No Image

USN-3462-1: Pacemaker vulnerabilities

2017-10-24 KENNETH 0

USN-3462-1: Pacemaker vulnerabilities Ubuntu Security Notice USN-3462-1 24th October, 2017 pacemaker vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Pacemaker. Software description pacemaker – Cluster resource manager Details Jan Pokorný and Alain Moulle discovered that Pacemaker incorrectly handledthe IPC interface. A local attacker could possibly use this issue toexecute arbitrary code with root privileges. (CVE-2016-7035) Alain Moulle discovered that Pacemaker incorrectly handled authentication.A remote attacker could possibly use this issue to shut down connections,leading to a denial of service. This issue only affected Ubuntu 16.04 LTS.(CVE-2016-7797) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: pacemaker 1.1.14-2ubuntu1.2 Ubuntu 14.04 LTS: pacemaker 1.1.10+git20130802-1ubuntu2.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, [ more… ]

No Image

USN-3454-2: libffi vulnerability

2017-10-24 KENNETH 0

USN-3454-2: libffi vulnerability Ubuntu Security Notice USN-3454-2 24th October, 2017 libffi vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary A security issue was fixed in libffi. Software description libffi – Foreign Function Interface library (development files, 32bit) Details USN-3454-1 fixed a vulnerability in libffi. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that libffi incorrectly enforced an executable stack. An attacker could possibly use this issue, in combination with another vulnerability, to facilitate executing arbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: libffi6 3.0.11~rc1-5ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2017-1000376 Source: USN-3454-2: libffi vulnerability

No Image

USN-3434-2: Libidn vulnerability

2017-10-24 KENNETH 0

USN-3434-2: Libidn vulnerability Ubuntu Security Notice USN-3434-2 23rd October, 2017 libidn vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Libidn could be made to crash or run programs if it processed specially crafted input. Software description libidn – implementation of IETF IDN specifications Details USN-3434-1 fixed a vulnerability in Libidn. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that Libidn incorrectly handled decoding certain digits. A remote attacker could use this issue to cause Libidn to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: libidn11 1.23-2ubuntu0.2 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will [ more… ]

No Image

USN-3441-2: curl vulnerabilities

2017-10-24 KENNETH 0

USN-3441-2: curl vulnerabilities Ubuntu Security Notice USN-3441-2 23rd October, 2017 curl vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in curl. Software description curl – HTTP, HTTPS, and FTP client and client libraries Details USN-3441-1 fixed several vulnerabilities in curl. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: Daniel Stenberg discovered that curl incorrectly handled large floating point output. A remote attacker could use this issue to cause curl to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2016-9586) Even Rouault discovered that curl incorrectly handled large file names when doing TFTP transfers. A remote attacker could use this issue to cause curl to crash, resulting in a denial of service, or possibly obtain sensitive memory contents. (CVE-2017-1000100) Brian [ more… ]

No Image

USN-3458-2: ICU vulnerability

2017-10-24 KENNETH 0

USN-3458-2: ICU vulnerability Ubuntu Security Notice USN-3458-2 23rd October, 2017 icu vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary ICU could be made to crash or run arbitrary code as your login if it received specially crafted input. Software description icu – International Components for Unicode library Details USN-3458-1 fixed a vulnerability in ICU. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that ICU incorrectly handled certain inputs. If an application using ICU processed crafted data, a remote attacker could possibly cause it to crash or potentially execute arbitrary code with the privileges of the user invoking the program. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: libicu48 4.8.1.1-3ubuntu0.9 lib32icu48 4.8.1.1-3ubuntu0.9 To update your [ more… ]