No Image

USN-3985-2: libvirt update

2019-05-17 KENNETH 0

USN-3985-2: libvirt update libvirt update A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Summary Several security issues were addressed in libvirt. Software Description libvirt – Libvirt virtualization toolkit Details Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Giorgi Maisuradze, Dan Horea Lutas, Andrei Lutas, Volodymyr Pikhur, Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Moritz Lipp, Michael Schwarz, and Daniel Gruss discovered that memory previously stored in microarchitectural fill buffers of an Intel CPU core may be exposed to a malicious process that is executing on the same CPU core. A local attacker could use this to expose sensitive information. (CVE-2018-12130) Brandon Falk, Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos, and Cristiano Giuffrida [ more… ]

No Image

USN-3988-1: MediaInfo vulnerabilities

2019-05-17 KENNETH 0

USN-3988-1: MediaInfo vulnerabilities libmediainfo vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Summary MediaInfo could be made to crash if it opened a specially crafted file. Software Description libmediainfo – library reading metadata from media files Details It was discovered that MediaInfo contained multiple security issues when handling certain multimedia files. If a user were tricked into opening a crafted multimedia file, an attacker could cause MediaInfo to crash, resulting in a denial of service. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 libmediainfo0v5 – 18.12-1ubuntu0.1 Ubuntu 18.10 libmediainfo0v5 – 18.03.1-1ubuntu0.1 Ubuntu 18.04 LTS libmediainfo0v5 – 17.12-1ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References [ more… ]

No Image

USN-3986-1: Wireshark vulnerabilities

2019-05-17 KENNETH 0

USN-3986-1: Wireshark vulnerabilities Wireshark vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Wireshark could be made to crash if it received specially crafted network traffic or input files. Software Description wireshark – network traffic analyzer Details It was discovered that Wireshark improperly handled certain input. A remote or local attacker could cause Wireshark to crash by injecting malform packets onto the wire or convincing someone to read a malformed packet trace file. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10 libwireshark-data – 2.6.8-1~ubuntu18.10.0 libwireshark11 – 2.6.8-1~ubuntu18.10.0 libwiretap8 – 2.6.8-1~ubuntu18.10.0 libwscodecs2 – 2.6.8-1~ubuntu18.10.0 libwsutil9 – 2.6.8-1~ubuntu18.10.0 tshark – 2.6.8-1~ubuntu18.10.0 wireshark – 2.6.8-1~ubuntu18.10.0 wireshark-common – 2.6.8-1~ubuntu18.10.0 wireshark-gtk – 2.6.8-1~ubuntu18.10.0 wireshark-qt – 2.6.8-1~ubuntu18.10.0 Ubuntu 18.04 LTS libwireshark-data – 2.6.8-1~ubuntu18.04.0 libwireshark11 [ more… ]

No Image

USN-3985-1: libvirt update

2019-05-16 KENNETH 0

USN-3985-1: libvirt update libvirt update A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several issues were addressed in libvirt. Software Description libvirt – Libvirt virtualization toolkit Details Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Giorgi Maisuradze, Dan Horea Lutas, Andrei Lutas, Volodymyr Pikhur, Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Moritz Lipp, Michael Schwarz, and Daniel Gruss discovered that memory previously stored in microarchitectural fill buffers of an Intel CPU core may be exposed to a malicious process that is executing on the same CPU core. A local attacker could use this to expose sensitive information. (CVE-2018-12130) Brandon Falk, Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh [ more… ]

No Image

USN-3983-2: Linux kernel (Trusty HWE) vulnerabilities

2019-05-15 KENNETH 0

USN-3983-2: Linux kernel (Trusty HWE) vulnerabilities linux-lts-trusty vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 ESM Summary Several security issues were fixed in the Linux kernel. Software Description linux-lts-trusty – Linux hardware enablement kernel from Trusty for Precise ESM Details USN-3983-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04 LTS. This update provides the corresponding updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu 12.04 LTS. Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Giorgi Maisuradze, Dan Horea Lutas, Andrei Lutas, Volodymyr Pikhur, Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Moritz Lipp, Michael Schwarz, and Daniel Gruss discovered that memory previously stored in microarchitectural fill buffers of an Intel CPU core may be exposed to a malicious process that is [ more… ]