Recent content by LinuxBot

  1. LinuxBot

    Ubuntu Security Update USN-6145-1: Sysstat vulnerabilities

    It was discovered that Sysstat incorrectly handled certain arithmetic multiplications. An attacker could use this issue to cause Sysstat to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue was only fixed for Ubuntu 16.04 LTS. (CVE-2022-39377) It was...
  2. LinuxBot

    Ubuntu Security Update USN-6028-2: libxml2 vulnerabilities

    USN-6028-1 fixed vulnerabilities in libxml2. This update provides the corresponding updates for Ubuntu 23.04. Original advisory details: It was discovered that libxml2 incorrectly handled certain XML files. An attacker could possibly use this issue to cause a crash. (CVE-2022-2309) It was...
  3. LinuxBot

    Ubuntu Security Update USN-6143-1: Firefox vulnerabilities

    Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. (CVE-2023-34414, CVE-2023-34416...
  4. LinuxBot

    Ubuntu Security Update USN-6144-1: LibreOffice vulnerabilities

    It was discovered that LibreOffice did not properly validate the number of parameters passed to the formula interpreter, leading to an array index underflow attack. If a user were tricked into opening a specially crafted spreadsheet file, an attacker could possibly use this issue to execute...
  5. LinuxBot

    Debian Security Update DSA-5419 c-ares - security update

    Two vunerabilities were discovered in c-ares, an asynchronous name resolver library: Continue reading...
  6. LinuxBot

    Ubuntu Security Update USN-6140-1: Go vulnerabilities

    It was discovered that Go did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause a panic resulting in a denial of service. This issue only affected golang-1.19 on Ubuntu 22.10. (CVE-2022-41724, CVE-2023-24534, CVE-2023-24537) It was...
  7. LinuxBot

    Ubuntu Security Update USN-6141-1: xfce4-settings vulnerability

    Robin Peraglie and Johannes Moritz discovered that xfce4-settings incorrectly parsed quoted input when processed through xdg-open. A remote attacker could possibly use this issue to inject arbitrary arguments into the default browser or file manager. Continue reading...
  8. LinuxBot

    Ubuntu Security Update USN-6142-1: nghttp2 vulnerability

    Gal Goldshtein discovered that nghttp2 incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. Continue reading...
  9. LinuxBot

    Ubuntu Security Update USN-6136-1: FRR vulnerabilities

    It was discovered that FRR incorrectly handled parsing certain BGP messages. A remote attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. This issue only affected Ubuntu 23.04. (CVE-2023-31489) It was discovered that FRR incorrectly handled parsing...
  10. LinuxBot

    Ubuntu Security Update USN-6137-1: LibRaw vulnerabilities

    It was discovered that LibRaw incorrectly handled photo files. If a user or automated system were tricked into processing a specially crafted photo file, a remote attacker could cause applications linked against LibRaw to crash, resulting in a denial of service, or possibly execute arbitrary...
  11. LinuxBot

    Ubuntu Security Update USN-6138-1: libssh vulnerabilities

    Philip Turnbull discovered that libssh incorrectly handled rekeying with algorithm guessing. A remote attacker could use this issue to cause libssh to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-1667) Kevin Backhouse discovered that libssh incorrectly...
  12. LinuxBot

    Ubuntu Security Update USN-6139-1: Python vulnerability

    Yebo Cao discovered that Python incorrectly handled certain URLs. An attacker could use this issue to bypass blockinglisting methods. This issue was first addressed in USN-5960-1, but was incomplete. Here we address an additional fix to that issue. (CVE-2023-24329) Continue reading...
  13. LinuxBot

    Ubuntu Security Update USN-6112-2: Perl vulnerability

    USN-6112-1 fixed vulnerabilities in Perl. This update provides the corresponding updates for Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 22.10, and Ubuntu 23.04. Original advisory details: It was discovered that Perl was not properly verifying TLS certificates when using CPAN together with...
  14. LinuxBot

    Debian Security Update DSA-5418 chromium - security update

    Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure. Continue reading...
  15. LinuxBot

    Ubuntu Security Update USN-6135-1: Linux kernel (Azure CVM) vulnerabilities

    Patryk Sondej and Piotr Krysiuk discovered that a race condition existed in the netfilter subsystem of the Linux kernel when processing batch requests, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute...
Top