All posts by 007admin

USN-3258-2: Dovecot regression

Ubuntu Security Notice USN-3258-2

11th April, 2017

dovecot regression

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 16.10
  • Ubuntu 16.04 LTS

Summary

USN-3258-1 introduced a regression in Dovecot.

Software description

  • dovecot
    – IMAP and POP3 email server

Details

USN-3258-1 intended to fix a vulnerability in Dovecot. Further investigation
revealed that only Dovecot versions 2.2.26 and newer were affected by the
vulnerability. Additionally, the change introduced a regression when Dovecot
was configured to use the “dict” authentication database. This update reverts
the change. We apologize for the inconvenience.

Original advisory details:

It was discovered that Dovecot incorrectly handled some usernames. An attacker
could possibly use this issue to cause Dovecot to hang or crash, resulting in a
denial of service.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 16.10:
dovecot-core

1:2.2.24-1ubuntu1.3
Ubuntu 16.04 LTS:
dovecot-core

1:2.2.22-1ubuntu2.4

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References

CVE-2017-2669

Microsoft Issues Patches for Actively Exploited Critical Vulnerabilities

Besides a previously undisclosed code-execution flaw in Microsoft Word, the tech giant patches two more zero-day vulnerabilities that attackers had been exploiting in the wild for months, as part of this month’s Patch Tuesday.

In total, Microsoft patches 45 unique vulnerabilities in its nine products, including three previously undisclosed vulnerabilities under active attack.

The first

Hackers Can Steal Your Passwords Just by Monitoring SmartPhone Sensors

Do you know how many kinds of sensors your smartphone has inbuilt? And what data they gather about your physical and digital activities?

An average smartphone these days is packed with a wide array of sensors such as GPS, Camera, microphone, accelerometer, magnetometer, proximity, gyroscope, pedometer, and NFC, to name a few.

Now, according to a team of scientists from Newcastle University