No Image

USN-3874-1: Firefox vulnerabilities

2019-01-31 KENNETH 0

USN-3874-1: Firefox vulnerabilities firefox vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description firefox – Mozilla Open Source web browser Details Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, gain additional privileges by escaping the sandbox, or execute arbitrary code. (CVE-2018-18500, CVE-2018-18501, CVE-2018-18502, CVE-2018-18503, CVE-2018-18504, CVE-2018-18505) It was discovered that Firefox allowed PAC files to specify that requests to localhost are sent through the proxy to another server. If proxy auto-detection is enabled, an attacker could potentially exploit this to conduct attacks [ more… ]

No Image

RHSA-2019:0219-1: Critical: firefox security update

2019-01-31 KENNETH 0

RHSA-2019:0219-1: Critical: firefox security update Red Hat Enterprise Linux: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2018-18500, CVE-2018-18501, CVE-2018-18505 Source: RHSA-2019:0219-1: Critical: firefox security update

No Image

RHSA-2019:0218-1: Critical: firefox security update

2019-01-31 KENNETH 0

RHSA-2019:0218-1: Critical: firefox security update Red Hat Enterprise Linux: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2018-18500, CVE-2018-18501, CVE-2018-18505 Source: RHSA-2019:0218-1: Critical: firefox security update

No Image

USN-3873-1: Open vSwitch vulnerabilities

2019-01-30 KENNETH 0

USN-3873-1: Open vSwitch vulnerabilities openvswitch vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in Open vSwitch. Software Description openvswitch – Ethernet virtual switch Details It was discovered that Open vSwitch incorrectly decoded certain packets. A remote attacker could possibly use this issue to cause Open vSwitch to crash, resulting in a denial of service. (CVE-2018-17204) It was discovered that Open vSwitch incorrectly handled processing certain flows. A remote attacker could possibly use this issue to cause Open vSwitch to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-17205) It was discovered that Open vSwitch incorrectly handled BUNDLE action decoding. A remote attacker could possibly use this issue to cause Open vSwitch to crash, resulting in a denial of [ more… ]

No Image

RHBA-2019:0175-1: freetype bug fix update

2019-01-30 KENNETH 0

RHBA-2019:0175-1: freetype bug fix update Red Hat Enterprise Linux: Updated freetype packages that fix one bug are now available for Red Hat Enterprise Linux 7. Source: RHBA-2019:0175-1: freetype bug fix update