Friday, June 10, 2016

[USN-3001-1] Linux kernel (Vivid HWE) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXWlcgAAoJEAUvNnAY1cPYQCkP/RMIJl0VU6qmcUO65+YBOeqh
Om4anZ25RugmY1o7ApFsJTjM8e3J0UIRXAcOexgb3VJjCaj3jASoD1zEteBZoK4D
oRXvRHztcqmLg2FUwZUnTIa9WWzE+QnNmVyN1XPoQxNVmtHuTOVhaUt6V9Zmd/qD
Ttk7Jg8TMGxT6e8tux4eRsS0YxjHF9k5ad155CDpuKj3MjE1B4b3ZMWIh9ZNj40M
PjLFypUyq0TVIHLWkJglishF+ZPRn+Ihaz59AKoEjpUQQo0gw8Iq1LUuK4XtfJpa
bchqgD3xgC6Fn1OrYf/RuzrErWldVpQFcFOIcl0dtapv9RgSmk3ORUkVlaqNcbra
O6nzqxIseFfdPNCNA2xZnxpdqKTYCDbGDRaWT1P4P8M2mpoJxEgdulhejKjbtYjS
YN5Hnu5L63osEwZYlan15vox9k0sFF1KUg2qzeS8Y+X1utBF+8Bgn4nPoSb/fJgT
TsR4Cs/sfFC0SLfBArELnTc532TNrzHz2YQYMsLnE3na2POwjyykAa1uQTojrUjz
xRwObx7fsCviRdHkEirZ3IQavTeGFUi6qm4PWqUrfa2rtaHaoNo0TJgyFgKAjFme
9Y1sLkc7nr/8+BzWt7Dui8j7XWKUtA5Z12b4Etbo69pkA92BtgKd1j1pyx/ef00n
36VUP3Iz/VRdWdlJLOcQ
=CfTK
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3001-1
June 10, 2016

linux-lts-vivid vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-lts-vivid: Linux hardware enablement kernel from Vivid for Trusty

Details:

Justin Yackoski discovered that the Atheros L2 Ethernet Driver in the Linux
kernel incorrectly enables scatter/gather I/O. A remote attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-2117)

Jann Horn discovered that eCryptfs improperly attempted to use the mmap()
handler of a lower filesystem that did not implement one, causing a
recursive page fault to occur. A local unprivileged attacker could use to
cause a denial of service (system crash) or possibly execute arbitrary code
with administrative privileges. (CVE-2016-1583)

Jason A. Donenfeld discovered multiple out-of-bounds reads in the OZMO USB
over wifi device drivers in the Linux kernel. A remote attacker could use
this to cause a denial of service (system crash) or obtain potentially
sensitive information from kernel memory. (CVE-2015-4004)

Ralf Spenneberg discovered that the Linux kernel's GTCO digitizer USB
device driver did not properly validate endpoint descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2187)

Hector Marco and Ismael Ripoll discovered that the Linux kernel would
improperly disable Address Space Layout Randomization (ASLR) for x86
processes running in 32 bit mode if stack-consumption resource limits were
disabled. A local attacker could use this to make it easier to exploit an
existing vulnerability in a setuid/setgid program. (CVE-2016-3672)

Andrey Konovalov discovered that the CDC Network Control Model USB driver
in the Linux kernel did not cancel work events queued if a later error
occurred, resulting in a use-after-free. An attacker with physical access
could use this to cause a denial of service (system crash). (CVE-2016-3951)

It was discovered that an out-of-bounds write could occur when handling
incoming packets in the USB/IP implementation in the Linux kernel. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-3955)

Vitaly Kuznetsov discovered that the Linux kernel did not properly suppress
hugetlbfs support in X86 paravirtualized guests. An attacker in the guest
OS could cause a denial of service (guest system crash). (CVE-2016-3961)

Kangjie Lu discovered an information leak in the ANSI/IEEE 802.2 LLC type 2
Support implementations in the Linux kernel. A local attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-4485)

Kangjie Lu discovered an information leak in the routing netlink socket
interface (rtnetlink) implementation in the Linux kernel. A local attacker
could use this to obtain potentially sensitive information from kernel
memory. (CVE-2016-4486)

Jann Horn discovered that the InfiniBand interfaces within the Linux kernel
could be coerced into overwriting kernel memory. A local unprivileged
attacker could use this to possibly gain administrative privileges on
systems where InifiniBand related kernel modules are loaded.
(CVE-2016-4565)

It was discovered that in some situations the Linux kernel did not handle
propagated mounts correctly. A local unprivileged attacker could use this
to cause a denial of service (system crash). (CVE-2016-4581)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
linux-image-3.19.0-61-generic 3.19.0-61.69~14.04.1
linux-image-3.19.0-61-generic-lpae 3.19.0-61.69~14.04.1
linux-image-3.19.0-61-lowlatency 3.19.0-61.69~14.04.1
linux-image-3.19.0-61-powerpc-e500mc 3.19.0-61.69~14.04.1
linux-image-3.19.0-61-powerpc-smp 3.19.0-61.69~14.04.1
linux-image-3.19.0-61-powerpc64-emb 3.19.0-61.69~14.04.1
linux-image-3.19.0-61-powerpc64-smp 3.19.0-61.69~14.04.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-3001-1
CVE-2015-4004, CVE-2016-1583, CVE-2016-2117, CVE-2016-2187,
CVE-2016-3672, CVE-2016-3951, CVE-2016-3955, CVE-2016-3961,
CVE-2016-4485, CVE-2016-4486, CVE-2016-4565, CVE-2016-4581

Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-vivid/3.19.0-61.69~14.04.1

[USN-3000-1] Linux kernel (Utopic HWE) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXWlcKAAoJEAUvNnAY1cPYSnQQAJIPOEEsTxficDWb5d5UUhlK
PRyGpCtWP7tRc9sQdEUtkFVz3AXsGrcX+2n1nTm2U30k4cftRmhhQG6C/suaoPjc
FohICJkFzJ0t54TdiiS7+okq4ON1TG8zES79Q9kvp0uAdyQx2v1DYuFwqnMJdA3M
JKmjNVbnsk7KQgT8C3tVLHwwpbpiPsI8RoVNcNyhRt9j9rvnpfKlNBjjJRYptOjO
xvVRdITBfWGeCqC96LgswGZ30H6t2/B8p5iGzGKkGCtMEtzWktWHvMzAw5dNy1qx
t2zE7qEYYrR/6EXtcH2jyYMSNvtCHKYhlrjzV8mUUTa6v+jpvDDqr/rWiWwlW7YS
8KOq5nUNbSEXesm7UuSNIv32c2cZ73mdVsupzaxyxwzpN1/YLo8y/ldYmoZ9FMBA
3bD8uhWHIr2trAQgluX+DphOIRql3QyGjcO17xBYvEW+i7QjC1iVnVbcWZkhDPsd
btoJsIEY4QETKlR97m2UDVgw10cJ0MhCKaKbow/nTauG7Beq1Z5H1d9hGOk9TsL4
wJX+EBhDm0oU+Ofw68ALMT+S8ORgUXH6LdOTdb5DF3IHB2V4qxPIdcV6u8g8FINB
FYWCr+O7c1BOazI0chvxvQf9ahvVpQMEumWLXT330DIr846EY8+7mGOLtLdddscD
SUMqEIpGeSGDrqgLSJWG
=qP+q
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3000-1
June 10, 2016

linux-lts-utopic vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-lts-utopic: Linux hardware enablement kernel from Utopic for Trusty

Details:

Justin Yackoski discovered that the Atheros L2 Ethernet Driver in the Linux
kernel incorrectly enables scatter/gather I/O. A remote attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-2117)

Jann Horn discovered that eCryptfs improperly attempted to use the mmap()
handler of a lower filesystem that did not implement one, causing a
recursive page fault to occur. A local unprivileged attacker could use to
cause a denial of service (system crash) or possibly execute arbitrary code
with administrative privileges. (CVE-2016-1583)

Jason A. Donenfeld discovered multiple out-of-bounds reads in the OZMO USB
over wifi device drivers in the Linux kernel. A remote attacker could use
this to cause a denial of service (system crash) or obtain potentially
sensitive information from kernel memory. (CVE-2015-4004)

Ralf Spenneberg discovered that the Linux kernel's GTCO digitizer USB
device driver did not properly validate endpoint descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2187)

Sergej Schumilo, Hendrik Schwartke, and Ralf Spenneberg discovered that the
MCT USB RS232 Converter device driver in the Linux kernel did not properly
validate USB device descriptors. An attacker with physical access could use
this to cause a denial of service (system crash). (CVE-2016-3136)

Sergej Schumilo, Hendrik Schwartke, and Ralf Spenneberg discovered that the
Cypress M8 USB device driver in the Linux kernel did not properly validate
USB device descriptors. An attacker with physical access could use this to
cause a denial of service (system crash). (CVE-2016-3137)

Sergej Schumilo, Hendrik Schwartke, and Ralf Spenneberg discovered that the
Linux kernel's USB driver for Digi AccelePort serial converters did not
properly validate USB device descriptors. An attacker with physical access
could use this to cause a denial of service (system crash). (CVE-2016-3140)

Hector Marco and Ismael Ripoll discovered that the Linux kernel would
improperly disable Address Space Layout Randomization (ASLR) for x86
processes running in 32 bit mode if stack-consumption resource limits were
disabled. A local attacker could use this to make it easier to exploit an
existing vulnerability in a setuid/setgid program. (CVE-2016-3672)

It was discovered that the Linux kernel's USB driver for IMS Passenger
Control Unit devices did not properly validate the device's interfaces. An
attacker with physical access could use this to cause a denial of service
(system crash). (CVE-2016-3689)

Andrey Konovalov discovered that the CDC Network Control Model USB driver
in the Linux kernel did not cancel work events queued if a later error
occurred, resulting in a use-after-free. An attacker with physical access
could use this to cause a denial of service (system crash). (CVE-2016-3951)

It was discovered that an out-of-bounds write could occur when handling
incoming packets in the USB/IP implementation in the Linux kernel. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-3955)

Kangjie Lu discovered an information leak in the ANSI/IEEE 802.2 LLC type 2
Support implementations in the Linux kernel. A local attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-4485)

Kangjie Lu discovered an information leak in the routing netlink socket
interface (rtnetlink) implementation in the Linux kernel. A local attacker
could use this to obtain potentially sensitive information from kernel
memory. (CVE-2016-4486)

It was discovered that in some situations the Linux kernel did not handle
propagated mounts correctly. A local unprivileged attacker could use this
to cause a denial of service (system crash). (CVE-2016-4581)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
linux-image-3.16.0-73-generic 3.16.0-73.95~14.04.1
linux-image-3.16.0-73-generic-lpae 3.16.0-73.95~14.04.1
linux-image-3.16.0-73-lowlatency 3.16.0-73.95~14.04.1
linux-image-3.16.0-73-powerpc-e500mc 3.16.0-73.95~14.04.1
linux-image-3.16.0-73-powerpc-smp 3.16.0-73.95~14.04.1
linux-image-3.16.0-73-powerpc64-emb 3.16.0-73.95~14.04.1
linux-image-3.16.0-73-powerpc64-smp 3.16.0-73.95~14.04.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-3000-1
CVE-2015-4004, CVE-2016-1583, CVE-2016-2117, CVE-2016-2187,
CVE-2016-3136, CVE-2016-3137, CVE-2016-3140, CVE-2016-3672,
CVE-2016-3689, CVE-2016-3951, CVE-2016-3955, CVE-2016-4485,
CVE-2016-4486, CVE-2016-4581

Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-73.95~14.04.1

[USN-2999-1] Linux kernel vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXWlbyAAoJEAUvNnAY1cPYrCcP/Rn3UdyhWHlgpYyOq8wGqXZE
un4rkD9WmByOkDhdx8mmv29SevevI3dPYs4OAnVifAiYWlGXSlTkcKa6cKnBBTK2
0iSTgH+K+jEQ9cIT1Lkqu5rC5G54/FoXe0YW+mAocGiTmidmA6lavFYkFqWnKo+h
xdCzR4sEmoW6xMvc/8BU5cdtFS04rBHymuF5tbktRvi3ZB7uofZxz4SXU0w6HA7j
CxpbDEy6iOTrsL+8P76pvErNDwkA/2XA2+qP06eyh5ClQXZzb4BK5Gjg/WS+Uw6E
DfGfhuPW2udUvnHs22Ovvunxl1FrUENoP3Gh7TbLZUMks/UEnzTrxUbWExTpxIiR
4bThMM0RumaulvBQicT8aJMomy3kZjJZOk8kz9qvBLLmTQxYw6oANWXilZ6VFpli
ysiBDKKnnFin4EWrooWF7XaPnicPtHxBEtu3X758PNF/3GmW0PqxbqE8ZSkdl/I3
PKfQ8SMNLTqgarPHDhDeE+GhjribZoyhisv46Vz6DaKhvwT8FgxKCDZN4v1Kfq8a
/vk2Pzmrdg1+cK++Q64SFUtuffg91kxFPDfh3g2/Svmczbal2s6DjXXszyxYgbTD
q0iIGuYj7xDS1Nu/vg7VebHQFz2/hK7t7Lqtnf5LWYajQZv7S11kGk1hgzPTkTc2
FLOmNxpcHrXqobDZLaRs
=+CZ4
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2999-1
June 10, 2016

linux vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

The system could be made to crash or run programs as an administrator.

Software Description:
- linux: Linux kernel

Details:

Jann Horn discovered that eCryptfs improperly attempted to use the mmap()
handler of a lower filesystem that did not implement one, causing a
recursive page fault to occur. A local unprivileged attacker could use to
cause a denial of service (system crash) or possibly execute arbitrary code
with administrative privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
linux-image-3.13.0-88-generic 3.13.0-88.135
linux-image-3.13.0-88-generic-lpae 3.13.0-88.135
linux-image-3.13.0-88-lowlatency 3.13.0-88.135
linux-image-3.13.0-88-powerpc-e500 3.13.0-88.135
linux-image-3.13.0-88-powerpc-e500mc 3.13.0-88.135
linux-image-3.13.0-88-powerpc-smp 3.13.0-88.135
linux-image-3.13.0-88-powerpc64-emb 3.13.0-88.135
linux-image-3.13.0-88-powerpc64-smp 3.13.0-88.135

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-2999-1
CVE-2016-1583

Package Information:
https://launchpad.net/ubuntu/+source/linux/3.13.0-88.135

[USN-2998-1] Linux kernel (Trusty HWE) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXWlbbAAoJEAUvNnAY1cPY9vUQAJKnSs6iTvP4A6jmSy6qRnQL
BvpL02cPqiKHf8/wpSiu9fKs5RVildo3whwTrWU5RePQPIqrs2KRMm7lVBaFY3W/
amrI7L4NBp8T1D216hWhliebUUfHx+XdZgWXqxIrqOiJoFi0LoNSwRiJScGcqtOK
UscbUmugbIU7bLRvraf/cbrUQziFdbvAYGQnppnoFNvdmEE/6bwCnFNVnt9mNX7+
PHC+aAgRgF6uJippURygrwsBDEikU0nPI7CfFYd1+7D38ZdIDnA0Hj1+LKr3nITN
swUvcwvc7tedM7dgfAiZJA0zukcJy5ZQLzroKd/beBIitUat9JO1fZTLW0Z6LQOf
Q2KD9CEqHBctzXDgYDUIKXoO5l1FJCMtdxl9AWprCiNMQPEzhVruP81VgK8Ov+ft
gjwpnBdaPirXFlqa2PVnl+PzZDVr0r7En9/GOpuwRbS2pMj31Si1xUIevvYNbAP9
181RFsmvUuVoRR/aauXUWlOkNepdDtlj5A83qE5eZJtwAQJbflD5gXeJwmICZD7v
PQaUj9kTrE0WdEbbkstcr9insqEbAcRcPudIeDE6kTALxtMATRhTdUZm0uXNWjHH
Gx1Vbdb4i74pys2gBts2nspRjCfmPrePl5/0WRqB+ipKMvXB6W8vTgRmZUJM4QFv
yAmgsuxja+2UPPNXcLc9
=VZOe
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2998-1
June 10, 2016

linux-lts-trusty vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-lts-trusty: Linux hardware enablement kernel from Trusty for Precise

Details:

Justin Yackoski discovered that the Atheros L2 Ethernet Driver in the Linux
kernel incorrectly enables scatter/gather I/O. A remote attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-2117)

