Security announcements
USN-802-1: Apache vulnerabilities
Submitted by MarcDeslauriers on Mon, 2009-07-13 19:37Referenced CVEs:
CVE-2009-1890, CVE-2009-1891
Description:
===========================================================
Ubuntu Security Notice USN-802-1 July 13, 2009
apache2 vulnerabilities
CVE-2009-1890, CVE-2009-1891
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
apache2-common 2.0.55-4ubuntu2.6
apache2-mpm-perchild 2.0.55-4ubuntu2.6
apache2-mpm-prefork 2.0.55-4ubuntu2.6
apache2-mpm-worker 2.0.55-4ubuntu2.6
libapr0 2.0.55-4ubuntu2.6
Ubuntu 8.04 LTS:
apache2-mpm-event 2.2.8-1ubuntu0.10
apache2-mpm-perchild 2.2.8-1ubuntu0.10
apache2-mpm-prefork 2.2.8-1ubuntu0.10
apache2-mpm-worker 2.2.8-1ubuntu0.10
apache2.2-common 2.2.8-1ubuntu0.10
Ubuntu 8.10:
apache2-mpm-event 2.2.9-7ubuntu3.2
apache2-mpm-prefork 2.2.9-7ubuntu3.2
apache2-mpm-worker 2.2.9-7ubuntu3.2
apache2.2-common 2.2.9-7ubuntu3.2
Ubuntu 9.04:
apache2-mpm-event 2.2.11-2ubuntu2.2
apache2-mpm-prefork 2.2.11-2ubuntu2.2
apache2-mpm-worker 2.2.11-2ubuntu2.2
apache2.2-common 2.2.11-2ubuntu2.2
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that mod_proxy_http did not properly handle a large
amount of streamed data when used as a reverse proxy. A remote attacker
could exploit this and cause a denial of service via memory resource
consumption. This issue affected Ubuntu 8.04 LTS, 8.10 and 9.04.
(CVE-2009-1890)
It was discovered that mod_deflate did not abort compressing large files
when the connection was closed. A remote attacker could exploit this and
cause a denial of service via CPU resource consumption. (CVE-2009-1891)
USN-801-1: tiff vulnerability
Submitted by MarcDeslauriers on Mon, 2009-07-13 19:36Referenced CVEs:
CVE-2009-2347
Description:
===========================================================
Ubuntu Security Notice USN-801-1 July 13, 2009
tiff vulnerability
CVE-2009-2347
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libtiff4 3.7.4-1ubuntu3.6
Ubuntu 8.04 LTS:
libtiff4 3.8.2-7ubuntu3.4
Ubuntu 8.10:
libtiff4 3.8.2-11ubuntu0.8.10.3
Ubuntu 9.04:
libtiff4 3.8.2-11ubuntu0.9.04.3
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Tielei Wang and Tom Lane discovered that the TIFF library did not correctly
handle certain malformed TIFF images. If a user or automated system were
tricked into processing a malicious image, an attacker could execute
arbitrary code with the privileges of the user invoking the program.
USN-799-1: D-Bus vulnerability
Submitted by MarcDeslauriers on Mon, 2009-07-13 19:35Referenced CVEs:
CVE-2009-1189
Description:
===========================================================
Ubuntu Security Notice USN-799-1 July 13, 2009
dbus vulnerability
CVE-2009-1189
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libdbus-1-2 0.60-6ubuntu8.4
Ubuntu 8.04 LTS:
libdbus-1-3 1.1.20-1ubuntu3.3
Ubuntu 8.10:
libdbus-1-3 1.2.4-0ubuntu1.1
Ubuntu 9.04:
libdbus-1-3 1.2.12-0ubuntu2.1
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Details follow:
It was discovered that the D-Bus library did not correctly validate
signatures. If a local user sent a specially crafted D-Bus key, they could
spoof a valid signature and bypass security policies.
