USN-971-1: OpenJDK vulnerabilities

Referenced CVEs: 
CVE-2010-2548, CVE-2010-2783

Description: 
===========================================================
Ubuntu Security Notice USN-971-1 August 16, 2010
openjdk-6 vulnerabilities
CVE-2010-2548, CVE-2010-2783
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 9.04:
icedtea6-plugin 6b18-1.8.1-0ubuntu1~9.04.1

Ubuntu 9.10:
icedtea6-plugin 6b18-1.8.1-0ubuntu1~9.10.1

Ubuntu 10.04 LTS:
icedtea6-plugin 6b18-1.8.1-0ubuntu1

After a standard system update you need to restart any Java applications
to make all the necessary changes.

Details follow:

It was discovered that the IcedTea plugin did not correctly check certain
accesses. If a user or automated system were tricked into running a
specially crafted Java applet, a remote attacker could read arbitrary
files with user privileges, leading to a loss of privacy. (CVE-2010-2548,
CVE-2010-2783)

Articoli Correlati

  • No Related Posts

USN-970-1: GnuPG2 vulnerability

Referenced CVEs: 
CVE-2010-2547

Description: 
===========================================================
Ubuntu Security Notice USN-970-1 August 11, 2010
gnupg2 vulnerability
CVE-2010-2547
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.04 LTS:
gpgsm 2.0.7-1ubuntu0.1

Ubuntu 9.04:
gpgsm 2.0.9-3.1ubuntu0.1

Ubuntu 9.10:
gpgsm 2.0.12-0ubuntu2.1

Ubuntu 10.04 LTS:
gpgsm 2.0.14-1ubuntu1.2

In general, a standard system update will make all the necessary changes.

Details follow:

It was discovered that GPGSM in GnuPG2 did not correctly handle
certificates with a large number of Subject Alternate Names. If a user or
automated system were tricked into processing a specially crafted
certificate, an attacker could cause a denial of service or execute
arbitrary code with privileges of the user invoking the program.

Articoli Correlati

  • No Related Posts

USN-965-1: OpenLDAP vulnerabilities

Referenced CVEs: 
CVE-2010-0211, CVE-2010-0212

Description: 
===========================================================
Ubuntu Security Notice USN-965-1 August 09, 2010
openldap, openldap2.2, openldap2.3 vulnerabilities
CVE-2010-0211, CVE-2010-0212
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
slapd 2.2.26-5ubuntu2.10

Ubuntu 8.04 LTS:
slapd 2.4.9-0ubuntu0.8.04.4

Ubuntu 9.04:
slapd 2.4.15-1ubuntu3.1

Ubuntu 9.10:
slapd 2.4.18-0ubuntu1.1

Ubuntu 10.04 LTS:
slapd 2.4.21-0ubuntu5.2

In general, a standard system update will make all the necessary changes.

Details follow:

Using the Codenomicon LDAPv3 test suite, Ilkka Mattila and Tuomas
Salomäki discovered that the slap_modrdn2mods function in modrdn.c
in OpenLDAP does not check the return value from a call to the
smr_normalize function. A remote attacker could use specially crafted
modrdn requests to crash the slapd daemon or possibly execute arbitrary
code. (CVE-2010-0211)

Using the Codenomicon LDAPv3 test suite, Ilkka Mattila and Tuomas
Salomäki discovered that OpenLDAP does not properly handle empty
RDN strings. A remote attacker could use specially crafted modrdn
requests to crash the slapd daemon. (CVE-2010-0212)

In the default installation under Ubuntu 8.04 LTS and later, attackers
would be isolated by the OpenLDAP AppArmor profile for the slapd daemon.

Articoli Correlati

  • No Related Posts

USN-967-1: w3m vulnerability

Referenced CVEs: 
CVE-2010-2074

Description: 
===========================================================
Ubuntu Security Notice USN-967-1 August 09, 2010
w3m vulnerability
CVE-2010-2074
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
w3m 0.5.1-4ubuntu2.6.06.1

Ubuntu 8.04 LTS:
w3m 0.5.1-5.1ubuntu1.1

Ubuntu 9.04:
w3m 0.5.2-2ubuntu0.1

Ubuntu 9.10:
w3m 0.5.2-2ubuntu1.1

Ubuntu 10.04 LTS:
w3m 0.5.2-2.1ubuntu1.1

After a standard system update you need to restart any running instances
of w3m to effect the necessary changes.

