No Image

RHEA-2017:3011-1: new packages: devtoolset-7-valgrind

2017-10-24 KENNETH 0

RHEA-2017:3011-1: new packages: devtoolset-7-valgrind Red Hat Enterprise Linux: New devtoolset-7-valgrind packages are now available as a part of Red Hat Developer Toolset 7.0 for Red Hat Enterprise Linux. Source: RHEA-2017:3011-1: new packages: devtoolset-7-valgrind

No Image

USN-3434-2: Libidn vulnerability

2017-10-24 KENNETH 0

USN-3434-2: Libidn vulnerability Ubuntu Security Notice USN-3434-2 23rd October, 2017 libidn vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Libidn could be made to crash or run programs if it processed specially crafted input. Software description libidn – implementation of IETF IDN specifications Details USN-3434-1 fixed a vulnerability in Libidn. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that Libidn incorrectly handled decoding certain digits. A remote attacker could use this issue to cause Libidn to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: libidn11 1.23-2ubuntu0.2 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will [ more… ]

No Image

USN-3441-2: curl vulnerabilities

2017-10-24 KENNETH 0

USN-3441-2: curl vulnerabilities Ubuntu Security Notice USN-3441-2 23rd October, 2017 curl vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in curl. Software description curl – HTTP, HTTPS, and FTP client and client libraries Details USN-3441-1 fixed several vulnerabilities in curl. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: Daniel Stenberg discovered that curl incorrectly handled large floating point output. A remote attacker could use this issue to cause curl to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2016-9586) Even Rouault discovered that curl incorrectly handled large file names when doing TFTP transfers. A remote attacker could use this issue to cause curl to crash, resulting in a denial of service, or possibly obtain sensitive memory contents. (CVE-2017-1000100) Brian [ more… ]

No Image

USN-3458-2: ICU vulnerability

2017-10-24 KENNETH 0

USN-3458-2: ICU vulnerability Ubuntu Security Notice USN-3458-2 23rd October, 2017 icu vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary ICU could be made to crash or run arbitrary code as your login if it received specially crafted input. Software description icu – International Components for Unicode library Details USN-3458-1 fixed a vulnerability in ICU. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that ICU incorrectly handled certain inputs. If an application using ICU processed crafted data, a remote attacker could possibly cause it to crash or potentially execute arbitrary code with the privileges of the user invoking the program. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: libicu48 4.8.1.1-3ubuntu0.9 lib32icu48 4.8.1.1-3ubuntu0.9 To update your [ more… ]

No Image

USN-3458-1: ICU vulnerability

2017-10-24 KENNETH 0

USN-3458-1: ICU vulnerability Ubuntu Security Notice USN-3458-1 23rd October, 2017 icu vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary ICU could be made to crash or run arbitrary code as your login if it received specially crafted input. Software description icu – International Components for Unicode library Details It was discovered that ICU incorrectly handled certain inputs. If anapplication using ICU processed crafted data, a remote attacker couldpossibly cause it to crash or potentially execute arbitrary code withthe privileges of the user invoking the program. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: libicu57 57.1-6ubuntu0.2 Ubuntu 17.04: libicu57 57.1-5ubuntu0.2 Ubuntu 16.04 LTS: libicu55 55.1-7ubuntu0.3 Ubuntu 14.04 LTS: libicu52 52.1-3ubuntu0.7 To update your system, please follow [ more… ]