No Image

USN-4927-1: File Roller vulnerability

2021-04-26 KENNETH 0

USN-4927-1: File Roller vulnerability It was discovered that File Roller incorrectly handled symlinks. An attacker could possibly use this issue to expose sensitive information. Source: USN-4927-1: File Roller vulnerability

No Image

USN-4926-1: Firefox vulnerabilities

2021-04-26 KENNETH 0

USN-4926-1: Firefox vulnerabilities Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, spoof the browser UI, bypass security restrictions, trick the user into disclosing confidential information, or execute arbitrary code. (CVE-2021-23994, CVE-2021-23996, CVE-2021-23997, CVE-2021-23998, CVE-2021-23999, CVE-2021-24000, CVE-2021-24001, CVE-2021-29945, CVE-2021-29946, CVE-2021-29947) A use-after-free was discovered when Responsive Design Mode was enabled. If a user were tricked into opening a specially crafted website with Responsive Design Mode enabled, an attacker could potentially exploit this to cause a denial of service, or execute arbitrary code. (CVE-2021-23995) It was discovered that Firefox mishandled ftp URLs with encoded newline characters. If a user were tricked into clicking on a specially crafted link, an attacker could potentially exploit this to send arbitrary FTP commands. (CVE-2021-24002) [ more… ]

No Image

USN-4925-1: Shibboleth vulnerability

2021-04-23 KENNETH 0

USN-4925-1: Shibboleth vulnerability Toni Huttunen and Fraktal Oy discovered that the Shibboleth Service provider allowed content injection due to allowing attacker-controlled parameters in error or other status pages. An attacker could use this to inject malicious content. Source: USN-4925-1: Shibboleth vulnerability

No Image

USN-4924-1: Dnsmasq vulnerabilities

2021-04-23 KENNETH 0

USN-4924-1: Dnsmasq vulnerabilities It was discovered that Dnsmasq incorrectly handled certain wildcard synthesized NSEC records. A remote attacker could possibly use this issue to prove the non-existence of hostnames that actually exist. (CVE-2017-15107) It was discovered that Dnsmasq incorrectly handled certain large DNS packets. A remote attacker could possibly use this issue to cause Dnsmasq to crash, resulting in a denial of service. (CVE-2019-14513) Source: USN-4924-1: Dnsmasq vulnerabilities

No Image

USN-4916-2: Linux kernel regression

2021-04-22 KENNETH 0

USN-4916-2: Linux kernel regression USN-4916-1 fixed vulnerabilities in the Linux kernel. Unfortunately, the fix for CVE-2021-3493 introduced a memory leak in some situations. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that the overlayfs implementation in the Linux kernel did not properly validate the application of file system capabilities with respect to user namespaces. A local attacker could use this to gain elevated privileges. (CVE-2021-3493) Piotr Krysiuk discovered that the BPF JIT compiler for x86 in the Linux kernel did not properly validate computation of branch displacements in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-29154) Source: USN-4916-2: Linux kernel regression