Feeds : Ubuntu
USN-674-1: HPLIP vulnerabilities (Ubuntu) 
2 h, 18 min and 24 secs ago
Referenced CVEs: CVE-2008-2940, CVE-2008-2941Description: ===========================================================
Ubuntu Security Notice USN-674-1 November 19, 2008
hplip vulnerabilities
CVE-2008-2940, CVE-2008-2941
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.10
Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
hplip 0.9.7-4ubuntu1.1
Ubuntu 7.10:
hplip 2.7.7.dfsg.1-0ubuntu5.1
Ubuntu 8.04 LTS:
hplip 2.8.2-0ubuntu8.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that the hpssd tool of hplip did not validate
privileges in the alert-mailing function. A local attacker could
exploit this to gain privileges and send e-mail messages from the
account of the hplip user. This update alters hplip behaviour by
preventing users from setting alerts and by moving alert configuration
to a root-controlled /etc/hp/alerts.conf file. (CVE-2008-2940)
It was discovered that the hpssd tool of hplip did not correctly
handle certain commands. A local attacker could use a specially
crafted packet to crash hpssd, leading to a denial of service.
(CVE-2008-2941)
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-673-1: libxml2 vulnerabilities (Ubuntu) 
22 h, 31 min and 45 secs ago
Referenced CVEs: CVE-2008-4225, CVE-2008-4226Description:
===========================================================
Ubuntu Security Notice USN-673-1 November 19, 2008
libxml2 vulnerabilities
CVE-2008-4225, CVE-2008-4226
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.10
Ubuntu 8.04 LTS
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libxml2 2.6.24.dfsg-1ubuntu1.4
Ubuntu 7.10:
libxml2 2.6.30.dfsg-2ubuntu1.4
Ubuntu 8.04 LTS:
libxml2 2.6.31.dfsg-2ubuntu1.3
Ubuntu 8.10:
libxml2 2.6.32.dfsg-4ubuntu1.1
After a standard system upgrade you need to restart your sessions to effect
the necessary changes.
Details follow:
Drew Yao discovered that libxml2 did not correctly handle certain corrupt
XML documents. If a user or automated system were tricked into processing
a malicious XML document, a remote attacker could cause applications
linked against libxml2 to enter an infinite loop, leading to a denial
of service. (CVE-2008-4225)
Drew Yao discovered that libxml2 did not correctly handle large memory
allocations. If a user or automated system were tricked into processing a
very large XML document, a remote attacker could cause applications linked
against libxml2 to crash, leading to a denial of service. (CVE-2008-4226)
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-672-1: ClamAV vulnerability (Ubuntu) 
1 d, 23 h, 31 min and 17 secs ago
Referenced CVEs: CVE-2008-5050Description:
===========================================================
Ubuntu Security Notice USN-672-1 November 17, 2008
clamav vulnerability
CVE-2008-5050
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.10:
libclamav5 0.94.dfsg.1-1ubuntu0.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Moritz Jodeit discovered that ClamAV did not correctly handle certain
strings when examining a VBA project. If a remote attacker tricked ClamAV
into processing a malicious VBA file, ClamAV would crash, leading to a
denial of service.
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-667-1 Firefox and xulrunner vulnerabilities (Ubuntu) 
2 d, 0 h, 10 min and 34 secs ago
Referenced CVEs: CVE-2008-0017 CVE-2008-4582 CVE-2008-5012 CVE-2008-5013 CVE-2008-5014 CVE-2008-5015 CVE-2008-5016 CVE-2008-5017 CVE-2008-5018 CVE-2008-5019 CVE-2008-5021 CVE-2008-5022 CVE-2008-5023 CVE-2008-5024 Description: ===========================================================
Ubuntu Security Notice USN-667-1 November 17, 2008
firefox, firefox-3.0, xulrunner-1.9 vulnerabilities
CVE-2008-0017, CVE-2008-4582, CVE-2008-5012, CVE-2008-5013,
CVE-2008-5014, CVE-2008-5015, CVE-2008-5016, CVE-2008-5017,
CVE-2008-5018, CVE-2008-5019, CVE-2008-5021, CVE-2008-5022,
CVE-2008-5023, CVE-2008-5024
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.10
Ubuntu 8.04 LTS
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
firefox 1.5.dfsg+1.5.0.15~prepatch080614h-0ubuntu1
Ubuntu 7.10:
firefox 2.0.0.18+nobinonly-0ubuntu0.7.10
Ubuntu 8.04 LTS:
firefox-3.0 3.0.4+nobinonly-0ubuntu0.8.04.1
xulrunner-1.9 1.9.0.4+nobinonly-0ubuntu0.8.04.1
Ubuntu 8.10:
abrowser 3.0.4+nobinonly-0ubuntu0.8.10.1
firefox-3.0 3.0.4+nobinonly-0ubuntu0.8.10.1
xulrunner-1.9 1.9.0.4+nobinonly-0ubuntu0.8.10.1
After a standard system upgrade you need to restart Firefox and any
application that use xulrunner, such as Epiphany, to effect the
necessary changes.
