No Image

USN-3575-1: QEMU vulnerabilities

2018-02-21 KENNETH 0

USN-3575-1: QEMU vulnerabilities Ubuntu Security Notice USN-3575-1 20th February, 2018 qemu vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in QEMU. Software description qemu – Machine emulator and virtualizer Details It was discovered that QEMU incorrectly handled guest ram. A privilegedattacker inside the guest could use this issue to cause QEMU to crash,resulting in a denial of service. This issue only affected Ubuntu 14.04 LTSand Ubuntu 16.04 LTS. (CVE-2017-11334) David Buchanan discovered that QEMU incorrectly handled the VGA device. Aprivileged attacker inside the guest could use this issue to cause QEMU tocrash, resulting in a denial of service. This issue was only addressed inUbuntu 17.10. (CVE-2017-13672) Thomas Garnier discovered that QEMU incorrectly handled multiboot. Anattacker could use this issue to cause QEMU [ more… ]

No Image

USN-3576-1: libvirt vulnerabilities

2018-02-21 KENNETH 0

USN-3576-1: libvirt vulnerabilities Ubuntu Security Notice USN-3576-1 20th February, 2018 libvirt vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in libvirt. Software description libvirt – Libvirt virtualization toolkit Details Vivian Zhang and Christoph Anton Mitterer discovered that libvirtincorrectly disabled password authentication when the VNC password was setto an empty string. A remote attacker could possibly use this issue tobypass authentication, contrary to expectations. This issue only affectedUbuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-5008) Daniel P. Berrange discovered that libvirt incorrectly handled validatingSSL/TLS certificates. A remote attacker could possibly use this issue toobtain sensitive information. This issue only affected Ubuntu 17.10.(CVE-2017-1000256) Daniel P. Berrange and Peter Krempa discovered that libvirt incorrectlyhandled large QEMU replies. An attacker could possibly use this issue tocause [ more… ]

No Image

USN-3574-1: Bind vulnerability

2018-02-20 KENNETH 0

USN-3574-1: Bind vulnerability Ubuntu Security Notice USN-3574-1 19th February, 2018 bind9 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Bind could be made to crash if it received specially crafted network traffic. Software description bind9 – Internet Domain Name Server Details It was discovered that Bind incorrectly handled DNSSECvalidation. An attacker could possibly use this to cause a denialof service. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: bind9 1:9.8.1.dfsg.P1-4ubuntu0.25 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2018-5735 Source: USN-3574-1: Bind vulnerability