No Image

USN-5060-2: NTFS-3G vulnerabilities

2021-09-01 KENNETH 0

USN-5060-2: NTFS-3G vulnerabilities USN-5060-1 fixed a vulnerability in NTFS-3G. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Original advisory details: It was discovered that NTFS-3G incorrectly handled certain image file. An attacker could possibly use this issue to execute arbitrary code. Source: USN-5060-2: NTFS-3G vulnerabilities

No Image

USN-5060-1: NTFS-3G vulnerabilities

2021-09-01 KENNETH 0

USN-5060-1: NTFS-3G vulnerabilities It was discovered that NTFS-3G incorrectly handled certain image file. An attacker could possibly use this issue to execute arbitrary code. Source: USN-5060-1: NTFS-3G vulnerabilities

No Image

USN-5058-1: Thunderbird vulnerabilities

2021-08-31 KENNETH 0

USN-5058-1: Thunderbird vulnerabilities It was discovered that Thunderbird didn’t ignore IMAP server responses prior to completion of the STARTTLS handshake. A person-in-the-middle could potentially exploit this to trick Thunderbird into showing incorrect information. (CVE-2021-29969) Multiple security issues were discovered in Thunderbird. If a user were tricked into opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, or execute arbitrary code. (CVE-2021-29970, CVE-2021-29976, CVE-2021-29980, CVE-2021-29984, CVE-2021-29985, CVE-2021-29986, CVE-2021-29988, CVE-2021-29989, CVE-2021-30547) Source: USN-5058-1: Thunderbird vulnerabilities

No Image

USN-5057-1: Squashfs-Tools vulnerability

2021-08-31 KENNETH 0

USN-5057-1: Squashfs-Tools vulnerability Etienne Stalmans discovered that Squashfs-Tools mishandled certain malformed SQUASHFS files. An attacker could use this vulnerability to write arbitrary files to the filesystem. Source: USN-5057-1: Squashfs-Tools vulnerability

No Image

USN-5054-1: uWSGI vulnerability

2021-08-31 KENNETH 0

USN-5054-1: uWSGI vulnerability Felix Wilhelm discovered a buffer overflow flaw in the mod_proxy_uwsgi module. An attacker could use this vulnerability to provoke an information disclosure or potentially remote code execution. Source: USN-5054-1: uWSGI vulnerability