No Image

USN-3084-1: Linux kernel vulnerabilities

2016-09-20 KENNETH 0

USN-3084-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3084-1 19th September, 2016 linux vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the kernel. Software description linux – Linux kernel Details Pengfei Wang discovered a race condition in the audit subsystem in theLinux kernel. A local attacker could use this to corrupt audit logs ordisrupt system-call auditing. (CVE-2016-6136) It was discovered that the powerpc and powerpc64 hypervisor-mode KVMimplementation in the Linux kernel for did not properly maintain stateabout transactional memory. An unprivileged attacker in a guest could causea denial of service (CPU lockup) in the host OS. (CVE-2016-5412) Pengfei Wang discovered a race condition in the Chrome OS embeddedcontroller device driver in the Linux kernel. A local attacker could usethis to cause a denial of service (system crash). [ more… ]

No Image

RHEA-2016:1906-1: bash Shift_JIS enhancement update

2016-09-20 KENNETH 0

RHEA-2016:1906-1: bash Shift_JIS enhancement update Red Hat Enterprise Linux: Updated bash Shift_JIS packages that add one enhancement are now available for Red Hat Enterprise Linux 6. Source: RHEA-2016:1906-1: bash Shift_JIS enhancement update

No Image

RHEA-2016:1907-1: coreutils Shift_JIS enhancement update

2016-09-20 KENNETH 0

RHEA-2016:1907-1: coreutils Shift_JIS enhancement update Red Hat Enterprise Linux: Updated coreutils Shift_JIS packages that add one enhancement are now available for Red Hat Enterprise Linux 6. Source: RHEA-2016:1907-1: coreutils Shift_JIS enhancement update

No Image

USN-3081-1: Tomcat vulnerability

2016-09-20 KENNETH 0

USN-3081-1: Tomcat vulnerability Ubuntu Security Notice USN-3081-1 19th September, 2016 tomcat6, tomcat7, tomcat8 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary The system could be made to run programs as an administrator. Software description tomcat6 – Servlet and JSP engine tomcat7 – Servlet and JSP engine tomcat8 – Servlet and JSP engine Details Dawid Golunski discovered that the Tomcat init script incorrectly handledcreating log files. A remote attacker could possibly use this issue to obtain root privileges. (CVE-2016-1240) This update also reverts a change in behaviour introduced in USN-3024-1 bysetting mapperContextRootRedirectEnabled to True by default. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: libtomcat8-java 8.0.32-1ubuntu1.2 tomcat8 8.0.32-1ubuntu1.2 Ubuntu 14.04 LTS: tomcat7 7.0.52-1ubuntu0.7 libtomcat7-java 7.0.52-1ubuntu0.7 Ubuntu [ more… ]

No Image

RHSA-2016:1905-1: Important: chromium-browser security update

2016-09-16 KENNETH 0

RHSA-2016:1905-1: Important: chromium-browser security update Red Hat Enterprise Linux: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2016-5170, CVE-2016-5171, CVE-2016-5172, CVE-2016-5173, CVE-2016-5174, CVE-2016-5175 Source: RHSA-2016:1905-1: Important: chromium-browser security update