«
Expand/Collapse
381 items tagged "usn"
Related tags:
kernel [+],
linux [+],
firefox [+],
security notice [+],
ubuntu [+],
openjdk [+],
security [+],
notice [+],
vasiliy kulikov [+],
lts [+],
vulnerability [+],
txt [+],
xulrunner [+],
world writable [+],
update [+],
udev [+],
tiff [+],
server request [+],
server [+],
root privileges [+],
php [+],
perl [+],
file [+],
daniel holbert [+],
content disposition [+],
confidential data [+],
based buffer overflow [+],
arbitrary name [+],
x.org [+],
taint [+],
stefan cornelius [+],
service [+],
safe [+],
proxy settings [+],
proxy [+],
postgresql [+],
plaintext attack [+],
openssl [+],
module [+],
libvpx [+],
libvirt [+],
kerberos [+],
java software [+],
ian beer [+],
gsettings [+],
dhcp client [+],
dell latitude [+],
cups [+],
clamav [+],
circumstances [+],
bzip2 [+],
bzip [+],
bogofilter [+],
basedir [+],
architectures [+],
arbitrary code execution [+],
attacker [+],
thunderbird [+],
sudo [+],
stefan esser [+],
split function [+],
single quote [+],
secunia [+],
samba [+],
root user [+],
richard moore [+],
quang minh [+],
pseudorandom number generator [+],
proof of concept [+],
proof [+],
postfix [+],
php session [+],
pdb files [+],
pcsc lite [+],
partial ip address [+],
nussel [+],
null characters [+],
nelson bolyard [+],
morten krakvik [+],
minh [+],
ludwig nussel [+],
logical volume manager [+],
libxml [+],
library [+],
julius plenz [+],
java applet [+],
irc connection [+],
internet printing protocol [+],
integer overflow [+],
grzegorz stachowiak [+],
gnu c library [+],
gnu [+],
fuse [+],
freetype [+],
exchange implementation [+],
escalation [+],
encrypted communications [+],
emmanuel bouillon [+],
django [+],
directory pathnames [+],
diffie hellman [+],
denial [+],
default compiler [+],
ctcp requests [+],
cookie value [+],
cluster [+],
christoph diehl [+],
certificate [+],
bui [+],
bind [+],
avahi [+],
archive mirror [+],
arbitrary files [+],
arbitrary commands [+],
apache [+],
alasdair macgregor [+],
denial of service [+],
x11 [+],
wget [+],
webkit [+],
web browser security [+],
weatherford [+],
virtinst [+],
tomcat [+],
subversion [+],
subject alternate names [+],
rsync [+],
qemu [+],
provider account [+],
poppler [+],
pidgin [+],
php5 [+],
pango [+],
pam [+],
openslp [+],
openldap [+],
open [+],
nss [+],
mysql [+],
mountall [+],
mike roszkowski [+],
matt weatherford [+],
malicious website [+],
mako [+],
mailman [+],
little [+],
linux update [+],
libmikmod [+],
libhx [+],
lftp [+],
koffice [+],
kernel regression [+],
kde libs [+],
kdc service [+],
kdc [+],
imagemagick [+],
image [+],
ifupdown [+],
hplip [+],
gnupg [+],
gimp [+],
gdm [+],
firefox vulnerability [+],
ffmpeg [+],
evince [+],
dpkg [+],
d bus [+],
cms [+],
browser [+],
bind vulnerabilities [+],
awstats [+],
apturl [+],
aptdaemon [+],
apr util [+],
apparmor [+],
arbitrary code [+],
vulnerabilities [+],
regression [+],
user [+],
bugtraq [+],
linux kernel [+],
automated system [+],
yelp,
xml rpc,
william grant,
war,
vte,
unix extensions,
tls,
title request,
tex,
tcp wrappers,
system,
suspected,
steve dispensa,
sslv3,
squid,
spam,
source packages,
source,
snmp vulnerability,
snmp server,
snmp,
sid stamm,
showmodaldialog,
setuid program,
sensitive objects,
select statement,
sebastian krahmer,
ruby,
rpc,
root privilege,
ronald volgers,
robert swiecki,
renegotiation,
ramon de carvalho,
pyxml,
python,
paul stone,
pam motd,
packet contents,
overflows,
org,
opie,
null pointer,
nspr,
network traffic,
netpbm,
multimedia files,
motd,
moinmoin,
mikael pettersson,
metalink,
memory protection,
memory contents,
mathias krause,
martijn wargers,
marsh ray,
marc schoenefeld,
man in the middle attack,
mail directory,
ludovic hirlimann,
ludovic,
live,
lintian,
libpng,
libopie,
krahmer,
kernel memory,
josh soref,
jesse ruderman,
javascript engine,
janne snabb,
irssi,
input validation,
htcp,
hierarchical access control,
hash algorithm,
gzip,
group writable,
group mail,
gnutls,
gnome,
ghostscript,
georgi guninski,
font files,
font,
flaw,
fireware,
firebug,
filter window,
filenames,
fastjar,
expat,
ethernet frames,
erlang,
epiphany,
emacs,
ehsan,
dvipng,
dvi files,
dvi,
directory traversal,
dhcp vulnerability,
dhcp,
despam,
denis excoffier,
de carvalho,
database environment,
dan rosenberg,
cmake,
cab file,
cab,
buffer overflow,
browser engine,
bit,
binhex,
awt library,
audio file library,
audio,
arbitrary locations,
application crash,
application,
ant,
adam zabrocki,
access controls,
access control lists,
access
-
-
12:53
»
Packet Storm Security Advisories
Ubuntu Security Notice 1400-5 - USN-1400-1 fixed vulnerabilities in Firefox. Firefox 11 started using GSettings to access the system proxy settings. If there is a GSettings proxy settings schema, Firefox will consume it. The GSettings proxy settings schema that was shipped by default was unused by other applications and broke Firefox's ability to use system proxy settings. This update removes the unused schema. Various other issues were also addressed.
