Mozilla: importanti aggiornamenti per Firefox e Thunderbird

Da mozillaitalia.

Firefox:

È disponibile per il download la versione 3.6.7 di Firefox (note di versione). Questo aggiornamento risolve diversi problemi di sicurezza e stabilità dell’applicazione.

Gli utenti che già utilizzano Firefox 3.6.6 riceveranno automaticamente l’aggiornamento in queste ore; ricordiamo che è comunque possibile avviare manualmente la ricerca degli aggiornamenti attraverso l’apposito comando nel menu Aiuto.

È disponibile per il download anche la versione 3.5.11 di Firefox (note di versione). Questo aggiornamento risolve alcuni problemi di sicurezza e stabilità della precedente versione.

Gli utenti che già utilizzano Firefox 3.5.x riceveranno automaticamente l’aggiornamento in queste ore; ricordiamo che è comunque possibile avviare manualmente la ricerca degli aggiornamenti attraverso l’apposito comando nel menu Aiuto.

Ricordiamo che il ramo 3.0.x non è più supportato. Per questo motivo consigliamo di effettuare quanto prima il passaggio alla versione 3.6 (dopo aver verificato i requisiti di sistema).

Thunderbird:

È disponibile per il download Mozilla Thunderbird 3.1.1 in italiano (note di versione in inglese). Questo aggiornamento risolve diversi problemi di sicurezza e stabilità della precedente versione, invitiamo pertanto tutti gli utenti ad installarlo.

Gli utenti della versione 3.1 del client di posta riceveranno automaticamente l’aggiornamento nelle prossime ore; è comunque possibile cercare manualmente gli aggiornamenti disponibili attraverso l’apposito comando presente nel menu Aiuto.

È inoltre disponibile per il download Mozilla Thunderbird 3.0.6 in italiano (note di versione in inglese). Questo aggiornamento corregge diverse criticità segnalate su BugZilla, invitiamo pertanto tutti gli utenti ad installarlo.

Gli utenti della versione 3.0.5 del client di posta riceveranno automaticamente l’aggiornamento nelle prossime ore; è comunque possibile cercare manualmente gli aggiornamenti disponibili attraverso l’apposito comando presente nel menu Aiuto.

Ricordiamo a coloro che ancora stiano usando la versione 1.5 che tale versione non è più supportata da Mozilla, presto lo sarà anche il ramo 2.0.x; consigliamo perciò di effettuare l’aggiornamento alla versione 3.0.5 (dopo aver verificato i requisiti di sistema)

Articoli Correlati

USN-963-1: FreeType vulnerabilities

Referenced CVEs: 
CVE-2010-2498, CVE-2010-2499, CVE-2010-2500, CVE-2010-2519, CVE-2010-2520, CVE-2010-2527

Description: 
===========================================================
Ubuntu Security Notice USN-963-1 July 20, 2010
freetype vulnerabilities
CVE-2010-2498, CVE-2010-2499, CVE-2010-2500, CVE-2010-2519,
CVE-2010-2520, CVE-2010-2527
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
libfreetype6 2.1.10-1ubuntu2.7

Ubuntu 8.04 LTS:
libfreetype6 2.3.5-1ubuntu4.8.04.3

Ubuntu 9.04:
libfreetype6 2.3.9-4ubuntu0.2

Ubuntu 9.10:
libfreetype6 2.3.9-5ubuntu0.1

Ubuntu 10.04 LTS:
libfreetype6 2.3.11-1ubuntu2.1

After a standard system update you need to restart your session to make
all the necessary changes.

Details follow:

Robert Święcki discovered that FreeType did not correctly handle certain
malformed font files. If a user were tricked into using a specially crafted
font file, a remote attacker could execute arbitrary code with user
privileges.

Articoli Correlati

  • No Related Posts

USN-962-1: VTE vulnerability

Referenced CVEs: 
CVE-2010-2713

Description: 
===========================================================
Ubuntu Security Notice USN-962-1 July 15, 2010
vte vulnerability
CVE-2010-2713
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 9.04:
libvte9 1:0.20.0-0ubuntu2.1

Ubuntu 9.10:
libvte9 1:0.22.2-0ubuntu2.1

Ubuntu 10.04 LTS:
libvte9 1:0.23.5-0ubuntu1.1

After a standard system update you need to restart your session to make
all the necessary changes.

