No Image

USN-3607-1: Screen Resolution Extra vulnerability

2018-03-27 KENNETH 0

USN-3607-1: Screen Resolution Extra vulnerability screen-resolution-extra vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Screen Resolution Extra could be tricked into bypassing PolicyKit authorizations. Software Description screen-resolution-extra – Extension for the GNOME screen resolution applet Details It was discovered that Screen Resolution Extra was using PolicyKit in an unsafe manner. A local attacker could potentially exploit this issue to bypass intended PolicyKit authorizations. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 17.10 screen-resolution-extra – 0.17.1.1 Ubuntu 16.04 LTS screen-resolution-extra – 0.17.1.1~16.04.1 Ubuntu 14.04 LTS screen-resolution-extra – 0.17.1.1~14.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2018-8885 Source: USN-3607-1: Screen Resolution Extra vulnerability

No Image

RHSA-2018:0591-1: Critical: python-paramiko security and bug fix update

2018-03-27 KENNETH 0

RHSA-2018:0591-1: Critical: python-paramiko security and bug fix update Red Hat Enterprise Linux: An update for python-paramiko is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2018-7750 Source: RHSA-2018:0591-1: Critical: python-paramiko security and bug fix update

No Image

USN-3606-1: LibTIFF vulnerabilities

2018-03-26 KENNETH 0

USN-3606-1: LibTIFF vulnerabilities tiff vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file. Software Description tiff – Tag Image File Format (TIFF) library Details It was discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a specially crafted image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 17.10 libtiff-tools – 4.0.8-5ubuntu0.1 libtiff5 – 4.0.8-5ubuntu0.1 Ubuntu 16.04 LTS libtiff-tools – 4.0.6-1ubuntu0.4 libtiff5 – 4.0.6-1ubuntu0.4 Ubuntu 14.04 LTS libtiff-tools – 4.0.3-7ubuntu0.9 libtiff5 [ more… ]

No Image

RHSA-2018:0586-1: Important: rh-mysql57-mysql security update

2018-03-26 KENNETH 0

RHSA-2018:0586-1: Important: rh-mysql57-mysql security update Red Hat Enterprise Linux: An update for rh-mysql57-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2018-2565, CVE-2018-2573, CVE-2018-2576, CVE-2018-2583, CVE-2018-2586, CVE-2018-2590, CVE-2018-2600, CVE-2018-2612, CVE-2018-2622, CVE-2018-2640, CVE-2018-2645, CVE-2018-2646, CVE-2018-2647, CVE-2018-2665, CVE-2018-2667, CVE-2018-2668, CVE-2018-2696, CVE-2018-2703 Source: RHSA-2018:0586-1: Important: rh-mysql57-mysql security update