No Image

Azure Sphere Security Research Challenge Now Open

2020-05-06 KENNETH 0

Azure Sphere Security Research Challenge Now Open The Azure Sphere Security Research Challenge is an expansion of Azure Security Lab, announced at Black Hat in August 2019. At that time, a select group of talented researchers was invited to come and do their worst, emulating criminal hackers in a customer-safe cloud environment. This new research challenge aims to spark new high impact … Azure Sphere Security Research Challenge Now Open Read More » The post Azure Sphere Security Research Challenge Now Open appeared first on Microsoft Security Response Center. Source: Azure Sphere Security Research Challenge Now Open

No Image

USN-4350-1: MySQL vulnerabilities

2020-05-04 KENNETH 0

USN-4350-1: MySQL vulnerabilities mysql-5.7, mysql-8.0 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 20.04 LTS Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in MySQL. Software Description mysql-8.0 – MySQL database mysql-5.7 – MySQL database Details Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.80 in Ubuntu 19.10 and Ubuntu 20.04 LTS. Ubuntu 16.04 LTS and Ubuntu 18.04 LTS have been updated to MySQL 5.7.30. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-30.html https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-20.html https://www.oracle.com/security-alerts/cpuapr2020.html Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS mysql-server-8.0 – [ more… ]

No Image

LSN-0066-1: Kernel Live Patch Security Notice

2020-05-01 KENNETH 0

LSN-0066-1: Kernel Live Patch Security Notice Linux kernel vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Ubuntu 16.04 LTS Ubuntu 14.04 ESM Summary Several security issues were fixed in the Linux kernel. Software Description linux – Linux kernel linux-aws – Linux kernel for Amazon Web Services (AWS) systems linux-azure – Linux kernel for Microsoft Azure Cloud systems linux-oem – Linux kernel for OEM processors Details It was discovered that the virtual terminal implementation in the Linux kernel did not properly handle resize events. A local attacker could use this to expose sensitive information. (CVE-2020-8647) It was discovered that the virtual terminal implementation in the Linux kernel contained a race condition. A local attacker could possibly use this to cause a denial of service (system crash) or expose sensitive information. (CVE-2020-8648) It was discovered [ more… ]

No Image

USN-4349-1: EDK II vulnerabilities

2020-05-01 KENNETH 0

USN-4349-1: EDK II vulnerabilities edk2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in edk2. Software Description edk2 – UEFI firmware for 64-bit x86 virtual machines Details A buffer overflow was discovered in the network stack. An unprivileged user could potentially enable escalation of privilege and/or denial of service. This issue was already fixed in a previous release for 18.04 LTS and 19.10. (CVE-2018-12178) A buffer overflow was discovered in BlockIo service. An unauthenticated user could potentially enable escalation of privilege, information disclosure and/or denial of service. This issue was already fixed in a previous release for 18.04 LTS and 19.10. (CVE-2018-12180) A stack overflow was discovered in bmp. An unprivileged user could potentially enable denial of service or elevation of privilege [ more… ]

No Image

USN-4333-2: Python vulnerabilities

2020-04-30 KENNETH 0

USN-4333-2: Python vulnerabilities python3.8 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 20.04 LTS Summary Several security issues were fixed in Python. Software Description python3.8 – Interactive high-level object-oriented language (version 3.8) Details USN-4333-1 fixed vulnerabilities in Python. This update provides the corresponding update for Ubuntu 20.04 LTS. Original advisory details: It was discovered that Python incorrectly stripped certain characters from requests. A remote attacker could use this issue to perform CRLF injection. (CVE-2019-18348) It was discovered that Python incorrectly handled certain HTTP requests. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-8492) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS python3.8 – 3.8.2-1ubuntu1.1 python3.8-minimal – 3.8.2-1ubuntu1.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a [ more… ]