No Image

USN-2958-1: poppler vulnerabilities

2016-05-03 KENNETH 0

USN-2958-1: poppler vulnerabilities Ubuntu Security Notice USN-2958-1 2nd May, 2016 poppler vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary poppler could be made to crash or run programs if it opened a specially crafted file. Software description poppler – PDF rendering library Details It was discovered that the poppler pdfseparate tool incorrectly handledcertain filenames. A local attacker could use this issue to cause the toolto crash, resulting in a denial of service, or possibly execute arbitrarycode. This issue only applied to Ubuntu 12.04 LTS. (CVE-2013-4473,CVE-2013-4474) It was discovered that poppler incorrectly parsed certain malformed PDFdocuments. If a user or automated system were tricked into opening acrafted PDF file, an attacker could cause a denial of service or possiblyexecute arbitrary code with privileges of the user invoking the [ more… ]

No Image

USN-2957-1: Libtasn1 vulnerability

2016-05-03 KENNETH 0

USN-2957-1: Libtasn1 vulnerability Ubuntu Security Notice USN-2957-1 2nd May, 2016 libtasn1-3, libtasn1-6 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Libtasn1 could be made to hang if it processed specially crafted data. Software description libtasn1-3 – Library to manage ASN.1 structures libtasn1-6 – Library to manage ASN.1 structures Details Pascal Cuoq and Miod Vallat discovered that Libtasn1 incorrectly handledcertain malformed DER certificates. A remote attacker could possibly usethis issue to cause applications using Libtasn1 to hang, resulting in adenial of service. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 15.10: libtasn1-6 4.5-2ubuntu0.1 Ubuntu 14.04 LTS: libtasn1-6 3.4-3ubuntu0.4 Ubuntu 12.04 LTS: libtasn1-3 2.10-1ubuntu1.5 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will [ more… ]

No Image

RHSA-2016:0708-1: Critical: java-1.6.0-ibm security update

2016-05-03 KENNETH 0

RHSA-2016:0708-1: Critical: java-1.6.0-ibm security update Red Hat Enterprise Linux: An update for java-1.6.0-ibm is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2016-0264, CVE-2016-0363, CVE-2016-0376, CVE-2016-0686, CVE-2016-0687, CVE-2016-3422, CVE-2016-3426, CVE-2016-3427, CVE-2016-3443, CVE-2016-3449 Source: RHSA-2016:0708-1: Critical: java-1.6.0-ibm security update

No Image

RHSA-2016:0706-1: Important: mercurial security update

2016-05-02 KENNETH 0

RHSA-2016:0706-1: Important: mercurial security update Red Hat Enterprise Linux: An update for mercurial is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2016-3068, CVE-2016-3069 Source: RHSA-2016:0706-1: Important: mercurial security update

No Image

RHSA-2016:0707-1: Important: chromium-browser security update

2016-05-02 KENNETH 0

RHSA-2016:0707-1: Important: chromium-browser security update Red Hat Enterprise Linux: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2016-1660, CVE-2016-1661, CVE-2016-1662, CVE-2016-1663, CVE-2016-1664, CVE-2016-1665, CVE-2016-1666 Source: RHSA-2016:0707-1: Important: chromium-browser security update