-
12:53
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1400-5 - USN-1400-1 fixed vulnerabilities in Firefox. Firefox 11 started using GSettings to access the system proxy settings. If there is a GSettings proxy settings schema, Firefox will consume it. The GSettings proxy settings schema that was shipped by default was unused by other applications and broke Firefox's ability to use system proxy settings. This update removes the unused schema. Various other issues were also addressed.
-
12:53
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1400-5 - USN-1400-1 fixed vulnerabilities in Firefox. Firefox 11 started using GSettings to access the system proxy settings. If there is a GSettings proxy settings schema, Firefox will consume it. The GSettings proxy settings schema that was shipped by default was unused by other applications and broke Firefox's ability to use system proxy settings. This update removes the unused schema. Various other issues were also addressed.
-
-
18:26
»
Packet Storm Security Advisories
Ubuntu Security Notice 1414-1 - It was discovered that Aptdaemon incorrectly handled installing packages without performing a transaction simulation. An attacker could possibly use this flaw to install altered packages.
-
18:26
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1414-1 - It was discovered that Aptdaemon incorrectly handled installing packages without performing a transaction simulation. An attacker could possibly use this flaw to install altered packages.
-
18:26
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1414-1 - It was discovered that Aptdaemon incorrectly handled installing packages without performing a transaction simulation. An attacker could possibly use this flaw to install altered packages.
-
-
8:40
»
Packet Storm Security Advisories
Ubuntu Security Notice 1391-1 - A flaw was discovered in the XFS filesystem. If a local user mounts a specially crafted XFS image it could potential execute arbitrary code on the system.
-
8:40
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1391-1 - A flaw was discovered in the XFS filesystem. If a local user mounts a specially crafted XFS image it could potential execute arbitrary code on the system.
-
8:40
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1391-1 - A flaw was discovered in the XFS filesystem. If a local user mounts a specially crafted XFS image it could potential execute arbitrary code on the system.
-
-
19:55
»
Packet Storm Security Advisories
Ubuntu Security Notice 1373-2 - USN 1373-1 fixed vulnerabilities in OpenJDK 6 in Ubuntu 10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04 for all architectures except for ARM (armel). This provides the corresponding OpenJDK 6 update for use with the ARM (armel) architecture in Ubuntu 10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04.
-
19:55
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1373-2 - USN 1373-1 fixed vulnerabilities in OpenJDK 6 in Ubuntu 10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04 for all architectures except for ARM (armel). This provides the corresponding OpenJDK 6 update for use with the ARM (armel) architecture in Ubuntu 10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04.
-
19:55
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1373-2 - USN 1373-1 fixed vulnerabilities in OpenJDK 6 in Ubuntu 10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04 for all architectures except for ARM (armel). This provides the corresponding OpenJDK 6 update for use with the ARM (armel) architecture in Ubuntu 10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04.
-
-
13:08
»
Packet Storm Security Advisories
Ubuntu Security Notice 1358-2 - USN 1358-1 fixed multiple vulnerabilities in PHP. The fix for CVE-2012-0831 introduced a regression where the state of the magic_quotes_gpc setting was not correctly reflected when calling the ini_get() function. Various other issues were also addressed.
-
13:08
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1358-2 - USN 1358-1 fixed multiple vulnerabilities in PHP. The fix for CVE-2012-0831 introduced a regression where the state of the magic_quotes_gpc setting was not correctly reflected when calling the ini_get() function. Various other issues were also addressed.
-
13:08
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1358-2 - USN 1358-1 fixed multiple vulnerabilities in PHP. The fix for CVE-2012-0831 introduced a regression where the state of the magic_quotes_gpc setting was not correctly reflected when calling the ini_get() function. Various other issues were also addressed.
-
-
16:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 1263-2 - USN-1263-1 fixed vulnerabilities in OpenJDK 6. The upstream patch for the chosen plaintext attack on the block-wise AES encryption algorithm to fail when using certain algorithms. This update fixes the problem. Various other issues were also addressed.
-
16:00
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1263-2 - USN-1263-1 fixed vulnerabilities in OpenJDK 6. The upstream patch for the chosen plaintext attack on the block-wise AES encryption algorithm to fail when using certain algorithms. This update fixes the problem. Various other issues were also addressed.
