvswitch bug fix update

No Image

RHEA-2016:2951-1: rhosp-director-images bug fix and enhancement update

2016-12-15 KENNETH 0

RHEA-2016:2951-1: rhosp-director-images bug fix and enhancement update Red Hat Enterprise Linux: Updated rhosp-director-images packages that fix several bugs and add various enhancements are now available for Red Hat OpenStack Platform 10 (Newton) for Red Hat Enterprise Linux 7. Source: RHEA-2016:2951-1: rhosp-director-images bug fix and enhancement update

No Image

RHEA-2016:2948-1: Red Hat OpenStack Platform 10 enhancement update

2016-12-15 KENNETH 0

RHEA-2016:2948-1: Red Hat OpenStack Platform 10 enhancement update Red Hat Enterprise Linux: New Red Hat OpenStack Platform 10.0 (Newton) packages that add features and fix multiple bugs are now available for Red Hat Enterprise Linux 7. Source: RHEA-2016:2948-1: Red Hat OpenStack Platform 10 enhancement update

No Image

RHSA-2016:2947-1: Critical: flash-plugin security update

2016-12-14 KENNETH 0

RHSA-2016:2947-1: Critical: flash-plugin security update Red Hat Enterprise Linux: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2016-7867, CVE-2016-7868, CVE-2016-7869, CVE-2016-7870, CVE-2016-7871, CVE-2016-7872, CVE-2016-7873, CVE-2016-7874, CVE-2016-7875, CVE-2016-7876, CVE-2016-7877, CVE-2016-7878, CVE-2016-7879, CVE-2016-7880, CVE-2016-7881, CVE-2016-7890, CVE-2016-7892 Source: RHSA-2016:2947-1: Critical: flash-plugin security update