Ubuntu 6591 Published by

The following updates has been released for Ubuntu Linux:

USN-3690-2: AMD Microcode regression

USN-3690-1 provided updated microcode for AMD processors to address CVE-2017-5715 (aka Spectre). Unfortunately, the update caused some systems to fail to boot. This update reverts the update for Ubuntu 14.04 LTS.

USN-3705-1: Firefox vulnerabilities

Firefox could be made to crash or run programs as your login if it opened a malicious website.



USN-3690-2: AMD Microcode regression


=========================================================================
Ubuntu Security Notice USN-3690-2
July 05, 2018

amd64-microcode regression
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

The system could be made to expose sensitive information.

Software Description:
- amd64-microcode: Processor microcode firmware for AMD CPUs

Details:

USN-3690-1 provided updated microcode for AMD processors to address
CVE-2017-5715 (aka Spectre). Unfortunately, the update caused some
systems to fail to boot. This update reverts the update for Ubuntu
14.04 LTS.

We apologize for the inconvenience.

Original advisory details:

Jann Horn discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory.

This update provides the microcode updates for AMD 17H family
processors required for the corresponding Linux kernel updates.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
amd64-microcode 3.20180524.1~ubuntu0.14.04.2+really20130710.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3690-2
https://usn.ubuntu.com/usn/usn-3690-1
https://launchpad.net/bugs/1779092

Package Information:
https://launchpad.net/ubuntu/+source/amd64-microcode/3.20180524.1~ubuntu0.14.04.2+really20130710.1


USN-3705-1: Firefox vulnerabilities


==========================================================================
Ubuntu Security Notice USN-3705-1
July 05, 2018

firefox vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 17.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Firefox could be made to crash or run programs as your login if it
opened a malicious website.

Software Description:
- firefox: Mozilla Open Source web browser

Details:

Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, read uninitialized
memory, bypass same-origin restrictions, bypass CORS restrictions,
bypass CSRF protections, obtain sensitive information, or execute
arbitrary code. (CVE-2018-5156, CVE-2018-5186, CVE-2018-5187,
CVE-2018-5188, CVE-2018-12358, CVE-2018-12359, CVE-2018-12360,
CVE-2018-12361, CVE-2018-12362, CVE-2018-12363, CVE-2018-12364,
CVE-2018-12365, CVE-2018-12366, CVE-2018-12367, CVE-2018-12370,
CVE-2018-12371)

A security issue was discovered with WebExtensions. If a user were
tricked in to installing a specially crafted extension, an attacker
could potentially exploit this to obtain full browser permissions.
(CVE-2018-12369)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
firefox 61.0+build3-0ubuntu0.18.04.1

Ubuntu 17.10:
firefox 61.0+build3-0ubuntu0.17.10.1

Ubuntu 16.04 LTS:
firefox 61.0+build3-0ubuntu0.16.04.2

Ubuntu 14.04 LTS:
firefox 61.0+build3-0ubuntu0.14.04.2

After a standard system update you need to restart Firefox to make
all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3705-1
CVE-2018-12358, CVE-2018-12359, CVE-2018-12360, CVE-2018-12361,
CVE-2018-12362, CVE-2018-12363, CVE-2018-12364, CVE-2018-12365,
CVE-2018-12366, CVE-2018-12367, CVE-2018-12369, CVE-2018-12370,
CVE-2018-12371, CVE-2018-5156, CVE-2018-5186, CVE-2018-5187,
CVE-2018-5188

Package Information:
https://launchpad.net/ubuntu/+source/firefox/61.0+build3-0ubuntu0.18.04.1
https://launchpad.net/ubuntu/+source/firefox/61.0+build3-0ubuntu0.17.10.1
https://launchpad.net/ubuntu/+source/firefox/61.0+build3-0ubuntu0.16.04.2
https://launchpad.net/ubuntu/+source/firefox/61.0+build3-0ubuntu0.14.04.2



--4RyF7oCH91rpagV1DeiHNVaA0BZmxGLd1--

--eg7pQE0notV3atXmk01mUof1YHd3b0rdH
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"