Advisory for Ubuntu Packages Security Update

  • NIC-CERT/2022-10/426
  • Date: 2022-10-10
  • CVE ID: Multiple
  • Severity: High
  1. Description:

Vulnerability have been reported in Ubuntu package which could allow an attackerto take control of the affected system.

  1. Security Issues Fixed:
    Ubuntu has released an advisory for package which contains vulnerabilities in thunderbird, Libre Office, Linux Kernel, kitty, jackd2, python-Django.
  2. Affected Package and Solution:

Affected Package

CVE IDs

Updated Version

thunderbird - Mozilla Open-Source mail and newsgroup client

CVE-2022-36059 CVE-2022-38476 CVE-2022-3034 CVE-2022-38472 CVE-2022-3033 CVE-2022-36319 CVE-2022-3032 CVE-2022-38473 CVE-2022-38478 CVE-2022-38477 CVE-2022-2505 CVE-2022-36318

Ubuntu 22.04

Ubuntu 20.04

Ubuntu 18.04

LibreOffice - Office productivity suite

CVE-2022-26307 CVE-2022-26306 CVE-2022-26305

Ubuntu 20.04

linux-gcp-5.4 - Linux kernel for Google Cloud Platform (GCP) systems

CVE-2022-36946 CVE-2022-2503 CVE-2022-32296 CVE-2021-33655 CVE-2022-1012 CVE-2022-1729

Ubuntu 18.04

kitty - fast, featureful, GPU based terminal emulator

CVE-2022-41322 CVE-2020-35605

Ubuntu 22.04

Ubuntu 20.04

isc-dhcp - DHCP server and client

CVE-2022-2929 CVE-2022-2928

Ubuntu 22.04

Ubuntu 20.04

Ubuntu 18.04

jackd2 - JACK Audio Connection Kit (server and example clients)

CVE-2019-13351

Ubuntu 16.04

linux-intel-iotg - Linux kernel for Intel IoT platforms

CVE-2022-33741 CVE-2022-33744 CVE-2021-33655 CVE-2022-33740 CVE-2022-34495 CVE-2022-26365 CVE-2022-36946 CVE-2022-33743 CVE-2022-33742 CVE-2022-34494 CVE-2022-2318

Ubuntu 22.04

linux-gke - Linux kernel for Google Container Engine (GKE) systems

CVE-2022-36946 CVE-2022-32296 CVE-2021-33655 CVE-2022-1012 CVE-2022-2503 CVE-2022-1729

Ubuntu 20.04

python-django - High-level Python web development framework

CVE-2022-41323

Ubuntu 22.04

Ubuntu 20.04

The problem can be corrected by updating your system the updated package versions.

  1. References:

https://ubuntu.com/security/notices