Several security issues were fixed in Mono.. =========================================================================Ubuntu Security Notice USN-2547-1 March 24, 2015 mono vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Several security issues were fixed in Mono. Software Description: - mono: Mono is a platform for running and developing applications Details: It was discovered that the Mono TLS implementation was vulnerable to the SKIP-TLS vulnerability. A remote attacker could possibly use this issue to perform client impersonation attacks. (CVE-2015-2318) It was discovered that the Mono TLS implementation was vulnerable to the FREAK vulnerability. A remote attacker or a man in the middle could possibly use this issue to force the use of insecure ciphersuites. (CVE-2015-2319) It was discovered that the Mono TLS implementation still supported a fallback to SSLv2. This update removes the functionality as use of SSLv2 is known to be insecure. (CVE-2015-2320) It was discovered that Mono incorrectly handled memory in certain circumstances. A remote attacker could possibly use this issue to cause Mono to crash, resulting in a denial of service, or to obtain sensitive information. This issue only applied to Ubuntu 12.04 LTS. (CVE-2011-0992) It was discovered that Mono incorrectly handled hash collisions. A remote attacker could possibly use this issue to cause Mono to crash, resulting in a denial of service. This issue only applied to Ubuntu 12.04 LTS. (CVE-2012-3543) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: libmono-2.0-1 3.2.8+dfsg-4ubuntu2.1 mono-runtime 3.2.8+dfsg-4ubuntu2.1 Ubuntu 14.04 LTS: libmono-2.0-1 3.2.8+dfsg-4ubuntu1.1 mono-runtime 3.2.8+dfsg-4ubuntu1.1 Ubuntu 12.04 LTS: libmono-2.0-1 2.10.8.1-1ubuntu2.3 mono-runtime 2.10.8.1-1ubuntu2.3 After a standard system update you need to restart Mono applications to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2547-1 CVE-2011-0992, CVE-2012-3543, CVE-2015-2318, CVE-2015-2319, CVE-2015-2320 Package Information: https://launchpad.net/ubuntu/+source/mono/3.2.8+dfsg-4ubuntu2.1 https://launchpad.net/ubuntu/+source/mono/3.2.8+dfsg-4ubuntu1.1 https://launchpad.net/ubuntu/+source/mono/2.10.8.1-1ubuntu2.3 . Several vulnerabilities in Mono have been addressed for Ubuntu versions 14.10, 14.04 LTS, and 12.04 LTS. Ensure your system is up-to-date to maintain security.. Mono Security Issues, Ubuntu Security Advisory, TLS Update Information, Mono Update Steps, Client Impersonation Risk. . Severity: Critical. LinuxSecurity.com Team
Researchers at INRIA and Xamarin discovered several vulnerabilities in mono, a platform for running and developing applications based on the ECMA/ISO Standards. Mono's TLS stack contained several problems that hampered its capabilities: those issues could lead to client . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3202-1
An updated elinks package that fixes one security issue is now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: elinks security update Advisory ID: RHSA-2013:0250-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2013:0250.html Issue date: 2013-02-11 CVE Names: CVE-2012-4545 ==================================================================== 1. Summary: An updated elinks package that fixes one security issue is now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 3. Description: ELinks is a text-based web browser. ELinks does not display any images, but it does support frames, tables, and most other HTML tags. It was found that ELinks performed client credentials delegation during the client-to-server GSS security mechanisms negotiation. A rogue server could use this flaw to obtain the client's credentials and impersonate that client to other servers that are using GSSAPI. (CVE-2012-4545) This issue was discovered by Marko Myllynen of Red Hat. All ELinks users are advised to upgrade to this updated package, which contains a backported patch to resolve theissue. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 864566 - CVE-2012-4545 elinks: Improper delegation of client credentials during GSS negotiation 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: elinks-0.11.1-8.el5_9.i386.rpm elinks-debuginfo-0.11.1-8.el5_9.i386.rpm x86_64: elinks-0.11.1-8.el5_9.x86_64.rpm elinks-debuginfo-0.11.1-8.el5_9.x86_64.rpm Red Hat Enterprise Linux (v. 5 server): Source: i386: elinks-0.11.1-8.el5_9.i386.rpm elinks-debuginfo-0.11.1-8.el5_9.i386.rpm ia64: elinks-0.11.1-8.el5_9.ia64.rpm elinks-debuginfo-0.11.1-8.el5_9.ia64.rpm ppc: elinks-0.11.1-8.el5_9.ppc.rpm elinks-debuginfo-0.11.1-8.el5_9.ppc.rpm s390x: elinks-0.11.1-8.el5_9.s390x.rpm elinks-debuginfo-0.11.1-8.el5_9.s390x.rpm x86_64: elinks-0.11.1-8.el5_9.x86_64.rpm elinks-debuginfo-0.11.1-8.el5_9.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 6): Source: i386: elinks-0.12-0.21.pre5.el6_3.i686.rpm elinks-debuginfo-0.12-0.21.pre5.el6_3.i686.rpm x86_64: elinks-0.12-0.21.pre5.el6_3.x86_64.rpm elinks-debuginfo-0.12-0.21.pre5.el6_3.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: elinks-0.12-0.21.pre5.el6_3.x86_64.rpm elinks-debuginfo-0.12-0.21.pre5.el6_3.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: i386: elinks-0.12-0.21.pre5.el6_3.i686.rpm elinks-debuginfo-0.12-0.21.pre5.el6_3.i686.rpm ppc64: elinks-0.12-0.21.pre5.el6_3.ppc64.rpm elinks-debuginfo-0.12-0.21.pre5.el6_3.ppc64.rpm s390x: elinks-0.12-0.21.pre5.el6_3.s390x.rpm elinks-debuginfo-0.12-0.21.pre5.el6_3.s390x.rpm x86_64: elinks-0.12-0.21.pre5.el6_3.x86_64.rpm elinks-debuginfo-0.12-0.21.pre5.el6_3.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: i386: elinks-0.12-0.21.pre5.el6_3.i686.rpm elinks-debuginfo-0.12-0.21.pre5.el6_3.i686.rpm x86_64: elinks-0.12-0.21.pre5.el6_3.x86_64.rpm elinks-debuginfo-0.12-0.21.pre5.el6_3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2012-4545 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2013 Red Hat, Inc. . Address a critical elinks vulnerability via the newest Red Hat release. Ensure safety by implementing essential upgrade procedures.. Red Hat Enterprise, elinks security, client credential attack, server impersonation. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.