RHSA-2017:2493-1: Important: Red Hat JBoss Web Server 2 security update

Red Hat Enterprise Linux: An update is now available for Red Hat JBoss Enterprise Web Server 2.1.2 for Red
Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Web Server 2.1.2 for Red Hat
Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives
a detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.
CVE-2016-6304, CVE-2016-8610, CVE-2017-5647, CVE-2017-5664

Read More

RHSA-2017:2492-1: Moderate: xmlsec1 security update

Red Hat Enterprise Linux: An update for xmlsec1 is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact of
Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a
detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.
CVE-2017-1000061

Read More

USN-3397-1: strongSwan vulnerability

Ubuntu Security Notice USN-3397-1

21st August, 2017

strongswan vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 17.04
  • Ubuntu 16.04 LTS
  • Ubuntu 14.04 LTS

Summary

strongSwan could be made to crash or hang if it received specially crafted
network traffic.

Software description

  • strongswan
    – IPsec VPN solution

Details

It was discovered that strongSwan incorrectly handled verifying
specific RSA signatures. A remote attacker could use this issue
to cause strongSwan to crash, resulting in a denial of service.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 17.04:
libstrongswan

5.5.1-1ubuntu3.2
strongswan

5.5.1-1ubuntu3.2
Ubuntu 16.04 LTS:
libstrongswan

5.3.5-1ubuntu3.4
strongswan

5.3.5-1ubuntu3.4
Ubuntu 14.04 LTS:
libstrongswan

5.1.2-0ubuntu2.7
strongswan

5.1.2-0ubuntu2.7

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References

CVE-2017-11185

Read More

USN-3398-1: graphite2 vulnerabilities

Ubuntu Security Notice USN-3398-1

21st August, 2017

graphite2 vulnerabilities

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 17.04
  • Ubuntu 16.04 LTS
  • Ubuntu 14.04 LTS

Summary

graphite2 could be made to crash or run programs if it opened a specially
crafted font.

Software description

  • graphite2
    – Font rendering engine for Complex Scripts

Details

Holger Fuhrmannek and Tyson Smith discovered that graphite2 incorrectly
handled certain malformed fonts. If a user or automated system were tricked
into opening a specially-crafted font file, a remote attacker could use
this issue to cause graphite2 to crash, resulting in a denial of service,
or possibly execute arbitrary code.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 17.04:
libgraphite2-3

1.3.10-0ubuntu0.17.04.1
Ubuntu 16.04 LTS:
libgraphite2-3

1.3.10-0ubuntu0.16.04.1
Ubuntu 14.04 LTS:
libgraphite2-3

1.3.10-0ubuntu0.14.04.1

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart applications
using graphite2, such as LibreOffice, to make all the necessary changes.

References

CVE-2017-7771,

CVE-2017-7772,

CVE-2017-7773,

CVE-2017-7774,

CVE-2017-7775,

CVE-2017-7776,

CVE-2017-7777,

CVE-2017-7778

Read More

USN-3399-1: cvs vulnerability

Ubuntu Security Notice USN-3399-1

21st August, 2017

cvs vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 17.04
  • Ubuntu 16.04 LTS
  • Ubuntu 14.04 LTS

Summary

cvs could be made run programs as your login if it opened a
specially crafted cvs repository.

Software description

  • cvs
    – Concurrent Versions System

Details

Hank Leininger discovered that cvs did not properly handle SSH
for remote repositories. A remote attacker could use this to
construct a cvs repository that when accessed could run arbitrary
code with the privileges of the user.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 17.04:
cvs

2:1.12.13+real-22ubuntu0.1
Ubuntu 16.04 LTS:
cvs

2:1.12.13+real-15ubuntu0.1
Ubuntu 14.04 LTS:
cvs

2:1.12.13+real-12ubuntu0.1

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References

CVE-2017-12836

Read More

USN-3400-1: Augeas vulnerability

Ubuntu Security Notice USN-3400-1

21st August, 2017

augeas vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 17.04
  • Ubuntu 16.04 LTS
  • Ubuntu 14.04 LTS

Summary

Augeas could be made to crash if it received specially crafted
input.

Software description

  • augeas
    – Configuration editing tool

Details

It was discovered that Augeas incorrectly handled certain strings.
An attacker could use this issue to cause Augeas to crash, leading
to a denial of service, or possibly execute arbitrary code.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 17.04:
augeas-tools

1.6.0-0ubuntu3.1
libaugeas0

1.6.0-0ubuntu3.1
Ubuntu 16.04 LTS:
augeas-tools

1.4.0-0ubuntu1.1
libaugeas0

1.4.0-0ubuntu1.1
Ubuntu 14.04 LTS:
augeas-tools

1.2.0-0ubuntu1.3
libaugeas0

1.2.0-0ubuntu1.3

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References

CVE-2017-7555

Read More

PS4 Controller Battery Level Extension for the GNOME Desktop

dual shock 4 battery level extensionUsing a DualShock 4 controller on Ubuntu? If so, you may find the following new GNOME extension a handy thing to have around. It’s called ‘Dual Shock 4 battery percentage’ and, in an unexpected and not at all predictable twist, it lets you see PS4 controller battery level on the GNOME desktop. Nothing more, and […]

This post, PS4 Controller Battery Level Extension for the GNOME Desktop, was written by Joey Sneddon and first appeared on OMG! Ubuntu!.

Read More

MellowPlayer is a Cross-Platform Qt Cloud Music App

MellowPlayer is a Qt cloud music app for Linux, Windows and Mac. Never heard of it? I can’t say I had, either. But a reader of this site, and a fan of MellowPlayer,  asked if I could write a few lines about its latest release. MellowPlayer is a Qt Cloud Music Player If you’ve been […]

This post, MellowPlayer is a Cross-Platform Qt Cloud Music App, was written by Joey Sneddon and first appeared on OMG! Ubuntu!.

Read More

Docker Enterprise Now Runs Windows and Linux in One Cluster

With the newest Docker Enterprise Edition, you can now have Docker clusters composed of nodes running different operating systems.

Three of the key OSes supported by Docker—Windows, Linux, and IBM System Z—can run applications side by side in the same cluster, all orchestrated by a common mechanism.

Clustering apps across multiple OSes in Docker requires that you build per-OS images for each app. But those apps, when running on both Windows and Linux, can be linked to run in concert via Docker’s overlay networking.

Read More