No Image

USN-6143-3: Firefox regressions

2023-06-21 KENNETH 0

USN-6143-3: Firefox regressions USN-6143-1 fixed vulnerabilities and USN-6143-2 fixed minor regressions in Firefox. The update introduced several minor regressions. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. (CVE-2023-34414, CVE-2023-34416, CVE-2023-34417) Jun Kokatsu discovered that Firefox did not properly validate site-isolated process for a document loaded from a data: URL that was the result of a redirect, leading to an open redirect attack. An attacker could possibly use this issue to perform phishing attacks. (CVE-2023-34415) Source: USN-6143-3: Firefox regressions

No Image

USN-5948-2: Werkzeug vulnerabilities

2023-06-21 KENNETH 0

USN-5948-2: Werkzeug vulnerabilities USN-5948-1 fixed vulnerabilities in Werkzeug. This update provides the corresponding updates for Ubuntu 23.04. Original advisory details: It was discovered that Werkzeug did not properly handle the parsing of nameless cookies. A remote attacker could possibly use this issue to shadow other cookies. (CVE-2023-23934) It was discovered that Werkzeug could be made to process unlimited number of multipart form data parts. A remote attacker could possibly use this issue to cause Werkzeug to consume resources, leading to a denial of service. (CVE-2023-25577) Source: USN-5948-2: Werkzeug vulnerabilities

No Image

USN-6180-1: VLC media player vulnerabilities

2023-06-21 KENNETH 0

USN-6180-1: VLC media player vulnerabilities It was discovered that VLC could be made to read out of bounds when decoding image files. If a user were tricked into opening a crafted image file, a remote attacker could possibly use this issue to cause VLC to crash, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-19721) It was discovered that VLC could be made to write out of bounds when processing H.264 video files. If a user were tricked into opening a crafted H.264 video file, a remote attacker could possibly use this issue to cause VLC to crash, leading to a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-13428) It was discovered that VLC could be made to read [ more… ]

No Image

Releasing Windows 11 Build 22621.1926 to the Release Preview Channel

2023-06-21 KENNETH 0

Releasing Windows 11 Build 22621.1926 to the Release Preview Channel Hello Windows Insiders, today we’re releasing Windows 11 Build 22621.1926 (KB5027303) to Insiders in the Release Preview Channel on Windows 11, version 22H2.   This update includes the following features and improvements. As part of this update, we are enabling the new features and enhancements that began gradually rolling out last month. New! This update improves several simplified Chinese fonts and the Microsoft Pinyin Input Method Editor (IME) to support GB18030-2022. You can enter and display characters from conformance level 1 or 2 using the additions to Microsoft Yahei, Simsun, and Dengxian. This update now supports Unicode Extensions E and F in the Simsun Ext-B font. This meets the requirements for level 3. New! This update expands the roll out of notification badging for Microsoft accounts on the Start menu. [ more… ]

No Image

USN-6168-2: libx11 vulnerability

2023-06-20 KENNETH 0

USN-6168-2: libx11 vulnerability USN-6168-1 fixed a vulnerability in libx11. This update provides the corresponding update for Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, and Ubuntu 18.04 ESM. Original advisory details: Gregory James Duck discovered that libx11 incorrectly handled certain Request, Event, or Error IDs. If a user were tricked into connecting to a malicious X Server, a remote attacker could possibly use this issue to cause libx11 to crash, resulting in a denial of service. Source: USN-6168-2: libx11 vulnerability