No Image

USN-3573-1: Quagga vulnerabilities

2018-02-16 KENNETH 0

USN-3573-1: Quagga vulnerabilities Ubuntu Security Notice USN-3573-1 15th February, 2018 quagga vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Quagga. Software description quagga – BGP/OSPF/RIP routing daemon Details It was discovered that a double-free vulnerability existed in theQuagga BGP daemon when processing certain forms of UPDATE message.A remote attacker could use this to cause a denial of service orpossibly execute arbitrary code. (CVE-2018-5379) It was discovered that the Quagga BGP daemon did not properly boundscheck the data sent with a NOTIFY to a peer. An attacker could use thisto expose sensitive information or possibly cause a denial of service.This issue only affected Ubuntu 17.10. (CVE-2018-5378) It was discovered that a table overrun vulnerability existed in theQuagga BGP daemon. An attacker in [ more… ]

No Image

Inside the MSRC– The Monthly Security Update Releases

2018-02-15 KENNETH 0

Inside the MSRC– The Monthly Security Update Releases For the second in this series of blog entries we want to look into which vulnerability reports make it into the monthly release cadence. It may help to start with some history.  In September 2003 we made a change from a release anytime approach to a mostly predictable, monthly release cadence.  October 2003 ushered in what became known as Update Tuesday.  How and when Microsoft releases new products and services in market products has changed over the years, but the monthly delivery of security content has remained steady. So how do we decide what goes into a monthly security release?  That decision largely rides on required customer action and risk.  Required customer action is realized through products where customers need to take action to protect themselves against a vulnerability.  For consumers, protection [ more… ]

No Image

USN-3572-1: FreeType vulnerability

2018-02-15 KENNETH 0

USN-3572-1: FreeType vulnerability Ubuntu Security Notice USN-3572-1 14th February, 2018 freetype vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Summary FreeType could be made to crash if it opened a specially crafted file. Software description freetype – FreeType 2 is a font engine library Details It was discovered that FreeType incorrectly handled certain files.An attacker could possibly use this to cause a denial of service. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: libfreetype6 2.8-0.2ubuntu2.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to restart your session to makeall the necessary changes. References CVE-2018-6942 Source: USN-3572-1: FreeType vulnerability