No Image

RHSA-2016:0309-1: Low: openstack-glance security update

2016-02-29 KENNETH 0

RHSA-2016:0309-1: Low: openstack-glance security update Red Hat Enterprise Linux: Updated openstack-glance packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a Low security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. CVE-2016-0757 Source: RHSA-2016:0309-1: Low: openstack-glance security update

No Image

USN-2908-5: Linux kernel (Wily HWE) regression

2016-02-27 KENNETH 0

USN-2908-5: Linux kernel (Wily HWE) regression Ubuntu Security Notice USN-2908-5 27th February, 2016 linux-lts-wily regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary USN-2908-2 introduced a regression in the Ubuntu 15.10 Linux kernel backported to Ubuntu 14.04 LTS. Software description linux-lts-wily – Linux hardware enablement kernel from Wily for Trusty Details USN-2908-2 fixed vulnerabilities in the Ubuntu 15.10 Linux kernelbackported to Ubuntu 14.04 LTS. An incorrect locking fix caused aregression that broke graphics displays for Ubuntu 14.04 LTS guestsrunning the Ubuntu 15.10 backport kernel within VMWare virtualmachines. This update fixes the problem. We apologize for the inconvenience. Original advisory details: halfdog discovered that OverlayFS, when mounting on top of a FUSE mount, incorrectly propagated file attributes, including setuid. A local unprivileged attacker could use this to gain privileges. (CVE-2016-1576) halfdog discovered that OverlayFS [ more… ]

No Image

USN-2909-2: Linux kernel (Utopic HWE) regression

2016-02-27 KENNETH 0

USN-2909-2: Linux kernel (Utopic HWE) regression Ubuntu Security Notice USN-2909-2 27th February, 2016 linux-lts-utopic regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary USN-2909-1 introduced a regression in the Ubuntu 14.10 Linux kernel backported to Ubuntu 14.04 LTS. Software description linux-lts-utopic – Linux hardware enablement kernel from Utopic for Trusty Details USN-2909-1 fixed vulnerabilities in the Ubuntu 14.10 Linux kernelbackported to Ubuntu 14.04 LTS. An incorrect locking fix caused aregression that broke graphics displays for Ubuntu 14.04 LTS guestsrunning the Ubuntu 14.10 backport kernel within VMWare virtualmachines. This update fixes the problem. We apologize for the inconvenience. Original advisory details: halfdog discovered that OverlayFS, when mounting on top of a FUSE mount, incorrectly propagated file attributes, including setuid. A local unprivileged attacker could use this to gain privileges. (CVE-2016-1576) halfdog discovered that OverlayFS [ more… ]

No Image

USN-2910-2: Linux kernel (Vivid HWE) regression

2016-02-27 KENNETH 0

USN-2910-2: Linux kernel (Vivid HWE) regression Ubuntu Security Notice USN-2910-2 27th February, 2016 linux-lts-vivid regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary USN-2910-1 introduced a regression in the Ubuntu 15.04 Linux kernel backported to Ubuntu 14.04 LTS. Software description linux-lts-vivid – Linux hardware enablement kernel from Vivid for Trusty Details USN-2910-1 fixed vulnerabilities in the Ubuntu 15.04 Linux kernelbackported to Ubuntu 14.04 LTS. An incorrect locking fix caused aregression that broke graphics displays for Ubuntu 14.04 LTS guestsrunning the Ubuntu 15.04 backport kernel within VMWare virtualmachines. This update fixes the problem. We apologize for the inconvenience. Original advisory details: halfdog discovered that OverlayFS, when mounting on top of a FUSE mount, incorrectly propagated file attributes, including setuid. A local unprivileged attacker could use this to gain privileges. (CVE-2016-1576) halfdog discovered that OverlayFS [ more… ]

No Image

USN-2908-4: Linux kernel regression

2016-02-27 KENNETH 0

USN-2908-4: Linux kernel regression Ubuntu Security Notice USN-2908-4 26th February, 2016 linux regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Summary USN-2908-1 introduced a regression in the Linux kernel. Software description linux – Linux kernel Details USN-2908-1 fixed vulnerabilities in the Linux kernel for Ubuntu15.10. An incorrect locking fix caused a regression that brokegraphics displays for Ubuntu 15.10 guests running within VMWarevirtual machines. This update fixes the problem. We apologize for the inconvenience. Original advisory details: halfdog discovered that OverlayFS, when mounting on top of a FUSE mount, incorrectly propagated file attributes, including setuid. A local unprivileged attacker could use this to gain privileges. (CVE-2016-1576) halfdog discovered that OverlayFS in the Linux kernel incorrectly propagated security sensitive extended attributes, such as POSIX ACLs. A local unprivileged attacker could use this to gain privileges. (CVE-2016-1575) [ more… ]