No Image

USN-4756-1: Firefox vulnerabilities

2021-02-27 KENNETH 0

USN-4756-1: Firefox vulnerabilities Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, conduct cross-site scripting (XSS) attacks, bypass HTTP auth phishing warnings, or execute arbitrary code. Source: USN-4756-1: Firefox vulnerabilities

No Image

USN-4754-2: Python regression

2021-02-26 KENNETH 0

USN-4754-2: Python regression USN-4754-1 fixed a vulnerability in Python. The fix for CVE-2021-3177 introduced a regression in Python 2.7. This update reverts the security fix pending further investigation. We apologize for the inconvenience. Original advisory details: It was discovered that Python incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code or cause a denial of service. (CVE-2020-27619, CVE-2021-3177) Source: USN-4754-2: Python regression

No Image

USN-4755-1: LibTIFF vulnerabilities

2021-02-26 KENNETH 0

USN-4755-1: LibTIFF vulnerabilities It was discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a specially crafted image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges. Source: USN-4755-1: LibTIFF vulnerabilities

No Image

USN-4754-1: Python vulnerabilities

2021-02-25 KENNETH 0

USN-4754-1: Python vulnerabilities It was discovered that Python incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code or cause a denial of service. (CVE-2020-27619, CVE-2021-3177) Source: USN-4754-1: Python vulnerabilities

No Image

USN-4749-1: Linux kernel vulnerabilities

2021-02-25 KENNETH 0

USN-4749-1: Linux kernel vulnerabilities Bodong Zhao discovered a use-after-free in the Sun keyboard driver implementation in the Linux kernel. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2020-25669) It was discovered that the jfs file system implementation in the Linux kernel contained an out-of-bounds read vulnerability. A local attacker could use this to possibly cause a denial of service (system crash). (CVE-2020-27815) Shisong Qin and Bodong Zhao discovered that Speakup screen reader driver in the Linux kernel did not correctly handle setting line discipline in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2020-27830, CVE-2020-28941) It was discovered that the memory management subsystem in the Linux kernel did not properly handle copy-on-write operations in some situations. A local attacker could possibly use this [ more… ]