ISC DHCP, Thunderbird, and Linux Kernel Security Advisories
Happy Friday fellow Linux geeks! This week, important updates have been issued for ISC DHCP, Thunderbird and the Linux kernel. Read on to learn about these vulnerabilities and how to secure your system against them.
Have a question about or comment on one of the vulnerabilities highlighted in today's newsletter? Let's discuss!
Check out the new Remote Access Plus solution from ManageEngine to help admins secure their servers against vulnerabilities like these by automating security patches.
Yours in Open Source,

ISC DHCPThe DiscoverySeveral vulnerabilities have been discovered in the ISC DHCP client, relay and server. It was found that the DHCP server does not correctly perform option reference counting when configured with "allow leasequery;" (CVE-2022-2928), and that the DHCP server is prone to a memory leak flaw when handling contents of option 81 (fqdn) data received in a DHCP packet (CVE-2022-2929). |
ThunderbirdThe DiscoverySeveral security issues were found in the Thunderbird open-source mail and newsgroup client (CVE-2022-2505, CVE-2022-3032, CVE-2022-3033, CVE-2022-3034, CVE-2022-36059, CVE-2022-36318, CVE-2022-36319, CVE-2022-38472, CVE-2022-38473, CVE-2022-38476, CVE-2022-38477 and CVE-2022-38478). The ImpactIf a user were tricked into opening a specially crafted website in a browsing context, an attacker could potentially exploit these flaws to cause a denial of service (DoS), spoof the mouse pointer position, obtain sensitive information, spoof the contents of the addressbar, bypass security restrictions, or execute arbitrary code. The FixThese vulnerabilities have now been addressed with an update for Mozilla Thunderbird. We recommend that you update now to protect the security, integrity and availability of your systems and the confidentiality of your sensitive information. Your Related Advisories:[distro_list_2] |
Linux KernelThe DiscoveryMultiple security issues were discovered in the Linux kernel (CVE-2021-33655, CVE-2022-1012, CVE-2022-1729, CVE-2022-2503, CVE-2022-32296 and CVE-2022-36946). The ImpactExploitation of these bugs could lead to denial of service (system crash), the execution of arbitrary code, or the exposure of sensitive information. |