Details follow:
Liu Die Yu discovered an information disclosure vulnerability in Firefox
when using saved .url shortcut files. If a user were tricked into
downloading a crafted .url file and a crafted HTML file, an attacker
could steal information from the user's cache. (CVE-2008-4582)
Georgi Guninski, Michal Zalewsk and Chris Evans discovered that the
same-origin check in Firefox could be bypassed. If a user were tricked
into opening a malicious website, an attacker could obtain private
information from data stored in the images, or discover information
about software on the user's computer. This issue only affects Firefox 2.
(CVE-2008-5012)
It was discovered that Firefox did not properly check if the Flash
module was properly unloaded. By tricking a user into opening a crafted
SWF file, an attacker could cause Firefox to crash and possibly execute
arbitrary code with user privileges. This issue only affects Firefox 2.
(CVE-2008-5013)
Jesse Ruderman discovered that Firefox did not properly guard locks on
non-native objects. If a user were tricked into opening a malicious
website, an attacker could cause a browser crash and possibly execute
arbitrary code with user privileges. This issue only affects Firefox 2.
(CVE-2008-5014)
Luke Bryan discovered that Firefox sometimes opened file URIs with
chrome privileges. If a user saved malicious code locally, then opened
the file in the same tab as a privileged document, an attacker could
run arbitrary JavaScript code with chrome privileges. This issue only
affects Firefox 3.0. (CVE-2008-5015)
Several problems were discovered in the browser, layout and JavaScript
engines. These problems could allow an attacker to crash the browser
and possibly execute arbitrary code with user privileges.
(CVE-2008-5016, CVE-2008-5017, CVE-2008-5018)
David Bloom discovered that the same-origin check in Firefox could be
bypassed by utilizing the session restore feature. An attacker could
exploit this to run JavaScript in the context of another site or
execute arbitrary JavaScript code with chrome privileges.
(CVE-2008-5019)
Justin Schuh discovered a flaw in Firefox's mime-type parsing. If a
user were tricked into opening a malicious website, an attacker could
send a crafted header in the HTTP index response, causing a browser
crash and execute arbitrary code with user privileges. (CVE-2008-0017)
A flaw was discovered in Firefox's DOM constructing code. If a user
were tricked into opening a malicious website, an attacker could
cause the browser to crash and potentially execute arbitrary code with
user privileges. (CVE-2008-5021)
It was discovered that the same-origin check in Firefox could be
bypassed. If a user were tricked into opening a malicious website, an
attacker could execute JavaScript in the context of a different website.
(CVE-2008-5022)
Collin Jackson discovered various flaws in Firefox when processing
stylesheets which allowed JavaScript to be injected into signed JAR
files. If a user were tricked into opening malicious web content, an
attacker could execute arbitrary code with the privileges of the
signed JAR or of a different website. (CVE-2008-5023)
Chris Evans discovered that Firefox did not properly parse E4X
documents, leading to quote characters in the namespace not being
properly escaped. (CVE-2008-5024)
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-671-1: MySQL vulnerabilities (Ubuntu) 
2 d, 2 h, 12 min and 12 secs ago
Referenced CVEs: CVE-2008-2079, CVE-2008-3963, CVE-2008-4097, CVE-2008-4098Description: ===========================================================
Ubuntu Security Notice USN-671-1 November 17, 2008
mysql-dfsg-5.0 vulnerabilities
CVE-2008-2079, CVE-2008-3963, CVE-2008-4097, CVE-2008-4098
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.10
Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
mysql-server-5.0 5.0.22-0ubuntu6.06.11
Ubuntu 7.10:
mysql-server-5.0 5.0.45-1ubuntu3.4
Ubuntu 8.04 LTS:
mysql-server-5.0 5.0.51a-3ubuntu5.4
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that MySQL could be made to overwrite existing table
files in the data directory. An authenticated user could use the
DATA DIRECTORY and INDEX DIRECTORY options to possibly bypass privilege
checks. This update alters table creation behaviour by disallowing the
use of the MySQL data directory in DATA DIRECTORY and INDEX DIRECTORY
options. (CVE-2008-2079, CVE-2008-4097 and CVE-2008-4098)
It was discovered that MySQL did not handle empty bit-string literals
properly. An attacker could exploit this problem and cause the MySQL
server to crash, leading to a denial of service. (CVE-2008-3963)
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-670-1: VMBuilder vulnerability (Ubuntu) 
[1 views] 5 d and 20 h ago
Description:
===========================================================
Ubuntu Security Notice USN-670-1 November 13, 2008
vm-builder vulnerability
https://bugs.launchpad.net/+bug/296841
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.10
Ubuntu 8.04 LTS
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
passwd 1:4.0.13-7ubuntu3.3
Ubuntu 7.10:
passwd 1:4.0.18.1-9ubuntu0.1
Ubuntu 8.04 LTS:
passwd 1:4.0.18.2-1ubuntu2.1
Ubuntu 8.10:
passwd 1:4.1.1-1ubuntu1.1
python-vm-builder 0.9-0ubuntu3.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Mathias Gug discovered that vm-builder improperly set the root
password when creating virtual machines. An attacker could exploit
this to gain root privileges to the virtual machine by using a
predictable password.
