No Image

USN-3531-2: Intel Microcode regression

2018-01-24 KENNETH 0

USN-3531-2: Intel Microcode regression Ubuntu Security Notice USN-3531-2 22nd January, 2018 intel-microcode regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary USN-3531-1 introduced regressions in intel-microcode. Software description intel-microcode – Processor microcode for Intel CPUs Details USN-3531-1 updated Intel microcode to the 20180108 release. Regressionswere discovered in the microcode updates which could cause systeminstability on certain hardware platforms. At the request of Intel, we havereverted to the previous packaged microcode version, the 20170707 release. Original advisory details: It was discovered that microprocessors utilizing speculative execution and branch prediction may allow unauthorized memory reads via sidechannel attacks. This flaw is known as Spectre. A local attacker could use this to expose sensitive information, including kernel memory. (CVE-2017-5715) This update provides the microcode updates required for the corresponding Linux kernel [ more… ]

No Image

USN-3538-1: OpenSSH vulnerabilities

2018-01-24 KENNETH 0

USN-3538-1: OpenSSH vulnerabilities Ubuntu Security Notice USN-3538-1 22nd January, 2018 openssh vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in OpenSSH. Software description openssh – secure shell (SSH) for secure access to remote machines Details Jann Horn discovered that OpenSSH incorrectly loaded PKCS#11 modules fromuntrusted directories. A remote attacker could possibly use this issue toexecute arbitrary PKCS#11 modules. This issue only affected Ubuntu 14.04LTS and Ubuntu 16.04 LTS. (CVE-2016-10009) Jann Horn discovered that OpenSSH incorrectly handled permissions onUnix-domain sockets when privilege separation is disabled. A local attackercould possibly use this issue to gain privileges. This issue only affectedUbuntu 16.04 LTS. (CVE-2016-10010) Jann Horn discovered that OpenSSH incorrectly handled certain buffer memoryoperations. A local attacker could possibly use this issue to obtainsensitive information. [ more… ]