Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The system could be made to crash or run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-5783-1 December 16, 2022 linux-oem-5.17 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: The system could be made to crash or run programs as an administrator. Software Description: - linux-oem-5.17: Linux kernel for OEM systems Details: Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation in the Linux kernel contained multiple use-after-free vulnerabilities. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: linux-image-5.17.0-1025-oem 5.17.0-1025.26 linux-image-oem-22.04 5.17.0.1025.23 linux-image-oem-22.04a 5.17.0.1025.23 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: CVE-2022-42896 Package Information: https://launchpad.net/ubuntu/+source/linux-oem-5.17/5.17.0-1025.26 . The Ubuntu Security Notice USN-5784-1 highlights a vulnerability within the kernel that may allow unauthorized administrator privileges or potentially lead to system instability.. Linux Kernel Vulnerability, Ubuntu Security Update, Denial ofService. . LinuxSecurity.com Team
Less privileged Webmin users (excluding those created by Virtualmin and Cloudmin) can modify arbitrary files with root privileges, and so run commands as root (CVE-2022-30708). References: . MGASA-2022-0216 - Updated webmin packages fix security vulnerability Publication date: 03 Jun 2022 URL: https://advisories.mageia.org/MGASA-2022-0216.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-30708 Less privileged Webmin users (excluding those created by Virtualmin and Cloudmin) can modify arbitrary files with root privileges, and so run commands as root (CVE-2022-30708). References: - https://bugs.mageia.org/show_bug.cgi?id=30465 - https://webmin.com/security/ - https://webmin.com/tags/webmin-changelog/ - https://www.cve.org/CVERecord?id=CVE-2022-30708 SRPMS: - 8/core/webmin-1.994-1.mga8 . MGASA-2022-0217: New versions of Webmin for Mageia resolve a severe security vulnerability that permitted unauthorized root file access.. Mageia Webmin Security Fix, User Privilege Escalation, Webmin Update. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in Apport.. =========================================================================Ubuntu Security Notice USN-4965-2 May 25, 2021 apport vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: Several security issues were fixed in Apport. Software Description: - apport: automatically generate crash reports for debugging Details: USN-4965-1 fixed several vulnerabilities in Apport. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Original advisory details: Maik Münch discovered that Apport incorrectly handled certain information gathering operations. A local attacker could use these issues to read and write arbitrary files as an administrator, and possibly escalate privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: apport 2.20.1-0ubuntu2.30+esm1 python-apport 2.20.1-0ubuntu2.30+esm1 python3-apport 2.20.1-0ubuntu2.30+esm1 Ubuntu 14.04 ESM: apport 2.14.1-0ubuntu3.29+esm7 python-apport 2.14.1-0ubuntu3.29+esm7 python3-apport 2.14.1-0ubuntu3.29+esm7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4965-2 https://ubuntu.com/security/notices/USN-4965-1 CVE-2021-32547, CVE-2021-32548, CVE-2021-32549, CVE-2021-32550, CVE-2021-32551, CVE-2021-32552, CVE-2021-32553, CVE-2021-32554, CVE-2021-32555, CVE-2021-32556, CVE-2021-32557 . Remedies for Apport vulnerabilities on Ubuntu 14.04 and 16.04 ESM. Find guidance for updates and effects.. Apport Security Fix, Ubuntu Update, Security Notice. . LinuxSecurity.com Team
Sean Larsson of iDefense Labs discovered that the MISC-XC extension of Xorg did not correctly verify the size of allocated memory. An authenticated user could send a specially crafted X11 request and execute arbitrary code with root privileges. (CVE-2007-1003)Greg MacManus of iDefense Labs discovered that the BDF font handling code in Xorg and FreeType did not correctly verify the size of allocated memory. . =========================================================== Ubuntu Security Notice USN-448-1 April 03, 2007 freetype, libxfont, xorg, xorg-server vulnerabilities CVE-2007-1003, CVE-2007-1351, CVE-2007-1352 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 5.10 Ubuntu 6.06 LTS Ubuntu 6.