No Image

USN-3562-1: MiniUPnP vulnerabilities

2018-02-08 KENNETH 0

USN-3562-1: MiniUPnP vulnerabilities Ubuntu Security Notice USN-3562-1 7th February, 2018 miniupnpc vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary MiniUPnP could be made to crash or run programs if it received specially crafted network traffic. Software description miniupnpc – UPnP IGD client lightweight library Details It was discovered that MiniUPnP incorrectly handled memory. A remoteattacker could use this issue to cause a denial of service or possiblyexecute arbitrary code with privileges of the user running an applicationthat uses the MiniUPnP library. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: libminiupnpc10 1.9.20140610-4ubuntu1.1 Ubuntu 16.04 LTS: libminiupnpc10 1.9.20140610-2ubuntu2.16.04.2 Ubuntu 14.04 LTS: libminiupnpc8 1.6-3ubuntu2.14.04.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will [ more… ]

No Image

RHSA-2018:0285-1: Critical: flash-plugin security update

2018-02-08 KENNETH 0

RHSA-2018:0285-1: Critical: flash-plugin security update Red Hat Enterprise Linux: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2018-4877, CVE-2018-4878 Source: RHSA-2018:0285-1: Critical: flash-plugin security update

No Image

USN-3561-1: libvirt update

2018-02-08 KENNETH 0

USN-3561-1: libvirt update Ubuntu Security Notice USN-3561-1 7th February, 2018 libvirt update A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Spectre mitigations were added to libvirt. Software description libvirt – Libvirt virtualization toolkit Details It was discovered that microprocessors utilizing speculative executionand branch prediction may allow unauthorized memory reads via sidechannelattacks. This flaw is known as Spectre. An attacker in the guest could usethis to expose sensitive guest information, including kernel memory. This update allows libvirt to expose new CPU features added by microcodeupdates to guests. On amd64 and i386, new CPU models that match the updatedmicrocode features were added with an -IBRS suffix. Certain environmentswill require guests to be switched manually to the new CPU models aftermicrocode updates have been applied to the host. Update instructions The [ more… ]

No Image

USN-3560-1: QEMU update

2018-02-08 KENNETH 0

USN-3560-1: QEMU update Ubuntu Security Notice USN-3560-1 7th February, 2018 qemu update A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Spectre mitigations were added to QEMU. Software description qemu – Machine emulator and virtualizer Details It was discovered that microprocessors utilizing speculative executionand branch prediction may allow unauthorized memory reads via sidechannelattacks. This flaw is known as Spectre. An attacker in the guest could usethis to expose sensitive guest information, including kernel memory. This update allows QEMU to expose new CPU features added by microcodeupdates to guests on amd64, i386, and s390x. On amd64 and i386, new CPUmodels that match the updated microcode features were added with an -IBRSsuffix. Certain environments will require guests to be switched manually tothe new CPU models after microcode updates have been applied [ more… ]