Login
Newsletter
Werbung

Sicherheit: Denial of Service in Tracker
Aktuelle Meldungen Distributionen
Name: Denial of Service in Tracker
ID: USN-3101-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS
Datum: Mi, 12. Oktober 2016, 16:40
Referenzen: Keine Angabe
Applikationen: Tracker

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============8852862676974556595==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="AbTKN79qfqE5j8wnbsGa6NcnttSVAvsNm"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--AbTKN79qfqE5j8wnbsGa6NcnttSVAvsNm
Content-Type: multipart/mixed;
boundary="rDnvdrIar5Wrh2VtVM0lGrOVbrKRfkFQa"
From: Marc Deslauriers <marc.deslauriers@canonical.com>
Reply-To: Ubuntu Security <security@ubuntu.com>
To: ubuntu-security-announce@lists.ubuntu.com
Message-ID: <0245df4d-949e-7e79-068e-066aa12e0d91@canonical.com>
Subject: [USN-3101-1] Tracker vulnerability

--rDnvdrIar5Wrh2VtVM0lGrOVbrKRfkFQa
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-3101-1
October 12, 2016

tracker vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Tracker could be made to crash if it opened a specially crafted file.

Software Description:
- tracker: metadata database, indexer and search tool

Details:

It was discovered that Tracker incorrectly handled certain malformed GIF
images. If a user or automated system were tricked into downloading a
specially-crafted GIF image, Tracker could crash, resulting in a denial of
service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
tracker-extract 1.6.2-0ubuntu1.1

After a standard system update you need to restart your session to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-3101-1
https://launchpad.net/bugs/1178402

Package Information:
https://launchpad.net/ubuntu/+source/tracker/1.6.2-0ubuntu1.1



--rDnvdrIar5Wrh2VtVM0lGrOVbrKRfkFQa--

--AbTKN79qfqE5j8wnbsGa6NcnttSVAvsNm
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJX/ih4AAoJEGVp2FWnRL6TwtcP/39zXYfkNCepYDhQSZcQZ7P9
GVjTLrqqtWmUfcALT5ugHeOByg0pQ7h/L9x/3+48Olc4AeimfDHOS7pkCa5mtHN/
TH/PK7pGbax16YABvq+jrGb29+KXPUuB1lC1BDFfCHMGSDtfEZDjJ5X0RNK5ErZh
y+gYLBQRPqQwUQMr7IiBW+5uhngDWh3NPEgtcZQVZg3lWCiEgHRiJpSrggBfi5mG
v68k43ha4LqexQuCqEgEF3FOm8+5VzeUar+55ElstEX5EILGKfLsuvhpYMQAWum0
HkhNqaYPt/QTnMriDOt45bn+8b1zdkYut3i0t0sVsBtZDJUz09w2apDsWuWpCbga
fHt0r033+syfQI+XcbtK9fXvIyR6GOnxCcz55JuGpf54aA4eQBSeufoSldkNDZKc
eLoHKHf0QPA2zShKSsRe8NWZJB0UbWYVfTACcbmf+XZ2EuOEZzbrih15sUJbwNwH
448BcFS3VcjDjxi9MjU219nKDQw45oj504RkO/mt4GSUPdY8T3mGKqPFLfH6CqW0
7tO8RnhxnlPGZCZqRJWi3ejZ5cMU6gRUlxxoSlx8Bi/Lgem+yylP2/ArG41W6RFy
dVPUTCqujCZe/gUS3t6yihB+xQ+zs0dvIVvzfdbNe+9t//+dvZ8HIwY2OIrHr/Rj
QELKBZ9jeS23LsnegeIM
=F6BW
-----END PGP SIGNATURE-----

--AbTKN79qfqE5j8wnbsGa6NcnttSVAvsNm--


--===============8852862676974556595==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============8852862676974556595==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung