Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
172

Ubuntu 18.04 LTS: USN-3874-1 Moderate: Firefox Attack Risks

Firefox could be made to crash or run programs as your login if it opened a malicious website.. =========================================================================Ubuntu Security Notice USN-3874-1 January 30, 2019 firefox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.10 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, gain additional privileges by escaping the sandbox, or execute arbitrary code. (CVE-2018-18500, CVE-2018-18501, CVE-2018-18502, CVE-2018-18503, CVE-2018-18504, CVE-2018-18505) It was discovered that Firefox allowed PAC files to specify that requests to localhost are sent through the proxy to another server. If proxy auto-detection is enabled, an attacker could potentially exploit this to conduct attacks on local services and tools. (CVE-2018-18506) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10: firefox 65.0+build2-0ubuntu0.18.10.1 Ubuntu 18.04 LTS: firefox 65.0+build2-0ubuntu0.18.04.1 Ubuntu 16.04 LTS: firefox 65.0+build2-0ubuntu0.16.04.1 Ubuntu 14.04 LTS: firefox 65.0+build2-0ubuntu0.14.04.1 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3874-1 CVE-2018-18500, CVE-2018-18501, CVE-2018-18502, CVE-2018-18503, CVE-2018-18504, CVE-2018-18505, CVE-2018-18506 Package Information: https://launchpad.net/ubuntu/+source/firefox/65.0+build2-0ubuntu0.18.10.1 https://launchpad.net/ubuntu/+source/firefox/65.0+build2-0ubuntu0.18.04.1 https://launchpad.net/ubuntu/+source/firefox/65.0+build2-0ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/firefox/65.0+build2-0ubuntu0.14.04.1 . =========================================================================Ubuntu Security Notice USN-. firefox, crash, programs, login, opened, malicious, website, =====. . LinuxSecurity.com Team

Calendar%202 Jan 30, 2019 Ubuntu
89

Fedora 25: 2017-c85c0e5637 Critical: Ghostscript Application Crashes

Security fixes release for these CVEs: * [CVE-2016-10217](https://access.redhat.com/security/cve/CVE-2016-10217) *(use- after-free and application crash)* * [CVE-2016-10218](https://access.redhat.com/security/cve/CVE-2016-10218) *(NULL pointer dereference and application crash)* *. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-c85c0e5637 2017-05-06 17:08:31.477958 --------------------------------------------------------------------------------Name : ghostscript Product : Fedora 25 Version : 9.20 Release : 9.fc25 URL : https://www.ghostscript.com/ Summary : A PostScript interpreter and renderer Description : Ghostscript is a set of software that provides a PostScript interpreter, a set of C procedures (the Ghostscript library, which implements the graphics capabilities in the PostScript language) and an interpreter for Portable Document Format (PDF) files. Ghostscript translates PostScript code into many common, bitmapped formats, like those understood by your printer or screen. Ghostscript is normally used to display PostScript files and to print PostScript files to non-PostScript printers. If you need to display PostScript files or print them to non-PostScript printers, you should install ghostscript. If you install ghostscript, you also need to install the ghostscript-fonts package. --------------------------------------------------------------------------------Update Information: Security fixes release for these CVEs: * [CVE-2016-10217](https://access.redhat.com/security/cve/CVE-2016-10217) *(use-after-free and application crash)* * [CVE-2016-10218](https://access.redhat.com/security/cve/CVE-2016-10218) *(NULL pointer dereference and application crash)* * [CVE-2016-10219](https://access.redhat.com/security/cve/CVE-2016-10219) *(divide-by-zero error and application crash)* * [CVE-2016-10220](https://access.redhat.com/security/cve/CVE-2016-10220) *(NULL pointerdereference and application crash)* * [CVE-2017-5951](https://access.redhat.com/security/cve/CVE-2017-5951) *(NULL pointer dereference and application crash)* * [CVE-2017-7975](https://access.redhat.com/security/cve/CVE-2017-7975) *(application crash or possible execution of arbitrary code)* * [CVE-2017-8291](https://access.redhat.com/security/cve/CVE-2017-8291) *( -dSAFER bypass and remote command execution)* --------------------------------------------------------------------------------References: [ 1 ] Bug #1441581 - CVE-2016-10217 CVE-2016-10218 CVE-2016-10219 CVE-2016-10220 CVE-2016-10317 CVE-2017-5951 ghostscript: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1441581 [ 2 ] Bug #1443934 - CVE-2017-7885 CVE-2017-7975 CVE-2017-7976 ghostscript: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1443934 [ 3 ] Bug #1446064 - CVE-2017-8291 ghostscript: -dSAFER bypass and command execution via a "/OutputFile (%pipe%" substring [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1446064 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade ghostscript' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent update to Ghostscript in Fedora addresses multiple severe security flaws that could result in system crashes and potential execution threats.. GhostscriptSecurity, Fedora 25 Update, Critical Security Flaws. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 07, 2017 Critical Fedora
200

