No Image

USN-3494-1: XML::LibXML vulnerability

2017-11-28 KENNETH 0

USN-3494-1: XML::LibXML vulnerability Ubuntu Security Notice USN-3494-1 27th November, 2017 libxml-libxml-perl vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary XML::LibXML could be made to crash or run programs if it processed specially crafted input. Software description libxml-libxml-perl – Perl interface to the libxml2 library Details It was discovered that XML::LibXML incorrectly handled memory whenprocessing a replaceChild call. A remote attacker could possibly use thisissue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: libxml-libxml-perl 2.0128+dfsg-3ubuntu0.1 Ubuntu 17.04: libxml-libxml-perl 2.0128+dfsg-1ubuntu0.1 Ubuntu 16.04 LTS: libxml-libxml-perl 2.0123+dfsg-1ubuntu0.1 Ubuntu 14.04 LTS: libxml-libxml-perl 2.0108+dfsg-1ubuntu0.2 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2017-10672 [ more… ]

No Image

USN-3493-1: Exim vulnerability

2017-11-28 KENNETH 0

USN-3493-1: Exim vulnerability Ubuntu Security Notice USN-3493-1 27th November, 2017 exim4 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 17.04 Summary Exim could be made to crash or run programs if it received specially crafted network traffic. Software description exim4 – Exim is a mail transport agent Details It was discovered that Exim incorrectly handled memory in the ESMTPCHUNKING extension. A remote attacker could use this issue to cause Exim tocrash, resulting in a denial of service, or possibly execute arbitrarycode. The default compiler options for affected releases should reduce thevulnerability to a denial of service. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: exim4-daemon-heavy 4.89-5ubuntu1.1 exim4-daemon-light 4.89-5ubuntu1.1 Ubuntu 17.04: exim4-daemon-heavy 4.88-5ubuntu1.2 exim4-daemon-light 4.88-5ubuntu1.2 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. [ more… ]

No Image

RHSA-2017:3264-1: Critical: java-1.8.0-ibm security update

2017-11-28 KENNETH 0

RHSA-2017:3264-1: Critical: java-1.8.0-ibm security update Red Hat Enterprise Linux: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2016-10165, CVE-2017-10281, CVE-2017-10285, CVE-2017-10295, CVE-2017-10309, CVE-2017-10345, CVE-2017-10346, CVE-2017-10347, CVE-2017-10348, CVE-2017-10349, CVE-2017-10350, CVE-2017-10355, CVE-2017-10356, CVE-2017-10357, CVE-2017-10388 Source: RHSA-2017:3264-1: Critical: java-1.8.0-ibm security update

No Image

RHSA-2017:3265-1: Important: rh-mysql56-mysql security update

2017-11-28 KENNETH 0

RHSA-2017:3265-1: Important: rh-mysql56-mysql security update Red Hat Enterprise Linux: An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2017-10155, CVE-2017-10227, CVE-2017-10268, CVE-2017-10276, CVE-2017-10279, CVE-2017-10283, CVE-2017-10286, CVE-2017-10294, CVE-2017-10314, CVE-2017-10378, CVE-2017-10379, CVE-2017-10384 Source: RHSA-2017:3265-1: Important: rh-mysql56-mysql security update

No Image

USN-3476-2: postgresql-common vulnerabilities

2017-11-28 KENNETH 0

USN-3476-2: postgresql-common vulnerabilities Ubuntu Security Notice USN-3476-2 27th November, 2017 postgresql-common vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary postgresql-common could be made to overwrite files as the administrator. Software description postgresql-common – PostgreSQL database-cluster manager Details USN-3476-1 fixed two vulnerabilities in postgresql-common. This update providesthe corresponding update for Ubuntu 12.04 ESM. Original advisory details: Dawid Golunski discovered that the postgresql-common pg_ctlcluster script incorrectly handled symlinks. A local attacker could possibly use this issue to escalate privileges. (CVE-2016-1255) It was discovered that the postgresql-common helper scripts incorrectly handled symlinks. A local attacker could possibly use this issue to escalate privileges. (CVE-2017-8806) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: postgresql-common 129ubuntu1.2 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In [ more… ]