drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in uriparser
Name: |
Mehrere Probleme in uriparser |
|
ID: |
USN-5172-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 18.04 LTS |
|
Datum: |
Mo, 6. Dezember 2021, 21:32 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19199
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20721
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19200
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19198 |
|
Applikationen: |
uriparser |
|
Originalnachricht |
--===============7118123355122236406== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="57d3gby2daq4z57y" Content-Disposition: inline
--57d3gby2daq4z57y Content-Type: text/plain; charset=us-ascii Content-Disposition: inline
========================================================================== Ubuntu Security Notice USN-5172-1 December 06, 2021
uriparser vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in uriparser.
Software Description: - uriparser: Strictly RFC 3986 compliant URI parsing library
Details:
It was discovered that uriparser mishandled certain input. An attacker could use this vulnerability to cause uriparser to crash or possibly execute arbitrary code. (CVE-2018-19198, CVE-2018-19199, CVE-2018-19200)
It was discovered that uriparser incorrectly handled certain URIs. An attacker could use this vulnerability to cause a crash or possibly leak sensitive information. (CVE-2018-20721)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04 LTS: liburiparser1 0.8.4-1+deb9u2build0.18.04.1
In general, a standard system update will make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-5172-1 CVE-2018-19198, CVE-2018-19199, CVE-2018-19200, CVE-2018-20721
Package Information: https://launchpad.net/ubuntu/+source/uriparser/0.8.4-1+deb9u2build0.18.04.1
--57d3gby2daq4z57y Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEECtyyz6azUy6AZBzSkGeI6zGnN/8FAmGuJvwACgkQkGeI6zGn N/8zJhAAiqBylA5X46BJR2YXFga8dIeDAreqyUemymBE0mRrIgklqdPPaz0coGt6 AgDjihKJYbVNm/V0Yfnslwd2udI18G+85Ba3H9o3KivIQ27sg2kHCf3sT/Ab5wS6 fDzvsTPYhMOVDEFcb8sOS3h0AiOeg8SNix7y7Zx/i6g7K35TXozEXacDX8m73jrh bne4EhXQ1SHN3vjQtDe0goEr7814pP6X0eFuDmU9Q9Je9x2z6oMYwEEku8W8to5J 53LiPOWYd9TViIZ1KI1pP5jWhwECKRCj42urfdyUCIbzxUk0vsia/Tpx3iRfGEx0 FGa8MA67Qogeik64f8VPdUWi45L8ATUQDTPYTm/1KJT/Th+ZQaiNNzWZzto4kW8W ELCaLGJdpCuUMnpRiGtuJyZZfp1PQCgd0IqYrjppjWhVh9hwy4SZXobidpf17QH1 rBBBmgfy+ByZAYxh0EpI7OsvSyY5idznmO+mJEGGeoTgidj5mWFZUNl4DgKJEBnF VIZzCF3SORMyfYljmsJc2YaETersf8zLbdzUHsSZ1rJ+KDARC81RGwlpGVjsZyaD VfILKoFyQ1TmLx+hPB2Wsshx5IbDF36Q32Kk5Lff+V/d64rtC89Z58Lu1tAim5zm PVIHonPJTY8XOm8OHLIKepNeSt/s3nxWSuYGaVX2WedmAA4yJDc= =hyoX -----END PGP SIGNATURE-----
--57d3gby2daq4z57y--
--===============7118123355122236406== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
|
|
|
|