Scientific Linux: 2013-02-19 Critical Security Update for Firefox

Critical: firefox security update. Date: Wed, 20 Feb 2013 13:16:36 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Critical: firefox on SL5.x, SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Critical: firefox security update Issue Date: 2013-02-19 CVE Numbers: CVE-2013-0783 CVE-2013-0775 CVE-2013-0776 CVE-2013-0780 CVE-2013-0782 -- Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2013-0775, CVE-2013-0780, CVE-2013-0782, CVE-2013-0783) It was found that, after canceling a proxy server's authentication prompt, the address bar continued to show the requested site's address. An attacker could use this flaw to conduct phishing attacks by tricking a user into believing they are viewing a trusted site. (CVE-2013-0776) Note that due to a Kerberos credentials change, the following configuration steps may be required when using Firefox 17.0.3 ESR with the Enterprise Identity Management (IPA) web interface: Important: Firefox 17 is not completely backwards-compatible with all Mozilla add-ons and Firefox plug-ins that worked with Firefox 10.0. Firefox 17 checks compatibility on first-launch, and, depending on the individual configuration and the installed add-ons and plug-ins, may disable said Add-ons and plug-ins, or attempt to check for updates and upgrade them. Add-ons and plug-ins may have to be manually updated. After installing the update, Firefox must be restarted for the changes to take effect. -- SL5 x86_64 devhelp-0.12-23.el5_9.i386.rpm devhelp-0.12-23.el5_9.x86_64.rpm devhelp-debuginfo-0.12-23.el5_9.i386.rpm devhelp-debuginfo-0.12-23.el5_9.x86_64.rpm firefox-17.0.3-1.el5_9.i386.rpm firefox-17.0.3-1.el5_9.x86_64.rpm firefox-debuginfo-17.0.3-1.el5_9.i386.rpm firefox-debuginfo-17.0.3-1.el5_9.x86_64.rpm xulrunner-17.0.3-1.el5_9.i386.rpm xulrunner-17.0.3-1.el5_9.x86_64.rpm xulrunner-debuginfo-17.0.3-1.el5_9.i386.rpm xulrunner-debuginfo-17.0.3-1.el5_9.x86_64.rpm yelp-2.16.0-30.el5_9.x86_64.rpm yelp-debuginfo-2.16.0-30.el5_9.x86_64.rpm devhelp-devel-0.12-23.el5_9.i386.rpm devhelp-devel-0.12-23.el5_9.x86_64.rpm xulrunner-devel-17.0.3-1.el5_9.i386.rpm xulrunner-devel-17.0.3-1.el5_9.x86_64.rpm i386 devhelp-0.12-23.el5_9.i386.rpm devhelp-debuginfo-0.12-23.el5_9.i386.rpm firefox-17.0.3-1.el5_9.i386.rpm firefox-debuginfo-17.0.3-1.el5_9.i386.rpm xulrunner-17.0.3-1.el5_9.i386.rpm xulrunner-debuginfo-17.0.3-1.el5_9.i386.rpm yelp-2.16.0-30.el5_9.i386.rpm yelp-debuginfo-2.16.0-30.el5_9.i386.rpm devhelp-devel-0.12-23.el5_9.i386.rpm xulrunner-devel-17.0.3-1.el5_9.i386.rpm SL6 x86_64 firefox-17.0.3-1.el6_3.i686.rpm firefox-17.0.3-1.el6_3.x86_64.rpm firefox-debuginfo-17.0.3-1.el6_3.i686.rpm firefox-debuginfo-17.0.3-1.el6_3.x86_64.rpm libproxy-0.3.0-4.el6_3.i686.rpm libproxy-0.3.0-4.el6_3.x86_64.rpm libproxy-bin-0.3.0-4.el6_3.x86_64.rpm libproxy-debuginfo-0.3.0-4.el6_3.i686.rpm libproxy-debuginfo-0.3.0-4.el6_3.x86_64.rpm libproxy-python-0.3.0-4.el6_3.x86_64.rpm xulrunner-17.0.3-1.el6_3.i686.rpm xulrunner-17.0.3-1.el6_3.x86_64.rpm xulrunner-debuginfo-17.0.3-1.el6_3.i686.rpm xulrunner-debuginfo-17.0.3-1.el6_3.x86_64.rpm yelp-2.28.1-17.el6_3.x86_64.rpm yelp-debuginfo-2.28.1-17.el6_3.x86_64.rpm libproxy-devel-0.3.0-4.el6_3.i686.rpm libproxy-devel-0.3.0-4.el6_3.x86_64.rpm libproxy-gnome-0.3.0-4.el6_3.x86_64.rpm libproxy-kde-0.3.0-4.el6_3.x86_64.rpm libproxy-mozjs-0.3.0-4.el6_3.x86_64.rpm libproxy-webkit-0.3.0-4.el6_3.x86_64.rpm xulrunner-devel-17.0.3-1.el6_3.i686.rpm xulrunner-devel-17.0.3-1.el6_3.x86_64.rpm i386 firefox-17.0.3-1.el6_3.i686.rpm firefox-debuginfo-17.0.3-1.el6_3.i686.rpm libproxy-0.3.0-4.el6_3.i686.rpm libproxy-bin-0.3.0-4.el6_3.i686.rpm libproxy-debuginfo-0.3.0-4.el6_3.i686.rpm libproxy-python-0.3.0-4.el6_3.i686.rpm xulrunner-17.0.3-1.el6_3.i686.rpm xulrunner-debuginfo-17.0.3-1.el6_3.i686.rpm yelp-2.28.1-17.el6_3.i686.rpm yelp-debuginfo-2.28.1-17.el6_3.i686.rpm libproxy-devel-0.3.0-4.el6_3.i686.rpm libproxy-gnome-0.3.0-4.el6_3.i686.rpm libproxy-kde-0.3.0-4.el6_3.i686.rpm libproxy-mozjs-0.3.0-4.el6_3.i686.rpm libproxy-webkit-0.3.0-4.el6_3.i686.rpm xulrunner-devel-17.0.3-1.el6_3.i686.rpm - Scientific Linux Development Team . Google Chrome enhancement patch for Ubuntu 20.04 resolves major vulnerabilities in versions 80 and 81 stemming from browser content errors.. firefox update, Scientific Linux security, critical patch, application flaws. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 20, 2013 Critical Scientific Linux
172

Ubuntu 12.10: 1659-1 Critical GIMP Program Execution Threat

GIMP could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-1659-1 December 10, 2012 gimp vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 10.04 LTS Summary: GIMP could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - gimp: The GNU Image Manipulation Program Details: It was discovered that GIMP incorrectly handled malformed XWD files. If a user were tricked into opening a specially crafted XWD file, an attacker could cause GIMP to crash, or possibly execute arbitrary code with the user's privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: gimp 2.8.2-1ubuntu1.1 Ubuntu 12.04 LTS: gimp 2.6.12-1ubuntu1.2 Ubuntu 11.10: gimp 2.6.11-2ubuntu4.2 Ubuntu 10.04 LTS: gimp 2.6.8-2ubuntu1.6 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1659-1 CVE-2012-5576 Package Information: https://launchpad.net/ubuntu/+source/gimp/2.8.2-1ubuntu1.1 https://launchpad.net/ubuntu/+source/gimp/2.6.12-1ubuntu1.2 https://launchpad.net/ubuntu/+source/gimp/2.6.11-2ubuntu4.2 https://launchpad.net/ubuntu/+source/gimp/2.6.8-2ubuntu1.6 . A critical vulnerability has been found in GIMP on Ubuntu, potentially risking unauthorized access to images, affecting system integrity and user security. GIMP Issue, Ubuntu Security, Application Flaw, Program Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 10, 2012 Critical Ubuntu
200

