No Image

USN-3403-1: Ghostscript vulnerabilities

2017-08-29 KENNETH 0

USN-3403-1: Ghostscript vulnerabilities Ubuntu Security Notice USN-3403-1 28th August, 2017 ghostscript vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Ghostscript. Software description ghostscript – PostScript and PDF interpreter Details Kamil Frankowicz discovered that Ghostscript mishandles references.A remote attacker could use this to cause a denial of service.(CVE-2017-11714) Kim Gwan Yeong discovered that Ghostscript could allow a heap-based bufferover-read and application crash. A remote attacker could use a crafteddocument to cause a denial of service. (CVE-2017-9611, CVE-2017-9726,CVE-2017-9727, CVE-2017-9739) Kim Gwan Yeong discovered an use-after-free vulnerability in Ghostscript.A remote attacker could use a crafted file to cause a denial of service.(CVE-2017-9612) Kim Gwan Yeong discovered a lack of integer overflow check in Ghostscript.A remote attacker could use crafted PostScript document to cause a [ more… ]

No Image

USN-3199-3: Python Crypto vulnerability

2017-08-29 KENNETH 0

USN-3199-3: Python Crypto vulnerability Ubuntu Security Notice USN-3199-3 28th August, 2017 python-crypto vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Programs using the Python Cryptography Toolkit could be made to crash or run programs if they receive specially crafted network traffic or other input. Software description python-crypto – cryptographic algorithms and protocols for Python Details USN-3199-1 fixed a vulnerability in Python Crypto. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that the ALGnew function in block_templace.c in the Python Cryptography Toolkit contained a heap-based buffer overflow vulnerability. A remote attacker could use this flaw to execute arbitrary code by using a crafted initialization vector parameter. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: python3-crypto [ more… ]

No Image

USN-3401-1: TeX Live vulnerability

2017-08-26 KENNETH 0

USN-3401-1: TeX Live vulnerability Ubuntu Security Notice USN-3401-1 22nd August, 2017 texlive-base vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary TeX Live could be made to run programs as your login if it opened a specially crafted file. Software description texlive-base – TeX Live: Essential programs and files Details It was discovered that TeX Live incorrectly handled certainsystem commands. If a user were tricked into processing aspecially crafted TeX file, a remote attacker could executearbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: texlive-base 2015.20160320-1ubuntu0.1 texlive-latex-base 2015.20160320-1ubuntu0.1 Ubuntu 14.04 LTS: texlive-base 2013.20140215-1ubuntu0.1 texlive-latex-base 2013.20140215-1ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2016-10243 [ more… ]

No Image

USN-3402-1: PySAML2 vulnerability

2017-08-26 KENNETH 0

USN-3402-1: PySAML2 vulnerability Ubuntu Security Notice USN-3402-1 24th August, 2017 python-pysaml2 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.04 LTS Summary The system could be made to expose sensitive information. Software description python-pysaml2 – Pure python implementation of SAML2 Details It was discovered that PySAML2 incorrectly handled certainSAML XML requests and responses. A remote attacker could usethis issue to read arbitrary files. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.04: python-pysaml2 3.0.0-3ubuntu1.17.04.1 python3-pysaml2 3.0.0-3ubuntu1.17.04.1 Ubuntu 16.04 LTS: python-pysaml2 3.0.0-3ubuntu1.16.04.1 python3-pysaml2 3.0.0-3ubuntu1.16.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2016-10149 Source: USN-3402-1: PySAML2 vulnerability

No Image

USN-3400-1: Augeas vulnerability

2017-08-22 KENNETH 0

USN-3400-1: Augeas vulnerability Ubuntu Security Notice USN-3400-1 21st August, 2017 augeas vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Augeas could be made to crash if it received specially crafted input. Software description augeas – Configuration editing tool Details It was discovered that Augeas incorrectly handled certain strings.An attacker could use this issue to cause Augeas to crash, leadingto a denial of service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.04: augeas-tools 1.6.0-0ubuntu3.1 libaugeas0 1.6.0-0ubuntu3.1 Ubuntu 16.04 LTS: augeas-tools 1.4.0-0ubuntu1.1 libaugeas0 1.4.0-0ubuntu1.1 Ubuntu 14.04 LTS: augeas-tools 1.2.0-0ubuntu1.3 libaugeas0 1.2.0-0ubuntu1.3 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2017-7555 [ more… ]