USN-800-1: irssi vulnerability
Submitted by JamesStrandboge on Mon, 2009-07-13 19:25Referenced CVEs:
CVE-2009-1959
Description:
===========================================================
Ubuntu Security Notice USN-800-1 July 13, 2009
irssi vulnerability
CVE-2009-1959
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
irssi 0.8.10-1ubuntu1.1
Ubuntu 8.04 LTS:
irssi 0.8.12-3ubuntu3.1
Ubuntu 8.10:
irssi 0.8.12-4ubuntu2.1
Ubuntu 9.04:
irssi 0.8.12-6ubuntu1.1
After a standard system upgrade you need to restart irssi to effect the
necessary changes.
Details follow:
It was discovered that irssi did not properly check the length of strings
when processing WALLOPS messages. If a user connected to an IRC network
where an attacker had IRC operator privileges, a remote attacker could
cause a denial of service.
USN-797-1: tiff vulnerability
Submitted by MarcDeslauriers on Mon, 2009-07-06 18:34Referenced CVEs:
CVE-2009-2285
Description:
===========================================================
Ubuntu Security Notice USN-797-1 July 06, 2009
tiff vulnerability
CVE-2009-2285
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libtiff4 3.7.4-1ubuntu3.4
Ubuntu 8.04 LTS:
libtiff4 3.8.2-7ubuntu3.2
Ubuntu 8.10:
libtiff4 3.8.2-11ubuntu0.8.10.1
Ubuntu 9.04:
libtiff4 3.8.2-11ubuntu0.9.04.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that the TIFF library did not correctly handle certain
malformed TIFF images. If a user or automated system were tricked into
processing a malicious image, a remote attacker could cause an application
linked against libtiff to crash, leading to a denial of service.
USN-796-1: Pidgin vulnerability
Submitted by MarcDeslauriers on Mon, 2009-07-06 18:33Referenced CVEs:
CVE-2009-1889
Description:
===========================================================
Ubuntu Security Notice USN-796-1 July 06, 2009
pidgin vulnerability
CVE-2009-1889
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.04 LTS:
pidgin 1:2.4.1-1ubuntu2.5
Ubuntu 8.10:
pidgin 1:2.5.2-0ubuntu1.3
Ubuntu 9.04:
pidgin 1:2.5.5-1ubuntu8.3
After a standard system upgrade you need to restart Pidgin to effect
the necessary changes.
Details follow:
Yuriy Kaminskiy discovered that Pidgin did not properly handle certain
messages in the ICQ protocol handler. A remote attacker could send a
specially crafted message and cause Pidgin to crash.
USN-795-1: Nagios vulnerability
Submitted by MarcDeslauriers on Thu, 2009-07-02 18:31Referenced CVEs:
CVE-2009-2288
Description:
===========================================================
Ubuntu Security Notice USN-795-1 July 02, 2009
nagios2, nagios3 vulnerability
CVE-2009-2288
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.04 LTS:
nagios2 2.11-1ubuntu1.5
Ubuntu 8.10:
nagios3 3.0.2-1ubuntu1.2
Ubuntu 9.04:
nagios3 3.0.6-2ubuntu1.1
After a standard system upgrade you need to restart Nagios to effect
the necessary changes.
Details follow:
It was discovered that Nagios did not properly parse certain commands
submitted using the WAP web interface. An authenticated user could exploit
this flaw and execute arbitrary programs on the server.
USN-794-1: Perl vulnerability
Submitted by MarcDeslauriers on Thu, 2009-07-02 18:30Referenced CVEs:
CVE-2009-1391
Description:
===========================================================
Ubuntu Security Notice USN-794-1 July 02, 2009
libcompress-raw-zlib-perl, perl vulnerability
CVE-2009-1391
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.04 LTS:
libcompress-raw-zlib-perl 2.008-1ubuntu0.1
Ubuntu 8.10:
libcompress-raw-zlib-perl 2.011-2ubuntu0.1
perl 5.10.0-11.1ubuntu2.3
Ubuntu 9.04:
libcompress-raw-zlib-perl 2.015-1ubuntu0.1
perl 5.10.0-19ubuntu1.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that the Compress::Raw::Zlib Perl module incorrectly
handled certain zlib compressed streams. If a user or automated system were
tricked into processing a specially crafted compressed stream or file, a
remote attacker could crash the application, leading to a denial of
service.
