Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in Pound
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in Pound
ID: USN-4702-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS
Datum: Mo, 25. Januar 2021, 22:19
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-21245
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10711
Applikationen: Pound

Originalnachricht


--===============3106166903101427883==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="eJnRUKwClWJh1Khz"
Content-Disposition: inline


--eJnRUKwClWJh1Khz
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-4702-1
January 25, 2021

pound vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in pound.

Software Description:
- pound: reverse proxy, load balancer and HTTPS front-end for Web servers

Details:

It was discovered that Pound incorrectly handled certain HTTP requests
A remote attacker could use it to retrieve some sensitive
information. (CVE-2016-10711, CVE-2018-21245)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
pound 2.6-6.1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4702-1
CVE-2016-10711, CVE-2018-21245

Package Information:
https://launchpad.net/ubuntu/+source/pound/2.6-6.1ubuntu0.1

--eJnRUKwClWJh1Khz
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAmAOxkIACgkQRbznW4QL
H2lJRBAAhF5Fvum92VHHty6fd8WTmhJ9N+jAtaAGwmXjpD7YQdAGJB2QjLEAsZzY
xaJDXPwdSMyQ4Pg9UIppQF/COeuBm4aJmoMbbeCsOxymFOPR/j3jnrH2yNYsPuNB
ZSAr9CQZrbsECYo96xrnWiGnOFimYuBv1yGltEMiplaE6SUcTTuXriWjYiyl6Yk3
raxp3vlC5GQuuIjbzKGHM5ET2T/Na/hc7KOgV9WPDQtEGPb38aJJ1B3RXUxXIfvQ
M4W1evqde1bFFXnx1HsZoKkRP6BN+2UkhWymzy3Gudkd0lpuKKZjlkOr+CC8Jzg2
m3bAWxtPIdHwU55/7hmtUuO0qllXVMDZEvIZUhsbbOCFGujMA2gERMItS4L21pGB
p5Ghg6RNaWPpAG5zirehOOX7QPe+6avVno3NeqrzBR5J6QpnvYkBP6y/9RFsmd0P
k47u0c3HWQDomMW0pxZG1wrBof47t799p2N80Q/BLZt+uL6BgpaeFs+Fsa/pJotJ
KOaGkJqzimyR+wh2bT8dZl9ZQcb1lYlAN0W/yxapf9pjODuYaKy2rAsAtxItHzAx
QqbYDu8u1yevQI5JmIN9HY0HZfAzXgkmeBbSznhLBNLGAeDyc/dwX/6080rfmDMX
c1dYj2pycCypzNEvtDLtSEM382ZgSjqg0IikD04MufNrSjD9DJ8=
=LWTc
-----END PGP SIGNATURE-----

--eJnRUKwClWJh1Khz--


--===============3106166903101427883==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung