No Image

USN-3140-1: Firefox vulnerabilities

2016-12-01 KENNETH 0

USN-3140-1: Firefox vulnerabilities Ubuntu Security Notice USN-3140-1 30th November, 2016 firefox vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Firefox could be made to crash or run programs as your login if it opened a malicious website. Software description firefox – Mozilla Open Source web browser Details It was discovered that data: URLs can inherit the wrong origin after aHTTP redirect in some circumstances. An attacker could potentiallyexploit this to bypass same-origin restrictions. (CVE-2016-9078) A use-after-free was discovered in SVG animations. If a user were trickedin to opening a specially crafted website, an attacker could exploit thisto cause a denial of service via application crash, or execute arbitrarycode. (CVE-2016-9079) Update instructions The problem can be corrected by updating your system to the following package [ more… ]

No Image

USN-3146-2: Linux kernel (Xenial HWE) vulnerabilities

2016-12-01 KENNETH 0

USN-3146-2: Linux kernel (Xenial HWE) vulnerabilities Ubuntu Security Notice USN-3146-2 30th November, 2016 linux-lts-xenial vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in the kernel. Software description linux-lts-xenial – Linux hardware enablement kernel from Xenial for Trusty Details USN-3146-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04LTS. This update provides the corresponding updates for the LinuxHardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu14.04 LTS. It was discovered that the __get_user_asm_ex implementation in the Linuxkernel for x86/x86_64 contained extended asm statements that wereincompatible with the exception table. A local attacker could use this togain administrative privileges. (CVE-2016-9644) Andreas Gruenbacher and Jan Kara discovered that the filesystemimplementation in the Linux kernel did not clear the setgid bit during asetxattr call. A local attacker could use this [ more… ]

No Image

USN-3146-1: Linux kernel vulnerabilities

2016-12-01 KENNETH 0

USN-3146-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3146-1 30th November, 2016 linux vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the kernel. Software description linux – Linux kernel Details It was discovered that the __get_user_asm_ex implementation in the Linuxkernel for x86/x86_64 contained extended asm statements that wereincompatible with the exception table. A local attacker could use this togain administrative privileges. (CVE-2016-9644) Andreas Gruenbacher and Jan Kara discovered that the filesystemimplementation in the Linux kernel did not clear the setgid bit during asetxattr call. A local attacker could use this to possibly elevate groupprivileges. (CVE-2016-7097) Marco Grassi discovered that the driver for Areca RAID Controllers in theLinux kernel did not properly validate control messages. A local attackercould use this to cause a denial of service (system crash) [ more… ]

No Image

USN-3145-2: Linux kernel (Trusty HWE) vulnerabilities

2016-12-01 KENNETH 0

USN-3145-2: Linux kernel (Trusty HWE) vulnerabilities Ubuntu Security Notice USN-3145-2 30th November, 2016 linux-lts-trusty vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in the kernel. Software description linux-lts-trusty – Linux hardware enablement kernel from Trusty for Precise Details USN-3145-1 fixed vulnerabilities in the Linux kernel for Ubuntu14.04 LTS. This update provides the corresponding updates for theLinux Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS forUbuntu 12.04 LTS. Marco Grassi discovered that the driver for Areca RAID Controllers in theLinux kernel did not properly validate control messages. A local attackercould use this to cause a denial of service (system crash) or possibly gainprivileges. (CVE-2016-7425) Daxing Guo discovered a stack-based buffer overflow in the BroadcomIEEE802.11n FullMAC driver in the Linux kernel. A local attacker could usethis to cause a [ more… ]

No Image

USN-3145-1: Linux kernel vulnerabilities

2016-12-01 KENNETH 0

USN-3145-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3145-1 30th November, 2016 linux vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in the kernel. Software description linux – Linux kernel Details Marco Grassi discovered that the driver for Areca RAID Controllers in theLinux kernel did not properly validate control messages. A local attackercould use this to cause a denial of service (system crash) or possibly gainprivileges. (CVE-2016-7425) Daxing Guo discovered a stack-based buffer overflow in the BroadcomIEEE802.11n FullMAC driver in the Linux kernel. A local attacker could usethis to cause a denial of service (system crash) or possibly gainprivileges. (CVE-2016-8658) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 14.04 LTS: linux-image-powerpc-smp 3.13.0.103.111 linux-image-powerpc-e500mc 3.13.0.103.111 linux-image-3.13.0-103-powerpc-e500 3.13.0-103.150 linux-image-3.13.0-103-generic 3.13.0-103.150 linux-image-generic [ more… ]