Security announcements
USN-792-1: OpenSSL vulnerabilities
Submitted by MarcDeslauriers on Thu, 2009-06-25 18:28Referenced CVEs:
CVE-2009-1377, CVE-2009-1378, CVE-2009-1379, CVE-2009-1386, CVE-2009-1387
Description:
===========================================================
Ubuntu Security Notice USN-792-1 June 25, 2009
openssl vulnerabilities
CVE-2009-1377, CVE-2009-1378, CVE-2009-1379, CVE-2009-1386,
CVE-2009-1387
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libssl0.9.8 0.9.8a-7ubuntu0.9
Ubuntu 8.04 LTS:
libssl0.9.8 0.9.8g-4ubuntu3.7
Ubuntu 8.10:
libssl0.9.8 0.9.8g-10.1ubuntu2.4
Ubuntu 9.04:
libssl0.9.8 0.9.8g-15ubuntu3.2
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Details follow:
It was discovered that OpenSSL did not limit the number of DTLS records it
would buffer when they arrived with a future epoch. A remote attacker could
cause a denial of service via memory resource consumption by sending a
large number of crafted requests. (CVE-2009-1377)
It was discovered that OpenSSL did not properly free memory when processing
DTLS fragments. A remote attacker could cause a denial of service via
memory resource consumption by sending a large number of crafted requests.
(CVE-2009-1378)
It was discovered that OpenSSL did not properly handle certain server
certificates when processing DTLS packets. A remote DTLS server could cause
a denial of service by sending a message containing a specially crafted
server certificate. (CVE-2009-1379)
It was discovered that OpenSSL did not properly handle a DTLS
ChangeCipherSpec packet when it occured before ClientHello. A remote
attacker could cause a denial of service by sending a specially crafted
request. (CVE-2009-1386)
It was discovered that OpenSSL did not properly handle out of sequence
DTLS handshake messages. A remote attacker could cause a denial of service
by sending a specially crafted request. (CVE-2009-1387)
USN-791-2: Moodle vulnerability
Submitted by KeesCook on Wed, 2009-06-24 20:02Referenced CVEs:
CVE-2009-1171
Description:
===========================================================
Ubuntu Security Notice USN-791-2 June 24, 2009
moodle vulnerability
CVE-2009-1171
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 9.04:
moodle 1.9.4.dfsg-0ubuntu1.1
After a standard system upgrade you need to access the Moodle instance
and accept the database update to clear any invalid cached data.
Details follow:
Christian Eibl discovered that the TeX filter in Moodle allowed any
function to be used. An authenticated remote attacker could post a
specially crafted TeX formula to execute arbitrary TeX functions,
potentially reading any file accessible to the web server user, leading
to a loss of privacy. (CVE-2009-1171, MSA-09-0009)
USN-791-3: Smarty vulnerability
Submitted by KeesCook on Wed, 2009-06-24 20:01Referenced CVEs:
CVE-2009-1669
Description:
===========================================================
Ubuntu Security Notice USN-791-3 June 24, 2009
smarty vulnerability
CVE-2009-1669
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 9.04:
smarty 2.6.22-1ubuntu1.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that Smarty did not correctly filter certain math
inputs. A remote attacker using Smarty via a web service could exploit
this to execute subsets of shell commands as the web server user.
USN-791-1: Moodle vulnerabilities
Submitted by KeesCook on Wed, 2009-06-24 19:54Referenced CVEs:
CVE-2007-3215, CVE-2008-4796, CVE-2008-4810, CVE-2008-4811, CVE-2008-5153, CVE-2008-5432, CVE-2008-5619, CVE-2008-6124, CVE-2009-0499, CVE-2009-0500, CVE-2009-0501, CVE-2009-0502, CVE-2009-1171, CVE-2009-1669
Description:
===========================================================
Ubuntu Security Notice USN-791-1 June 24, 2009
moodle vulnerabilities
CVE-2007-3215, CVE-2008-4796, CVE-2008-4810, CVE-2008-4811,
CVE-2008-5153, CVE-2008-5432, CVE-2008-5619, CVE-2008-6124,
CVE-2009-0499, CVE-2009-0500, CVE-2009-0501, CVE-2009-0502,
CVE-2009-1171, CVE-2009-1669
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.04 LTS:
moodle 1.8.2-1ubuntu4.2
Ubuntu 8.10:
moodle 1.8.2-1.2ubuntu2.1
After a standard system upgrade you need to access the Moodle instance
and accept the database update to clear any invalid cached data.
