No Image

USN-5651-1: strongSwan vulnerability

2022-10-04 KENNETH 0

USN-5651-1: strongSwan vulnerability Lahav Schlesinger discovered that strongSwan incorrectly handled certain OCSP URIs and and CRL distribution points (CDP) in certificates. A remote attacker could possibly use this issue to initiate IKE_SAs and send crafted certificates that contain URIs pointing to servers under their control, which can lead to a denial-of-service attack. Source: USN-5651-1: strongSwan vulnerability

No Image

USN-5614-2: Wayland vulnerability

2022-10-04 KENNETH 0

USN-5614-2: Wayland vulnerability USN-5614-1 fixed a vulnerability in Wayland. This update provides the corresponding update for Ubuntu 16.04 ESM. Original advisory details: It was discovered that Wayland incorrectly handled reference counting certain objects. An attacker could use this issue to cause Wayland to crash, resulting in a denial of service, or possibly execute arbitrary code. Source: USN-5614-2: Wayland vulnerability

No Image

USN-5652-1: Linux kernel (Azure) vulnerabilities

2022-10-04 KENNETH 0

USN-5652-1: Linux kernel (Azure) vulnerabilities It was discovered that the framebuffer driver on the Linux kernel did not verify size limits when changing font or screen size, leading to an out-of- bounds write. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-33655) Domingo Dirutigliano and Nicola Guerrera discovered that the netfilter subsystem in the Linux kernel did not properly handle rules that truncated packets below the packet header size. When such rules are in place, a remote attacker could possibly use this to cause a denial of service (system crash). (CVE-2022-36946) Source: USN-5652-1: Linux kernel (Azure) vulnerabilities

No Image

USN-5649-1: Firefox vulnerabilities

2022-10-01 KENNETH 0

USN-5649-1: Firefox vulnerabilities Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, bypass Content Security Policy (CSP) or other security restrictions, conduct session fixation attacks, or execute arbitrary code. Source: USN-5649-1: Firefox vulnerabilities

No Image

USN-5650-1: Linux kernel vulnerabilities

2022-10-01 KENNETH 0

USN-5650-1: Linux kernel vulnerabilities It was discovered that the framebuffer driver on the Linux kernel did not verify size limits when changing font or screen size, leading to an out-of- bounds write. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-33655) It was discovered that the virtual terminal driver in the Linux kernel did not properly handle VGA console font changes, leading to an out-of-bounds write. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-33656) Christian Brauner discovered that the XFS file system implementation in the Linux kernel did not properly handle setgid file creation. A local attacker could use this to gain elevated privileges. (CVE-2021-4037) It was discovered that the ext4 file system implementation in the Linux [ more… ]