Security announcements

USN-811-1: Firefox and Xulrunner vulnerability

Referenced CVEs: 
CVE-2009-2654
Description: 
=========================================================== Ubuntu Security Notice USN-811-1 August 05, 2009 firefox-3.0, xulrunner-1.9 vulnerability CVE-2009-2654 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: firefox-3.0 3.0.13+nobinonly-0ubuntu0.8.04.1 xulrunner-1.9 1.9.0.13+nobinonly-0ubuntu0.8.04.1 Ubuntu 8.10: abrowser 3.0.13+nobinonly-0ubuntu0.8.10.1 firefox-3.0 3.0.13+nobinonly-0ubuntu0.8.10.1 xulrunner-1.9 1.9.0.13+nobinonly-0ubuntu0.8.10.1 Ubuntu 9.04: abrowser 3.0.13+nobinonly-0ubuntu0.9.04.1 firefox-3.0 3.0.13+nobinonly-0ubuntu0.9.04.1 xulrunner-1.9 1.9.0.13+nobinonly-0ubuntu0.9.04.1 After a standard system upgrade you need to restart Firefox and any applications that use xulrunner, such as Epiphany, to effect the necessary changes. Details follow: Juan Pablo Lopez Yacubian discovered that Firefox did not properly display invalid URLs. If a user were tricked into accessing a malicious website, an attacker could exploit this to spoof the location bar, such as in a phishing attack. Furthermore, if the malicious website had a valid SSL certificate, Firefox would display the spoofed page as trusted.

USN-810-2: NSPR update

Description: 
=========================================================== Ubuntu Security Notice USN-810-2 August 04, 2009 nspr update https://launchpad.net/bugs/387745 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: libnspr4-0d 4.7.5-0ubuntu0.8.04.1 Ubuntu 8.10: libnspr4-0d 4.7.5-0ubuntu0.8.10.1 Ubuntu 9.04: libnspr4-0d 4.7.5-0ubuntu0.9.04.1 After a standard system upgrade you need to restart any applications that use NSPR, such as Firefox, to effect the necessary changes. Details follow: USN-810-1 fixed vulnerabilities in NSS. This update provides the NSPR needed to use the new NSS. Original advisory details: Moxie Marlinspike discovered that NSS did not properly handle regular expressions in certificate names. A remote attacker could create a specially crafted certificate to cause a denial of service (via application crash) or execute arbitrary code as the user invoking the program. (CVE-2009-2404) Moxie Marlinspike and Dan Kaminsky independently discovered that NSS did not properly handle certificates with NULL characters in the certificate name. An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. (CVE-2009-2408) Dan Kaminsky discovered NSS would still accept certificates with MD2 hash signatures. As a result, an attacker could potentially create a malicious trusted certificate to impersonate another site. (CVE-2009-2409)

USN-810-1: NSS vulnerabilities

Referenced CVEs: 
CVE-2009-2404, CVE-2009-2408, CVE-2009-2409
Description: 
=========================================================== Ubuntu Security Notice USN-810-1 August 04, 2009 nss vulnerabilities CVE-2009-2404, CVE-2009-2408, CVE-2009-2409 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: libnss3-1d 3.12.3.1-0ubuntu0.8.04.1 Ubuntu 8.10: libnss3-1d 3.12.3.1-0ubuntu0.8.10.1 Ubuntu 9.04: libnss3-1d 3.12.3.1-0ubuntu0.9.04.1 After a standard system upgrade you need to restart any applications that use NSS, such as Firefox, to effect the necessary changes. Details follow: Moxie Marlinspike discovered that NSS did not properly handle regular expressions in certificate names. A remote attacker could create a specially crafted certificate to cause a denial of service (via application crash) or execute arbitrary code as the user invoking the program. (CVE-2009-2404) Moxie Marlinspike and Dan Kaminsky independently discovered that NSS did not properly handle certificates with NULL characters in the certificate name. An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. (CVE-2009-2408) Dan Kaminsky discovered NSS would still accept certificates with MD2 hash signatures. As a result, an attacker could potentially create a malicious trusted certificate to impersonate another site. (CVE-2009-2409)

USN-808-1: Bind vulnerability

Referenced CVEs: 
CVE-2009-0696
Description: 
=========================================================== Ubuntu Security Notice USN-808-1 July 29, 2009 bind9 vulnerability CVE-2009-0696 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: bind9 1:9.3.2-2ubuntu1.7 Ubuntu 8.04 LTS: bind9 1:9.4.2.dfsg.P2-2ubuntu0.2 Ubuntu 8.10: bind9 1:9.5.0.dfsg.P2-1ubuntu3.2 Ubuntu 9.04: bind9 1:9.5.1.dfsg.P2-1ubuntu0.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Micha Krause discovered that Bind did not correctly validate certain dynamic DNS update packets. An unauthenticated remote attacker could send specially crafted traffic to crash the DNS server, leading to a denial of service.