This vulnerability only affects virtual machines created with
vm-builder under Ubuntu 8.10, and does not affect native Ubuntu
installations. An update was made to the shadow package to detect
vulnerable systems and disable password authentication for the
root account. Vulnerable virtual machines which an attacker has
access to should be considered compromised, and appropriate actions
taken to secure the machine.
[usn ]
View original post
|
Add to del.icio.us
|
Share
ARM and Canonical to bring full Ubuntu desktop experience to low-power, ARM technology-based computing devices (Ubuntu) 
6 d and 8 h ago
ARM and Canonical to bring full Ubuntu desktop experience to low-power, ARM technology-based computing devices
Popular commercially-supported Linux distribution Ubuntu to be available on low-power ARM SoCs with rich integrated graphics and video subsystems and a proven track record of low-power design
ARM and Canonical to bring full Ubuntu desktop experience to low-power, ARM technology-based computing devices
Popular commercially-supported Linux distribution Ubuntu to be available on low-power ARM SoCs with rich integrated graphics and video subsystems and a proven track record of low-power design
read more
[news ]
View original post
|
Add to del.icio.us
|
Share
USN-669-1: gnome-screensaver vulnerabilities (Ubuntu) 
8 d and 2 h ago
Referenced CVEs: CVE-2007-6389, CVE-2008-0887Description: ===========================================================
Ubuntu Security Notice USN-669-1 November 11, 2008
gnome-screensaver vulnerabilities
CVE-2007-6389, CVE-2008-0887
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
gnome-screensaver 2.14.3-0ubuntu1.1
Ubuntu 7.10:
gnome-screensaver 2.20.0-0ubuntu4.3
After a standard system upgrade you need to restart all user sessions on
your computer to effect the necessary changes.
Details follow:
It was discovered that the notify feature in gnome-screensaver could let
a local attacker read the clipboard contents of a locked session by
using Ctrl-V. (CVE-2007-6389)
Alan Matsuoka discovered that gnome-screensaver did not properly handle
network outages when using a remote authentication service. During a
network interruption, or by disconnecting the network cable, a local
attacker could gain access to locked sessions. (CVE-2008-0887)
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-666-1: Dovecot vulnerability (Ubuntu) 
12 d and 2 h ago
Referenced CVEs: CVE-2008-4907Description:
===========================================================
Ubuntu Security Notice USN-666-1 November 07, 2008
dovecot vulnerability
CVE-2008-4907
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.10:
dovecot-imapd 1:1.1.4-0ubuntu1.2
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that certain email headers were not correctly handled
by Dovecot. If a remote attacker sent a specially crafted email to a
user with a mailbox managed by Dovecot, that user's mailbox would become
inaccessible through Dovecot, leading to a denial of service.
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-662-2: Ubuntu kernel modules vulnerability (Ubuntu) 
12 d and 22 h ago
Referenced CVEs: CVE-2008-4395Description:
===========================================================
Ubuntu Security Notice USN-662-2 November 06, 2008
linux-ubuntu-modules-2.6.22/24 vulnerability
CVE-2008-4395
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 7.10
Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 7.10:
linux-ubuntu-modules-2.6.22-15-386 2.6.22-15.40
linux-ubuntu-modules-2.6.22-15-generic 2.6.22-15.40
linux-ubuntu-modules-2.6.22-15-rt 2.6.22-15.40
linux-ubuntu-modules-2.6.22-15-server 2.6.22-15.40
Ubuntu 8.04 LTS:
linux-ubuntu-modules-2.6.24-21-386 2.6.24-21.33
linux-ubuntu-modules-2.6.24-21-generic 2.6.24-21.33
linux-ubuntu-modules-2.6.24-21-rt 2.6.24-21.33
linux-ubuntu-modules-2.6.24-21-server 2.6.24-21.33
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Details follow:
USN-662-1 fixed vulnerabilities in ndiswrapper in Ubuntu 8.10.
This update provides the corresponding updates for Ubuntu 8.04 and 7.10.
Original advisory details:
Anders Kaseorg discovered that ndiswrapper did not correctly handle long
ESSIDs. For a system using ndiswrapper, a physically near-by attacker
could generate specially crafted wireless network traffic and execute
arbitrary code with root privileges. (CVE-2008-4395)
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-665-1: Netpbm vulnerability (Ubuntu) 
13 d and 0 h ago
Referenced CVEs: CVE-2008-0554Description:
===========================================================
Ubuntu Security Notice USN-665-1 November 06, 2008
netpbm-free vulnerability
CVE-2008-0554
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
netpbm 2:10.0-10ubuntu1.1
Ubuntu 7.10:
netpbm 2:10.0-11ubuntu0.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that Netpbm could be made to overrun a buffer when loading
certain images. If a user were tricked into opening a specially crafted
GIF image, remote attackers could cause a denial of service or execute
arbitrary code with user privileges.
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-664-1: Tk vulnerability (Ubuntu) 
13 d and 3 h ago
Referenced CVEs: CVE-2008-0553Description:
===========================================================
Ubuntu Security Notice USN-664-1 November 06, 2008
tk8.0, tk8.3, tk8.4 vulnerability
CVE-2008-0553
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.10
Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
tk8.0 8.0.5-11ubuntu0.1
tk8.3 8.3.5-4ubuntu1.2
tk8.4 8.4.12-0ubuntu1.2
Ubuntu 7.10:
tk8.3 8.3.5-6ubuntu3.1
tk8.4 8.4.15-1ubuntu1.1
Ubuntu 8.04 LTS:
tk8.4 8.4.16-2ubuntu1.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that Tk could be made to overrun a buffer when loading
certain images. If a user were tricked into opening a specially crafted
GIF image, remote attackers could cause a denial of service or execute
arbitrary code with user privileges.
