USN-813-2: Apache vulnerability

Referenced CVEs: 
CVE-2009-2412
Description: 
=========================================================== Ubuntu Security Notice USN-813-2 August 08, 2009 apache2 vulnerability CVE-2009-2412 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libapr0 2.0.55-4ubuntu2.7 After a standard system upgrade you need to restart any applications using apr, such as Subversion and Apache, to effect the necessary changes. Details follow: USN-813-1 fixed vulnerabilities in apr. This update provides the corresponding updates for apr as provided by Apache on Ubuntu 6.06 LTS. Original advisory details: Matt Lewis discovered that apr did not properly sanitize its input when allocating memory. If an application using apr processed crafted input, a remote attacker could cause a denial of service or potentially execute arbitrary code as the user invoking the application.

USN-813-1: apr vulnerability

Referenced CVEs: 
CVE-2009-2412
Description: 
=========================================================== Ubuntu Security Notice USN-813-1 August 08, 2009 apr vulnerability CVE-2009-2412 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: libapr1 1.2.11-1ubuntu0.1 Ubuntu 8.10: libapr1 1.2.12-4ubuntu0.1 Ubuntu 9.04: libapr1 1.2.12-5ubuntu0.1 After a standard system upgrade you need to restart any applications using apr, such as Subversion and Apache, to effect the necessary changes. Details follow: Matt Lewis discovered that apr did not properly sanitize its input when allocating memory. If an application using apr processed crafted input, a remote attacker could cause a denial of service or potentially execute arbitrary code as the user invoking the application.

USN-812-1: Subversion vulnerability

Referenced CVEs: 
CVE-2009-2411
Description: 
=========================================================== Ubuntu Security Notice USN-812-1 August 08, 2009 subversion vulnerability CVE-2009-2411 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libsvn0 1.3.1-3ubuntu1.2 Ubuntu 8.04 LTS: libsvn1 1.4.6dfsg1-2ubuntu1.1 Ubuntu 8.10: libsvn1 1.5.1dfsg1-1ubuntu2.1 Ubuntu 9.04: libsvn1 1.5.4dfsg1-1ubuntu2.1 After a standard system upgrade you need to restart any applications that use Subversion, such as Apache when using mod_dav_svn, to effect the necessary changes. Details follow: Matt Lewis discovered that Subversion did not properly sanitize its input when processing svndiff streams, leading to various integer and heap overflows. If a user or automated system processed crafted input, a remote attacker could cause a denial of service or potentially execute arbitrary code as the user processing the input.

USN-811-1: Firefox and Xulrunner vulnerability

Referenced CVEs: 
CVE-2009-2654
Description: 
=========================================================== Ubuntu Security Notice USN-811-1 August 05, 2009 firefox-3.0, xulrunner-1.9 vulnerability CVE-2009-2654 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: firefox-3.0 3.0.13+nobinonly-0ubuntu0.8.04.1 xulrunner-1.9 1.9.0.13+nobinonly-0ubuntu0.8.04.1 Ubuntu 8.10: abrowser 3.0.13+nobinonly-0ubuntu0.8.10.1 firefox-3.0 3.0.13+nobinonly-0ubuntu0.8.10.1 xulrunner-1.9 1.9.0.13+nobinonly-0ubuntu0.8.10.1 Ubuntu 9.04: abrowser 3.0.13+nobinonly-0ubuntu0.9.04.1 firefox-3.0 3.0.13+nobinonly-0ubuntu0.9.04.1 xulrunner-1.9 1.9.0.13+nobinonly-0ubuntu0.9.04.1 After a standard system upgrade you need to restart Firefox and any applications that use xulrunner, such as Epiphany, to effect the necessary changes. Details follow: Juan Pablo Lopez Yacubian discovered that Firefox did not properly display invalid URLs. If a user were tricked into accessing a malicious website, an attacker could exploit this to spoof the location bar, such as in a phishing attack. Furthermore, if the malicious website had a valid SSL certificate, Firefox would display the spoofed page as trusted.

