USN-971-1: OpenJDK vulnerabilities

Referenced CVEs: 
CVE-2010-2548, CVE-2010-2783

Description: 
===========================================================
Ubuntu Security Notice USN-971-1 August 16, 2010
openjdk-6 vulnerabilities
CVE-2010-2548, CVE-2010-2783
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 9.04:
icedtea6-plugin 6b18-1.8.1-0ubuntu1~9.04.1

Ubuntu 9.10:
icedtea6-plugin 6b18-1.8.1-0ubuntu1~9.10.1

Ubuntu 10.04 LTS:
icedtea6-plugin 6b18-1.8.1-0ubuntu1

After a standard system update you need to restart any Java applications
to make all the necessary changes.

Details follow:

It was discovered that the IcedTea plugin did not correctly check certain
accesses. If a user or automated system were tricked into running a
specially crafted Java applet, a remote attacker could read arbitrary
files with user privileges, leading to a loss of privacy. (CVE-2010-2548,
CVE-2010-2783)

Articoli Correlati

  • No Related Posts

USN-970-1: GnuPG2 vulnerability

Referenced CVEs: 
CVE-2010-2547

Description: 
===========================================================
Ubuntu Security Notice USN-970-1 August 11, 2010
gnupg2 vulnerability
CVE-2010-2547
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.04 LTS:
gpgsm 2.0.7-1ubuntu0.1

Ubuntu 9.04:
gpgsm 2.0.9-3.1ubuntu0.1

Ubuntu 9.10:
gpgsm 2.0.12-0ubuntu2.1

Ubuntu 10.04 LTS:
gpgsm 2.0.14-1ubuntu1.2

In general, a standard system update will make all the necessary changes.

Details follow:

It was discovered that GPGSM in GnuPG2 did not correctly handle
certificates with a large number of Subject Alternate Names. If a user or
automated system were tricked into processing a specially crafted
certificate, an attacker could cause a denial of service or execute
arbitrary code with privileges of the user invoking the program.

Articoli Correlati

  • No Related Posts

USN-967-1: w3m vulnerability

Referenced CVEs: 
CVE-2010-2074

Description: 
===========================================================
Ubuntu Security Notice USN-967-1 August 09, 2010
w3m vulnerability
CVE-2010-2074
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
w3m 0.5.1-4ubuntu2.6.06.1

Ubuntu 8.04 LTS:
w3m 0.5.1-5.1ubuntu1.1

Ubuntu 9.04:
w3m 0.5.2-2ubuntu0.1

Ubuntu 9.10:
w3m 0.5.2-2ubuntu1.1

Ubuntu 10.04 LTS:
w3m 0.5.2-2.1ubuntu1.1

After a standard system update you need to restart any running instances
of w3m to effect the necessary changes.

Details follow:

Ludwig Nussel discovered w3m does not properly handle SSL/TLS
certificates with NULL characters in the certificate name. An
attacker could exploit this to perform a man in the middle
attack to view sensitive information or alter encrypted
communications. (CVE-2010-2074)

Articoli Correlati

  • No Related Posts

USN-965-1: OpenLDAP vulnerabilities

Referenced CVEs: 
CVE-2010-0211, CVE-2010-0212

Description: 
===========================================================
Ubuntu Security Notice USN-965-1 August 09, 2010
openldap, openldap2.2, openldap2.3 vulnerabilities
CVE-2010-0211, CVE-2010-0212
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
slapd 2.2.26-5ubuntu2.10

Ubuntu 8.04 LTS:
slapd 2.4.9-0ubuntu0.8.04.4

Ubuntu 9.04:
slapd 2.4.15-1ubuntu3.1

Ubuntu 9.10:
slapd 2.4.18-0ubuntu1.1

Ubuntu 10.04 LTS:
slapd 2.4.21-0ubuntu5.2

In general, a standard system update will make all the necessary changes.

