Ubuntu Essential and Critical Security Patch Updates - Page 363

Find the information you need for your favorite open source distribution .

Ubuntu 813-1: apr vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Matt Lewis discovered that apr did not properly sanitize its input whenallocating memory. If an application using apr processed crafted input, aremote attacker could cause a denial of service or potentially executearbitrary code as the user invoking the application. [More...]

Ubuntu 812-1: Subversion vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Matt Lewis discovered that Subversion did not properly sanitize its inputwhen processing svndiff streams, leading to various integer and heapoverflows. If a user or automated system processed crafted input, a remoteattacker could cause a denial of service or potentially execute arbitrarycode as the user processing the input. [More...]

Ubuntu 811-1: Firefox and Xulrunner vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Juan Pablo Lopez Yacubian discovered that Firefox did not properly displayinvalid URLs. If a user were tricked into accessing a malicious website, anattacker could exploit this to spoof the location bar, such as in aphishing attack. Furthermore, if the malicious website had a valid SSLcertificate, Firefox would display the spoofed page as trusted. [More...]

Ubuntu 810-1: NSS vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Moxie Marlinspike discovered that NSS did not properly handle regularexpressions in certificate names. A remote attacker could create aspecially crafted certificate to cause a denial of service (via applicationcrash) or execute arbitrary code as the user invoking the program.(CVE-2009-2404) [More...]

Ubuntu 808-1: Bind vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Micha Krause discovered that Bind did not correctly validate certaindynamic DNS update packets. An unauthenticated remote attacker couldsend specially crafted traffic to crash the DNS server, leading to adenial of service. [More...]

Ubuntu 807-1: Linux kernel vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Michael Tokarev discovered that the RTL8169 network driver did notcorrectly validate buffer sizes. A remote attacker on the local networkcould send specially traffic traffic that would crash the system orpotentially grant elevated privileges. (CVE-2009-1389) [More...]

Ubuntu 806-1: Python vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that Python incorrectly handled certain arguments in the imageop module. If an attacker were able to pass specially crafted arguments through the crop function, they could execute arbitrary code with user privileges. For Python 2.5, this issue only affected Ubuntu 8.04 LTS. (CVE-2008-4864) [More...]

Ubuntu 798-1: Firefox and Xulrunner vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Several flaws were discovered in the Firefox browser and JavaScriptengines. If a user were tricked into viewing a malicious website, a remoteattacker could cause a denial of service or possibly execute arbitrary codewith the privileges of the user invoking the program. (CVE-2009-2462,CVE-2009-2463, CVE-2009-2464, CVE-2009-2465, CVE-2009-2466, CVE-2009-2469) [More...]

Ubuntu 803-1: dhcp vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that the DHCP client as included in dhcp3 did not verifythe length of certain option fields when processing a response from an IPv4dhcp server. If a user running Ubuntu 6.06 LTS or 8.04 LTS connected to amalicious dhcp server, a remote attacker could cause a denial of service orexecute arbitrary code as the user invoking the program, typically the [More...]

Ubuntu 802-1: Apache vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that mod_proxy_http did not properly handle a large amount of streamed data when used as a reverse proxy. A remote attacker could exploit this and cause a denial of service via memory resource consumption. This issue affected Ubuntu 8.04 LTS, 8.10 and 9.04. (CVE-2009-1890) [More...]

Ubuntu 801-1: tiff vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Tielei Wang and Tom Lane discovered that the TIFF library did not correctly handle certain malformed TIFF images. If a user or automated system were tricked into processing a malicious image, an attacker could execute arbitrary code with the privileges of the user invoking the program. [More...]

Ubuntu 800-1: irssi vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that irssi did not properly check the length of stringswhen processing WALLOPS messages. If a user connected to an IRC networkwhere an attacker had IRC operator privileges, a remote attacker couldcause a denial of service. [More...]

Ubuntu 797-1: tiff vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that the TIFF library did not correctly handle certain malformed TIFF images. If a user or automated system were tricked into processing a malicious image, a remote attacker could cause an application linked against libtiff to crash, leading to a denial of service. [More...]