No Image

USN-3477-3: Firefox regressions

2017-12-02 KENNETH 0

USN-3477-3: Firefox regressions Ubuntu Security Notice USN-3477-3 1st December, 2017 firefox regressions A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary USN-3477-1 caused some minor regressions in Firefox. Software description firefox – Mozilla Open Source web browser Details USN-3477-1 fixed vulnerabilities in Firefox. The update introduced variousminor regressions. This update fixes the problems. We apologize for the inconvenience. Original advisory details: Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, read uninitialized memory, obtain sensitive information, bypass same-origin restrictions, bypass CSP protections, bypass mixed content blocking, spoof the addressbar, or execute arbitrary code. (CVE-2017-7826, CVE-2017-7827, CVE-2017-7828, CVE-2017-7830, CVE-2017-7831, CVE-2017-7832, CVE-2017-7833, CVE-2017-7834, CVE-2017-7835, CVE-2017-7837, CVE-2017-7838, CVE-2017-7842) [ more… ]

No Image

USN-3490-1: Thunderbird vulnerabilities

2017-12-01 KENNETH 0

USN-3490-1: Thunderbird vulnerabilities Ubuntu Security Notice USN-3490-1 1st December, 2017 thunderbird vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Thunderbird. Software description thunderbird – Mozilla Open Source mail and newsgroup client Details Multiple security issues were discovered in Thunderbird. If a user weretricked in to opening a specially crafted website in a browsing-likecontext, an attacker could potentially exploit these to bypass same-originrestrictions, cause a denial of service via application crash, or executearbitrary code. (CVE-2017-7826, CVE-2017-7828, CVE-2017-7830) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: thunderbird 1:52.5.0+build1-0ubuntu0.17.10.1 Ubuntu 17.04: thunderbird 1:52.5.0+build1-0ubuntu0.17.04.1 Ubuntu 16.04 LTS: thunderbird 1:52.5.0+build1-0ubuntu0.16.04.1 Ubuntu 14.04 LTS: thunderbird 1:52.5.0+build1-0ubuntu0.14.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. [ more… ]

No Image

USN-3500-1: libXfont vulnerability

2017-11-30 KENNETH 0

USN-3500-1: libXfont vulnerability Ubuntu Security Notice USN-3500-1 29th November, 2017 libxfont, libxfont1, libxfont2 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary libXfont could be made to access arbitrary files, including special device files. Software description libxfont – X11 font rasterisation library libxfont1 – X11 font rasterisation library libxfont2 – X11 font rasterisation library Details It was discovered that libXfont incorrectly followed symlinks when openingfont files. A local unprivileged user could use this issue to cause the Xserver to access arbitrary files, including special device files. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: libxfont1 1:1.5.2-4ubuntu1.1 libxfont2 1:2.0.1-3ubuntu1.1 Ubuntu 17.04: libxfont1 1:1.5.2-4ubuntu0.2 libxfont2 1:2.0.1-3ubuntu0.2 Ubuntu 16.04 LTS: libxfont1 1:1.5.1-1ubuntu0.16.04.4 libxfont2 1:2.0.1-3~ubuntu16.04.3 Ubuntu 14.04 LTS: libxfont1 1:1.4.7-1ubuntu0.4 [ more… ]

No Image

USN-3499-1: Exim vulnerability

2017-11-30 KENNETH 0

USN-3499-1: Exim vulnerability Ubuntu Security Notice USN-3499-1 29th November, 2017 exim4 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 17.04 Summary Exim could be made to crash if it received specially crafted network traffic. Software description exim4 – Exim is a mail transport agent Details It was discovered that Exim incorrectly handled certain BDAT data headers.A remote attacker could possibly use this issue to cause Exim to crash,resulting in a denial of service. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: exim4-daemon-heavy 4.89-5ubuntu1.2 exim4-daemon-light 4.89-5ubuntu1.2 Ubuntu 17.04: exim4-daemon-heavy 4.88-5ubuntu1.3 exim4-daemon-light 4.88-5ubuntu1.3 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2017-16944 Source: USN-3499-1: Exim vulnerability

No Image

USN-3501-1: libxcursor vulnerability

2017-11-30 KENNETH 0

USN-3501-1: libxcursor vulnerability Ubuntu Security Notice USN-3501-1 29th November, 2017 libxcursor vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary libxcursor could be made to crash or run programs if it opened a specially crafted file. Software description libxcursor – X11 cursor management library Details It was discovered that libxcursor incorrectly handled certain files. Anattacker could use these issues to cause libxcursor to crash, resulting ina denial of service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: libxcursor1 1:1.1.14-3ubuntu0.1 Ubuntu 17.04: libxcursor1 1:1.1.14-1ubuntu0.17.04.1 Ubuntu 16.04 LTS: libxcursor1 1:1.1.14-1ubuntu0.16.04.1 Ubuntu 14.04 LTS: libxcursor1 1:1.1.14-1ubuntu0.14.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to reboot [ more… ]