No Image

USN-3883-1: LibreOffice vulnerabilities

2019-02-06 KENNETH 0

USN-3883-1: LibreOffice vulnerabilities libreoffice vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in LibreOffice. Software Description libreoffice – Office productivity suite Details It was discovered that LibreOffice incorrectly handled certain document files. If a user were tricked into opening a specially crafted document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code. (CVE-2018-10119, CVE-2018-10120, CVE-2018-11790) It was discovered that LibreOffice incorrectly handled embedded SMB connections in document files. If a user were tricked in to opening a specially crafted document, a remote attacker could possibly exploit this to obtain sensitive information. (CVE-2018-10583) Alex Inführ discovered that LibreOffice incorrectly handled embedded scripts in document files. If a user were tricked into opening a specially crafted document, a remote attacker could possibly [ more… ]

No Image

USN-3882-1: curl vulnerabilities

2019-02-06 KENNETH 0

USN-3882-1: curl vulnerabilities curl vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in curl. Software Description curl – HTTP, HTTPS, and FTP client and client libraries Details Wenxiang Qian discovered that curl incorrectly handled certain NTLM authentication messages. A remote attacker could possibly use this issue to cause curl to crash, resulting in a denial of service. This issue only applied to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 18.10. (CVE-2018-16890) Wenxiang Qian discovered that curl incorrectly handled certain NTLMv2 authentication messages. A remote attacker could use this issue to cause curl to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only applied to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu [ more… ]

No Image

RHBA-2019:0280-1: Red Hat Certification bug fix and enhancement update

2019-02-06 KENNETH 0

RHBA-2019:0280-1: Red Hat Certification bug fix and enhancement update Red Hat Enterprise Linux: An updated redhat-certification package that fixes several bugs and adds various enhancements is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Source: RHBA-2019:0280-1: Red Hat Certification bug fix and enhancement update

No Image

RHBA-2019:0279-1: parted bug fix update

2019-02-06 KENNETH 0

RHBA-2019:0279-1: parted bug fix update Red Hat Enterprise Linux: Updated parted packages that fix one bug are now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Source: RHBA-2019:0279-1: parted bug fix update

No Image

USN-3881-2: Dovecot vulnerability

2019-02-06 KENNETH 0

USN-3881-2: Dovecot vulnerability dovecot vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 ESM Summary Dovecot could be made to expose sensitive information over the network. Software Description dovecot – IMAP and POP3 email server Details USN-3881-1 fixed a vulnerability in Dovecot. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that Dovecot incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM dovecot-core – 1:2.0.19-0ubuntu2.6 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References USN-3881-1 CVE-2019-3814 Source: USN-3881-2: [ more… ]