No Image

USN-4316-2: GD Graphics Library vulnerabilities

2020-04-03 KENNETH 0

USN-4316-2: GD Graphics Library vulnerabilities libgd2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Summary Several security issues were fixed in GD Graphics Library. Software Description libgd2 – Open source code library for the dynamic creation of images Details USN-4316-1 fixed a vulnerability in GD Graphics Library. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: It was discovered that GD Graphics Library incorrectly handled cloning an image. An attacker could possibly use this issue to cause GD Graphics Library to crash, resulting in a denial of service. (CVE-2018-14553) It was discovered that GD Graphics Library incorrectly handled loading images from X bitmap format files. An attacker could possibly use this issue to cause GD Graphics Library to crash, resulting in a denial of service, or to disclose contents [ more… ]

No Image

USN-4316-1: GD Graphics Library vulnerabilities

2020-04-03 KENNETH 0

USN-4316-1: GD Graphics Library vulnerabilities libgd2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in GD Graphics Library. Software Description libgd2 – Open source code library for the dynamic creation of images Details It was discovered that GD Graphics Library incorrectly handled cloning an image. An attacker could possibly use this issue to cause GD Graphics Library to crash, resulting in a denial of service. (CVE-2018-14553) It was discovered that GD Graphics Library incorrectly handled loading images from X bitmap format files. An attacker could possibly use this issue to cause GD Graphics Library to crash, resulting in a denial of service, or to disclose contents of the stack that has been left there by previous code. This issue only affected Ubuntu [ more… ]

No Image

USN-4315-1: Apport vulnerabilities

2020-04-02 KENNETH 0

USN-4315-1: Apport vulnerabilities apport vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in Apport. Software Description apport – automatically generate crash reports for debugging Details Maximilien Bourgeteau discovered that the Apport lock file was created with insecure permissions. This could allow a local attacker to escalate their privileges via a symlink attack. (CVE-2020-8831) Maximilien Bourgeteau discovered a race condition in Apport when setting crash report permissions. This could allow a local attacker to read arbitrary files via a symlink attack. (CVE-2020-8833) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 apport – 2.20.11-0ubuntu8.8 python-apport – 2.20.11-0ubuntu8.8 python3-apport – 2.20.11-0ubuntu8.8 Ubuntu 18.04 LTS apport – 2.20.9-0ubuntu7.14 python-apport – 2.20.9-0ubuntu7.14 python3-apport – 2.20.9-0ubuntu7.14 Ubuntu 16.04 [ more… ]

No Image

USN-4314-1: pam-krb5 vulnerability

2020-03-31 KENNETH 0

USN-4314-1: pam-krb5 vulnerability libpam-krb5 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary pam-krb5 could be made to execute arbitrary code if it received a specially crafted response. Software Description libpam-krb5 – PAM module for MIT Kerberos Details Russ Allbery discovered that pam-krb5 incorrectly handled some responses. An attacker could possibly use this issue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 libpam-krb5 – 4.8-2ubuntu0.1 Ubuntu 18.04 LTS libpam-krb5 – 4.8-1ubuntu0.1 Ubuntu 16.04 LTS libpam-krb5 – 4.7-2ubuntu0.1 Ubuntu 14.04 ESM libpam-krb5 – 4.6-2ubuntu0.1~esm1 Ubuntu 12.04 ESM libpam-krb5 – 4.5-3ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the [ more… ]

No Image

USN-4313-1: Linux kernel vulnerability

2020-03-31 KENNETH 0

USN-4313-1: Linux kernel vulnerability linux, linux-aws, linux-azure, linux-azure-5.3, linux-gcp, linux-gcp-5.3, linux-gke-5.3, linux-hwe, linux-kvm, linux-oracle, linux-oracle-5.3, linux-raspi2, linux-raspi2-5.3 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Summary The system could be made to expose sensitive information or run programs as an administrator. Software Description linux – Linux kernel linux-aws – Linux kernel for Amazon Web Services (AWS) systems linux-azure – Linux kernel for Microsoft Azure Cloud systems linux-gcp – Linux kernel for Google Cloud Platform (GCP) systems linux-kvm – Linux kernel for cloud environments linux-oracle – Linux kernel for Oracle Cloud systems linux-raspi2 – Linux kernel for Raspberry Pi 2 linux-azure-5.3 – Linux kernel for Microsoft Azure Cloud systems linux-gcp-5.3 – Linux kernel for Google Cloud Platform (GCP) systems linux-gke-5.3 – Linux kernel for Google Container Engine (GKE) systems linux-hwe – Linux [ more… ]