USN-847-1: Devscripts vulnerability

Referenced CVEs: 
CVE-2009-2946
Description: 
=========================================================== Ubuntu Security Notice USN-847-1 October 08, 2009 devscripts vulnerability CVE-2009-2946 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: devscripts 2.10.11ubuntu5.8.04.4 Ubuntu 8.10: devscripts 2.10.26ubuntu15.2 Ubuntu 9.04: devscripts 2.10.39ubuntu7.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Raphael Geissert discovered that uscan, a part of devscripts, did not properly sanitize its input when processing pathnames. If uscan processed a crafted filename for a file on a remote server, an attacker could execute arbitrary code with the privileges of the user invoking the program.

USN-846-1: ICU vulnerability

Referenced CVEs: 
CVE-2009-0153
Description: 
=========================================================== Ubuntu Security Notice USN-846-1 October 08, 2009 icu vulnerability CVE-2009-0153 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: libicu38 3.8-6ubuntu0.2 Ubuntu 8.10: libicu38 3.8.1-2ubuntu0.2 Ubuntu 9.04: libicu38 3.8.1-3ubuntu1.1 After a standard system upgrade you need to restart applications linked against libicu, such as OpenOffice.org, to effect the necessary changes. Details follow: It was discovered that ICU did not properly handle invalid byte sequences during Unicode conversion. If an application using ICU processed crafted data, content security mechanisms could be bypassed, potentially leading to cross-site scripting (XSS) attacks.

USN-845-1: Pan vulnerability

Referenced CVEs: 
CVE-2008-2363
Description: 
=========================================================== Ubuntu Security Notice USN-845-1 October 08, 2009 pan vulnerability CVE-2008-2363 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: pan 0.132-2ubuntu2.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Pavel Polischouk discovered that Pan incorrectly handled certain data structures. If a user were tricked into viewing malicious nntp data, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program.

USN-844-1: mimeTeX vulnerabilities

Referenced CVEs: 
CVE-2009-1382, CVE-2009-2459
Description: 
=========================================================== Ubuntu Security Notice USN-844-1 October 08, 2009 mimetex vulnerabilities CVE-2009-1382, CVE-2009-2459 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: mimetex 1.50-1ubuntu0.8.04.1 Ubuntu 8.10: mimetex 1.50-1ubuntu0.8.10.1 Ubuntu 9.04: mimetex 1.50-1ubuntu0.9.04.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Chris Evans discovered that mimeTeX incorrectly handled certain long tags. An attacker could exploit this with a crafted mimeTeX expression and cause a denial of service or possibly execute arbitrary code. (CVE-2009-1382) Chris Evans discovered that mimeTeX contained certain directives that may be unsuitable for handling untrusted user input. This update fixed the issue by disabling the \input and \counter tags. (CVE-2009-2459)

USN-843-1: BackupPC vulnerability

Referenced CVEs: 
CVE-2009-3369
Description: 
=========================================================== Ubuntu Security Notice USN-843-1 October 06, 2009 backuppc vulnerability CVE-2009-3369 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: backuppc 3.0.0-4ubuntu1.1 Ubuntu 8.10: backuppc 3.1.0-3ubuntu2.1 Ubuntu 9.04: backuppc 3.1.0-4ubuntu1.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that BackupPC did not restrict normal users from setting the ClientNameAlias parameter. An authenticated user could exploit this to gain access to unauthorized hosts. This update fixed the issue by preventing normal users from modifying the ClientNameAlias configuration parameter.

USN-842-1: Wget vulnerability

Referenced CVEs: 
CVE-2009-3490
Description: 
=========================================================== Ubuntu Security Notice USN-842-1 October 06, 2009 wget vulnerability CVE-2009-3490 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: wget 1.10.2-1ubuntu1.1 Ubuntu 8.04 LTS: wget 1.10.2-3ubuntu1.1 Ubuntu 8.10: wget 1.11.4-1ubuntu1.1 Ubuntu 9.04: wget 1.11.4-2ubuntu1.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that Wget did not correctly handle SSL certificates with zero bytes in the Common Name. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications.

USN-841-1: GLib vulnerability

Referenced CVEs: 
CVE-2009-3289
Description: 
=========================================================== Ubuntu Security Notice USN-841-1 October 05, 2009 glib2.0 vulnerability CVE-2009-3289 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: libglib2.0-0 2.16.6-0ubuntu1.2 Ubuntu 8.10: libglib2.0-0 2.18.2-0ubuntu2.2 Ubuntu 9.04: libglib2.0-0 2.20.1-0ubuntu2.1 After a standard system upgrade you need to restart your session to effect the necessary changes. Details follow: Arand Nash discovered that applications linked to GLib (e.g. Nautilus) did not correctly copy symlinks. If a user copied symlinks with GLib, the symlink target files would become world-writable, allowing local attackers to gain access to potentially sensitive information.

