No Image

USN-3559-1: Django vulnerabilities

2018-02-08 KENNETH 0

USN-3559-1: Django vulnerabilities Ubuntu Security Notice USN-3559-1 7th February, 2018 python-django vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Summary Several security issues were fixed in Django. Software description python-django – High-level Python web development framework Details It was discovered that Django incorrectly handled certain requests.An attacker could possibly use this to access sensitive information.(CVE-2017-12794, CVE-2018-6188) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: python3-django 1:1.11.4-1ubuntu1.1 python-django 1:1.11.4-1ubuntu1.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2017-12794, CVE-2018-6188 Source: USN-3559-1: Django vulnerabilities

No Image

RHBA-2018:0281-2: openvswitch bug fix update

2018-02-07 KENNETH 0

RHBA-2018:0281-2: openvswitch bug fix update Red Hat Enterprise Linux: Updated openvswitch packages that fix several bugs are now available in the Fast Datapath channel of Red Hat Enterprise Linux 7. Source: RHBA-2018:0281-2: openvswitch bug fix update

No Image

RHSA-2018:0279-1: Moderate: rh-mariadb100-mariadb security update

2018-02-06 KENNETH 0

RHSA-2018:0279-1: Moderate: rh-mariadb100-mariadb security update Red Hat Enterprise Linux: An update for rh-mariadb100-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2016-5617, CVE-2016-6664, CVE-2017-10268, CVE-2017-10286, CVE-2017-10378, CVE-2017-10379, CVE-2017-10384, CVE-2017-3238, CVE-2017-3243, CVE-2017-3244, CVE-2017-3257, CVE-2017-3258, CVE-2017-3265, CVE-2017-3291, CVE-2017-3302, CVE-2017-3308, CVE-2017-3309, CVE-2017-3312, CVE-2017-3313, CVE-2017-3317, CVE-2017-3318, CVE-2017-3453, CVE-2017-3456, CVE-2017-3464, CVE-2017-3636, CVE-2017-3641, CVE-2017-3653 Source: RHSA-2018:0279-1: Moderate: rh-mariadb100-mariadb security update

No Image

USN-3557-1: Squid vulnerabilities

2018-02-06 KENNETH 0

USN-3557-1: Squid vulnerabilities Ubuntu Security Notice USN-3557-1 5th February, 2018 squid3 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Squid. Software description squid3 – Web proxy cache server Details Mathias Fischer discovered that Squid incorrectly handled certain longstrings in headers. A malicious remote server could possibly cause Squid tocrash, resulting in a denial of service. This issue was only addressed inUbuntu 16.04 LTS. (CVE-2016-2569) William Lima discovered that Squid incorrectly handled XML parsing whenprocessing Edge Side Includes (ESI). A malicious remote server couldpossibly cause Squid to crash, resulting in a denial of service. This issuewas only addressed in Ubuntu 16.04 LTS. (CVE-2016-2570) Alex Rousskov discovered that Squid incorrectly handled response-parsingfailures. A malicious remote server could possibly cause Squid to crash,resulting in [ more… ]

No Image

USN-3558-1: systemd vulnerabilities

2018-02-06 KENNETH 0

USN-3558-1: systemd vulnerabilities Ubuntu Security Notice USN-3558-1 5th February, 2018 systemd vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in systemd. Software description systemd – system and service manager Details Karim Hossen & Thomas Imbert and Nelson William Gamazo Sanchezindependently discovered that systemd-resolved incorrectly handled certainDNS responses. A remote attacker could possibly use this issue to causesystemd to temporarily stop responding, resulting in a denial of service.This issue only affected Ubuntu 16.04 LTS. (CVE-2017-15908) It was discovered that systemd incorrectly handled automounted volumes. Alocal attacker could possibly use this issue to cause applications to hang,resulting in a denial of service. (CVE-2018-1049) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: systemd 229-4ubuntu21.1 Ubuntu 14.04 [ more… ]