No Image

USN-4142-2: e2fsprogs vulnerability

2019-09-30 KENNETH 0

USN-4142-2: e2fsprogs vulnerability e2fsprogs vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary e2fsprogs could be made to execute arbitrary code if it is running in a crafted ext4 partition. Software Description e2fsprogs – ext2/ext3/ext4 file system utilities Details USN-4142-1 fixed a vulnerability in e2fsprogs. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It was discovered that e2fsprogs incorrectly handled certain ext4 partitions. An attacker could possibly use this issue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM e2fsprogs – 1.42.9-3ubuntu1.3+esm1 Ubuntu 12.04 ESM e2fsprogs – 1.42-1ubuntu2.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the [ more… ]

No Image

USN-4142-1: e2fsprogs vulnerability

2019-09-30 KENNETH 0

USN-4142-1: e2fsprogs vulnerability e2fsprogs vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary e2fsprogs could be made to execute arbitrary code if it is running in a crafted ext4 partition. Software Description e2fsprogs – ext2/ext3/ext4 file system utilities Details It was discovered that e2fsprogs incorrectly handled certain ext4 partitions. An attacker could possibly use this issue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 e2fsprogs – 1.44.6-1ubuntu0.1 Ubuntu 18.04 LTS e2fsprogs – 1.44.1-1ubuntu1.2 Ubuntu 16.04 LTS e2fsprogs – 1.42.13-1ubuntu1.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-5094 Source: USN-4142-1: e2fsprogs vulnerability

No Image

USN-4141-1: Exim vulnerability

2019-09-29 KENNETH 0

USN-4141-1: Exim vulnerability exim4 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Summary Exim could be made to crash or run programs if it received specially crafted network traffic. Software Description exim4 – Exim is a mail transport agent Details It was discovered that Exim incorrectly handled certain string operations. A remote attacker could use this issue to cause Exim to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 exim4-daemon-heavy – 4.92-4ubuntu1.4 exim4-daemon-light – 4.92-4ubuntu1.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-16928 Source: USN-4141-1: Exim vulnerability

No Image

USN-4140-1: Firefox vulnerability

2019-09-26 KENNETH 0

USN-4140-1: Firefox vulnerability firefox vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Firefox could be made to hijack the mouse pointer it if opened a malicious website. Software Description firefox – Mozilla Open Source web browser Details It was discovered that no user notification was given when pointer lock is enabled. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to hijack the mouse pointer and confuse users. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 firefox – 69.0.1+build1-0ubuntu0.19.04.1 Ubuntu 18.04 LTS firefox – 69.0.1+build1-0ubuntu0.18.04.1 Ubuntu 16.04 LTS firefox – 69.0.1+build1-0ubuntu0.16.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to [ more… ]

No Image

USN-4139-1: File Roller vulnerability

2019-09-25 KENNETH 0

USN-4139-1: File Roller vulnerability file-roller vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary File Roller could be made to overwrite sensitive files if it received a specially crafted TAR file. Software Description file-roller – archive manager for GNOME Details It was discovered that File Roller incorrectly handled certain TAR files. An attacker could possibly use this issue to overwrite sensitive files during extraction. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS file-roller – 3.28.0-1ubuntu1.1 Ubuntu 16.04 LTS file-roller – 3.16.5-0ubuntu1.3 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-16680 Source: USN-4139-1: File Roller vulnerability