Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Ubuntu 14.10: USN-2427-1 Critical: Libksba Denial of Service

Ubuntu Large Esm H500
Libksba could be made to crash or run programs if it opened a specially crafted file.
=========================================================================Ubuntu Security Notice USN-2427-1
November 27, 2014

libksba vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Libksba could be made to crash or run programs if it opened a specially
crafted file.

Software Description:
- libksba: X.509 and CMS support library

Details:

Hanno Böck discovered that Libksba incorrectly handled certain S/MIME
messages or ECC based OpenPGP data. An attacker could use this issue to
cause Libksba to crash, resulting in a denial of service, or possibly execute
arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.10:
  libksba8                        1.3.0-3ubuntu0.14.10.1

Ubuntu 14.04 LTS:
  libksba8                        1.3.0-3ubuntu0.14.04.1

Ubuntu 12.04 LTS:
  libksba8                        1.2.0-2ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2427-1
  CVE-2014-9087

Package Information:
  https://launchpad.net/ubuntu/+source/libksba/1.3.0-3ubuntu0.14.10.1
  https://launchpad.net/ubuntu/+source/libksba/1.3.0-3ubuntu0.14.04.1
  https://launchpad.net/ubuntu/+source/libksba/1.2.0-2ubuntu0.1


Ubuntu 14.10: USN-2427-1 Critical: Libksba Denial of Service

ubuntu
Calendar Grey November 27, 2014
Dist Ubuntu Esm H88
Ubuntu Security Alert USN-2428-1 discloses an issue in libgcrypt that may lead to system instability and possible remote code execution through specially designed inputs.
Libksba could be made to crash or run programs if it opened a specially crafted file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: libksba8 1.3.0-3ubuntu0.14.10.1 Ubuntu 14.04 LTS: libksba8 1.3.0-3ubuntu0.14.04.1 Ubuntu 12.04 LTS: libksba8 1.2.0-2ubuntu0.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2427-1

CVE-2014-9087

Severity
critical
Lowest
Low
Medium
High
Critical

November 27, 2014

Package Information

https://launchpad.net/ubuntu/+source/libksba/1.3.0-3ubuntu0.14.10.1 https://launchpad.net/ubuntu/+source/libksba/1.3.0-3ubuntu0.14.04.1 https://launchpad.net/ubuntu/+source/libksba/1.2.0-2ubuntu0.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here