ubuntu Updates
2587Warning Date
Severity Level
Warning Number
Target Sector
28 October, 2020
● Medium
2020-1979
All
Description:
ubuntu has released security updates to address several vulnerabilities in the following products:
- mysql-5.7 - MySQL database
- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- blueman - Graphical bluetooth manager
- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- tomcat6 - Servlet and JSP engine
- Ubuntu 16.04 LTS
- perl - Practical Extraction and Report Language
- Ubuntu 14.04 ESM
- Ubuntu 12.04 ESM
- mariadb-10.1 - MariaDB database
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- php7.4 - server-side, HTML-embedded scripting language (metapackage)
- Ubuntu 20.10
- netty - None
- Ubuntu 18.04 LTS
- openjdk-8 - Open Source Java implementation
- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Escalation of privilege
- HTTP request smuggling attack
- Denial of service attack (DoS)
- Buffer overflow
Best practice and Recommendations:
The CERT team encourages users to review ubuntu security advisory and apply the necessary updates:
- https://ubuntu.com/security/notices/USN-4603-1
- https://ubuntu.com/security/notices/USN-3081-2
- https://ubuntu.com/security/notices/USN-4604-1
- https://ubuntu.com/security/notices/USN-4605-1
- https://ubuntu.com/security/notices/USN-4607-1
- https://ubuntu.com/security/notices/USN-4583-2
- https://ubuntu.com/security/notices/USN-4602-2
- https://ubuntu.com/security/notices/USN-4600-2