No Image

USN-4115-2: Linux kernel regression

2019-09-11 KENNETH 0

USN-4115-2: Linux kernel regression linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary USN 4115-1 introduced a regression in the Linux kernel. Software Description linux – Linux kernel linux-aws – Linux kernel for Amazon Web Services (AWS) systems linux-gke-4.15 – Linux kernel for Google Container Engine (GKE) systems linux-kvm – Linux kernel for cloud environments linux-oracle – Linux kernel for Oracle Cloud systems linux-raspi2 – Linux kernel for Raspberry Pi 2 linux-aws-hwe – Linux kernel for Amazon Web Services (AWS-HWE) systems linux-azure – Linux kernel for Microsoft Azure Cloud systems linux-gcp – Linux kernel for Google Cloud Platform (GCP) systems linux-hwe – Linux hardware enablement (HWE) kernel Details USN 4115-1 fixed vulnerabilities in the Linux 4.15 kernel for Ubuntu 18.04 [ more… ]

No Image

2019 年 9 月のセキュリティ更新プログラム (月例)

2019-09-11 KENNETH 0

2019 年 9 月のセキュリティ更新プログラム (月例) 2019 年 9 月 11 日 (日本時間)、マイクロソフトは以下のソフトウェアのセキュリティ更新プログラムを公開しました。 The post 2019 年 9 月のセキュリティ更新プログラム (月例) appeared first on Microsoft Security Response Center. Source: 2019 年 9 月のセキュリティ更新プログラム (月例)

No Image

USN-4120-2: systemd regression

2019-09-11 KENNETH 0

USN-4120-2: systemd regression systemd regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Summary USN-4120-1 caused a regression in systemd. Software Description systemd – system and service manager Details USN-4120-1 fixed a vulnerability in systemd. The update included a recent SRU from the updates pocket that introduced networking problems for some users. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that the systemd-resolved D-Bus interface did not enforce appropriate access controls. A local unprivileged user could exploit this to modify a system’s DNS resolver settings. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 systemd – 240-6ubuntu5.7 Ubuntu 18.04 LTS systemd – 237-3ubuntu10.29 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard [ more… ]

No Image

USN-4128-1: Tomcat vulnerabilities

2019-09-11 KENNETH 0

USN-4128-1: Tomcat vulnerabilities tomcat8 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in Tomcat 8. Software Description tomcat8 – Servlet and JSP engine Details It was discovered that the Tomcat 8 SSI printenv command echoed user provided data without escaping it. An attacker could possibly use this issue to perform an XSS attack. (CVE-2019-0221) It was discovered that Tomcat 8 did not address HTTP/2 connection window exhaustion on write while addressing CVE-2019-0199. An attacker could possibly use this issue to cause a denial of service. (CVE-2019-10072) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libtomcat8-java – 8.5.39-1ubuntu1~18.04.3 tomcat8 – 8.5.39-1ubuntu1~18.04.3 Ubuntu 16.04 LTS libtomcat8-java – 8.0.32-1ubuntu1.10 tomcat8 – 8.0.32-1ubuntu1.10 To update your system, [ more… ]

No Image

September 2019 Security Updates

2019-09-11 KENNETH 0

September 2019 Security Updates We have released the September security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this month’s security updates can be found in the Security Update Guide. As a reminder, Windows 7 and Windows Server 2008 R2 will be out of … September 2019 Security Updates Read More » The post September 2019 Security Updates appeared first on Microsoft Security Response Center. Source: September 2019 Security Updates