Details follow:

Ludwig Nussel discovered w3m does not properly handle SSL/TLS
certificates with NULL characters in the certificate name. An
attacker could exploit this to perform a man in the middle
attack to view sensitive information or alter encrypted
communications. (CVE-2010-2074)

Articoli Correlati

  • No Related Posts

USN-969-1: PCSC-Lite vulnerability

Referenced CVEs: 
CVE-2009-4901, CVE-2009-4902, CVE-2010-0407

Description: 
===========================================================
Ubuntu Security Notice USN-969-1 August 05, 2010
pcsc-lite vulnerability
CVE-2009-4901, CVE-2009-4902, CVE-2010-0407
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 9.04:
pcscd 1.4.102-1ubuntu2.1

Ubuntu 9.10:
pcscd 1.5.3-1ubuntu1.1

Ubuntu 10.04 LTS:
pcscd 1.5.3-1ubuntu4.1

In general, a standard system update will make all the necessary changes.

Details follow:

It was discovered that the PC/SC service did not correctly handle
malformed messages. A local attacker could exploit this to execute
arbitrary code with root privileges.

Articoli Correlati

  • No Related Posts

USN-966-1: Linux kernel vulnerabilities

Referenced CVEs: 
CVE-2008-7256, CVE-2010-1173, CVE-2010-1436, CVE-2010-1437, CVE-2010-1451, CVE-2010-1636, CVE-2010-1641, CVE-2010-1643, CVE-2010-2071, CVE-2010-2492

Description: 
===========================================================
Ubuntu Security Notice USN-966-1 August 04, 2010
linux, linux-{source-2.6.15,ec2,mvl-dove,ti-omap} vulnerabilities
CVE-2008-7256, CVE-2010-1173, CVE-2010-1436, CVE-2010-1437,
CVE-2010-1451, CVE-2010-1636, CVE-2010-1641, CVE-2010-1643,
CVE-2010-2071, CVE-2010-2492
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
linux-image-2.6.15-55-386 2.6.15-55.86
linux-image-2.6.15-55-686 2.6.15-55.86
linux-image-2.6.15-55-amd64-generic 2.6.15-55.86
linux-image-2.6.15-55-amd64-k8 2.6.15-55.86
linux-image-2.6.15-55-amd64-server 2.6.15-55.86
linux-image-2.6.15-55-amd64-xeon 2.6.15-55.86
linux-image-2.6.15-55-hppa32 2.6.15-55.86
linux-image-2.6.15-55-hppa32-smp 2.6.15-55.86
linux-image-2.6.15-55-hppa64 2.6.15-55.86
linux-image-2.6.15-55-hppa64-smp 2.6.15-55.86
linux-image-2.6.15-55-itanium 2.6.15-55.86
linux-image-2.6.15-55-itanium-smp 2.6.15-55.86
linux-image-2.6.15-55-k7 2.6.15-55.86
linux-image-2.6.15-55-mckinley 2.6.15-55.86
linux-image-2.6.15-55-mckinley-smp 2.6.15-55.86
linux-image-2.6.15-55-powerpc 2.6.15-55.86
linux-image-2.6.15-55-powerpc-smp 2.6.15-55.86
linux-image-2.6.15-55-powerpc64-smp 2.6.15-55.86
linux-image-2.6.15-55-server 2.6.15-55.86
linux-image-2.6.15-55-server-bigiron 2.6.15-55.86
linux-image-2.6.15-55-sparc64 2.6.15-55.86
linux-image-2.6.15-55-sparc64-smp 2.6.15-55.86

Ubuntu 8.04 LTS:
linux-image-2.6.24-28-386 2.6.24-28.73
linux-image-2.6.24-28-generic 2.6.24-28.73
linux-image-2.6.24-28-hppa32 2.6.24-28.73
linux-image-2.6.24-28-hppa64 2.6.24-28.73
linux-image-2.6.24-28-itanium 2.6.24-28.73
linux-image-2.6.24-28-lpia 2.6.24-28.73
linux-image-2.6.24-28-lpiacompat 2.6.24-28.73
linux-image-2.6.24-28-mckinley 2.6.24-28.73
linux-image-2.6.24-28-openvz 2.6.24-28.73
linux-image-2.6.24-28-powerpc 2.6.24-28.73
linux-image-2.6.24-28-powerpc-smp 2.6.24-28.73
linux-image-2.6.24-28-powerpc64-smp 2.6.24-28.73
linux-image-2.6.24-28-rt 2.6.24-28.73
linux-image-2.6.24-28-server 2.6.24-28.73
linux-image-2.6.24-28-sparc64 2.6.24-28.73
linux-image-2.6.24-28-sparc64-smp 2.6.24-28.73
linux-image-2.6.24-28-virtual 2.6.24-28.73
linux-image-2.6.24-28-xen 2.6.24-28.73

