No Image

USN-5212-2: Apache HTTP Server vulnerabilities

2022-01-10 KENNETH 0

USN-5212-2: Apache HTTP Server vulnerabilities USN-5212-1 fixed several vulnerabilities in Apache. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Original advisory details: It was discovered that the Apache HTTP Server incorrectly handled certain forward proxy requests. A remote attacker could use this issue to cause the server to crash, resulting in a denial of service, or possibly perform a Server Side Request Forgery attack. (CVE-2021-44224) It was discovered that the Apache HTTP Server Lua module incorrectly handled memory in the multipart parser. A remote attacker could use this issue to cause the server to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-44790) Source: USN-5212-2: Apache HTTP Server vulnerabilities

No Image

USN-5213-1: WebKitGTK vulnerabilities

2022-01-06 KENNETH 0

USN-5213-1: WebKitGTK vulnerabilities A large number of security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Source: USN-5213-1: WebKitGTK vulnerabilities

No Image

USN-5212-1: Apache HTTP Server vulnerabilities

2022-01-06 KENNETH 0

USN-5212-1: Apache HTTP Server vulnerabilities It was discovered that the Apache HTTP Server incorrectly handled certain forward proxy requests. A remote attacker could use this issue to cause the server to crash, resulting in a denial of service, or possibly perform a Server Side Request Forgery attack. (CVE-2021-44224) It was discovered that the Apache HTTP Server Lua module incorrectly handled memory in the multipart parser. A remote attacker could use this issue to cause the server to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-44790) Source: USN-5212-1: Apache HTTP Server vulnerabilities

No Image

LSN-0083-1: Kernel Live Patch Security Notice

2022-01-06 KENNETH 0

LSN-0083-1: Kernel Live Patch Security Notice The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.(CVE-2018-25020) Maxim Levitsky discovered that the KVM hypervisor implementation for AMD processors in the Linux kernel did not properly prevent a guest VM from enabling AVIC in nested guest VMs. An attacker in a guest VM could use this to write to portions of the host’s physical memory.(CVE-2021-3653) Nadav Amit discovered that the hugetlb implementation in the Linux kernel did not perform TLB flushes under certain conditions. A local attacker could use this to leak or alter data from other processes that use huge pages.(CVE-2021-4002) Andy Nguyen discovered that the netfilter subsystem in the Linux kernel contained [ more… ]

No Image

USN-5211-1: Linux kernel vulnerability

2022-01-06 KENNETH 0

USN-5211-1: Linux kernel vulnerability Nadav Amit discovered that the hugetlb implementation in the Linux kernel did not perform TLB flushes under certain conditions. A local attacker could use this to leak or alter data from other processes that use huge pages. Source: USN-5211-1: Linux kernel vulnerability