Details follow:

Using the Codenomicon LDAPv3 test suite, Ilkka Mattila and Tuomas
Salomäki discovered that the slap_modrdn2mods function in modrdn.c
in OpenLDAP does not check the return value from a call to the
smr_normalize function. A remote attacker could use specially crafted
modrdn requests to crash the slapd daemon or possibly execute arbitrary
code. (CVE-2010-0211)

Using the Codenomicon LDAPv3 test suite, Ilkka Mattila and Tuomas
Salomäki discovered that OpenLDAP does not properly handle empty
RDN strings. A remote attacker could use specially crafted modrdn
requests to crash the slapd daemon. (CVE-2010-0212)

In the default installation under Ubuntu 8.04 LTS and later, attackers
would be isolated by the OpenLDAP AppArmor profile for the slapd daemon.

Articoli Correlati

  • No Related Posts

USN-969-1: PCSC-Lite vulnerability

Referenced CVEs: 
CVE-2009-4901, CVE-2009-4902, CVE-2010-0407

Description: 
===========================================================
Ubuntu Security Notice USN-969-1 August 05, 2010
pcsc-lite vulnerability
CVE-2009-4901, CVE-2009-4902, CVE-2010-0407
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 9.04:
pcscd 1.4.102-1ubuntu2.1

Ubuntu 9.10:
pcscd 1.5.3-1ubuntu1.1

Ubuntu 10.04 LTS:
pcscd 1.5.3-1ubuntu4.1

In general, a standard system update will make all the necessary changes.

Details follow:

It was discovered that the PC/SC service did not correctly handle
malformed messages. A local attacker could exploit this to execute
arbitrary code with root privileges.

Articoli Correlati

  • No Related Posts

USN-968-1: Dell Latitude 2110 vulnerability

Referenced CVEs: 
CVE-2010-0834

Description: 
===========================================================
Ubuntu Security Notice USN-968-1 August 05, 2010
base-files vulnerability
CVE-2010-0834
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 9.10:
base-files 5.0.0ubuntu7.1

Ubuntu 10.04 LTS:
base-files 5.0.0ubuntu20.10.04.2

In general, a standard system update will make all the necessary changes.

Details follow:

It was discovered that the Ubuntu image shipped on some Dell Latitude
2110 systems was accidentally configured to allow unauthenticated package
installations. A remote attacker intercepting network communications or
a malicious archive mirror server could exploit this to trick the user
into installing unsigned packages, resulting in arbitrary code execution
with root privileges.

Articoli Correlati

  • No Related Posts

USN-966-1: Linux kernel vulnerabilities

Referenced CVEs: 
CVE-2008-7256, CVE-2010-1173, CVE-2010-1436, CVE-2010-1437, CVE-2010-1451, CVE-2010-1636, CVE-2010-1641, CVE-2010-1643, CVE-2010-2071, CVE-2010-2492

Description: 
===========================================================
Ubuntu Security Notice USN-966-1 August 04, 2010
linux, linux-{source-2.6.15,ec2,mvl-dove,ti-omap} vulnerabilities
CVE-2008-7256, CVE-2010-1173, CVE-2010-1436, CVE-2010-1437,
CVE-2010-1451, CVE-2010-1636, CVE-2010-1641, CVE-2010-1643,
CVE-2010-2071, CVE-2010-2492
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
linux-image-2.6.15-55-386 2.6.15-55.86
linux-image-2.6.15-55-686 2.6.15-55.86
linux-image-2.6.15-55-amd64-generic 2.6.15-55.86
linux-image-2.6.15-55-amd64-k8 2.6.15-55.86
linux-image-2.6.15-55-amd64-server 2.6.15-55.86
linux-image-2.6.15-55-amd64-xeon 2.6.15-55.86
linux-image-2.6.15-55-hppa32 2.6.15-55.86
linux-image-2.6.15-55-hppa32-smp 2.6.15-55.86
linux-image-2.6.15-55-hppa64 2.6.15-55.86
linux-image-2.6.15-55-hppa64-smp 2.6.15-55.86
linux-image-2.6.15-55-itanium 2.6.15-55.86
linux-image-2.6.15-55-itanium-smp 2.6.15-55.86
linux-image-2.6.15-55-k7 2.6.15-55.86
linux-image-2.6.15-55-mckinley 2.6.15-55.86
linux-image-2.6.15-55-mckinley-smp 2.6.15-55.86
linux-image-2.6.15-55-powerpc 2.6.15-55.86
linux-image-2.6.15-55-powerpc-smp 2.6.15-55.86
linux-image-2.6.15-55-powerpc64-smp 2.6.15-55.86
linux-image-2.6.15-55-server 2.6.15-55.86
linux-image-2.6.15-55-server-bigiron 2.6.15-55.86
linux-image-2.6.15-55-sparc64 2.6.15-55.86
linux-image-2.6.15-55-sparc64-smp 2.6.15-55.86

