No Image

USN-4047-2: libvirt update vulnerability

2020-01-13 KENNETH 0

USN-4047-2: libvirt update vulnerability libvirt vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Summary Several security issues were fixed in libvirt. Software Description libvirt – Libvirt virtualization toolkit Details USN-4047-1 fixed a vulnerability in libvirt. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: Matthias Gerstner and Ján Tomko discovered that libvirt incorrectly handled certain API calls. An attacker could possibly use this issue to check for arbitrary files, or execute arbitrary binaries. In the default installation, attackers would be isolated by the libvirt AppArmor profile. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM libvirt-bin – 1.2.2-0ubuntu13.1.28+esm1 libvirt0 – 1.2.2-0ubuntu13.1.28+esm1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to reboot [ more… ]

No Image

USN-4234-1: Firefox vulnerabilities

2020-01-10 KENNETH 0

USN-4234-1: Firefox vulnerabilities firefox vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description firefox – Mozilla Open Source web browser Details Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, bypass Content Security Policy (CSP) restrictions, conduct cross-site scripting (XSS) attacks, or execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 firefox – 72.0.1+build1-0ubuntu0.19.10.1 Ubuntu 19.04 firefox – 72.0.1+build1-0ubuntu0.19.04.1 Ubuntu 18.04 LTS firefox – 72.0.1+build1-0ubuntu0.18.04.1 Ubuntu 16.04 LTS firefox [ more… ]

No Image

USN-4229-1: NTP vulnerability

2020-01-10 KENNETH 0

USN-4229-1: NTP vulnerability ntp vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary A security issue was fixed in ntpq and ntpdc. Software Description ntp – Network Time Protocol daemon and utility programs Details It was discovered that ntpq and ntpdc incorrectly handled some arguments. An attacker could possibly use this issue to cause ntpq or ntpdc to crash, execute arbitrary code, or escalate to higher privileges. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS ntp – 1:4.2.8p4+dfsg-3ubuntu5.10 Ubuntu 14.04 ESM ntp – 1:4.2.6.p5+dfsg-3ubuntu2.14.04.13+esm1 Ubuntu 12.04 ESM ntp – 1:4.2.6.p3+dfsg-1ubuntu3.13 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2018-12327 Source: USN-4229-1: NTP [ more… ]

No Image

USN-4233-1: GnuTLS update

2020-01-09 KENNETH 0

USN-4233-1: GnuTLS update gnutls28 update A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary SHA1 has been marked as untrusted in GnuTLS. Software Description gnutls28 – GNU TLS library Details As a security improvement, this update marks SHA1 as being untrusted for digital signature operations. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libgnutls30 – 3.5.18-1ubuntu1.2 Ubuntu 16.04 LTS libgnutls30 – 3.4.10-4ubuntu1.6 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References LP: 1858691 Source: USN-4233-1: GnuTLS update

No Image

USN-4231-1: NSS vulnerability

2020-01-09 KENNETH 0

USN-4231-1: NSS vulnerability nss vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary NSS could be made to execute arbitrary code if it received a specially crafted input. Software Description nss – Network Security Service library Details It was discovered that NSS incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 libnss3 – 2:3.45-1ubuntu2.2 Ubuntu 19.04 libnss3 – 2:3.42-1ubuntu2.5 Ubuntu 18.04 LTS libnss3 – 2:3.35-2ubuntu2.7 Ubuntu 16.04 LTS libnss3 – 2:3.28.4-0ubuntu0.16.04.10 Ubuntu 14.04 ESM libnss3 – 2:3.28.4-0ubuntu0.14.04.5+esm4 Ubuntu 12.04 ESM libnss3 – 2:3.28.4-0ubuntu0.12.04.7 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system [ more… ]