Details follow:

Janne Snabb discovered that applications using VTE, such as gnome-terminal,
did not correctly filter window and icon title request escape codes. If a
user were tricked into viewing specially crafted output in their terminal,
a remote attacker could execute arbitrary commands with user privileges.

Articoli Correlati

  • No Related Posts

USN-961-1: Ghostscript vulnerabilities

Referenced CVEs: 
CVE-2009-4270, CVE-2009-4897, CVE-2010-1628, CVE-2010-1869

Description: 
===========================================================
Ubuntu Security Notice USN-961-1 July 13, 2010
ghostscript vulnerabilities
CVE-2009-4270, CVE-2009-4897, CVE-2010-1628, CVE-2010-1869
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.04 LTS:
libgs8 8.61.dfsg.1-1ubuntu3.3

Ubuntu 9.04:
libgs8 8.64.dfsg.1-0ubuntu8.1

Ubuntu 9.10:
libgs8 8.70.dfsg.1-0ubuntu3.1

Ubuntu 10.04 LTS:
libgs8 8.71.dfsg.1-0ubuntu5.2

In general, a standard system update will make all the necessary changes.

Details follow:

David Srbecky discovered that Ghostscript incorrectly handled debug
logging. If a user or automated system were tricked into opening a crafted
PDF file, an attacker could cause a denial of service or execute arbitrary
code with privileges of the user invoking the program. This issue only
affected Ubuntu 9.04 and Ubuntu 9.10. The default compiler options for
affected releases should reduce the vulnerability to a denial of service.
(CVE-2009-4270)

It was discovered that Ghostscript incorrectly handled certain malformed
files. If a user or automated system were tricked into opening a crafted
Postscript or PDF file, an attacker could cause a denial of service or
execute arbitrary code with privileges of the user invoking the program.
This issue only affected Ubuntu 8.04 LTS and Ubuntu 9.04. (CVE-2009-4897)

Dan Rosenberg discovered that Ghostscript incorrectly handled certain
recursive Postscript files. If a user or automated system were tricked into
opening a crafted Postscript file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program. (CVE-2010-1628)

Rodrigo Rubira Branco and Dan Rosenberg discovered that Ghostscript
incorrectly handled certain malformed Postscript files. If a user or
automated system were tricked into opening a crafted Postscript file, an
attacker could cause a denial of service or execute arbitrary code with
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS, 9.04 and 9.10. (CVE-2010-1869)

Articoli Correlati

  • No Related Posts

USN-959-1: PAM vulnerability

Referenced CVEs: 
CVE-2010-0832

Description: 
===========================================================
Ubuntu Security Notice USN-959-1 July 07, 2010
pam vulnerability
CVE-2010-0832
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 9.10:
libpam-modules 1.1.0-2ubuntu1.1

Ubuntu 10.04 LTS:
libpam-modules 1.1.1-2ubuntu5

In general, a standard system update will make all the necessary changes.

Details follow:

Denis Excoffier discovered that the PAM MOTD module in Ubuntu did
not correctly handle path permissions when creating user file stamps.
A local attacker could exploit this to gain root privilieges.

Articoli Correlati

  • No Related Posts

USN-960-1: libpng vulnerabilities

Referenced CVEs: 
CVE-2010-1205, CVE-2010-2249

Description: 
===========================================================
Ubuntu Security Notice USN-960-1 July 08, 2010
libpng vulnerabilities
CVE-2010-1205, CVE-2010-2249
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
libpng12-0 1.2.8rel-5ubuntu0.6

Ubuntu 8.04 LTS:
libpng12-0 1.2.15~beta5-3ubuntu0.3

Ubuntu 9.04:
libpng12-0 1.2.27-2ubuntu2.2

Ubuntu 9.10:
libpng12-0 1.2.37-1ubuntu0.2

Ubuntu 10.04 LTS:
libpng12-0 1.2.42-1ubuntu2.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

Details follow:

It was discovered that libpng did not properly handle certain malformed PNG
images. If a user or automated system were tricked into opening a crafted
PNG file, an attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2010-1205)

It was discovered that libpng did not properly handle certain malformed PNG
images. If a user or automated system were tricked into processing a
crafted PNG image, an attacker could possibly use this flaw to consume all
available resources, resulting in a denial of service. (CVE-2010-2249)

