These are the Ubuntu security notices that affect the current supported releases of Ubuntu. These notices are also posted to the ubuntu-security-announce mailing list (list archive). To report a security vulnerability in an Ubuntu package, please contact the Ubuntu Security Team. You may also be interested in learning about Ubuntu security policies. For more details on a specific CVE or source package, please see the Ubuntu CVE Tracker.

You can also view the latest notices by subscribing to the RSS or the Atom feeds.

Latest notices

USN-102-1: shar vulnerabilities

Shaun Colley discovered a buffer overflow in “shar” that was triggered by output files (specified with -o) with names longer than 49 characters. This could be exploited to run arbitrary attacker specified code on systems that automatically process uploaded files with shar. Ulf Harnhammar discovered that shar does not check the data…

29 March 2005 | ubuntu-4.10

USN-101-1: telnet vulnerabilities

A buffer overflow was discovered in the telnet client’s handling of the LINEMODE suboptions. By sending a specially constructed reply containing a large number of SLC (Set Local Character) commands, a remote attacker (i. e. a malicious telnet server) could execute arbitrary commands with the privileges of the user running the telnet client….

29 March 2005 | ubuntu-4.10

USN-100-1: cdrecord vulnerability

Javier Fern�ndez-Sanguino Pe�a noticed that cdrecord created temporary files in an insecure manner if DEBUG was enabled in /etc/cdrecord/rscsi. If the default value was used (which stored the debug output file in /tmp), this could allow a symbolic link attack to create or overwrite arbitrary files with the privileges of the user invoking…

24 March 2005 | ubuntu-4.10

USN-99-2: Fixed php4 packages for USN-99-1

USN-99-1 fixed a safe mode bypass which allowed malicious PHP scripts to circumvent path restrictions by creating a specially crafted directory whose length exceeded the capacity of the realpath() function (CAN-2004-1064). However, this caused severe regressions, some applications like SquirrelMail and Gallery did not work any more, and the…

24 March 2005 | ubuntu-4.10

USN-99-1: PHP4 vulnerabilities

Stefano Di Paola discovered integer overflows in PHP’s pack() and unpack() functions. A malicious PHP script could exploit these to break out of safe mode and execute arbitrary code with the privileges of the PHP interpreter. (CAN-2004-1018) Note: The second part of CAN-2004-1018 (buffer overflow in the shmop_write() function) was already fixed…

18 March 2005 | ubuntu-4.10

USN-98-1: OpenSLP vulnerabilities

The SuSE Security Team discovered several buffer overflows in the OpenSLP server and client library. By sending specially crafted SLP packets, a remote attacker could exploit this to crash the SLP server or execute arbitrary code with the privileges of the “daemon” user. Likewise, a malicious SLP server could exploit the client…

18 March 2005 | ubuntu-4.10

USN-97-1: libxpm vulnerability

Chris Gilbert discovered a buffer overflow in the XPM library shipped with XFree86. If an attacker tricked a user into loading a malicious XPM image with an application that uses libxpm, he could exploit this to execute arbitrary code with the privileges of the user opening the image. These overflows do not allow privilege escalation through the…

16 March 2005 | ubuntu-4.10

USN-96-1: mySQL vulnerabilities

Stefano Di Paola discovered three privilege escalation flaws in the MySQL server: - If an authenticated user had INSERT privileges on the ‘mysql’ administrative database, the CREATE FUNCTION command allowed that user to use libc functions to execute arbitrary code with the privileges of the database server (user ‘mysql’). (CAN-2005-0709) -…

16 March 2005 | ubuntu-4.10

USN-95-1: Linux kernel vulnerabilities

A remote Denial of Service vulnerability was discovered in the Netfilter IP packet handler. This allowed a remote attacker to crash the machine by sending specially crafted IP packet fragments. (CAN-2005-0209) The Netfilter code also contained a memory leak. Certain locally generated packet fragments are reassembled twice, which caused a double…

15 March 2005 | ubuntu-4.10

USN-94-1: Perl vulnerability

Paul Szabo discovered another vulnerability in the rmtree() function in File::Path.pm. While a process running as root (or another user) was busy deleting a directory tree, a different user could exploit a race condition to create setuid binaries in this directory tree, provided that he already had write permissions in any subdirectory of that…

9 March 2005 | ubuntu-4.10