No Image

USN-4619-1: dom4j vulnerability

2020-11-06 KENNETH 0

USN-4619-1: dom4j vulnerability Mário Areias discovered that dom4j did not properly validate XML document elements. An attacker could exploit this with a crafted XML file to cause dom4j to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2018-1000632) Source: USN-4619-1: dom4j vulnerability

No Image

USN-4618-1: tmux vulnerability

2020-11-05 KENNETH 0

USN-4618-1: tmux vulnerability Sergey Nizovtsev discovered that tmux incorrectly handled some inputs. An attacker could possibly use this issue to cause a crash or execute arbitrary code. Source: USN-4618-1: tmux vulnerability

No Image

USN-4616-2: AccountsService vulnerabilities

2020-11-04 KENNETH 0

USN-4616-2: AccountsService vulnerabilities USN-4616-1 fixed several vulnerabilities in AccountsService. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: Kevin Backhouse discovered that AccountsService incorrectly dropped privileges. A local user could possibly use this issue to cause AccountsService to crash or hang, resulting in a denial of service. (CVE-2020-16126) Matthias Gerstner discovered that AccountsService incorrectly handled certain path checks. A local attacker could possibly use this issue to read arbitrary files. (CVE-2018-14036) Source: USN-4616-2: AccountsService vulnerabilities

No Image

USN-4617-1: SPICE vdagent vulnerabilities

2020-11-04 KENNETH 0

USN-4617-1: SPICE vdagent vulnerabilities Matthias Gerstner discovered that SPICE vdagent incorrectly handled the active_xfers hash table. A local attacker could possibly use this issue to cause SPICE vdagent to consume memory, resulting in a denial of service. (CVE-2020-25650) Matthias Gerstner discovered that SPICE vdagent incorrectly handled the active_xfers hash table. A local attacker could possibly use this issue to cause SPICE vdagent to consume memory, resulting in a denial of service, or obtain sensitive file contents. (CVE-2020-25651) Matthias Gerstner discovered that SPICE vdagent incorrectly handled a large number of client connections. A local attacker could possibly use this issue to cause SPICE vdagent to consume resources, resulting in a denial of service. (CVE-2020-25652) Matthias Gerstner discovered that SPICE vdagent incorrectly handled client connections. A local attacker could possibly use this issue to obtain sensitive information, paste clipboard contents, and transfer [ more… ]

No Image

USN-4615-1: Yerase's TNEF vulnerabilities

2020-11-04 KENNETH 0

USN-4615-1: Yerase's TNEF vulnerabilities It was discovered that Yerase’s TNEF had null pointer dereferences, infinite loop, buffer overflow, out of bounds reads, directory traversal issues and other vulnerabilities. An attacker could use those issues to cause a crash and consequently a denial of service. (CVE-2017-6298, CVE-2017-6299, CVE-2017-6300, CVE-2017-6301, CVE-2017-6302, CVE-2017-6303, CVE-2017-6304, CVE-2017-6305, CVE-2017-6306, CVE-2017-6800, CVE-2017-6801, CVE-2017-6802) Source: USN-4615-1: Yerase's TNEF vulnerabilities