No Image

USN-4265-1: SpamAssassin vulnerabilities

2020-02-04 KENNETH 0

USN-4265-1: SpamAssassin vulnerabilities spamassassin vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in SpamAssassin. Software Description spamassassin – Perl-based spam filter using text analysis Details It was discovered that SpamAssassin incorrectly handled certain CF files. If a user or automated system were tricked into using a specially-crafted CF file, a remote attacker could possibly run arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 spamassassin – 3.4.2-1ubuntu0.19.10.2 Ubuntu 18.04 LTS spamassassin – 3.4.2-0ubuntu0.18.04.3 Ubuntu 16.04 LTS spamassassin – 3.4.2-0ubuntu0.16.04.3 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2020-1930 CVE-2020-1931 Source: USN-4265-1: SpamAssassin vulnerabilities

No Image

USN-4264-1: Django vulnerability

2020-02-04 KENNETH 0

USN-4264-1: Django vulnerability python-django vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Summary Django could be vulnerable to SQL injection attacks. Software Description python-django – High-level Python web development framework Details Simon Charette discovered that Django incorrectly handled input in the PostgreSQL module. A remote attacker could possibly use this to perform SQL injection attacks. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 python-django – 1:1.11.22-1ubuntu1.2 python3-django – 1:1.11.22-1ubuntu1.2 Ubuntu 18.04 LTS python-django – 1:1.11.11-1ubuntu1.7 python3-django – 1:1.11.11-1ubuntu1.7 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2020-7471 Source: USN-4264-1: Django vulnerability

No Image

USN-4263-1: Sudo vulnerability

2020-02-03 KENNETH 0

USN-4263-1: Sudo vulnerability sudo vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Sudo could allow unintended access to the administrator account. Software Description sudo – Provide limited super user privileges to specific users Details Joe Vennix discovered that Sudo incorrectly handled memory operations when the pwfeedback option is enabled. A local attacker could possibly use this issue to obtain unintended access to the administrator account. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 sudo – 1.8.27-1ubuntu4.1 sudo-ldap – 1.8.27-1ubuntu4.1 Ubuntu 18.04 LTS sudo – 1.8.21p2-3ubuntu1.2 sudo-ldap – 1.8.21p2-3ubuntu1.2 Ubuntu 16.04 LTS sudo – 1.8.16-0ubuntu1.9 sudo-ldap – 1.8.16-0ubuntu1.9 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary [ more… ]

No Image

USN-4234-2: Firefox regressions

2020-01-30 KENNETH 0

USN-4234-2: Firefox regressions firefox regressions A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary USN-4234-1 caused some minor regressions in Firefox. Software Description firefox – Mozilla Open Source web browser Details USN-4234-1 fixed vulnerabilities in Firefox. The update introduced various minor regressions. This update fixes the problems. We apologize for the inconvenience. Original advisory details: Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, bypass Content Security Policy (CSP) restrictions, conduct cross-site scripting (XSS) attacks, or execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 firefox – 72.0.2+build1-0ubuntu0.19.10.1 Ubuntu 18.04 LTS firefox [ more… ]

No Image

USN-4262-1: OpenStack Keystone vulnerability

2020-01-30 KENNETH 0

USN-4262-1: OpenStack Keystone vulnerability keystone vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Summary OpenStack Keystone could be made to expose sensitive information over the network. Software Description keystone – OpenStack identity service Details Daniel Preussker discovered that OpenStack Keystone incorrectly handled the list credentials API. A user with a role on the project could use this issue to view any other user’s credentials. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 keystone – 2:16.0.0-0ubuntu1.1 python3-keystone – 2:16.0.0-0ubuntu1.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-19687 Source: USN-4262-1: OpenStack Keystone vulnerability