Scientific Linux: Important Update for OpenJDK on SL5.x i386/x86_64

Important: java-1.6.0-openjdk security update. Date: Wed, 13 Jun 2012 12:08:31 -0500 Reply-To: This email address is being protected from spambots. You need JavaScript enabled to view it. Sender: Security Errata for Scientific Linux From: Patrick Riehecky Subject: Security ERRATA Important: java-1.6.0-openjdk on SL5.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Important: java-1.6.0-openjdk security update Issue Date: 2012-06-13 CVE Numbers: CVE-2012-1711 CVE-2012-1717 CVE-2012-1716 CVE-2012-1713 CVE-2012-1719 CVE-2012-1718 CVE-2012-1723 CVE-2012-1724 CVE-2012-1725 These packages provide the OpenJDK 6 Java Runtime Environment and the OpenJDK 6 Software Development Kit. Multiple flaws were discovered in the CORBA (Common Object Request Broker Architecture) implementation in Java. A malicious Java application or applet could use these flaws to bypass Java sandbox restrictions or modify immutable object data. (CVE-2012-1711, CVE-2012-1719) It was discovered that the SynthLookAndFeel class from Swing did not properly prevent access to certain UI elements from outside the current application context. A malicious Java application or applet could use this flaw to crash the Java Virtual Machine, or bypass Java sandbox restrictions. (CVE-2012-1716) Multiple flaws were discovered in the font manager's layout lookup implementation. A specially-crafted font file could cause the Java Virtual Machine to crash or, possibly, execute arbitrary code with the privileges of the user running the virtual machine. (CVE-2012-1713) Multiple flaws were found in the way the Java HotSpot Virtual Machine verified the bytecode of the class file to be executed. A specially-crafted Java application or applet could use these flaws to crash the Java Virtual Machine, or bypass Java sandbox restrictions. (CVE-2012-1723, CVE-2012-1725) It was discovered that the Java XML parser did not properly handle certain XML documents. An attacker able to make a Java application parse a specially-crafted XML file could use this flaw to make the XML parser enter an infinite loop.(CVE-2012-1724) It was discovered that the Java security classes did not properly handle Certificate Revocation Lists (CRL). CRL containing entries with duplicate certificate serial numbers could have been ignored. (CVE-2012-1718) It was discovered that various classes of the Java Runtime library could create temporary files with insecure permissions. A local attacker could use this flaw to gain access to the content of such temporary files. (CVE-2012-1717) This erratum also upgrades the OpenJDK package to IcedTea6 1.10.8. All users of java-1.6.0-openjdk are advised to upgrade to these updated packages, which resolve these issues. All running instances of OpenJDK Java must be restarted for the update to take effect. SL5: i386 java-1.6.0-openjdk-1.6.0.0-1.27.1.10.8.el5_8.i386.rpm java-1.6.0-openjdk-debuginfo-1.6.0.0-1.27.1.10.8.el5_8.i386.rpm java-1.6.0-openjdk-demo-1.6.0.0-1.27.1.10.8.el5_8.i386.rpm java-1.6.0-openjdk-devel-1.6.0.0-1.27.1.10.8.el5_8.i386.rpm java-1.6.0-openjdk-javadoc-1.6.0.0-1.27.1.10.8.el5_8.i386.rpm java-1.6.0-openjdk-src-1.6.0.0-1.27.1.10.8.el5_8.i386.rpm x86_64 java-1.6.0-openjdk-1.6.0.0-1.27.1.10.8.el5_8.x86_64.rpm java-1.6.0-openjdk-debuginfo-1.6.0.0-1.27.1.10.8.el5_8.x86_64.rpm java-1.6.0-openjdk-demo-1.6.0.0-1.27.1.10.8.el5_8.x86_64.rpm java-1.6.0-openjdk-devel-1.6.0.0-1.27.1.10.8.el5_8.x86_64.rpm java-1.6.0-openjdk-javadoc-1.6.0.0-1.27.1.10.8.el5_8.x86_64.rpm java-1.6.0-openjdk-src-1.6.0.0-1.27.1.10.8.el5_8.x86_64.rpm - Scientific Linux Development Team . Implementing a vital OpenJDK security patch for Scientific Linux to resolve multiple application vulnerabilities.. OpenJDK Update, Java Security, Scientific Linux, Java Runtime, Application Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 13, 2012 Important Scientific Linux
172

