No Image

USN-4141-1: Exim vulnerability

2019-09-29 KENNETH 0

USN-4141-1: Exim vulnerability exim4 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Summary Exim could be made to crash or run programs if it received specially crafted network traffic. Software Description exim4 – Exim is a mail transport agent Details It was discovered that Exim incorrectly handled certain string operations. A remote attacker could use this issue to cause Exim to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 exim4-daemon-heavy – 4.92-4ubuntu1.4 exim4-daemon-light – 4.92-4ubuntu1.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-16928 Source: USN-4141-1: Exim vulnerability

No Image

USN-4140-1: Firefox vulnerability

2019-09-26 KENNETH 0

USN-4140-1: Firefox vulnerability firefox vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Firefox could be made to hijack the mouse pointer it if opened a malicious website. Software Description firefox – Mozilla Open Source web browser Details It was discovered that no user notification was given when pointer lock is enabled. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to hijack the mouse pointer and confuse users. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 firefox – 69.0.1+build1-0ubuntu0.19.04.1 Ubuntu 18.04 LTS firefox – 69.0.1+build1-0ubuntu0.18.04.1 Ubuntu 16.04 LTS firefox – 69.0.1+build1-0ubuntu0.16.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to [ more… ]

No Image

USN-4139-1: File Roller vulnerability

2019-09-25 KENNETH 0

USN-4139-1: File Roller vulnerability file-roller vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary File Roller could be made to overwrite sensitive files if it received a specially crafted TAR file. Software Description file-roller – archive manager for GNOME Details It was discovered that File Roller incorrectly handled certain TAR files. An attacker could possibly use this issue to overwrite sensitive files during extraction. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS file-roller – 3.28.0-1ubuntu1.1 Ubuntu 16.04 LTS file-roller – 3.16.5-0ubuntu1.3 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-16680 Source: USN-4139-1: File Roller vulnerability

No Image

USN-4138-1: LibreOffice vulnerability

2019-09-24 KENNETH 0

USN-4138-1: LibreOffice vulnerability libreoffice vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary LibreOffice could be made to run programs as your login if it opened a specially crafted file. Software Description libreoffice – Office productivity suite Details It was discovered that LibreOffice incorrectly handled embedded scripts in document files. If a user were tricked into opening a specially crafted document, a remote attacker could possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 libreoffice-core – 1:6.2.7-0ubuntu0.19.04.1 Ubuntu 18.04 LTS libreoffice-core – 1:6.0.7-0ubuntu0.18.04.10 Ubuntu 16.04 LTS libreoffice-core – 1:5.1.6~rc2-0ubuntu1~xenial10 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to restart LibreOffice to make all the necessary changes. References [ more… ]

No Image

MSRC is going to ROOTCON!

2019-09-24 KENNETH 0

MSRC is going to ROOTCON! The Microsoft Security Response Center (MSRC) works with partners all over the world to protect Microsoft customers. This week we’re headed to the Philippines to meet security researchers and bounty hunters at ROOTCON 13! Planning on attending ROOTCON? If you want to learn more about how you can earn rewards for reporting vulnerabilities to Microsoft … MSRC is going to ROOTCON! Read More » The post MSRC is going to ROOTCON! appeared first on Microsoft Security Response Center. Source: MSRC is going to ROOTCON!