Ubuntu 8.04 LTS:
linux-image-2.6.24-28-386 2.6.24-28.73
linux-image-2.6.24-28-generic 2.6.24-28.73
linux-image-2.6.24-28-hppa32 2.6.24-28.73
linux-image-2.6.24-28-hppa64 2.6.24-28.73
linux-image-2.6.24-28-itanium 2.6.24-28.73
linux-image-2.6.24-28-lpia 2.6.24-28.73
linux-image-2.6.24-28-lpiacompat 2.6.24-28.73
linux-image-2.6.24-28-mckinley 2.6.24-28.73
linux-image-2.6.24-28-openvz 2.6.24-28.73
linux-image-2.6.24-28-powerpc 2.6.24-28.73
linux-image-2.6.24-28-powerpc-smp 2.6.24-28.73
linux-image-2.6.24-28-powerpc64-smp 2.6.24-28.73
linux-image-2.6.24-28-rt 2.6.24-28.73
linux-image-2.6.24-28-server 2.6.24-28.73
linux-image-2.6.24-28-sparc64 2.6.24-28.73
linux-image-2.6.24-28-sparc64-smp 2.6.24-28.73
linux-image-2.6.24-28-virtual 2.6.24-28.73
linux-image-2.6.24-28-xen 2.6.24-28.73

Ubuntu 9.04:
linux-image-2.6.28-19-generic 2.6.28-19.62
linux-image-2.6.28-19-imx51 2.6.28-19.62
linux-image-2.6.28-19-iop32x 2.6.28-19.62
linux-image-2.6.28-19-ixp4xx 2.6.28-19.62
linux-image-2.6.28-19-lpia 2.6.28-19.62
linux-image-2.6.28-19-server 2.6.28-19.62
linux-image-2.6.28-19-versatile 2.6.28-19.62
linux-image-2.6.28-19-virtual 2.6.28-19.62

Ubuntu 9.10:
linux-image-2.6.31-214-dove 2.6.31-214.29
linux-image-2.6.31-214-dove-z0 2.6.31-214.29
linux-image-2.6.31-22-386 2.6.31-22.61
linux-image-2.6.31-22-generic 2.6.31-22.61
linux-image-2.6.31-22-generic-pae 2.6.31-22.61
linux-image-2.6.31-22-ia64 2.6.31-22.61
linux-image-2.6.31-22-lpia 2.6.31-22.61
linux-image-2.6.31-22-powerpc 2.6.31-22.61
linux-image-2.6.31-22-powerpc-smp 2.6.31-22.61
linux-image-2.6.31-22-powerpc64-smp 2.6.31-22.61
linux-image-2.6.31-22-server 2.6.31-22.61
linux-image-2.6.31-22-sparc64 2.6.31-22.61
linux-image-2.6.31-22-sparc64-smp 2.6.31-22.61
linux-image-2.6.31-22-virtual 2.6.31-22.61
linux-image-2.6.31-307-ec2 2.6.31-307.16

