drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in Apache
Name: |
Mehrere Probleme in Apache |
|
ID: |
USN-6117-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 22.10, Ubuntu 16.04 LTS (Available with Ubuntu Pro), Ubuntu 14.04 LTS (Available with Ubuntu Pro) |
|
Datum: |
Mi, 31. Mai 2023, 06:39 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11987
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42890
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17566
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38398
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41704
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38648
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40146 |
|
Applikationen: |
Apache |
|
Originalnachricht |
--===============1060140528147146757== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="44y42xf4nxk6pype" Content-Disposition: inline
--44y42xf4nxk6pype Content-Type: text/plain; charset=us-ascii Content-Disposition: inline
========================================================================== Ubuntu Security Notice USN-6117-1 May 30, 2023
batik vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro)
Summary:
Several security issues were fixed in Apache Batik.
Software Description: - batik: SVG Library
Details:
It was discovered that Apache Batik incorrectly handled certain inputs. An attacker could possibly use this to perform a cross site request forgery attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some situations. A remote attacker could use this issue to access files on the server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from an SVG. An attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.10: libbatik-java 1.14-2ubuntu0.1
Ubuntu 22.04 LTS: libbatik-java 1.14-1ubuntu0.2
Ubuntu 20.04 LTS: libbatik-java 1.12-1ubuntu0.1
Ubuntu 18.04 LTS: libbatik-java 1.10-2~18.04.1
Ubuntu 16.04 LTS (Available with Ubuntu Pro): libbatik-java 1.8-3ubuntu1+esm1
Ubuntu 14.04 LTS (Available with Ubuntu Pro): libbatik-java 1.7.ubuntu-8ubuntu2.14.04.3+esm1
In general, a standard system update will make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-6117-1 CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648, CVE-2022-40146, CVE-2022-41704, CVE-2022-42890
Package Information: https://launchpad.net/ubuntu/+source/batik/1.14-2ubuntu0.1 https://launchpad.net/ubuntu/+source/batik/1.14-1ubuntu0.2 https://launchpad.net/ubuntu/+source/batik/1.12-1ubuntu0.1 https://launchpad.net/ubuntu/+source/batik/1.10-2~18.04.1
--44y42xf4nxk6pype Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEkCdEQ5T6DutSveCybUp5kL3izGYFAmR2STkACgkQbUp5kL3i zGYPlw/+MbRjqZ2AlAIFPzMrpneaZisUR7mcS2MyhDMJaN9wISQt3TbYmzN/sFgq M77uxW80/0tzsPoax1GYosC0KHvV4Kf+sHCAe7XPRh72nN8Ua6DWvy2mqWFzjURo LSxrdg5cplHaNhkJ7K+O5eMe1c5zCWkcF++CQrwOV+xDz4YenlsiT76TS40o9dhf TjNWQWFvef6YrKVcTVNGqqpYRVdHjX4hW0W8XpvUBPbnLYMQVALNwSh0VkSnhgAB aGQAzwrLoPXJGA1KJTV6LtAwZfH/ee3/HyRwBb+V7Y2DwX7Clcudt+UlBQiqTWwy 3CHJvMaiRymJE7FT/8yH5XPoh/4BDCwAk6sotcyw2Egs4phuOuLg8fsG46/zb6DI XcKAHR6TOIIV/Bx4/RnafrxPufERhjggvllkigFklYpBd5DUYn+7Ycy0nOH5nSVv P0ZJPaMJTuEZooo7+CDuQW5dq8MO5CHkF04y0Ln6nwelAroYI8o79ar5olleBJyt Y5daGpK5hCYAe7bt20krrZWIG+gT/xwk09Fl05iNun7FB24UDMIWzUwCwfa/tQip f6g7qL3OEgD1dNRKqFOfkw3lu33k6JjzmoeKpbdwcEKPRDJ6QP8eabq8rM6wn5cA GyyEhO5I97qnMIhzcHb4zgnrgmj3FkhcLcoAQGYxc3aQv28hQaw= =Weh1 -----END PGP SIGNATURE-----
--44y42xf4nxk6pype--
--===============1060140528147146757== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
--===============1060140528147146757==--
|
|
|
|