Details follow:
Thor Larholm discovered that PHPMailer, as used by Moodle, did not
correctly escape email addresses. A local attacker with direct access
to the Moodle database could exploit this to execute arbitrary commands
as the web server user. (CVE-2007-3215)
Nigel McNie discovered that fetching https URLs did not correctly escape
shell meta-characters. An authenticated remote attacker could execute
arbitrary commands as the web server user, if curl was installed and
configured. (CVE-2008-4796, MSA-09-0003)
It was discovered that Smarty (also included in Moodle), did not
correctly filter certain inputs. An authenticated remote attacker could
exploit this to execute arbitrary PHP commands as the web server user.
(CVE-2008-4810, CVE-2008-4811, CVE-2009-1669)
It was discovered that the unused SpellChecker extension in Moodle did not
correctly handle temporary files. If the tool had been locally modified,
it could be made to overwrite arbitrary local files via symlinks.
(CVE-2008-5153)
Mike Churchward discovered that Moodle did not correctly filter Wiki page
titles in certain areas. An authenticated remote attacker could exploit
this to cause cross-site scripting (XSS), which could be used to modify
or steal confidential data of other users within the same web domain.
(CVE-2008-5432, MSA-08-0022)
It was discovered that the HTML sanitizer, "Login as" feature, and logging
in Moodle did not correctly handle certain inputs. An authenticated
remote attacker could exploit this to generate XSS, which could be used
to modify or steal confidential data of other users within the same
web domain. (CVE-2008-5619, CVE-2009-0500, CVE-2009-0502, MSA-08-0026,
MSA-09-0004, MSA-09-0007)
It was discovered that the HotPot module in Moodle did not correctly
filter SQL inputs. An authenticated remote attacker could execute
arbitrary SQL commands as the moodle database user, leading to a loss
of privacy or denial of service. (CVE-2008-6124, MSA-08-0010)
Kevin Madura discovered that the forum actions and messaging settings
in Moodle were not protected from cross-site request forgery (CSRF).
If an authenticated user were tricked into visiting a malicious
website while logged into Moodle, a remote attacker could change the
user's configurations or forum content. (CVE-2009-0499, MSA-09-0008,
MSA-08-0023)
Daniel Cabezas discovered that Moodle would leak usernames from the
Calendar Export tool. A remote attacker could gather a list of users,
leading to a loss of privacy. (CVE-2009-0501, MSA-09-0006)
Christian Eibl discovered that the TeX filter in Moodle allowed any
function to be used. An authenticated remote attacker could post
a specially crafted TeX formula to execute arbitrary TeX functions,
potentially reading any file accessible to the web server user, leading
to a loss of privacy. (CVE-2009-1171, MSA-09-0009)
Johannes Kuhn discovered that Moodle did not correctly validate user
permissions when attempting to switch user accounts. An authenticated
remote attacker could switch to any other Moodle user, leading to a loss
of privacy. (MSA-08-0003)
Hanno Boeck discovered that unconfigured Moodle instances contained
XSS vulnerabilities. An unauthenticated remote attacker could exploit
this to modify or steal confidential data of other users within the same
web domain. (MSA-08-0004)
Debbie McDonald, Mauno Korpelainen, Howard Miller, and Juan Segarra
Montesinos discovered that when users were deleted from Moodle, their
profiles and avatars were still visible. An authenticated remote attacker
could exploit this to store information in profiles even after they were
removed, leading to spam traffic. (MSA-08-0015, MSA-09-0001, MSA-09-0002)
Lars Vogdt discovered that Moodle did not correctly filter certain inputs.
An authenticated remote attacker could exploit this to generate XSS from
which they could modify or steal confidential data of other users within
the same web domain. (MSA-08-0021)
It was discovered that Moodle did not correctly filter inputs for group
creation, mnet, essay question, HOST param, wiki param, and others.
