No Image

USN-6046-1: OpenSSL-ibmca vulnerabilities

2023-04-27 KENNETH 0

USN-6046-1: OpenSSL-ibmca vulnerabilities It was discovered that OpenSSL-ibmca incorrectly handled certain RSA decryption. An attacker could possibly use this issue to expose sensitive information. Source: USN-6046-1: OpenSSL-ibmca vulnerabilities

No Image

USN-6042-1: Cloud-init vulnerability

2023-04-27 KENNETH 0

USN-6042-1: Cloud-init vulnerability James Glovich discovered that sensitive data could be exposed in logs. An attacker could use this information to find hashed passwords and possibly escalate their privilege. Source: USN-6042-1: Cloud-init vulnerability

No Image

USN-6017-2: Ghostscript vulnerability

2023-04-27 KENNETH 0

USN-6017-2: Ghostscript vulnerability USN-6017-1 fixed vulnerabilities in Ghostscript. This update provides the corresponding updates for Ubuntu 23.04. Original advisory details: Hadrien Perrineau discovered that Ghostscript incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary code. Source: USN-6017-2: Ghostscript vulnerability

No Image

USN-6045-1: Linux kernel vulnerabilities

2023-04-27 KENNETH 0

USN-6045-1: Linux kernel vulnerabilities It was discovered that the Traffic-Control Index (TCINDEX) implementation in the Linux kernel did not properly perform filter deactivation in some situations. A local attacker could possibly use this to gain elevated privileges. Please note that with the fix for this CVE, kernel support for the TCINDEX classifier has been removed. (CVE-2023-1829) Gwnaun Jung discovered that the SFB packet scheduling implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3586) Zheng Wang and Zhuorao Yang discovered that the RealTek RTL8712U wireless driver in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-4095) It was discovered that the TIPC protocol [ more… ]

No Image

USN-6044-1: Linux kernel vulnerabilities

2023-04-27 KENNETH 0

USN-6044-1: Linux kernel vulnerabilities It was discovered that the Traffic-Control Index (TCINDEX) implementation in the Linux kernel did not properly perform filter deactivation in some situations. A local attacker could possibly use this to gain elevated privileges. Please note that with the fix for this CVE, kernel support for the TCINDEX classifier has been removed. (CVE-2023-1829) It was discovered that a race condition existed in the io_uring subsystem in the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-1872) Source: USN-6044-1: Linux kernel vulnerabilities