USN-807-1: Linux kernel vulnerabilities

Referenced CVEs: 
CVE-2009-1389, CVE-2009-1895, CVE-2009-2287, CVE-2009-2406, CVE-2009-2407
Description: 
=========================================================== Ubuntu Security Notice USN-807-1 July 28, 2009 linux, linux-source-2.6.15 vulnerabilities CVE-2009-1389, CVE-2009-1895, CVE-2009-2287, CVE-2009-2406, CVE-2009-2407 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: linux-image-2.6.15-54-386 2.6.15-54.78 linux-image-2.6.15-54-686 2.6.15-54.78 linux-image-2.6.15-54-amd64-generic 2.6.15-54.78 linux-image-2.6.15-54-amd64-k8 2.6.15-54.78 linux-image-2.6.15-54-amd64-server 2.6.15-54.78 linux-image-2.6.15-54-amd64-xeon 2.6.15-54.78 linux-image-2.6.15-54-hppa32 2.6.15-54.78 linux-image-2.6.15-54-hppa32-smp 2.6.15-54.78 linux-image-2.6.15-54-hppa64 2.6.15-54.78 linux-image-2.6.15-54-hppa64-smp 2.6.15-54.78 linux-image-2.6.15-54-itanium 2.6.15-54.78 linux-image-2.6.15-54-itanium-smp 2.6.15-54.78 linux-image-2.6.15-54-k7 2.6.15-54.78 linux-image-2.6.15-54-mckinley 2.6.15-54.78 linux-image-2.6.15-54-mckinley-smp 2.6.15-54.78 linux-image-2.6.15-54-powerpc 2.6.15-54.78 linux-image-2.6.15-54-powerpc-smp 2.6.15-54.78 linux-image-2.6.15-54-powerpc64-smp 2.6.15-54.78 linux-image-2.6.15-54-server 2.6.15-54.78 linux-image-2.6.15-54-server-bigiron 2.6.15-54.78 linux-image-2.6.15-54-sparc64 2.6.15-54.78 linux-image-2.6.15-54-sparc64-smp 2.6.15-54.78 Ubuntu 8.04 LTS: linux-image-2.6.24-24-386 2.6.24-24.57 linux-image-2.6.24-24-generic 2.6.24-24.57 linux-image-2.6.24-24-hppa32 2.6.24-24.57 linux-image-2.6.24-24-hppa64 2.6.24-24.57 linux-image-2.6.24-24-itanium 2.6.24-24.57 linux-image-2.6.24-24-lpia 2.6.24-24.57 linux-image-2.6.24-24-lpiacompat 2.6.24-24.57 linux-image-2.6.24-24-mckinley 2.6.24-24.57 linux-image-2.6.24-24-openvz 2.6.24-24.57 linux-image-2.6.24-24-powerpc 2.6.24-24.57 linux-image-2.6.24-24-powerpc-smp 2.6.24-24.57 linux-image-2.6.24-24-powerpc64-smp 2.6.24-24.57 linux-image-2.6.24-24-rt 2.6.24-24.57 linux-image-2.6.24-24-server 2.6.24-24.57 linux-image-2.6.24-24-sparc64 2.6.24-24.57 linux-image-2.6.24-24-sparc64-smp 2.6.24-24.57 linux-image-2.6.24-24-virtual 2.6.24-24.57 linux-image-2.6.24-24-xen 2.6.24-24.57 Ubuntu 8.10: linux-image-2.6.27-14-generic 2.6.27-14.37 linux-image-2.6.27-14-server 2.6.27-14.37 linux-image-2.6.27-14-virtual 2.6.27-14.37 Ubuntu 9.04: linux-image-2.6.28-14-generic 2.6.28-14.47 linux-image-2.6.28-14-imx51 2.6.28-14.47 linux-image-2.6.28-14-iop32x 2.6.28-14.47 linux-image-2.6.28-14-ixp4xx 2.6.28-14.47 linux-image-2.6.28-14-lpia 2.6.28-14.47 linux-image-2.6.28-14-server 2.6.28-14.47 linux-image-2.6.28-14-versatile 2.6.28-14.47 linux-image-2.6.28-14-virtual 2.6.28-14.47 After a standard system upgrade you need to reboot your computer to effect the necessary changes. ATTENTION: Due to an unavoidable ABI change for Ubuntu 9.04 the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. Details follow: Michael Tokarev discovered that the RTL8169 network driver did not correctly validate buffer sizes. A remote attacker on the local network could send specially crafted traffic that would crash the system or potentially grant elevated privileges. (CVE-2009-1389) Julien Tinnes and Tavis Ormandy discovered that when executing setuid processes the kernel did not clear certain personality flags. A local attacker could exploit this to map the NULL memory page, causing other vulnerabilities to become exploitable. Ubuntu 6.06 was not affected. (CVE-2009-1895) Matt T. Yourst discovered that KVM did not correctly validate the page table root. A local attacker could exploit this to crash the system, leading to a denial of service. Ubuntu 6.06 was not affected. (CVE-2009-2287) Ramon de Carvalho Valle discovered that eCryptfs did not correctly validate certain buffer sizes. A local attacker could create specially crafted eCryptfs files to crash the system or gain elevated privileges. Ubuntu 6.06 was not affected. (CVE-2009-2406, CVE-2009-2407)