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-663-1: system-tools-backends regression (Ubuntu) 
14 d and 4 h ago
Description:
===========================================================
Ubuntu Security Notice USN-663-1 November 05, 2008
system-tools-backends regression
https://launchpad.net/bugs/287134
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.10:
system-tools-backends 2.6.0-1ubuntu1.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that passwords changed (or new users created) via the
"Users and Groups" tool were created with 3DES hashing. This reduced the
security of stored user passwords, and was a regression from the correct
MD5 hashing. This update fixes the problem; future password changes
will correct the hashing used. We apologize for the inconvenience.
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-662-1: Linux kernel vulnerabilities (Ubuntu) 
14 d and 13 h ago
Referenced CVEs: CVE-2008-3528, CVE-2008-4395Description:
===========================================================
Ubuntu Security Notice USN-662-1 November 05, 2008
linux vulnerability
CVE-2008-3528, CVE-2008-4395
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.10:
linux-image-2.6.27-7-generic 2.6.27-7.16
linux-image-2.6.27-7-server 2.6.27-7.16
linux-image-2.6.27-7-virtual 2.6.27-7.16
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Details follow:
It was discovered that the Linux kernel could be made to hang temporarily
when mounting corrupted ext2/3 filesystems. If a user were tricked into
mounting a specially crafted filesystem, a remote attacker could cause
system hangs, leading to a denial of service. (CVE-2008-3528)
Anders Kaseorg discovered that ndiswrapper did not correctly handle long
ESSIDs. For a system using ndiswrapper, a physically near-by attacker
could generate specially crafted wireless network traffic and execute
arbitrary code with root privileges. (CVE-2008-4395)
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-660-1: enscript vulnerability (Ubuntu) 
15 d and 22 h ago
Referenced CVEs: CVE-2008-3863, CVE-2008-4306Description:
===========================================================
Ubuntu Security Notice USN-660-1 November 03, 2008
enscript vulnerability
CVE-2008-3863, CVE-2008-4306
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.10
Ubuntu 8.04 LTS
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
enscript 1.6.4-7ubuntu0.2
Ubuntu 7.10:
enscript 1.6.4-11ubuntu0.2
Ubuntu 8.04 LTS:
enscript 1.6.4-12ubuntu0.8.04.1
Ubuntu 8.10:
enscript 1.6.4-12ubuntu0.8.10.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Ulf Härnhammar discovered multiple stack overflows in enscript's handling of
special escape arguments. If a user or automated system were tricked into
processing a malicious file with the "-e" option enabled, a remote attacker
could execute arbitrary code or cause enscript to crash, possibly leading
to a denial of service.
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-661-1: Linux kernel regression (Ubuntu) 
20 d and 5 h ago
Description:
===========================================================
Ubuntu Security Notice USN-661-1 October 30, 2008
linux regression
https://launchpad.net/bugs/264019
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.10:
linux-image-2.6.27-7-generic 2.6.27-7.15
linux-image-2.6.27-7-server 2.6.27-7.15
linux-image-2.6.27-7-virtual 2.6.27-7.15
procps 1:3.2.7-9ubuntu2.1
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Details follow:
Version 2.6.27 of the Linux kernel changed the order of options in
TCP headers. While this change was RFC-compliant, it was found that
some old routers and consumer DSL modems would not route traffic for
these systems when TCP timestamps were enabled. As a workaround, TCP
timestamps were disabled via sysctl.
This update restores the previous ordering of TCP options, and
reenables TCP timestamps. We apologize for the inconvenience.