USN-840-1: OpenOffice.org vulnerabilities

Referenced CVEs: 
CVE-2009-0200, CVE-2009-0201, CVE-2009-2139
Description: 
=========================================================== Ubuntu Security Notice USN-840-1 October 01, 2009 openoffice.org vulnerabilities CVE-2009-0200, CVE-2009-0201, CVE-2009-2139 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: openoffice.org-core 1:2.4.1-1ubuntu2.2 Ubuntu 8.10: openoffice.org-core 1:2.4.1-11ubuntu2.2 Ubuntu 9.04: openoffice.org-core 1:3.0.1-9ubuntu3.1 After a standard system upgrade you need to restart OpenOffice.org to effect the necessary changes. Details follow: Dyon Balding discovered flaws in the way OpenOffice.org handled tables. If a user were tricked into opening a specially crafted Word document, a remote attacker might be able to execute arbitrary code with user privileges. (CVE-2009-0200, CVE-2009-0201) A memory overflow flaw was discovered in OpenOffice.org's handling of EMF files. If a user were tricked into opening a specially crafted document, a remote attacker might be able to execute arbitrary code with user privileges. (CVE-2009-2139)

USN-839-1: Samba vulnerabilities

Referenced CVEs: 
CVE-2009-1886, CVE-2009-1888, CVE-2009-2813, CVE-2009-2906, CVE-2009-2948
Description: 
=========================================================== Ubuntu Security Notice USN-839-1 October 01, 2009 samba vulnerabilities CVE-2009-1886, CVE-2009-1888, CVE-2009-2813, CVE-2009-2906, CVE-2009-2948 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: samba 3.0.22-1ubuntu3.9 smbfs 3.0.22-1ubuntu3.9 Ubuntu 8.04 LTS: samba 3.0.28a-1ubuntu4.9 smbfs 3.0.28a-1ubuntu4.9 Ubuntu 8.10: samba 2:3.2.3-1ubuntu3.6 smbclient 2:3.2.3-1ubuntu3.6 smbfs 2:3.2.3-1ubuntu3.6 Ubuntu 9.04: samba 2:3.3.2-1ubuntu3.2 smbfs 2:3.3.2-1ubuntu3.2 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: J. David Hester discovered that Samba incorrectly handled users that lack home directories when the automated [homes] share is enabled. An authenticated user could connect to that share name and gain access to the whole filesystem. (CVE-2009-2813) Tim Prouty discovered that the smbd daemon in Samba incorrectly handled certain unexpected network replies. A remote attacker could send malicious replies to the server and cause smbd to use all available CPU, leading to a denial of service. (CVE-2009-2906) Ronald Volgers discovered that the mount.cifs utility, when installed as a setuid program, would not verify user permissions before opening a credentials file. A local user could exploit this to use or read the contents of unauthorized credential files. (CVE-2009-2948) Reinhard Nißl discovered that the smbclient utility contained format string vulnerabilities in its file name handling. Because of security features in Ubuntu, exploitation of this vulnerability is limited. If a user or automated system were tricked into processing a specially crafted file name, smbclient could be made to crash, possibly leading to a denial of service. This only affected Ubuntu 8.10. (CVE-2009-1886) Jeremy Allison discovered that the smbd daemon in Samba incorrectly handled permissions to modify access control lists when dos filemode is enabled. A remote attacker could exploit this to modify access control lists. This only affected Ubuntu 8.10 and Ubuntu 9.04. (CVE-2009-1886)

USN-838-1: Dovecot vulnerabilities

Referenced CVEs: 
CVE-2008-4577, CVE-2008-5301, CVE-2009-2632, CVE-2009-3235
Description: 
=========================================================== Ubuntu Security Notice USN-838-1 September 28, 2009 dovecot vulnerabilities CVE-2008-4577, CVE-2008-5301, CVE-2009-2632, CVE-2009-3235 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: dovecot-common 1:1.0.10-1ubuntu5.2 Ubuntu 8.10: dovecot-common 1:1.1.4-0ubuntu1.3 Ubuntu 9.04: dovecot-common 1:1.1.11-0ubuntu4.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that the ACL plugin in Dovecot would incorrectly handle negative access rights. An attacker could exploit this flaw to access the Dovecot server, bypassing the intended access restrictions. This only affected Ubuntu 8.04 LTS. (CVE-2008-4577) It was discovered that the ManageSieve service in Dovecot incorrectly handled ".." in script names. A remote attacker could exploit this to read and modify arbitrary sieve files on the server. This only affected Ubuntu 8.10. (CVE-2008-5301) It was discovered that the Sieve plugin in Dovecot incorrectly handled certain sieve scripts. An authenticated user could exploit this with a crafted sieve script to cause a denial of service or possibly execute arbitrary code. (CVE-2009-2632, CVE-2009-3235)
Syndicate content