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 5.10: libfreetype6 2.1.7-2.4ubuntu1.3 libxfont1 1:0.99.0+cvs.20050909-1.3 xserver-xorg-core 6.8.2-77.3 Ubuntu 6.06 LTS: libfreetype6 2.1.10-1ubuntu2.3 libxfont1 1:1.0.0-0ubuntu3.3 xserver-xorg-core 1:1.0.2-0ubuntu10.6 Ubuntu 6.10: libfreetype6 2.2.1-5ubuntu0.1 libxfont1 1:1.2.0-0ubuntu3.1 xserver-xorg-core 1:1.1.1-0ubuntu12.2 After a standard system upgrade you need to reboot your computer to effect the necessary changes. Details follow: Sean Larsson of iDefense Labs discovered that the MISC-XC extension of Xorg did not correctly verify the size of allocated memory. An authenticated user could send a specially crafted X11 request and execute arbitrary code with root privileges. (CVE-2007-1003) Greg MacManus of iDefense Labs discoveredthat the BDF font handling code in Xorg and FreeType did not correctly verify the size of allocated memory. If a user were tricked into using a specially crafted font, a remote attacker could execute arbitrary code with root privileges. (CVE-2007-1351, CVE-2007-1352) Updated packages for Ubuntu 5.10: Source archives: Size/MD5: 57463 b8f6fa3ee48672ceca86bf9625536545 Size/MD5: 695 b4b76f4eb02a68844666cecef2655e87 Size/MD5: 1245623 991ff86e88b075ba363e876f4ea58680 Size/MD5: 7087 fa6f3d6472398c4afe51232508d5bd25 Size/MD5: 771 220ed305b077585687ccec6564955b03 Size/MD5: 788911 32b390bd94e4250475702e668b2bf243 Size/MD5: 2491611 eaa8cba7cdd69c746d88c0c28fe51c5c Size/MD5: 3728 9ae8a29c6619763c73ac3c7554615886 Size/MD5: 49471925 34cba217afe2c547e3a72657a3a27e37 Architecture independent packages: Size/MD5: 65788 12bad26276ea4cb67cd2ef6959e8dc59 Size/MD5: 72432 2c968bd2d7fcc1f5f7ebbc07193f58a5 Size/MD5: 65560 073f34a0d879c566823c70a701e40aeb Size/MD5: 92072 af61cbb4688ff1affeed10a82a8660dc Size/MD5: 715620 e4f2e86619a5f21ed660eca3f03897e3 Size/MD5: 65536 e1edff49971cdb0872f71941f37950b3 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 75540 9be3f1b17f6ca112f2907b69d1e87ffa Size/MD5: 722918 748a13b1cfbdf910d89f435a822d0546 Size/MD5: 241784 bc3519b183a983495121373cd78c9456 Size/MD5: 392948 d6f2e48fe489ca394fad153c07400d14 Size/MD5: 297970 157c10e1e0db8aced07b462777318da5 Size/MD5: 377708 bfc5fba5bc6305a66dc0836712e7a91b Size/MD5: 243588 f275099ce971aa990f3d28e0d7aea5f3 Size/MD5: 65746 e85a37b8b5ca3e0150961324914dd38a Size/MD5: 65774 dd5d197fe97c558ec418dde967a914a1 Size/MD5: 1029630 40e93609ec560b44558b86cc717d2991 Size/MD5: 11740235860dfb00719c6fffddb2b4a5747abd Size/MD5: 113704 24f40fbf5593dd653e72f6c2797516c0 Size/MD5: 1526642 e357f9979668602743c2596992abee80 Size/MD5: 123324 d10670b3b2a2ae50b816062e004d1b7f Size/MD5: 3993068 d361ba44f7464198b2d990dd2f939ff3 Size/MD5: 4773852 f644788b79b0d0a6deb0bb3e27743416 Size/MD5: 126370 521f72819330e496e89a253021cf5215 Size/MD5: 73882 3ebb4a5f56625e7b78d9e536072bc763 Size/MD5: 324240 e01da75bc223cdd1b8699b19291334d6 Size/MD5: 152244 43f0e543b835068278f56c60690769bf Size/MD5: 101702 9ebbefa73e1c3194b6c04269fdb292d8 Size/MD5: 81032 5d524764bb1c2bd8b918ed563b68886e Size/MD5: 70664 2db770e3cc6802174762f55c99ffd1b4 Size/MD5: 74290 49d5ffa068a163464a569a4c8cd662f1 Size/MD5: 160244 e59c1b781ec041ac3df2486743ba07cc Size/MD5: 89792 4b5528d20347eb721df443aa14be6084 Size/MD5: 168474 a98c9ebf3b71b96066ee96c461e51de1 Size/MD5: 154206 f146cd927b79c7f43fc4afe904fd7028 Size/MD5: 99620 45382b9464fc7c21021ca81f7601977a Size/MD5: 131230 d73416650296039e0d59d2a2b75f2d8e Size/MD5: 90240 5af0c68193b4349fbcd239ec482ed2ab Size/MD5: 91726 cb82c871f03ffb6e968bea210a6af75d Size/MD5: 104188 eb7e8e83da3cf9b4e7c65ed24b92a2e0 Size/MD5: 107776 31c8cc09a6a9241c91d2c03975287842 Size/MD5: 105300 e06379b5530410c398c23d24e4a2682d Size/MD5: 340896 0114deb2e7cea78860e08ada6fc9d3d9 Size/MD5: 99038 bd5c774e186120d851799de0d060ef3f Size/MD5: 88846 e611135fac9da5e514defd35fadd8025 Size/MD5: 132244 aab798cb57d644b327fe6a7bb5c51637 Size/MD5: 96404 3ee874ea69eefd45491d6ca56830f307 Size/MD5: 73392 6d5439acff5d2098ca6741cfb8ef6a00 Size/MD5: 77434 6e8e03907c375a01588e05d5e1b18b23 Size/MD5: 75352b12939451111e63dd0917362e42ec4cf Size/MD5: 70676 730768c822fa4c806bab0459866971aa Size/MD5: 80550 184a471135082d501936061092fb607f Size/MD5: 70248 656d22076f2b45ded25f4d2f08d8801a Size/MD5: 90044 676d14ebebf88b4e12114b08b169003c Size/MD5: 71032 fd5b286d4122018630fe6afec181edb6 Size/MD5: 70166 f1c622c52ee792548953adce5f372a2d Size/MD5: 69772 099498b9bb81379b15f5c24741a2befc Size/MD5: 73234 3410e093a87090fcf4ca0134c7f00ab3 Size/MD5: 70778 b37384a5c58b046fef89f487ff49f5a0 Size/MD5: 72940 b873ef7a14637241aacfbce9951b60da Size/MD5: 74632 79a5026db158fb123ff54af1e35d501d Size/MD5: 69366 8f0c8b39e5f88d657a8c038aae1305eb Size/MD5: 72022 0dd20d44c7f77c47c3dd3f7a3353b894 Size/MD5: 98390 2c172d033b5252846ceeee40990d0a16 Size/MD5: 73580 3d3b88bf32deff96a074b58a30a0cbee Size/MD5: 71608 db4f436ea8ad1ecf12698014afca127f Size/MD5: 70346 ca124fdfda754fcd9a91adb46d62a84e Size/MD5: 69124 ac4fa56df52b175d81769cc20caf3777 Size/MD5: 72888 c1279a890e388b9cdb7e8e79c6e6cafb Size/MD5: 70860 c17d207b3d04bd35ad5afa7ba56597e7 Size/MD5: 67680 77d2e92de46a38a197f62355e45a84ee Size/MD5: 101040 b66ac048fc5858c86e9dc079c79f8b38 Size/MD5: 274146 40e3014ce80f6be8852fa043105bab70 Size/MD5: 1640494 bf0c8235665a11c099cd227ad2b3a60b i386 architecture (x86 compatible Intel/AMD) Size/MD5: 52860 8f9822785a4d4feeb120b7ef6d874709 Size/MD5: 686404 46b3001cdee7cd73141461033f8f4482 Size/MD5: 209260 17f5df161bde9954b46051ef2e989159 Size/MD5: 361112 e8d31f9d89c442a5834144b374b49a54 Size/MD5: 275968 4d5e4d8c032a149c09033a3f4d078faa Size/MD5: 321688 f7e708a09b31924830357d10ad2fec40 Size/MD5: 217758 a18b74fa709fa38ba055e8e4b820a09c Size/MD5: 65750 