No Image

USN-2896-1: Libgcrypt vulnerability

2016-02-16 KENNETH 0

Ubuntu Security Notice USN-2896-1 15th February, 2016 libgcrypt11, libgcrypt20 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Libgcrypt could be made to expose sensitive information. Software description libgcrypt11 – LGPL Crypto library libgcrypt20 – LGPL Crypto library Details Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discoveredthat Libgcrypt was susceptible to an attack via physical side channels. Alocal attacker could use this attack to possibly recover private keys. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 15.10: libgcrypt20 1.6.3-2ubuntu1.1 Ubuntu 14.04 LTS: libgcrypt11 1.5.3-2ubuntu4.3 Ubuntu 12.04 LTS: libgcrypt11 1.5.0-3ubuntu0.5 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2015-7511 Source: ubuntu-usn

No Image

Cisco ASA 소프트웨어 신규 취약점 보안 업데이트 권고

2016-02-12 KENNETH 0

출처 : http://www.boho.or.kr/data/secNoticeView.do?bulletin_writing_sequence=24007   □ 개요 o Cisco社는 ASA 소프트웨어에 영향을 주는 취약점을 해결한 보안 업데이트를 발표[1] o 공격자는 취약점에 영향 받는 시스템에 임의코드 실행 및 서비스 거부 등의 피해를 발생시킬 수 있으므로, 최신버전으로 업데이트 권고 □ 설명 o Cisco ASA 소프트웨어의 IKEv1 및 IKEv2에서 조작 된 UDP 패킷을 처리할 때 임의코드 실행이 가능한 취약점(CVE-2016-1287) □ 해당 시스템 o 영향을 받는 제품 – 참고사이트에 명시되어 있는 ‘Affected Products’을 통해 취약한 제품 확인 □ 해결 방안 o 취약점이 발생한 Cisco 소프트웨어가 설치된 Cisco 장비의 운영자는, 해당되는 참고사이트에 명시되어 있는 ‘Affected Products’ 및 ‘Obtaining Fixed Software’ 내용을 확인하여, 패치 적용 □ 용어 설명 o ASA(Adaptive Security Appliance) 소프트웨어 : Cisco社에서 제작한 네트워크 보안 플랫폼 □ 기타 문의사항 o 한국인터넷진흥원 인터넷침해대응센터: 국번없이 118 [참고사이트] [1] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160210-asa-ike

No Image

USN-2893-1: Firefox vulnerability

2016-02-12 KENNETH 0

Ubuntu Security Notice USN-2893-1 11th February, 2016 firefox vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary A same-origin-policy bypass was discovered in Firefox. Software description firefox – Mozilla Open Source web browser Details Jason Pang discovered that service workers intercept responses to pluginnetwork requests made through the browser. An attacker could potentiallyexploit this to bypass same origin restrictions using the Flash plugin.(CVE-2016-1949) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 15.10: firefox 44.0.2+build1-0ubuntu0.15.10.1 Ubuntu 14.04 LTS: firefox 44.0.2+build1-0ubuntu0.14.04.1 Ubuntu 12.04 LTS: firefox 44.0.2+build1-0ubuntu0.12.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to restart Firefox to makeall the necessary changes. References CVE-2016-1949 Source: ubuntu-usn

No Image

USN-2894-1: PostgreSQL vulnerabilities

2016-02-12 KENNETH 0

Ubuntu Security Notice USN-2894-1 11th February, 2016 postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary PostgreSQL could be made to crash or run programs if it handled specially crafted data. Software description postgresql-9.1 – Object-relational SQL database postgresql-9.3 – Object-relational SQL database postgresql-9.4 – Object-relational SQL database Details It was discovered that PostgreSQL incorrectly handled certain regularexpressions. A remote attacker could possibly use this issue to causePostgreSQL to crash, resulting in a denial of service. (CVE-2016-0773) It was discovered that PostgreSQL incorrectly handled certain configurationsettings (GUCS) for users of PL/Java. A remote attacker could possibly usethis issue to escalate privileges. (CVE-2016-0766) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 15.10: postgresql-9.4 9.4.6-0ubuntu0.15.10 Ubuntu 14.04 LTS: [ more… ]