USN-810-2: NSPR update

Description: 
=========================================================== Ubuntu Security Notice USN-810-2 August 04, 2009 nspr update https://launchpad.net/bugs/387745 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: libnspr4-0d 4.7.5-0ubuntu0.8.04.1 Ubuntu 8.10: libnspr4-0d 4.7.5-0ubuntu0.8.10.1 Ubuntu 9.04: libnspr4-0d 4.7.5-0ubuntu0.9.04.1 After a standard system upgrade you need to restart any applications that use NSPR, such as Firefox, to effect the necessary changes. Details follow: USN-810-1 fixed vulnerabilities in NSS. This update provides the NSPR needed to use the new NSS. Original advisory details: Moxie Marlinspike discovered that NSS did not properly handle regular expressions in certificate names. A remote attacker could create a specially crafted certificate to cause a denial of service (via application crash) or execute arbitrary code as the user invoking the program. (CVE-2009-2404) Moxie Marlinspike and Dan Kaminsky independently discovered that NSS did not properly handle certificates with NULL characters in the certificate name. An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. (CVE-2009-2408) Dan Kaminsky discovered NSS would still accept certificates with MD2 hash signatures. As a result, an attacker could potentially create a malicious trusted certificate to impersonate another site. (CVE-2009-2409)

USN-810-1: NSS vulnerabilities

Referenced CVEs: 
CVE-2009-2404, CVE-2009-2408, CVE-2009-2409
Description: 
=========================================================== Ubuntu Security Notice USN-810-1 August 04, 2009 nss vulnerabilities CVE-2009-2404, CVE-2009-2408, CVE-2009-2409 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: libnss3-1d 3.12.3.1-0ubuntu0.8.04.1 Ubuntu 8.10: libnss3-1d 3.12.3.1-0ubuntu0.8.10.1 Ubuntu 9.04: libnss3-1d 3.12.3.1-0ubuntu0.9.04.1 After a standard system upgrade you need to restart any applications that use NSS, such as Firefox, to effect the necessary changes. Details follow: Moxie Marlinspike discovered that NSS did not properly handle regular expressions in certificate names. A remote attacker could create a specially crafted certificate to cause a denial of service (via application crash) or execute arbitrary code as the user invoking the program. (CVE-2009-2404) Moxie Marlinspike and Dan Kaminsky independently discovered that NSS did not properly handle certificates with NULL characters in the certificate name. An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. (CVE-2009-2408) Dan Kaminsky discovered NSS would still accept certificates with MD2 hash signatures. As a result, an attacker could potentially create a malicious trusted certificate to impersonate another site. (CVE-2009-2409)

Canonical Systems Management and Monitoring Tool Adds Dedicated Server

Canonical Systems Management and Monitoring Tool Adds Dedicated Server

‘Landscape Dedicated Server’ Now Available For Pre-Order

LONDON, August 4, 2008 – Canonical, the founder of the Ubuntu project, announced today a new architecture and installation option for its systems management and monitoring system for Ubuntu machines - enabling enterprises to have greater local control over their deployments.

Canonical’s Landscape Dedicated Server will be available to be installed on the customer's site running on their local network.

Canonical to Offer Ubuntu Desktop Support and Services

Canonical to Offer Ubuntu Desktop Support and Services

New offerings to individuals and small businesses to ease transition to fastest growing Linux desktop

London, July 31, 2009: Canonical, the founder of the Ubuntu project, announced today it has launched new support services for individuals using Ubuntu desktop – and small businesses looking for cost effective alternatives to Microsoft Windows and Apple Mac.

USN-808-1: Bind vulnerability

Referenced CVEs: 
CVE-2009-0696
Description: 
=========================================================== Ubuntu Security Notice USN-808-1 July 29, 2009 bind9 vulnerability CVE-2009-0696 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: bind9 1:9.3.2-2ubuntu1.7 Ubuntu 8.04 LTS: bind9 1:9.4.2.dfsg.P2-2ubuntu0.2 Ubuntu 8.10: bind9 1:9.5.0.dfsg.P2-1ubuntu3.2 Ubuntu 9.04: bind9 1:9.5.1.dfsg.P2-1ubuntu0.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Micha Krause discovered that Bind did not correctly validate certain dynamic DNS update packets. An unauthenticated remote attacker could send specially crafted traffic to crash the DNS server, leading to a denial of service.

USN-807-1: Linux kernel vulnerabilities

Referenced CVEs: 
CVE-2009-1389, CVE-2009-1895, CVE-2009-2287, CVE-2009-2406, CVE-2009-2407
Description: 
=========================================================== Ubuntu Security Notice USN-807-1 July 28, 2009 linux, linux-source-2.6.15 vulnerabilities CVE-2009-1389, CVE-2009-1895, CVE-2009-2287, CVE-2009-2406, CVE-2009-2407 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: linux-image-2.6.15-54-386 2.6.15-54.78 linux-image-2.6.15-54-686 2.6.15-54.78 linux-image-2.6.15-54-amd64-generic 2.6.15-54.78 linux-image-2.6.15-54-amd64-k8 2.6.15-54.78 linux-image-2.6.15-54-amd64-server 2.6.15-54.78 linux-image-2.6.15-54-amd64-xeon 2.6.15-54.78 linux-image-2.6.15-54-hppa32 2.6.15-54.78 linux-image-2.6.15-54-hppa32-smp 2.6.15-54.78 linux-image-2.6.15-54-hppa64 2.6.15-54.78 linux-image-2.6.15-54-hppa64-smp 2.6.15-54.78 linux-image-2.6.15-54-itanium 2.6.15-54.78 linux-image-2.6.15-54-itanium-smp 2.6.15-54.78 linux-image-2.6.15-54-k7 2.6.15-54.78 linux-image-2.6.15-54-mckinley 2.6.15-54.78 linux-image-2.6.15-54-mckinley-smp 2.6.15-54.78 linux-image-2.6.15-54-powerpc 2.6.15-54.78 linux-image-2.6.15-54-powerpc-smp 2.6.15-54.78 linux-image-2.6.15-54-powerpc64-smp 2.6.15-54.78 linux-image-2.6.15-54-server 2.6.15-54.78 linux-image-2.6.15-54-server-bigiron 2.6.15-54.78 linux-image-2.6.15-54-sparc64 2.6.15-54.78 linux-image-2.6.15-54-sparc64-smp 2.6.15-54.78 Ubuntu 8.04 LTS: linux-image-2.6.24-24-386 2.6.24-24.57 linux-image-2.6.24-24-generic 2.6.24-24.57 linux-image-2.6.24-24-hppa32 2.6.24-24.57 linux-image-2.6.24-24-hppa64 2.6.24-24.57 linux-image-2.6.24-24-itanium 2.6.24-24.57 linux-image-2.6.24-24-lpia 2.6.24-24.57 linux-image-2.6.24-24-lpiacompat 2.6.24-24.57 linux-image-2.6.24-24-mckinley 2.6.24-24.57 linux-image-2.6.24-24-openvz 2.6.24-24.57 linux-image-2.6.24-24-powerpc 2.6.24-24.57 linux-image-2.6.24-24-powerpc-smp 2.6.24-24.57 linux-image-2.6.24-24-powerpc64-smp 2.6.24-24.57 linux-image-2.6.24-24-rt 2.6.24-24.57 linux-image-2.6.24-24-server 2.6.24-24.57 linux-image-2.6.24-24-sparc64 2.6.24-24.57 linux-image-2.6.24-24-sparc64-smp 2.6.24-24.57 linux-image-2.6.24-24-virtual 2.6.24-24.57 linux-image-2.6.24-24-xen 2.6.24-24.57 Ubuntu 8.10: linux-image-2.6.27-14-generic 2.6.27-14.37 linux-image-2.6.27-14-server 2.6.27-14.37 linux-image-2.6.27-14-virtual 2.6.27-14.37 Ubuntu 9.04: linux-image-2.6.28-14-generic 2.6.28-14.47 linux-image-2.6.28-14-imx51 2.6.28-14.47 linux-image-2.6.28-14-iop32x 2.6.28-14.47 linux-image-2.6.28-14-ixp4xx 2.6.28-14.47 linux-image-2.6.28-14-lpia 2.6.28-14.47 linux-image-2.6.28-14-server 2.6.28-14.47 linux-image-2.6.28-14-versatile 2.6.28-14.47 linux-image-2.6.28-14-virtual 2.6.28-14.47 After a standard system upgrade you need to reboot your computer to effect the necessary changes. ATTENTION: Due to an unavoidable ABI change for Ubuntu 9.04 the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. Details follow: Michael Tokarev discovered that the RTL8169 network driver did not correctly validate buffer sizes. A remote attacker on the local network could send specially crafted traffic that would crash the system or potentially grant elevated privileges. (CVE-2009-1389) Julien Tinnes and Tavis Ormandy discovered that when executing setuid processes the kernel did not clear certain personality flags. A local attacker could exploit this to map the NULL memory page, causing other vulnerabilities to become exploitable. Ubuntu 6.06 was not affected. (CVE-2009-1895) Matt T. Yourst discovered that KVM did not correctly validate the page table root. A local attacker could exploit this to crash the system, leading to a denial of service. Ubuntu 6.06 was not affected. (CVE-2009-2287) Ramon de Carvalho Valle discovered that eCryptfs did not correctly validate certain buffer sizes. A local attacker could create specially crafted eCryptfs files to crash the system or gain elevated privileges. Ubuntu 6.06 was not affected. (CVE-2009-2406, CVE-2009-2407)
Syndicate content