An authenticated remote attacker could exploit this to generate XSS
from which they could modify or steal confidential data of other users
within the same web domain. (MDL-9288, MDL-11759, MDL-12079, MDL-12793,
MDL-14806)
It was discovered that Moodle did not correctly filter SQL inputs when
performing a restore. An attacker authenticated as a Moodle administrator
could execute arbitrary SQL commands as the moodle database user,
leading to a loss of privacy or denial of service. (MDL-11857)
USN-790-1: Cyrus SASL vulnerability
Submitted by KeesCook on Wed, 2009-06-24 18:28Referenced CVEs:
CVE-2009-0688
Description:
===========================================================
Ubuntu Security Notice USN-790-1 June 24, 2009
cyrus-sasl2 vulnerability
CVE-2009-0688
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libsasl2 2.1.19.dfsg1-0.1ubuntu3.1
Ubuntu 8.04 LTS:
libsasl2-2 2.1.22.dfsg1-18ubuntu2.1
Ubuntu 8.10:
libsasl2-2 2.1.22.dfsg1-21ubuntu2.1
Ubuntu 9.04:
libsasl2-2 2.1.22.dfsg1-23ubuntu3.1
After a standard system upgrade you need to restart services using SASL
to effect the necessary changes.
Details follow:
James Ralston discovered that the Cyrus SASL base64 encoding function
could be used unsafely. If a remote attacker sent a specially crafted
request to a service that used SASL, it could lead to a loss of privacy,
or crash the application, resulting in a denial of service.
USN-789-1: GStreamer Good Plugins vulnerability
Submitted by MarcDeslauriers on Mon, 2009-06-22 13:24Referenced CVEs:
CVE-2009-1932
Description:
===========================================================
Ubuntu Security Notice USN-789-1 June 22, 2009
gst-plugins-good0.10 vulnerability
CVE-2009-1932
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
gstreamer0.10-plugins-good 0.10.3-0ubuntu4.2
Ubuntu 8.04 LTS:
gstreamer0.10-plugins-good 0.10.7-3ubuntu0.3
Ubuntu 8.10:
gstreamer0.10-plugins-good 0.10.10.4-1ubuntu1.2
Ubuntu 9.04:
gstreamer0.10-plugins-good 0.10.14-1ubuntu0.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Tielei Wang discovered that GStreamer Good Plugins did not correctly handle
malformed PNG image files. If a user were tricked into opening a crafted
PNG image file with a GStreamer application, an attacker could cause a
denial of service via application crash, or possibly execute arbitrary code
with the privileges of the user invoking the program.
USN-788-1: Tomcat vulnerabilities
Submitted by MarcDeslauriers on Mon, 2009-06-15 15:24Referenced CVEs:
CVE-2008-5515, CVE-2009-0033, CVE-2009-0580, CVE-2009-0781, CVE-2009-0783
Description:
===========================================================
Ubuntu Security Notice USN-788-1 June 15, 2009
tomcat6 vulnerabilities
CVE-2008-5515, CVE-2009-0033, CVE-2009-0580, CVE-2009-0781,
CVE-2009-0783
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.10:
libtomcat6-java 6.0.18-0ubuntu3.2
tomcat6-examples 6.0.18-0ubuntu3.2
Ubuntu 9.04:
libtomcat6-java 6.0.18-0ubuntu6.1
tomcat6-examples 6.0.18-0ubuntu6.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Iida Minehiko discovered that Tomcat did not properly normalise paths. A
remote attacker could send specially crafted requests to the server and
bypass security restrictions, gaining access to sensitive content.
(CVE-2008-5515)
Yoshihito Fukuyama discovered that Tomcat did not properly handle errors
when the Java AJP connector and mod_jk load balancing are used. A remote
attacker could send specially crafted requests containing invalid headers
to the server and cause a temporary denial of service. (CVE-2009-0033)
D. Matscheko and T. Hackner discovered that Tomcat did not properly handle
malformed URL encoding of passwords when FORM authentication is used. A
remote attacker could exploit this in order to enumerate valid usernames.
(CVE-2009-0580)
Deniz Cevik discovered that Tomcat did not properly escape certain
parameters in the example calendar application which could result in
browsers becoming vulnerable to cross-site scripting attacks when
processing the output. With cross-site scripting vulnerabilities, if a user
were tricked into viewing server output during a crafted server request, a
remote attacker could exploit this to modify the contents, or steal
confidential data (such as passwords), within the same domain.
