No Image

USN-3930-2: Linux kernel (HWE) vulnerabilities

2019-04-03 KENNETH 0

USN-3930-2: Linux kernel (HWE) vulnerabilities linux-hwe, linux-azure vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Summary Several security issues were fixed in the Linux kernel. Software Description linux-azure – Linux kernel for Microsoft Azure Cloud systems linux-hwe – Linux hardware enablement (HWE) kernel Details USN-3930-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.10. This update provides the corresponding updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu 18.10 for Ubuntu 18.04 LTS. Mathias Payer and Hui Peng discovered a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) subsystem. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2018-19824) Shlomi Oberman, Yuli Shapiro, and Ran Menscher discovered an information leak in the Bluetooth implementation of the Linux kernel. An attacker within Bluetooth range could use [ more… ]

No Image

USN-3930-1: Linux kernel vulnerabilities

2019-04-03 KENNETH 0

USN-3930-1: Linux kernel vulnerabilities linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-raspi2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Summary Several security issues were fixed in the Linux kernel. Software Description linux – Linux kernel linux-aws – Linux kernel for Amazon Web Services (AWS) systems linux-azure – Linux kernel for Microsoft Azure Cloud systems linux-gcp – Linux kernel for Google Cloud Platform (GCP) systems linux-kvm – Linux kernel for cloud environments linux-raspi2 – Linux kernel for Raspberry Pi 2 Details Mathias Payer and Hui Peng discovered a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) subsystem. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2018-19824) Shlomi Oberman, Yuli Shapiro, and Ran Menscher discovered an information leak in the Bluetooth implementation of the Linux kernel. An attacker within [ more… ]

No Image

USN-3929-1: Firebird vulnerabilities

2019-04-02 KENNETH 0

USN-3929-1: Firebird vulnerabilities firebird2.5 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in Firebird. Software Description firebird2.5 – A full-featured, open source SQL database derived from Borland InterBase 6.0 Details It was discovered that Firebird incorrectly handled certain malformed packets. A remote attacker could possibly use this issue with a specially crafted network packet to cause Firebird to crash, resulting in a denial of service. (CVE-2014-9323) It was discovered that Firebird incorrectly handled certain UDF libraries. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2017-6369) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS firebird2.5-classic – 2.5.2.26540.ds4-9ubuntu1.1 firebird2.5-classic-common – 2.5.2.26540.ds4-9ubuntu1.1 firebird2.5-server-common – 2.5.2.26540.ds4-9ubuntu1.1 firebird2.5-super – 2.5.2.26540.ds4-9ubuntu1.1 firebird2.5-superclassic – 2.5.2.26540.ds4-9ubuntu1.1 libfbclient2 – 2.5.2.26540.ds4-9ubuntu1.1 libfbembed2.5 [ more… ]

No Image

USN-3928-1: Dovecot vulnerability

2019-04-01 KENNETH 0

USN-3928-1: Dovecot vulnerability dovecot vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Dovecot could be made to crash or run programs as an administrator if it opened a specially crafted file. Software Description dovecot – IMAP and POP3 email server Details It was discovered that Dovecot incorrectly handled reading certain headers from the index. A local attacker could possibly use this issue to escalate privileges. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10 dovecot-core – 1:2.3.2.1-1ubuntu3.2 Ubuntu 18.04 LTS dovecot-core – 1:2.2.33.2-1ubuntu4.3 Ubuntu 16.04 LTS dovecot-core – 1:2.2.22-1ubuntu2.10 Ubuntu 14.04 LTS dovecot-core – 1:2.2.9-1ubuntu2.6 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary [ more… ]

No Image

USN-3926-1: GPAC vulnerabilities

2019-03-29 KENNETH 0

USN-3926-1: GPAC vulnerabilities gpac vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary GPAC could be made to crash or run programs as your login if it opened a specially crafted file. Software Description gpac – GPAC Project on Advanced Content Details It was discovered that the GPAC MP4Box utility incorrectly handled certain memory operations. If an user or automated system were tricked into opening a specially crafted MP4 file, a remote attacker could use this issue to cause MP4Box to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10 gpac – 0.5.2-426-gc5ad4e4+dfsg5-4ubuntu0.1 gpac-modules-base – 0.5.2-426-gc5ad4e4+dfsg5-4ubuntu0.1 libgpac4 – 0.5.2-426-gc5ad4e4+dfsg5-4ubuntu0.1 Ubuntu 18.04 LTS gpac – 0.5.2-426-gc5ad4e4+dfsg5-3ubuntu0.1 gpac-modules-base – [ more… ]