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-659-1: Linux kernel vulnerabilities (Ubuntu) 
22 d and 23 h ago
Referenced CVEs: CVE-2007-6716, CVE-2008-2372, CVE-2008-3276, CVE-2008-3525, CVE-2008-3526, CVE-2008-3534, CVE-2008-3535, CVE-2008-3792, CVE-2008-3831, CVE-2008-3915, CVE-2008-4113, CVE-2008-4445Description:
===========================================================
Ubuntu Security Notice USN-659-1 October 27, 2008
linux, linux-source-2.6.15/22 vulnerabilities
CVE-2007-6716, CVE-2008-2372, CVE-2008-3276, CVE-2008-3525,
CVE-2008-3526, CVE-2008-3534, CVE-2008-3535, CVE-2008-3792,
CVE-2008-3831, CVE-2008-3915, CVE-2008-4113, CVE-2008-4445
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.10
Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
linux-image-2.6.15-52-386 2.6.15-52.73
linux-image-2.6.15-52-686 2.6.15-52.73
linux-image-2.6.15-52-amd64-generic 2.6.15-52.73
linux-image-2.6.15-52-amd64-k8 2.6.15-52.73
linux-image-2.6.15-52-amd64-server 2.6.15-52.73
linux-image-2.6.15-52-amd64-xeon 2.6.15-52.73
linux-image-2.6.15-52-hppa32 2.6.15-52.73
linux-image-2.6.15-52-hppa32-smp 2.6.15-52.73
linux-image-2.6.15-52-hppa64 2.6.15-52.73
linux-image-2.6.15-52-hppa64-smp 2.6.15-52.73
linux-image-2.6.15-52-itanium 2.6.15-52.73
linux-image-2.6.15-52-itanium-smp 2.6.15-52.73
linux-image-2.6.15-52-k7 2.6.15-52.73
linux-image-2.6.15-52-mckinley 2.6.15-52.73
linux-image-2.6.15-52-mckinley-smp 2.6.15-52.73
linux-image-2.6.15-52-powerpc 2.6.15-52.73
linux-image-2.6.15-52-powerpc-smp 2.6.15-52.73
linux-image-2.6.15-52-powerpc64-smp 2.6.15-52.73
linux-image-2.6.15-52-server 2.6.15-52.73
linux-image-2.6.15-52-server-bigiron 2.6.15-52.73
linux-image-2.6.15-52-sparc64 2.6.15-52.73
linux-image-2.6.15-52-sparc64-smp 2.6.15-52.73
Ubuntu 7.10:
linux-image-2.6.22-15-386 2.6.22-15.59
linux-image-2.6.22-15-cell 2.6.22-15.59
linux-image-2.6.22-15-generic 2.6.22-15.59
linux-image-2.6.22-15-hppa32 2.6.22-15.59
linux-image-2.6.22-15-hppa64 2.6.22-15.59
linux-image-2.6.22-15-itanium 2.6.22-15.59
linux-image-2.6.22-15-lpia 2.6.22-15.59
linux-image-2.6.22-15-lpiacompat 2.6.22-15.59
linux-image-2.6.22-15-mckinley 2.6.22-15.59
linux-image-2.6.22-15-powerpc 2.6.22-15.59
linux-image-2.6.22-15-powerpc-smp 2.6.22-15.59
linux-image-2.6.22-15-powerpc64-smp 2.6.22-15.59
linux-image-2.6.22-15-rt 2.6.22-15.59
linux-image-2.6.22-15-server 2.6.22-15.59
linux-image-2.6.22-15-sparc64 2.6.22-15.59
linux-image-2.6.22-15-sparc64-smp 2.6.22-15.59
linux-image-2.6.22-15-ume 2.6.22-15.59
linux-image-2.6.22-15-virtual 2.6.22-15.59
linux-image-2.6.22-15-xen 2.6.22-15.59
Ubuntu 8.04 LTS:
linux-image-2.6.24-21-386 2.6.24-21.43
linux-image-2.6.24-21-generic 2.6.24-21.43
linux-image-2.6.24-21-hppa32 2.6.24-21.43
linux-image-2.6.24-21-hppa64 2.6.24-21.43
linux-image-2.6.24-21-itanium 2.6.24-21.43
linux-image-2.6.24-21-lpia 2.6.24-21.43
linux-image-2.6.24-21-lpiacompat 2.6.24-21.43
linux-image-2.6.24-21-mckinley 2.6.24-21.43
linux-image-2.6.24-21-openvz 2.6.24-21.43
linux-image-2.6.24-21-powerpc 2.6.24-21.43
linux-image-2.6.24-21-powerpc-smp 2.6.24-21.43
linux-image-2.6.24-21-powerpc64-smp 2.6.24-21.43
linux-image-2.6.24-21-rt 2.6.24-21.43
linux-image-2.6.24-21-server 2.6.24-21.43
linux-image-2.6.24-21-sparc64 2.6.24-21.43
linux-image-2.6.24-21-sparc64-smp 2.6.24-21.43
linux-image-2.6.24-21-virtual 2.6.24-21.43
linux-image-2.6.24-21-xen 2.6.24-21.43
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
ATTENTION: For systems without the hardy-updates pocket enabled, the 8.04
kernel update will include an unavoidable ABI change. The kernel update
has been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-386,
linux-powerpc, linux-amd64-generic), a standard system upgrade will
automatically perform this as well.
Details follow:
It was discovered that the direct-IO subsystem did not correctly validate
certain structures. A local attacker could exploit this to cause a system
crash, leading to a denial of service. (CVE-2007-6716)
It was discovered that the disabling of the ZERO_PAGE optimization could
lead to large memory consumption. A local attacker could exploit this to
allocate all available memory, leading to a denial of service.
(CVE-2008-2372)
It was discovered that the Datagram Congestion Control Protocol (DCCP) did
not correctly validate its arguments. If DCCP was in use, a remote attacker
could send specially crafted network traffic and cause a system crash,
leading to a denial of service. (CVE-2008-3276)
It was discovered that the SBNI WAN driver did not correctly check for the
NET_ADMIN capability. A malicious local root user lacking CAP_NET_ADMIN
would be able to change the WAN device configuration, leading to a denial
of service. (CVE-2008-3525)
It was discovered that the Stream Control Transmission Protocol (SCTP) did
not correctly validate the key length in the SCTP_AUTH_KEY option. If SCTP
is in use, a remote attacker could send specially crafted network traffic
that would crash the system, leading to a denial of service.
