No Image

USN-5378-4: Gzip vulnerability

2022-04-14 KENNETH 0

USN-5378-4: Gzip vulnerability USN-5378-1 fixed a vulnerability in Gzip. This update provides the corresponding update for Ubuntu 14.04 ESM and 16.04 ESM. Original advisory details: Cleemy Desu Wayo discovered that Gzip incorrectly handled certain filenames. If a user or automated system were tricked into performing zgrep operations with specially crafted filenames, a remote attacker could overwrite arbitrary files. Source: USN-5378-4: Gzip vulnerability

No Image

USN-5378-3: XZ Utils vulnerability

2022-04-13 KENNETH 0

USN-5378-3: XZ Utils vulnerability USN-5378-2 fixed a vulnerability in XZ Utils. This update provides the corresponding update for Ubuntu 14.04 ESM and 16.04 ESM. Original advisory details: Cleemy Desu Wayo discovered that Gzip incorrectly handled certain filenames. If a user or automated system were tricked into performing zgrep operations with specially crafted filenames, a remote attacker could overwrite arbitrary files. Source: USN-5378-3: XZ Utils vulnerability

No Image

USN-5378-2: XZ Utils vulnerability

2022-04-13 KENNETH 0

USN-5378-2: XZ Utils vulnerability Cleemy Desu Wayo discovered that XZ Utils incorrectly handled certain filenames. If a user or automated system were tricked into performing xzgrep operations with specially crafted filenames, a remote attacker could overwrite arbitrary files. Source: USN-5378-2: XZ Utils vulnerability

No Image

USN-5378-1: Gzip vulnerability

2022-04-13 KENNETH 0

USN-5378-1: Gzip vulnerability Cleemy Desu Wayo discovered that Gzip incorrectly handled certain filenames. If a user or automated system were tricked into performing zgrep operations with specially crafted filenames, a remote attacker could overwrite arbitrary files. Source: USN-5378-1: Gzip vulnerability

No Image

USN-5377-1: Linux kernel (BlueField) vulnerabilities

2022-04-13 KENNETH 0

USN-5377-1: Linux kernel (BlueField) vulnerabilities It was discovered that the network traffic control implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1055) Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the Linux kernel did not properly restrict access to the cgroups v1 release_agent feature. A local attacker could use this to gain administrative privileges. (CVE-2022-0492) Jürgen Groß discovered that the Xen subsystem within the Linux kernel did not adequately limit the number of events driver domains (unprivileged PV backends) could send to other guest VMs. An attacker in a driver domain could use this to cause a denial of service in other guest VMs. (CVE-2021-28711, CVE-2021-28712, CVE-2021-28713) Jürgen Groß discovered that the Xen network backend driver in [ more… ]