Ubuntu Security Notice USN-3132-1

Ubuntu Security Notice 3132-1 – Harry Sintonen discovered that tar incorrectly handled extracting files when path names are specified on the command line. If a user or automated system were tricked into processing a specially crafted archive, an attacker could possibly overwrite arbitrary files.

xen-4.6.4-2.fc24

xen : various security flaws (#1397383)
x86 null segments not always treated as unusable [XSA-191, CVE-2016-9386]
x86 task switch to VM86 mode mis-handled [XSA-192, CVE-2016-9382]
x86 segment base write emulation lacking canonical address checks [XSA-193,
CVE-2016-9385]
x86 64-bit bit test instruction emulation broken [XSA-195, CVE-2016-9383]
x86 software interrupt injection mis-handled [XSA-196, CVE-2016-9377,
CVE-2016-9378]
qemu incautious about shared ring processing [XSA-197, CVE-2016-9381]
delimiter injection vulnerabilities in pygrub [XSA-198, CVE-2016-9379,
CVE-2016-9380]

xen-4.7.1-3.fc25

xen : various security flaws (#1397383)
x86 null segments not always treated as unusable [XSA-191, CVE-2016-9386]
x86 task switch to VM86 mode mis-handled [XSA-192, CVE-2016-9382]
x86 segment base write emulation lacking canonical address checks [XSA-193,
CVE-2016-9385]
guest 32-bit ELF symbol table load leaking host data [XSA-194, CVE-2016-9384]
x86 64-bit bit test instruction emulation broken [XSA-195, CVE-2016-9383]
x86 software interrupt injection mis-handled [XSA-196, CVE-2016-9377,
CVE-2016-9378]
qemu incautious about shared ring processing [XSA-197, CVE-2016-9381]
delimiter injection vulnerabilities in pygrub [XSA-198, CVE-2016-9379,
CVE-2016-9380]