No Image

USN-5481-1: BlueZ vulnerabilities

2022-06-16 KENNETH 0

USN-5481-1: BlueZ vulnerabilities It was discovered that BlueZ incorrectly validated certain capabilities and lengths when handling the A2DP profile. A remote attacker could use this issue to cause BlueZ to crash, resulting in a denial of service, or possibly execute arbitrary code. Source: USN-5481-1: BlueZ vulnerabilities

No Image

USN-5479-1: PHP vulnerabilities

2022-06-15 KENNETH 0

USN-5479-1: PHP vulnerabilities Charles Fol discovered that PHP incorrectly handled initializing certain arrays when handling the pg_query_params function. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2022-31625) Charles Fol discovered that PHP incorrectly handled passwords in mysqlnd. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2022-31626) Source: USN-5479-1: PHP vulnerabilities

No Image

USN-5478-1: util-linux vulnerability

2022-06-15 KENNETH 0

USN-5478-1: util-linux vulnerability Christian Moch and Michael Gruhn discovered that the libblkid library of util-linux did not properly manage memory under certain circumstances. A local attacker could possibly use this issue to cause denial of service by consuming all memory through a specially crafted MSDOS partition table. Source: USN-5478-1: util-linux vulnerability

No Image

USN-5477-1: ncurses vulnerabilities

2022-06-14 KENNETH 0

USN-5477-1: ncurses vulnerabilities Hosein Askari discovered that ncurses was incorrectly performing memory management operations when dealing with long filenames while writing structures into the file system. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2017-16879) Chung-Yi Lin discovered that ncurses was incorrectly handling access to invalid memory areas when parsing terminfo or termcap entries where the use-name had invalid syntax. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-19211) It was discovered that ncurses was incorrectly performing bounds checks when processing invalid hashcodes. An attacker could possibly use this issue to cause a denial of service or to expose sensitive information. (CVE-2019-17594) It was discovered that ncurses was incorrectly handling end-of-string characters when processing terminfo and termcap files. An attacker could possibly use this issue to [ more… ]

No Image

USN-5359-2: rsync vulnerability

2022-06-14 KENNETH 0

USN-5359-2: rsync vulnerability USN-5359-1 fixed vulnerabilities in rsync. This update provides the corresponding updates for Ubuntu 16.04 ESM. Original advisory details: Danilo Ramos discovered that rsync incorrectly handled memory when performing certain zlib deflating operations. An attacker could use this issue to cause rsync to crash, resulting in a denial of service, or possibly execute arbitrary code. Source: USN-5359-2: rsync vulnerability