86dfe78dfa09f1d7a52d646fb10401cf Size/MD5: 65778 5dbe48fb74851b2c6e85cd143560884a Size/MD5: 880068 69e876557cbb97c0b51a2574f2ab4a2a Size/MD5: 111442 5fb72b1e75b0a6e8a528940045233288 Size/MD5: 107366 88bf57b6009f6e5e1b74543933d90952 Size/MD5: 1282444 a1616fca7bbd45734eeac5dbadd4ddca Size/MD5: 122984 46402235fcb4c943f421d0081767c228 Size/MD5: 3393114 cf2287d566a90325bdf5d37d0d772c9f Size/MD5: 21046384 e74d9ad7ebea1118a0991b54de50b21b Size/MD5: 122974 a2d63f1a30e2e8778d3737d334224e44 Size/MD5: 72406 c79fce80a122bcb69cb8aa2840027183 Size/MD5: 300354 be69393fd4c49073fc291d4382682af6 Size/MD5: 147054 13477206d327d76ed6cc6760081b6a0d Size/MD5: 94812 6dbbfc2081ce19bd705e65a76c370b18 Size/MD5: 79216 96e108be36d7e96d1d7c61c55d2eada5 Size/MD5: 69808 919b659eacec53b4612e0fac956adca7 Size/MD5: 73250 78bb84280077b3aba53beded9161a244 Size/MD5: 74914 040afc6608d22fee2eae20ba8b0e840b Size/MD5: 159892 2780f991c85e2be15dda1635f8c98b11 Size/MD5: 87476 f4505c09091c8d4e49b3bbb345340e2e Size/MD5: 86544 d08ed7ba7921a6341be43b1b597c7c01 Size/MD5: 158570 b6a1db2cde816a16be29d2aeb627ebee Size/MD5: 73262 07d1fa25882621bad5be61b318fd3a66 Size/MD5: 143748 8868549c96ba8150954a69cbf3730801 Size/MD5: 95818 b3b86c3fdce299e35aba1f8189fe5005 Size/MD5: 74236 e55cf778b3b0f1d43604722bdd8689b2 Size/MD5: 160514 2ececee8091f44f6dd61de03d9ddf77e Size/MD5: 123050 8e43b21c9dce1af5e5b88f24b8239952 Size/MD5: 87578 52ec26ae5b375ef892d6a86f180577db Size/MD5: 88736 1538d94d86c0603bde8c1f8504121c8f Size/MD5: 100086 c31e59302ae59a2b4eeb015050922b41 Size/MD5: 102452 f1eec9b8382457b89406d69b526ad11e Size/MD5: 102018fe04cd8d4a6e461491add407142d3ff8 Size/MD5: 320680 c7a5363feaea7213a73835fb53a023dd Size/MD5: 94190 4b8e7c65cc416de4a6d4691250776493 Size/MD5: 86104 94013a70b7734e0f4205e723093f71a0 Size/MD5: 125852 2352b91c3e6f9de7f5e5d63efdb22c82 Size/MD5: 93760 809003f68c722bd4cfae1a197fc5f652 Size/MD5: 72098 5651248f206d8b9987370ebbd24531ab Size/MD5: 75834 e41fa0b5de64e33a4c38c15f947cbb37 Size/MD5: 74320 9f80f3d04c9ffd9f5a505847a7fbbc4e Size/MD5: 138682 7e1c4877500e1dca3a735dd2f33d3193 Size/MD5: 81378 ea3a2925ac33d30af17a184c1160ab34 Size/MD5: 70188 dbba5b087d2dd682d7df359c6ecf7aaa Size/MD5: 79394 52f292de69593f4126072df958002b5d Size/MD5: 69716 edd13af3e98d5f70248479424f7597c2 Size/MD5: 87794 c6c08212db44d8cf26e0884a04c2d9b9 Size/MD5: 70516 a91e7e0beab053a8ff753050c2f15b35 Size/MD5: 69564 618499e29d79c7bc8f11ffa925c09b75 Size/MD5: 69266 f457352b4675b27b7d40337cbe0a2695 Size/MD5: 71954 153e6af112f360033a37aeb4670c14cc Size/MD5: 70338 c01097e2eb0a2a3abc95a3dfa0247327 Size/MD5: 71888 2f84d4568562561ef3498c9791ccab7f Size/MD5: 73402 7e0ab015ba49f103afb96c7211ce5755 Size/MD5: 68822 4f17e665de66a9940ff3c6722fb08198 Size/MD5: 71282 ac55322bb00e6c33b1f764e47a2896e2 Size/MD5: 96556 c3fce835be42eb0c31d03056fac32376 Size/MD5: 72546 05232e76ad9b9dc93d3db86c423d1b7c Size/MD5: 71022 4fd42ec380a437249a026bedc2e44cfe Size/MD5: 69748 7f95915c766d8f5486b6ee4af5f824ca Size/MD5: 68636 6e64a58144fd2364f5a27cacadc668a4 Size/MD5: 71956 f9a757c36bec95a75413995401d7fec8 Size/MD5: 70302 2ec147acfc14c068896185d2dd01887a Size/MD5: 67446 ca456ab89714cb807ab26dfa676578b2 Size/MD5: 969862799f489d096d23cc91037d7705f7abd Size/MD5: 274176 ea1d2fc5b60b7754d47ada4cbbe7a612 Size/MD5: 1383664 7fca88ca86e1d9545c0a5a7ed877f2cf powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 80654 12c06589e94a6d6da139a27d5bd48b4c Size/MD5: 729308 9c85d5592d0f162884bc52bc82e09457 Size/MD5: 230642 65a12121f60f8096bea04955e30ae42a Size/MD5: 382478 7b1ac5f12fdba3482ad3251c3c24bef3 Size/MD5: 286022 d37d7708a0341cd63c1390fb0ff387a9 Size/MD5: 373114 ed63b7e61d8a65f90cd8c3599d0c96a6 Size/MD5: 237726 289174b8732579cc6b38f50f6398525e Size/MD5: 65746 c5de437f4027dec1acb8640bf14c4ccf Size/MD5: 65774 9d5e6b227f9799035e83f10ffa1f4cbe Size/MD5: 1006498 218159bdb9b8b250ef184881db5364e6 Size/MD5: 114636 384d4379cf21cc360da3f74252dc6e48 Size/MD5: 110580 054183b9a9c8a86fefac3017592eeb3f Size/MD5: 1477044 d49494dfeb3fbb06cc60ac2397b104b4 Size/MD5: 123370 5084044b08a994ade1e05ca769fbfeab Size/MD5: 4153716 d136a45467ed83aa7c9be079d38bbea1 Size/MD5: 17841844 cc6a10b4f49e0a3dc197f4b4a25be310 Size/MD5: 316180 8da85e525823bd09bc3648d5f642baad Size/MD5: 158800 f6957aec1dfb811624d4223b3b8792c3 Size/MD5: 74910 886ebb1cc261a13774fb37442f67b04b Size/MD5: 177164 4df697145e0bc9e405269f370c098ad3 Size/MD5: 74766 af48765f0b61b699ef013e7fb91d0563 Size/MD5: 154718 49e8c9067f4196f735100fdb88abf241 Size/MD5: 133938 1f37af997b732cce638c2f442ac32c27 Size/MD5: 98722 fd531207bb51ee7557839113134c03de Size/MD5: 107536 eb327385a5f0410f9a1180d7c6808903 Size/MD5: 110162 a70cd8531c61382bcc07b92a34202bed Size/MD5: 368234 fde514af99dfabf48ab685c95a95249b Size/MD5: 100614 d6dabc2023c08f6379f0fb98d3c076b3 Size/MD5: 142422 42f616549b5dac01f66403b64d5c5e5c Size/MD5: 74212 d6d45dde725417a9a4b014c65a41cb12 Size/MD5: 76358 450f581f1d862d20f67f0054ea46cc66 Size/MD5: 70846 9b2d0fa88f4fa0edacffdef2ee62901a Size/MD5: 82626 b4af3fee8db47771e9325f634119c6b4 