(CVE-2009-0781)
Philippe Prados discovered that Tomcat allowed web applications to replace
the XML parser used by other web applications. Local users could exploit
this to bypass security restrictions and gain access to certain sensitive
files. (CVE-2009-0783)
USN-779-1: Firefox and Xulrunner vulnerabilities
Submitted by JamesStrandboge on Sat, 2009-06-13 00:21Referenced CVEs:
CVE-2009-1392, CVE-2009-1832, CVE-2009-1833, CVE-2009-1834, CVE-2009-1835, CVE-2009-1836, CVE-2009-1837, CVE-2009-1838, CVE-2009-1839, CVE-2009-1840, CVE-2009-1841
Description:
===========================================================
Ubuntu Security Notice USN-779-1 June 12, 2009
firefox-3.0, xulrunner-1.9 vulnerabilities
CVE-2009-1392, CVE-2009-1832, CVE-2009-1833, CVE-2009-1834,
CVE-2009-1835, CVE-2009-1836, CVE-2009-1837, CVE-2009-1838,
CVE-2009-1839, CVE-2009-1840, CVE-2009-1841
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.04 LTS:
firefox-3.0 3.0.11+build2+nobinonly-0ubuntu0.8.04.1
xulrunner-1.9 1.9.0.11+build2+nobinonly-0ubuntu0.8.04.1
Ubuntu 8.10:
abrowser 3.0.11+build2+nobinonly-0ubuntu0.8.10.1
firefox-3.0 3.0.11+build2+nobinonly-0ubuntu0.8.10.1
xulrunner-1.9 1.9.0.11+build2+nobinonly-0ubuntu0.8.10.2
Ubuntu 9.04:
abrowser 3.0.11+build2+nobinonly-0ubuntu0.9.04.1
firefox-3.0 3.0.11+build2+nobinonly-0ubuntu0.9.04.1
xulrunner-1.9 1.9.0.11+build2+nobinonly-0ubuntu0.9.04.1
After a standard system upgrade you need to restart Firefox and any
applications that use xulrunner, such as Epiphany, to effect the necessary
changes.
Details follow:
Several flaws were discovered in the browser and JavaScript engines of
Firefox. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-1392,
CVE-2009-1832, CVE-2009-1833, CVE-2009-1837, CVE-2009-1838)
Pavel Cvrcek discovered that Firefox would sometimes display certain
invalid Unicode characters as whitespace. An attacker could exploit this to
spoof the location bar, such as in a phishing attack. (CVE-2009-1834)
Gregory Fleischer, Adam Barth and Collin Jackson discovered that Firefox
would allow access to local files from resources loaded via the file:
protocol. If a user were tricked into downloading then opening a malicious
file, an attacker could steal potentially sensitive information.
(CVE-2009-1835, CVE-2009-1839)
Shuo Chen, Ziqing Mao, Yi-Min Wang, and Ming Zhang discovered that Firefox
did not properly handle error responses when connecting to a proxy server.
If a remote attacker were able to perform a man-in-the-middle attack, this
flaw could be exploited to view sensitive information. (CVE-2009-1836)
Wladimir Palant discovered Firefox did not check content-loading policies
when loading external script files into XUL documents. As a result, Firefox
might load malicious content under certain circumstances. (CVE-2009-1840)
It was discovered that Firefox could be made to run scripts with elevated
privileges. If a user were tricked into viewing a malicious website, an
attacker could cause a chrome privileged object, such as the browser
sidebar, to run arbitrary code via interactions with the attacker
controlled website. (CVE-2009-1841)
USN-787-1: Apache vulnerabilities
Submitted by JamesStrandboge on Fri, 2009-06-12 00:51Referenced CVEs:
CVE-2009-0023, CVE-2009-1191, CVE-2009-1195, CVE-2009-1955, CVE-2009-1956
Description:
===========================================================
Ubuntu Security Notice USN-787-1 June 12, 2009
apache2 vulnerabilities
CVE-2009-0023, CVE-2009-1191, CVE-2009-1195, CVE-2009-1955,
CVE-2009-1956
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
apache2-common 2.0.55-4ubuntu2.5
apache2-mpm-perchild 2.0.55-4ubuntu2.5
apache2-mpm-prefork 2.0.55-4ubuntu2.5
apache2-mpm-worker 2.0.55-4ubuntu2.5
libapr0 2.0.55-4ubuntu2.5