-
16:00
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1263-2 - USN-1263-1 fixed vulnerabilities in OpenJDK 6. The upstream patch for the chosen plaintext attack on the block-wise AES encryption algorithm to fail when using certain algorithms. This update fixes the problem. Various other issues were also addressed.
-
-
19:58
»
Packet Storm Security Advisories
Ubuntu Security Notice 1289-1 - It was discovered that colord incorrectly handled certain SQL queries. A local attacker could exploit this to modify arbitrary sqlite databases. On Ubuntu, colord runs as its own user by default, so standard file permissions would limit which databases could be altered.
-
19:58
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1289-1 - It was discovered that colord incorrectly handled certain SQL queries. A local attacker could exploit this to modify arbitrary sqlite databases. On Ubuntu, colord runs as its own user by default, so standard file permissions would limit which databases could be altered.
-
19:58
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1289-1 - It was discovered that colord incorrectly handled certain SQL queries. A local attacker could exploit this to modify arbitrary sqlite databases. On Ubuntu, colord runs as its own user by default, so standard file permissions would limit which databases could be altered.
-
-
17:13
»
Packet Storm Security Advisories
Ubuntu Security Notice 1275-1 - Vasiliy Kulikov discovered that taskstats did not enforce access restrictions. A local attacker could exploit this to read certain information, leading to a loss of privacy.
-
17:13
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1275-1 - Vasiliy Kulikov discovered that taskstats did not enforce access restrictions. A local attacker could exploit this to read certain information, leading to a loss of privacy.
-
17:13
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1275-1 - Vasiliy Kulikov discovered that taskstats did not enforce access restrictions. A local attacker could exploit this to read certain information, leading to a loss of privacy.
-
-
15:30
»
Packet Storm Security Advisories
Ubuntu Security Notice 1266-1 - It was discovered that slapd contained an off-by-one error. An authenticated attacker could potentially exploit this by sending a crafted LDIF entry containing an empty postalAddress.
-
15:30
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1266-1 - It was discovered that slapd contained an off-by-one error. An authenticated attacker could potentially exploit this by sending a crafted LDIF entry containing an empty postalAddress.
-
15:30
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1266-1 - It was discovered that slapd contained an off-by-one error. An authenticated attacker could potentially exploit this by sending a crafted LDIF entry containing an empty postalAddress.
-
-
21:38
»
Packet Storm Security Advisories
Ubuntu Security Notice 1260-1 - Vasiliy Kulikov discovered that taskstats did not enforce access restrictions. A local attacker could exploit this to read certain information, leading to a loss of privacy.
-
21:38
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1260-1 - Vasiliy Kulikov discovered that taskstats did not enforce access restrictions. A local attacker could exploit this to read certain information, leading to a loss of privacy.
-
21:38
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1260-1 - Vasiliy Kulikov discovered that taskstats did not enforce access restrictions. A local attacker could exploit this to read certain information, leading to a loss of privacy.
-
-
15:52
»
Packet Storm Security Advisories
Ubuntu Security Notice 1192-3 - USN-1192-1 provided Firefox 6 as a security upgrade. Unfortunately, this caused a regression in libvoikko which caused Firefox to crash while spell checking words with hyphens. This update corrects the issue.
-
15:52
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1192-3 - USN-1192-1 provided Firefox 6 as a security upgrade. Unfortunately, this caused a regression in libvoikko which caused Firefox to crash while spell checking words with hyphens. This update corrects the issue.
-
15:52
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1192-3 - USN-1192-1 provided Firefox 6 as a security upgrade. Unfortunately, this caused a regression in libvoikko which caused Firefox to crash while spell checking words with hyphens. This update corrects the issue.
-
15:50
»
Packet Storm Security Advisories
Ubuntu Security Notice 1232-2 - USN-1232-1 fixed vulnerabilities in the X.Org X server. A regression was found on Ubuntu 10.04 LTS that affected GLX support. This update temporarily disables the fix for CVE-2010-4818 that introduced the regression.
-
15:50
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1232-2 - USN-1232-1 fixed vulnerabilities in the X.Org X server. A regression was found on Ubuntu 10.04 LTS that affected GLX support. This update temporarily disables the fix for CVE-2010-4818 that introduced the regression.
-
15:50
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1232-2 - USN-1232-1 fixed vulnerabilities in the X.Org X server. A regression was found on Ubuntu 10.04 LTS that affected GLX support. This update temporarily disables the fix for CVE-2010-4818 that introduced the regression.
-
-
23:11
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1149-2 - USN-1149-1 fixed vulnerabilities in Firefox. Unfortunately, a regression was introduced that prevented cookies from being stored properly when the hostname was a single character. This update fixes the problem.
-
23:11
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1149-2 - USN-1149-1 fixed vulnerabilities in Firefox. Unfortunately, a regression was introduced that prevented cookies from being stored properly when the hostname was a single character. This update fixes the problem.
