No Image

USN-4090-1: PostgreSQL vulnerabilities

2019-08-09 KENNETH 0

USN-4090-1: PostgreSQL vulnerabilities postgresql-10, postgresql-11, postgresql-9.5 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in PostgreSQL. Software Description postgresql-11 – Object-relational SQL database postgresql-10 – Object-relational SQL database postgresql-9.5 – Object-relational SQL database Details Tom Lane discovered that PostgreSQL did not properly restrict functions declared as "SECURITY DEFINER". An attacker could use this to execute arbitrary SQL with the permissions of the function owner. (CVE-2019-10208) Andreas Seltenreich discovered that PostgreSQL did not properly handle user-defined hash equality operators. An attacker could use this to expose sensitive information (arbitrary PostgreSQL server memory). This issue only affected Ubuntu 19.04. (CVE-2019-10209) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 postgresql-11 – 11.5-0ubuntu0.19.04.1 Ubuntu 18.04 LTS [ more… ]

No Image

USN-4089-1: Rack vulnerability

2019-08-08 KENNETH 0

USN-4089-1: Rack vulnerability ruby-rack vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Rack could allow cross-site scripting (XSS) attacks. Software Description ruby-rack – modular Ruby webserver interface Details It was discovered that Rack incorrectly handled carefully crafted requests. A remote attacker could use this issue to execute a cross-site scripting (XSS) attack. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS ruby-rack – 1.6.4-4ubuntu0.1 Ubuntu 16.04 LTS ruby-rack – 1.6.4-3ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2018-16471 Source: USN-4089-1: Rack vulnerability

No Image

USN-4088-1: PHP vulnerability

2019-08-07 KENNETH 0

USN-4088-1: PHP vulnerability php5 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary PHP could be made to denial of service, expose sensitive information or execute arbitrary code if it received a specially crafted regular expression. Software Description php5 – HTML-embedded scripting language interpreter Details It was discovered that PHP incorrectly handled certain regular expressions. An attacker could possibly use this issue to expose sensitive information, cause a denial of service or execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM libapache2-mod-php5 – 5.5.9+dfsg-1ubuntu4.29+esm4 php5-cgi – 5.5.9+dfsg-1ubuntu4.29+esm4 php5-cli – 5.5.9+dfsg-1ubuntu4.29+esm4 php5-fpm – 5.5.9+dfsg-1ubuntu4.29+esm4 php5-xmlrpc – 5.5.9+dfsg-1ubuntu4.29+esm4 Ubuntu 12.04 ESM libapache2-mod-php5 – 5.3.10-1ubuntu3.38 php5-cgi – 5.3.10-1ubuntu3.38 php5-cli – 5.3.10-1ubuntu3.38 php5-fpm – 5.3.10-1ubuntu3.38 php5-xmlrpc – 5.3.10-1ubuntu3.38 To update your [ more… ]

No Image

USN-4087-1: BWA vulnerability

2019-08-07 KENNETH 0

USN-4087-1: BWA vulnerability BWA vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Summary BWA could be made to crash or run programs as your login if it opened a specially crafted file. Software Description bwa – Software package for mapping DNA sequences against a large reference genome Details It was discovered that Burrows-Wheeler Aligner (BWA) mishandled certain crafted .alt files. An attacker could use this vulnerability to cause a denial of service (crash) or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 bwa – 0.7.17-3~ubuntu0.19.04.1 Ubuntu 18.04 LTS bwa – 0.7.17-1ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-10269 Source: USN-4087-1: BWA [ more… ]

No Image

USN-4086-1: Mercurial vulnerability

2019-08-07 KENNETH 0

USN-4086-1: Mercurial vulnerability Mercurial vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Summary Mercurial could be made to overwrite files. Software Description mercurial – easy-to-use, scalable distributed version control system Details It was discovered that Mercurial mishandled symlinks in subrepositories. An attacker could use this vulnerability to write arbitrary files to the target’s filesystem. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 mercurial – 4.8.2-1ubuntu3.19.04.1 mercurial-common – 4.8.2-1ubuntu3.19.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-3902 Source: USN-4086-1: Mercurial vulnerability