Ubuntu 6937 Published by Philipp Esselbach 0

The following updates has been released for Ubuntu Linux:

USN-3678-3: Linux kernel (Azure) vulnerabilities
This update addresses 3 security issues in the Linux kernel for Microsoft Azure Cloud systems. Available for Ubuntu Linux 18.04 LTS

USN-3679-1: QEMU update
Ken Johnson and Jann Horn independently discovered that microprocessors utilizing speculative execution of a memory read may allow unauthorized memory reads via sidechannel attacks. Available for Ubuntu Linux 14.04 LTS, 16.04 LTS, 17.10, and 18.04 LTS

USN-3680-1: libvirt vulnerability and update
This update adds Side channel execution mitigations to libvirt. Available for Ubuntu 14.04 LTS, 16.04 LTS, 17.10, and 18.04 LTS

USN-3681-1: ImageMagick vulnerabilities
This update fixes several security issues in ImageMagick. Available for Ubuntu 14.04 LTS, 16.04 LTS, 17.10, and 18.04 LTS

USN-3682-1: Firefox vulnerability
This update addresses an issue where Firefox could or run programs as your login if it opened a malicious website. Available for Ubuntu 14.04 LTS, 16.04 LTS, 17.10, and 18.04 LTS

Ubuntu 6937 Published by Philipp Esselbach 0

Ralph Dolmans and Karst Koymans discovered that Unbound did not properly handle certain NSEC records. An attacker could use this to to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick Unbound into accepting a NODATA proof. Updated unbound packages now available for Ubuntu 18.04 LTS, 17.10, 16.04 LTS, and 14.04 LTS

Ubuntu 6937 Published by Philipp Esselbach 0

The following updates has been released for Ubuntu Linux:

USN-3658-2: procps-ng vulnerabilities
This address two security issues: 1) It was discovered that libprocps incorrectly handled the file2strvec() function. A local attacker could possibly use this to execute
 arbitrary code. (CVE-2018-1124). 2) It was discovered that procps-ng incorrectly handled memory. A local attacker could use this issue to cause a denial of service, or
 possibly execute arbitrary code. (CVE-2018-1126)

This update is available for Ubuntu Linux 12.04 ESM

USN-3671-1: Git vulnerabilities
This address twe security issues: 1) A remote attacker could possibly use this to craft a git repo that causes arbitrary code execution when "git clone --recurse-submodules" is used. (CVE-2018-11235). 2) An attacker could use this to cause a denial of service or expose sensitive information. (CVE-2018-11233)

This update is available for Ubuntu Linux 14.04 LTS, 16.04 LTS, 17.10, and 18.04 LTS

USN-3672-1: Liblouis vulnerabilities
Henri Salo discovered that Liblouis incorrectly handled certain files. An attacker could possibly use this to execute arbitrary code.

This update is available for Ubuntu Linux 14.04 LTS, 16.04 LTS, 17.10, and 18.04 LTS

Ubuntu 6937 Published by Philipp Esselbach 0

Updated elfutils packages has been released for both Ubuntu 14.04 LTS and 16.04 LTS. This addresses an issue where elfutils could be made to crash or consume resources if it opened a specially crafted file.

Ubuntu 6937 Published by Philipp Esselbach 0

The following updates has been released for Ubuntu Linux:

USN-3664-2: Apport vulnerability
Sander Bos reported that Ubuntu 14.04 LTS was also vulnerable to this issue, but was incorrectly omitted from the previous updates. This update provides the corresponding update
for Ubuntu 14.04 LTS.

USN-3669-1: Liblouis vulnerabilities
It was discovered that Liblouis incorrectly handled certain files. 1) An attacker could possibly use this to cause a denial of service. Ubuntu 18.04 LTS only (CVE-2018-11410). 2) An attacker could possibly use this to execute arbitrary code. (CVE-2018-11440). 3) An attacker could possibly use this to cause a denial of service or execute arbitrary code. (CVE-2018-11577).

Updated packages are available for Ubuntu Linux 14.04 LTS, 16.04 LTS, 17.10, and 18.04 LTS

Ubuntu 6937 Published by Philipp Esselbach 0

It was discovered that Exempi incorrectly handled certain media files. If a user or automated system were tricked into opening a specially crafted file, a remote attacker could cause Exempi to hang or crash, resulting in a denial of service, or possibly execute arbitrary code.

Updated packages are now available for Ubuntu Linux 14.04 LTS, 16.04 LTS, and 17.10