Ubuntu 10.04 LTS:
linux-image-2.6.32-207-dove 2.6.32-207.21
linux-image-2.6.32-24-386 2.6.32-24.39
linux-image-2.6.32-24-generic 2.6.32-24.39
linux-image-2.6.32-24-generic-pae 2.6.32-24.39
linux-image-2.6.32-24-ia64 2.6.32-24.39
linux-image-2.6.32-24-lpia 2.6.32-24.39
linux-image-2.6.32-24-powerpc 2.6.32-24.39
linux-image-2.6.32-24-powerpc-smp 2.6.32-24.39
linux-image-2.6.32-24-powerpc64-smp 2.6.32-24.39
linux-image-2.6.32-24-preempt 2.6.32-24.39
linux-image-2.6.32-24-server 2.6.32-24.39
linux-image-2.6.32-24-sparc64 2.6.32-24.39
linux-image-2.6.32-24-sparc64-smp 2.6.32-24.39
linux-image-2.6.32-24-versatile 2.6.32-24.39
linux-image-2.6.32-24-virtual 2.6.32-24.39
linux-image-2.6.32-308-ec2 2.6.32-308.14
linux-image-2.6.33-502-omap 2.6.33-502.9

After a standard system update you need to reboot your computer to make
all the necessary changes.

Details follow:

Junjiro R. Okajima discovered that knfsd did not correctly handle
strict overcommit. A local attacker could exploit this to crash knfsd,
leading to a denial of service. (Only Ubuntu 6.06 LTS and 8.04 LTS were
affected.) (CVE-2008-7256, CVE-2010-1643)

Chris Guo, Jukka Taimisto, and Olli Jarva discovered that SCTP did
not correctly handle invalid parameters. A remote attacker could send
specially crafted traffic that could crash the system, leading to a
denial of service. (CVE-2010-1173)

Mario Mikocevic discovered that GFS2 did not correctly handle certain
quota structures. A local attacker could exploit this to crash the
system, leading to a denial of service. (Ubuntu 6.06 LTS was not
affected.) (CVE-2010-1436)

Toshiyuki Okajima discovered that the kernel keyring did not correctly
handle dead keyrings. A local attacker could exploit this to crash the
system, leading to a denial of service. (CVE-2010-1437)

Brad Spengler discovered that Sparc did not correctly implement
non-executable stacks. This made userspace applications vulnerable to
exploits that would have been otherwise blocked due to non-executable
memory protections. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1451)

Dan Rosenberg discovered that the btrfs clone function did not correctly
validate permissions. A local attacker could exploit this to read
sensitive information, leading to a loss of privacy. (Only Ubuntu 9.10
was affected.) (CVE-2010-1636)

Dan Rosenberg discovered that GFS2 set_flags function did not correctly
validate permissions. A local attacker could exploit this to gain
access to files, leading to a loss of privacy and potential privilege
escalation. (Ubuntu 6.06 LTS was not affected.) (CVE-2010-1641)

Shi Weihua discovered that btrfs xattr_set_acl function did not
correctly validate permissions. A local attacker could exploit
this to gain access to files, leading to a loss of privacy and
potential privilege escalation. (Only Ubuntu 9.10 and 10.04 LTS were
affected.) (CVE-2010-2071)

Andre Osterhues discovered that eCryptfs did not correctly calculate
hash values. A local attacker with certain uids could exploit this to
crash the system or potentially gain root privileges. (Ubuntu 6.06 LTS
was not affected.) (CVE-2010-2492)

Articoli Correlati

  • No Related Posts

USN-964-2: Likewise Open regression

Description: 
===========================================================
Ubuntu Security Notice USN-964-2 July 29, 2010
likewise-open regression
https://launchpad.net/bugs/610300
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 10.04 LTS:
likewise-open 5.4.0.42111-2ubuntu1.2

In general, a standard system update will make all the necessary changes.

Details follow:

USN-964-1 fixed vulnerabilities in Likewise Open. The upstream fixes
were incomplete, which caused problems running certain services. This
update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Matt Weatherford discovered that Likewise Open did not correctly check
password expiration for the local-provider account. A local attacker could
exploit this to log into a system they would otherwise not have access to.

