========================================================================== Ubuntu Security Notice USN-1705-1 January 28, 2013 libav vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 11.10 Summary: Libav could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - libav: Multimedia player, server, encoder and transcoder Details: It was discovered that Libav incorrectly handled certain malformed media files. If a user were tricked into opening a crafted media file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: libavcodec53 6:0.8.5-0ubuntu0.12.10.1 libavformat53 6:0.8.5-0ubuntu0.12.10.1 Ubuntu 12.04 LTS: libavcodec53 4:0.8.5-0ubuntu0.12.04.1 libavformat53 4:0.8.5-0ubuntu0.12.04.1 Ubuntu 11.10: libavcodec53 4:0.7.6-0ubuntu0.11.10.3 libavformat53 4:0.7.6-0ubuntu0.11.10.3 In general, a standard system update will make all the necessary changes. References: http://www.ubuntu.com/usn/usn-1705-1 CVE-2012-2783, CVE-2012-2791, CVE-2012-2797, CVE-2012-2798, CVE-2012-2801, CVE-2012-2802, CVE-2012-2803, CVE-2012-2804, CVE-2012-5144 Package Information: https://launchpad.net/ubuntu/+source/libav/6:0.8.5-0ubuntu0.12.10.1 https://launchpad.net/ubuntu/+source/libav/4:0.8.5-0ubuntu0.12.04.1 https://launchpad.net/ubuntu/+source/libav/4:0.7.6-0ubuntu0.11.10.3
Spotlight

Information security executives need to be strategic thinkers
Posted on 17 June 2013. | George Baker, the Director of Information Security at Exostar, talks about the challenges in working in a dynamic threat landscape, offers tips for aspiring infosec leaders, and more.

Large orgs in denial about own security breaches?
Posted on 14 June 2013. | Over two thirds (66%) of large organizations said they either had not experienced a security incident in the last 12-18 months or were unsure if they had.

Vulnerability scanning with PureCloud
Posted on 12 June 2013. | nCircle PureCloud is a cloud-based network security scanning product built upon the companies' vulnerability and risk management system IP360.

To hack back or not to hack back?
Posted on 12 June 2013. | If you think of cyberspace as a new resource for you and your organization, it makes sense to protect your part of it as best you can. But is it a good idea?

Reactions from the security community to the NSA spying scandal
Posted on 11 June 2013. | Read on for comments on this scandal that Help Net Security received from a variety of security professionals and analysts.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.


