No Image

USN-4245-1: PySAML2 vulnerability

2020-01-22 KENNETH 0

USN-4245-1: PySAML2 vulnerability python-pysaml2 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary PySAML2 could be made to bypass signature verification with arbitrary data. Software Description python-pysaml2 – Pure python implementation of SAML2 Details It was discovered that PySAML2 incorrectly handled certain SAML files. An attacker could possibly use this issue to bypass signature verification with arbitrary data. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 python-pysaml2 – 4.5.0+dfsg1-0ubuntu2.19.10.1 python3-pysaml2 – 4.5.0+dfsg1-0ubuntu2.19.10.1 Ubuntu 19.04 python-pysaml2 – 4.5.0+dfsg1-0ubuntu2.19.04.1 python3-pysaml2 – 4.5.0+dfsg1-0ubuntu2.19.04.1 Ubuntu 18.04 LTS python-pysaml2 – 4.0.2-0ubuntu3.1 python3-pysaml2 – 4.0.2-0ubuntu3.1 Ubuntu 16.04 LTS python-pysaml2 – 3.0.0-3ubuntu1.16.04.4 python3-pysaml2 – 3.0.0-3ubuntu1.16.04.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all [ more… ]

No Image

USN-4244-1: Samba vulnerabilities

2020-01-21 KENNETH 0

USN-4244-1: Samba vulnerabilities samba vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in Samba. Software Description samba – SMB/CIFS file, print, and login server for Unix Details It was discovered that Samba did not automatically replicate ACLs set to inherit down a subtree on AD Directory, contrary to expectations. This issue was only addressed in Ubuntu 18.04 LTS, Ubuntu 19.04 and Ubuntu 19.10. (CVE-2019-14902) Robert Święcki discovered that Samba incorrectly handled certain character conversions when the log level is set to 3 or above. In certain environments, a remote attacker could possibly use this issue to cause Samba to crash, resulting in a denial of service. (CVE-2019-14907) Christian Naumer discovered that Samba incorrectly handled DNS zone scavenging. This issue could [ more… ]

No Image

USN-4243-1: libbsd vulnerabilities

2020-01-21 KENNETH 0

USN-4243-1: libbsd vulnerabilities libbsd vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary Several security issues were fixed in libbsd. Software Description libbsd – utility functions from BSD systems – development files Details It was discovered that libbsd incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 14.04 ESM. (CVE-2016-2090) It was discovered that libbsd incorrectly handled certain strings. An attacker could possibly use this issue to access sensitive information. (CVE-2019-20367) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 libbsd0 – 0.9.1-2ubuntu0.1 Ubuntu 18.04 LTS libbsd0 – 0.8.7-1ubuntu0.1 Ubuntu 16.04 LTS libbsd0 – 0.8.2-1ubuntu0.1 Ubuntu 14.04 ESM libbsd0 – 0.6.0-2ubuntu1+esm1 Ubuntu [ more… ]

No Image

USN-4242-1: Sysstat vulnerabilities

2020-01-20 KENNETH 0

USN-4242-1: Sysstat vulnerabilities sysstat vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in Sysstat. Software Description sysstat – system performance tools for Linux Details It was discovered that Sysstat incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash or execute arbitrary code. This issue only affected Ubuntu 19.04 and Ubuntu 19.10. (CVE-2019-16167) It was discovered that Sysstat incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. (CVE-2019-19725) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 sysstat – 12.0.6-1ubuntu0.1 Ubuntu 19.04 sysstat – 12.0.1-1ubuntu0.1 Ubuntu 18.04 LTS sysstat – 11.6.1-1ubuntu0.1 Ubuntu 16.04 LTS sysstat – 11.2.0-1ubuntu0.3 To update your [ more… ]

No Image

USN-4225-2: Linux kernel (HWE) vulnerabilities

2020-01-18 KENNETH 0

USN-4225-2: Linux kernel (HWE) vulnerabilities linux-hwe vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Summary Several security issues were fixed in the Linux kernel. Software Description linux-hwe – Linux hardware enablement (HWE) kernel Details USN-4225-1 fixed vulnerabilities in the Linux kernel for Ubuntu 19.10. This update provides the corresponding updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu 19.10 for Ubuntu 18.04 LTS. It was discovered that a heap-based buffer overflow existed in the Marvell WiFi-Ex Driver for the Linux kernel. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2019-14895, CVE-2019-14901) It was discovered that a heap-based buffer overflow existed in the Marvell Libertas WLAN Driver for the Linux kernel. A physically proximate attacker could use this to cause a [ more… ]