CVE-2017-3847

A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc72741. Known Affected Releases: 6.2.1.

CVE-2017-3841

A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sensitive information. More Information: CSCvc04854. Known Affected Releases: 5.8(2.5).

CVE-2017-3836

A vulnerability in the web framework Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data. More Information: CSCvb61689. Known Affected Releases: 11.5(1.11007.2). Known Fixed Releases: 12.0(0.98000.162) 12.0(0.98000.178) 12.0(0.98000.383) 12.0(0.98000.488) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.98500.6).

CVE-2017-3843

A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files that should be restricted. More Information: CSCvc99446. Known Affected Releases: 11.5(0).

CVE-2017-3838

A vulnerability in Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc04838. Known Affected Releases: 5.8(2.5).

CVE-2017-3833

A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. More Information: CSCvb95951. Known Affected Releases: 12.0(0.99999.2). Known Fixed Releases: 11.0(1.23064.1) 11.5(1.12031.1) 11.5(1.12900.21) 11.5(1.12900.7) 11.5(1.12900.8) 11.6(1.10000.4) 12.0(0.98000.155) 12.0(0.98000.178) 12.0(0.98000.366) 12.0(0.98000.367) 12.0(0.98000.468) 12.0(0.98000.469) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.98500.6).

CVE-2017-3840

A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect Vulnerability. More Information: CSCvc04849. Known Affected Releases: 5.8(2.5).

CVE-2017-3842

A vulnerability in the web-based management interface of the Cisco Intrusion Prevention System Device Manager (IDM) could allow an unauthenticated, remote attacker to view sensitive information stored in certain HTML comments. More Information: CSCuh91455. Known Affected Releases: 7.2(1)V7.

USN-3205-1: tcpdump vulnerabilities

Ubuntu Security Notice USN-3205-1

21st February, 2017

tcpdump vulnerabilities

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 16.10
  • Ubuntu 16.04 LTS
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

tcpdump could be made to crash or run programs if it received specially
crafted network traffic.

Software description

  • tcpdump
    – command-line network traffic analyzer

Details

It was discovered that tcpdump incorrectly handled certain packets. A
remote attacker could use this issue to cause tcpdump to crash, resulting
in a denial of service, or possibly execute arbitrary code.

In the default installation, attackers would be isolated by the tcpdump
AppArmor profile.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 16.10:
tcpdump

4.9.0-1ubuntu1~ubuntu16.10.1
Ubuntu 16.04 LTS:
tcpdump

4.9.0-1ubuntu1~ubuntu16.04.1
Ubuntu 14.04 LTS:
tcpdump

4.9.0-1ubuntu1~ubuntu14.04.1
Ubuntu 12.04 LTS:
tcpdump

4.9.0-1ubuntu1~ubuntu12.04.1

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.

References

CVE-2016-7922,

CVE-2016-7923,

CVE-2016-7924,

CVE-2016-7925,

CVE-2016-7926,

CVE-2016-7927,

CVE-2016-7928,

CVE-2016-7929,

CVE-2016-7930,

CVE-2016-7931,

CVE-2016-7932,

CVE-2016-7933,

CVE-2016-7934,

CVE-2016-7935,

CVE-2016-7936,

CVE-2016-7937,

CVE-2016-7938,

CVE-2016-7939,

CVE-2016-7940,

CVE-2016-7973,

CVE-2016-7974,

CVE-2016-7975,

CVE-2016-7983,

CVE-2016-7984,

CVE-2016-7985,

CVE-2016-7986,

CVE-2016-7992,

CVE-2016-7993,

CVE-2016-8574,

CVE-2016-8575,

CVE-2017-5202,

CVE-2017-5203,

CVE-2017-5204,

CVE-2017-5205,

CVE-2017-5341,

CVE-2017-5342,

CVE-2017-5482,

CVE-2017-5483,

CVE-2017-5484,

CVE-2017-5485,

CVE-2017-5486