(CVE-2008-3526)
It was discovered that the tmpfs implementation did not correctly handle
certain sequences of inode operations. A local attacker could exploit this
to crash the system, leading to a denial of service. (CVE-2008-3534)
It was discovered that the readv/writev functions did not correctly handle
certain sequences of file operations. A local attacker could exploit this
to crash the system, leading to a denial of service. (CVE-2008-3535)
It was discovered that SCTP did not correctly validate its userspace
arguments. A local attacker could call certain sctp_* functions with
malicious options and cause a system crash, leading to a denial of service.
(CVE-2008-3792, CVE-2008-4113, CVE-2008-4445)
It was discovered the the i915 video driver did not correctly validate
memory addresses. A local attacker could exploit this to remap memory
that could cause a system crash, leading to a denial of service.
(CVE-2008-3831)
Johann Dahm and David Richter discovered that NFSv4 did not correctly
handle certain file ACLs. If NFSv4 is in use, a local attacker could create
a malicious ACL that could cause a system crash, leading to a denial of
service. (CVE-2008-3915)
[usn ]
View original post
|
Add to del.icio.us
|
Share
Ubuntu 8.10 Server Edition delivers significant new features to innovative user base (Ubuntu) 
23 d and 18 h ago
Ubuntu® 8.10 Server
Edition delivers significant new features to innovative user base
Ubuntu Server Edition
enhances Java®,
virtualization and system management capabilities
London,
October 28, 2008:
Canonical Ltd. announced the upcoming availability of Ubuntu®
8.10 Server Edition for free download on 30 October. In related news
Canonical also announced the simultaneous release of Ubuntu 8.10
Desktop Edition.
Ubuntu® 8.10 Server
Edition delivers significant new features to innovative user base
Ubuntu Server Edition
enhances Java®,
virtualization and system management capabilities
London,
October 28, 2008:
Canonical Ltd. announced the upcoming availability of Ubuntu®
8.10 Server Edition for free download on 30 October. In related news
Canonical also announced the simultaneous release of Ubuntu 8.10
Desktop Edition.
read more
[news ]
View original post
|
Add to del.icio.us
|
Share
Ubuntu 8.10 Desktop Edition enables mobile, flexible computing for a changing digital world (Ubuntu) 
23 d and 19 h ago
Ubuntu® 8.10 Desktop Edition enables mobile, flexible computing for a changing digital world
London, October 27, 2008: Canonical Ltd. announced the upcoming availability of Ubuntu® 8.10 Desktop Edition for free download on 30 October. In related news, Canonical also announced the simultaneous release of Ubuntu 8.10 Server Edition.
Ubuntu® 8.10 Desktop Edition enables mobile, flexible computing for a changing digital world
London, October 27, 2008: Canonical Ltd. announced the upcoming availability of Ubuntu® 8.10 Desktop Edition for free download on 30 October. In related news, Canonical also announced the simultaneous release of Ubuntu 8.10 Server Edition.
read more
[news ]
View original post
|
Add to del.icio.us
|
Share
USN-658-1: Moodle vulnerability (Ubuntu) 
[1 views] 27 d and 1 h ago
Referenced CVEs: CVE-2008-1502Description:
===========================================================
Ubuntu Security Notice USN-658-1 October 23, 2008
moodle vulnerability
CVE-2008-1502
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 7.10
Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 7.10:
moodle 1.8.2-1ubuntu2.1
Ubuntu 8.04 LTS:
moodle 1.8.2-1ubuntu4.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Lukasz Pilorz discovered that the HTML filtering used in Moodle was not
strict enough. A remote attacker could send malicious requests to Moodle
and execute arbitrary code as the web server user.
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-657-1: Amarok vulnerability (Ubuntu) 
29 d and 9 h ago
Referenced CVEs: CVE-2008-3699Description:
===========================================================
Ubuntu Security Notice USN-657-1 October 21, 2008
amarok vulnerability
CVE-2008-3699
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 7.10
Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 7.10:
amarok 2:1.4.7-0ubuntu3.1
Ubuntu 8.04 LTS:
amarok 2:1.4.9.1-0ubuntu3.1
After a standard system upgrade you need to restart Amarok to effect
the necessary changes.
Details follow:
Dwayne Litzenberger discovered that Amarok created temporary files in
an insecure way. Local users could exploit a race condition to create
or overwrite files with the privileges of the user invoking the
program. (CVE-2008-3699)
[usn ]
View original post
|
Add to del.icio.us
|
Share
Ubuntu 7.04 reaches end-of-life on October 19, 2008 (Ubuntu) 
34 d and 1 h ago
Ubuntu 7.04 reaches end-of-life on October 19, 2008
Ubuntu announced the release of 7.04 almost 18 months ago, on April 19, 2007. As with the earlier releases, Ubuntu committed to ongoing security and critical fixes for a period of 18 months. The support period is now nearing its end and Ubuntu 7.04 will reach end of life on Sunday, October 19th, 2008. At that time, Ubuntu Security Notices will no longer include information or updated packages for Ubuntu 7.04.