Ubuntu 9.04:
linux-image-2.6.28-19-generic 2.6.28-19.62
linux-image-2.6.28-19-imx51 2.6.28-19.62
linux-image-2.6.28-19-iop32x 2.6.28-19.62
linux-image-2.6.28-19-ixp4xx 2.6.28-19.62
linux-image-2.6.28-19-lpia 2.6.28-19.62
linux-image-2.6.28-19-server 2.6.28-19.62
linux-image-2.6.28-19-versatile 2.6.28-19.62
linux-image-2.6.28-19-virtual 2.6.28-19.62

Ubuntu 9.10:
linux-image-2.6.31-214-dove 2.6.31-214.29
linux-image-2.6.31-214-dove-z0 2.6.31-214.29
linux-image-2.6.31-22-386 2.6.31-22.61
linux-image-2.6.31-22-generic 2.6.31-22.61
linux-image-2.6.31-22-generic-pae 2.6.31-22.61
linux-image-2.6.31-22-ia64 2.6.31-22.61
linux-image-2.6.31-22-lpia 2.6.31-22.61
linux-image-2.6.31-22-powerpc 2.6.31-22.61
linux-image-2.6.31-22-powerpc-smp 2.6.31-22.61
linux-image-2.6.31-22-powerpc64-smp 2.6.31-22.61
linux-image-2.6.31-22-server 2.6.31-22.61
linux-image-2.6.31-22-sparc64 2.6.31-22.61
linux-image-2.6.31-22-sparc64-smp 2.6.31-22.61
linux-image-2.6.31-22-virtual 2.6.31-22.61
linux-image-2.6.31-307-ec2 2.6.31-307.16

Ubuntu 10.04 LTS:
linux-image-2.6.32-207-dove 2.6.32-207.21
linux-image-2.6.32-24-386 2.6.32-24.39
linux-image-2.6.32-24-generic 2.6.32-24.39
linux-image-2.6.32-24-generic-pae 2.6.32-24.39
linux-image-2.6.32-24-ia64 2.6.32-24.39
linux-image-2.6.32-24-lpia 2.6.32-24.39
linux-image-2.6.32-24-powerpc 2.6.32-24.39
linux-image-2.6.32-24-powerpc-smp 2.6.32-24.39
linux-image-2.6.32-24-powerpc64-smp 2.6.32-24.39
linux-image-2.6.32-24-preempt 2.6.32-24.39
linux-image-2.6.32-24-server 2.6.32-24.39
linux-image-2.6.32-24-sparc64 2.6.32-24.39
linux-image-2.6.32-24-sparc64-smp 2.6.32-24.39
linux-image-2.6.32-24-versatile 2.6.32-24.39
linux-image-2.6.32-24-virtual 2.6.32-24.39
linux-image-2.6.32-308-ec2 2.6.32-308.14
linux-image-2.6.33-502-omap 2.6.33-502.9

After a standard system update you need to reboot your computer to make
all the necessary changes.

Details follow:

Junjiro R. Okajima discovered that knfsd did not correctly handle
strict overcommit. A local attacker could exploit this to crash knfsd,
leading to a denial of service. (Only Ubuntu 6.06 LTS and 8.04 LTS were
affected.) (CVE-2008-7256, CVE-2010-1643)

Chris Guo, Jukka Taimisto, and Olli Jarva discovered that SCTP did
not correctly handle invalid parameters. A remote attacker could send
specially crafted traffic that could crash the system, leading to a
denial of service. (CVE-2010-1173)

Mario Mikocevic discovered that GFS2 did not correctly handle certain
quota structures. A local attacker could exploit this to crash the
system, leading to a denial of service. (Ubuntu 6.06 LTS was not
affected.) (CVE-2010-1436)

Toshiyuki Okajima discovered that the kernel keyring did not correctly
handle dead keyrings. A local attacker could exploit this to crash the
system, leading to a denial of service. (CVE-2010-1437)

Brad Spengler discovered that Sparc did not correctly implement
non-executable stacks. This made userspace applications vulnerable to
exploits that would have been otherwise blocked due to non-executable
memory protections. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1451)

