No Image

USN-2910-2: Linux kernel (Vivid HWE) regression

2016-02-27 KENNETH 0

USN-2910-2: Linux kernel (Vivid HWE) regression Ubuntu Security Notice USN-2910-2 27th February, 2016 linux-lts-vivid regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary USN-2910-1 introduced a regression in the Ubuntu 15.04 Linux kernel backported to Ubuntu 14.04 LTS. Software description linux-lts-vivid – Linux hardware enablement kernel from Vivid for Trusty Details USN-2910-1 fixed vulnerabilities in the Ubuntu 15.04 Linux kernelbackported to Ubuntu 14.04 LTS. An incorrect locking fix caused aregression that broke graphics displays for Ubuntu 14.04 LTS guestsrunning the Ubuntu 15.04 backport kernel within VMWare virtualmachines. This update fixes the problem. We apologize for the inconvenience. Original advisory details: halfdog discovered that OverlayFS, when mounting on top of a FUSE mount, incorrectly propagated file attributes, including setuid. A local unprivileged attacker could use this to gain privileges. (CVE-2016-1576) halfdog discovered that OverlayFS [ more… ]

No Image

USN-2908-4: Linux kernel regression

2016-02-27 KENNETH 0

USN-2908-4: Linux kernel regression Ubuntu Security Notice USN-2908-4 26th February, 2016 linux regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Summary USN-2908-1 introduced a regression in the Linux kernel. Software description linux – Linux kernel Details USN-2908-1 fixed vulnerabilities in the Linux kernel for Ubuntu15.10. An incorrect locking fix caused a regression that brokegraphics displays for Ubuntu 15.10 guests running within VMWarevirtual machines. This update fixes the problem. We apologize for the inconvenience. Original advisory details: halfdog discovered that OverlayFS, when mounting on top of a FUSE mount, incorrectly propagated file attributes, including setuid. A local unprivileged attacker could use this to gain privileges. (CVE-2016-1576) halfdog discovered that OverlayFS in the Linux kernel incorrectly propagated security sensitive extended attributes, such as POSIX ACLs. A local unprivileged attacker could use this to gain privileges. (CVE-2016-1575) [ more… ]

No Image

USN-2913-4: GnuTLS update

2016-02-25 KENNETH 0

USN-2913-4: GnuTLS update Ubuntu Security Notice USN-2913-4 24th February, 2016 gnutls26 update A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Updated GnuTLS packages are required for the USN-2913-1 update. Software description gnutls26 – GNU TLS library Details USN-2913-1 removed 1024-bit RSA CA certificates from the ca-certificatespackage. This update adds support for alternate certificate chains to theGnuTLS package to properly handle the removal. Original advisory details: The ca-certificates package contained outdated CA certificates. This update refreshes the included certificates to those contained in the 20160104 package, including the removal of the SPI CA and CA certificates with 1024-bit RSA keys. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 14.04 LTS: libgnutls26 2.12.23-12ubuntu2.5 Ubuntu 12.04 LTS: libgnutls26 2.12.14-5ubuntu3.12 To update your system, please [ more… ]

No Image

USN-2913-1: ca-certificates update

2016-02-25 KENNETH 0

USN-2913-1: ca-certificates update Ubuntu Security Notice USN-2913-1 24th February, 2016 ca-certificates update A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary ca-certificates was updated to the 20160104 package. Software description ca-certificates – Common CA certificates Details The ca-certificates package contained outdated CA certificates. This updaterefreshes the included certificates to those contained in the 20160104package, including the removal of the SPI CA and CA certificates with1024-bit RSA keys. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 15.10: ca-certificates 20160104ubuntu0.15.10.1 Ubuntu 14.04 LTS: ca-certificates 20160104ubuntu0.14.04.1 Ubuntu 12.04 LTS: ca-certificates 20160104ubuntu0.12.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References LP: 1528645 Source: USN-2913-1: ca-certificates update

No Image

USN-2913-3: OpenSSL update

2016-02-25 KENNETH 0

USN-2913-3: OpenSSL update Ubuntu Security Notice USN-2913-3 24th February, 2016 openssl update A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Updated OpenSSL packages are required for the USN-2913-1 update. Software description openssl – Secure Socket Layer (SSL) cryptographic library and tools Details USN-2913-1 removed 1024-bit RSA CA certificates from the ca-certificatespackage. This update adds support for alternate certificate chains to theOpenSSL package to properly handle the removal. Original advisory details: The ca-certificates package contained outdated CA certificates. This update refreshes the included certificates to those contained in the 20160104 package, including the removal of the SPI CA and CA certificates with 1024-bit RSA keys. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 14.04 LTS: libssl1.0.0 1.0.1f-1ubuntu2.17 Ubuntu 12.04 LTS: libssl1.0.0 1.0.1-4ubuntu5.34 [ more… ]