Ubuntu 9.04, 9.10, 10.04 LTS USN-962-1 Moderate: VTE Command Execution Risk

Janne Snabb discovered that applications using VTE, such as gnome-terminal,did not correctly filter window and icon title request escape codes. If auser were tricked into viewing specially crafted output in their terminal,a remote attacker could execute arbitrary commands with user privileges. [More...]. ==========================================================Ubuntu Security Notice USN-962-1 July 15, 2010 vte vulnerability CVE-2010-2713 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 9.04 Ubuntu 9.10 Ubuntu 10.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 9.04: libvte9 1:0.20.0-0ubuntu2.1 Ubuntu 9.10: libvte9 1:0.22.2-0ubuntu2.1 Ubuntu 10.04 LTS: libvte9 1:0.23.5-0ubuntu1.1 After a standard system update you need to restart your session to make all the necessary changes. Details follow: Janne Snabb discovered that applications using VTE, such as gnome-terminal, did not correctly filter window and icon title request escape codes. If a user were tricked into viewing specially crafted output in their terminal, a remote attacker could execute arbitrary commands with user privileges. Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 428402 e765295968fe78b4d8e72050dce5f2b7 Size/MD5: 1742 91b6ea4ecd1400d57d72190fab77960c Size/MD5: 1372195 2634f593b93950c58cc12983bdc363cc Architecture independent packages: Size/MD5: 34100 cb3960a156fb27606aeafcc8a3222b46 Size/MD5: 64118 50ab6b9ed24762be4629e480b28e18c1 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 381230 d11c934f31bd1382bb6d62603e839199 Size/MD5: 333636 77562502f522d91fbbea6b5eba1d0982 Size/MD5: 599364edc9be7f0fa11e6281a553208dfb3842 Size/MD5: 177654 58665e2a253ecf2653d9023733573ce2 Size/MD5: 36754 2f3d7f2540a8e6089eb143887ece13d2 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 357832 e255a12e7f921dd4da70a9c81ccd8a72 Size/MD5: 320620 b0f150837119c4e557c9c535a969e949 Size/MD5: 578074 cefed97e22169f7c47d2576ff925b3ff Size/MD5: 160650 3c6f0e195b16937bd6c159bc32ffd34c Size/MD5: 29878 082fd94ee2d4079d8e120e7adc525d01 lpia architecture (Low Power Intel Architecture): Size/MD5: 357150 275ea65ad8d4f0afa645070809bc83db Size/MD5: 318818 d4239f5aca45b71b5b51469111abaaa1 Size/MD5: 575628 90f4af7d86e34f4eb49ac2c69751b544 Size/MD5: 161258 9906e6464b75188f61bcf2626209f4e5 Size/MD5: 29788 5d8228882a46943378e300854c2e8bf9 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 434366 44f0c8d2cc517dec5cda7b23ae364989 Size/MD5: 380478 af6da9a37b4b4dfe9277985388726c97 Size/MD5: 702506 9cd310cc8a3a9b10eb3ee3753500fcbe Size/MD5: 171112 1392f41f7fd399d4f5a2b6901b9afdc8 Size/MD5: 33216 348af61aab2378a5bd4ace0e72bf0463 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 417216 90a00c9c1aecfe8b3982516a327b3693 Size/MD5: 377752 a646e0dff2d00326f36006ce9da6b929 Size/MD5: 684664 8bdae71547bcdd1dbab0db1c3f23af29 Size/MD5: 160572 b92f538e7f75edaea8b95bf1ee21a1d1 Size/MD5: 30318 c90d3f542a6c5e0e5015e26c4a91834b Updated packages for Ubuntu 9.10: Source archives: Size/MD5: 243298 3edfa4d3d5f316572e5740fcfad6921d Size/MD5: 1834 3d1255fc5bb5c83888fe03c41717ba23 Size/MD5: 1690961 395d1cfb26eb88cd59cf8c4ba9cff5a3 Architecture independent packages: Size/MD5: 39738 7816f27f3df3317200f462a8ee331ed7 Size/MD5: 67816 dc826cf7ce0f58631e99c1ba0b32c9dc amd64 architecture (Athlon64, Opteron,EM64T Xeon): Size/MD5: 374980 10a34defb72515939bf8b6a5f5d54528 Size/MD5: 323702 f9bb18bba04c415c5193e9c41b0ee1ce Size/MD5: 569660 b231f66728c13796395a867c890cea2b Size/MD5: 178312 d5435792bd9eb94c5e56ea1e2737ae72 Size/MD5: 37610 de87e338985117dd7424dd4bfd300ecf i386 architecture (x86 compatible Intel/AMD): Size/MD5: 354286 1a93396e5e8a9b18436add12955364ba Size/MD5: 311194 1fa31d2b232688a45eef99db548756bc Size/MD5: 553646 9580f3c6612faefb0ed78256fed07621 Size/MD5: 163708 f137ea721dcb9ea1627f71ad2b481a0b Size/MD5: 30848 564462811d1f26275dbdccd29fe35d5c lpia architecture (Low Power Intel Architecture): Size/MD5: 353152 1d3641a6ca8b9897e5fe17913d2e5c52 Size/MD5: 309680 ac6253b76ea51b4bf412f8e2ead3423f Size/MD5: 550788 27c11af8f9397f36551e32157c964344 Size/MD5: 164154 5ed643aaef2ad3582f1dac314ec696b3 Size/MD5: 30586 a68eefbfa31ee1358953a15f80a898a2 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 400068 bf0db507a15bcc2f5295a0d69869c8ab Size/MD5: 341556 aaf3f154b40ac28c5bb3ba3934f20772 Size/MD5: 608182 0fd96c473b3320e8fc7c4a8d42114831 Size/MD5: 176394 b4581dbaba32185dba6b26c98cdedbd7 Size/MD5: 33718 b90e936340b1c9e717f8b402dca16e82 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 383916 0052cb2d7180822c17893a4cfcef0383 Size/MD5: 339134 0f3b107ecdffe6a2de793f5d1766634a Size/MD5: 596110 eea4bc4b68616012efdf53abf0d5fbf7 Size/MD5: 163172 af1ecf447961b7498c6edc0f3d9b4ab9 Size/MD5: 31042 4c32e63f44db4715188932deb2e1b362 Updated packages for Ubuntu 10.04: Source archives: Size/MD5: 211284 5f70b3dca901eb710f241ae58ddbe82f Size/MD5: 1834 d2cd6ea9a2d74191eac929364df284e3 Size/MD5: 1703653 8256980f2c9b9914bb640870568adeff Architecture independentpackages: Size/MD5: 41216 3362a9b7570880c5f121d45cf45f1635 Size/MD5: 71402 4e9fb7db00aa46b294c826eb2b912048 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 373946 2232ba9a261fa26950da8fd4cd77c0f4 Size/MD5: 323570 0965c8fcc82a46e4a61df68db2d55286 Size/MD5: 569720 bf13b0ef86f2cb016f875925d8ea1cb6 Size/MD5: 91070 7bb8a16739115b0fb18bee882c2496a1 Size/MD5: 19886 a22e380ba799ea4a964cbf462dc242a7 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 353460 0e0a36204d17e2e06838b3e953f4494a Size/MD5: 311344 d3bbb99765dd1b0bc4b37ffeb74e47a0 Size/MD5: 553716 0362fb78ab8e9c657235b1207040c21d Size/MD5: 84008 edb76ddf1c422af64b31ec3227466040 Size/MD5: 16534 254d655ff5f7ad3037e9847d209f6426 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 399062 650d527c3a8ceabca5e46945cc577608 Size/MD5: 344968 0274fac76ecb7fcf24fa1e7876322364 Size/MD5: 608296 6ee308e8e565b3ef77a14187d44fa9ca Size/MD5: 90264 d5e52a1bdc82da13dc10bf6d50e44bb6 Size/MD5: 17832 d9023a1b08175c47a95213b694b55a38 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 385478 abb9a0b4f444c1588530f7cd4f4ca818 Size/MD5: 341688 a582c6a4dc3cb517a4ff86b0fadd0ed3 Size/MD5: 599642 841b2459776c09a06a584fe41ee86bd9 Size/MD5: 83800 0d1d2bfb961cdeb8c1f32debaf2e6939 Size/MD5: 16784 5ac61fa9db2c471452e0690769732841 . A vulnerability in the VTE component of Ubuntu permits distant adversaries to run commands under user privileges. Upgrade your packages promptly to reduce the threat.. VTE Vulnerability, Ubuntu Security Notice, Remote Execution Risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 15, 2010 Important Ubuntu
172

