No Image

USN-5763-1: NumPy vulnerabilities

2022-12-07 KENNETH 0

USN-5763-1: NumPy vulnerabilities It was discovered that NumPy did not properly manage memory when specifying arrays of large dimensions. If a user were tricked into running malicious Python file, an attacker could cause a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-33430) It was discovered that NumPy did not properly perform string comparison operations under certain circumstances. An attacker could possibly use this issue to cause NumPy to crash, resulting in a denial of service. (CVE-2021-34141) It was discovered that NumPy did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause NumPy to crash, resulting in a denial of service. (CVE-2021-41495, CVE-2021-41496) Source: USN-5763-1: NumPy vulnerabilities

No Image

USN-5761-2: ca-certificates update

2022-12-06 KENNETH 0

USN-5761-2: ca-certificates update USN-5761-1 updated ca-certificates. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Original advisory details: Due to security concerns, the TrustCor certificate authority has been marked as distrusted in Mozilla’s root store. This update removes the TrustCor CA certificates from the ca-certificates package. Source: USN-5761-2: ca-certificates update

No Image

USN-5764-1: U-Boot vulnerabilities

2022-12-06 KENNETH 0

USN-5764-1: U-Boot vulnerabilities It was discovered that U-Boot incorrectly handled certain USB DFU download setup packets. A local attacker could use this issue to cause U-Boot to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2022-2347) Nicolas Bidron and Nicolas Guigo discovered that U-Boot incorrectly handled certain fragmented IP packets. A local attacker could use this issue to cause U-Boot to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-30552, CVE-2022-30790) It was discovered that U-Boot incorrectly handled certain NFS lookup replies. A remote attacker could use this issue to cause U-Boot to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 [ more… ]

No Image

USN-5762-1: GNU binutils vulnerability

2022-12-06 KENNETH 0

USN-5762-1: GNU binutils vulnerability It was discovered that GNU binutils incorrectly handled certain COFF files. An attacker could possibly use this issue to cause a crash or execute arbitrary code. Source: USN-5762-1: GNU binutils vulnerability

No Image

USN-5761-1: ca-certificates update

2022-12-06 KENNETH 0

USN-5761-1: ca-certificates update Due to security concerns, the TrustCor certificate authority has been marked as distrusted in Mozilla’s root store. This update removes the TrustCor CA certificates from the ca-certificates package. Source: USN-5761-1: ca-certificates update