Ubuntu Essential and Critical Security Patch Updates - Page 346

Find the information you need for your favorite open source distribution .

Ubuntu 1100-1: OpenLDAP vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that OpenLDAP did not properly check forwarded authentication failures when using a slave server and chain overlay. If OpenLDAP were configured in this manner, an attacker could bypass authentication checks by sending an invalid password to a slave server. (CVE-2011-1024) [More...]

Ubuntu 1099-1: GDM vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Sebastian Krahmer discovered that GDM (GNOME Display Manager) did notproperly drop privileges when handling the cache directories usedto store users' dmrc and face icon files. This could allow a localattacker to change the ownership of arbitrary files, thereby gainingroot privileges. [More...]

Ubuntu 1096-1: Subversion vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Philip Martin discovered that the Subversion mod_dav_svn module for Apache did not properly handle certain requests containing a lock token. A remote attacker could use this flaw to cause the service to crash, leading to a denial of service. [More...]

Ubuntu 1088-1: Kerberos vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Cameron Meadors discovered that the MIT Kerberos 5 Key DistributionCenter (KDC) daemon is vulnerable to a double-free condition ifthe Public Key Cryptography for Initial Authentication (PKINIT)capability is enabled. This could allow a remote attacker to causea denial of service. [More...]

Ubuntu 1085-1: tiff vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Sauli Pahlman discovered that the TIFF library incorrectly handled invalid td_stripbytecount fields. If a user or automated system were tricked into opening a specially crafted TIFF image, a remote attacker could crash the application, leading to a denial of service. This issue only affected Ubuntu 10.04 LTS and 10.10. (CVE-2010-2482) [More...]