Ubuntu 6.06 LTS USN-787-1 Critical: Apache Application Crash DoS

Matthew Palmer discovered an underflow flaw in apr-util as included inApache. An attacker could cause a denial of service via application crashin Apache using a crafted SVNMasterURI directive, .htaccess file, or whenusing mod_apreq2. This issue only affected Ubuntu 6.06 LTS. (CVE-2009-0023) [More...]. ==========================================================Ubuntu Security Notice USN-787-1 June 12, 2009 apache2 vulnerabilities CVE-2009-0023, CVE-2009-1191, CVE-2009-1195, CVE-2009-1955, CVE-2009-1956 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: apache2-common 2.0.55-4ubuntu2.5 apache2-mpm-perchild 2.0.55-4ubuntu2.5 apache2-mpm-prefork 2.0.55-4ubuntu2.5 apache2-mpm-worker 2.0.55-4ubuntu2.5 libapr0 2.0.55-4ubuntu2.5 Ubuntu 8.04 LTS: apache2-mpm-event 2.2.8-1ubuntu0.8 apache2-mpm-perchild 2.2.8-1ubuntu0.8 apache2-mpm-prefork 2.2.8-1ubuntu0.8 apache2-mpm-worker 2.2.8-1ubuntu0.8 apache2.2-common 2.2.8-1ubuntu0.8 Ubuntu 8.10: apache2-mpm-event 2.2.9-7ubuntu3.1 apache2-mpm-prefork 2.2.9-7ubuntu3.1 apache2-mpm-worker 2.2.9-7ubuntu3.1 apache2.2-common 2.2.9-7ubuntu3.1 Ubuntu 9.04: apache2-mpm-event 2.2.11-2ubuntu2.1 apache2-mpm-prefork 2.2.11-2ubuntu2.1 apache2-mpm-worker 2.2.11-2ubuntu2.1 apache2.2-common 2.2.11-2ubuntu2.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Matthew Palmer discovered an underflow flaw in apr-util as includedin Apache. An attacker could cause a denial of service via application crash in Apache using a crafted SVNMasterURI directive, .htaccess file, or when using mod_apreq2. This issue only affected Ubuntu 6.06 LTS. (CVE-2009-0023) Sander de Boer discovered that mod_proxy_ajp would reuse connections when a client closed a connection without sending a request body. A remote attacker could exploit this to obtain sensitive response data. This issue only affected Ubuntu 9.04. (CVE-2009-1191) Jonathan Peatfield discovered that Apache did not process Includes options correctly. With certain configurations of Options and AllowOverride, a local attacker could use an .htaccess file to override intended restrictions and execute arbitrary code via a Server-Side-Include file. This issue affected Ubuntu 8.04 LTS, 8.10 and 9.04. (CVE-2009-1195) It was discovered that the XML parser did not properly handle entity expansion. A remote attacker could cause a denial of service via memory resource consumption by sending a crafted request to an Apache server configured to use mod_dav or mod_dav_svn. This issue only affected Ubuntu 6.06 LTS. (CVE-2009-1955) C. Michael Pilato discovered an off-by-one buffer overflow in apr-util when formatting certain strings. For big-endian machines (powerpc, hppa and sparc in Ubuntu), a remote attacker could cause a denial of service or information disclosure leak. All other architectures for Ubuntu are not considered to be at risk. This issue only affected Ubuntu 6.06 LTS. (CVE-2009-1956) Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 123724 00519250c6506489a6c39936925e568e Size/MD5: 1156 20f5954982f1615b73eb8d180069a55e Size/MD5: 6092031 45e32c9432a8e3cf4227f5af91b03622 Architecture independent packages: Size/MD5: 2125174 6ee0433b3d2fbf33c6514599bcfe047b amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 833636 0e14aa964bbfd817e44d0c6517bb0d03 Size/MD5: 228830db8dee716fa4906b74138b6efbb8f52a Size/MD5: 223844 4277481db3a7217319f1fb4bc9a9df5b Size/MD5: 228456 d4e86af7ea2751f782c9f81504c899e9 Size/MD5: 171972 16352ec1565ada8204deb4d4aa7e460d Size/MD5: 172750 3e8ad9cc35d7a6b8a97d320610c79024 Size/MD5: 94816 f251b0a95e6554c4d6e686b5a6f9132f Size/MD5: 36864 7d4f1abc24314c8f1682d0bc5a727882 Size/MD5: 286326 240a6f25212bacab7cef3af8218ef235 Size/MD5: 144886 20ce4e07cf33f50c279aa57876da241d i386 architecture (x86 compatible Intel/AMD): Size/MD5: 786858 9086ee9622bf2f6299d521751b7984cc Size/MD5: 203506 903fda93a0084cbeb163c06823a2424c Size/MD5: 199358 ab3b3082cdd4537004f92f0cf9d67331 Size/MD5: 202902 69f2874396cc0895e05b369f9806e34c Size/MD5: 171980 2eca5344df9c14e289ea045633d33439 Size/MD5: 172750 46fc5dc35f23b087f1438f88b1a0d082 Size/MD5: 92760 065675c9336669192e09604adbec77d1 Size/MD5: 36866 c95b2e1cd3b70a2714c6a1a12a780038 Size/MD5: 262324 e3598aad5a3be422319e509b1fc17386 Size/MD5: 132808 c36dc81bbc044508961082c730659356 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 859676 46bd81028dcf7be9e41770dd11af37ae Size/MD5: 220862 b1f08076334f064ca0bd69dd599aa59d Size/MD5: 216506 57bd719b0a500747320db3c77350a97e Size/MD5: 220360 8451b10349e241687954b916a31e9680 Size/MD5: 171978 37abe43c6f3bb7ff514ec55b7b23c2c7 