Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-6402-1

Ubuntu Security Notice 6402-1 - It was discovered that LibTomMath incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code and cause a denial of service.

Packet Storm
#vulnerability#ubuntu#dos

==========================================================================
Ubuntu Security Notice USN-6402-1
October 02, 2023

libtommath vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 23.04
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 LTS (Available with Ubuntu Pro)
  • Ubuntu 16.04 LTS (Available with Ubuntu Pro)

Summary:

LibTomMatch could be made to execute arbitrary code or
denial of service if it received a specially crafted input.

Software Description:

  • libtommath: multiple-precision integer library [development files]

Details:

It was discovered that LibTomMath incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code
and cause a denial of service (DoS).

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.04:
libtommath1 1.2.0-6ubuntu0.23.04.1

Ubuntu 22.04 LTS:
libtommath1 1.2.0-6ubuntu0.22.04.1

Ubuntu 20.04 LTS:
libtommath1 1.2.0-3ubuntu0.1

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
libtommath1 1.0.1-1ubuntu0.1~esm1

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
libtommath0 0.42.0-1.2ubuntu0.1~esm1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6402-1
CVE-2023-36328

Package Information:
https://launchpad.net/ubuntu/+source/libtommath/1.2.0-6ubuntu0.23.04.1
https://launchpad.net/ubuntu/+source/libtommath/1.2.0-6ubuntu0.22.04.1
https://launchpad.net/ubuntu/+source/libtommath/1.2.0-3ubuntu0.1

Related news

Ubuntu Security Notice USN-6402-2

Ubuntu Security Notice 6402-2 - USN-6402-1 fixed vulnerabilities in LibTomMath. This update provides the corresponding updates for Ubuntu 23.10. It was discovered that LibTomMath incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code and cause a denial of service.

CVE-2023-36328: Fix possible integer overflow by czurnieden · Pull Request #546 · libtom/libtommath

Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).

Packet Storm: Latest News

Ubuntu Security Notice USN-7121-3