Dan Rosenberg discovered that the btrfs clone function did not correctly
validate permissions. A local attacker could exploit this to read
sensitive information, leading to a loss of privacy. (Only Ubuntu 9.10
was affected.) (CVE-2010-1636)

Dan Rosenberg discovered that GFS2 set_flags function did not correctly
validate permissions. A local attacker could exploit this to gain
access to files, leading to a loss of privacy and potential privilege
escalation. (Ubuntu 6.06 LTS was not affected.) (CVE-2010-1641)

Shi Weihua discovered that btrfs xattr_set_acl function did not
correctly validate permissions. A local attacker could exploit
this to gain access to files, leading to a loss of privacy and
potential privilege escalation. (Only Ubuntu 9.10 and 10.04 LTS were
affected.) (CVE-2010-2071)

Andre Osterhues discovered that eCryptfs did not correctly calculate
hash values. A local attacker with certain uids could exploit this to
crash the system or potentially gain root privileges. (Ubuntu 6.06 LTS
was not affected.) (CVE-2010-2492)

Articoli Correlati

  • No Related Posts

USN-968-1: Dell Latitude 2110 vulnerability

Referenced CVEs: 
CVE-2010-0834

Description: 
===========================================================
Ubuntu Security Notice USN-968-1 August 05, 2010
base-files vulnerability
CVE-2010-0834
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 9.10:
base-files 5.0.0ubuntu7.1

Ubuntu 10.04 LTS:
base-files 5.0.0ubuntu20.10.04.2

In general, a standard system update will make all the necessary changes.

Details follow:

It was discovered that the Ubuntu image shipped on some Dell Latitude
2110 systems was accidentally configured to allow unauthenticated package
installations. A remote attacker intercepting network communications or
a malicious archive mirror server could exploit this to trick the user
into installing unsigned packages, resulting in arbitrary code execution
with root privileges.

Articoli Correlati

  • No Related Posts

USN-964-2: Likewise Open regression

Description: 
===========================================================
Ubuntu Security Notice USN-964-2 July 29, 2010
likewise-open regression
https://launchpad.net/bugs/610300
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 10.04 LTS:
likewise-open 5.4.0.42111-2ubuntu1.2

In general, a standard system update will make all the necessary changes.

Details follow:

USN-964-1 fixed vulnerabilities in Likewise Open. The upstream fixes
were incomplete, which caused problems running certain services. This
update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Matt Weatherford discovered that Likewise Open did not correctly check
password expiration for the local-provider account. A local attacker could
exploit this to log into a system they would otherwise not have access to.

Articoli Correlati

  • No Related Posts

Internet, nuovo virus on line: occhio alle email con la mappa degli autovelox

Roma – (Adnkronos) – Email, aventi come falso mittente la polizia, forniscono un link per consultare l’elenco aggiornato delle postazioni fisse autovelox. In realtà cliccando si installa un virus che ‘cattura’ informazioni sensibili contenute nel computer

Roma, 30 lug. (Adnkronos) – La polizia postale mette in guardia da una nuova truffa che da ieri sera circola online: email, aventi come falso mittente la polizia, nelle quali si dà la possibilità di consultare l’elenco aggiornato delle postazioni fisse autovelox e a tale scopo viene fornito un link. In realtà cliccando si installa un virus molto insidioso che ‘cattura’ informazioni sensibili contenute nel computer.

Scopo di queste mail ‘truffaldine’, dietro le quali spesso si nasconde la mano della criminalità organizzata, è accedere ad esempio ai conti correnti bancari. ”Abbiamo già allertato le forze di polizia locali colombiane e ucraine, dove si trovano i server a cui rimanda il link – spiega all’ADNKRONOS Nunzia Ciardi, una dirigente della Polizia Postale e delle Comunicazioni – Sappiamo che stanno circolando centinaia di migliaia di queste mail, che possono trarre in inganno perché prendono spunto da un testo pubblicato sul sito della polizia ma poi rimandano a un link che se viene cliccato scarica un virus capace di catturare le informazioni sensibili”.
”Le truffe più comuni sono quelle che, servendosi di pagine clonate dai siti degli istituti bancari comunicano al cliente la modifica delle modalità di accesso – prosegue Ciardi – chiedendogli di fornire username e password: a quel punto possono avere accesso al conto e il gioco è fatto”. Nel caso degli autovelox, invece, ”è la prima volta che scopriamo una truffa del genere.
Forse hanno pensato di approfittare dell’esodo estivo, in modo da rendere più credibile la truffa”.