Size/MD5: 172754 c2b337ff66a86c0ad67a02667e63618a Size/MD5: 104538 1d91ed96d5f569ad59f07767dc7aadbe Size/MD5: 36866 605992b543ab267be7fff50c028b96eb Size/MD5: 281870 40933a88468e6a97a06828e24a430ad5 Size/MD5: 141986 ad0ee1e4188fa56dfc23d217b31b9e4a sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 803992 df7406ce6b8c2037e17eab5aba1fd947 Size/MD5: 211278 8c29e978a758d2a885048bc8e8529be7 Size/MD5: 206812 9f549366fdc0481d40bc6123ddbb3d91 Size/MD5: 210522 27dadfb40c60d99aa5570daaa05f5ba6 Size/MD5: 171976 aa9dd20fbb4eea6a4e0e0fa20538dad7 Size/MD5: 172756 480182b02dc98f8e86119452cf4dc031 Size/MD5: 93858 6f000d7b9a0f48de4e22a39f42e53fe8 Size/MD5: 36864 246e286fdb3f71b2b92c7cd783628dad Size/MD5: 268458 1c29830b1e623ff497ad20240861dc42 Size/MD5: 130780 46fbba05af3cdc1f39e73c2cca8716e1 Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 135718 b67b9e9cab0d958b01bf47433fcb299f Size/MD5: 1379 5f83de71908712e7fa37c517c6b9daf0 Size/MD5: 6125771 39a755eb0f584c279336387b321e3dfc Architecture independent packages: Size/MD5: 1928684 ccf0bbc4560b1d63f86681c5f91d38a5 Size/MD5: 72322 ffe7242eb5807cb4faf04af195824773 Size/MD5: 6254304 8dae450a6d4f8b948ae02dc3a165ad99 Size/MD5: 45252 0f62ab2a6205b27126c6c30ce0e8cc9d amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 252474 661f84e26a417adb6fb293cda4170146 Size/MD5: 248086 3196e11d84f523ef5e3409171eda56cf Size/MD5: 251832 ab128185607a1812fae9b7da809c5471 Size/MD5: 204994 5ce24738c1785a6ba05dd3e86337b1b3 Size/MD5: 205770 e8a688cfd6b67367c66c8ff0f2227e30 Size/MD5: 141084 da5c7a4aba57d0088a0122d81bbff9ad Size/MD5: 801788 0359700bb1d80e0e3a6fc1d8efe74d02 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 235446 0a61cd153337e09a91482b781fbf108e Size/MD5: 230978 c5a4a358ddfdba46ba19f8758614e85b Size/MD5: 234696 9a90bad413d4d46316f328776a2d950a Size/MD5: 205002 4cdf06a62da153d9b7d2cd6772a00c76 Size/MD5: 205766 36ee4a8ad7a8de250676d00aa02f9195 Size/MD5: 140046 a1adc8e4bdbf11a7c0856ecfbb333e08 Size/MD5: 754798 afea0689b2508b4d5bc5c41e19019eb0 lpia architecture (Low Power IntelArchitecture): Size/MD5: 234958 4f05df526ebd1e4ab2b909b7e041e4c1 Size/MD5: 230616 ff72890c7622b3a291789006aa2099b4 Size/MD5: 234102 16fb9ac5b25ed2cc19729cfc48ad6014 Size/MD5: 204996 d8888829d11f62961a01fec4c0919403 Size/MD5: 205770 1c73843afed774da460e39b79ab332a7 Size/MD5: 140622 b1537a8a7a01aea78b0a67ba5ab6f84d Size/MD5: 748640 e2fc6fe941ec7a2238e57004816d3bb1 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 253568 1d84c15e686047e1eebd6812da6adcd9 Size/MD5: 248958 9e418948b0c7fed12e70e9ee07f193dc Size/MD5: 253052 e070abbfc3cd142234a30688320e5dbc Size/MD5: 205000 25018ddf577a7e66655b79775d67eb50 Size/MD5: 205782 9e78cbd7348964b8ab831e0482d3e41b Size/MD5: 157810 4b7d728303d38b057b043e96ee3ab7aa Size/MD5: 904910 359c25a1948ac2728e445082e60a7b44 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 236684 330ec61baee83347b37132f646264596 Size/MD5: 232578 11681fc7d5013b55d2e3f4e500797726 Size/MD5: 235912 cc331eab50a4ede19d0f88fd4fc0d00d Size/MD5: 204994 8b3d7bd0db0db66235a4f06f257108bf Size/MD5: 205762 134ff600abb6954b657a2fe8f9e5fa00 Size/MD5: 143256 90b0f6e9362aa3866e412a98e255b086 Size/MD5: 763970 c6bc1c87855dcc1e72a438a791d6952e Updated packages for Ubuntu 8.10: Source archives: Size/MD5: 130909 ed59ca0fc5288b93fa2cb04af9aa2b7d Size/MD5: 1788 f80e4b56abc6bfc56125fc78aebab185 Size/MD5: 6396996 80d3754fc278338033296f0d41ef2c04 Architecture independent packages: Size/MD5: 2041562 05e984048a661ec86fe5051cab223b33 Size/MD5: 6537296 e9f14f43d75ec050e3d70cac84ba318f Size/MD5: 45016 f63b7b86981f837f780ae1a821c4b43d amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 254484 0e095f99d2e0e3ba925fff298a6f57f2 Size/MD5: 24867888d8afa20352f18c8e5d810c6e474c97 Size/MD5: 253868 7ccad99f2fc89e63a394d4ad95335082 Size/MD5: 208050 187e0b01d15af23717d0d26771023c60 Size/MD5: 84018 9f56eeec1f836774e7e91f3cdfbf3ee5 Size/MD5: 82380 9085526c648b9d8656a2b7d2c7326655 Size/MD5: 209104 dcac98c57f63870120667d613939bbb0 Size/MD5: 147294 a6d9883304675907594ed1aab442d81a Size/MD5: 819450 a8562063da879ed20251894bd1e0746e i386 architecture (x86 compatible Intel/AMD): Size/MD5: 240916 d05183c57521d23cf2281e2d9589c8c3 Size/MD5: 235528 b4908cd5d4b70f8ede12cf7b6e103223 Size/MD5: 240188 63c83e128a121c7c9c188b02eb59edcb Size/MD5: 208056 01f550eb1d15495d5d896d522ade4396 Size/MD5: 83470 97a20ccf92b43e4b32d182a128b22072 Size/MD5: 81868 4f3ef154558c65db2daf74f940779760 Size/MD5: 209110 b291e921de088d2efabf33e4cd35c99e Size/MD5: 146130 6ea24f8ff6bd7a5921c575b402bc2d32 Size/MD5: 777780 e598efbc86f7a1d7e9675deb6a237e4c lpia architecture (Low Power Intel