Normally, if you’re a healthy, red-blooded cheetah, a nice juicy impala is the “runs really fast and goes ‘boing!’ ” part of this good-for-you breakfast. But what if you’re not very hungry at the moment? Then he’s your new playmate! That’s what photographer Michel Denis-Huot discovered in these amazing shots for the Daily Mail. Already tired from hunting, the cheetahs patted and nuzzled the impala for about 15 minutes… … and, even more amazingly, the impala nuzzled back … … before remembering that it was food and scampering away. Sent in by a gazillion people, all of whom were Goran G.





Published: January 27, 2010
Source: Ubuntu - news, usn
Referenced CVEs:
CVE-2009-0692
Description:
===========================================================
Ubuntu Security Notice USN-803-2 January 27, 2010
dhcp3 vulnerability
CVE-2009-0692
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.10
Ubuntu 9.04
Ubuntu 9.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.10:
dhcp3-client 3.1.1-1ubuntu2.2
dhcp3-client-udeb 3.1.1-1ubuntu2.2
Ubuntu 9.04:
dhcp-client 3.1.1-5ubuntu8.2
dhcp3-client 3.1.1-5ubuntu8.2
Ubuntu 9.10:
dhcp-client 3.1.2-1ubuntu7.1
dhcp3-client 3.1.2-1ubuntu7.1
After a standard system upgrade you need to restart any DHCP network
connections utilizing dhclient3 to effect the necessary changes.
Details follow:
USN-803-1 fixed a vulnerability in Dhcp. Due to an error, the patch to
fix the vulnerability was not properly applied on Ubuntu 8.10 and higher.
Even with the patch improperly applied, the default compiler options
reduced the vulnerability to a denial of service. Additionally, in Ubuntu
9.04 and higher, users were also protected by the AppArmor dhclient3
profile. This update fixes the problem.
Original advisory details:
It was discovered that the DHCP client as included in dhcp3 did not verify
the length of certain option fields when processing a response from an IPv4
dhcp server. If a user running Ubuntu 6.06 LTS or 8.04 LTS connected to a
malicious dhcp server, a remote attacker could cause a denial of service or
execute arbitrary code as the user invoking the program, typically the
'dhcp' user. For users running Ubuntu 8.10 or 9.04, a remote attacker
should only be able to cause a denial of service in the DHCP client. In
Ubuntu 9.04, attackers would also be isolated by the AppArmor dhclient3
profile.
Published: January 28, 2010
Source: Ubuntu - news, usn
Referenced CVEs:
CVE-2009-3297
Description:
===========================================================
Ubuntu Security Notice USN-893-1 January 28, 2010
samba vulnerability
CVE-2009-3297
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
Ubuntu 9.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
smbfs 3.0.22-1ubuntu3.10
Ubuntu 8.04 LTS:
smbfs 3.0.28a-1ubuntu4.10
Ubuntu 8.10:
smbfs 2:3.2.3-1ubuntu3.7
Ubuntu 9.04:
smbfs 2:3.3.2-1ubuntu3.3
Ubuntu 9.10:
smbfs 2:3.4.0-3ubuntu5.4
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Ronald Volgers discovered that the mount.cifs utility, when installed as a
setuid program, suffered from a race condition when verifying user
permissions. A local attacker could trick samba into mounting over
arbitrary locations, leading to a root privilege escalation.
Published: January 28, 2010
Source: Ubuntu - news, usn
Referenced CVEs:
CVE-2009-3297
Description:
===========================================================
Ubuntu Security Notice USN-892-1 January 28, 2010
fuse vulnerability
CVE-2009-3297
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
Ubuntu 9.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
fuse-utils 2.4.2-0ubuntu3.1
Ubuntu 8.04 LTS:
fuse-utils 2.7.2-1ubuntu2.1
Ubuntu 8.10:
fuse-utils 2.7.3-4ubuntu2.1
Ubuntu 9.04:
fuse-utils 2.7.4-1.1ubuntu4.0.9.04.1
Ubuntu 9.10:
fuse-utils 2.7.4-1.1ubuntu4.3
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Dan Rosenberg discovered that FUSE did not correctly check mount
locations. A local attacker, with access to use FUSE, could unmount
arbitrary locations, leading to a denial of service.
Published: February 1, 2010
Source: Cute Overload
Published: January 30, 2010
Source: recently added on we heart it

0 Responses to “Google reader”