La polizia consiglia di cestinare l’e-mail evitando di cliccare sul link e di tenere sempre aggiornato il proprio antivirus.

fonte: http://www.adnkronos.com/IGN/News/Cronaca/?id=3.1.756431152

Articoli Correlati

Pubblicati i dettagli di 100 milioni di account Facebook

Ron Bowes, sviluppatore del noto tool nmap, ha scritto un piccolo programma di scansione e lo ha lanciato sugli account pubblici di Facebook.

Il risultato? Un bel file di 2.8 GB contenente oltre 100 milioni di account dei quali è possibile sapere nome, cognome, ID, e molte altre informazioni lasciate pubblice.

Mi ricordo un’altra provocazione del genere di poco tempo fa: su un sito si mostrava chi non era a casa, raccogliendo i dati da questo sito social.

Comunque ecco una bella intervista dell’autore di questo “furto”:

Ron Bowes, a security consultant, used a piece of code to scan Facebook profiles, collecting data not hidden by the user’s privacy settings.

The list, which contains the URL of every searchable Facebook user’s profile, name and unique ID, has been shared as a downloadable file.

Mr Bowes told BBC News that he did it as part of his work on a security tool.

“I’m a developer for the Nmap Security Scanner and one of our recent tools is called Ncrack,” he said.

“It is designed to test password policies of organisations by using brute force attacks; in other words, guessing every username and password combination.”

By downloading the data from Facebook, and compiling a user’s first initial and surname, he was able to make a list of the most common probable usernames to use in the tool.

The three most common names, he found, were jsmith, ssmith and skhan.

In theory, researchers could then combine this list with a catalogue of the most commonly used passwords to test the security of sites. Similar techniques could be used by criminals for more nefarious means.

Mr Bowes said his original plan was to “collect a good list of human names that could be used for these tests”.

“Once I had the data, though, I realised that it could be of interest to the community if I released it, so I did,” he added.

Mr Bowes confirmed that all the data he harvested was already publicly available but acknowledged that if anyone now changed their privacy settings, their information would still be accessible.

“If 100,000 Facebook users decide that they no longer want to be in Facebook’s directory, I would still have their name and URL but it would no longer, technically, be public,” he said.

Mr Bowes said that collecting the data was in no way irresponsible and likened it to a telephone directory.

“All I’ve done is compile public information into a nice format for statistical analysis,” he said

Simon Davies from the watchdog Privacy International told BBC News it was an “ethical attack” and that more personal information had not been included in the trawl.

“This is a reputational and business issue for Facebook, for now,” he said

“They can continue to ride the risk and hope nothing cataclysmic occurs, but I would argue that Facebook has a special responsibility to go beyond doing the bare minimum,” he added.

Snowball effect

Mr Bowes’ file has spread rapidly across the net.

On the Pirate Bay, the world’s biggest file-sharing website, the list was being distributed and downloaded by thousands of users.

One user said that the list showed “why people need to read the privacy agreements and everything they click through”.

In a statement to BBC News, Facebook confirmed that the information in the list was already freely available online.

“No private data is available or has been compromised,” the statement added.

That view is shared by Mr Bowes, who added that harvesting this data highlighted the possible risks users put themselves in.

“I am of the belief that, if I can do something then there are about 1,000 bad guys that can do it too.

“For that reason, I believe in open disclosure of issues like this, especially when there’s minimal potential for anybody to get hurt.

“Since this is already public information, I see very little harm in disclosing it.”

Digital trends

However, he said, it also highlighted a new trend that was emerging in the digital age.

“With traditional paper media, it wasn’t possible to compile 170 million records in a searchable format and distribute it, but now we can,” he said.

“Having the name of one person means nothing, and having the name of a hundred people means nothing; it isn’t statistically significant.

“But when you start scaling to 170 million, statistical data emerges that we have never seen in the past.”

A spokesperson for Facebook said the list was “similar to the white pages of the phone book.

“This is the information available to enable people to find each other, which is the reason people join Facebook.”

“If someone does not want to be found, we also offer a number of controls to enable people not to appear in search on Facebook, in search engines, or share any information with applications.”

Earlier this year there was a storm of protest from users of the site over the complexity of Facebook’s privacy settings. As a result, the site rolled out simplified privacy controls.

Facebook has a default setting for privacy that makes some user information publicly available. People have to make a conscious choice to opt-out of the defaults.

Articoli Correlati