No Image

USN-4507-1: ncmpc vulnerability

2020-09-17 KENNETH 0

USN-4507-1: ncmpc vulnerability It was discovered that ncmpc incorrectly handled long chat messages. A remote attacker could possibly exploit this with a crafted chat message, causing ncmpc to crash, resulting in a denial of service. (CVE-2018-9240) Source: USN-4507-1: ncmpc vulnerability

No Image

USN-4506-1: MCabber vulnerability

2020-09-17 KENNETH 0

USN-4506-1: MCabber vulnerability It was discovered that MCabber does not properly manage roster pushes. An attacker could possibly use this issue to remotely perform man-in-the-middle attacks. (CVE-2016-9928). Source: USN-4506-1: MCabber vulnerability

No Image

USN-4505-1: PHPMailer vulnerability

2020-09-17 KENNETH 0

USN-4505-1: PHPMailer vulnerability Elar Lang discovered that PHPMailer did not properly escape double quote characters in filenames. A remote attacker could possibly exploit this with a crafted filename to bypass attachment filters that are based on matching filename extensions. (CVE-2020-13625) Source: USN-4505-1: PHPMailer vulnerability

No Image

USN-4504-1: OpenSSL vulnerabilities

2020-09-16 KENNETH 0

USN-4504-1: OpenSSL vulnerabilities Robert Merget, Marcus Brinkmann, Nimrod Aviram, and Juraj Somorovsky discovered that certain Diffie-Hellman ciphersuites in the TLS specification and implemented by OpenSSL contained a flaw. A remote attacker could possibly use this issue to eavesdrop on encrypted communications. This was fixed in this update by removing the insecure ciphersuites from OpenSSL. (CVE-2020-1968) Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin, Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL incorrectly handled ECDSA signatures. An attacker could possibly use this issue to perform a timing side-channel attack and recover private ECDSA keys. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-1547) Guido Vranken discovered that OpenSSL incorrectly performed the x86_64 Montgomery squaring procedure. While unlikely, a remote attacker could possibly use this issue to recover private keys. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-1551) Bernd Edlinger [ more… ]

No Image

USN-4502-1: websocket-extensions vulnerability

2020-09-16 KENNETH 0

USN-4502-1: websocket-extensions vulnerability It was discovered that websocket-extensions does not properly parse special headers. A remote attacker could use this issue to cause regex backtracking, resulting in a denial of service. (CVE-2020-7663) Source: USN-4502-1: websocket-extensions vulnerability