Security announcements
USN-811-1: Firefox and Xulrunner vulnerability
Submitted by JamesStrandboge on Wed, 2009-08-05 02:33Referenced CVEs:
CVE-2009-2654
Description:
===========================================================
Ubuntu Security Notice USN-811-1 August 05, 2009
firefox-3.0, xulrunner-1.9 vulnerability
CVE-2009-2654
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.04 LTS:
firefox-3.0 3.0.13+nobinonly-0ubuntu0.8.04.1
xulrunner-1.9 1.9.0.13+nobinonly-0ubuntu0.8.04.1
Ubuntu 8.10:
abrowser 3.0.13+nobinonly-0ubuntu0.8.10.1
firefox-3.0 3.0.13+nobinonly-0ubuntu0.8.10.1
xulrunner-1.9 1.9.0.13+nobinonly-0ubuntu0.8.10.1
Ubuntu 9.04:
abrowser 3.0.13+nobinonly-0ubuntu0.9.04.1
firefox-3.0 3.0.13+nobinonly-0ubuntu0.9.04.1
xulrunner-1.9 1.9.0.13+nobinonly-0ubuntu0.9.04.1
After a standard system upgrade you need to restart Firefox and any
applications that use xulrunner, such as Epiphany, to effect the necessary
changes.
Details follow:
Juan Pablo Lopez Yacubian discovered that Firefox did not properly display
invalid URLs. If a user were tricked into accessing a malicious website, an
attacker could exploit this to spoof the location bar, such as in a
phishing attack. Furthermore, if the malicious website had a valid SSL
certificate, Firefox would display the spoofed page as trusted.
USN-810-2: NSPR update
Submitted by JamesStrandboge on Tue, 2009-08-04 22:00Description:
===========================================================
Ubuntu Security Notice USN-810-2 August 04, 2009
nspr update
https://launchpad.net/bugs/387745
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.04 LTS:
libnspr4-0d 4.7.5-0ubuntu0.8.04.1
Ubuntu 8.10:
libnspr4-0d 4.7.5-0ubuntu0.8.10.1
Ubuntu 9.04:
libnspr4-0d 4.7.5-0ubuntu0.9.04.1
After a standard system upgrade you need to restart any applications that
use NSPR, such as Firefox, to effect the necessary changes.
Details follow:
USN-810-1 fixed vulnerabilities in NSS. This update provides the NSPR
needed to use the new NSS.
Original advisory details:
Moxie Marlinspike discovered that NSS did not properly handle regular
expressions in certificate names. A remote attacker could create a
specially crafted certificate to cause a denial of service (via application
crash) or execute arbitrary code as the user invoking the program.
(CVE-2009-2404)
Moxie Marlinspike and Dan Kaminsky independently discovered that NSS did
not properly handle certificates with NULL characters in the certificate
name. An attacker could exploit this to perform a man in the middle attack
to view sensitive information or alter encrypted communications.
(CVE-2009-2408)
Dan Kaminsky discovered NSS would still accept certificates with MD2 hash
signatures. As a result, an attacker could potentially create a malicious
trusted certificate to impersonate another site. (CVE-2009-2409)
USN-810-1: NSS vulnerabilities
Submitted by JamesStrandboge on Tue, 2009-08-04 21:22Referenced CVEs:
CVE-2009-2404, CVE-2009-2408, CVE-2009-2409
Description:
===========================================================
Ubuntu Security Notice USN-810-1 August 04, 2009
nss vulnerabilities
CVE-2009-2404, CVE-2009-2408, CVE-2009-2409
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.04 LTS:
libnss3-1d 3.12.3.1-0ubuntu0.8.04.1
Ubuntu 8.10:
libnss3-1d 3.12.3.1-0ubuntu0.8.10.1
Ubuntu 9.04:
libnss3-1d 3.12.3.1-0ubuntu0.9.04.1
After a standard system upgrade you need to restart any applications that
use NSS, such as Firefox, to effect the necessary changes.
Details follow:
Moxie Marlinspike discovered that NSS did not properly handle regular
expressions in certificate names. A remote attacker could create a
specially crafted certificate to cause a denial of service (via application
crash) or execute arbitrary code as the user invoking the program.
(CVE-2009-2404)
Moxie Marlinspike and Dan Kaminsky independently discovered that NSS did
not properly handle certificates with NULL characters in the certificate
name. An attacker could exploit this to perform a man in the middle attack
to view sensitive information or alter encrypted communications.
