Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Fedora: 7892-2 High: GStreamer Buffer Overflow Vulnerability

Ubuntu Large Esm H500
libproxy could be made to crash or execute arbitrary code if it received a specially crafted file.
=========================================================================Ubuntu Security Notice USN-4673-1
January 04, 2021

libproxy vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

libproxy could be made to crash or execute arbitrary code if it received a specially
crafted file.

Software Description:
- libproxy: automatic proxy configuration management library

Details:

Li Fei discovered that libproxy incorrectly handled certain PAC files.
An attacker could possibly use this issue to cause a crash or execute arbitrary
code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
  libproxy1v5                     0.4.15-13ubuntu1.1

Ubuntu 20.04 LTS:
  libproxy1v5                     0.4.15-10ubuntu1.2

Ubuntu 18.04 LTS:
  libproxy1v5                     0.4.15-1ubuntu0.2

Ubuntu 16.04 LTS:
  libproxy1v5                     0.4.11-5ubuntu1.2

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4673-1
  CVE-2020-26154

Package Information:
  https://launchpad.net/ubuntu/+source/libproxy/0.4.15-13ubuntu1.1
  https://launchpad.net/ubuntu/+source/libproxy/0.4.15-10ubuntu1.2
  https://launchpad.net/ubuntu/+source/libproxy/0.4.15-1ubuntu0.2
  https://launchpad.net/ubuntu/+source/libproxy/0.4.11-5ubuntu1.2

Fedora: 7892-2 High: GStreamer Buffer Overflow Vulnerability

ubuntu
Calendar Grey January 4, 2021
Dist Ubuntu Esm H88
The libproxy security flaw can lead to system crashes or remote code execution in Ubuntu versions. Take immediate action to safeguard your machine.
libproxy could be made to crash or execute arbitrary code if it received a specially crafted file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: libproxy1v5 0.4.15-13ubuntu1.1 Ubuntu 20.04 LTS: libproxy1v5 0.4.15-10ubuntu1.2 Ubuntu 18.04 LTS: libproxy1v5 0.4.15-1ubuntu0.2 Ubuntu 16.04 LTS: libproxy1v5 0.4.11-5ubuntu1.2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4673-1

CVE-2020-26154

January 04, 2021

Package Information

https://launchpad.net/ubuntu/+source/libproxy/0.4.15-13ubuntu1.1 https://launchpad.net/ubuntu/+source/libproxy/0.4.15-10ubuntu1.2 https://launchpad.net/ubuntu/+source/libproxy/0.4.15-1ubuntu0.2 https://launchpad.net/ubuntu/+source/libproxy/0.4.11-5ubuntu1.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here