No Image

USN-4034-1: ImageMagick vulnerabilities

2019-06-25 KENNETH 0

USN-4034-1: ImageMagick vulnerabilities imagemagick vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in ImageMagick. Software Description imagemagick – Image manipulation programs and library Details It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program. Due to a large number of issues discovered in GhostScript that prevent it from being used by ImageMagick safely, the update for Ubuntu 18.10 and Ubuntu 19.04 includes a default policy change that disables support for the Postscript and PDF formats in ImageMagick. This policy [ more… ]

No Image

USN-4033-1: libmysofa vulnerability

2019-06-25 KENNETH 0

USN-4033-1: libmysofa vulnerability libmysofa vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Summary libmysofa could be made to crash if it received specially crafted input. Software Description libmysofa – library to read HRTFs stored in the AES69-2015 SOFA format Details It was discovered that a libmysofa component does not properly validate multiplications and additions, and may crash with some specific input. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 libmysofa0 – 0.6~dfsg0-2ubuntu0.19.04.1 Ubuntu 18.10 libmysofa0 – 0.6~dfsg0-2ubuntu0.18.10.1 Ubuntu 18.04 LTS libmysofa0 – 0.6~dfsg0-2ubuntu0.18.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-10672 Source: USN-4033-1: libmysofa vulnerability

Windows 10 Tip: New Windows light theme

2019-06-25 KENNETH 0

Windows 10 Tip: New Windows light theme Editor’s note: We’re back with the summer batch of weekly Windows 10 tips posts, which highlight some of the many helpful features that come with the Windows 10 May 2019 Update. We’ve been working hard behind the scenes to make your daily life easier with a streamlined update process, as well as clean and simple experiences for your desktop. Thanks to the Windows 10 May 2019 Update, you can brighten up your settings, experiences and desktop with the new Windows light theme. Check it out: To try out the new light theme, go to Settings > Personalization > Colors, and select Light in the “Choose your color” dropdown. And don’t worry, if you’re a fan of the dark mode, that’s still an option too! Check out our tip for how to enable dark [ more… ]

No Image

USN-4032-1: Firefox vulnerability

2019-06-25 KENNETH 0

USN-4032-1: Firefox vulnerability firefox vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary A sandbox escape was discovered in Firefox. Software Description firefox – Mozilla Open Source web browser Details It was discovered that a sandboxed child process could open arbitrary web content in the parent process via the Prompt:Open IPC message. When combined with another vulnerability, an attacker could potentially exploit this to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 firefox – 67.0.4+build1-0ubuntu0.19.04.1 Ubuntu 18.10 firefox – 67.0.4+build1-0ubuntu0.18.10.1 Ubuntu 18.04 LTS firefox – 67.0.4+build1-0ubuntu0.18.04.1 Ubuntu 16.04 LTS firefox – 67.0.4+build1-0ubuntu0.16.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to restart Firefox to make [ more… ]

No Image

USN-4031-1: Linux kernel vulnerability

2019-06-24 KENNETH 0

USN-4031-1: Linux kernel vulnerability linux, linux-hwe vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Summary 64-Bit PowerPC systems could be made to expose sensitive information. Software Description linux – Linux kernel linux-hwe – Linux hardware enablement (HWE) kernel Details It was discovered that the Linux kernel did not properly separate certain memory mappings when creating new userspace processes on 64-bit Power (ppc64el) systems. A local attacker could use this to access memory contents or cause memory corruption of other processes on the system. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 linux-image-5.0.0-19-generic – 5.0.0-19.20 linux-image-generic – 5.0.0.19.20 linux-image-virtual – 5.0.0.19.20 Ubuntu 18.10 linux-image-4.18.0-24-generic – 4.18.0-24.25 linux-image-generic – 4.18.0.24.25 linux-image-powerpc-e500mc – 4.18.0.24.25 linux-image-powerpc-smp – 4.18.0.24.25 linux-image-powerpc64-emb – 4.18.0.24.25 linux-image-powerpc64-smp – [ more… ]