-
-
2:12
»
Packet Storm Security Advisories
Ubuntu Security Notice 1157-3 - USN-1157-1 fixed vulnerabilities in Firefox. Unfortunately, this update produced the side effect of pulling in Firefox on some systems that did not have it installed during a dist-upgrade due to changes in the Ubuntu language packs. This update fixes the problem.
-
2:12
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1157-3 - USN-1157-1 fixed vulnerabilities in Firefox. Unfortunately, this update produced the side effect of pulling in Firefox on some systems that did not have it installed during a dist-upgrade due to changes in the Ubuntu language packs. This update fixes the problem.
-
2:12
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1157-3 - USN-1157-1 fixed vulnerabilities in Firefox. Unfortunately, this update produced the side effect of pulling in Firefox on some systems that did not have it installed during a dist-upgrade due to changes in the Ubuntu language packs. This update fixes the problem.
-
-
17:29
»
Packet Storm Security Advisories
Ubuntu Security Notice 1142-1 - Henne Vogelsang discovered that under certain PolicyKit configurations, GDM could be made to launch a browser. A local attacker could exploit this to gain access to files with the privileges of the gdm user. PolicyKit is not configured in this manner in Ubuntu by default.
-
17:29
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1142-1 - Henne Vogelsang discovered that under certain PolicyKit configurations, GDM could be made to launch a browser. A local attacker could exploit this to gain access to files with the privileges of the gdm user. PolicyKit is not configured in this manner in Ubuntu by default.
-
17:29
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1142-1 - Henne Vogelsang discovered that under certain PolicyKit configurations, GDM could be made to launch a browser. A local attacker could exploit this to gain access to files with the privileges of the gdm user. PolicyKit is not configured in this manner in Ubuntu by default.
-
-
8:44
»
Packet Storm Security Advisories
Ubuntu Security Notice 1129-1 - It was discovered that the Safe.pm Perl module incorrectly handled Safe::reval and Safe::rdo access restrictions. It was discovered that the CGI.pm Perl module incorrectly handled certain MIME boundary strings. It was discovered that the CGI.pm Perl module incorrectly handled newline characters. It was discovered that the lc, lcfirst, uc, and ucfirst functions did not properly apply the taint attribute when processing tainted input.
-
8:44
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1129-1 - It was discovered that the Safe.pm Perl module incorrectly handled Safe::reval and Safe::rdo access restrictions. It was discovered that the CGI.pm Perl module incorrectly handled certain MIME boundary strings. It was discovered that the CGI.pm Perl module incorrectly handled newline characters. It was discovered that the lc, lcfirst, uc, and ucfirst functions did not properly apply the taint attribute when processing tainted input.
-
8:44
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1129-1 - It was discovered that the Safe.pm Perl module incorrectly handled Safe::reval and Safe::rdo access restrictions. It was discovered that the CGI.pm Perl module incorrectly handled certain MIME boundary strings. It was discovered that the CGI.pm Perl module incorrectly handled newline characters. It was discovered that the lc, lcfirst, uc, and ucfirst functions did not properly apply the taint attribute when processing tainted input.
-
-
9:37
»
Packet Storm Security Advisories
Ubuntu Security Notice 1112-1 - Multiple vulnerabilities have been identified and fixed in Firefox. It was discovered that there was a vulnerability in the memory handling of certain types of content. It was discovered that Firefox incorrectly handled certain JavaScript requests. Ian Beer discovered a vulnerability in the memory handling of a certain types of documents. Various other issues were also addressed.
-
9:37
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1112-1 - Multiple vulnerabilities have been identified and fixed in Firefox. It was discovered that there was a vulnerability in the memory handling of certain types of content. It was discovered that Firefox incorrectly handled certain JavaScript requests. Ian Beer discovered a vulnerability in the memory handling of a certain types of documents. Various other issues were also addressed.
-
9:37
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1112-1 - Multiple vulnerabilities have been identified and fixed in Firefox. It was discovered that there was a vulnerability in the memory handling of certain types of content. It was discovered that Firefox incorrectly handled certain JavaScript requests. Ian Beer discovered a vulnerability in the memory handling of a certain types of documents. Various other issues were also addressed.
-
-
19:45
»
Packet Storm Security Advisories
Ubuntu Security Notice 1052-1 - It was discovered that the JNLP SecurityManager in IcedTea for Java OpenJDK in some instances failed to properly apply the intended security policy in its checkPermission method. This could allow an attacker execute code with privileges that should have been prevented.
-
19:45
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1052-1 - It was discovered that the JNLP SecurityManager in IcedTea for Java OpenJDK in some instances failed to properly apply the intended security policy in its checkPermission method. This could allow an attacker execute code with privileges that should have been prevented.
-
19:45
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1052-1 - It was discovered that the JNLP SecurityManager in IcedTea for Java OpenJDK in some instances failed to properly apply the intended security policy in its checkPermission method. This could allow an attacker execute code with privileges that should have been prevented.
