No Image

USN-5077-1: Apport vulnerabilities

2021-09-14 KENNETH 0

USN-5077-1: Apport vulnerabilities Maik Münch and Stephen Röttger discovered that Apport incorrectly handled certain information gathering operations. A local attacker could use this issue to gain read access to arbitrary files, possibly containing sensitive information. Source: USN-5077-1: Apport vulnerabilities

No Image

USN-5076-1: Git vulnerability

2021-09-13 KENNETH 0

USN-5076-1: Git vulnerability It was discovered that Git allowed newline characters in certain repository paths. An attacker could potentially use this issue to perform cross-protocol requests. Source: USN-5076-1: Git vulnerability

No Image

LSN-0081-1: Kernel Live Patch Security Notice

2021-09-13 KENNETH 0

LSN-0081-1: Kernel Live Patch Security Notice Maxim Levitsky discovered that the KVM hypervisor implementation for AMD processors in the Linux kernel did not properly prevent a guest VM from enabling AVIC in nested guest VMs. An attacker in a guest VM could use this to write to portions of the host’s physical memory.(CVE-2021-3653) Maxim Levitsky and Paolo Bonzini discovered that the KVM hypervisor implementation for AMD processors in the Linux kernel allowed a guest VM to disable restrictions on VMLOAD/VMSAVE in a nested guest. An attacker in a guest VM could use this to read or write portions of the host’s physical memory.(CVE-2021-3656) Andy Nguyen discovered that the netfilter subsystem in the Linux kernel contained an out-of-bounds write in its setsockopt() implementation. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary [ more… ]

No Image

USN-5075-1: Ghostscript vulnerability

2021-09-10 KENNETH 0

USN-5075-1: Ghostscript vulnerability It was discovered that Ghostscript incorrectly handled certain PostScript files. If a user or automated system were tricked into processing a specially crafted file, a remote attacker could possibly use this issue to access arbitrary files, execute arbitrary code, or cause a denial of service. Source: USN-5075-1: Ghostscript vulnerability

No Image

USN-5074-1: Firefox vulnerabilities

2021-09-10 KENNETH 0

USN-5074-1: Firefox vulnerabilities Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, bypass mixed content blocking, or execute arbitrary code. Source: USN-5074-1: Firefox vulnerabilities