No Image

USN-6272-1: OpenJDK 20 vulnerabilities

2023-08-03 KENNETH 0

USN-6272-1: OpenJDK 20 vulnerabilities Motoyasu Saburi discovered that OpenJDK 20 incorrectly handled special characters in file name parameters. An attacker could possibly use this issue to insert, edit or obtain sensitive information. (CVE-2023-22006) Eirik Bjørsnøs discovered that OpenJDK 20 incorrectly handled certain ZIP archives. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-22036) David Stancu discovered that OpenJDK 20 had a flaw in the AES cipher implementation. An attacker could possibly use this issue to obtain sensitive information. (CVE-2023-22041) Zhiqiang Zang discovered that OpenJDK 20 incorrectly handled array accesses when using the binary ‘%’ operator. An attacker could possibly use this issue to obtain sensitive information. (CVE-2023-22044) Zhiqiang Zang discovered that OpenJDK 20 incorrectly handled array accesses. An attacker could possibly use this issue to obtain sensitive information. (CVE-2023-22045) It was discovered that OpenJDK 20 [ more… ]

No Image

USN-6271-1: MaraDNS vulnerabilities

2023-08-03 KENNETH 0

USN-6271-1: MaraDNS vulnerabilities Xiang Li discovered that MaraDNS incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to obtain sensitive information. (CVE-2022-30256) Huascar Tejeda discovered that MaraDNS incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2023-31137) Source: USN-6271-1: MaraDNS vulnerabilities

No Image

USN-6270-1: Vim vulnerabilities

2023-08-03 KENNETH 0

USN-6270-1: Vim vulnerabilities It was discovered that Vim incorrectly handled memory when opening certain files. If an attacker could trick a user into opening a specially crafted file, it could cause Vim to crash, or possibly execute arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-2182) It was discovered that Vim incorrectly handled memory when deleting buffers in diff mode. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-2208) It was discovered that Vim incorrectly handled memory access. An attacker could possibly use this issue to cause the corruption of sensitive information, a crash, or arbitrary code execution. This issue only affected Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-2210) It was discovered that Vim incorrectly handled [ more… ]

No Image

USN-6269-1: GStreamer Good Plugins vulnerability

2023-08-03 KENNETH 0

USN-6269-1: GStreamer Good Plugins vulnerability It was discovered that GStreamer Good Plugins incorrectly handled certain FLAC image tags. A remote attacker could use this issue to cause GStreamer Good Plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-37327) Source: USN-6269-1: GStreamer Good Plugins vulnerability

No Image

USN-6268-1: GStreamer Base Plugins vulnerabilities

2023-08-03 KENNETH 0

USN-6268-1: GStreamer Base Plugins vulnerabilities It was discovered that GStreamer Base Plugins incorrectly handled certain FLAC image tags. A remote attacker could use this issue to cause GStreamer Base Plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-37327) It was discovered that GStreamer Base Plugins incorrectly handled certain subtitles. A remote attacker could use this issue to cause GStreamer Base Plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-37328) Source: USN-6268-1: GStreamer Base Plugins vulnerabilities