No Image

USN-5222-1: Apache Log4j 2 vulnerabilities

2022-01-12 KENNETH 0

USN-5222-1: Apache Log4j 2 vulnerabilities It was discovered that Apache Log4j 2 was vulnerable to remote code execution (RCE) attack when configured to use a JDBC Appender with a JNDI LDAP data source URI. A remote attacker could possibly use this issue to cause a crash, leading to a denial of service. (CVE-2021-44832) Hideki Okamoto and Guy Lederfein discovered that Apache Log4j 2 did not protect against infinite recursion in lookup evaluation. A remote attacker could possibly use this issue to cause Apache Log4j 2 to crash, leading to a denial of service. This issue only affected Ubuntu 16.04 ESM. (CVE-2021-45105) Source: USN-5222-1: Apache Log4j 2 vulnerabilities

No Image

USN-5043-2: Exiv2 regression

2022-01-11 KENNETH 0

USN-5043-2: Exiv2 regression USN-5043-1 fixed vulnerabilities in Exiv2. The update introduced a new regression that could cause a crash in applications using libexiv2. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that Exiv2 incorrectly handled certain image files. An attacker could possibly use this issue to cause a denial of service. (CVE-2021-37620) Source: USN-5043-2: Exiv2 regression

No Image

USN-5219-1: Linux kernel vulnerability

2022-01-11 KENNETH 0

USN-5219-1: Linux kernel vulnerability It was discovered that the eBPF implementation in the Linux kernel did not properly validate the memory size of certain ring buffer operation arguments. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. Source: USN-5219-1: Linux kernel vulnerability

No Image

USN-5218-1: Linux kernel (OEM) vulnerabilities

2022-01-11 KENNETH 0

USN-5218-1: Linux kernel (OEM) vulnerabilities Nadav Amit discovered that the hugetlb implementation in the Linux kernel did not perform TLB flushes under certain conditions. A local attacker could use this to leak or alter data from other processes that use huge pages. (CVE-2021-4002) It was discovered that the eBPF implementation in the Linux kernel did not properly validate the memory size of certain ring buffer operation arguments. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (LP: #1956585) It was discovered that a race condition existed in the overlay file system implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash). (CVE-2021-20321) It was discovered that the NFC subsystem in the Linux kernel contained a use-after-free vulnerability in its NFC Controller [ more… ]

No Image

USN-5217-1: Linux kernel (OEM) vulnerabilities

2022-01-11 KENNETH 0

USN-5217-1: Linux kernel (OEM) vulnerabilities It was discovered that the NFS server implementation in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-4090) It was discovered that the eBPF implementation in the Linux kernel did not properly validate the memory size of certain ring buffer operation arguments. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (LP: #1956585) Source: USN-5217-1: Linux kernel (OEM) vulnerabilities