No Image

USN-4125-1: Memcached vulnerability

2019-09-09 KENNETH 0

USN-4125-1: Memcached vulnerability memcached vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Memcached could be made to expose sensitive information if it received a specially crafted UNIX socket. Software Description memcached – high-performance memory object caching system Details It was discovered that Memcached incorrectly handled certain UNIX sockets. An attacker could possibly use this issue to access sensitive information. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 memcached – 1.5.10-0ubuntu1.19.04.2 Ubuntu 18.04 LTS memcached – 1.5.6-0ubuntu1.2 Ubuntu 16.04 LTS memcached – 1.4.25-2ubuntu1.5 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-15026 Source: USN-4125-1: Memcached vulnerability

No Image

USN-4124-1: Exim vulnerability

2019-09-06 KENNETH 0

USN-4124-1: Exim vulnerability exim4 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Exim could be made to run programs as an administrator if it received specially crafted network traffic. Software Description exim4 – Exim is a mail transport agent Details It was discovered that Exim incorrectly handled certain decoding operations. A remote attacker could possibly use this issue to execute arbitrary commands. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 exim4-daemon-heavy – 4.92-4ubuntu1.3 exim4-daemon-light – 4.92-4ubuntu1.3 Ubuntu 18.04 LTS exim4-daemon-heavy – 4.90.1-1ubuntu1.4 exim4-daemon-light – 4.90.1-1ubuntu1.4 Ubuntu 16.04 LTS exim4-daemon-heavy – 4.86.2-2ubuntu2.5 exim4-daemon-light – 4.86.2-2ubuntu2.5 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-15846 [ more… ]

No Image

USN-4123-1: npm/fstream vulnerability

2019-09-05 KENNETH 0

USN-4123-1: npm/fstream vulnerability npm/fstream vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Summary npm/fstream could be made to overwrite files. Software Description node-fstream – Advanced filesystem streaming tools for Node.js Details It was discovered that npm/fstream incorrectly handled certain crafted tarballs. An attacker could use this vulnerability to write aritrary files to the filesystem. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 node-fstream – 1.0.10-1ubuntu0.19.04.2 Ubuntu 18.04 LTS node-fstream – 1.0.10-1ubuntu0.18.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-13173 Source: USN-4123-1: npm/fstream vulnerability

No Image

USN-4122-1: Firefox vulnerabilities

2019-09-05 KENNETH 0

USN-4122-1: Firefox vulnerabilities firefox vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description firefox – Mozilla Open Source web browser Details Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to obtain sensitive information, bypass Content Security Policy (CSP) protections, bypass same-origin restrictions, conduct cross-site scripting (XSS) attacks, cause a denial of service, or execute arbitrary code. (CVE-2019-5849, CVE-2019-11734, CVE-2019-11735, CVE-2019-11737, CVE-2019-11738, CVE-2019-11740, CVE-2019-11742, CVE-2019-11743, CVE-2019-11744, CVE-2019-11746, CVE-2019-11748, CVE-2019-11749, CVE-2019-11750, CVE-2019-11752) It was discovered that a compromised content process could log in to a malicious Firefox Sync account. An attacker could potentially [ more… ]

No Image

USN-4121-1: Samba vulnerability

2019-09-04 KENNETH 0

USN-4121-1: Samba vulnerability samba vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Summary Samba would allow unintended access to files over the network. Software Description samba – SMB/CIFS file, print, and login server for Unix Details Stefan Metzmacher discovered that the Samba SMB server did not properly prevent clients from escaping outside the share root directory in some situations. An attacker could use this to gain access to files outside of the Samba share, where allowed by the permissions of the underlying filesystem. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 samba – 2:4.10.0+dfsg-0ubuntu2.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-10197 Source: USN-4121-1: Samba vulnerability