A vulnerability in the GNOME desktop library may allow attackers to escape the sandbox.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201908-28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: GNOME desktop library: Security bypass Date: August 31, 2019 Bugs: #692782 ID: 201908-28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in the GNOME desktop library may allow attackers to escape the sandbox. Background ========= Library with common API for various GNOME modules. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 gnome-base/gnome-desktop < 3.30.2.3 > = 3.30.2.3 Description ========== A vulnerability was discovered in the GNOME desktop library which allows an attacker to escape the sandbox. Impact ===== A local attacker could possibly bypass sandbox protection. Workaround ========= There is no known workaround at this time. Resolution ========= All GNOME desktop library users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =gnome-base/gnome-desktop-3.30.2.3" References ========= [ 1 ] CVE-2019-11460 https://nvd.nist.gov/vuln/detail/CVE-2019-11460 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201908-28 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is ofutmost importance to us. Any security concerns should be addressed to
Several security issues were fixed in Jinja2.. =========================================================================Ubuntu Security Notice USN-4011-1 June 06, 2019 jinja2 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.04 - Ubuntu 18.10 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Jinja2. Software Description: - jinja2: small but fast and easy to use stand-alone template engine Details: Olivier Dony discovered that Jinja incorrectly handled str.format. An attacker could possibly use this issue to escape the sandbox. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10745) Brian Welch discovered that Jinja incorrectly handled str.format_map. An attacker could possibly use this issue to escape the sandbox. (CVE-2019-10906) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04: python-jinja2 2.10-1ubuntu0.19.04.1 python3-jinja2 2.10-1ubuntu0.19.04.1 Ubuntu 18.10: python-jinja2 2.10-1ubuntu0.18.10.1 python3-jinja2 2.10-1ubuntu0.18.10.1 Ubuntu 18.04 LTS: python-jinja2 2.10-1ubuntu0.18.04.1 python3-jinja2 2.10-1ubuntu0.18.04.1 Ubuntu 16.04 LTS: python-jinja2 2.8-1ubuntu0.1 python3-jinja2 2.8-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4011-1 CVE-2016-10745, CVE-2019-10906 Package Information: https://launchpad.net/ubuntu/+source/jinja2/2.10-1ubuntu0.19.04.1 https://launchpad.net/ubuntu/+source/jinja2/2.10-1ubuntu0.18.10.1 https://launchpad.net/ubuntu/+source/jinja2/2.10-1ubuntu0.18.04.1 https://launchpad.net/ubuntu/+source/jinja2/2.8-1ubuntu0.1 . Jinja2 security flaws addressed in Ubuntu versions 16.04 through 19.04. Ensure your system is current to mitigate vulnerabilities.. Ubuntu Security, Jinja2 Vulnerabilities, Update Instructions. . Severity: Critical. LinuxSecurity.com Team
Updated ghostscript packages fix many bugs and security vulnerabilities: Bypassing executeonly to escape -dSAFER sandbox. (CVE-2018-17961) Saved execution stacks can leak operator arrays. (CVE-2018-18073) . MGASA-2018-0408 - Updated ghostscript packages fix security vulnerabilities Publication date: 19 Oct 2018 URL: https://advisories.mageia.org/MGASA-2018-0408.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-17961, CVE-2018-18073, CVE-2018-18284 Updated ghostscript packages fix many bugs and security vulnerabilities: Bypassing executeonly to escape -dSAFER sandbox. (CVE-2018-17961) Saved execution stacks can leak operator arrays. (CVE-2018-18073) 1Policy operator gives access to .forceput. (CVE-2018-18284) References: - https://bugs.mageia.org/show_bug.cgi?id=23659 - https://www.openwall.com/lists/oss-security/2018/10/09/4 - https://www.openwall.com/lists/oss-security/2018/10/11/3 - https://www.openwall.com/lists/oss-security/2018/10/10/12 - https://www.openwall.com/lists/oss-security/2018/10/16/2 - https://www.cve.org/CVERecord?id=CVE-2018-17961 - https://www.cve.org/CVERecord?id=CVE-2018-18073 - https://www.cve.org/CVERecord?id=CVE-2018-18284 SRPMS: - 6/core/ghostscript-9.25-1.2.mga6 . Revamped ghostscript updates rectify vulnerabilities within Mageia 6, boosting package reliability and overall system protection.. Mageia Updates, Ghostscript Security, Software Integrity. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.