No Image

USN-5087-1: WebKitGTK vulnerabilities

2021-09-23 KENNETH 0

USN-5087-1: WebKitGTK vulnerabilities A large number of security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Source: USN-5087-1: WebKitGTK vulnerabilities

No Image

USN-5086-1: Linux kernel vulnerability

2021-09-22 KENNETH 0

USN-5086-1: Linux kernel vulnerability Johan Almbladh discovered that the eBPF JIT implementation for IBM s390x systems in the Linux kernel miscompiled operations in some situations, allowing circumvention of the BPF verifier. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. Source: USN-5086-1: Linux kernel vulnerability

No Image

USN-5085-1: SQL parse vulnerability

2021-09-22 KENNETH 0

USN-5085-1: SQL parse vulnerability It was discovered that SQL parse incorrectly handled certain regular expression. An attacker could possibly use this issue to cause a denial of service. Source: USN-5085-1: SQL parse vulnerability

No Image

USN-5071-3: Linux kernel (Raspberry Pi) vulnerabilities

2021-09-22 KENNETH 0

USN-5071-3: Linux kernel (Raspberry Pi) vulnerabilities It was discovered that the KVM hypervisor implementation in the Linux kernel did not properly perform reference counting in some situations, leading to a use-after-free vulnerability. An attacker who could start and control a VM could possibly use this to expose sensitive information or execute arbitrary code. (CVE-2021-22543) Murray McAllister discovered that the joystick device interface in the Linux kernel did not properly validate data passed via an ioctl(). A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code on systems with a joystick device registered. (CVE-2021-3612) Source: USN-5071-3: Linux kernel (Raspberry Pi) vulnerabilities

No Image

USN-5073-3: Linux kernel (Raspberry Pi) vulnerabilities

2021-09-22 KENNETH 0

USN-5073-3: Linux kernel (Raspberry Pi) vulnerabilities Norbert Slusarek discovered that the CAN broadcast manger (bcm) protocol implementation in the Linux kernel did not properly initialize memory in some situations. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2021-34693) Murray McAllister discovered that the joystick device interface in the Linux kernel did not properly validate data passed via an ioctl(). A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code on systems with a joystick device registered. (CVE-2021-3612) It was discovered that the Virtio console implementation in the Linux kernel did not properly validate input lengths in some situations. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2021-38160) Source: USN-5073-3: Linux kernel (Raspberry Pi) vulnerabilities