Ubuntu 7.04 reaches end-of-life on October 19, 2008
Ubuntu announced the release of 7.04 almost 18 months ago, on April 19, 2007. As with the earlier releases, Ubuntu committed to ongoing security and critical fixes for a period of 18 months. The support period is now nearing its end and Ubuntu 7.04 will reach end of life on Sunday, October 19th, 2008. At that time, Ubuntu Security Notices will no longer include information or updated packages for Ubuntu 7.04.
read more
[news ]
View original post
|
Add to del.icio.us
|
Share
USN-656-1: CUPS vulnerabilities (Ubuntu) 
35 d and 1 h ago
Referenced CVEs: CVE-2008-1722, CVE-2008-3639, CVE-2008-3640, CVE-2008-3641Description:
===========================================================
Ubuntu Security Notice USN-656-1 October 15, 2008
cupsys vulnerabilities
CVE-2008-1722, CVE-2008-3639, CVE-2008-3640, CVE-2008-3641
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.04
Ubuntu 7.10
Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
cupsys 1.2.2-0ubuntu0.6.06.11
Ubuntu 7.04:
cupsys 1.2.8-0ubuntu8.6
Ubuntu 7.10:
cupsys 1.3.2-1ubuntu7.8
Ubuntu 8.04 LTS:
cupsys 1.3.7-1ubuntu3.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that the SGI image filter in CUPS did not perform
proper bounds checking. If a user or automated system were tricked
into opening a crafted SGI image, an attacker could cause a denial
of service. (CVE-2008-3639)
It was discovered that the texttops filter in CUPS did not properly
validate page metrics. If a user or automated system were tricked into
opening a crafted text file, an attacker could cause a denial of
service. (CVE-2008-3640)
It was discovered that the HP-GL filter in CUPS did not properly check
for invalid pen parameters. If a user or automated system were tricked
into opening a crafted HP-GL or HP-GL/2 file, a remote attacker could
cause a denial of service or execute arbitrary code with user
privileges. In Ubuntu 7.10 and 8.04 LTS, attackers would be isolated by
the AppArmor CUPS profile. (CVE-2008-3641)
NOTE: The previous update for CUPS on Ubuntu 6.06 LTS did not have the
the fix for CVE-2008-1722 applied. This update includes fixes for the
problem. We apologize for the inconvenience.
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-655-1: exiv2 vulnerabilities (Ubuntu) 
35 d and 20 h ago
Referenced CVEs: CVE-2007-6353, CVE-2008-2696Description:
===========================================================
Ubuntu Security Notice USN-655-1 October 15, 2008
exiv2 vulnerabilities
CVE-2007-6353, CVE-2008-2696
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 7.04
Ubuntu 7.10
Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 7.04:
libexiv2-0.12 0.12-0ubuntu2.1
Ubuntu 7.10:
libexiv2-0 0.15-1ubuntu2.1
Ubuntu 8.04 LTS:
libexiv2-2 0.16-3ubuntu1.1
After a standard system upgrade you need to restart your session to effect
the necessary changes.
Details follow:
Meder Kydyraliev discovered that exiv2 did not correctly handle certain
EXIF headers. If a user or automated system were tricked into processing
a specially crafted image, a remote attacker could cause the application
linked against libexiv2 to crash, leading to a denial of service, or
possibly executing arbitrary code with user privileges. (CVE-2007-6353)
Joakim Bildrulle discovered that exiv2 did not correctly handle Nikon
lens EXIF information. If a user or automated system were tricked into
processing a specially crafted image, a remote attacker could cause the
application linked against libexiv2 to crash, leading to a denial of
service. (CVE-2008-2696)
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-654-1: libexif vulnerabilities (Ubuntu) 
35 d and 22 h ago
Referenced CVEs: CVE-2007-6351, CVE-2007-6352Description:
===========================================================
Ubuntu Security Notice USN-654-1 October 14, 2008
libexif vulnerabilities
CVE-2007-6351, CVE-2007-6352
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.04
Ubuntu 7.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libexif12 0.6.12-2ubuntu0.3
Ubuntu 7.04:
libexif12 0.6.13-5ubuntu0.3
Ubuntu 7.10:
libexif12 0.6.16-1ubuntu0.1
After a standard system upgrade you need to restart your session to effect
the necessary changes.
Details follow:
Meder Kydyraliev discovered that libexif did not correctly handle certain
EXIF headers. If a user or automated system were tricked into processing
a specially crafted image, a remote attacker could cause the application
linked against libexif to crash, leading to a denial of service, or
possibly executing arbitrary code with user privileges.