USN-793-1: Linux kernel vulnerabilities
Submitted by KeesCook on Thu, 2009-07-02 05:43Referenced CVEs:
CVE-2009-1072, CVE-2009-1184, CVE-2009-1192, CVE-2009-1242, CVE-2009-1265, CVE-2009-1336, CVE-2009-1337, CVE-2009-1338, CVE-2009-1360, CVE-2009-1385, CVE-2009-1439, CVE-2009-1630, CVE-2009-1633, CVE-2009-1914, CVE-2009-1961
Description:
===========================================================
Ubuntu Security Notice USN-793-1 July 02, 2009
linux, linux-source-2.6.15 vulnerabilities
CVE-2009-1072, CVE-2009-1184, CVE-2009-1192, CVE-2009-1242,
CVE-2009-1265, CVE-2009-1336, CVE-2009-1337, CVE-2009-1338,
CVE-2009-1360, CVE-2009-1385, CVE-2009-1439, CVE-2009-1630,
CVE-2009-1633, CVE-2009-1914, CVE-2009-1961
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
linux-image-2.6.15-54-386 2.6.15-54.77
linux-image-2.6.15-54-686 2.6.15-54.77
linux-image-2.6.15-54-amd64-generic 2.6.15-54.77
linux-image-2.6.15-54-amd64-k8 2.6.15-54.77
linux-image-2.6.15-54-amd64-server 2.6.15-54.77
linux-image-2.6.15-54-amd64-xeon 2.6.15-54.77
linux-image-2.6.15-54-hppa32 2.6.15-54.77
linux-image-2.6.15-54-hppa32-smp 2.6.15-54.77
linux-image-2.6.15-54-hppa64 2.6.15-54.77
linux-image-2.6.15-54-hppa64-smp 2.6.15-54.77
linux-image-2.6.15-54-itanium 2.6.15-54.77
linux-image-2.6.15-54-itanium-smp 2.6.15-54.77
linux-image-2.6.15-54-k7 2.6.15-54.77
linux-image-2.6.15-54-mckinley 2.6.15-54.77
linux-image-2.6.15-54-mckinley-smp 2.6.15-54.77
linux-image-2.6.15-54-powerpc 2.6.15-54.77
linux-image-2.6.15-54-powerpc-smp 2.6.15-54.77
linux-image-2.6.15-54-powerpc64-smp 2.6.15-54.77
linux-image-2.6.15-54-server 2.6.15-54.77
linux-image-2.6.15-54-server-bigiron 2.6.15-54.77
linux-image-2.6.15-54-sparc64 2.6.15-54.77
linux-image-2.6.15-54-sparc64-smp 2.6.15-54.77
Ubuntu 8.04 LTS:
linux-image-2.6.24-24-386 2.6.24-24.55
linux-image-2.6.24-24-generic 2.6.24-24.55
linux-image-2.6.24-24-hppa32 2.6.24-24.55
linux-image-2.6.24-24-hppa64 2.6.24-24.55
linux-image-2.6.24-24-itanium 2.6.24-24.55
linux-image-2.6.24-24-lpia 2.6.24-24.55
linux-image-2.6.24-24-lpiacompat 2.6.24-24.55
linux-image-2.6.24-24-mckinley 2.6.24-24.55
linux-image-2.6.24-24-openvz 2.6.24-24.55
linux-image-2.6.24-24-powerpc 2.6.24-24.55
linux-image-2.6.24-24-powerpc-smp 2.6.24-24.55
linux-image-2.6.24-24-powerpc64-smp 2.6.24-24.55
linux-image-2.6.24-24-rt 2.6.24-24.55
linux-image-2.6.24-24-server 2.6.24-24.55
linux-image-2.6.24-24-sparc64 2.6.24-24.55
linux-image-2.6.24-24-sparc64-smp 2.6.24-24.55
linux-image-2.6.24-24-virtual 2.6.24-24.55
linux-image-2.6.24-24-xen 2.6.24-24.55
Ubuntu 8.10:
linux-image-2.6.27-14-generic 2.6.27-14.35
linux-image-2.6.27-14-server 2.6.27-14.35
linux-image-2.6.27-14-virtual 2.6.27-14.35
Ubuntu 9.04:
linux-image-2.6.28-13-generic 2.6.28-13.45
linux-image-2.6.28-13-imx51 2.6.28-13.45
linux-image-2.6.28-13-iop32x 2.6.28-13.45
linux-image-2.6.28-13-ixp4xx 2.6.28-13.45
linux-image-2.6.28-13-lpia 2.6.28-13.45
linux-image-2.6.28-13-server 2.6.28-13.45
linux-image-2.6.28-13-versatile 2.6.28-13.45
linux-image-2.6.28-13-virtual 2.6.28-13.45
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
ATTENTION: Due to an unavoidable ABI change for Ubuntu 8.04, 8.10 and 9.04
the kernel updates have been given a new version number, which requires
you to recompile and reinstall all third party kernel modules you
