No Image

USN-5008-2: Avahi vulnerability

2021-07-08 KENNETH 0

USN-5008-2: Avahi vulnerability USN-5008-1 fixed a vulnerability in avahi. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Original advisory details: Thomas Kremer discovered that Avahi incorrectly handled termination signals on the Unix socket. A local attacker could possibly use this issue to cause Avahi to hang, resulting in a denial of service. Source: USN-5008-2: Avahi vulnerability

No Image

USN-5008-1: Avahi vulnerabilities

2021-07-08 KENNETH 0

USN-5008-1: Avahi vulnerabilities Thomas Kremer discovered that Avahi incorrectly handled termination signals on the Unix socket. A local attacker could possibly use this issue to cause Avahi to hang, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 20.10. (CVE-2021-3468) It was discovered that Avahi incorrectly handled certain hotnames. A local attacker could possibly use this issue to cause Avahi to crash, resulting in a denial of service. This issue only affected Ubuntu 20.10 and Ubuntu 21.04. (CVE-2021-3502) Source: USN-5008-1: Avahi vulnerabilities

No Image

USN-5007-1: libuv vulnerability

2021-07-07 KENNETH 0

USN-5007-1: libuv vulnerability Eric Sesterhenn discovered that libuv incorrectly handled certain strings. An attacker could possibly use this issue to access sensitive information or cause a crash. Source: USN-5007-1: libuv vulnerability

No Image

USN-5006-1: PHP vulnerabilities

2021-07-07 KENNETH 0

USN-5006-1: PHP vulnerabilities It was discovered that PHP incorrectly handled certain PHAR files. A remote attacker could possibly use this issue to cause PHP to crash, resulting in a denial of service, or possibly obtain sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-7068) It was discovered that PHP incorrectly handled parsing URLs with passwords. A remote attacker could possibly use this issue to cause PHP to mis-parse the URL and produce wrong data. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 20.10. (CVE-2020-7071) It was discovered that PHP incorrectly handled certain malformed XML data when being parsed by the SOAP extension. A remote attacker could possibly use this issue to cause PHP to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, [ more… ]

No Image

USN-5005-1: DjVuLibre vulnerability

2021-07-05 KENNETH 0

USN-5005-1: DjVuLibre vulnerability It was discovered that DjVuLibre incorrectly handled certain djvu files. An attacker could possibly use this issue to execute arbitrary code or cause a crash. Source: USN-5005-1: DjVuLibre vulnerability