USN-2706-1: OpenJDK 6 vulnerabilities

Ubuntu Security Notice USN-2706-1

6th August, 2015

openjdk-6 vulnerabilities

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 12.04 LTS

Summary

Several security issues were fixed in OpenJDK 6.

Software description

  • openjdk-6
    – Open Source Java implementation

Details

Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)

Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)

As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.

As a security improvement, this update modifies OpenJDK behavior to
reject DH key sizes below 768 bits by default, preventing a possible
downgrade attack.

Several vulnerabilities were discovered in the OpenJDK JRE related
to information disclosure. An attacker could exploit these to expose
sensitive data over the network. (CVE-2015-2621, CVE-2015-2632)

A vulnerability was discovered with how the JNDI component of the
OpenJDK JRE handles DNS resolutions. A remote attacker could exploit
this to cause a denial of service. (CVE-2015-4749)

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 12.04 LTS:
icedtea-6-jre-cacao

6b36-1.13.8-0ubuntu1~12.04
icedtea-6-jre-jamvm

6b36-1.13.8-0ubuntu1~12.04
openjdk-6-jdk

6b36-1.13.8-0ubuntu1~12.04
openjdk-6-source

6b36-1.13.8-0ubuntu1~12.04
openjdk-6-jre

6b36-1.13.8-0ubuntu1~12.04
openjdk-6-jre-headless

6b36-1.13.8-0ubuntu1~12.04
openjdk-6-jre-zero

6b36-1.13.8-0ubuntu1~12.04
openjdk-6-jre-lib

6b36-1.13.8-0ubuntu1~12.04

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

This update uses a new upstream release, which includes additional
bug fixes. After a standard system update you need to restart any
Java applications or applets to make all the necessary changes.

References

CVE-2015-2590,

CVE-2015-2601,

CVE-2015-2621,

CVE-2015-2625,

CVE-2015-2628,

CVE-2015-2632,

CVE-2015-2808,

CVE-2015-4000,

CVE-2015-4731,

CVE-2015-4732,

CVE-2015-4733,

CVE-2015-4748,

CVE-2015-4749,

CVE-2015-4760

USN-2707-1: Firefox vulnerability

Ubuntu Security Notice USN-2707-1

7th August, 2015

firefox vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 15.04
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

Firefox could be made to expose sensitive information from local files.

Software description

  • firefox
    – Mozilla Open Source web browser

Details

Cody Crews discovered a way to violate the same-origin policy to inject
script in to a non-privileged part of the PDF viewer. If a user were
tricked in to opening a specially crafted website, an attacker could
exploit this to read sensitive information from local files.
(CVE-2015-4495)

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 15.04:
firefox

39.0.3+build2-0ubuntu0.15.04.1
Ubuntu 14.04 LTS:
firefox

39.0.3+build2-0ubuntu0.14.04.1
Ubuntu 12.04 LTS:
firefox

39.0.3+build2-0ubuntu0.12.04.1

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

CVE-2015-4495

Manipulating WSUS to Own Enterprises

Researchers at Black Hat found a weak spot in some WSUS configurations that could allow an attacker to compromise any server or desktop in an enterprise.

Fedora 22 Security Update: webkitgtk4-2.8.5-1.fc22

WebKitGTK+ 2.8.5 includes fixes for 3 security issues. Additional fixes:
* Fix the window size reported when the web view isn’t realized yet. This fixes the layout of some websites when opening new tabs in the browser and anchor links when opened in new tabs too.
* Prevent clipboard contents from being lost when web process finishes.
* Always allow font matching for strong aliases.
* Move GStreamer missing plugins installer to the UI process.
* Fix a crash when spell checker returns no guesses.
* Fix a crash when SoupSession is destroyed in exit handler.
* Fix a crash closing a page when default context menu is open.
* Several crashes and rendering issues fixed.
* Translation updates: Swedish.