Jann Horn discovered that eCryptfs improperly attempted to use the mmap()
handler of a lower filesystem that did not implement one, causing a
recursive page fault to occur. A local unprivileged attacker could use to
cause a denial of service (system crash) or possibly execute arbitrary code
with administrative privileges. (CVE-2016-1583)

Jason A. Donenfeld discovered multiple out-of-bounds reads in the OZMO USB
over wifi device drivers in the Linux kernel. A remote attacker could use
this to cause a denial of service (system crash) or obtain potentially
sensitive information from kernel memory. (CVE-2015-4004)

Andy Lutomirski discovered a race condition in the Linux kernel's
translation lookaside buffer (TLB) handling of flush events. A local
attacker could use this to cause a denial of service or possibly leak
sensitive information. (CVE-2016-2069)

Ralf Spenneberg discovered that the Linux kernel's GTCO digitizer USB
device driver did not properly validate endpoint descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2187)

Hector Marco and Ismael Ripoll discovered that the Linux kernel would
improperly disable Address Space Layout Randomization (ASLR) for x86
processes running in 32 bit mode if stack-consumption resource limits were
disabled. A local attacker could use this to make it easier to exploit an
existing vulnerability in a setuid/setgid program. (CVE-2016-3672)

Andrey Konovalov discovered that the CDC Network Control Model USB driver
in the Linux kernel did not cancel work events queued if a later error
occurred, resulting in a use-after-free. An attacker with physical access
could use this to cause a denial of service (system crash). (CVE-2016-3951)

It was discovered that an out-of-bounds write could occur when handling
incoming packets in the USB/IP implementation in the Linux kernel. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-3955)

Kangjie Lu discovered an information leak in the ANSI/IEEE 802.2 LLC type 2
Support implementations in the Linux kernel. A local attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-4485)

Kangjie Lu discovered an information leak in the routing netlink socket
interface (rtnetlink) implementation in the Linux kernel. A local attacker
could use this to obtain potentially sensitive information from kernel
memory. (CVE-2016-4486)

It was discovered that in some situations the Linux kernel did not handle
propagated mounts correctly. A local unprivileged attacker could use this
to cause a denial of service (system crash). (CVE-2016-4581)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
linux-image-3.13.0-88-generic 3.13.0-88.135~precise1
linux-image-3.13.0-88-generic-lpae 3.13.0-88.135~precise1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-2998-1
CVE-2015-4004, CVE-2016-1583, CVE-2016-2069, CVE-2016-2117,
CVE-2016-2187, CVE-2016-3672, CVE-2016-3951, CVE-2016-3955,
CVE-2016-4485, CVE-2016-4486, CVE-2016-4581

Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-88.135~precise1

[USN-2997-1] Linux kernel (OMAP4) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXWlbDAAoJEAUvNnAY1cPYIOsQAIc1FEkUlTMRU4lh864zxQsf
R+uFi3cvRJrKGgUWZRVF/UVyiWw87UIGIOZahUgNrkD3I0az9EEUcTD5+HhFP6Ce
7S2Fo1wmr6yKDb+yVM+eutFFLiAJExsY6fKPnIZr3iUMIjidYgRyxtj5Zfgd04ef
248uXJkRYhGP0lMHoZT4AJyhKw1HSJjBGMvXOrOogFO+l9kSUD8C6E4AsVSUBhQo
NplXY+BKSrKdF4LEWNzUfHPV5lquWBeWXA+ELLbx7QpjBj7wjzBki7n0T06vkAmf
iFDu40bAhdHkzqtNM6mAJ87YStzRY58PUoSTlBRIsw9qOYTKnU16OJp5Tj1vqPEJ
lJyQosPPjNWxaVcdT3R8IZ2dxKlsPXrqE86mp9vSj77k8zzmuLUyOomCVPy2/LCW
hRhDaWM1doVIJT5V5e8i2fnx3O2Vdh8w7hNLysFtUCtiONtYDPX4KxIzseAH0sqx
lEyFzpIflN3ol3tKqol01Vqi66zEwWpwTwHXwQODbGZYInzhKMr2vl/Nf9de74v2
YYn6oulGeHBvl9gNdSLvqiPVMnSEn1vebtSEk9fFcTPhplk7H9JSOgFyiBsKfXAC
t3LWSMFEThgcpgUhqDsxF5pNbWWFvjnolETnpT6OXobe5fAsaIMjMU2UOl8KEGQj
wDNqSYBO01QPkXt+V+w1
=mPGi
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2997-1
June 10, 2016

linux-ti-omap4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-ti-omap4: Linux kernel for OMAP4

Details:

Jann Horn discovered that eCryptfs improperly attempted to use the mmap()
handler of a lower filesystem that did not implement one, causing a
recursive page fault to occur. A local unprivileged attacker could use to
cause a denial of service (system crash) or possibly execute arbitrary code
with administrative privileges. (CVE-2016-1583)

Ralf Spenneberg discovered that the USB sound subsystem in the Linux kernel
did not properly validate USB device descriptors. An attacker with physical
access could use this to cause a denial of service (system crash).
(CVE-2016-2184)

Ralf Spenneberg discovered that the ATI Wonder Remote II USB driver in the
Linux kernel did not properly validate USB device descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2185)

Ralf Spenneberg discovered that the PowerMate USB driver in the Linux
kernel did not properly validate USB device descriptors. An attacker with
physical access could use this to cause a denial of service (system crash).
(CVE-2016-2186)

Ralf Spenneberg discovered that the Linux kernel's GTCO digitizer USB
device driver did not properly validate endpoint descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2187)

Ralf Spenneberg discovered that the I/O-Warrior USB device driver in the
Linux kernel did not properly validate USB device descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2188)

