No Image

USN-4007-1: Linux kernel vulnerability

2019-06-05 KENNETH 0

USN-4007-1: Linux kernel vulnerability linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Summary A system hardening measure could be bypassed. Software Description linux – Linux kernel linux-aws – Linux kernel for Amazon Web Services (AWS) systems linux-gcp – Linux kernel for Google Cloud Platform (GCP) systems linux-kvm – Linux kernel for cloud environments linux-meta linux-oem – Linux kernel for OEM processors linux-oracle – Linux kernel for Oracle Cloud systems linux-raspi2 – Linux kernel for Raspberry Pi 2 linux-snapdragon – Linux kernel for Snapdragon processors Details Federico Manuel Bento discovered that the Linux kernel did not properly apply Address Space Layout Randomization (ASLR) in some situations for setuid a.out binaries. A local attacker could use this to improve the chances of exploiting an existing vulnerability in [ more… ]

No Image

USN-4005-1: Linux kernel vulnerabilities

2019-06-05 KENNETH 0

USN-4005-1: Linux kernel vulnerabilities linux, linux-aws, linux-gcp, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Summary Several security issues were fixed in the Linux kernel. Software Description linux – Linux kernel linux-aws – Linux kernel for Amazon Web Services (AWS) systems linux-gcp – Linux kernel for Google Cloud Platform (GCP) systems linux-kvm – Linux kernel for cloud environments linux-raspi2 – Linux kernel for Raspberry Pi 2 linux-snapdragon – Linux kernel for Snapdragon processors Details It was discovered that a null pointer dereference vulnerability existed in the LSI Logic MegaRAID driver in the Linux kernel. A local attacker could use this to cause a denial of service (system crash). (CVE-2019-11810) It was discovered that a race condition leading to a use-after-free existed in the Reliable Datagram Sockets (RDS) protocol implementation in the [ more… ]

No Image

USN-4006-1: Linux kernel vulnerability

2019-06-05 KENNETH 0

USN-4006-1: Linux kernel vulnerability linux, linux-aws, linux-gcp, linux-kvm, linux-raspi2 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Summary A system hardening measure could be bypassed. Software Description linux – Linux kernel linux-aws – Linux kernel for Amazon Web Services (AWS) systems linux-gcp – Linux kernel for Google Cloud Platform (GCP) systems linux-kvm – Linux kernel for cloud environments linux-raspi2 – Linux kernel for Raspberry Pi 2 Details Federico Manuel Bento discovered that the Linux kernel did not properly apply Address Space Layout Randomization (ASLR) in some situations for setuid a.out binaries. A local attacker could use this to improve the chances of exploiting an existing vulnerability in a setuid a.out binary. As a hardening measure, this update disables a.out support. Update instructions The problem can be corrected by updating your system to the following [ more… ]

No Image

USN-4004-2: Berkeley DB vulnerability

2019-06-05 KENNETH 0

USN-4004-2: Berkeley DB vulnerability db5.3 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Summary Berkeley DB could be made to expose sensitive information. Software Description db5.3 – Berkeley DB Utilities Details USN-4004-1 fixed a vulnerability in Berkeley DB. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: It was discovered that Berkeley DB incorrectly handled certain inputs. An attacker could possibly use this issue to read sensitive information. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM db5.3-sql-util – 5.3.28-3ubuntu3.1+esm1 db5.3-util – 5.3.28-3ubuntu3.1+esm1 libdb5.3 – 5.3.28-3ubuntu3.1+esm1 libdb5.3-sql – 5.3.28-3ubuntu3.1+esm1 libdb5.3-sql-dev – 5.3.28-3ubuntu3.1+esm1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References USN-4004-1 CVE-2019-8457 Source: USN-4004-2: Berkeley [ more… ]

No Image

USN-4004-1: Berkeley DB vulnerability

2019-06-05 KENNETH 0

USN-4004-1: Berkeley DB vulnerability db5.3 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Berkeley DB could be made to expose sensitive information. Software Description db5.3 – Berkeley DB Utilities Details It was discovered that Berkeley DB incorrectly handled certain inputs. An attacker could possibly use this issue to read sensitive information. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 db5.3-sql-util – 5.3.28+dfsg1-0.5ubuntu0.1 db5.3-util – 5.3.28+dfsg1-0.5ubuntu0.1 libdb5.3 – 5.3.28+dfsg1-0.5ubuntu0.1 libdb5.3-sql – 5.3.28+dfsg1-0.5ubuntu0.1 libdb5.3-sql-dev – 5.3.28+dfsg1-0.5ubuntu0.1 Ubuntu 18.10 db5.3-sql-util – 5.3.28+dfsg1-0.1ubuntu0.1 db5.3-util – 5.3.28+dfsg1-0.1ubuntu0.1 libdb5.3 – 5.3.28+dfsg1-0.1ubuntu0.1 libdb5.3-sql – 5.3.28+dfsg1-0.1ubuntu0.1 libdb5.3-sql-dev – 5.3.28+dfsg1-0.1ubuntu0.1 Ubuntu 18.04 LTS db5.3-sql-util – 5.3.28-13.1ubuntu1.1 db5.3-util – 5.3.28-13.1ubuntu1.1 libdb5.3 – 5.3.28-13.1ubuntu1.1 libdb5.3-sql – 5.3.28-13.1ubuntu1.1 libdb5.3-sql-dev – 5.3.28-13.1ubuntu1.1 Ubuntu 16.04 LTS db5.3-sql-util – 5.3.28-11ubuntu0.2 [ more… ]