Apple iBooks Author before 2.4.1 allows remote attackers to read arbitrary files via an iBooks Author file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Monthly Archives: April 2016
Bugtraq: [security bulletin] HPSBGN03569 rev.1 – HPE OneView for VMware vCenter (OV4VC), Remote Disclosure of Information
[security bulletin] HPSBGN03569 rev.1 – HPE OneView for VMware vCenter (OV4VC), Remote Disclosure of Information
Bugtraq: [SECURITY] [DSA 3541-1] roundcube security update
[SECURITY] [DSA 3541-1] roundcube security update
Bugtraq: Apple iOS 9.3.1 (iPhone 6S & iPhone Plus) – (3D Touch) Passcode Bypass Vulnerability
Apple iOS 9.3.1 (iPhone 6S & iPhone Plus) – (3D Touch) Passcode Bypass Vulnerability
Bugtraq: [SECURITY] [DSA 3542-1] mercurial security update
[SECURITY] [DSA 3542-1] mercurial security update
RHSA-2016:0590-1: Moderate: spacewalk-java security update
RHN Satellite and Proxy: An update for spacewalk-java is now available for Red Hat Satellite 5.7.
Red Hat Product Security has rated this update as having a security impact of
Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a
detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.
CVE-2015-0284, CVE-2016-2103, CVE-2016-2104, CVE-2016-3079
RHSA-2016:0591-1: Moderate: nss, nss-util, and nspr security, bug fix, and enhancement update
Red Hat Enterprise Linux: An update for nss, nss-util, and nspr is now available for Red Hat Enterprise
Linux 6.
Red Hat Product Security has rated this update as having a security impact of
Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a
detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.
CVE-2016-1978, CVE-2016-1979
RHEA-2016:0593-1: libguestfs enhancement update
Red Hat Enterprise Linux: Updated libguestfs packages that add two enhancements are now available for Red
Hat Enterprise Linux 7.
USN-2944-1: Libav vulnerabilities
Ubuntu Security Notice USN-2944-1
4th April, 2016
libav vulnerabilities
A security issue affects these releases of Ubuntu and its
derivatives:
- Ubuntu 12.04 LTS
Summary
Libav could be made to crash or run programs as your login if it opened a
specially crafted file.
Software description
- libav
– Multimedia player, server, encoder and transcoder
Details
It was discovered that Libav incorrectly handled certain malformed media
files. If a user were tricked into opening a crafted media file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Update instructions
The problem can be corrected by updating your system to the following
package version:
- Ubuntu 12.04 LTS:
-
libavformat53
4:0.8.17-0ubuntu0.12.04.2
-
libavcodec53
4:0.8.17-0ubuntu0.12.04.2
To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.
In general, a standard system update will make all the necessary changes.
References
USN-2945-1: XChat-GNOME vulnerability
Ubuntu Security Notice USN-2945-1
4th April, 2016
xchat-gnome vulnerability
A security issue affects these releases of Ubuntu and its
derivatives:
- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary
XChat-GNOME could be made to expose sensitive information over the network.
Software description
- xchat-gnome
– simple and featureful IRC client for GNOME
Details
It was discovered that XChat-GNOME incorrectly verified the hostname in an
SSL certificate. An attacker could trick XChat-GNOME into trusting a rogue
server’s certificate, which was signed by a trusted certificate authority,
to perform a man-in-the-middle attack.
Update instructions
The problem can be corrected by updating your system to the following
package version:
- Ubuntu 15.10:
-
xchat-gnome
1:0.30.0~git20141005.816798-0ubuntu6.2
- Ubuntu 14.04 LTS:
-
xchat-gnome
1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2
- Ubuntu 12.04 LTS:
-
xchat-gnome
1:0.30.0~git20110821.e2a400-0.2ubuntu4.3
To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.
After a standard system update you need to restart XChat-GNOME to make
all the necessary changes.