Sergej Schumilo, Hendrik Schwartke, and Ralf Spenneberg discovered that the
MCT USB RS232 Converter device driver in the Linux kernel did not properly
validate USB device descriptors. An attacker with physical access could use
this to cause a denial of service (system crash). (CVE-2016-3136)

Sergej Schumilo, Hendrik Schwartke, and Ralf Spenneberg discovered that the
Cypress M8 USB device driver in the Linux kernel did not properly validate
USB device descriptors. An attacker with physical access could use this to
cause a denial of service (system crash). (CVE-2016-3137)

Sergej Schumilo, Hendrik Schwartke, and Ralf Spenneberg discovered that the
USB abstract device control driver for modems and ISDN adapters did not
validate endpoint descriptors. An attacker with physical access could use
this to cause a denial of service (system crash). (CVE-2016-3138)

Sergej Schumilo, Hendrik Schwartke, and Ralf Spenneberg discovered that the
Linux kernel's USB driver for Digi AccelePort serial converters did not
properly validate USB device descriptors. An attacker with physical access
could use this to cause a denial of service (system crash). (CVE-2016-3140)

It was discovered that the IPv4 implementation in the Linux kernel did not
perform the destruction of inet device objects properly. An attacker in a
guest OS could use this to cause a denial of service (networking outage) in
the host OS. (CVE-2016-3156)

Andy Lutomirski discovered that the Linux kernel did not properly context-
switch IOPL on 64-bit PV Xen guests. An attacker in a guest OS could use
this to cause a denial of service (guest OS crash), gain privileges, or
obtain sensitive information. (CVE-2016-3157)

Hector Marco and Ismael Ripoll discovered that the Linux kernel would
improperly disable Address Space Layout Randomization (ASLR) for x86
processes running in 32 bit mode if stack-consumption resource limits were
disabled. A local attacker could use this to make it easier to exploit an
existing vulnerability in a setuid/setgid program. (CVE-2016-3672)

It was discovered that an out-of-bounds write could occur when handling
incoming packets in the USB/IP implementation in the Linux kernel. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-3955)

Kangjie Lu discovered an information leak in the ANSI/IEEE 802.2 LLC type 2
Support implementations in the Linux kernel. A local attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-4485)

Kangjie Lu discovered an information leak in the routing netlink socket
interface (rtnetlink) implementation in the Linux kernel. A local attacker
could use this to obtain potentially sensitive information from kernel
memory. (CVE-2016-4486)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
linux-image-3.2.0-1482-omap4 3.2.0-1482.109

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-2997-1
CVE-2016-1583, CVE-2016-2184, CVE-2016-2185, CVE-2016-2186,
CVE-2016-2187, CVE-2016-2188, CVE-2016-3136, CVE-2016-3137,
CVE-2016-3138, CVE-2016-3140, CVE-2016-3156, CVE-2016-3157,
CVE-2016-3672, CVE-2016-3955, CVE-2016-4485, CVE-2016-4486

Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1482.109

[USN-2996-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXWlapAAoJEAUvNnAY1cPYFJ8P/17Zm3Jrt4wI9v+oOMKd4skc
jJhrtHMt4Ltr4ZEVVXKXl0ce0ap/HyxVlv0dqjp8rNsVFoiXM/uN9I+Lb2noozux
ajabPSjCfZZ9WhBmV2GhV3pNdt9DBtepuvFxvIeKzZe9ITQXHHS2VRGEIJriRp0V
h1ZZTPzWqAR1F6s+PPi9DTCSpO8zDA4+HRrfFhDoAMkryywric4w4xzKByAEKeWT
3lJKvDzuDgfmdiGwrr+PCTatGd+ABusVKDZQdLe5fvtDY3B9+Pi+KxRgT3CDWjLx
ASajcdS10XHoxpZnvVlTAd7jsNmPfOxSxpPRvFghJt/acQkzPuJZjYTImGtapX4D
DXkBREFaRxzbb537cDzJaxRGKYWveLxdkzk2D86sDEYzSCk1/sleXCmzqz0xnA22
dO1I4lLutE9m8rMJ+S421ltaK5gN5TIKXHg4pHAohXlYviAKsU//AW5scS4beoN9
p9s3sNBEy6u9CPkEYTgivsfR42avnQkZmje0e91jW+M8o0DV72QSu84EcsOMqNZT
OKjqNFw25PJaJI0at6447Zuo2AfnBg2s+fXZy2Lqsrb6DwIaDsJ6bpKvJBlGUTAH
TlzfPQikfN9UI5+I4HmJ68MQaMreoY5NHKU8hO8ZiKGGSTvzIjasN+N2LWt/8eNC
mss/oHlqWlZsPqSfXaNk
=XQB2
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2996-1
June 10, 2016

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

Jann Horn discovered that eCryptfs improperly attempted to use the mmap()
handler of a lower filesystem that did not implement one, causing a
recursive page fault to occur. A local unprivileged attacker could use to
cause a denial of service (system crash) or possibly execute arbitrary code
with administrative privileges. (CVE-2016-1583)

Ralf Spenneberg discovered that the USB sound subsystem in the Linux kernel
did not properly validate USB device descriptors. An attacker with physical
access could use this to cause a denial of service (system crash).
(CVE-2016-2184)

Ralf Spenneberg discovered that the ATI Wonder Remote II USB driver in the
Linux kernel did not properly validate USB device descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2185)

Ralf Spenneberg discovered that the PowerMate USB driver in the Linux
kernel did not properly validate USB device descriptors. An attacker with
physical access could use this to cause a denial of service (system crash).
(CVE-2016-2186)