Size/MD5: 70766 2f945c77af13fed6788bdabc71c312ce Size/MD5: 93244 e8dee7a2b70acb94d51c7cd1c1e97b9c Size/MD5: 71734 e73893cfe3b9d5b693569c2382905cf1 Size/MD5: 70374 7082960291a9bb88d003eeeb4285358b Size/MD5: 69938 d7113c27bbd386c14ff9a2b712c51342 Size/MD5: 74028 4bd41187c68fa51fb0adced0ccaad0ac Size/MD5: 70956 a0f37dfd435cba240a1d3a35f27841aa Size/MD5: 74336 41cacbfcdc99b42b0264d82a7578a8ec Size/MD5: 74960 52611ed1fc10530d4ab44fd16577bce1 Size/MD5: 69550 22c49ab9f187bdca55a0fbb83857ce25 Size/MD5: 72498 44c3195bdcf64c2c5cf8504f6089e619 Size/MD5: 99586 ac9781c897e4dc052af9c9c80a4853db Size/MD5: 74312 6d10ae854f4e4a3c5f137950e307db5f Size/MD5: 71850 80b3b7bd7b567be9d5dd896e8613ec16 Size/MD5: 70548 37d1b7c034b9f792608d3e6dd2a867d1 Size/MD5: 69216 7ee83181573ac45a56f2a4fb044a5e6f Size/MD5: 74222 a0f33d1df407af5b5a6c51a5882a9e60 Size/MD5: 71126 9140e6af3e6ad35bd68a5f5968399b0b Size/MD5: 67622 d3f49e28e34a285865f8870b3eeb8aae Size/MD5: 106738 88fbfbd6e6ad9f5336552ec2e50ec9a1 Size/MD5: 274024 93076262a05833b4807e98699103d946 Size/MD5: 1590104 e71d49333a98a285fe438d08e48ca2e9 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 68646 bd18602999ade0786089cf0c117a8340 Size/MD5: 699952 0697ae616e5f96afe661a7a121eaf8ee Size/MD5: 216454 7d29da7d817ac7ff1c6d7914630493ad Size/MD5: 367276 9024cd052d0210a8bacdaff20589b06c Size/MD5: 294964 b666356962ef9506da0b76efd05c9908 Size/MD5: 3242387dfef6defc80be665990fcbdd0e08e2e Size/MD5: 232476 dd914e38e4765a07e0980dd6ad5907b8 Size/MD5: 65744 69da99ffdd8daf0a439b098b2e284b32 Size/MD5: 65772 de0733e94929d4379e05d3c88a13a285 Size/MD5: 920880 2d70ca5f3de16d1192b1c05d99e21d93 Size/MD5: 112780 bf763538fea32c5f73f85ab86438014b Size/MD5: 108622 99531cb07cdffc17daf11727bc7e11bf Size/MD5: 1357838 e4491783b6a9e3d45d19a1ffa086bc81 Size/MD5: 123326 32c21b631ab344dd58d27bf7a62c605b Size/MD5: 3746340 8e6087848c828cfc5d72cde99b21242b Size/MD5: 19778476 767707fd2df5e224381a33fa872cf19a Size/MD5: 124424 081cfba509d6784ba22518521c18aa79 Size/MD5: 73344 ca0e2f22257a9911dbbe7c9c0f479d57 Size/MD5: 302440 861d677e1de334391174481377f437cf Size/MD5: 152068 643d54a96746678c36f17c3ffd3ab91c Size/MD5: 99108 b1a219d38a08ec0a3ca4cecba79a2784 Size/MD5: 70306 2b541fd5e4f10f05266800b2f977f120 Size/MD5: 74052 448582ffd40305e797cf2815c6f9c1a0 Size/MD5: 174824 44a2ace41f17b1f0da1c3ff7199de0f0 Size/MD5: 90378 e8c95b12f1882e1f9294cb9821dff299 Size/MD5: 88784 7069730f8ea7530b607c0ecdedabe693 Size/MD5: 74196 a67897463a21167d281a29fab9414ecf Size/MD5: 151636 442a736cb4530a699e4ea844e01763a0 Size/MD5: 98780 9b374f040468ddfa4c8559c63e4598e1 Size/MD5: 75054 e41f20599375cef562d50cfd5ea91f22 Size/MD5: 130164 7d81597fa246853896dee123c93a3443 Size/MD5: 89382 0c4f8f40654fdd09e520145ca2e886bd Size/MD5: 105294 1f6862c1c719219da1b965623774def5 Size/MD5: 107562 634a4e99cee1f7ed5a96fa6d1e5053aa Size/MD5: 106838 ca4bcbbcbb250fc4374477ef17dd5dbd Size/MD5: 68678 95aa8f3f675f84b9b445fd5a85c75952 Size/MD5: 69252 2d87f35b35295d29bdd76a8172351ac2 Size/MD5: 687348809dd6543372feddd2a5886f6976776 Size/MD5: 69728 1b59fdb3a45e0a569445b34d064d0633 Size/MD5: 127670 0b38955174a4ed44bd4578c87da66684 Size/MD5: 81660 117464ff17f748d0c95aa59f89abf250 Size/MD5: 70446 e69222c475300674077226d927e4a156 Size/MD5: 99410 33d1cafe6bf0edca99ba9392966d6ab7 Size/MD5: 87728 726ce3e0143dafcd495e3de4a40cf8c0 Size/MD5: 131950 e98574be1b719debd2c4542b199cdfcc Size/MD5: 73412 b1d2672fcf4c22e883e9b93ddfe70e1a Size/MD5: 76710 1254832b3fa89d4cf901bce0bb79c6ba Size/MD5: 75206 36b39c918f6061dd11711972d2025110 Size/MD5: 82618 c65b2958ebcc66702c6db1a24aee3813 Size/MD5: 70412 26c69d8e78229e07af1aa8176594728d Size/MD5: 80920 710cf56fd1e938d25cd1b0ad6a524a08 Size/MD5: 70316 83f3d61a2bed0574b25b2b0afb808ff6 Size/MD5: 91828 01867c3013e5a645d22cd97dc2068e1c Size/MD5: 71154 447987785afddd40f58871ed82d1d8c7 Size/MD5: 69880 df7253bb410088887e963b4ec185a761 Size/MD5: 69582 772f0ae3564c523c6f010b9e54b9dbe6 Size/MD5: 73168 0a6bc07c0a89ed382852a9f22212882f Size/MD5: 70622 a647189fd612aad8b9d57ee1d8d29da4 Size/MD5: 73350 e5ca5c4d5c85b8b58a2d966c9cc122a5 Size/MD5: 74194 2d9b7ab568db94f2fdfbf9208c51f269 Size/MD5: 69170 bd51f60f99bea164a1655bf99d81080d Size/MD5: 71910 f439b8d1778d01df70f869e04d0f916a Size/MD5: 97820 daa144c86465f941bad248f7f2011095 Size/MD5: 73544 67eead253f6f73a4c95cff9ee3fe5e45 Size/MD5: 71470 462bf1db6bf06a3541c048e978f619e1 Size/MD5: 70044 56d63787661918acfa11b4c2edf1b363 Size/MD5: 68896 407a96555ef0aca1c0f862756985bcc4 Size/MD5: 73208 c124d986e5ede6f22d2e6e4468ef44da Size/MD5: 70788 139b257d986d1d81abc5df96ff6c07ac Size/MD5: 67526da4b3fa6d2ea2cd03ff074fae1f99e11 Size/MD5: 102200 d20486be0bd003c871362662945890ce Size/MD5: 274186 2936a9182f8fe998082ea1b094cb4d84 Size/MD5: 1463574 ed56597df856cf23c99ea94b0df46132 Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 59540 862bd1b35276a1f6295ab86afbb0c585 Size/MD5: 710 e45aa32ea5d21cea1443eef299963ab6 Size/MD5: 1323617 adf145ce51196ad1b3054d5fb032efe6 Size/MD5: 7292 53e0bf4639f85be2596ea73128f9786f Size/MD5: 743 