No Image

USN-4036-1: OpenStack Neutron vulnerability

2019-06-25 KENNETH 0

USN-4036-1: OpenStack Neutron vulnerability neutron vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 16.04 LTS Summary A system hardening measure could be bypassed. Software Description neutron – OpenStack Virtual Network Service Details Erik Olof Gunnar Andersson discovered that OpenStack Neutron incorrectly handled certain security group rules in the iptables firewall module. An authenticated attacker could possibly use this issue to block further application of security group rules for other instances. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10 python-neutron – 2:13.0.2-0ubuntu3.4 python3-neutron – 2:13.0.2-0ubuntu3.4 Ubuntu 16.04 LTS python-neutron – 2:8.4.0-0ubuntu7.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-9735 Source: USN-4036-1: OpenStack Neutron vulnerability

No Image

USN-4035-1: Ceph vulnerabilities

2019-06-25 KENNETH 0

USN-4035-1: Ceph vulnerabilities ceph vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 16.04 LTS Summary Several security issues were fixed in Ceph. Software Description ceph – distributed storage and file system Details It was discovered that Ceph incorrectly handled read only permissions. An authenticated attacker could use this issue to obtain dm-crypt encryption keys. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-14662) It was discovered that Ceph incorrectly handled certain OMAPs holding bucket indices. An authenticated attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-16846) It was discovered that Ceph incorrectly sanitized certain debug logs. A local attacker could possibly use this issue to obtain encryption key information. This issue was only addressed in Ubuntu 18.10 and Ubuntu 19.04. (CVE-2018-16889) [ more… ]

No Image

USN-4034-1: ImageMagick vulnerabilities

2019-06-25 KENNETH 0

USN-4034-1: ImageMagick vulnerabilities imagemagick vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in ImageMagick. Software Description imagemagick – Image manipulation programs and library Details It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program. Due to a large number of issues discovered in GhostScript that prevent it from being used by ImageMagick safely, the update for Ubuntu 18.10 and Ubuntu 19.04 includes a default policy change that disables support for the Postscript and PDF formats in ImageMagick. This policy [ more… ]

No Image

USN-4033-1: libmysofa vulnerability

2019-06-25 KENNETH 0

USN-4033-1: libmysofa vulnerability libmysofa vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Summary libmysofa could be made to crash if it received specially crafted input. Software Description libmysofa – library to read HRTFs stored in the AES69-2015 SOFA format Details It was discovered that a libmysofa component does not properly validate multiplications and additions, and may crash with some specific input. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 libmysofa0 – 0.6~dfsg0-2ubuntu0.19.04.1 Ubuntu 18.10 libmysofa0 – 0.6~dfsg0-2ubuntu0.18.10.1 Ubuntu 18.04 LTS libmysofa0 – 0.6~dfsg0-2ubuntu0.18.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-10672 Source: USN-4033-1: libmysofa vulnerability

No Image

USN-4032-1: Firefox vulnerability

2019-06-25 KENNETH 0

USN-4032-1: Firefox vulnerability firefox vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary A sandbox escape was discovered in Firefox. Software Description firefox – Mozilla Open Source web browser Details It was discovered that a sandboxed child process could open arbitrary web content in the parent process via the Prompt:Open IPC message. When combined with another vulnerability, an attacker could potentially exploit this to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 firefox – 67.0.4+build1-0ubuntu0.19.04.1 Ubuntu 18.10 firefox – 67.0.4+build1-0ubuntu0.18.10.1 Ubuntu 18.04 LTS firefox – 67.0.4+build1-0ubuntu0.18.04.1 Ubuntu 16.04 LTS firefox – 67.0.4+build1-0ubuntu0.16.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to restart Firefox to make [ more… ]