-
-
17:17
»
Packet Storm Security Advisories
Ubuntu Security Notice 1042-2 - USN-1042-1 fixed vulnerabilities in PHP5. The fix for CVE-2010-3436 introduced a regression in the open_basedir restriction handling code. This update fixes the problem. We apologize for the inconvenience. It was discovered that attackers might be able to bypass open_basedir() restrictions by passing a specially crafted filename.
-
17:17
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1042-2 - USN-1042-1 fixed vulnerabilities in PHP5. The fix for CVE-2010-3436 introduced a regression in the open_basedir restriction handling code. This update fixes the problem. We apologize for the inconvenience. It was discovered that attackers might be able to bypass open_basedir() restrictions by passing a specially crafted filename.
-
17:17
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1042-2 - USN-1042-1 fixed vulnerabilities in PHP5. The fix for CVE-2010-3436 introduced a regression in the open_basedir restriction handling code. This update fixes the problem. We apologize for the inconvenience. It was discovered that attackers might be able to bypass open_basedir() restrictions by passing a specially crafted filename.
-
-
19:34
»
Packet Storm Security Advisories
Ubuntu Security Notice 1037-1 - Under certain circumstances, the DHCP client could start before its AppArmor profile was loaded and therefore run unconfined. This update ensures the AppArmor profile is loaded before DHCP client starts.
-
19:34
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1037-1 - Under certain circumstances, the DHCP client could start before its AppArmor profile was loaded and therefore run unconfined. This update ensures the AppArmor profile is loaded before DHCP client starts.
-
19:34
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1037-1 - Under certain circumstances, the DHCP client could start before its AppArmor profile was loaded and therefore run unconfined. This update ensures the AppArmor profile is loaded before DHCP client starts.
-
19:33
»
Packet Storm Security Advisories
Ubuntu Security Notice 1036-1 - Under certain circumstances, CUPS could start before its AppArmor profile was loaded and therefore run unconfined. This update ensures the AppArmor profile is loaded before CUPS starts.
-
19:33
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1036-1 - Under certain circumstances, CUPS could start before its AppArmor profile was loaded and therefore run unconfined. This update ensures the AppArmor profile is loaded before CUPS starts.
-
19:33
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1036-1 - Under certain circumstances, CUPS could start before its AppArmor profile was loaded and therefore run unconfined. This update ensures the AppArmor profile is loaded before CUPS starts.
-
-
17:24
»
Packet Storm Security Advisories
Ubuntu Security Notice 1024-2 - USN-1024-1 fixed vulnerabilities in OpenJDK. Some of the additional backported improvements could interfere with the compilation of certain Java software. This update fixes the problem. We apologize for the inconvenience. It was discovered that certain system property information was being leaked, which could allow an attacker to obtain sensitive information.
-
17:24
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1024-2 - USN-1024-1 fixed vulnerabilities in OpenJDK. Some of the additional backported improvements could interfere with the compilation of certain Java software. This update fixes the problem. We apologize for the inconvenience. It was discovered that certain system property information was being leaked, which could allow an attacker to obtain sensitive information.
-
17:24
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1024-2 - USN-1024-1 fixed vulnerabilities in OpenJDK. Some of the additional backported improvements could interfere with the compilation of certain Java software. This update fixes the problem. We apologize for the inconvenience. It was discovered that certain system property information was being leaked, which could allow an attacker to obtain sensitive information.
-
-
20:56
»
Packet Storm Security Advisories
Ubuntu Security Notice 1024-1 - It was discovered that certain system property information was being leaked, which could allow an attacker to obtain sensitive information.
-
20:56
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1024-1 - It was discovered that certain system property information was being leaked, which could allow an attacker to obtain sensitive information.
-
20:56
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1024-1 - It was discovered that certain system property information was being leaked, which could allow an attacker to obtain sensitive information.
-
-
18:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1015-1 - Christoph Diehl discovered that libvpx did not properly perform bounds checking. If an application using libvpx opened a specially crafted WebM file, an attacker could cause a denial of service or possibly execute code as the user invoking the program.
-
18:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1016-1 - Bui Quang Minh discovered that libxml2 did not properly process XPath namespaces and attributes. If an application using libxml2 opened a specially crafted XML file, an attacker could cause a denial of service or possibly execute code as the user invoking the program.
-
18:01
»
Packet Storm Security Advisories
Ubuntu Security Notice 1015-1 - Christoph Diehl discovered that libvpx did not properly perform bounds checking. If an application using libvpx opened a specially crafted WebM file, an attacker could cause a denial of service or possibly execute code as the user invoking the program.
-
18:01
»
Packet Storm Security Advisories
Ubuntu Security Notice 1016-1 - Bui Quang Minh discovered that libxml2 did not properly process XPath namespaces and attributes. If an application using libxml2 opened a specially crafted XML file, an attacker could cause a denial of service or possibly execute code as the user invoking the program.
-
-
22:28
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1012-1 - Emmanuel Bouillon discovered that CUPS did not properly handle certain Internet Printing Protocol (IPP) packets. A remote attacker could use this flaw to cause a denial of service or possibly execute arbitrary code. In the default installation in Ubuntu 8.04 LTS and later, attackers would be isolated by the CUPS AppArmor profile.
