No Image

USN-3814-3: ClamAV vulnerabilities

2018-11-13 KENNETH 0

USN-3814-3: ClamAV vulnerabilities clamav vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 ESM Summary Several security issues were fixed in ClamAV. Software Description clamav – Anti-virus utility for Unix Details USN-3814-2 fixed several vulnerabilities in clamav. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered ClamAV incorrectly handled certain malformed CAB files. A remote attacker could use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2018-18584, CVE-2018-18585) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM clamav – 0.100.2+dfsg-1ubuntu0.12.04.2 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References USN-3814-1 CVE-2018-18584 CVE-2018-18585 Source: USN-3814-3: ClamAV vulnerabilities

No Image

USN-3814-2: ClamAV vulnerabilities

2018-11-13 KENNETH 0

USN-3814-2: ClamAV vulnerabilities clamav vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in ClamAV. Software Description clamav – Anti-virus utility for Unix Details USN-3814-1 fixed several vulnerabilities in libmspack. In Ubuntu 14.04 libmspack is included into ClamAV. This update provides the corresponding update for Ubuntu 14.04 LTS. Original advisory details: It was discovered libmspack incorrectly handled certain malformed CAB files. A remote attacker could use this issue to cause libmspack to crash, resulting in a denial of service. (CVE-2018-18584, CVE-2018-18585) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS clamav – 0.100.2+dfsg-1ubuntu0.14.04.2 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References USN-3814-1 CVE-2018-18584 CVE-2018-18585 [ more… ]

No Image

USN-3816-1: systemd vulnerabilities

2018-11-13 KENNETH 0

USN-3816-1: systemd vulnerabilities systemd vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in systemd. Software Description systemd – system and service manager Details Jann Horn discovered that unit_deserialize incorrectly handled status messages above a certain length. A local attacker could potentially exploit this via NotifyAccess to inject arbitrary state across re-execution and obtain root privileges. (CVE-2018-15686) Jann Horn discovered a race condition in chown_one(). A local attacker could potentially exploit this by setting arbitrary permissions on certain files to obtain root privileges. This issue only affected Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-15687) It was discovered that systemd-tmpfiles mishandled symlinks in non-terminal path components. A local attacker could potentially exploit this by gaining ownership of certain files to obtain root privileges. This [ more… ]

No Image

USN-3815-2: gettext vulnerability

2018-11-12 KENNETH 0

USN-3815-2: gettext vulnerability gettext vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 ESM Summary gettext could be made to execute arbitrary code if it received a specially crafted message. Software Description gettext – GNU Internationalization utilities Details USN-3815-1 fixed a vulnerability in gettext. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that gettext incorrectly handled certain messages. An attacker could possibly use this issue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM gettext – 0.18.1.1-5ubuntu3.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References USN-3815-1 CVE-2018-18751 Source: USN-3815-2: gettext vulnerability

No Image

USN-3815-1: gettext vulnerability

2018-11-12 KENNETH 0

USN-3815-1: gettext vulnerability gettext vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary gettext could be made to execute arbitrary code if it received a specially crafted message. Software Description gettext – GNU Internationalization utilities Details It was discovered that gettext incorrectly handled certain messages. An attacker could possibly use this issue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10 gettext – 0.19.8.1-8ubuntu0.1 Ubuntu 18.04 LTS gettext – 0.19.8.1-6ubuntu0.1 Ubuntu 16.04 LTS gettext – 0.19.7-2ubuntu3.1 Ubuntu 14.04 LTS gettext – 0.18.3.1-1ubuntu3.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2018-18751 Source: USN-3815-1: gettext vulnerability