Ralf Spenneberg discovered that the Linux kernel's GTCO digitizer USB
device driver did not properly validate endpoint descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2187)

Ralf Spenneberg discovered that the I/O-Warrior USB device driver in the
Linux kernel did not properly validate USB device descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2188)

Sergej Schumilo, Hendrik Schwartke, and Ralf Spenneberg discovered that the
MCT USB RS232 Converter device driver in the Linux kernel did not properly
validate USB device descriptors. An attacker with physical access could use
this to cause a denial of service (system crash). (CVE-2016-3136)

Sergej Schumilo, Hendrik Schwartke, and Ralf Spenneberg discovered that the
Cypress M8 USB device driver in the Linux kernel did not properly validate
USB device descriptors. An attacker with physical access could use this to
cause a denial of service (system crash). (CVE-2016-3137)

Sergej Schumilo, Hendrik Schwartke, and Ralf Spenneberg discovered that the
USB abstract device control driver for modems and ISDN adapters did not
validate endpoint descriptors. An attacker with physical access could use
this to cause a denial of service (system crash). (CVE-2016-3138)

Sergej Schumilo, Hendrik Schwartke, and Ralf Spenneberg discovered that the
Linux kernel's USB driver for Digi AccelePort serial converters did not
properly validate USB device descriptors. An attacker with physical access
could use this to cause a denial of service (system crash). (CVE-2016-3140)

It was discovered that the IPv4 implementation in the Linux kernel did not
perform the destruction of inet device objects properly. An attacker in a
guest OS could use this to cause a denial of service (networking outage) in
the host OS. (CVE-2016-3156)

Andy Lutomirski discovered that the Linux kernel did not properly context-
switch IOPL on 64-bit PV Xen guests. An attacker in a guest OS could use
this to cause a denial of service (guest OS crash), gain privileges, or
obtain sensitive information. (CVE-2016-3157)

Hector Marco and Ismael Ripoll discovered that the Linux kernel would
improperly disable Address Space Layout Randomization (ASLR) for x86
processes running in 32 bit mode if stack-consumption resource limits were
disabled. A local attacker could use this to make it easier to exploit an
existing vulnerability in a setuid/setgid program. (CVE-2016-3672)

It was discovered that an out-of-bounds write could occur when handling
incoming packets in the USB/IP implementation in the Linux kernel. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-3955)

Kangjie Lu discovered an information leak in the ANSI/IEEE 802.2 LLC type 2
Support implementations in the Linux kernel. A local attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-4485)

Kangjie Lu discovered an information leak in the routing netlink socket
interface (rtnetlink) implementation in the Linux kernel. A local attacker
could use this to obtain potentially sensitive information from kernel
memory. (CVE-2016-4486)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
linux-image-3.2.0-104-generic 3.2.0-104.145
linux-image-3.2.0-104-generic-pae 3.2.0-104.145
linux-image-3.2.0-104-highbank 3.2.0-104.145
linux-image-3.2.0-104-omap 3.2.0-104.145
linux-image-3.2.0-104-powerpc-smp 3.2.0-104.145
linux-image-3.2.0-104-powerpc64-smp 3.2.0-104.145
linux-image-3.2.0-104-virtual 3.2.0-104.145

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-2996-1
CVE-2016-1583, CVE-2016-2184, CVE-2016-2185, CVE-2016-2186,
CVE-2016-2187, CVE-2016-2188, CVE-2016-3136, CVE-2016-3137,
CVE-2016-3138, CVE-2016-3140, CVE-2016-3156, CVE-2016-3157,
CVE-2016-3672, CVE-2016-3955, CVE-2016-4485, CVE-2016-4486

Package Information:
https://launchpad.net/ubuntu/+source/linux/3.2.0-104.145

Thursday, June 9, 2016

Re: Fedora 24 Final Release Readiness Meeting on Thursday, June 9th @ 19:00 UTC

Hi,

during the meeting we were able to check the status with all the team
representatives and there is no know blocking issue, except the NO-GO
status as published at [1].
For more details please check the meeting minutes at [2][3].

Thanks all the participants on the meeting for coming and providing the status.

[1] https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org/thread/CCPEFDBYMHBNLTNG2CC57KUBBQOO67RD/
[2] https://meetbot.fedoraproject.org/fedora-meeting-1/2016-06-09/f24-final-readiness-meeting.2016-06-09-19.00.html
[3] https://meetbot.fedoraproject.org/fedora-meeting-1/2016-06-09/f24-final-readiness-meeting.2016-06-09-19.00.log.html

Regards,
Jan


On Mon, Jun 6, 2016 at 11:02 AM, Jan Kurik <jkurik@redhat.com> wrote:
> This Thursday, we will meet on irc.freenode.net in #fedora-meeting-1
> to make sure we are coordinated and ready for the release of Fedora 24
> on Tuesday, June 14th, 2016.
>
> Please note that this meeting will occur even if the release is
> delayed at the Go/No-Go meeting on the same day two hours earlier.
>
> The meeting is scheduled at 19:00 UTC. Please follow the [FedoCal]
> link to find the time of the meeting in your time-zone.
>
> [FedoCal] https://apps.fedoraproject.org/calendar/meeting/4105/
>
> You may received this message several times as this meeting is opened
> to all teams. I also hope this will raise awareness and more team
> representatives will come to this meeting. This meeting works best
> when we have representatives from all of the teams.
>
> Thanks for attending,
> Jan
> --
> Jan KuÅ™ík
> Platform & Fedora Program Manager
> Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic

--
Jan KuÅ™ík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/devel-announce@lists.fedoraproject.org

Fedora 24 Final status is NO-GO

The decision of the Fedora 24 Final Go/No-Go Meeting is NO-GO.

