No Image

USN-5739-1: MariaDB vulnerabilities

2022-11-24 KENNETH 0

USN-5739-1: MariaDB vulnerabilities Several security issues were discovered in MariaDB and this update includes new upstream MariaDB versions to fix these issues. MariaDB has been updated to 10.3.37 in Ubuntu 20.04 LTS and to 10.6.11 in Ubuntu 22.04 LTS and Ubuntu 22.10. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Source: USN-5739-1: MariaDB vulnerabilities

No Image

USN-5638-3: Expat vulnerability

2022-11-24 KENNETH 0

USN-5638-3: Expat vulnerability USN-5638-1 fixed a vulnerability in Expat. This update provides the corresponding updates for Ubuntu 16.04 ESM, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-43680) This update also fixes a minor regression introduced in Ubuntu 18.04 LTS. We apologize for the inconvenience. Original advisory details: Rhodri James discovered that Expat incorrectly handled memory when processing certain malformed XML files. An attacker could possibly use this issue to cause a crash or execute arbitrary code. Source: USN-5638-3: Expat vulnerability

No Image

USN-5737-1: APR-util vulnerability

2022-11-23 KENNETH 0

USN-5737-1: APR-util vulnerability It was discovered that APR-util did not properly handle memory when using SDBM database files. A local attacker with write access to the database can make a program or process using these functions crash, and cause a denial of service. Source: USN-5737-1: APR-util vulnerability

No Image

USN-5735-1: Sysstat vulnerability

2022-11-23 KENNETH 0

USN-5735-1: Sysstat vulnerability It was discovered that Sysstat did not properly check bounds when perfoming certain arithmetic operations on 32 bit systems. An attacker could possibly use this issue to cause a crash or arbitrary code execution. Source: USN-5735-1: Sysstat vulnerability

No Image

USN-5734-1: FreeRDP vulnerabilities

2022-11-22 KENNETH 0

USN-5734-1: FreeRDP vulnerabilities It was discovered that FreeRDP incorrectly handled certain data lenghts. A malicious server could use this issue to cause FreeRDP clients to crash, resulting in a denial of service, or possibly obtain sensitive information. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-39282, CVE-2022-39283) It was discovered that FreeRDP incorrectly handled certain data lenghts. A malicious server could use this issue to cause FreeRDP clients to crash, resulting in a denial of service, or possibly obtain sensitive information. (CVE-2022-39316, CVE-2022-39317, CVE-2022-39318, CVE-2022-39319, CVE-2022-39320) It was discovered that FreeRDP incorrectly handled certain path checks. A malicious server could use this issue to cause FreeRDP clients to read files outside of the shared directory. (CVE-2022-39347) Source: USN-5734-1: FreeRDP vulnerabilities