might have installed. If you use linux-restricted-modules, you have to
update that package as well to get modules which work with the new kernel
version. Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-server, linux-powerpc), a standard system
upgrade will automatically perform this as well.
Details follow:
Igor Zhbanov discovered that NFS clients were able to create device nodes
even when root_squash was enabled. An authenticated remote attacker
could create device nodes with open permissions, leading to a loss of
privacy or escalation of privileges. Only Ubuntu 8.10 and 9.04 were
affected. (CVE-2009-1072)
Dan Carpenter discovered that SELinux did not correctly handle
certain network checks when running with compat_net=1. A local
attacker could exploit this to bypass network checks. Default Ubuntu
installations do not enable SELinux, and only Ubuntu 8.10 and 9.04 were
affected. (CVE-2009-1184)
Shaohua Li discovered that memory was not correctly initialized in the
AGP subsystem. A local attacker could potentially read kernel memory,
leading to a loss of privacy. (CVE-2009-1192)
Benjamin Gilbert discovered that the VMX implementation of KVM did
not correctly handle certain registers. An attacker in a guest VM
could exploit this to cause a host system crash, leading to a denial
of service. This only affected 32bit hosts. Ubuntu 6.06 was not
affected. (CVE-2009-1242)
Thomas Pollet discovered that the Amateur Radio X.25 Packet Layer Protocol
did not correctly validate certain fields. A remote attacker could exploit
this to read kernel memory, leading to a loss of privacy. (CVE-2009-1265)
Trond Myklebust discovered that NFS did not correctly handle certain
long filenames. An authenticated remote attacker could exploit this to
cause a system crash, leading to a denial of service. Only Ubuntu 6.06
was affected. (CVE-2009-1336)
Oleg Nesterov discovered that the kernel did not correctly handle
CAP_KILL. A local user could exploit this to send signals to arbitrary
processes, leading to a denial of service. (CVE-2009-1337)
Daniel Hokka Zakrisson discovered that signal handling was not correctly
limited to process namespaces. A local user could bypass namespace
restrictions, possibly leading to a denial of service. Only Ubuntu 8.04
was affected. (CVE-2009-1338)
Pavel Emelyanov discovered that network namespace support for IPv6 was
not correctly handled. A remote attacker could send specially crafted
IPv6 traffic that would cause a system crash, leading to a denial of
service. Only Ubuntu 8.10 and 9.04 were affected. (CVE-2009-1360)
Neil Horman discovered that the e1000 network driver did not correctly
validate certain fields. A remote attacker could send a specially
crafted packet that would cause a system crash, leading to a denial of
service. (CVE-2009-1385)
Pavan Naregundi discovered that CIFS did not correctly check lengths
when handling certain mount requests. A remote attacker could send
specially crafted traffic to cause a system crash, leading to a denial
of service. (CVE-2009-1439)
Simon Vallet and Frank Filz discovered that execute permissions were
not correctly handled by NFSv4. A local user could bypass permissions
and run restricted programs, possibly leading to an escalation of
