No Image

USN-2862-1: Pygments vulnerability

2016-01-07 KENNETH 0

Ubuntu Security Notice USN-2862-1 7th January, 2016 pygments vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 15.04 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Pygments could be made to crash or run programs if it processed a specially crafted font request. Software description pygments – syntax highlighting package written in Python Details It was discovered that Pygments incorrectly sanitized strings used tosearch system fonts. An attacker could possibly use this issue to executearbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 15.10: python3-pygments 2.0.1+dfsg-1.1svn1.1 python-pygments 2.0.1+dfsg-1.1svn1.1 Ubuntu 15.04: python3-pygments 2.0.1+dfsg-1svn1.1 python-pygments 2.0.1+dfsg-1svn1.1 Ubuntu 14.04 LTS: python3-pygments 1.6+dfsg-1ubuntu1.1 python-pygments 1.6+dfsg-1ubuntu1.1 Ubuntu 12.04 LTS: python3-pygments 1.4+dfsg-2ubuntu0.1 python-pygments 1.4+dfsg-2ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make [ more… ]

WordPress 4.4.1 Security and Maintenance Release

2016-01-07 KENNETH 0

WordPress 4.4.1 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately. WordPress versions 4.4 and earlier are affected by a cross-site scripting vulnerability that could allow a site to be compromised. This was reported by Crtc4L. There were also several non-security bug fixes: Emoji support has been updated to include all of the latest emoji characters, including the new diverse emoji! Some sites with older versions of OpenSSL installed were unable to communicate with other services provided through some plugins. If a post URL was ever re-used, the site could redirect to the wrong post. WordPress 4.4.1 fixes 52 bugs from 4.4. For more information, see the release notes or consult the list of changes. Download WordPress 4.4.1 or venture over to Dashboard → Updates and simply click “Update Now.” Sites [ more… ]

No Image

USN-2861-1: libpng vulnerabilities

2016-01-07 KENNETH 0

Ubuntu Security Notice USN-2861-1 6th January, 2016 libpng vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 15.04 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary libpng could be made to crash or run programs as your login if it opened a specially crafted file. Software description libpng – PNG (Portable Network Graphics) file library Details It was discovered that libpng incorrectly handled certain small bit-depthvalues. If a user or automated system using libpng were tricked intoopening a specially crafted image, an attacker could exploit this to causea denial of service or execute code with the privileges of the userinvoking the program. (CVE-2015-8472) Qixue Xiao and Chen Yu discovered that libpng incorrectly handled certainmalformed images. If a user or automated system using libpng were trickedinto opening a specially crafted image, an attacker could exploit this [ more… ]