No Image

USN-5786-1: GNOME Files vulnerability

2023-01-05 KENNETH 0

USN-5786-1: GNOME Files vulnerability It was discovered that GNOME Files incorrectly handled certain filenames. An attacker could possibly use this issue to cause GNOME Files to crash, leading to a denial of service. Source: USN-5786-1: GNOME Files vulnerability

No Image

USN-5785-1: FreeRADIUS vulnerabilities

2023-01-04 KENNETH 0

USN-5785-1: FreeRADIUS vulnerabilities It was discovered that FreeRADIUS incorrectly handled multiple EAP-pwd handshakes. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-17185) Shane Guan discovered that FreeRADIUS incorrectly handled memory when checking unknown SIM option sent by EAP-SIM supplicant. An attacker could possibly use this issue to cause a denial of service on the server. This issue only affected Ubuntu 16.04 ESM, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2022-41860) It was discovered that FreeRADIUS incorrectly handled memory when processing certain abinary attributes. An attacker could possibly use this issue to cause a denial of service on the server. (CVE-2022-41861) Source: USN-5785-1: FreeRADIUS vulnerabilities

No Image

USN-5784-1: usbredir vulnerability

2023-01-03 KENNETH 0

USN-5784-1: usbredir vulnerability It was discovered that usbredir incorrectly handled memory when serializing large amounts of data in the case of a slow or blocked destination. An attacker could possibly use this issue to cause applications using usbredir to crash, resulting in a denial of service, or possibly execute arbitrary code. Source: USN-5784-1: usbredir vulnerability

No Image

USN-5783-1: Linux kernel (OEM) vulnerability

2022-12-17 KENNETH 0

USN-5783-1: Linux kernel (OEM) vulnerability Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation in the Linux kernel contained multiple use-after-free vulnerabilities. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. Source: USN-5783-1: Linux kernel (OEM) vulnerability

No Image

USN-5782-1: Firefox vulnerabilities

2022-12-15 KENNETH 0

USN-5782-1: Firefox vulnerabilities It was discovered that Firefox was using an out-of-date libusrsctp library. An attacker could possibly use this library to perform a reentrancy issue on Firefox. (CVE-2022-46871) Nika Layzell discovered that Firefox was not performing a check on paste received from cross-processes. An attacker could potentially exploit this to obtain sensitive information. (CVE-2022-46872) Pete Freitag discovered that Firefox did not implement the unsafe-hashes CSP directive. An attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject an executable script. (CVE-2022-46873) Matthias Zoellner discovered that Firefox was not keeping the filename ending intact when using the drag-and-drop event. An attacker could possibly use this issue to add a file with a malicious extension, leading to execute arbitrary code. (CVE-2022-46874) Hafiizh discovered that Firefox was not handling [ more… ]