No Image

USN-4193-1: Ghostscript vulnerability

2019-11-15 KENNETH 0

USN-4193-1: Ghostscript vulnerability ghostscript vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Ghostscript could be made to crash, access files, or run programs if it opened a specially crafted file. Software Description ghostscript – PostScript and PDF interpreter Details Paul Manfred and Lukas Schauer discovered that Ghostscript incorrectly handled certain PostScript files. If a user or automated system were tricked into processing a specially crafted file, a remote attacker could possibly use this issue to access arbitrary files, execute arbitrary code, or cause a denial of service. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 ghostscript – 9.27~dfsg+0-0ubuntu3.1 libgs9 – 9.27~dfsg+0-0ubuntu3.1 Ubuntu 19.04 ghostscript – 9.26~dfsg+0-0ubuntu7.4 libgs9 – 9.26~dfsg+0-0ubuntu7.4 Ubuntu 18.04 LTS ghostscript – 9.26~dfsg+0-0ubuntu0.18.04.12 [ more… ]

No Image

USN-4192-1: ImageMagick vulnerabilities

2019-11-14 KENNETH 0

USN-4192-1: ImageMagick vulnerabilities imagemagick vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in ImageMagick. Software Description imagemagick – Image manipulation programs and library Details It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 imagemagick – 8:6.9.10.23+dfsg-2.1ubuntu3.1 imagemagick-6.q16 – 8:6.9.10.23+dfsg-2.1ubuntu3.1 libmagick++-6.q16-8 – 8:6.9.10.23+dfsg-2.1ubuntu3.1 libmagickcore-6.q16-6 – 8:6.9.10.23+dfsg-2.1ubuntu3.1 libmagickcore-6.q16-6-extra – 8:6.9.10.23+dfsg-2.1ubuntu3.1 Ubuntu 19.04 imagemagick – 8:6.9.10.14+dfsg-7ubuntu2.3 imagemagick-6.q16 – 8:6.9.10.14+dfsg-7ubuntu2.3 libmagick++-6.q16-8 – 8:6.9.10.14+dfsg-7ubuntu2.3 libmagickcore-6.q16-6 [ more… ]

No Image

USN-4191-2: QEMU vulnerabilities

2019-11-14 KENNETH 0

USN-4191-2: QEMU vulnerabilities qemu vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Summary Several security issues were fixed in QEMU. Software Description qemu – Machine emulator and virtualizer Details USN-4191-2 fixed a vulnerability in QEMU. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: It was discovered that the LSI SCSI adapter emulator implementation in QEMU did not properly validate executed scripts. A local attacker could use this to cause a denial of service. (CVE-2019-12068) Sergej Schumilo, Cornelius Aschermann and Simon Wörner discovered that the qxl paravirtual graphics driver implementation in QEMU contained a null pointer dereference. A local attacker in a guest could use this to cause a denial of service. (CVE-2019-12155) Riccardo Schirone discovered that the QEMU bridge helper did not properly validate network interface names. A [ more… ]

No Image

USN-4191-1: QEMU vulnerabilities

2019-11-14 KENNETH 0

USN-4191-1: QEMU vulnerabilities qemu vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in QEMU. Software Description qemu – Machine emulator and virtualizer Details It was discovered that the LSI SCSI adapter emulator implementation in QEMU did not properly validate executed scripts. A local attacker could use this to cause a denial of service. (CVE-2019-12068) Sergej Schumilo, Cornelius Aschermann and Simon Wörner discovered that the qxl paravirtual graphics driver implementation in QEMU contained a null pointer dereference. A local attacker in a guest could use this to cause a denial of service. (CVE-2019-12155) Riccardo Schirone discovered that the QEMU bridge helper did not properly validate network interface names. A local attacker could possibly use this to bypass ACL restrictions. (CVE-2019-13164) It [ more… ]

No Image

USN-4186-3: Linux kernel vulnerability

2019-11-14 KENNETH 0

USN-4186-3: Linux kernel vulnerability linux vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the Linux kernel. Software Description linux – Linux kernel Details USN-4186-1 fixed vulnerabilities in the Linux kernel. It was discovered that the kernel fix for CVE-2019-0155 (i915 missing Blitter Command Streamer check) was incomplete on 64-bit Intel x86 systems. This update addresses the issue. We apologize for the inconvenience. Original advisory details: Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel processors using Transactional Synchronization Extensions (TSX) could expose memory contents previously stored in microarchitectural buffers to a malicious process that is executing on the same CPU core. A local attacker could [ more… ]