No Image

USN-3404-1: Linux kernel vulnerability

2017-08-29 KENNETH 0

USN-3404-1: Linux kernel vulnerability Ubuntu Security Notice USN-3404-1 28th August, 2017 linux, linux-raspi2 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Summary The system could be made to crash under certain conditions. Software description linux – Linux kernel linux-raspi2 – Linux kernel for Raspberry Pi 2 Details A reference count bug was discovered in the Linux kernel ipx protocolstack. A local attacker could exploit this flaw to cause a denial ofservice or possibly other unspecified problems. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.04: linux-image-4.10.0-33-generic 4.10.0-33.37 linux-image-generic-lpae 4.10.0.33.33 linux-image-4.10.0-33-lowlatency 4.10.0-33.37 linux-image-4.10.0-1016-raspi2 4.10.0-1016.19 linux-image-generic 4.10.0.33.33 linux-image-4.10.0-33-generic-lpae 4.10.0-33.37 linux-image-lowlatency 4.10.0.33.33 linux-image-raspi2 4.10.0.1016.17 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to reboot your computer to makeall the necessary [ more… ]

No Image

USN-3405-2: Linux kernel (Xenial HWE) vulnerabilities

2017-08-29 KENNETH 0

USN-3405-2: Linux kernel (Xenial HWE) vulnerabilities Ubuntu Security Notice USN-3405-2 28th August, 2017 linux-lts-xenial vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in the Linux kernel. Software description linux-lts-xenial – Linux hardware enablement kernel from Xenial for Trusty Details USN-3405-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04LTS. This update provides the corresponding updates for the LinuxHardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu14.04 LTS. It was discovered that a use-after-free vulnerability existed in the POSIXmessage queue implementation in the Linux kernel. A local attacker coulduse this to cause a denial of service (system crash) or possibly executearbitrary code. (CVE-2017-11176) Huang Weller discovered that the ext4 filesystem implementation in theLinux kernel mishandled a needs-flushing-before-commit list. A localattacker could use this to expose sensitive information. [ more… ]

No Image

RHSA-2017:2538-1: Low: rh-nginx110-nginx security update

2017-08-29 KENNETH 0

RHSA-2017:2538-1: Low: rh-nginx110-nginx security update Red Hat Enterprise Linux: An update for rh-nginx110-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2017-7529 Source: RHSA-2017:2538-1: Low: rh-nginx110-nginx security update

No Image

USN-3403-1: Ghostscript vulnerabilities

2017-08-29 KENNETH 0

USN-3403-1: Ghostscript vulnerabilities Ubuntu Security Notice USN-3403-1 28th August, 2017 ghostscript vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Ghostscript. Software description ghostscript – PostScript and PDF interpreter Details Kamil Frankowicz discovered that Ghostscript mishandles references.A remote attacker could use this to cause a denial of service.(CVE-2017-11714) Kim Gwan Yeong discovered that Ghostscript could allow a heap-based bufferover-read and application crash. A remote attacker could use a crafteddocument to cause a denial of service. (CVE-2017-9611, CVE-2017-9726,CVE-2017-9727, CVE-2017-9739) Kim Gwan Yeong discovered an use-after-free vulnerability in Ghostscript.A remote attacker could use a crafted file to cause a denial of service.(CVE-2017-9612) Kim Gwan Yeong discovered a lack of integer overflow check in Ghostscript.A remote attacker could use crafted PostScript document to cause a [ more… ]

No Image

USN-3199-3: Python Crypto vulnerability

2017-08-29 KENNETH 0

USN-3199-3: Python Crypto vulnerability Ubuntu Security Notice USN-3199-3 28th August, 2017 python-crypto vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Programs using the Python Cryptography Toolkit could be made to crash or run programs if they receive specially crafted network traffic or other input. Software description python-crypto – cryptographic algorithms and protocols for Python Details USN-3199-1 fixed a vulnerability in Python Crypto. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that the ALGnew function in block_templace.c in the Python Cryptography Toolkit contained a heap-based buffer overflow vulnerability. A remote attacker could use this flaw to execute arbitrary code by using a crafted initialization vector parameter. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: python3-crypto [ more… ]