Ubuntu Essential and Critical Security Patch Updates - Page 358

Find the information you need for your favorite open source distribution .

Ubuntu 901-1: Squid vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that Squid incorrectly handled certain auth headers. A remote attacker could exploit this with a specially-crafted auth header and cause Squid to go into an infinite loop, resulting in a denial of service. This issue only affected Ubuntu 8.10, 9.04 and 9.10. (CVE-2009-2855) [More...]

Ubuntu 899-1: Tomcat vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that Tomcat did not correctly validate WAR filenames or paths when deploying. A remote attacker could send a specially crafted WAR file to be deployed and cause arbitrary files and directories to be created, overwritten, or deleted. [More...]

Ubuntu 897-1: MySQL vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that MySQL could be made to overwrite existing table files in the data directory. An authenticated user could use the DATA DIRECTORY and INDEX DIRECTORY options to possibly bypass privilege checks. This update alters table creation behaviour by disallowing the use of the MySQL data directory in DATA DIRECTORY and INDEX DIRECTORY options. This [More...]

Ubuntu 894-1: Linux kernel vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Amerigo Wang and Eric Sesterhenn discovered that the HFS and ext4filesystems did not correctly check certain disk structures. If a userwere tricked into mounting a specially crafted filesystem, a remoteattacker could crash the system or gain root privileges. (CVE-2009-4020,CVE-2009-4308) [More...]

Ubuntu 893-1: Samba vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Ronald Volgers discovered that the mount.cifs utility, when installed as a setuid program, suffered from a race condition when verifying user permissions. A local attacker could trick samba into mounting over arbitrary locations, leading to a root privilege escalation. [More...]

Ubuntu 891-1: lintian vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that lintian did not correctly validate certainfilenames when processing input. If a user or an automated systemwere tricked into running lintian on a specially crafted set of files,a remote attacker could execute arbitrary code with user privileges. [More...]

Ubuntu 803-2: Dhcp vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

USN-803-1 fixed a vulnerability in Dhcp. Due to an error, the patch tofix the vulnerability was not properly applied on Ubuntu 8.10 and higher.Even with the patch improperly applied, the default compiler optionsreduced the vulnerability to a denial of service. Additionally, in Ubuntu9.04 and higher, users were also protected by the AppArmor dhclient3 [More...]

Ubuntu 890-1: Expat vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat didnot properly process malformed XML. If a user or application linked againstExpat were tricked into opening a crafted XML file, an attacker could causea denial of service via application crash. (CVE-2009-2625, CVE-2009-3720) [More...]

Ubuntu 888-1: Bind vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that Bind would incorrectly cache bogus NXDOMAIN responses. When DNSSEC validation is in use, a remote attacker could exploit this to cause a denial of service, and possibly poison DNS caches. (CVE-2010-0097) [More...]

Ubuntu 889-1: gzip vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that gzip incorrectly handled certain malformed compressed files. If a user or automated system were tricked into opening a specially crafted gzip file, an attacker could cause gzip to crash or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2009-2624) [More...]