usbredir could be made to crash or run programs if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-5784-1 January 03, 2023 usbredir vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: usbredir could be made to crash or run programs if it received specially crafted input. Software Description: - usbredir: usbredir libraries and utilities Details: It was discovered that usbredir incorrectly handled memory when serializing large amounts of data in the case of a slow or blocked destination. An attacker could possibly use this issue to cause applications using usbredir to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libusbredirhost1 0.8.0-1ubuntu0.1 libusbredirparser1 0.8.0-1ubuntu0.1 usbredirserver 0.8.0-1ubuntu0.1 Ubuntu 18.04 LTS: libusbredirhost1 0.7.1-1ubuntu0.18.04.1 libusbredirparser1 0.7.1-1ubuntu0.18.04.1 usbredirserver 0.7.1-1ubuntu0.18.04.1 Ubuntu 16.04 ESM: libusbredirhost1 0.7.1-1ubuntu0.16.04.1~esm1 libusbredirparser1 0.7.1-1ubuntu0.16.04.1~esm1 usbredirserver 0.7.1-1ubuntu0.16.04.1~esm1 Ubuntu 14.04 ESM: libusbredirhost1 0.6-2ubuntu1.1+esm1 libusbredirparser1 0.6-2ubuntu1.1+esm1 usbredirserver 0.6-2ubuntu1.1+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5784-1 CVE-2021-3700 Package Information: https://launchpad.net/ubuntu/+source/usbredir/0.8.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/usbredir/0.7.1-1ubuntu0.18.04.1 . Ubuntu Security Notice USN-5785-1 announces a vulnerability in libjpeg-turbo affecting image processing and provides steps for remediation.. usbredir Vulnerability,Software Patch,Denial Of Service,Package Update. . Severity: Critical. LinuxSecurity.com Team
A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination. (CVE-2021-3700) . MGASA-2022-0133 - Updated usbredir packages fix security vulnerability Publication date: 09 Apr 2022 URL: https://advisories.mageia.org/MGASA-2022-0133.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-3700 A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination. (CVE-2021-3700) References: - https://bugs.mageia.org/show_bug.cgi?id=30194 - https://lists.debian.org/debian-lts-announce/2022/03/msg00030.html - https://www.cve.org/CVERecord?id=CVE-2021-3700 SRPMS: - 8/core/usbredir-0.8.0-3.1.mga8 . Revamped Mageia usbredir components tackled use-after-free vulnerability to boost protection. Advisory encompasses full specifics.. usbredir security update,Mageia vulnerability,security advisory,Mageia release. . Severity: Critical. LinuxSecurity.com Team
A use-after-free vulnerability was found in Usbredirparser, a parser for the usbredir protocol, which could result in denial of service or potentially arbitrary code execution. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2958-1
Get the latest Linux and open source security news straight to your inbox.