Ubuntu Essential and Critical Security Patch Updates - Page 368

Find the information you need for your favorite open source distribution .

Ubuntu 724-1: Squid vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Joshua Morin, Mikko Varpiola and Jukka Taimisto discovered that Squid didnot properly validate the HTTP version when processing requests. A remoteattacker could exploit this to cause a denial of service (assertion failure). [More...]

Ubuntu 723-1: Git vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that Git did not properly handle long file paths. If a user were tricked into performing commands on a specially crafted Git repository, an attacker could possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2008-3546) [More...]

Ubuntu 722-1: sudo vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Harald Koenig discovered that sudo did not correctly handle certainprivilege changes when handling groups. If a local attacker belongedto a group included in a "RunAs" list in the /etc/sudoers file, thatuser could gain root privileges. This was not an issue for the defaultsudoers file shipped with Ubuntu. [More...]

Ubuntu 721-1: fglrx-installer vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Marko Lindqvist discovered that the fglrx installer created an unsafeLD_LIBRARY_PATH on 64bit systems. If a user were tricked into downloadingspecially crafted libraries and running commands in the same directory,a remote attacker could execute arbitrary code with user privileges. [More...]

Ubuntu 720-1: PHP vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that PHP did not properly enforce php_admin_value and php_admin_flag restrictions in the Apache configuration file. A local attacker could create a specially crafted PHP script that would bypass intended security restrictions. This issue only applied to Ubuntu 6.06 LTS, 7.10, and 8.04 LTS. [More...]

Ubuntu 717-2: Firefox vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

A flaw was discovered in the browser engine when restoring closed tabs. If auser were tricked into restoring a tab to a malicious website with form inputcontrols, an attacker could steal local files on the user's system.(CVE-2009-0355) [More...]

Ubuntu 716-1: MoinMoin vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Fernando Quintero discovered than MoinMoin did not properly sanitize itsinput when processing login requests, resulting in cross-site scripting (XSS)vulnerabilities. With cross-site scripting vulnerabilities, if a user weretricked into viewing server output during a crafted server request, a remoteattacker could exploit this to modify the contents, or steal confidential data, [More...]

Ubuntu 712-1: Vim vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Jan Minar discovered that Vim did not properly sanitize inputs before invoking the execute or system functions inside Vim scripts. If a user were tricked into running Vim scripts with a specially crafted input, an attacker could execute arbitrary code with the privileges of the user invoking the program. [More...]

Ubuntu 710-1: xine-lib vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that xine-lib did not correctly handle certain malformed Ogg and Windows Media files. If a user or automated system were tricked into opening a specially crafted Ogg or Windows Media file, an attacker could cause xine-lib to crash, creating a denial of service. This issue only applied to [More...]

Ubuntu 711-1: KTorrent vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that KTorrent did not properly restrict access when using the web interface plugin. A remote attacker could use a crafted http request and upload arbitrary torrent files to trigger the start of downloads and seeding. (CVE-2008-5905) [More...]

Ubuntu 700-2: Perl regression

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

USN-700-1 fixed vulnerabilities in Perl. Due to problems with the Ubuntu 8.04 build, some Perl .ph files were missing from the resulting update. This update fixes the problem. We apologize for the inconvenience. [More...]

Ubuntu 709-1: tar vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Dmitry V. Levin discovered a buffer overflow in tar. If a user or automatedsystem were tricked into opening a specially crafted tar file, an attackercould crash tar or possibly execute arbitrary code with the privileges of theuser invoking the program. [More...]

Ubuntu 708-1: HPLIP vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that an installation script in the HPLIP package would change permissions on the hplip config files located in user's home directories. A local user could exploit this and change permissions on arbitrary files upon an HPLIP installation or upgrade, which could lead to root privileges. [More...]

Ubuntu 707-1: CUPS vulnerabilities

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that CUPS didn't properly handle adding a large number of RSS subscriptions. A local user could exploit this and cause CUPS to crash, leading to a denial of service. This issue only applied to Ubuntu 7.10, 8.04 LTS and 8.10. (CVE-2008-5183) [More...]