-
22:01
»
Packet Storm Security Advisories
Ubuntu Security Notice 1012-1 - Emmanuel Bouillon discovered that CUPS did not properly handle certain Internet Printing Protocol (IPP) packets. A remote attacker could use this flaw to cause a denial of service or possibly execute arbitrary code. In the default installation in Ubuntu 8.04 LTS and later, attackers would be isolated by the CUPS AppArmor profile.
-
1:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1011-1 - Morten Krakvik discovered a heap-based buffer overflow in Firefox. If a user were tricked into navigating to a malicious site, an attacker could cause a denial of service or possibly execute arbitrary code as the user invoking the program.
-
1:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 1011-1 - Morten Krakvik discovered a heap-based buffer overflow in Firefox. If a user were tricked into navigating to a malicious site, an attacker could cause a denial of service or possibly execute arbitrary code as the user invoking the program.
-
-
15:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1007-1 - Richard Moore discovered that NSS would sometimes incorrectly match an SSL certificate which had a Common Name that used a wildcard followed by a partial IP address. While it is very unlikely that a Certificate Authority would issue such a certificate, if an attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to view sensitive information. Nelson Bolyard discovered a weakness in the Diffie-Hellman Ephemeral mode (DHE) key exchange implementation which allowed servers to use a too small key length.
-
15:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 1007-1 - Richard Moore discovered that NSS would sometimes incorrectly match an SSL certificate which had a Common Name that used a wildcard followed by a partial IP address. While it is very unlikely that a Certificate Authority would issue such a certificate, if an attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to view sensitive information. Nelson Bolyard discovered a weakness in the Diffie-Hellman Ephemeral mode (DHE) key exchange implementation which allowed servers to use a too small key length.
-
-
18:02
»
Packet Storm Security Advisories
Ubuntu Security Notice 1006-1 - A large number of security issues were discovered in the WebKit browser and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Please consult the bug listed at the top of this advisory to get the exact list of CVE numbers fixed for each release.
-
-
21:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1004-1 - It was discovered that Django did not properly sanitize the cookie value when applying CSRF protections resulting in a cross-site scripting (XSS) vulnerability. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain.
-
21:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 1004-1 - It was discovered that Django did not properly sanitize the cookie value when applying CSRF protections resulting in a cross-site scripting (XSS) vulnerability. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain.
-
-
18:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1002-1 - It was discovered that PostgreSQL did not properly enforce permissions within sessions when PL/Perl and PL/Tcl functions or operators were redefined. A remote authenticated attacker could exploit this to execute arbitrary code with permissions of a different user, possibly leading to privilege escalation.
-
18:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 1002-1 - It was discovered that PostgreSQL did not properly enforce permissions within sessions when PL/Perl and PL/Tcl functions or operators were redefined. A remote authenticated attacker could exploit this to execute arbitrary code with permissions of a different user, possibly leading to privilege escalation.
-
-
15:02
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1001-1 - The cluster logical volume manager daemon (clvmd) in LVM2 did not correctly validate credentials. A local user could use this flaw to manipulate logical volumes without root privileges and cause a denial of service in the cluster.
-
15:01
»
Packet Storm Security Advisories
Ubuntu Security Notice 1001-1 - The cluster logical volume manager daemon (clvmd) in LVM2 did not correctly validate credentials. A local user could use this flaw to manipulate logical volumes without root privileges and cause a denial of service in the cluster.
-
-
17:14
»
Packet Storm Security Recent Files
Ubuntu Security Notice 999-1 - Mike Roszkowski discovered that the Kerberos KDC did not correctly validate the contents of certain messages. If an authenticated remote attacker sent specially crafted TGS requests, the KDC service would crash, leading to a denial of service.
-
-
14:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 994-1 - It was discovered that libHX incorrectly handled certain parameters to the HX_split function. An attacker could use this flaw to cause a denial of service or possibly execute arbitrary code with the privileges of the user. The default compiler options for affected releases should reduce the vulnerability to a denial of service.
-
14:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 996-1 - It was discovered that Mako incorrectly filtered single-quote characters when performing html filtering. An attacker could utilize this to perform cross-site scripting attacks.
-
14:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 993-1 - Stefan Cornelius discovered that libgdiplus incorrectly handled certain image files. If a user or automated system were tricked into opening a crafted image file, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program.
-
14:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 994-1 - It was discovered that libHX incorrectly handled certain parameters to the HX_split function. An attacker could use this flaw to cause a denial of service or possibly execute arbitrary code with the privileges of the user. The default compiler options for affected releases should reduce the vulnerability to a denial of service.
-
14:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 996-1 - It was discovered that Mako incorrectly filtered single-quote characters when performing html filtering. An attacker could utilize this to perform cross-site scripting attacks.
-
-
20:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 991-1 - Jima discovered that quassel would respond to a single privmsg containing multiple CTCP requests with multiple NOTICEs, possibly resulting in a denial of service against the IRC connection.
