[USN-5340-1] CKEditor vulnerabilities

David Fernandez Gonzalez david.fernandezgonzalez at canonical.com
Tue Mar 22 16:58:14 UTC 2022


==========================================================================
Ubuntu Security Notice USN-5340-1
March 22, 2022

ckeditor vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in CKEditor.

Software Description:
- ckeditor: text editor which can be embedded into web pages

Details:

Kyaw Min Thein discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue
to execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS. (CVE-2018-9861)

Micha Bentkowski discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-9281)

Anton Subbotin discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 21.10. (CVE-2021-32808)

Anton Subbotin discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
inject arbitrary code. (CVE-2021-32809)

Or Sahar discovered that CKEditor incorrectly handled certain
inputs. An attacker could possibly use this issue to execute
arbitrary code. This issue only affects
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-33829)

Mika Kulmala discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2021-37695)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.10:
ckeditor 4.16.0+dfsg-2ubuntu0.1

Ubuntu 20.04 LTS:
ckeditor 4.12.1+dfsg-1ubuntu0.1

Ubuntu 18.04 LTS:
ckeditor 4.5.7+dfsg-2ubuntu0.18.04.1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5340-1
CVE-2018-9861, CVE-2020-9281, CVE-2021-32808, CVE-2021-32809,
CVE-2021-33829, CVE-2021-37695

Package Information:
https://launchpad.net/ubuntu/+source/ckeditor/4.16.0+dfsg-2ubuntu0.1
https://launchpad.net/ubuntu/+source/ckeditor/4.12.1+dfsg-1ubuntu0.1
https://launchpad.net/ubuntu/+source/ckeditor/4.5.7+dfsg-2ubuntu0.18.04.1
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_0x196D412138F33F64.asc
Type: application/pgp-keys
Size: 2497 bytes
Desc: OpenPGP public key
URL: <https://lists.ubuntu.com/archives/ubuntu-security-announce/attachments/20220322/d9f7122d/attachment.key>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature
Type: application/pgp-signature
Size: 665 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/ubuntu-security-announce/attachments/20220322/d9f7122d/attachment.sig>


More information about the ubuntu-security-announce mailing list