No Image

USN-3610-1: ICU vulnerability

2018-03-29 KENNETH 0

USN-3610-1: ICU vulnerability icu vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary ICU could be made to crash if it received specially crafted input. Software Description icu – International Components for Unicode library Details It was discovered that ICU incorrectly handled certain calendars. If an application using ICU processed crafted data, a remote attacker could possibly cause it to crash, leading to a denial of service. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 17.10 libicu57 – 57.1-6ubuntu0.3 Ubuntu 16.04 LTS libicu55 – 55.1-7ubuntu0.4 Ubuntu 14.04 LTS libicu52 – 52.1-3ubuntu0.8 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2017-15422 Source: USN-3610-1: ICU vulnerability

No Image

USN-3609-1: Firefox vulnerability

2018-03-28 KENNETH 0

USN-3609-1: Firefox vulnerability firefox vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description firefox – Mozilla Open Source web browser Details A use-after-free was discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service or execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 17.10 firefox – 59.0.2+build1-0ubuntu0.17.10.1 Ubuntu 16.04 LTS firefox – 59.0.2+build1-0ubuntu0.16.04.1 Ubuntu 14.04 LTS firefox – 59.0.2+build1-0ubuntu0.14.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to restart Firefox to [ more… ]

No Image

USN-3608-1: Zsh vulnerabilities

2018-03-27 KENNETH 0

USN-3608-1: Zsh vulnerabilities zsh vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Zsh. Software Description zsh – shell with lots of features Details Richard Maciel Costa discovered that Zsh incorrectly handled certain inputs. An attacker could possibly use this to cause a denial of service. (CVE-2018-1071) It was discovered that Zsh incorrectly handled certain files. An attacker could possibly use this to execute arbitrary code. (CVE-2018-1083) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 17.10 zsh – 5.2-5ubuntu1.2 Ubuntu 16.04 LTS zsh – 5.1.1-1ubuntu2.2 Ubuntu 14.04 LTS zsh – 5.0.2-3ubuntu6.2 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to restart Zsh to make all [ more… ]

No Image

RHBA-2018:0597-1: tzdata enhancement update

2018-03-27 KENNETH 0

RHBA-2018:0597-1: tzdata enhancement update Red Hat Enterprise Linux: Updated tzdata packages that add various enhancements are now available for Red Hat Enterprise Linux 5.9 Advanced Update Support, Red Hat Enterprise Linux 5 Extended Life Cycle Support, Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 Telco Extended Update Support, Red Hat Enterprise Linux 6.7 Extended Update Support, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, Red Hat Enterprise Linux 7.3 Extended Update Support, and Red Hat Enterprise Linux 7. Source: RHBA-2018:0597-1: tzdata enhancement update