-
20:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 991-1 - Jima discovered that quassel would respond to a single privmsg containing multiple CTCP requests with multiple NOTICEs, possibly resulting in a denial of service against the IRC connection.
-
-
23:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 989-1 - Auke van Slooten discovered that PHP incorrectly handled certain xmlrpc requests. It was discovered that the pseudorandom number generator in PHP did not provide the expected entropy. It was discovered that PHP did not properly handle directory pathnames that lacked a trailing slash character. Grzegorz Stachowiak discovered that the PHP session extension did not properly handle semicolon characters. Stefan Esser discovered that PHP incorrectly decoded remote HTTP chunked encoding streams. Various other issues were also addressed.
-
23:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 989-1 - Auke van Slooten discovered that PHP incorrectly handled certain xmlrpc requests. It was discovered that the pseudorandom number generator in PHP did not provide the expected entropy. It was discovered that PHP did not properly handle directory pathnames that lacked a trailing slash character. Grzegorz Stachowiak discovered that the PHP session extension did not properly handle semicolon characters. Stefan Esser discovered that PHP incorrectly decoded remote HTTP chunked encoding streams. Various other issues were also addressed.
-
19:01
»
Packet Storm Security Recent Files
Local proof of concept exploit that demonstrates a vulnerability with mountall where a udev rule is created with world-writable permissions.
-
19:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 986-1 - An integer overflow was discovered in bzip2. If a user or automated system were tricked into decompressing a crafted bz2 file, an attacker could cause bzip2 or any application linked against libbz2 to crash or possibly execute code as the user running the program.
-
19:00
»
Packet Storm Security Exploits
Local proof of concept exploit that demonstrates a vulnerability with mountall where a udev rule is created with world-writable permissions.
-
19:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 986-1 - An integer overflow was discovered in bzip2. If a user or automated system were tricked into decompressing a crafted bz2 file, an attacker could cause bzip2 or any application linked against libbz2 to crash or possibly execute code as the user running the program.
-
-
21:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 985-1 - Alasdair MacGregor discovered that mountall created a udev rule file with world-writable permissions. A local attacker could exploit this under certain conditions to cause udev to execute arbitrary commands as the root user.
-
21:01
»
Packet Storm Security Advisories
Ubuntu Security Notice 985-1 - Alasdair MacGregor discovered that mountall created a udev rule file with world-writable permissions. A local attacker could exploit this under certain conditions to cause udev to execute arbitrary commands as the root user.
-
-
23:02
»
Packet Storm Security Recent Files
Ubuntu Security Notice 984-1 - It was discovered that LFTP incorrectly filtered filenames suggested by Content-Disposition headers. If a user or automated system were tricked into downloading a file from a malicious site, a remote attacker could create the file with an arbitrary name, such as a dotfile, and possibly run arbitrary code.
-
23:01
»
Packet Storm Security Advisories
Ubuntu Security Notice 984-1 - It was discovered that LFTP incorrectly filtered filenames suggested by Content-Disposition headers. If a user or automated system were tricked into downloading a file from a malicious site, a remote attacker could create the file with an arbitrary name, such as a dotfile, and possibly run arbitrary code.
-
-
22:02
»
Packet Storm Security Recent Files
Ubuntu Security Notice 982-1 - It was discovered that Wget would use filenames provided by the server when following 3xx redirects. If a user or automated system were tricked into downloading a file from a malicious site, a remote attacker could create the file with an arbitrary name (e.g. .wgetrc), and possibly run arbitrary code.
-
22:01
»
Packet Storm Security Advisories
Ubuntu Security Notice 982-1 - It was discovered that Wget would use filenames provided by the server when following 3xx redirects. If a user or automated system were tricked into downloading a file from a malicious site, a remote attacker could create the file with an arbitrary name (e.g. .wgetrc), and possibly run arbitrary code.
-
-
12:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 980-1 - Julius Plenz discovered that bogofilter incorrectly handled certain malformed encodings. By sending a specially crafted email, a remote attacker could exploit this and cause bogofilter to crash, resulting in a denial of service.
-
12:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 981-1 - It was discovered that libwww-perl incorrectly filtered filenames suggested by Content-Disposition headers. If a user were tricked into downloading a file from a malicious site, a remote attacker could overwrite hidden files in the user's directory.
-
12:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 980-1 - Julius Plenz discovered that bogofilter incorrectly handled certain malformed encodings. By sending a specially crafted email, a remote attacker could exploit this and cause bogofilter to crash, resulting in a denial of service.
-
12:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 981-1 - It was discovered that libwww-perl incorrectly filtered filenames suggested by Content-Disposition headers. If a user were tricked into downloading a file from a malicious site, a remote attacker could overwrite hidden files in the user's directory.
-
-
21:00
»
Packet Storm Security Recent Files
Ubuntu Security Notice 979-1 - Stefan Cornelius of Secunia Research discovered a boundary error during RLE decompression in the TranscribePalmImageToJPEG() function in generators/plucker/inplug/image.cpp of okular when processing images embedded in PDB files, which can be exploited to cause a heap-based buffer overflow.