(CVE-2009-2408)
Dan Kaminsky discovered NSS would still accept certificates with MD2 hash
signatures. As a result, an attacker could potentially create a malicious
trusted certificate to impersonate another site. (CVE-2009-2409)
USN-808-1: Bind vulnerability
Submitted by KeesCook on Wed, 2009-07-29 06:38Referenced CVEs:
CVE-2009-0696
Description:
===========================================================
Ubuntu Security Notice USN-808-1 July 29, 2009
bind9 vulnerability
CVE-2009-0696
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
bind9 1:9.3.2-2ubuntu1.7
Ubuntu 8.04 LTS:
bind9 1:9.4.2.dfsg.P2-2ubuntu0.2
Ubuntu 8.10:
bind9 1:9.5.0.dfsg.P2-1ubuntu3.2
Ubuntu 9.04:
bind9 1:9.5.1.dfsg.P2-1ubuntu0.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Micha Krause discovered that Bind did not correctly validate certain
dynamic DNS update packets. An unauthenticated remote attacker could
send specially crafted traffic to crash the DNS server, leading to a
denial of service.
USN-807-1: Linux kernel vulnerabilities
Submitted by KeesCook on Tue, 2009-07-28 20:36Referenced CVEs:
CVE-2009-1389, CVE-2009-1895, CVE-2009-2287, CVE-2009-2406, CVE-2009-2407
Description:
===========================================================
Ubuntu Security Notice USN-807-1 July 28, 2009
linux, linux-source-2.6.15 vulnerabilities
CVE-2009-1389, CVE-2009-1895, CVE-2009-2287, CVE-2009-2406,
CVE-2009-2407
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
linux-image-2.6.15-54-386 2.6.15-54.78
linux-image-2.6.15-54-686 2.6.15-54.78
linux-image-2.6.15-54-amd64-generic 2.6.15-54.78
linux-image-2.6.15-54-amd64-k8 2.6.15-54.78
linux-image-2.6.15-54-amd64-server 2.6.15-54.78
linux-image-2.6.15-54-amd64-xeon 2.6.15-54.78
linux-image-2.6.15-54-hppa32 2.6.15-54.78
linux-image-2.6.15-54-hppa32-smp 2.6.15-54.78
linux-image-2.6.15-54-hppa64 2.6.15-54.78
linux-image-2.6.15-54-hppa64-smp 2.6.15-54.78
linux-image-2.6.15-54-itanium 2.6.15-54.78
linux-image-2.6.15-54-itanium-smp 2.6.15-54.78
linux-image-2.6.15-54-k7 2.6.15-54.78
linux-image-2.6.15-54-mckinley 2.6.15-54.78
linux-image-2.6.15-54-mckinley-smp 2.6.15-54.78
linux-image-2.6.15-54-powerpc 2.6.15-54.78
linux-image-2.6.15-54-powerpc-smp 2.6.15-54.78
linux-image-2.6.15-54-powerpc64-smp 2.6.15-54.78
linux-image-2.6.15-54-server 2.6.15-54.78
linux-image-2.6.15-54-server-bigiron 2.6.15-54.78
linux-image-2.6.15-54-sparc64 2.6.15-54.78
linux-image-2.6.15-54-sparc64-smp 2.6.15-54.78
Ubuntu 8.04 LTS:
linux-image-2.6.24-24-386 2.6.24-24.57
linux-image-2.6.24-24-generic 2.6.24-24.57
linux-image-2.6.24-24-hppa32 2.6.24-24.57
linux-image-2.6.24-24-hppa64 2.6.24-24.57
linux-image-2.6.24-24-itanium 2.6.24-24.57
linux-image-2.6.24-24-lpia 2.6.24-24.57
linux-image-2.6.24-24-lpiacompat 2.6.24-24.57
linux-image-2.6.24-24-mckinley 2.6.24-24.57
linux-image-2.6.24-24-openvz 2.6.24-24.57
linux-image-2.6.24-24-powerpc 2.6.24-24.57
linux-image-2.6.24-24-powerpc-smp 2.6.24-24.57
linux-image-2.6.24-24-powerpc64-smp 2.6.24-24.57
linux-image-2.6.24-24-rt 2.6.24-24.57
linux-image-2.6.24-24-server 2.6.24-24.57
linux-image-2.6.24-24-sparc64 2.6.24-24.57
linux-image-2.6.24-24-sparc64-smp 2.6.24-24.57
linux-image-2.6.24-24-virtual 2.6.24-24.57
linux-image-2.6.24-24-xen 2.6.24-24.57
Ubuntu 8.10:
linux-image-2.6.27-14-generic 2.6.27-14.37
linux-image-2.6.27-14-server 2.6.27-14.37
linux-image-2.6.27-14-virtual 2.6.27-14.37
Ubuntu 9.04:
linux-image-2.6.28-14-generic 2.6.28-14.47
linux-image-2.6.28-14-imx51 2.6.28-14.47
linux-image-2.6.28-14-iop32x 2.6.28-14.47
linux-image-2.6.28-14-ixp4xx 2.6.28-14.47
linux-image-2.6.28-14-lpia 2.6.28-14.47
linux-image-2.6.28-14-server 2.6.28-14.47
linux-image-2.6.28-14-versatile 2.6.28-14.47
linux-image-2.6.28-14-virtual 2.6.28-14.47
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
ATTENTION: Due to an unavoidable ABI change for Ubuntu 9.04 the kernel
updates have been given a new version number, which requires you to
recompile and reinstall all third party kernel modules you might have
installed. If you use linux-restricted-modules, you have to update
that package as well to get modules which work with the new kernel
version. Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-server, linux-powerpc), a standard system
upgrade will automatically perform this as well.