Articoli Correlati

  • No Related Posts

Firma digitale: dal 3 settembre 2010 in vigore nuove regole tecniche

Il 3 settembre p.v. entrano in vigore le modifiche alla firma digitale approvate con deliberazione n. 45/2009 dal Centro Nazionale per l’Informatica nella Pubblica Amministrazione (CNIPA) (pubblicata in Gazzetta Ufficiale lo scorso 3 dicembre).

Le nuove regole tecniche, che han modificato i formati delle firme digitali, sono supportate da tutte le Smart Card e dalle Business Key distribuite, tranne che dalle smart card con numero di serie che inizia con 1202… (il numero di serie è riportato sulla carta).

I possessori di tali carte possono richiedere il rilascio di un nuovo dispositivo (Business Key) allo sportello Servizi Telematici della Camera di Commercio di Venezia (sede di Mestre, Via Forte Marghera, 151 – tel. 041.2576612 – email: infosmartcard@ve.camcom.it – orario di sportello: dal lunedì al venerdì, dalle 8,45 alle 12,30).

È in corso da parte di Infocert S.p.A.l’invio di un’apposita comunicazione sull’argomento a tutti i titolari delle tessere in questione.

Da tale data devono essere sostituiti i programmi di firma dei documenti per poter apporre le nuove firme e verificare tutti i documenti firmati. Nel dettaglio la deliberazione prevede l’utilizzo di nuovi algoritmi matematici e nuovi formati dei dati per innalzare ulteriormente il livello di sicurezza, mantenendo inalterato il valore legale delle firme. Il nuovo software sarà disponibile dal 3 settembre 2010. Comunque in fase di aggiornamento dei vecchi programmi verrà richiesto di effettuare l’adeguamento alla nuova versione.
Per ulteriori approfondimenti su come richiedere la Business Key e sui costi relativi consulta la sezione del sito camerale http://www.ve.camcom.it/registro_imp/pagina.phtml?pagina=business_key&explode=40.3.1.

Articoli Correlati

ICT in Italia

Per riprendere la discussione sulle cause del ritardo tecnologico in Italia e della mancanza di competitività, vi riporto alcuni dati trovati in un rapporto in un sito del Governo Italiano.

Utilizzatori di Internet:

Indicatori Italia Francia Germania Spagna Regno Unito
Donne Online 32% 64% 71% 53% 66%
Ragazzi 16-24 online 91% 92% 97% 90% 96%
Adulti 55-74 online 13% 36% 38% 15% 44%
Utenti B2C online 7% 28% 63% 40% 49%

Mi sembra non ci sia nulla da commentare su questi numeri.

Ma continuiamo con altri indicatori:

Descrizione 2008 EU27 (2008) Ranking
Copertura DSL (in percentuale della popolazione) 95,0 91,4 12
Diffusione della banda larga (in percentuale della  popolazione) 19,0 22,9 16
Velocità di connessione (% contratti con velocità superiore 2 Mbps) 67,4 52,5 11
% famiglie connesse ad Internet 47 60 21
% damiglie con connessione a banda larga 31 49 24
% aziende con accesso a banda larga 81 81 14
% popolazione che utilizza frequentemente internet (ogni giorno o quasi) 35 43 19
% servizi pubblici base ai cittadini interamente disponibili online 58(2007) 51 9
% servizi pubblici base alle imprese interamente disponibili online 88(2007 72 manca
% di imprese che vendono online 3 16 24
% popolazione che utilizza servizi di e-Governement 15 (era 17 nel 2007) 28 23
% imprese che utilizza servizi di e-Governement 82 (era 87 nel 2006) 68 9
% imprese che acquistano online 12 28 18

Sono dati sconfortanti.

Leggendo i numeri poi si vede uno scollamento impressionante tra offerta pubblica e effettivo utilizzo: a fronte di percentuali alte di servizi offerti dalle istituzioni (fra i più alti in Europa) emerge in fatto che siamo tra le nazioni che li utilizzano meno. Quindi: o i servizi sono inutili (soldi pubblici spesi per niente) oppure non si è informati, oppure sono servizi che non servono o scarsamente fruibili.

Sono dati che dovrebbero essere ben presi in considerazione.

Articoli Correlati