privileges. (CVE-2009-1630)
Jeff Layton and Suresh Jayaraman discovered buffer overflows in the CIFS
client code. A malicious remote server could exploit this to cause a
system crash or execute arbitrary code as root. (CVE-2009-1633)
Mikulas Patocka discovered that /proc/iomem was not correctly
initialized on Sparc. A local attacker could use this file to crash
the system, leading to a denial of service. Ubuntu 6.06 was not
affected. (CVE-2009-1914)
Miklos Szeredi discovered that OCFS2 did not correctly handle certain
splice operations. A local attacker could exploit this to cause
a system hang, leading to a denial of service. Ubuntu 6.06 was not
affected. (CVE-2009-1961)
USN-782-1: Thunderbird vulnerabilities
Submitted by JamesStrandboge on Fri, 2009-06-26 00:17Referenced CVEs:
CVE-2009-1303, CVE-2009-1305, CVE-2009-1306, CVE-2009-1307, CVE-2009-1308, CVE-2009-1309, CVE-2009-1392, CVE-2009-1833, CVE-2009-1836, CVE-2009-1838, CVE-2009-1841
Description:
===========================================================
Ubuntu Security Notice USN-782-1 June 25, 2009
thunderbird vulnerabilities
CVE-2009-1303, CVE-2009-1305, CVE-2009-1306, CVE-2009-1307,
CVE-2009-1308, CVE-2009-1309, CVE-2009-1392, CVE-2009-1833,
CVE-2009-1836, CVE-2009-1838, CVE-2009-1841
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.04 LTS:
thunderbird 2.0.0.22+build1+nobinonly-0ubuntu0.8.04.1
Ubuntu 8.10:
thunderbird 2.0.0.22+build1+nobinonly-0ubuntu0.8.10.1
Ubuntu 9.04:
thunderbird 2.0.0.22+build1+nobinonly-0ubuntu0.9.04.1
After a standard system upgrade you need to restart Thunderbird to effect
the necessary changes.
Details follow:
Several flaws were discovered in the JavaScript engine of Thunderbird. If a
user had JavaScript enabled and were tricked into viewing malicious web
content, a remote attacker could cause a denial of service or possibly
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2009-1303, CVE-2009-1305, CVE-2009-1392, CVE-2009-1833,
CVE-2009-1838)
Several flaws were discovered in the way Thunderbird processed malformed
URI schemes. If a user were tricked into viewing a malicious website and
had JavaScript and plugins enabled, a remote attacker could execute
arbitrary JavaScript or steal private data. (CVE-2009-1306, CVE-2009-1307,
CVE-2009-1309)
Cefn Hoile discovered Thunderbird did not adequately protect against
embedded third-party stylesheets. If JavaScript were enabled, an attacker
could exploit this to perform script injection attacks using XBL bindings.
(CVE-2009-1308)
Shuo Chen, Ziqing Mao, Yi-Min Wang, and Ming Zhang discovered that
Thunderbird did not properly handle error responses when connecting to a
proxy server. If a user had JavaScript enabled while using Thunderbird to
view websites and a remote attacker were able to perform a
man-in-the-middle attack, this flaw could be exploited to view sensitive
information. (CVE-2009-1836)
It was discovered that Thunderbird could be made to run scripts with
elevated privileges. If a user had JavaScript enabled while having
certain non-default add-ons installed and were tricked into viewing a
malicious website, an attacker could cause a chrome privileged object, such
as the browser sidebar, to run arbitrary code via interactions with the
attacker controlled website. (CVE-2009-1841)