Ubuntu 8.04 LTS:
apache2-mpm-event 2.2.8-1ubuntu0.8
apache2-mpm-perchild 2.2.8-1ubuntu0.8
apache2-mpm-prefork 2.2.8-1ubuntu0.8
apache2-mpm-worker 2.2.8-1ubuntu0.8
apache2.2-common 2.2.8-1ubuntu0.8
Ubuntu 8.10:
apache2-mpm-event 2.2.9-7ubuntu3.1
apache2-mpm-prefork 2.2.9-7ubuntu3.1
apache2-mpm-worker 2.2.9-7ubuntu3.1
apache2.2-common 2.2.9-7ubuntu3.1
Ubuntu 9.04:
apache2-mpm-event 2.2.11-2ubuntu2.1
apache2-mpm-prefork 2.2.11-2ubuntu2.1
apache2-mpm-worker 2.2.11-2ubuntu2.1
apache2.2-common 2.2.11-2ubuntu2.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Matthew Palmer discovered an underflow flaw in apr-util as included in
Apache. An attacker could cause a denial of service via application crash
in Apache using a crafted SVNMasterURI directive, .htaccess file, or when
using mod_apreq2. This issue only affected Ubuntu 6.06 LTS. (CVE-2009-0023)
Sander de Boer discovered that mod_proxy_ajp would reuse connections when
a client closed a connection without sending a request body. A remote
attacker could exploit this to obtain sensitive response data. This issue
only affected Ubuntu 9.04. (CVE-2009-1191)
Jonathan Peatfield discovered that Apache did not process Includes options
correctly. With certain configurations of Options and AllowOverride, a
local attacker could use an .htaccess file to override intended
restrictions and execute arbitrary code via a Server-Side-Include file.
This issue affected Ubuntu 8.04 LTS, 8.10 and 9.04. (CVE-2009-1195)
It was discovered that the XML parser did not properly handle entity
expansion. A remote attacker could cause a denial of service via memory
resource consumption by sending a crafted request to an Apache server
configured to use mod_dav or mod_dav_svn. This issue only affected Ubuntu
6.06 LTS. (CVE-2009-1955)
C. Michael Pilato discovered an off-by-one buffer overflow in apr-util when
formatting certain strings. For big-endian machines (powerpc, hppa and
sparc in Ubuntu), a remote attacker could cause a denial of service or
information disclosure leak. All other architectures for Ubuntu are not
considered to be at risk. This issue only affected Ubuntu 6.06 LTS.
(CVE-2009-1956)
USN-786-1: apr-util vulnerabilities
Submitted by JamesStrandboge on Wed, 2009-06-10 20:11Referenced CVEs:
CVE-2009-0023, CVE-2009-1955, CVE-2009-1956
Description:
===========================================================
Ubuntu Security Notice USN-786-1 June 10, 2009
apr-util vulnerabilities
CVE-2009-0023, CVE-2009-1955, CVE-2009-1956
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.04 LTS:
libaprutil1 1.2.12+dfsg-3ubuntu0.1
Ubuntu 8.10:
libaprutil1 1.2.12+dfsg-7ubuntu0.1
Ubuntu 9.04:
libaprutil1 1.2.12+dfsg-8ubuntu0.1
After a standard system upgrade you need to restart any services that use
apr-util, such as Apache or svnserve, to effect the necessary changes.
Details follow:
Matthew Palmer discovered an underflow flaw in apr-util. An attacker could
cause a denial of service via application crash in Apache using a crafted
SVNMasterURI directive, .htaccess file, or when using mod_apreq2.
Applications using libapreq2 are also affected. (CVE-2009-0023)
It was discovered that the XML parser did not properly handle entity
expansion. A remote attacker could cause a denial of service via memory
resource consumption by sending a crafted request to an Apache server
configured to use mod_dav or mod_dav_svn. (CVE-2009-1955)
C. Michael Pilato discovered an off-by-one buffer overflow in apr-util when
formatting certain strings. For big-endian machines (powerpc, hppa and
sparc in Ubuntu), a remote attacker could cause a denial of service or
information disclosure leak. All other architectures for Ubuntu are
not considered to be at risk. (CVE-2009-1956)