Architecture): Size/MD5: 237796 38656143c16829748990fe35c2618b95 Size/MD5: 232460 9e20d4fb43009cba2133ecb7d0fe5684 Size/MD5: 237088 2ca48410f10f3e9b800e1c131edc8192 Size/MD5: 208070 02f11c5c6874f97a7e737030cd22d333 Size/MD5: 83412 fb1c3db7a5c0a6c25d842600e7166584 Size/MD5: 81840 43514a92cf231cb8e57a21448b4183df Size/MD5: 209122 7fd0dd58cbc286cf730fd7e3be8e5329 Size/MD5: 145818 92e9731915cc84e775fd303142186bad Size/MD5: 765882 179c476b74f6d593dde3a53febb5684e powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 261012 4706fe724bc8469e9693983b6e5cb542 Size/MD5: 255554 70580bb638d16932a6376e8e593f012a Size/MD5: 260364 1703559523a2765da24f8cb748992345 Size/MD5: 208078 f538ef7ed95defc239ecc498b898efaa Size/MD5: 841045f127b51e775dfe285eb8d5c448ff752 Size/MD5: 82462 960f91f842e5fc0eea867a14290334bc Size/MD5: 209116 13c8662a31d5fdef85ca3ac3637a8689 Size/MD5: 160562 4734c80d99389ab39d553aee59fa6ff7 Size/MD5: 925502 4400f5d7e9411b679249a34551d34b83 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 246136 2132add596f6b3cde962f2f0d7fc31ad Size/MD5: 240772 0e3e5f9de7a877c3dfe0a9b8167a6c53 Size/MD5: 245500 e7f1c5af7f735a3f10b3be90df71fc0e Size/MD5: 208076 ec4d3e98ca11376db2b9d8fd6d884b60 Size/MD5: 83642 2b61d89fe5f802d75289ceb000d5725b Size/MD5: 82022 07d39ee448a55ebcfe25194bfff62929 Size/MD5: 209124 2c3a8b2f2a2863350baec615cf5e3643 Size/MD5: 150470 ab783bdd5be74dd06e791aba78113be0 Size/MD5: 783186 bdfe2bc8f54cb65d38cb96038ceddb09 Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 134781 129b768f9b402dbab2177edc6cffc1b4 Size/MD5: 1795 f6124369956b88a09f1786687e187af8 Size/MD5: 6806786 03e0a99a5de0f3f568a0087fb9993af9 Architecture independent packages: Size/MD5: 2218488 ab645fa9c67940ee29934317f2383bec Size/MD5: 46084 7be24aa4d43f4d55e36e95e831e04fcb Size/MD5: 6945842 a0742af1b44b20a35c24cca56a0b59a0 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 258410 de4fb0f20ec133b06d7464a9ea80866d Size/MD5: 252600 96fc657175db7e0958b2aff2884787ce Size/MD5: 257804 d7089118239d000dbc68ab95bfd271dd Size/MD5: 212740 7fd9950428d290b6b3aee7278b20801b Size/MD5: 213712 67b090ab9856a9812df4b8b8ef66dccb Size/MD5: 150594 58993a2d2fae87fafecfab2bdc06b521 Size/MD5: 824406 af48b8490ac13329fd761d279d16b22b Size/MD5: 87250 6ef1e665dab19ae16a0a3a8d8b441f52 Size/MD5: 85530 a104eeb1d1114e57ad91f3f646ff8e2d i386 architecture (x86 compatible Intel/AMD): Size/MD5: 2449221fff6a156eb80ae9edf1965b205215d3 Size/MD5: 239444 a61af2e80ff7a7d397478396968efa7a Size/MD5: 244292 a80eae6d7f5c060cfa12950759433a4f Size/MD5: 212748 684eac3801bf1650ca4662cc354ef95e Size/MD5: 213718 d9c889bad26894b386934ca35a1e1379 Size/MD5: 149484 755cb6034670192a724407b37e7cb355 Size/MD5: 783390 b6fa516c19bb6d82776347dd3e940094 Size/MD5: 86630 d20a788cb4ac4eb1315ef0739e015214 Size/MD5: 85030 96d33de27e43def58d919d6cf9660d68 lpia architecture (Low Power Intel Architecture): Size/MD5: 241826 7f57b43f10b1c3c9ed8936c1fce4b13c Size/MD5: 236352 bb836a54002a4245cae4c26f24b9f7c0 Size/MD5: 241204 6b7073a4e777394416240b7da64d4036 Size/MD5: 212724 abfa6f5688aacdb6ceab53d14bf93f0e Size/MD5: 213702 fdd3ddcf889bc8cbe5625e3dd8959bff Size/MD5: 149198 e6eae8fa571b6bf17b98aeb232d22e4d Size/MD5: 772602 612374c962f685533d55e821f2748828 Size/MD5: 86576 13c229e63eb2011c9a74f1eaea7bacb6 Size/MD5: 84988 e70529926eb88e73ee1f7f06f73ef414 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 265034 8244078723fb247d4cddfd0376374b8d Size/MD5: 259822 a81eb991f88dbb4cb6b374ea6315f0ba Size/MD5: 264502 512f211e4bc233c8351b620fb9e27fa4 Size/MD5: 212754 f284e4114d049c15632ac08ddc6ddc2d Size/MD5: 213728 c8caee451ecefb8d856412ebcaaff627 Size/MD5: 163892 c7b9a87427478a72be106c8de950de13 Size/MD5: 931558 3280b97e8ab35c15b6b9f0192c60895b Size/MD5: 87326 da229fa04d2536679c0cdd7a4447929b Size/MD5: 85592 72dd8fe34d798e65b77bcb5b3e40122d sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 250148 f903b1decc466013c618579f36e30ec4 Size/MD5: 244470 66c2b05cf6585a40346c341d1b3ba3b2 Size/MD5: 249532 50f65920d24048ba1e7444d7bf42e9bd Size/MD5: 212752 100150fe2cc4ffeb96b41965995493bd Size/MD5: 213718 16c269440c2cba44360cd49c89463ece Size/MD5: 153740 8531a5268c9ead29583a2102f1ee929b Size/MD5: 788532 415364037e428a8d1dcf3565fefced36 Size/MD5: 86830 662ac6195c360fbf5416f9fbefde46ac Size/MD5: 85124 585acf45b85fe68308c459076f7d6d93 . Uncover essential Apache flaws impacting Ubuntu platforms, accompanied by comprehensive remediation guidelines to bolster safety.. Ubuntu Security Notice, Apache Flaws, Denial of Service, Ubuntu Linux Patch, Security Advisories. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 12, 2009 Critical Ubuntu
172

