No Image

USN-3996-1: GNU Screen vulnerability

2019-05-29 KENNETH 0

USN-3996-1: GNU Screen vulnerability GNU Screen vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary GNU Screen could be made to crash or run programs as your login if it opened a specially crafted file or received specially crafted input. Software Description screen – terminal multiplexer with VT100/ANSI terminal emulation Details Kuang-che Wu discovered that GNU Screen improperly handled certain input. An attacker could use this issue to cause GNU Screen to crash, resulting in a denial of service or the execution of arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM screen – 4.1.0~20120320gitdb59704-9ubuntu0.1~esm1 Ubuntu 12.04 ESM screen – 4.0.3-14ubuntu8.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make [ more… ]

No Image

USN-3997-1: Thunderbird vulnerabilities

2019-05-29 KENNETH 0

USN-3997-1: Thunderbird vulnerabilities thunderbird vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in Thunderbird. Software Description thunderbird – Mozilla Open Source mail and newsgroup client Details Multiple security issues were discovered in Thunderbird. If a user were tricked in to opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, bypass same-origin protections, or execute arbitrary code. (CVE-2019-18511, CVE-2019-11691, CVE-2019-11692, CVE-2019-11693, CVE-2019-9797, CVE-2019-9800, CVE-2019-9817, CVE-2019-9819, CVE-2019-9820) Multiple security issues were discovered in Thunderbird. If a user were tricked in to opening a specially crafted message, an attacker could potentially exploit these to cause a denial of service, or execute arbitrary code. (CVE-2019-5798, CVE-2019-7317) A type confusion bug was discovered [ more… ]

No Image

USN-3995-2: Keepalived vulnerability

2019-05-29 KENNETH 0

USN-3995-2: Keepalived vulnerability keepalived vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary Keepalived could be made to crash or run programs if it received specially crafted network traffic. Software Description keepalived – Failover and monitoring daemon for LVS clusters Details USN-3995-1 fixed a vulnerability in keepalived. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It was discovered that Keepalived incorrectly handled certain HTTP status response codes. A remote attacker could use this issue to cause Keepalived to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM keepalived – 1:1.2.7-1ubuntu1+esm1 Ubuntu 12.04 ESM keepalived – 1:1.2.2-3ubuntu1.2 To update your [ more… ]

No Image

USN-3845-2: FreeRDP vulnerabilities

2019-05-29 KENNETH 0

USN-3845-2: FreeRDP vulnerabilities freerdp vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 18.04 LTS Summary Several security issues were fixed in FreeRDP. Software Description freerdp – RDP client for Windows Terminal Services Details USN-3845-1 fixed several vulnerabilities in FreeRDP. This update provides the corresponding update for Ubuntu 18.04 LTS and Ubuntu 18.10. Original advisory details: Eyal Itkin discovered FreeRDP incorrectly handled certain stream encodings. A malicious server could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only applies to Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-8784, CVE-2018-8785) Eyal Itkin discovered FreeRDP incorrectly handled bitmaps. A malicious server could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2018-8786, CVE-2018-8787) Eyal [ more… ]

No Image

USN-3995-1: Keepalived vulnerability

2019-05-28 KENNETH 0

USN-3995-1: Keepalived vulnerability keepalived vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Keepalived could be made to crash or run programs if it received specially crafted network traffic. Software Description keepalived – Failover and monitoring daemon for LVS clusters Details It was discovered that Keepalived incorrectly handled certain HTTP status response codes. A remote attacker could use this issue to cause Keepalived to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10 keepalived – 1:1.3.9-1ubuntu1.1 Ubuntu 18.04 LTS keepalived – 1:1.3.9-1ubuntu0.18.04.2 Ubuntu 16.04 LTS keepalived – 1:1.2.24-1ubuntu0.16.04.2 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the [ more… ]