========================================================================== Ubuntu Security Notice USN-3759-1 September 05, 2018 libtirpc vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in libtirpc. Software Description: - libtirpc: transport-independent RPC library - development files Details: Aldy Hernandez discovered that libtirpc incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-4429) It was discovered that libtirpc incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-14622) It was discovered that libtirpc incorrectly handled certain strings. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-8779) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libtirpc-dev 0.2.5-1.2ubuntu0.1 libtirpc1 0.2.5-1.2ubuntu0.1 Ubuntu 16.04 LTS: libtirpc-dev 0.2.5-1ubuntu0.1 libtirpc1 0.2.5-1ubuntu0.1 Ubuntu 14.04 LTS: libtirpc-dev 0.2.2-5ubuntu2.1 libtirpc1 0.2.2-5ubuntu2.1 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://usn.ubuntu.com/usn/usn-3759-1 CVE-2016-4429, CVE-2017-8779, CVE-2018-14622 Package Information: https://launchpad.net/ubuntu/+source/libtirpc/0.2.5-1.2ubuntu0.1 https://launchpad.net/ubuntu/+source/libtirpc/0.2.5-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libtirpc/0.2.2-5ubuntu2.1