USN-806-1: Python vulnerabilities

Referenced CVEs: 
CVE-2008-4864, CVE-2008-5031
Description: 
=========================================================== Ubuntu Security Notice USN-806-1 July 23, 2009 python2.4, python2.5 vulnerabilities CVE-2008-4864, CVE-2008-5031 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: python2.4 2.4.3-0ubuntu6.3 python2.4-minimal 2.4.3-0ubuntu6.3 Ubuntu 8.04 LTS: python2.4 2.4.5-1ubuntu4.2 python2.4-minimal 2.4.5-1ubuntu4.2 python2.5 2.5.2-2ubuntu6 python2.5-minimal 2.5.2-2ubuntu6 Ubuntu 8.10: python2.4 2.4.5-5ubuntu1.1 python2.4-minimal 2.4.5-5ubuntu1.1 After a standard system upgrade you need to reboot your computer to effect the necessary changes. Details follow: It was discovered that Python incorrectly handled certain arguments in the imageop module. If an attacker were able to pass specially crafted arguments through the crop function, they could execute arbitrary code with user privileges. For Python 2.5, this issue only affected Ubuntu 8.04 LTS. (CVE-2008-4864) Multiple integer overflows were discovered in Python's stringobject and unicodeobject expandtabs method. If an attacker were able to exploit these flaws they could execute arbitrary code with user privileges or cause Python applications to crash, leading to a denial of service. (CVE-2008-5031)

USN-798-1: Firefox and Xulrunner vulnerabilities

Referenced CVEs: 
CVE-2009-2462, CVE-2009-2463, CVE-2009-2464, CVE-2009-2465, CVE-2009-2466, CVE-2009-2467, CVE-2009-2469, CVE-2009-2472
Description: 
=========================================================== Ubuntu Security Notice USN-798-1 July 22, 2009 firefox-3.0, xulrunner-1.9 vulnerabilities CVE-2009-2462, CVE-2009-2463, CVE-2009-2464, CVE-2009-2465, CVE-2009-2466, CVE-2009-2467, CVE-2009-2469, CVE-2009-2472 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: firefox-3.0 3.0.12+build1+nobinonly-0ubuntu0.8.04.1 xulrunner-1.9 1.9.0.12+build1+nobinonly-0ubuntu0.8.04.1 Ubuntu 8.10: abrowser 3.0.12+build1+nobinonly-0ubuntu0.8.10.1 firefox-3.0 3.0.12+build1+nobinonly-0ubuntu0.8.10.1 xulrunner-1.9 1.9.0.12+build1+nobinonly-0ubuntu0.8.10.2 Ubuntu 9.04: abrowser 3.0.12+build1+nobinonly-0ubuntu0.9.04.1 firefox-3.0 3.0.12+build1+nobinonly-0ubuntu0.9.04.1 xulrunner-1.9 1.9.0.12+build1+nobinonly-0ubuntu0.9.04.1 After a standard system upgrade you need to restart Firefox and any applications that use xulrunner, such as Epiphany, to effect the necessary changes. Details follow: Several flaws were discovered in the Firefox browser and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2009-2462, CVE-2009-2463, CVE-2009-2464, CVE-2009-2465, CVE-2009-2466, CVE-2009-2469) Attila Suszter discovered a flaw in the way Firefox processed Flash content. If a user were tricked into viewing and navigating within a specially crafted Flash object, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2009-2467) It was discovered that Firefox did not properly handle some SVG content. An attacker could exploit this to cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2009-2469) A flaw was discovered in the JavaScript engine. If a user were tricked into viewing a malicious website, an attacker could exploit this perform cross-site scripting attacks. (CVE-2009-2472)

