Ubuntu Essential and Critical Security Patch Updates - Page 355

Find the information you need for your favorite open source distribution .

Ubuntu 954-1: tiff vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Kevin Finisterre discovered that the TIFF library did not correctly handlecertain image structures. If a user or automated system were trickedinto opening a specially crafted TIFF image, a remote attacker couldexecute arbitrary code with user privileges, or crash the application,leading to a denial of service. (CVE-2010-1411) [More...]

Ubuntu 955-1: OPIE vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Maksymilian Arciemowicz and Adam Zabrocki discovered that OPIE incorrectly handled long usernames. A remote attacker could exploit this with a crafted username and make applications linked against libopie crash, leading to a denial of service. [More...]

Ubuntu 952-1: CUPS vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Adrian Pastor and Tim Starling discovered that the CUPS web interface incorrectly protected against cross-site request forgery (CSRF) attacks. If an authenticated user were tricked into visiting a malicious website while logged into CUPS, a remote attacker could modify the CUPS configuration and possibly steal confidential data. (CVE-2010-0540) [More...]

Ubuntu 953-1: fastjar vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Dan Rosenberg discovered that fastjar incorrectly handled file paths containing ".." when unpacking archives. If a user or an automated system were tricked into unpacking a specially crafted jar file, arbitrary files could be overwritten with user privileges. [More...]

Ubuntu 951-1: Samba vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Jun Mao discovered that Samba did not correctly validate SMB1 packetcontents. An unauthenticated remote attacker could send specially craftednetwork traffic that could execute arbitrary code as the root user. [More...]

Ubuntu 950-1: MySQL vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that MySQL did not check privileges before uninstalling plugins. An authenticated user could uninstall arbitrary plugins, bypassing intended restrictions. This issue only affected Ubuntu 9.10 and 10.04 LTS. (CVE-2010-1621) [More...]

Ubuntu 949-1: OpenOffice.org vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Marc Schoenefeld discovered that OpenOffice.org would run document macros from the macro browser, even when macros were disabled. If a user were tricked into opening a specially crafted document and examining a macro, a remote attacker could execute arbitrary code with user privileges. [More...]

Ubuntu 948-1: GnuTLS vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that GnuTLS did not always properly verify the hashalgorithm of X.509 certificates. If an application linked against GnuTLSprocessed a crafted certificate, an attacker could make GnuTLS dereferencea NULL pointer and cause a DoS via application crash. [More...]

Ubuntu 947-1: Linux kernel vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that the Linux kernel did not correctly handle memoryprotection of the Virtual Dynamic Shared Object page when runninga 32-bit application on a 64-bit kernel. A local attacker couldexploit this to cause a denial of service. (Only affected Ubuntu 6.06LTS.) (CVE-2009-4271) [More...]

Ubuntu 946-1: Net-SNMP vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The SNMP server did not correctly validate certain UDP clients when usingTCP wrappers. Under some situations, a remote attacker could bypassaccess restrictions and communicate with the SNMP server, potentiallyleading to a loss of privacy or a denial of service. [More...]

Ubuntu 944-1: GNU C Library vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Maksymilian Arciemowicz discovered that the GNU C library did notcorrectly handle integer overflows in the strfmon function. If a useror automated system were tricked into processing a specially craftedformat string, a remote attacker could crash applications, leading toa denial of service. (Ubuntu 10.04 was not affected.) (CVE-2008-1391) [More...]

Ubuntu 942-1: PostgreSQL vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that the Safe.pm module as used by PostgreSQL did notproperly restrict PL/perl procedures. If PostgreSQL was configured to usePerl stored procedures, a remote authenticated attacker could exploit thisto execute arbitrary Perl code. (CVE-2010-1169) [More...]

Ubuntu 940-1: Kerberos vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that Kerberos did not correctly free memory in theGSSAPI and kdb libraries. If a remote attacker were able to manipulatean application using these libraries carefully, the service couldcrash, leading to a denial of service. (Only Ubuntu 6.06 LTS wasaffected.) (CVE-2007-5902, CVE-2007-5971, CVE-2007-5972) [More...]

Ubuntu 939-1: X.org vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Loïc Minier discovered that xvfb-run did not correctly keep the X.org session cookie private. A local attacker could gain access to any local sessions started by xvfb-run. Ubuntu 9.10 was not affected. (CVE-2009-1573) [More...]