No Image

USN-4235-1: nginx vulnerability

2020-01-14 KENNETH 0

USN-4235-1: nginx vulnerability nginx vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary nginx could be made to expose sensitive information over the network. Software Description nginx – small, powerful, scalable web/proxy server Details Bert JW Regeer and Francisco Oca Gonzalez discovered that nginx incorrectly handled certain error_page configurations. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks and access resources contrary to expectations. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 nginx-common – 1.16.1-0ubuntu2.1 nginx-core – 1.16.1-0ubuntu2.1 nginx-extras – 1.16.1-0ubuntu2.1 nginx-full – 1.16.1-0ubuntu2.1 nginx-light – 1.16.1-0ubuntu2.1 Ubuntu 19.04 nginx-common – 1.15.9-0ubuntu1.2 nginx-core – 1.15.9-0ubuntu1.2 nginx-extras – 1.15.9-0ubuntu1.2 nginx-full – 1.15.9-0ubuntu1.2 nginx-light – 1.15.9-0ubuntu1.2 Ubuntu 18.04 LTS nginx-common – 1.14.0-0ubuntu1.7 nginx-core [ more… ]

No Image

USN-4047-2: libvirt update vulnerability

2020-01-13 KENNETH 0

USN-4047-2: libvirt update vulnerability libvirt vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Summary Several security issues were fixed in libvirt. Software Description libvirt – Libvirt virtualization toolkit Details USN-4047-1 fixed a vulnerability in libvirt. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: Matthias Gerstner and Ján Tomko discovered that libvirt incorrectly handled certain API calls. An attacker could possibly use this issue to check for arbitrary files, or execute arbitrary binaries. In the default installation, attackers would be isolated by the libvirt AppArmor profile. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM libvirt-bin – 1.2.2-0ubuntu13.1.28+esm1 libvirt0 – 1.2.2-0ubuntu13.1.28+esm1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to reboot [ more… ]

No Image

USN-4234-1: Firefox vulnerabilities

2020-01-10 KENNETH 0

USN-4234-1: Firefox vulnerabilities firefox vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description firefox – Mozilla Open Source web browser Details Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, bypass Content Security Policy (CSP) restrictions, conduct cross-site scripting (XSS) attacks, or execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 firefox – 72.0.1+build1-0ubuntu0.19.10.1 Ubuntu 19.04 firefox – 72.0.1+build1-0ubuntu0.19.04.1 Ubuntu 18.04 LTS firefox – 72.0.1+build1-0ubuntu0.18.04.1 Ubuntu 16.04 LTS firefox [ more… ]

No Image

USN-4229-1: NTP vulnerability

2020-01-10 KENNETH 0

USN-4229-1: NTP vulnerability ntp vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary A security issue was fixed in ntpq and ntpdc. Software Description ntp – Network Time Protocol daemon and utility programs Details It was discovered that ntpq and ntpdc incorrectly handled some arguments. An attacker could possibly use this issue to cause ntpq or ntpdc to crash, execute arbitrary code, or escalate to higher privileges. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS ntp – 1:4.2.8p4+dfsg-3ubuntu5.10 Ubuntu 14.04 ESM ntp – 1:4.2.6.p5+dfsg-3ubuntu2.14.04.13+esm1 Ubuntu 12.04 ESM ntp – 1:4.2.6.p3+dfsg-1ubuntu3.13 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2018-12327 Source: USN-4229-1: NTP [ more… ]

No Image

Announcing the Microsoft Identity Research Project Grant

2020-01-10 KENNETH 0

Announcing the Microsoft Identity Research Project Grant We are excited to announce the Microsoft Identity Research Project Grant a new opportunity in partnership with the security community to help protect Microsoft customers. This project grant awards up to $75,000 USD for approved research proposals that improve the security of the Microsoft Identity solutions in new ways for both Consumers (Microsoft Account) and Enterprise (Azure Active Directory). The post Announcing the Microsoft Identity Research Project Grant appeared first on Microsoft Security Response Center. Source: Announcing the Microsoft Identity Research Project Grant