No Image

USN-4320-1: Linux kernel vulnerability

2020-04-07 KENNETH 0

USN-4320-1: Linux kernel vulnerability linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 14.04 ESM Summary The system could be made to crash or expose sensitive information. Software Description linux – Linux kernel linux-aws – Linux kernel for Amazon Web Services (AWS) systems linux-kvm – Linux kernel for cloud environments linux-raspi2 – Linux kernel for Raspberry Pi 2 linux-snapdragon – Linux kernel for Snapdragon processors linux-lts-xenial – Linux hardware enablement kernel from Xenial for Trusty Details Al Viro discovered that the vfs layer in the Linux kernel contained a use- after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information (kernel memory). Update instructions The problem can be corrected by updating your system to the following package [ more… ]

No Image

USN-4319-1: Linux kernel vulnerabilities

2020-04-07 KENNETH 0

USN-4319-1: Linux kernel vulnerabilities linux, linux-aws, linux-gcp, linux-gcp-5.3, linux-hwe, linux-kvm, linux-oracle, linux-oracle-5.3, linux-raspi2, linux-raspi2-5.3 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Summary Several security issues were fixed in the Linux kernel. Software Description linux – Linux kernel linux-aws – Linux kernel for Amazon Web Services (AWS) systems linux-gcp – Linux kernel for Google Cloud Platform (GCP) systems linux-kvm – Linux kernel for cloud environments linux-oracle – Linux kernel for Oracle Cloud systems linux-raspi2 – Linux kernel for Raspberry Pi 2 linux-gcp-5.3 – Linux kernel for Google Cloud Platform (GCP) systems linux-hwe – Linux hardware enablement (HWE) kernel linux-oracle-5.3 – Linux kernel Oracle Cloud systems linux-raspi2-5.3 – Linux kernel for Raspberry Pi 2 Details It was discovered that the IPMI message handler implementation in the Linux kernel did not properly deallocate [ more… ]

No Image

USN-4317-1: Firefox vulnerabilities

2020-04-04 KENNETH 0

USN-4317-1: Firefox vulnerabilities firefox vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description firefox – Mozilla Open Source web browser Details Two use-after-free bugs were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could exploit these to cause a denial of service or execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 firefox – 74.0.1+build1-0ubuntu0.19.10.1 Ubuntu 18.04 LTS firefox – 74.0.1+build1-0ubuntu0.18.04.1 Ubuntu 16.04 LTS firefox – 74.0.1+build1-0ubuntu0.16.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to restart Firefox to [ more… ]

No Image

USN-4316-2: GD Graphics Library vulnerabilities

2020-04-03 KENNETH 0

USN-4316-2: GD Graphics Library vulnerabilities libgd2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Summary Several security issues were fixed in GD Graphics Library. Software Description libgd2 – Open source code library for the dynamic creation of images Details USN-4316-1 fixed a vulnerability in GD Graphics Library. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: It was discovered that GD Graphics Library incorrectly handled cloning an image. An attacker could possibly use this issue to cause GD Graphics Library to crash, resulting in a denial of service. (CVE-2018-14553) It was discovered that GD Graphics Library incorrectly handled loading images from X bitmap format files. An attacker could possibly use this issue to cause GD Graphics Library to crash, resulting in a denial of service, or to disclose contents [ more… ]

No Image

USN-4316-1: GD Graphics Library vulnerabilities

2020-04-03 KENNETH 0

USN-4316-1: GD Graphics Library vulnerabilities libgd2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in GD Graphics Library. Software Description libgd2 – Open source code library for the dynamic creation of images Details It was discovered that GD Graphics Library incorrectly handled cloning an image. An attacker could possibly use this issue to cause GD Graphics Library to crash, resulting in a denial of service. (CVE-2018-14553) It was discovered that GD Graphics Library incorrectly handled loading images from X bitmap format files. An attacker could possibly use this issue to cause GD Graphics Library to crash, resulting in a denial of service, or to disclose contents of the stack that has been left there by previous code. This issue only affected Ubuntu [ more… ]