Articoli Correlati

  • No Related Posts

USN-956-1: sudo vulnerability

Referenced CVEs: 
CVE-2010-1646

Description: 
===========================================================
Ubuntu Security Notice USN-956-1 June 30, 2010
sudo vulnerability
CVE-2010-1646
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
sudo 1.6.8p12-1ubuntu6.3
sudo-ldap 1.6.8p12-1ubuntu6.3

Ubuntu 8.04 LTS:
sudo 1.6.9p10-1ubuntu3.8
sudo-ldap 1.6.9p10-1ubuntu3.8

Ubuntu 9.04:
sudo 1.6.9p17-1ubuntu3.3
sudo-ldap 1.6.9p17-1ubuntu3.3

Ubuntu 9.10:
sudo 1.7.0-1ubuntu2.4
sudo-ldap 1.7.0-1ubuntu2.4

Ubuntu 10.04 LTS:
sudo 1.7.2p1-1ubuntu5.1
sudo-ldap 1.7.2p1-1ubuntu5.1

In general, a standard system update will make all the necessary changes.

Details follow:

Evan Broder and Anders Kaseorg discovered that sudo did not properly
sanitize its environment when configured to use secure_path (the default in
Ubuntu). A local attacker could exploit this to execute arbitrary code as
root if sudo was configured to allow the attacker to use a program that
interpreted the PATH environment variable.

Articoli Correlati

  • No Related Posts

USN-943-1: Thunderbird vulnerabilities

Referenced CVEs: 
CVE-2010-1121, CVE-2010-1196, CVE-2010-1199, CVE-2010-1200, CVE-2010-1201, CVE-2010-1202, CVE-2010-1203

Description: 
===========================================================
Ubuntu Security Notice USN-943-1 July 06, 2010
thunderbird vulnerabilities
CVE-2010-1121, CVE-2010-1196, CVE-2010-1199, CVE-2010-1200,
CVE-2010-1201, CVE-2010-1202, CVE-2010-1203
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 10.04 LTS:
thunderbird 3.0.5+build2+nobinonly-0ubuntu0.10.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

Details follow:

Martin Barbella discovered an integer overflow in an XSLT node sorting
routine. An attacker could exploit this to overflow a buffer and cause a
denial of service or possibly execute arbitrary code with the privileges of
the user invoking the program. (CVE-2010-1199)

An integer overflow was discovered in Thunderbird. If a user were tricked
into viewing malicious content, an attacker could overflow a buffer and
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-1196)

Several flaws were discovered in the browser engine of Thunderbird. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,
CVE-2010-1202, CVE-2010-1203)

If was discovered that Thunderbird could be made to access freed memory. If
a user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-1121)

Articoli Correlati

  • No Related Posts

Ubuntu 10.4 e sun java 6

Capita di dover utilizzare il pacchetto java di sun.

Ma nell’ultima versione di ubuntu, non ci sono i repositary della versione.

Nessuna paura:

Disinstallate, se installata, la versine openjdk con

  1. sudo apt-get remove openjdk-6-jre
  2. seguita da sudo apt-get autoremove

e quindi

  1. sudo add-apt-repository “deb http://archive.canonical.com/ lucid partner”  && sudo apt-get update &&  sudo apt-get install sun-java6-jre sun-java6-jdk sun-java6-plugin sun-java6-fonts

Rispondete alle domande che il sistema vi porrà ed aspettate la fine dell’installazione.

E’ tutto.

Articoli Correlati

Aria di pensionamento in casa Microsoft

Aria di pensionamento in casa Microsoft.

Oggi, martedi’ 13 luglio è l’ultimo giorno utile per ottenere supporto per Microsoft Windows XP SP2. Da oggi, chi deciderà di rimanere con questa versione del sistema operativo non riceverà più patch di sicurezza. Dovrà necessariamente passare a Microsoft Windows XP service pack 3 oppure a Windows 7.

L’8 aprile 2014 invece terminerà il supporto anche per Microsoft Windows XP SP3, e in quel momento il glorioso sistema operativo di Microsoft sarà definitivamente pensionato.

Passando a Windows 2000, sia nella versione client che server, oggi è l’ultimo giorno di supporto. Da domani sarà pensionato anche questo sistema operativo.

Anche per Windows 2003 oggi è una data importante. Da oggi parte il supporto esteso, saranno rilasciate solo le patch di sicurezza per poi pensionarlo definitivamente il 13 luglio 2015.

Articoli Correlati