No Image

USN-4144-1: Linux kernel vulnerabilities

2019-10-01 KENNETH 0

USN-4144-1: Linux kernel vulnerabilities linux, linux-aws, linux-aws-hwe, linux-azure, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in the Linux kernel. Software Description linux – Linux kernel linux-aws – Linux kernel for Amazon Web Services (AWS) systems linux-kvm – Linux kernel for cloud environments linux-oem – Linux kernel for OEM processors linux-oracle – Linux kernel for Oracle Cloud systems linux-raspi2 – Linux kernel for Raspberry Pi 2 linux-snapdragon – Linux kernel for Snapdragon processors linux-aws-hwe – Linux kernel for Amazon Web Services (AWS-HWE) systems linux-azure – Linux kernel for Microsoft Azure Cloud systems linux-hwe – Linux hardware enablement (HWE) kernel Details It was discovered that the XFS file system in the Linux kernel did not properly handle mount failures [ more… ]

No Image

Building the Azure IoT Edge Security Daemon in Rust

2019-10-01 KENNETH 0

Building the Azure IoT Edge Security Daemon in Rust Azure IoT Edge is an open source, cross platform software project from the Azure IoT team at Microsoft that seeks to solve the problem of managing distribution of compute to the edge of your on-premise network from the cloud. This post explains some of the rationale behind our choice of Rust as the implementation programming … Building the Azure IoT Edge Security Daemon in Rust Read More » The post Building the Azure IoT Edge Security Daemon in Rust appeared first on Microsoft Security Response Center. Source: Building the Azure IoT Edge Security Daemon in Rust

No Image

USN-4143-1: SDL 2.0 vulnerabilities

2019-10-01 KENNETH 0

USN-4143-1: SDL 2.0 vulnerabilities SDL 2.0 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary SDL 2.0 could be made to crash or run programs as your login if it opened a specially crafted file. Software Description libsdl2 – Simple DirectMedia Layer: cross-platform development library providing access to low level media interfaces Details It was discovered that SDL 2.0 mishandled crafted image files resulting in an integer overflow. If a user were tricked into opening a malicious file, SDL 2.0 could be caused to crash or potentially run arbitrary code. (CVE-2017-2888) It was discovered that SDL 2.0 mishandled crafted image files. If a user were tricked into opening a malicious file, SDL 2.0 could be caused to crash or potentially run arbitrary code. (CVE-2019-7635, CVE-2019-7636, CVE-2019-7637, CVE-2019-7638) Update [ more… ]

No Image

USN-4142-2: e2fsprogs vulnerability

2019-09-30 KENNETH 0

USN-4142-2: e2fsprogs vulnerability e2fsprogs vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary e2fsprogs could be made to execute arbitrary code if it is running in a crafted ext4 partition. Software Description e2fsprogs – ext2/ext3/ext4 file system utilities Details USN-4142-1 fixed a vulnerability in e2fsprogs. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It was discovered that e2fsprogs incorrectly handled certain ext4 partitions. An attacker could possibly use this issue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM e2fsprogs – 1.42.9-3ubuntu1.3+esm1 Ubuntu 12.04 ESM e2fsprogs – 1.42-1ubuntu2.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the [ more… ]

No Image

USN-4142-1: e2fsprogs vulnerability

2019-09-30 KENNETH 0

USN-4142-1: e2fsprogs vulnerability e2fsprogs vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary e2fsprogs could be made to execute arbitrary code if it is running in a crafted ext4 partition. Software Description e2fsprogs – ext2/ext3/ext4 file system utilities Details It was discovered that e2fsprogs incorrectly handled certain ext4 partitions. An attacker could possibly use this issue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 e2fsprogs – 1.44.6-1ubuntu0.1 Ubuntu 18.04 LTS e2fsprogs – 1.44.1-1ubuntu1.2 Ubuntu 16.04 LTS e2fsprogs – 1.42.13-1ubuntu1.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-5094 Source: USN-4142-1: e2fsprogs vulnerability