No Image

USN-3029-1: NSS vulnerability

2016-07-12 KENNETH 0

USN-3029-1: NSS vulnerability Ubuntu Security Notice USN-3029-1 11th July, 2016 nss vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary NSS could be made to crash or run programs if it processed specially crafted network traffic. Software description nss – Network Security Service library Details Tyson Smith and Jed Davis discovered that NSS incorrectly handled memory. Aremote attacker could use this issue to cause NSS to crash, resulting in adenial of service, or possibly execute arbitrary code. This update refreshes the NSS package to version 3.23 which includesthe latest CA certificate bundle. As a security improvement, this updatealso modifies NSS behaviour to reject DH key sizes below 1024 bits,preventing a possible downgrade attack. Update instructions The problem can be corrected by updating your system to [ more… ]

No Image

USN-3028-1: NSPR vulnerability

2016-07-12 KENNETH 0

USN-3028-1: NSPR vulnerability Ubuntu Security Notice USN-3028-1 11th July, 2016 nspr vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary NSPR could be made to crash or run programs if it received specially crafted input. Software description nspr – NetScape Portable Runtime Library Details It was discovered that NSPR incorrectly handled memory allocation. A remoteattacker could use this issue to cause NSPR to crash, resulting in a denialof service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: libnspr4 2:4.12-0ubuntu0.16.04.1 Ubuntu 15.10: libnspr4 2:4.12-0ubuntu0.15.10.1 Ubuntu 14.04 LTS: libnspr4 2:4.12-0ubuntu0.14.04.1 Ubuntu 12.04 LTS: libnspr4 4.12-0ubuntu0.12.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need [ more… ]

No Image

USN-3027-1: Tomcat vulnerability

2016-07-07 KENNETH 0

USN-3027-1: Tomcat vulnerability Ubuntu Security Notice USN-3027-1 6th July, 2016 tomcat8 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Tomcat could be made to hang if it received specially crafted network traffic. Software description tomcat8 – Servlet and JSP engine Details It was discovered that the Tomcat Fileupload library incorrectly handledcertain upload requests. A remote attacker could possibly use this issue tocause a denial of service. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: tomcat8 8.0.32-1ubuntu1.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2016-3092 Source: USN-3027-1: Tomcat vulnerability

No Image

USN-3024-1: Tomcat vulnerabilities

2016-07-06 KENNETH 0

USN-3024-1: Tomcat vulnerabilities Ubuntu Security Notice USN-3024-1 5th July, 2016 tomcat6, tomcat7 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in Tomcat. Software description tomcat6 – Servlet and JSP engine tomcat7 – Servlet and JSP engine Details It was discovered that Tomcat incorrectly handled pathnames used by webapplications in a getResource, getResourceAsStream, or getResourcePathscall. A remote attacker could use this issue to possibly list a parentdirectory . This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04 LTS andUbuntu 15.10. (CVE-2015-5174) It was discovered that the Tomcat mapper component incorrectly handledredirects. A remote attacker could use this issue to determine theexistence of a directory. This issue only affected Ubuntu 12.04 LTS,Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-5345) It was discovered [ more… ]

No Image

USN-3026-2: libusbmuxd vulnerability

2016-07-06 KENNETH 0

USN-3026-2: libusbmuxd vulnerability Ubuntu Security Notice USN-3026-2 5th July, 2016 libusbmuxd vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Summary libusbmuxd would allow unintended access to devices over the network. Software description libusbmuxd – USB multiplexor daemon for iPhone and iPod Touch devices Details It was discovered that libusbmuxd incorrectly handled socket permissions.A remote attacker could use this issue to access services on iOS devices,contrary to expectations. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: libusbmuxd4 1.0.10-2ubuntu0.1 Ubuntu 15.10: libusbmuxd2 1.0.9-1ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2016-5104 Source: USN-3026-2: libusbmuxd vulnerability