No Image

USN-3124-1: Firefox vulnerabilities

2016-11-19 KENNETH 0

USN-3124-1: Firefox vulnerabilities Ubuntu Security Notice USN-3124-1 18th November, 2016 firefox vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Firefox could be made to crash or run programs as your login if it opened a malicious website. Software description firefox – Mozilla Open Source web browser Details Christian Holler, Andrew McCreight, Dan Minor, Tyson Smith, Jon Coppeard,Jan-Ivar Bruaroey, Jesse Ruderman, Markus Stange, Olli Pettay, EhsanAkhgari, Gary Kwong, Tooru Fujisawa, and Randell Jesup discovered multiplememory safety issues in Firefox. If a user were tricked in to opening aspecially crafted website, an attacker could potentially exploit these tocause a denial of service via application crash, or execute arbitrarycode. (CVE-2016-5289, CVE-2016-5290) A same-origin policy bypass was discovered with local HTML files in somecircumstances. An attacker could potentially [ more… ]

No Image

USN-3130-1: OpenJDK 7 vulnerabilities

2016-11-18 KENNETH 0

USN-3130-1: OpenJDK 7 vulnerabilities Ubuntu Security Notice USN-3130-1 17th November, 2016 openjdk-7 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in XXX-APP-XXX. Software description openjdk-7 – Open Source Java implementation Details It was discovered that OpenJDK did not restrict the set of algorithms usedfor Jar integrity verification. An attacker could use this to modifywithout detection the content of a JAR file, affecting system integrity.(CVE-2016-5542) It was discovered that the JMX component of OpenJDK did not sufficientlyperform classloader consistency checks. An attacker could use this tobypass Java sandbox restrictions. (CVE-2016-5554) It was discovered that the Hotspot component of OpenJDK did not properlycheck received Java Debug Wire Protocol (JDWP) packets. An attacker coulduse this to send debugging commands to a Java application with debuggingenabled. (CVE-2016-5573) It was discovered that [ more… ]

No Image

USN-3128-1: Linux kernel vulnerability

2016-11-11 KENNETH 0

USN-3128-1: Linux kernel vulnerability Ubuntu Security Notice USN-3128-1 11th November, 2016 linux vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary The system could be made to crash under certain conditions. Software description linux – Linux kernel Details Ondrej Kozina discovered that the keyring interface in the Linux kernelcontained a buffer overflow when displaying timeout events via the/proc/keys interface. A local attacker could use this to cause a denial ofservice (system crash). Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: linux-image-4.4.0-47-powerpc64-emb 4.4.0-47.68 linux-image-powerpc-e500mc 4.4.0.47.50 linux-image-4.4.0-47-lowlatency 4.4.0-47.68 linux-image-4.4.0-47-powerpc64-smp 4.4.0-47.68 linux-image-4.4.0-47-generic 4.4.0-47.68 linux-image-4.4.0-47-powerpc-smp 4.4.0-47.68 linux-image-powerpc-smp 4.4.0.47.50 linux-image-generic-lpae 4.4.0.47.50 linux-image-powerpc64-emb 4.4.0.47.50 linux-image-virtual 4.4.0.47.50 linux-image-4.4.0-47-generic-lpae 4.4.0-47.68 linux-image-generic 4.4.0.47.50 linux-image-lowlatency 4.4.0.47.50 linux-image-4.4.0-47-powerpc-e500mc 4.4.0-47.68 linux-image-powerpc64-smp 4.4.0.47.50 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard [ more… ]

No Image

USN-3127-2: Linux kernel (Trusty HWE) vulnerabilities

2016-11-11 KENNETH 0

USN-3127-2: Linux kernel (Trusty HWE) vulnerabilities Ubuntu Security Notice USN-3127-2 11th November, 2016 linux-lts-trusty vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in the kernel. Software description linux-lts-trusty – Linux hardware enablement kernel from Trusty for Precise Details USN-3127-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04LTS. This update provides the corresponding updates for the LinuxHardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu12.04 LTS. It was discovered that the compression handling code in the Advanced LinuxSound Architecture (ALSA) subsystem in the Linux kernel did not properlycheck for an integer overflow. A local attacker could use this to cause adenial of service (system crash). (CVE-2014-9904) Kirill A. Shutemov discovered that memory manager in the Linux kernel didnot properly handle anonymous pages. A local attacker could [ more… ]

No Image

USN-3127-1: Linux kernel vulnerabilities

2016-11-11 KENNETH 0

USN-3127-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3127-1 11th November, 2016 linux vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in the kernel. Software description linux – Linux kernel Details It was discovered that the compression handling code in the Advanced LinuxSound Architecture (ALSA) subsystem in the Linux kernel did not properlycheck for an integer overflow. A local attacker could use this to cause adenial of service (system crash). (CVE-2014-9904) Kirill A. Shutemov discovered that memory manager in the Linux kernel didnot properly handle anonymous pages. A local attacker could use this tocause a denial of service or possibly gain administrative privileges.(CVE-2015-3288) Vitaly Kuznetsov discovered that the Linux kernel did not properly suppresshugetlbfs support in X86 paravirtualized guests. An attacker in the guestOS could cause a denial [ more… ]