Microsoft Edge Security Feature Bypass (MS17-007: CVE-2017-0140)

Security feature bypass exists in Microsoft Edge. The vulnerability is due to a breach in the way Microsoft Edge implements SOP (Same Origin Policy) for HTML elements present in other browser windows. A remote attacker could exploit this vulnerability by enticing a user to visit a maliciously crafted web-page. Successful exploitation of this vulnerability would allow an attacker to bypass the same origin policy and disclose sensitive information.

USN-3226-1: icoutils vulnerabilities

Ubuntu Security Notice USN-3226-1

13th March, 2017

icoutils vulnerabilities

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 12.04 LTS

Summary

icoutils could be made to crash or run programs as your login if it opened
a specially crafted file.

Software description

  • icoutils
    – Create and extract MS Windows icons and cursors

Details

Jerzy Kramarz discovered that icoutils incorrectly handled memory when
processing certain files. If a user or automated system were tricked into
opening a specially crafted file, an attacker could cause icoutils to
crash, resulting in a denial of service, or possibly execute arbitrary code.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 12.04 LTS:
icoutils

0.29.1-2ubuntu0.2

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References

CVE-2017-6009,

CVE-2017-6010,

CVE-2017-6011

USN-3227-1: ICU vulnerabilities

Ubuntu Security Notice USN-3227-1

13th March, 2017

icu vulnerabilities

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 16.10
  • Ubuntu 16.04 LTS
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

Several security issues were fixed in ICU.

Software description

  • icu
    – International Components for Unicode library

Details

It was discovered that ICU incorrectly handled certain memory operations
when processing data. If an application using ICU processed crafted data,
a remote attacker could possibly cause it to crash or potentially execute
arbitrary code with the privileges of the user invoking the program.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 16.10:
libicu57

57.1-4ubuntu0.1
Ubuntu 16.04 LTS:
libicu55

55.1-7ubuntu0.1
Ubuntu 14.04 LTS:
libicu52

52.1-3ubuntu0.5
Ubuntu 12.04 LTS:
libicu48

4.8.1.1-3ubuntu0.7

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References

CVE-2014-9911,

CVE-2015-4844,

CVE-2016-0494,

CVE-2016-6293,

CVE-2016-7415