Ubuntu 7.10: USN-728-2 Critical: Firefox Remote Code Risk

Jesse Ruderman and Gary Kwong discovered flaws in the browser engine.If a user were tricked into viewing a malicious website, a remoteattacker could cause a denial of service or possibly execute arbitrarycode with the privileges of the user invoking the program.(CVE-2009-0772, CVE-2009-0774) [More...]. ==========================================================Ubuntu Security Notice USN-728-2 March 06, 2009 firefox vulnerabilities CVE-2009-0772, CVE-2009-0774, CVE-2009-0776 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 7.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 7.10: firefox 2.0.0.21~tb.21+nobinonly-0ubuntu0.7.10.1 After a standard system upgrade you need to restart Firefox to effect the necessary changes. Details follow: Jesse Ruderman and Gary Kwong discovered flaws in the browser engine. If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2009-0772, CVE-2009-0774) Georgi Guninski discovered a flaw when Firefox performed a cross-domain redirect. An attacker could bypass the same-origin policy in Firefox by utilizing nsIRDFService and steal private data from users authenticated to the redirected website. (CVE-2009-0776) Updated packages for Ubuntu 7.10: Source archives: Size/MD5: 194047 099271c2ea597d2a115b3be40995b2c7 Size/MD5: 2340 63a3a1d155642b593de0ea6f4e7692de Size/MD5: 37774008 b2ba5de5a4123fb7e9a796cf790e8315 Architecture independent packages: Size/MD5: 201048 c24401e053bc602c592bd8a6dfe919c5 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 78166004 07ac094a00f59264c33d5ef3010016e1 Size/MD5: 3203128 8afc60d5fc1e8b9975648a0b29adbcc7 Size/MD5: 98360 efde6e650c8e51c0cc18691a3a5c6fcd Size/MD5: 67414 c5901a62027583b17b0e9ad3206dc97b Size/MD5: 10469312 8eea2241465336d5ea9d41eefecec737 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 77309416 0338ce165f4a8491a962489b8e71ae4f Size/MD5: 3191016 08e9a1379c006a822f728b480c81d5ca Size/MD5: 92086 9af96f24ebe279862df72a913d4d8f7b Size/MD5: 66690 5a02205c5307f59398ad670273b415d7 Size/MD5: 9210704 dcec421746059ebdbdaae9dd1cf0ff43 lpia architecture (Low Power Intel Architecture): Size/MD5: 77579288 00f0752dc0e48c926e61ed3043234cf9 Size/MD5: 3188640 11596823330f193c75d84e9065052f1d Size/MD5: 91748 f063e011410244eeb33f64d9504ad4a0 Size/MD5: 66636 bed3e1795c9b6cf073dc5d4b21ac0866 Size/MD5: 9071204 dda4ba5582f1013f0447dd6084dbc4b8 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 80777664 2f86b2bbf427f5cd9ad4230f87aab6a1 Size/MD5: 3206352 e4adf960e211dbe93c7cb70a3d8cae75 Size/MD5: 96424 c005071737505b567f60f1d453baae1a Size/MD5: 67694 b0af3582bb18d21a1f4b8a9ab8337fcd Size/MD5: 10313582 ab429fc180c403c804ed6b387de9427c sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 78135176 6c21f46463479bd7ee265bdfda6c56f7 Size/MD5: 3188258 d64a8e32dc28d89b27acf203718a18eb Size/MD5: 91868 8f1982672a49fc6a3b4c143f908a323b Size/MD5: 66766 72ea8ae2a21540c480e979b65d971ba8 Size/MD5: 9464780 66cd0a187121b63fbc050c52e1b9e59c . Ubuntu 7.10 encountered significant security risks with Firefox, including remote code execution and denial-of-service vulnerabilities, threatening user systems.. Ubuntu Security,Browser Flaws,Firefox Update,Remote Code Risk,Cross-Domain Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 06, 2009 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200