Due to a blocker bug [1] and subsequently missing Fedora 24 Final RC
compose it has been agreed on the Go/No-Go meeting to slip the Final
release of Fedora 24 for one week.
The next Go/No-Go meeting is planned on the next Thursday 2016-June-16
at 17:00 UTC.
More information can be found in the meeting minutes [2][3].

[1] https://qa.fedoraproject.org/blockerbugs/milestone/24/final/buglist
[2] https://meetbot.fedoraproject.org/fedora-meeting-1/2016-06-09/f24-final-go_no_go-meeting.2016-06-09-17.11.html
[3] https://meetbot.fedoraproject.org/fedora-meeting-1/2016-06-09/f24-final-go_no_go-meeting.2016-06-09-17.11.log.html
--
Jan KuÅ™ík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/devel-announce@lists.fedoraproject.org

[USN-2995-1] Squid vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXWapGAAoJEGVp2FWnRL6T8+oQAK+Hdgw8Z7Yb4bfR71/l4Uo+
gkW9ULWBN8HlR24VNoiVEseTfiRa+TW5idRrM8DKmdNihV2Wt23MqtixHXX+tl1U
Q3Uj4tgRWlV0FqDbe6e478AXwedKdAIQpPQQHjO/pnjEKasPwWbkw7lAAQkUkJX3
MrUe9gb6ZqkM1Ov79mrW696dO1XcENiDnwgIyeVCw/ZmZSLdISTvsN1/SOP9CF0N
VnhQjNuir70FDw8EERCY/lQcZRC7P9t7a/y4Atken7CLTjSVkaeq7nIjNh7di200
ZJG5RVHCkp7Hkkw4zBAVcXmjL9fxwumjs3fS5nRoHneMyXfb0W352AtADlKvFo9S
cwVQd1A/pKqPm4x993tOABM94w09xxtfr+QbArjudt3/iVhuIs66v1K8klv7ltNH
cFO4QmUZ5e0t2fPXF50YzP6QG/bf8I3BNNGopdhYGTjE+MC9O0u134FLPHPZn4HF
GGwpmT8wsodwF4T9GSQkLu6q+TmWktn1RtuLMzaBq9FVlQEkm4OPSSkaml/Eigx7
ZjoY/RyxMZUi0+i4vF7rgEqdEFa1MVKxu33SZS+ksEGBjKxaik2glrPuqlNdCNNH
+Xq2qEU2r7bNMHjdhVAMWJyJNRr3XKkniVnCKUDY8vC8C1YWtuwxskouVvZceMGp
x7w2rc8FPg0oR+9iDLow
=RhMk
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2995-1
June 09, 2016

squid3 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS
- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in Squid.

Software Description:
- squid3: Web proxy cache server

Details:

Yuriy M. Kaminskiy discovered that the Squid pinger utility incorrectly
handled certain ICMPv6 packets. A remote attacker could use this issue to
cause Squid to crash, resulting in a denial of service, or possibly cause
Squid to leak information into log files. (CVE-2016-3947)

Yuriy M. Kaminskiy discovered that the Squid cachemgr.cgi tool incorrectly
handled certain crafted data. A remote attacker could use this issue to
cause Squid to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2016-4051)

It was discovered that Squid incorrectly handled certain Edge Side Includes
(ESI) responses. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2016-4052, CVE-2016-4053, CVE-2016-4054)

Jianjun Chen discovered that Squid did not correctly ignore the Host header
when absolute-URI is provided. A remote attacker could possibly use this
issue to conduct cache-poisoning attacks. This issue only affected Ubuntu
14.04 LTS, Ubuntu 15.10 and Ubuntu 16.04 LTS. (CVE-2016-4553)

Jianjun Chen discovered that Squid incorrectly handled certain HTTP Host
headers. A remote attacker could possibly use this issue to conduct
cache-poisoning attacks. (CVE-2016-4554)

It was discovered that Squid incorrectly handled certain Edge Side Includes
(ESI) responses. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2016-4555,
CVE-2016-4556)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
squid-cgi 3.5.12-1ubuntu7.2
squid3 3.5.12-1ubuntu7.2

Ubuntu 15.10:
squid-cgi 3.3.8-1ubuntu16.3
squid3 3.3.8-1ubuntu16.3

Ubuntu 14.04 LTS:
squid-cgi 3.3.8-1ubuntu6.8
squid3 3.3.8-1ubuntu6.8

Ubuntu 12.04 LTS:
squid-cgi 3.1.19-1ubuntu3.12.04.7
squid3 3.1.19-1ubuntu3.12.04.7

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2995-1
CVE-2016-3947, CVE-2016-4051, CVE-2016-4052, CVE-2016-4053,
CVE-2016-4054, CVE-2016-4553, CVE-2016-4554, CVE-2016-4555,
CVE-2016-4556

Package Information:
https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2
https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu16.3
https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8
https://launchpad.net/ubuntu/+source/squid3/3.1.19-1ubuntu3.12.04.7

[USN-2993-1] Firefox vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJXWYmKAAoJEGEfvezVlG4PwaUIAI+MWPPe/+Z11pSFTlNNchUW
I4TTrrYOIz/2D3Zm+qMFFMyh2FZCcLuIbIPKOdmewRNkI8BdGvzAIvGdxPGxZylI
u3pZRsCVlMna1TYX2XsldkUSkPiuL2Gn9rS+HEZ7KuW5i98JR6s9xn0Ad2WR7c7W
ygABN8T64WSof0zEhpm1O9t8E9n8BunY93zCSF9r53N/qClT3+bJSPiaIjtR05ZN
y2uo3EeSgxhfDHeK9Y19zz/8ApikidYmO3XLVzQ4XJSGx1HlvF8sN9PFk6pgnxnX
fQa6WJlKxkdibbHC1AMhqVzkTnm1B/h4XauvEotO7n+5yXkt76b04+R7ff/fXXg=
=Szqe
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2993-1
June 09, 2016

firefox vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS
- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Firefox could be made to crash or run programs as your login if it
opened a malicious website.

