No Image

USN-4647-1: Thunderbird vulnerabilities

2020-11-26 KENNETH 0

USN-4647-1: Thunderbird vulnerabilities Multiple security issues were discovered in Thunderbird. If a user were tricked in to opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across origins, bypass security restrictions, conduct phishing attacks, conduct cross-site scripting (XSS) attacks, bypass Content Security Policy (CSP) restrictions, conduct DNS rebinding attacks, or execute arbitrary code. Source: USN-4647-1: Thunderbird vulnerabilities

No Image

USN-4646-1: poppler vulnerabilities

2020-11-26 KENNETH 0

USN-4646-1: poppler vulnerabilities It was discovered that Poppler incorrectly handled certain files. If a user or automated system were tricked into opening a crafted PDF file, an attacker could cause a denial of service. Source: USN-4646-1: poppler vulnerabilities

No Image

USN-4645-1: Mutt vulnerability

2020-11-26 KENNETH 0

USN-4645-1: Mutt vulnerability It was discovered that Mutt incorrectly handled certain connections. An attacker could possibly use this issue to expose sensitive information. Source: USN-4645-1: Mutt vulnerability

No Image

USN-4644-1: igraph vulnerability

2020-11-25 KENNETH 0

USN-4644-1: igraph vulnerability It was discovered that igraph mishandled certain malformed XML. An attacker could use this vulnerability to cause a denial of service (crash). Source: USN-4644-1: igraph vulnerability

No Image

USN-4643-1: atftp vulnerabilities

2020-11-24 KENNETH 0

USN-4643-1: atftp vulnerabilities It was discovered that atftp’s FTP server did not properly handler certain input. An attacker could use this to to cause a denial of service (crash) or possibly execute arbitrary code. (CVE-2019-11365) It was discovered that atftp’s FTP server did not make proper use of mutexes when locking certain data structures. An attacker could use this to cause a denial of service via a NULL pointer dereference. (CVE-2019-11366) Source: USN-4643-1: atftp vulnerabilities