No Image

USN-3038-1: Apache HTTP Server vulnerability

2016-07-19 KENNETH 0

USN-3038-1: Apache HTTP Server vulnerability Ubuntu Security Notice USN-3038-1 18th July, 2016 apache2 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary A security issue was fixed in the Apache HTTP Server. Software description apache2 – Apache HTTP server Details It was discovered that the Apache HTTP Server would set the HTTP_PROXYenvironment variable based on the contents of the Proxy header from HTTPrequests. A remote attacker could possibly use this issue in combinationwith CGI scripts that honour the HTTP_PROXY variable to redirect outgoingHTTP requests. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: apache2-bin 2.4.18-2ubuntu3.1 Ubuntu 15.10: apache2-bin 2.4.12-2ubuntu2.1 Ubuntu 14.04 LTS: apache2.2-bin 2.4.7-1ubuntu4.13 Ubuntu 12.04 LTS: apache2.2-bin 2.2.22-1ubuntu1.11 To update your system, please follow [ more… ]

No Image

USN-3023-1: Thunderbird vulnerabilities

2016-07-19 KENNETH 0

USN-3023-1: Thunderbird vulnerabilities Ubuntu Security Notice USN-3023-1 18th July, 2016 thunderbird vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in Thunderbird. Software description thunderbird – Mozilla Open Source mail and newsgroup client Details It was discovered that NSPR incorrectly handled memory allocation. If auser were tricked in to opening a specially crafted message, an attackercould potentially exploit this to cause a denial of service viaapplication crash, or execute arbitrary code. (CVE-2016-1951) Christian Holler, Gary Kwong, Jesse Ruderman, Tyson Smith, Timothy Nikkel,Sylvestre Ledru, Julian Seward, Olli Pettay, and Karl Tomlinson,discovered multiple memory safety issues in Thunderbird. If a user weretricked in to opening a specially crafted message, an attacker couldpotentially exploit these to cause a denial of service via applicationcrash, [ more… ]

No Image

USN-3037-1: Linux kernel (Vivid HWE) vulnerability

2016-07-15 KENNETH 0

USN-3037-1: Linux kernel (Vivid HWE) vulnerability Ubuntu Security Notice USN-3037-1 14th July, 2016 linux-lts-vivid vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary The system could be made to crash under certain conditions. Software description linux-lts-vivid – Linux hardware enablement kernel from Vivid for Trusty Details Jan Stancek discovered that the Linux kernel's memory manager did notproperly handle moving pages mapped by the asynchronous I/O (AIO) ringbuffer to the other nodes. A local attacker could use this to cause adenial of service (system crash). Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 14.04 LTS: linux-image-3.19.0-65-powerpc64-smp 3.19.0-65.73~14.04.1 linux-image-3.19.0-65-powerpc-smp 3.19.0-65.73~14.04.1 linux-image-3.19.0-65-powerpc-e500mc 3.19.0-65.73~14.04.1 linux-image-3.19.0-65-powerpc64-emb 3.19.0-65.73~14.04.1 linux-image-3.19.0-65-generic 3.19.0-65.73~14.04.1 linux-image-3.19.0-65-generic-lpae 3.19.0-65.73~14.04.1 linux-image-3.19.0-65-lowlatency 3.19.0-65.73~14.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need [ more… ]

No Image

USN-3036-1: Linux kernel (Utopic HWE) vulnerability

2016-07-15 KENNETH 0

USN-3036-1: Linux kernel (Utopic HWE) vulnerability Ubuntu Security Notice USN-3036-1 14th July, 2016 linux-lts-utopic vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary The system could be made to crash under certain conditions. Software description linux-lts-utopic – Linux hardware enablement kernel from Utopic for Trusty Details Jan Stancek discovered that the Linux kernel's memory manager did notproperly handle moving pages mapped by the asynchronous I/O (AIO) ringbuffer to the other nodes. A local attacker could use this to cause adenial of service (system crash). Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 14.04 LTS: linux-image-3.16.0-77-powerpc-smp 3.16.0-77.99~14.04.1 linux-image-3.16.0-77-powerpc-e500mc 3.16.0-77.99~14.04.1 linux-image-3.16.0-77-powerpc64-smp 3.16.0-77.99~14.04.1 linux-image-3.16.0-77-generic 3.16.0-77.99~14.04.1 linux-image-3.16.0-77-generic-lpae 3.16.0-77.99~14.04.1 linux-image-3.16.0-77-powerpc64-emb 3.16.0-77.99~14.04.1 linux-image-3.16.0-77-lowlatency 3.16.0-77.99~14.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need [ more… ]

No Image

USN-3035-3: Linux kernel (Wily HWE) vulnerability

2016-07-15 KENNETH 0

USN-3035-3: Linux kernel (Wily HWE) vulnerability Ubuntu Security Notice USN-3035-3 14th July, 2016 linux-lts-wily vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary The system could be made to crash under certain conditions. Software description linux-lts-wily – Linux hardware enablement kernel from Wily for Trusty Details USN-3035-1 fixed vulnerabilities in the Linux kernel for Ubuntu 15.10.This update provides the corresponding updates for the Linux HardwareEnablement (HWE) kernel from Ubuntu 15.10 for Ubuntu 14.04 LTS. Jan Stancek discovered that the Linux kernel's memory manager did notproperly handle moving pages mapped by the asynchronous I/O (AIO) ringbuffer to the other nodes. A local attacker could use this to cause adenial of service (system crash). Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 14.04 LTS: linux-image-4.2.0-42-powerpc64-smp 4.2.0-42.49~14.04.1 [ more… ]