Software Description:
- firefox: Mozilla Open Source web browser

Details:

Christian Holler, Gary Kwong, Jesse Ruderman, Tyson Smith, Timothy Nikkel,
Sylvestre Ledru, Julian Seward, Olli Pettay, Karl Tomlinson, Christoph
Diehl, Julian Hector, Jan de Mooij, Mats Palmgren, and Tooru Fujisawa
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code. (CVE-2016-2815, CVE-2016-2818)

A buffer overflow was discovered when parsing HTML5 fragments in some
circumstances. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary code. (CVE-2016-2819)

A use-after-free was discovered in contenteditable mode in some
circumstances. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary code. (CVE-2016-2821)

Jordi Chancel discovered a way to use a persistent menu within a <select>
element and place this in an arbitrary location. If a user were tricked in
to opening a specially crafted website, an attacker could potentially
exploit this to spoof the addressbar contents. (CVE-2016-2822)

Armin Razmdjou that the location.host property can be set to an arbitrary
string after creating an invalid data: URI. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to bypass some same-origin protections. (CVE-2016-2825)

A use-after-free was discovered when processing WebGL content in some
circumstances. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary code. (CVE-2016-2828)

Tim McCormack discovered that the permissions notification can show the
wrong icon when a page requests several permissions in quick succession.
An attacker could potentially exploit this by tricking the user in to
giving consent for access to the wrong resource. (CVE-2016-2829)

It was discovered that a pointerlock can be created in a fullscreen
window without user consent in some circumstances, and this pointerlock
cannot be cancelled without quitting Firefox. If a user were tricked in
to opening a specially crafted website, an attacker could potentially
exploit this to cause a denial of service or conduct clickjacking attacks.
(CVE-2016-2831)

John Schoenick discovered that CSS pseudo-classes can leak information
about plugins that are installed but disabled. An attacker could
potentially exploit this to fingerprint users. (CVE-2016-2832)

Matt Wobensmith discovered that Content Security Policy (CSP) does not
block the loading of cross-domain Java applets when specified by policy.
An attacker could potentially exploit this to bypass CSP protections and
conduct cross-site scripting (XSS) attacks. (CVE-2016-2833)

In addition, multiple unspecified security issues were discovered in NSS.
(CVE-2016-2834)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
firefox 47.0+build3-0ubuntu0.16.04.1

Ubuntu 15.10:
firefox 47.0+build3-0ubuntu0.15.10.1

Ubuntu 14.04 LTS:
firefox 47.0+build3-0ubuntu0.14.04.1

Ubuntu 12.04 LTS:
firefox 47.0+build3-0ubuntu0.12.04.1

After a standard system update you need to restart Firefox to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2993-1
CVE-2016-2815, CVE-2016-2818, CVE-2016-2819, CVE-2016-2821,
CVE-2016-2822, CVE-2016-2825, CVE-2016-2828, CVE-2016-2829,
CVE-2016-2831, CVE-2016-2832, CVE-2016-2833, CVE-2016-2834

Package Information:
https://launchpad.net/ubuntu/+source/firefox/47.0+build3-0ubuntu0.16.04.1
https://launchpad.net/ubuntu/+source/firefox/47.0+build3-0ubuntu0.15.10.1
https://launchpad.net/ubuntu/+source/firefox/47.0+build3-0ubuntu0.14.04.1
https://launchpad.net/ubuntu/+source/firefox/47.0+build3-0ubuntu0.12.04.1

Wednesday, June 8, 2016

[CentOS-announce] CESA-2016:1217 Critical CentOS 5 firefox Security Update

CentOS Errata and Security Advisory 2016:1217 Critical

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-1217.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
4f682310ef08803318d69e4044446dac5beab8bc046daf8e66ac5c1c4f95e373 firefox-45.2.0-1.el5.centos.i386.rpm

x86_64:
4f682310ef08803318d69e4044446dac5beab8bc046daf8e66ac5c1c4f95e373 firefox-45.2.0-1.el5.centos.i386.rpm
95a69b243ad4569af34a05fc1806d826a665a38550abe275f93de0b4378ddf95 firefox-45.2.0-1.el5.centos.x86_64.rpm

Source:
02393904e04805e7f719e8b2d47d0f63a639e788a7c0f9f9df13826db83edb74 firefox-45.2.0-1.el5.centos.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2016:1217 Critical CentOS 6 firefox Security Update

CentOS Errata and Security Advisory 2016:1217 Critical

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-1217.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
acc8466a5e2e7b4f97e476ef08608babd3957f9dea929ede45436549dd189940 firefox-45.2.0-1.el6.centos.i686.rpm

x86_64:
acc8466a5e2e7b4f97e476ef08608babd3957f9dea929ede45436549dd189940 firefox-45.2.0-1.el6.centos.i686.rpm
3c0badf351a25c811dce868afd434b9341a3da64018937be7bac76c39ecb5a42 firefox-45.2.0-1.el6.centos.x86_64.rpm

Source:
733ca4db9bc0d6dcb4edc0d270299834e4b78b0f115025fd310146ce420380e2 firefox-45.2.0-1.el6.centos.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce