ubuntu Updates
2590Warning Date
Severity Level
Warning Number
Target Sector
27 September, 2020
● Medium
2020-1841
All
Description:
ubuntu has released security updates to address several vulnerabilities in the following products:
- libquicktime - Library for reading and writing quicktime files
- Ubuntu 16.04 LTS
- spip - website engine for publishing
- Ubuntu 18.04 LTS
- linux - Linux kernel
- Ubuntu 16.04 LTS
- Ubuntu 14.04 ESM
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- packagekit - Provides a package management service
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- atftp - Advanced TFTP Server and Client
- Ubuntu 18.04 LTS
- aptdaemon - transaction based package management service
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- awl - PHP Utility Libraries
- Ubuntu 20.04 LTS
- gnuplot - Command-line driven interactive plotting program
- Ubuntu 16.04 LTS
- ruby-sanitize - allowlist-based HTML and CSS sanitizer
- Ubuntu 20.04 LTS
- miniupnpd - UPnP and NAT-PMP daemon for gateway routers
- Ubuntu 16.04 LTS
- rdflib - Pure Python package for working with RDF
- Ubuntu 16.04 LTS
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Execute arbitrary code
- Cross-site scripting (XSS)
Best practice and Recommendations:
The CERT team encourages users to review ubuntu security advisory and apply the necessary updates:
- https://ubuntu.com/security/notices/USN-4542-1
- https://ubuntu.com/security/notices/USN-4543-1
- https://ubuntu.com/security/notices/USN-4536-1
- https://ubuntu.com/security/notices/USN-4545-1
- https://ubuntu.com/security/notices/USN-4535-1
- https://ubuntu.com/security/notices/USN-4525-1
- https://ubuntu.com/security/notices/USN-4539-1
- https://ubuntu.com/security/notices/USN-4538-1
- https://ubuntu.com/security/notices/USN-4540-1
- https://ubuntu.com/security/notices/USN-4541-1
- https://ubuntu.com/security/notices/USN-4527-1
- https://ubuntu.com/security/notices/USN-4537-1