No Image

USN-3359-1: Linux kernel vulnerabilities

2017-07-21 KENNETH 0

USN-3359-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3359-1 20th July, 2017 linux, linux-raspi2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Summary Several security issues were fixed in the Linux kernel. Software description linux – Linux kernel linux-raspi2 – Linux kernel for Raspberry Pi 2 Details It was discovered that the Linux kernel did not properly initialize a Wake-on-Lan data structure. A local attacker could use this to expose sensitiveinformation (kernel memory). (CVE-2014-9900) Dmitry Vyukov, Andrey Konovalov, Florian Westphal, and Eric Dumazetdiscovered that the netfiler subsystem in the Linux kernel mishandled IPv6packet reassembly. A local user could use this to cause a denial of service(system crash) or possibly execute arbitrary code. (CVE-2016-9755) Alexander Potapenko discovered a race condition in the Advanced Linux SoundArchitecture (ALSA) subsystem in the Linux kernel. A local attacker coulduse this [ more… ]

No Image

USN-3358-1: Linux kernel vulnerabilities

2017-07-21 KENNETH 0

USN-3358-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3358-1 20th July, 2017 linux, linux-raspi2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Summary Several security issues were fixed in the Linux kernel. Software description linux – Linux kernel linux-raspi2 – Linux kernel for Raspberry Pi 2 Details It was discovered that the Linux kernel did not properly initialize a Wake-on-Lan data structure. A local attacker could use this to expose sensitiveinformation (kernel memory). (CVE-2014-9900) Alexander Potapenko discovered a race condition in the Advanced Linux SoundArchitecture (ALSA) subsystem in the Linux kernel. A local attacker coulduse this to expose sensitive information (kernel memory).(CVE-2017-1000380) Li Qiang discovered that the DRM driver for VMware Virtual GPUs in theLinux kernel did not properly validate some ioctl arguments. A localattacker could use this to cause a denial of service (system [ more… ]

No Image

RHSA-2017:1793-1: Important: graphite2 security update

2017-07-21 KENNETH 0

RHSA-2017:1793-1: Important: graphite2 security update Red Hat Enterprise Linux: An update for graphite2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2017-7771, CVE-2017-7772, CVE-2017-7773, CVE-2017-7774, CVE-2017-7775, CVE-2017-7776, CVE-2017-7777, CVE-2017-7778 Source: RHSA-2017:1793-1: Important: graphite2 security update

No Image

USN-3357-1: MySQL vulnerabilities

2017-07-21 KENNETH 0

USN-3357-1: MySQL vulnerabilities Ubuntu Security Notice USN-3357-1 20th July, 2017 mysql-5.5, mysql-5.7 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in MySQL. Software description mysql-5.5 – MySQL database mysql-5.7 – MySQL database Details Multiple security issues were discovered in MySQL and this update includesnew upstream MySQL versions to fix these issues. MySQL has been updated to 5.5.57 in Ubuntu 14.04 LTS. Ubuntu 16.04 LTSand Ubuntu 17.04 have been updated to MySQL 5.7.19. In addition to security fixes, the updated packages contain bug fixes,new features, and possibly incompatible changes. Please see the following for more information:http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-56.htmlhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-57.htmlhttp://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-19.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.04: mysql-server-5.7 5.7.19-0ubuntu0.17.04.1 Ubuntu 16.04 LTS: mysql-server-5.7 5.7.19-0ubuntu0.16.04.1 Ubuntu 14.04 [ more… ]

No Image

RHSA-2017:1791-1: Critical: java-1.7.0-oracle security update

2017-07-21 KENNETH 0

RHSA-2017:1791-1: Critical: java-1.7.0-oracle security update Red Hat Enterprise Linux: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2017-10053, CVE-2017-10067, CVE-2017-10074, CVE-2017-10081, CVE-2017-10086, CVE-2017-10087, CVE-2017-10089, CVE-2017-10090, CVE-2017-10096, CVE-2017-10101, CVE-2017-10102, CVE-2017-10105, CVE-2017-10107, CVE-2017-10108, CVE-2017-10109, CVE-2017-10110, CVE-2017-10114, CVE-2017-10115, CVE-2017-10116, CVE-2017-10118, CVE-2017-10135, CVE-2017-10176, CVE-2017-10193, CVE-2017-10198, CVE-2017-10243 Source: RHSA-2017:1791-1: Critical: java-1.7.0-oracle security update