USN-959-1: PAM vulnerability

Referenced CVEs: 
CVE-2010-0832

Description: 
===========================================================
Ubuntu Security Notice USN-959-1 July 07, 2010
pam vulnerability
CVE-2010-0832
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 9.10:
libpam-modules 1.1.0-2ubuntu1.1

Ubuntu 10.04 LTS:
libpam-modules 1.1.1-2ubuntu5

In general, a standard system update will make all the necessary changes.

Details follow:

Denis Excoffier discovered that the PAM MOTD module in Ubuntu did
not correctly handle path permissions when creating user file stamps.
A local attacker could exploit this to gain root privilieges.

Articoli Correlati

  • No Related Posts

USN-943-1: Thunderbird vulnerabilities

Referenced CVEs: 
CVE-2010-1121, CVE-2010-1196, CVE-2010-1199, CVE-2010-1200, CVE-2010-1201, CVE-2010-1202, CVE-2010-1203

Description: 
===========================================================
Ubuntu Security Notice USN-943-1 July 06, 2010
thunderbird vulnerabilities
CVE-2010-1121, CVE-2010-1196, CVE-2010-1199, CVE-2010-1200,
CVE-2010-1201, CVE-2010-1202, CVE-2010-1203
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 10.04 LTS:
thunderbird 3.0.5+build2+nobinonly-0ubuntu0.10.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

Details follow:

Martin Barbella discovered an integer overflow in an XSLT node sorting
routine. An attacker could exploit this to overflow a buffer and cause a
denial of service or possibly execute arbitrary code with the privileges of
the user invoking the program. (CVE-2010-1199)

An integer overflow was discovered in Thunderbird. If a user were tricked
into viewing malicious content, an attacker could overflow a buffer and
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-1196)

Several flaws were discovered in the browser engine of Thunderbird. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,
CVE-2010-1202, CVE-2010-1203)

If was discovered that Thunderbird could be made to access freed memory. If
a user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-1121)

Articoli Correlati

  • No Related Posts

USN-956-1: sudo vulnerability

Referenced CVEs: 
CVE-2010-1646

Description: 
===========================================================
Ubuntu Security Notice USN-956-1 June 30, 2010
sudo vulnerability
CVE-2010-1646
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
sudo 1.6.8p12-1ubuntu6.3
sudo-ldap 1.6.8p12-1ubuntu6.3

Ubuntu 8.04 LTS:
sudo 1.6.9p10-1ubuntu3.8
sudo-ldap 1.6.9p10-1ubuntu3.8

Ubuntu 9.04:
sudo 1.6.9p17-1ubuntu3.3
sudo-ldap 1.6.9p17-1ubuntu3.3

Ubuntu 9.10:
sudo 1.7.0-1ubuntu2.4
sudo-ldap 1.7.0-1ubuntu2.4

Ubuntu 10.04 LTS:
sudo 1.7.2p1-1ubuntu5.1
sudo-ldap 1.7.2p1-1ubuntu5.1

In general, a standard system update will make all the necessary changes.

Details follow:

Evan Broder and Anders Kaseorg discovered that sudo did not properly
sanitize its environment when configured to use secure_path (the default in
Ubuntu). A local attacker could exploit this to execute arbitrary code as
root if sudo was configured to allow the attacker to use a program that
interpreted the PATH environment variable.

Articoli Correlati

  • No Related Posts

Ubuntu 10.4 e sun java 6

Capita di dover utilizzare il pacchetto java di sun.

Ma nell’ultima versione di ubuntu, non ci sono i repositary della versione.

Nessuna paura:

Disinstallate, se installata, la versine openjdk con

  1. sudo apt-get remove openjdk-6-jre
  2. seguita da sudo apt-get autoremove

e quindi

  1. sudo add-apt-repository “deb http://archive.canonical.com/ lucid partner”  && sudo apt-get update &&  sudo apt-get install sun-java6-jre sun-java6-jdk sun-java6-plugin sun-java6-fonts

Rispondete alle domande che il sistema vi porrà ed aspettate la fine dell’installazione.

E’ tutto.

Articoli Correlati

Aria di pensionamento in casa Microsoft

Aria di pensionamento in casa Microsoft.

Oggi, martedi’ 13 luglio è l’ultimo giorno utile per ottenere supporto per Microsoft Windows XP SP2. Da oggi, chi deciderà di rimanere con questa versione del sistema operativo non riceverà più patch di sicurezza. Dovrà necessariamente passare a Microsoft Windows XP service pack 3 oppure a Windows 7.

L’8 aprile 2014 invece terminerà il supporto anche per Microsoft Windows XP SP3, e in quel momento il glorioso sistema operativo di Microsoft sarà definitivamente pensionato.

Passando a Windows 2000, sia nella versione client che server, oggi è l’ultimo giorno di supporto. Da domani sarà pensionato anche questo sistema operativo.

Anche per Windows 2003 oggi è una data importante. Da oggi parte il supporto esteso, saranno rilasciate solo le patch di sicurezza per poi pensionarlo definitivamente il 13 luglio 2015.

Articoli Correlati