No Image

USN-3496-1: Python vulnerability

2017-11-29 KENNETH 0

USN-3496-1: Python vulnerability Ubuntu Security Notice USN-3496-1 28th November, 2017 python2.7 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Python could be made to run arbitrary code. Software description python2.7 – An interactive high-level object-oriented language Details It was discovered that Python incorrectly handled decoding certain strings.An attacker could possibly use this issue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.04: python2.7-minimal 2.7.13-2ubuntu0.1 python2.7 2.7.13-2ubuntu0.1 Ubuntu 16.04 LTS: python2.7-minimal 2.7.12-1ubuntu0~16.04.2 python2.7 2.7.12-1ubuntu0~16.04.2 Ubuntu 14.04 LTS: python2.7-minimal 2.7.6-8ubuntu0.4 python2.7 2.7.6-8ubuntu0.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2017-1000158 Source: USN-3496-1: Python vulnerability

No Image

USN-3496-2: Python vulnerability

2017-11-29 KENNETH 0

USN-3496-2: Python vulnerability Ubuntu Security Notice USN-3496-2 28th November, 2017 python2.7 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Python could be made to run arbitrary code. Software description python2.7 – An interactive high-level object-oriented language Details USN-3496-1 fixed a vulnerability in Python. This update providesthe corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that Python incorrectly handled decoding certain strings. An attacker could possibly use this issue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: python2.7-minimal 2.7.3-0ubuntu3.10 python2.7 2.7.3-0ubuntu3.10 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2017-1000158 Source: USN-3496-2: Python vulnerability

No Image

RHEA-2017:3266-1: new package: python-pytoml

2017-11-29 KENNETH 0

RHEA-2017:3266-1: new package: python-pytoml Red Hat Enterprise Linux: A new python-pytoml package is now available for Red Hat Enterprise Linux 7 Extras. Source: RHEA-2017:3266-1: new package: python-pytoml

No Image

USN-3477-2: Firefox regression

2017-11-28 KENNETH 0

USN-3477-2: Firefox regression Ubuntu Security Notice USN-3477-2 27th November, 2017 firefox regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary USN-3477-1 caused a regression in Firefox. Software description firefox – Mozilla Open Source web browser Details USN-3477-1 fixed vulnerabilities in Firefox. The update caused searchsuggestions to not be displayed when performing Google searches from thesearch bar. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, read uninitialized memory, obtain sensitive information, bypass same-origin restrictions, bypass CSP protections, bypass mixed content blocking, spoof the addressbar, or execute arbitrary code. (CVE-2017-7826, CVE-2017-7827, CVE-2017-7828, [ more… ]

No Image

USN-3495-1: OptiPNG vulnerability

2017-11-28 KENNETH 0

USN-3495-1: OptiPNG vulnerability Ubuntu Security Notice USN-3495-1 27th November, 2017 optipng vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary OptiPNG could be made to crash or run programs as your login if it opened a specially crafted file. Software description optipng – advanced PNG (Portable Network Graphics) optimizer Details It was discovered that OptiPNG incorrectly handled memory. A remoteattacker could use this issue with a specially crafted image file to causeOptiPNG to crash, resulting in a denial of service, or possibly executearbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: optipng 0.7.6-1ubuntu0.17.10.1 Ubuntu 17.04: optipng 0.7.6-1ubuntu0.17.04.1 Ubuntu 16.04 LTS: optipng 0.7.6-1ubuntu0.16.04.1 Ubuntu 14.04 LTS: optipng 0.6.4-1ubuntu0.14.04.2 To update your system, please follow these instructions: [ more… ]