Details follow:
Michael Tokarev discovered that the RTL8169 network driver did not
correctly validate buffer sizes. A remote attacker on the local network
could send specially crafted traffic that would crash the system or
potentially grant elevated privileges. (CVE-2009-1389)
Julien Tinnes and Tavis Ormandy discovered that when executing setuid
processes the kernel did not clear certain personality flags. A local
attacker could exploit this to map the NULL memory page, causing other
vulnerabilities to become exploitable. Ubuntu 6.06 was not affected.
(CVE-2009-1895)
Matt T. Yourst discovered that KVM did not correctly validate the
page table root. A local attacker could exploit this to crash the
system, leading to a denial of service. Ubuntu 6.06 was not affected.
(CVE-2009-2287)
Ramon de Carvalho Valle discovered that eCryptfs did not correctly
validate certain buffer sizes. A local attacker could create specially
crafted eCryptfs files to crash the system or gain elevated privileges.
Ubuntu 6.06 was not affected. (CVE-2009-2406, CVE-2009-2407)
USN-806-1: Python vulnerabilities
Submitted by MarcDeslauriers on Thu, 2009-07-23 19:32Referenced CVEs:
CVE-2008-4864, CVE-2008-5031
Description:
===========================================================
Ubuntu Security Notice USN-806-1 July 23, 2009
python2.4, python2.5 vulnerabilities
CVE-2008-4864, CVE-2008-5031
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
python2.4 2.4.3-0ubuntu6.3
python2.4-minimal 2.4.3-0ubuntu6.3
Ubuntu 8.04 LTS:
python2.4 2.4.5-1ubuntu4.2
python2.4-minimal 2.4.5-1ubuntu4.2
python2.5 2.5.2-2ubuntu6
python2.5-minimal 2.5.2-2ubuntu6
Ubuntu 8.10:
python2.4 2.4.5-5ubuntu1.1
python2.4-minimal 2.4.5-5ubuntu1.1
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Details follow:
It was discovered that Python incorrectly handled certain arguments in the
imageop module. If an attacker were able to pass specially crafted
arguments through the crop function, they could execute arbitrary code with
user privileges. For Python 2.5, this issue only affected Ubuntu 8.04 LTS.
(CVE-2008-4864)
Multiple integer overflows were discovered in Python's stringobject and
unicodeobject expandtabs method. If an attacker were able to exploit these
flaws they could execute arbitrary code with user privileges or cause
Python applications to crash, leading to a denial of service.
(CVE-2008-5031)
USN-798-1: Firefox and Xulrunner vulnerabilities
Submitted by JamesStrandboge on Wed, 2009-07-22 15:40Referenced CVEs:
CVE-2009-2462, CVE-2009-2463, CVE-2009-2464, CVE-2009-2465, CVE-2009-2466, CVE-2009-2467, CVE-2009-2469, CVE-2009-2472
Description:
===========================================================
Ubuntu Security Notice USN-798-1 July 22, 2009
firefox-3.0, xulrunner-1.9 vulnerabilities
CVE-2009-2462, CVE-2009-2463, CVE-2009-2464, CVE-2009-2465,
CVE-2009-2466, CVE-2009-2467, CVE-2009-2469, CVE-2009-2472
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.04 LTS:
firefox-3.0 3.0.12+build1+nobinonly-0ubuntu0.8.04.1
xulrunner-1.9 1.9.0.12+build1+nobinonly-0ubuntu0.8.04.1
Ubuntu 8.10:
abrowser 3.0.12+build1+nobinonly-0ubuntu0.8.10.1
firefox-3.0 3.0.12+build1+nobinonly-0ubuntu0.8.10.1
xulrunner-1.9 1.9.0.12+build1+nobinonly-0ubuntu0.8.10.2
Ubuntu 9.04:
abrowser 3.0.12+build1+nobinonly-0ubuntu0.9.04.1
firefox-3.0 3.0.12+build1+nobinonly-0ubuntu0.9.04.1
xulrunner-1.9 1.9.0.12+build1+nobinonly-0ubuntu0.9.04.1
After a standard system upgrade you need to restart Firefox and any
applications that use xulrunner, such as Epiphany, to effect the necessary
changes.