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-653-1: D-Bus vulnerabilities (Ubuntu) 
36 d ago
Referenced CVEs: CVE-2008-0595, CVE-2008-3834Description:
===========================================================
Ubuntu Security Notice USN-653-1 October 14, 2008
dbus vulnerabilities
CVE-2008-0595, CVE-2008-3834
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.04
Ubuntu 7.10
Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libdbus-1-2 0.60-6ubuntu8.3
Ubuntu 7.04:
libdbus-1-3 1.0.2-1ubuntu4.2
Ubuntu 7.10:
libdbus-1-3 1.1.1-3ubuntu4.2
Ubuntu 8.04 LTS:
libdbus-1-3 1.1.20-1ubuntu3.1
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Details follow:
Havoc Pennington discovered that the D-Bus daemon did not correctly
validate certain security policies. If a local user sent a specially
crafted D-Bus request, they could bypass security policies that had a
"send_interface" defined. (CVE-2008-0595)
It was discovered that the D-Bus library did not correctly validate
certain corrupted signatures. If a local user sent a specially crafted
D-Bus request, they could crash applications linked against the D-Bus
library, leading to a denial of service. (CVE-2008-3834)
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-652-1: LittleCMS vulnerability (Ubuntu) 
36 d ago
Referenced CVEs: CVE-2007-2741Description:
===========================================================
Ubuntu Security Notice USN-652-1 October 14, 2008
lcms vulnerability
CVE-2007-2741
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
liblcms1 1.13-1ubuntu0.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Chris Evans discovered that certain ICC operations in lcms were not
correctly bounds-checked. If a user or automated system were tricked
into processing an image with malicious ICC tags, a remote attacker could
crash applications linked against liblcms1, leading to a denial of service,
or possibly execute arbitrary code with user privileges.
[usn ]
View original post
|
Add to del.icio.us
|
Share
Wikimedia chooses Ubuntu for all of its servers (Ubuntu) 
37 d ago
Wikimedia case study

Background
Most people with a passing acquaintance with a browser or Google search know Wikipedia, the web-based encyclopedia spanning topics from the ridiculous to the sublime. Want Britney Spear’s bio? It’s there.
Wikimedia case study

Background
Most people with a passing acquaintance with a browser or Google search know Wikipedia, the web-based encyclopedia spanning topics from the ridiculous to the sublime. Want Britney Spear’s bio? It’s there.
read more
[news ]
View original post
|
Add to del.icio.us
|
Share
USN-651-1: Ruby vulnerabilities (Ubuntu) 
40 d ago
Referenced CVEs: CVE-2008-2376, CVE-2008-3443, CVE-2008-3655, CVE-2008-3656, CVE-2008-3657, CVE-2008-3790, CVE-2008-3905Description:
===========================================================
Ubuntu Security Notice USN-651-1 October 10, 2008
ruby1.8 vulnerabilities
CVE-2008-2376, CVE-2008-3443, CVE-2008-3655, CVE-2008-3656,
CVE-2008-3657, CVE-2008-3790, CVE-2008-3905
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.04
Ubuntu 7.10
Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libruby1.8 1.8.4-1ubuntu1.6
ruby1.8 1.8.4-1ubuntu1.6
Ubuntu 7.04:
libruby1.8 1.8.5-4ubuntu2.3
ruby1.8 1.8.5-4ubuntu2.3
Ubuntu 7.10:
libruby1.8 1.8.6.36-1ubuntu3.3
ruby1.8 1.8.6.36-1ubuntu3.3
Ubuntu 8.04 LTS:
libruby1.8 1.8.6.111-2ubuntu1.2
ruby1.8 1.8.6.111-2ubuntu1.2
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Akira Tagoh discovered a vulnerability in Ruby which lead to an integer
overflow. If a user or automated system were tricked into running a
malicious script, an attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user
invoking the program. (CVE-2008-2376)
Laurent Gaffie discovered that Ruby did not properly check for memory
allocation failures. If a user or automated system were tricked into
running a malicious script, an attacker could cause a denial of
service. (CVE-2008-3443)
Keita Yamaguchi discovered several safe level vulnerabilities in Ruby.
An attacker could use this to bypass intended access restrictions.
(CVE-2008-3655)
Keita Yamaguchi discovered that WEBrick in Ruby did not properly
validate paths ending with ".". A remote attacker could send a crafted
HTTP request and cause a denial of service. (CVE-2008-3656)
Keita Yamaguchi discovered that the dl module in Ruby did not check
the taintness of inputs. An attacker could exploit this vulnerability
to bypass safe levels and execute dangerous functions. (CVE-2008-3657)
Luka Treiber and Mitja Kolsek discovered that REXML in Ruby did not
always use expansion limits when processing XML documents. If a user or
automated system were tricked into open a crafted XML file, an attacker
could cause a denial of service via CPU consumption. (CVE-2008-3790)
Jan Lieskovsky discovered several flaws in the name resolver of Ruby. A
remote attacker could exploit this to spoof DNS entries, which could
lead to misdirected traffic. This is a different vulnerability from
CVE-2008-1447. (CVE-2008-3790)
[usn ]
View original post
|
Add to del.icio.us
|
Share
USN-650-1: cpio vulnerability (Ubuntu) 
48 d ago
Referenced CVEs: CVE-2007-4476Description:
===========================================================
Ubuntu Security Notice USN-650-1 October 02, 2008
cpio vulnerability
CVE-2007-4476
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.04
Ubuntu 7.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
cpio 2.6-10ubuntu0.3
Ubuntu 7.04:
cpio 2.6-17ubuntu0.7.04.1
Ubuntu 7.10:
cpio 2.8-1ubuntu2.2
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
A buffer overflow was discovered in cpio. If a user were tricked into
opening a crafted cpio archive, an attacker could cause a denial of
service via application crash, or possibly execute code with the
privileges of the user invoking the program. (CVE-2007-4476)
[usn ]
View original post
|
Add to del.icio.us
|
Share