No Image

USN-3179-1: OpenJDK 8 vulnerabilities

2017-01-26 KENNETH 0

USN-3179-1: OpenJDK 8 vulnerabilities Ubuntu Security Notice USN-3179-1 25th January, 2017 openjdk-8 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Summary Several security issues were fixed in OpenJDK 8. Software description openjdk-8 – Open Source Java implementation Details Karthik Bhargavan and Gaetan Leurent discovered that the DES andTriple DES ciphers were vulnerable to birthday attacks. A remoteattacker could possibly use this flaw to obtain clear text data fromlong encrypted sessions. This update moves those algorithms to thelegacy algorithm set and causes them to be used only if no non-legacyalgorithms can be negotiated. (CVE-2016-2183) It was discovered that OpenJDK accepted ECSDA signatures usingnon-canonical DER encoding. An attacker could use this to modify orexpose sensitive data. (CVE-2016-5546) It was discovered that OpenJDK did not properly verify objectidentifier (OID) length when reading Distinguished Encoding [ more… ]

No Image

USN-3178-1: icoutils vulnerabilities

2017-01-25 KENNETH 0

USN-3178-1: icoutils vulnerabilities Ubuntu Security Notice USN-3178-1 24th January, 2017 icoutils vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary icoutils could be made to crash or run programs as your login if it opened a specially crafted file. Software description icoutils – Create and extract MS Windows icons and cursors Details It was discovered that icoutils incorrectly handled memory when processingcertain files. If a user or automated system were tricked into opening aspecially crafted file, an attacker could cause icoutils to crash,resulting in a denial of service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: icoutils 0.29.1-2ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the [ more… ]

No Image

USN-3177-1: Tomcat vulnerabilities

2017-01-24 KENNETH 0

USN-3177-1: Tomcat vulnerabilities Ubuntu Security Notice USN-3177-1 23rd January, 2017 tomcat6, tomcat7, tomcat8 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in Tomcat. Software description tomcat6 – Servlet and JSP engine tomcat7 – Servlet and JSP engine tomcat8 – Servlet and JSP engine Details It was discovered that the Tomcat realm implementations incorrectly handledpasswords when a username didn't exist. A remote attacker could possiblyuse this issue to enumerate usernames. This issue only applied to Ubuntu12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-0762) Alvaro Munoz and Alexander Mirosh discovered that Tomcat incorrectlylimited use of a certain utility method. A malicious application couldpossibly use this to bypass Security Manager restrictions. This issue onlyapplied to Ubuntu 12.04 LTS, Ubuntu 14.04 [ more… ]

No Image

USN-3176-1: PCSC-Lite vulnerability

2017-01-24 KENNETH 0

USN-3176-1: PCSC-Lite vulnerability Ubuntu Security Notice USN-3176-1 23rd January, 2017 pcsc-lite vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary PCSC-Lite could be made to crash or run programs as an administrator if it received specially crafted input. Software description pcsc-lite – Middleware to access a smart card using PC/SC Details Peter Wu discovered that the PC/SC service did not correctly handle certainresources. A local attacker could use this issue to cause PC/SC to crash,resulting in a denial of service, or possibly execute arbitrary code withroot privileges. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.10: pcscd 1.8.14-1ubuntu1.16.10.1 Ubuntu 16.04 LTS: pcscd 1.8.14-1ubuntu1.16.04.1 Ubuntu 14.04 LTS: pcscd 1.8.10-1ubuntu1.1 Ubuntu 12.04 LTS: pcscd 1.7.4-2ubuntu2.1 To update your [ more… ]

No Image

USN-3174-1: MySQL vulnerabilities

2017-01-19 KENNETH 0

USN-3174-1: MySQL vulnerabilities Ubuntu Security Notice USN-3174-1 19th January, 2017 mysql-5.5, mysql-5.7 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in MySQL. Software description mysql-5.5 – MySQL database mysql-5.7 – MySQL database Details Multiple security issues were discovered in MySQL and this update includesnew upstream MySQL versions to fix these issues. MySQL has been updated to 5.5.54 in Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.Ubuntu 16.04 LTS and Ubuntu 16.10 have been updated to MySQL 5.7.17. In addition to security fixes, the updated packages contain bug fixes,new features, and possibly incompatible changes. Please see the following for more information:http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-54.htmlhttp://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.10: mysql-server-5.7 5.7.17-0ubuntu0.16.10.1 [ more… ]