Details follow:
Several flaws were discovered in the Firefox browser and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-2462,
CVE-2009-2463, CVE-2009-2464, CVE-2009-2465, CVE-2009-2466, CVE-2009-2469)
Attila Suszter discovered a flaw in the way Firefox processed Flash content.
If a user were tricked into viewing and navigating within a specially
crafted Flash object, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2009-2467)
It was discovered that Firefox did not properly handle some SVG content. An
attacker could exploit this to cause a denial of service or possibly
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2009-2469)
A flaw was discovered in the JavaScript engine. If a user were tricked into
viewing a malicious website, an attacker could exploit this perform
cross-site scripting attacks. (CVE-2009-2472)
USN-805-1: Ruby vulnerabilities
Submitted by MarcDeslauriers on Mon, 2009-07-20 14:51Referenced CVEs:
CVE-2009-0642, CVE-2009-1904
Description:
===========================================================
Ubuntu Security Notice USN-805-1 July 20, 2009
ruby1.8, ruby1.9 vulnerabilities
CVE-2009-0642, CVE-2009-1904
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libruby1.8 1.8.4-1ubuntu1.7
ruby1.8 1.8.4-1ubuntu1.7
Ubuntu 8.04 LTS:
libruby1.8 1.8.6.111-2ubuntu1.3
ruby1.8 1.8.6.111-2ubuntu1.3
Ubuntu 8.10:
libruby1.8 1.8.7.72-1ubuntu0.2
libruby1.9 1.9.0.2-7ubuntu1.2
ruby1.8 1.8.7.72-1ubuntu0.2
ruby1.9 1.9.0.2-7ubuntu1.2
Ubuntu 9.04:
libruby1.8 1.8.7.72-3ubuntu0.1
libruby1.9 1.9.0.2-9ubuntu1.1
ruby1.8 1.8.7.72-3ubuntu0.1
ruby1.9 1.9.0.2-9ubuntu1.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that Ruby did not properly validate certificates. An
attacker could exploit this and present invalid or revoked X.509
certificates. (CVE-2009-0642)
It was discovered that Ruby did not properly handle string arguments that
represent large numbers. An attacker could exploit this and cause a denial
of service. (CVE-2009-1904)
USN-804-1: PulseAudio vulnerability
Submitted by KeesCook on Thu, 2009-07-16 18:23Referenced CVEs:
CVE-2009-1894
Description:
===========================================================
Ubuntu Security Notice USN-804-1 July 16, 2009
pulseaudio vulnerability
CVE-2009-1894
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.04 LTS:
pulseaudio 0.9.10-1ubuntu1.1
Ubuntu 8.10:
pulseaudio 0.9.10-2ubuntu9.4
Ubuntu 9.04:
pulseaudio 1:0.9.14-0ubuntu20.2
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Tavis Ormandy, Julien Tinnes, and Yorick Koster discovered that
PulseAudio did not safely re-execute itself. A local attacker could
exploit this to gain root privileges.
USN-803-1: dhcp vulnerability
Submitted by JamesStrandboge on Tue, 2009-07-14 19:44Referenced CVEs:
CVE-2009-0692
Description:
===========================================================
Ubuntu Security Notice USN-803-1 July 14, 2009
dhcp3 vulnerability
CVE-2009-0692
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
dhcp3-client 3.0.3-6ubuntu7.1
dhcp3-client-udeb 3.0.3-6ubuntu7.1
Ubuntu 8.04 LTS:
dhcp3-client 3.0.6.dfsg-1ubuntu9.1
dhcp3-client-udeb 3.0.6.dfsg-1ubuntu9.1
Ubuntu 8.10:
dhcp3-client 3.1.1-1ubuntu2.1
dhcp3-client-udeb 3.1.1-1ubuntu2.1
Ubuntu 9.04:
dhcp3-client 3.1.1-5ubuntu8.1
dhcp3-client-udeb 3.1.1-5ubuntu8.1
After a standard system upgrade you need to restart any DHCP network
connections utilizing dhclient3 to effect the necessary changes.
Details follow:
It was discovered that the DHCP client as included in dhcp3 did not verify
the length of certain option fields when processing a response from an IPv4
dhcp server. If a user running Ubuntu 6.06 LTS or 8.04 LTS connected to a
malicious dhcp server, a remote attacker could cause a denial of service or
execute arbitrary code as the user invoking the program, typically the
'dhcp' user. For users running Ubuntu 8.10 or 9.04, a remote attacker
should only be able to cause a denial of service in the DHCP client. In
Ubuntu 9.04, attackers would also be isolated by the AppArmor dhclient3
profile.