-
21:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 979-1 - Stefan Cornelius of Secunia Research discovered a boundary error during RLE decompression in the TranscribePalmImageToJPEG() function in generators/plucker/inplug/image.cpp of okular when processing images embedded in PDB files, which can be exploited to cause a heap-based buffer overflow.
-
-
23:38
»
Packet Storm Security Recent Files
Ubuntu Security Notice 977-1 - It was discovered that MoinMoin did not properly sanitize its input, resulting in cross-site scripting (XSS) vulnerabilities. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain.
-
23:38
»
Packet Storm Security Advisories
Ubuntu Security Notice 976-1 - It was discovered that Tomcat incorrectly handled invalid Transfer-Encoding headers. A remote attacker could send specially crafted requests containing invalid headers to the server and cause a denial of service, or possibly obtain sensitive information from other requests.
-
23:38
»
Packet Storm Security Advisories
Ubuntu Security Notice 977-1 - It was discovered that MoinMoin did not properly sanitize its input, resulting in cross-site scripting (XSS) vulnerabilities. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain.
-
-
22:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 971-1 - It was discovered that the IcedTea plugin did not correctly check certain accesses. If a user or automated system were tricked into running a specially crafted Java applet, a remote attacker could read arbitrary files with user privileges, leading to a loss of privacy.
-
22:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 971-1 - It was discovered that the IcedTea plugin did not correctly check certain accesses. If a user or automated system were tricked into running a specially crafted Java applet, a remote attacker could read arbitrary files with user privileges, leading to a loss of privacy.
-
-
20:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 970-1 - It was discovered that GPGSM in GnuPG2 did not correctly handle certificates with a large number of Subject Alternate Names. If a user or automated system were tricked into processing a specially crafted certificate, an attacker could cause a denial of service or execute arbitrary code with privileges of the user invoking the program.
-
0:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 967-1 - Ludwig Nussel discovered w3m does not properly handle SSL/TLS certificates with NULL characters in the certificate name. An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications.
-
0:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 967-1 - Ludwig Nussel discovered w3m does not properly handle SSL/TLS certificates with NULL characters in the certificate name. An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications.
-
-
13:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 969-1 - It was discovered that the PC/SC service did not correctly handle malformed messages. A local attacker could exploit this to execute arbitrary code with root privileges.
-
13:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 969-1 - It was discovered that the PC/SC service did not correctly handle malformed messages. A local attacker could exploit this to execute arbitrary code with root privileges.
-
12:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 968-1 - It was discovered that the Ubuntu image shipped on some Dell Latitude 2110 systems was accidentally configured to allow unauthenticated package installations. A remote attacker intercepting network communications or a malicious archive mirror server could exploit this to trick the user into installing unsigned packages, resulting in arbitrary code execution with root privileges.
-
12:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 968-1 - It was discovered that the Ubuntu image shipped on some Dell Latitude 2110 systems was accidentally configured to allow unauthenticated package installations. A remote attacker intercepting network communications or a malicious archive mirror server could exploit this to trick the user into installing unsigned packages, resulting in arbitrary code execution with root privileges.
-
-
20:34
»
Packet Storm Security Recent Files
Ubuntu Security Notice 957-2 - USN-957-1 fixed vulnerabilities in Firefox and Xulrunner. Daniel Holbert discovered that the fix for CVE-2010-1214 introduced a regression which did not properly initialize a plugin pointer. If a user were tricked into viewing a malicious site, a remote attacker could use this to crash the browser or run arbitrary code as the user invoking the program. This update fixes the problem.
-
20:34
»
Packet Storm Security Recent Files
Ubuntu Security Notice 930-6 - USN-957-1 fixed vulnerabilities in Firefox and Xulrunner. Daniel Holbert discovered that the fix for CVE-2010-1214 introduced a regression which did not properly initialize a plugin pointer. If a user were tricked into viewing a malicious site, a remote attacker could use this to crash the browser or run arbitrary code as the user invoking the program. This update fixes the problem.
-
20:34
»
Packet Storm Security Recent Files
Ubuntu Security Notice 964-1 - Matt Weatherford discovered that Likewise Open did not correctly check password expiration for the local-provider account. A local attacker could exploit this to log into a system they would otherwise not have access to.
-
20:33
»
Packet Storm Security Advisories
Ubuntu Security Notice 957-2 - USN-957-1 fixed vulnerabilities in Firefox and Xulrunner. Daniel Holbert discovered that the fix for CVE-2010-1214 introduced a regression which did not properly initialize a plugin pointer. If a user were tricked into viewing a malicious site, a remote attacker could use this to crash the browser or run arbitrary code as the user invoking the program. This update fixes the problem.
-
20:33
»
Packet Storm Security Advisories
Ubuntu Security Notice 930-6 - USN-957-1 fixed vulnerabilities in Firefox and Xulrunner. Daniel Holbert discovered that the fix for CVE-2010-1214 introduced a regression which did not properly initialize a plugin pointer. If a user were tricked into viewing a malicious site, a remote attacker could use this to crash the browser or run arbitrary code as the user invoking the program. This update fixes the problem.