fb5f2db984b7aa11cc61b95c08908f4e Size/MD5: 816966 29c00c678d4ac9bea8ffe7ba264825d0 Size/MD5: 31362 fb578e86128d4cefd37470d2b1b7a800 Size/MD5: 1804 b8fa2ff2adefb6457a217c145f0a99ee Size/MD5: 7966941 f44f0f07136791ed7a4028bd0dd5eae3 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 133862 9849bf94a3c83769fee1c8c40cc5a195 Size/MD5: 717494 0b0587f17aa8338d68f00f4f6de40cf8 Size/MD5: 251748 ea23cce32b15ed7b944ceea15a7c28c4 Size/MD5: 439876 f4511db24d690e234e2c6157f6f0d86d Size/MD5: 302752 cdb9b9f31fc890e1f81b6b84e62e6743 Size/MD5: 375884 261b8c8db1350e1729a58bf14455f0d2 Size/MD5: 242806 0d259ee4f74d911e61e8d6c1c3fd45a9 Size/MD5: 49900 6cd998c1385119c61c656454fcafdc57 Size/MD5: 848976 1de01ffe87bc9aad344ceebf57136501 Size/MD5: 1414328 fcd5128c61ea7c91f5dd0fdd67eb04fd Size/MD5: 4048070 8a20c1e88020a82b1831541874ce7c48 Size/MD5: 294524 6b2619e3fbfc72356dc7afa6ee3afa0e Size/MD5: 1564542 9ba68a1f137e86d212d7eb264008f4cd i386 architecture (x86 compatible Intel/AMD) Size/MD5: 117358 a678e7f1914fdc53c66bc12b2563c104 Size/MD5: 677468 1245a799d53d0326992d1fa22bad875b Size/MD5: 227264 9c15e03342736754f33977e838c6d801 Size/MD5: 415384 7ae6d5bbe1a4bde544290a80a3e3dc3f Size/MD5: 279004 3551439419ec533ee6e13b4ddad9879f Size/MD5: 320798 e118c7ba341674944cd61dce7dd45266 Size/MD5: 216576 9357f5af25709f7e2c5627960a1c965c Size/MD5: 42444 13fe0025f651e11decf5072e9ba7c88e Size/MD5: 748738 8c8fb9a5513045b418ffc3c37337aaa9 Size/MD5: 1241568 96276d9b49ce87040e0d355de948d7af Size/MD5: 3531364 addce36a358f8e1566118b490517d0d1 Size/MD5: 294542 401c8007c96f3468eee908422fe384d5 Size/MD5: 1382554 bfdc3acaba7eae4bfa8f09466c1a14f1 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 134248 3f73867444b6902b21ece5e88bda5736 Size/MD5: 708456 fd230d35b21882e8f33a733571589eb3 Size/MD5: 241444 985d65e2f522108b58cbb7101a1c4e93 Size/MD5: 429892 e96a4115854d6b32907a3249bda2a0b4 Size/MD5: 290970 714aaa371169f80396afd1d5d0bc082a Size/MD5: 369962 cda66f3b003f5faeabe2225356ff414c Size/MD5: 235378 3086125be0dd5bb2480f31d4a21b46c6 Size/MD5: 55158 3d6a6b1cf5be95e00a48e5523d641d29 Size/MD5: 825340 a5329d0d2322ebb0c2d102a47635216f Size/MD5: 1368184 0e1b6171168a996773c760b8b875648e Size/MD5: 4076112 3668d14302e64241292219b67e1f9659 Size/MD5: 294538 5ef1c38d239ef6e6ac65d852d96c1665 Size/MD5: 1506656 fc1885b7b5f482fe734f5d081b072b51 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 120076 f0524701f9defa5d49f80b333dba9161 Size/MD5: 683560 22024047655d0a6e26c484d1d231be3c Size/MD5: 222408 4a26ce30531b338bc5ce9e16bfcda691 Size/MD5: 410888 897071c782c16c0e3000a9c4586e184f Size/MD5: 297866 0775567bab801a064f92e79c0939886c Size/MD5: 321246 8e57f2843bf6cb39a8cbde389c740872 Size/MD5: 229820 c0e50a0ea242052b971dbd43f4144d6f Size/MD5: 43880 705741e8b4a3cd9b591da2a1b85db401 Size/MD5: 758608 92ca7b1ee8f4509a4222c1dae58cb288 Size/MD5: 1313218 208167a5f9f5d074bf1f162da5377664 Size/MD5: 3789064 d7127a902bc8951e03e70baece970b34 Size/MD5: 294998 c2d3c3b6673c8c8f70d23db3712c134b Size/MD5: 1445764 a1efd9aa2fa04d62f69771887a5d557f Updated packages for Ubuntu 6.10: Source archives: Size/MD5: 32265 c95bae22cdf8aff7dd045ffd19b84acb Size/MD5: 804 3c64a49cc8029e44361ec5b5dbac0a96 Size/MD5: 1451392 a584e84d617c6e7919b4aef9b5106cf4 Size/MD5: 21080 14f360ae2e6a5c3a535ba34244f513c9 Size/MD5: 923 df21beb2608cc68aa140d315041d9795 Size/MD5: 827186 b4cb7808df5804efeb457043fed13782 Size/MD5: 92001 cbe621e817e97c8a67ee7465bf3fa266 Size/MD5: 2020 e4b095a246fd0a52f314ce371b3e0cb6 Size/MD5: 8388609 15852049050e49f380f953d8715500b9 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 150940 92d6b1c0aa652e6e8f013ae4048f4062 Size/MD5: 668960 0e5ff244ad6488cd3eb801b3768b7eda Size/MD5: 248264 4328e1df8f13a92086bc6dc0c43add50 Size/MD5: 353738 c41d6ae077ca5f31a25cc0f58cbd93c9 Size/MD5: 305140 eaa2799e4a889de2924c16629750c749 Size/MD5: 354690 d06520d61f32e74f26764e6dbc1c14c4 Size/MD5: 242998 5e24330de281bfc1bd33341abb57d967 Size/MD5: 57434 5edf610ecbdd99e59f118959ca0eb414 Size/MD5: 813654 4da55af97b7c83f85c557df79f66c0c2 Size/MD5: 1427180 efafeb1045b436463419496481cfdc78 Size/MD5: 1608506 39e8887d0c3b1d4b4059a990ccacc07b Size/MD5: 3917424 d69cc89a0777f800d5e74e3a8041fd93 Size/MD5: 297442 b41410b7b585f2960827f912241891bc Size/MD5: 1579394 facb0f2f9c2722e4d07af7dea9f838e5 i386 architecture (x86 compatible Intel/AMD) Size/MD5: 134026 6a3c9319eba74a20e6f5c0e3457a2e97 Size/MD5: 640492 bb5ed3196a9e9fb626c17d96f40b3b2e Size/MD5: 235400cde67a8b74de363b4d3e1abe0f41e781 Size/MD5: 341274 5aee6b86c26c312e17acf68808b737cc Size/MD5: 291958 2344c15719ade83c6e125e29e4b86c23 Size/MD5: 336952 fe81984c7c8cf4a8ca6a0f44998bc0eb Size/MD5: 226028 5456ac2131d824a096d1e979cecfcea4 Size/MD5: 50646 23cd4f9ca5689117c09c43ebdcfea49e Size/MD5: 751476 f3769d8fb8508eca644db0c8d9530a08 Size/MD5: 1327210 73b1fa3c9d0e365f029962cb4e920b8e Size/MD5: 1498720 e7e629d60198742c9040687d9c02d108 Size/MD5: 3563454 7f18073d92ab9a8a5fbb096b483598b5 Size/MD5: 297484 7d506b6a3fee567e20a2a5e7aa6c2bc7 Size/MD5: 1475138 fffb6ddb7a71160b492de7c8987cfc9b powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 148582 24a4dc3fcd4e9ed1cc439178926016b4 Size/MD5: 663380 d84c7eab9c0a1678485b5c10c99e227d Size/MD5: 241628 bff6e436dc7884091e9a159425fb3345 Size/MD5: 346870 8da887f46827f7a148b9d5573d6cb526 Size/MD5: 295948 e373a2fb962bbd917ed1475707925379 Size/MD5: 353796 9ad2219e7d15c1e5267c922f5d518954 Size/MD5: 237280 a187dc106461ded50a6cafe3b7e5442d Size/MD5: 63432 d611ac901c34e99a1cfc77956c6f42c4 Size/MD5: 797454 d0208072254a9e1e6041b12f660a7cf0 Size/MD5: 1401888 9af060d4e15bcbc8bd55ec3b77f8f733 Size/MD5: 1565976 22e88a95a1d3dc23299f782df124578e Size/MD5: 3983002 3345dba424bb25e0862b66acda8747d8 Size/MD5: 297498 55dd5abe4abf1c7ef441c85dc070e68a Size/MD5: 1541334 474f69d831b778c5825ae02d340556e2 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 131806 c3d342df6c666a6ff77ad70c7c729297 Size/MD5: 635934 2ba5cf3a10353ed63a2b08a5ebd038ff Size/MD5: 220156 4f9315e0d159b61aed69ae09c8282b82 Size/MD5: 325494 95813d719f39a3b86f6b44cda4519a83 Size/MD5: 304582 8bca3c95b9e5f10d08357fb32ffa690c Size/MD5: 321526 1765ba83a127b01ed81632785688a0b0 Size/MD5: 234114 fd5c8e1b70051aeae6d189037043c23e Size/MD5: 50314 9fdc77ad9a5448d3b92c3b05fcfc4ac1 Size/MD5: 733754 8d5052a6cb973b478b57efcf9535020b Size/MD5: 1344340 10ad7e4b138b14102ab3a396fa31255f Size/MD5: 1500142 801229631c468c808bc3570a02f36436 Size/MD5: 3695516 c037048a7c2971f1c064e1644083a738 Size/MD5: 297856 45e8359cdae581b6ab4d5ad683a4ba89 Size/MD5: 1477724 8d6c6d871e63e6009ab6f9be3b10300f . Address Xorg security issues affecting various Ubuntu versions with urgent patches to avert unauthorized code execution.. Ubuntu Security, Xorg Vulnerabilities, Memory Handling, Code Execution. . Severity: Critical. LinuxSecurity.com Team
A vulnerability in GKSu might allow attackers to execute arbitrary commands.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201812-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: GKSu: Arbitrary command execution Date: December 30, 2018 Bugs: #534540 ID: 201812-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in GKSu might allow attackers to execute arbitrary commands. Background ========= A library that provides a Gtk+ frontend to su and sudo. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 x11-libs/gksu
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for znc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2231-1 Rating: moderate References: #1101280 #1101281 Cross-References: CVE-2018-14055 CVE-2018-14056 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for znc fixes the following issues: - Update to version 1.7.1 * CVE-2018-14055: non-admin user could gain admin privileges and shell access by injecting values into znc.conf (bnc#1101281) * CVE-2018-14056: path traversal in HTTP handler via ../ in a web skin name. (bnc#1101280) - Update to version 1.7.0 * Make ZNC UI translateable to different languages * Configs written before ZNC 0.206 can't be read anymore * Implement IRCv3.2 capabilities away-notify, account-notify, extended-join * Implement IRCv3.2 capabilities echo-message, cap-notify on the "client side" * Update capability names as they are named in IRCv3.2: znc.in/server-time-iso?server-time, znc.in/batch?batch. Old names will continue working for a while, then will be removed in some future version. * Make ZNC request server-time from server when available * Add "AuthOnlyViaModule" global/user setting * Stop defaulting real name to "Got ZNC?" * Add SNI SSL client support * Add support for CIDR notation in allowed hosts list and in trusted proxy list * Add network-specific config for cert validation in addition to user-supplied fingerprints: TrustAllCerts, defaults to false, and TrustPKI, defaults to true. * Add /attach command for symmetry with /detach. Unlike /join it allows wildcards. - Update to version 1.6.6: * Fix use-after-free in znc --makepem. It was broken for a long time, but started segfaulting only now. This is a useability fix, not a security fix, because self-signed (or signed by a CA) certificates can be created without using --makepem, and then combined into znc.pem. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-819=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-819=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): znc-1.7.1-20.3.1 znc-debuginfo-1.7.1-20.3.1 znc-debugsource-1.7.1-20.3.1 znc-devel-1.7.1-20.3.1 znc-perl-1.7.1-20.3.1 znc-perl-debuginfo-1.7.1-20.3.1 znc-python3-1.7.1-20.3.1 znc-python3-debuginfo-1.7.1-20.3.1 znc-tcl-1.7.1-20.3.1 znc-tcl-debuginfo-1.7.1-20.3.1 - openSUSE Leap 42.3 (noarch): znc-lang-1.7.1-20.3.1 - openSUSE Leap 15.0 (x86_64): znc-1.7.1-lp150.2.6.1 znc-debuginfo-1.7.1-lp150.2.6.1 znc-debugsource-1.7.1-lp150.2.6.1 znc-devel-1.7.1-lp150.2.6.1 znc-perl-1.7.1-lp150.2.6.1 znc-perl-debuginfo-1.7.1-lp150.2.6.1 znc-python3-1.7.1-lp150.2.6.1 znc-python3-debuginfo-1.7.1-lp150.2.6.1 znc-tcl-1.7.1-lp150.2.6.1 znc-tcl-debuginfo-1.7.1-lp150.2.6.1 - openSUSE Leap 15.0 (noarch): znc-lang-1.7.1-lp150.2.6.1 References: https://www.suse.com/security/cve/CVE-2018-14055.html https://www.suse.com/security/cve/CVE-2018-14056.html https://bugzilla.suse.com/1101280 https://bugzilla.suse.com/1101281 -- . This Fedora patch resolves various vulnerabilities in nginx, enhancing reliability and user management overall.. openSUSE Security, ZNC Admin Issue, Security Update, Software Vulnerability. . LinuxSecurity.com Team