USN-805-1: Ruby vulnerabilities

Referenced CVEs: 
CVE-2009-0642, CVE-2009-1904
Description: 
=========================================================== Ubuntu Security Notice USN-805-1 July 20, 2009 ruby1.8, ruby1.9 vulnerabilities CVE-2009-0642, CVE-2009-1904 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libruby1.8 1.8.4-1ubuntu1.7 ruby1.8 1.8.4-1ubuntu1.7 Ubuntu 8.04 LTS: libruby1.8 1.8.6.111-2ubuntu1.3 ruby1.8 1.8.6.111-2ubuntu1.3 Ubuntu 8.10: libruby1.8 1.8.7.72-1ubuntu0.2 libruby1.9 1.9.0.2-7ubuntu1.2 ruby1.8 1.8.7.72-1ubuntu0.2 ruby1.9 1.9.0.2-7ubuntu1.2 Ubuntu 9.04: libruby1.8 1.8.7.72-3ubuntu0.1 libruby1.9 1.9.0.2-9ubuntu1.1 ruby1.8 1.8.7.72-3ubuntu0.1 ruby1.9 1.9.0.2-9ubuntu1.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that Ruby did not properly validate certificates. An attacker could exploit this and present invalid or revoked X.509 certificates. (CVE-2009-0642) It was discovered that Ruby did not properly handle string arguments that represent large numbers. An attacker could exploit this and cause a denial of service. (CVE-2009-1904)

USN-804-1: PulseAudio vulnerability

Referenced CVEs: 
CVE-2009-1894
Description: 
=========================================================== Ubuntu Security Notice USN-804-1 July 16, 2009 pulseaudio vulnerability CVE-2009-1894 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: pulseaudio 0.9.10-1ubuntu1.1 Ubuntu 8.10: pulseaudio 0.9.10-2ubuntu9.4 Ubuntu 9.04: pulseaudio 1:0.9.14-0ubuntu20.2 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Tavis Ormandy, Julien Tinnes, and Yorick Koster discovered that PulseAudio did not safely re-execute itself. A local attacker could exploit this to gain root privileges.

USN-803-1: dhcp vulnerability

Referenced CVEs: 
CVE-2009-0692
Description: 
=========================================================== Ubuntu Security Notice USN-803-1 July 14, 2009 dhcp3 vulnerability CVE-2009-0692 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: dhcp3-client 3.0.3-6ubuntu7.1 dhcp3-client-udeb 3.0.3-6ubuntu7.1 Ubuntu 8.04 LTS: dhcp3-client 3.0.6.dfsg-1ubuntu9.1 dhcp3-client-udeb 3.0.6.dfsg-1ubuntu9.1 Ubuntu 8.10: dhcp3-client 3.1.1-1ubuntu2.1 dhcp3-client-udeb 3.1.1-1ubuntu2.1 Ubuntu 9.04: dhcp3-client 3.1.1-5ubuntu8.1 dhcp3-client-udeb 3.1.1-5ubuntu8.1 After a standard system upgrade you need to restart any DHCP network connections utilizing dhclient3 to effect the necessary changes. Details follow: It was discovered that the DHCP client as included in dhcp3 did not verify the length of certain option fields when processing a response from an IPv4 dhcp server. If a user running Ubuntu 6.06 LTS or 8.04 LTS connected to a malicious dhcp server, a remote attacker could cause a denial of service or execute arbitrary code as the user invoking the program, typically the 'dhcp' user. For users running Ubuntu 8.10 or 9.04, a remote attacker should only be able to cause a denial of service in the DHCP client. In Ubuntu 9.04, attackers would also be isolated by the AppArmor dhclient3 profile.
Syndicate content