No Image

USN-3547-1: Libtasn1 vulnerabilities

2018-01-26 KENNETH 0

USN-3547-1: Libtasn1 vulnerabilities Ubuntu Security Notice USN-3547-1 25th January, 2018 libtasn1-6 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Libtasn1. Software description libtasn1-6 – Library to manage ASN.1 structures Details It was discovered that Libtasn1 incorrectly handled certain files.If a user were tricked into opening a crafted file, an attacker could possiblyuse this to cause a denial of service. This issue only affected Ubuntu 14.04LTS and Ubuntu 16.04 LTS. (CVE-2017-10790) It was discovered that Libtasn1 incorrectly handled certain inputs.An attacker could possibly use this to cause Libtasn1 to hang, resultingin a denial of service. This issue only affected Ubuntu 16.04 LTS andUbuntu 17.10. (CVE-2018-6003) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu [ more… ]

No Image

USN-3537-2: MySQL vulnerabilities

2018-01-25 KENNETH 0

USN-3537-2: MySQL vulnerabilities Ubuntu Security Notice USN-3537-2 25th January, 2018 mysql-5.5 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in MySQL. Software description mysql-5.5 – MySQL database Details USN-3537-1 fixed vulnerabilities in MySQL. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 5.5.59 in Ubuntu 12.04 ESM LTS. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-59.html http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: mysql-server-5.5 5.5.59-0ubuntu0.12.04.1 To update your system, please [ more… ]

No Image

USN-3544-1: Firefox vulnerabilities

2018-01-25 KENNETH 0

USN-3544-1: Firefox vulnerabilities Ubuntu Security Notice USN-3544-1 24th January, 2018 firefox vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Firefox could be made to crash or run programs as your login if it opened a malicious website. Software description firefox – Mozilla Open Source web browser Details Multiple security issues were discovered in Firefox. If a user weretricked in to opening a specially crafted website, an attacker couldpotentially exploit these to cause a denial of service via applicationcrash, spoof the origin in audio capture prompts, trick the user in toproviding HTTP credentials for another origin, spoof the addressbarcontents, or execute arbitrary code. (CVE-2018-5089, CVE-2018-5090,CVE-2018-5091, CVE-2018-5092, CVE-2018-5093, CVE-2018-5094, CVE-2018-5095,CVE-2018-5097, CVE-2018-5098, CVE-2018-5099, CVE-2018-5100, CVE-2018-5101,CVE-2018-5102, CVE-2018-5103, CVE-2018-5104, CVE-2018-5109, CVE-2018-5114,CVE-2018-5115, CVE-2018-5117, CVE-2018-5122) Multiple security issues were discovered in WebExtensions. If a [ more… ]

No Image

USN-3546-1: gcab vulnerability

2018-01-25 KENNETH 0

USN-3546-1: gcab vulnerability Ubuntu Security Notice USN-3546-1 24th January, 2018 gcab vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Summary gcab could be made to crash or run programs if it opened a specially crafted file. Software description gcab – Microsoft Cabinet file manipulation tool Details Richard Hughes discovered that gcab incorrectly handled certain malformedcabinet files. If a user or automated system were tricked into opening aspecially crafted cabinet file, a remote attacker could use this issue tocause gcab to crash, resulting in a denial of service, or possibly executearbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: libgcab-1.0-0 0.7-4ubuntu0.1 gcab 0.7-4ubuntu0.1 Ubuntu 16.04 LTS: libgcab-1.0-0 0.7-1ubuntu0.1 gcab 0.7-1ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a [ more… ]

No Image

USN-3531-2: Intel Microcode regression

2018-01-24 KENNETH 0

USN-3531-2: Intel Microcode regression Ubuntu Security Notice USN-3531-2 22nd January, 2018 intel-microcode regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary USN-3531-1 introduced regressions in intel-microcode. Software description intel-microcode – Processor microcode for Intel CPUs Details USN-3531-1 updated Intel microcode to the 20180108 release. Regressionswere discovered in the microcode updates which could cause systeminstability on certain hardware platforms. At the request of Intel, we havereverted to the previous packaged microcode version, the 20170707 release. Original advisory details: It was discovered that microprocessors utilizing speculative execution and branch prediction may allow unauthorized memory reads via sidechannel attacks. This flaw is known as Spectre. A local attacker could use this to expose sensitive information, including kernel memory. (CVE-2017-5715) This update provides the microcode updates required for the corresponding Linux kernel [ more… ]