No Image

USN-3014-1: Spice vulnerabilities

2016-06-21 KENNETH 0

USN-3014-1: Spice vulnerabilities Ubuntu Security Notice USN-3014-1 21st June, 2016 spice vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Summary Several security issues were fixed in Spice. Software description spice – SPICE protocol client and server library Details Jing Zhao discovered that the Spice smartcard support incorrectly handledmemory. A remote attacker could use this issue to cause Spice to crash,resulting in a denial of service, or possibly execute arbitrary code. Thisissue only applied to Ubuntu 15.10 and Ubuntu 16.04 LTS. (CVE-2016-0749) Frediano Ziglio discovered that Spice incorrectly handled certain primarysurface parameters. A malicious guest operating system could potentiallyexploit this issue to escape virtualization. (CVE-2016-2150) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: libspice-server1 0.12.6-4ubuntu0.1 Ubuntu 15.10: libspice-server1 [ more… ]

No Image

RHEA-2016:1263-1: new packages: rh-nodejs4

2016-06-21 KENNETH 0

RHEA-2016:1263-1: new packages: rh-nodejs4 Red Hat Enterprise Linux: New rh-nodejs4 packages are now available as a part of Red Hat Software Collections 2.2 for Red Hat Enterprise Linux 6. Source: RHEA-2016:1263-1: new packages: rh-nodejs4

No Image

RHBA-2016:1261-1: libvirt bug fix update

2016-06-21 KENNETH 0

RHBA-2016:1261-1: libvirt bug fix update Red Hat Enterprise Linux: Updated libvirt packages that fix one bug are now available for Red Hat Enterprise Linux 6 Advanced Update Support. Source: RHBA-2016:1261-1: libvirt bug fix update

No Image

RHSA-2016:1262-1: Important: chromium-browser security update

2016-06-21 KENNETH 0

RHSA-2016:1262-1: Important: chromium-browser security update Red Hat Enterprise Linux: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2016-1704 Source: RHSA-2016:1262-1: Important: chromium-browser security update

No Image

USN-3013-1: XML-RPC for C and C++ vulnerabilities

2016-06-21 KENNETH 0

USN-3013-1: XML-RPC for C and C++ vulnerabilities Ubuntu Security Notice USN-3013-1 20th June, 2016 xmlrpc-c vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in XML-RPC for C and C++. Software description xmlrpc-c – Lightweight RPC library based on XML and HTTP Details It was discovered that the Expat code in XML-RPC for C and C++ unexpectedlycalled srand in certain circumstances. This could reduce the security ofcalling applications. (CVE-2012-6702) It was discovered that the Expat code in XML-RPC for C and C++ incorrectlyhandled seeding the random number generator. A remote attacker couldpossibly use this issue to cause a denial of service. (CVE-2016-5300) Gustavo Grieco discovered that the Expat code in XML-RPC for C and C++incorrectly handled malformed XML data. If a user or application linkedagainst XML-RPC for C [ more… ]