John Johansen | 25 May 21:53
Favicon

[USN-1454-1] Linux kernel vulnerability

==========================================================================
Ubuntu Security Notice USN-1454-1
May 25, 2012

linux vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 8.04 LTS

Summary:

The system could be made to crash or become unresponsive under certain
conditions.

Software Description:
- linux: Linux kernel

Details:

A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

(Continue reading)

John Johansen | 25 May 21:37
Favicon

[USN-1453-1] Linux kernel (EC2) vulnerabilities

==========================================================================
Ubuntu Security Notice USN-1453-1
May 25, 2012

linux-ec2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-ec2: Linux kernel for EC2

Details:

A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service. (CVE-2011-4086)

A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual
cpu setup. An unprivileged local user could exploit this flaw to crash the
system leading to a denial of service. (CVE-2012-1601)

Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of a process. For
(Continue reading)

John Johansen | 25 May 21:19
Favicon

[USN-1452-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-1452-1
May 25, 2012

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual
cpu setup. An unprivileged local user could exploit this flaw to crash the
system leading to a denial of service. (CVE-2012-1601)

Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of a process. For
application on which fscaps are in use a local attacker can disable address
space randomization to make attacking the process with raised privileges
easier. (CVE-2012-2123)

(Continue reading)

Steve Beattie | 25 May 00:58
Favicon

[USN-1451-1] OpenSSL vulnerabilities

==========================================================================
Ubuntu Security Notice USN-1451-1
May 24, 2012

openssl vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

Applications using OpenSSL in certain situations could be made to
crash or expose sensitive information.

Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools

Details:

Ivan Nestlerode discovered that the Cryptographic Message Syntax
(CMS) and PKCS #7 implementations in OpenSSL returned early if RSA
decryption failed. This could allow an attacker to expose sensitive
information via a Million Message Attack (MMA). (CVE-2012-0884)

(Continue reading)

Marc Deslauriers | 23 May 20:12
Favicon

[USN-1450-1] Net-SNMP vulnerability

==========================================================================
Ubuntu Security Notice USN-1450-1
May 23, 2012

net-snmp vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

Net-SNMP could be made to crash if it received specially crafted network
traffic.

Software Description:
- net-snmp: SNMP (Simple Network Management Protocol) server and applications

Details:

It was discovered that Net-SNMP incorrectly performed entry lookups in the
extension table. A remote attacker could send a specially crafted request
and cause the SNMP server to crash, leading to a denial of service.

Update instructions:
(Continue reading)

Jamie Strandboge | 22 May 21:23
Favicon

[USN-1449-1] feedparser vulnerability

==========================================================================
Ubuntu Security Notice USN-1449-1
May 22, 2012

feedparser vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Applications using feedparser could be made to crash if they fetched a
specially crafted feed.

Software Description:
- feedparser: Universal Feed Parser for Python

Details:

It was discovered that feedparser did not properly sanitize ENTITY
declarations in encoded fields. A remote attacker could exploit this to
cause a denial of service via memory exhaustion.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

(Continue reading)

John Johansen | 22 May 01:12
Favicon

[USN-1448-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-1448-1
May 21, 2012

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual
cpu setup. An unprivileged local user could exploit this flaw to crash the
system leading to a denial of service. (CVE-2012-1601)

Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of a process. For
application on which fscaps are in use a local attacker can disable address
space randomization to make attacking the process with raised privileges
easier. (CVE-2012-2123)

(Continue reading)

Jamie Strandboge | 22 May 00:15
Favicon

[USN-1447-1] libxml2 vulnerability

==========================================================================
Ubuntu Security Notice USN-1447-1
May 21, 2012

libxml2 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

Applications using libxml2 could be made to crash or run programs as your
login if they opened a specially crafted file.

Software Description:
- libxml2: GNOME XML library

Details:

Juri Aedla discovered that libxml2 contained an off by one error in its
XPointer functionality. If a user or application linked against libxml2
were tricked into opening a specially crafted XML file, an attacker could
cause the application to crash or possibly execute arbitrary code with the
privileges of the user invoking the program.
(Continue reading)

John Johansen | 18 May 03:32
Favicon

[USN-1445-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-1445-1
May 18, 2012

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service. (CVE-2011-4086)

A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual
cpu setup. An unprivileged local user could exploit this flaw to crash the
system leading to a denial of service. (CVE-2012-1601)

Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of a process. For
(Continue reading)

John Johansen | 18 May 02:38
Favicon

[USN-1445-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-1445-1
May 18, 2012

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service. (CVE-2011-4086)

A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual
cpu setup. An unprivileged local user could exploit this flaw to crash the
system leading to a denial of service. (CVE-2012-1601)

Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of a process. For
(Continue reading)

Jamie Strandboge | 18 May 00:48
Favicon

[USN-1444-1] BackupPC vulnerability

==========================================================================
Ubuntu Security Notice USN-1444-1
May 17, 2012

backuppc vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

BackupPC could be made to expose sensitive information over the network.

Software Description:
- backuppc: high-performance, enterprise-grade system for backing up PCs

Details:

It was discovered that BackupPC did not properly sanitize its input when
processing RestoreFile error messages, resulting in a cross-site
scripting (XSS) vulnerability. With cross-site scripting vulnerabilities,
if a user were tricked into viewing server output during a crafted server
request, a remote attacker could exploit this to modify the contents, or
steal confidential data, within the same domain.
(Continue reading)


Gmane