No Image

USN-3321-1: Thunderbird vulnerabilities

2017-07-06 KENNETH 0

USN-3321-1: Thunderbird vulnerabilities Ubuntu Security Notice USN-3321-1 5th July, 2017 thunderbird vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Thunderbird. Software description thunderbird – Mozilla Open Source mail and newsgroup client Details Multiple security issues were discovered in Thunderbird. If a user weretricked in to opening a specially crafted website in a browsing context,an attacker could potentially exploit these to cause a denial of service,read uninitialized memory, obtain sensitive information or executearbitrary code. (CVE-2017-5470, CVE-2017-5472,CVE-2017-7749, CVE-2017-7750, CVE-2017-7751, CVE-2017-7752, CVE-2017-7754,CVE-2017-7756, CVE-2017-7757, CVE-2017-7758, CVE-2017-7764) Multiple security issues were discovered in the Graphite 2 library usedby Thunderbird. If a user were tricked in to opening a specially craftedmessage, an attacker could potentially exploit these to cause a denial ofservice, read uninitialized memory, [ more… ]

No Image

USN-3349-1: NTP vulnerabilities

2017-07-06 KENNETH 0

USN-3349-1: NTP vulnerabilities Ubuntu Security Notice USN-3349-1 5th July, 2017 ntp vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in NTP. Software description ntp – Network Time Protocol daemon and utility programs Details Yihan Lian discovered that NTP incorrectly handled certain large requestdata values. A remote attacker could possibly use this issue to cause NTPto crash, resulting in a denial of service. This issue only affectedUbuntu 16.04 LTS. (CVE-2016-2519) Miroslav Lichvar discovered that NTP incorrectly handled certain spoofedaddresses when performing rate limiting. A remote attacker could possiblyuse this issue to perform a denial of service. This issue only affectedUbuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10. (CVE-2016-7426) Matthew Van Gundy discovered that NTP incorrectly handled certain craftedbroadcast mode packets. [ more… ]

No Image

USN-3348-1: Samba vulnerability

2017-07-06 KENNETH 0

USN-3348-1: Samba vulnerability Ubuntu Security Notice USN-3348-1 5th July, 2017 samba vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Samba could be made to hang if it received specially crafted network traffic. Software description samba – SMB/CIFS file, print, and login server for Unix Details It was discovered that Samba incorrectly handled dangling symlinks. Aremote attacker could possibly use this issue to cause Samba to hang,resulting in a denial of service. This issue only applied to Ubuntu 14.04LTS and Ubuntu 16.04 LTS. (CVE-2017-9461) In addition, this update fixes a regression introduced by USN-3267-1that caused Samba to incorrectly handle non-wide symlinks to directories. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.04: samba 2:4.5.8+dfsg-0ubuntu0.17.04.3 Ubuntu 16.10: samba [ more… ]

No Image

USN-3347-1: Libgcrypt vulnerabilities

2017-07-04 KENNETH 0

USN-3347-1: Libgcrypt vulnerabilities Ubuntu Security Notice USN-3347-1 3rd July, 2017 libgcrypt11, libgcrypt20 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Libgcrypt. Software description libgcrypt11 – LGPL Crypto library libgcrypt20 – LGPL Crypto library Details Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon GrootBruinderink, Nadia Heninger, Tanja Lange, Christine van Vredendaal, andYuval Yarom discovered that Libgcrypt was susceptible to an attack viaside channels. A local attacker could use this attack to recover RSAprivate keys. (CVE-2017-7526) It was discovered that Libgcrypt was susceptible to an attack viaside channels. A local attacker could use this attack to possibly recoverEdDSA private keys. This issue only applied to Ubuntu 16.04 LTS, Ubuntu16.10 and Ubuntu 17.04. (CVE-2017-9526) Update instructions The problem can be corrected by [ more… ]

No Image

USN-3346-1: bind9 vulnerabilities

2017-06-30 KENNETH 0

USN-3346-1: bind9 vulnerabilities Ubuntu Security Notice USN-3346-1 29th June, 2017 bind9 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Bind could be made to serve incorrect information or expose sensitive information over the network. Software description bind9 – Internet Domain Name Server Details Clément Berthaux discovered that Bind did not correctly check TSIGauthentication for zone update requests. An attacker could use thisto improperly perform zone updates. (CVE-2017-3143) Clément Berthaux discovered that Bind did not correctly check TSIGauthentication for zone transfer requests. An attacker could use thisto improperly transfer entire zones. (CVE-2017-3142) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.04: bind9 1:9.10.3.dfsg.P4-10.1ubuntu5.1 Ubuntu 16.10: bind9 1:9.10.3.dfsg.P4-10.1ubuntu1.7 Ubuntu 16.04 LTS: bind9 1:9.10.3.dfsg.P4-8ubuntu1.7 Ubuntu 14.04 LTS: bind9 1:9.9.5.dfsg-3ubuntu0.15 [ more… ]