No Image

USN-2935-2: PAM regression

2016-03-17 KENNETH 0

USN-2935-2: PAM regression Ubuntu Security Notice USN-2935-2 16th March, 2016 pam regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary USN-2935-1 introduced a regression in PAM. Software description pam – Pluggable Authentication Modules Details USN-2935-1 fixed vulnerabilities in PAM. The updates contained a packagingchange that prevented upgrades in certain multiarch environments. Thisupdate fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that the PAM pam_userdb module incorrectly used a case-insensitive method when comparing hashed passwords. A local attacker could possibly use this issue to make brute force attacks easier. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041) Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly performed filtering. A local attacker could use this issue to create arbitrary files, [ more… ]

No Image

RHSA-2016:0460-1: Important: thunderbird security update

2016-03-17 KENNETH 0

RHSA-2016:0460-1: Important: thunderbird security update Red Hat Enterprise Linux: An updated thunderbird package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5, 6, and 7. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. CVE-2016-1952, CVE-2016-1954, CVE-2016-1957, CVE-2016-1960, CVE-2016-1961, CVE-2016-1964, CVE-2016-1966, CVE-2016-1974, CVE-2016-1977, CVE-2016-2790, CVE-2016-2791, CVE-2016-2792, CVE-2016-2793, CVE-2016-2794, CVE-2016-2795, CVE-2016-2796, CVE-2016-2797, CVE-2016-2798, CVE-2016-2799, CVE-2016-2800, CVE-2016-2801, CVE-2016-2802 Source: RHSA-2016:0460-1: Important: thunderbird security update

No Image

USN-2935-1: PAM vulnerabilities

2016-03-16 KENNETH 0

USN-2935-1: PAM vulnerabilities Ubuntu Security Notice USN-2935-1 16th March, 2016 pam vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in PAM. Software description pam – Pluggable Authentication Modules Details It was discovered that the PAM pam_userdb module incorrectly used acase-insensitive method when comparing hashed passwords. A local attackercould possibly use this issue to make brute force attacks easier. Thisissue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041) Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectlyperformed filtering. A local attacker could use this issue to createarbitrary files, or possibly bypass authentication. This issue onlyaffected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-2583) Sebastien Macke discovered that the PAM pam_unix module incorrectly handledlarge passwords. A local attacker could possibly use this [ more… ]

No Image

USN-2930-3: Linux kernel (Raspberry Pi 2) vulnerabilities

2016-03-16 KENNETH 0

USN-2930-3: Linux kernel (Raspberry Pi 2) vulnerabilities Ubuntu Security Notice USN-2930-3 16th March, 2016 linux-raspi2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Summary Several security issues were fixed in the kernel. Software description linux-raspi2 – Linux kernel for Raspberry Pi 2 Details Ben Hawkes discovered that the Linux netfilter implementation did notcorrectly perform validation when handling IPT_SO_SET_REPLACE events. Alocal unprivileged attacker could use this to cause a denial of service(system crash) or possibly execute arbitrary code with administrativeprivileges. (CVE-2016-3134) Ben Hawkes discovered an integer overflow in the Linux netfilterimplementation. On systems running 32 bit kernels, a local unprivilegedattacker could use this to cause a denial of service (system crash) orpossibly execute arbitrary code with administrative privileges.(CVE-2016-3135) Ralf Spenneberg discovered that the USB driver for Clie devices in theLinux kernel did not properly sanity [ more… ]

No Image

RHSA-2016:0458-1: Important: bind97 security update

2016-03-16 KENNETH 0

RHSA-2016:0458-1: Important: bind97 security update Red Hat Enterprise Linux: Updated bind97 packages that fix two security issues are now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. CVE-2016-1285, CVE-2016-1286 Source: RHSA-2016:0458-1: Important: bind97 security update