Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in libmspack
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in libmspack
ID: USN-4066-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS
Datum: Fr, 19. Juli 2019, 07:15
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010305
Applikationen: libmspack

Originalnachricht


--===============0572231092236984032==
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature";
boundary="Q68bSM7Ycu6FN28Q"
Content-Disposition: inline


--Q68bSM7Ycu6FN28Q
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-4066-1
July 18, 2019

libmspack vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

libmspack could be made to expose sensitive information if it received
a specially crafted CHM file.

Software Description:
- libmspack: library for Microsoft compression formats

Details:

It was discovered that libmspack incorrectly handled certain CHM files.
A remote attacker could possibly use this issue to access sensitive
information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
libmspack0 0.6-3ubuntu0.3

Ubuntu 16.04 LTS:
libmspack0 0.5-1ubuntu0.16.04.4

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4066-1
CVE-2019-1010305

Package Information:
https://launchpad.net/ubuntu/+source/libmspack/0.6-3ubuntu0.3
https://launchpad.net/ubuntu/+source/libmspack/0.5-1ubuntu0.16.04.4

--Q68bSM7Ycu6FN28Q
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJdMPupAAoJEEW851uECx9pqzcP/i7CGfIM8RUPrtyt2TeoKP9m
0E1z5yh3jm/JZ5zsAqMlkE0nUf+rmu8iB1s28I4CcX8vWyWKa4QMrHTMlTLmyls6
tRGq1MZbB/y+lhS3WG/zUWnivT05Euo7kmptPJgRGZDo+A4PGiBx1Nyc+6nEFpp/
amBqhmsFQxHyxHZYXR+Y7EGVQcuWgEp0JjBbnZtFkKRK5wrH3JsLzyXxdgJHRuWk
FV29i4cvtH3sUdC82UMCGMQwH8QyGr+zh+a+X1tebkkuadRGictDXruYlPDr1mFz
7S5zyRtpXiC3ajal6e1mE3V/lXiRz68nno+meR23J2kz6cBAy/oLn0A4D8jHNHvt
Nx2GZk74xwsunjpQ2mYaS1ync2FXLvXZo6YQ0traywqtcQ7YwOxRdj94FRgOeqhA
i3jXWQJ7exEJ7rxrHrruMtAZ4kiAFLEUvA9Db2+/zF6Gwb6azHZjwPMdCs8ejtzg
0OsNGTT1B1NqsEKXzGhHj3qhElG+e/SIIG4s9Bn3DL6aZIMyD6gfsAwhS1sMLOLX
OL8VxD4zCXNXZolE8T/+UspzZhw90SPRA1Dind/jO5SIbM6V550zkcqcm0Lstu20
7z+6DU8E7SFNTHF7jre09Y8pALmANPmsMEhmPUe/vHzFZL1yXId8LvbmnNu4ZSyS
c0dWySSY2jxXoOnpmnqJ
=9OCz
-----END PGP SIGNATURE-----

--Q68bSM7Ycu6FN28Q--


--===============0572231092236984032==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung