No Image

USN-5821-4: pip regression

2023-03-03 KENNETH 0

USN-5821-4: pip regression USN-5821-3 fixed a vulnerability in pip. The update introduced a minor regression in Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Sebastian Chnelik discovered that wheel incorrectly handled certain file names when validated against a regex expression. An attacker could possibly use this issue to cause a denial of service. Source: USN-5821-4: pip regression

No Image

USN-5908-1: Sudo vulnerability

2023-03-02 KENNETH 0

USN-5908-1: Sudo vulnerability It was discovered that Sudo incorrectly handled the per-command chroot feature. In certain environments where Sudo is configured with a rule that contains a CHROOT setting, a local attacker could use this issue to cause Sudo to crash, resulting in a denial of service, or possibly escalate privileges. Source: USN-5908-1: Sudo vulnerability

No Image

USN-5871-2: Git regression

2023-03-02 KENNETH 0

USN-5871-2: Git regression USN-5871-1 fixed vulnerabilities in Git. A backport fixing part of the vulnerability in CVE-2023-22490 was required. This update fix this for Ubuntu 18.04 LTS. Original advisory details: It was discovered that Git incorrectly handled certain repositories. An attacker could use this issue to make Git uses its local clone optimization even when using a non-local transport. (CVE-2023-22490) Source: USN-5871-2: Git regression

No Image

USN-5907-1: c-ares vulnerability

2023-03-02 KENNETH 0

USN-5907-1: c-ares vulnerability It was discovered that c-ares incorrectly handled certain sortlist strings. A remote attacker could use this issue to cause c-ares to crash, resulting in a denial of service, or possibly execute arbitrary code. Source: USN-5907-1: c-ares vulnerability

No Image

USN-5906-1: PostgreSQL vulnerability

2023-03-02 KENNETH 0

USN-5906-1: PostgreSQL vulnerability Jacob Champion discovered that the PostgreSQL client incorrectly handled Kerberos authentication. If a user or automated system were tricked into connecting to a malicious server, a remote attacker could possibly use this issue to obtain sensitive information. Source: USN-5906-1: PostgreSQL vulnerability