No Image

USN-5661-1: LibreOffice vulnerabilities

2022-10-06 KENNETH 0

USN-5661-1: LibreOffice vulnerabilities It was discovered that LibreOffice incorrectly validated macro signatures. If a user were tricked into opening a specially crafted document, a remote attacker could possibly use this issue to execute arbitrary macros. (CVE-2022-26305) It was discovered that Libreoffice incorrectly handled encrypting the master key provided by the user for storing passwords for web connections. A local attacker could possibly use this issue to obtain access to passwords stored in the user’s configuration data. (CVE-2022-26306, CVE-2022-26307) Source: USN-5661-1: LibreOffice vulnerabilities

No Image

USN-5660-1: Linux kernel (GCP) vulnerabilities

2022-10-06 KENNETH 0

USN-5660-1: Linux kernel (GCP) vulnerabilities It was discovered that the framebuffer driver on the Linux kernel did not verify size limits when changing font or screen size, leading to an out-of- bounds write. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-33655) Moshe Kol, Amit Klein and Yossi Gilad discovered that the IP implementation in the Linux kernel did not provide sufficient randomization when calculating port offsets. An attacker could possibly use this to expose sensitive information. (CVE-2022-1012, CVE-2022-32296) Norbert Slusarek discovered that a race condition existed in the perf subsystem in the Linux kernel, resulting in a use-after-free vulnerability. A privileged local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1729) It was discovered that the device-mapper verity (dm-verity) [ more… ]

No Image

USN-5659-1: kitty vulnerabilities

2022-10-06 KENNETH 0

USN-5659-1: kitty vulnerabilities Stephane Chauveau discovered that kitty incorrectly handled image filenames with special characters in error messages. A remote attacker could possibly use this to execute arbitrary commands. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-35605) Carter Sande discovered that kitty incorrectly handled escape sequences in desktop notifications. A remote attacker could possibly use this to execute arbitrary commands. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-41322) Source: USN-5659-1: kitty vulnerabilities

No Image

USN-5657-1: Graphite2 vulnerability

2022-10-06 KENNETH 0

USN-5657-1: Graphite2 vulnerability It was discovered that Graphite2 mishandled specially crafted files. An attacker could possibly use this issue to cause a denial of service or other unspecified impact. Source: USN-5657-1: Graphite2 vulnerability

No Image

USN-5658-1: DHCP vulnerabilities

2022-10-06 KENNETH 0

USN-5658-1: DHCP vulnerabilities It was discovered that DHCP incorrectly handled option reference counting. A remote attacker could possibly use this issue to cause DHCP servers to crash, resulting in a denial of service. (CVE-2022-2928) It was discovered that DHCP incorrectly handled certain memory operations. A remote attacker could possibly use this issue to cause DHCP clients and servers to consume resources, leading to a denial of service. (CVE-2022-2929) Source: USN-5658-1: DHCP vulnerabilities