It was found that some selectivity estimation functions did not check user privileges before providing information from pg_statistic, possibly leaking information. A non-administrative database user could use this flaw to steal some information from tables they are otherwise not allowed to access. (CVE-2017-7484) * It was found that the pg_user_mappings view could disclose information about u [More...]. Synopsis: Moderate: postgresql security and enhancement update Advisory ID: SLSA-2017:1983-1 Issue Date: 2017-08-01 CVE Numbers: CVE-2017-7484 CVE-2017-7486 -- The following packages have been upgraded to a later upstream version: postgresql (9.2.21). Security Fix(es): * It was found that some selectivity estimation functions did not check user privileges before providing information from pg_statistic, possibly leaking information. A non-administrative database user could use this flaw to steal some information from tables they are otherwise not allowed to access. (CVE-2017-7484) * It was found that the pg_user_mappings view could disclose information about user mappings to a foreign database to non-administrative database users. A database user with USAGE privilege for this mapping could, when querying the view, obtain user mapping data, such as the username and password used to connect to the foreign database. (CVE-2017-7486) -- SL7 x86_64 postgresql-debuginfo-9.2.21-1.el7.i686.rpm postgresql-debuginfo-9.2.21-1.el7.x86_64.rpm postgresql-libs-9.2.21-1.el7.i686.rpm postgresql-libs-9.2.21-1.el7.x86_64.rpm postgresql-9.2.21-1.el7.i686.rpm postgresql-9.2.21-1.el7.x86_64.rpm postgresql-contrib-9.2.21-1.el7.x86_64.rpm postgresql-devel-9.2.21-1.el7.i686.rpm postgresql-devel-9.2.21-1.el7.x86_64.rpm postgresql-docs-9.2.21-1.el7.x86_64.rpm postgresql-plperl-9.2.21-1.el7.x86_64.rpm postgresql-plpython-9.2.21-1.el7.x86_64.rpm postgresql-pltcl-9.2.21-1.el7.x86_64.rpm postgresql-server-9.2.21-1.el7.x86_64.rpm postgresql-static-9.2.21-1.el7.i686.rpm postgresql-static-9.2.21-1.el7.x86_64.rpm postgresql-test-9.2.21-1.el7.x86_64.rpm postgresql-upgrade-9.2.21-1.el7.x86_64.rpm - Scientific Linux Development Team . Scheduled PostgreSQL upgrade on Scientific Linux to address security vulnerabilities related to memory leaks and enhance data access management. Advisory ID: SLSA-2017:1983-1.. postgresql security, scientific linux update, data leak issues, user privilege management. . LinuxSecurity.com Team
An updated thunderbird package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5, 6, and 7. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2016:0460-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:0460.html Issue date: 2016-03-16 CVE Names: CVE-2016-1952 CVE-2016-1954 CVE-2016-1957 CVE-2016-1960 CVE-2016-1961 CVE-2016-1964 CVE-2016-1966 CVE-2016-1974 CVE-2016-1977 CVE-2016-2790 CVE-2016-2791 CVE-2016-2792 CVE-2016-2793 CVE-2016-2794 CVE-2016-2795 CVE-2016-2796 CVE-2016-2797 CVE-2016-2798 CVE-2016-2799 CVE-2016-2800 CVE-2016-2801 CVE-2016-2802 ==================================================================== 1. Summary: An updated thunderbird package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5, 6, and 7. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Optional Productivity Applications (v. 5 server) - i386, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64le,x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: Mozilla Thunderbird is a standalone mail and newsgroup client. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2016-1952, CVE-2016-1954, CVE-2016-1957, CVE-2016-1960, CVE-2016-1961, CVE-2016-1974, CVE-2016-1964, CVE-2016-1966) Multiple security flaws were found in the graphite2 font library shipped with Thunderbird. A web page containing malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2016-1977, CVE-2016-2790, CVE-2016-2791, CVE-2016-2792, CVE-2016-2793, CVE-2016-2794, CVE-2016-2795, CVE-2016-2796, CVE-2016-2797, CVE-2016-2798, CVE-2016-2799, CVE-2016-2800, CVE-2016-2801, CVE-2016-2802) Red Hat would like to thank the Mozilla project for reporting these issues. Upstream acknowledges Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel Holbert, Jesse Ruderman, Randell Jesup, Nicolas Golubovic, Jose Martinez, Romina Santillan, ca0nguyen, lokihardt, Nicolas Grégoire, the Communications Electronics Security Group (UK) of the GCHQ, Holger Fuhrmannek, Ronald Crane, and Tyson Smith as the original reportersof these issues. For technical details regarding these flaws, refer to the Mozilla security advisories for Thunderbird 38.7.0. You can find a link to the Mozilla