No Image

May 2019 Security Update Release

2019-05-15 KENNETH 0

May 2019 Security Update Release Today, we released security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this month’s security updates can be found on the Security Update Guide. Source: May 2019 Security Update Release

No Image

USN-3976-2: Samba vulnerability

2019-05-14 KENNETH 0

USN-3976-2: Samba vulnerability samba vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary Samba could allow unintended access to network services. Software Description samba – SMB/CIFS file, print, and login server for Unix Details USN-3976-1 fixed a vulnerability in Samba. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: Isaac Boukris and Andrew Bartlett discovered that Samba incorrectly checked S4U2Self packets. In certain environments, a remote attacker could possibly use this issue to escalate privileges. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM samba – 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm1 Ubuntu 12.04 ESM samba – 2:3.6.25-0ubuntu0.12.04.18 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the [ more… ]

No Image

USN-3976-1: Samba vulnerability

2019-05-14 KENNETH 0

USN-3976-1: Samba vulnerability samba vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Samba could allow unintended access to network services. Software Description samba – SMB/CIFS file, print, and login server for Unix Details Isaac Boukris and Andrew Bartlett discovered that Samba incorrectly checked S4U2Self packets. In certain environments, a remote attacker could possibly use this issue to escalate privileges. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 samba – 2:4.10.0+dfsg-0ubuntu2.1 Ubuntu 18.10 samba – 2:4.8.4+dfsg-2ubuntu2.4 Ubuntu 18.04 LTS samba – 2:4.7.6+dfsg~ubuntu-0ubuntu2.10 Ubuntu 16.04 LTS samba – 2:4.3.11+dfsg-0ubuntu0.16.04.20 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2018-16860 Source: USN-3976-1: Samba vulnerability

No Image

USN-3975-1: OpenJDK vulnerabilities

2019-05-14 KENNETH 0

USN-3975-1: OpenJDK vulnerabilities openjdk-8, openjdk-lts vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in OpenJDK. Software Description openjdk-lts – Open Source Java implementation openjdk-8 – Open Source Java implementation Details It was discovered that the BigDecimal implementation in OpenJDK performed excessive computation when given certain values. An attacker could use this to cause a denial of service (excessive CPU usage). (CVE-2019-2602) Corwin de Boor and Robert Xiao discovered that the RMI registry implementation in OpenJDK did not properly select the correct skeleton class in some situations. An attacker could use this to possibly escape Java sandbox restrictions. (CVE-2019-2684) Mateusz Jurczyk discovered a vulnerability in the 2D component of OpenJDK. An attacker could use this to possibly escape Java sandbox restrictions. [ more… ]

No Image

USN-3974-1: VCFtools vulnerabilities

2019-05-14 KENNETH 0

USN-3974-1: VCFtools vulnerabilities VCFtools vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary VCFTools could be made to crash if it received specially crafted input. Software Description vcftools – Collection of tools to work with VCF files Details It was discovered that VCFtools improperly handled certain input. If a user was tricked into opening a crafted input file, VCFtools could be made to crash. (CVE-2018-11099, CVE-2018-11129, CVE-2018-11130) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS vcftools – 0.1.14+dfsg-2ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2018-11099 CVE-2018-11129 CVE-2018-11130 Source: USN-3974-1: VCFtools vulnerabilities