advisories in the References section of this erratum. All Thunderbird users should upgrade to this updated package, which contains Thunderbird version 38.7.0, which corrects these issues. After installing the update, Thunderbird must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. Fordetails on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1315566 - CVE-2016-1952 Mozilla: Miscellaneous memory safety hazards (rv:38.7) (MFSA 2016-16) 1315569 - CVE-2016-1954 Mozilla: Local file overwriting and potential privilege escalation through CSP reports (MFSA 2016-17) 1315573 - CVE-2016-1957 Mozilla: Memory leak in libstagefright when deleting an array during MP4 processing (MFSA 2016-20) 1315576 - CVE-2016-1960 Mozilla: Use-after-free in HTML5 string parser (MFSA 2016-23) 1315577 - CVE-2016-1961 Mozilla: Use-after-free in SetBody (MFSA 2016-24) 1315774 - CVE-2016-1964 Mozilla: Use-after-free during XML transformations (MFSA 2016-27) 1315778 - CVE-2016-1966 Mozilla: Memory corruption with malicious NPAPI plugin (MFSA 2016-31) 1315785 - CVE-2016-1974 Mozilla: Out-of-bounds read in HTML parser following a failed allocation (MFSA 2016-34) 1315795 - graphite2: multiple font parsing vulnerabilities (Mozilla MFSA 2016-37) 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: thunderbird-38.7.0-1.el5_11.src.rpm i386: thunderbird-38.7.0-1.el5_11.i386.rpm thunderbird-debuginfo-38.7.0-1.el5_11.i386.rpm x86_64: thunderbird-38.7.0-1.el5_11.x86_64.rpm thunderbird-debuginfo-38.7.0-1.el5_11.x86_64.rpm Red Hat Enterprise Linux Optional Productivity Applications (v. 5 server): Source: thunderbird-38.7.0-1.el5_11.src.rpm i386: thunderbird-38.7.0-1.el5_11.i386.rpm thunderbird-debuginfo-38.7.0-1.el5_11.i386.rpm x86_64: thunderbird-38.7.0-1.el5_11.x86_64.rpm thunderbird-debuginfo-38.7.0-1.el5_11.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 6): Source: thunderbird-38.7.0-1.el6_7.src.rpm i386: thunderbird-38.7.0-1.el6_7.i686.rpm thunderbird-debuginfo-38.7.0-1.el6_7.i686.rpm x86_64: thunderbird-38.7.0-1.el6_7.x86_64.rpm thunderbird-debuginfo-38.7.0-1.el6_7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.6): Source: thunderbird-38.7.0-1.el6_7.src.rpm i386: thunderbird-38.7.0-1.el6_7.i686.rpm thunderbird-debuginfo-38.7.0-1.el6_7.i686.rpm ppc64: thunderbird-38.7.0-1.el6_7.ppc64.rpm thunderbird-debuginfo-38.7.0-1.el6_7.ppc64.rpm s390x: thunderbird-38.7.0-1.el6_7.s390x.rpm thunderbird-debuginfo-38.7.0-1.el6_7.s390x.rpm x86_64: thunderbird-38.7.0-1.el6_7.x86_64.rpm thunderbird-debuginfo-38.7.0-1.el6_7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: thunderbird-38.7.0-1.el6_7.src.rpm i386: thunderbird-38.7.0-1.el6_7.i686.rpm thunderbird-debuginfo-38.7.0-1.el6_7.i686.rpm x86_64: thunderbird-38.7.0-1.el6_7.x86_64.rpm thunderbird-debuginfo-38.7.0-1.el6_7.x86_64.rpm Red Hat Enterprise Linux Client (v. 7): Source: thunderbird-38.7.0-1.el7_2.src.rpm x86_64: thunderbird-38.7.0-1.el7_2.x86_64.rpm thunderbird-debuginfo-38.7.0-1.el7_2.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): Source: thunderbird-38.7.0-1.el7_2.src.rpm ppc64le: thunderbird-38.7.0-1.el7_2.ppc64le.rpm thunderbird-debuginfo-38.7.0-1.el7_2.ppc64le.rpm x86_64: thunderbird-38.7.0-1.el7_2.x86_64.rpm thunderbird-debuginfo-38.7.0-1.el7_2.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: thunderbird-38.7.0-1.el7_2.src.rpm x86_64: thunderbird-38.7.0-1.el7_2.x86_64.rpm thunderbird-debuginfo-38.7.0-1.el7_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2016-1952 https://access.redhat.com/security/cve/CVE-2016-1954 https://access.redhat.com/security/cve/CVE-2016-1957 https://access.redhat.com/security/cve/CVE-2016-1960 https://access.redhat.com/security/cve/CVE-2016-1961 https://access.redhat.com/security/cve/CVE-2016-1964 https://access.redhat.com/security/cve/CVE-2016-1966 https://access.redhat.com/security/cve/CVE-2016-1974 https://access.redhat.com/security/cve/CVE-2016-1977 https://access.redhat.com/security/cve/CVE-2016-2790 https://access.redhat.com/security/cve/CVE-2016-2791 https://access.redhat.com/security/cve/CVE-2016-2792 https://access.redhat.com/security/cve/CVE-2016-2793 https://access.redhat.com/security/cve/CVE-2016-2794 https://access.redhat.com/security/cve/CVE-2016-2795 https://access.redhat.com/security/cve/CVE-2016-2796 https://access.redhat.com/security/cve/CVE-2016-2797 https://access.redhat.com/security/cve/CVE-2016-2798 https://access.redhat.com/security/cve/CVE-2016-2799 https://access.redhat.com/security/cve/CVE-2016-2800 https://access.redhat.com/security/cve/CVE-2016-2801 https://access.redhat.com/security/cve/CVE-2016-2802 https://access.redhat.com/security/updates/classification#important https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird38.7 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFW6Zo2XlSAg2UNWIIRAjzbAJ99OWGc3kLk5XmWA5amHVK1AI36lgCfY7Ic BFmg0SBshaYX5xHuGkO3s3Q=uOtA -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Get the latest Linux and open source security news straight to your inbox.